Back to portzero.net

Data Processing Addendum

Effective date: July 24, 2026

This Data Processing Addendum ("DPA") describes how Port Zero ("Provider", "we", "us") processes personal data on behalf of a customer ("Customer") in connection with the Cloud Service, and supplements the Terms of Service and the Common Paper Cloud Service Agreement Standard Terms incorporated there. Where this DPA conflicts with the Terms on the handling of personal data, this DPA controls.

1. Roles: Controller and Processor

For personal data that Customer submits to the Cloud Service about its own end users, tunnel visitors, or reviewers (for example, guest comment names, review-record content, or data routed through Customer's tunnels), Customer is the controller and Provider is the processor, acting only on Customer's documented instructions as set out in the Terms and this DPA.

For personal data Provider collects directly about Customer and its authorized users to operate the relationship — account and billing data, security and abuse logs, and product analytics described in the Privacy PolicyProvider acts as an independent controller, since that processing is for Provider's own service-operation, billing, and security purposes rather than on Customer's instructions.

2. Subprocessors

Provider uses the subprocessors listed on the Subprocessors page to provide the Cloud Service. That page names each subprocessor, its purpose, and its processing location, and is the authoritative, current list — we update it before adding a new subprocessor or materially changing an existing one. Provider remains responsible for each subprocessor's performance of its data-processing obligations under a written agreement that imposes data protection terms no less protective than this DPA.

3. International Transfers

Personal data is processed in the United States, as described in the Privacy Policy. Where Customer's personal data originating in the European Economic Area or the United Kingdom is transferred to the United States, the parties rely on the European Commission's Standard Contractual Clauses (SCCs) (Module Two: Controller to Processor, or Module Three: Processor to Processor, as applicable), and, for transfers of UK personal data, the UK's International Data Transfer Addendum to those SCCs. Entering into this DPA and using the Cloud Service constitutes execution of the applicable SCCs module between the parties, incorporated by reference; a signed copy is available on request (see Contact).

4. Security Measures

Provider maintains administrative, technical, and physical safeguards designed to protect personal data, consistent with Section 5 of the Privacy Policy, including:

  • Encryption of data in transit (TLS) between Customer, the Cloud Service, and Provider's infrastructure
  • Access to production systems and Customer data limited to authorized personnel who need it to operate the Cloud Service
  • Logging and monitoring of production access and security-relevant events, retained per the schedule in the Privacy Policy
  • Point-in-time database backups, with a 7-day recovery window, so residual copies of deleted data are purged on the same schedule

5. Breach Notification

If Provider becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer's personal data processed under this DPA, Provider will notify Customer without undue delay after becoming aware, and will provide the information reasonably available to Provider to help Customer meet its own notification obligations to regulators or affected individuals. Provider will take reasonable steps to contain, investigate, and remediate the incident.

6. Assistance With Data Subject Requests

Taking into account the nature of the processing, Provider will assist Customer, by appropriate technical and organizational measures, in fulfilling Customer's obligation to respond to requests from data subjects exercising their rights (access, correction, deletion, restriction, portability, or objection). If Provider receives a request directly from one of Customer's data subjects concerning data Provider processes on Customer's behalf, Provider will direct the individual to Customer and notify Customer of the request without undue delay, unless prohibited by law.

7. How to Use This Addendum

This DPA applies automatically to Customer's use of the Cloud Service as of the effective date above, incorporated by reference into the Terms as described in Section 3 of the Terms. If your organization needs a countersigned copy for its own records, email legal@portzero.net and we will provide one.

8. Contact