HQPartizan Data Processing Addendum
================================================================================
DATA PROCESSING ADDENDUM
HQPartizan - Firebird SQL Query Optimization Tool
IBSurgeon Software (Processor) and Customer (Controller)
Version 1.0 - Effective Date: February 1, 2025
================================================================================
TABLE OF CONTENTS
1. Scope and Application
2. Definitions
3. Roles and Processing Instructions
4. Security Measures
5. Sub-Processors
6. Data Subject Rights
7. Personal Data Breaches
8. International Data Transfers
9. Data Retention and Deletion
10. Audits
11. Liability
12. Term and Termination
13. General Provisions
14. Execution
================================================================================
1. SCOPE AND APPLICATION
================================================================================
1.1 Purpose
This DPA governs IBSurgeon’s processing of Personal Data on behalf of Customer
when using the SQL Query Optimization Tool.
1.2 When This DPA Applies
- Customer processes Personal Data using the Software
- Customer is subject to GDPR, UK GDPR, LGPD, CCPA/CPRA, or similar laws
- Customer needs Standard Contractual Clauses for international transfers
1.3 Incorporation
This DPA is part of the EULA. For data protection matters, this DPA prevails
over the EULA.
1.4 Execution
Execute this DPA via email to [email protected]
================================================================================
2. DEFINITIONS
================================================================================
Controller: Customer (determines purposes and means of Processing)
Processor: IBSurgeon (Processes Personal Data on behalf of Customer)
Personal Data: Information relating to an identified or identifiable person
Data Subject: Individual to whom Personal Data relates
Processing: Any operation on Personal Data (collection, storage, use,
deletion, etc.)
Sub-Processor: Third party engaged by IBSurgeon to Process Personal Data
Personal Data Breach: Security breach affecting Personal Data
Data Protection Laws: GDPR, UK GDPR, LGPD, CCPA/CPRA, and similar laws
Standard Contractual Clauses (SCCs): EU-approved clauses for international
transfers
================================================================================
3. ROLES AND PROCESSING INSTRUCTIONS
================================================================================
3.1 Customer’s Role (Controller)
Customer:
- Determines whether to use the Software and which databases to connect
- Is responsible for legal basis for Processing
- Must obtain necessary consents from Data Subjects
- Must provide privacy notices to Data Subjects
- Must comply with Data Protection Laws
3.2 IBSurgeon’s Role (Processor)
IBSurgeon:
- Processes Personal Data only on Customer’s instructions
- Will not use Personal Data for own purposes (except anonymized aggregated data)
- Implements security measures per Section 4
- Assists with Data Subject rights per Section 6
3.3 Processing Instructions
Customer instructs IBSurgeon to:
- Collect database metadata and query information
- Transmit to LLM Services (OpenAI in USA, DeepSeek in China) for optimization
- Store successful Optimization Data in AWS S3 (USA)
- Return optimization results to Customer
- Delete data per Section 9
3.4 Processing Details
Subject Matter: SQL query optimization using AI/ML
Duration: Subscription Term + 90 days post-termination
Nature: Collection, transmission, analysis, storage, deletion
Purpose: Optimize query performance; improve Software algorithms
Types of Personal Data: Database metadata (if containing identifiers), query patterns (anonymized)
Categories of Data Subjects: Database developers, administrators, end users (indirect)
3.5 Restrictions
IBSurgeon will NOT:
- Sell, rent, or lease Personal Data
- Use Personal Data for marketing or profiling
- Disclose Personal Data except to Sub-Processors or as required by law
- Process outside Customer’s instructions
3.6 Aggregated Data (Not Subject to This DPA)
Once data is fully anonymized (no identifiers, cannot be re-identified),
IBSurgeon may use it as an independent Controller for product development and
research.
