Skip to Content

Data Processing Addendum

Data-processing terms to accompany the MSA when Company 2 processes customer personal data.

Open decisions

Provider / processor[US ENTITY LEGAL NAME], [LEGAL FORM]
Customer / controller[CUSTOMER LEGAL NAME AND ROLE]
Applicable laws[GDPR, U.S. STATE LAWS, AND OTHER APPLICABLE LAWS]
Privacy contact[PRIVACY AND SECURITY CONTACTS]
Security schedule[APPROVED TECHNICAL AND ORGANIZATIONAL MEASURES]
Subprocessors[APPROVED SUBPROCESSOR LIST AND NOTICE METHOD]
Transfers[DATA LOCATIONS AND TRANSFER MECHANISM]
Incident notice[APPROVED NOTICE PERIOD AND METHOD]

1. Scope and roles

This DPA applies when the Provider processes personal data for the customer under the MSA or an order. The parties' roles, applicable privacy laws, and any independent-controller activities must be confirmed for each service.

2. Processing details

  • Subject matter and duration: [DESCRIBE SERVICES AND TERM].
  • Nature and purpose: [DESCRIBE HOSTING, SUPPORT, DESIGN, MARKETING, OR OTHER PROCESSING].
  • Data subjects: [CUSTOMERS, PROSPECTS, EMPLOYEES, WEBSITE USERS, OR OTHER CATEGORIES].
  • Personal data: [IDENTIFIERS, CONTACT DATA, ACCOUNT DATA, CONTENT, LOGS, OR OTHER TYPES].
  • Sensitive data: [NONE OR SPECIFY CATEGORIES AND CONTROLS].

3. Documented instructions

The Provider will process personal data only on documented customer instructions, including the MSA, orders, and authorized support requests, unless law requires otherwise. The Provider will notify the customer if an instruction appears to violate applicable data-protection law, unless prohibited.

4. Personnel and confidentiality

The Provider will limit access to personnel who need it for the services and who are subject to confidentiality obligations and appropriate training.

5. Security

The Provider will maintain the approved technical and organizational measures in [SECURITY SCHEDULE]. The final schedule must address access control, authentication, encryption, backups, logging, vulnerability management, incident response, availability, and review appropriate to the service and risk.

6. Subprocessors

The customer authorizes only the subprocessors on [APPROVED SUBPROCESSOR LIST]. The Provider will impose materially equivalent data-protection obligations and follow [NOTICE AND OBJECTION PROCESS] before adding or replacing a subprocessor.

7. Assistance

Taking account of the processing, the Provider will reasonably assist with data-subject requests, security obligations, breach notifications, impact assessments, consultations, and regulator inquiries. Fees and response times for assistance must be stated in the final DPA or order.

8. Security incidents

The Provider will notify the customer without undue delay and within [APPROVED NOTICE PERIOD] after confirming a personal-data breach affecting customer data. The notice will include available information about the nature, likely effects, affected data, mitigation, and contact point. Notice is not an admission of fault.

9. Return, deletion, and audits

At the end of the services, the Provider will return or delete customer personal data under [APPROVED RETENTION AND BACKUP RULES], unless law requires retention. The Provider will provide information reasonably needed to demonstrate compliance and support audits under approved scope, confidentiality, timing, security, and cost rules.

10. Transfers and conflicts

Cross-border transfers require [APPROVED TRANSFER MECHANISM AND SUPPLEMENTARY MEASURES]. If this DPA conflicts with the MSA on personal-data processing, this DPA controls. Mandatory law and any signed transfer addendum control where required.

Preview source: https://portal2.bezalel-systems.de/data-processing-addendum. Review again before moving this page to bezalel-systems.com.