Data Processing Addendum
This Data Processing Addendum (this “DPA”) forms part of, and is incorporated into, the Terms of Service between the Merchant and ComplyRUO. It applies where and to the extent ComplyRUO processes personal data of a Merchant’s Buyers on the Merchant’s behalf in connection with the Service. With respect to that personal data, the Merchant is the controller (or business) and ComplyRUO, which means Cevgate LLC, an Arizona limited liability company, doing business as ComplyRUO, is the processor (or service provider). Capitalized terms not defined here have the meanings given in the Terms of Service.
Contents
- Definitions and roles
- Processing on documented instructions
- Confidentiality
- Security measures
- Subprocessors
- Data subject requests
- Personal data breach
- International transfers
- Audits
- Return and deletion
- CCPA and CPRA service-provider terms
- Liability and order of precedence
- Annex 1: Description of the processing
- Annex 2: Technical and organizational security measures
- Contact
1.Definitions and roles
In this DPA: “ComplyRUO,” the “Service,” the “Company,” “we,” “us,” or “our” means Cevgate LLC, an Arizona limited liability company, doing business as ComplyRUO. “Merchant,” “you,” or “your” means the business that uses ComplyRUO. “Buyer” means the Merchant’s end customer, a research counterparty.
“Data Protection Laws” means all laws and regulations applicable to the processing of personal data under this DPA, including, as applicable, Regulation (EU) 2016/679 (the “GDPR”), the GDPR as it forms part of the law of the United Kingdom (the “UK GDPR”) together with the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (the “Swiss FADP”), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”). Terms such as “personal data,” “processing,” “controller,” “processor,” “data subject,” and “supervisory authority” have the meanings given in the GDPR, and terms such as “business,” “service provider,” “sell,” “share,” and “personal information” have the meanings given in the CCPA. References to “personal data” in this DPA include “personal information” under the CCPA. “SCCs” means the Standard Contractual Clauses defined in Section 8.
1.1 Roles of the parties
With respect to personal data of the Merchant’s Buyers processed by ComplyRUO under this DPA, the Merchant is the controller (and, under the CCPA, the business) and ComplyRUO is the processor (and, under the CCPA, the service provider). ComplyRUO processes such personal data only on the Merchant’s behalf. Where the Merchant is itself a processor acting on behalf of a third-party controller, the Merchant is the controller as between the Merchant and ComplyRUO for the purposes of this DPA, ComplyRUO acts as the Merchant’s subprocessor, and the Merchant warrants that it has the authority and instructions of that third-party controller to engage ComplyRUO on the terms of this DPA. This DPA does not apply to personal data for which ComplyRUO is itself a controller, such as the Merchant’s own account, billing, and support data, which is governed by the Privacy Policy.
1.2 Nature and purpose of processing
ComplyRUO processes Buyer personal data for the limited purpose of providing the Service to the Merchant, namely operating the researcher gate (collecting and validating the Buyer’s intended-use attestation before checkout) and producing and maintaining the resulting attestation records on the Merchant’s behalf. ComplyRUO also processes such personal data as needed to secure, support, and maintain the Service and to comply with applicable law. The full description of the processing required for the SCCs is set out in Annex 1.
1.3 Categories of data subjects and personal data
The categories of data subjects are the Merchant’s Buyers, that is, the research counterparties who interact with the gate. The categories of personal data are those the Buyer or the Merchant’s site submits through the gate, which may include:
- identity details (such as name, business or institution name, and email address);
- counterparty type (the category of research counterparty the Buyer identifies);
- the Buyer’s intended-use attestation (the statements the Buyer affirms at the gate);
- a drawn or typed signature, where the gate captures one;
- the date and time (timestamp) of the attestation;
- the Internet Protocol (IP) address from which the attestation was made; and
- cryptographic hashes and integrity values derived from the above to make the record tamper-evident.
ComplyRUO does not request or require special categories of personal data (sensitive data) for this purpose. The duration of processing is the term of the Merchant’s use of the Service, plus any period during which records are retained as described in Section 10. The details in this Section are restated, in the structured form required for the SCCs, in Annex 1.
2.Processing on documented instructions
ComplyRUO processes Buyer personal data only on the Merchant’s documented instructions, including with regard to international transfers, unless ComplyRUO is required to process otherwise by applicable law, in which case ComplyRUO will inform the Merchant of that legal requirement before processing unless the law prohibits such notice on important grounds of public interest. The Merchant’s documented instructions are set out in the Terms of Service, in this DPA, and in the Merchant’s configuration and use of the Service (including the settings the Merchant selects for the gate). ComplyRUO may also process such personal data as reasonably necessary to provide, secure, support, and maintain the Service and to comply with applicable law.
