Parties & scope
This DPA applies between SwiftPatch, Inc. ("Processor") and the customer ("Controller") that has signed up for a paid plan.
It governs the processing of any personal data Controller submits to SwiftPatch while using the service.
Subject matter & duration
Subject matter: processing of personal data as needed to deliver the SwiftPatch service.
Duration: until all personal data is deleted or returned, per the main agreement.
Security measures
Encryption in transit (TLS 1.3) and at rest (AES-256).
Role-based access control, enforced via SSO for SwiftPatch employees.
Annual penetration testing by an independent third party.
Written incident response plan with 72-hour breach notification commitment.
Sub-processors
AWS (hosting, us-east-1 / eu-west-1 / ap-south-1).
Stripe (billing).
Postmark (transactional email).
We notify Controller 30 days before adding or changing sub-processors.
Signing
Request a countersigned copy from dpo@swiftpatch.io with your entity's legal name and jurisdiction.