Data Processing Agreement (DPA)
For "Studio" Organizations acting as Data Controllers.
1. Scope. This agreement governs the processing of data by mewicu ("Processor") on behalf of the Organization ("Controller").
2. Nature of Processing. The Processor handles data solely to provide cloud-based build and obfuscation services, including ephemeral processing of files and storage of organizational audit logs.
3. Security. The Processor implements industry-standard technical measures (encryption at rest and in transit) and strict access controls to protect Controller data.
4. Breach Notification. In the event of a Personal Data Breach affecting Controller data, the Processor shall notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of the breach.
5. Sub-Processors. The Controller generally authorizes the use of the sub-processors listed in the Privacy Policy (including AWS and security providers) necessary for the delivery of the Service.
6. Deletion. Upon termination of the Service or upon specific request, the Processor shall delete all Controller data, except where retention is required by law or for legitimate security auditing purposes (e.g., fraud prevention logs).
7. Inquiries. For specific inquiries regarding data processing, contact: [email protected]