The Merchant is responsible for ensuring that its instructions and its collection and processing of Buyer personal data comply with applicable law, that it has a valid legal basis for the processing, and that it has provided any required notices to, and obtained any required consents from, its Buyers. If ComplyRUO becomes aware that an instruction infringes applicable Data Protection Laws, it will inform the Merchant, and ComplyRUO may suspend the affected processing until the instruction is confirmed, corrected, or withdrawn.
2.1 Merchant downstream use of exported Buyer data
The Merchant, as controller, may export, download, or otherwise receive Buyer personal data from the Service. The Merchant must not use, retain, disclose, sell, share, or otherwise process any such exported Buyer personal data for any purpose outside the lawful purposes that the Merchant disclosed to its Buyers and that are permitted under applicable Data Protection Laws and the privacy notice the Merchant provided to those Buyers. Once Buyer personal data leaves the Service into the Merchant’s own systems or control, the Merchant is the sole controller of, and is solely responsible for, that data and its subsequent processing. The Merchant’s breach of this Section is a breach of the Terms of Service and is subject to the Merchant’s indemnification obligations set out in the Terms of Service, under which the Merchant will defend, indemnify, and hold harmless ComplyRUO (Cevgate LLC) from claims arising out of the Merchant’s unlawful or unauthorized processing of Buyer personal data. Nothing in this DPA limits the Merchant’s direct responsibilities or liability as controller under applicable law. Notwithstanding any limitation of liability in the Terms of Service or in Section 12, where Article 28(4) of the GDPR or any other applicable law imposes full-chain or joint responsibility on a party in respect of the entire processing chain (including the acts and omissions of subprocessors or of the controller), that responsibility applies to the extent the law so requires and may not be contracted away by the liability cap as against data subjects or supervisory authorities.
3.Confidentiality
ComplyRUO ensures that personnel authorized to process Buyer personal data are bound by appropriate obligations of confidentiality, whether by a contractual duty or a statutory duty, and that access to such personal data is limited to personnel who need it to perform their duties in connection with the Service. These confidentiality obligations survive the end of the relevant person’s engagement with ComplyRUO.
4.Security measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects, ComplyRUO implements and maintains appropriate technical and organizational measures designed to protect Buyer personal data against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access. These measures include, as appropriate:
- encryption of personal data in transit;
- cryptographic hashing of attestation records to make them tamper-evident;
- role-based access controls and the principle of least privilege;
- masking or truncation of identifying values where full values are not needed to operate the gate;
- logging and monitoring of access to and processing of personal data;
- measures to maintain the confidentiality, integrity, availability, and resilience of the systems used to provide the Service; and
- procedures for regularly reviewing and, where appropriate, improving the effectiveness of these measures.
The technical and organizational measures are described in full, in the structured form required for the SCCs, in Annex 2. ComplyRUO may update its security measures from time to time, provided that any such update does not materially reduce the overall level of protection for Buyer personal data.
5.Subprocessors
The Merchant grants ComplyRUO general written authorization to engage subprocessors to process Buyer personal data in connection with the Service. The subprocessors currently engaged are listed at /legal/subprocessors and currently include Cloudflare (hosting, content delivery, and network security), Stripe (payment processing), Resend (transactional email), and Anthropic (assisted compliance review). The list at that page, as updated from time to time, is incorporated into this DPA.
Before a subprocessor processes Buyer personal data, ComplyRUO imposes on that subprocessor, by a written agreement, data-protection obligations that are substantially equivalent to those set out in this DPA, to the extent applicable to the services the subprocessor provides, including the international-transfer safeguards in Section 8 where the subprocessor processes personal data outside the country of origin, and the incident-notification, pass-through, and remedy obligations set out in Section 7.1. ComplyRUO remains responsible to the Merchant for the performance of each subprocessor’s obligations.
