Vendor Data Processing AddendumSample agreement · 4 pages
4 passages
Sample agreement

Vendor Data Processing Addendum

Effective 1 October 2026 · Northstar Systems, Inc. and Customer

1. Scope and instructions

The Vendor will process Customer Data only to provide the hosted analytics service and only on documented instructions from Customer. Customer remains responsible for the lawfulness of those instructions.

2. Data location and subprocessors

Customer Data will be stored and processed in the United States. The Vendor may transfer data to another jurisdiction only after providing thirty days’ written notice and implementing an approved transfer mechanism.Key passage

The current subprocessor list is available on request. The Customer may object to a new subprocessor on reasonable data-protection grounds within fifteen days of notice.

3. Security and incident response

The Vendor will maintain administrative, technical, and physical safeguards proportionate to the nature of the Customer Data, including encryption in transit and at rest and role-based access controls.

The Vendor will notify Customer without undue delay, and in no event later than forty-eight hours after confirming a Security Incident affecting Customer Data.Key passage

Notice will describe the known nature and scope of the incident, the categories of affected data, and mitigation steps taken. This notice obligation does not apply to unsuccessful attempts that do not compromise Customer Data.

4. Audit rights

Once in any twelve-month period, Customer may request the Vendor’s then-current independent audit report. If that report does not reasonably address a material control concern, Customer may conduct a targeted audit at its own expense with ten business days’ notice.Key passage

Audits must occur during normal business hours, avoid unreasonable disruption, and comply with the Vendor’s security and confidentiality requirements.

5. Return and deletion

On termination, the Vendor will make Customer Data available for export for thirty days and will delete remaining copies within sixty days, except where law requires longer retention.Key passage

If retention is required by law, the Vendor will isolate the retained data from further processing and delete it when the legal obligation ends.

Your reading desk

Return to source-backed reviews from this prototype.

PDFVendor Data Processing Addendum Recommended demoSample agreement · 4 verified passagesOpen →