Data Processing Addendum
Introduction and Background
This Data Protection Agreement (this “DPA”) is entered into by and between Fermyon Inc., a Delaware C corporation doing business as LinkToAny (“LinkToAny,” “Processor,” or “Service Provider”), and [CUSTOMER LEGAL NAME], a [STATE/ENTITY TYPE] (“Customer”), each a “Party” and together the “Parties.”
This DPA is incorporated into and forms part of the master services agreement, subscription agreement, order form, or other written agreement governing LinkToAny’s provision of services to Customer (the “Agreement”). It governs LinkToAny’s Processing of Personal Information on Customer’s behalf in connection with LinkToAny’s data cleansing, automated migration, and embeddable integration services (the “Services”).
Background. LinkToAny provides commerce integration services to point-of-sale (“POS”) and commerce platforms (for example, Qu) and, through those platforms, to the platform’s restaurant and retail merchants. In delivering the Services, LinkToAny Processes Personal Information originating from a Customer platform, from the merchants served on that platform (each a “Merchant”), and from the Merchants’ own end customers (for example, diners). The Parties enter into this DPA to allocate their respective data protection responsibilities for such Processing.
Multi-tier roles. Where Customer is the entity that determines the purposes and means of Processing the Personal Information, Customer is the Business / Controller and LinkToAny is the Service Provider / Processor. Where Customer itself acts as a service provider or processor on behalf of its Merchants (or other third parties), Customer appoints LinkToAny as a Subprocessor, and Customer represents that it has authority and a lawful basis to make that appointment. LinkToAny’s obligations under this DPA run to Customer in either case.
1. Definitions
Capitalized terms not defined here have the meanings given in the Agreement or in Applicable Data Protection Law.
|
Applicable Data Protection Law |
All privacy and data protection laws applicable to the Processing under this DPA, including the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (collectively, the “CCPA/CPRA”) and its implementing regulations, and, to the extent applicable, other U.S. state privacy laws (for example, the Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana statutes). |
|
Business, Service Provider, Contractor, Consumer, Sell, Share, Process/Processing |
Have the meanings given in the CCPA/CPRA. |
|
Controller, Processor, Data Subject |
Have the meanings given in Applicable Data Protection Law; where the CCPA/CPRA applies, “Controller” maps to “Business,” “Processor” to “Service Provider,” and “Data Subject” to “Consumer.” |
|
Personal Information |
Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or household, that is Processed by LinkToAny on Customer’s behalf under the Agreement. Described further in Annex 1. |
|
Permitted Purpose |
The Business Purposes for which Customer discloses Personal Information to LinkToAny, namely performing the Services as set out in the Agreement and Annex 1, and as further instructed by Customer in writing. |
|
Security Incident |
A breach of LinkToAny’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Personal Information Processed by LinkToAny. Unsuccessful attempts and routine events that do not compromise Personal Information are not Security Incidents. |
|
Subprocessor |
Any third party engaged by LinkToAny to Process Personal Information on Customer’s behalf in connection with the Services. |
2. Roles of the Parties and Scope
- Roles. For the Processing under this DPA, Customer is the Business/Controller (or acts as a Processor/Service Provider for which LinkToAny is a Subprocessor, as described in the Introduction), and LinkToAny acts solely as a Service Provider/Processor.
- Subject matter and details. The subject matter, nature and purpose of the Processing, the types of Personal Information, and the categories of Data Subjects are described in Annex 1 (Details of Processing).
- No sensitive or payment data. The Services are not designed to Process, and Customer shall not provide to LinkToAny, full payment card numbers (PAN), card verification values, PINs, magnetic-stripe or chip data, payment tokens, account credentials, or any “sensitive personal information” as defined by the CCPA/CPRA (including government identifiers, precise geolocation, health, biometric, or financial account information). If Customer reasonably believes such data has been transmitted to LinkToAny, it shall notify LinkToAny promptly, and the Parties shall cooperate in good faith to securely delete it.
- Order of precedence. In the event of a conflict between this DPA and the Agreement regarding the Processing of Personal Information, this DPA controls. The Annexes form part of this DPA.
3. Customer Instructions and Processing Restrictions
- Documented instructions. LinkToAny shall Process Personal Information only for the Permitted Purpose and in accordance with Customer’s documented instructions, including those set out in this DPA, the Agreement, and Annex 1, except where otherwise required by law (in which case LinkToAny shall, unless legally prohibited, inform Customer of that requirement before Processing).
