Data processing agreement
Last updated . Version 2026-09-11.
These processing terms take effect when LaunchProof and the customer agree to them in writing, including by email identifying this version and the workspace. Arrange this before uploading personal data on behalf of other people. Use synthetic, non-personal test data otherwise.
1. Parties and application
The processor is the company below. The customer is the organization or person identified in the written agreement, which records its legal name, address, contact, workspace, and whether it is a controller or an authorized processor for another controller. Both parties must confirm the agreement; viewing this page alone does not conclude it. Contact contact@exponentialeducation.ro to arrange it.
EXPONENTIAL EDUCATION S.R.L.Municipiul Iași, Strada N. Istrati, Nr. 6, Județ Iași, 700460, Romania
Romanian tax identifier, CUI: 54790758
Trade registry: J2026035424002
European unique identifier, EUID: ROONRC.J2026035424002
Email: contact@exponentialeducation.ro
This DPA supplements the agreed LaunchProof service terms and prevails for processing of customer personal data if they conflict. GDPR terms have their statutory meanings. It does not cover our own controller processing of account administration, security, billing, and correspondence, described in the privacy notice.
2. Processing instructions and details
The subject matter is hosted storage and review of customer-run application-test reports. Operations include receiving, validating, organizing, storing, retrieving, displaying, comparing, exporting, reviewing, and deleting reports and related notes. The purpose is providing the customer's agreed reporting service or assisted review. Processing occurs when instructed by uploads, workspace actions, and the agreed review scope, for the service period and applicable deletion period.
Data subjects can include the customer's authorized users, developers, reviewers, and people referred to in permitted test evidence. Data types can include user identifiers, names and contact details inadvertently retained in evidence, authorization records, activity timestamps, test observations, and review notes. The customer must minimize these data and use synthetic fixtures. Special-category data, criminal-offence data, production customer datasets, and target credentials are outside the agreed scope.
The customer controls the purpose, lawful basis, accuracy, and disclosure of its data, provides required notices, and gives lawful documented instructions. A customer acting as a processor must obtain the controller's authority. We process only on documented instructions, including for transfers, unless law requires otherwise. We inform the customer of a legally required processing operation before it occurs unless prohibited, and immediately flag an instruction we believe infringes applicable data-protection law.
3. Confidentiality and security
We restrict authorized access to people who need it for the service and who are bound by confidentiality. We maintain measures appropriate to the risk under GDPR Article 32. Application measures include HTTPS in production, authentication, current workspace membership and role checks, application-scoped hashed reporting tokens, request-origin checks, bounded report validation, access revocation, and report expiry and deletion jobs. Customer target credentials remain on the customer's machine or CI.
We assess the effectiveness of security measures and work with infrastructure providers on availability, recovery, and incident handling. This clause does not promise a particular certification, recovery time, or fixed backup-erasure deadline. The customer secures its own devices, fixtures, exports, and tokens.
4. Subprocessors and international transfers
The customer grants general written authorization for the relevant providers identified in the subprocessor list at agreement. Before a new or replacement subprocessor processes its data, we give the customer notice at its agreed contact with enough time to assess and object on data-protection grounds. We will not begin the proposed processing while a timely, reasonable objection remains unresolved. If no suitable alternative can be agreed, the affected processing or service may end, with any refund required by the contract or law.
We require written obligations providing the same protection for the relevant processing and remain responsible to the customer for a subprocessor's performance. A restricted transfer requires an applicable Chapter V GDPR mechanism, including appropriate contractual safeguards where required. We provide information about applicable safeguards on request and assess additional protection where necessary. This DPA alone is not a substitute for international-transfer clauses.
5. Assistance and breaches
Taking account of the processing and information available to us, we assist the customer with requests under GDPR Articles 12 to 22, security duties, breach assessments and notifications, impact assessments, and prior consultation. We forward requests concerning customer-controlled data without undue delay and do not respond on the customer's behalf unless instructed or legally required.
We notify the customer without undue delay after becoming aware of a personal-data breach affecting its data. We provide available information about the nature of the breach, affected records and people, likely consequences, contact point, and measures taken or proposed, and supplement it as further facts become available. The customer remains responsible for its own authority and individual notifications, with our assistance.
6. Return and deletion
During use, each hosted report has the expiry shown in the service. On termination, at the customer's choice we return or delete customer personal data, and delete copies unless EU or Member State law requires retention. Arrange an export before report expiry or termination; an already purged report cannot be returned. Retained data are restricted to the legally required purpose.
Report expiry is 7, 30, or 90 days under the applicable hosted plan. Background deletion includes report checks and report-specific dispositions. Replay-prevention hashes can remain for 90 days after report cleanup unless the related application or workspace is deleted. Workspace records and independently required controller records have separate handling described in the privacy notice. Provider backup deletion follows the applicable provider lifecycle; we confirm the handling for the request without representing active-data deletion as immediate erasure of every backup.
7. Information, audits, and duration
We make available information needed to demonstrate these obligations and allow and contribute to audits, including inspections by the customer or its mandated auditor. The parties arrange proportionate confidentiality, security, and timing measures without preventing a statutory audit or regulator access. Other customers' confidential data must be protected.
These obligations continue for as long as we hold the customer's personal data within this DPA. Changes require written agreement where needed and cannot reduce mandatory protections. Applicable law, competent courts, and mandatory data-subject rights remain as provided by the GDPR and the service agreement.