Data Processing Addendum

[OPERATOR: complete with counsel]

Template, not legal advice.

This page is scaffolding for the operator to complete with counsel. The bracketed passages are the decisions a lawyer needs to make; the unbracketed ones describe how the software actually behaves and should be kept accurate rather than rewritten to sound better.

1. Roles

For the personal information your department puts into ProbieTrack, your department is the controller and [operator legal entity name] is the processor. You decide what is collected and why. We process it on your documented instructions, which are: run the service described in the Terms.

2. Subject matter and duration

Processing lasts as long as your account, plus the deletion window described below. The subject matter is the training, evaluation and probationary records of members of your department.

3. Categories of data and data subjects

Data subjects: your members, your account holders. Categories: identity and contact details, employment details, and performance evaluations. This is employment-performance information about identifiable people, and some of it may be produced in a grievance, an arbitration or litigation. It should be treated as sensitive whether or not a statute labels it so.

4. Our obligations

5. Sub-processors

Current sub-processors: Stripe (payments; billing contact details only, no personnel records), [email provider] (notification delivery), [hosting provider] (infrastructure). We will give [notice period] notice before adding another.

6. Security measures

Encryption in transit; passwords hashed with a current key-derivation function; optional two-factor authentication, which can be required for administrative tiers; rate limiting and lockout on authentication; session idle timeout and absolute ceiling; private file storage reachable only through short-lived signed links; per-department isolation enforced in the data layer such that a query without a department fails rather than returning everything; an append-only audit trail; daily backups with [retention] retention and a documented, exercised restore procedure.

7. Support access

Our support sessions inside your account are read-only, time-limited, visibly banner-marked for their duration, and recorded at both ends on your own audit trail with the stated reason. You can see every such session we have had.

8. Breach notification

We will tell you without undue delay, and in any case within [hours] hours, of becoming aware of a personal data breach affecting your data, with what we know at the time and updates as we learn more.

9. Return and deletion

You can export everything at any time, including while your account is lapsed or suspended. On termination, deletion runs after a 30-day window during which nothing is destroyed and you can still export. After the window, data is permanently removed, subject only to backups already taken, which age out on the backup retention schedule.

Non-payment never triggers deletion. A lapsed account becomes read-only and retains everything.

10. Transfers

[Where the data is hosted, and the mechanism for any cross-border transfer.]

11. Audits

[Audit rights, notice, frequency and cost allocation.]

12. Order of precedence

Where this addendum and the Terms of Service conflict on the processing of personal data, this addendum governs.

Last updated: 2026-09-11