================================================================================
4. SECURITY MEASURES
================================================================================
4.1 Encryption
- At Rest: AES-256 encryption (AWS S3 server-side encryption)
- In Transit: TLS 1.2+ for all data transmission
4.2 Anonymization
- SHA-256 hashing of database object names (tables, columns, indexes)
- Literal value stripping from SQL queries
- Irreversible pseudonymization
4.3 Access Controls
- Multi-Factor Authentication (MFA) required for all admin access
- Role-Based Access Control (RBAC) - least privilege principle
- Access logging and quarterly access reviews
- Strong password policies (12+ characters, complexity requirements)
4.4 Network Security
- Firewalls and intrusion detection/prevention
- Network segmentation (production isolated from dev/test)
- Regular vulnerability scanning
4.5 Monitoring and Response
- 24/7 security monitoring and alerting
- Centralized logging (12-month retention)
- Incident response procedures
- Annual penetration testing
4.6 Personnel Security
- Background checks (where legally permitted)
- Confidentiality agreements for all personnel
- Annual security and privacy training
4.7 Backup and Recovery
- Regular backups (weekly full, daily incremental)
- 30-day backup retention
- Encrypted backups
4.8 Planned Certifications
- SOC 2 Type 2: Q4 2026 (in progress)
- ISO 27001: Q2 2027 (planned)
================================================================================
5. SUB-PROCESSORS
================================================================================
5.1 Current Sub-Processors
┌─────────────┬─────────────────────┬──────────┬───────────────────────┐
│Sub-Processor│ Entity │ Location │ Purpose │
├─────────────┼─────────────────────┼──────────┼───────────────────────┤
│ OpenAI │ OpenAI LLC │ USA │ LLM optimization │
├─────────────┼─────────────────────┼──────────┼───────────────────────┤
│ DeepSeek │ Beijing DeepSeek AI │ China │ LLM optimization │
├─────────────┼─────────────────────┼──────────┼───────────────────────┤
│ AWS │ Amazon Web Services │ USA │ Storage/infrastructure│
└─────────────┴─────────────────────┴──────────┴───────────────────────┘
5.2 New Sub-Processors
IBSurgeon will provide 30 days’ advance notice before engaging new
Sub-Processors via:
- Email to registered account
5.3 Objection Rights
Customer may object within 30 days if:
- Sub-Processor is in jurisdiction with inadequate data protection
- Sub-Processor has history of breaches
- Engagement violates Customer’s legal obligations
To object: Email [email protected] with grounds for objection within 30 days
5.4 Resolution
If objection is reasonable and cannot be resolved:
- Customer may terminate without penalty
- Customer receives pro-rated refund
5.5 Sub-Processor Obligations
All Sub-Processors bound by agreements requiring:
- Data protection obligations no less protective than this DPA
- Appropriate security measures
- Confidentiality obligations
- Audit rights
================================================================================
6. DATA SUBJECT RIGHTS
================================================================================
6.1 Assistance Obligation
IBSurgeon will provide reasonable assistance to help Customer respond to Data Subject requests.
6.2 Data Subject Rights
┌────────────────┬─────────────────────────┬──────────────────────────┐
│ Right │ Description │ IBSurgeon Response Time │
├────────────────┼─────────────────────────┼──────────────────────────┤
│ Access │ Obtain copy of Personal │ 15 business days │
│ │ Data │ │
├────────────────┼─────────────────────────┼──────────────────────────┤
│ Rectification │ Correct inaccurate data │ 10 business days │
├────────────────┼─────────────────────────┼──────────────────────────┤
│ Erasure │ Delete Personal Data │ 30 calendar days │
├────────────────┼─────────────────────────┼──────────────────────────┤
│ Restriction │ Suspend Processing │ 5 business days │
├────────────────┼─────────────────────────┼──────────────────────────┤
│ Portability │ Export in JSON format │ 15 business days │
├────────────────┼─────────────────────────┼──────────────────────────┤
│ Object │ Stop Processing │ 5 business days │
└────────────────┴─────────────────────────┴──────────────────────────┘
6.3 Request Process
If Data Subject contacts IBSurgeon directly: IBSurgeon redirects to Customer
If Customer forwards request to IBSurgeon:
- Email: [email protected]
- Subject: “Data Subject Request - [Type]”
- IBSurgeon acknowledges within 2 business days
- IBSurgeon provides assistance per timeframes above
6.4 Fees
- First 2 requests per year: No charge
- Additional requests: Reasonable fees may apply
6.5 Customer Responsibility
Customer is responsible for:
- Receiving and verifying Data Subject requests
- Determining validity
- Responding to Data Subjects within legal deadlines (e.g., 30 days under GDPR)
- Instructing IBSurgeon
================================================================================
7. PERSONAL DATA BREACHES
================================================================================
7.1 Notification Obligation
IBSurgeon will notify Customer within 48 hours of becoming aware of a Personal
Data Breach affecting Customer’s Personal Data.
