Security & trust
DPA key terms
The contractual terms of the Data Processing Agreement Infralign offers every customer: breach notification, deletion, subprocessors, data location, retention, and audit rights.
This page summarises the DPA Infralign offers every customer. The executed DPA governs.
| Term | Position |
|---|---|
| EU Commission SCCs | Controller-processor clauses, Implementing Decision (EU) 2021/915 |
| EU-only processing | Microsoft Azure, EU regions, with disaster recovery in a second EU region |
| Two subprocessors | Microsoft Azure (EU regions) and Cloudflare, with 30 days’ notice before any addition |
Roles and legal basis
Section titled “Roles and legal basis”You are the controller. Your organisation:
- decides what Infralign connects to and why;
- grants the read-only roles in your own tenant, and can remove them at any time.
Infralign is the processor. Infralign Smart Solutions Limited, Ireland (CRO reg. 815072):
- processes only on your documented instructions, under GDPR Article 28;
- offers a DPA based on the European Commission’s Standard Contractual Clauses for controller-processor relationships (Implementing Decision (EU) 2021/915), so it is Article 28-compliant by construction.
Commitments
Section titled “Commitments”These are the contractual terms of the DPA.
| Commitment | The term |
|---|---|
| Breach notification | Without undue delay, and in any case within 48 hours of awareness. An initial notice within 24 hours can be agreed where your regulatory timelines require it. |
| Deletion | Within 30 days of offboarding or request, backup copies included, with written confirmation. |
| Subprocessors | Two: Microsoft Azure (EU regions) and Cloudflare, Inc. At least 30 days’ written notice before any addition, with a right to object in the DPA. |
| Data location | Customer data is processed and stored in the EU: Microsoft Azure, EU regions, with disaster recovery in a second EU region. Cloudflare provides edge delivery in front of the platform: it terminates TLS at its global edge and traffic may transit its network, it stores no customer data, and the position is covered by the standard contractual safeguards in Cloudflare’s own DPA. |
| Retention | Cost history is retained for the life of your subscription. Up to 13 months is backfilled on first connection. A shorter horizon can be agreed at any time. At the end, the Deletion row above applies: within 30 days, backups included. |
| Audit rights | Article 28(3)(h) audit and inspection rights. In practice we support audits through documentation, questionnaire responses, and audits by agreement. |
| Confidentiality | All personnel with access to customer data are bound by confidentiality agreements. |
| Security measures | TLS 1.2+ in transit. Encryption at rest with Azure storage-service encryption (Azure-managed keys). MFA on all accounts. Least-privilege access limited to named engineers. Isolated per-customer stacks. The full technical and organisational measures are annexed to the DPA. |
Subprocessors
Section titled “Subprocessors”| Name | Purpose | Location |
|---|---|---|
| Microsoft Ireland Operations Ltd | Microsoft Azure: cloud infrastructure, including Azure OpenAI Service for AI features | EU regions |
| Cloudflare, Inc. | Content delivery and edge security in front of the platform: transit and TLS termination. Stores no customer data. | Global edge network |
Requesting the full DPA
Section titled “Requesting the full DPA”Last reviewed: 31 August 2026 · v1.6 · This summary is provided for convenience; the executed DPA governs. · Security at Infralign