Peractio Labs
Services Process Portfolio About Contact Get Started
Services Process Portfolio About Contact Get Started
Back to Trust Center

Data Processing Agreement

This Data Processing Agreement establishes the responsibilities of both parties regarding the processing, security, and protection of personal data.

Last updated: August 27, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Peractio Labs ("Processor", "we", "our", or "us") and the client ("Controller", "you", or "your") where Peractio Labs processes personal data on behalf of the Controller while providing professional services.

This DPA establishes the responsibilities of both parties regarding the processing, security, and protection of personal data.

1. Purpose

The purpose of this DPA is to ensure that personal data processed by Peractio Labs is handled in accordance with applicable data protection laws and contractual obligations.

This DPA supplements, and where applicable forms part of, the commercial agreement between the parties.

2. Definitions

For the purposes of this Agreement:

Controller means the organization that determines the purposes and means of processing personal data.

Processor means Peractio Labs acting on behalf of the Controller.

Personal Data means any information relating to an identified or identifiable natural person.

Processing includes collecting, storing, organizing, using, transmitting, securing, deleting, or otherwise handling personal data.

Applicable Data Protection Laws means all privacy and data protection laws applicable to the services, including where relevant:

  • General Data Protection Regulation (GDPR)

UK GDPR

  • Applicable national privacy legislation
  • Other applicable international privacy regulations

3. Scope of Processing

Peractio Labs may process personal data only to the extent necessary to provide the agreed services.

Processing activities may include:

  • Product engineering
  • Software development
  • Mobile application development
  • Web application development
  • Product support
  • Cloud infrastructure management
  • Quality assurance
  • AI-assisted development
  • Technical consulting
  • We process personal data solely for purposes authorized by the Controller.

4. Nature of Personal Data

Depending on the project, personal data may include:

  • Names
  • Email addresses
  • Phone numbers
  • Business contact information
  • User account information
  • Device identifiers
  • Application usage information
  • Customer support records
  • Other categories specified by the Controller
  • The categories of personal data processed depend on the specific services requested.

5. Categories of Data Subjects

Data subjects may include:

  • Employees
  • Customers
  • End users
  • Contractors
  • Suppliers

Business partners

  • Website visitors
  • Other individuals whose information is processed as part of the agreed services

6. Processor Responsibilities

Peractio Labs agrees to:

  • Process personal data only on documented instructions from the Controller.

Maintain appropriate technical and organizational security measures.

Protect the confidentiality of personal data.

Ensure personnel with access to personal data are subject to confidentiality obligations.

Assist the Controller in meeting applicable legal obligations where reasonably required.

Notify the Controller of confirmed personal data breaches affecting the processed data without undue delay, as required by applicable law or contractual obligations.

Delete or return personal data upon termination of services where required, unless retention is required by law or agreed otherwise.

7. Controller Responsibilities

The Controller agrees to:

  • Ensure that it has a lawful basis for processing personal data.

Provide accurate instructions regarding processing activities.

Obtain any required consents where applicable.

Comply with applicable privacy laws.

Ensure that personal data shared with Peractio Labs is relevant and limited to what is necessary.

The Controller remains responsible for determining the purposes and legal basis of processing.

8. Confidentiality

Peractio Labs will ensure that individuals authorized to process personal data:

Understand confidentiality obligations.

Receive appropriate guidance regarding data protection.

Access personal data only where necessary for their responsibilities.

Confidentiality obligations continue after the conclusion of the engagement.

9. Security Measures

Peractio Labs implements reasonable technical and organizational measures designed to protect personal data.

These measures may include:

  • Encryption in transit where appropriate.

Encryption at rest where supported.

Access controls.

Multi-factor authentication.

Secure cloud infrastructure.

Logging and monitoring.

Secure software development practices.

Backup and recovery procedures.

Role-based permissions.

Regular software updates.

Additional security practices are described in our Security Policy.

10. Subprocessors

Peractio Labs may engage trusted subprocessors to support the delivery of services.

Examples may include providers for:

  • Cloud hosting
  • Source code management
  • Project collaboration
  • Customer support
  • Communication
  • Analytics
  • AI services
  • Payment processing
  • Where subprocessors process personal data on our behalf, we take reasonable steps to ensure they are bound by contractual obligations that provide an appropriate level of data protection.

A current list of significant subprocessors will be made available upon reasonable request.

11. International Data Transfers

Where personal data is transferred internationally, Peractio Labs will implement appropriate safeguards as required by applicable law.

These safeguards may include:

  • Standard contractual protections
  • Technical safeguards
  • Organizational controls
  • Other lawful transfer mechanisms
  • International transfers will be limited to what is reasonably necessary to provide the agreed services.

12. AI-Assisted Processing

As an AI-native Product Engineering company, Peractio Labs may use AI-assisted tools to support software development and internal productivity.

Where AI technologies are used:

  • Human oversight is maintained.

Confidential client data is handled in accordance with contractual obligations and applicable law.

Public AI models are not intentionally trained using confidential client information without authorization.

AI-assisted outputs are reviewed before use in client deliverables.

Our broader approach is described in our Responsible AI Policy.

13. Data Subject Rights

Where required by applicable law, Peractio Labs will reasonably assist the Controller in responding to requests relating to:

Access

  • Rectification
  • Erasure
  • Restriction of processing
  • Data portability
  • Objection to processing
  • The Controller remains responsible for responding to data subject requests unless otherwise agreed.

14. Personal Data Breaches

If Peractio Labs becomes aware of a confirmed personal data breach affecting personal data processed on behalf of the Controller, we will notify the Controller without undue delay.

Where appropriate, notification may include:

Nature of the incident

  • Categories of affected data
  • Known or likely consequences
  • Measures taken to contain the incident
  • Planned remediation activities

15. Audit & Information Requests

Upon reasonable written request, and subject to appropriate confidentiality obligations, Peractio Labs may provide information reasonably necessary to demonstrate compliance with this DPA.

Where an audit is requested:

It must not unreasonably interfere with business operations.

Appropriate notice should be provided.

Confidential information relating to other clients will remain protected.

Costs associated with extensive audit requests may be allocated as agreed between the parties.

16. Data Retention & Deletion

Upon completion or termination of the services, Peractio Labs will, at the Controller's instruction and subject to legal or contractual requirements:

Return personal data,

  • Securely delete personal data, or
  • Continue retaining data only where required by applicable law.
  • Reasonable backup and archival processes may temporarily retain data until scheduled deletion cycles are completed.

17. Changes to This Agreement

Peractio Labs may update this DPA to reflect changes in:

Applicable law

  • Security practices
  • Service offerings
  • Industry standards
  • Material updates will be communicated where required by contractual obligations or applicable law.
Peractio Labs

Peractio Labs is a product engineering company helping founders, startups, and enterprises transform ideas, MVPs, and AI-generated prototypes into secure, scalable, production-ready digital products.

Services

  • Product Engineering
  • Mobile App Development
  • Web App Development
  • AI Integration

Company

  • About Us
  • Trust Center
  • Case Studies
  • Contact

Contact

  • @ support@peractiolabs.com
  • Location Remote

Copyright 2026 Peractio Labs. All rights reserved.

Trust Center Privacy Policy Terms of Service