- No unauthorized use. LinkToAny shall not Sell or Share Personal Information; shall not retain, use, or disclose Personal Information for any purpose other than the Permitted Purpose, including outside the direct business relationship between the Parties; and shall not combine Personal Information received under the Agreement with Personal Information it receives from, or on behalf of, any third party, or collects from its own interactions with Consumers, except as permitted by the CCPA/CPRA to perform a Business Purpose.
- Lawfulness of instructions. As between the Parties, Customer is responsible for the accuracy and lawfulness of the Personal Information and of its Processing instructions, including having provided all required notices and obtained all required consents from Data Subjects.
- Notice of inability to comply. LinkToAny shall notify Customer if it makes a determination that it can no longer meet its obligations under Applicable Data Protection Law, and in such case Customer may take reasonable and appropriate steps to stop and remediate unauthorized Processing.
4. Confidentiality and Personnel
- Confidentiality. LinkToAny shall treat Personal Information as confidential and shall ensure that personnel authorized to Process Personal Information are bound by written confidentiality obligations or an appropriate statutory duty of confidentiality.
- Access limitation and training. LinkToAny shall limit access to Personal Information to personnel who require access to perform the Services, apply role-based access controls and the principle of least privilege, and provide regular data protection and security awareness training to such personnel.
5. Security of Processing
- Security measures. LinkToAny shall implement and maintain appropriate technical and organizational measures designed to protect Personal Information against a Security Incident, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing. A description of those measures is set out in Annex 2 (Technical and Organizational Measures).
- Evaluation. LinkToAny shall periodically review and, where appropriate, update its security measures, provided that no update shall materially reduce the overall level of protection during the term.
6. Hosting, Data Location, and Account Ownership Model
- Cloud infrastructure. The Services are hosted on Amazon Web Services (“AWS”). Personal Information Processed in connection with the Services is hosted in the AWS US-West (Oregon) region (us-west-2) in the United States, and LinkToAny shall configure the production environment so that Personal Information is stored at rest within that region. [CONFIRM region selection: us-west-2 (Oregon).]
- Account ownership and tenancy. The AWS account(s) and underlying cloud infrastructure used to deliver the Services are owned and controlled by LinkToAny. The Services operate on a multi-tenant basis in which Customer (and Merchant) data is logically separated from that of other LinkToAny customers through access controls, segregation of data records by tenant identifiers, and authentication boundaries. As between the Parties, Customer (or, as applicable, the Merchant) retains all right, title, and interest in and to the Personal Information; LinkToAny acquires no ownership rights in the Personal Information by virtue of hosting or Processing it.
- Logical isolation. LinkToAny shall maintain controls designed to prevent Personal Information associated with one tenant from being accessed by, or commingled with the data of, another tenant, except as necessary to perform the Services for the applicable Customer.
7. Subprocessors
- General authorization. Customer provides a general authorization for LinkToAny to engage the Subprocessors listed in Annex 3 (Approved Subprocessors), and to appoint replacement or additional Subprocessors, subject to this Section.
- Flow-down obligations. Before a Subprocessor Processes Personal Information, LinkToAny shall enter into a written contract with the Subprocessor that imposes data protection and security obligations no less protective than those in this DPA, including the CCPA/CPRA Service Provider restrictions in Section 12. LinkToAny remains responsible for the performance of each Subprocessor’s obligations.
- Notice and objection. LinkToAny shall notify Customer of any intended addition or replacement of a Subprocessor (for example, by updating Annex 3 or an online list and notifying Customer) with reasonable advance notice. Customer may object in writing on reasonable data protection grounds within [15] days of notice. The Parties shall work in good faith to resolve the objection; if they cannot, Customer may, as its sole remedy, terminate the affected Services in accordance with the Agreement.
8. Offshore Personnel and Remote Access
- Personnel in India. LinkToAny uses personnel and/or affiliated team members located in India to help deliver and support the Services. Such personnel may access Personal Information remotely for the Permitted Purpose (for example, integration configuration, data migration, quality assurance, and technical support).
- Data residency preserved. Remote access by offshore personnel is provided through the LinkToAny production environment hosted in the AWS US-West (Oregon) region. Personal Information is not stored, copied, or downloaded onto local devices or systems located outside that environment in the ordinary course, and LinkToAny shall maintain technical controls designed to prevent local export of Personal Information.
