
Data Protection Policy & DPA
Including the Data Processing Addendum and Technical & Organisational Measures
Effective August 25, 2026·Version 1.0
Our programme
Data protection principles, governance, privacy by design, personnel controls, and incident management.
Processing on your behalf
The DPA terms: documented instructions, sub-processing, breach notice within 72 hours, audit rights, and transfers.
Security measures
Encryption in transit and at rest, least-privilege access, monitoring, testing, and resilience (Annex B).
1. Purpose and Scope
This Data Protection Policy sets out how SoftwarePac LLC ("SoftwarePac LLC", "we", "us") protects personal data, the responsibilities of our personnel, and the commitments we make to customers whose personal data we process. It applies to all personal data we process in any format, to all of our personnel, contractors, and subcontractors, and to all systems used to deliver our IT services, software-as-a-service products, and licensed software products (the "Services").
Part A describes our internal data protection programme. Part B is our Data Processing Addendum ("DPA"), which applies where we process personal data on behalf of a customer. The Annexes set out processing details, security measures, sub-processors, and retention.
2. Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data, including collection, storage, use, disclosure, and erasure.
- Controller: the party that determines the purposes and means of processing.
- Processor: the party that processes personal data on behalf of a controller.
- Sub-processor: a third party engaged by a processor to process personal data on the controller's behalf.
- Personal data breach: a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
- Data Protection Laws: all laws applicable to the processing of personal data, including the EU General Data Protection Regulation, the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended, the Virginia Consumer Data Protection Act, and comparable U.S. state legislation.
PART A
OUR DATA PROTECTION PROGRAMME
3. Data Protection Principles
We process personal data in accordance with the following principles, and our personnel are trained to apply them:
- Lawfulness, fairness, and transparency: we process personal data on a valid legal basis and tell people clearly what we do with it.
- Purpose limitation: we collect personal data for specified, explicit, and legitimate purposes and do not process it in a manner incompatible with those purposes.
- Data minimisation: we collect only what is adequate, relevant, and limited to what is necessary.
- Accuracy: we take reasonable steps to keep personal data accurate and up to date, and to correct or erase inaccurate data without delay.
- Storage limitation: we keep personal data in identifiable form only as long as necessary for the purposes for which it is processed.
- Integrity and confidentiality: we protect personal data using appropriate technical and organisational security measures.
- Accountability: we document our processing, assess risk, and can demonstrate compliance with these principles.
4. Governance and Responsibilities
Overall accountability for data protection rests with our management. We have appointed a Privacy Lead responsible for maintaining this Policy, overseeing the records of processing, coordinating responses to data subject requests and breaches, managing vendor due diligence, and acting as the contact point for customers and regulators. The Privacy Lead can be reached at info@softwarepac.com.
We have assessed that we are not currently required to appoint a statutory Data Protection Officer, as our core activities do not consist of large-scale regular and systematic monitoring or large-scale processing of special category data. We keep this assessment under review and will appoint a DPO and publish contact details if the position changes. Where we are required to designate an EU or UK representative under Article 27 of the GDPR, we will do so and publish those details.
All personnel are responsible for complying with this Policy. Data protection responsibilities are included in employment terms, contractor agreements, and role descriptions. Breach of this Policy may result in disciplinary action, up to and including termination.
5. Records of Processing and Risk Assessment
We maintain records of processing activities covering the categories of data subjects and personal data, the purposes of processing, recipients, international transfers, retention periods, and security measures, for both our controller and processor activities. These records are reviewed at least annually and on any material change to the Services.
We conduct a Data Protection Impact Assessment before beginning processing likely to result in a high risk to individuals — for example, large-scale processing of sensitive data, systematic monitoring, or the deployment of new technologies with significant privacy implications. Where a DPIA indicates a high residual risk that cannot be mitigated, we will consult the relevant supervisory authority before proceeding.
6. Privacy by Design and by Default
We build data protection into our products and engagements from the outset. This includes assessing privacy impact during solution design, defaulting to the least permissive access settings, minimising the personal data collected by new features, segregating environments so that production personal data is not used in development or testing without pseudonymisation, and requiring privacy review as part of our change management process.
7. Personnel, Training, and Access
- All personnel sign confidentiality undertakings that survive the end of their engagement.
- Background verification is carried out on personnel with access to production systems, to the extent permitted by applicable law.
- Data protection and security awareness training is provided at onboarding and at least annually thereafter, with additional role-specific training for engineering and support staff.
- Access to personal data is granted on a least-privilege, need-to-know basis, approved by the system owner, reviewed at least quarterly, and revoked promptly on role change or departure.
- Access to production environments containing Customer Data requires multi-factor authentication and is logged.
8. Vendor and Sub-Processor Management
Before engaging any vendor that will process personal data, we carry out risk-based due diligence covering their security posture, certifications, sub-processing arrangements, transfer mechanisms, and breach history. Every such vendor is bound by a written contract containing data protection obligations no less protective than those we owe our customers. Vendors are re-reviewed periodically according to their risk tier, and we maintain a current list of sub-processors used in delivering the Services.
9. Data Subject Requests
Where we act as controller, we handle requests to access, correct, delete, restrict, object to, or port personal data in accordance with Data Protection Laws. Requests are logged on receipt, the requester's identity is verified, and a substantive response is provided within the statutory period — generally one month under the GDPR and 45 days under most U.S. state laws — with any permitted extension notified to the requester with reasons.
Where we act as processor and receive a request relating to a customer's data, we will not respond directly except to confirm that the request should be directed to the customer. We will forward the request to the customer without undue delay and provide reasonable assistance in responding.
10. Incident and Breach Management
We maintain a documented incident response plan covering detection, triage, containment, eradication, recovery, notification, and post-incident review. All personnel are required to report suspected incidents immediately through the internal reporting channel. Every incident is logged with an assessment of the risk to affected individuals, actions taken, and notification decisions, whether or not notification is ultimately required.
Where we act as controller and a breach is likely to result in a risk to individuals' rights and freedoms, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, and notify affected individuals where the risk is high. Where we act as processor, we notify the affected customer without undue delay after becoming aware, and provide the information reasonably available to support the customer's own notification obligations. We do not require the customer's approval before taking containment measures necessary to protect data.
The incident response plan is tested at least annually through a tabletop exercise, and findings are used to update the plan.
11. International Transfers
We are established in the United States. Where personal data originating in the EEA, the UK, or Switzerland is transferred to us or to a sub-processor in a third country, we implement an appropriate transfer mechanism — typically the European Commission's Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum where the UK GDPR applies. We carry out a transfer impact assessment considering the laws and practices of the destination country, and apply supplementary measures including encryption in transit and at rest, strict access controls, and a policy of challenging unlawful government access requests and notifying affected customers where legally permitted.
12. Retention and Secure Disposal
Personal data is retained only for as long as necessary for the purpose for which it is processed, in accordance with the retention schedule at Annex D. When the retention period expires, personal data is securely deleted, de-identified, or anonymised. Physical media containing personal data is destroyed using methods that prevent reconstruction, and cloud storage is deleted through provider mechanisms that render data unrecoverable. Deletion from active systems is followed by expiry of the data from backups on the ordinary backup cycle.
13. Audit, Monitoring, and Continuous Improvement
We review this Policy at least annually and whenever there is a material change to our processing, the Services, or applicable law. We conduct periodic internal reviews of access controls, retention practices, and vendor arrangements, and we track and remediate findings. Where the Services are covered by an independent audit or certification, we make the resulting report or certificate available to customers under confidentiality on request.
PART B
DATA PROCESSING ADDENDUM
This DPA applies where SoftwarePac LLC processes personal data on behalf of a customer ("Customer") in providing the Services, and forms part of the agreement between SoftwarePac LLC and the Customer (the "Agreement"). Where this DPA conflicts with the Agreement in relation to the processing of personal data, this DPA prevails.
14. Roles and Scope of Processing
For personal data contained in Customer Data, the Customer is the controller (or a processor acting on behalf of a further controller) and SoftwarePac LLC is the processor. Where the Customer is itself a processor, SoftwarePac LLC acts as sub-processor, and the Customer warrants that it has the necessary authority from the ultimate controller to engage SoftwarePac LLC on these terms. The subject matter, duration, nature, purpose, categories of data, and categories of data subjects are set out in Annex A.
