Data Processing Agreement (DPA)
Last Updated: June 1, 2026
At Numerikraft, we understand that data is the lifeblood of innovation. Whether managing client projects in scientific research, digital strategy, or technological development, we handle sensitive and proprietary information daily.
This Data Processing Agreement (DPA) formalizes our commitment to ethical, secure, and compliant processing of personal and sensitive data. It defines the responsibilities and expectations between Numerikraft ("Processor") and its clients ("Controller"), ensuring that data is processed in accordance with applicable laws, including the ANPDP Algeria and international standards such as ISO/IEC 27001 and OECD Privacy Guidelines.
Our approach integrates security, transparency, accountability, and innovation to create trust at every stage of collaboration. This document not only formalizes obligations but also reflects our philosophy that data protection is central to responsible innovation.
Scope & Definitions
This DPA applies to all personal data processed by Numerikraft on behalf of its clients. Key definitions include:
- Personal Data: Any information relating to an identifiable individual, including project participants, collaborators, or contacts.
- Processing: Any operation on personal data, including collection, storage, analysis, sharing, or deletion.
- Controller: The client determining the purpose and means of processing.
- Processor: Numerikraft, operating under the Controller's instructions to deliver agreed services.
By defining these roles clearly, we ensure accountability and a shared understanding of responsibilities, which is essential for trustworthy data management.
Principles of Responsible Data Processing
Numerikraft adheres to principles designed to safeguard the rights and interests of data subjects:
- Lawfulness, fairness, and transparency: All processing activities are documented, lawful, and clearly communicated.
- Purpose limitation: Data is used solely for the purposes agreed upon with the Controller.
- Data minimization: Only the necessary data is collected and processed to achieve specific objectives.
- Accuracy: Data is kept current and corrected when necessary.
- Storage limitation: Data is retained only as long as necessary for project purposes and legal obligations.
- Integrity and confidentiality: Strong technical and organizational measures protect data from unauthorized access, alteration, or loss.
This framework ensures that ethical and legal obligations are embedded in our day-to-day operations, not just as policy but as practice.
Data Security & Technical Safeguards
Numerikraft implements layered security measures to protect client data, following international best practices:
- Encryption at rest and in transit using industry-standard protocols to protect data confidentiality.
- Strict access controls, ensuring that only authorized team members can access data relevant to their tasks.
- Regular security audits and vulnerability assessments to detect and mitigate potential risks.
- Backups and disaster recovery planning, providing resilience against accidental loss or system failure.
- Secure development practices for software and platform projects, aligning with OWASP guidelines.
Our infrastructure and processes are designed to anticipate, prevent, and respond to threats, giving clients confidence that their data is protected throughout its lifecycle.
Subprocessors & Third-Party Providers
Numerikraft may engage external collaborators or service providers to support project delivery. All subprocessors are carefully vetted:
- Due diligence ensures compliance with our strict security, ethical, and legal standards.
- Contractual obligations guarantee adherence to this DPA and maintain confidentiality.
- Transparency: Clients can request a current list of subprocessors and their processing scope.
By controlling and monitoring subprocessors, we maintain a chain of trust across all project partners, ensuring the highest standards of accountability.
International Data Transfers
When personal data must be transferred outside of Algeria, Numerikraft ensures:
- Use of compliant mechanisms such as Standard Contractual Clauses (SCCs).
- Transfers only to countries with adequate legal safeguards.
- Transparent documentation and notification to the Controller regarding all international processing.
This guarantees that data protection obligations are never compromised in cross-border collaborations.
Data Subject Rights & Support
Numerikraft facilitates the Controller's obligations to data subjects by:
- Responding to requests for access, correction, restriction, or deletion of personal data.
- Supporting inquiries related to objections to processing.
- Providing audit trails and documentation demonstrating compliance with data protection obligations.
Our approach ensures that individual rights are respected, while clients retain control and oversight of their data.
Breach Notification & Incident Response
In the unlikely event of a data breach:
- Numerikraft will notify the Controller promptly, within 24 hours of detection.
- Detailed reports will include the scope, impact, and remediation actions.
- We assist clients in fulfilling regulatory reporting obligations, maintaining transparency and trust.
This proactive approach ensures rapid response and mitigation, minimizing potential impact.
Data Retention & Deletion
Data is retained only for as long as necessary to achieve agreed purposes:
- Personal and sensitive data is securely archived, anonymized, or destroyed at the end of its lifecycle.
- Backup copies are also securely deleted according to documented retention policies.
- Retention actions are fully auditable, ensuring accountability and compliance.
This practice balances operational needs with responsible data stewardship.
Audits, Reviews & Continuous Improvement
To maintain high standards, Numerikraft performs:
- Regular internal audits to verify adherence to processing instructions.
- External audit support, allowing clients or approved third parties to assess compliance.
- Ongoing policy and procedure reviews, ensuring alignment with evolving legal, ethical, and technological frameworks.
Continuous improvement guarantees that our data handling practices remain rigorous, transparent, and reliable.
Contact
For any questions, concerns, or feedback related to our Data Processing Agreement, please contact our dedicated team:
Email: contact@numerikraft.com
Address: 06 les vergers 01, Birkhadem, Algiers
Business Owner: Sid Ahmed Mili