Data Processing Agreement (DPA)
Standard Technical & Organizational Measures (TOMs) • Version 2.2
1. Purpose & Processing Instructions
This Data Processing Agreement ("DPA") governs the processing of project data and business contact identifiers submitted by the Client ("Data Controller") to Erayaha ("Data Processor") in connection with environmental clearance pre-submission screening and audit services.
2. Technical & Organizational Measures (TOMs)
- Ephemeral Processing: Project documents are parsed strictly in isolated ephemeral runtime containers with zero persistence after audit report generation.
- Access Control: Strict role-based access control (RBAC) enforced via multi-factor authentication (MFA).
- Transmission Security: TLS 1.3 enforced across all public endpoints and internal service boundaries.
- Audit Logging: Immutable tamper-evident logging of administrative and processing events.
3. Subprocessors
Erayaha utilizes verified enterprise cloud infrastructure providers (such as Cloudflare for distributed edge execution and enterprise tier-1 AI compute providers with executed zero-data-retention commitments). We provide 30 days prior written notice of any subprocessor modifications.