Data Processing Agreement.

How Perch processes personal data on behalf of customer organizations.

Template — not yet in force. The binding agreement is the countersigned copy exchanged with each pilot organization. This page documents the agreed structure; the reviewed legal text replaces it before any external tenant is onboarded.

1. Parties and roles

The customer organization is the data controller; Perch is the data processor, processing personal data only on the controller's documented instructions.

2. Subject matter and duration

Processing lasts for the term of the pilot and ends on account deletion, subject to the retention windows in clause 7.

3. Nature and purpose of processing

Operating a desk-booking service: authentication, organization and membership management, bookings, transactional email, and a per-user calendar feed.

4. Categories of data and data subjects

Names, email addresses, organization membership, and booking activity of the controller's members. No special-category data is collected.

5. Sub-processors

Supabase (database and auth, EU region), Vercel (hosting, EU region), Resend (transactional email), and Sentry (error monitoring, EU region). The controller is notified before any sub-processor is added. The current, canonical list — with each sub-processor's purpose, data, and region — is on the Sub-processors page.

6. Security measures

Row-level security for tenant isolation, encryption in transit, least-privilege access, and an append-only audit log of administrative actions.

7. Data-subject rights and retention

Members can export their own data at any time (Settings → Export my data). On account deletion, personal data is soft-deleted immediately and purged after a 30-day grace window; audit-log entries are retained per the retention policy with the actor anonymized.

8. Contact

Questions about this agreement: privacy@perch.app.