Data Processing Agreement

Effective date: 1 January 2025

This Data Processing Agreement ("DPA") forms part of the Terms of Service between B Code (Pvt) Ltd ("Processor", "we") and the subscribing organization ("Controller", "you").

Scope: This DPA applies wherever we process personal data on your behalf in connection with the STAG service, in accordance with the Sri Lanka Personal Data Protection Act No. 9 of 2022 (PDPA).

1. Definitions

"Personal Data" means any information that identifies or could identify a natural person, as defined by the Sri Lanka PDPA.

"Controller" means the subscribing organization that determines the purposes and means of processing Personal Data.

"Processor" means B Code (Pvt) Ltd, which processes Personal Data on behalf of the Controller.

"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.

"Sub-processor" means a third party engaged by the Processor to assist in processing Personal Data.

2. Scope of Processing

2.1 The Processor shall process Personal Data only:

  • On documented instructions from the Controller (including as set out in this DPA and the Terms of Service)
  • As required by applicable Sri Lankan or international law

2.2 Categories of data processed: Employee records, payroll data, contact information, usage logs, and any other data uploaded by the Controller.

2.3 Purposes of processing: Providing, maintaining, and supporting the STAG service as described in the Terms of Service.

2.4 Duration: For the term of the subscription agreement plus any retention period specified herein or required by law.

3. Processor Obligations

The Processor agrees to:

  • Process Personal Data only on the Controller's documented instructions
  • Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures (see Section 5)
  • Assist the Controller in responding to data subject rights requests
  • Assist the Controller in ensuring compliance with applicable PDPA obligations
  • Delete or return all Personal Data to the Controller upon termination of the agreement, as per Section 6
  • Make available all information necessary to demonstrate compliance with this DPA
  • Notify the Controller without undue delay upon becoming aware of a Personal Data breach

4. Sub-processors

4.1 The Controller grants the Processor general authorization to engage sub-processors. The current list of sub-processors includes:

  • Supabase Inc. — Cloud database and authentication (USA, with data stored per region configuration)
  • Cloudflare Inc. — CDN, DDoS protection, and SSL termination
  • Amazon Web Services — Cloud infrastructure (where applicable)

4.2 The Processor will notify the Controller of any intended changes to sub-processors with at least 14 days' advance notice, giving the Controller the opportunity to object.

4.3 The Processor ensures that sub-processors are bound by data protection obligations equivalent to those in this DPA.

5. Security Measures

The Processor implements the following technical and organizational measures:

  • Encryption: Data encrypted at rest (AES-256) and in transit (TLS 1.2+)
  • Access Control: Role-based access controls, principle of least privilege, multi-factor authentication for administrative access
  • Audit Logging: All data access and changes are logged with timestamps and user identity
  • Network Security: Firewall protection, DDoS mitigation, intrusion detection
  • Backup: Regular automated backups with encryption
  • Incident Response: Documented incident response procedures; breaches reported within 72 hours
  • Personnel: Staff training on data protection; confidentiality agreements

6. Data Retention and Deletion

Upon termination or expiry of the subscription:

  • The Processor will retain Customer Data for 30 days post-termination to allow the Controller to export data
  • After 30 days, Customer Data will be permanently deleted from production systems
  • Backup copies may persist for up to 90 days in encrypted archives before being deleted
  • Financial and billing records will be retained for 7 years as required by Sri Lankan accounting law; this data will not include Customer's operational data

The Controller may request a data export before or within 30 days of termination by contacting legal@stag.bcode.lk.

7. Data Subject Rights

The Processor will assist the Controller in fulfilling data subject rights requests (access, rectification, erasure, portability, objection) within 72 hours of receiving a forwarded request. The Processor will not respond directly to data subjects without Controller authorization, except where required by law.

8. Data Breach Notification

In the event of a Personal Data breach, the Processor will:

  • Notify the Controller without undue delay and no later than 72 hours after becoming aware
  • Provide information including the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed
  • Cooperate with the Controller in managing the breach response and any notifications required under the PDPA

9. International Transfers

Some sub-processors (e.g., Supabase, Cloudflare) may process data in jurisdictions outside Sri Lanka. The Processor ensures that such transfers are protected by appropriate safeguards, including standard contractual clauses or equivalent protections, consistent with PDPA requirements.

10. Audit Rights

The Controller may, with 30 days' written notice, audit the Processor's data processing activities, or appoint an independent auditor to do so. Such audits will be conducted at the Controller's expense, no more than once per year, and in a manner that does not unreasonably disrupt the Processor's operations. The Processor may provide a recent third-party security audit report in lieu of a full audit.

11. Liability

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. Nothing in this DPA limits liability for breach of the PDPA where such limitation is prohibited by law.

12. Governing Law

This DPA is governed by the laws of Sri Lanka. Disputes shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.

13. Contact

Data protection inquiries: legal@stag.bcode.lk

B Code (Pvt) Ltd, Colombo, Sri Lanka.