Data Processing Addendum

This Data Processing Addendum (this “DPA”) is entered into by and between CJB Consulting Ltd. (hereafter “Processor”), and Controller. This DPA supplements the Master Agreement.

  • 1. Definitions

For the purposes of this DPA, the following terms have the meanings set out below:

Applicable Data Protection Laws” means all laws and regulations relating to data protection, privacy, or the processing of Personal Data that apply to the Processing contemplated by this DPA, including (as applicable): (a) the GDPR; (b) the UK GDPR; (c) the CCPA and other comparable US state privacy laws in force from time to time; and (d) PIPEDA, and any other applicable Canadian federal, provincial or territorial privacy legislation.

CCPA” means the California Consumer Privacy Act of 2018, Cal. Civ. Code §§ 1798.100–1798.199.100, as amended by the California Privacy Rights Act of 2020 (CPRA), and any implementing regulations thereunder.

Controller” means the entity that has entered into the Master Agreement with Processor.

Data Subject” means an identified or identifiable individual whose Personal Data is Processed, including (where protected under Applicable Data Protection Laws) a household or consumer.

EEA” means the European Economic Area (comprising the EU Member States together with Iceland, Liechtenstein, and Norway).

GDPR” means Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.

Master Agreement” means the principal agreement between the parties governing the provision of the Services (e.g., Terms of Service, Subscription Agreement, EULA).

Personal Data” means any data or information that: (a) is linked or reasonably linkable to an identified or identifiable natural person; or (b) is otherwise “personal data”, “personal information”, “personally identifiable information”, or similarly defined data under Applicable Data Protection Laws.

PIPEDA” means the Personal Information Protection and Electronic Documents Act. S.C. 2000, c. 5.

Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means. “Process”, “Processes”, and “Processed” are interpreted accordingly.

Personal Data Breach means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Personal Data transmitted, stored, or otherwise Processed by the Processor on behalf of the Controller.

SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as may be amended, supplemented, or replaced from time to time.

Services means the quality management software services provided by the Processor under the Master Agreement.

Sub-processor” means any third party engaged by the Processor to carry out Processing activities in connection with the Services.

Third Country” means a country outside the EEA which has not been the subject of an adequacy decision by the European Commission pursuant to Article 45 of the GDPR.

UK GDPR” means the General Data Protection Regulation ((EU) 2016/679) as it forms part of domestic law in the United Kingdom by virtue of Section 3 of the European Union (Withdrawal) Act 2018, as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419), and as supplemented by the Data Protection Act 2018.

