Data Processing Addendum
Version 2026.09.20 | Effective September 20, 2026
Source package: Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement between Tactically Safe LLC ("TacSafe") and Customer for use of TacSafe. Capitalized terms not defined here have the meaning in the governing agreement.
1. Definitions
"Applicable Data Protection Law" means privacy, data protection, and breach-notification law that applies to TacSafe processing of Customer Personal Data. "Customer Personal Data" means personal data, personal information, or similar regulated information contained in Customer Content and processed by TacSafe on Customer's behalf. "Security Incident" means confirmed unauthorized access to, acquisition of, or disclosure of Customer Personal Data in TacSafe systems, excluding unsuccessful attempts that do not compromise data.
2. Roles and instructions
Customer is the controller/business or equivalent party for Customer Personal Data, and TacSafe is the processor/service provider/contractor, except when TacSafe processes limited account, billing, security, and business-administration data for its own lawful purposes. TacSafe will process Customer Personal Data only on documented Customer instructions, including the governing agreement and Customer use of the Service, unless required by law.
3. Purpose limitation and U.S. state terms
TacSafe will not sell Customer Personal Data, retain/use/disclose it outside the direct business relationship except as permitted by Applicable Data Protection Law, or combine it with personal data received from another person except as permitted for service-provider/processor purposes. TacSafe will notify Customer if it can no longer meet an applicable processor or service-provider obligation and will reasonably cooperate with Customer to stop and remediate unauthorized use.
4. Confidentiality and personnel
TacSafe will ensure persons authorized to process Customer Personal Data are subject to confidentiality obligations and receive access only as necessary for their responsibilities.
5. Security measures
TacSafe will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of Customer Personal Data and the Service. Measures include, as applicable:
- role-based and least-privilege access controls;
- tenant-aware database authorization and row-level access restrictions;
- private object storage and controlled file-delivery mechanisms;
- TLS for data in transit and provider-supported encryption at rest;
- MFA and strengthened controls for privileged access where configured;
- secret management and separation of production credentials from source code;
- logging, monitoring, vulnerability remediation, and secure development practices;
- backup, recovery, business-continuity, and incident-response procedures appropriate to the Service;
- human-controlled production promotion and restrictions on autonomous engineering-agent production authority.
6. Subprocessors
Customer authorizes TacSafe to use subprocessors to provide the Service. TacSafe will impose data-protection obligations on subprocessors that are materially consistent with this DPA to the extent required by law. TacSafe remains responsible for its contractual obligations concerning subprocessor processing.
TacSafe will maintain a current Subprocessor List. Where required by law or contract, TacSafe will provide notice of a new material subprocessor and a reasonable period for Customer to object on legitimate data-protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected processing service without penalty for the unused prepaid portion attributable to that service.
7. Assistance with individual rights
Taking into account the nature of processing, TacSafe will provide reasonable assistance to Customer in responding to verified requests to access, correct, delete, restrict, or export Customer Personal Data where Customer cannot reasonably fulfill the request through available Service functionality.
8. Security Incidents
TacSafe will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data and will provide information reasonably available regarding the nature of the incident, affected data, remediation, and recommended Customer actions. Notification is not an admission of fault or liability. Customer is responsible for regulatory or individual notifications unless law requires TacSafe to notify directly.
9. Return and deletion
During the subscription term, Customer may use available export functionality to retrieve Customer Content. Following termination, the Customer workspace may remain in restricted archive status for 30 days. After that period, Customer Personal Data is scheduled for permanent deletion from production and primary storage, unless retention is legally required. Backup copies may remain until overwritten or expired through normal disaster-recovery cycles and will remain protected and unavailable for ordinary use.
10. Audits and information
Upon reasonable written request, TacSafe will provide information reasonably necessary to demonstrate compliance with this DPA, which may include security questionnaires, policies, architecture summaries, or third-party reports that TacSafe lawfully possesses. If legally required and documentary information is insufficient, Customer may request an audit no more than once per year at Customer expense, during normal business hours, subject to reasonable scope, confidentiality, security, and non-disruption requirements.
11. International transfers
If Applicable Data Protection Law requires a transfer mechanism for Customer Personal Data transferred internationally, the parties will use the applicable approved contractual clauses or another lawful mechanism. The parties will complete required annexes based on actual processing locations and subprocessors.
12. Sensitive and regulated data
Unless TacSafe expressly agrees in writing to specialized handling, Customer will not submit protected health information subject to HIPAA, payment card data for storage in TacSafe, biometric templates used for identification, classified information, or other data subject to specialized regulatory regimes not contemplated by the Service. Workplace incident or credential records may contain sensitive information; Customer is responsible for minimizing such content to what is necessary.
13. Precedence
If this DPA conflicts with the governing agreement regarding processing of Customer Personal Data, this DPA controls for that processing. Otherwise the governing agreement remains in effect.
Tactically Safe LLC
- By
- Name
- Title
- Date
Customer
- By
- Name
- Title
- Date
Included exhibit
Annex 1 - Processing Details
Version 2026.09.20 | Effective September 20, 2026
| Item | Description |
|---|---|
| Subject matter | Provision of TacSafe construction-safety SaaS, including account administration, document processing, storage, safety workflows, AI-assisted features, credentials, incidents, project content, reporting, and support as enabled by Customer. |
| Duration | Subscription term plus the 30-day restricted archive period and limited backup/legal retention described in the DPA. |
| Data subjects | Customer administrators, employees, workers, contractors, applicants or visitors if Customer enters their data, and business contacts. |
| Personal data | Names, contact information, account identifiers, organization/role, credential and training records, evaluations, incident information, project assignments, photographs, files, comments, authentication/security metadata, usage logs, and support communications. |
| Processing operations | Collection, transmission, storage, organization, access, retrieval, search, extraction, classification, AI-assisted analysis, display, export, backup, security monitoring, support, and deletion. |
| Special categories | Not intentionally required. May be present in Customer incident or personnel content if Customer submits it. Customer should minimize sensitive data. |
| Frequency | Continuous or on-demand during Customer use of the Service. |
Included exhibit
Annex 2 - Security Measures
Version 2026.09.20 | Effective September 20, 2026
| Area | Measures |
|---|---|
| Access control | Least privilege, role-based access, tenant scoping, privileged-access controls, user lifecycle controls. |
| Authentication | Managed authentication, secure credential handling, MFA for privileged access where configured. |
| Data isolation | Tenant-aware database policies and application-layer authorization. |
| Storage | Private object storage and controlled signed/authorized access patterns. |
| Encryption | TLS in transit; infrastructure-provider encryption at rest. |
| Development | Code review, testing, controlled changes, security remediation, human production authority. |
| Secrets | Secrets stored outside source code; production secrets restricted. |
| Logging | Authentication, security, and operational logging appropriate to service operation. |
| Resilience | Managed backups/recovery and provider redundancy appropriate to the selected architecture. |
| Incident response | Investigation, containment, remediation, evidence preservation, Customer notice as required. |
| Vendor controls | Data-processing agreements and security review for material subprocessors. |
| Deletion | 30-day restricted archive after cancellation/termination, then scheduled deletion from production/primary storage, subject to backups/legal holds. |
