Data Processing Agreement
Data Processing Agreement (DPA)
Governly acts as a data processor for the personal data that customers and their suppliers upload while running a vendor assessment. This page is maintained by the Governly team and describes what our DPA covers. It is not itself a signed agreement.
What our DPA covers
- Scope, nature and purpose of processing performed by Governly on the customer's behalf.
- Categories of data subjects and personal data processed.
- Sub-processors used to deliver the service (see the Sub-processors page).
- Data residency: primary storage region and processing locations.
- Security measures aligned with the practices described on the Security page.
- Customer rights: audit, data return and deletion at the end of the contract.
- Personal-data breach notification process and contact channel.
Standard Contractual Clauses
Where a sub-processor operates outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses (2021/914) with the safeguards documented in our security posture.
Request a signed copy
We provide a signed DPA on request for paid tiers, and can also review a customer-provided DPA. Email privacy@governly.se and include your legal entity name.
Related pages
- • Sub-processors — current list, purpose and processing region for each.
- • Security & privacy — encryption, residency, retention and compliance posture.
- • Trust — incident response, backup and continuity posture.
- • Privacy Policy — how we handle personal data as a controller.