Last Updated: January 2025
"GDPR-compliant data processing with 50 years of trust"
This Data Processing Agreement ("DPA") complies with GDPR, CCPA, and other privacy regulations. It governs how we process personal data on your behalf when providing managed security services.
Key Points: We act as your Data Processor. You remain the Data Controller. We only process data per your instructions. We maintain strict security and confidentiality.
As Data Controller, you:
As Data Processor, we:
We process Personal Data only for the following purposes:
We process Personal Data only based on your documented instructions, which are established through:
If we believe an instruction violates applicable laws, we will inform you immediately and refrain from processing until the matter is resolved.
We may process the following categories of Personal Data while providing services:
Personal Data may relate to:
All personnel with access to Personal Data are:
We implement industry-standard technical security measures:
We maintain organizational security controls:
Our security program aligns with recognized frameworks:
By entering into this DPA, you provide general authorization for us to engage Sub-Processors to assist with service delivery. We maintain responsibility for their compliance with this DPA.
We currently engage the following categories of Sub-Processors:
Note: A complete list of Sub-Processors is available upon request. Contact (603) 285-9680 x5050.
We ensure all Sub-Processors:
If we engage new Sub-Processors or change existing ones:
We will assist you in responding to data subject rights requests, including:
When you receive a data subject rights request:
If a data subject contacts us directly with a rights request:
If we discover a Personal Data breach, we will notify you:
Our breach notification will include:
Following a breach, we will:
Personal Data is primarily stored and processed in:
If Personal Data is transferred outside the EEA or UK, we ensure appropriate safeguards:
For clients subject to GDPR:
You have the right to audit our compliance with this DPA:
We will provide upon request:
If a regulatory authority contacts us regarding your Personal Data:
This DPA remains in effect for the duration of your service agreement with us, and for as long as we process Personal Data on your behalf.
Upon termination of services, we will:
We may retain Personal Data to the extent required by:
Retained data remains subject to confidentiality and security obligations.
The following sections survive termination:
For questions or requests related to this Data Processing Agreement:
Phone: (603) 285-9680 x5050
Main Line: (603) 285-9680
Address: Mainstream Technology Group
We will respond to DPA-related inquiries within 5 business days.
This DPA may be amended to reflect:
Notice: We will notify you of material amendments at least 30 days in advance. Continued use of services constitutes acceptance of amendments.
This DPA, together with your service agreement and our Privacy Policy, constitutes the entire agreement regarding processing of Personal Data. In case of conflict, this DPA takes precedence on data protection matters.
Last Updated: January 2025
We're here to help. Contact our team with any questions or concerns.