Skip to DPA
← Legal Library
A R C H A N G E L  ·  D P A

Data Processing Addendum

Article 28 GDPR processor terms between White Crown Enterprises (Processor) and each Authority (Controller). Automatically attaches to every executed Master Services Agreement where Personal Data is processed on the Controller's behalf.

Document AX-DPA-1.0.0 Effective 2026-10-01 Publisher White Crown Enterprises Governing law Follows the MSA Version 1.0.0

Table of Contents

  1. Definitions
  2. Subject-matter, duration, nature, and purpose
  3. Categories of Data Subject and Personal Data
  4. Processor obligations
  5. Sub-processors
  6. International transfers
  7. Data-subject rights
  8. Personal Data Breach notification
  9. Data Protection Impact Assessments and prior consultation
  10. Return or deletion
  11. Audit and demonstrable compliance
  12. Liability and limitation
  13. Order of precedence
  14. Annex 1 — Processing details
  15. Annex 2 — Technical and organisational measures
  16. Annex 3 — Sub-processors

1. Definitions

Terms not defined here have the meaning given in the MSA or, if not defined there, in the GDPR. Where the CCPA/CPRA, UK-GDPR, PIPEDA, LGPD, or another applicable law defines an equivalent term, the definition most protective of the Data Subject applies to Personal Data originating in that jurisdiction. "Personal Data Breach," "Controller," "Processor," "Sub-processor," "Data Subject," and "Processing" bear the meanings given in the GDPR.

2. Subject-matter, duration, nature, and purpose

Processor processes Personal Data on behalf of Controller solely to deliver the Archangel Platform under the MSA. The duration of Processing is the Term of the MSA plus any period during which Processor holds Personal Data pursuant to a legal-hold obligation or the return/deletion procedure in Section 10. Nature of Processing: hosting, storage, transmission, and generation of Notifications and Chain-of-Custody Records. Purpose: to provide the Platform. Processor shall not process Personal Data for its own purposes.

3. Categories of Data Subject and Personal Data

See Annex 1. In general, categories may include: (a) Controller's operators (identifiers, session data), (b) individuals present in a Coverage Area (only categorical, non-identifying Notification metadata generated by the Platform, and any media Controller elects to attach to a Notification), and (c) support-request originators.

4. Processor obligations

Processor shall (a) process Personal Data only on Controller's documented instructions, including the instructions set forth in the MSA and this DPA; (b) ensure persons authorised to process Personal Data are bound by confidentiality; (c) implement the technical and organisational measures in Annex 2; (d) assist Controller in fulfilling Data-Subject requests under Section 7; (e) assist Controller with compliance obligations under Articles 32–36 GDPR taking into account the nature of Processing and information available to Processor; and (f) inform Controller promptly if, in Processor's opinion, an instruction infringes applicable data-protection law.

5. Sub-processors

Controller grants Processor a general authorisation to engage Sub-processors subject to the safeguards in this Section. Processor shall (a) impose contract terms on each Sub-processor no less protective than this DPA, (b) maintain and publish a current list of Sub-processors at /legal/subprocessors.html, (c) provide Controller with at least thirty (30) days' prior notice of the addition or replacement of a Sub-processor, and (d) allow Controller to reasonably object on data-protection grounds within that notice period. If Controller reasonably objects, the Parties will work in good faith toward a resolution, failing which Controller may terminate the affected Order Form without penalty.

6. International transfers

Where Personal Data originating in the EEA or UK is transferred to a country not covered by an adequacy decision, the Parties agree that the transfer is subject to the European Commission's Standard Contractual Clauses (Module 2 or 3, as applicable) and, for UK data, the UK International Data Transfer Addendum, each of which is incorporated by reference as if fully set forth. The Parties agree to the docking clause. Where the transfer originates in a jurisdiction whose law requires a different transfer mechanism, the Parties will execute that mechanism in good faith.

7. Data-subject rights

Taking into account the nature of the Processing, Processor shall assist Controller by appropriate technical and organisational measures for the fulfilment of Controller's obligation to respond to requests to exercise Data-Subject rights. Where Processor receives a request directly, it will (unless prohibited by law) forward the request to Controller within five (5) business days and not respond substantively without Controller's instruction.

