1. Purpose & Scope
This Data Processing Agreement ("DPA") sets out the terms on which SleepScorePro (operated by PAPASIDDHI, the "Data Processor") processes personal data on behalf of business partners, advertisers, and sponsors (the "Data Controller") in accordance with Article 28 of the General Data Protection Regulation (GDPR) (EU) 2016/679.
This DPA applies when a business partner shares personal data with SleepScorePro for processing, including but not limited to: advertising campaign contact data, sponsorship enquiry data, affiliate referral data, or any other personal data provided by the Controller in the course of a commercial relationship with SleepScorePro.
This DPA supplements and forms part of any broader commercial agreement between the parties. In the event of conflict between this DPA and any other agreement, the provisions of this DPA shall prevail with respect to data protection matters.
2. Data Processing Details
| Nature of Processing | Email communications, campaign management, advertising delivery, performance reporting, contract management |
| Purpose of Processing | Delivering agreed advertising, sponsorship, or affiliate services as specified in the commercial agreement |
| Duration of Processing | For the term of the business agreement plus 12 months, unless earlier deletion is requested |
| Data Subjects | The Data Controller's customers, contacts, or representatives whose data is shared for processing |
| Categories of Personal Data | Name, email address, job title, company name, and any other data voluntarily provided by the Controller |
3. Processor Obligations
As Data Processor, SleepScorePro commits to the following obligations with respect to all personal data processed under this DPA:
Process data only on documented instructions from the Data Controller
Ensure confidentiality — all personnel with access are bound by confidentiality obligations
Implement appropriate technical and organisational security measures (TOMs) as described in Section 5
Not engage sub-processors without prior written consent from the Data Controller
Assist the Controller with data subject rights requests (access, erasure, portability) within 72 hours
Delete or return all personal data to the Controller upon termination of the agreement
Provide all information necessary to demonstrate GDPR compliance upon request
Notify the Controller of any personal data breach within 72 hours of becoming aware of it
4. Sub-Processors Currently Authorised
SleepScorePro uses the following sub-processors in the delivery of its services. The Data Controller provides general written authorisation for the use of these sub-processors by entering into a commercial agreement with SleepScorePro. SleepScorePro will notify the Controller of any changes to sub-processors and allow 30 days to object before a new sub-processor is engaged.
| Sub-Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Vercel Inc. | Website hosting and infrastructure | United States | Standard Contractual Clauses (SCCs) |
| Google LLC (Analytics) | Usage analytics (consent-gated only) | United States | Standard Contractual Clauses (SCCs) |
| Google LLC (AdSense) | Advertising delivery (consent-gated) | United States | Standard Contractual Clauses (SCCs) |
| Email service provider (TBD) | Newsletter delivery when applicable | TBD | SCCs / Adequacy decision |
5. Security Measures — Technical and Organisational Measures (TOMs)
Technical Measures
- HTTPS / TLS 1.3 encryption for all data in transit
- Database access controls with role-based permissions
- No plaintext passwords stored — hashed with bcrypt
- Environment variable secret management (not in source code)
- HTTP security headers: X-Frame-Options, X-Content-Type-Options, HSTS
Organisational Measures
- Data access limited to authorised personnel only
- Admin panel protected by secret key authentication
- Regular security reviews of access controls and dependencies
- Confidentiality obligations for all personnel with data access
- Documented incident response procedure
6. Data Breach Notification Procedure
In the event of a personal data breach affecting data processed under this DPA, SleepScorePro will follow the procedure set out below. All timelines comply with Article 33 GDPR.
Detection
SleepScorePro identifies or receives report of a potential personal data breach.
Assessment (within 24 hours)
Internal assessment of scope, nature of data involved, likely consequences, and mitigation measures.
Controller Notification (within 72 hours)
Data Controller notified at the contact email provided in the agreement. Notification includes nature of breach, categories of data, approximate number of records, likely consequences, and measures taken or proposed.
Regulatory Notification
Data Controller notifies the relevant Data Protection Authority (DPA) if required under Article 33 GDPR. SleepScorePro will assist with the notification where necessary.
Full Documentation (within 14 days)
Complete written breach report provided to the Controller, including root cause analysis, timeline, and remediation steps taken.
Breach Contact
Email: contact[at]sleepscorepro.com
Subject line: "DATA BREACH NOTIFICATION"
7. International Data Transfers
Where personal data processed under this DPA is transferred outside the European Economic Area (EEA), SleepScorePro ensures appropriate safeguards are in place via Standard Contractual Clauses (SCCs)as approved by the European Commission Decision 2021/914. All sub-processors listed in Section 4 operate under SCCs or an applicable adequacy decision.
Transfers to the United States rely on the EU-US Data Privacy Framework (DPF) where the recipient is certified, or on Module 2 SCCs (Controller-to-Processor) where the DPF is not applicable.
8. Data Subject Rights
SleepScorePro will assist the Data Controller in fulfilling data subject rights requests under GDPR Articles 15–22 (right of access, rectification, erasure, restriction, portability, objection). Upon receiving a data subject request relating to Controller data, SleepScorePro will:
- Acknowledge receipt within 24 hours
- Provide the Controller with all relevant data or confirmation of deletion within 72 hours
- Not respond directly to data subjects without Controller authorisation (except where required by law)
9. Requesting This DPA
Business partners requiring a signed copy of this DPA for their compliance records should contact us at contact[at]sleepscorepro.com with the subject line "DPA Request — [Your Company Name]". We aim to provide signed DPAs within 5 business days of the request.
10. Governing Law
This DPA is governed by the laws of England and Wales, without prejudice to mandatory provisions of the GDPR as applicable in the Data Controller's jurisdiction. Any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales, unless mandatory local law requires otherwise.
See also: Privacy Policy · GDPR Policy · Cookie Policy
SleepScorePro — A product of PAPASIDDHI. DPA enquiries: contact[at]sleepscorepro.com