Data Processing Addendum
Related drafts: Acceptable use · Security · Open-source notices · Export & sanctions
This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer") and the registered legal entity behind Ferrite Security (available on request — contact admin@ferritesec.com; name it here directly, not as a personal name) ("Ferrite", "we") for use of Ferrite where we process personal data on the Customer's behalf. It is intended to reflect GDPR Article 28 and comparable laws.
1. Local-only processing — important
Ferrite is a local-only, zero-telemetry product: the connection, DNS, and inspection data it processes stays on the Customer's devices and is not transmitted to us. For that data we are neither controller nor processor. This DPA therefore applies to the limited personal data we do process — principally account and purchase data for Pro / Enterprise licensing (for example a contact email, license and device-activation identifiers, and payment metadata handled by our payment processor).
2. Roles
For that limited data, the Customer is the controller and Ferrite is the processor. Each party complies with its obligations under applicable data-protection law.
3. Scope, nature & purpose
Subject matter: provision of Ferrite licensing and support. Duration: the term of the agreement. Nature and purpose: account creation, license activation and validation, billing, and support. Categories of data subjects: the Customer's authorized users and administrators. Categories of personal data: [contact details, license identifiers, device identifiers, billing metadata]. No special-category data is required. [See Schedule 1.]
4. Our obligations as processor
- Process personal data only on the Customer's documented instructions.
- Ensure persons authorized to process are bound by confidentiality.
- Implement appropriate technical and organizational security measures (GDPR Art. 32). [See Schedule 2.]
- Assist the Customer with data-subject requests, and with DPIAs and prior consultations, taking into account the nature of processing.
- Notify the Customer without undue delay, and within [X hours], of a personal-data breach.
- Delete or return personal data at the end of the agreement, subject to legal retention.
- Make available information needed to demonstrate compliance and allow for reasonable audits.
5. Sub-processors
The Customer authorizes our use of sub-processors, currently including Polar (payment processing and merchant of record) and [hosting / email providers — to be listed]. We remain responsible for their compliance and will give [X days'] notice of changes so the Customer can object.
6. International transfers
Where personal data is transferred across borders, the parties will rely on a valid transfer mechanism, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable. [To be completed by counsel.]
7. Customer responsibilities for deployments to others' devices
Where the Customer deploys Ferrite on devices used by its personnel or clients, the Customer is solely responsible for establishing a lawful basis and providing any notice or consent required (including employee-monitoring and works-council obligations), as noted in our Acceptable Use Policy.
Schedules: Schedule 1 — details of processing · Schedule 2 — technical & organizational measures · Schedule 3 — approved sub-processors. [To be attached.]
← Back to home · Requests: admin@ferritesec.com