Data Processing Addendum
Version 1.0 · Effective August 8, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Terms") between Ellis Intelligence LLC d/b/a SafeguardsMark ("Processor", "we") and the customer entity identified in the subscription order ("Customer"). It governs Processor's processing of Personal Data on Customer's behalf. Customer acts as the controller of that Personal Data as described in §2.1.
- 1. Definitions
- 2. Roles and scope
- 3. Processor's obligations
- 4. Data subject rights
- 5. Subprocessors
- 6. Personal data breaches
- 7. Audit rights
- 8. International data transfers
- 9. Deletion and return
- 10. Liability and indemnification
- 11. General
- Schedule 1 — Processing details
- Schedule 2 — Technical and organizational measures
1. Definitions
"Adequacy Decision" means a decision by the European Commission (or, for transfers from the UK or Switzerland, the competent UK or Swiss authority) that a country ensures an adequate level of data protection. "Customer Data" has the meaning given in the Terms. "Data Protection Law" means all data protection and privacy laws applicable to the Processing under this DPA, including the GDPR, UK GDPR, Swiss FADP, CCPA, and CPA. "Data Subject" means the identified or identifiable natural person to whom Personal Data relates. "Personal Data" has the meaning set out in applicable Data Protection Law. "SCCs" means the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, Module 2. "Service" means the SafeguardsMark software-as-a-service offering. "Subprocessor" means a third party engaged by Processor to process Personal Data on Customer's behalf.
2. Roles and scope
2.1 As between the parties, Customer is the controller of Personal Data within Customer Data. Processor processes Personal Data only as Customer's processor and on Customer's documented instructions.
2.2 The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are described in Schedule 1 below.
2.3 Processor will not process Personal Data for any purpose other than to provide the Service to Customer, except as required by law.
3. Processor's obligations
3.1 Compliance with instructions. Processor will process Personal Data only on Customer's documented instructions as set forth in this DPA, the Terms, and Customer's use of the Service.
3.2 Confidentiality. Persons authorized by Processor to process Personal Data are subject to a duty of confidentiality.
3.3 Security measures. Processor will implement appropriate technical and organizational measures described in Schedule 2.
3.4 Assistance to Customer. Processor will assist Customer in responding to Data Subject rights requests, notifying breaches, and (where required) conducting data protection impact assessments and consulting supervisory authorities.
3.5 Records of processing. Processor maintains records of processing activities as required by Article 30 GDPR.
4. Data subject rights
4.1 Where a Data Subject contacts Processor directly with a rights request, Processor will not respond substantively except to acknowledge receipt, will promptly forward the request to Customer (within 5 business days), and will reasonably assist Customer in responding.
4.2 Customer is responsible for verifying Data Subject identity and determining whether the request is valid and applicable.
4.3 Customer is solely responsible for responding to Data Subject requests forwarded under §4.1 within the time and manner required by applicable Data Protection Law.
5. Subprocessors
5.1 Customer authorizes Processor to engage Subprocessors. The current list is at safeguardsmark.com/subprocessors.
5.2 Processor will impose contractual obligations on each Subprocessor no less protective in substance than this DPA with respect to security, confidentiality, and assistance to Customer.
5.3 Processor will notify Customer in writing at least 30 days before adding or replacing a Subprocessor, by emailing the account's designated contacts (or by in-product notice) and by posting the change on the subprocessor list. Customer may object on reasonable data-protection grounds within 30 days of notice. A timely objection suspends the objected-to Subprocessor for that Customer while unresolved; if unresolved after 15 days, Customer may terminate the affected subscription with a pro rata refund of prepaid fees.
5.4 Where a Subprocessor must be replaced immediately for reasons beyond Processor's reasonable control, Processor may engage a replacement without advance notice and will post and email notice without undue delay; the objection right then runs from that notice.
5.5 Processor remains liable to Customer for the acts and omissions of its Subprocessors to the same extent as if Processor performed the Processing itself.
6. Personal data breaches
6.1 Processor will notify Customer without undue delay, and in any event within five (5) business days of becoming aware, of a Personal Data Breach affecting Customer's Personal Data; where the strictest applicable state breach-notification law requires Customer to act sooner, Processor will use commercially reasonable efforts to notify within whatever shorter period Customer needs.
6.2 The notice will include, to the extent reasonably known: the nature of the breach and categories/approximate number of Data Subjects and records affected; likely consequences; measures taken or proposed; and a point of contact.
6.3 Processor will cooperate with Customer's investigation and provide reasonably necessary information.
7. Audit rights
7.1 On at least 30 days' written notice (or sooner for a breach-related emergency), Customer may verify Processor's compliance with this DPA by (a) reviewing Processor's security-posture documentation (or SOC 2 report, once one exists) under NDA; (b) a written questionnaire Processor will answer within 30 days; or (c) for material verified deficiencies not addressed within 60 days, an on-site audit by a mutually agreed independent auditor at Customer's expense, not more than once in any 12-month period.