  • 2. Scope and Duration
    • 2.1. Precedence. This DPA is incorporated into, and forms an integral part of, the Master Agreement. To the extent of any conflict or inconsistency between this DPA and the Master Agreement regarding the Processing of Personal Data, the terms of this DPA shall prevail.
    • 2.2. Term. This DPA shall take effect on the date on which the Master Agreement comes into force and shall continue in full force and effect for so long as the Processor Processes Personal Data on behalf of the Controller in connection with the Services. This DPA shall terminate automatically upon the earlier of: (a) the expiry or termination of the Master Agreement; or (b) the cessation of all Processing of Personal Data by the Processor under this DPA, in each case subject to any obligations that, by their nature, survive termination.
    • 2.3. Roles and Applicable Definitions. For the purposes of this DPA, the parties’ roles and the applicable statutory definitions are as follows:
      • (a) to the extent that the GDPR or the UK GDPR applies to the Processing of Personal Data under this DPA, the Controller is a “controller” and the Processor is a “processor”, each as defined in Article 4 of the GDPR or (as applicable) the UK GDPR;
      • (b) to the extent that the CCPA applies to the Processing of Personal Data under this DPA, the Controller is a “Business” and the Processor is a “Service Provider”, each as defined in California Civil Code § 1798.140;
      • (c) where a provision of this DPA is specific to a particular data protection regime, that provision shall apply only to the extent that the relevant regime governs the Processing activity in question;
      • (d) any Processing operation described in Section 4 and Schedule 1 of this DPA shall be subject to the terms of this DPA; and
      • (e) any reference to a statute, regulation, or other enactment includes that statute, regulation, or enactment as amended, re-enacted, consolidated, or replaced from time to time.
  • 3. Controller Obligations
    • 3.1. Representations and Warranties. The Controller represents and warrants that it:
      • (a) shall comply with all Applicable Data Protection Laws in connection with its use of the Services and the Processing of Personal Data pursuant to this DPA;
      • (b) has established and shall maintain a lawful basis under Applicable Data Protection Laws for each category of Personal Data transferred to the Processor, including, where required, obtaining valid consent from Data Subjects;
      • (c) has provided, and shall continue to provide, Data Subjects with all requisite privacy notices in accordance with Applicable Data Protection Laws, including transparent disclosure of the Processor’s role in Processing their Personal Data;
      • (d) shall ensure that all instructions issued to the Processor regarding the Processing of Personal Data comply with Applicable Data Protection Laws at all times; and
      • (e) shall promptly notify the Processor of any changes to its Processing instructions that may affect the Processor’s obligations under this DPA.
    • 3.2. Regulatory Compliance. Where the Controller is subject to a specific regulatory framework governing the Processing of Personal Data (including, without limitation, the GDPR or the UK GDPR), the Controller shall be solely responsible for satisfying itself that the Processor’s Processing activities and technical and organizational measures described in this DPA are sufficient to meet the Controller’s obligations under that framework.
    • 3.3. Suspension and Termination for Data Protection Breach. Without prejudice to any other rights or remedies available under this DPA or the Master Agreement, the Controller may:
      • (a) suspend the transfer of Personal Data to the Processor where the Controller reasonably determines that the Processor is in material breach of its obligations under this DPA and such breach, if continuing, would result in a risk to the rights and freedoms of Data Subjects; and
      • (b) terminate the Master Agreement immediately on written notice to the Processor where: (i) the Processor fails to remedy a material breach of this DPA within thirty (30) days of receiving written notice from the Controller specifying the breach and requiring its remedy; or (ii) a competent supervisory authority orders the cessation of Processing by the Processor.
  • 4. Details of Processing
    • 4.1. Permitted Processing. The Processor shall Process Personal Data only for the following purposes:
      • (a) providing the Services to the Controller, including the operation of the Isolocity QMS platform, as further described in Schedule 1;
      • (b) complying with legal obligations applicable to the Processor;
      • (c) enforcing the terms of the Master Agreement;
      • (d) maintaining, securing, and ensuring the continued availability of the Services;
      • (e) any other purpose expressly authorized in writing by the Controller or expressly consented to by the Data Subject.
    • 4.2. Controller Instructions. The Processor shall Process Personal Data only on behalf of and in accordance with the documented instructions of the Controller, and in compliance with Applicable Data Protection Laws. The Master Agreement and this DPA constitute the Controller’s complete documented instructions for the Processing of Personal Data as at the date of this DPA. The Controller may issue additional or amended written instructions in accordance with the terms of this DPA, provided that such instructions are consistent with the terms of the Master Agreement and Applicable Data Protection Laws. Where the Processor reasonably believes that any instruction received from the Controller infringes Applicable Data Protection Laws, the Processor shall promptly notify the Controller in writing before carrying out the relevant Processing, unless prohibited by law from doing so.
    • 4.3. Description of Processing Activities. The categories of Personal Data Processed and the purposes for which they are Processed are set out in the table below:
