← hazrespondr.com
Data Processing Addendum (DPA)
Effective Date: Completed at signature — the date on the executed signature page. This public copy is the unsigned template.
Processor: HazRespondr LLC, a Maryland limited liability company ("HazRespondr")
Controller: The customer organization identified on the executed signature page ("Customer")
Document status. Drafted by the HazRespondr engineering/ops team as an
acquisition-diligence-grade template, intended to be reviewed and finalized by qualified
legal counsel before execution. This is not legal advice. The canonical source is
docs/legal/DPA-TEMPLATE.md; this page is its public mirror.
This Data Processing Addendum ("DPA") supplements and is incorporated into the Master Services Agreement, Terms of Service, order form, or other written agreement between the parties governing Customer's use of the HazRespondr platform (the "Agreement"). In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls.
1. Definitions
Capitalized terms not defined below have the meaning given in the Agreement or in applicable Data Protection Laws.
- "Applicable Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data under the Agreement, including (as applicable) the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA"), and US state privacy statutes (VCDPA, CPA, CTDPA, UCPA, and successors).
- "Controller" means the natural or legal person who, alone or jointly, determines the purposes and means of the processing of Personal Data. Under CCPA/CPRA, "Controller" also includes "Business."
- "Processor" means the entity that processes Personal Data on behalf of the Controller. Under CCPA/CPRA, "Processor" also includes "Service Provider."
- "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject") that Customer makes available to HazRespondr through the Service. Under CCPA/CPRA, "Personal Data" also includes "Personal Information."
- "Processing" means any operation performed on Personal Data, including collection, recording, organization, storage, retrieval, use, disclosure, and deletion.
- "Sub-processor" means a third party engaged by HazRespondr to process Personal Data in connection with the Service.
- "Data Subject" means the individual to whom Personal Data relates (typically Customer's employees, contractors, volunteers, or administrators).
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
- "Standard Contractual Clauses" / "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission (Decision 2021/914) and, for UK transfers, the UK International Data Transfer Addendum.
- "Service" means the HazRespondr software-as-a-service platform as described in the Agreement.
2. Subject Matter and Duration
2.1 Subject matter
HazRespondr provides a cloud-hosted hazmat team compliance platform covering inventory management, personnel training records, equipment maintenance, and incident reporting. In the course of providing the Service, HazRespondr processes Personal Data that Customer submits to the Service.
2.2 Duration
This DPA is effective for the duration of the Agreement and for any additional period during which HazRespondr processes Personal Data on Customer's behalf (including the return/deletion period described in Section 13).
3. Nature and Purpose of Processing
HazRespondr processes Personal Data solely to:
- Provide the Service to Customer under the Agreement, including account provisioning, authentication, access control, and feature delivery (training tracking, certification expiry alerts, equipment/calibration management, incident reporting, audit logging);
- Support Customer's compliance with applicable safety, training, and recordkeeping regulations (OSHA 29 CFR 1910.120, NFPA standards, EPA Tier II, NFIRS, etc.);
- Provide customer support, troubleshooting, and security monitoring;
- Deliver transactional email notifications (certification expiry, work-order assignments, incident assignments) to Data Subjects Customer has added to the Service;
- Meet HazRespondr's legal obligations;
- Preserve tamper-evident audit records as required by Customer's compliance programs and by SOC 2 control objectives.
HazRespondr will not process Personal Data for any purpose other than those set out above or subsequently agreed in writing. HazRespondr specifically confirms that it does not sell or share Personal Data, and does not use Personal Data for advertising, profiling, or training of AI/ML models beyond what is necessary to provide the Service to the originating Customer.
4. Types of Personal Data
The categories of Personal Data processed under this DPA typically include:
- Identity data: full name, email address, phone number (optional), employee/badge number, job title, rank, department.
- Authentication data: hashed passwords, TOTP secrets (encrypted with AES-256-GCM), SAML NameID, refresh-token hashes.
- Professional qualification data: certification type, issuing authority, issue date, expiry date, certificate number, CEU/contact-hour records, training history.
- Operational data: equipment assignments, check-in/out logs, shift-check records, incident participation, entry-team assignments, air-monitoring readings attributed to an operator.
- Health and safety data (subject to Customer control of what is uploaded): exposure records, decontamination records, PPE usage logs, injury details captured in OSHA 300 entries, medical surveillance status (whether current/expired), symptoms and treatment notes when entered into incident reports.
- Billing data (processed by Stripe as a separate controller for payment processing): cardholder name, last four digits of payment card, billing address, transaction history. HazRespondr does not store full card numbers or CVV.