7.2 Customer may not access another customer's data, Processor's source code, or data that would breach Processor's confidentiality obligations to third parties.
7.3 For a Customer whose Personal Data is transferred under the SCCs or the UK Addendum incorporated at §8, nothing in this §7 limits that Customer's audit rights under Clause 8.9 of the SCCs; such a request is satisfied first by §7.1(a) and the relevant Subprocessors' audit reports under NDA, with a further Clause 8.9 inspection on reasonable notice, during business hours, and at Customer's expense except where the audit reveals material non-compliance.
8. International data transfers
8.1 Where Processor's processing of Personal Data subject to the GDPR or UK GDPR involves transfer outside the EEA, UK, or Switzerland to a country without an Adequacy Decision, the SCCs (Module 2) and UK Addendum are incorporated into this DPA by reference (Clause 9 Subprocessors: Option 2, general authorization with notice per §5; Clause 17 governing law and Clause 18 forum: Ireland; Annex I.B: Schedule 1; Annex II: Schedule 2).
8.2 For transfers subject to the UK GDPR, the UK Addendum's mandatory clauses govern in place of Clauses 17–18, so those transfers are governed by the laws of England and Wales.
8.3 Where processing is subject to the Swiss FADP, the SCCs apply with FADP-equivalent adaptations, including the Swiss FDPIC as competent authority and Swiss courts available to Swiss Data Subjects.
9. Deletion and return
9.1 Upon Customer's written request, Processor will delete or return Personal Data within 30 days of the request, except as required by law to retain. Upon termination of the Terms, absent such a request, Processor will retain Personal Data for 24 months following termination, to preserve an evidentiary and statutory record-keeping basis, and will thereafter delete or return it within 30 days.
9.2 Customer may export Personal Data via in-product export tooling at any time during the subscription — this is how the Customer's document vault (issued WISPs, risk assessments) is retrieved.
9.3 Personal Data deleted under §9.1 may persist briefly in Processor's Subprocessors' backup or system logs consistent with each Subprocessor's own retention practice before those copies are purged; this does not extend the periods in §9.1.
10. Liability and indemnification
10.1 Each party's liability under this DPA is subject to the limitation of liability in the Terms.
10.2 Notwithstanding §10.1, neither party's limitation of liability applies to any finding, inquiry, investigation, or fine by any regulatory or enforcement body arising from a violation of applicable Data Protection Law.
10.3 Customer indemnity — stated in the executed instrument. Customer's indemnity for a failure to timely or properly respond to a Data Subject request forwarded under §4.1, and every other indemnity obligation between the parties, is stated in full on the face of the executed SafeguardsMark Engagement & Tiers SOW / Order Form (the click-signed instrument you accept). Those provisions govern; this §10.3 is a cross-reference and does not restate or enlarge them.
11. General
11.1 Conflict. In case of conflict between the Terms and this DPA, the DPA controls for matters within its scope.
11.2 Term. This DPA remains in force while Processor processes Customer's Personal Data and survives termination for the period required by §9.
11.3 Governing law. Same as the Terms, except where the SCCs or applicable Data Protection Law specifies otherwise.
Schedule 1 — Processing details
Subject matter. Processor's provision of the SafeguardsMark WISP-builder Service to Customer.
Nature and purpose. Hosting, storage, and processing of the business-profile and WISP-builder inputs Customer declares, so that Processor can generate, seal, and retain Written Information Security Programs and related risk-assessment and service-provider-inventory records on Customer's behalf.
Duration. The term of the subscription, plus the retention period in §9.1.
Categories of Data Subjects. Customer's own personnel only — account holders, the named Qualified Individual, and the incident-response contact. SafeguardsMark's Service does not process personal data of the Customer's own customers or of any natural person outside Customer's staff (see Privacy Policy §1).
Categories of Personal Data. Name, business email, job title, and (for the incident-response contact) phone number.
Schedule 2 — Technical and organizational measures
Customer data is stored on encrypted infrastructure (disk-level encryption at rest) and served exclusively over TLS with authenticated, least-privilege access; we operate automated health monitoring, with independent external uptime monitoring being brought online ahead of launch.
- Per-tenant data isolation (flat multi-tenancy — every tenant-scoped read/write routes through tenant-scoping helpers that raise if the scope is missing)
- Annual security review and remediation
- Personnel confidentiality obligations and security training
- Subprocessor due diligence and contractual obligations
- Incident response procedures with a breach-notification commitment of five (5) business days of becoming aware