Skip to content

Security & trust

DPA key terms

The contractual terms of the Data Processing Agreement Infralign offers every customer: breach notification, deletion, subprocessors, data location, retention, and audit rights.

This page summarises the DPA Infralign offers every customer. The executed DPA governs.

TermPosition
EU Commission SCCsController-processor clauses, Implementing Decision (EU) 2021/915
EU-only processingMicrosoft Azure, EU regions, with disaster recovery in a second EU region
Two subprocessorsMicrosoft Azure (EU regions) and Cloudflare, with 30 days’ notice before any addition

You are the controller. Your organisation:

  • decides what Infralign connects to and why;
  • grants the read-only roles in your own tenant, and can remove them at any time.

Infralign is the processor. Infralign Smart Solutions Limited, Ireland (CRO reg. 815072):

  • processes only on your documented instructions, under GDPR Article 28;
  • offers a DPA based on the European Commission’s Standard Contractual Clauses for controller-processor relationships (Implementing Decision (EU) 2021/915), so it is Article 28-compliant by construction.

These are the contractual terms of the DPA.

CommitmentThe term
Breach notificationWithout undue delay, and in any case within 48 hours of awareness. An initial notice within 24 hours can be agreed where your regulatory timelines require it.
DeletionWithin 30 days of offboarding or request, backup copies included, with written confirmation.
SubprocessorsTwo: Microsoft Azure (EU regions) and Cloudflare, Inc. At least 30 days’ written notice before any addition, with a right to object in the DPA.
Data locationCustomer data is processed and stored in the EU: Microsoft Azure, EU regions, with disaster recovery in a second EU region. Cloudflare provides edge delivery in front of the platform: it terminates TLS at its global edge and traffic may transit its network, it stores no customer data, and the position is covered by the standard contractual safeguards in Cloudflare’s own DPA.
RetentionCost history is retained for the life of your subscription. Up to 13 months is backfilled on first connection. A shorter horizon can be agreed at any time. At the end, the Deletion row above applies: within 30 days, backups included.
Audit rightsArticle 28(3)(h) audit and inspection rights. In practice we support audits through documentation, questionnaire responses, and audits by agreement.
ConfidentialityAll personnel with access to customer data are bound by confidentiality agreements.
Security measuresTLS 1.2+ in transit. Encryption at rest with Azure storage-service encryption (Azure-managed keys). MFA on all accounts. Least-privilege access limited to named engineers. Isolated per-customer stacks. The full technical and organisational measures are annexed to the DPA.
NamePurposeLocation
Microsoft Ireland Operations LtdMicrosoft Azure: cloud infrastructure, including Azure OpenAI Service for AI featuresEU regions
Cloudflare, Inc.Content delivery and edge security in front of the platform: transit and TLS termination. Stores no customer data.Global edge network

Last reviewed: 31 August 2026 · v1.6 · This summary is provided for convenience; the executed DPA governs. · Security at Infralign