5.1 Changes, notice period, and right to object
ComplyRUO will provide notice of the addition or replacement of a subprocessor that will process Buyer personal data by updating the list at /legal/subprocessors and, where the Merchant has subscribed to receive such notices, by email to the address on file. ComplyRUO will provide that notice commonly at least thirty (30) days before the new subprocessor begins processing Buyer personal data, except where a shorter period is reasonably required to address a security, legal, or service-continuity need, in which case ComplyRUO will give as much notice as is reasonably practicable. The Merchant may object, on reasonable data-protection grounds, to a new subprocessor by notifying ComplyRUO at support@complyruo.com within the notice period (commonly within thirty (30) days after the notice is given). The parties will work in good faith to resolve the objection, which may include ComplyRUO offering a commercially reasonable alternative or additional safeguards. If the parties cannot resolve it within a reasonable time, the Merchant may, as its sole and exclusive remedy, terminate the affected portion of the Service in accordance with the Terms of Service. If the Merchant does not object within the notice period, the Merchant is deemed to have authorized the new subprocessor.
6.Data subject requests
Taking into account the nature of the processing, ComplyRUO will provide reasonable assistance to the Merchant, by appropriate technical and organizational measures and insofar as this is possible, to enable the Merchant to respond to requests from data subjects to exercise their rights under Data Protection Laws, such as rights of access, rectification, erasure, restriction, portability, and objection. If ComplyRUO receives such a request directly from a Buyer, it will, unless legally required to act, promptly direct the Buyer to the Merchant and may inform the Buyer that the request should be directed to the Merchant, without otherwise responding to the substance of the request. The Merchant is responsible for responding to data subject requests and for verifying the identity of the requester. ComplyRUO will acknowledge and begin providing the assistance described in this Section within ten (10) business days after receiving the Merchant’s written request for assistance with a verified data subject request, and will complete that assistance as promptly as reasonably practicable thereafter and in any event in sufficient time to allow the Merchant to meet its own statutory response deadline.
7.Personal data breach
ComplyRUO will notify the Merchant of a personal data breach affecting Buyer personal data processed under this DPA without undue delay and in any event within seventy-two (72) hours after ComplyRUO becomes aware of the breach. This fixed seventy-two (72) hour processor-side notification commitment is consistent with the controller notification timeline under Article 33 of the GDPR and with the breach-notification expectations of Arizona law, including A.R.S. § 18-552. The notification will, to the extent then known and as it becomes available, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it; where it is not possible to provide all such information within the seventy-two (72) hour period, ComplyRUO will provide the information then available within that period and will supply the remaining information in phases without further undue delay as it becomes available. ComplyRUO will provide the Merchant with reasonable information and cooperation to assist the Merchant in meeting any obligations it may have to notify supervisory authorities or affected data subjects within their own legal deadlines. ComplyRUO’s notification is not, and may not be construed as, an acknowledgment by ComplyRUO of any fault or liability with respect to the breach.
7.1 Subprocessor incident notification and pass-through
ComplyRUO requires each subprocessor, by written agreement, to notify ComplyRUO of any personal data breach or security incident affecting Buyer personal data without undue delay and in any event within forty-eight (48) hours after the subprocessor becomes aware of it, so that ComplyRUO can meet the seventy-two (72) hour commitment in this Section. ComplyRUO will pass through to the Merchant the relevant incident documentation it receives from a subprocessor, to the extent it lawfully may, and will use commercially reasonable efforts to pursue, on the Merchant’s behalf, the remedies available to ComplyRUO against the responsible subprocessor under the applicable subprocessor agreement.
8.International transfers
Where ComplyRUO processes Buyer personal data originating from the European Economic Area, the United Kingdom, or Switzerland and transfers it to a country that has not received an adequacy decision applicable to the transfer, the parties agree that the following safeguards apply to the extent required by Data Protection Laws:
- the Standard Contractual Clauses approved by the European Commission under Implementing Decision (EU) 2021/914 (the “SCCs”) are incorporated into this DPA by reference, with the Merchant as data exporter and ComplyRUO as data importer;
- for transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the SCCs, issued by the United Kingdom Information Commissioner (the “UK Addendum” or “UK IDTA”), is incorporated by reference; and
- for transfers subject to Swiss data protection law, the SCCs apply with the adjustments necessary under that law as described in Section 8.3.
8.1 Module selection
The SCCs apply by module according to the roles of the parties for the relevant transfer:
- Module Two (controller to processor) applies where the Merchant acts as a controller of the Buyer personal data and ComplyRUO acts as the Merchant’s processor. This is the ordinary case under this DPA; and
- Module Three (processor to processor) applies where the Merchant acts as a processor on behalf of a third-party controller (as described in Section 1.1) and ComplyRUO acts as the Merchant’s subprocessor. In that case the references in the SCCs to the controller’s instructions are read as the instructions of that third-party controller as relayed through the Merchant.