- System-generated data: audit-log entries, IP addresses, timestamps, user-agent strings, error logs.
The categories of Personal Data are ultimately determined by Customer based on what Customer and its authorized users upload to the Service.
5. Categories of Data Subjects
The Data Subjects typically include:
- Customer's employees, volunteers, contractors, and reserve/auxiliary personnel who are team members tracked in the Service (fire-department responders, industrial emergency response team members, safety officers, trainers);
- Customer's administrative users and managers who log into the Service;
- Customer's mutual-aid partners or visiting personnel where Customer records their attendance or participation in incidents/trainings;
- Individuals referenced in incident reports (for example, patients treated at an incident scene, where applicable and controlled by Customer);
- Billing contacts designated by Customer.
6. Controller and Processor Obligations
6.1 Customer as Controller
Customer acknowledges that it is the Controller (and, where applicable, the "Business" under CCPA/CPRA) of Personal Data it uploads to or generates within the Service. Customer represents and warrants that:
- It has a lawful basis under Applicable Data Protection Laws for its own and HazRespondr's processing;
- It has provided required notices to Data Subjects and obtained required consents where consent is the lawful basis;
- Its instructions to HazRespondr (including Customer's configuration of the Service) comply with Applicable Data Protection Laws;
- It is responsible for the accuracy, quality, and legality of Personal Data uploaded to the Service.
6.2 HazRespondr as Processor
HazRespondr will:
- Process Personal Data only on documented instructions from Customer, including the Agreement, this DPA, Customer's configuration of the Service, and any subsequent written instructions. If HazRespondr is required by law to process Personal Data otherwise, HazRespondr will (to the extent legally permitted) inform Customer of that legal requirement before processing.
- Ensure that authorized personnel who process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement the technical and organizational security measures described in Section 11 and in the HazRespondr Security Practices document.
- Not engage a Sub-processor without prior general written authorization from Customer and subject to Section 7.
- Assist Customer in fulfilling its obligations to respond to Data Subject rights requests, as set out in Section 9.
- Assist Customer in ensuring compliance with its obligations under Applicable Data Protection Laws, including security, breach notification, and data-protection impact assessment obligations, taking into account the nature of processing and the information available to HazRespondr.
- At Customer's choice, delete or return all Personal Data to Customer after the end of the provision of Services relating to processing, and delete existing copies, unless Applicable Data Protection Laws require otherwise (see Section 13).
- Make available to Customer all information reasonably necessary to demonstrate compliance with this DPA (see Section 12).
6.3 CCPA/CPRA-specific obligations
For Personal Data subject to CCPA/CPRA, HazRespondr will:
- Not sell or share Personal Data as those terms are defined under CCPA/CPRA;
- Not retain, use, or disclose Personal Data outside the direct business relationship with Customer, except as permitted by CCPA/CPRA §1798.140(ag)(1);
- Not combine Personal Data received from Customer with personal information received from or on behalf of other persons, except as permitted by CCPA/CPRA;
- Notify Customer if HazRespondr determines it can no longer meet its obligations under CCPA/CPRA;
- Grant Customer the right to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data.
7. Sub-processors
7.1 General authorization
Customer grants HazRespondr general written authorization to engage Sub-processors to assist in providing the Service, provided that HazRespondr:
- Enters into a written agreement with each Sub-processor imposing data-protection obligations substantially similar to those in this DPA;
- Remains liable to Customer for the acts and omissions of its Sub-processors;
- Selects Sub-processors that provide sufficient guarantees of appropriate technical and organizational measures.
7.2 Current Sub-processors
The current list of Sub-processors is maintained at docs/legal/SUBPROCESSORS.md and a public version is available on request. As of the Effective Date:
7.3 Notification of new Sub-processors
HazRespondr will notify Customer in writing (email to the Customer's designated security/admin contact, or via a notification to security@hazrespondr.com subscribers, or via the HazRespondr status/changelog page) at least 30 days before authorizing a new Sub-processor to process Personal Data.
7.4 Customer objection rights
Customer may object to the engagement of a new Sub-processor on reasonable grounds relating to data protection within 14 days of receiving notice. The parties will work in good faith to resolve the objection. If the objection cannot be resolved, Customer may terminate the portion of the Service that requires the new Sub-processor by written notice, and HazRespondr will refund any prepaid fees for the affected portion of the Service following termination.
7.5 Updates
Customers may subscribe to Sub-processor update notices by emailing security@hazrespondr.com.
