1. Purpose
This DPA supplements the service agreement when DFX processes personal data on the Customer's behalf for hosting, infrastructure, support, backups, maintenance, email, security, CRM, automation, or related services.
2. Roles
The Customer acts as controller or equivalent role and determines purposes and essential means. DFX acts as processor or service provider when following documented Customer instructions.
3. Instructions
DFX will process data only to deliver, secure, maintain, and support the contracted services, as documented in the agreement, tickets, and configurations.
4. Confidentiality
Personnel and contractors with access are subject to confidentiality and need-to-know restrictions.
5. Security measures
Depending on the service, measures may include access control, authentication, isolation, encryption in transit, backups, monitoring, logging, vulnerability management, antimalware, and incident procedures.
6. Subprocessors
The Customer generally authorizes DFX to use necessary data center, registrar, email, security, CDN, support, storage, and cloud providers.
7. International transfers
Data may be processed where DFX or its providers operate. The parties will cooperate on legally required transfer mechanisms.
8. Assistance
Considering the nature of processing, DFX will provide reasonable assistance with data subject requests, assessments, regulatory inquiries, or security matters. Extraordinary work may be billed.
9. Incidents
DFX will notify the Customer without undue delay after confirming a security incident affecting personal data processed on the Customer's behalf. Notice is not an admission of liability.
10. Return or deletion
Upon termination, data will be returned or deleted according to service functionality, Customer instructions, technical retention cycles, and legal obligations.
11. Audits
DFX will provide reasonably necessary compliance information. On-site audits require prior agreement, confidentiality, proportional scope, noninterference, and payment of costs unless legally required otherwise.
12. Customer responsibilities
The Customer is responsible for lawful basis, transparency, minimization, accuracy, data subject rights, and appropriate service configuration.
13. Processing description
Subject: contracted services. Duration: contract term and retention period. Operations: storage, transmission, support, backup, recovery, security, and deletion. Data subjects: Customer users, employees, contacts, and visitors. Data: information the Customer elects to submit.