Data Processing Addendum
GDPR / UK GDPR / CCPA / other US state privacy·Source: docs/legal/DPA.md
Draft — pending final legal review. Text marked {{PLACEHOLDER}}is filled in by counsel before publication. Content shown here is a good- faith draft + reflects HallPal's current operational posture, but is not a substitute for legal advice.
HallPal Data Processing Addendum
Suggested public route: /legal/dpa
Effective: {{EFFECTIVE_DATE}}
Version: {{DPA_VERSION}}
This Data Processing Addendum ("DPA") supplements the agreement (the "Agreement") between {{COMPANY_LEGAL_NAME}} ("HallPal", "Processor") and the customer identified in the Agreement (the "Customer", "Controller"). If the Agreement is our public Terms of Service, this DPA takes effect on the date Customer accepts those Terms. If the Agreement is a negotiated MSA, this DPA is the default DPA; a Customer-negotiated variation supersedes to the extent inconsistent.
1. Definitions
- "Personal Data" — any information relating to an identified or identifiable natural person that Customer submits to the Service, as defined by GDPR Article 4(1), UK GDPR, or an applicable US state privacy law.
- "Student Data" — Personal Data about K-12 students. Also covered by STUDENT_DATA_AGREEMENT.md; where the two documents overlap, the stricter commitment applies.
- "Data Subject" — the individual to whom Personal Data relates.
- "Processing" — any operation performed on Personal Data (collection, storage, use, disclosure, deletion, etc.).
- "Subprocessor" — a third-party engaged by HallPal to process Personal Data on Customer's behalf. Current list at SUBPROCESSORS.md.
- "Security Incident" — a breach of security leading to unauthorized access, acquisition, disclosure, alteration, or destruction of Personal Data.
- "SCCs" — the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.
2. Role + scope of processing
Customer is the Controller of Personal Data submitted to the Service. HallPal is the Processor + processes Personal Data solely:
- On documented instructions from Customer.
- To perform the Service as described in the Agreement.
- As required by applicable law (in which case HallPal will notify Customer beforehand unless legally prohibited).
Customer's use of the Service is deemed a documented instruction to process Personal Data as described in the Service documentation
- this DPA. Additional instructions require written agreement.
3. Details of processing
- Subject matter: provision of the Service to Customer + Customer's authorized users.
- Duration: for the duration of the Agreement, plus the retention + deletion windows in §7.
- Nature + purpose: as set out in PRIVACY.md §4
- Categories of Data Subjects: Customer's staff (school administrators, teachers, support staff), Customer's students, and visitors to Customer's Homebase kiosks.
- Categories of Personal Data: as enumerated in PRIVACY.md §3 and STUDENT_DATA_AGREEMENT.md §3.
- Special categories: HallPal does not process special-category Personal Data (health, biometric, race, religion, political opinions, etc.) by design. Customer must not submit special-category data.
4. HallPal obligations
HallPal will:
- Process Personal Data only per §2 above.
- Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations.
- Implement + maintain the technical + organizational security measures described in Annex II (attached at end of this DPA).
- Assist Customer, taking into account the nature of the processing
- information available to HallPal, in fulfilling Customer's obligations under applicable data protection law, including Customer's obligations under Articles 32–36 GDPR + equivalent provisions in other laws (security, breach notification, DPIA, regulator consultation).
- Notify Customer of Security Incidents per §8.
- Assist Customer with responding to Data Subject requests per §6.
- Delete or return Personal Data at the end of the Agreement per §7.
- Make available to Customer all information necessary to demonstrate compliance with this DPA per §9.
5. Subprocessors
Customer authorizes HallPal to engage the Subprocessors listed in SUBPROCESSORS.md as of the effective date of this DPA.
For any new Subprocessor:
- HallPal will provide Customer with at least 30 days' advance written notice (via update to SUBPROCESSORS.md + email to Customer's designated notification contact).
- Customer may reasonably object within the 30-day window. If HallPal + Customer cannot resolve the objection within 30 days of the objection, Customer may terminate the Agreement without penalty as to the affected services, + HallPal will proceed to deletion per §7.
