Data Processing Addendum
Version 2026-09-25 · Effective September 25, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Interlock MDR ("MDR") and the Company ("Customer") and applies to the extent MDR processes personal data on the Customer's behalf that is subject to data protection law — including the GDPR, the UK GDPR, and the CCPA/CPRA. It is accepted by the Customer's acceptance of the Terms. Where it conflicts with the Terms, this DPA controls for the processing of personal data.
1. Roles
For account data — the information MDR collects to run the service, described in the Privacy Policy — MDR is an independent controller.
For transferred data — the business records MDR moves from the Customer's systems to a Partner, or receives from a Partner on the Customer's behalf — the Customer is the controller (or a processor acting for its own customer) and MDR is the processor, acting only on the Customer's documented instructions. The Partner that receives transferred data is an independent controller of what it receives, and the relationship between the Customer and that Partner — including any data protection terms between them — is theirs to establish in the transfer terms attached to the Product and the Contract they approve. MDR is not a party to it.
2. Details of processing
- Subject matter: transfer of the data described by a Product from the Customer's connected system to a Partner under an approved Contract, and the operation of the MDR service.
- Duration: for each transfer, the duration of that request; for the service, the term of the Customer's account.
- Nature and purpose: reading data from the Customer's connected system, applying the Contract's controls, and streaming the result to the Partner; MDR does not store, analyse or otherwise use transferred data. Where the Customer enables AI features, bounded samples may be processed to produce mapping and design suggestions, at the access level the Customer sets.
- Categories of data subjects: whoever appears in the Customer's business records — typically the Customer's customers, vendors, employees and contacts — as determined by the Products the Customer defines.
- Categories of personal data: whatever the Customer includes in a Product. MDR does not require, and recommends against, including special categories of data. The Customer, not MDR, decides what a Product contains.
3. Instructions
The Customer's instructions are: the Terms, this DPA, the Products the Customer defines, the controls it sets, the Contracts it approves, and the settings it chooses in the application (including AI preferences). MDR executes a Contract exactly as approved and will not process transferred data for any other purpose. If MDR believes an instruction violates data protection law it will inform the Customer and may suspend the affected processing.
4. Customer responsibilities
The Customer is responsible for the lawfulness of the personal data it transfers, for having a lawful basis and any required notices or consents, for the accuracy of the data, for choosing Partners entitled to receive it, for the transfer terms it attaches to its Products, and for responding to data subjects. The Customer will not instruct MDR to process data in violation of law.
5. Confidentiality and personnel
MDR limits access to personal data to personnel who need it to provide the service and who are bound by confidentiality obligations.
6. Security
MDR implements and maintains technical and organisational measures appropriate to the risk, including:
- encryption in transit (TLS) and at rest;
- application-level encryption of stored credentials, sync positions and AI results, with keys held in a managed key vault separate from the database;
- tenant isolation — every record attributed to a Company and every query scoped to it — and role-based entitlements enforced on every request;
- an audit trail of authentication events and every change to who can see what;
- no retention of transferred data: it is processed in memory for the duration of a transfer only;
- complete-or-fail delivery, so a partial transfer is never delivered silently;
- verified email addresses, session-scoped sign-in and automatic sign-out on inactivity;
- hosting on Microsoft Azure with its physical, network and operational controls.
7. Sub-processors
The Customer authorises MDR to engage the sub-processors listed at interlockmdr.com/subprocessors. MDR will give at least 30 days' notice before adding a sub-processor that will process transferred data; the Customer may object on reasonable data protection grounds within that period, and if the objection cannot be resolved the Customer may terminate the affected service. MDR remains responsible for its sub-processors' performance of this DPA.
8. Assistance
Taking into account the nature of the processing, MDR will assist the Customer, at the Customer's reasonable request, in responding to data subject requests and in meeting its obligations regarding security, breach notification and data protection impact assessments. Because MDR does not retain transferred data, requests concerning transferred data are usually fulfilled by the Customer and the receiving Partner in their own systems.
9. Personal data breach
MDR will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Customer's personal data, and will provide the information reasonably available to help the Customer meet its own notification obligations.
10. Deletion and return
Transferred data is not retained and requires no deletion. On deletion of the Customer's Company, MDR deletes the Customer's connected credentials and ends its Contracts; account data is handled as the Privacy Policy describes. Data delivered to a Partner is in the Partner's possession and is that Partner's responsibility.
11. Audit
On written request no more than once a year, MDR will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security measures and any third-party audit reports it holds. Where that is insufficient to meet a legal requirement, MDR will allow an audit by the Customer or an independent auditor bound by confidentiality, at the Customer's expense, at a mutually agreed time and scope.
12. International transfers
MDR processes personal data in the United States. For personal data subject to the GDPR, the UK GDPR or Swiss law, the parties enter into the EU Standard Contractual Clauses (Module Two, controller to processor) and the UK International Data Transfer Addendum, which are incorporated by reference with the Customer as data exporter and MDR as data importer, the details in Section 2 as the annexes, and the security measures in Section 6 as the technical and organisational measures. A signed copy is available on request through contact.
13. CCPA / CPRA
To the extent the CCPA/CPRA applies, MDR is a service provider. MDR will not sell or share the Customer's personal information, retain, use or disclose it for any purpose other than providing the service, or combine it with personal information from other sources except as the law permits for a service provider, and will notify the Customer if it can no longer meet these obligations.
14. Liability
Liability under this DPA is subject to the limitations in the Terms of Service. Nothing in this DPA makes MDR responsible for the Customer's or a Partner's own compliance, for the content of transferred data, or for what a Partner does with data it receives. Because MDR does not store or hold transferred data, the release in Section 17 of the Terms of Service applies to any breach occurring on the systems of the Customer or of a Partner, before a transfer or after delivery.
Questions about this DPA: contact us.