Data Processing Agreement
This Data Processing Agreement ("DPA") supplements the agreement between Torienta, operated by Ayoub Khayati, a private individual based in Denmark, contactable at info@torienta.com for all general and data-subject matters (full registered postal address available on request; a registered office address will be provided on conversion to a Danish legal entity per §1.1, to which formal legal notices may then be addressed) ("Torienta," "we," or the "Processor" for the scope defined below) and the Customer identified in the executed services agreement (the "Customer" or the "Controller" for the scope defined below). It governs the processing of Personal Data carried out by Torienta on behalf of the Customer in connection with the Torienta Org Health Scanner service.
1. Scope of this DPA
Torienta processes data on the Customer's Salesforce org via OAuth-authorized API access. Within that processing, two distinct legal postures apply per ADR-011 D2:
- Processor scope (covered by this DPA, GDPR Art. 28). When Torienta executes record-derived capabilities (
salesforce.format_validation,salesforce.dedup_hash,salesforce.system_dates— the "Optional Capabilities") at the Customer's instruction. The Customer determines purpose; Torienta executes. This DPA describes the obligations Torienta accepts as Processor. - Successive independent controller scope (NOT covered by this DPA, see Privacy Notice). When Torienta independently derives insights from schema metadata (object/field metadata, aggregate counts, derived org-health benchmarks). Torienta acts as an independent controller of those derivations. The Customer's privacy notice and Torienta's published privacy notice each describe the respective controller relationship. No joint-controller arrangement is claimed.
This DPA only governs scope (1). Scope (2) is governed by Torienta's published privacy notice and applicable controller obligations.
1.1 Controller / Processor succession
The Processor (Torienta) may be succeeded, without renewed Customer consent and without amendment to this DPA, by any Danish-registered legal entity wholly owned and controlled by Ayoub Khayati that succeeds to the Torienta service. Permitted successor forms include Personligt Ejet Mindre Virksomhed (PMV), Enkeltmandsvirksomhed (EM), Anpartsselskab (ApS), or any future legal form serving the same controlling natural person. Customer will be notified of any such transition via in-app banner + email at least 14 days before it takes effect. Sub-Processor list, processing purposes, technical/organisational measures, retention periods, and all obligations of this DPA remain unchanged through the transition; only the Processor's legal form changes.
2. Subject Matter and Duration
Processing: Torienta executes Optional Capabilities on Customer's Salesforce records on the Customer's behalf, returning derived results (e.g., field-format validation flags, deduplication hashes, system-date summaries) to the Customer's Torienta dashboard.
Duration: from execution of the services agreement until termination of services or 24 hours after the Customer disconnects the Salesforce integration via the Torienta UI (whichever is earlier). Per ADR-012 D6, hard-deletion completes within 24 hours of disconnect.
3. Nature and Purpose of Processing
Nature: read access to records in the Customer's Salesforce org limited to the Optional Capabilities the Customer has explicitly granted via Torienta's consent UI per CONSENT-002 / GDPR Art. 6(1)(a) consent.
Purpose: to compute and return derived results to the Customer to support the Customer's data-quality, deduplication, and operational visibility decisions. Torienta does not use Personal Data processed under this DPA to train, fine-tune, or develop any machine-learning or large-language model.
4. Categories of Data Subjects
Data subjects whose Personal Data may be present in the Customer's Salesforce records and accessed pursuant to the Optional Capabilities. The exact categories depend on the Customer's Salesforce schema and which capabilities the Customer has consented to.
Change-actor (SetupAuditTrail) — controller scope, out of this DPA. Named administrators recorded in the Customer Org's own SetupAuditTrail, surfaced for change accountability (the /changes feed "who changed it"), are processed under Torienta's independent-controller scope (ROPA Activity 8 / LEGAL-026), like schema metadata (§1 scope) — not as a processor under this DPA. The Customer remains the primary controller of its own SetupAuditTrail and retains the Art. 13/14 notice duty to its admins. See the Privacy Notice ("Who made each change") + ROPA Activity 8.
5. Categories of Personal Data
Categories depend on the consented capabilities and the Customer's schema. Torienta does NOT read or store record values for the non-optional capabilities (salesforce.metadata_read, salesforce.aggregate_count); those operate under Torienta's controller scope (out of DPA).
