Skip to main content
Citadel Exchange
TrustPricingSign inGet started

Legal · draft — counsel review required

Data Processing Agreement (DPA)

Template draft — have counsel review before reliance. Not legal advice. Product: Citadel Exchange · Language: English · Last updated: 2026-08-01

This DPA forms part of the agreement between the customer (“Controller”) and the operator of Citadel Exchange (“Processor”) for personal data processed when providing the Service.

1. Subject matter and duration

Processor provides the Service described in the Terms. Processing continues for the subscription term and any post-termination retention period.

2. Nature and purpose of processing

Host and transmit customer account data, authentication data, wrapped key material, room metadata, and customer-encrypted content as required to operate secure exchange rooms, billing, and support.

3. Types of personal data and data subjects

  • Types: account identifiers, contact data, auth factors, metadata, ciphertext

that may contain personal data once decrypted by the customer

  • Subjects: customer staff, invited clients/agents, and other end users the

customer authorizes

4. Controller instructions

Processor processes personal data only on documented instructions from Controller, including via product configuration, unless required by law.

5. Confidentiality

Processor ensures persons authorized to process personal data are bound by confidentiality.

6. Security measures

Processor implements appropriate technical and organizational measures, including access control, encryption in transit, encrypted content at rest (customer-held keys for room plaintext), audit logging, MFA for privileged roles, and incident response procedures. Details: cryptographic-controls and access-control policies.

7. Sub-processors

Controller authorizes the following sub-processors. Processor will give notice of material changes before they take effect (except emergencies).

Sub-processorPurposeTypical data
Infrastructure host (e.g. cloud VM / container host)Run application & PostgresAccount data, metadata, ciphertext blobs metadata
Object storage (MinIO or S3-compatible provider)Store encrypted file objectsCiphertext objects, object keys
Stripe, Inc.Payments, invoices, Customer PortalBilling identity, subscription status
Transactional email provider (as configured)Invitations, security alerts, digestsEmail address, notification content
Error / uptime monitoring (if enabled)ReliabilityOperational telemetry, limited personal data in logs

Replace vendor names with the production choices before counsel sign-off.

8. International transfers

Where sub-processors process data outside the Controller’s jurisdiction, Processor will ensure an adequate transfer mechanism (e.g. SCCs).

9. Assistance with data subject rights

Processor assists Controller, insofar as possible via product features (export, erasure requests) and reasonable cooperation, in responding to data subject requests.

10. Breach notification

Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller data, and provide information reasonably required for Controller’s own notification duties (including the GDPR 72-hour clock where applicable). See incident-response policy.

11. Deletion and return

On termination, Controller may export available data via product tools. After the agreed retention/grace period, Processor deletes or anonymizes personal data from active systems, except data retained for legal obligations or dispute resolution. Ciphertext without customer keys remains unreadable to Processor.

12. Audits

Upon reasonable notice, Processor will make available information necessary to demonstrate compliance with this DPA and allow audits as agreed in the order form (e.g. summary reports, questionnaires, scheduled reviews).

13. Liability

Liability under this DPA follows the limitation terms in the main agreement, except where mandatory data-protection law provides otherwise.

14. Order of precedence

If this DPA conflicts with the Terms on data-protection matters, this DPA controls.

Data Processing Agreement