1. Purpose and Scope This Data Processing Addendum ("DPA") supplements the master service agreements, statements of work, or service terms entered into between Northwind Studio ("Processor") and the contracting enterprise client ("Controller").#
This DPA applies where and to the extent that Northwind Studio processes Customer Personal Data on behalf of the Controller during the delivery of custom software engineering, cloud architecture, AI development, or digital services, in accordance with GDPR Article 28, the UK Data Protection Act 2018, and applicable data protection legislation.
2. Roles and Instructions of the Parties - **Roles:** The client acts as the Data Controller, determining the purposes and means of processing. Northwind Studio acts as the Data Processor, processing personal data exclusively on behalf of and under the documented instructions of the Controller. - **Documented Instructions:** Northwind Studio processes customer personal data solely to fulfill project deliverables outlined in the applicable Statement of Work, or as required by applicable EU or UK law.#
3. Personnel Confidentiality and Security Northwind Studio ensures that all personnel authorized to process customer personal data:#
- Are bound by enforceable contractual confidentiality obligations.
- Receive role-appropriate data protection and security hygiene training.
- Access customer data strictly on a need-to-know basis governed by least-privilege access controls.
4. Technical and Organizational Measures (TOMs) Northwind Studio implements and maintains rigorous technical and organizational measures to ensure a level of security appropriate to the risk, including:#
- Data Encryption: Mandatory TLS 1.3 encryption for all data in transit and AES-256 encryption for data at rest.
- Access Governance: Centralized identity management, role-based access control (RBAC), and mandatory multi-factor authentication (MFA).
- Vulnerability Management: Automated dependency vulnerability scanning, regular code reviews, and defensive DevSecOps pipelines.
- Resilience & Backups: Automated backups, infrastructure redundancy across secure cloud data centers, and documented incident response procedures.
5. Subprocessor Engagement - **Authorization:** Controller grants general written authorization for Northwind Studio to engage subprocessors to support infrastructure and tooling operations. - **Current Subprocessors:** An up-to-date registry of authorized subprocessors is publicly maintained in our Subprocessors Directory. - **Notification of Changes:** Northwind Studio provides at least 30 days prior written notice before onboarding a new subprocessor, giving Controller an opportunity to raise reasonable data protection objections. - **Contractual Pass-Through:** Northwind Studio executes written agreements with all subprocessors imposing data protection obligations no less protective than those set forth in this DPA.#
6. Assistance with Data Subject Requests (DSRs) Taking into account the nature of the processing, Northwind Studio assists the Controller through appropriate technical and organizational measures to fulfill the Controller's obligations to respond to data subjects exercising rights under Chapter III of the GDPR (access, rectification, erasure, portability, objection).#
7. Personal Data Breach Notification In the event of a confirmed Personal Data Breach affecting Controller's personal data within Northwind Studio systems:#
- Northwind Studio will notify the Controller without undue delay, and in any event within 48 hours of becoming aware of the breach.
- The notification will detail the nature of the incident, affected data categories, estimated impact, and corrective mitigation measures taken or planned.
8. Deletion and Return of Customer Personal Data Upon completion of the services or termination of the applicable agreement, Northwind Studio will, at the Controller's choice, securely delete or return all customer personal data in its possession, unless applicable statutory law mandates retention.#
9. Cross-Border Transfers & Standard Contractual Clauses Where processing involves cross-border transfers of personal data from the EEA or UK to countries not recognized as providing adequate data protection, the parties incorporate by reference the European Commission's Standard Contractual Clauses (SCCs Module 2 Controller-to-Processor) and the UK International Data Transfer Addendum.#
10. Contact for DPA Execution To execute a signed enterprise copy of this DPA or request custom contractual addenda, please contact our legal team at [contact@northwindstudio.tech](mailto:contact@northwindstudio.tech).#
Questions or Inquiries?
Direct inquiries regarding this policy are handled by our governance team.
If you require clarification on any term, wish to exercise a data subject right, or need custom contractual addenda, please contact:
Related Policies & Agreements
Privacy Policy
How Northwind Studio collects, processes, secures, and retains personal data across our digital platforms, client inquiries, and engineering operations in compliance with GDPR, UK Data Protection Act, and CCPA.
Subprocessors & Infrastructure Providers
Directory of authorized third-party infrastructure, cloud hosting, and tooling subprocessors engaged by Northwind Studio to deliver platform and client services.
Terms of Service
Terms governing public website access, informational materials, intellectual property, and the relationship between website terms and project-specific client contracts.