This Data Processing Agreement ("DPA") forms part of the Master Services Agreement between TraKNC Inc. ("Processor") and the Customer ("Controller"). This DPA reflects the parties' agreement with regard to the processing of Personal Data.
This DPA is intended to ensure compliance with applicable data protection laws, including the GDPR and CCPA.
1. Scope and Purpose
The Processor shall process Personal Data on behalf of the Controller solely for the purpose of providing the Services described in the main agreement. The nature and purpose of processing include the collection, storage, and analysis of security data to provide threat intelligence and incident response services.
2. Types of Personal Data
The types of Personal Data processed may include names, email addresses, IP addresses, device identifiers, and log data associated with the Controller's users and systems. The categories of data subjects include the Controller's employees, customers, and users.
3. Obligations of Processor
The Processor agrees to:
- Process Personal Data only on documented instructions from the Controller.
- Ensure that persons authorized to process Personal Data have committed themselves to confidentiality.
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
- Assist the Controller in fulfilling its obligation to respond to requests for exercising data subject rights.
4. Sub-processors
The Controller authorizes the Processor to engage sub-processors to support the delivery of the Services. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors. The Processor remains liable for the acts and omissions of its sub-processors.
5. Data Breaches
In the event of a Personal Data Breach, the Processor shall notify the Controller without undue delay, and in any event within 72 hours after becoming aware of the breach. The notification shall include details of the nature of the breach, the categories of data affected, and recommended measures to mitigate the adverse effects.
6. Data Transfer
If Personal Data is transferred to a country outside the European Economic Area (EEA) or a country not recognized as providing an adequate level of protection, the Processor agrees to abide by the Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms.
7. Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
8. Termination and Deletion
Upon termination of the main agreement, the Processor shall, at the choice of the Controller, delete or return all Personal Data to the Controller and delete existing copies unless applicable law requires storage of the Personal Data.
9. Contact Us
If you have questions about this DPA, please contact our Data Protection Officer at:
TraKNC Inc.
7601 River Rd, North Bergen, New Jersey 07047
Email: [email protected]