      Category Data Types Purpose
      User Data Name, email address, postal address, telephone number, and other personal details provided by the user. Service provision, account management, and support. Where consented, promotional and marketing communications.
      Usage Data Location, IP address, browser type, operating system, and device identifiers. Analytics, security monitoring, platform improvement, and detecting interference.
      Billing Data (if applicable) Payment method details, billing address, and transaction history. Invoicing and subscription management.
    • 4.4. Internal Access Controls. Personal Data shall be accessible internally only to those members of the Processor’s staff who require access in order to perform their duties in connection with the Services, including staff in operations, product development, customer success, and finance functions. The Processor shall ensure that all such personnel are subject to appropriate obligations of confidentiality.
    • 4.5. Special Categories of Personal Data. The Processor shall not Process special categories of Personal Data (including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic data, biometric data for the purposes of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation, or data relating to criminal convictions and offences) unless: (a) expressly authorized in writing by the Controller in advance; and (b) the parties have agreed in writing on appropriate supplementary technical and organizational safeguards prior to any such Processing.
    • 4.6. Categories of Data Subjects. The categories of Data Subjects whose Personal Data may be Processed under this DPA include employees, contractors, and authorized users of the Controller who access or use the Services.
    • 4.7. Restriction on Secondary Use of Personal Data. For the avoidance of doubt, the Processor shall not Process Personal Data for the purpose of developing, improving, training, or building products, services, or models outside the scope of the Services. This restriction shall not apply to the Processor’s use of data that has been anonymized or aggregated such that it no longer constitutes Personal Data within the meaning of Applicable Data Protection Laws.
    • 4.8. Data Protection Impact Assessments. The Processor shall provide the Controller with such information as is reasonably necessary to enable the Controller to conduct and document any data protection impact assessment or transfer impact assessment required under Applicable Data Protection Laws. In fulfilling this obligation, the Processor shall take into account the nature of the Processing and the information reasonably available to it. Any information provided by the Processor pursuant to this Section 4.8 shall remain subject to the Processor’s confidentiality and security obligations.
    • 4.9. Controllers Right of Oversight and Remediation. The Controller shall have the right to take reasonable and appropriate steps to: (a) ensure that the Processor Processes Personal Data in a manner consistent with the Controller’s obligations under Applicable Data Protection Laws; and (b) stop and remediate any unauthorized Processing of Personal Data by the Processor.
    • 4.10. Records of Processing Activities. The Processor shall maintain a written record of all categories of Processing activities carried out on behalf of the Controller. The Processor shall make such records available to the Controller and to any competent supervisory authority upon reasonable request.
  • 5. Data Subject Rights
    • 5.1. Individual Rights. The Processor shall provide reasonable assistance to the Controller in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Laws in relation to their Personal Data.
    • 5.2. Direct Requests from Data Subjects. Where the Processor receives a request directly from a Data Subject, the Processor shall promptly notify the Controller and shall not respond to or act upon such request without the Controller’s prior written instruction, unless required to do so by Applicable Data Protection Laws.
    • 5.3. Erasure and Backup Retention. The Controller shall be responsible for determining which Data Subject rights apply under Applicable Data Protection Laws and for communicating those rights to Data Subjects accordingly. The Processor shall assist the Controller in fulfilling valid erasure requests in accordance with the following:
      • (a) Active systems: The Processor shall delete Personal Data from live production systems within a reasonable timeframe following receipt of a valid erasure request confirmed by the Controller.
      • (b) Automated backups: The Processor maintains daily automated backups with the following retention periods: seven (7) days for database backups (AWS RDS) and twenty (20) days for server snapshots (AWS EC2). Residual copies of erased Personal Data may persist within these backups until the applicable retention period expires in the ordinary course, at which point such copies shall be automatically purged.
      • (c) Manual backups: The Processor retains certain manual backups created prior to platform releases for system rollback and reference purposes. Such backups may contain residual Personal Data and are retained for a maximum period of twelve (12) months. Manual backups are stored in isolated cold storage, are not actively processed, and the Personal Data contained therein shall not be used for any purpose other than system recovery.
    • 5.4. Communication of Limitations to Data Subjects. The Controller shall be responsible for communicating the limitations set out in Section 5.3 of this DPA to Data Subjects where required under Applicable Data Protection Laws.
  • 6. Sub-processors
    • 6.1. Authorization of Sub-processors. The Controller authorizes the Processor to engage the Sub-processors identified in Schedule 2 for the purpose of Processing Personal Data in connection with the provision of the Services. Such authorization is subject to the Processor’s compliance with the requirements set out in Sections 6.2 and 6.3 of this DPA.