Where the Customer licenses our software and installs it in the Customer's own environment, the Customer is the sole controller of the personal data that software processes and SoftwarePac LLC is neither controller nor processor of that data, as SoftwarePac LLC has no access to it. This DPA applies to such deployments only in respect of (a) licence activation and entitlement data that SoftwarePac LLC receives, for which SoftwarePac LLC is an independent controller, and (b) any period during which the Customer grants SoftwarePac LLC access to its systems or supplies diagnostic material for support or professional services, for which SoftwarePac LLC acts as processor. The Customer is responsible for securing the environment in which self-hosted software runs and for minimising personal data in any diagnostic material it sends.
15. Processing Instructions
SoftwarePac LLC will process personal data only on documented instructions from the Customer, including with regard to international transfers, unless required to do otherwise by law to which SoftwarePac LLC is subject. In that case, SoftwarePac LLC will inform the Customer of the legal requirement before processing, unless the law prohibits such notice on important grounds of public interest. The Agreement, the Order Form, this DPA, and the Customer's configuration and use of the Services constitute the Customer's complete documented instructions. SoftwarePac LLC will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
The Customer is responsible for ensuring it has a lawful basis for the processing it instructs, for the accuracy and legality of Customer Data, and for providing any notices and obtaining any consents required from data subjects.
16. Confidentiality
SoftwarePac LLC ensures that all personnel authorised to process personal data are bound by an appropriate statutory or contractual duty of confidentiality, are trained in data protection, and access personal data only as necessary to perform the Services.
17. Security
SoftwarePac LLC implements and maintains the technical and organisational measures set out in Annex B, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects. SoftwarePac LLC may update these measures from time to time provided that the overall level of protection is not materially reduced.
18. Sub-Processing
The Customer grants SoftwarePac LLC general authorisation to engage sub-processors to process personal data, subject to the conditions in this Section. The current sub-processors are listed in Annex C. SoftwarePac LLC will give the Customer at least thirty (30) days' notice before adding or replacing a sub-processor, by email to the Customer's designated contact or via a subscribable notification list. The Customer may object on reasonable data protection grounds within that period, and the parties will work in good faith to resolve the objection; if no resolution is reached, the Customer may terminate the affected Services without penalty and receive a pro-rata refund of prepaid, unused fees.
SoftwarePac LLC imposes on each sub-processor data protection obligations no less protective than those in this DPA and remains fully liable to the Customer for the performance of each sub-processor's obligations.
19. Assistance to the Customer
- Taking into account the nature of the processing, assisting the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to data subject requests.
- Notifying the Customer without undue delay if it receives a request directly from a data subject relating to Customer Data, and not responding to that request except on the Customer's documented instructions or as required by law.
- Providing reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, taking into account the information available to SoftwarePac LLC.
- Providing reasonable assistance in relation to the security of processing and personal data breach notification obligations.
20. Personal Data Breach Notification
SoftwarePac LLC will notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Data. The notification will describe, to the extent then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a point of contact for further information. SoftwarePac LLC will provide further information as the investigation progresses and will cooperate reasonably with the Customer's own notification obligations. Notification is not an acknowledgement of fault or liability.
21. Audit and Information Rights
SoftwarePac LLC will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA. On written request, and no more than once in any twelve (12) month period unless required by a supervisory authority or following a personal data breach, SoftwarePac LLC will provide its most recent third-party audit report, certification, or completed security questionnaire, subject to confidentiality. Where that information is not sufficient to demonstrate compliance, the Customer may conduct an audit on at least thirty (30) days' written notice, during business hours, without unreasonable disruption to SoftwarePac LLC's operations, at the Customer's expense, and subject to the auditor signing a confidentiality undertaking. Audits will not extend to other customers' data or to SoftwarePac LLC's confidential commercial information.
22. International Transfers under this DPA
The Customer authorises SoftwarePac LLC to transfer personal data to the United States and to the sub-processor locations listed in Annex C. Where such transfer is subject to the GDPR or UK GDPR, the parties agree that the European Commission's Standard Contractual Clauses (Module Two, controller to processor, or Module Three, processor to processor, as applicable) are incorporated into this DPA by reference and apply, supplemented by the UK International Data Transfer Addendum where the UK GDPR applies. For the purposes of those clauses, Annex A serves as the description of transfer, Annex B as the technical and organisational measures, and Annex C as the list of sub-processors. The governing law and forum are those of the Member State or the United Kingdom as required by the applicable module.