Where ComplyRUO transfers Buyer personal data to a subprocessor located in a country without an applicable adequacy decision, the onward processor-to-processor transfer is likewise covered by the SCCs (and, where applicable, the UK Addendum) on the basis selected in this Section.
8.2 Elections within the SCCs
For both modules, and to the extent the SCCs require the parties to make elections, the parties agree as follows:
- the optional docking clause in Clause 7 applies;
- for Clause 9 (use of subprocessors), Option 2 (general written authorization) applies, with the change-notice period set out in Section 5.1 of this DPA;
- the optional independent dispute-resolution and redress mechanism in Clause 11 does not apply;
- for Clause 17 (governing law), the SCCs are governed by the law of a permitted European Union member state, namely Ireland, except where a different member-state law is required for the transfer in question, in which case that law applies;
- for Clause 18 (choice of forum and jurisdiction), disputes arising from the SCCs are resolved before the courts of the member state whose law governs the SCCs under Clause 17; this is solely for the purposes of the SCCs and does not alter the governing-law, arbitration, and venue provisions of the Terms of Service, which are Arizona and which otherwise control as between the parties to the fullest extent permitted by law;
- the audit and inspection rights afforded to the data exporter under the SCCs are exercised through, and are satisfied by, the audit process set out in Section 9 of this DPA; and
- the description of the transfer, the parties, the categories of data and data subjects, the frequency of the transfer, the safeguards, and the competent supervisory authority required by Annex I to the SCCs are populated by Annex 1, and the technical and organizational measures required by Annex II to the SCCs are populated by Annex 2.
8.3 UK and Swiss adaptations
For transfers subject to the UK GDPR, the UK Addendum amends and incorporates the SCCs as set out in that Addendum; the information required by Tables 1 to 3 of the UK Addendum is taken from Annex 1 and Annex 2 of this DPA, and the start date is the effective date of this DPA. For transfers subject to Swiss data protection law, the SCCs apply with the following adaptations: references to the GDPR are read as references to the Swiss FADP to the extent the processing is governed by Swiss law; the term “member state” is read so as not to exclude data subjects in Switzerland from exercising their rights in their place of habitual residence; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (the “FDPIC”) with respect to data transfers governed by Swiss law; and, until the entry into force of the revised Swiss FADP, the SCCs also protect the personal data of legal entities to the extent required by Swiss law.
8.4 Where a separate mechanism is completed
Where the parties have completed a separate transfer mechanism, that mechanism applies in addition to or instead of the foregoing as the parties agree. The relevant choices and details (such as the parties, the description of the processing, and the competent supervisory authority) are taken from this DPA, including Annex 1, and the Terms of Service.
9.Audits
ComplyRUO will make available to the Merchant information reasonably necessary to demonstrate compliance with the obligations set out in this DPA. Where an audit is required under Data Protection Laws, the parties will conduct it through a reasonable, confidential process designed to protect the security and confidentiality of ComplyRUO’s systems and of other customers’ data, and to avoid undue disruption. In the first instance, the Merchant’s right to audit is satisfied by ComplyRUO’s provision of relevant documentation and responses to a reasonable security questionnaire. Any further audit will be conducted at the Merchant’s expense, on reasonable advance written notice, during normal business hours, subject to confidentiality obligations, and not more than once in any twelve-month period, except where required by a supervisory authority or where the Merchant has a reasonable, good-faith belief of a material breach by ComplyRUO of this DPA. The audit and inspection rights afforded to the data exporter under the SCCs are exercised through, and are satisfied by, this Section.
10.Return and deletion
Upon termination of the Service, and at the Merchant’s written election, ComplyRUO will delete or return to the Merchant the Buyer personal data processed on the Merchant’s behalf within a reasonable period, and will delete existing copies, except to the extent retention is required by applicable law or is reasonably necessary to comply with legal, regulatory, or recordkeeping obligations.
The parties acknowledge that the attestation ledger serves the parties’ shared compliance interest: it is the tamper-evident record that the gate’s preventive measures operated, and it may be needed by either party to respond to inquiries from Stripe, the Card Networks, banks, or authorities. Accordingly, ComplyRUO may retain attestation records, in whole or in part and where appropriate in a hashed, masked, or otherwise minimized form, for as long as reasonably necessary for those compliance and legal-retention purposes.
