Legal review required. This document contains realistic placeholder content suitable for a data-collection SaaS. It must be reviewed and approved by qualified legal counsel before publication or enforcement.
Data Processing Agreement
Effective1 January 2025
Last updatedJune 2025
Introduction
This Data Processing Agreement ("DPA") forms part of the agreement between BRIDGES Technology Group ("Processor") and the subscribing organization ("Controller") and governs the processing of personal data through the Reportiva platform.
This DPA applies where the Controller's use of Reportiva involves the collection, storage, or processing of personal data as defined under applicable data protection law, including the EU General Data Protection Regulation (GDPR) and equivalent national legislation.
Organizations with GDPR or equivalent obligations who require a signed DPA should contact legal@bridgesliberia.com.
Roles and responsibilities
The subscribing organization is the Data Controller — it determines the purposes and means of processing personal data collected through its Reportiva forms and programs.
BRIDGES Technology Group / Reportiva is the Data Processor — it processes personal data solely on the Controller's documented instructions and for no other purpose.
Nature and purpose of processing
The Processor processes personal data for the following purposes:
- Storing and organizing survey and monitoring data submitted by the Controller's field teams
- Generating dashboards, reports, and exports at the Controller's direction
- Providing user authentication and access management for the Controller's team members
- Maintaining platform security, audit logs, and operational integrity
The categories of data subjects and personal data processed depend entirely on the forms and data collection activities configured by the Controller. Common examples include survey respondent identifiers, geolocation data, and health or demographic indicators.
Processor obligations
BRIDGES Technology Group, as Processor, commits to:
- Process personal data only on documented instructions from the Controller
- Ensure all personnel with access to personal data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Not engage sub-processors without prior notice to and consent from the Controller
- Assist the Controller in responding to data subject rights requests
- Delete or return all personal data upon termination of the agreement
- Provide documentation sufficient for the Controller to demonstrate compliance
- Notify the Controller of any personal data breach without undue delay
Technical and organizational security measures
We implement the following measures to protect personal data:
- Encryption in transit using TLS 1.2 or higher
- Encryption at rest using AES-256 or equivalent
- Tenant isolation — each organization's data is stored and processed in a logically separate environment
- Role-based access controls limiting data access to authorized personnel
- Audit logging of access to personal data
- Regular security reviews and vulnerability assessments
- Incident response procedures with defined notification timelines
Sub-processors
We use the following categories of sub-processors to provide the Service:
- Cloud infrastructure providers (hosting and storage)
- Email delivery services (transactional notifications)
- Payment processors (billing — they do not have access to program data)
A current list of named sub-processors is available on request. We will provide 30 days' advance notice of material sub-processor changes.
International data transfers
Where personal data is transferred outside the country of collection, we implement appropriate safeguards including Standard Contractual Clauses (SCCs) or equivalent mechanisms as required by applicable law. Controllers with specific data residency requirements should contact us to discuss available arrangements.
Audit rights
The Controller has the right to audit our compliance with this DPA, either directly or through an appointed auditor, with reasonable notice and at the Controller's expense. We will cooperate with reasonable audit requests and provide documentation of our security measures and sub-processor arrangements.
Contact and signed DPA
Organizations requiring a signed Data Processing Agreement for procurement or compliance purposes should contact legal@bridgesliberia.com. We can provide a signed DPA within 5 business days of a verified request.