Data Processing Addendum
GDPR Compliance Framework
This Data Processing Addendum ("DPA") forms part of the Master Platform Services Agreement between Deal Box, Inc. and users located in the European Economic Area, United Kingdom, or Switzerland.
1. Definitions and Interpretation
Terms used in this DPA have the meanings given in the GDPR. "Personal Data," "Data Subject," "Processing," and "Controller" shall have the meanings set forth in applicable data protection laws.
2. Processing of Personal Data
Deal Box processes personal data as a processor on behalf of controllers (issuers and users). Processing is limited to purposes specified in the service agreement and in accordance with documented instructions.
3. Data Subject Rights
Deal Box will assist controllers in responding to data subject requests regarding access, rectification, erasure, restriction, portability, and objection rights under GDPR.
4. Security Measures
Technical and organizational measures include encryption, access controls, security monitoring, incident response procedures, and regular security assessments.