- Safeguards for offshore access. LinkToAny shall ensure that offshore personnel: (i) access Personal Information only through controlled, authenticated, and logged channels; (ii) are subject to role-based access controls and least-privilege provisioning; (iii) are bound by written confidentiality obligations; (iv) receive data protection and security training; and (v) are subject to the same CCPA/CPRA restrictions set out in Section 12, applied through LinkToAny’s internal policies and any applicable intra-group or contractor agreements.
- Compliance with U.S. law. LinkToAny acknowledges that remote access from India does not relieve it of its obligations under Applicable Data Protection Law with respect to U.S.-resident data, and it shall not disclose Personal Information to any government authority except as legally required and, where lawful, after notice to Customer.
9. Assistance with Data Subject and Consumer Requests
- Forwarding requests. Taking into account the nature of the Processing, LinkToAny shall promptly notify Customer if it receives a request from a Data Subject or Consumer to exercise rights under Applicable Data Protection Law (such as access, deletion, correction, or opt-out) relating to Personal Information Processed for Customer, and shall not respond to the request itself except to direct the individual to Customer or as instructed by Customer.
- Cooperation. LinkToAny shall provide reasonable assistance, including by appropriate technical and organizational measures, to enable Customer to fulfill its obligations to respond to such verifiable requests, and shall comply with reasonable instructions from Customer to give effect to a Consumer’s exercised rights to the extent the relevant Personal Information is within LinkToAny’s control.
10. Security Incident Notification
- Notification. LinkToAny shall notify Customer without undue delay, and in any event within [72] hours, after becoming aware of a Security Incident affecting Personal Information Processed for Customer.
- Contents and cooperation. The notification shall include, to the extent then known, the nature of the incident, the categories and approximate volume of Personal Information and Data Subjects affected, the likely consequences, and the measures taken or proposed to address it. LinkToAny shall provide reasonable cooperation and information to assist Customer in meeting Customer’s own breach notification and mitigation obligations. LinkToAny’s notification is not an acknowledgment of fault or liability.
11. Retention, Return, and Deletion
- Retention during the term. LinkToAny shall retain Personal Information only for as long as necessary to provide the Services or as otherwise instructed by Customer. Active Customer and Merchant data is retained for the duration of the term of the Agreement.
- Migration source data. Where the Services include a one-time or scheduled data migration, source Personal Information used for that migration shall be deleted within thirty (30) days after the applicable migration is completed and signed off by Customer, unless Customer instructs otherwise in writing.
- Backups and logs. Backups containing Personal Information are maintained on a rolling cycle and are overwritten or deleted within thirty-five (35) days. Operational and access logs are retained for ninety (90) days, after which they are deleted or de-identified, except where a longer period is required by law or to investigate a Security Incident.
- Return and deletion on termination. Upon expiry or termination of the Agreement, and upon Customer’s request made within thirty (30) days of such expiry or termination, LinkToAny shall return the Personal Information to Customer in a commercially reasonable format. LinkToAny shall then delete the Personal Information from its active production systems within thirty (30) days, and shall purge it from backups within ninety (90) days through the ordinary backup-rotation cycle. If Customer does not request return within the thirty (30)-day window, LinkToAny may proceed directly to deletion on the same timetable.
- Certification. Upon Customer’s written request, LinkToAny shall provide written certification that it has deleted the Personal Information in accordance with this Section.
- Legal retention exception. LinkToAny may retain Personal Information to the extent required by applicable law, provided that it continues to protect the Personal Information in accordance with this DPA and Processes it only for the purpose and duration of the legal requirement.
12. CCPA / CPRA Service Provider Obligations
This Section applies to Processing of Personal Information subject to the CCPA/CPRA. LinkToAny is a Service Provider with respect to such Personal Information and certifies that it understands and shall comply with the restrictions in this Section.
- Business Purpose only. LinkToAny shall Process Personal Information solely for the Permitted Purpose (the Business Purposes specified in the Agreement and Annex 1) and shall not retain, use, or disclose Personal Information for any purpose other than the specific Business Purposes set out in the Agreement, including outside the direct business relationship between LinkToAny and Customer, except as permitted by the CCPA/CPRA.
- No selling or sharing. LinkToAny shall not Sell or Share Personal Information and receives no monetary or other valuable consideration for Personal Information beyond the fees for the Services.
- No combining. LinkToAny shall not combine Personal Information it receives from or on behalf of Customer with Personal Information it receives from or on behalf of any other person, or collects from its own interaction with the Consumer, except as permitted by the CCPA/CPRA (for example, to perform a Business Purpose).
- No unauthorized retention. LinkToAny shall not retain, use, or disclose Personal Information outside the direct business relationship between the Parties, and shall not use it for the purpose of providing services to another person.
- Compliance and assistance. LinkToAny shall comply with applicable obligations under the CCPA/CPRA and shall provide the same level of privacy protection as required of a Business. LinkToAny shall reasonably assist Customer in responding to and complying with verifiable Consumer requests under Section 9, and with Customer’s obligations regarding security and data protection assessments.
- Customer oversight rights. Customer has the right, upon reasonable notice, to take reasonable and appropriate steps to help ensure that LinkToAny uses Personal Information in a manner consistent with Customer’s obligations under the CCPA/CPRA, and to take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information.
- Subcontractor flow-down. LinkToAny shall ensure that any Subprocessor (subcontractor) that Processes Personal Information is bound by a written contract requiring the same level of data protection and the same CCPA/CPRA restrictions imposed on LinkToAny under this Section.
- Notice of non-compliance. LinkToAny shall notify Customer if it determines that it can no longer meet its obligations under the CCPA/CPRA, after which Customer may exercise the remediation rights described above.
13. Other U.S. State Privacy Laws
- Catch-all. To the extent any other U.S. state privacy law applies to the Processing (for example, the privacy statutes of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or Montana), LinkToAny shall act as a “processor” (or equivalent role) and shall: Process Personal Information only on Customer’s documented instructions and for the Permitted Purpose; maintain confidentiality and appropriate security; assist Customer with data subject rights requests, security obligations, and data protection assessments as required; impose equivalent obligations on Subprocessors by written contract; and, on request, make available information reasonably necessary to demonstrate compliance. The specific obligations of each such statute are deemed incorporated to the extent applicable.
14. Records and Audit
- Demonstrating compliance. LinkToAny shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA. LinkToAny may satisfy this obligation by providing summaries of applicable third-party audit reports, security certifications, or completed security questionnaires.
- Audits. No more than once per twelve (12) month period (unless required by a regulator or following a Security Incident), and on reasonable prior written notice, Customer may audit LinkToAny’s compliance with this DPA, subject to reasonable confidentiality and security conditions and during normal business hours, in a manner that does not unreasonably disrupt LinkToAny’s operations.
15. General Data Handling
- Accounts and credentials. LinkToAny shall not create accounts on Customer’s behalf with third parties, and shall not require or store end-user banking details, full payment card data, or government identifiers as part of the Services.
- De-identified data. To the extent LinkToAny creates or Processes de-identified data, it shall maintain such data in de-identified form, shall not attempt to reidentify it except as permitted by law to test the effectiveness of de-identification, and shall contractually obligate recipients to comply with the same.
16. Liability
- Limitations. Each Party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference to a Party’s liability means the aggregate liability of that Party under the Agreement and this DPA together.
17. Term and Termination
- Duration. This DPA takes effect on the Effective Date and remains in force for as long as LinkToAny Processes Personal Information on Customer’s behalf under the Agreement. The obligations that by their nature should survive (including confidentiality, deletion, and CCPA/CPRA obligations) survive termination.
18. General
- Governing law. This DPA is governed by the governing law and dispute-resolution provisions of the Agreement. [CONFIRM: if the Agreement is silent, the Parties intend the laws of the State of Delaware to apply, without regard to conflict-of-laws rules.]
- Entire agreement; amendment. This DPA, together with the Agreement and its Annexes, constitutes the entire agreement of the Parties regarding the Processing of Personal Information and supersedes prior understandings on that subject. It may be amended only in a writing signed by both Parties, except that the Subprocessor list in Annex 3 may be updated in accordance with Section 7.
- Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force, and the invalid provision shall be modified to the minimum extent necessary to make it enforceable while preserving its intent.
- Counterparts. This DPA may be executed in counterparts, including by electronic signature, each of which is deemed an original and all of which together constitute one instrument.
IN WITNESS WHEREOF, the Parties have executed this DPA as of the Effective Date.
