Legal / Data Processing Addendum
Data Processing Addendum
Effective
This Data Processing Addendum applies when an order or written support confirmation makes it part of the agreement between the customer and Resilis, Inc. The parties must confirm the processing scope, roles, service, and applicable requirements for each use.
Scope and roles
Processing covers the customer-selected cloud services for the term of the applicable agreement. Operations may include receiving, hosting, storing, organizing, retrieving, transmitting, securing, supporting, returning, and deleting customer personal data. The customer determines data subjects and data categories through its workloads and documented instructions; the applicable order must identify any additional service-specific requirements. Controller and processor roles depend on the service and the customer’s instructions and must be identified in the applicable order or written confirmation.
Instructions and confidentiality
Where applicable data-protection law requires, Resilis processes customer personal data only on documented customer instructions, including instructions concerning international transfers, unless law requires otherwise. Resilis will inform the customer of that legal requirement unless prohibited and will notify the customer if an instruction appears to infringe applicable data-protection law. The customer must have the rights and notices needed to send the data to Resilis.
People who handle customer personal data must have a confidentiality duty.
Security and assistance
Resilis uses appropriate technical and organizational measures to protect customer personal data as required by applicable law. Specific measures depend on the service, the risks to the data, and the applicable order.
Where applicable data-protection law requires, Resilis will assist with data-subject requests, security obligations, impact assessments, and regulator consultations, taking account of the nature of processing and information available to Resilis. Where required by applicable data-protection law, Resilis will notify the customer of a personal-data breach without undue delay after becoming aware of it and provide the information required by applicable law.
Service providers
Resilis may use subprocessors to operate the agreed service. Where applicable law requires, Resilis will obtain specific or general written authorization before engaging a subprocessor. Under general authorization, Resilis will give advance notice of intended additions or replacements and an opportunity to object. Resilis will impose equivalent data-protection obligations on subprocessors as required by applicable law. The provider roles, locations, notice process, and applicable safeguards must be identified in the service-specific information or order.
Transfers and locations
Processing locations depend on the Resilis-operated service, its delivery providers, and any customer-selected external data, storage, or compute. Any region, transfer safeguard, or data-location commitment must be identified in the applicable service agreement before use.
Return, deletion, and records
Where applicable law requires, at the end of the service Resilis will return or delete customer personal data at the customer’s choice, unless law requires retention. Retained data remains subject to the applicable protection obligations. The order describes supported export and deletion procedures, including backup handling. The Privacy Notice describes a three-month limit for Resilis personal information after account termination; customer data processed under this Addendum may have a different service-specific schedule.
Resilis will make compliance information available and allow or contribute to audits and inspections to the extent required by applicable data-protection law. The parties will use the agreed process for these requests without limiting rights that the law requires.