Data Processing Agreement
How AdeptLink processes personal data on behalf of business customers as a data processor under GDPR and equivalent data protection laws.
1. Scope and parties
This Data Processing Agreement ("DPA") forms part of the AdeptLink Terms of Service between AdeptLink Solutions Inc. ("AdeptLink", "Processor", "we") and the business entity that has accepted the Terms of Service ("Controller", "you"). It applies where AdeptLink processes personal data on behalf of the Controller in the course of providing the AdeptLink B2B marketplace platform and related services.
2. Definitions
"Personal data", "processing", "data subject", "controller", "processor", "supervisory authority" and "personal data breach" have the meanings given in applicable data protection law, including Regulation (EU) 2016/679 (GDPR) where applicable. "Services" means the AdeptLink marketplace platform as described in the Terms of Service.
3. Processing instructions
AdeptLink processes personal data only on documented instructions from the Controller, as set out in the Terms of Service, this DPA, and any additional written instructions agreed in writing. AdeptLink informs the Controller if, in its opinion, an instruction infringes applicable data protection law. If required to process personal data by applicable law, AdeptLink notifies the Controller unless prohibited by law.
4. Purpose and categories of processing
AdeptLink processes personal data for the purpose of providing the Services — including account management, transaction processing, KYC verification, customer support, fraud prevention, and product improvement. Categories of personal data processed may include: contact information (name, email, company, phone), financial information (payment method, bank details), identity documents (for KYC), transaction records, and platform usage data.
5. Security measures
AdeptLink implements and maintains technical and organisational security measures appropriate to the risk, including: TLS 1.3 encryption in transit; AES-256 encryption at rest; role-based access control; multi-factor authentication on all internal systems; audit logging; regular vulnerability assessments; and annual third-party penetration testing. Full security details are available in the AdeptLink Security Addendum, available on request.
6. Sub-processors
AdeptLink may engage sub-processors to assist in providing the Services. Current sub-processors include AWS (infrastructure), Stripe (payments), Brevo (email), and Upstash (caching). AdeptLink: (a) provides 30 days' advance notice of sub-processor changes; (b) imposes data protection obligations on sub-processors equivalent to those in this DPA; and (c) remains liable for sub-processor acts or omissions. The full sub-processor list is available at privacy@adeptlink.com.
7. Data subject rights
AdeptLink assists the Controller in fulfilling its obligations to respond to data subject requests — including rights of access, rectification, erasure, restriction, portability and objection — by providing appropriate technical and organisational measures. AdeptLink notifies the Controller without undue delay upon receiving a data subject request relating to the Controller's personal data.
8. International transfers
AdeptLink processes personal data in data centres located in the United States and Singapore. For transfers of personal data from the EEA or UK, AdeptLink relies on Standard Contractual Clauses (SCCs) as approved by the European Commission. Copies of applicable SCCs are available on request at privacy@adeptlink.com.
9. Incident notification
AdeptLink notifies the Controller of a personal data breach within 72 hours of becoming aware, to the extent required by GDPR Article 33. Notification includes: the nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed to address the breach.
10. Deletion and return of data
Upon termination of the Terms of Service, AdeptLink, at the Controller's choice, deletes or returns all personal data processed under this DPA within 30 days of the termination date, unless applicable law requires longer retention. Confirmation of deletion is provided in writing upon request.
11. Audit rights
AdeptLink makes available information reasonably necessary to demonstrate compliance with this DPA and, upon reasonable written notice (not less than 30 days), cooperates with and contributes to audits conducted by the Controller or an independent auditor mandated by the Controller, subject to reasonable confidentiality obligations. Audit costs are borne by the Controller.
12. Contact
For DPA enquiries, sub-processor lists, signed DPA requests, and data protection questions, contact the AdeptLink privacy team at privacy@adeptlink.com. For security incident reports, contact security@adeptlink.com.
Data protection FAQ
- Is AdeptLink GDPR compliant?
- Yes. AdeptLink is designed to comply with the General Data Protection Regulation (GDPR) for customers operating in the European Economic Area, as well as equivalent data protection laws in the UK, Singapore (PDPA), and Vietnam (PDPL). The DPA sets out the contractual framework for how AdeptLink, as a data processor, handles personal data on behalf of business customers (controllers).
- How do I get a signed copy of the DPA?
- Email privacy@adeptlink.com with the subject line 'DPA Request — [Company Name]'. Include your company legal name, registered address and the name and title of the signatory. AdeptLink will return a countersigned DPA within 5 business days. The DPA is incorporated by reference into the AdeptLink Terms of Service.
- Who are AdeptLink's sub-processors?
- AdeptLink's primary sub-processors include: AWS (cloud infrastructure, EU and APAC regions), Stripe (payment processing), Brevo (transactional email), and Upstash (Redis caching). A full, up-to-date sub-processor list is available on request at privacy@adeptlink.com. AdeptLink provides 30 days' notice before adding or changing a sub-processor.
- How long does AdeptLink retain personal data?
- AdeptLink retains personal data for as long as needed to provide the platform services and comply with legal obligations (typically up to 7 years for financial records under applicable accounting laws). Upon contract termination, AdeptLink deletes or returns all personal data within 30 days of request, unless retention is required by law.
- What security measures does AdeptLink use to protect personal data?
- AdeptLink implements: TLS 1.3 encryption for all data in transit; AES-256 encryption for data at rest; role-based access control with principle of least privilege; multi-factor authentication for all internal systems; SOC 2-aligned audit logging; and annual penetration testing by a third-party security firm. Security incident notification is provided within 72 hours as required by GDPR Article 33.