Fermyon Inc. (DBA LinkToAny)
By: ______________________________________
Name: ___________________________________
Title: ____________________________________
Date: ____________________________________
[CUSTOMER LEGAL NAME]
By: ______________________________________
Name: ___________________________________
Title: ____________________________________
Date: ____________________________________
Annex 1 — Details of Processing
|
Controller / Business |
[CUSTOMER LEGAL NAME] (and, where Customer acts as a processor/service provider, the relevant Merchant as the underlying Business). |
|
Processor / Service Provider |
Fermyon Inc. (DBA LinkToAny), a Delaware C corporation. |
|
Subject matter |
Provision of data cleansing, automated data migration, and embeddable integration services connecting the Customer platform and its Merchants to commerce systems (POS, ERP, CRM, payments, marketing, and inventory systems). |
|
Nature and purpose of Processing |
Collection, organization, structuring, cleansing/normalization, mapping, migration, storage, retrieval, transmission between integrated systems, and deletion of Personal Information, in order to deliver and support the Services. |
|
Categories of Data Subjects |
End customers of Merchants (for example, diners / retail customers); Merchant staff and authorized platform users (for example, restaurant employees, account administrators); Customer platform personnel acting as users of the Services. |
|
Categories of Personal Information |
Contact identifiers: name, email address, telephone number, billing/shipping or service address; Account/profile data: customer or staff account identifiers, usernames, role/permission attributes; Transactional and order data: order history, items, amounts, timestamps, store/location identifiers (excluding full payment card data); Loyalty / membership data: program identifiers, points, status, and related history; Limited payment-related references: last four digits and/or processor-generated transaction references only — NO full card numbers, PINs, tokens, or cardholder authentication data. |
|
Special / sensitive categories |
None. The Services do not Process “sensitive personal information” as defined by the CCPA/CPRA, and Customer shall not provide such data. |
|
Frequency of Processing |
Continuous and/or batch, as required to perform integrations and migrations during the term. |
|
Duration of Processing |
For the term of the Agreement, subject to the retention and deletion terms in Section 11. |
|
Hosting location |
AWS US-West (Oregon) region (us-west-2), United States. [CONFIRM] |
Annex 2 — Technical and Organizational Measures
LinkToAny maintains the following technical and organizational measures, which it may update provided the overall level of protection is not materially reduced.
|
Access control |
Role-based access control and least-privilege provisioning; Unique user accounts and multi-factor authentication for administrative access; Periodic access reviews and prompt deprovisioning of departed personnel. |
|
Encryption |
Encryption of Personal Information in transit (TLS) and at rest; Managed key handling within the AWS environment. |
|
Network and infrastructure security |
Segmentation and firewalling of the production environment; Hardening of hosts and services; vulnerability management and patching; Logging and monitoring of access and security-relevant events. |
|
Tenant isolation |
Logical separation of tenant data through access controls and tenant identifiers in a multi-tenant architecture. |
|
Data residency controls |
Production Personal Information stored at rest within AWS us-west-2; Controls designed to prevent local download/export by remote (including offshore) personnel. |
|
Resilience and recovery |
Backups on a rolling cycle (overwritten/deleted within ~35 days); Documented incident response and business continuity procedures. |
|
Organizational measures |
Confidentiality obligations for personnel; Security and privacy awareness training; Vendor/Subprocessor due diligence and contractual flow-down. |
Annex 3 — Approved Subprocessors
As of the Effective Date, LinkToAny engages the following Subprocessor(s). Additions or replacements are governed by Section 7.
|
Subprocessor |
Service / Purpose |
Location |
Notes |
|---|---|---|---|
|
Amazon Web Services, Inc. |
Cloud hosting and infrastructure for the Services |
United States (us-west-2, Oregon) |
Primary hosting environment |
|
Gitlab |
Source Control and CI/CD pipeline management |
United States |
|
|
PagerDuty |
Alerting, incident management, and operational response |
United States |
|
|
Prometheus |
Metrics collection and monitoring |
United States |
|
|
AWS IAM |
Identity and access management for cloud resources |
United States |
|
|
Hashicorp Vault |
Secure storage and management of application secrets, credentials, and tokens. |
United States |
|
|
Google (Gmail) |
Email Management |
United States |
Note on integrated systems: Third-party commerce systems that Customer or its Merchants connect to via the Services (e.g., Toast, Clover, Square, Shopify, NetSuite, Stripe, Revel, Oracle Micros, NCR, Lightspeed, Restaurant365) are independent recipients/sources determined by Customer or the Merchant, not LinkToAny Subprocessors, unless otherwise agreed in writing.