Data processing addendum
How we handle personal data on a client's behalf. This forms part of the agreement wherever we process personal data for you.
Roles and scope
This addendum applies where Stratovia Consulting LLC processes personal data on behalf of a client in the course of an engagement. For that processing the client is the controller, or a processor acting for its own controller, and we are the processor or subprocessor. For our own business records, including the client's contact details and our invoices, we are an independent controller and our privacy policy applies.
Terms such as personal data, processing, controller, processor, data subject and personal data breach carry the meanings given in the applicable data protection law, which includes the EU General Data Protection Regulation, the UK GDPR and the United States state privacy laws that apply to the client.
Our instructions
We process personal data only on the client's documented instructions, which are the agreement itself, this addendum, and any further written instruction the client gives. We do not process it for our own purposes, we do not sell it, and we do not use it to train models or to build products.
If we believe an instruction breaches data protection law, we will tell the client promptly and may pause that part of the processing until it is resolved. If we are required by law to process beyond the client's instructions, we will inform the client first unless that law forbids it.
Confidentiality of staff
Access is limited to the people who need it to deliver the engagement. Everyone with access is bound by a written confidentiality obligation that survives the end of their involvement, and access is removed when someone leaves the engagement.
Security measures
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. The measures in force are listed in Annex B. We keep them under review and may update them, provided the level of protection is not reduced.
Subprocessors
The client gives general authorisation for us to appoint subprocessors. Our current list is published at stratovia.services/legal/subprocessors, and any client can ask to be notified by email when it changes.
We give at least thirty days' notice before adding or replacing a subprocessor. The client may object on reasonable data protection grounds within that period; if we cannot resolve the objection, the client may terminate the affected part of the engagement without penalty, with a pro-rata refund of prepaid fees for services not delivered. Each subprocessor is bound by written terms offering protection equivalent to this addendum, and we remain fully liable for their performance.
Data subject requests
If a data subject contacts us directly about the client's data, we will not respond substantively. We will forward the request to the client without undue delay and, taking into account the nature of the processing, assist the client with appropriate technical and organisational measures in responding to requests to access, correct, delete, restrict, port or object.
Breach notification
We notify the client of a personal data breach affecting the client's data without undue delay, and in any event within seventy-two hours of becoming aware of it. The notification describes the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where we cannot provide all of that at once, we provide it in phases as it becomes available, and we assist the client with its own notification obligations to regulators and data subjects.
Assessments and consultation
Taking into account the nature of the processing and the information available to us, we provide reasonable assistance with data protection impact assessments and with prior consultation of a supervisory authority where the client is required to carry them out.
Return and deletion
On termination of the engagement, and at the client's choice, we return or delete the personal data we hold on the client's behalf, and delete existing copies, within thirty days of the client's written request. This does not apply where law requires us to keep a copy, in which case we tell the client what we are keeping and why, and continue to protect it under this addendum for as long as we hold it. Where we have delegated access to the client's own systems, deletion means removal of our access rather than deletion of the client's records.
Audits
We make available the information reasonably necessary to demonstrate compliance with this addendum, and allow for and contribute to audits conducted by the client or an independent auditor it appoints. Audits take place on at least thirty days' written notice, no more than once in any twelve-month period unless a breach or a regulator requires otherwise, during business hours, subject to confidentiality, and in a way that does not unreasonably disrupt our operations. The client bears the cost of an audit it initiates.
International transfers
We are established in the United States. Where personal data is transferred from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the parties incorporate by reference the European Commission's Standard Contractual Clauses of 4 June 2021, module two where the client is a controller and module three where the client is itself a processor, with the following selections: clause 7 docking is included; clause 9 option 2 applies with the notice period in the subprocessors section above; clause 11 does not include the independent dispute resolution option; clause 17 is governed by the law of Ireland; and clause 18(b) selects the courts of Ireland. Annexes I and II of the clauses are populated by Annex A and Annex B below.
For transfers subject to the UK GDPR, the parties incorporate the UK International Data Transfer Addendum to the Standard Contractual Clauses, version B1.0, with tables 1 to 3 populated from this addendum and table 4 selecting neither party as able to end the addendum on changes to it. For transfers from Switzerland, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the competent authority is the Federal Data Protection and Information Commissioner.
United States privacy law
Where the California Consumer Privacy Act, as amended by the CPRA, or a comparable state law applies, we act as a service provider or processor. We do not sell or share personal information, we do not retain, use or disclose it for any purpose other than performing the services or as permitted by law, and we do not combine it with personal information received from other sources except as that law permits. We certify that we understand these restrictions and will comply with them.
Annex A: processing details
| Item | Detail |
|---|---|
| Subject matter | Delivery of the marketing, search, advertising and analytics services described in the statement of work |
| Duration | The term of the engagement, plus any period required for return or deletion |
| Nature and purpose | Access to and configuration of the client's analytics, advertising and CRM systems; audience and campaign analysis; reporting; conversion measurement |
| Types of personal data | Identifiers such as name, email address and telephone number; online identifiers such as IP address, cookie identifiers and device identifiers; professional information such as company and role; commercial information such as enquiry and purchase history; usage data from the client's own properties |
| Categories of data subjects | The client's customers, prospects, enquirers, subscribers and website visitors |
| Special category data | None. We instruct clients not to give us special category or sensitive data, and we do not request it |
| Frequency | Continuous for the duration of the engagement |
| Controller contact | As named in the statement of work |
| Processor contact | Stratovia Consulting LLC, [email protected] |
Annex B: security measures
| Area | Measure |
|---|---|
| Access control | Named individual accounts, no shared logins, multi-factor authentication on every system that supports it, access granted on a least-privilege basis and removed when someone leaves an engagement |
| Credential handling | Passwords held in a dedicated password manager; client credentials never sent by email or chat; delegated access preferred over shared credentials wherever a platform supports it |
| Encryption | TLS for data in transit; full-disk encryption on every device used for client work |
| Data minimisation | We work inside the client's own systems wherever possible and avoid taking copies of personal data; exports are limited to what a task requires and deleted when it is done |
| Endpoint security | Supported operating systems with automatic updates, screen lock, and remote wipe capability |
| Personnel | Written confidentiality obligations for everyone with access, and equivalent written terms for subcontractors |
| Business continuity | Documentation of account configuration so an engagement can be resumed or handed over; the client retains ownership of the underlying accounts at all times |
| Incident response | A documented process for identifying, containing and reporting incidents, with notification to affected clients within seventy-two hours |
| Vendor review | Subprocessors reviewed for security posture and contractual terms before appointment, and reviewed again when their role changes |
A signed copy of this addendum is available on request. If your organisation requires its own DPA on its own paper, send it over and we will review it.
Questions about this document
Write to Stratovia Consulting LLC, 3831 Montgomery Blvd NE, Apt 433, Albuquerque, NM 87109, United States, or email [email protected]. We answer within 30 days, and sooner where the law requires it.