7.2 Notification Method
- Email to: Security contact + primary account contact
- Phone call if high severity
- Subject: “URGENT: Personal Data Breach Notification - [Incident ID]”
7.3 Notice Contents
- Nature of breach
- Categories and approximate number of Data Subjects affected
- Volume of Personal Data records affected
- Contact point: [email protected]
- Likely consequences
- Measures taken to address breach
7.4 IBSurgeon’s Response
- Containment: Immediate (isolate systems, revoke credentials, block access)
- Investigation: 24-72 hours (determine cause, assess scope, identify affected parties)
- Remediation: Within 7 days (patch vulnerabilities, implement controls)
- Documentation: Maintain detailed records
7.5 Customer’s Obligations
IBSurgeon’s notification does NOT relieve Customer of obligations to:
- Notify Supervisory Authorities (e.g., within 72 hours under GDPR)
- Notify Data Subjects (if high risk)
7.6 Assistance
IBSurgeon will provide reasonable assistance to:
- Assess risk
- Prepare notifications
- Coordinate response
- Respond to regulatory inquiries
7.7 Sub-Processor Breaches
If breach occurs at Sub-Processor, IBSurgeon will notify Customer per above
and coordinate response.
================================================================================
8. INTERNATIONAL DATA TRANSFERS
================================================================================
8.1 Acknowledgment
Customer acknowledges Personal Data will be transferred to:
┌─────────────────┬─────────────────────┬─────────────────────────────┐
│ Destination │ Purpose │ Adequacy Status │
├─────────────────┼─────────────────────┼─────────────────────────────┤
│ United States │ OpenAI (LLM), AWS │ No adequacy decision │
│ │ (storage) │ │
├─────────────────┼─────────────────────┼─────────────────────────────┤
│ China │ DeepSeek (LLM) │ No adequacy decision; high- │
│ │ │ risk jurisdiction │
└─────────────────┴─────────────────────┴─────────────────────────────┘
8.2 Transfer Mechanisms
(a) Standard Contractual Clauses (SCCs): EU-approved SCCs apply (Module Two:
Controller to Processor; Module Three: Processor to Sub-Processor)
(b) Supplemental Measures for China:
\- Enhanced anonymization (SHA-256 hashing)
\- Encryption (TLS 1.3)
\- Contractual prohibitions on DeepSeek sharing data with Chinese
government
\- Regular audits
8.3 Transfer Impact Assessment (TIA)
WARNING: Customer must conduct TIA before transferring Personal Data to assess:
- Whether destination country laws allow effective implementation of SCCs
- Whether government surveillance undermines protections
- Whether supplemental measures are sufficient
IBSurgeon will provide information to support TIA.
8.4 China Transfer Risks
Customer acknowledges risks:
- China National Intelligence Law (2017): Organizations must “support, assist,
and cooperate with state intelligence work”
- Cybersecurity Law and Data Security Law: Broad government access requirements
- Limited legal recourse for Data Subjects
- No effective judicial remedies against government access
IBSurgeon’s supplemental measures mitigate but CANNOT eliminate these risks.
8.5 Alternatives
If transfer risks unacceptable:
- Professional Tier: US-only (no China)
- Local-Only Tier: On-premises (no external transfers)
- Contact: [email protected]
8.6 Standard Contractual Clauses Details
- Clause 7: Docking clause (Sub-Processors may join)
- Clause 9: General authorization with objection rights
- Clause 11: Data Subjects can claim against IBSurgeon
- Clause 13: Irish Data Protection Commission supervises (for EEA customers)
- Clause 17: Irish law governs (for EEA customers)
- Clause 18: Irish courts have jurisdiction (for EEA customers)
Full SCCs text: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
8.7 UK and Swiss Transfers
- UK: UK Addendum to SCCs applies
- Switzerland: Swiss FDPIC-approved SCCs apply
================================================================================
9. DATA RETENTION AND DELETION
================================================================================
9.1 Retention Periods
┌──────────────────────┬─────────────────────┬─────────────────────────┐
│ Data Category │ Retention Period │ Basis │
├──────────────────────┼─────────────────────┼─────────────────────────┤
│ Active Subscription │ During Term │ Service provision │
├──────────────────────┼─────────────────────┼─────────────────────────┤
│ Post-Termination │ Up to 90 days │ Transition, compliance │
├──────────────────────┼─────────────────────┼─────────────────────────┤
│ Aggregated Data │ Indefinite │ Not Personal Data │
│ (Anonymized) │ │ │
├──────────────────────┼─────────────────────┼─────────────────────────┤
│ Backup Systems │ Max 30 days │ Backup rotation │
├──────────────────────┼─────────────────────┼─────────────────────────┤
│ Legal Hold │ As required by law │ Legal obligation │
└──────────────────────┴─────────────────────┴─────────────────────────┘
9.2 Deletion Upon Request
Customer may request deletion anytime:
- Email: [email protected]
- Subject: “Data Deletion Request - [Customer Name] - [Account ID]”
- IBSurgeon acknowledges within 5 business days
- Deletion within 30 calendar days
- Written certification provided upon request
No charge for up to 5 deletion requests per year.