8. International Data Transfers
8.1 US-only processing (current default)
As of the Effective Date, all Personal Data is processed and stored in the United States. HazRespondr does not currently transfer Customer Personal Data outside the United States, with the exception of edge-level metadata (e.g., TLS-terminated request routing through Cloudflare's global edge, which does not persistently store Personal Data).
8.2 Transfers from the EEA, UK, or Switzerland
To the extent Customer transfers Personal Data originating in the EEA, UK, or Switzerland to HazRespondr in the United States, the parties agree:
- The EU Standard Contractual Clauses (SCCs), Module Two (Controller-to-Processor), adopted under Commission Implementing Decision (EU) 2021/914, are incorporated into and form part of this DPA and apply to such transfers.
- For transfers from the UK, the UK International Data Transfer Addendum issued by the Information Commissioner's Office supplements the SCCs.
- For transfers from Switzerland, references to the GDPR in the SCCs are interpreted to include the Swiss Federal Act on Data Protection (FADP).
- Annex I, II, and III to the SCCs are populated as set out in Schedule A to this DPA.
- HazRespondr will carry out a transfer impact assessment on request and implement supplementary measures where required (e.g., encryption of Personal Data in transit using TLS 1.2+ and at rest using AES-256).
8.3 Onward transfers
HazRespondr will not cause or permit Personal Data to be transferred to a Sub-processor outside the United States except under appropriate safeguards (SCCs or equivalent) and will update the Sub-processor list in Section 7.2 accordingly.
8.4 EU customer readiness
HazRespondr is not currently actively selling into the EU market and expects to do so only after SOC 2 Type II certification is obtained. The framework in this Section 8 is in place so that EU-origin data can be lawfully processed on request.
9. Data Subject Rights
9.1 Customer responsibility
As Controller, Customer is primarily responsible for responding to Data Subject requests under Applicable Data Protection Laws, including requests for access, rectification, erasure, restriction of processing, data portability, and objection.
9.2 HazRespondr assistance
Taking into account the nature of processing, HazRespondr will assist Customer by appropriate technical and organizational measures, insofar as possible, for the fulfillment of Customer's obligation to respond to Data Subject requests. In particular:
- Access / portability: Customer admins can export org data via CSV/JSON/PDF through the in-product export functionality and via the
/api/v1/gdpr/export endpoint. HazRespondr will assist within 10 business days of a written request where admin-level export is insufficient.
- Rectification: Customer admins can directly rectify most Personal Data in the Service. HazRespondr will assist where admin-level edit is insufficient.
- Erasure ("right to be forgotten"): Customer admins can delete users and records via the Service. HazRespondr's anonymize-on-delete flow preserves audit-log integrity while erasing the identifying PII fields of the Data Subject. HazRespondr will assist with any erasure not achievable through admin controls.
- Restriction: Customer admins can deactivate user accounts, which prevents further processing while preserving the record. Additional restriction measures are available on request.
- Objection: HazRespondr does not use Personal Data for direct marketing or profiling, so objection rights are typically addressed by deactivating the account or removing the Data Subject from the org.
- Complaints to supervisory authority: HazRespondr will not interfere with a Data Subject's right to lodge a complaint with a supervisory authority.
9.3 Requests received by HazRespondr
If HazRespondr receives a request from a Data Subject directly, HazRespondr will (unless legally prohibited) promptly inform the Data Subject that they should direct the request to Customer and notify Customer of the request without undue delay.
10. Personal Data Breach Notification
10.1 Notification timeline
HazRespondr will notify Customer of a confirmed Personal Data Breach affecting Customer's Personal Data without undue delay and in any event within 72 hours of HazRespondr becoming aware of the breach.
10.2 Notification content
The notification will, to the extent known at the time, include:
- A description of the nature of the breach, including categories and approximate number of Data Subjects and records concerned;
- The name and contact details of HazRespondr's security/breach contact;
- A description of the likely consequences of the breach;
- A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
Where not all information is available at the time of initial notification, HazRespondr will provide information in phases as it becomes available.
10.3 Cooperation
HazRespondr will cooperate with Customer in investigating, remediating, and (as required by Applicable Data Protection Laws) notifying affected individuals and regulatory authorities. HazRespondr will document each breach, including its facts, effects, and the remedial action taken, and make that documentation available to Customer on reasonable request.
10.4 Notification does not imply fault
Notification of a breach does not constitute or imply any admission of fault or liability.
