Legal
Data Processing Agreement
Effective: January 1, 2024
This Data Processing Agreement ("DPA") forms part of the agreement between VertexStudio, Inc. ("Processor") and the customer ("Controller") for the provision of the EEv3 platform services. This DPA is entered into pursuant to Articles 28 and 29 of the General Data Protection Regulation (EU 2016/679) ("GDPR").
Scope
This DPA applies to all processing of personal data by the Processor on behalf of the Controller in connection with the provision of the EEv3 platform. The Controller determines the purposes and means of processing; the Processor processes personal data only on documented instructions from the Controller, except where required by applicable law.
Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.
- "Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, and erasure.
- "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
- "Sub-Processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Standard Contractual Clauses" (SCCs) means the contractual clauses approved by the European Commission for transfers of Personal Data to third countries.
Processing Details
The Processor processes the following categories of Personal Data on behalf of the Controller:
- Categories of Data Subjects: end users of the Controller's applications, employees, and business contacts.
- Types of Personal Data: names, email addresses, IP addresses, authentication credentials, and any other data stored by the Controller through the EEv3 platform.
- Purpose of processing: provision and maintenance of the EEv3 platform services as described in the Terms of Service.
- Duration of processing: for the term of the agreement between the parties, plus any retention period required by applicable law.
Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligations to respond to Data Subject requests under Chapter III of the GDPR, including rights of access, rectification, erasure, restriction, portability, and objection. The Processor shall promptly notify the Controller of any Data Subject request received directly and shall not respond to such requests without the Controller's authorization, except as required by law.
Sub-Processors
The Controller authorizes the Processor to engage sub-processors to process Personal Data on behalf of the Controller. The Processor maintains a current list of sub-processors, available upon request. The Processor shall notify the Controller at least 30 days before adding or replacing a sub-processor. If the Controller objects to a new sub-processor, the parties shall work in good faith to resolve the objection. Each sub-processor is bound by data protection obligations no less protective than those in this DPA.
Security Measures
The Processor implements and maintains appropriate technical and organizational measures to protect Personal Data, including:
- Encryption of Personal Data at rest (AES-256) and in transit (TLS 1.3).
- Network-level isolation between tenant environments.
- Role-based access controls with least-privilege principles for all internal systems.
- Regular penetration testing and vulnerability assessments by independent third parties.
- Incident detection and response procedures with defined escalation paths.
- Employee background checks and mandatory data protection training.
Data Transfers
The Processor shall not transfer Personal Data to a country outside the European Economic Area (EEA) unless adequate safeguards are in place. For transfers to the United States, the Processor relies on the EU-U.S. Data Privacy Framework and, as a fallback mechanism, the Standard Contractual Clauses (SCCs) approved by the European Commission (Commission Implementing Decision 2021/914). A copy of the executed SCCs is available upon request.
Audits
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits conducted by the Controller or an independent auditor mandated by the Controller. Audits shall be conducted with reasonable notice (no less than 30 days), during normal business hours, and shall not unreasonably interfere with the Processor's operations. The Processor maintains SOC 2 Type II certification, and audit reports are available upon request under NDA.
Term and Termination
This DPA shall remain in effect for the duration of the agreement between the parties. Upon termination, the Processor shall, at the Controller's election, return or delete all Personal Data within 30 days, unless retention is required by applicable law. The Processor shall certify deletion in writing upon request.