Data Processing Addendum - DataLocker Inc.
Version: AUG 2026
1. Scope and Duration
This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with the use of DataLocker products and services, including SafeConsole. Processing shall be carried out for the duration of the active service relationship and any subsequent Retention Period (as described in Section 11) specifically instructed by the Controller to facilitate future service reactivation.
2. Nature and Purpose of Processing
The Processor shall process personal data solely for the following purposes:
- Provision and operation of device management services
- Enforcement of security policies
- Logging, monitoring, and audit functions
Processing is limited to what is strictly necessary for these purposes. The Processor shall not have access to, nor process, any files stored on the Controller’s devices or within SafeCrypt. These files are never sent to the SafeConsole Server.
3. Categories of Data and Data Subjects
Categories of personal data:
- User Identification Data: Computer username, Email address, and Active Directory OU path.
- Technical Identifiers: Public IP address, Device Serial Number, Software Version, and unique
machine digital fingerprints. - Cryptographic Data: Random one-time pad keys (used for password hash encryption) and
encrypted recovery passwords. - Usage and Metadata Logs: Computer hostname, OS version, used device capacity, and device
action timestamps. - Administrator Data: Name, Email, Phone Number, Public IP, and hashed passwords of
SafeConsole Admins. - File Metadata (Audit Logs): Created filenames, file locations on the device, file sizes, and
MD5 hashes of files.
Categories of data subjects:
- Employees and authorized users of the Controller
4. Instructions
The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable Data Protection Laws.
5. Confidentiality
The Processor shall ensure that all persons authorized to process personal data are bound by confidentiality obligations.
6. Technical and Organizational Measures (TOMs)
The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Access to processed data is strictly limited to the DataLocker Web Operations (WebOps) team through a controlled and audited process.
- Single-tenant architecture ensuring dedicated application and database instances for each Controller to prevent data co-mingling
- Encryption of data in transit and at rest
- Implementation of Multi-Factor Authentication (MFA) and a minimum 20-character password policy for production access
- Logging and monitoring of system access
- Protection against unauthorized access
7. Subprocessing
The Processor may engage subprocessors only where necessary for the provision of the services.
The Processor shall:
- ensure that subprocessors are bound by equivalent obligations
- remain fully responsible for the performance of subprocessors
- Maintain an up-to-date list of subprocessors and make it available to the Controller
- Provide the Controller with prior written notification of any intended additions or replacements of subprocessors, providing the Controller a reasonable opportunity to object on legitimate data protection grounds.
8. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), the Processor shall ensure appropriate safeguards, including:
- Certification under the EU-U.S. Data Privacy Framework
- Standard Contractual Clauses (SCCs), where applicable
9. Assistance to the Controller
The Processor shall assist the Controller in:
- responding to data subject requests
- ensuring compliance with Articles 32 to 36 GDPR
- handling personal data breaches
10. Notification of Personal Data Breaches
The Processor shall notify the Controller without undue delay after becoming aware of a
personal data breach.
11. Deletion or Return of Data
Upon termination of active services, the Processor shall not automatically delete personal data but shall instead maintain the Controller’s dedicated application instance and database in a dormant state to allow for seamless service renewal. The Processor shall delete or return the personal data upon: (a) receipt of a written request from the Controller, or (b) following a period of up to 3 years of continuous account inactivity, whichever occurs first. During the dormant state, the Processor shall continue to apply the Technical and Organizational Measures described in Section 6 to ensure the ongoing security of the data.
12. Audit and Compliance
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice.
13. Liability
Liability shall be governed by the provisions of the underlying agreement between the Parties.
14. Governing Law
This DPA shall be governed by the applicable law of the underlying agreement and interpreted in accordance with the General Data Protection Regulation (EU) 2016/679.