01
Parties, scope, and definitions
The customer is controller or business and the Batch Scale contracting entity is processor or service provider for Customer Personal Data processed to provide the service. Applicable Data Protection Law, Customer Personal Data, processing, controller, processor, business, service provider, sale, and subprocessor require counsel-approved definitions.
02
Documented instructions and purpose limitation
Batch Scale will process Customer Personal Data only to provide, secure, support, and maintain the service; comply with documented customer instructions; and satisfy law. We will inform the customer if an instruction appears unlawful unless prohibited.
03
Customer obligations
Customer is responsible for lawful collection, notices, legal bases, instructions, configured users, data minimization, request decisions, and accuracy. Customer will not provide data outside the agreed processing details or prohibited by the Terms.
04
Confidentiality and personnel
People authorized to process Customer Personal Data will be bound by confidentiality and receive access appropriate to their duties. Access will be reviewed and removed when no longer needed.
05
Security measures
Batch Scale will maintain measures appropriate to risk, including access control, tenant isolation, authentication, transport protection, secure development, logging, vulnerability and dependency management, backup and recovery controls, incident response, provider review, and deletion practices. The final technical-measures annex must state verified production facts, not targets.
06
Subprocessors
Customer provides general authorization for subprocessors on the published approved register. Batch Scale will contractually require appropriate protection, remain responsible as required by law, provide advance notice of material additions under the agreement, and offer the counsel-approved objection and termination process.
07
Individual rights
Taking into account the nature of processing, Batch Scale will provide reasonable assistance for verified access, correction, deletion, portability, restriction, objection, opt-out, and appeal requests. If a person contacts Batch Scale about Customer Personal Data, we may direct the request to Customer unless law requires otherwise.
08
Incidents
Batch Scale will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data and provide available information needed for Customer’s obligations. Notice is not an admission of fault. The final DPA must state channels, required content, updates, cooperation, and legally reviewed timing.
09
DPIAs, regulators, and government requests
Batch Scale will reasonably assist with data-protection impact assessments and regulator consultation relevant to the service. Unless prohibited, we will notify Customer of a binding government demand for Customer Personal Data and challenge overbroad demands where reasonable.
10
Return and deletion
At termination or verified instruction, Batch Scale will return or delete Customer Personal Data according to the approved lifecycle, except information retained by law or in isolated backups until ordinary expiration. The final annex must define export windows, deletion verification, backup rotation, legal holds, and subprocessor deletion.
11
Audit information
Batch Scale will make information reasonably necessary to demonstrate compliance available under confidentiality and appropriate scope. Independent reports should be used when available. On-site inspection, cost, frequency, security, and competing-customer protections require final contractual terms.
12
International transfers
Restricted transfers require an approved mechanism. The final DPA must select and complete relevant EU SCC modules, UK addendum or IDTA, Swiss adaptations, transfer-impact documentation, supplementary measures, and conflict rules.
13
Processing-details annex
The annex must identify subject matter and duration; purposes; processing operations; data-subject categories; personal-data categories; sensitive-data restrictions and safeguards; deletion periods; and customer instructions. It cannot be completed accurately until the production data inventory is approved.
14
Execution and precedence
The DPA should terminate with the main agreement except for surviving protection and deletion duties. Applicable signatures, entity details, liability relationship, governing law, amendment procedure, and order of precedence require counsel approval.