Data Processing Agreement — outline
What a DPA with EcoKure would have to say, published as an engineering description before legal review rather than withheld until someone asks. When a regulated buyer asks “do you have a DPA”, the answer here is a specific, dated position — not silence, and not a document that implies a legal review that never happened.
This is not a contract and must not be treated as one. A lawyer has not read it. It exists so the position is known, not to be signed.
The distinction that governs everything
Two systems, and a single DPA covering both would be wrong.
| ecokure.com | Assurance Runtime | |
|---|---|---|
| Role | EcoKure is controller for site data | Customer is controller; EcoKure is at most processor |
| Where it runs | EcoKure’s hosting | The customer’s own account |
| Subprocessors | Seven — see the list | None |
| Data EcoKure can access | Site analytics, enquiries, orders | None by default |
The runtime deploys inside the customer’s boundary. Evidence, signing keys and decision records do not reach EcoKure. In a standard deployment there is no transfer to EcoKure at all, and the DPA’s operative clauses would cover support access — the exceptional case — rather than ongoing processing.
What the runtime actually holds
Relevant because it changes the risk profile substantially.
- An input digest, not the input. The evidence store holds a hash of the request, never the request body. Customer content does not enter it.
- Reviewer identity, held tenant-side. The public chain carries only a hiding commitment, not a person.
- No tenant dimension on the transparency surface, by design.
Clauses a DPA would need
Listed so nothing is quietly dropped. Wording is counsel’s.
- Subject matter, duration, nature and purpose — deterministic verification of customer-defined controls, for the licence term.
- Categories of data and data subjects — customer-determined. EcoKure cannot enumerate them because it does not see the inputs.
- Instructions — process only on documented instruction; obligation to notify if an instruction appears unlawful.
- Confidentiality — personnel bound.
- Security measures — reference the security pack rather than restating it, so one document does not drift from the other.
- Subprocessors — the published list, with notice of change and a right to object. The runtime has none, which is worth stating explicitly.
- Data subject rights — assistance obligations. See the erasure position below.
- Breach notification — timeframe to be set by counsel.
- DPIA assistance.
- Deletion or return on termination — the hard one, below.
- Audit and inspection rights.
- International transfers — the site’s subprocessors sit in the US and EU; the runtime transfers nothing.
The clause that cannot be written normally
A standard DPA promises deletion on termination. The evidence chain is append-only and shared across tenants. Deleting an entry breaks the tamper-evidence for every other tenant on that chain.
What EcoKure can do is destroy everything that makes an entry meaningful: the nonce that opens the commitment, the tenant attribution, the decision record and the reviewer identity. What remains is an unattributed hash that was never readable without the nonce and cannot be made readable again.
This is cryptographic erasure and de-attribution. It is not deletion, and the DPA must not call it deletion. The procedure this triggers, and what a customer actually receives, is described on the offboarding page.
The audit clause EcoKure can actually honour
Most vendors resist audit rights. EcoKure’s position is unusual and should be used.
- Evidence packs verify with a standalone verifier containing no EcoKure code, offline. A customer can audit the evidence without our cooperation, our servers, or our continued existence.
- The runtime runs in their account, so infrastructure audit is theirs by default.
What must not be signed until resolved
- The erasure clause above — unresolved and material.
- Breach notification timeframes — no incident response has been rehearsed against a real incident.
- Any security warranty implying certification: there is no SOC 2, no ISO 27001 and no independent penetration test. A DPA that implies otherwise would misrepresent the position. Current status is on the security pack.
- Liability and indemnity — entirely counsel’s.
Honest interim answer
“A DPA outline exists and has not been legally reviewed. We can share it, clearly marked, so your legal team sees our position before drafting. Two points need resolving before signature: the deletion clause, because an append-only evidence chain cannot delete in the ordinary sense and we will not describe cryptographic erasure as deletion; and the security warranty, because we hold no certifications and will not imply that we do.”
That answer loses some deals. It loses fewer than being found out later.