9.3 Deletion Upon Termination
┌────────────────────────┬──────────────────────────────────────────────┐
│ Timeline │ Action │
├────────────────────────┼──────────────────────────────────────────────┤
│ Day 0 │ Software access terminated │
├────────────────────────┼──────────────────────────────────────────────┤
│ Days 1-30 │ Data remains for transition; Customer may │
│ │ request export │
├────────────────────────┼──────────────────────────────────────────────┤
│ Days 31-90 │ IBSurgeon deletes identifiable Personal Data│
├────────────────────────┼──────────────────────────────────────────────┤
│ Day 91+ │ Only anonymized aggregated data retained │
└────────────────────────┴──────────────────────────────────────────────┘
9.4 Data Export
During 30-day transition: Request export in JSON/CSV format via
9.5 Deletion Method
- Digital: DoD 5220.22-M standard or cryptographic erasure
- Backups: Marking for deletion on next rotation
- Cloud (AWS S3): Object deletion with lifecycle policies
9.6 Exceptions to Deletion
IBSurgeon may retain only if:
- Required by law (e.g., tax records, litigation holds)
- Fully anonymized (no individual identifiers)
- Technically impossible (will anonymize and delete when feasible)
Customer will be notified of any exceptions.
9.7 Certification of Deletion
Upon request, IBSurgeon provides written certificate within 15 business days
including:
- Date of request and completion
- Systems from which deleted
- Sub-Processors instructed to delete
- Any exceptions with legal basis
================================================================================
10. AUDITS
================================================================================
10.1 Audit Rights
Customer may audit IBSurgeon’s Processing once per year (more frequently if
required by Supervisory Authority or after breach).
10.2 Audit Notice
90 days’ advance notice to [email protected] including:
- Proposed scope, dates, duration
- Proposed auditor (if third-party)
- Specific concerns (if any)
10.3 Audit Scope
- Review policies/procedures
- Test security controls
- Review Sub-Processor agreements
- Review incident logs
10.4 Limitations
- Business hours only (9 AM - 5 PM, Monday-Friday)
- Minimally disruptive
- Personnel bound by confidentiality
- Max 2 business days duration
- Third-party auditors must be independent and sign NDA
10.5 Alternative: Audit Reports
IBSurgeon may provide instead of on-site audit:
- SOC 2 Type 2 reports (when available)
- ISO 27001 certifications (when available)
- Penetration test summaries (redacted)
- Compliance questionnaires
10.6 Audit Costs
Included at no charge:
- Providing audit reports/certifications
- Responding to reasonable inquiries
- Up to 4 hours of personnel time per year
Additional costs (Customer pays):
- Customer’s personnel and auditors
- Travel/accommodation
- IBSurgeon time beyond 4 hours
- Extensive testing/analysis
10.7 DPIA Assistance
If Customer must conduct Data Protection Impact Assessment (DPIA), IBSurgeon
will provide reasonable assistance within 15 business days:
- Processing description
- Security information
- Risk assessment support
- Review draft DPIA
10.8 Supervisory Authority Cooperation
IBSurgeon will:
- Cooperate with Supervisory Authorities
- Respond to inquiries within required timeframes
- Notify Customer within 2 business days of any inquiry
10.9 Remediation
If audit reveals non-compliance:
- IBSurgeon acknowledges within 10 business days
- Provides remediation plan within 30 days
- Implements remediation (timeframe based on severity)
- Notifies Customer upon completion
Serious non-compliance: Customer may suspend or terminate.