23. U.S. State Privacy Law Terms
Where the CCPA as amended, the VCDPA, or comparable U.S. state law applies, SoftwarePac LLC acts as a "service provider" or "processor" and certifies that it will not sell or share personal information, will not retain, use, or disclose personal information for any purpose other than performing the Services specified in the Agreement or as otherwise permitted by law, will not retain, use, or disclose personal information outside the direct business relationship with the Customer, and will not combine personal information received from the Customer with personal information from other sources except as permitted by law. SoftwarePac LLC will comply with applicable obligations and provide the same level of privacy protection as required of the Customer, and will notify the Customer if it determines it can no longer meet these obligations.
24. Return and Deletion
On termination or expiry of the Services, and at the Customer's election, SoftwarePac LLC will return Customer Data to the Customer or delete it. Unless the Customer requests otherwise within thirty (30) days of termination, SoftwarePac LLC will delete Customer Data in accordance with Annex D. SoftwarePac LLC may retain personal data to the extent required by applicable law, and any retained data remains subject to the confidentiality and security obligations of this DPA. Data held in routine backups is deleted on expiry of the applicable backup cycle.
25. Liability and Term
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA takes effect on the effective date of the Agreement and continues until SoftwarePac LLC ceases all processing of personal data on the Customer's behalf. Provisions that by their nature should survive, including confidentiality, security, and deletion obligations, survive termination.
ANNEX A — Details of Processing
| Item | Description |
|---|---|
| Subject matter | Provision of IT services and SaaS products as described in the Agreement and applicable Order Form |
| Duration | For the term of the Agreement, plus the return and deletion period set out in Annex D |
| Nature and purpose | Hosting, storage, transmission, backup, access management, technical support, troubleshooting, maintenance, migration, and related processing necessary to deliver the Services. For self-hosted licensed software, limited to support access granted by the Customer and diagnostic material supplied by the Customer |
| Categories of data subjects | Customer's personnel, contractors, and authorised users; Customer's own clients and end users; Customer's business contacts and suppliers; any other individuals whose data the Customer submits |
| Categories of personal data | Identity and contact data; account credentials and authentication data; job title and organisational role; business communications and correspondence; usage, log, and device data; billing and transaction data; any other personal data contained in Customer Data at the Customer's discretion |
| Special category data | Not anticipated. The Customer must not submit special category data without prior written agreement and any additional safeguards agreed by the parties |
| Frequency of transfer | Continuous, for the duration of the Agreement |
| Processing locations | United States, and the sub-processor locations listed in Annex C |
ANNEX B — Technical and Organisational Measures
B.1 Organisational security
- Documented information security policies, reviewed at least annually and approved by management.
- Defined security roles and responsibilities, with a named owner for the security programme.
- Risk assessment process covering assets, threats, and mitigations.
- Confidentiality obligations and, where lawful, background verification for personnel with production access.
- Security awareness training at onboarding and annually, with role-specific training for engineering and support.
- Documented onboarding and offboarding procedures, including prompt revocation of access.
- Vendor risk management and contractual data protection obligations for all sub-processors.
B.2 Access control
- Least-privilege, role-based access control with documented approval by the system owner.
- Unique named accounts; shared or generic accounts prohibited for administrative access.
- Multi-factor authentication enforced for administrative and remote access to production.
- Password policy enforcing complexity, rotation on compromise, and storage using salted one-way hashing.
- Quarterly access reviews and immediate revocation on role change or departure.
- Logical separation of customer environments and tenant data within multi-tenant systems.
B.3 Encryption and data protection
- Encryption in transit using TLS 1.2 or higher for all external connections.
- Encryption at rest for production databases, object storage, and backups using AES-256 or equivalent.
- Key management using a managed key service, with restricted access and documented rotation.
- Pseudonymisation or synthetic data used in non-production environments; production personal data not used for development or testing without approval and safeguards.
- Full-disk encryption and endpoint protection required on all company devices accessing personal data.
B.4 Operational and network security
- Network segmentation, firewalling, and default-deny ingress rules.
