# Bonterms / DPA draft (finalize-ready outline)

**Status:** counsel-ready draft outline (TDD-444) — **not legal advice**  
**Supersedes stub pointer:** [asr-vrm/dpa-draft-stub.md](asr-vrm/dpa-draft-stub.md)  
**Non-claim:** this document is not a signed Bonterms order form, DPA, or
certification. Completing sections with counsel does not assert GDPR/HIPAA/SOC 2
/ISO/FedRAMP certification.

## 1. Parties and roles

- **Customer** — controller (or equivalent) for operational decisions and any
  personal data they choose to process in Ops notes/SIEM sinks.
- **Provider** — CyberHalluciNet software/components as deployed by Customer;
  processing of **synthetic attacker interaction** telemetry is incidental to
  deception operation, not a primary personal-data service.

## 2. Nature and purpose of processing

| Category | Purpose | Notes |
|----------|---------|-------|
| Protocol metadata | Deception engagement evidence | Sensor zero-egress default |
| Sessionintel / Class B digests | Investigate / CTI export | Metadata-only SIEM paths |
| Ops notes / ITSM sync | Operator workflow | Customer-selected sinks |
| Canary / PLG callbacks | Optional PLG plane | Separated from sensor |

## 3. Subprocessors

Operator-selected sinks only (SIEM/SOAR/cloud). No silent third-party transfer
from the sensor plane. List maintained by Customer for their deployment.

## 4. Security measures (mapping, not certification)

Reference SEC-001…012, SEC-AG-*, containment, and plane separation. Kill-switch
independence remains Customer-operable without vendor cloud dependency.

## 5. International transfers and AGTI scrub

Jurisdiction filters and SEC-AG-004 scrub before leave-tenant apply to AGTI
exports. Customer configures residency.

## 6. Audit, retention, deletion

Evidence retention and tombstones under Customer control. No hard-delete of
tombstones before policy TTL (estate lifecycle docs).

## 7. Bonterms commercial schedule hooks

- Per-facility SKUs: [per-facility-price-sheet.yaml](../marketplace/per-facility-price-sheet.yaml)
- Private offer checklist: [private-offer-checklist.md](../marketplace/private-offer-checklist.md)
- Trust center: [trust-center.md](trust-center.md)

## 8. Signatures (placeholder)

| Role | Name | Date | Signature |
|------|------|------|-----------|
| Customer authorized signer | | | |
| Provider authorized signer | | | |

Counsel must replace placeholders before execution.
