Version 1.0 — Last updated: 2025-10-31
This DPA governs processing of personal data by the Service provider (“Processor”) on behalf of the customer (“Controller”) in connection with use of phasi.app, pursuant to Art. 28 GDPR.
Processing is limited to workspace/project data uploaded by Controller’s users and lasts for the subscription term.
Authorized sub-processors are listed at /subprocessors. Processor remains responsible for sub-processors and uses appropriate safeguards.
Transfers outside the EEA (if any) rely on appropriate safeguards (e.g., EU SCCs) and transfer impact assessments where required.
Upon reasonable request, Processor provides information necessary to demonstrate compliance; audits subject to confidentiality and reasonable limitations.
Liability is governed by the Terms of Service. Nothing herein expands Processor’s liability beyond those Terms.
This DPA forms part of the Agreement and terminates with it. In case of conflict, the DPA prevails with respect to data protection.