Vendor Data Processing Addendum
Effective 1 October 2026 · Northstar Systems, Inc. and Customer
1. Scope and instructions
The Vendor will process Customer Data only to provide the hosted analytics service and only on documented instructions from Customer. Customer remains responsible for the lawfulness of those instructions.
2. Data location and subprocessors
Customer Data will be stored and processed in the United States. The Vendor may transfer data to another jurisdiction only after providing thirty days’ written notice and implementing an approved transfer mechanism.Key passage
The current subprocessor list is available on request. The Customer may object to a new subprocessor on reasonable data-protection grounds within fifteen days of notice.
3. Security and incident response
The Vendor will maintain administrative, technical, and physical safeguards proportionate to the nature of the Customer Data, including encryption in transit and at rest and role-based access controls.
The Vendor will notify Customer without undue delay, and in no event later than forty-eight hours after confirming a Security Incident affecting Customer Data.Key passage
Notice will describe the known nature and scope of the incident, the categories of affected data, and mitigation steps taken. This notice obligation does not apply to unsuccessful attempts that do not compromise Customer Data.
4. Audit rights
Once in any twelve-month period, Customer may request the Vendor’s then-current independent audit report. If that report does not reasonably address a material control concern, Customer may conduct a targeted audit at its own expense with ten business days’ notice.Key passage
Audits must occur during normal business hours, avoid unreasonable disruption, and comply with the Vendor’s security and confidentiality requirements.
5. Return and deletion
On termination, the Vendor will make Customer Data available for export for thirty days and will delete remaining copies within sixty days, except where law requires longer retention.Key passage
If retention is required by law, the Vendor will isolate the retained data from further processing and delete it when the legal obligation ends.