Data Processing Agreement

GDPR-compliant data processing terms for NetJet Labs services. Protect your data with our comprehensive security framework.

Version 1.0
Effective July 17, 2024
Compliance GDPR, CCPA

Quick Navigation

1

Definitions

â–ŧ

Data Controller: The natural or legal person that determines the purposes and means of personal data processing. Typically, this is you (our client).

Data Processor: The natural or legal person that processes personal data on behalf of the controller. NetJet Labs acts as your data processor.

Personal Data: Any information relating to an identified or identifiable natural person. Examples include names, email addresses, IP addresses, cookies, and location data.

Processing: Any operation performed on personal data, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, transmission, erasure, or destruction.

Data Subject: The individual to whom personal data relates (e.g., your customers, employees, or users).

Other Key Terms

  • GDPR: General Data Protection Regulation (EU 2016/679) - the primary data protection regulation
  • Sub-processor: A natural or legal person that processes personal data on behalf of the processor (our subcontractors)
  • Data Breach: A security incident resulting in accidental or unlawful destruction, loss, alteration, or disclosure of personal data
  • Processing Agreement: A contract between controller and processor that complies with GDPR Article 28
  • Standard Contractual Clauses (SCCs): Approved contract terms for transferring personal data outside the EEA

🔐 This DPA supplements the Services Agreement between our organizations and complies with GDPR Article 28.

2

Scope and Applicability

â–ŧ

This DPA applies whenever NetJet Labs processes personal data on your behalf as a data processor under GDPR.

When This DPA Applies

  • You are the data controller (you determine what data to process and why)
  • We are processing EU residents' personal data
  • GDPR applies to the processing
  • We process data as a service provider on your instructions

Services Covered

This DPA covers all NetJet Labs services including:

  • Web application hosting and maintenance
  • Cloud storage and backup services
  • Email delivery services
  • Analytics and monitoring
  • Support services
  • Any other services involving personal data processing

Data Processing Details

Element Details
Subject Matter Processing of personal data as necessary to deliver contracted services
Duration For the term of the Services Agreement, plus retention period
Nature of Processing Storage, analysis, backup, transmission, and access management
Purpose To provide the contracted services under your instructions
Types of Data Any personal data you provide or process through our services
Categories of Data Subjects Your customers, employees, users, or other data subjects you control

â„šī¸ This is a standard processor agreement. It does not grant NetJet Labs control over data processing.

3

Processing Instructions

â–ŧ

NetJet Labs will process personal data only on documented instructions from you.

Your Role as Controller

You are responsible for:

  • Determining what personal data to process
  • Determining the purposes of processing
  • Determining the means of processing
  • Ensuring you have a lawful basis for processing
  • Informing data subjects about processing
  • Responding to data subject requests

Our Role as Processor

NetJet Labs will:

  • Process data only as instructed by you
  • Not determine purposes or means of processing
  • Not disclose data to third parties without authorization
  • Implement reasonable security measures
  • Assist with your compliance obligations
  • Delete or return data upon termination

Initial Instructions

The initial processing instructions are set forth in:

  • The Services Agreement between our organizations
  • Any project specifications or statements of work
  • Written instructions you provide via email or our support portal

Changing Instructions

You may modify processing instructions by:

  • Written request to legal@netjetlabs.com
  • Instructions through our admin dashboard (for supported services)
  • Changes take effect within 5 business days unless otherwise agreed
  • We will confirm receipt and implementation of changes

âš ī¸ We will not process personal data in ways that deviate from your documented instructions without your prior written consent.

4

Security Measures

â–ŧ

NetJet Labs implements comprehensive technical and organizational measures to protect personal data from unauthorized processing, accidental loss, destruction, and damage.

Technical Measures

  • Encryption: TLS/SSL for data in transit, AES-256 for data at rest
  • Access Controls: Role-based authentication, multi-factor authentication available
  • Firewalls: Network-level protection with DDoS mitigation
  • Intrusion Detection: 24/7 monitoring for unauthorized access attempts
  • Vulnerability Scanning: Regular automated and manual security assessments
  • Backup Systems: Automated daily backups with geographic redundancy
  • Disaster Recovery: RTO < 4 hours, RPO < 1 hour

Organizational Measures

  • Staff Training: Annual data protection and security training
  • Access Controls: Principle of least privilege, immediate offboarding procedures
  • Incident Response: Documented procedures for data breach response
  • Data Protection: Data protection by default and design principles
  • Vendor Management: Security assessments for all sub-processors
  • Audit Trails: Comprehensive logging of all data access and modifications

Data Protection Impact Assessment (DPIA)

We support your DPIA requirements by:

  • Providing detailed information about our security measures
  • Responding to security questionnaires
  • Providing audit reports and certifications upon request
  • Assisting with risk assessments

🔒 Our security measures are regularly reviewed and updated to match industry standards and emerging threats.

5

Sub-processors

â–ŧ

NetJet Labs may use sub-processors to deliver certain services. All sub-processors are bound by confidentiality and security obligations.

