A reviewable DPA process for larger customers
Timastra Collect does not ask customers to accept an unseen enterprise addendum. The process below creates a documented request, review, and approval trail.
1. Open a request
In Help & legal, choose DPA request and describe the contracting entity, operating countries, expected user count, data categories, requested launch date, and security or procurement deadline. Do not upload confidential contract drafts or personal data in the initial request.
2. Scope the processing
Timastra Collect confirms controller/processor roles, processing instructions, duration, data-subject groups, categories of personal data, retention, deletion, audit evidence, subprocessors, hosting location, and any cross-border transfer mechanism that applies to the proposed deployment.
3. Security and legal review
The customer receives the current security summary, subprocessor description, incident-notification process, assistance commitments, return/deletion process, and proposed DPA. Requested amendments are tracked through the support record. Neither side should mark the review complete without authorized legal and security approval.
4. Execute before expanded processing
The authorized entities sign the final DPA or incorporate it into the order form before production use that requires it. Timastra Collect records the approved version and effective date outside the product database; the in-product request records status and non-confidential correspondence only.
5. Maintain and revisit
Material changes to subprocessors, processing purpose, location, or security commitments trigger review under the signed agreement. Customers can request updated evidence or exercise audit rights using the same support path.