Skip to content
LEGAL · PAGE 6 // DPA-v26

Data Processing Addendum (DPA)

Contractual framework and technical/organizational safeguards governing enterprise Customer Personal Data processed by Aeltrix.

Controller / Processor relationship defined
Standard Contractual Clauses (SCCs) incorporated
Mandatory incident notification without undue delay
Strict subprocessor audit & security standards
LEGAL SUITE // PAGE 6

Data Processing Addendum

Effective Date: September 17, 2026
Entity: Aeltrix Technologies LLC

1. Application

This Data Processing Addendum applies where Aeltrix processes personal data on behalf of Customer in connection with contracted software platforms, APIs, or infrastructure operations.

2. Roles

Customer is controller or processor as applicable. Aeltrix is processor or subprocessor.

3. Instructions

Aeltrix will process Customer Personal Data only:

  • to provide the Services;
  • according to Customer's documented instructions;
  • as described in the agreement; or
  • where law requires processing.

4. Confidentiality

Persons authorized to process Customer Personal Data will be subject to appropriate statutory or contractual confidentiality obligations.

5. Security Measures

Aeltrix will maintain technical and organizational measures designed to provide security appropriate to risk. Measures may include, as appropriate:

access control & role-based scoping
multi-factor authentication
TLS 1.3 encryption in transit
AES-256 encryption at rest where supported
tamper-evident audit logging
cryptographic secret management
continuous vulnerability management
isolated network segmentation
immutable automated backups
structured incident response runbooks
high-availability & failover controls
disciplined change management
strict personnel confidentiality agreements

Specific contractual security commitments set forth in an applicable Order or Statement of Work prevail over general descriptions.

6. Subprocessors

Customer provides general authorization for Aeltrix to use subprocessors. Aeltrix will impose data-protection obligations appropriate to their processing. Aeltrix will maintain a current subprocessor register and provide legally or contractually required notice of material additions.

7. Data Subject Requests

Taking into account the nature of processing, Aeltrix will provide reasonable assistance to Customer in responding to data-subject requests exercised under applicable data protection laws.

8. Security Incidents

Aeltrix will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data where notification is required. Notification will include information reasonably available concerning:

  • nature of the incident;
  • affected systems or data;
  • known consequences;
  • mitigation measures taken or planned; and
  • relevant contact details for incident inquiries.

Information may be provided in phases as forensic investigation progresses.

9. Regulatory Assistance

Aeltrix will provide reasonable assistance regarding: Data Protection Impact Assessments (DPIAs); regulatory consultations; security obligations; and breach obligations, taking into account the nature of processing and information available to Aeltrix.

10. Return and Deletion

Following termination of the relevant Services, Aeltrix will delete or return Customer Personal Data according to the applicable Service and retention policy unless applicable law requires continued retention.

11. Audits

Aeltrix will provide information reasonably necessary to demonstrate compliance with processor obligations. Where appropriate, Aeltrix may satisfy audit requests through: security documentation; third-party reports; questionnaires; certifications; or a controlled audit. Audits must protect other customers, security information, and confidential systems.

12. International Transfers

Where Customer Personal Data subject to GDPR is transferred to a country lacking an adequacy decision, the parties incorporate the applicable European Commission Standard Contractual Clauses (SCCs) where required.

Modules will be selected according to the parties' roles (e.g., Module 2 Controller-to-Processor or Module 3 Processor-to-Processor). The parties will complete required annex information through the Order, DPA schedules, or subprocessor disclosures.

LEGAL & COMPLIANCE

Questions about this legal document?

For legal notices, compliance questions, or requests relating to this document, contact Aeltrix Technologies LLC through the legal channel below.

Execute Enterprise DPA