Data Processing Agreement

Last updated: January 2026

For Business Partners, Advertisers & Sponsors — GDPR Article 28 Compliant

Request a Signed DPA

Business partners requiring a signed DPA for their records — email us and we will respond within 5 business days.

contact@sleepscorepro.com

Subject: "DPA Request — [Your Company Name]"

1. Purpose & Scope

This Data Processing Agreement ("DPA") sets out the terms on which SleepScorePro (operated by PAPASIDDHI, the "Data Processor") processes personal data on behalf of business partners, advertisers, and sponsors (the "Data Controller") in accordance with Article 28 of the General Data Protection Regulation (GDPR) (EU) 2016/679.

This DPA applies when a business partner shares personal data with SleepScorePro for processing, including but not limited to: advertising campaign contact data, sponsorship enquiry data, affiliate referral data, or any other personal data provided by the Controller in the course of a commercial relationship with SleepScorePro.

This DPA supplements and forms part of any broader commercial agreement between the parties. In the event of conflict between this DPA and any other agreement, the provisions of this DPA shall prevail with respect to data protection matters.

2. Data Processing Details

Nature of ProcessingEmail communications, campaign management, advertising delivery, performance reporting, contract management
Purpose of ProcessingDelivering agreed advertising, sponsorship, or affiliate services as specified in the commercial agreement
Duration of ProcessingFor the term of the business agreement plus 12 months, unless earlier deletion is requested
Data SubjectsThe Data Controller's customers, contacts, or representatives whose data is shared for processing
Categories of Personal DataName, email address, job title, company name, and any other data voluntarily provided by the Controller

3. Processor Obligations

As Data Processor, SleepScorePro commits to the following obligations with respect to all personal data processed under this DPA:

Process data only on documented instructions from the Data Controller

Ensure confidentiality — all personnel with access are bound by confidentiality obligations

Implement appropriate technical and organisational security measures (TOMs) as described in Section 5

Not engage sub-processors without prior written consent from the Data Controller

Assist the Controller with data subject rights requests (access, erasure, portability) within 72 hours

Delete or return all personal data to the Controller upon termination of the agreement

Provide all information necessary to demonstrate GDPR compliance upon request

Notify the Controller of any personal data breach within 72 hours of becoming aware of it

4. Sub-Processors Currently Authorised

SleepScorePro uses the following sub-processors in the delivery of its services. The Data Controller provides general written authorisation for the use of these sub-processors by entering into a commercial agreement with SleepScorePro. SleepScorePro will notify the Controller of any changes to sub-processors and allow 30 days to object before a new sub-processor is engaged.

Sub-ProcessorPurposeLocationSafeguard
Vercel Inc.Website hosting and infrastructureUnited StatesStandard Contractual Clauses (SCCs)
Google LLC (Analytics)Usage analytics (consent-gated only)United StatesStandard Contractual Clauses (SCCs)
Google LLC (AdSense)Advertising delivery (consent-gated)United StatesStandard Contractual Clauses (SCCs)
Email service provider (TBD)Newsletter delivery when applicableTBDSCCs / Adequacy decision

5. Security Measures — Technical and Organisational Measures (TOMs)

Technical Measures

  • HTTPS / TLS 1.3 encryption for all data in transit
  • Database access controls with role-based permissions
  • No plaintext passwords stored — hashed with bcrypt
  • Environment variable secret management (not in source code)
  • HTTP security headers: X-Frame-Options, X-Content-Type-Options, HSTS

Organisational Measures

  • Data access limited to authorised personnel only
  • Admin panel protected by secret key authentication
  • Regular security reviews of access controls and dependencies
  • Confidentiality obligations for all personnel with data access
  • Documented incident response procedure

6. Data Breach Notification Procedure

In the event of a personal data breach affecting data processed under this DPA, SleepScorePro will follow the procedure set out below. All timelines comply with Article 33 GDPR.

01

Detection

SleepScorePro identifies or receives report of a potential personal data breach.

02

Assessment (within 24 hours)

Internal assessment of scope, nature of data involved, likely consequences, and mitigation measures.

03

Controller Notification (within 72 hours)

Data Controller notified at the contact email provided in the agreement. Notification includes nature of breach, categories of data, approximate number of records, likely consequences, and measures taken or proposed.

04

Regulatory Notification

Data Controller notifies the relevant Data Protection Authority (DPA) if required under Article 33 GDPR. SleepScorePro will assist with the notification where necessary.

05

Full Documentation (within 14 days)

Complete written breach report provided to the Controller, including root cause analysis, timeline, and remediation steps taken.

Breach Contact

Email: contact[at]sleepscorepro.com
Subject line: "DATA BREACH NOTIFICATION"

7. International Data Transfers

Where personal data processed under this DPA is transferred outside the European Economic Area (EEA), SleepScorePro ensures appropriate safeguards are in place via Standard Contractual Clauses (SCCs)as approved by the European Commission Decision 2021/914. All sub-processors listed in Section 4 operate under SCCs or an applicable adequacy decision.

Transfers to the United States rely on the EU-US Data Privacy Framework (DPF) where the recipient is certified, or on Module 2 SCCs (Controller-to-Processor) where the DPF is not applicable.

8. Data Subject Rights

SleepScorePro will assist the Data Controller in fulfilling data subject rights requests under GDPR Articles 15–22 (right of access, rectification, erasure, restriction, portability, objection). Upon receiving a data subject request relating to Controller data, SleepScorePro will:

  • Acknowledge receipt within 24 hours
  • Provide the Controller with all relevant data or confirmation of deletion within 72 hours
  • Not respond directly to data subjects without Controller authorisation (except where required by law)

9. Requesting This DPA

Business partners requiring a signed copy of this DPA for their compliance records should contact us at contact[at]sleepscorepro.com with the subject line "DPA Request — [Your Company Name]". We aim to provide signed DPAs within 5 business days of the request.

10. Governing Law

This DPA is governed by the laws of England and Wales, without prejudice to mandatory provisions of the GDPR as applicable in the Data Controller's jurisdiction. Any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales, unless mandatory local law requires otherwise.

See also: Privacy Policy · GDPR Policy · Cookie Policy


SleepScorePro — A product of PAPASIDDHI. DPA enquiries: contact[at]sleepscorepro.com