================================================================================
11. LIABILITY
================================================================================
11.1 General Framework
Liability governed by EULA Section 8, except as modified below.
11.2 GDPR Article 82 Liability
For GDPR Processing:
- Both Controller and Processor may be liable for damages
- Processor liable only if failed to comply with GDPR Article 28 obligations
or acted outside/contrary to instructions
- Data Subjects have right to full compensation
- If both parties liable, liability apportioned based on fault
- Processor exempt if proves not responsible
11.3 Maximum Liability
IBSurgeon’s total liability: Greater of (i) fees paid in 12 months prior, or
(ii) $1,000 USD
Exception (cap does NOT apply):
- GDPR Article 82 damages (if caps prohibited by law)
- Gross negligence or willful misconduct
- Breach of confidentiality
- Indemnification obligations
11.4 Excluded Damages
IBSurgeon not liable for indirect, consequential, or special damages, EXCEPT:
- Where prohibited by Data Protection Laws
- GDPR Article 82 damages (if limitation prohibited)
11.5 Customer Indemnification
Customer indemnifies IBSurgeon for claims from:
- Customer’s violation of Data Protection Laws
- Failure to obtain necessary consents
- Breach of compliance obligations
- Unlawful Processing instructions
- Customer’s acts/omissions
11.6 IBSurgeon Indemnification
IBSurgeon indemnifies Customer for third-party claims where IBSurgeon’s Processing violated Data Protection Laws due to IBSurgeon’s breach
Conditions:
- Customer notifies within 10 days
- IBSurgeon controls defense
- Customer cooperates
- Claim doesn’t arise from Customer’s actions
Exceptions (no indemnification):
- Customer’s unlawful instructions
- Customer’s non-compliance
- Data that shouldn’t have been submitted
- Combination with Customer’s systems
Maximum: Subject to EULA liability caps unless prohibited.
11.7 Regulatory Fines
- Customer responsible for fines due to Customer’s violations
- IBSurgeon responsible for fines due to IBSurgeon’s violations
- If both contributed: Negotiate allocation based on fault (arbitration if no agreement)
================================================================================
12. TERM AND TERMINATION
================================================================================
12.1 Term
This DPA:
- Begins: On execution or first use of Software to Process Personal Data
- Continues: As long as IBSurgeon Processes Personal Data
- Terminates: Upon later of EULA termination or deletion of all Personal Data
12.2 Termination Rights
(a) Automatic: Terminates if EULA terminates
(b) For Cause: Either party may terminate for material breach not cured within
30 days
(c) Regulatory Changes: Either party may terminate on 30 days’ notice if Data
Protection Law changes make DPA unlawful
12.3 Effect of Termination
Upon termination:
- IBSurgeon ceases Processing (except as necessary for deletion/return)
- IBSurgeon deletes or returns all Personal Data (Customer’s choice)
- Customer must instruct within 15 days (if no instruction, IBSurgeon deletes)
- IBSurgeon directs Sub-Processors to delete
- IBSurgeon provides written certification within 30 days
- Data retained only if legally required (isolated, deleted when permitted)
12.4 Survival
Provisions that survive:
- Section 4 (Security) - for retained data
- Section 7 (Breaches) - for breaches discovered after termination
- Section 9 (Retention/Deletion)
- Section 10 (Audits) - for pre-termination Processing
- Section 11 (Liability/Indemnification)
- Section 13 (General Provisions)
================================================================================
13. GENERAL PROVISIONS
================================================================================
13.1 Relationship to EULA
- This DPA is part of EULA
- For data protection matters: DPA prevails
- For other matters: EULA prevails
13.2 Precedence
This DPA supersedes any prior data processing agreements between parties.
13.3 Amendments
IBSurgeon may amend upon 60 days’ notice (90 days for material changes
reducing protections).
Notice via email.
If Customer objects:
- May terminate before effective date without penalty
- Receives pro-rated refund
Continued use after effective date = acceptance
Regulatory amendments: Effective immediately (no objection rights).
13.4 Governing Law
EEA/UK Customers: Irish law and Irish courts
Other Customers: As specified in EULA (Delaware, USA)
Exception: Data Protection Law requirements prevail if conflict.
