Data Processing Addendum

Version 2026-09-25 · Effective September 25, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Interlock MDR ("MDR") and the Company ("Customer") and applies to the extent MDR processes personal data on the Customer's behalf that is subject to data protection law — including the GDPR, the UK GDPR, and the CCPA/CPRA. It is accepted by the Customer's acceptance of the Terms. Where it conflicts with the Terms, this DPA controls for the processing of personal data.

1. Roles

For account data — the information MDR collects to run the service, described in the Privacy Policy — MDR is an independent controller.

For transferred data — the business records MDR moves from the Customer's systems to a Partner, or receives from a Partner on the Customer's behalf — the Customer is the controller (or a processor acting for its own customer) and MDR is the processor, acting only on the Customer's documented instructions. The Partner that receives transferred data is an independent controller of what it receives, and the relationship between the Customer and that Partner — including any data protection terms between them — is theirs to establish in the transfer terms attached to the Product and the Contract they approve. MDR is not a party to it.

2. Details of processing

3. Instructions

The Customer's instructions are: the Terms, this DPA, the Products the Customer defines, the controls it sets, the Contracts it approves, and the settings it chooses in the application (including AI preferences). MDR executes a Contract exactly as approved and will not process transferred data for any other purpose. If MDR believes an instruction violates data protection law it will inform the Customer and may suspend the affected processing.

4. Customer responsibilities

The Customer is responsible for the lawfulness of the personal data it transfers, for having a lawful basis and any required notices or consents, for the accuracy of the data, for choosing Partners entitled to receive it, for the transfer terms it attaches to its Products, and for responding to data subjects. The Customer will not instruct MDR to process data in violation of law.

5. Confidentiality and personnel

MDR limits access to personal data to personnel who need it to provide the service and who are bound by confidentiality obligations.

6. Security

MDR implements and maintains technical and organisational measures appropriate to the risk, including:

7. Sub-processors

The Customer authorises MDR to engage the sub-processors listed at interlockmdr.com/subprocessors. MDR will give at least 30 days' notice before adding a sub-processor that will process transferred data; the Customer may object on reasonable data protection grounds within that period, and if the objection cannot be resolved the Customer may terminate the affected service. MDR remains responsible for its sub-processors' performance of this DPA.

8. Assistance

Taking into account the nature of the processing, MDR will assist the Customer, at the Customer's reasonable request, in responding to data subject requests and in meeting its obligations regarding security, breach notification and data protection impact assessments. Because MDR does not retain transferred data, requests concerning transferred data are usually fulfilled by the Customer and the receiving Partner in their own systems.

9. Personal data breach

MDR will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Customer's personal data, and will provide the information reasonably available to help the Customer meet its own notification obligations.

10. Deletion and return

Transferred data is not retained and requires no deletion. On deletion of the Customer's Company, MDR deletes the Customer's connected credentials and ends its Contracts; account data is handled as the Privacy Policy describes. Data delivered to a Partner is in the Partner's possession and is that Partner's responsibility.

11. Audit

On written request no more than once a year, MDR will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security measures and any third-party audit reports it holds. Where that is insufficient to meet a legal requirement, MDR will allow an audit by the Customer or an independent auditor bound by confidentiality, at the Customer's expense, at a mutually agreed time and scope.

12. International transfers

MDR processes personal data in the United States. For personal data subject to the GDPR, the UK GDPR or Swiss law, the parties enter into the EU Standard Contractual Clauses (Module Two, controller to processor) and the UK International Data Transfer Addendum, which are incorporated by reference with the Customer as data exporter and MDR as data importer, the details in Section 2 as the annexes, and the security measures in Section 6 as the technical and organisational measures. A signed copy is available on request through contact.

13. CCPA / CPRA

To the extent the CCPA/CPRA applies, MDR is a service provider. MDR will not sell or share the Customer's personal information, retain, use or disclose it for any purpose other than providing the service, or combine it with personal information from other sources except as the law permits for a service provider, and will notify the Customer if it can no longer meet these obligations.

14. Liability

Liability under this DPA is subject to the limitations in the Terms of Service. Nothing in this DPA makes MDR responsible for the Customer's or a Partner's own compliance, for the content of transferred data, or for what a Partner does with data it receives. Because MDR does not store or hold transferred data, the release in Section 17 of the Terms of Service applies to any breach occurring on the systems of the Customer or of a Partner, before a transfer or after delivery.

Questions about this DPA: contact us.