This page summarizes the framework for CLAWOLF's Data Processing Addendum (DPA). The executed DPA in your order or master agreement controls in case of conflict.
DPA structure
- Parties and order reference
- Controller/processor roles
- Documented instructions
- Confidentiality
- Verified security measures
- Subprocessor authorization and notice
- Assistance with data-subject rights requests
- Personal-data breach cooperation and notice terms
- Data protection impact assessment and regulator assistance where applicable
- Deletion or return after termination
- Audit-information process
- International-transfer mechanism only when applicable and executed
- Processing details schedule
- Technical and organizational measures schedule
- Verified subprocessor schedule
Core processing terms
Customer appoints CLAWOLF to process personal data only to provide and secure the services described in the applicable agreement and according to Customer's documented lawful instructions. CLAWOLF will ensure that persons authorized to process personal data are subject to appropriate confidentiality obligations.
CLAWOLF will implement and maintain technical and organizational measures appropriate to the risk and documented in the applicable security schedule. Customer authorizes the subprocessors listed in the then-current Subprocessor Schedule. CLAWOLF will provide reasonable assistance for data-subject requests, security incidents, DPIAs, and regulator inquiries as required by applicable law.
On termination, CLAWOLF will delete or return personal data according to the agreement, except where law requires retention.
International transfers
If a restricted transfer requires European Commission Standard Contractual Clauses, UK transfer terms, KVKK standard contracts, or another mechanism, the parties will complete and execute the applicable module and schedules. No transfer mechanism is incorporated merely by being mentioned on this website.
Contact [email protected] for a executed DPA copy applicable to your agreement.