GDPR Article 28 — Standard Controller-Processor Terms
This DPA governs the processing of personal data by J Computer Solutions LLC on behalf of organizations (controllers) that use the Project Aziz API or platform in connection with their own data subjects.
"Controller" means the organization determining the purposes and means of processing. "Processor" means J Computer Solutions LLC, processing data on behalf of the Controller. "Personal Data," "Data Subject," "Processing," and "Supervisory Authority" have the meanings given in the GDPR and applicable data protection law.
J Computer Solutions LLC, as Processor, shall: process personal data only on documented instructions from the Controller; ensure that authorized personnel are bound by confidentiality obligations; implement the security measures described in Section 5; engage sub-processors only under equivalent data protection obligations; assist the Controller in fulfilling data subject rights requests; delete or return all personal data upon contract termination at the Controller's choice.
The Controller shall: ensure it has a lawful basis for instructing the Processor to process personal data; provide clear and documented processing instructions; notify the Processor promptly of any changes to processing requirements; and be responsible for the accuracy and lawfulness of personal data submitted to the platform.
J Computer Solutions LLC uses the following sub-processors: Stripe (payment processing), cloud infrastructure providers (hosting and storage), and email delivery services. A complete and updated sub-processor list is available upon request. We will provide 30 days notice before adding new sub-processors, during which the Controller may object.
Technical and organizational measures include: AES-256 encryption at rest; TLS 1.3 in transit; role-based access control; multi-factor authentication for administrative access; regular penetration testing; incident response procedures; and personnel security training.
We will assist Controllers in responding to data subject requests within applicable timeframes. Controllers must forward data subject requests to us within 5 business days of receipt. We will respond to requests within the statutory timeframes (generally 30 days under GDPR).
In the event of a personal data breach, J Computer Solutions LLC will notify the Controller without undue delay and within 72 hours of becoming aware. Notification will include: the nature of the breach; categories and approximate number of data subjects affected; likely consequences; and measures taken or proposed to address the breach.
J Computer Solutions LLC will provide all information necessary to demonstrate compliance and allow for audits conducted by the Controller or a mandated auditor, with reasonable advance notice and subject to confidentiality obligations.
Organizations requiring a signed DPA should contact us via our contact page. We will provide a countersigned DPA within 10 business days of a written request.