Data processing agreement status
No DPA is currently issued on this site because controller/processor allocation, customer instructions, subprocessor list, regions, retention, security schedule, breach-notice commitment, audit rights, and transfer terms require business and legal approval.
Technical facts available for DPA review
- 01
RipoDoc supports PostgreSQL-backed identity and optional durable audit records, email through email service, anti-automation through edge-infrastructure provider challenge service, and a private authoring worker.
- 02
The public deployment currently reports hosted identity, intake, private worker, and durable audit as not configured.
- 03
Self-hosted operators may control their own database, proxy, storage, email service, backups, worker, and processor chain.
Required DPA decisions
- 01
Legal parties and roles, permitted processing instructions, data categories, data-subject categories, and duration.
- 02
Approved subprocessors, notification/change process, cross-border transfer mechanism, data location, deletion/return, and audit assistance.
- 03
Security measures, incident notification target, customer responsibilities, and healthcare/BAA relationship where applicable.