Effective date: September 28, 2026
This Data Processing Addendum ("DPA") supplements the Terms of Service between the customer ("Controller") and DSPLife Collaborative Group ("RisqRadar", "Processor"). It applies to the extent RisqRadar processes personal data contained in Customer Data on the Controller's behalf. Where the GDPR or UK GDPR applies, the Controller is the controller and RisqRadar is the processor.
RisqRadar will: (a) process personal data only on the Controller's documented instructions, including with regard to transfers to a third country, as set out in the Terms and this DPA; (b) ensure personnel authorized to process personal data are bound by confidentiality; (c) implement appropriate technical and organizational security measures; and (d) not sell personal data, share it for cross-context behavioral advertising, retain it outside the direct business relationship, or use it for any purpose other than providing the service.
Where RisqRadar is required by Union, Member State or other applicable law to process personal data otherwise than on the Controller's instructions, it will inform the Controller of that legal requirement before processing, unless the law prohibits it from doing so on important grounds of public interest.
RisqRadar will immediately inform the Controller if, in its opinion, an instruction infringes the GDPR, the UK GDPR, or other applicable data protection law.
The technical and organizational measures RisqRadar applies are described in its published information security policies, which serve as the description of measures for the purposes of Article 32 and of the Standard Contractual Clauses. Those measures may be updated over time provided the level of protection is not diminished.
The Controller authorizes RisqRadar to engage the subprocessors listed on our Subprocessors page. RisqRadar will impose data-protection obligations on each subprocessor substantially similar to those in this DPA and remains responsible for its subprocessors' performance. RisqRadar will provide notice before adding a new subprocessor, during which the Controller may object on reasonable data-protection grounds; if an objection cannot be resolved, the Controller may terminate the affected service.
Taking into account the nature of the processing, RisqRadar will provide reasonable assistance to the Controller by appropriate technical and organizational measures, insofar as this is possible, in responding to data-subject requests to exercise their rights under Chapter III of the GDPR, and in meeting its obligations under Articles 32 to 36 regarding security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
If a data subject contacts RisqRadar directly about personal data processed on the Controller's behalf, RisqRadar will not respond to the substance of the request. It will promptly forward the request to the Controller and may acknowledge receipt and identify the Controller as the party responsible for responding.
RisqRadar will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to help the Controller meet its notification obligations. The Controller remains responsible for notifying its supervisory authority and, where required, affected data subjects; RisqRadar does not make those notifications on the Controller's behalf.
On termination of the service, and at the Controller's choice, RisqRadar will make Customer Data available for export for a limited period and will then delete or return it, and will delete existing copies, except where Union, Member State or other applicable law requires continued storage. Backup copies are deleted on the ordinary backup rotation, which is 30 days.
RisqRadar will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality, scheduling, and security conditions. Where available, third-party reports and security documentation may be provided to satisfy audit requests.
Where processing of personal data subject to the GDPR involves a transfer to a country without an adequacy decision, the parties incorporate by reference the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, and specifically Module Two (controller to processor), with the Controller as data exporter and DSPLife Collaborative Group as data importer. The optional docking clause applies. Where the Clauses require a choice, the parties select the supervisory authority and governing law of the Member State in which the Controller is established or, where the Controller is not established in the EEA, of Ireland.
Where the UK GDPR applies, the parties incorporate the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, appended to those Clauses. Where Swiss data protection law applies, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
For the purposes of the Clauses, the details of processing in section 2, the subprocessor list, and the security measures referenced in section 3 serve as the required annexes. A copy of the safeguards relied on for a particular transfer is available on request from privacy@risqradar.com.
In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls. A signed counterpart of this DPA is available on request for customers that require an executed agreement. Questions may be sent to legal@risqradar.com.