> ## Documentation Index
> Fetch the complete documentation index at: https://internal.softcrum.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Processing Annex (DPA) — DRAFT v0.1

> Between [SOFTCRUM SpA], RUT [__] ("the Processor") and the client identified in the Service Order ("the Controller"). Forms an integral part of the Terms of Service.

> ⚠️ **INFORMATIVE TRANSLATION — NOT BINDING.** The Spanish version at
> [`../../legal/`](/legal/overview) is the authoritative text and the only one that may be signed,
> published or presented to a third party. This English rendering exists so that non-Spanish readers
> can review the content; where the two differ, Spanish governs. Like its original, it is an
> unreviewed working draft — nothing here is legal advice, and nothing is final until a Chilean
> data-protection lawyer has signed off.

1. **Purpose.** The Processor will process personal data on behalf of the Controller solely to
   provide the Softcrum Suite services (contracted modules), in accordance with the Controller's
   documented instructions expressed through the platform configuration and this annex.
2. **Data and data subjects.** Categories: identification and contact data of the Controller's end
   customers (including identity document where the Controller enables it), transactional and
   interaction behaviour data, preferences and consents. Data subjects: end customers, commercial
   contacts and users of the Controller.
3. **Duration.** The term of the main contract; on termination, deletion or return per clause 10.
4. **Processor obligations.** (a) process only under instructions; (b) confidentiality of personnel;
   (c) security measures of the Security Annex (TOMs); (d) assist the Controller in handling data
   subject rights (access, rectification, erasure, objection, portability) through platform features,
   execution within ≤30 days; (e) assist with impact assessments and consultations with the
   authority; (f) maintain a record of processing activities; (g) make available the information
   necessary to demonstrate compliance.
5. **Sub-processors.** General authorisation for the sub-processors listed publicly at \[trust center
   URL]; the Processor will notify additions \[30] days in advance, and the Controller may object on
   reasoned grounds. The Processor is liable for its sub-processors.
6. **International transfers.** Sub-processors may process data outside Chile; basis: contractual
   clauses and the guarantees stated in the sub-processor list, in accordance with the transfer
   regime of Ley 21.719.
7. **Security breaches.** The Processor will notify the Controller without undue delay and at the
   latest within \[48] hours of becoming aware, with the information available (scope, categories,
   measures). Notification to the authority and to data subjects is the Controller's responsibility;
   the Processor will provide assistance.
8. **Audit.** At most \[1] time per year, with \[15] days' notice, by questionnaire and documentary
   evidence; on-site audit only upon demonstrated serious breach, at the Controller's cost.
9. **Liability.** In accordance with the liability regime of the main contract; each party is liable
   for the infringements attributable to it under its role.
10. **Termination.** At the Controller's election: export of data in a structured, commonly used
    format followed by deletion, or direct deletion; a deletion certificate is available. Accounting
    and ledger records are anonymized.

\[Signatures]
