This Data Processing Addendum (“DPA”) forms part of the Master Subscription Agreement (the “Agreement”) between Chad Enterprises Inc. (“Chad”) and Customer, and is incorporated into the Agreement by reference. It applies where and to the extent Chad processes personal data subject to the EU General Data Protection Regulation (“GDPR”), the UK GDPR, or the Swiss Federal Act on Data Protection (together, “Data Protection Laws”) on behalf of Customer as a processor (“Customer Personal Data”). For the avoidance of doubt, this DPA applies only where and to the extent Data Protection Laws expressly apply to the processing of Customer Personal Data under the Agreement; it creates no rights or obligations with respect to processing to which Data Protection Laws do not apply, and does not extend the protections of Data Protection Laws to any Customer, data subject or processing otherwise outside their scope. Capitalized terms not defined here have the meaning given in the Agreement.
1. Roles and Scope
As between the Parties, Customer is the controller (or, where Customer acts on behalf of a third-party controller, a processor) of Customer Personal Data, and Chad is Customer’s processor (or sub-processor). The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I. This DPA does not apply to personal data for which Chad is a controller, which is governed by the Chad Privacy Policy, the Shopper Privacy Notice and the Chad GDPR Policy (including the shared shopper record described there).
2. Processing on Documented Instructions
Chad will process Customer Personal Data only on Customer’s documented instructions, including with regard to transfers of personal data to a third country, unless required to do so by European Union or Member State (or UK or Swiss) law to which Chad is subject; in that case, Chad will inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The Agreement, this DPA, and Customer’s configuration and use of the Services constitute Customer’s complete documented instructions. Chad will inform Customer without undue delay if, in its opinion, an instruction infringes Data Protection Laws.
3. Confidentiality
Chad ensures that persons it authorizes to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and process Customer Personal Data only as needed to perform the Services.
4. Security
Chad implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing. These measures include, at a minimum, those described in Annex II. Chad may update its measures from time to time, provided the updates do not materially reduce the overall level of protection during a Subscription Term.
5. Sub-processors
Customer provides general written authorization for Chad to engage sub-processors to process Customer Personal Data, as set out in Section 5.3 of the Agreement. The current list of sub-processors, along with the purpose of each, is maintained on Chad’s Trust Center. Chad will notify Customer of material changes to the list, and Customer may object on reasonable data-protection grounds within thirty (30) days of the notice as set out in the Agreement. Chad imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for its sub-processors’ performance as set out in the Agreement.
6. Assistance
Taking into account the nature of the processing, Chad will assist Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling Customer’s obligation to respond to requests from data subjects exercising their rights under Data Protection Laws (including access, rectification, erasure, restriction, portability and objection). If a data subject contacts Chad directly regarding Customer Personal Data, Chad will direct the data subject to Customer and will not respond substantively except on Customer’s instruction or where required by law.
Taking into account the nature of the processing and the information available to Chad, Chad will assist Customer in ensuring compliance with Customer’s obligations under Articles 32 to 36 GDPR, including security of processing, notification of personal data breaches to supervisory authorities and data subjects, data protection impact assessments, and prior consultation with supervisory authorities.
7. Personal Data Breach
Chad will notify Customer without undue delay, and in any event within seventy-two (72) hours of discovery, of a Security Incident affecting Customer Personal Data, as set out in Section 5.2 of the Agreement. Chad’s notification will include information reasonably available to Chad to assist Customer in meeting its own breach-notification obligations, and Chad will provide timely updates as further information becomes available.
8. Deletion or Return
Upon termination or expiration of the Agreement, Chad will, at Customer’s choice, delete or return all Customer Personal Data, and delete existing copies, unless European Union or Member State (or UK or Swiss) law requires storage of the personal data or retention is otherwise permitted under this Section. If Customer does not communicate a choice within the 45-day retrieval window described in Section 4.4 of the Agreement, Chad will proceed to deletion in accordance with the retention schedule in the Chad GDPR Policy. Chad may retain Customer Personal Data (a) where retention is required by applicable law, (b) to the extent necessary for the establishment, exercise or defense of legal claims, in accordance with the retention periods described in the Chad GDPR Policy, and (c) where the same data constitutes part of a shared shopper record that remains necessary to provide the Services to another customer, in which case Chad processes that record as an independent controller as described in the Shopper Privacy Notice. Data retained under this Section remains protected by the measures in Annex II and is deleted when the applicable retention ground expires, including erasure from backups within Chad’s standard backup rotation cycle.
9. Audit and Information
Chad will make available to Customer information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allow for and contribute to audits, as set out in Section 5.3 of the Agreement. The Parties agree that this obligation may be satisfied by Chad’s then-current SOC 2 report or an equivalent third-party audit report, provided no more than once per year on reasonable written request, in lieu of an on-site audit.
10. International Transfers
Customer Personal Data is stored and processed in the United States. For transfers of personal data from the EU/EEA, the United Kingdom, or Switzerland, Chad relies on the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework, under the applicable adequacy decisions. If a transfer mechanism relied on by Chad is invalidated or otherwise ceases to be a lawful basis for the transfer, the Parties will cooperate in good faith to promptly implement an alternative lawful transfer mechanism.
Annex I — Description of the Processing
Annex II — Technical and Organisational Measures
Encryption. All data is encrypted in transit using TLS (version 1.2 or higher), with HTTPS enforced and HTTP Strict Transport Security enabled, and encrypted at rest on Google Cloud Platform. Credentials and authentication tokens are additionally encrypted at the application layer using rotation-capable keys held in a dedicated secrets-management service. A written data-classification policy governs handling requirements for each data sensitivity level.
Access control. Access follows least-privilege, role-based principles. All human access is federated through a single identity provider with multi-factor authentication. Production infrastructure is managed exclusively as reviewed code: organisation-level deny policies prevent direct human modification of production resources, and creation of long-lived service-account keys is disabled organisation-wide — workloads and personnel authenticate using short-lived, keyless credentials. Access rights are reviewed quarterly.
Network and application security. Public services are protected by a web application firewall with OWASP Core Rule Set protections, DDoS mitigation and rate limiting; internal services are not reachable from the internet. Inbound third-party webhooks are verified using constant-time signature checks.
Logging and monitoring. Cloud audit logs are monitored with automated alerting on destructive or out-of-process changes. Application logging redacts personal data by design. Security-relevant alerts are routed to engineering and compliance channels, and scheduled data-protection jobs carry failure alerting.
Backups and resilience. Databases are backed up daily with defined retention periods. Restore procedures are exercised through automated quarterly restore drills, with recorded evidence of each drill.
Secure development. All code changes require independent review and must pass automated gates, including secret scanning and personal-data scanning, before release. Dependencies are updated under a supply-chain cooldown policy. Infrastructure configuration drift is detected on a weekly schedule.
Data minimisation and deletion. Automated retention and erasure processes enforce documented retention periods, action erasure requests, and verify propagation of erasures to sub-processors, each monitored for failure.
Organisational measures. Chad maintains SOC 2 attestation covering its organisational controls, including personnel security, confidentiality commitments and access management. Chad’s then-current SOC 2 report is available as described in Section 9 of this DPA.