Data Processing Agreement

Standard terms for processing personal data you submit to the Praesidia platform, consistent with Article 28 GDPR.

Version 1.0 — last updated: July 2026. This page describes Praesidia's standard Data Processing Agreement (DPA). To request a countersigned copy referencing your specific order or agreement, contact legal@praesidia.ai.

1. Parties and scope

This DPA forms part of the Terms of Service between you ("Customer", acting as data controller) and Squad Technology SRL, operating as Praesidia ("Processor"), whenever Praesidia processes personal data on Customer's behalf as part of the Service. It applies for as long as the underlying agreement is in effect.

2. Subject matter, duration, and nature of processing

Praesidia processes personal data to authenticate, govern, and monitor interactions between Customer's applications, AI agents, and MCP servers, and to provide the resulting dashboards, alerts, and audit records — for the duration of the underlying agreement. The categories of data subjects and personal data are those Customer chooses to submit through the Service (typically: Customer's own personnel, end users, and any personal data an agent or connected system processes on Customer's behalf).

3. Processor obligations

Praesidia will:

  • process personal data only on Customer's documented instructions, including with regard to international transfers, unless required otherwise by law;
  • ensure personnel authorized to process personal data are bound by confidentiality;
  • implement the technical and organizational security measures described on our Security & Compliance page;
  • assist Customer in responding to data-subject requests (access, correction, deletion, portability) and in meeting its own obligations under Articles 32–36 GDPR;
  • make available the information reasonably necessary to demonstrate compliance with this DPA.

4. Sub-processors

Customer authorizes Praesidia to engage the sub-processors listed on our Subprocessor List. Praesidia will give notice via that page and, on request, by email before adding or replacing a sub-processor, and Customer may object on reasonable data-protection grounds by contacting privacy@praesidia.ai. Praesidia remains liable for a sub-processor's performance to the same extent it is liable for its own.

5. International transfers

Where personal data is transferred outside the European Economic Area, Praesidia relies on the European Commission's Standard Contractual Clauses (SCCs) or another valid transfer mechanism recognized under GDPR, incorporated into this DPA by reference.

6. Personal data breach notification

Praesidia will notify Customer without undue delay, and in any event within 72 hours of confirming a personal data breach affecting Customer's data, with the information reasonably available at the time and updates as the investigation progresses, consistent with Praesidia's obligations as a processor under Article 33 GDPR.

7. Audit rights

On reasonable prior notice and no more than once per year (or following a confirmed security incident), Praesidia will make available the information and documentation reasonably necessary to demonstrate compliance with this DPA, including relevant portions of independent audit reports where available, subject to reasonable confidentiality restrictions.

8. Data return and deletion

On termination of the underlying agreement, Praesidia will delete or return Customer's personal data within the period stated in our Privacy Policy, except where retention is required by law or for the compliance audit trail as described there.

9. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service.

10. Contact

Questions about this DPA, or to request a countersigned copy: legal@praesidia.ai. Data-protection questions: privacy@praesidia.ai.