Data Processing Addendum (DPA)
Effective Date: January, 2026
This Data Processing Addendum ("Addendum") forms part of the Agreement between the Client ("Controller") and Urban Digital Studio, LLC ("Processor") and sets out the terms governing the processing of personal data in connection with the services provided.
1 Definitions
- Controller: The entity that determines the purposes and means of processing personal data.
- Processor: Urban Digital Studio, LLC, which processes personal data on behalf of the Controller.
- Personal Data: Any information relating to an identified or identifiable individual.
- Processing: Any operation performed on Personal Data such as collection, storage, use, disclosure, or destruction.
2 Subject Matter and Duration of Processing
- The Processor will process Personal Data as necessary to provide the contracted services, including reputation management and AI chatbot platforms.
- Processing will continue for the duration of the services or until otherwise instructed by the Controller.
3 Nature and Purpose of Processing
- Processing includes collecting, storing, analyzing, and transmitting Personal Data to deliver and improve services.
- The Processor will only process data as instructed by the Controller and in compliance with applicable data protection laws.
4 Types of Personal Data
- Personal identifiers (e.g., names, contact information)
- Health-related information where applicable (e.g., data related to healthcare clients)
- Usage data and interaction data collected via services
5 Obligations of the Processor
- Implement appropriate technical and organizational security measures to protect Personal Data, considering the sensitivity of healthcare data.
- Ensure confidentiality by restricting data access to authorized personnel.
- Notify the Controller promptly of any data breaches affecting Personal Data.
- Assist the Controller in responding to data subject requests and regulatory inquiries.
- Engage subprocessors only with prior notice to the Controller and ensure they adhere to similar data protection obligations.
- Delete or return Personal Data after the end of service, unless required otherwise by law.
6 Obligations of the Controller
- Provide clear, lawful instructions regarding Personal Data processing.
- Ensure that data subjects have been properly informed and consented where required.
- Comply with all applicable data protection laws.
7 Subprocessors
- The Processor may use third-party subprocessors (e.g., AWS, payment processors, API providers, etc).
- The Processor will inform the Controller of any intended changes concerning subprocessors.
8 Data Subject Rights
The Processor will assist the Controller in fulfilling obligations related to data subject rights such as access, correction, deletion, and portability.
9 Data Breach Notification
The Processor will notify the Controller without undue delay upon becoming aware of a Personal Data breach.
10 Audit and Inspection
The Controller may audit Processor compliance upon reasonable notice and during regular business hours, subject to confidentiality.
11 Governing Law and Jurisdiction
This Addendum shall be governed by the laws specified in the main service agreement.