Data Processing Agreement (DPA) — Template
Status: template. Tailor the blanks in
{{braces}}, cross-check with your legal counsel, and sign before production use. This template follows GDPR Art. 28 and is compatible with UK GDPR, Swiss FADP, and (with minor additions) Brazilian LGPD. For California CCPA/CPRA, see the Service Provider Addendum below.
1. Parties
- Controller (the customer):
{{Customer legal entity}}, registered at{{address}}, represented by{{name, title}}(“Customer”). - Processor (the vendor): Mockarty OÜ (or local legal entity — substitute as applicable), registered at
{{vendor address}}, represented by{{name, title}}(“Mockarty”).
Together referred to as the “Parties”.
2. Subject matter and duration
This DPA forms part of the Master Service Agreement (MSA) / End-User License Agreement between the Parties dated {{date}} (the “Principal Agreement”). It governs the processing of Personal Data by Mockarty on behalf of the Customer in connection with the use of the Mockarty software.
Duration: this DPA applies for as long as Mockarty processes Personal Data on behalf of the Customer. On termination of the Principal Agreement, Section 10 (Return and deletion) applies.
3. Nature and purpose of processing
| Item | Details |
|---|---|
| Nature of processing | Storage, retrieval, transmission, organisation, and structured access to Personal Data that the Customer chooses to place inside Mockarty (mock definitions, test payloads, configuration, audit logs of tool operators). |
| Purpose of processing | Enabling the Customer to design, execute, and document API mocking, functional and load testing, fuzzing, chaos and contract tests, plus AI-oriented integrations (MCP server, A2A agent protocol) — all inside the Customer’s own infrastructure. |
| Categories of data subjects | (i) Tool operators: named employees or contractors of the Customer with Mockarty accounts. (ii) Any data subjects whose Personal Data the Customer voluntarily places into mock payloads (discouraged — see Section 8). |
| Categories of Personal Data | Tool operators: name, email, hashed password, optional MFA secret, IP address, user-agent, action audit trail. Other categories only if the Customer voluntarily places them in mocks. |
| Special categories (Art. 9) | None by default. Customer must not place Art. 9 data into Mockarty without an independent legal basis and its own DPIA. |
| Processing location | Customer-controlled infrastructure (on-premise, private cloud, air-gapped). No mandatory outbound data flow to Mockarty. |
4. Customer instructions
Mockarty processes Personal Data only on documented instructions from the Customer, including as set out in the Principal Agreement and this DPA. The deployment configuration, role assignments, retention policies, and data that the Customer chooses to enter are the Customer’s instructions.
If Mockarty considers an instruction to infringe applicable data protection law, Mockarty will inform the Customer without undue delay and may suspend execution of the instruction until clarified.
5. Confidentiality
Mockarty ensures that all personnel authorised to process Personal Data are bound by written confidentiality undertakings or by a statutory duty of confidentiality, and receive training appropriate to their role.
6. Technical and organisational measures (TOMs)
Mockarty ships the following controls in the product; the Customer is responsible for enabling and operating them:
| Control category | Mockarty product features | Customer operates |
|---|---|---|
| Access control | System and namespace roles, MFA (TOTP), OIDC/SAML/LDAP | Identity provider, MFA enforcement, offboarding |
| Encryption in transit | TLS 1.2+; optional mTLS for gRPC | Certificate lifecycle |
| Encryption at rest | Optional field-level AES-256-GCM for PII columns (MOCKARTY_PII_ENCRYPTION_KEY); DBMS-level encryption delegated to the database |
Key custody; database-level encryption configuration |
| Pseudonymisation | HMAC-SHA256 blind-index for login lookup | Pepper secret rotation |
| Audit | Immutable audit log (DB triggers), legal-hold flag, RFC 5424 Syslog + ArcSight CEF export | SIEM ingestion, retention policy, alerting |
| Multi-tenancy | Namespace isolation enforced at handler/SQL/audit layers | Namespace-to-team mapping |
| Key management | Software KeyStore (default) or PKCS#11 HSM (build tag pkcs11) |
HSM hardware or KMS service |
| Resilience | Graceful shutdown with audit drain, K8s liveness/readiness probes, cluster leader election | Backup schedule, restore drills, DR plan |
| Integrity | Signed release binaries, SBOM (CycloneDX) per release, Trivy CVE scan per release | Patch cadence, release verification |
A full and current list of TOMs is maintained in the SECURITY_COMPLIANCE document, which is incorporated into this DPA by reference.
7. Sub-processors
Default deployment: Mockarty itself does not use sub-processors, because the software runs entirely inside the Customer’s infrastructure and Mockarty has no access to the processed data.