13.5 Severability
If provision held invalid:
- Modify to minimum extent to make enforceable
- If not possible, sever
- Remainder remains in effect
Special rule: SCCs cannot be modified/severed. If invalid, entire SCCs may be
void; parties implement alternative or terminate.
13.6 Entire Agreement
This DPA + EULA + SCCs + Schedules = entire agreement on Personal Data
Processing.
13.7 No Waiver
Failure to enforce ≠ waiver. Waiver must be in writing and signed.
13.8 Assignment
Customer: Cannot assign without consent (except with EULA assignment)
IBSurgeon: May assign with 30 days’ notice (merger, acquisition, affiliate)
13.9 Notices
To IBSurgeon: support@ib-aid
To Customer: Email registered in account
Effective: Email upon transmission (or next business day)
13.10 Third-Party Beneficiaries
- Data Subjects: Third-party beneficiaries under GDPR Article 82 and SCC
Clause 11
- Sub-Processors: May join SCCs under Clause 7 (docking)
- No other third parties
13.11 Language
English version controls. Any translation for convenience only.
13.12 Counterparts and Electronic Signatures
May execute in counterparts. Electronic signatures valid and binding.
13.13 Interpretation
- Defined terms have meanings in Section 2 or EULA
- Headings for convenience only
- For data protection: DPA prevails; for other matters: EULA prevails
================================================================================
14. EXECUTION
================================================================================
14.1 Execution Methods
(a) Online at www.ibsurgeon.com/dpa
(b) Countersigned PDF to [email protected]
(c) Order Form incorporating DPA by reference
14.2 Effective Date
Earlier of:
- Date of execution
- Date Customer first uses Software to Process Personal Data
14.3 Signatures
FOR CUSTOMER (CONTROLLER):
Customer Legal Name: ___________________________________________________
Signature: _____________________________________________________________
Name: __________________________________________________________________
Title: _________________________________________________________________
Date: __________________________________________________________________
Email: _________________________________________________________________
FOR IBSURGEON SOFTWARE (PROCESSOR):
IBSurgeon Software
Signature: _____________________________________________________________
Name: __________________________________________________________________
Title: Data Protection Officer / Legal Representative
Date: __________________________________________________________________
================================================================================
SCHEDULE 1: PROCESSING DETAILS
================================================================================
A. Parties
Controller: Customer [Address and email from account]
Processor: IBSurgeon Software, support@ib-aid
B. Processing Description
Subject Matter: SQL query optimization using AI/ML
Duration: Subscription Term + 90 days post-termination
Nature: Collection, transmission, analysis, storage, deletion
Purpose: Optimize query performance; improve Software algorithms
Categories of Data Subjects:
- Database developers
- Database administrators
- Application developers
- End users (indirect)
Categories of Personal Data:
- Database metadata (table/column names if containing identifiers before
anonymization)
- Query patterns (SQL text with literals stripped)
- Performance data (anonymized)
- Account information (pseudonymized)
Special Categories: Customer represents Software does NOT process special
categories (health, biometric, genetic, racial/ethnic, political, religious,
trade union, sexual orientation) unless additional safeguards implemented.
Sensitive Data: Customer represents Software does NOT process payment card
data (PCI DSS), PHI (HIPAA), student records (FERPA), or financial account
info (GLBA) unless appropriate agreements executed.
