BELF
RU/O‘Z/EN
Download BELF

Legal information · 21.09.2026

Data Processing Agreement (DPA)

Terms governing DIGITAL REVOLUTION MAKERS’ processing of personal data on behalf of a corporate client.

BELF documents

Data and infrastructureCustomer DPACookie PolicyTerms of UseWorkforce monitoringAcceptable use
SupplierDIGITAL REVOLUTION MAKERSRU: ДИДЖИТАЛ РЕВОЛЮШН МЕЙКЕРС · UZ/EN: DIGITAL REVOLUTION MAKERS

1. Subject matter and priority

The DPA forms part of the BELF agreement when DIGITAL REVOLUTION MAKERS processes personal data on the client’s behalf. For data processing matters, the DPA prevails over the general terms unless the signed agreement provides otherwise.

2. Processing parameters

  • Subject matter: provision, operation, protection, and support of BELF.
  • Duration: the service period and the agreed period for return or deletion.
  • Data subjects: employees, contractors, administrators, and representatives of the client.
  • Data: accounts, work events, devices, logs, screenshots, and data from enabled modules.
  • Operations: storage, organisation, transfer, diagnostics, backup, return, and deletion.

3. Client obligations

  • Ensure the lawfulness of instructions, purposes, notices, and legal bases.
  • Provide only necessary data and configure roles, modules, and retention periods.
  • Respond to requests from data subjects and regulators in a timely manner.

4. Provider obligations

  • Process data only on documented lawful instructions.
  • Ensure staff confidentiality and proportionate security measures.
  • Assist with data subject requests, assessments, audits, and incidents to the agreed extent.
  • After termination of services, return or delete the data except where retention is legally required.

5. Subprocessors and transfers

The client authorises the engagement of necessary subprocessors, including UzCloud or AWS, subject to comparable data protection obligations. Material changes are communicated to the client in the agreed manner. Region and cross-border transfers are determined by the contract, law, and Privacy Policy.

6. Security and incidents

Measures include access controls, secure transmission, logging, backups, vulnerability management, and recovery. The client is notified of a confirmed breach without undue delay.

7. Audit and liability

Upon a reasonable written request, the provider supplies information to demonstrate compliance with the DPA. An audit must not compromise the security of other clients. Liability is governed by the main agreement and mandatory law.

BELF — Digital Revolution MakersHome