Introduction
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Raindex, Inc. ("Raindex") and the customer ("Customer") and governs the processing of personal data by Raindex on behalf of the Customer in connection with the Service. This DPA is intended to address applicable data protection requirements where Raindex acts as a data processor.
Roles and Responsibilities
Customer as Data Controller
The Customer acts as the data controller and determines the purposes and means of processing personal data. The Customer is responsible for ensuring that personal data is collected and processed in accordance with applicable data protection laws and that appropriate legal bases exist for processing.
Raindex as Data Processor
Raindex acts as a data processor and processes personal data only on documented instructions from the Customer, as necessary to provide the Service. Raindex does not determine the purposes or means of processing Customer personal data.
Data Handling Responsibilities
Raindex's responsibilities as a data processor include:
- processing personal data solely in accordance with Customer instructions and this DPA;
- implementing reasonable technical and organizational measures to protect personal data;
- maintaining the confidentiality of personal data;
- notifying the Customer of personal data breaches without undue delay, where required by applicable law;
- assisting the Customer, where applicable, with data subject rights requests; and
- returning or deleting personal data upon termination of the applicable agreement, subject to legal retention obligations.
Subprocessors
Raindex may engage subprocessors to assist in providing the Service, such as providers of cloud infrastructure, authentication services, database and storage services, and, where applicable, AI/ML processing services. Raindex remains responsible for the performance of its subprocessors in accordance with this DPA.
Raindex will maintain a general description of subprocessors and will provide notice of material changes to subprocessors through reasonable means.
Data Transfers
Personal data may be processed or stored in jurisdictions outside of the Customer's location. Where required by applicable law, Raindex will implement appropriate safeguards to support such transfers, such as contractual protections or other lawful transfer mechanisms.
Security Measures
Raindex implements reasonable administrative, technical, and organizational security measures designed to protect personal data against unauthorized or unlawful processing, loss, destruction, or damage. Additional details regarding security practices are described on the Raindex Security page.
Audit Rights
Upon reasonable request and subject to confidentiality obligations, Raindex will provide information reasonably necessary to demonstrate compliance with this DPA. Audit rights, if any, will be limited to what is reasonable and proportionate and may be subject to mutually agreed scope and timing.
Data Retention and Deletion
Personal data will be retained only for as long as necessary to provide the Service or as required by law. Upon termination of the applicable agreement, Raindex will delete or return personal data in accordance with the Data Retention Policy, unless retention is required by law.
Contact
For questions about this Data Processing Addendum, please contact us at privacy@raindex.ai