11. Security Measures
11.1 Standards
HazRespondr maintains appropriate technical and organizational measures ("TOMs") to ensure a level of security appropriate to the risk, taking into account the state of the art, cost of implementation, and the nature, scope, context, and purposes of processing, and the risk to Data Subjects. Current TOMs include:
- Encryption at rest: AES-256 at the storage layer (Render managed PostgreSQL volumes). Designated PII columns (phone numbers, injured-personnel names, medical symptoms and treatment notes, treating-physician identifiers, TOTP secrets) are additionally encrypted with AES-256-GCM at the application layer before being written to the database, using 96-bit random IVs and authentication tags.
- Encryption in transit: TLS 1.2+ (and TLS 1.3 where supported) for all client-to-server and server-to-database connections. HSTS enforced with
max-age=15552000 and includeSubDomains.
- Authentication: email+password with bcrypt (cost factor 12) hashing; TOTP-based 2FA with AES-256-GCM-encrypted secrets and hashed backup codes; SAML 2.0 SSO for supported IdPs (Okta, Azure AD/Entra ID, Google Workspace, OneLogin, PingFederate, ADFS).
- Session management: JWT access tokens (HS256, 1-hour TTL), refresh tokens (7-day TTL, rotated on use, stored server-side as SHA-256 hashes), delivered via httpOnly, Secure, SameSite=Strict cookies.
- Access control: RBAC with
admin, team_lead, field_member, plus internal super_admin; per-request role enforcement; PostgreSQL Row-Level Security for tenant isolation; fail-closed auth middleware.
- Audit logging: All create/update/delete operations written to an
audit_log table with user, org, action, entity, old/new JSONB values, IP address, timestamp, and a SHA-256 hash chain linking each entry to the previous one for tamper evidence.
- Application hardening: Zod validation on all endpoints; parameterized SQL queries (no string interpolation); CSP, HSTS, X-Frame-Options, X-Content-Type-Options headers via Helmet; CSRF protection via SameSite=Strict cookies; CORS allowlist.
- Rate limiting: Layered limits — global (1,000 req/15 min/IP),
/auth/* (100/15 min), sensitive auth endpoints (10/15 min), lead-capture (5/hr).
- Backup & DR: Daily automated Postgres backups with 7-day retention and point-in-time recovery. RPO 24 hours; RTO 15 minutes.
- Vulnerability management: Parameterized queries across 100% of DB access;
npm audit pre-release; SSRF defenses on outbound fetches; external penetration test planned annually starting before SOC 2 Type I audit.
- Physical security: Inherited from Sub-processors (Render → AWS SOC 2 Type II, ISO 27001, PCI DSS).
11.2 Reference documents
Detailed TOMs are documented in HazRespondr's customer-facing Security Practices document and procurement-facing Security Questionnaire. HazRespondr will provide the most current version of either document on reasonable request, subject to NDA.
11.3 Changes to TOMs
HazRespondr may update its TOMs from time to time, provided that the overall level of security is not materially reduced.
12. Audit Rights
12.1 Audit reports
HazRespondr will make available to Customer, on reasonable request and subject to appropriate confidentiality obligations, information reasonably necessary to demonstrate compliance with this DPA, including:
- HazRespondr's most recent SOC 2 Type I or Type II report (when available; currently targeted for completion in line with the SOC 2 readiness plan);
- Executive summary of the most recent third-party penetration test (when available);
- The current Security Questionnaire tailored to Customer's specific questions;
- The Sub-processor list.
12.2 On-site audits
Customer may, on no less than 30 days' written notice and no more than once per calendar year (except in the event of a Personal Data Breach reasonably requiring an audit), conduct or have a reputable third-party auditor conduct an audit of HazRespondr's compliance with this DPA. Such audit will:
- Be conducted during normal business hours and with reasonable disruption to HazRespondr's operations;
- Be subject to written confidentiality obligations;
- Not grant access to Personal Data of other HazRespondr customers, HazRespondr's confidential business information unrelated to the processing, or HazRespondr's production systems beyond what is reasonably necessary to demonstrate compliance;
- Be at Customer's expense, except where the audit identifies a material breach of this DPA by HazRespondr, in which case HazRespondr will reimburse Customer's reasonable documented audit fees.
12.3 Reliance on SOC 2 or equivalent
Customer agrees that, where HazRespondr makes available a current SOC 2 Type II report (or equivalent recognized industry audit) covering the scope of the Service, Customer will treat that report as sufficient to satisfy routine annual audit rights under Section 12.2, unless Customer has specific, documented concerns not addressed by the report.
