Third Party Index

Snapshot 51371

Document
Data processing addendum
URL
https://www.raklet.com/legal/data-processing-addendum-dpa/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
255372 bytes
SHA-256 (raw)
009331a813c068609195a2d88eac00068be30c4b8d66e9e694a55156263109e7
SHA-256 (normalized text)
0bb4a013970144810afea80e00863b772fdf2e478033316449e010c77ea7c9f9

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Raklet EU, UK, and Swiss Data Processing Addendum (DPA)
Raklet EU, UK, and Swiss Data Processing Addendum (DPA)
Last Updated: July 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between Raklet, Inc. (“Raklet” or “Processor”) and the entity or individual agreeing to this DPA (“Customer” or “Controller”). This DPA reflects the parties’ obligations under the General Data Protection Regulation (EU Regulation 2016/679, “GDPR”), the UK Data Protection Act 2018 (“UK GDPR”), and the Swiss Data Protection Act.
By using Raklet’s services, you accept the terms of this DPA.
1. Definitions
Unless otherwise defined in this DPA, terms are as defined in the GDPR:
•Agreement: The main contract governing Raklet’s services.
•Controller: The entity determining the purposes and means of personal data processing.
•Processor: Raklet, processing data on behalf of the Controller.
•Personal Data: Any information relating to an identified or identifiable individual.
•Processing: Any operation performed on personal data, such as collection or storage.
•Sub-processor: A third party engaged by Raklet to process personal data.
•Standard Contractual Clauses (SCCs): EU-approved clauses ensuring lawful data transfers outside the EEA.
2. Scope of Processing
Raklet processes personal data to deliver its services:
•Purpose: CRM, membership management, events, and payment processing.
•Data Subjects: Members, users, and employees of the Controller.
•Data Types:
•Basic data: Name, email, phone number.
•Financial data (via Stripe): Credit card information, payment records.
•Optional data: Any additional information users voluntarily provide.
•Retention Period: Personal data is deleted 30 days after contract termination, except as required by law.
3. Obligations of Raklet as Processor
Raklet agrees to:
1.Process personal data only as instructed by the Controller.
2.Ensure security through encryption, access controls, and regular backups.
3.Notify the Controller within 72 hours of any personal data breach.
4.Assist the Controller with data subject requests (e.g., access, rectification, deletion).
5.Ensure all sub-processors comply with equivalent obligations under this DPA.
4. Sub-Processors
Raklet maintains a complete list of Raklet’s subprocessors used to provide its services, including:
Sub-Processor Purpose Location
Amazon Web Services Data hosting EU
Microsoft Azure Data hosting EU
Stripe Payment processing Global
PayPal Payment processing Global
Intercom Customer support & communication Global
Rollbar Error monitoring Global
HubSpot CRM and marketing automation Global
ElasticSearch Search and analytics engine Global
Raklet notifies customers of sub-processor changes and provides a 14-day objection window.
5. International Data Transfers
Raklet ensures international data transfers comply with GDPR:
1. Sub-processor Compliance: All sub-processors (e.g., AWS, Stripe) include SCCs in their DPAs.
2. SCCs: Raklet uses SCCs to ensure data transferred outside the EEA is protected.
6. Security Measures
Raklet implements the following security measures:
• Encryption: Data is encrypted at rest and in transit using SSL/TLS.
• Access Controls: Only authorized Raklet team members can access production systems.
• Backups: Automated daily backups are retained for 30 days.
• Monitoring: Regular security audits and vulnerability scans.
7. Data Breach Notification
In the event of a data breach:
1. Raklet will notify the Controller within 72 hours.
2. Details provided will include:
•Nature and scope of the breach.
•Impact on data subjects.
•Mitigation actions taken.
8. Data Subject Rights
Raklet assists the Controller in fulfilling data subject rights under GDPR:
1.Access, correction, or deletion of personal data.
2.Data portability requests.
3.Objection to processing requests.
Requests will be addressed within 30 days.
9. Termination and Data Deletion
The subscription can be cancelled anytime customer wants, and customer will not be charged going forward. It is important to get all the export reports needed (such as payments, reminders, list of contacts, etc.) before taking any action. If customer has already paid the amount annually/monthly, Raklet has to provide customer with the service for the remainder of the year/month that they have paid for. Customer will not receive any refund for the billing period in which they are charged.
Upon termination of the agreement:
1.Raklet will delete or anonymize personal data within 30 days.
2.Backups will be deleted after the retention period.
10. Governing Law
This DPA is governed by the laws outlined in the main Agreement. Disputes will be resolved in the jurisdiction specified therein.
11. Contact
For questions or concerns regarding this DPA, please contact Raklet at:
Email: contact page
Address: 4347 20th Street, San Francisco CA 94114
Annex 1: Security and Compliance
Security Measure Details
Encryption SSL/TLS for data in transit and encryption at rest.
Access Control Restricted access to production systems.
Backups Automated daily backups retained for 30 days.
Monitoring Security audits, vulnerability scans, and testing.