Data Processing Addendum
For business customers that use Prolter to process personal data
01. Purpose and Relationship
This Data Processing Addendum (“DPA”) forms part of the Prolter Terms of Service between the customer (“Customer”) and Prolter. It applies where Prolter processes Personal Data on behalf of Customer in connection with the Services.
For such processing, Customer is the controller/data fiduciary or equivalent and Prolter is the processor/service provider or equivalent, to the extent required by applicable law.
02. Definitions
- “Customer Data” means information submitted to the Services by or on behalf of Customer.
- “Personal Data” means information relating to an identified or identifiable individual, or the equivalent concept under applicable law.
- “Processing” includes collection, storage, retrieval, use, disclosure, transmission, deletion, and other processing activities performed through the Services.
- “Subprocessor” means a third party engaged by Prolter to process Personal Data on Prolter’s behalf.
03. Subject Matter and Duration
The subject matter is the provision of the Prolter SaaS platform, including hosting, storage, authentication, client/project management, asset management, credential-management functionality, security, support, and related Services.
Processing continues for the duration of Customer’s use of the Services and for limited periods thereafter as necessary for deletion, backup, legal compliance, security, dispute resolution, and other purposes permitted by applicable law.
04. Nature and Purpose of Processing
- Providing and operating the Services;
- Hosting and storing Customer Data;
- Synchronizing and displaying information to authorized users;
- Maintaining authentication, authorization, and audit logs;
- Processing support requests;
- Maintaining security and preventing abuse;
- Performing backups and disaster-recovery operations;
- Deleting or exporting data as requested and as supported by the Services.
05. Categories of Data and Data Subjects
Depending on Customer’s use of the Services, Personal Data may include names, email addresses, business contact information, usernames, client records, project information, activity information, IP addresses, device or browser information, and other information entered by Customer.
Credentials such as passwords, API keys, tokens, and access information may be stored by Customer. Prolter does not require Customer to submit special-category or highly sensitive personal data unless expressly supported by the Services and appropriate safeguards are in place.
Data subjects may include Customer’s employees, contractors, clients, prospects, suppliers, business contacts, and authorized users.
06. Customer Instructions
Prolter will process Customer Data only to provide the Services, follow Customer’s documented instructions as reflected in the Terms, product configuration, and applicable support requests, and comply with applicable law.
If Prolter reasonably believes an instruction violates applicable law, Prolter may suspend the affected processing and will notify Customer where legally permitted.
07. Confidentiality
Prolter will ensure that persons authorized to process Customer Data are subject to appropriate confidentiality obligations or are otherwise under an appropriate statutory duty of confidentiality.
08. Security Measures
Prolter will maintain reasonable technical and organizational measures appropriate to the risk, including encrypted transmission, access controls, authentication, restricted administrative access, logging, backups, and encryption of sensitive stored information where applicable.
Customer acknowledges that no security measure guarantees absolute security and remains responsible for configuring appropriate user permissions, authentication, and endpoint security.
09. Subprocessors
Customer authorizes Prolter to use subprocessors reasonably necessary to provide the Services. Current categories include cloud hosting/infrastructure, payment processing, email delivery, monitoring, security, and support providers.
Prolter will require relevant subprocessors to provide appropriate data-protection obligations consistent with applicable law. Where required by applicable law, Prolter will provide information about material subprocessors and a reasonable mechanism for addressing material changes.
10. Hosting
The primary Prolter application/database infrastructure is currently hosted in Germany using OVHcloud. Hosting location and providers may change as the Services evolve, subject to applicable law and contractual obligations.
11. Assistance with Data Subject Rights
Taking into account the nature of processing and information reasonably available to Prolter, Prolter will provide reasonable assistance to Customer with requests from data subjects to exercise applicable privacy rights, where such assistance is required by law.
Customer is responsible for responding to data subjects and determining whether a request is legally valid, except where applicable law places a direct obligation on Prolter.
12. Security Incidents
Prolter will notify Customer without undue delay after becoming aware of a confirmed Personal Data breach affecting Customer Data, where required by applicable law or the parties’ agreement.
Prolter will take reasonable steps to investigate, contain, mitigate, and remediate the incident and will provide information reasonably available to Prolter that Customer needs to meet applicable notification obligations.
Customer is responsible for determining whether and how it must notify regulators or affected individuals, except where applicable law directly requires Prolter to notify them.
13. International Transfers
Where Personal Data is transferred across jurisdictions, Prolter will implement transfer mechanisms and safeguards required by applicable law. Customer is responsible for ensuring that its instructions and use of the Services are lawful.
14. Return and Deletion
At the end of the Services, Prolter will delete or return Customer Data as required by the Terms and applicable law, subject to legitimate retention for legal, security, backup, accounting, or dispute-resolution purposes.
Backup copies may remain temporarily until overwritten in accordance with Prolter’s normal backup lifecycle.
15. Audits and Information
Where required by applicable law, Prolter will make available information reasonably necessary to demonstrate compliance with the obligations applicable to Prolter as a processor. Any audit must be reasonable, proportionate, subject to confidentiality and security requirements, and must not unreasonably disrupt Prolter’s operations or expose other customers’ information.
16. Customer Responsibilities
- Customer determines the purposes and means of processing Customer Data.
- Customer provides appropriate privacy notices and obtains required consents or other lawful bases.
- Customer ensures that its instructions to Prolter are lawful.
- Customer configures user permissions and access controls appropriately.
- Customer does not submit information that it is not authorized to process.
17. Priority
If this DPA conflicts with the Prolter Terms solely with respect to data-protection processing obligations, this DPA controls to the extent of that conflict. Mandatory applicable law controls where it cannot lawfully be varied by contract.
18. Contact Information
For inquiries regarding this Data Processing Addendum, please contact us at: