Legal

Data Processing Addendum

Draft - pending attorney review

01

Overview

This Data Processing Addendum ("DPA") forms part of the agreement between the Department customer (the "Controller") and WhyUAscii LLC, which operates RescueShift (the "Processor"), for the provision of the RescueShift service. It applies where and to the extent WhyUAscii LLC processes personal data on behalf of a Department customer. Where the Controller has signed a Master Service Agreement (MSA) with WhyUAscii LLC, this DPA is incorporated into it. Where they conflict on data-protection matters, this DPA controls. WhyUAscii LLC is a limited liability company based in Florida, United States.

02

Definitions

"Controller," "Processor," "Personal Data," "Processing," "Data Subject," and "Subprocessor" have the meanings given in applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and applicable U.S. state privacy laws. "Controller" means the Department customer that determines the purposes and means of processing. "Processor" means WhyUAscii LLC, acting on the Controller's documented instructions.

03

Scope, Nature, Purpose, and Duration

Subject matter: WhyUAscii LLC processes personal data to provide the RescueShift scheduling and tracking service. Nature and purpose: hosting, storing, organizing, and displaying member and scheduling data so the Controller can operate its schedule, including shift patterns, teams, rosters, staffing requirements, calendars and events, trades, training and certification records, and related account information. Duration: for the term of the RescueShift service, plus the limited period needed to return or delete data on termination. Categories of data subjects: the Controller's department members, administrators, and invited users. Categories of personal data: name and contact details (email, phone), nickname and profile picture, rank, badge number, hire date, duty roles, station and apparatus assignments, schedule and event data (which may include PTO and sick time), trades, and training and certification records (including license numbers and expiration dates). Special-category data is not requested; the Controller should not enter it.

04

Processing Instructions

WhyUAscii LLC will process personal data only on the documented instructions of the Controller, including with regard to international transfers, unless required to act otherwise by law (in which case it will inform the Controller unless the law prohibits it). The Controller's instructions are set out in this DPA, the MSA, and the Controller's configuration and use of the service. If WhyUAscii LLC believes an instruction violates applicable data protection law, it will inform the Controller without undue delay.

05

Confidentiality

WhyUAscii LLC ensures that personnel authorized to process personal data are bound by appropriate confidentiality obligations and access personal data only as needed to deliver and support the service.

06

Security Measures

WhyUAscii LLC maintains technical and organizational measures appropriate to the risk, including: encryption of data in transit (HTTPS/TLS) and encryption at rest by our infrastructure host; access controls and role-based access; tenant isolation between departments and deny-by-default row-level security in the database; authentication with rate limiting and account lockout; audit logging of administrative actions; and periodic review of its subprocessors' security posture. The Controller is responsible for configuring roles and access within its department appropriately.

07

Subprocessors

The Controller provides general authorization for WhyUAscii LLC to engage the following subprocessors to deliver the service:

Amazon Web Services (AWS): hosting and data storage infrastructure (United States). Supabase: managed database platform. Stripe: subscription billing and payment processing. RevenueCat: mobile subscription management for App Store and Google Play purchases. PostHog: product and web analytics, including masked session replay. Resend: transactional and notification email delivery. Expo Push (with the Apple Push Notification service and Google Firebase Cloud Messaging): push notification delivery. Cloudflare: bot-protection and CAPTCHA challenges (Turnstile) on login and signup. Receives visitor IP address and browser challenge signals. MXRoute: inbound email hosting for our support mailbox. Receives the sender address and content of emails sent to our support address. Google AdMob and Google AdSense: advertising on the free tier only.

WhyUAscii LLC remains responsible for its subprocessors' performance and imposes data-protection terms on them no less protective than this DPA. WhyUAscii LLC will give the Controller prior notice of any intended addition or replacement of a subprocessor so the Controller has an opportunity to object on reasonable data-protection grounds.

08

Assistance with Data Subject Rights

Taking into account the nature of the processing, WhyUAscii LLC will assist the Controller with appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects to exercise their rights (such as access, correction, deletion, portability, restriction, and objection). Where a data subject contacts WhyUAscii LLC directly about Controller data, WhyUAscii LLC will refer them to the Controller.

09

Assistance with Compliance

Taking into account the nature of processing and the information available to it, WhyUAscii LLC will provide reasonable assistance to the Controller with data-protection impact assessments, prior consultations with supervisory authorities, and the Controller's obligations to keep personal data secure, to the extent applicable to the processing under this DPA.

10

Breach Notification

WhyUAscii LLC will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide information reasonably available to it to help the Controller meet its own notification obligations.

11

Records and Audits

WhyUAscii LLC will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency limits, and in a manner that does not compromise the security or data of other customers. Reasonable documentation may be provided in place of an on-site audit where sufficient.

12

International Transfers

Where processing involves transferring personal data outside the EEA, UK, or another restricted jurisdiction, WhyUAscii LLC and its subprocessors rely on lawful transfer mechanisms, such as the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated by reference where required by applicable law.

13

Return and Deletion of Data

Upon termination of the RescueShift service, WhyUAscii LLC will, at the Controller's choice, delete or return the Controller's personal data and delete existing copies, unless retention is required by law. Deletion from active systems generally occurs within 30 days of the request, and backups expire on their normal cycle. Departments can export their data while the subscription is active.

14

GDPR Article 28 and General Terms

This DPA is intended to satisfy Article 28 of the GDPR and the equivalent UK GDPR requirements. Each party will comply with its obligations under applicable data protection law. This DPA supplements, and does not replace, obligations under applicable law. Except as amended here, the terms of the MSA and Terms of Service remain in effect, and liability under this DPA is subject to the limitations of liability in those agreements.

15

Contact Us

To request a signed copy of this DPA or to discuss data-processing questions, contact eddy@whyuascii.com.