10.1 Defined retention cap, basis, and erasure
Retention of attestation records is not indefinite. The retention basis is the parties’ legitimate compliance interest and the legal, regulatory, recordkeeping, and dispute-defense obligations described above (including responding to inquiries from Stripe, the Card Networks, banks, and authorities and defending chargebacks and claims). Retention is capped at seven (7) years from the date of the relevant attestation, except where a longer period is required by applicable law or is reasonably necessary to preserve evidence for a pending or reasonably anticipated legal claim, regulatory inquiry, or audit, in which case retention is limited to the period that need subsists. On expiry of the applicable retention period, or upon a valid erasure instruction from the Merchant once the retention basis for the relevant records has lapsed, ComplyRUO will erase the affected Buyer personal data, or irreversibly anonymize it so that it can no longer be attributed to a data subject, in the ordinary course and without undue delay. Personal data retained under this Section remains protected by the obligations of this DPA for as long as ComplyRUO holds it.
10.2 Certification of deletion or return
Upon the Merchant’s written request, ComplyRUO will provide written certification that it has deleted, or returned to the Merchant, the Buyer personal data processed on the Merchant’s behalf, except for personal data that ComplyRUO is permitted to retain under the legal-retention and attestation-ledger carve-outs set out above. Any personal data so retained remains protected by, and is processed only in accordance with, the obligations of this DPA for as long as ComplyRUO holds it, and ComplyRUO will delete it in the ordinary course when the retention purpose has been satisfied. The certification confirms the deletion or return that has occurred and does not require ComplyRUO to delete or return personal data that it is entitled or required to retain.
11.CCPA and CPRA service-provider terms
This Section applies to personal information subject to the CCPA. With respect to such personal information, ComplyRUO acts as a “service provider” to the Merchant. ComplyRUO:
- will not sell or share the personal information, as those terms are defined in the CCPA;
- will not retain, use, or disclose the personal information for any purpose other than the business purposes specified in this DPA and the Terms of Service, or as otherwise permitted by the CCPA, including not retaining, using, or disclosing it outside the direct business relationship between the parties;
- processes the personal information only for the limited and specified business purposes set out in this DPA, namely providing the Service to the Merchant, and not for any commercial purpose other than providing the Service;
- will not combine the personal information with personal information that it receives from, or on behalf of, another person, or that it collects from its own interaction with the data subject, except as permitted by the CCPA; and
- certifies that it understands and will comply with the restrictions in this Section.
Consistent with Annex 1, ComplyRUO does not collect or process sensitive personal information for the purpose of inferring characteristics about a data subject or for any other purpose that would give rise to a right to limit the use of sensitive personal information under the CCPA. ComplyRUO will notify the Merchant if it determines that it can no longer meet its obligations as a service provider under the CCPA. The Merchant may, upon reasonable notice, take reasonable and appropriate steps to stop and remediate any unauthorized use of personal information.
12.Liability and order of precedence
Each party’s liability arising out of or in connection with this DPA, whether in contract, tort, or any other theory, is subject to, and counts toward, the exclusions and the limitation of liability set out in the Terms of Service. Any reference to the liability of a party in this DPA means the aggregate liability of that party under the Terms of Service and this DPA together.
This DPA supplements the Terms of Service. In the event of a conflict between this DPA and the Terms of Service, this DPA prevails only on data-protection matters and only to the extent of the conflict; in all other respects, and on all other matters, the Terms of Service prevail. In the event of a conflict between this DPA (including its Annexes) and the SCCs or the UK Addendum incorporated under Section 8, those instruments prevail to the extent required by Data Protection Laws.
13.Annex 1: Description of the processing
This Annex 1 sets out the description of the processing required by Annex I.B to the SCCs and the corresponding tables of the UK Addendum, and it forms part of this DPA. The data exporter is the Merchant (acting as controller or, where Module Three applies, as processor for a third-party controller). The data importer is ComplyRUO, which means Cevgate LLC, an Arizona limited liability company, doing business as ComplyRUO. The contact point for both data-protection purposes is support@complyruo.com.
