Legal
This Data Processing Addendum ("DPA") is between the legal entity that registers for or uses the Service and agrees to the Terms and this DPA ("Customer") and Iridae ApS, Maglebjergvej 6, 2800 Kongens Lyngby, established in Denmark ("Company"). It applies where Company processes Personal Data on behalf of Customer in providing the Service.
If this DPA conflicts with the Terms of Service, this DPA controls for Personal Data processing.
Customer is the Controller.
Company is the Processor.
Processing details are in Annex 1.
Company will process Personal Data only on documented instructions from Customer, including as set out in the Terms, this DPA, and Customer's use/configuration of the Service. Company will notify Customer if it believes an instruction violates applicable law (unless prohibited).
Company ensures persons authorized to process Personal Data are bound by confidentiality obligations.
Company implements appropriate technical and organizational measures as described in Annex 2 and may update them over time provided security is not materially reduced.
Customer authorizes Company to use Subprocessors to provide the Service.
Current Subprocessor list: /legal/subprocessors/
Company will impose data protection obligations on Subprocessors substantially similar to this DPA.
Company remains responsible for Subprocessors' performance under this DPA.
Changes/objections: Company may update Subprocessors. If Customer reasonably objects on data protection grounds, the parties will try to resolve. If unresolved, Customer may stop using the affected feature or terminate the affected order; fees are handled per the Terms/order form.
Where Personal Data is transferred outside the EU/EEA, Company will ensure a valid transfer mechanism (for example, adequacy decision or Standard Contractual Clauses). Where required, the parties are deemed to enter into SCCs (Controller-to-Processor, Module 2), with Customer as exporter and Company as importer, unless another lawful mechanism applies.
Taking into account the nature of processing, Company will reasonably assist Customer with:
To the extent Customer cannot fulfill them via the Service. Company may charge reasonable fees for assistance beyond what the Service normally provides.
Company will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data and share information reasonably required for Customer's compliance.
Upon termination/expiry of the Service, Company will delete or return Customer Personal Data within 60 days, unless retention is required by law or necessary for purposes stated in the Terms (for example, dispute resolution and security logs). Backups are deleted per standard rotation cycles.
Company will make available information reasonably necessary to demonstrate compliance with this DPA and allow audits:
Customer bears audit costs and must avoid disruption.
Liability under this DPA follows the limitations in the Terms, except where prohibited by applicable law.
If documents conflict: (1) SCCs (if applicable), (2) this DPA, (3) the Terms, (4) other policies.
Company maintains measures appropriate to risk, which may include: