Data Processing Addendum (DPA)
This Data Processing Addendum ("DPA") forms part of the Master Services Agreement ("Agreement") between the Customer and WILLAY LLC, a company incorporated in Wyoming with a mailing address at 530-B Harkle Road, Suite 100, Santa Fe, New Mexico (NM), 87505, USA ("WILLAY").
1. Definitions
- Data Protection Laws: All applicable data protection and privacy legislation, including the EU GDPR, UK GDPR, and CCPA.
- Customer Personal Data: Any personal data that WILLAY processes on behalf of the Customer under the Agreement.
- Data Subject: The individual to whom the personal data relates.
- Subprocessor: Any third party engaged by WILLAY to process Customer Personal Data.
2. Processing of Personal Data
2.1 Roles of the Parties: Customer is the Data Controller; WILLAY is the Data Processor.
2.2 Customer Instructions: WILLAY processes data only per documented Customer instructions.
2.3 Purpose Limitation: Data is processed solely to provide Services or as legally required.
3. Security Measures
3.1 WILLAY will implement appropriate technical and organizational safeguards.
3.2 Measures include encryption, access controls, incident response, and secure storage.
4. Subprocessors
4.1 Subprocessors may be used, provided they meet the same obligations.
- Bound by similar data protection terms
- WILLAY remains liable for their actions
4.2 A list of Subprocessors is available upon request.
5. International Transfers
Transfers outside the EEA/UK will use safeguards like SCCs, adequacy decisions, or binding corporate rules.
6. Data Subject Rights
6.1 WILLAY assists with access, correction, or deletion requests.
6.2 Direct requests from data subjects will be forwarded to Customer.
7. Data Breach Notification
7.1 In the event of a breach, WILLAY will notify Customer without undue delay.
7.2 Notification will include breach details, data affected, and mitigation steps.
8. Return or Deletion of Data
Upon termination, WILLAY will return or delete Customer Personal Data unless legally required to retain it.
9. Audit Rights
Customer may audit WILLAY's compliance with this DPA once per year with prior notice, subject to confidentiality obligations.
10. Miscellaneous
10.1 This DPA is governed by the same law and jurisdiction as the Master Services Agreement.
10.2 In case of conflict, this DPA prevails with respect to data protection matters.