Legal
Data Processing Addendum
Last updated July 20, 2026
This Data Processing Addendum (“DPA”) forms part of the Master Software as a Service Agreement and applicable Order Form (the “Agreement”) between the customer identified in the Order Form (“Customer”) and 2raywall Solutions Inc. (“2raywall”, “Provider”). It applies to 2raywall’s Processing of Personal Data on Customer’s behalf in connection with the CruiseControl platform and Service. In the event of a conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA controls. Except as modified here, the Agreement remains in full force.
1. DEFINITIONS
- “Data Protection Laws” means all laws applicable to the Processing of Personal Data under the Agreement, including, as applicable, the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, and U.S. state privacy laws including the California Consumer Privacy Act as amended (“CCPA”).
- “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, and “Personal Data Breach” have the meanings given under Data Protection Laws.
- “Customer Personal Data” means Personal Data contained within Customer Data that 2raywall Processes on Customer’s behalf under the Agreement.
- “Sub-processor” means a third party engaged by 2raywall to Process Customer Personal Data.
- “Standard Contractual Clauses” or “SCCs” means the clauses approved by the European Commission for the transfer of Personal Data to third countries, and, where applicable, the UK International Data Transfer Addendum.
2. ROLES OF THE PARTIES
As between the parties, Customer is the Controller (or a Processor acting on behalf of its own controllers) of Customer Personal Data, and 2raywall is the Processor. Under the CCPA, 2raywall acts as a “service provider” and will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than performing the Service (or as otherwise permitted by the CCPA), and will not combine it with data from other sources except as permitted by law. Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and for having an appropriate legal basis to Process it and to authorize 2raywall’s Processing.
3. SCOPE AND INSTRUCTIONS
2raywall will Process Customer Personal Data only on Customer’s documented instructions, including as set out in the Agreement, this DPA, and Customer’s configuration and use of the Service, and as required by applicable law. If 2raywall believes an instruction violates Data Protection Laws, it will inform Customer (unless prohibited by law). The subject matter, duration, nature, and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex A.
4. CONFIDENTIALITY
2raywall ensures that personnel authorized to Process Customer Personal Data are subject to appropriate obligations of confidentiality and Process such data only as necessary to provide the Service.
5. SECURITY
Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to Data Subjects, 2raywall implements appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, as described in Annex B and in our Data Access Management Policy.
6. SUB-PROCESSORS
Customer provides general authorization for 2raywall to engage Sub-processors to Process Customer Personal Data. A list of current Sub-processors (by category) is described in Annex C and is available on request. 2raywall will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA and remains responsible for its Sub-processors’ performance. 2raywall will give Customer reasonable notice of the addition or replacement of a Sub-processor, and Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, Customer’s remedy is to terminate the affected portion of the Service.
7. ASSISTANCE WITH DATA SUBJECT REQUESTS
Taking into account the nature of the Processing, 2raywall will provide reasonable assistance, including through appropriate technical and organizational measures, to enable Customer to respond to requests from Data Subjects to exercise their rights. If a Data Subject request is made directly to 2raywall, 2raywall will (unless legally prohibited) forward it to Customer and will not respond except on Customer’s instructions.
8. ASSISTANCE WITH COMPLIANCE OBLIGATIONS
2raywall will provide Customer with reasonable assistance in relation to security, Personal Data Breach notification, data protection impact assessments, and prior consultation with supervisory authorities, in each case taking into account the nature of Processing and the information available to 2raywall.
9. PERSONAL DATA BREACH
2raywall will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and will provide information reasonably available to it to assist Customer in meeting its breach-notification obligations. 2raywall’s notification is not an acknowledgment of fault or liability.
10. RETURN AND DELETION
Upon expiration or termination of the Agreement, 2raywall will, at Customer’s election and subject to the timeframes in the Agreement, delete or return Customer Personal Data, and delete existing copies unless retention is required by applicable law. This obligation does not apply to aggregated, anonymized, de-identified, or derived data that no longer identifies any Data Subject, which is not Customer Personal Data.
11. AUDITS
2raywall will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. Audits are subject to reasonable conditions of confidentiality, advance notice, scope, frequency (no more than once per year absent a regulator requirement or a Personal Data Breach), and cost, and may be satisfied through up-to-date third-party audit reports or certifications where available.
12. INTERNATIONAL TRANSFERS
Where the Processing of Customer Personal Data involves a transfer from the European Economic Area, the United Kingdom, or Switzerland to a country that does not provide an adequate level of protection, the Standard Contractual Clauses (and the UK International Data Transfer Addendum, as applicable) are incorporated into this DPA by reference and apply to that transfer, with 2raywall acting as data importer. The parties agree the SCCs are completed with the information set out in the Annexes.
13. CCPA SERVICE PROVIDER TERMS
To the extent 2raywall Processes Personal Data of California residents on Customer’s behalf, 2raywall is a service provider and certifies that it understands and will comply with the restrictions in Section 2 above. Customer may take reasonable steps to ensure that 2raywall uses such Personal Data in a manner consistent with Customer’s obligations under the CCPA.
14. LIABILITY
Each party’s liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Agreement, and any reference in the Agreement to a party’s liability means the aggregate liability of that party under the Agreement and this DPA together.
15. TERM
This DPA takes effect on the effective date of the Agreement and remains in effect for as long as 2raywall Processes Customer Personal Data on Customer’s behalf.
ANNEX A — DETAILS OF PROCESSING
- Subject matter: 2raywall’s provision of the CruiseControl platform and Service to Customer.
- Duration: the term of the Agreement plus any period during which Customer Personal Data is retained as permitted by the Agreement or required by law.
- Nature and purpose: hosting, storage, and Processing of Customer Personal Data to provide, secure, support, and improve the Service, as instructed by Customer.
- Categories of Data Subjects: Customer’s employees, crew members, contractors, applicants and candidates, administrators, and other individuals whose data Customer submits to the Service.
- Types of Personal Data: identifiers and contact details; account credentials; employment, role, and organizational data; performance, learning, recognition, and disciplinary records; documents Customer uploads; recruitment and application data; and, where Customer elects to submit it, payroll-related and other data described in the Service documentation.
- Special category data: not required by the Service; Customer is responsible for any special-category or sensitive data it chooses to submit and for any additional legal basis required.
ANNEX B — TECHNICAL AND ORGANIZATIONAL MEASURES
2raywall maintains a security program that includes, as described in our Data Access Management Policy: role- and attribute-based access control and least-privilege access; authentication controls and access recertification; encryption of Personal Data in transit and, where appropriate, at rest; network and application security controls; centralized logging and monitoring; backup and recovery procedures; personnel confidentiality obligations and security awareness; and vendor management for Sub-processors. Measures are reviewed periodically and updated to address evolving risks.
ANNEX C — SUB-PROCESSORS
2raywall engages Sub-processors in the following categories to support the Service: cloud hosting and infrastructure; email and notification delivery; error monitoring and analytics; and payment processing (for billing). A current list of specific Sub-processors is available to Customer on request. 2raywall imposes data protection obligations on each Sub-processor consistent with this DPA.
CONTACT
Questions about this DPA, or requests to execute a countersigned copy, may be directed to:
2raywall Solutions Inc.
18117 Biscayne Blvd Suite 201
Miami, FL 33160
United States
contact@cruisecontrolapp.com