Data processing addendum
Where a product processes personal data on behalf of a business customer, these terms apply between that customer and Airosofts LLC, in addition to the product's terms of service.
1. Roles
The customer is the controller of personal data it submits to the service. Airosofts LLC is the processor. Each party complies with the data-protection law that applies to it.
2. Instructions
We process personal data only to provide the service, as documented in the product's terms and the customer's configuration, and on the customer's documented instructions. We will tell the customer if an instruction appears to infringe the law.
3. Confidentiality
People authorised to process personal data are bound by confidentiality obligations and receive appropriate training.
4. Security
We implement the technical and organisational measures described on the security page, and any additional measures agreed in writing, taking into account the nature of the data and the risks.
5. Sub-processors
The customer authorises the sub-processors listed on the sub-processors page. We give at least thirty days' notice of additions by updating that page and, for customers who ask, by email. A customer may object on reasonable grounds; if we cannot resolve the objection the customer may terminate the affected service.
6. Assistance
We assist the customer, at reasonable cost, with data-subject requests, security of processing, breach notification, and impact assessments, to the extent the customer cannot do these things through the service itself.
7. Breach notification
We notify the customer without undue delay after becoming aware of a personal-data breach affecting their data, with the information reasonably available at the time and updates as we learn more.
8. Deletion and return
On termination the customer may export their data through the service for a period of thirty days, after which we delete it, except where the law or the evidential nature of signed documents requires retention.
9. Audit
We provide information necessary to demonstrate compliance and, no more than once a year and on reasonable notice, allow audits by the customer or an independent auditor, subject to confidentiality.
10. Transfers
Where data is transferred internationally we rely on appropriate safeguards, including standard contractual clauses incorporated by reference where required.
11. Signing
This addendum is effective when the customer accepts the product terms that reference it. Customers who need a countersigned copy or specific terms should write to info@airosofts.com with the subject "DPA".