This Data Processing Agreement governs the processing of personal data by MS Power House on behalf of our clients in compliance with GDPR Article 28.
This DPA is designed to meet the requirements of GDPR Article 28 and ensures that personal data processing is conducted in accordance with applicable data protection laws. This agreement supplements our Master Service Agreement.
MS Power House will process personal data as necessary to provide IT services including managed services, cloud migration, data migration, and related technical support.
Duration: For the duration of the Master Service Agreement and applicable data retention periods.
| Processing Activity | Purpose | Lawful Basis |
|---|---|---|
| Email Migration | Transfer email data to new systems | Contract Performance |
| System Monitoring | Ensure service availability and security | Legitimate Interest |
| Technical Support | Resolve technical issues and incidents | Contract Performance |
| Backup Services | Data protection and disaster recovery | Contract Performance |
MS Power House will process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to third countries.
MS Power House ensures that persons authorized to process personal data have committed themselves to confidentiality or are under appropriate statutory obligation of confidentiality.
MS Power House will assist the Controller in fulfilling data subject rights requests:
MS Power House implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk:
The Controller provides general written authorization for MS Power House to engage sub-processors, subject to the conditions set out in this DPA.
| Sub-processor | Service | Location | Safeguards |
|---|---|---|---|
| Microsoft Corporation | Azure Cloud Services | Global (EU Data Residency) | Standard Contractual Clauses |
| Amazon Web Services | Backup and Archive Services | EU/US (Data Residency Controls) | Data Processing Addendum |
| Atlassian | Service Management Platform | Global (EU Data Residency) | Standard Contractual Clauses |
MS Power House will inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such changes.
Where personal data is transferred outside the EEA, MS Power House ensures appropriate safeguards are in place:
Default Policy: Personal data of EU residents is processed and stored within the EU unless explicitly authorized otherwise by the Controller. Technical and organizational measures prevent unauthorized international transfers.
Breach notifications will include:
Upon termination of services, MS Power House will, at the Controller's choice:
MS Power House will make available to the Controller information necessary to demonstrate compliance with Article 28 GDPR and allow for audits:
Controller may conduct one audit per year at no cost. Additional audits or on-site inspections may be subject to MS Power House's then-current professional services rates.
DPA Version: 1.3 | Effective Date: January 1, 2025
Last Updated: January 2025 | Next Review: January 2026