HallPal remains fully liable to Customer for Subprocessor performance. HallPal has flowed down data-protection terms substantively equivalent to this DPA to each Subprocessor.
Customer can subscribe to Subprocessor-change notifications by emailing privacy@hallpal.divz.io with the subject line "Subscribe: Subprocessor updates".
6. Data Subject rights
HallPal will assist Customer in responding to Data Subject requests for access, correction, deletion, restriction, portability, or objection under applicable law.
Where a Data Subject contacts HallPal directly with such a request, HallPal will (unless legally required to respond directly):
- Refer the Data Subject to Customer (the correct point of contact under the "school as data custodian" model — see STUDENT_DATA_AGREEMENT.md §7).
- Notify Customer of the request within 5 business days.
- Not otherwise respond to the request except at Customer's documented direction.
7. Deletion + return
Within {{POST_TERM_DELETION_DAYS}} days of the end of the Agreement, HallPal will (at Customer's option):
- Return Personal Data to Customer in a machine-readable format
- delete all copies; or
- Delete all Personal Data.
In either case:
- Personal Data is removed from live systems within {{POST_TERM_DELETION_DAYS}} days.
- Personal Data is purged from backups on the next scheduled backup-rotation cycle (up to {{BACKUP_RETENTION_DAYS}} additional days).
- HallPal will provide a written attestation of deletion within 15 days of completion. Template: CERTIFICATE_OF_DESTRUCTION.md.
Legal-hold or compulsory-retention obligations are the sole exception
- apply only to the minimum data required.
8. Security Incidents
HallPal will notify Customer of a confirmed Security Incident affecting Customer's Personal Data:
- Without undue delay and in no event more than 72 hours of confirmed detection, per Article 33 GDPR.
- Notification will include (to the extent available at time of notice): the nature of the incident, the categories + approximate number of Data Subjects + records concerned, the likely consequences, the measures taken or proposed to address it, and the contact point for follow-up.
HallPal will provide updates as new information becomes available + a written incident report within 30 days of initial notice.
Notification of a Security Incident does not constitute admission of fault or liability. HallPal + Customer will cooperate in the investigation + remediation.
9. Audits + information
Customer may request evidence of HallPal's compliance with this DPA once per calendar year (more frequently after a Security Incident or where required by supervisory authority).
HallPal satisfies the audit obligation by providing:
- The current SOC 2 Type II report (when available), under NDA.
- A completed security-questionnaire response (e.g. CAIQ or Customer's own) within 30 business days.
- Written evidence of key controls on Customer's reasonable request.
On-site or on-infrastructure audits are available for large enterprise customers by written agreement + at Customer's expense, scheduled at least 60 days in advance + subject to reasonable scope + confidentiality restrictions.
10. International transfers
Where Customer transfers Personal Data of EU or UK Data Subjects to HallPal in a country not subject to an adequacy decision, the transfer relies on:
- For EU-outbound transfers: the 2021 EU SCCs, Module 2 (Controller-to-Processor), annexed at the end of this DPA. The parties are deemed to have signed the SCCs on the effective date of this DPA.
- For UK-outbound transfers: the UK International Data Transfer Addendum (IDTA) to the EU SCCs, published by the UK ICO in February 2022, incorporated by reference.
- For Swiss-outbound transfers: the SCCs with the Swiss Federal Data Protection + Information Commissioner (FDPIC) as the competent supervisory authority.
The parties will complete Annex I (parties + processing details) + Annex II (technical + organizational measures) at the end of this DPA. Annex III (subprocessors) is incorporated by reference from SUBPROCESSORS.md.
Customer represents that Customer has completed a transfer impact assessment (TIA) or equivalent + is satisfied with the transfer. HallPal will support any TIA-refresh Customer conducts.
11. US state privacy laws
For Personal Data subject to the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), Colorado Privacy Act, Connecticut Data Privacy Act, Virginia Consumer Data Protection Act, Utah Consumer Privacy Act, and other US state comprehensive privacy laws:
HallPal is a Service Provider / Processor (not a Third Party or Controller), and:
- Will process Personal Data only for the business purposes specified in the Agreement.
- Will not sell or share Personal Data as those terms are defined by CCPA/CPRA.
