NEWFSMA 204 & SQF Edition 9 Evidence Templates are now live.Run free spreadsheet audit →
Home/Legal/Data Processing Addendum
ENTERPRISE COMPLIANCE STANDARD

Data Processing Addendum (DPA)

Effective Date: September 5, 2026 Processor: DragonVerse Media Inc. / Evidlane Framework: GDPR Article 28 & CCPA Compliant
DPA Sections

1. Scope, Purpose and Parties

This Data Processing Addendum ("DPA") supplements the Terms of Service between Customer and DragonVerse Media Inc. ("Evidlane").

This DPA applies to the processing of personal data included in Customer Content during the provision of the Evidlane food supplier approval and evidence tracking software.

Customer (Data Controller)

Determines the purposes, scope of evidence requests, and document retention policies for its food suppliers.

DragonVerse Media Inc. (Data Processor)

Processes data exclusively on behalf of and pursuant to documented instructions from Customer.

2. Processing Instructions & Data Categories

Evidlane shall process personal data solely in accordance with Customer's documented instructions, including with respect to international transfers, unless required to do so by applicable law.

Categories of Data Subjects & Data Types

  • Customer QA Personnel: Names, work emails, session identifiers, review signatures, approval audit timestamps.
  • Supplier Contacts: Vendor names, representative emails, phone numbers, facility addresses.
  • Audit & Certificate Signatories: Auditor names, certification body representatives, laboratory technician signatures on Certificates of Analysis (COAs).

3. Technical and Organizational Security Measures (TOMs)

Evidlane implements and maintains industry-leading technical and organizational measures to ensure a level of security appropriate to the risk:

• Multi-Tenant Isolation & Access Control:
Database records are forcefully segregated using strict organizationId foreign key filters and server-side RBAC.
• Encryption at Rest & In Transit:
TLS 1.3 encryption for all external web traffic and API routes. AES-256 encryption at rest for Cloudflare R2 object storage and Neon PostgreSQL databases.
• Ephemeral Ingestion & Presigned URLs:
Vendor upload tokens are 32-byte cryptographic random strings with 7-day TTLs. Download URLs use short-lived presigned credentials (300-second TTL).
• Asynchronous Antivirus Quarantine:
Integrated ClamAV scanning checks all vendor uploads before QA preview to prevent supply chain payload execution.

4. Authorized Subprocessor Management

Customer grants general authorization for Evidlane to engage the infrastructure subprocessors listed in our Privacy Policy (Cloudflare R2, Neon Postgres, Brevo, Stripe, Vercel).

Evidlane shall give Customer at least thirty (30) days prior written notice before onboarding any new subprocessor. Customer may object to a new subprocessor on reasonable data protection grounds within 14 days of notice.

5. Security Incident & Breach Notification (72-Hour SLA)

In the event of a confirmed Security Incident involving Customer Personal Data, Evidlane shall:

  • Notify Customer without undue delay and in any event within seventy-two (72) hours of becoming aware of the incident.
  • Provide details regarding the nature of the breach, affected records, and remediation measures taken.
  • Cooperate fully with Customer in fulfilling statutory notification obligations to data protection authorities and affected data subjects.

6. Assistance with Data Subject Requests

Evidlane provides self-service features in the dashboard allowing Customers to access, rectify, export, and delete supplier records. If a data subject contacts Evidlane directly, Evidlane will promptly forward the request to Customer without taking direct action, unless authorized by Customer.

7. Deletion and Return of Customer Personal Data

Upon termination of the underlying subscription agreement, Customer may export a complete ZIP audit archive of all documents and metadata. Following a 30-day export transition period, Evidlane will permanently delete all copies of Customer Content from production databases and object storage, except where retention is required by applicable statutory law.

8. Counterparts & Execution Inquiries

This DPA is automatically incorporated into the Evidlane Terms of Service. Enterprise customers requiring an executed PDF version with Standard Contractual Clauses (SCCs) may request one by emailing our compliance team:

DPA Execution & Compliance Office

DragonVerse Media Inc. · Attn: Privacy & Contracts Counsel
Email: dpa@getevidlane.com / defhnhqf@gmail.com
Website: https://getevidlane.com