Status of this framework
This page describes the baseline data-processing commitments Pacorda, Inc. expects to include in an enterprise Data Processing Addendum (“DPA”). It is not self-executing and does not replace a signed DPA, customer agreement, order form, or jurisdiction-specific schedule.
The signed DPA will identify the parties, services, subject matter, duration, data categories, data subjects, processing instructions, transfer mechanism, audit process, liability allocation, and any negotiated terms.
Roles and instructions
For customer-controlled personal information, the enterprise customer generally acts as controller or business and Pacorda, Inc. acts as processor or service provider. Pacorda, Inc. processes that information only to provide, secure, support, and improve the contracted service; follow documented lawful instructions; comply with law; or as otherwise permitted by the signed DPA.
Pacorda will notify the customer if it reasonably believes an instruction violates applicable data-protection law, unless prohibited from doing so.
Subprocessors
Pacorda may use carefully selected subprocessors for technology, development, hosting, security, reliability, and technical-support services. Each subprocessor must be bound to confidentiality, security, use, and data-protection obligations appropriate to its role.
Customer-controlled personal information is not used for unrelated advertising or independent commercial purposes.
Confidentiality and personnel
Personnel authorized to process customer-controlled personal information must be subject to confidentiality obligations, receive role-appropriate training, and access information only according to business need and least-privilege controls.
Security measures
The signed DPA and security schedule should address access governance, authentication, encryption where appropriate, environment separation, logging, secure development, vulnerability management, incident response, backups, resilience, vendor risk, deletion, and periodic review.
Security measures may evolve to address risk and technology, provided the overall level of protection is not materially reduced during the service term.
Subprocessors
Pacorda may engage affiliates and third parties to provide infrastructure, communications, verification, compliance, analytics, support, and other contracted functions. The signed DPA should provide a current subprocessor mechanism, advance notice of material changes, an objection process based on reasonable data-protection grounds, and flow-down obligations.
Independent banks and financial providers may act under their own legal roles rather than as Pacorda subprocessors; their terms and notices govern their independent processing.
Individual rights
Taking into account the nature of processing, Pacorda will provide reasonable assistance for access, correction, deletion, restriction, portability, objection, opt-out, and automated-decision requests that apply to customer-controlled data. Pacorda may direct an individual to the relevant enterprise and will not independently respond on the enterprise’s behalf unless authorized or legally required.
Security incidents
Pacorda will notify the customer without undue delay after confirming a personal-data breach affecting customer-controlled data, consistent with the signed DPA. Notice should include available information about nature, scope, likely consequences, mitigation, and a contact point, and may be provided in phases as facts develop.
Incident notice is not an admission of fault or liability. The customer remains responsible for notifications it is legally required to make, with reasonable assistance from Pacorda.
Government requests
Where legally permitted, Pacorda will notify the customer of a binding government request for customer-controlled data, review the request for facial validity, seek appropriate limitation, and disclose only information legally required. Pacorda will not provide voluntary bulk access to customer-controlled data.
International transfers
When restricted transfers require a mechanism, the signed DPA may incorporate applicable standard contractual clauses, UK addendum, adequacy decisions, certifications, or other lawful safeguards. The parties may document transfer assessments and supplementary measures appropriate to the data and destination.
Return and deletion
At termination or expiration, Pacorda will return or delete customer-controlled personal information as specified in the signed DPA, except information retained under law, financial-record requirements, security controls, legal holds, dispute preservation, or technically isolated backup cycles. Retained information remains protected and is not used for unrelated purposes.
Information and audits
Pacorda will make information reasonably necessary to demonstrate DPA compliance available through documentation, independent reports where available, questionnaires, and a proportionate audit process that protects other customers, security, confidentiality, and provider obligations. Audit frequency, notice, scope, cost, and remediation will be defined in the signed DPA.
Contact and execution
To request an executable DPA for a production engagement, contact [email protected]. The signed version must be reviewed together with the customer agreement, security schedule, financial-provider structure, and applicable laws.