Last updated: 1 July 2025 · BlockLabs Group Ltd, Nicosia, Cyprus
This Data Processing Agreement ("DPA") sets out the terms under which BlockLabs Group Ltd ("Processor") processes personal data on behalf of its clients ("Controller") in the course of providing software development and related services. This DPA is incorporated into and forms part of any master services agreement between the parties.
"Personal Data", "Processing", "Data Subject", "Controller", "Processor", and "Supervisory Authority" have the meanings given in the GDPR (EU) 2016/679.
The Processor shall process personal data only on documented instructions from the Controller, unless required to do so by EU or member state law. The Processor shall inform the Controller if, in its opinion, any instruction infringes applicable data protection law.
The Processor shall ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption of personal data in transit and at rest, access controls, and regular security assessments.
The Processor shall not engage another processor without prior specific or general written authorisation of the Controller. Where general authorisation is given, the Processor shall inform the Controller of intended changes and give the Controller the opportunity to object.
Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures in fulfilling the Controller's obligation to respond to requests for exercising Data Subjects' rights.
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach. Such notification shall include all information reasonably available to the Processor to allow the Controller to meet its notification obligations.
The Processor shall not transfer personal data to a third country or international organisation without appropriate safeguards in accordance with Chapter V of the GDPR.
Upon termination of the services, the Processor shall, at the choice of the Controller, delete or return all personal data and delete existing copies unless EU or member state law requires storage.
This DPA is governed by the laws of the Republic of Cyprus, consistent with the applicable data protection law.
To enter into a formal DPA or for queries, contact contact@blocklabs.digital.