Data Processing Addendum (DPA)
Contractual framework and technical/organizational safeguards governing enterprise Customer Personal Data processed by Aeltrix.
Data Processing Addendum
1. Application
This Data Processing Addendum applies where Aeltrix processes personal data on behalf of Customer in connection with contracted software platforms, APIs, or infrastructure operations.
2. Roles
Customer is controller or processor as applicable. Aeltrix is processor or subprocessor.
3. Instructions
Aeltrix will process Customer Personal Data only:
- to provide the Services;
- according to Customer's documented instructions;
- as described in the agreement; or
- where law requires processing.
4. Confidentiality
Persons authorized to process Customer Personal Data will be subject to appropriate statutory or contractual confidentiality obligations.
5. Security Measures
Aeltrix will maintain technical and organizational measures designed to provide security appropriate to risk. Measures may include, as appropriate:
Specific contractual security commitments set forth in an applicable Order or Statement of Work prevail over general descriptions.
6. Subprocessors
Customer provides general authorization for Aeltrix to use subprocessors. Aeltrix will impose data-protection obligations appropriate to their processing. Aeltrix will maintain a current subprocessor register and provide legally or contractually required notice of material additions.
7. Data Subject Requests
Taking into account the nature of processing, Aeltrix will provide reasonable assistance to Customer in responding to data-subject requests exercised under applicable data protection laws.
8. Security Incidents
Aeltrix will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data where notification is required. Notification will include information reasonably available concerning:
- nature of the incident;
- affected systems or data;
- known consequences;
- mitigation measures taken or planned; and
- relevant contact details for incident inquiries.
Information may be provided in phases as forensic investigation progresses.
9. Regulatory Assistance
Aeltrix will provide reasonable assistance regarding: Data Protection Impact Assessments (DPIAs); regulatory consultations; security obligations; and breach obligations, taking into account the nature of processing and information available to Aeltrix.
10. Return and Deletion
Following termination of the relevant Services, Aeltrix will delete or return Customer Personal Data according to the applicable Service and retention policy unless applicable law requires continued retention.
11. Audits
Aeltrix will provide information reasonably necessary to demonstrate compliance with processor obligations. Where appropriate, Aeltrix may satisfy audit requests through: security documentation; third-party reports; questionnaires; certifications; or a controlled audit. Audits must protect other customers, security information, and confidential systems.
12. International Transfers
Where Customer Personal Data subject to GDPR is transferred to a country lacking an adequacy decision, the parties incorporate the applicable European Commission Standard Contractual Clauses (SCCs) where required.
Modules will be selected according to the parties' roles (e.g., Module 2 Controller-to-Processor or Module 3 Processor-to-Processor). The parties will complete required annex information through the Order, DPA schedules, or subprocessor disclosures.
Questions about this legal document?
For legal notices, compliance questions, or requests relating to this document, contact Aeltrix Technologies LLC through the legal channel below.