    • 6.2. Sub-processor Obligations. Prior to any Sub-processor commencing the Processing of Personal Data, the Processor shall enter into a written agreement with that Sub-processor which imposes data protection obligations that are, in all material respects, no less protective of Personal Data than those imposed on the Processor under this DPA. The Processor shall remain fully liable to the Controller for the acts and omissions of each Sub-processor as if such acts or omissions were those of the Processor itself.
    • 6.3. Notification for Sub-processor Changes. The Processor shall provide the Controller with no fewer than thirty (30) days’ prior written notice before engaging any new Sub-processor or replacing any existing Sub-processor (a “Change”). The Controller may object to a proposed Change by providing the Processor with a written objection setting out reasonable grounds within the thirty (30) day notice period. Where the Controller does not raise an objection within that period, the Controller shall be deemed to have approved the Change. Where the Controller raises a valid objection, the parties shall negotiate in good faith to resolve the objection within a further thirty (30) days. If the parties are unable to reach a resolution within that period, either party may terminate the Master Agreement upon written notice to the other party, without prejudice to any accrued rights or obligations.
  • 7. Security
    • 7.1. Security Measures. The Processor shall implement and maintain appropriate technical, administrative, and organizational measures designed to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, alteration, or damage. In determining the appropriate level of security, the Processor shall take into account:
      • (a) the nature, scope, context, and purposes of the Processing;
      • (b) the risks arising from accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed; and
      • (c) the state of the art, the costs of implementation, and applicable industry standards.
    • 7.2. Regular Review. Without limiting the generality of Section 7.1, the Processor shall implement and maintain the specific security measures set out in Schedule 3. The Processor shall regularly monitor, test, and review the effectiveness of its security measures and shall update them as necessary to address: (a) developments in technology and applicable industry standards; (b) changes in the nature, scope, context, or purposes of Processing; and (c) any identified vulnerabilities, threats, or risks to the security of Personal Data.
  • 8. Audit Rights
    • 8.1. Controllers Right to Audit. The Controller has the right to audit the Processor’s compliance with this DPA. All audits shall be conducted: (a) upon no fewer than thirty (30) days’ prior written notice to the Processor, specifying the proposed scope and duration of the audit; (b) no more than once in any twelve (12)-month period, unless a supervisory authority directs an additional audit or an audit is reasonably necessary following a Personal Data Breach; and (c) during the Processor’s normal business hours and in a manner that minimizes disruption to the Processor’s operations.
    • 8.2. Third-Party Auditors. The Controller may engage a qualified, independent third-party auditor to conduct an audit on its behalf, provided that the auditor is bound by written confidentiality obligations no less protective than those set forth in this DPA. Prior to commencement, the Controller and the Processor shall agree on an audit plan that is consistent with the Processor’s reasonable security policies and site-access requirements. The Controller shall promptly notify the Processor in writing of any material non-compliance identified during the audit and shall provide the Processor with a copy of the audit findings upon request.
    • 8.3. Alternative Evidence. Upon the Controller’s reasonable written request, the Processor shall make available documentation sufficient to demonstrate implementation of the technical and organizational measures described in this DPA. Where the scope of a requested audit is substantially addressed by a current certification or independent third-party audit report (including SOC 2 Type II or ISO/IEC 27001 reports) issued within the twelve (12) months preceding the Controller’s request, and the Processor confirms that no material changes have been made to the controls audited, the Controller shall accept such certification or report in lieu of conducting an on-site audit with respect to the controls covered therein.
    • 8.4. Audit Costs. The Controller shall bear all costs and expenses associated with any audit conducted under this Section 8.
    • 8.5. Sub-processor Audits. The Processor shall regularly audit each Sub-processor’s compliance with Applicable Data Protection Laws and the Sub-processor’s contractual obligations. Upon the Controller’s reasonable written request, the Processor shall provide the Controller with a summary of its most recent Sub-processor audit findings or, where applicable, evidence of the Sub-processor’s relevant certifications.
  • 9. Personal Data Breach
    • 9.1. Notification Obligation. In the event of a Personal Data Breach, the Processor shall notify the Controller without undue delay and in no event later than seventy-two (72) hours after becoming aware of the breach.
    • 9.2. Content of Notification. The notification provided under Section 9.1 shall include, to the extent reasonably available at the time of notification:
      • (a) a description of the nature of the Personal Data Breach, including the categories of Personal Data affected;
      • (b) the approximate number of Data Subjects and Personal Data records concerned;
      • (c) the likely consequences of the Personal Data Breach; and
      • (d) the measures taken or proposed to be taken by the Processor to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

