Data Processing Agreement Mediusware

This Data Processing Agreement explains how Mediusware may process personal data on behalf of clients when delivering software development, design, AI, automation, consulting, and related digital services.

Last updated: July 13, 2026

01.

Agreement Overview

This Data Processing Agreement describes the responsibilities, safeguards, and cooperation expectations that may apply when Mediusware processes personal data for a client as part of a project, service engagement, support activity, or digital product delivery.

Document type

Data Processing Agreement (DPA)

Applicability

Mediusware software engineering, design, AI, automation, and support engagements

Procurement use

Legal review, vendor assessment, security due diligence, and client onboarding

02.

How We Support Responsible Data Processing

Before the detailed agreement terms, this summary explains how Mediusware supports privacy-aware delivery, data handling clarity, security safeguards, and client assistance across project work.

Documented Processing Scope
Role Clarity
Security Measures
Subprocessor Awareness
Retention & Deletion Support
Client Assistance
03.

Data Processing Responsibilities At A Glance

This matrix gives procurement, legal, and project stakeholders a quick view of how Mediusware can support common DPA responsibilities.

Processing Scope
Client Instructions
Security Measures
Subprocessors
Data Requests
Retention / Deletion
04.

Roles And Scope

Depending on the project, the client may act as the data controller or business, and Mediusware may act as the processor or service provider for personal data processed under the client's instructions.

The client determines the purpose and lawful basis for processing personal data.
Mediusware processes project-related personal data only for agreed service purposes.
Specific project scope, systems, regions, and security obligations should be defined in the applicable agreement, proposal, or statement of work.
05.

Processing Instructions

Mediusware processes personal data based on documented client instructions, including instructions provided through project requirements, support requests, contracts, technical documentation, and approved communication channels.

Documented Scope
Purpose Limitation
06.

Personal Data And Data Subjects

The personal data processed may vary by project and client system. Data may include information submitted through websites, applications, dashboards, forms, customer portals, integrations, analytics tools, or support workflows.

Contact information such as name, email, phone number, company, and role.
User account information, authentication identifiers, and access-related data.
Customer, employee, vendor, applicant, or end-user records where included in the project scope.
Technical data such as IP address, device data, logs, usage information, and error reports.
07.

Purpose Of Processing

Mediusware may process personal data to deliver contracted services and support client systems. Processing activities may include analysis, design, development, testing, quality assurance, deployment, migration, integrations, support, monitoring, and maintenance.

Build And Improve Systems
Provide Project Support
Enable Delivery Operations
08.

Security Measures

Mediusware applies reasonable technical, administrative, and organizational safeguards designed to protect project-related personal data against unauthorized access, misuse, loss, disclosure, alteration, or destruction.

Access Control
Secure Development
Confidentiality
Monitoring And Support
09.

Subprocessors

Mediusware may use trusted third-party tools or service providers to support hosting, communication, project management, analytics, repository management, deployment, monitoring, or customer support.

Subprocessors are used only where reasonably necessary for service delivery.
Relevant subprocessors may operate under their own privacy, security, and compliance obligations.
Client-specific subprocessors, hosting environments, or tool restrictions should be documented in the applicable project agreement.
10.

International Transfers

Depending on the client, project, team location, hosting provider, or third-party tools used, personal data may be accessed or processed across different countries. Mediusware aims to apply reasonable safeguards where cross-border processing occurs.

Where required, transfer safeguards may be addressed through contractual terms, approved hosting choices, client instructions, or applicable data protection mechanisms.

11.

Data Subject Requests

If Mediusware receives a request from an individual relating to personal data controlled by a client, Mediusware may refer the request to the client or assist the client where reasonably required and within the scope of the service agreement.

Access or correction requests.
Deletion or restriction requests.
Objection or portability requests.
Privacy-related questions from users, customers, or project stakeholders.
12.

Security Incidents

If Mediusware identifies a security incident involving personal data processed on behalf of a client, Mediusware will take reasonable steps to investigate, contain, and communicate relevant information to the client as appropriate.

Review the reported issue, affected system, logs, access, and project context.
Assess the likely scope, severity, data categories, affected systems, and required next steps.
Take reasonable technical or operational steps to reduce potential impact.
Communicate with relevant client contacts when the issue requires project, legal, or operational attention.
Support remediation, documentation, and reasonable improvements to reduce future risk.
13.

Retention And Deletion

Personal data processed for a client is retained only as reasonably necessary for project delivery, legal obligations, support requirements, backup cycles, documentation, or as instructed by the client.

Upon project completion or termination, Mediusware may return, delete, anonymize, or securely retain data according to the contract, project requirements, technical feasibility, and applicable obligations.

14.

Audit And Assistance

Mediusware may provide reasonable assistance to clients for data protection questions, project security reviews, compliance documentation, and processor-related obligations where the request is relevant to the agreed services.

This page is a general template-style DPA overview for website and service communication. Final legal terms should be reviewed and confirmed through the applicable client contract or separately executed DPA.

Project-level security and access review support.
Documentation support for client compliance needs.
Reasonable cooperation for privacy or security assessments.
Clarification of subprocessors, hosting tools, or delivery workflows.
15.

Procurement Resources

Enterprise buyers, procurement teams, and legal reviewers may need additional context before approving a software development engagement. These resources help connect the DPA with Mediusware's broader trust and delivery documentation.

Security Practices
Privacy Policy
Compliance Overview
Vendor Security Questionnaire
Security Documentation
Enterprise Services
16.

Data Processing Agreement FAQ

Quick answers for procurement, legal, compliance, and enterprise buyers reviewing Mediusware's data processing approach.

What is a Data Processing Agreement?

A DPA explains how a service provider may process personal data on behalf of a client, including scope, instructions, safeguards, subprocessors, retention, deletion, and assistance obligations.

When is a DPA required?

A DPA may be required when Mediusware processes personal data for a client as part of software development, support, migration, integration, QA, hosting coordination, or system maintenance.

Does Mediusware sign client DPAs?

Project-specific DPA terms can be reviewed during contracting. Final obligations depend on the client agreement, applicable laws, project scope, data categories, subprocessors, and delivery requirements.

How does Mediusware protect customer data?

Mediusware supports reasonable safeguards such as role-based access, secure development practices, authentication planning, code reviews, monitoring, incident response, and controlled project communication.

How are international data transfers handled?

Where cross-border processing is relevant, transfer expectations may be addressed through contract terms, client-approved tools, hosting choices, security controls, and applicable data protection mechanisms.

Can procurement request security documentation?

Yes. Enterprise clients can request security clarification, subprocessor details, vendor questionnaire responses, or project-specific documentation before starting an engagement.

17.

Version History

This page may be updated as Mediusware improves trust documentation, project delivery practices, compliance readiness, or service terms.

Version 1.2

Updated enterprise trust sections, procurement resources, FAQ, and data processing responsibility summaries.

Effective date

July 2026

Review cadence

Reviewed periodically to reflect website, service, compliance, and documentation changes.

18.

Contact Mediusware

If you have questions about this Data Processing Agreement, privacy, security, subprocessors, or project-level data handling, please contact us.