| Subject matter | The provision of the Service to the Merchant, namely the operation of the researcher gate (collecting and validating the Buyer’s intended-use attestation before checkout) and the production and maintenance of the resulting tamper-evident attestation records on the Merchant’s behalf. |
| Nature of the processing | Collection, recording, organization, structuring, storage, hashing, masking or truncation, consultation, use, transmission to subprocessors, retention, and erasure of Buyer personal data, carried out by automated means as part of the Service. |
| Purpose of the processing | Collecting and validating the Buyer’s intended-use attestation; producing and maintaining tamper-evident attestation records; securing, supporting, and maintaining the Service; and complying with applicable law. ComplyRUO does not process the personal data for any commercial purpose other than providing the Service. |
| Categories of data subjects | The Merchant’s Buyers, that is, the research counterparties who interact with the gate. |
| Categories of personal data | Identity details (such as name, business or institution name, and email address); counterparty type (the category of research counterparty the Buyer identifies); the Buyer’s intended-use attestation statements; a drawn or typed signature, where captured; the date and time (timestamp) of the attestation; the Internet Protocol (IP) address from which the attestation was made; and cryptographic hashes and integrity values derived from the above. |
| Special categories of data | None. ComplyRUO does not request or require special categories of personal data (sensitive data), and the Service is not designed to collect them, for this purpose. |
| Frequency of the transfer | Continuous, on each gate interaction, for the duration of the Merchant’s use of the Service. |
| Duration of the processing | The term of the Merchant’s use of the Service, plus any retention period applicable under Section 10 of this DPA (including retention of attestation records for compliance and legal-retention purposes). |
| Subprocessors | The subprocessors listed at /legal/subprocessors, as updated from time to time in accordance with Section 5, including (currently) Cloudflare, Stripe, Resend, and Anthropic. For each subprocessor, the subject matter, nature, and duration of the processing are as set out in this Annex 1 and limited to what is needed for the service that subprocessor provides. |
| Competent supervisory authority | For transfers governed by the GDPR, the supervisory authority of the relevant European Union member state (where the data exporter is established in the EEA, the supervisory authority of that member state; otherwise the supervisory authority determined in accordance with the SCCs, namely, where the Merchant has appointed an EU representative, the authority of the member state in which that representative is established). For transfers governed by the UK GDPR, the United Kingdom Information Commissioner’s Office. For transfers governed by Swiss law, the Swiss Federal Data Protection and Information Commissioner (FDPIC). |
14.Annex 2: Technical and organizational security measures
This Annex 2 sets out the technical and organizational measures required by Annex II to the SCCs, and it forms part of this DPA. It restates and expands the measures summarized in Section 4. ComplyRUO implements and maintains these measures taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects.
| Encryption | Encryption of personal data in transit using current, industry-standard transport encryption. Encryption at rest is applied unconditionally to all attestation records stored by ComplyRUO, including any drawn or typed signature captured at the gate, using current, industry-standard encryption. Encryption keys are managed under access controls separate from the encrypted data. |
| Logical segregation | Buyer personal data is logically segregated on a per-merchant basis, so that each Merchant’s attestation records and Buyer personal data are isolated from those of other Merchants by access controls and data-partitioning measures, and one Merchant cannot access another Merchant’s Buyer personal data. |
| Pseudonymization and minimization | Masking or truncation of identifying values where full values are not needed to operate the gate, and retention of attestation records in a hashed, masked, or otherwise minimized form where appropriate, consistent with Section 10. |
| Access control and least privilege | Role-based access controls and the principle of least privilege, so that access to personal data is limited to personnel and systems that need it to provide the Service, with authentication controls protecting administrative access. |
| Confidentiality of personnel | Personnel authorized to process personal data are bound by appropriate contractual or statutory obligations of confidentiality, which survive the end of their engagement, as set out in Section 3. |
| Integrity and tamper-evidence | Cryptographic hashing of attestation records and the derivation of integrity values, so that records are tamper-evident and unauthorized alteration can be detected. |
| Availability and resilience | Measures designed to maintain the availability and resilience of the systems used to provide the Service, including use of resilient hosting and content-delivery infrastructure and the ability to restore availability and access to personal data in a timely manner after an incident. |
| Logging and monitoring | Logging and monitoring of access to and processing of personal data, to support detection of and response to unauthorized or anomalous activity. |
| Incident and breach handling | Procedures for identifying, assessing, and responding to security incidents and personal data breaches, including notification to the Merchant without undue delay and the cooperation described in Section 7. |
| Subprocessor security | Flow-down of data-protection and security obligations substantially equivalent to those in this DPA to subprocessors before they process Buyer personal data, as set out in Section 5, including the international-transfer safeguards in Section 8 where applicable. |
| Testing and review | Procedures for regularly reviewing, and where appropriate testing and improving, the effectiveness of the technical and organizational measures. |
ComplyRUO may update these measures from time to time, provided that any such update does not materially reduce the overall level of protection for Buyer personal data.
15.Contact
Questions, notices, and requests relating to this DPA or to the processing of personal data may be sent to ComplyRUO at support@complyruo.com. For legal notices generally, see the notice provisions in the Terms of Service.