Data Processing Addendum
Effective 29 July 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Controller”) and Terra Tester (“Processor”) for the TerraTester service, and applies to the extent the Processor processes personal data on the Controller's behalf. Terms such as “personal data”, “processing”, “data subject” and “personal data breach” have the meanings given in applicable data-protection law.
1. Subject matter and duration
The Processor processes personal data contained in Customer Data to provide the Service, for the duration of the agreement plus any agreed export and deletion window.
2. Nature and purpose
Hosting, storage and processing of laboratory records so the Controller can operate its laboratory workflow — jobs, samples, specimens, test results, conformity assessments, certificates and user administration.
3. Personal data and data subjects
Categories of personal data: the names, email addresses and roles of the Controller's users; and any personal data the Controller chooses to include in laboratory records, such as client contact details. Categories of data subjects: the Controller's personnel and the contacts of its clients. The parties do not intend for special-category data to be processed.
4. Processor obligations
The Processor shall:
- process personal data only on the Controller's documented instructions, including as set out in the agreement and through use of the Service, unless required to do otherwise by law (in which case it will inform the Controller unless legally prohibited);
- ensure that persons authorised to process personal data are bound by confidentiality;
- implement appropriate technical and organisational measures under Article 32, including TLS in transit, bcrypt password hashing, per-tenant isolation with access control, an append-only audit log and login throttling;
- taking into account the nature of processing, assist the Controller with responding to data-subject requests and with its security, breach-notification and data-protection-impact-assessment obligations;
- notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data;
- at the Controller's choice, delete or return personal data at the end of the provision of services, subject to any legal retention requirement; and
- make available information necessary to demonstrate compliance and allow for and contribute to audits as described below.
5. Subprocessors
The Controller authorises the Processor to engage the subprocessors listed below. The Processor imposes data-protection obligations on each subprocessor no less protective than those in this DPA and remains responsible for their performance.
- PerfGrid — Application hosting and backups (The Netherlands).
- Mailtrap — Transactional email delivery (EU / US).
- Stripe — payment processing.
The Processor will give the Controller prior notice of any intended addition or replacement of a subprocessor, giving the Controller the opportunity to object on reasonable data-protection grounds.
6. International transfers
Personal data is hosted in The Netherlands. Where personal data is transferred outside that region, the parties rely on the Standard Contractual Clauses or another lawful transfer mechanism.
7. Audits
The Processor will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and no more than once per year (unless required by a supervisory authority or following a breach), allow for and contribute to audits, subject to confidentiality and to not compromising the security of other customers.
8. Liability and governing law
Each party's liability under this DPA is subject to the limitations and exclusions in the agreement. This DPA is governed by the laws of the applicable jurisdiction. In the event of a conflict between this DPA and the agreement on the subject of data protection, this DPA prevails.