Where it is not possible to provide all information simultaneously, the Processor shall provide such information in phases as it becomes available.

    • 9.3. Legally Required Notifications. The Controller shall be solely responsible for determining and fulfilling its own notification obligations to supervisory authorities and affected Data Subjects under Applicable Data Protection Laws. The Processor shall provide reasonable cooperation and assistance to the Controller in connection with the Controller’s compliance with such notification obligations, including by making available any further information within the Processor’s possession that is reasonably required for that purpose.
    • 9.4. Evidence Preservation. Upon becoming aware of a Personal Data Breach, the Processor shall take all reasonable steps to preserve and protect all relevant evidence, including system logs, access records, and communications, for a period of no less than twelve (12) months following the date of notification, or such longer period as may be required by Applicable Data Protection Laws or a supervisory authority.
    • 9.5. Root-Cause Analysis. The Processor shall conduct a thorough root-cause analysis of any Personal Data Breach and shall provide the Controller with a written report summarizing its findings. Such report shall be provided within ninety (90) days of the date on which the Processor became aware of the breach, unless a longer period is agreed in writing by the Controller.
    • 9.6. Cooperation with Authorities. The Processor shall provide reasonable cooperation to the Controller and, where directed by the Controller, to any competent supervisory authority or law enforcement body in connection with any investigation arising from a Personal Data Breach.
  • 10. Deletion and Return
    • 10.1. Data Export. Upon termination or expiration of the Master Agreement, the Processor shall make Personal Data available for export to the Controller in an industry-standard, machine-readable format for a period of sixty (60) calendar days (the “Export Period”), in accordance with the Processor’s obligations under the Master Agreement. The Controller is solely responsible for requesting and retrieving its Personal Data during the Export Period.
    • 10.2. Deletion Following Expiration of the Export Period. Following expiration of the Export Period, the Processor shall delete or destroy all Personal Data from active production systems and shall use reasonable efforts to ensure that each Sub-processor does the same. The Processor shall provide written confirmation of such deletion or destruction to the Controller within sixty (60) calendar days of the expiration of the Export Period. The Controller acknowledges that residual copies of Personal Data may persist in automated and manual backup systems, as described in Section 5.3 of this DPA, and that such copies shall be handled in accordance with the backup retention practices set out therein.
    • 10.3. Early Deletion at Controllers Request. Where the Controller requests deletion of Personal Data prior to the expiration of the Export Period, the Processor shall carry out such request within a commercially reasonable timeframe. The Controller acknowledges and agrees that early deletion shall irrevocably preclude any subsequent export of the affected Personal Data.
    • 10.4. Retention for Direct Marketing Purposes. Where a Data Subject has provided consent to the processing of their Personal Data for direct marketing purposes, such Personal Data shall be retained by the Processor until such time as the Data Subject withdraws that consent, at which point the Processor shall delete the relevant Personal Data in accordance with Applicable Data Protection Laws and its internal practices.
  • 11. International Data Transfers
    • 11.1. Transfer Impact Assessments. Prior to engaging any Sub-processor established in a Third Country, or otherwise transferring Personal Data to such a country, or otherwise transferring Personal Data to a recipient in a Third Country, the Processor shall carry out and document a transfer impact assessment (“TIA”) in accordance with Applicable Data Protection Laws. The Processor shall make a copy or a meaningful summary of each TIA available to the Controller within a reasonable period following the Controller’s written request, provided that the Processor may redact information that is genuinely commercially confidential and not material to the Controller’s assessment of the adequacy of protection. If a TIA concludes that adequate protection of Personal Data cannot be ensured through the transfer mechanism and any supplementary measures taken together, the Processor shall not proceed with the transfer unless and until the Controller provides prior written authorization to do so.
    • 11.2. Standard Contractual Clauses. Without prejudice to the requirement to conduct a TIA under Section 11.1, where Personal Data is transferred onward to a Sub-processor located in a Third Country, the Processor shall ensure that each such Sub-processor enters into the SCCs (Module 3, processor-to-processor) or, where the transfer is subject to the UK GDPR, the International Data Transfer Addendum issued by the Information Commissioner’s Office (or such successor instrument as may be in force at the relevant time). Such SCCs or Addendum shall be annexed to, or incorporated by reference into, the relevant sub-processing agreement.
  • 12. Liability
    • 12.1. Direct Damages. Each party shall be independently responsible for its own compliance with all Applicable Data Protection Laws. The Processor’s liability under this DPA shall be limited to direct damages arising from the Processor’s breach of the obligations expressly set out in this DPA.
    • 12.2. Liability Cap. The aggregate liability of either party arising under or in connection with this DPA shall be subject to, and shall not exceed, any limitations or caps on liability set out in the Master Agreement.

