← hazrespondr.com

Data Processing Addendum (DPA)

Effective Date: Completed at signature — the date on the executed signature page. This public copy is the unsigned template.

Processor: HazRespondr LLC, a Maryland limited liability company ("HazRespondr")

Controller: The customer organization identified on the executed signature page ("Customer")

Document status. Drafted by the HazRespondr engineering/ops team as an acquisition-diligence-grade template, intended to be reviewed and finalized by qualified legal counsel before execution. This is not legal advice. The canonical source is docs/legal/DPA-TEMPLATE.md; this page is its public mirror.

This Data Processing Addendum ("DPA") supplements and is incorporated into the Master Services Agreement, Terms of Service, order form, or other written agreement between the parties governing Customer's use of the HazRespondr platform (the "Agreement"). In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls.

1. Definitions

Capitalized terms not defined below have the meaning given in the Agreement or in applicable Data Protection Laws.

2. Subject Matter and Duration

2.1 Subject matter

HazRespondr provides a cloud-hosted hazmat team compliance platform covering inventory management, personnel training records, equipment maintenance, and incident reporting. In the course of providing the Service, HazRespondr processes Personal Data that Customer submits to the Service.

2.2 Duration

This DPA is effective for the duration of the Agreement and for any additional period during which HazRespondr processes Personal Data on Customer's behalf (including the return/deletion period described in Section 13).

3. Nature and Purpose of Processing

HazRespondr processes Personal Data solely to:

  1. Provide the Service to Customer under the Agreement, including account provisioning, authentication, access control, and feature delivery (training tracking, certification expiry alerts, equipment/calibration management, incident reporting, audit logging);
  2. Support Customer's compliance with applicable safety, training, and recordkeeping regulations (OSHA 29 CFR 1910.120, NFPA standards, EPA Tier II, NFIRS, etc.);
  3. Provide customer support, troubleshooting, and security monitoring;
  4. Deliver transactional email notifications (certification expiry, work-order assignments, incident assignments) to Data Subjects Customer has added to the Service;
  5. Meet HazRespondr's legal obligations;
  6. Preserve tamper-evident audit records as required by Customer's compliance programs and by SOC 2 control objectives.

HazRespondr will not process Personal Data for any purpose other than those set out above or subsequently agreed in writing. HazRespondr specifically confirms that it does not sell or share Personal Data, and does not use Personal Data for advertising, profiling, or training of AI/ML models beyond what is necessary to provide the Service to the originating Customer.

4. Types of Personal Data

The categories of Personal Data processed under this DPA typically include:

The categories of Personal Data are ultimately determined by Customer based on what Customer and its authorized users upload to the Service.

5. Categories of Data Subjects

The Data Subjects typically include:

6. Controller and Processor Obligations

6.1 Customer as Controller

Customer acknowledges that it is the Controller (and, where applicable, the "Business" under CCPA/CPRA) of Personal Data it uploads to or generates within the Service. Customer represents and warrants that:

6.2 HazRespondr as Processor

HazRespondr will:

  1. Process Personal Data only on documented instructions from Customer, including the Agreement, this DPA, Customer's configuration of the Service, and any subsequent written instructions. If HazRespondr is required by law to process Personal Data otherwise, HazRespondr will (to the extent legally permitted) inform Customer of that legal requirement before processing.
  2. Ensure that authorized personnel who process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  3. Implement the technical and organizational security measures described in Section 11 and in the HazRespondr Security Practices document.
  4. Not engage a Sub-processor without prior general written authorization from Customer and subject to Section 7.
  5. Assist Customer in fulfilling its obligations to respond to Data Subject rights requests, as set out in Section 9.
  6. Assist Customer in ensuring compliance with its obligations under Applicable Data Protection Laws, including security, breach notification, and data-protection impact assessment obligations, taking into account the nature of processing and the information available to HazRespondr.
  7. At Customer's choice, delete or return all Personal Data to Customer after the end of the provision of Services relating to processing, and delete existing copies, unless Applicable Data Protection Laws require otherwise (see Section 13).
  8. Make available to Customer all information reasonably necessary to demonstrate compliance with this DPA (see Section 12).

6.3 CCPA/CPRA-specific obligations

For Personal Data subject to CCPA/CPRA, HazRespondr will:

7. Sub-processors

7.1 General authorization

Customer grants HazRespondr general written authorization to engage Sub-processors to assist in providing the Service, provided that HazRespondr:

  1. Enters into a written agreement with each Sub-processor imposing data-protection obligations substantially similar to those in this DPA;
  2. Remains liable to Customer for the acts and omissions of its Sub-processors;
  3. Selects Sub-processors that provide sufficient guarantees of appropriate technical and organizational measures.

