Data Processing Addendum
Last updated 19 July 2026
This addendum applies where we process personal data on your behalf as a processor (you being the controller), and forms part of our agreement. It is designed to meet GDPR Article 28 and equivalent POPIA obligations.
Roles
You are the controller of the Workspace directory and configuration data audited by the service. We are your processor and process it only on your documented instructions — namely, to provide the audit.
Scope of processing
- Subject matter: read-only security auditing of a Google Workspace tenant.
- Data: directory metadata, configuration settings, admin/audit metadata. No email, file, calendar or chat contents.
- Data subjects: your Workspace users and administrators.
- Duration: for the term of your use, subject to the retention terms in our Privacy Policy.
Our obligations
- Process only on your instructions and for the purpose of the service.
- Ensure personnel with access are bound by confidentiality.
- Apply appropriate technical and organisational security measures (encryption in transit and at rest, least-privilege access, no domain-wide delegation).
- Engage sub-processors only as listed, under equivalent obligations, and notify you of changes — see sub-processors.
- Assist you with data-subject requests and, where applicable, with your own compliance obligations.
- Notify you without undue delay on becoming aware of a personal-data breach.
- Delete or return the data at the end of processing, per our Privacy Policy.
International transfers
Our database is hosted in the EU (eu-west-1). Application hosting and Google APIs may involve transfers to other regions under appropriate safeguards; see our sub-processor list.
Signing
If you require a countersigned DPA for procurement, contact darren@dcai.co.za.
This document is provided in good faith and is subject to final legal review before it is relied upon contractually.