- Centralised logging of authentication, administrative, and security-relevant events, with tamper-resistant retention.
- Monitoring and alerting for anomalous activity and availability degradation.
- Vulnerability scanning and risk-based patching, with critical vulnerabilities remediated on an expedited timeline.
- Periodic penetration testing by a qualified third party, with tracked remediation of findings.
- Malware protection on endpoints and, where applicable, on servers.
- Change management with peer review, testing, and approval before production deployment.
- Secure software development practices including code review, dependency scanning, and secrets management.
B.5 Physical security
- Production infrastructure hosted in facilities operated by reputable cloud providers holding recognised certifications such as ISO 27001 and SOC 2.
- Physical access to hosting facilities controlled by the provider, with 24/7 monitoring, access logging, and environmental controls.
- Office access controls, visitor management, and clear-desk and clear-screen expectations for personnel.
B.6 Resilience and continuity
- Automated backups with defined frequency, encryption, and access restrictions.
- Periodic restoration testing to verify backup integrity.
- Documented business continuity and disaster recovery plans with defined recovery objectives, reviewed and tested at least annually.
- Redundancy and failover capability for critical components, appropriate to the service tier.
B.7 Incident management
- Documented incident response plan with defined severity levels, roles, and escalation paths.
- Internal reporting channel for suspected incidents, available to all personnel.
- Breach notification to affected customers without undue delay and within 72 hours of awareness.
- Root cause analysis and post-incident review with tracked corrective actions.
- Annual tabletop testing of the incident response plan.
ANNEX C — Sub-Processors
SoftwarePac LLC engages the categories of sub-processors below to deliver the Services. The current itemised list, including entity names and processing locations, is maintained by SoftwarePac LLC and provided to customers on request to info@softwarepac.com, with notice of changes as set out in Section 18.
| Category | Purpose of processing | Typical location |
|---|---|---|
| Cloud infrastructure and hosting | Hosting of application, database, and storage infrastructure | United States |
| Backup and disaster recovery | Encrypted backup storage and recovery capability | United States |
| Payment processing | Processing of subscription and service payments | United States |
| Email and notification delivery | Delivery of transactional, service, and support communications | United States |
| Customer support and ticketing | Management of support requests and correspondence | United States |
| Product and web analytics | Aggregated usage measurement and service improvement | United States / EU |
| Error and performance monitoring | Diagnostic logging and application reliability monitoring | United States |
| Identity and authentication services | Authentication, single sign-on, and multi-factor authentication | United States |
| Professional advisers and auditors | Legal, accounting, and audit services | United States |
ANNEX D — Retention and Deletion Schedule
| Data category | Retention period | Disposal method |
|---|---|---|
| Customer Data in SaaS products | Term of the Agreement, then deleted within 30 to 90 days of termination unless return is requested | Secure deletion; backups expire on cycle |
| Account and user profile data | Duration of the relationship plus up to 24 months | Secure deletion or anonymisation |
| Billing, invoice, and tax records | 7 years from the end of the relevant financial year | Secure deletion after statutory period |
| Licence, activation, and entitlement records | Duration of the licence, plus 7 years for perpetual licences | Secure deletion |
| Support diagnostics and log files supplied by customers | Up to 12 months from ticket closure | Secure deletion |
| Support tickets and correspondence | Up to 3 years from ticket closure | Secure deletion |
| Security, audit, and access logs | 12 to 24 months, longer if required for an investigation | Automated expiry |
| Backups | Rolling cycle, typically 30 to 90 days | Automatic overwrite on cycle expiry |
| Marketing contact data | Until opt-out or 24 months of inactivity, whichever is earlier | Secure deletion; suppression list retained |
| Incident and breach records | 6 years from closure, for accountability purposes | Secure deletion |
| Recruitment records (unsuccessful) | Up to 12 months unless the candidate consents to longer | Secure deletion |
Contact and Version Control
Questions about this Policy, requests for our sub-processor list or audit documentation, and data protection enquiries should be directed to:
SoftwarePac LLC
4727 Valley View Blvd. NW #1096
Roanoke, VA 24012, United States
Email: info@softwarepac.com
This Policy is reviewed at least annually. Superseded versions are retained for accountability purposes.

