This Data Processing Addendum (“DPA”) forms part of the agreement between Belfort, Inc. (“Processor”) and the customer (“Controller”) for the provision of the Services. It reflects the parties' agreement on the processing of personal data in compliance with applicable data protection laws, including the GDPR and UK GDPR.
Roles of the parties
For end-user data processed through the Services, the Controller determines the purposes and means of processing, and Belfort acts as Processor. Belfort processes personal data only on documented instructions from the Controller, including as set out in this DPA and the agreement.
Scope of processing
The subject matter is the provision of the Services. Belfort processes paywall impression, conversion, entitlement, and event data relating to the Controller's end users, for the duration of the agreement, to deliver, secure, and support the Services.
Subprocessors
The Controller authorizes Belfort to engage subprocessors listed on our Security page. Belfort imposes data protection obligations on each subprocessor no less protective than this DPA and remains liable for their performance. We will give notice of new subprocessors and an opportunity to object.
Security measures
Belfort maintains appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, network segmentation, logging, and regular testing. A summary is available on our Security page.
Data subject requests
Taking into account the nature of the processing, Belfort will assist the Controller with appropriate measures to fulfill its obligations to respond to data subject requests. If we receive such a request directly, we will refer the data subject to the Controller.
Personal data breaches
Belfort will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide information reasonably needed to meet the Controller's notification obligations.
Audits
Belfort will make available information necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by the Controller or an appointed auditor, subject to reasonable confidentiality and scheduling terms.
Return & deletion
Upon termination, Belfort will, at the Controller's choice, delete or return Customer Data and delete existing copies within a reasonable period, unless retention is required by law.
International transfers
Where processing involves transfers outside the EEA or UK, the parties incorporate the applicable Standard Contractual Clauses, which prevail in case of conflict with this DPA.
Contact
For DPA requests, contact our Data Protection team at dpo@belfort.dev.