This Data Protection Addendum ("DPA") is an integral part of the Terms of Service, which can be accessed at https://iedge.in/terms-of-service.html, or , if applicable, any other separate written agreement (referred to as the "Agreement" or "Services Agreement"), by and between iEdge Digital Business Cards (a division of FutureSoft India Pvt Ltd), and the Customer/Client named in the Agreement, pursuant to which Customer/Client has purchased a subscription to access and use the Service (as defined in the Agreement). The parties intend this DPA to be an extension of the Agreement that will outline certain requirements for iEdge’s processing of certain personal data provided or made available by Customer/Client, or collected or otherwise obtained by iEdge, in the course of providing services to Customer/Client.
"Agreement" means the agreement between the Controller and the Processor for the provision of the Services;
"CCPA" means the California Consumer Privacy Act of 2018, along with its regulations and as amended from time to time;
"Data Protection Legislation" means all applicable laws relating to privacy and the processing of personal data that may exist in any relevant jurisdiction where iEdge conducts business. Data Protection Legislation includes, but is not limited to, EU GDPR and UK GDPR.
“Data Subject” shall have the same meaning as in Data Protection Law or means a “Consumer” as that term is defined in the CCPA;
“EU GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data;
“Personal Data” shall have the same meaning as in Data Protection Law;
“Processor” means the Company, including as applicable any “Service Provider” as that term is defined by the CCPA;
“Services” means all services and software applications and solutions provided to the Controller by the Processor under and as described in the Agreement;
“Sub-Processor” means any third party (including the Processor’s Affiliates) engaged directly or indirectly by the Processor to process Personal Data under this DPA in the provision of the Services to the Controller;
"UK GDPR” means the EU GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018.
The Processor has agreed to provide the Services to the Controller in accordance with the terms of the Agreement. In providing the Services, the Processor shall process Customer Data on behalf of the Controller. Customer Data may include Personal Data. The Processor will process and protect such Personal Data in accordance with the terms of this DPA.
The parties agree that, as between the parties, Customer is a data controller and that iEdge is a processor in relation to personal data that iEdge processes on behalf of Customer in the course of providing the services under the Services Agreement ("Services"). The subject-matter of the data processing, the types of personal data processed, and the categories of data subjects will be defined by, and/or limited to that necessary to carry out the Services described in, the Services Agreement. The processing will be carried out until the date iEdge ceases to provide the Services to Customer. The categories of data subjects and personal data are set forth on Annex 1 hereto.
In respect of personal data processed in the course of providing the Services, iEdge shall adhere to the following requirements:
iEdge has established a robust access control system to ensure that only authorized personnel have access to Personal Data. Access to Personal Data is restricted to authorized individuals who require it solely for support purposes. This access is governed by a role-based access control system, which grants access only to the data necessary for the specific support task.
All iEdge personnel authorized to access Personal Data undergo training to ensure compliance with relevant Data Protection Laws. Furthermore, they are bound by perpetual confidentiality obligations, applicable to their support duties.
We maintain relevant audit logs, documenting access to sensitive information, including personal data. These logs are exclusively accessed by the Security team.
We employ encryption and pseudonymization techniques to safeguard Personal Data from unauthorized access, disclosure, or destruction. iEdge utilizes cutting-edge encryption technologies to ensure the security of data during transmission and storage.
We take necessary measures to securely store and retain Customers' data. This includes logically separating Customers' data from system and application data, as well as implementing access controls and monitoring mechanisms. Additionally, we regularly assess and test the effectiveness of our technical and organizational measures to ensure data security.
iEdge has also implemented measures to ensure the availability and accessibility of Personal Data in case of physical or technical incidents.
We have established processes to address data breaches, which involve notifying relevant stakeholders in accordance with the type of incident and applicable legislation.
Our development process adheres to a secure methodology, incorporating peer review, secure coding, and thorough testing.
iEdge implements measures to safeguard the security and integrity of our systems and processes, including our system configuration and default settings. We adhere to industry best practices and standards to ensure secure system configurations and prevent vulnerabilities from default settings.
We conduct regular reviews and updates of our system configuration settings to align with our security policies. Additionally, we enforce stringent controls over changes to system configurations, requiring documentation, approval, and testing before implementation.
Moreover, our software development processes incorporate secure coding practices, and we consistently assess and update default configurations to maintain security and mitigate potential vulnerabilities.
iEdge recognizes its role as a Data Processor and acknowledges the responsibility to support the Customer in safeguarding the security and integrity of Personal Data. Accordingly, we have enacted targeted technical and organizational measures to facilitate effective assistance to the Customer in their capacity as a Data Controller.
A pivotal measure we've implemented involves the formation of a specialized customer support team comprising personnel trained in compliance with relevant Data Protection Laws and regulations. This team is tasked with assisting the Customer in managing and processing Personal Data, including addressing requests for data access, rectification, and deletion.
The iEdge platform is developed by the parent company FutureSoft India Pvt Ltd, which is an ISO 27001 certified company. iEdge has also obtained VAPT certification. We undergo regular audits and assessments to uphold this certification, ensuring our adherence to relevant data protection laws.
The data exporter is Customer.
The data importer is iEdge.
The personal data transferred concern the following categories of data subjects:
The personal data transferred concern the following categories of data: