Data Processing Agreement

IDM Solutions LLC  ·  Last updated:

This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Service, any Partner Agreement Addendum where applicable, and the separate contract between IDM Solutions LLC ("IDM" or "Processor") and the Client ("Controller"). It sets out the terms on which IDM processes personal data on behalf of the Client in connection with the Services, and is intended to satisfy the requirements of Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and, where applicable, the UK GDPR and the Georgian Law on Personal Data Protection.

Where applicable law, a supervisory authority, or procurement requirements require a separately executed version of this DPA or additional transfer documentation, the parties shall execute such documentation on written request.

In the event of any conflict between this DPA and the Terms of Service on matters of data protection, this DPA shall prevail.

1. Definitions

Terms defined in the GDPR have the same meaning here. In addition:

"Personal Data"
means any information relating to an identified or identifiable natural person that is processed by IDM on behalf of the Client in connection with the Services, as further described in Annex 1.
"Processing"
has the meaning given in the GDPR and includes any operation performed on Personal Data, whether automated or not.
"Data Subject"
means the natural person to whom Personal Data relates, including Authorised Users of the Client such as merchandisers, moderators and administrators.
"Sub-processor"
means any third party engaged by IDM to carry out processing activities on Personal Data on behalf of the Client, as listed in Annex 2.
"Security Incident"
means any confirmed or reasonably suspected breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed under this DPA.
"Services"
has the meaning given in the Terms of Service.
"EEA"
means the European Economic Area.

2. Roles and Relationship of the Parties

2.1 The Client acts as the data controller and IDM acts as the data processor with respect to the Personal Data processed under this DPA.

2.2 The Client determines the purposes and means of processing. IDM processes Personal Data only on documented instructions from the Client, as set out in this DPA and the Terms of Service, unless otherwise required by applicable law.

2.3 Where IDM is required by applicable law to process Personal Data beyond the Client's instructions, IDM shall inform the Client of that legal requirement before processing, unless prohibited by law on grounds of public interest.

2.4 Where the Services are provided under a Partner arrangement, the relevant End Client remains the data controller for its Authorised Users' Personal Data, and IDM remains the data processor. The Partner may act as an administrative intermediary for account management and communication, but does not become the controller solely by managing billing, provisioning, or support coordination. IDM may receive and handle data subject requests directly in accordance with the controller's documented instructions, while copying the relevant End Client and, where practicable, the Partner on material handling steps.

3. Subject Matter, Nature, and Purpose of Processing

3.1 IDM processes Personal Data solely to provide the Services described in the Terms of Service, which includes:

  • Facilitating account creation, authentication, and access management for Authorised Users.
  • Enabling field merchandisers to submit Photoreports with associated geolocation data, images, and timestamps.
  • Storing and displaying uploaded reports and associated metadata for access by the Client's moderators and administrators.
  • Generating and displaying statistical performance data derived from Authorised User activity.
  • Providing application stability monitoring and error tracking.
  • Communicating with the Client and its Authorised Users for administrative and support purposes.

3.2 IDM does not process Personal Data for any purpose other than the provision of the Services, except where required by applicable law or with the Client's prior written authorisation.

4. Categories of Data Subjects and Personal Data

The categories of data subjects and the types of personal data processed under this DPA are set out in detail in Annex 1. In summary:

  • Merchandisers (field employees): name, phone number, job title, company affiliation, precise GPS geolocation, a fraction of image metadata, some device information, IP address, statistical activity data, and error/message log references.
  • Moderators and Administrators: name, phone number, job title, company affiliation, some device information, and IP address.

5. IDM's Obligations as Processor

5.1 Instructions

IDM shall process Personal Data only on the documented instructions of the Client, as set out in this DPA and the Terms of Service, or as otherwise agreed in writing. If IDM believes any instruction infringes the GDPR or applicable data protection law, it shall promptly inform the Client.

5.2 Confidentiality

IDM shall ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations, whether contractual or statutory, and have received adequate data protection training for their role.

5.3 Security

IDM shall implement and maintain the technical and organisational security measures described in Annex 3 to protect Personal Data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures apply to processing under IDM's direct control. IDM bears no responsibility for loss, damage, or unlawful processing caused by the Client's or its Authorised Users' own actions within the platform; such cases are governed by Section 9 of the Terms of Service.

