Effective date: August 8, 2026
This Data Processing Addendum ("DPA") supplements the Terms of Service between the customer ("Controller") and DSPLife Collaborative Group ("RisqRadar", "Processor"). It applies to the extent RisqRadar processes personal data contained in Customer Data on the Controller's behalf. Where the GDPR or UK GDPR applies, the Controller is the controller and RisqRadar is the processor.
RisqRadar will: (a) process personal data only on the Controller's documented instructions, including as set out in the Terms and this DPA, unless required by law; (b) ensure personnel authorized to process personal data are bound by confidentiality; (c) implement appropriate technical and organizational security measures; and (d) not sell personal data or use it other than to provide the service.
The Controller authorizes RisqRadar to engage the subprocessors listed on our Subprocessors page. RisqRadar will impose data-protection obligations on each subprocessor substantially similar to those in this DPA and remains responsible for its subprocessors' performance. RisqRadar will provide notice before adding a new subprocessor, and the Controller may object on reasonable data-protection grounds.
Taking into account the nature of the processing, RisqRadar will provide reasonable assistance to the Controller in responding to data-subject requests and in meeting its obligations regarding security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
RisqRadar will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to help the Controller meet its notification obligations.
On termination of the service, and at the Controller's choice, RisqRadar will make Customer Data available for export for a limited period and will then delete or return it, except where retention is required by law.
RisqRadar will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality, scheduling, and security conditions. Where available, third-party reports and security documentation may be provided to satisfy audit requests.
Where the processing of personal data subject to the GDPR or UK GDPR involves a transfer to a country without an adequacy decision, the parties agree that the applicable Standard Contractual Clauses are incorporated by reference and apply to that transfer.
In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls. A signed counterpart of this DPA is available on request for customers that require an executed agreement. Questions may be sent to legal@risqradar.com.