# 1. Scope & Definitions
This DPA applies to all processing of personal data conducted by Certifada ('Processor') on behalf of Customer ('Controller') in connection with credential issuance services.
# 2. Processor Obligations
Processor agrees to process personal data strictly in accordance with Controller documented instructions, implement AES-256 technical and organizational security measures, and ensure personnel confidentiality commitments.
# 3. Standard Contractual Clauses (SCCs)
Where personal data is transferred outside the EEA or UAE to countries without an adequacy decision, the EU Standard Contractual Clauses (Module 2 Controller-to-Processor) are hereby incorporated by reference.
# 4. Authorized Subprocessors
Controller grants general authorization to Processor to engage infrastructure subprocessors listed on our Subprocessors Page. Processor will provide 14 days notice prior to adding new subprocessors.
# 5. Security Audits & Compliance Documentation
Processor shall make available to Controller all information reasonably necessary to demonstrate compliance with GDPR Article 28 and UAE PDPL requirements, including ISO/SOC audit summaries upon request.