Data Processing Addendum
Effective date: September 4, 2026
Last updated September 4, 2026
This DPA applies to personal data in customer data that HQDIRECTOR CORP processes for a customer while providing a Director service, where the parties have agreed that a DPA applies. The customer generally determines why and how it uses customer data. For processing covered by this DPA, HQDIRECTOR CORP processes that data on the customer's documented instructions, including this DPA, the order, and authorized use of the service. Applicable law and the actual processing determine each party's legal role.
Processing instructions
We process customer data to provide, secure, support, and administer the service; prevent abuse; and comply with applicable law. We will notify the customer if we believe an instruction conflicts with applicable law, unless law prohibits notice. The customer is responsible for the lawfulness of its instructions and customer data.
Processing scope and role boundaries
Customer-directed processing may include organization, membership, role, entitlement, assignment, launcher, and Director-application operational data. HQDirector.com visitor and contact data, MyHQDirector commercial administration, Stripe payment and tax records, and security or audit logs may involve separate corporate responsibilities. This DPA applies only to processing identified as customer data under the applicable agreement; the Privacy Policy describes the broader information categories.
People, security, and assistance
We limit access to personnel and subprocessors with a need to process customer data and require appropriate confidentiality commitments. We will use appropriate technical and organizational measures for the service, notify the customer of a confirmed personal-data incident affecting customer data without undue delay, and provide reasonable assistance with data-subject requests, security inquiries, and impact assessments to the extent required by applicable law and available to us.
Subprocessors and return
The customer authorizes the subprocessors described in the Subprocessor List to process customer data for the stated purposes. We will use a written arrangement requiring materially consistent protection. At the end of the service, we will return or delete customer data according to the applicable service process, unless retention is required by law. This DPA does not make unsupported conclusions about a party's legal status beyond the roles stated above.