Effective Date: September 2, 2026 · Version 1.0
Data Controller / Business: The SERVNORA customer that determines the purposes and means of processing personal data (“Controller”).
Data Processor / Service Provider: SERVNORA (“Processor”), operating the SERVNORA customer experience intelligence platform.
The legal contracting entity providing the Services will be identified in the applicable order form, subscription record, or other commercial agreement between the parties.
Applicable Data Protection Law means all laws and regulations applicable to the processing of personal data under this DPA, including (where applicable) the EU General Data Protection Regulation (Regulation 2016/679) (“GDPR”), the UK GDPR, the California Consumer Privacy Act (“CCPA”), the Canadian Personal Information Protection and Electronic Documents Act (“PIPEDA”), and any successor legislation.
Personal Data means any information relating to an identified or identifiable natural person that is processed by the Processor on behalf of the Controller under this DPA.
Subprocessor means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
Security Incident means any confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
This DPA applies to all processing of Personal Data performed by the Processor on behalf of the Controller in connection with the SERVNORA service.
This DPA remains in effect for the duration of the Controller’s use of the SERVNORA service, plus any period during which the Processor retains Personal Data as described in Section 14 (Deletion and Return).
The Processor processes Personal Data solely to provide the SERVNORA service as described in the Terms of Service. Processing activities include:
The Processor shall not process Personal Data for any purpose other than as necessary to provide the Service, unless required to do so by applicable law.
Processing may involve the following categories of Personal Data:
Data subjects include:
The Controller represents and warrants that:
The Processor shall process Personal Data only on documented instructions from the Controller, including with respect to transfers of Personal Data to third countries, unless required to do so by Applicable Data Protection Law. In such cases, the Processor shall inform the Controller of the legal requirement before processing, unless prohibited by law.
The Processor shall ensure that all persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation survives the termination of the engagement.
The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as appropriate:
The Processor regularly evaluates and updates its security measures in response to new threats, vulnerabilities, and changes in the processing environment.
The Processor may engage Subprocessors to assist in providing the Service. The Processor shall:
If the Controller objects to a new Subprocessor on reasonable data-protection grounds, the parties shall discuss the objection in good faith. If the objection cannot be resolved, the Controller may terminate the affected Service without penalty.
The Processor shall assist the Controller in fulfilling its obligations to respond to data-subject requests under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, portability, and objection, taking into account the nature of the processing.
Where the Processor receives a request directly from a data subject, the Processor shall promptly notify the Controller (unless prohibited by law) and shall not respond without the Controller’s written authorization.
The Processor provides self-service data-export and deletion tools within the Service that the Controller may use to fulfill data-subject requests. The Processor shall respond to direct requests from the Controller within 30 calendar days.
The Processor shall notify the Controller without undue delay and no later than 72 hours after becoming aware of a Security Incident affecting the Controller’s Personal Data.
The notification shall include, to the extent reasonably available:
Where the Processor cannot provide complete information within the initial notification, it shall provide supplementary information in phases without further undue delay.
The Processor shall cooperate with the Controller and take such reasonable commercial steps as the Controller may direct to assist in the investigation, mitigation, and remediation of each Security Incident.
Upon termination of the Service or upon the Controller’s written request, the Processor shall, at the Controller’s choice:
The Processor shall complete deletion within 30 calendar days of the request, except where retention is required by Applicable Data Protection Law or a binding legal obligation.
Residual copies in system backups, where backups are configured, may persist for up to 90 days for disaster-recovery purposes and will be overwritten in the normal backup rotation cycle.
The Processor shall make available to the Controller, upon request, information reasonably necessary to demonstrate compliance with this DPA, including:
The Controller may conduct or commission an audit of the Processor’s compliance with this DPA no more than once per calendar year, upon 30 days’ prior written notice. The audit shall be conducted during normal business hours, shall not unreasonably interfere with the Processor’s operations, and the Controller shall bear its own costs. Where the Controller engages a third-party auditor, the auditor must be reasonably acceptable to the Processor and must be bound by confidentiality obligations.
The Processor currently processes and stores Personal Data in the United States. Where Personal Data is transferred from the EU/EEA or the United Kingdom to a country outside that area that has not been deemed to provide an adequate level of data protection, the parties shall ensure that an appropriate transfer mechanism is in place, such as:
The Processor shall cooperate with the Controller to execute the applicable transfer mechanism and shall assist with any required transfer-impact assessments.
Current Subprocessor locations are listed on the Subprocessor Disclosure page.
Each party’s liability under this DPA is subject to the limitations set forth in the Terms of Service, except where prohibited by Applicable Data Protection Law. Nothing in this DPA shall limit or exclude either party’s liability for:
Any governing-law and jurisdiction provisions applicable to a customer’s subscription will be specified in the applicable agreement or order form.
This DPA shall be governed by and construed in accordance with the laws of the jurisdiction specified in the applicable agreement, without regard to its conflict-of-laws provisions.
For data-protection matters arising under GDPR or UK GDPR, the parties acknowledge that the supervisory authority having jurisdiction over the Controller’s establishment shall have authority over disputes relating to this DPA.
The Processor may update this DPA from time to time to reflect changes in the Service, subprocessors, or legal requirements. Material changes will be notified to the Controller at least 30 days before they take effect. The Controller’s continued use of the Service after the effective date constitutes acceptance of the updated DPA. If the Controller does not agree to the changes, it may terminate the Service without penalty before the effective date.
If any provision of this DPA is held to be invalid, illegal, or unenforceable, the remaining provisions shall continue in full force and effect. The invalid provision shall be modified to the minimum extent necessary to make it valid and enforceable while preserving the parties’ original intent.
This Data Processing Addendum is supplementary to and forms part of the SERVNORA Terms of Service. Defined terms used but not defined herein have the meaning given to them in the Terms of Service.
This document should be reviewed by qualified legal counsel before execution with customers.