Data Processing Addendum

Applies where RisqRadar processes personal data on behalf of a customer.

Effective date: August 8, 2026

1. Roles of the parties

This Data Processing Addendum ("DPA") supplements the Terms of Service between the customer ("Controller") and DSPLife Collaborative Group ("RisqRadar", "Processor"). It applies to the extent RisqRadar processes personal data contained in Customer Data on the Controller's behalf. Where the GDPR or UK GDPR applies, the Controller is the controller and RisqRadar is the processor.

2. Details of processing

  • Subject matter — provision of the RisqRadar GRC platform.
  • Duration — the term of the agreement, plus any limited post-termination export/deletion period.
  • Nature and purpose — hosting, storing, and processing Customer Data to provide and support the service.
  • Types of personal data — determined by the Controller; may include names, business contact details, user account data, and any personal data the Controller enters into records.
  • Categories of data subjects — the Controller's personnel, contacts at its vendors and business units, and other individuals referenced in Customer Data.

3. Processor obligations

RisqRadar will: (a) process personal data only on the Controller's documented instructions, including as set out in the Terms and this DPA, unless required by law; (b) ensure personnel authorized to process personal data are bound by confidentiality; (c) implement appropriate technical and organizational security measures; and (d) not sell personal data or use it other than to provide the service.

4. Subprocessors

The Controller authorizes RisqRadar to engage the subprocessors listed on our Subprocessors page. RisqRadar will impose data-protection obligations on each subprocessor substantially similar to those in this DPA and remains responsible for its subprocessors' performance. RisqRadar will provide notice before adding a new subprocessor, and the Controller may object on reasonable data-protection grounds.

5. Assistance to the Controller

Taking into account the nature of the processing, RisqRadar will provide reasonable assistance to the Controller in responding to data-subject requests and in meeting its obligations regarding security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.

6. Personal data breach notification

RisqRadar will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to help the Controller meet its notification obligations.

7. Return and deletion

On termination of the service, and at the Controller's choice, RisqRadar will make Customer Data available for export for a limited period and will then delete or return it, except where retention is required by law.

8. Audits

RisqRadar will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality, scheduling, and security conditions. Where available, third-party reports and security documentation may be provided to satisfy audit requests.

9. International transfers

Where the processing of personal data subject to the GDPR or UK GDPR involves a transfer to a country without an adequacy decision, the parties agree that the applicable Standard Contractual Clauses are incorporated by reference and apply to that transfer.

10. Precedence and execution

In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls. A signed counterpart of this DPA is available on request for customers that require an executed agreement. Questions may be sent to legal@risqradar.com.