Your Consent

  • By signing this DPA, you provide general authorization for sub-processors
  • You have the right to object to additions of new sub-processors
  • Objections must be made in writing within 15 days of notification
  • If you object, you may terminate services without penalty (with 30 days notice)

Current Sub-processors

Current approved sub-processors include:

  • Amazon Web Services (AWS) - Cloud infrastructure hosting
  • Google Cloud Platform - Email services and analytics
  • SendGrid - Email delivery
  • Stripe / PayPal - Payment processing
  • GitHub - Code repository and deployment

For a current list of sub-processors, visit: https://netjetlabs.com/sub-processors

Sub-processor Requirements

All sub-processors must:

  • Process data only on documented instructions
  • Implement equivalent security measures
  • Be bound by confidentiality obligations
  • Not sub-contract further without our written approval
  • Provide assistance with data subject rights
  • Comply with GDPR requirements

Adding New Sub-processors

When we add new sub-processors, we will:

  • Notify you 15 days in advance via email and website notice
  • Provide the sub-processor's name and processing details
  • Confirm equivalent security measures are in place
  • Give you 15 days to object

📋 We maintain a current sub-processor list that you can review anytime.

6

Data Subject Rights

â–ŧ

Data subjects have rights under GDPR. NetJet Labs will assist you in fulfilling these requests.

Data Subject Rights Overview

Right What It Means Our Assistance
Access Right to obtain a copy of personal data Export data in structured format
Rectification Right to correct inaccurate data Update or correct data as instructed
Erasure Right to be forgotten (delete data) Delete data from active systems
Portability Right to receive data in machine-readable format Export in CSV, JSON, or XML format
Restriction Right to restrict processing Stop processing but retain data
Objection Right to object to processing Stop processing if legally permitted

How to Handle Requests

Your Responsibility:

  • You receive data subject requests from your customers/users
  • You verify the identity of the requester
  • You forward verified requests to us

Our Assistance:

  • Provide the requested data/action within 5 business days
  • Assist with technically complex requests
  • Confirm completion of the request in writing
  • Document all assistance for compliance records

Requesting Data Subject Rights Assistance

To request our assistance, email: dpa-requests@netjetlabs.com with:

  • Your company name and account ID
  • The data subject's name/identifier
  • The specific right being exercised (access, deletion, etc.)
  • Any relevant details (date range, data categories, etc.)

✅ We aim to respond to all data subject rights requests within 5 business days.

7

Assistance and Audit Rights

â–ŧ

NetJet Labs provides reasonable assistance to help you meet your GDPR compliance obligations and audit requirements.

Compliance Assistance

We assist you by providing:

  • Documentation of our security measures
  • Data protection impact assessment (DPIA) support
  • Responses to regulatory information requests
  • Audit reports and compliance certifications
  • Training on our security features
  • Breach notification support (if applicable)

Your Audit Rights

You have the right to audit our compliance:

  • SOC 2 Type II Report: Available annually (covers security and confidentiality)
  • On-site Audits: Permitted with 30 days notice (reasonable frequency)
  • Security Questionnaires: Completed within 10 business days
  • Penetration Testing: Coordinated with our security team

Audit Limitations

  • Maximum 1 on-site audit per year (more frequent with mutual consent)
  • Audits conducted during business hours
  • You must sign an NDA before reviewing sensitive information
  • Audits must not interfere with service operations

Requesting Audits or Reports

Contact: compliance@netjetlabs.com

  • Specify the audit type or report needed
  • Provide your audit scope and timeline
  • We'll coordinate scheduling and any required NDAs

📊 We maintain SOC 2 Type II certification and can provide current reports upon request.

8

Breach Notification

â–ŧ

In the event of a data breach, NetJet Labs will notify you immediately and provide full cooperation in your breach response.

Breach Definition

A confirmed or suspected security incident involving:

  • Accidental or unlawful destruction of personal data
  • Loss or alteration of personal data
  • Unauthorized disclosure of personal data
  • Unauthorized access to personal data

Our Breach Response

  • Detection: We monitor for suspicious activity 24/7
  • Containment: Immediately isolate affected systems
  • Notification: Contact you within 4 hours of confirmation
  • Investigation: Determine cause and scope
  • Evidence Preservation: Maintain forensic evidence for 90 days

Information We Provide

Your breach notification will include:

  • Date and time of the breach
  • Description of what happened
  • Types of personal data affected
  • Number of individuals affected (if known)
  • Likely consequences
  • Steps we're taking to mitigate
  • Your contact point for questions

🚨 We notify you of breaches within 4 hours of confirmation - giving you time to notify data subjects as required by law.

9

International Data Transfers

â–ŧ

If your data is transferred outside the EEA, NetJet Labs ensures adequate safeguards comply with GDPR Chapter 5.

Transfer Mechanisms

For transfers outside the EEA/UK, we use:

  • Standard Contractual Clauses (SCCs): EU-approved contract terms
  • Data Protection Agreements: Binding corporate rules
  • Adequacy Decisions: Countries deemed adequate (Canada, Japan, etc.)

