Data Processing Agreement

Effective Date: Dec 18, 2025

This Data Processing Agreement (“DPA”) forms part of the master agreement (“Master Agreement”) between DEGU LABS, INC. with an address at 440 N Barranca Ave, #4556
Covina, CA 91723 (“Processor,” “Degu Labs”) and [Customer Legal Name]
[Customer Address] (“Controller” or “Customer”).

This DPA governs the processing of Personal Data by Degu Labs on behalf of Customer.

Effective Date: [Date]

1. Definitions

2. Roles of the Parties

Customer is the Controller.
Degu Labs is the Processor.

Processor will process Personal Data only in accordance with:

  1. Customer’s documented instructions

  2. The Master Agreement

  3. This DPA

3. Controller Responsibilities

Customer shall:

Degu Labs is not responsible for Customer’s accidental ingestion of prohibited or sensitive data.

4. Processor Obligations

4.1 Processing on Instructions

Degu Labs processes Personal Data only:

4.2 Confidentiality

Degu Labs ensures personnel accessing Personal Data are bound by confidentiality obligations.

4.3 Security Measures

Degu Labs maintains appropriate technical and organizational security measures, including:

See Schedule 2 for details.

4.4 Subprocessor Management

Degu Labs will:

4.5 Assistance

Degu Labs will reasonably assist Customer with:

4.6 Data Deletion or Return

Upon termination of the Service:

5. Data Breach Notification

Processor will notify Customer without undue delay after becoming aware of a Personal Data Breach.

Notification will include (where known):

Processor is not responsible for breaches arising from Customer’s systems.

6. International Transfers

Processor may transfer Personal Data internationally, including to the U.S.

Transfers are safeguarded using:

7. Audit Rights

Customer may conduct audits:

  1. No more than once annually (unless required by law)

  2. With reasonable notice

  3. Primarily via questionnaire or remote audit

Onsite audits must:

8. Liability

Liability is governed by the Master Agreement.
Degu Labs is not liable for:

9. Term and Termination

This DPA remains effective:

Upon termination:

SCHEDULE 1

Subprocessors

SubprocessorPurpose
HetznerHosting and compute infrastructure
CloudflareCDN, network security, DDoS protection
StripePayment processing

SCHEDULE 2

Technical & Organizational Measures (TOMs)

Organizational Measures

Technical Measures

Availability & Resilience

SCHEDULE 3

Categories of Data & Processing Purposes

Categories of Personal Data

Data Subjects

Processing Purposes

CONTACT

For privacy matters:

[email protected]
[email protected]

Degu Labs, Inc.
440 N Barranca Ave, #4556
Covina, CA 91723