← TerraTester

Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Controller”) and Terra Tester (“Processor”) for the TerraTester service, and applies to the extent the Processor processes personal data on the Controller's behalf. Terms such as “personal data”, “processing”, “data subject” and “personal data breach” have the meanings given in applicable data-protection law.

1. Subject matter and duration

The Processor processes personal data contained in Customer Data to provide the Service, for the duration of the agreement plus any agreed export and deletion window.

2. Nature and purpose

Hosting, storage and processing of laboratory records so the Controller can operate its laboratory workflow — jobs, samples, specimens, test results, conformity assessments, certificates and user administration.

3. Personal data and data subjects

Categories of personal data: the names, email addresses and roles of the Controller's users; and any personal data the Controller chooses to include in laboratory records, such as client contact details. Categories of data subjects: the Controller's personnel and the contacts of its clients. The parties do not intend for special-category data to be processed.

4. Processor obligations

The Processor shall:

5. Subprocessors

The Controller authorises the Processor to engage the subprocessors listed below. The Processor imposes data-protection obligations on each subprocessor no less protective than those in this DPA and remains responsible for their performance.

The Processor will give the Controller prior notice of any intended addition or replacement of a subprocessor, giving the Controller the opportunity to object on reasonable data-protection grounds.

6. International transfers

Personal data is hosted in The Netherlands. Where personal data is transferred outside that region, the parties rely on the Standard Contractual Clauses or another lawful transfer mechanism.

7. Audits

The Processor will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and no more than once per year (unless required by a supervisory authority or following a breach), allow for and contribute to audits, subject to confidentiality and to not compromising the security of other customers.

8. Liability and governing law

Each party's liability under this DPA is subject to the limitations and exclusions in the agreement. This DPA is governed by the laws of the applicable jurisdiction. In the event of a conflict between this DPA and the agreement on the subject of data protection, this DPA prevails.