Skip to content

Data Processing Agreement

Last updated: August 19, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Bestis, Inc. (a Delaware corporation, “Bestis,” “Processor”) and the customer or partner that accepts it (“Customer,” “Controller”) and governs the Processing of Personal Data by Bestis on the Controller’s behalf. Where a conflict arises, this DPA controls over the underlying agreement with respect to data protection. Capitalized terms not defined here have the meaning given in applicable data protection law.

1. Definitions

“Data Protection Laws” means all laws applicable to the Processing of Personal Data, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act/California Privacy Rights Act (CCPA/CPRA). “Personal Data,” “Controller,” “Processor,” “Processing,” “Data Subject,” and “Sub-processor” have the meanings given in those laws.

2. Roles & scope

The Controller determines the purposes and means of Processing; Bestis acts as Processor and Processes Personal Data only on the Controller’s documented instructions, including as set out in the agreement and this DPA, except where required by law. If Bestis is required by law to Process otherwise, it will inform the Controller unless prohibited.

3. Details of Processing

  • Subject matter: provision of the Bestis Service.
  • Duration: the term of the agreement, plus any period required for return or deletion.
  • Nature & purpose: hosting, storage, transmission, and processing necessary to provide the Service.
  • Categories of Data Subjects: the Controller’s authorized users and end users.
  • Types of Personal Data: identifiers and contact details, account and profile data, content, transaction data, and usage data.

4. Confidentiality

Bestis ensures that personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations and receive suitable training.

5. Security

Bestis implements and maintains appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful Processing and accidental loss, destruction, or damage, taking into account the state of the art and the risks involved. These include encryption in transit, access controls, network protections, and secure development and operational practices.

6. Sub-processors

The Controller authorizes Bestis to engage Sub-processors (such as cloud hosting, payment processing, email delivery, and analytics providers) to support the Service. Bestis imposes data protection obligations on Sub-processors that are no less protective than those in this DPA and remains responsible for their performance. We will inform the Controller of intended changes to Sub-processors and provide an opportunity to object on reasonable data protection grounds.

7. Data Subject requests

Taking into account the nature of the Processing, Bestis will provide reasonable assistance to the Controller in responding to Data Subject requests to exercise their rights, and will promptly forward any such request it receives directly.

8. Personal Data breach

Bestis will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller’s Personal Data, and will provide information reasonably available to assist the Controller in meeting its notification obligations.

9. Assistance

Bestis will provide reasonable assistance to the Controller with data protection impact assessments and prior consultations with supervisory authorities, where required, taking into account the nature of the Processing and the information available to Bestis.

10. International transfers

Where Processing involves transfers of Personal Data outside the EEA, UK, or other restricted regions, Bestis relies on lawful transfer mechanisms, such as the applicable Standard Contractual Clauses, which are incorporated by reference where required.

11. Audits

Bestis will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller, subject to reasonable notice, confidentiality, and scope limitations.

12. Return & deletion

On termination or expiry of the agreement, Bestis will, at the Controller’s choice, delete or return the Personal Data and delete existing copies, unless retention is required by law.

13. Contact

To request execution of this DPA or ask questions, contact [email protected].