Data Processing Agreement

Enterprise procurement document — forward to Legal / DPO

Document
DPA-001
Version
1.0.0
Updated
9 Feb 2026
Audience
Legal / DPO
Full DPA
Full document
Contact
privacy@feedoracle.io
This is a summary. The full DPA is at /assets/dpa-feedoracle.html. Enterprise customers receive a countersigned copy on request.

Processing Scope

AspectDetails
ControllerThe customer (API consumer)
ProcessorFeedOracle (data infrastructure provider)
PurposeProvision of RWA risk intelligence, regulatory evidence signals, and cryptographic attestation via API
Personal dataMinimal: email (account), API keys, access logs (IP + timestamp + endpoint)
Special categories (Art. 9)None
Data subjectsCustomer employees/agents who access the API

Key DPA Provisions

ProvisionSummary
Legal basisArt. 28 GDPR (processor agreement)
Sub-processorsnetcup GmbH (hosting, DE), Cloudflare Inc. (CDN, EU primary). 30-day objection window for changes.
International transfersPrimary processing in Germany. Cloudflare edge may transit non-EU (covered by SCCs). On-chain hashes contain no PII.
Technical measuresTLS 1.2+, ECDSA signing, encrypted backups, SSH key-only, fail2ban, restrictive firewall.
Data subject rightsFeedOracle assists customer in responding to DSARs. Contact: privacy@feedoracle.io
Breach notification≤ 72 hours to customer per GDPR Art. 33
Data deletionAPI credentials deleted within 30 days of termination. Logs per 90-day rolling policy.
Audit rightsDocumentation-based audit support. On-site audits negotiable for Enterprise tier.

What FeedOracle Does NOT Process

Applicable Law

AspectDetails
Governing lawGerman law
Data protectionGDPR (Regulation (EU) 2016/679)
Supervisory authorityLDI NRW (North Rhine-Westphalia)
JurisdictionCourts of Germany

How to Execute

Enterprise customers can request a countersigned DPA by emailing enterprise@feedoracle.io. Included in Enterprise tier onboarding at no additional cost.