Optional vendor-hosted services (not activated by default):
- License validation endpoint (
{{license server hostname}}). Receives only: license token, binary version, node fingerprint. No Personal Data. Can be proxied or disabled (offline mode). - Anonymous telemetry (feature counters, version). Disabled by default. If opted in, no Personal Data is transmitted.
Mockarty gives the Customer at least 30 days’ prior notice of any intended addition or replacement of sub-processors that would touch Personal Data, and the Customer may object on reasonable grounds.
8. Data minimisation — tool category caveat
Mockarty is a software-development tool, not a system of record. The intended use is mocking and testing. The Customer is strongly advised to use synthetic, pseudonymised, or fabricated data in mock payloads, and should not place real production Personal Data into Mockarty absent a separate assessment and legal basis. This is documented in the Customer-facing onboarding materials.
9. Assistance to the Customer
Taking into account the nature of the processing, Mockarty assists the Customer, insofar as reasonably possible, in fulfilling the Customer’s obligations to respond to:
- Data subject requests (access, rectification, erasure, restriction, portability, objection);
- Data protection impact assessments (Art. 35) and prior consultations (Art. 36);
- Security-of-processing obligations (Art. 32);
- Personal data breach obligations (Art. 33–34).
Because Mockarty runs on Customer infrastructure and does not access Customer data, the Customer performs the relevant operations (export, deletion, restriction) using Mockarty’s built-in features. Mockarty provides technical documentation, reasonable support, and, on request, expert personnel at its then-current rates.
10. Personal data breach notification
If Mockarty becomes aware of a Personal Data breach affecting the Mockarty software (e.g., a vendor-side supply-chain incident, a critical CVE in a Mockarty component), Mockarty notifies the Customer without undue delay and, where feasible, within seventy-two (72) hours, providing the information specified in GDPR Art. 33(3) to the extent known at the time.
Because Mockarty does not host Customer data, breach events of the Customer’s Mockarty instance (misconfiguration, stolen credentials, compromised host) are detected and reported by the Customer. Mockarty’s audit features and real-time SIEM export are designed to make this feasible; the Customer operates the incident response.
11. Return and deletion
On termination of the Principal Agreement, the Customer retains full control of the Personal Data because it resides on Customer infrastructure. Mockarty has no copies to return or delete. Customer administrators can use the built-in cascade-purge and recycle-bin features to delete namespace-scoped data; audit records are preserved under the retention policy chosen by the Customer unless placed under legal hold.
12. Audits and inspections
The Customer may, no more than once per 12-month period and on 30 days’ prior written notice, conduct an audit or inspection limited to Mockarty’s obligations under this DPA. The Customer bears its own costs. Mockarty may satisfy audit requests by providing:
- The most recent SBOM (CycloneDX) and Trivy CVE scan for the deployed release;
- The
SECURITY_COMPLIANCEdocument; - Responses to a reasonable vendor-questionnaire;
- Where relevant, SOC 2 / ISO 27001 reports (when available).
Where the Customer reasonably requests an independent third-party audit, the Parties agree on scope, auditor, and confidentiality terms in advance.
13. International transfers
The default deployment is on-premise within the Customer’s chosen jurisdiction. If the Customer enables vendor-hosted features (Section 7) and these involve cross-border Personal Data transfer, the Parties enter into the EU Commission Standard Contractual Clauses (module Processor-to-Controller, 2021/914) as a separate annex, unless another transfer mechanism applies.
14. Liability, indemnity, and governing law
Liability and indemnity under this DPA are limited and allocated as set out in the Principal Agreement. Governing law and jurisdiction follow the Principal Agreement.
In the event of conflict between this DPA and the Principal Agreement, this DPA prevails for matters relating to the processing of Personal Data.
Annex A — Service Provider Addendum (California CCPA / CPRA)
For Customers subject to the California Consumer Privacy Act as amended by CPRA:
- Mockarty is a “Service Provider” as defined in Cal. Civ. Code §1798.140(ag). It processes Personal Information only for the business purposes set out in the Principal Agreement.
- Mockarty shall not (i) sell or share Personal Information, (ii) retain, use, or disclose Personal Information for any purpose other than for the business purposes specified, (iii) combine Personal Information received from the Customer with Personal Information received from another source, except as permitted by §1798.140(ag)(1)(D).
- Mockarty complies with the applicable obligations and provides the same level of privacy protection as required of the Customer under the CCPA.
- The Customer may take reasonable and appropriate steps to ensure compliance, and to stop and remediate unauthorised use of Personal Information.
Annex B — Signatures
| Party | Name | Title | Signature | Date |
|---|---|---|---|---|
| Customer | {{...}} |
{{...}} |
||
| Mockarty | {{...}} |
{{...}} |