13. Return or Deletion of Personal Data
13.1 During the term
Customer may export Customer Personal Data at any time during the term of the Agreement through in-product export functionality (CSV, JSON, PDF) and via the /api/v1/gdpr/export endpoint.
13.2 On termination
Following termination or expiration of the Agreement:
- 30-day grace period. Personal Data remains available for export via the in-product tools for 30 days from the effective termination date.
- Production deletion. After the 30-day grace period (or earlier if Customer requests in writing), HazRespondr will delete Personal Data from production systems.
- Backup deletion. Personal Data in rolling backups is purged within an additional 30 days of deletion from production as backups age out of the 7-day retention window and longer-term snapshots rotate.
- Exception — audit logs. HazRespondr may retain tamper-evident audit-log records required for its own compliance (e.g., SOC 2 evidence) for up to 7 years, provided that such records are anonymized to the extent possible after Customer's termination while preserving the hash chain.
- Exception — legal hold. HazRespondr may retain Personal Data for longer where required by Applicable Data Protection Laws, subpoena, or legal hold, but only for the period and scope required.
13.3 Confirmation
Upon Customer's written request after the deletion is complete, HazRespondr will provide written confirmation that the deletion has been performed in accordance with this Section.
14. Liability and Indemnification
14.1 Mirrored with Agreement
The liability and indemnification provisions of the Agreement apply to each party's obligations under this DPA, except that nothing in this DPA is intended to limit the rights of Data Subjects under Applicable Data Protection Laws.
14.2 Liability cap
Each party's aggregate liability under this DPA is subject to the liability cap in the Agreement (typically 12 months of fees paid by Customer), subject to customary carve-outs for (i) willful misconduct and gross negligence, (ii) breach of confidentiality, (iii) indemnification for third-party IP infringement claims, and (iv) any liability that cannot be excluded under Applicable Data Protection Laws.
14.3 Indemnification
Each party will indemnify the other for regulatory fines, third-party claims, and reasonable legal fees arising out of that party's material breach of this DPA, subject to the liability cap above and to customary conditions (prompt notice, reasonable cooperation, sole control of defense).
15. Governing Law
This DPA is governed by the laws of the State of Maryland, USA, without regard to its conflict-of-laws principles, except that, with respect to Personal Data originating in the EEA, UK, or Switzerland, the SCCs are governed by the law specified in the SCCs themselves (typically Irish law for EU transfers) where required by applicable law.
16. Miscellaneous
16.1 Order of precedence
In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls. In the event of a conflict between this DPA and the SCCs with respect to EU-origin Personal Data, the SCCs control.
16.2 Updates
HazRespondr may update this DPA from time to time to reflect changes in Applicable Data Protection Laws, HazRespondr's Sub-processor list, or security practices. Material updates will be communicated to Customer with at least 30 days' notice before the effective date.
16.3 Severability
If any provision of this DPA is found unenforceable, the remaining provisions remain in full force and effect.
16.4 Counterparts
This DPA may be executed in counterparts, each of which is deemed an original.
Signature Blocks
HazRespondr LLC
Signature:
Name:
Title:
Date:
Customer
Legal Entity Name:
Signature:
Name:
Title:
Date:
Schedule A — SCCs Annexes (for EEA / UK / Switzerland transfers)
Annex I.A — List of Parties
- Data exporter: Customer (as identified on the signature page).
- Data importer: HazRespondr LLC, Maryland, USA, security@hazrespondr.com.
Annex I.B — Description of Transfer
- Categories of Data Subjects: Customer's employees, contractors, volunteers, administrators, and individuals referenced in Customer's operational records, as described in Section 5.
- Categories of Personal Data: as described in Section 4.
- Sensitive data: occupational health and safety data (exposure records, medical-surveillance status, injury/treatment notes in incident reports). Processed under heightened safeguards (application-layer AES-256-GCM on the most sensitive fields).
- Frequency of transfer: continuous, on a transactional basis as Customer uses the Service.
- Nature of processing: cloud hosting, database storage, application access, automated notifications, audit logging.
- Purpose of processing: provision of the Service as described in Section 3.
- Retention: as described in Section 13.
- Sub-processors: as listed in Section 7.2.
Annex I.C — Competent Supervisory Authority
As required by the SCCs, the competent supervisory authority is the Irish Data Protection Commission for EU-origin transfers, unless a different supervisory authority has jurisdiction under Applicable Data Protection Laws.
Annex II — Technical and Organizational Measures
The TOMs in Section 11 satisfy Annex II of the SCCs.
Annex III — List of Sub-processors
As listed in Section 7.2 of this DPA.