Data Processing Addendum
Last updated: 2026-10-04.1. This is a template pending review by counsel and does not constitute legal advice.
This Data Processing Addendum ("DPA") forms part of the Terms of Service between SmartCloud USA Inc. ("Processor," "we") and Customer ("Controller," "you") and applies to our processing of personal data contained in Customer Data on your behalf. Where there is a conflict with the Terms regarding personal-data processing, this DPA controls.
1. Roles and Scope
For Customer Data, Customer is the controller and Provider is the processor (or, where applicable, sub-processor). We process personal data only to provide the Service and on Customer's documented instructions, including as set out in the Terms and this DPA, unless required by law (in which case we will inform you unless legally prohibited).
2. Nature and Purpose of Processing
Subject matter: provision of the Service. Duration: the term plus any post- termination export/deletion period. Nature and purpose: hosting, storage, transmission, and processing to operate, secure, and support the Service. Types of personal data: as determined by Customer (e.g. names, business contact details, account identifiers, user-submitted records). Data subjects: Customer's Authorized Users and the individuals reflected in Customer Data.
3. Tenant Isolation and Confidentiality
Each tenant's data is stored in a separate, logically isolated database, and the Service enforces tenant scoping so one tenant cannot access another's data. We ensure personnel authorized to process personal data are bound by appropriate confidentiality obligations.
4. Security Measures
We maintain administrative, technical, and physical safeguards designed to protect personal data appropriate to the risk, including: encryption of data in transit; access controls and least-privilege administration; network and application controls; per-tenant database isolation; logging and audit trails; and regular backups with offsite, encrypted disaster-recovery copies. We review and update these measures as the Service evolves.
5. Sub-processors
You authorize us to engage sub-processors to provide the Service (e.g. cloud hosting, managed databases, object storage, email, and payment processing). We impose data-protection obligations on sub-processors no less protective than this DPA and remain responsible for their performance. A current list of sub-processors is available on request, and we will give notice of intended changes with a reasonable opportunity to object on reasonable data-protection grounds.
6. International Transfers
Where personal data is transferred across borders, we will implement an appropriate transfer mechanism (e.g. Standard Contractual Clauses) where required by applicable law. [Counsel to attach/insert the applicable SCCs or transfer terms.]
7. Assistance to Controller
Taking into account the nature of processing, we will provide reasonable assistance to help you: (a) respond to data-subject requests (access, correction, deletion, portability, objection), including via the Service's export and deletion tools; (b) meet your security, breach-notification, and data- protection-impact-assessment obligations; and (c) consult with regulators where required.
8. Personal Data Breach
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, and provide information reasonably available to help you meet your notification obligations. Our notice is not an acknowledgement of fault or liability.
9. Return and Deletion
On termination or expiration, we will, at your option and within the period stated in the Terms, make Customer Data available for export and thereafter delete or anonymize it, except where retention is required by law. Backup copies are deleted on our standard rotation.
10. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and subject to confidentiality, allow for audits limited to relevant systems and conducted so as not to disrupt the Service. We may satisfy audit requests by providing third- party reports or certifications where available.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms.