Data Processing Addendum
Effective date: August 23, 2026. Last reviewed: August 23, 2026.
1. Purpose and scope
This Data Processing Addendum ("DPA") is incorporated into and forms part of the AdminNow Terms and Conditions between CySec Firm, LLC ("Company") and the customer entity that accepted those Terms ("Customer"). It applies where Company processes Personal Data on Customer's behalf in the course of providing the Service, and reflects the parties' obligations under Applicable Data Protection Law. If there is a conflict between this DPA and the Terms regarding the processing of Personal Data, this DPA controls.
2. Definitions
"Applicable Data Protection Law" means, as applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and any other data protection law applicable to the processing of Personal Data under this DPA. "Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Personal Data Breach" have the meanings given in the GDPR, and equivalent terms in other Applicable Data Protection Law (e.g. "Business," "Service Provider," and "Consumer" under the CCPA/CPRA) are construed accordingly. "Standard Contractual Clauses" means the standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR, adopted by the European Commission (Module Two: Controller-to-Processor), as may be amended or replaced from time to time, and, for transfers subject to UK data protection law, the UK Information Commissioner's International Data Transfer Addendum to those clauses.
3. Roles of the parties
As between the parties, Customer is the Controller (or, where Customer itself processes Personal Data on behalf of a third party, a Processor acting on that third party's instructions) and Company is a Processor, with respect to the Personal Data Customer submits to or generates through the Service ("Customer Personal Data"). Each party will comply with the obligations that Applicable Data Protection Law places on its respective role.
4. Processing of Customer Personal Data
Company will process Customer Personal Data only: (a) to provide, secure, and support the Service; (b) on Customer's documented instructions, including those given through Customer's configuration of the Service and this DPA; and (c) as required by Applicable Data Protection Law, in which case Company will inform Customer of that legal requirement before processing, unless the law prohibits doing so. The subject matter, duration, nature and purpose of processing, and the types of Personal Data and categories of Data Subjects are described in Annex A.
5. Company personnel and confidentiality
Company will ensure that personnel authorized to process Customer Personal Data are subject to an obligation of confidentiality, whether contractual or statutory, and access Customer Personal Data only as necessary to perform their duties.
6. Security measures
Company will implement the technical and organizational measures described in Annex B, designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of processing.
7. Sub-processors
Customer authorizes Company to engage the sub-processors listed in Annex C as of the effective date of this DPA. Company will impose data protection terms on each sub-processor that are no less protective than this DPA, and remains responsible for each sub-processor's performance. Company will give Customer at least fourteen (14) days' notice before authorizing a new sub-processor (by updating Annex C and posting the update at this URL), during which Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, Customer's sole remedy is to terminate the affected part of the Service.
8. International data transfers
Where Company processes Customer Personal Data originating from the European Economic Area, the United Kingdom, or Switzerland in a country that has not been recognized as providing an adequate level of protection, the Standard Contractual Clauses are incorporated into this DPA by reference and apply to that processing, with Customer as "data exporter" and Company (or the relevant sub-processor) as "data importer." Where required, the parties will execute the Clauses in a separate signature page referencing this DPA.
9. Assistance with Data Subject requests
Taking into account the nature of the processing, Company will provide reasonable assistance to Customer, at Customer's expense for anything beyond a routine request, to enable Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law, and to fulfill Customer's obligations regarding data protection impact assessments and consultations with supervisory authorities, to the extent Company is required to provide such assistance under Applicable Data Protection Law.
10. Personal Data Breach notification
Company will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to Company to help Customer meet its own notification obligations. Company's notification is not an acknowledgment of fault or liability.
11. Audits
Company will make available to Customer, on written request no more than once per twelve-month period, information reasonably necessary to demonstrate compliance with this DPA, which may be satisfied by providing a summary of a current third-party audit report or security certification then maintained by Company, in lieu of an on-site audit.
12. Return or deletion of Customer Personal Data
On termination of the Service, Company will delete or return Customer Personal Data in accordance with the retention terms described in the Privacy Policy, except to the extent Company is required by Applicable Data Protection Law or Section 7 of the Terms (Data retention for tax and accounting purposes) to retain some or all of it.
13. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in Section 9 of the Terms.
14. Term
This DPA takes effect on the date Customer accepts the Terms and remains in effect for as long as Company processes Customer Personal Data under the Terms.
15. Governing law
This DPA is governed by the law specified in Section 12 of the Terms, except that the Standard Contractual Clauses incorporated under Section 8 above are governed by their own governing-law terms where those clauses apply.
Annex A — Details of processing
Subject matter: Company's provision of the AdminNow just-in-time local administrator rights service, including the cloud console.
Duration: For the term of the Terms, plus the retention period described in the Privacy Policy.
Nature and purpose: Hosting, storage, transmission, and display of Customer Personal Data to operate the Service - authentication, policy enforcement, workstation enrollment, elevation session tracking, security detection and alerting, and billing.
Categories of Data Subjects: Customer's administrators and end users whose workstations or accounts are managed through the Service.
Types of Personal Data: Name and email address of administrators; Windows account identifiers and elevation session metadata for end users; device and workstation identifiers; security event and evidence data (which may include command lines, file paths, and process metadata generated by end-user activity); billing contact details.
Annex B — Technical and organizational security measures
- Encryption of Personal Data in transit (TLS) between the Service and connecting clients;
- Hashed, salted storage of sign-in codes and no storage of plaintext passwords;
- Role-based access control limiting which Company personnel and Customer administrators can access which categories of data, enforced on every request rather than only at the user-interface level;
- Logical separation of each Customer's data by organization, enforced at the data-access layer;
- Session revocation and audit logging of administrative actions;
- Vendor security measures maintained by Company's infrastructure sub-processor for the physical and network layer underlying the Service.
Annex C — Sub-processors
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, and object storage for the Service | United States (with global edge network for request routing) |
| Stripe, Inc. | Subscription billing and payment processing | United States |
| Email delivery provider | Delivery of sign-in codes and account notices | United States |