Data Processing Agreement (DPA)
Standard Data Processing Addendum incorporating EU Standard Contractual Clauses (SCCs) and UK International Data Transfer Addendum.
1. Definitions & Roles
This Data Processing Agreement (“DPA”) supplements the Optruss Master Subscription Agreement. For the purposes of Data Protection Legislation (including GDPR, UK GDPR, and regional statutory data protection acts):
- Customer as Data Controller: The Customer acts as the Data Controller in respect of personal identity records of technicians, supervisors, and contractors utilizing the system.
- Optruss as Data Processor: Optruss acts as the Data Processor, processing identity credentials and operational logs solely on behalf of and under the documented instructions of the Customer.
2. Scope & Nature of Processing
Processing activities performed by Optruss encompass user authentication verification, deterministic kinematic telemetry correlation, work order dispatch tracking, and cryptographic ledger integrity maintenance.
3. Customer Instructions & Sovereignty
Optruss shall process personal data solely in compliance with Customer’s documented instructions, unless required to do so by applicable statutory law. Optruss shall immediately notify Customer if, in its technical assessment, an instruction infringes data protection legislation.
4. Sub-Processors & Infrastructure
Customer grants general written authorization for Optruss to engage vetted third-party sub-processors strictly for cloud management plane hosting (e.g., AWS GovCloud, Microsoft Azure for Government, Cloudflare Enterprise).
5. Technical & Organizational Measures (TOMs)
Optruss maintains comprehensive technical safeguards designed to protect personal and operational data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure:
- FIPS 140-3 validated cryptographic modules for all cryptographic token operations.
- Strict micro-segmentation isolating customer tenancy at the kernel namespace and database schema level.
- Automated vulnerability scanning and continuous static analysis integration in build pipelines.
- Hardware-enforced zero-trust mutual TLS (mTLS) for all inter-service and edge-to-controller communications.
6. Security Incident Management & Notification
In the event of a confirmed Personal Data Breach impacting Customer data, Optruss shall notify Customer without undue delay and, in any event, within 48 hours of becoming aware of the breach.
7. Cross-Border Transfers & Standard Contractual Clauses
Where personal data originating in the European Economic Area (EEA), United Kingdom, or Switzerland is transferred outside these territories to countries not recognized as providing an adequate level of data protection, the parties agree to incorporate by reference the European Commission’s Standard Contractual Clauses (Module 2: Controller-to-Processor).
8. Independent Audits & Certifications
Optruss shall make available to Customer all information necessary to demonstrate compliance with these obligations and allow for audits conducted by Customer or an independent accredited third-party auditor once per twelve-month period upon thirty (30) days advance notice.