Data Processing Agreement

Data Processing Agreement (DPA)

Governly acts as a data processor for the personal data that customers and their suppliers upload while running a vendor assessment. This page is maintained by the Governly team and describes what our DPA covers. It is not itself a signed agreement.

What our DPA covers

  • Scope, nature and purpose of processing performed by Governly on the customer's behalf.
  • Categories of data subjects and personal data processed.
  • Sub-processors used to deliver the service (see the Sub-processors page).
  • Data residency: primary storage region and processing locations.
  • Security measures aligned with the practices described on the Security page.
  • Customer rights: audit, data return and deletion at the end of the contract.
  • Personal-data breach notification process and contact channel.

Standard Contractual Clauses

Where a sub-processor operates outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses (2021/914) with the safeguards documented in our security posture.

Request a signed copy

We provide a signed DPA on request for paid tiers, and can also review a customer-provided DPA. Email privacy@governly.se and include your legal entity name.

Related pages

  • Sub-processors — current list, purpose and processing region for each.
  • Security & privacy — encryption, residency, retention and compliance posture.
  • Trust — incident response, backup and continuity posture.
  • Privacy Policy — how we handle personal data as a controller.