Data Processing Addendum
[OPERATOR: complete with counsel]
Template, not legal advice.
This page is scaffolding for the operator to complete with counsel. The bracketed passages are the decisions a lawyer needs to make; the unbracketed ones describe how the software actually behaves and should be kept accurate rather than rewritten to sound better.
1. Roles
For the personal information your department puts into ProbieTrack, your department is the controller and [operator legal entity name] is the processor. You decide what is collected and why. We process it on your documented instructions, which are: run the service described in the Terms.
2. Subject matter and duration
Processing lasts as long as your account, plus the deletion window described below. The subject matter is the training, evaluation and probationary records of members of your department.
3. Categories of data and data subjects
Data subjects: your members, your account holders. Categories: identity and contact details, employment details, and performance evaluations. This is employment-performance information about identifiable people, and some of it may be produced in a grievance, an arbitration or litigation. It should be treated as sensitive whether or not a statute labels it so.
4. Our obligations
- Process only on your instructions, and tell you if we believe an instruction breaks the law.
- Keep the people who handle it bound to confidentiality.
- Apply the security measures described in the Privacy Policy.
- Not engage a new sub-processor without notice to you.
- Help you respond to requests from your members about their data.
- Help you with security assessments and breach notification.
- Delete or return the data at the end, at your choice.
- Make available the information needed to demonstrate the above.
5. Sub-processors
Current sub-processors: Stripe (payments; billing contact details only, no personnel records), [email provider] (notification delivery), [hosting provider] (infrastructure). We will give [notice period] notice before adding another.
6. Security measures
Encryption in transit; passwords hashed with a current key-derivation function; optional two-factor authentication, which can be required for administrative tiers; rate limiting and lockout on authentication; session idle timeout and absolute ceiling; private file storage reachable only through short-lived signed links; per-department isolation enforced in the data layer such that a query without a department fails rather than returning everything; an append-only audit trail; daily backups with [retention] retention and a documented, exercised restore procedure.
7. Support access
Our support sessions inside your account are read-only, time-limited, visibly banner-marked for their duration, and recorded at both ends on your own audit trail with the stated reason. You can see every such session we have had.
8. Breach notification
We will tell you without undue delay, and in any case within [hours] hours, of becoming aware of a personal data breach affecting your data, with what we know at the time and updates as we learn more.
9. Return and deletion
You can export everything at any time, including while your account is lapsed or suspended. On termination, deletion runs after a 30-day window during which nothing is destroyed and you can still export. After the window, data is permanently removed, subject only to backups already taken, which age out on the backup retention schedule.
Non-payment never triggers deletion. A lapsed account becomes read-only and retains everything.
10. Transfers
[Where the data is hosted, and the mechanism for any cross-border transfer.]
11. Audits
[Audit rights, notice, frequency and cost allocation.]
12. Order of precedence
Where this addendum and the Terms of Service conflict on the processing of personal data, this addendum governs.
Last updated: 2026-09-11