SCHEDULE 1

Details of Processing Activities

Item Details
Subject Matter The processing of Personal Data relates to the provision of quality management system (QMS) software services, including document management, CAPA, training, inventory, inspection, and related modules as described in the Master Agreement.
Duration Processing shall continue for the term of the Master Agreement, unless earlier terminated or otherwise agreed in writing by the parties in accordance with this DPA.
Nature of Processing The Processor shall carry out the following processing activities in respect of Personal Data: collection, storage, retrieval, use, disclosure, and deletion, each performed via the SaaS platform in connection with the provision of the Services.
Purpose of Processing Personal Data is processed for the purpose of providing the Services, including user account management, platform operation, customer support, billing, and analytics.
Categories of Data Subjects Employees, contractors, and authorized users of the Controller who access the Services.
Categories of Personal Data User Data: name, email address, postal address, and telephone number. Usage Data: IP address, browser type, operating system, device identifiers, and location data. Billing Data: payment and invoicing information, where applicable.
Retention Period Personal Data shall be retained for as long as necessary to provide the Services, or as required by applicable law. Further detail on retention and deletion is set out in Sections 5.3 and 10 of this DPA.
Sensitive Data No sensitive data or special categories of Personal Data shall be processed under this DPA, unless separately agreed in writing by the parties.

SCHEDULE 2

List of Sub-Processors

Processor engages the following Sub-processors to Process Personal Data in connection with the Services:

Sub-processor Description of Processing Processing Location
Amazon Web Services, Inc. Used to host the Isolocity QMS platform. Controller may select one of the following data hosting regions: (a) Canada and USA; or (b) England.
Google LLC Used for business email, document storage, and collaboration tools (e.g., Gmail, Google Drive, Google Docs). USA
Microsoft Corporation Used for productivity and collaboration tools, including Word, Excel, and Teams. USA
PipeDrive Inc. Used as a customer relationship management (CRM) tool to store and manage sales and customer contact information. Canada
Zapier, Inc. Used to automate workflows and manage data transfers between connected applications. USA
n8n GmbH Used to automate workflows and manage data transfers between connected applications. Germany
RykeLabs, Inc. (d/b/a ChargeOver) Used for subscription billing and invoicing, processing customer billing and payment-related data. USA
Freshworks Inc. Used as a customer support helpdesk to manage and respond to support tickets and customer inquiries. USA
Asana, Inc. Used for internal project and task management, which may involve customer-related information in the course of operational work. USA
Shift4 Payments, Inc. Used for payment processing and card transaction settlement, processing customer billing and payment-related data. Canada, USA, Sweden, France, Germany
PayPal, Inc. Used for online payment processing and checkout, processing customer billing and payment-related data. USA
2144482 Ontario Limited (d/b/a Sparcblock) Used for accounts payable automation and vendor payment processing, processing customer billing and payment-related data. Canada
Intuit Inc. Used for accounting, invoicing, and bookkeeping, processing customer billing and payment-related data. USA
Three Hearts Digital Ltd. (d/b/a Email Octopus) Used to send marketing and/or transactional email communications to customers. USA, Ireland
Functional Software, Inc. (d/b/a Sentry) Used for application error monitoring and performance tracking, which may incidentally capture technical data and limited Personal Data during debugging. USA
Userpilot, Inc. Used to deliver in-app onboarding flows, product tours, and user engagement analytics. USA
SendGrid, Inc. Used to deliver transactional emails, including account notifications and password resets. USA
Laravel Holdings Inc. (Laravel Nightwatch) Used for application performance monitoring (APM), including request tracing, query performance, log aggregation, and error tracking within the Isolocity QMS platform. USA
8x8, Inc. Used to place and receive customer phone calls, including processing of call metadata such as caller/recipient phone numbers and call timestamps. USA
Webflow, Inc. Used to host Processor’s website, including processing of Personal Data voluntarily submitted through contact forms, demo requests, or newsletter sign-ups. USA
OpenAI, LLC Used to assist with generating reports and drafting email content, which may incidentally reference personal data; clients may opt out under Processor's Terms & Conditions. Not used for AI training. USA
Anthropic, PBC Used to assist with generating reports and drafting email content, which may incidentally reference personal data; clients may opt out under Processor's Terms & Conditions. Not used for AI training USA

