Data processing

Data Processing Addendum

A concise overview of FIRMA's data processing commitments for customer operational and personal data.

Last updated

Overview

This Data Processing Addendum ("DPA") describes how FIRMA Systems Inc. processes personal data on behalf of customers using FIRMA services.

This page is provided for general information and should be reviewed by legal counsel before production use.

Roles

The customer is generally the controller or business for personal data submitted to FIRMA. FIRMA generally acts as processor or service provider when processing that data to provide the service.

Each party is responsible for complying with data protection laws that apply to its role, systems, operations, and instructions.

Processing details

FIRMA processes personal data to provide account access, operate farm workflows, support storefront and customer portal functionality, maintain security, troubleshoot issues, process support requests, and meet contractual obligations.

Data categories may include user account data, customer contact data, storefront visitor submissions, order details, operational notes, support communications, and technical logs.

Security measures

FIRMA uses reasonable technical and organizational measures designed to protect customer data, including access controls, managed hosting infrastructure, encryption in transit where supported, logging, and administrative safeguards.

Customers remain responsible for configuring workspaces, assigning appropriate roles, removing inactive users, and protecting their own devices and credentials.

Subprocessors

FIRMA may use subprocessors for hosting, database services, authentication, payments, analytics, email, monitoring, storage, and support operations.

FIRMA will select subprocessors intended to support reliable and secure service delivery. A production DPA should include a maintained subprocessor list and notice process.

Data requests and incidents

FIRMA will reasonably assist customers with data subject requests when the customer cannot fulfill the request through available product functionality.

If FIRMA becomes aware of a confirmed security incident affecting customer personal data, FIRMA will notify affected customers without undue delay and provide available information needed to evaluate the incident.

Return and deletion

Upon termination or request, FIRMA will make reasonable efforts to return, export, or delete customer data according to product capabilities, contractual requirements, backup retention, and legal obligations.

Contact

Questions about this DPA can be sent to legal@firma.farm.