Back to Fís Studio

Data Processing Addendum (DPA)

Last updated: 19 August 2026 · Draft — pending owner approval.

This is a draft DPA summary. It is not an accepted addendum and does not itself form part of an agreement. Request an executed copy before relying on processor terms.

1. Subject-matter & duration

If executed, the DPA should define the processing needed to provide Fís Studio, its duration, and the agreed retention and deletion terms. Those terms are deployment- and agreement-dependent.

2. Nature & purpose of processing

Hosting and operating workshops; storing facilitator configuration, participant contributions, assessment records, templates, uploads, exports, and results shared through configured links.

3. Categories of data subjects & personal data

Data subjectsPersonal data
Workshop participantsDisplay name; contributions; configured email access data; participation and progress records
Assessment participantsVerified email identity; answers; saved-answer state; completion status; scores; assessment version
Facilitators / adminsEmail; authentication; audit data; workshop and template settings

The service does not require special-category data. Controllers must decide whether their chosen content or use case needs additional safeguards.

4. Proposed processor obligations

  • Process personal data only on documented instructions.
  • Set confidentiality, security, sub-processor, assistance, deletion, and audit terms in an executed DPA.
  • Confirm active providers and operational controls before production.

5. Sub-processors

The active provider list and any authorisation, notice, or objection process must be agreed in an executed DPA. The provider page is a current application configuration guide, not an authorisation record.

6. Current application measures

  • Secrets are supplied through environment configuration with startup checks.
  • Session cookies are httpOnly, Secure in secure-cookie environments, and SameSite.
  • The service applies server-side authorisation, tenant scoping, rate limits, and administrator two-factor authentication.
  • The service records administrative and sensitive actions and escapes user-supplied output.

7. Deployment confirmation

Before production, confirm hosting and backup locations, active providers, international-transfer analysis, retention and erasure operations, and the final security schedule. This draft makes no claim about them.

8. Contact

To request an executed DPA, contact privacy@fis.studio.

Straitéis AI Limited · 77 Lower Camden Street, Dublin 2, D02 XE80 · Company Registration Number: 799503 · info@straiteis.ie