This DPA supplements the Terms when Customer is a business controller/processor and becomes binding when incorporated into an order or accepted in writing by Fareground. Contact hello@fareground.com for execution.
1. Roles and instructions
Customer is controller or processor; Fareground is processor or subprocessor. Instructions are to provide, secure, support, and improve the configured Services. Each party complies with applicable data-protection law.
2. Confidentiality and security
Authorized personnel are bound by confidentiality. Fareground maintains risk-appropriate access control, encryption in transit, production encryption at rest, credential protection, logs, backups, monitoring, incident response, and recovery testing. Customer controls permissions, credentials, lawful basis, and content.
3. Subprocessors
Customer authorizes the register. We impose materially equivalent obligations and remain responsible as law requires. Material additions receive 15 days’ posted notice where practicable. Reasonable data-protection objections will be addressed; either party may terminate the affected service if no alternative exists.
4. Assistance and incidents
Taking processing into account, we reasonably assist with data-subject requests, security obligations, impact assessments, consultations, and compliance evidence. We notify Customer without undue delay after confirming a breach affecting its personal data and provide available required information.
5. Deletion, transfers, audits
At termination/instruction we delete or return data unless law requires retention; backups expire normally and remain recovery-only. For EEA restricted transfers, the 2021 SCCs apply (Module 2 or 3 as appropriate), with this DPA supplying Annexes I/II; the UK Addendum applies for UK transfers. We provide reasonable compliance information and allow one annual independent audit on notice, plus audits required after an incident or by a regulator, without exposing other customers or creating security risk.
6. Processing details
Subject/duration: operation of Services during the term plus retention. Nature: collection, hosting, organization, retrieval, transmission to configured providers, support, deletion, and recovery. Purpose: providing and securing Services. Subjects: users, collaborators, agent owners, and people in submitted data. Data: identifiers, communications, customer content, usage/device/support/billing metadata. Sensitive data is prohibited absent written agreement.