Subject Matter and Instructions
The Processor may process personal data only to provide contracted services to FreshDrop and only on documented instructions from FreshDrop, unless required by law. Processing details should identify data subjects, data categories, purposes, retention, subprocessors, and locations.
Security Measures
The Processor must implement appropriate technical and organizational measures including access control, encryption where appropriate, confidentiality, backups, vulnerability management, incident response, logging, and secure deletion.
Subprocessors and Transfers
The Processor must disclose subprocessors, impose equivalent obligations on them, and notify FreshDrop before material changes. Cross-border transfers must use safeguards required by applicable data protection law.
Assistance and Deletion
The Processor must assist FreshDrop with data subject rights, breach notifications, audits, DPIAs, regulator requests, and compliance evidence. On termination, the Processor must return or delete personal data unless retention is legally required.