1. Scope and incorporation
This Data Processing Addendum ("DPA") is incorporated into the Terms of Service or other agreement governing Asuruas when Lancaster Solutions LLC processes Customer Personal Data as a processor, subprocessor, contractor, or service provider for Customer. It does not apply to information for which Lancaster Solutions LLC independently determines the purposes and means of processing, which is governed by the Privacy Policy.
2. Definitions
"Customer Personal Data" means personal data, personal information, or a similar protected category contained in Customer Data and processed by Asuruas on Customer's behalf. "Data Protection Law" means privacy, data-protection, and breach-notification law applicable to that processing. The terms controller, processor, business, consumer, service provider, contractor, sell, and share have the meanings given by applicable law.
3. Roles and instructions
Customer is the controller or business and Lancaster Solutions LLC is the processor or service provider for Customer Personal Data, unless a signed order states another lawful role. We will process Customer Personal Data only on Customer's documented instructions, including the agreement, configured service use, support requests, and lawful written instructions, unless law requires processing. We will notify Customer of a legal requirement before processing unless prohibited.
Customer is responsible for the lawfulness, accuracy, notices, consents, instructions, scope, and rights associated with Customer Personal Data.
4. Processing details
- Subject matter: hosted website-audit, evidence, reporting, remediation, collaboration, support, billing-adjacent, and security operations.
- Duration: the agreement term plus the documented return, deletion, backup, legal-hold, and retention period.
- Nature and purpose: collect, transmit, crawl, render, organize, analyze, store, secure, back up, retrieve, report, export, delete, and support Customer-authorized data.
- Data subjects: Customer users, employees, contractors, clients, website visitors, content authors, business contacts, and other people represented in authorized website content or Customer submissions.
- Data types: identity and contact data, account and role data, website content and metadata, URLs, IP and device data, support communications, audit evidence, images and screenshots, identifiers, and other Customer-selected data. Special-category or highly sensitive data is not intended unless expressly agreed.
5. Confidentiality and personnel
We will limit access to personnel and contractors who need it to provide or secure the service and who are subject to appropriate confidentiality obligations. We will provide relevant privacy and security guidance and apply access controls appropriate to role and risk.
6. Security measures
- Access controls, role separation, account verification, password hashing, MFA capability, and session controls.
- Encrypted transport for public traffic and protected handling of secrets and credentials.
- Tenant context controls, database authorization, audit logging, and controlled administrative access.
- Backups, integrity evidence, deletion receipts, monitoring, vulnerability management, and incident procedures.
- Data minimization, bounded crawling, file and response limits, and controlled subprocessors.
- Regular testing and qualification appropriate to the release and deployment environment.
7. Subprocessors
Customer gives general written authorization for the subprocessors in the published register. We will impose data-protection obligations appropriate to the service and remain responsible for our obligations under this DPA.
For a planned material addition or replacement, we will provide prior notice through the public register, account contact, or another reasonable channel when practicable. Customer may object within 15 days on reasonable data-protection grounds. The parties will work in good faith on a reasonable alternative. If no reasonable alternative exists, Customer may discontinue the affected feature or terminate the affected service before the new subprocessor begins processing, and the Refund Policy will apply unless mandatory law requires otherwise. Urgent security or continuity changes may occur sooner with notice as soon as reasonably practicable.
8. Data-subject requests
Taking into account the nature of processing, we will provide reasonable assistance for Customer to respond to verified access, correction, deletion, restriction, portability, objection, or appeal requests required by Data Protection Law. If we receive a request concerning Customer Personal Data, we will direct the requester to Customer unless law requires us to respond directly.
9. Security incidents
We will notify Customer without undue delay after confirming a breach of security that affects Customer Personal Data processed under this DPA. Notice will include available information reasonably needed for Customer's legal duties and will be supplemented as material facts become available. Notification is not an admission of fault or liability.
Customer is responsible for determining whether notice to individuals, regulators, or others is required, except for notices we are independently required to provide.
10. Assessments, audits, and compliance information
We will make reasonably available information needed to demonstrate compliance with this DPA, such as relevant policies, subprocessor information, security summaries, and qualification evidence. Customer may request one reasonable remote assessment per year, and additional review after a confirmed material incident. Audits must protect other customers, security, privilege, and confidential information, avoid production disruption, and use existing reports before demanding custom inspection. Customer pays its audit costs unless a material breach by us is established.
11. Return and deletion
At Customer's verified request or termination, we will provide available export functions and delete Customer Personal Data according to the Data Retention Policy, unless law requires retention. Deletion may be delayed by a documented legal hold, active dispute, security investigation, or protected backup cycle. Data retained for those limited purposes remains protected and is not used for unrelated purposes.
12. International transfers
If Customer Personal Data protected by EEA or UK law is transferred to a country without an applicable adequacy decision, the parties incorporate the applicable controller-to-processor or processor-to-processor modules of the European Commission Standard Contractual Clauses adopted by Decision 2021/914, together with the UK addendum where required. The Customer is data exporter and Lancaster Solutions LLC is data importer unless the facts require another module. The governing member-state law and supervisory authority will be selected based on Customer's establishment or affected individuals as required by the clauses.
The parties will provide information reasonably required for a transfer assessment and implement supplementary safeguards where required and reasonably available.
13. U.S. state privacy terms
Where Lancaster Solutions LLC is a service provider, contractor, or processor under applicable U.S. state law, it will not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship or specified business purposes except as permitted by law, or combine it with personal information received from another source except as permitted. We will notify Customer if we determine we can no longer meet an applicable obligation and allow reasonable steps to stop and remediate unauthorized use.
14. Government requests
Unless prohibited, we will notify Customer of a legally binding request for Customer Personal Data and will review the request for facial validity. We will disclose only data legally required and may challenge an overbroad request where reasonable.
15. Liability and order of precedence
The liability limits in the governing agreement apply to this DPA except where Data Protection Law prohibits limitation. If this DPA conflicts with the governing agreement on data protection, this DPA controls. The unmodified Standard Contractual Clauses control over conflicting terms for transfers governed by those clauses.
16. Contact
DPA and privacy contacts: clancaster@lancastersolutionsllc.com. Effective August 9, 2026.