1. Scope
This Data Processing Addendum applies when incorporated into an agreement between Emissa and a customer and Emissa processes personal data on the customer's behalf in connection with the service.
2. Roles and instructions
For customer-controlled personal data, the customer acts as controller or business and Emissa acts as processor or service provider, as applicable. Emissa will process that data only on documented instructions, including the applicable agreement and configured use of the service, unless otherwise required by law.
3. Confidentiality and security
Emissa will require personnel authorized to process covered personal data to be subject to confidentiality obligations and will maintain reasonable technical and organizational measures appropriate to the service and risk.
4. Subprocessors
Emissa may use subprocessors to provide hosting, storage, authentication, payments, communications, analytics, support, and other service functions. Emissa remains responsible for requiring subprocessors to protect covered personal data consistent with applicable contractual obligations.
5. Assistance
Taking into account the nature of processing and information available to Emissa, Emissa will provide reasonable assistance with legally required data-subject requests, security obligations, breach response, and data-protection assessments where applicable.
6. Security incidents
Emissa will notify affected customers without undue delay after confirming a personal-data breach for which notification is required under the applicable agreement or law, and will provide reasonably available information relevant to the incident.
7. Return and deletion
At the end of the service, covered personal data will be returned or deleted according to the applicable agreement, customer instructions, backup cycles, and legal retention obligations.
8. International transfers
Where legally required, the parties will use an appropriate transfer mechanism for cross-border transfers of personal data.
9. Audits and information
Emissa will make reasonably necessary information available to demonstrate compliance with applicable processor obligations, subject to confidentiality, security, scope, and frequency limitations in the applicable agreement.
10. Priority
If this DPA conflicts with a signed customer agreement or negotiated data-processing addendum, the signed agreement controls.