Data Processing Agreement
This Data Processing Agreement (the “DPA”) sets out the terms on which Packet Pilot LLC (“we”) processes personal data on behalf of a customer (“you”) in providing the Service. The DPA forms part of the Terms of Service and is intended to satisfy the requirements of Article 28 GDPR. If you need a separately signed copy, contact us at the address in Article 10.
Article 1 (Scope and roles of the parties)
This DPA applies where we process personal data as a processor, following the purposes and means determined by you as controller.
The cases where we act as controller and where we act as processor are separated as follows. We state this explicitly to avoid confusion.
- Where we are the controller
- Information about your contracting contact, the users who sign in, and your billing contact. We handle this for our own purposes (contract administration, authentication, billing), so our Privacy Policy applies.
- Where we are the processor
- Personal data within the data you put into the Service, or that the Service obtains on your instructions. This DPA applies.
The terms “personal data”, “controller”, “processor”, “processing” and “personal data breach” have the meanings given in Article 4 GDPR.
Article 2 (Details of the processing)
- Subject matter
- Personal data you provide to us in using the Service, or that the Service obtains on your instructions.
- Purpose
- Providing the Service under the Terms of Service and this DPA.
- Nature of processing
- Storage, structuring, analysis, verification, issuing proofs, and the operations the Service needs to function.
- Duration
- For the term of the contract and until deletion or return under Article 7 is complete.
- Categories of personal data
- Name or contact person, business email address, sign-in identifier, IP address, access timestamps, audit logs, and the data handled by each product (Privacy Policy, section 2).
- Categories of data subjects
- Your officers and employees, the users you authorise, and personnel involved with your network or systems.
Certificates and timestamps are designed not to carry personal names or contact details that the proof does not need. Minimising the personal data we process is a design principle, not an afterthought.
Article 3 (Our obligations)
- We process personal data only on your documented instructions, which include the Terms of Service and your use of the Service itself. If law requires us to process outside those instructions, we will tell you beforehand unless the law forbids it.
- We bind personnel who handle personal data to confidentiality and grant access only to those who need it.
- If we consider an instruction from you to infringe the GDPR or other applicable law, we will tell you without delay.
- We do not use your personal data for any purpose beyond this DPA, and we never sell it.
Article 4 (Subprocessors)
You give general authorisation for us to engage the following subprocessors.
- Amazon Web Services Japan
- Hosting and email delivery for the Service. Tokyo region (Japan).
- Stripe
- Credit card payment processing. United States. Stripe collects the card number directly; it does not pass through our systems.
We impose obligations on subprocessors by contract that are materially equivalent to this DPA. We remain liable for a subprocessor’s acts as if they were our own.
If we add or replace a subprocessor, we will publish it on this page and notify you at least 30 days before the change takes effect. You may object on reasonable grounds within 14 days of the notice. If we cannot resolve the objection, you may terminate the contract as to the services that require that subprocessor.
We may add subprocessors — monitoring or log infrastructure, for example — when the Service launches. The current list is always published in this Article.
Article 5 (Assisting with data subject rights)
If a data subject makes a request to us, we will not answer it on our own judgement; we will forward it to you without delay, except where the law requires us to answer directly.
We assist you, so far as is reasonable, through the Service’s administrative functions and technical support, so that you can respond to requests for access, rectification, erasure, suspension of use, restriction of processing, objection and data portability.
Article 6 (Personal data breach notification)
If we become aware of a personal data breach within our sphere of control, we will notify you without undue delay.
The notification will include, so far as known: the nature of the breach, the categories and approximate number of personal data records affected, the likely consequences, the measures we have taken or propose to take, and a contact point on our side.
Where you as controller must notify a supervisory authority — within 72 hours of becoming aware, as a rule, where the GDPR applies — we assist you reasonably by providing the information you need.
Article 7 (Deletion and return on termination)
When the contract ends we will, at your choice, delete the personal data we processed or return it in a machine-readable format. If you give no instruction, we delete it 30 days after the contract ends.
Information we are required by law to retain, and certificates and timestamps already issued, are outside this. The latter are necessary so that recipients can still verify them, and you acknowledge this in advance.
Personal data contained in backups is deleted when the backup retention period expires. Until then it is not restored or used.
Article 8 (International transfers)
We process personal data in Japan (AWS Tokyo region). Transfers from the European Economic Area to Japan may be made without separately concluding Standard Contractual Clauses, because Japan holds an adequacy decision from the European Commission.
For payment processing, some personal data may be transferred to Stripe in the United States. Stripe participates in the EU-US Data Privacy Framework and also offers transfer mechanisms based on Standard Contractual Clauses.
We make no other third-country transfers. If one becomes necessary we will notify you in advance and put a lawful transfer mechanism in place.
Article 9 (Technical and organisational measures)
To meet the standard required by Article 32 GDPR we apply the following.
- Encryption in transit (TLS) and encryption of stored data.
- Secrets held in a key management service (KMS / Secrets Manager), never in source code or configuration files.
- Least-privilege access and role-based access control (RBAC).
- Two-factor authentication on administrative interfaces.
- Tenant isolation, separating each customer’s data.
- API key management. A complete API key is shown only at issue and never again.
- Audit logging, with logs protected against tampering.
- Regular backups, with restore procedures tested.
- Restricted direct access to production databases.
- Data protection by design: keeping the personal data we handle to a minimum.
Article 10 (Audit, evidence and contact)
We provide the information needed to demonstrate compliance with this DPA on your reasonable request.
You may request an audit once per year, on 30 days’ prior written notice. Audits are carried out in a manner and at times that do not unduly disrupt our operations, and you bear the cost. Where we can provide a third-party assessment report, that may take the place of an audit.
For questions about this DPA, or to request a separately signed copy, contact us here.
- Operator
- Packet Pilot LLC (Packet Pilot合同会社)
- product.support@packet-pilot.net