This Data Processing Addendum ("DPA") forms part of the RED Atlas Enterprise Terms of Service or other written agreement between RED Atlas Inc. ("RED Atlas") and Customer (the "Agreement"), and applies where RED Atlas processes Personal Data within Customer Data on Customer's behalf. Capitalized terms not defined here have the meanings in the Agreement. "Personal Data," "processing," "controller," "processor," "data subject," and "supervisory authority" have the meanings given by applicable Data Protection Laws, which means all laws applicable to the processing of Personal Data under the Agreement, including (as applicable) the EU and UK GDPR, the CCPA, Puerto Rico and other U.S. law, and Colombia's Law 1581 of 2012.
1. Roles and Scope
For Personal Data within Customer Data, Customer is the controller (or a processor acting for another controller, which Customer will disclose) and RED Atlas is a processor. For personal data RED Atlas processes for its own purposes — RED Atlas Data (including property and contact records described in the Property & Contact Data Privacy Notice), account data, and usage data — RED Atlas is an independent controller, processing as described in the RED Atlas Privacy Policy; that processing is outside this DPA. The subject matter, duration, nature and purpose of processing, and the types of Personal Data and categories of data subjects are set out in Annex I, as set out in the applicable Order Form.
2. Processing Instructions
RED Atlas will process Customer Personal Data only on Customer's documented instructions — as set out in the Agreement, this DPA, and Customer's configuration and use of the RED Atlas Services — unless required otherwise by law (in which case RED Atlas will inform Customer unless legally prohibited). RED Atlas will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
3. Confidentiality and Personnel
RED Atlas ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations and receive appropriate data-protection training, and limits access to personnel who need it to perform the Agreement.
4. Security
RED Atlas implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, including the measures described in Annex II, as attached to the applicable Order Form, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
5. Subprocessors
Customer generally authorizes RED Atlas to engage subprocessors for the processing described in this DPA. The current list is maintained at atlas.red/notices/subprocessors. RED Atlas will provide at least thirty (30) days' notice (by updating that page and/or email) before adding or replacing a subprocessor; Customer may object on reasonable data-protection grounds within that period, and the parties will work in good faith to resolve the objection (including, if unresolved, allowing Customer to terminate the affected Service with a prorated refund of prepaid fees). RED Atlas imposes data-protection obligations on subprocessors no less protective than this DPA and remains responsible for their performance.
6. Assistance
Taking into account the nature of the processing, RED Atlas will assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligations to respond to data-subject requests (access, rectification, erasure, restriction, objection, portability), and — taking into account the information available to RED Atlas — with Customer's security, breach-notification, data-protection-impact-assessment, and prior-consultation obligations. If a data subject contacts RED Atlas directly regarding Customer Personal Data, RED Atlas will redirect the request to Customer and will not respond substantively except as legally required.
7. Personal Data Breach
RED Atlas will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data, and will provide information reasonably available to RED Atlas about the nature of the breach, the categories and approximate numbers of data subjects and records concerned, likely consequences, and measures taken or proposed, supplementing the notice as information becomes available. RED Atlas's notification is not an acknowledgment of fault or liability.
8. Audits
On written request no more than once per twelve (12) months (and additionally following a Personal Data breach affecting Customer Personal Data), RED Atlas will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow and contribute to audits, including inspections, conducted by Customer or its mandated auditor, on reasonable notice, during business hours, under confidentiality, at Customer's expense, and in a manner that does not compromise other customers' data or RED Atlas security.
9. International Transfers
Where the processing involves a transfer of Personal Data from the EEA, the UK, or Switzerland to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor) — with Annexes completed by Annex I and Annex II of this DPA, the optional docking clause included, and Clause 17/18 electing the laws of the Commonwealth of Puerto Rico, with courts sitting in San Juan, Puerto Rico — and, for UK transfers, the UK International Data Transfer Addendum issued by the ICO; for Swiss transfers, the Clauses are adapted as required by the FDPIC. RED Atlas's Intra-Group Personal Data Protection Statement describes intra-group transfer safeguards.
10. Return and Deletion
Upon termination or expiration of the Agreement, RED Atlas will, at Customer's choice, return or delete Customer Personal Data within thirty (30) days, except where retention is required by law or the data resides in routine backups pending scheduled destruction, in which case this DPA continues to protect it and it is isolated from further processing.
11. CCPA Service Provider Terms
Where the CCPA applies to Customer Personal Data, RED Atlas acts as Customer's "service provider": it will not sell or share that Personal Data; will not retain, use, or disclose it outside the direct business relationship or for any purpose other than performing the Services (or as the CCPA otherwise permits); will comply with applicable CCPA obligations and provide the same level of privacy protection required of businesses; will notify Customer if it can no longer comply; and permits Customer to take reasonable steps to stop and remediate unauthorized use.
12. General
Liability under this DPA is subject to the limitations and exclusions of the Agreement. In case of conflict, this DPA prevails over the Agreement with respect to the processing of Customer Personal Data, and the Standard Contractual Clauses prevail over this DPA. This DPA terminates automatically with the Agreement, surviving only as long as RED Atlas processes Customer Personal Data.