5.4 Sub-processors

IDM shall not engage any new sub-processor without first notifying the Client and providing a reasonable opportunity to object. IDM shall enter into data processing agreements with each sub-processor on terms that impose obligations no less protective than those set out in this DPA. IDM remains fully liable to the Client for the acts and omissions of its sub-processors to the same extent as if IDM had performed the processing itself. The current list of sub-processors is set out in Annex 2.

5.5 Data Subject Rights

IDM shall, taking into account the nature of the processing, assist the Client by appropriate technical and organisational measures in responding to requests from data subjects exercising their rights under applicable data protection law. Where a data subject contacts IDM directly, IDM may acknowledge, log, and handle the request in line with the controller's documented instructions, and will copy the Client on material handling steps. In Partner arrangements, IDM will copy both the relevant End Client and, where practicable, the Partner. The following describes how specific rights are supported:

  • Access, rectification, and portability: The Client's administrators can access and update user account data directly within the platform. Data exports are available in Excel format for report and statistical data, CSV format for structured data, and PNG graph images for statistical visualisations.
  • Erasure: Account data is deleted immediately upon account deletion by an administrator within the platform. Administrators may also bulk-delete a user's reports at the time of account deletion via the in-app interface. Where the Client requires deletion of data held outside the platform UI — including logs in Sentry and server-side log data — the Client must submit a written request to IDM at privacy@idm.llc, and IDM will act on that request promptly.
  • Restriction: The Client may restrict access to specific user data by deleting accounts via the platform.

5.6 Transparency Regarding Data Retention After Deletion

IDM informs the Client of the following data handling behaviours that persist after deletion events:

  • Deleted user references in reports: When a user account is deleted, the user's account record is removed from the database. However, the deleted user's ID and display name are retained within any reports that were uploaded by that user. This is necessary to preserve the integrity and readability of historical report records. The retained name is a reference string only; it is no longer linked to an active account.
  • Soft-deleted facilities: When an administrator deletes a facility via the platform UI, the facility record is soft-deleted — it is removed from all active views but retained in the database to preserve the accuracy of reports historically linked to that facility. If a facility's details are updated and the default behaviour is selected, the original facility record is soft-deleted and a new record is created, ensuring that older reports continue to display the facility data as it was at the time of upload. If the administrator unchecks the default option, both the facility record and all linked report references are updated in place. Soft-deleted records are not surfaced to users and are not used for any purpose other than historical report integrity.
  • Post-termination retention: Following termination of the Client's contract, all Client Data is retained for up to 90 days to allow for final export, after which it is permanently deleted in accordance with Section 11.5 of the Terms of Service.

5.7 Assistance with Compliance Obligations

IDM shall provide reasonable assistance to the Client in connection with the Client's obligations under Articles 32–36 GDPR, including in relation to security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of processing and the information available to IDM.

5.8 Deletion or Return of Data on Termination

Upon expiry or termination of the Terms of Service, IDM shall, at the Client's election:

  • Make available a final export of Client Data in the formats described in Section 5.5 above, within the 90-day retention window described in the Terms of Service.
  • Permanently delete all Personal Data from IDM's active systems upon expiry of the retention period, unless retention is required by applicable law.

IDM shall confirm in writing upon the Client's request that deletion has been completed.

6. Client's Obligations as Controller

6.1 The Client warrants that it has a valid legal basis under applicable data protection law for each category of Personal Data it instructs IDM to process, and that its instructions to IDM are lawful.

6.2 The Client is responsible for ensuring that Data Subjects — in particular, Authorised Users such as merchandisers — have been appropriately informed about the processing of their Personal Data in connection with the Services, including through the IDM Privacy Policy and any additional notices the Client is obliged to provide as employer or data controller. In Partner arrangements, this responsibility remains with the relevant End Client as controller, while the Partner may support notice delivery as an administrative intermediary.

6.3 The Client is responsible for the accuracy, quality, and lawfulness of the Personal Data it submits to the Services.

6.4 The Client shall notify IDM promptly of any changes to its processing instructions that may affect IDM's obligations under this DPA.

6.5 The Client is responsible for the actions of its Authorised Users within the platform, including decisions to delete, update, or share Personal Data.

7. Security Incident Notification

7.1 IDM shall notify the Client without undue delay, and in any event within 48 hours of becoming aware of a confirmed or reasonably suspected Security Incident affecting Personal Data processed under this DPA.

7.2 Notification shall be provided by email to the contact address specified in the contract between the parties and shall include, to the extent known at the time:

  • A description of the nature of the Security Incident, including the categories and approximate number of data subjects and Personal Data records affected.
  • The name and contact details of IDM's data protection contact.
  • A description of the likely consequences of the Security Incident.
  • A description of the measures taken or proposed to address the Security Incident, including steps to mitigate its possible adverse effects.

