Data Processing Agreement

Effective Date: Jan 14, 2024

This Data Processing Agreement (“DPA”) forms part of the master agreement (“Master Agreement”) between DEGU LABS, INC. with an address at 440 N Barranca Ave, #4556
Covina, CA 91723 (“Processor,” “Degu Labs”) and you, or the entity you represent.
(“Controller” or “Customer”).

This DPA governs the processing of Personal Data by Degu Labs on behalf of Customer.

Effective Date: Jan 14, 2026

1. Definitions

2. Roles of the Parties

Customer is the Controller.
Degu Labs is the Processor.

Processor will process Personal Data only in accordance with:

  1. Customer’s documented instructions

  2. The Master Agreement

  3. This DPA

3. Controller Responsibilities

Customer shall:

Degu Labs is not responsible for Customer’s accidental ingestion of prohibited or sensitive data.

4. Processor Obligations

4.1 Processing on Instructions

Degu Labs processes Personal Data only:

4.2 Confidentiality

Degu Labs ensures personnel accessing Personal Data are bound by confidentiality obligations.

4.3 Security Measures

Degu Labs maintains appropriate technical and organizational security measures, including:

See Schedule 2 for details.

4.4 Subprocessor Management

Degu Labs will:

4.5 Assistance

Degu Labs will reasonably assist Customer with:

4.6 Data Deletion or Return

Upon termination of the Service:

5. Data Breach Notification

Processor will notify Customer without undue delay after becoming aware of a Personal Data Breach.

Notification will include (where known):

Processor is not responsible for breaches arising from Customer’s systems.

6. International Transfers

Processor may transfer Personal Data internationally, including to the U.S.

Transfers are safeguarded using:

7. Audit Rights

Customer may conduct audits:

  1. No more than once annually (unless required by law)

  2. With reasonable notice

  3. Primarily via questionnaire or remote audit

Onsite audits must:

8. Liability

Liability is governed by the Master Agreement.
Degu Labs is not liable for:

9. Term and Termination

This DPA remains effective:

Upon termination:

SCHEDULE 1

Subprocessors

SubprocessorPurpose
HetznerHosting and compute infrastructure
CloudflareCDN, network security, DDoS protection
StripePayment processing

SCHEDULE 2

Technical & Organizational Measures (TOMs)

Organizational Measures

Technical Measures

Availability & Resilience

SCHEDULE 3

Categories of Data & Processing Purposes

Categories of Personal Data

Data Subjects

Processing Purposes

CONTACT

For privacy matters:

[email protected]
[email protected]

Degu Labs, Inc.
440 N Barranca Ave, #4556
Covina, CA 91723