8. Personal Data Breach notification

Processor shall notify Controller of a confirmed Personal Data Breach affecting Controller's Personal Data without undue delay and, in any event, within seventy-two (72) hours of confirmation. The notification will include, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. Processor will provide further information as it becomes available.

9. DPIAs and prior consultation

Processor shall provide Controller with reasonable assistance in carrying out Data Protection Impact Assessments and, where required, with prior consultation with a supervisory authority, taking into account the nature of the Processing and information available to Processor.

10. Return or deletion

Upon termination or expiration of the MSA, or at Controller's earlier written request, Processor shall, at Controller's election, return to Controller or delete all Personal Data processed on Controller's behalf and delete existing copies, except to the extent applicable law requires Processor to retain the data. Processor will certify deletion in writing on request. Retention pursuant to a legal-hold obligation shall be strictly limited to the data required and shall not be used for any other purpose.

11. Audit and demonstrable compliance

Processor shall make available to Controller information necessary to demonstrate compliance with the obligations in Article 28 GDPR and with this DPA, and shall allow for and contribute to audits, including inspections, conducted by Controller or another auditor mandated by Controller. Processor's most recent SOC 2 Type II report and ISO/IEC 27001 certificate, made available under NDA, shall satisfy the audit obligation. On-site audits at Processor facilities require thirty (30) days' notice, shall be conducted no more than once per calendar year absent a material Personal Data Breach, and shall be at Controller's expense unless a material finding is confirmed.

12. Liability and limitation

Liability under this DPA is governed by the limitation-of-liability provisions of the MSA, subject to the exclusions from the cap set forth in the MSA for breach of confidentiality and unlawful Processing. Nothing in this DPA limits either Party's liability to a Data Subject or to a supervisory authority under Article 82 GDPR.

13. Order of precedence

In case of a conflict between the body of the MSA and this DPA, this DPA governs with respect to the Processing of Personal Data. The Standard Contractual Clauses (where applicable) take precedence over any conflicting provision of this DPA to the extent required by their terms.

Annex 1 — Processing details

Subject matter: Provision of the Archangel Platform. Duration: the Term of the MSA and any tail retention. Nature and purpose: hosting, storage, transmission, and generation of Notifications and Chain-of-Custody Records; providing operator console access; providing App functionality to consumer end-users authorised by Controller. Categories of Data Subject: operators; subjects present in Coverage Areas; consumer App users; support-request originators. Categories of Personal Data: account identifiers, session metadata, Notification metadata (categorical), diagnostic events, and any content Controller elects to attach to a Notification. Sensitive categories: not intentionally processed; where an Authority attaches sensitive content, additional controls apply per the relevant sector Addendum.

Annex 2 — Technical and organisational measures

Encryption: TLS 1.3 in transit; AES-256 at rest. Access control: role-based, need-to-know, MFA-mandatory, logged. Segregation: Controller data logically segregated per tenant, with per-tenant encryption keys where technically feasible. Integrity: XRYSTAL page-integrity attestation for legal documents; Lotus Chain-of-Custody for Notifications. Availability: multi-region replication; RPO 1 hour, RTO 4 hours (see SLA). Personnel: background checks consistent with law, mandatory security training, confidentiality obligations. Physical: Tier-3+ data centres of the sub-processors identified in Annex 3. Vulnerability management: continuous scanning, quarterly independent penetration testing, coordinated disclosure via security@whitecrownenterprises.com. Software supply chain: signed build artefacts, SBOM published on request. Incident response: 24/7 on-call rotation, documented playbooks, tabletop exercises quarterly.

Annex 3 — Sub-processors

Processor engages the Sub-processors listed at /legal/subprocessors.html. That list is updated with at least thirty (30) days' notice as provided in Section 5. The Parties agree that any Sub-processor listed on the effective date of this DPA is deemed approved.

This DPA takes effect concurrently with the MSA and remains in effect until the MSA terminates.

XRYSTAL: AX-DPA-1.0.0 · Published 2026-10-01 · Publisher: White Crown Enterprises

← Legal Library · Archangel