Data Processing Addendum (DPA)
Data Protection & Privacy Obligations
Last Updated: October 8, 2026
Owner: True Bearing Safety Solutions, LLC (Anchorage, Alaska) ? Contact: info@truebearingsafety.com
This Data Processing Addendum ("DPA") supplements the Master Subscription & Services Agreement ("Agreement") between True Bearing and Customer. It applies when True Bearing processes Personal Data on behalf of Customer in providing the Rivkor Platform and Agreement-referenced Platform-related services. Capitalized terms not defined here have the meanings in the Agreement.
0. Applicability
This DPA applies only to Personal Data Processing performed by True Bearing under the Platform subscription and any Platform-related professional services purchased under an Order that references the Agreement. Any non-Platform engagements (e.g., separate consulting agreements, site visits, audits/assessments, on-site training delivery) are governed by their own contracts and, if required, separate data protection terms or addenda.
1. Definitions
?Personal Data? means information relating to an identified or identifiable natural person. ?Processing? means any operation performed on Personal Data, such as collection, storage, use, disclosure, and deletion. ?Controller? means Customer; ?Processor? means True Bearing.
2. Roles; Instructions
Customer is the Controller and determines the purposes and means of Processing. True Bearing acts as Processor and will Process Personal Data only on documented instructions from Customer, including with respect to international transfers, deletions, and disclosures.
3. Scope of Processing (EHS Context)
Categories include training records, incident logs, corrective actions, inspections/audits, competency/qualification records, limited injury/illness details (if entered), and account identifiers. Processing is for providing the Platform (documentation, dashboards, administration, support).
4. Security Measures
- MFA for administrative accounts;
- Least-privilege and role-based access controls;
- Encryption in transit (TLS) and at rest;
- Access logging and monitoring;
- Vulnerability management and patching cadence;
- Backups and tested restore procedures;
- Documented incident response plan.
5. Confidentiality; Authorized Personnel
True Bearing ensures Authorized Personnel are bound by confidentiality, trained on data protection, and access only what is necessary to perform services.
6. Subprocessors
True Bearing may engage subprocessors to Process Personal Data, subject to written agreements imposing equivalent data protection obligations. True Bearing will maintain a list of subprocessors and provide notice of changes upon request.
7. International Transfers; Safeguards
Where Personal Data is transferred internationally, True Bearing will implement appropriate safeguards (e.g., Standard Contractual Clauses) and require subprocessors to do the same, consistent with applicable laws.
8. Data Subject Requests
Taking into account the nature of Processing, True Bearing will assist Customer in responding to requests to exercise data subject rights (access, rectification, erasure, portability, restriction, objection) under applicable laws. Customer is responsible for verifying the identity of requesters.
9. Audit; Information
Upon reasonable prior notice, True Bearing will provide information necessary to demonstrate compliance with this DPA and will cooperate with audits or inspections by Customer or Customer?s auditor, subject to confidentiality and reasonable limits. For complex audits, Customer will reimburse reasonable costs.
10. Incident Notification
True Bearing will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer?s Personal Data, and will provide information reasonably required for Customer to meet its obligations.
11. Retention; Deletion; Return
True Bearing retains Personal Data for as long as necessary to provide services and comply with legal obligations, including OSHA recordkeeping where applicable. Upon termination or upon Customer?s written request, True Bearing will delete or return Personal Data, subject to backup retention windows and legal holds.
12. De-Identified / Aggregated Data
True Bearing may create and use de-identified/aggregated data, not reasonably linkable to a person or company, for service improvement, analytics, and benchmarks; this does not include Customer-identifying analytics without consent.
13. Government Requests
Where True Bearing receives a legally binding request to disclose Personal Data, True Bearing will, to the extent permitted by law, notify Customer and seek to limit disclosure.
14. Liability; Remedies
Each party's liability under this DPA is subject to the limitations in the Agreement. The parties will cooperate in good faith to mitigate harm arising from incidents.
15. Governing Law
This DPA is governed by the laws specified in the Agreement (Alaska).
16. Order of Precedence
If there is a conflict between this DPA and the Agreement, this DPA controls with respect to data protection and privacy.
Questions? Contact info@truebearingsafety.com.