For Optional Capabilities, Torienta processes hashes, format-validation flags, and aggregate counts derived from record values. Raw record values are NOT persisted; they are processed in-memory and discarded.
6. Torienta's Obligations as Processor
Torienta will:
- Process Personal Data only on documented instructions from the Customer (the consent grants in Torienta's UI constitute such instructions).
- Ensure persons authorized to process Personal Data have committed to confidentiality.
- Implement technical and organizational measures appropriate to the risk (Art. 32). Measures include: AES-256-GCM encryption of OAuth tokens at rest with AAD binding (per ADR-009 D3 + SFAUTH-008); 24h hard-delete SLA on disconnect (per ADR-012 D6); audit logging of grant/revoke events (per CONSENT-005); ServiceAccount RoleBinding scoping for the encryption key (per ADR-009 amendment).
- Engage Sub-Processors only with the Customer's prior consent (general written authorization granted per Section 7 below; specific notice provided for additions or replacements).
- Assist the Customer in fulfilling data-subject-rights requests (Arts. 12-23).
- Notify the Customer without undue delay after becoming aware of a Personal Data breach (within 24 hours, target).
- At the Customer's choice, delete or return all Personal Data after the end of the provision of services (default: deletion per ADR-012 D6).
- Make available all information necessary to demonstrate compliance with Art. 28 obligations and contribute to audits.
7. Sub-Processors
Initial list of Sub-Processors:
| Sub-Processor | Purpose | Location |
|---|---|---|
| OVHcloud (OVH Public Cloud, GRA9 region) | Hosting (Postgres, K3s, Redis) | EU (France) |
Salesforce, Inc. is not a Sub-Processor. Salesforce is the source platform of the Customer's integration: the Customer is the data controller of records in its own Salesforce organisation, and Torienta receives data from Salesforce on the Customer's authorisation. The Customer's separate agreement with Salesforce, Inc. governs Salesforce's own processing.
Notification of additions or replacements: 30 days advance notice via email + in-app banner. Customer may object within 14 days; if objection cannot be resolved, Customer may terminate the affected services.
8. International Transfers
At MVP all Torienta processing occurs in the EU (OVH GRA9). If a Customer connects a Salesforce org hosted in a non-EU region (US, AU, etc.), data flows from Salesforce US → Torienta EU, with Salesforce, Inc. acting under its own DPA + Standard Contractual Clauses (SCCs) for any onward transfer back to the Customer's region. Torienta does NOT replicate Customer data outside the EU at MVP.
If, in the future, a Customer requires non-EU hosting of derived data, Torienta and the Customer will execute an SCC addendum + Transfer Impact Assessment per EDPB Recommendation 01/2020 before such replication.
9. Data Subject Rights
Torienta will assist the Customer in responding to data-subject requests:
- Access (Art. 15) — Torienta provides the Customer with an export of derived data on request.
- Erasure (Art. 17) — the Customer may disconnect the Salesforce integration via the Torienta UI at any time; all Personal Data processed under this DPA is hard-deleted within 24 hours of disconnect (see §2). Erasure requests may also be sent to
info@torienta.com; response within 30 days. - Rectification, restriction, portability, objection — handled per request, response within 30 days.
The Customer remains responsible for fulfilling data-subject requests on the original Salesforce records; Torienta does not directly serve data subjects whose Personal Data is in the Customer's org.
10. Liability and Indemnification
Limits of liability per the executed services agreement.
11. Termination
This DPA terminates with the executed services agreement. Torienta deletes Personal Data within 24 hours of termination notice per ADR-012 D6.
12. Governing Law
Governed by the laws of Denmark, excluding conflict-of-laws principles. Disputes subject to the exclusive jurisdiction of the Danish courts, except where a mandatory consumer-protection rule of the Customer's country of residence overrides this election.
13. Conflicts
If this DPA conflicts with the executed services agreement, this DPA prevails for matters of Personal Data processing under Art. 28.
End of DPA.
Self-drafted by founder from public templates; subject to professional legal review. This document is not legal advice. Draft date: 2026-05-07; published 2026-07-30. Questions: info@torienta.com.