Data Processing Addendum (DPA)

Data Protection & Privacy Obligations


Last Updated: October 8, 2026

Owner: True Bearing Safety Solutions, LLC (Anchorage, Alaska) ? Contact: info@truebearingsafety.com

This Data Processing Addendum ("DPA") supplements the Master Subscription & Services Agreement ("Agreement") between True Bearing and Customer. It applies when True Bearing processes Personal Data on behalf of Customer in providing the Rivkor Platform and Agreement-referenced Platform-related services. Capitalized terms not defined here have the meanings in the Agreement.

0. Applicability

This DPA applies only to Personal Data Processing performed by True Bearing under the Platform subscription and any Platform-related professional services purchased under an Order that references the Agreement. Any non-Platform engagements (e.g., separate consulting agreements, site visits, audits/assessments, on-site training delivery) are governed by their own contracts and, if required, separate data protection terms or addenda.

1. Definitions

?Personal Data? means information relating to an identified or identifiable natural person. ?Processing? means any operation performed on Personal Data, such as collection, storage, use, disclosure, and deletion. ?Controller? means Customer; ?Processor? means True Bearing.

2. Roles; Instructions

Customer is the Controller and determines the purposes and means of Processing. True Bearing acts as Processor and will Process Personal Data only on documented instructions from Customer, including with respect to international transfers, deletions, and disclosures.

3. Scope of Processing (EHS Context)

Categories include training records, incident logs, corrective actions, inspections/audits, competency/qualification records, limited injury/illness details (if entered), and account identifiers. Processing is for providing the Platform (documentation, dashboards, administration, support).

4. Security Measures

  • MFA for administrative accounts;
  • Least-privilege and role-based access controls;
  • Encryption in transit (TLS) and at rest;
  • Access logging and monitoring;
  • Vulnerability management and patching cadence;
  • Backups and tested restore procedures;
  • Documented incident response plan.

5. Confidentiality; Authorized Personnel

True Bearing ensures Authorized Personnel are bound by confidentiality, trained on data protection, and access only what is necessary to perform services.

6. Subprocessors

True Bearing may engage subprocessors to Process Personal Data, subject to written agreements imposing equivalent data protection obligations. True Bearing will maintain a list of subprocessors and provide notice of changes upon request.

7. International Transfers; Safeguards

Where Personal Data is transferred internationally, True Bearing will implement appropriate safeguards (e.g., Standard Contractual Clauses) and require subprocessors to do the same, consistent with applicable laws.

8. Data Subject Requests

Taking into account the nature of Processing, True Bearing will assist Customer in responding to requests to exercise data subject rights (access, rectification, erasure, portability, restriction, objection) under applicable laws. Customer is responsible for verifying the identity of requesters.

9. Audit; Information

Upon reasonable prior notice, True Bearing will provide information necessary to demonstrate compliance with this DPA and will cooperate with audits or inspections by Customer or Customer?s auditor, subject to confidentiality and reasonable limits. For complex audits, Customer will reimburse reasonable costs.

10. Incident Notification

True Bearing will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer?s Personal Data, and will provide information reasonably required for Customer to meet its obligations.

11. Retention; Deletion; Return

True Bearing retains Personal Data for as long as necessary to provide services and comply with legal obligations, including OSHA recordkeeping where applicable. Upon termination or upon Customer?s written request, True Bearing will delete or return Personal Data, subject to backup retention windows and legal holds.

12. De-Identified / Aggregated Data

True Bearing may create and use de-identified/aggregated data, not reasonably linkable to a person or company, for service improvement, analytics, and benchmarks; this does not include Customer-identifying analytics without consent.

13. Government Requests

Where True Bearing receives a legally binding request to disclose Personal Data, True Bearing will, to the extent permitted by law, notify Customer and seek to limit disclosure.

14. Liability; Remedies

Each party's liability under this DPA is subject to the limitations in the Agreement. The parties will cooperate in good faith to mitigate harm arising from incidents.

15. Governing Law

This DPA is governed by the laws specified in the Agreement (Alaska).

16. Order of Precedence

If there is a conflict between this DPA and the Agreement, this DPA controls with respect to data protection and privacy.


Questions? Contact info@truebearingsafety.com.