Back to home

Data Processing Addendum

Last updated July 8, 2026

This is a draft pending review by counsel, not legal advice. Have counsel review and tailor it before relying on it in production.

Contents

  1. 1. Roles and scope
  2. 2. Processing on instructions
  3. 3. Details of processing
  4. 4. Security measures
  5. 5. Subprocessors
  6. 6. Assistance and data subject requests
  7. 7. Security incidents
  8. 8. Audit and security documentation
  9. 9. Return and deletion
  10. 10. Data location
  11. 11. CCPA service-provider terms
  12. 12. General

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between ⟦ENTITY⟧ (“Credplot”) and the Customer and applies automatically to every Customer. It governs Credplot’s processing of personal information contained in Customer Data on the Customer’s behalf. Capitalized terms not defined here have the meaning given in the Terms.

Roles and scope

As between the parties, the Customer is the business (controller-equivalent) that determines the purposes and means of processing Customer Data, and Credplot is the service provider (processor-equivalent) that processes it on the Customer’s behalf. This DPA applies to the extent Credplot processes personal information governed by US state privacy laws.

Processing on instructions

Credplot processes Customer Data only to provide the Service, in accordance with the Terms, this DPA, and the Customer’s documented instructions given through the Service. Credplot will not process Customer Data for any other purpose. Credplot personnel with access to Customer Data are bound by confidentiality obligations.

Details of processing

  • Subject matter and purpose: providing the credential-management Service — storage, organization, automated extraction, exclusion screening at the Customer’s direction, license checks, compliance computation, and sharing with organizations the Customer selects.
  • Duration: for the term of the Terms and until Customer Data is deleted as described below.
  • Categories of data subjects: the Customer’s employees, contractors, and other workforce members.
  • Categories of personal information: identity and contact details, employment role, credential records and documents, date of birth, the last four digits of a Social Security number, screening results, and consent records.

Security measures

Credplot maintains technical and organizational measures appropriate to the risk, including: AES-256-GCM encryption of sensitive fields at rest and keyed blind indexes for searchable sensitive fields; encryption in transit; strict per-tenant access scoping so each query is bound to the owning account or a shared organization; server-side upload validation; an append-only audit log capturing meaningful actions with actor, IP, and user agent; rate limiting on sensitive endpoints; personal-information scrubbing in error reporting; and account- and employee-level erasure that purges stored documents before the database cascade.

Subprocessors

The Customer generally authorizes Credplot to engage subprocessors to process Customer Data, each bound by a written agreement imposing data-protection obligations no less protective than this DPA. Credplot maintains a current list of its subprocessors and will provide it to the Customer on request. Credplot remains responsible for its subprocessors’ performance. Before engaging a new subprocessor that will process Customer Data, Credplot will notify the Customer — by email or through the Service — with enough time to object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected Service as its exclusive remedy.

Assistance and data subject requests

Taking into account the nature of processing, Credplot will provide reasonable assistance to the Customer in meeting its obligations to respond to verified requests from individuals to exercise their rights (such as access, correction, and deletion) and to conduct data protection assessments where required. Where Credplot receives such a request directly from an individual regarding Customer Data, it will not respond on the Customer’s behalf, but will refer the individual to the Customer and, where permitted, inform the Customer.

Security incidents

Credplot will notify the Customer without undue delay, and in any event within seventy-two hours, after becoming aware of a security incident leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Data. The notice will describe the nature of the incident, the categories of data affected to the extent known, and the measures Credplot has taken or proposes to take. Credplot will reasonably cooperate with the Customer’s investigation and its own breach-notification obligations. Credplot’s notification is not an acknowledgment of fault or liability.

Audit and security documentation

On the Customer’s reasonable written request, no more than once per year (unless required by a supervisory authority or following a security incident), Credplot will make available information necessary to demonstrate compliance with this DPA — including responses to a reasonable security questionnaire and any then-current third-party audit reports or certifications Credplot maintains. The parties agree that these materials ordinarily satisfy the Customer’s audit rights; on-site audits are limited to cases required by law and are subject to reasonable confidentiality, scope, timing, and security conditions, at the requesting party’s expense.

Return and deletion

On termination of the Terms, or earlier on the Customer’s request, Credplot will delete or return Customer Data as described in the Terms and the Privacy Policy, subject to any legal hold and to copies retained in routine backups for a limited period before expiry.

Data location

Credplot processes and stores Customer Data in the United States. This DPA is limited to US state privacy laws; it does not address the GDPR, the UK GDPR, or international data-transfer mechanisms such as Standard Contractual Clauses, because the Service is not offered to or targeted at individuals in the European Economic Area or the United Kingdom.

CCPA service-provider terms

With respect to personal information subject to the California Consumer Privacy Act as amended, Credplot is a service provider. Credplot will not: sell or share the personal information; retain, use, or disclose it for any purpose other than the business purposes specified in the Terms, or outside the direct business relationship, or as otherwise permitted by the CCPA; or combine it with personal information obtained from other sources except as the CCPA permits a service provider. Credplot certifies that it understands and will comply with these restrictions.

General

If this DPA conflicts with the Terms on the subject of data processing, this DPA controls. All other terms remain in effect.

Portions of this DPA are adapted from the Common Paper Data Processing Agreement (Version 1.1), used under CC BY 4.0.