7.3 Where all required information is not yet available at the time of initial notification, IDM shall provide the information in phases as it becomes available, without undue further delay.

7.4 IDM's notification of a Security Incident does not constitute an admission of fault or liability.

7.5 The Client, as data controller, remains responsible for notifying the relevant supervisory authority and, where required, affected data subjects, in accordance with Articles 33 and 34 GDPR. In Partner arrangements, this responsibility remains with the relevant End Client as controller.

8. International Transfers

8.1 IDM stores all Client Data in data centres located within the EEA. Primary hosting is provided by Cloudways (EU region). Uploaded report images are stored in Cloudflare R2 (EU region), with AWS S3 (EU region) serving as a fallback storage in the event of Cloudflare unavailability.

8.2 No transfer of Personal Data to a country outside the EEA is made by IDM as part of its primary storage or processing infrastructure. However, certain sub-processors listed in Annex 2 are US-based entities (including Sentry, Google, and Amazon Web Services) and may process limited data as part of delivering their services. Each such transfer is governed by the relevant sub-processor's standard data processing agreement and applicable transfer mechanisms (as noted in Annex 2), which IDM has accepted.

8.3 Where applicable law requires additional transfer mechanisms beyond those in place with sub-processors, IDM shall take reasonable steps to implement them and inform the Client.

9. Audit Rights

9.1 IDM shall provide the Client with all information reasonably necessary to demonstrate compliance with its obligations under this DPA and applicable data protection law.

9.2 Upon the Client's written request, IDM shall respond to a reasonable security questionnaire or provide written confirmation of its data processing practices, including confirmation of the security measures described in Annex 3. IDM shall respond to such requests within thirty (30) days.

9.3 IDM shall not be required to permit physical on-site audits or inspections by the Client or any third party appointed by the Client. Where the Client has specific compliance concerns that cannot be addressed by written confirmation or questionnaire responses, the parties shall discuss in good faith whether any additional reasonable steps can be taken.

9.4 The Client may exercise audit rights no more than once per calendar year, unless there are reasonable grounds to believe a specific Security Incident or material compliance failure has occurred.

10. Liability

10.1 Each party's liability under this DPA is subject to the limitations and caps set out in Section 10 of the Terms of Service.

10.2 If IDM is held liable by a supervisory authority or court for damage caused by processing that was carried out contrary to the Client's documented instructions, IDM may seek to recover that portion of any fine or liability that is attributable to the Client's instructions or failures.

10.3 If the Client is held liable for damage caused by IDM's failure to comply with its obligations as processor under this DPA, the Client may seek indemnification from IDM in accordance with Section 10.5 of the Terms of Service.

11. Term and Termination

11.1 This DPA enters into force on the Effective Date of the Terms of Service and remains in effect for as long as IDM processes Personal Data on behalf of the Client.

11.2 Termination of the Terms of Service automatically terminates this DPA, subject to the post-termination obligations in Sections 5.6 and 5.8 of this DPA regarding data retention, export, and deletion. In Partner arrangements, transition and service-continuity effects are additionally governed by the Partner Agreement Addendum.

12. Governing Law

This DPA shall be governed by and construed in accordance with the laws of Georgia, consistent with Section 15 of the Terms of Service. For Clients located in the EU or UK, this DPA is also intended to satisfy the requirements of Article 28 GDPR and UK GDPR respectively, and shall be interpreted accordingly.

Annex 1

Categories of Personal Data and Data Subjects

Data Subjects

Role Description
Merchandisers Field employees of the Client who submit Photoreports
Moderators Client personnel who review, manage, and moderate reports within the platform
Administrators Client personnel responsible for account management, user administration, platform configuration and supervisory functions (also includes all rights from Moderators)

Categories of Personal Data

Category Detail Applies To
Identity data Full name, display name All roles
Contact data Phone number All roles
Professional data Job title, company affiliation All roles
Authentication data Phone number used for login; expiring one-time auth code (valid 10 minutes, no password stored) All roles
Device & network data IP address, device model, OS version, app or browser version, device memory available (for app), some other device information (without persistent device identifiers) All roles
Error & Message log references Username (where logged for debugging), some device context and information, report ID, timestamp, non-sensitive application context data All roles
Precise geolocation GPS coordinates at time of report upload; may be supplemented by network-based location if GPS signal is weak Merchandisers only
Image data Photographs uploaded as part of Photoreports, including some embedded metadata Merchandisers only
Statistical activity and performance data Total reports submitted, images uploaded, work time recorded, session activity and other statistical and performance data Merchandisers only
Historical report references Deleted user's ID and display name retained within reports submitted by that user Merchandisers (post-deletion)
Facility references Soft-deleted facility data retained in database to preserve historical report accuracy Linked to report records
Sensitive Data: No special categories of personal data as defined under Article 9 GDPR are knowingly collected or processed through the Services.