- Will not retain, use, or disclose Personal Data for any purpose other than the specific purpose of performing the Service, nor outside the direct business relationship between HallPal + Customer.
- Will not combine Personal Data with data from other sources except for detecting security incidents or complying with law.
- Certifies that it understands + will comply with these restrictions.
The certifications in this section satisfy the "written contract" requirement of CCPA § 1798.140(ag)(1) + Cal. Civ. Code § 1798.100(d).
12. Conflict resolution + hierarchy
In the event of a conflict:
- A district- or customer-signed contract exhibit (SDPC NDPA, negotiated MSA rider, etc.) prevails over this DPA.
- This DPA prevails over the Terms of Service as to data-protection matters.
- This DPA prevails over the Privacy Policy as to contractual obligations to Customer; the Privacy Policy prevails as to representations made to Data Subjects.
- The 2021 EU SCCs (Annex to this DPA) prevail over any conflicting provision of this DPA + the Agreement as to processing subject to the SCCs.
- State-specific requirements in STATE_PRIVACY_RIDERS.md prevail over this DPA where applicable.
13. General
- Term. This DPA is effective on the date Customer accepts it or the Agreement takes effect, whichever is later. It continues until the Agreement ends + all Personal Data is deleted or returned per §7.
- Governing law. As set out in the Agreement.
- Amendments. Material amendments require written agreement. Non-material amendments (typos, clarifications, subprocessor list updates) can be made by HallPal on notice.
Contact
Privacy + DPA questions: privacy@hallpal.divz.io Legal + contracting: legal@hallpal.divz.io Data Protection Officer / EU Representative: {{DPO_NAME_AND_CONTACT_OR_TBD}}
Annex I — Parties + processing details
Controller: the Customer identified in the Agreement. Processor: {{COMPANY_LEGAL_NAME}}, {{COMPANY_ADDRESS}}. Contact for Processor: privacy@hallpal.divz.io.
Categories of Data Subjects: as set out in §3 above + STUDENT_DATA_AGREEMENT.md §3. Categories of Personal Data: as set out in §3 above + STUDENT_DATA_AGREEMENT.md §3. Sensitive Data: none processed. Frequency of transfer: continuous, on Customer instruction via the Service. Nature of processing: as set out in §3 above. Retention period: as set out in §7 above + STUDENT_DATA_AGREEMENT.md §6. Subprocessors: as set out in SUBPROCESSORS.md.
Annex II — Technical + organizational security measures
Detailed in PRIVACY.md §12 + STUDENT_DATA_AGREEMENT.md §8. Summary:
- Encryption in transit (TLS 1.2+) + at rest (AES-256).
- HSTS with 1-year preload; Content-Security-Policy on every route.
- Row-Level Security at the DB layer scoping all queries to the Customer's Personal Data.
- Every mutation writes an immutable audit-log entry.
- Rate limiting on every sensitive route.
- Automatic session expiration after 120 minutes of inactivity.
- Personnel access to production systems limited to a small set of authorized engineers; MFA required.
- Vulnerability scanning + dependency-audit on every merge.
- Regular automated + manual security + accessibility testing.
- Subprocessors are security-reviewed before onboarding + reviewed at least annually.
Annex III — Subprocessors
Incorporated by reference from SUBPROCESSORS.md.
Annex IV — 2021 EU SCCs (Module 2)
The parties incorporate by reference the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, Module 2 (Controller-to-Processor), available at:
https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_en
The parties select the following optional clauses:
- Clause 7 (Docking clause): applies.
- Clause 9 (option 2): general written authorization for subprocessors, with 30 days' notice.
- Clause 11 (independent dispute resolution): does not apply.
- Clause 17 (governing law): the law of {{SCC_GOVERNING_LAW_MS}}.
- Clause 18 (choice of forum + jurisdiction): {{SCC_FORUM_JURISDICTION_MS}}.
The information in Annexes I–III of this DPA is deemed the information required by the SCCs' own Annexes I–III.
For UK-outbound transfers, the UK International Data Transfer Addendum to the EU SCCs, dated 21 March 2022 + issued by the UK Information Commissioner, is incorporated. Tables 1–4 of the Addendum are completed with the values in Annexes I–III of this DPA.