Data Processing Addendum
1. Roles & Scope
This Data Processing Addendum ("DPA") establishes the terms under which LORIQ Technologies, LLC ("Processor") processes Personal Data on behalf of the Customer ("Controller"). It applies when LORIQ acts as a data processor subject to applicable data protection laws.
2. Processing Instructions
LORIQ will process Personal Data only in accordance with Customer's documented instructions, which include processing to provide the services as defined in the primary agreement.
3. Confidentiality & Security Measures
LORIQ ensures that personnel authorized to process Personal Data have committed themselves to confidentiality. LORIQ implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
4. Subprocessors
Customer provides general authorization for LORIQ to engage Subprocessors. LORIQ will impose data protection obligations on Subprocessors that are substantially the same as those set out in this DPA.
5. Data Subject Requests
LORIQ will provide reasonable assistance to the Customer in fulfilling its obligation to respond to requests for exercising data subjects' rights (such as access, deletion, or rectification).
6. Incident Notification
In the event of a confirmed Personal Data Breach, LORIQ will notify the Customer without undue delay and provide reasonable assistance in investigating and mitigating the incident.
7. Deletion & Return
Upon termination of the services, LORIQ will, at the Customer's choice, delete or return all Personal Data, unless applicable law requires continued storage.
8. Audits & Compliance
LORIQ will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to reasonable audits conducted by the Customer or an independent auditor.
9. International Transfers
Any transfer of Personal Data originating from the EEA, UK, or Switzerland to countries lacking an adequacy decision will be governed by the applicable Standard Contractual Clauses (SCCs).
Exhibits
Exhibit A: Processing Details
The categories of Personal Data processed, the categories of data subjects, the nature and purpose of processing, and the duration of processing are specified for each Customer during enterprise onboarding and documented in the applicable order form or statement of work. Absent such documentation, LORIQ processes only the Personal Data submitted by the Customer through the services, solely for the purpose of providing those services, and for the duration of the primary agreement.
Exhibit B: Security Measures
LORIQ maintains technical and organizational security measures that include: encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256); role-based access controls with least-privilege provisioning; multi-factor authentication for administrative access; network segmentation and firewall protection; centralized logging and monitoring; regular vulnerability management; and documented incident response procedures. A current, detailed description of these measures is available to Customers upon request.
Exhibit C: Subprocessor List
LORIQ engages a limited set of infrastructure and service providers (such as cloud hosting and email delivery providers) to support delivery of the services. A current list of subprocessors is available to Customers upon written request to info@loriqtechnologies.com. LORIQ will provide notice of new subprocessors in accordance with Section 4 of this DPA.
Contact Information
For questions regarding this policy, please contact us at:
