Data Processing Agreement
Standard template — SecPry
1. Parties and roles
This Data Processing Agreement ("DPA") is entered into between the customer (the "Controller") and SecPry (the "Processor"). It governs the processing of personal data by SecPry on behalf of the Controller in the course of providing the SecPry Microsoft 365 security auditing service (the "Service").
2. Subject matter and duration
SecPry processes personal data for the duration of the Service subscription. Upon termination, data is deleted according to Section 8. The subject matter is the security assessment of the Controller's Microsoft 365 tenant.
3. Nature and purpose of processing
SecPry reads configuration and directory metadata from the Controller's Microsoft 365 tenant via the Microsoft Graph API to detect security risks (accounts without MFA, risky OAuth applications, expiring secrets, suspicious sign-ins). Processing is limited to what is necessary to generate security findings and recommendations.
4. Categories of data and data subjects
Data subjects: the Controller's employees and administrators. Categories: user principal names / email addresses, display names, role assignments, authentication method metadata, sign-in metadata (IP, location), and application registration metadata. No special-category data is intentionally processed.
5. Controller instructions
SecPry processes personal data only on documented instructions from the Controller, including this DPA and the configuration the Controller sets in the Service. SecPry informs the Controller if an instruction infringes applicable data protection law.
6. Security measures
SecPry implements appropriate technical and organizational measures, including encryption of tenant credentials at rest (AES-256-GCM), encryption in transit (TLS), tenant isolation at the application layer, mandatory two-factor authentication for privileged access, least-privilege Microsoft Graph scopes, and audit logging of sensitive actions.
7. Sub-processors
SecPry engages sub-processors (hosting and infrastructure providers) under written terms imposing data protection obligations equivalent to those in this DPA. A current list is available on request; SecPry gives prior notice of intended changes so the Controller may object.
8. Data subject rights, return and deletion
SecPry assists the Controller in responding to data subject requests. The Controller can export its data at any time (Settings → Data & GDPR) and can erase its account and organization data through the Service, which permanently deletes the associated personal data. Audit-trail records may be retained where required to evidence compliance.
9. Audits
SecPry makes available to the Controller information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality and scheduling terms.
10. International transfers
Where personal data is transferred outside the EEA, such transfers are made under an appropriate transfer mechanism (e.g. Standard Contractual Clauses) as required by applicable law.