Schedule B — Data Processing Addendum (DPA)
This Data Processing Addendum ("DPA") is incorporated by reference into, and forms Schedule B of, the Phishing Simulation & Security Awareness Training Services Agreement (the "Agreement") between Digitize Solutions ("Processor") and the Client identified in the Agreement ("Controller"). It is accepted as part of the same single-click acceptance flow described in the Agreement — the client does not sign this separately.
1. Roles
1.1 With respect to personal data of Controller's employees processed via the Platform (the "Personal Data"), Controller is the data controller and Processor is the data processor, as those terms are defined in Regulation (EU) 2016/679 (GDPR) and, where applicable, Lebanon's Law No. 81/2018 on Electronic Transactions and Personal Data.
2. Subject matter, duration, nature and purpose of processing (GDPR Art. 28(3))
| Item | Description |
|---|---|
| Subject matter | Provision of simulated phishing campaign delivery, click/training-completion tracking, and reporting services via the Platform |
| Duration | For the term of the Agreement, plus the retention period specified in Clause 4.3 of the Agreement (default 12–24 months post-collection, or Controller-requested earlier deletion) |
| Nature of processing | Automated collection, storage, and analysis of email delivery/interaction events; automated email sending; AI-assisted content generation and reporting (see Clause 6) |
| Purpose | Security awareness training and phishing-susceptibility measurement for Controller's own employees, at Controller's request and under Controller's authorization (see the Agreement, Clause 2) |
3. Categories of data subjects and personal data
- Data subjects: Controller's employees who are Authorized Recipients under the Agreement (Schedule A).
- Categories of Personal Data processed:
- Employee name and work email address
- Department/team (if provided by Controller)
- Campaign interaction events: email sent/delivered/opened/clicked timestamps, training-started/completed/quiz-result timestamps
- IP address and basic device/browser metadata captured at the moment of a tracked click (for security/anti-fraud purposes and to render the training page correctly)
- No special categories of data (GDPR Art. 9) are intentionally processed. Controller must not upload special-category data (health, biometric, etc.) into any freeform fields on the Platform.
4. Processor obligations (GDPR Art. 28(3) checklist)
Processor shall:
(a) process Personal Data only on Controller's documented instructions (including instructions embodied in the Agreement and Controller's configuration choices on the Platform), unless required to do otherwise by Lebanese or EU law, in which case Processor will inform Controller of that legal requirement before processing, unless prohibited from doing so;
(b) ensure that persons authorized to process the Personal Data (Processor's employees/contractors) are bound by confidentiality obligations;
(c) implement appropriate technical and organizational security measures per Annex III (Art. 32 GDPR);
(d) respect the conditions in Clause 5 (Sub-processors) for engaging another processor;
(e) taking into account the nature of the processing, assist Controller by appropriate technical and organizational measures for fulfilling Controller's obligation to respond to data subject rights requests (access, rectification, erasure, portability, objection);
(f) assist Controller in ensuring compliance with GDPR Art. 32–36 (security, breach notification, data protection impact assessments), taking into account the nature of processing and information available to Processor;
(g) at Controller's choice, delete or return all Personal Data to Controller at the end of the provision of services, and delete existing copies unless applicable law requires storage;
(h) make available to Controller information necessary to demonstrate compliance with this DPA and Art. 28 GDPR, and allow for and contribute to audits, including inspections, conducted by Controller or an auditor mandated by Controller, on reasonable prior notice and no more than [once per 12 months] absent a security incident.
5. Sub-processors
5.1 Controller provides general authorization for Processor to engage the following sub-processors as of the Effective Date, each processing Personal Data only to the extent necessary to provide the corresponding function:
| Sub-processor (category) | Function | Data flow note |
|---|---|---|
| Cloud infrastructure provider (AWS or Azure — TBD) | Database, compute, object storage hosting | EU region selected for data residency where available |
| Amazon SES (or equivalent email sending provider) | Simulated campaign email delivery | Sends to Authorized Recipients only, per domain verification |
| Anthropic (Claude API) | AI-generated campaign content, personalized explanations, report narratives, chatbot | Receives campaign metadata/content and click-context data as needed to generate the specific output; does not receive full employee PII beyond what's needed for a given generation call |
| Cloudflare (Stream/Mux for video; WAF/DDoS for the website) | Training video delivery; website protection | Video delivery may see employee IP address during training playback |
| Provider's selected payment processor | Payment processing for Controller's subscription | Processes Controller's own billing data, not employee Personal Data |
5.2 Processor will provide at least [30] days' notice before adding or replacing a sub-processor that will process Personal Data, via [the Platform dashboard / email to Controller's main contact]. Controller may object on reasonable data-protection grounds within that notice period; if unresolved, Controller may terminate the affected part of the Services as its exclusive remedy.
5.3 Processor remains liable for each sub-processor's compliance with data protection obligations equivalent to those in this DPA.
6. AI processing note
Where AI features (campaign content generation, personalized explanations, report narratives, chatbot) process Personal Data via a third-party AI provider (currently Anthropic), Processor confirms: (a) data sent to the AI provider is limited to what's necessary for the specific generation task (e.g., a click event's associated template content and metadata — not a full employee record); (b) the AI provider's data retention/training-use terms for API usage do not include using submitted data to train their models, per standard commercial API terms — confirm and cite the specific applicable terms once the AI vendor agreement is finalized.
7. Security Measures
- Encryption of Personal Data in transit (TLS) and at rest (cloud provider-managed encryption on the Postgres database and object storage).
- Access controls: role-based access to client dashboards; MFA required on client admin accounts and Processor staff accounts with production data access.
- Network protection: Cloudflare WAF/DDoS mitigation, rate limiting on sensitive endpoints.
- Audit logging of admin actions (campaign launches, employee list changes, report access).
- Automated backups with tested restore procedures (Postgres point-in-time recovery).
- Data minimization: AI processing limited to task-relevant data (Section 6); retention limits per Clause 4.3 of the Agreement.
- Incident response runbook; breach notification to Controller without undue delay and in any event within [48–72] hours of Processor becoming aware of a Personal Data breach, including known details of the breach, likely consequences, and measures taken/proposed.
8. Term
This DPA remains in effect for as long as Processor processes Personal Data on Controller's behalf under the Agreement, and survives termination to the extent needed to govern deletion/return of Personal Data per Clause 4(g) above.