7.2 Current Sub-processors

The current list of Sub-processors is maintained at docs/legal/SUBPROCESSORS.md and a public version is available on request. As of the Effective Date:

Sub-processorPurposeLocation
Render Services, Inc. (render.com)Primary application hosting and managed PostgreSQLUnited States (US-East, Ohio; AWS-backed)
Cloudflare, Inc.DNS, CDN, DDoS mitigation, email forwarding (MX routing), object storage (R2)United States / global edge
Stripe, Inc.Subscription billing and payment processing (independent controller for payment data)United States
Resend, Inc.Transactional email delivery (certification alerts, notifications, password resets)United States
Anthropic, PBCModel inference for AI Features (public Identify tool and in-app AI capabilities); receives only the text and photos a user submits to an AI Feature plus contextual metadataUnited States

7.3 Notification of new Sub-processors

HazRespondr will notify Customer in writing (email to the Customer's designated security/admin contact, or via a notification to security@hazrespondr.com subscribers, or via the HazRespondr status/changelog page) at least 30 days before authorizing a new Sub-processor to process Personal Data.

7.4 Customer objection rights

Customer may object to the engagement of a new Sub-processor on reasonable grounds relating to data protection within 14 days of receiving notice. The parties will work in good faith to resolve the objection. If the objection cannot be resolved, Customer may terminate the portion of the Service that requires the new Sub-processor by written notice, and HazRespondr will refund any prepaid fees for the affected portion of the Service following termination.

7.5 Updates

Customers may subscribe to Sub-processor update notices by emailing security@hazrespondr.com.

8. International Data Transfers

8.1 US-only processing (current default)

As of the Effective Date, all Personal Data is processed and stored in the United States. HazRespondr does not currently transfer Customer Personal Data outside the United States, with the exception of edge-level metadata (e.g., TLS-terminated request routing through Cloudflare's global edge, which does not persistently store Personal Data).

8.2 Transfers from the EEA, UK, or Switzerland

To the extent Customer transfers Personal Data originating in the EEA, UK, or Switzerland to HazRespondr in the United States, the parties agree:

8.3 Onward transfers

HazRespondr will not cause or permit Personal Data to be transferred to a Sub-processor outside the United States except under appropriate safeguards (SCCs or equivalent) and will update the Sub-processor list in Section 7.2 accordingly.

8.4 EU customer readiness

HazRespondr is not currently actively selling into the EU market and expects to do so only after SOC 2 Type II certification is obtained. The framework in this Section 8 is in place so that EU-origin data can be lawfully processed on request.

9. Data Subject Rights

9.1 Customer responsibility

As Controller, Customer is primarily responsible for responding to Data Subject requests under Applicable Data Protection Laws, including requests for access, rectification, erasure, restriction of processing, data portability, and objection.

9.2 HazRespondr assistance

Taking into account the nature of processing, HazRespondr will assist Customer by appropriate technical and organizational measures, insofar as possible, for the fulfillment of Customer's obligation to respond to Data Subject requests. In particular:

9.3 Requests received by HazRespondr

If HazRespondr receives a request from a Data Subject directly, HazRespondr will (unless legally prohibited) promptly inform the Data Subject that they should direct the request to Customer and notify Customer of the request without undue delay.

10. Personal Data Breach Notification

10.1 Notification timeline

HazRespondr will notify Customer of a confirmed Personal Data Breach affecting Customer's Personal Data without undue delay and in any event within 72 hours of HazRespondr becoming aware of the breach.

10.2 Notification content

The notification will, to the extent known at the time, include:

  1. A description of the nature of the breach, including categories and approximate number of Data Subjects and records concerned;
  2. The name and contact details of HazRespondr's security/breach contact;
  3. A description of the likely consequences of the breach;
  4. A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.

Where not all information is available at the time of initial notification, HazRespondr will provide information in phases as it becomes available.

10.3 Cooperation

HazRespondr will cooperate with Customer in investigating, remediating, and (as required by Applicable Data Protection Laws) notifying affected individuals and regulatory authorities. HazRespondr will document each breach, including its facts, effects, and the remedial action taken, and make that documentation available to Customer on reasonable request.

10.4 Notification does not imply fault

Notification of a breach does not constitute or imply any admission of fault or liability.

11. Security Measures

11.1 Standards

HazRespondr maintains appropriate technical and organizational measures ("TOMs") to ensure a level of security appropriate to the risk, taking into account the state of the art, cost of implementation, and the nature, scope, context, and purposes of processing, and the risk to Data Subjects. Current TOMs include:

11.2 Reference documents

Detailed TOMs are documented in HazRespondr's customer-facing Security Practices document and procurement-facing Security Questionnaire. HazRespondr will provide the most current version of either document on reasonable request, subject to NDA.

