Parties and roles
Confirm the customer and service operator, their controller and processor roles, and the agreement governing the service. Roles can differ between account administration and visitor data processed for a customer.
Processing scope
Document the purpose, duration, categories of individuals and information processed. Product data can include account records, website conversations, submitted contact details, published knowledge and usage information.
Instructions and safeguards
Define authorized instructions, confidentiality duties, access controls and security measures applicable to the deployed environment. Application controls should be supported by operational evidence.
Providers and international transfers
Attach an approved provider list with locations, processing purposes, change-notification rules and any required transfer mechanisms. Do not assume an enabled software dependency is automatically a contracted subprocessor.
Requests, incidents and end of service
Agree on assistance for individual requests, incident communication, audit handling and data return or deletion. Notification deadlines and retention commitments require legal and operational approval.