Our Data Location Policy

  • Primary processing location: EU-based data centers
  • Backup/redundancy: May use non-EEA providers with SCCs
  • You can request specific data residency (with additional fees)
  • Default: Data remains in EU unless you request otherwise

Sub-processor Transfers

If sub-processors are outside the EEA:

  • We inform you of transfer locations
  • SCCs or other safeguards are in place
  • You can object to transfers

🌍 We prioritize EU data residency but can accommodate global data placement with appropriate legal safeguards.

10

Data Return and Deletion

â–ŧ

Upon termination of services, NetJet Labs will return or securely delete your personal data per your instructions.

At End of Services

Data Return

  • Provided in structured, machine-readable format
  • CSV, JSON, database backup, or format you specify
  • Encryption applied if requested
  • Technical support provided for data import
  • Typically within 30 days of termination

Data Deletion

  • Deleted from active systems within 90 days
  • Backup systems purged within 90 days
  • Backup tapes physically destroyed or securely wiped
  • Certificate of deletion provided upon request
  • Exception: legally required retention

Retention Exceptions

We may retain personal data if required by:

  • Tax law (typically 7 years)
  • Contract law (typically 3-7 years)
  • Litigation hold
  • Regulatory authority requests

Your Responsibility

  • You are responsible for deleting your copy of returned data
  • You remain liable for data you retain
  • Ensure your sub-processors delete data

✅ Data deletion is verified and documented for your compliance records.

11

Liability and Indemnification

â–ŧ

This section clarifies liability for data processing and GDPR compliance.

Our Processor Liability

NetJet Labs is liable for violations of:

  • GDPR data processor obligations (Article 28-34)
  • Failure to implement security measures
  • Unauthorized disclosure of personal data
  • Failure to assist with data subject rights
  • Failure to notify of breaches

Limitation on Our Liability

  • We are not liable for losses caused by your instructions or failure to comply with GDPR
  • Not liable for data loss due to your failure to maintain backups
  • Not liable for unauthorized access if you don't secure credentials
  • See Terms of Service for overall liability caps

Your Controller Liability

You are liable for violations of:

  • GDPR data controller obligations
  • Failure to obtain lawful basis for processing
  • Failure to inform data subjects
  • Failure to respond to data subject requests
  • Failure to comply with regulatory requests

Indemnification

You indemnify us for:

  • Claims from your violation of GDPR
  • Claims from your unlawful instructions
  • Claims that your data infringes third-party rights
  • Claims from your failure to obtain consents
  • Regulatory fines from your violations

We indemnify you for:

  • Claims we violated GDPR processor obligations
  • Claims we failed to implement security measures
  • Claims from our breach or misconduct
  • Regulatory fines from our violations

âš–ī¸ Liability is shared based on who caused the violation - fair for both parties.

12

Term and Termination

â–ŧ

This DPA governs our data processing relationship for as long as we work together.

Term

  • Effective upon execution
  • Continues for duration of service engagement
  • Survives termination of services for 5 years for retention obligations

Termination Obligations

Upon termination or expiry:

  • We stop processing personal data immediately
  • We delete or return data per Section 10
  • Confidentiality obligations continue indefinitely
  • Liability obligations continue for past processing

Early Termination

  • For convenience: 30 days notice (see Terms of Service)
  • For cause: Immediate upon material breach
  • Data return required: Regardless of cause

📋 Termination obligations ensure clean data separation and your continued compliance.

13

GDPR Compliance Summary

â–ŧ

This DPA addresses all key GDPR requirements for data processor relationships.

GDPR Requirements Addressed

GDPR Article Requirement How We Comply
Article 5 Principles (lawfulness, fairness, transparency, data minimization, accuracy, storage limitation, integrity, accountability) We process only on your instructions with security measures and records
Articles 12-22 Data Subject Rights We assist with access, rectification, erasure, restriction, portability, objection (Section 6)
Article 28 Data Processing Agreement This DPA
Article 32 Security Measures Technical and organizational measures (Section 4)
Articles 33-34 Breach Notification Immediate notification within 4 hours (Section 8)
Articles 44-50 International Transfers Standard Contractual Clauses and safeguards (Section 9)

Key Principles Covered

  • ✓ Lawfulness and fairness of processing
  • ✓ Purpose limitation and data minimization
  • ✓ Accuracy and storage limitation
  • ✓ Integrity and confidentiality
  • ✓ Accountability with documentation
  • ✓ Data subject rights and assistance
  • ✓ Security and breach notification
  • ✓ International data transfer safeguards

✅ This DPA provides comprehensive GDPR Article 28 compliance for processor relationships.

Execution and Questions

DPA Execution

This DPA becomes effective upon execution by both parties. To execute:

Email: legal@netjetlabs.com
Subject: DPA Execution - [Your Company Name]

We will provide a fully executed copy for your records.

Data Protection Questions

Privacy Office: privacy@netjetlabs.com
Legal: legal@netjetlabs.com
Compliance: compliance@netjetlabs.com
Phone: +880 181741-4687

Effective Date: July 17, 2024
Version: 1.0
DPA ID: NETJET-LABS-DPA-v1.0-2024
Next Review: January 17, 2025
Current Sub-processors: https://netjetlabs.com/sub-processors