Version: 2026-06-19 · Effective date: June 19, 2026
This Data Processing Addendum forms part of the Terms of Service and applies where Dirigex processes Customer Personal Data on the Customer's behalf.
1. Roles and scope
The Customer is the Controller and determines the purposes and means of processing; Dirigex is the Processor and processes Customer Personal Data only on the Controller's documented instructions, including as set out in the Terms and this DPA.
2. Processor obligations
Dirigex will process only on instructions; bind personnel to confidentiality; implement appropriate technical and organizational security measures; assist with data-subject requests and with security, breach-notification, and DPIA obligations; and make available information needed to demonstrate compliance.
3. Sub-processors
The Customer authorizes Dirigex to engage Sub-processors under data-protection terms no less protective than this DPA. Dirigex remains responsible for their performance and will give notice of changes.
4. International transfers
Where Customer Personal Data is transferred across borders, the parties will rely on an approved transfer mechanism (e.g. Standard Contractual Clauses).
5. Security
Dirigex maintains security measures including encryption in transit, access controls, MFA support, and tamper-evident audit logging.
6. Personal data breach
Dirigex will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and will cooperate on remediation.
7. Return and deletion
On termination, Dirigex will delete or return Customer Personal Data per the Controller's instruction, subject to legal retention requirements.
8. Audits
Dirigex will make available information and, subject to confidentiality and reasonable scope, allow audits to verify compliance.
Annexes
Annex I (description of processing), Annex II (security measures), and Annex III (authorized sub-processors) will be attached to the finalized DPA.