Trust Center / Legal
Data Processing Agreement
This DPA covers personal data isotope13 LLC ("we") processes on behalf of a customer ("you"). It joins your agreement once both of us sign. Where they conflict on personal data, this DPA wins.
Scope (Annex I)
- Exporter: you, as controller, or as processor for your own customers
- Importer: isotope13 LLC, 109 Amber Ct, Carrboro, NC 27510, USA, as processor or subprocessor. Contact: Thomas Stromberg, CEO, trust(@)isotope13.io
- Subject and purpose: signing in your team and answering your API requests
- Duration: your agreement's term, plus deletion below
- Frequency: continuous
- Whose: your team members, and anyone who calls our API for you
- Data: OAuth subject identifier and username or email; IP address and user agent, never logged or passed on
- Sensitive data: none
- Retention: as in our Privacy Policy
- Supervisory authority: the exporter's, under Clause 13 of the Standard Contractual Clauses
- Not covered: billing, uploads, and verdicts. We control them under our Privacy Policy. Uploads and verdicts are public, so don't upload personal data.
Our Commitments
- We process only on your documented instructions: this agreement and your use of the service. We tell you if an instruction breaks the law.
- Everyone with access is bound to confidentiality.
- Security follows our Security Measures.
- You authorize our Approved Subprocessors. We notify you 30 days before adding one. Object, and if we can't resolve it, you may terminate for a refund of prepaid fees. Our subprocessors are bound to equivalent terms, and we remain liable for them.
- We notify you of a breach, as our Incident Response Plan defines it, within 48 hours of discovery, and help with your obligations.
- We help with data subject requests, impact assessments, and regulator consultations.
- We tell you about any government request for your data, unless the law forbids it.
- Under the CCPA, we are your service provider: we won't sell or share your personal data, or use it outside our agreement.
- When the agreement ends, we delete your personal data within 30 days, unless law requires otherwise, and confirm on request.
- For audits, we provide our SOC 2 report once available, or answer a reasonable security questionnaire. If that isn't enough, you or your auditor may audit us once a year, at your cost, with 30 days' notice.
Transfers
We process data in the US, after the nearest Cloudflare edge cache handles each request. Transfers from the EEA use the EU Standard Contractual Clauses (Module 2, or Module 3 where you are a processor), incorporated by reference, with the UK Addendum and Swiss amendments as needed: general subprocessor authorization as above, Irish law and courts. Their annexes are the Scope above, our Security Measures, and our Approved Subprocessors.
Liability
As limited by your agreement.