Data Processing Addendum (DPA)
This DPA forms part of the Terms of Service between TrueNorth Data Shield LLC ("Processor" / "Service Provider") and Customer ("Controller" / "Business").
- Scope. Processor processes Customer Personal Data only to provide TrueNorth Exposure Scan and related support, on Customer's documented instructions (the Terms, the order form, and Customer's settings).
- Data processed. Categories of individuals: Customer's employees, contractors, guests, and administrators. Data types: names, work email addresses, user principal names, guest account dates, admin role membership, and the names and paths of files and sites along with their sharing metadata. No special-category data is intentionally processed. File names may incidentally reveal sensitive topics, so Processor treats all scan data as confidential.
- U.S. state privacy laws. Processor will act as a "service provider" or "processor" under the CCPA/CPRA and similar state laws. It will not sell or share Customer Personal Data; will not retain, use or disclose it outside the direct business relationship or for any purpose other than the Service; will not combine it with other data except as those laws permit; will notify Customer if it can no longer meet its obligations; and will allow Customer to take reasonable steps to stop unauthorized use.
- Confidentiality. Everyone with access is bound by confidentiality and has had security training.
- Security measures (Annex A). These include TLS 1.2+ in transit; encryption at rest; read-only Microsoft Graph permissions with admin consent; secrets kept in Azure Key Vault; MFA and least privilege for all staff access; separation of each tenant's data; audit logging; vulnerability patching within 30 days (critical issues within 7); encrypted backups; and an annual review of these controls.
- Subprocessors. Customer authorizes the current list (Microsoft Azure, Stripe, [email provider]). Processor gives 30 days' notice of new subprocessors, and Customer may object on reasonable grounds. Processor passes equivalent obligations on to subprocessors and remains liable for them.
- Breach notification. Processor will notify Customer without undue delay, and in any case within 72 hours of confirming a Security Incident affecting Customer Personal Data. The notice will include the facts known, the likely impact, and the remediation steps. Processor will help Customer meet its own notification duties, such as HRS Chapter 487N.
- Assistance. Processor will help Customer respond to individuals' privacy requests and with reasonable security or assessment requests.
- Retention and deletion. Scan data is kept for 90 days by default. On termination or request, Processor deletes it within 30 days and certifies the deletion on request.
- Audits. On request, once a year, Processor will provide its security documentation and answer a reasonable questionnaire. If a SOC 2 or penetration-test summary exists, Processor will provide it under NDA.
- Location. Data is processed and stored in the United States.
- Precedence. For data-protection matters, this DPA controls over the Terms.
Signed: TrueNorth Data Shield LLC __ Customer __ Date ______