SCHEDULE 3

Technical and Organizational Security Measures

The Processor maintains the following security measures to protect Personal Data Processed under this DPA.

  • A. Encryption
    • Personal Data is encrypted in transit using TLS 1.2 or higher.
    • Personal Data is encrypted at rest using AES-256 encryption or an equivalent standard.
  • B. Access Controls
    • Access to Personal Data is restricted on a need-to-know basis through role-based access controls.
    • Multi-factor authentication (MFA) is implemented, where appropriate.
    • Each user is assigned unique credentials; password policies enforce minimum complexity requirements and periodic rotation.
    • All privileged access is logged and subject to periodic audit.
  • C. Confidentiality
    • All personnel with access to Personal Data are bound by confidentiality obligations.
    • Personnel receive regular training on data protection and information security.
  • D. Availability and Integrity
    • The Services are hosted on Amazon Web Services (AWS) infrastructure, providing high availability and built-in redundancy.
    • Automated backups are performed on a regular schedule, and restoration procedures are tested periodically.
    • Business continuity and disaster recovery procedures are maintained, with a recovery point objective (RPO) of no more than 4 hours and a recovery time objective (RTO) of no more than 12 hours.
  • E. Breach Management
    • The Processor maintains a documented Personal Data Breach response procedure.
    • Personal Data Breaches are logged, investigated, and remediated in accordance with the Processor's internal policies.
    • The Controller shall be notified without undue delay, and in any event within 72 hours, of the Processor becoming aware of a Personal Data Breach.
  • F. Sub-processor Security
    • Sub-processors are evaluated for adequacy of their security practices prior to engagement.
    • Appropriate data protection and security obligations are imposed on each Sub-processor by written contract.
  • G. Physical Security
    • Physical access to infrastructure is managed by AWS data center controls, including biometric access, video surveillance, and 24/7 security personnel.
  • H. Testing and Review
    • Security measures are reviewed on a regular basis and updated in response to changes in risk, technology, or applicable law.
    • Application-level monitoring is in place to detect vulnerabilities and performance issues.
  • I. Anonymization
    • Where technically feasible and appropriate to the risk, the Processor shall implement anonymization measures in respect of Personal Data Processed within the Services, such that Personal Data cannot be attributed to a specific Data Subject without the use of additional information.
  • J. Penetration Testing and Vulnerability Assessments
    • The Processor shall cause to be conducted, at least annually, an independent third-party penetration test and vulnerability assessment of the systems used to Process Personal Data. The Processor shall remediate any critical or high-severity vulnerabilities identified within a reasonable period of time.

See the Difference

Integrations

Connect your system with the rest of your software stack, and sync information with outside sources, including:

Lab Results

Customer Support Software

Commerce Platforms

Accounting Software

Production Software

Lab Results

Currently, we have integration with Microsoft Azure for SharePoint and OneDrive, QAD ERP, Dutchie POS, Elevated Signals, CertiCraft, MJ Freeway, and many more.
The options for integration are limitless with our open API.