Legal · Article 28 GDPR
Data Processing Agreement (DPA)
This Agreement governs the processing of personal data by Monolitica (processor) on behalf of its clients (controllers), within the scope of consulting and intelligent systems implementation projects, under Article 28 GDPR. It becomes an integral part of the Terms and Conditions.
Last updated: 20 July 2026
1.
Purpose and duration
Monolitica processes personal data on behalf of the client within the scope of providing consulting services and implementing intelligent systems (diagnosis and mapping, workshops, pilots, design and construction of intelligent agents, internal systems, automations, dashboards and integrations, training and knowledge transfer), according to the scope and for the duration of the main contract or project. The subject matter, nature, purposes, categories of data subjects and types of data are described in Annex I.
2.
Controller's instructions
Monolitica processes data only in accordance with the client's documented instructions, including international transfers provided for in this DPA. If a legal obligation requires processing outside the scope of the instructions, Monolitica notifies the client of this before carrying it out, unless expressly prohibited by law.
3.
Confidentiality
All persons with access to the data are subject to an appropriate duty of confidentiality, whether by contract or by legal duty.
4.
Security measures (TOMs)
Monolitica applies appropriate technical and organisational measures - encryption in transit (TLS 1.3) and at rest (AES-256) in the environments it controls, least-privilege access control with MFA, environment segregation, access restricted to the project team, periodic review of permissions, and ongoing team training in security and privacy. The systems may be implemented in cloud infrastructure managed by Monolitica, in the client's cloud, or on-premise. In the managed cloud, data is encrypted and hosted in the European Union. In the client's environments, the measures and the location of the infrastructure are also those defined by the client itself.
5.
Sub-processing
The client authorises Monolitica to engage the sub-processors listed at /sub-processadores. Any change (addition or replacement) will be notified by email to clients with active projects, with at least 30 days' prior notice. The client may object within a reasonable period; if the objection is well-founded and no equivalent alternative is possible, either party may terminate the affected contract without penalty.
6.
Support to the controller
Monolitica supports the client in fulfilling its obligations towards data subjects (Articles 12 to 22 GDPR), data protection impact assessments (Article 35) and prior consultation with the CNPD (the Portuguese data protection authority) (Article 36), upon reasonable request. Support exceeding the normal scope of the project may be subject to additional costs to be agreed.
7.
Data breaches
Monolitica notifies the client without undue delay, within a maximum of 48 hours of becoming aware of a breach, with the information reasonably available. The client retains the obligation to notify the CNPD within 72 hours (Article 33) and data subjects where applicable (Article 34).
8.
International transfers
Some operations may involve providers established outside the EEA (see /sub-processadores for the updated list and the processing country of each one). Where applicable, transfers outside the EEA rely on:
- providers' adherence to the EU-US Data Privacy Framework, where certified;
- Standard Contractual Clauses under Decision (EU) 2021/914 (SCCs), Module 3 (processor-to-processor), as a redundant safeguard; and
- a transfer impact assessment (TIA), when required by the sensitivity of the data concerned.
9.
Deletion and return
At the end of the project, Monolitica returns the data in structured format within 30 days upon request, and deletes or anonymises it within 90 days, unless otherwise required by law. A deletion certificate is issued upon request.
10.
Audit
The client has the right to verify compliance with this DPA, primarily through documentary evidence (security policies, responses to standard questionnaires). Monolitica does not currently hold formal certifications such as SOC 2 or ISO 27001. On-site audits require at least 30 days' prior notice and involve reasonable costs borne by the parties.
Annex I · Description of processing
- Categories of data subjects:the client's employees, citizens or residents whose data appears in the mapped processes (where applicable), end users of the delivered systems.
- Categories of data: identification (name, contact details), operational data from the analysed processes, content of documents and records used to build the systems, usage metadata and system records (logs).
- Purposes: process mapping, design and implementation of intelligent agents, internal systems, automations, dashboards, integrations, decision-support tools and intelligent reports.
- Duration: term of the main contract or project + retention period defined by the client.
Signature
Acceptance of the Terms and Conditions implies adherence to this DPA. Formal contracting with a qualified electronic signature is available by contacting [email protected].