1. Parties and scope
This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between Edge Shore Technologies LLC (1030 Salem Rd, Union, NJ 07083-7058-309, USA) ("Processor", "Speedlr") and the customer organization ("Controller", "Customer").
It applies where Speedlr processes personal data on Customer's behalf in providing the Services, and covers obligations under the EU GDPR, UK GDPR, Swiss FADP, and US state privacy laws including the CCPA/CPRA. In CCPA terms, Speedlr is a "service provider" and does not sell or share personal information.
2. Details of processing
- Subject matter: provision of the Speedlr telecom construction operations platform.
- Duration: the subscription term plus the retention periods set out below.
- Nature and purpose: hosting, storage, transmission, access management, support, backup and security monitoring.
- Categories of data subjects: Customer's employees, contractors, field crews, and business contacts including site or customer contacts recorded in work orders.
- Categories of personal data: identifiers, business contact details, job role, credentials and authentication metadata, activity and audit logs, location or timestamp data captured with field records, and free-text content submitted by users.
- Special category data: none is required or requested; Customer must not submit it without prior written agreement.
3. Processing instructions
Speedlr processes personal data only on Customer's documented instructions, which include the Terms, this DPA, configuration choices made in the Services, and support requests. Speedlr will not retain, use, disclose or otherwise process personal data for any purpose other than providing the Services, and will not combine it with data from other sources except as permitted by law. If Speedlr believes an instruction violates applicable data protection law, it will notify Customer without undue delay.
4. Personnel and confidentiality
Speedlr limits access to personal data to personnel who need it to deliver the Services, binds them to written confidentiality obligations that survive termination, and provides security and privacy awareness training at least annually.
5. Security measures (Annex II)
Speedlr implements and maintains technical and organizational measures appropriate to the risk, aligned to ISO/IEC 27001 Annex A controls and the SOC 2 Trust Services Criteria, including:
- Encryption of personal data in transit (TLS 1.2+) and at rest.
- Role-based access control, least privilege, unique accounts and multi-factor authentication for administrative access; quarterly access reviews.
- Network segmentation, hardened configurations, and separation of production from non-production environments.
- Secure software development, peer code review, dependency and vulnerability scanning, and documented change management.
- Centralized logging, monitoring and alerting of security-relevant events; retained audit trails.
- Encrypted backups with periodic restoration testing and documented business continuity and disaster recovery plans.
- Documented incident response with defined roles, escalation paths and post-incident review.
- Vendor risk assessment before onboarding subprocessors, and secure media disposal and data deletion procedures.
Measures may be updated as the Services evolve, provided the level of protection is not materially reduced.
6. Subprocessors
Customer grants general authorization for Speedlr to engage subprocessors for hosting, infrastructure, monitoring, communications and support. Speedlr maintains a current subprocessor list available at privacy@speedlr.com, imposes data protection obligations on each subprocessor no less protective than this DPA, and remains fully liable for their performance. Speedlr gives at least 30 days' notice before adding or replacing a subprocessor; Customer may object on reasonable data protection grounds and, if no resolution is reached, terminate the affected Services with a pro-rata refund of prepaid unused fees.
7. International transfers
Where processing involves transfer of personal data outside the EEA, UK or Switzerland to a country without an adequacy decision, the parties incorporate the European Commission Standard Contractual Clauses (Module Two, controller-to-processor) with the UK International Data Transfer Addendum and Swiss adaptations as applicable. Annex I is populated with the details in Section 2 and the parties' identities; Annex II is Section 5 above. Speedlr conducts transfer risk assessments and applies supplementary measures such as encryption and access controls.
8. Data subject rights and assistance
- Speedlr provides functionality allowing Customer to access, correct, export and delete personal data within the Services.
- If Speedlr receives a request directly from a data subject, it will not respond substantively and will forward it to Customer without undue delay.
- Speedlr provides reasonable assistance with data protection impact assessments, prior consultations and security obligations under Articles 32-36 GDPR, taking into account the nature of processing and the information available to it.
9. Personal data breach notification
Speedlr notifies Customer without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting Customer personal data. The notice will describe the nature of the breach, categories and approximate volume of data and data subjects affected, likely consequences, measures taken or proposed, and a contact point. Speedlr will cooperate with Customer's own notification obligations and will not make public statements identifying Customer without prior written consent unless legally required.
10. Audits and evidence
On written request no more than once per 12 months (or after a confirmed breach), Speedlr makes available information necessary to demonstrate compliance with this DPA, including security documentation, policy summaries and, when available, third-party audit reports or certifications. Where Customer requires an on-site or in-depth audit, the parties will agree scope, timing and confidentiality in advance; audits are at Customer's expense and must not disrupt operations or compromise other customers' data.
11. Return and deletion
On termination or expiry, Customer may export personal data through the Services during a 30-day retrieval window. After that window Speedlr deletes or de-identifies Customer personal data from production systems, with backup copies purged on the ordinary backup rotation cycle, unless retention is required by applicable law. Written confirmation of deletion is available on request.
12. Liability, precedence and signature
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms. In case of conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms with respect to processing of personal data.
A countersigned copy of this DPA is available on request from legal@speedlr.com. Absent a separate signed version, this DPA is deemed accepted on acceptance of the Terms.
Questions?
Contact Edge Shore Technologies LLC at legal@speedlr.com or write to 1030 Salem Rd, Union, NJ 07083-7058-309, USA.
This page is maintained by Edge Shore Technologies LLC and is provided for information only. It is not legal advice, and it is not a certification or independent attestation of compliance.