Last updated: March 21, 2026
Get our standard Data Processing Agreement for your compliance needs.
A Data Processing Agreement (DPA) is a legally binding contract between a data controller (your organization) and a data processor (Infmap) that governs how personal data is handled when using our services.
Under GDPR and other data protection regulations, a DPA is required when you engage a third-party service provider to process personal data on your behalf.
We process data only as instructed by you and for the purpose of providing Infmap services.
TLS 1.3 encryption in transit, role-based access controls, and secure infrastructure.
We maintain a list of approved subprocessors, available in our Privacy Policy.
We commit to notifying you within 72 hours of any data breach.
We assist you in responding to data subject access requests and other GDPR rights.
Our processors (Stripe, Google) include Standard Contractual Clauses (SCCs) in their data processing agreements.
Enterprise customers may require customized terms or additional provisions. Contact our support team to discuss your specific requirements.
For DPA inquiries:
This DPA is effective as of March 21, 2026 and is designed to meet GDPR requirements.