11.3 Changes to TOMs

HazRespondr may update its TOMs from time to time, provided that the overall level of security is not materially reduced.

12. Audit Rights

12.1 Audit reports

HazRespondr will make available to Customer, on reasonable request and subject to appropriate confidentiality obligations, information reasonably necessary to demonstrate compliance with this DPA, including:

12.2 On-site audits

Customer may, on no less than 30 days' written notice and no more than once per calendar year (except in the event of a Personal Data Breach reasonably requiring an audit), conduct or have a reputable third-party auditor conduct an audit of HazRespondr's compliance with this DPA. Such audit will:

12.3 Reliance on SOC 2 or equivalent

Customer agrees that, where HazRespondr makes available a current SOC 2 Type II report (or equivalent recognized industry audit) covering the scope of the Service, Customer will treat that report as sufficient to satisfy routine annual audit rights under Section 12.2, unless Customer has specific, documented concerns not addressed by the report.

13. Return or Deletion of Personal Data

13.1 During the term

Customer may export Customer Personal Data at any time during the term of the Agreement through in-product export functionality (CSV, JSON, PDF) and via the /api/v1/gdpr/export endpoint.

13.2 On termination

Following termination or expiration of the Agreement:

  1. 30-day grace period. Personal Data remains available for export via the in-product tools for 30 days from the effective termination date.
  2. Production deletion. After the 30-day grace period (or earlier if Customer requests in writing), HazRespondr will delete Personal Data from production systems.
  3. Backup deletion. Personal Data in rolling backups is purged within an additional 30 days of deletion from production as backups age out of the 7-day retention window and longer-term snapshots rotate.
  4. Exception — audit logs. HazRespondr may retain tamper-evident audit-log records required for its own compliance (e.g., SOC 2 evidence) for up to 7 years, provided that such records are anonymized to the extent possible after Customer's termination while preserving the hash chain.
  5. Exception — legal hold. HazRespondr may retain Personal Data for longer where required by Applicable Data Protection Laws, subpoena, or legal hold, but only for the period and scope required.

13.3 Confirmation

Upon Customer's written request after the deletion is complete, HazRespondr will provide written confirmation that the deletion has been performed in accordance with this Section.

14. Liability and Indemnification

14.1 Mirrored with Agreement

The liability and indemnification provisions of the Agreement apply to each party's obligations under this DPA, except that nothing in this DPA is intended to limit the rights of Data Subjects under Applicable Data Protection Laws.

14.2 Liability cap

Each party's aggregate liability under this DPA is subject to the liability cap in the Agreement (typically 12 months of fees paid by Customer), subject to customary carve-outs for (i) willful misconduct and gross negligence, (ii) breach of confidentiality, (iii) indemnification for third-party IP infringement claims, and (iv) any liability that cannot be excluded under Applicable Data Protection Laws.

14.3 Indemnification

Each party will indemnify the other for regulatory fines, third-party claims, and reasonable legal fees arising out of that party's material breach of this DPA, subject to the liability cap above and to customary conditions (prompt notice, reasonable cooperation, sole control of defense).

15. Governing Law

This DPA is governed by the laws of the State of Maryland, USA, without regard to its conflict-of-laws principles, except that, with respect to Personal Data originating in the EEA, UK, or Switzerland, the SCCs are governed by the law specified in the SCCs themselves (typically Irish law for EU transfers) where required by applicable law.

16. Miscellaneous

16.1 Order of precedence

In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls. In the event of a conflict between this DPA and the SCCs with respect to EU-origin Personal Data, the SCCs control.

16.2 Updates

HazRespondr may update this DPA from time to time to reflect changes in Applicable Data Protection Laws, HazRespondr's Sub-processor list, or security practices. Material updates will be communicated to Customer with at least 30 days' notice before the effective date.

16.3 Severability

If any provision of this DPA is found unenforceable, the remaining provisions remain in full force and effect.

16.4 Counterparts

This DPA may be executed in counterparts, each of which is deemed an original.


Signature Blocks

HazRespondr LLC

Signature:
Name:
Title:
Date:

Customer

Legal Entity Name:
Signature:
Name:
Title:
Date:

Schedule A — SCCs Annexes (for EEA / UK / Switzerland transfers)

Annex I.A — List of Parties

Annex I.B — Description of Transfer

Annex I.C — Competent Supervisory Authority

As required by the SCCs, the competent supervisory authority is the Irish Data Protection Commission for EU-origin transfers, unless a different supervisory authority has jurisdiction under Applicable Data Protection Laws.

Annex II — Technical and Organizational Measures

The TOMs in Section 11 satisfy Annex II of the SCCs.

Annex III — List of Sub-processors

As listed in Section 7.2 of this DPA.