Data Processing Addendum (DPA)
1. Scope, Purpose and Parties
This Data Processing Addendum ("DPA") supplements the Terms of Service between Customer and DragonVerse Media Inc. ("Evidlane").
This DPA applies to the processing of personal data included in Customer Content during the provision of the Evidlane food supplier approval and evidence tracking software.
Determines the purposes, scope of evidence requests, and document retention policies for its food suppliers.
Processes data exclusively on behalf of and pursuant to documented instructions from Customer.
2. Processing Instructions & Data Categories
Evidlane shall process personal data solely in accordance with Customer's documented instructions, including with respect to international transfers, unless required to do so by applicable law.
Categories of Data Subjects & Data Types
- Customer QA Personnel: Names, work emails, session identifiers, review signatures, approval audit timestamps.
- Supplier Contacts: Vendor names, representative emails, phone numbers, facility addresses.
- Audit & Certificate Signatories: Auditor names, certification body representatives, laboratory technician signatures on Certificates of Analysis (COAs).
3. Technical and Organizational Security Measures (TOMs)
Evidlane implements and maintains industry-leading technical and organizational measures to ensure a level of security appropriate to the risk:
organizationId foreign key filters and server-side RBAC.4. Authorized Subprocessor Management
Customer grants general authorization for Evidlane to engage the infrastructure subprocessors listed in our Privacy Policy (Cloudflare R2, Neon Postgres, Brevo, Stripe, Vercel).
Evidlane shall give Customer at least thirty (30) days prior written notice before onboarding any new subprocessor. Customer may object to a new subprocessor on reasonable data protection grounds within 14 days of notice.
5. Security Incident & Breach Notification (72-Hour SLA)
In the event of a confirmed Security Incident involving Customer Personal Data, Evidlane shall:
- Notify Customer without undue delay and in any event within seventy-two (72) hours of becoming aware of the incident.
- Provide details regarding the nature of the breach, affected records, and remediation measures taken.
- Cooperate fully with Customer in fulfilling statutory notification obligations to data protection authorities and affected data subjects.
6. Assistance with Data Subject Requests
Evidlane provides self-service features in the dashboard allowing Customers to access, rectify, export, and delete supplier records. If a data subject contacts Evidlane directly, Evidlane will promptly forward the request to Customer without taking direct action, unless authorized by Customer.
7. Deletion and Return of Customer Personal Data
Upon termination of the underlying subscription agreement, Customer may export a complete ZIP audit archive of all documents and metadata. Following a 30-day export transition period, Evidlane will permanently delete all copies of Customer Content from production databases and object storage, except where retention is required by applicable statutory law.
8. Counterparts & Execution Inquiries
This DPA is automatically incorporated into the Evidlane Terms of Service. Enterprise customers requiring an executed PDF version with Standard Contractual Clauses (SCCs) may request one by emailing our compliance team:
DPA Execution & Compliance Office
DragonVerse Media Inc. · Attn: Privacy & Contracts Counsel
Email: dpa@getevidlane.com / defhnhqf@gmail.com
Website: https://getevidlane.com