This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Customer") and Media Yard LLC ("Shorward"). It applies when Shorward processes Customer Personal Data as a processor under the UK GDPR, the EU GDPR, the Swiss FADP, the CCPA/CPRA or similar laws ("Data Protection Laws"). If you need a countersigned copy, email [email protected].
1. Definitions
"Customer Personal Data" means personal data in content the Customer uploads to the service, or in scan results for the Customer's domains, that Shorward processes on the Customer's behalf. "Controller", "processor", "data subject", "personal data breach" and "processing" have the meanings given in the Data Protection Laws.
2. Roles and instructions
The Customer is the controller and Shorward is the processor. Shorward processes Customer Personal Data only on the Customer's documented instructions, which are the Terms, this DPA and the Customer's use of the service, unless the law requires otherwise. If so, Shorward will tell the Customer first, unless the law forbids it. Shorward will tell the Customer if it believes an instruction breaks Data Protection Laws.
3. Details of processing
| Subject matter | Post-quantum readiness scanning, evidence review and reporting |
|---|---|
| Duration | The term of the Terms, plus the deletion period in section 10 |
| Nature and purpose | Storage, analysis (including by AI), report generation and retrieval, solely to provide the service |
| Data subjects | The Customer's staff and contractors named in uploaded evidence or certificates |
| Personal data | Names, work email addresses, job roles and system identifiers appearing in uploaded files or certificates |
| Special categories | None intended. The Customer must not upload special category data |
4. Confidentiality
Shorward ensures that anyone authorized to process Customer Personal Data is bound by confidentiality.
5. Security
Shorward maintains appropriate technical and organizational measures, described on Security. They include encryption in transit and at rest, least-privilege access, logging, and secure deletion.
6. Subprocessors
The Customer gives general authorization for the subprocessors listed on Subprocessors. Shorward will give at least 30 days' notice of a new subprocessor, by email or through a subscription on that page. The Customer may object on reasonable data protection grounds. If the parties can't resolve it, the Customer may terminate the affected service and receive a refund of prepaid fees for it. Shorward imposes data protection terms on each subprocessor that are no less protective than this DPA, and remains liable for its subprocessors.
7. Data subject requests
Shorward will help the Customer respond to data subject requests, taking into account the nature of the processing. It will pass on any request it receives directly without responding to it, unless authorized.
8. Personal data breaches
Shorward will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include the information available to help the Customer meet its own obligations.
9. Assistance
Shorward will reasonably assist the Customer with data protection impact assessments and prior consultations, in relation to Shorward's processing.
10. Deletion and return
When the service ends, Shorward will delete Customer Personal Data within 30 days, unless the law requires it to keep some. Before then, the Customer can export its reports and uploaded files.
11. Audits
Shorward will make available the information reasonably needed to show compliance with this DPA, including written answers to security questionnaires once a year. Where that's not enough, or a regulator requires it, the Customer may carry out an audit on 30 days' notice, during business hours, at its own cost, and under confidentiality.
12. International transfers
Where Customer Personal Data is transferred from the EEA, UK or Switzerland to a country without an adequacy decision, the parties incorporate the Standard Contractual Clauses (Commission Decision 2021/914), Module 2 (controller to processor), with the UK Addendum and Swiss adaptations as applicable. For the SCCs: clause 7 does not apply; clause 9 option 2 applies with the notice period in section 6; clause 11's optional language does not apply; clause 17 is governed by Irish law; clause 18 names the courts of Ireland; Annex I is section 3 of this DPA; Annex II is the Security page; and Annex III is the Subprocessors list.
13. US state laws
Where the CCPA/CPRA or similar laws apply, Shorward is a service provider. It won't sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship, or combine it with other data except as those laws allow.
14. Liability and precedence
Each party's liability under this DPA is subject to the limits in the Terms, except where Data Protection Laws or the SCCs don't allow it. If this DPA conflicts with the Terms, this DPA wins. If it conflicts with the SCCs, the SCCs win.