Legal

Data Processing Addendum

Baseline data-processing terms for customer personal data processed through Emissa.

Last updated: August 18, 2026

1. Scope

This Data Processing Addendum applies when incorporated into an agreement between Emissa and a customer and Emissa processes personal data on the customer's behalf in connection with the service.

2. Roles and instructions

For customer-controlled personal data, the customer acts as controller or business and Emissa acts as processor or service provider, as applicable. Emissa will process that data only on documented instructions, including the applicable agreement and configured use of the service, unless otherwise required by law.

3. Confidentiality and security

Emissa will require personnel authorized to process covered personal data to be subject to confidentiality obligations and will maintain reasonable technical and organizational measures appropriate to the service and risk.

4. Subprocessors

Emissa may use subprocessors to provide hosting, storage, authentication, payments, communications, analytics, support, and other service functions. Emissa remains responsible for requiring subprocessors to protect covered personal data consistent with applicable contractual obligations.

5. Assistance

Taking into account the nature of processing and information available to Emissa, Emissa will provide reasonable assistance with legally required data-subject requests, security obligations, breach response, and data-protection assessments where applicable.

6. Security incidents

Emissa will notify affected customers without undue delay after confirming a personal-data breach for which notification is required under the applicable agreement or law, and will provide reasonably available information relevant to the incident.

7. Return and deletion

At the end of the service, covered personal data will be returned or deleted according to the applicable agreement, customer instructions, backup cycles, and legal retention obligations.

8. International transfers

Where legally required, the parties will use an appropriate transfer mechanism for cross-border transfers of personal data.

9. Audits and information

Emissa will make reasonably necessary information available to demonstrate compliance with applicable processor obligations, subject to confidentiality, security, scope, and frequency limitations in the applicable agreement.

10. Priority

If this DPA conflicts with a signed customer agreement or negotiated data-processing addendum, the signed agreement controls.