Snapshot 17491
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Home 5 About 5 Legal 5 Data Processing Addendum Data Processing Addendum - DataLocker Inc. Version: AUG 2026 1. Scope and Duration This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with the use of DataLocker products and services, including SafeConsole. Processing shall be carried out for the duration of the active service relationship and any subsequent Retention Period (as described in Section 11) specifically instructed by the Controller to facilitate future service reactivation. 2. Nature and Purpose of Processing The Processor shall process personal data solely for the following purposes: Provision and operation of device management services Enforcement of security policies Logging, monitoring, and audit functions Processing is limited to what is strictly necessary for these purposes. The Processor shall not have access to, nor process, any files stored on the Controller’s devices or within SafeCrypt. These files are never sent to the SafeConsole Server. 3. Categories of Data and Data Subjects Categories of personal data: User Identification Data: Computer username, Email address, and Active Directory OU path. Technical Identifiers: Public IP address, Device Serial Number, Software Version, and unique machine digital fingerprints. Cryptographic Data: Random one-time pad keys (used for password hash encryption) and encrypted recovery passwords. Usage and Metadata Logs: Computer hostname, OS version, used device capacity, and device action timestamps. Administrator Data: Name, Email, Phone Number, Public IP, and hashed passwords of SafeConsole Admins. File Metadata (Audit Logs): Created filenames, file locations on the device, file sizes, and MD5 hashes of files. Categories of data subjects: Employees and authorized users of the Controller 4. Instructions The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable Data Protection Laws. 5. Confidentiality The Processor shall ensure that all persons authorized to process personal data are bound by confidentiality obligations. 6. Technical and Organizational Measures (TOMs) The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including: Access to processed data is strictly limited to the DataLocker Web Operations (WebOps) team through a controlled and audited process. Single-tenant architecture ensuring dedicated application and database instances for each Controller to prevent data co-mingling Encryption of data in transit and at rest Implementation of Multi-Factor Authentication (MFA) and a minimum 20-character password policy for production access Logging and monitoring of system access Protection against unauthorized access 7. Subprocessing The Processor may engage subprocessors only where necessary for the provision of the services. The Processor shall: ensure that subprocessors are bound by equivalent obligations remain fully responsible for the performance of subprocessors Maintain an up-to-date list of subprocessors and make it available to the Controller Provide the Controller with prior written notification of any intended additions or replacements of subprocessors, providing the Controller a reasonable opportunity to object on legitimate data protection grounds. 8. International Data Transfers Where personal data is transferred outside the European Economic Area (EEA), the Processor shall ensure appropriate safeguards, including: Certification under the EU-U.S. Data Privacy Framework Standard Contractual Clauses (SCCs), where applicable 9. Assistance to the Controller The Processor shall assist the Controller in: responding to data subject requests ensuring compliance with Articles 32 to 36 GDPR handling personal data breaches 10. Notification of Personal Data Breaches The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach. 11. Deletion or Return of Data Upon termination of active services, the Processor shall not automatically delete personal data but shall instead maintain the Controller’s dedicated application instance and database in a dormant state to allow for seamless service renewal. The Processor shall delete or return the personal data upon: (a) receipt of a written request from the Controller, or (b) following a period of up to 3 years of continuous account inactivity, whichever occurs first. During the dormant state, the Processor shall continue to apply the Technical and Organizational Measures described in Section 6 to ensure the ongoing security of the data. 12. Audit and Compliance The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice. 13. Liability Liability shall be governed by the provisions of the underlying agreement between the Parties. 14. Governing Law This DPA shall be governed by the applicable law of the underlying agreement and interpreted in accordance with the General Data Protection Regulation (EU) 2016/679. Download Printable Version