Data Processing Addendum
This Data Processing Addendum ("DPA") supplements the agreement between Scriza Private Limited, operating the Alert21 brand ("Alert21"), and the customer where Alert21 processes personal data on the customer's behalf in connection with communication, notification or related services.
1. Roles
For customer-controlled recipient data, the customer generally determines the purpose, recipients and lawful basis of the communication and acts as the applicable controller/data fiduciary. Alert21 generally acts as processor/data processor/service provider on the customer's documented instructions, except where Alert21 independently determines processing required for its own account security, billing, fraud prevention, legal obligations or service administration.
2. Processing Details
Subject matter: operation and delivery of Alert21 communication and notification services.
Duration: the service term plus permitted retention periods.
Data subjects: customer users, message recipients, customer contacts and other persons whose data is lawfully submitted.
Data types: contact identifiers such as mobile number or email address, message/template data, variable values, delivery metadata, IP/account/security data, billing records and other data submitted by the customer.
Processing activities: receipt, validation, storage as necessary, routing, transmission, logging, delivery-status processing, support, security, billing and deletion or return.
3. Customer Instructions and Lawfulness
The customer instructs Alert21 to process personal data only as necessary to provide the contracted service and confirms that it has provided required notices and obtained the rights, consent or other lawful basis required for the data and communications.
4. Confidentiality
Alert21 will restrict access to personnel and service providers who need the data for authorized purposes and who are subject to appropriate confidentiality obligations.
5. Security Measures
Alert21 will maintain technical and organizational measures appropriate to the service and risk, which may include access control, encryption in transit, encryption at rest where appropriate, logging, credential and secrets management, backup, monitoring, incident response, environment separation and vendor controls. An enterprise agreement may attach a more detailed security schedule.
6. Subprocessors
Alert21 may engage cloud, telecom, messaging, database, monitoring, support, payment and other subprocessors necessary to provide the service. Where applicable law or a signed agreement requires it, Alert21 will maintain a subprocessor list and provide a reasonable notice process for material changes.
7. Rights Requests
Taking into account the nature of processing, Alert21 will reasonably assist the customer with valid data-subject or data-principal rights requests to the extent required by applicable law and contract. Where Alert21 acts only as processor, the customer remains responsible for responding to the individual.
8. Security Incidents
Alert21 will maintain incident-response procedures and will notify affected customers of qualifying personal-data or security incidents within the timeline required by applicable law or the signed agreement, based on information reasonably available at the time.
9. Return and Deletion
At termination or upon a valid customer request, Alert21 will delete or return customer personal data according to the contract, applicable retention requirements and legal obligations. Backup copies may remain for a limited period until overwritten in the normal backup cycle.
10. Cross-Border Transfers
Where data is transferred across jurisdictions, the parties will apply safeguards and restrictions required by applicable law. International message routing may involve cross-border processing by telecom or platform providers and should be assessed for the relevant destination and service.
11. Audit and Compliance Information
Subject to confidentiality and security limitations, Alert21 will provide reasonable information necessary to demonstrate compliance with obligations that apply to Alert21 as processor. Any audit rights, frequency, scope, costs and third-party reports should be defined in the signed customer or enterprise agreement.
12. Order of Precedence
If this DPA conflicts with the main agreement on personal-data processing, the signed DPA or enterprise data-processing terms will prevail to the extent of the conflict.
Annex A - Processing Information
Customer: Customer Legal Name
Service: Alert21 Communication Services
Processing purpose: communication routing, delivery, status processing and associated support/security.
Categories of data subjects: Customer Users, Message Recipients
Categories of personal data: Contact Identifiers, Message Data, Delivery Metadata
Processing duration: Service Term plus applicable retention period
Approved processing locations / restrictions: As specified in enterprise agreement
Annex B - Security Measures
The signed DPA may reference or attach the production security controls applicable to the customer, including access control, authentication, encryption, logging, monitoring, vulnerability management, backup, incident response, business continuity and subprocessor oversight.
Turn your next business event into a traceable alert.
Start with DLT-ready SMS today on Alert21’s developer-first communication platform.
