Ækora · Legal

Data processing

A high-level overview of how a data processing agreement (DPA) for IEVA will be structured — without inventing commitments before they exist.

Status

IEVA is in private launch. A complete DPA will be finalized with counsel before any customer data is processed under contract. This page states the intended structure only; nothing here creates contractual commitments.

Intended DPA structure

  • Roles: customer as controller, Ækora as processor.
  • Processing scope bound to documented instructions and the product’s explicit source authorizations.
  • Confidentiality obligations for anyone with access to customer data.
  • Security measures consistent with the principles on the security page, stated concretely once verified.
  • Subprocessor transparency via /legal/subprocessors, with notice of changes.
  • Assistance with data-subject requests, deletion and return of data at termination, and audit support appropriate to the deployment.
  • International transfer mechanism: [INTERNATIONAL TRANSFER MECHANISM].

Requesting the full agreement

Private-launch participants can request the current draft DPA at hola@aekora.com.