LEGAL & COMPLIANCE

DATA PROCESSING ADDENDUM (DPA)

Effective Date: January 2026

This Data Processing Addendum ("DPA") forms part of the agreement between:
SFL Tech ("Processor" or "Sub-Processor") and The Customer ("Controller" or "Client")

This DPA applies where SFL Tech processes Personal Data on behalf of the Customer in connection with its services, including but not limited to supply chain technology implementation, managed services, system integration, analytics, and support.

1. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Processing: Any operation performed on Personal Data.
  • Controller: The entity determining purposes and means of processing.
  • Processor: The entity processing Personal Data on behalf of the Controller.
  • Applicable Data Protection Laws: Includes GDPR, UK GDPR, CCPA/CPRA, and other relevant regulations.

2. Scope and Roles

For the purposes of GDPR:

  • The Customer is the Controller.
  • SFL Tech acts as Processor (or Sub-Processor where applicable).

SFL Tech processes Personal Data only on documented instructions from the Customer.

3. Nature and Purpose of Processing

Processing activities may include:

  • Implementation and configuration of supply chain platforms
  • Data migration and integration services
  • Managed support services
  • System monitoring and troubleshooting
  • Hosting and infrastructure management (if applicable)

Types of Personal Data may include:

  • Names
  • Email addresses
  • Contact information
  • Employee IDs
  • Business communication data
  • Logistics or shipment-related contact data

Categories of Data Subjects:

  • Customer employees
  • End users
  • Business contacts
  • Suppliers and partners

4. Processor Obligations

SFL Tech shall:

  • Process Personal Data only per documented instructions.
  • Ensure personnel are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures.
  • Assist the Controller in responding to data subject requests.
  • Notify the Controller without undue delay of any Personal Data Breach.
  • Support compliance with Data Protection Impact Assessments (DPIAs) where required.

5. Security Measures

SFL Tech maintains:

  • Access control mechanisms
  • Role-based access policies
  • Encryption in transit (TLS)
  • Secure hosting environments
  • Incident response procedures
  • Regular monitoring and vulnerability management

Security measures are periodically reviewed and updated.

6. Sub-Processors

SFL Tech may engage Sub-Processors for:

  • Cloud infrastructure
  • Email services
  • Analytics tools
  • IT support

SFL Tech ensures Sub-Processors are bound by equivalent data protection obligations. A list of Sub-Processors will be provided upon request.

7. International Transfers

Where Personal Data is transferred outside the EEA/UK:

  • Standard Contractual Clauses (SCCs) or equivalent safeguards shall apply and transfers shall comply with applicable cross-border transfer requirements.

8. Data Subject Rights

SFL Tech shall assist the Customer in responding to:

  • Access requests
  • Rectification
  • Erasure
  • Restriction
  • Portability
  • Objection requests

9. Data Breach Notification

In the event of a Personal Data Breach, SFL Tech shall:

  • Notify the Customer without undue delay
  • Provide details of the breach
  • Outline mitigation measures
  • Cooperate in regulatory reporting if required

10. Data Retention & Deletion

Upon termination of services, SFL Tech shall:

  • Return or delete Personal Data as instructed
  • Confirm deletion in writing (upon request) and retain data only where legally required

11. CCPA/CPRA Specific Provisions

SFL Tech:

  • Does not sell Personal Data.
  • Processes Personal Data solely for business purposes.
  • Does not retain, use, or disclose Personal Data outside the direct business relationship.
  • Complies with CPRA "service provider" obligations.

12. Audit Rights

Upon reasonable notice, the Customer may request documentation demonstrating compliance. On-site audits may be permitted subject to confidentiality and security restrictions.

13. Governing Law

This DPA is governed by the governing law specified in the Master Services Agreement between the parties.