8.2

Privacy

High risk

Data processing

Where your data lives, who can see it, and how quickly you hear about a breach.

What this clause does

The data processing terms decide where your data is stored, who can reach it, and what the vendor must do after a breach. Regulators look here first when something goes wrong.

What Rubrel flags

Rubrel checks for a signed DPA, hosting regions, the breach notification deadline and the subprocessor list. It flags any language that lets the vendor use your data to improve or train its own models.

How the redline usually lands

The standard fix sets a 48-hour breach notice, requires advance notice of new subprocessors, and removes training rights outright. Rubrel links each change to the clause of your playbook that requires it.

Playbook positions

Standard position

Signed DPA, EU or US hosting, breach notice within 48 hours, and a published list of subprocessors.

Fallback

72-hour breach notice if the vendor holds a current SOC 2 Type II report.

Walk-away point

No DPA, or any right for the vendor to train models on our data.

Create a free website with Framer, the website builder loved by startups, designers and agencies.