Data Processing Addendum
Enterprise data protection terms for customer personal data processed by EmailGuard as a processor or service provider.
Overview
This Data Processing Addendum ("DPA") describes example terms for how Baker Assets LLC processes customer personal data on behalf of enterprise customers using EmailGuard.
This DPA is template language for a SaaS deployment. It is not legal advice and should be reviewed by counsel before use. A signed customer agreement may replace or modify these terms.
Applicability
This DPA applies when:
- A customer uses EmailGuard to submit, store, transmit, or otherwise process personal data.
- We process that personal data on the customer's behalf.
- Applicable data protection law requires processor, service provider, or similar contractual terms.
This DPA does not apply to account, billing, marketing, website, support, or business relationship data that we process as a controller, as described in our Privacy Policy.
Definitions
- Customer Personal Data means personal data contained in Customer Content that we process on behalf of the customer through the service.
- Customer means the organization or individual that controls the workspace or account.
- Data Protection Laws means privacy, security, and data protection laws applicable to the processing.
- Subprocessor means a third party engaged by us to process Customer Personal Data.
Roles of the parties
The customer is the controller, business, or equivalent decision-maker for Customer Personal Data. Baker Assets LLC is the processor, service provider, or equivalent service provider that processes Customer Personal Data according to customer instructions.
Processing instructions
We will process Customer Personal Data only to:
- Provide, secure, support, maintain, and improve the service.
- Follow documented customer instructions, including product configuration and API use.
- Comply with applicable law.
- Enforce the agreement and protect the service, customers, and third parties.
If we believe an instruction violates Data Protection Laws, we will notify the customer unless prohibited by law.
Customer responsibilities
The customer is responsible for:
- Providing required notices and obtaining required rights, consents, and lawful bases.
- Ensuring Customer Personal Data is appropriate for the service.
- Configuring users, roles, permissions, integrations, retention settings, and security controls.
- Responding to data subject requests unless the product or agreement assigns a task to us.
- Avoiding prohibited or regulated data unless expressly permitted in writing.
Confidentiality
Personnel authorized to process Customer Personal Data must be subject to confidentiality obligations or professional confidentiality duties.
Security measures
We will maintain reasonable technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures may include access controls, authentication, encryption in transit, logging, monitoring, backup procedures, vulnerability management, and incident response.
More detail is available in our Security documentation.
Subprocessors
The customer authorizes us to engage subprocessors to provide the service. Current and likely subprocessors are listed at Subprocessors.
We will impose data protection obligations on subprocessors that are materially consistent with this DPA. We remain responsible for subprocessors' performance of their data protection obligations to the extent required by applicable law or agreement.
Subprocessor changes
For enterprise customers with notice rights, we will provide notice of material new subprocessors through the method stated in the agreement or by updating the Subprocessors page. Customers may object on reasonable data protection grounds within the applicable notice period.
Assistance
Taking into account the nature of processing and information available to us, we will provide reasonable assistance for:
- Data subject requests.
- Security and data protection impact assessments.
- Regulatory consultations.
- Customer audits and compliance inquiries.
- Security incident investigation and notification.
Assistance may be subject to reasonable fees if it requires substantial effort outside standard product functionality or support.
Security incidents
We will notify affected customers without undue delay after confirming a security incident involving Customer Personal Data, unless prohibited by law. Notice may include the nature of the incident, affected data, mitigation steps, and recommended customer actions when available.
Notification is not an admission of fault or liability.
International transfers
Customer Personal Data may be processed in the United States and other countries where we or our subprocessors operate. Where required, the parties will use appropriate transfer mechanisms such as standard contractual clauses, data transfer addenda, or other lawful safeguards.
Deletion and return
Upon termination or expiration of the service, we will delete or return Customer Personal Data according to the agreement, product functionality, backup practices, and applicable law. Residual copies may remain in backups, logs, or archival systems for a limited period until overwritten or deleted according to retention schedules.
Audits
Upon reasonable request, we may provide security documentation, compliance summaries, subprocessor information, or responses to questionnaires. Onsite audits are subject to prior written agreement, confidentiality, scope limitations, and measures to protect other customers and systems.
Contact
Questions about data processing can be sent to [email protected].
Looking for another policy?
Browse privacy, security, subprocessors, and other legal documents.