Processing Operations:
- Collection: Gather database metadata, statistics and query info to analyze performance
- Transmission: Send anonymized data to LLM Services for optimization
- Analysis: Process through AI/ML algorithms to identify improvements
- Storage: Store successful results in AWS S3 to improve algorithms
- Deletion: Remove Personal Data after retention period
C. Supervisory Authority (for SCCs)
┌───────────────────────┬─────────────────────────────────────────────────┐
│ Customer Location │ Competent Supervisory Authority │
├───────────────────────┼─────────────────────────────────────────────────┤
│ Ireland │ Irish Data Protection Commission (DPC) │
├───────────────────────┼─────────────────────────────────────────────────┤
│ EEA │ Supervisory Authority of Member State │
├───────────────────────┼─────────────────────────────────────────────────┤
│ UK │ UK Information Commissioner’s Office (ICO) │
├───────────────────────┼─────────────────────────────────────────────────┤
│ Switzerland │ Swiss FDPIC │
├───────────────────────┼─────────────────────────────────────────────────┤
│ Other │ As determined under applicable law │
└───────────────────────┴─────────────────────────────────────────────────┘
================================================================================
SCHEDULE 2: SECURITY MEASURES SUMMARY
================================================================================
Encryption:
- At Rest: AES-256 (AWS S3)
- In Transit: TLS 1.2+
Anonymization:
- SHA-256 hashing of identifiers
- Literal stripping from queries
Access Controls:
- Multi-Factor Authentication (MFA)
- Role-Based Access Control (RBAC)
- Quarterly access reviews
- Strong password policies
Network Security:
- Firewalls and intrusion detection
- Network segmentation
- Regular vulnerability scanning
Monitoring:
- 24/7 security monitoring
- Centralized logging (12-month retention)
- Incident response procedures
- Annual penetration testing
Personnel:
- Background checks
- Confidentiality agreements
- Annual security training
Backup:
- Weekly full, daily incremental
- 30-day retention
Certifications (Planned):
- SOC 2 Type 2: Q4 2026
- ISO 27001: Q2 2027
Full details available upon request or via audit.
================================================================================
SCHEDULE 3: SUB-PROCESSOR LIST
================================================================================
Current Sub-Processors (as of February 1, 2025):
1. OpenAI LLC
Location: United States
Purpose: LLM query optimization services
Data: Anonymized query text, metadata
2. DeepSeek AI (Beijing DeepSeek Artificial Intelligence Fundamental
Technology Research Co., Ltd.)
Location: People’s Republic of China
Purpose: LLM query optimization services
Data: Anonymized query text, metadata
3. Amazon Web Services (AWS)
Location: United States (Oregon region US-West-2)
Purpose: Cloud infrastructure and data storage
Data: All Optimization Data, Personal Data (if any)
Note: AWS may use its own sub-contractors per AWS Sub-Processor list at
https://aws.amazon.com/compliance/sub-processors/
Current list maintained at: www.ibsurgeon.com/subprocessors
Subscribe to change notifications: www.ibsurgeon.com/subprocessors/subscribe
Historical versions available upon request: [email protected]
================================================================================
SCHEDULE 4: STANDARD CONTRACTUAL CLAUSES (SCCs)
================================================================================
EU Standard Contractual Clauses for International Transfers
Pursuant to European Commission Implementing Decision (EU) 2021/914
Modules Applied:
☑ MODULE TWO: Transfer Controller to Processor
Data Exporter: Customer (Controller)
Data Importer: IBSurgeon Software (Processor)
☑ MODULE THREE: Transfer Processor to Processor (for Sub-Processors)
Data Exporter: IBSurgeon Software (Processor)
Data Importer: Sub-Processors
Optional Clauses:
☑ Clause 7 (Docking): Sub-Processors may join by signing Accession Agreement
☑ Clause 9 (Sub-Processors): Option 2 - General authorization with
notification and objection rights (30 days)
☑ Clause 11 (Redress): Data Subjects have third-party beneficiary rights
☑ Clause 17 (Governing Law): Ireland (for EEA customers)
☑ Clause 18 (Jurisdiction): Irish courts (Dublin) for EEA customers
Annexes to SCCs:
- Annex I: Details of Processing (incorporated by reference to Schedule 1)
- Annex II: Technical and Organizational Measures (incorporated by reference
to Schedule 2)
- Annex III: Sub-Processor List (incorporated by reference to Schedule 3)
Full SCC Text:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
UK Addendum (for UK GDPR):
UK International Data Transfer Addendum (Version B1.0) applies
https://ico.org.uk/media/for-organisations/documents/4019539/international-
data-transfer-addendum.pdf
Swiss Addendum (for Swiss FADP):
References to “GDPR” include Swiss FADP
References to “EU Member State” include Switzerland
Supervisory authority: Swiss FDPIC
Governing law: Irish law (or Swiss law if parties agree)
By executing this DPA, parties agree to be bound by SCCs as if fully set forth
herein.
================================================================================
END OF DATA PROCESSING ADDENDUM
================================================================================
Document Version: 1.0 (Condensed)
Effective Date: February 1, 2025
Last Updated: February 1, 2025
For Questions or Execution:
IBSurgeon Software
Data Protection Officer
Email: [email protected]
================================================================================