MGTrace — Data Processing Agreement (DPA)
Between:
- Processor: ERIN AUTOMATION, S.L. (Sociedad Unipersonal; CIF B-25925611), Avinguda Can Serra, 3, Esc. B, 3º 3ª, 08390 Montgat (Barcelona), Spain ("MGTrace").
- Controller: the customer organization that has accepted this DPA and uses the MGTrace platform (the "Customer").
This DPA forms part of, and is governed by, the MGTrace Terms & Conditions (the "Agreement"). It reflects Article 28 GDPR and applies where MGTrace processes personal data on the Customer's behalf. In case of conflict on data-protection matters, this DPA prevails.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given in the GDPR (Regulation (EU) 2016/679). "Customer Personal Data" means personal data contained in the Customer's content within the Service and processed by MGTrace on the Customer's behalf.
2. Roles and scope
2.1 The Customer is the controller and MGTrace is the processor of Customer Personal Data. Each party complies with its obligations under applicable data protection law. 2.2 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.
3. MGTrace's obligations
MGTrace shall:
- Process only on documented instructions from the Customer (including on international transfers), as set out in the Agreement, this DPA and the Customer's use of the Service, unless required by EU/Member-State law (in which case MGTrace informs the Customer unless the law prohibits it).
- Ensure persons authorized to process Customer Personal Data are under an appropriate duty of confidentiality.
- Implement the technical and organizational measures in Annex II (Article 32).
- Respect the conditions in Clause 4 for engaging sub-processors.
- Assist the Customer, by appropriate measures, to respond to data-subject requests (Chapter III GDPR).
- Assist the Customer in ensuring compliance with Articles 32–36 (security, breach notification, DPIA, prior consultation), taking into account the nature of processing and information available to MGTrace.
- At the Customer's choice, delete or return all Customer Personal Data at the end of the provision of services, and delete existing copies unless EU/Member-State law requires storage (Clause 8).
- Make available to the Customer information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits (Clause 9).
- Notify the Customer without undue delay upon becoming aware of a personal data breach (Clause 7).
- Immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other data-protection law.
4. Sub-processors
4.1 The Customer grants MGTrace general written authorization to engage sub-processors to provide the Service. The current sub-processors are listed in Annex III. 4.2 MGTrace imposes on each sub-processor data-protection obligations equivalent to those in this DPA and remains fully liable to the Customer for the sub-processor's performance. 4.3 MGTrace will give the Customer at least 30 days' prior notice of the addition or replacement of a sub-processor (by email or in-product/website notice). The Customer may object on reasonable data-protection grounds within that period; the parties will work in good faith to resolve it, and if unresolved the Customer may terminate the affected Service.
5. International transfers
Where processing involves a transfer of Customer Personal Data outside the EEA, MGTrace ensures an appropriate transfer mechanism is in place, in particular the European Commission's Standard Contractual Clauses (SCCs) with the relevant sub-processor, together with any additional safeguards required. Details are available on request.
6. Data-subject requests
If MGTrace receives a request from a data subject regarding Customer Personal Data, it will not respond directly (except to confirm the request concerns the Customer) and will forward the request to the Customer without undue delay and assist the Customer in responding.
7. Personal data breach
MGTrace will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, providing the information reasonably available (nature of the breach, categories/approximate numbers affected, likely consequences and measures taken/proposed) to enable the Customer to meet its Article 33/34 obligations.
8. Deletion and return
On termination or expiry of the Agreement, MGTrace will, at the Customer's choice, return or delete Customer Personal Data within 90 days, except copies required to be retained by law or contained in routine backups (which are deleted on the standard backup rotation) and records whose integrity must be preserved for regulated purposes (e.g. audit trail, electronic signatures).
9. Audits
MGTrace makes available information necessary to demonstrate compliance with this DPA. The Customer may audit no more than once per year (or after a breach) on 30 days' notice, during business hours, subject to confidentiality and without unreasonably disrupting operations. MGTrace may satisfy audit requests by providing up-to-date certifications, security documentation and its Technical & Organizational Measures (Annex II).
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.
11. Term
This DPA takes effect when the Customer accepts the Agreement and continues while MGTrace processes Customer Personal Data.
Annex I — Details of processing
- Subject matter: provision of the MGTrace commissioning & qualification / eQMS platform.
- Duration: the term of the Agreement.
- Nature and purpose: hosting, storing and processing the Customer's content to provide the Service (document authoring, requirements, protocols, execution, electronic signatures, traceability, audit trail, exports).
- Types of personal data: identification and professional data of the Customer's users and collaborators — name, email, role/job title, organization, electronic-signature metadata (identity, meaning, date-time, IP address), audit-trail entries, and any personal data the Customer includes in its documents/content.
- Categories of data subjects: the Customer's employees, contractors and other authorized users (e.g. authors, reviewers, approvers, QA).
- Special categories: none. The Customer shall not upload special-category data (Article 9).
Annex II — Technical and Organizational Measures (TOMs)
MGTrace maintains measures appropriate to the risk, including:
- Encryption: TLS/HTTPS in transit; encryption at rest at the database/storage layer.
- Access control & isolation: email/password authentication; role-based access control (six roles); row-level security isolating each organization's data; least-privilege internal access; session inactivity time-out (~15 min).
- Record integrity & auditability: immutable audit trail of critical actions (user, timestamp, IP, change); electronic signatures bound to the signed record version with re-authentication; controlled-change workflow preventing edits to released/signed records.
- Data segregation: logical separation of environments (development / production on separate database projects).
- Resilience & backup: managed hosting with daily backups and no auto-pause on the production database.
- Network & platform security: reputable managed sub-processors (Supabase, Vercel) with their own certifications; secrets managed as environment variables, not in code.
- Vulnerability & change management: version-controlled codebase; automated type/lint/build checks; staged deployments (dev → prod).
- Personnel: confidentiality obligations for anyone with access.
- Incident response: breach detection and notification process (Clause 7).
(These measures reflect the current architecture and evolve as the Service develops.)
Annex III — Sub-processor list
| Sub-processor | Role | Location of processing | Transfer safeguard |
|---|---|---|---|
| Supabase (Supabase, Inc.) | Database, authentication, file storage | EU — eu-west-1, Ireland | Within EEA |
| Vercel (Vercel, Inc.) | Application hosting, serverless compute, IP-based geolocation, cookieless web analytics (aggregated visits and page performance) | United States / global edge | EU SCCs (Vercel DPA) |
| Resend (Resend, Inc.) | Transactional/service emails sent by the authentication service (verification, invitation, password reset) | EU — eu-west-1, Ireland (sending region) | EU SCCs (Resend DPA) |
Last updated: 10 August 2026. The current list is maintained at https://mgtrace.com/dpa.