This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Controller") and Sisu Logistic, LLC (DBA Sisu IO) ("ClimbSuite," "Processor") for the ClimbSuite Service, where ClimbSuite processes personal data on the Controller's behalf.
1. Roles & scope
The Controller determines the purposes and means of processing the personal data it uploads or collects through the Service (e.g., its contacts/leads). ClimbSuite processes that personal data only as a Processor to provide the Service and on the Controller's documented instructions (including this DPA and the Terms).
2. Subject matter & details
- Subject matter: provision of the ClimbSuite Service.
- Duration: the term of the agreement plus any retention period.
- Nature/purpose: hosting, storage, and processing to operate CRM, email, funnels, courses, payments.
- Data subjects: the Controller's contacts, leads, customers, students, and users.
- Data types: identifiers and contact details, account/usage data, content the Controller submits.
[REVIEW: confirm; exclude special categories unless agreed.]
3. Processor obligations
ClimbSuite will: (a) process only on documented instructions; (b) ensure personnel are bound by confidentiality; (c) implement appropriate technical and organizational security measures (§6); (d) assist the Controller, taking into account the nature of processing, with data-subject requests and with security, breach, and impact-assessment obligations; (e) delete or return personal data at the end of services, subject to legal retention.
4. Subprocessors
The Controller authorizes ClimbSuite to engage subprocessors listed at [/subprocessors](/subprocessors). ClimbSuite will impose data-protection obligations on subprocessors substantially similar to this DPA and remains responsible for their performance. We will give notice of new subprocessors and a chance to object.
5. International transfers
Where personal data is transferred across borders, the parties will rely on a lawful transfer mechanism (e.g., the EU Standard Contractual Clauses), incorporated by reference where applicable. [REVIEW with counsel.]
6. Security
ClimbSuite maintains measures including tenant isolation, access controls, encryption in transit, secret management, and audit logging, appropriate to the risk. [REVIEW: attach a measures schedule.]
7. Personal data breach
ClimbSuite will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, with information reasonably available to assist the Controller's obligations.
8. Audits
ClimbSuite will make available information reasonably necessary to demonstrate compliance and allow audits per a mutually agreed, reasonable process. [REVIEW.]
9. Liability & precedence
Liability under this DPA is subject to the limitations in the Terms. If this DPA conflicts with the Terms on data protection, this DPA controls.
10. Contact
Data protection contact: tero@sisulogistic.co — Sisu Logistic, LLC (DBA Sisu IO), Miami, FL, USA.