1. Scope and Relationship
This Data Processing Addendum (“DPA”) forms part of the agreement between ControlAxis Systems (“ControlAxis”) and the business customer using the Services (“Customer”). To the extent ControlAxis processes personal data contained in Customer Data on Customer’s behalf, Customer is the controller or business and ControlAxis is the processor or service provider, as those terms are used in applicable data-protection law.
2. Processing Instructions
ControlAxis will process Customer Data only to provide, secure, support, and improve the Services; comply with documented instructions from Customer; and meet applicable legal obligations. The subject matter, duration, nature, purpose, categories of data, and categories of data subjects are those inherent in the Customer’s use of the Services and its documented instructions.
3. Confidentiality and Security
ControlAxis will ensure that personnel authorized to process Customer Data are bound by confidentiality obligations and will maintain appropriate technical and organizational measures designed to protect Customer Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.
4. Subprocessors
Customer authorizes ControlAxis to use service providers that support hosting, infrastructure, security, communications, billing, analytics, and support, provided that ControlAxis remains responsible for the performance of its data-protection obligations and requires subprocessors to protect Customer Data in a manner consistent with this DPA.
5. Assistance and Requests
Taking into account the nature of processing, ControlAxis will provide reasonable assistance to Customer in responding to verifiable requests from individuals exercising rights under applicable data-protection law. Customer remains responsible for responding to requests related to Customer Data and for determining the legal basis and instructions for processing.
6. Incident Notification
ControlAxis will notify Customer without undue delay after becoming aware of a confirmed security incident involving unauthorized access to Customer Data, taking into account the information available and applicable law. ControlAxis will provide information reasonably available to support Customer’s assessment and response.
7. Return and Deletion
Upon termination of the Services, ControlAxis will return or delete Customer Data in accordance with the applicable agreement, available functionality, and legal retention obligations. Customer is responsible for exporting or retaining Customer Data before termination where export functionality is available.
8. Contact
For questions regarding this DPA or data-protection matters, contact contact@controlaxissystems.com.