Annex 2

Sub-processors

IDM shall maintain an up-to-date version of this sub-processor list and notify the Client of any additions or replacements in accordance with Section 5.4 of this DPA.

Sub-processor Purpose Data Processed Location Transfer Mechanism
Cloudways Primary application and database hosting All Client Data EU/EEA EU-based infrastructure; IDM's data processing terms with Cloudways
Cloudflare R2 Primary object storage for uploaded report images Image files EU/EEA EU-based infrastructure; accepted under Cloudflare's standard DPA
Amazon Web Services (S3) Fallback object storage for uploaded report images Image files EU/EEA EU-based infrastructure; accepted under AWS standard DPA
Sentry Application error tracking and stability monitoring Username (where logged for debugging), device context, report ID, error timestamp, non-sensitive application context data US (Sentry infrastructure) Accepted under Sentry's standard DPA (including SCCs where applicable)
Google reCAPTCHA Bot and automated abuse prevention on web forms and login flows Behavioural signals, browser/device technical data, interaction metadata, and IP address used to distinguish human users from automated traffic US/global Accepted under Google's standard DPA and SCCs
Google Workspace (Gmail) Business email communication and support correspondence Names, email addresses, message content US/global Accepted under Google's standard DPA and SCCs
Third-party communication platforms (e.g. WhatsApp) Client communication outside the platform, as agreed per client Names, phone numbers, message content Varies by platform Subject to each platform's own data processing terms; used only where adequate protection is available

Annex 3

Technical and Organisational Security Measures

IDM implements the following technical and organisational measures to protect Personal Data processed under this DPA:

Encryption

  • In transit: All data transmitted between client devices and IDM's servers is encrypted using TLS (HTTPS). All API communications are encrypted in transit.
  • At rest: Personal data is protected by AES-256 encryption at the infrastructure storage layer, implemented and managed by Cloudways at the physical disk level. This applies to all data stored on the primary application server, including database contents and associated files.
  • Application-level encryption: Authentication data (one-time auth codes) is additionally encrypted at the application and database layer.

Authentication

  • IDM's platform does not use or store passwords. Authentication is performed exclusively via phone number combined with a one-time auth code delivered to that number.
  • Auth codes expire after 10 minutes from issuance. During the validity window, a code may be used multiple times for the same account (e.g. to support immediate re-login after logout).
  • This approach eliminates risks associated with password storage, credential stuffing, and password reuse.

Access Controls

  • Role-based access controls are enforced within the platform. Access to personal data is limited based on the Authorised User's assigned role (administrator, moderator, or merchandiser).
  • Internal access to production systems and personal data is restricted to IDM personnel who require it to perform their duties.

Security Testing and Vulnerability Management

  • IDM conducts security testing and vulnerability scanning in connection with significant updates or changes to the production environment, upon client request, or on IDM's own initiative where a risk is identified.
  • Security testing is not performed on a fixed routine schedule; it is risk-driven and tied to system change events.

Error Monitoring

  • Application errors or messages are reported to Sentry. Usernames may also be transmitted to Sentry where required for debugging; access to Sentry is restricted to authorised IDM engineering personnel.
  • Persistent device identifiers are stripped from error reports before transmission to Sentry.

Infrastructure and Resilience

  • Primary hosting is provided by Cloudways (EU region), which maintains a 99.99% infrastructure-level uptime SLA.
  • Uploaded report images are stored in Cloudflare R2 (EU region), with AWS S3 (EU region) as an automatic fallback.
  • IDM maintains periodic backups of its database, image files, and other stored data as part of standard operational continuity practice.

Organisational Measures

  • Personnel with access to personal data are subject to confidentiality obligations.
  • IDM reviews its data protection and security practices in connection with product updates and as required by this DPA.

This Data Processing Agreement was last updated on .


This Data Processing Agreement is written in English. Where a translation is provided for convenience, the English version shall prevail in the event of any conflict or ambiguity.