Data Processing Addendum
Entity: {{LEGAL_ENTITY}} · Product: CommitLayer · Draft updated 2026-09
1. Scope
This Data Processing Addendum ("DPA") forms part of the agreement between the Customer (controller) and {{LEGAL_ENTITY}} (processor) for CommitLayer.
2. Processing details
- Subject matter: verification of vendor outcome claims against Customer systems of record.
- Duration: the term of the agreement plus the retention period configured by the Customer.
- Nature and purpose: reading, matching and evaluating records; producing statements, evidence pointers and dispute packages.
- Categories of data subjects: Customer personnel; Customer end users appearing in connected systems.
- Categories of personal data: identifiers, timestamps and status attributes of support and billing records; redacted conversation excerpts only when transcript assist is enabled.
3. Processor obligations
Process personal data only on documented instructions; ensure personnel are bound by confidentiality; implement the technical and organisational measures described in the Trust Center; assist the controller with data-subject requests and impact assessments; delete or return data at the end of the engagement; make available information necessary to demonstrate compliance.
4. Subprocessors
The processor may engage the subprocessors listed on the subprocessors page and will give at least 30 days' notice of additions, during which the controller may object.
5. International transfers
Transfers outside the controller's jurisdiction will rely on an appropriate mechanism to be specified by counsel.
6. Security incidents
The processor will notify the controller without undue delay after becoming aware of a personal data breach affecting Customer data.
7. Audit
The controller may audit compliance once per year on reasonable notice, or more often following an incident.
8. Liability
As set out in the main agreement.