Data Processing Agreement

Effective July 1, 2026. This Data Processing Agreement supersedes and replaces all prior versions. Download PDF

This Data Processing Agreement (the “Agreement”) between Provider (sometimes referred to as “Provider,” “we,” “us,” or “our”), and the Client found on the applicable Order (sometimes referred to as “you,” or “your,”) and, together with the Order, Master Services Agreement, Schedule of Services, and other relevant Service Attachments, forms the Agreement between the parties the terms to which the parties agree to be bound.

The parties agree as follows:

1. Health Insurance Portability and Accountability Act (“HIPAA”) Data Processing

This Agreement documents the safeguards imposed upon the parties to protect health information that is subject to the Health Insurance Portability and Accountability Act (“HIPAA”). If Provider is engaged as a “Business Associate” under HIPAA, then this Agreement shall apply to Provider’s activities as a Business Associate. If HIPAA applies to Provider’s activities as a Business Associate, in Order to demonstrate the parties’ compliance with HIPAA, this Agreement applies to each agreement between Provider or any of Provider’s Affiliates and Client or any of Client’s Affiliates under which Provider engages protected health information as part of its performance.

a. Definitions

The following terms used in this Agreement have the same meanings as those terms in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

Specific Definitions:

b. Obligations of Business Associate

Business Associate agrees to:

c. Permitted Uses and Disclosures

d. Privacy Practices and Restrictions

e. Permissible Requests

Covered entity shall not request Business Associate to use or disclose protected health information in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by covered entity.

2. Gramm-Leach-Bliley Act (“GLBA”) Data Processing

This section documents the safeguard standards imposed to protect Client financial information subject to the Gramm-Leach Bliley Act (“GLBA”). To the extent Provider’s services constitute processing of financial information governed by GLBA, these provisions shall apply.

a. Definitions

All capitalized terms in this Addendum which are not otherwise defined in this Addendum or in the MSA have the meaning set forth in Title V of the Gramm-Leach-Bliley Act (P. L. 106-102; 15 USC §6801 et seq.) and the regulations issued pursuant thereto by the Financial Institution’s Functional Regulator.

b. Receipt of Information

To perform its duties under the Agreement, Provider is authorized and permitted to receive, hold and, to the extent necessary, review Nonpublic Personal Information of Client in order to provide services for Client at Client’s direction as provided under the MSA. Provider may further use and disclose Nonpublic Personal Information for the proper management and administration of the business of Provider.

c. Obligations of Service Provider

Provider will take reasonable steps to:

d. Permitted Uses and Disclosures

Provider may disclose the information received by it under the Agreement only if the disclosure is required by law.

e. Permissible Requests

Client shall not request Provider to use or disclose Nonpublic Personal Information in any manner that would not be permissible Title V of the Gramm-Leach-Bliley Act (P. L. 106-102; 15 USC §6801 et seq.) and the regulations issued pursuant thereto if done by Client.

3. Department of Defense Standards for Controlled Unclassified Information (“CUI”)

This section documents the safeguards imposed to protect CUI subject to the DoD and CMMC’s standards. To the extent Provider’s services involve CUI subject to DoD or CMMC standards or regulations, these provisions shall apply.

a. System Environment. Provider will prepare a detailed description of system boundaries, system interconnectedness, and key devices.

b. Requirements. Provider will thoroughly describe how the CMMC requirements have been implemented for each of the following:

4. California Consumer Privacy Act

This section documents the safeguard standards imposed to protect Client information subject to the California Consumer and Privacy Act (“CCPA”). To the extent Provider’s services constitute processing of personal information governed by CCPA, these provisions shall apply.

a. Definitions

b. Roles. The parties acknowledge and agree that with regard to the processing of Client Personal Information performed solely on behalf of Client, Provider is a Service Provider and receives Client Personal Information pursuant to the business purpose of providing the Services to Client in accordance with the Agreement.

c. No Sale of Client Personal Information to Provider. Client and Provider hereby acknowledge and agree that in no event shall the transfer of Client Personal Information from Client to Provider pursuant to the Agreement constitute a sale of information to Provider, and that nothing in the Agreement shall be construed as providing for the sale of Client Personal Information to Provider.

d. Limitations on Use and Disclosure. Provider is prohibited from using or disclosing Client Personal Information for any purpose other than the specific purpose of performing the Services specified in the Agreement, the permitted business purposes set under applicable law, and as required under applicable law. Provider hereby certifies that it understands the foregoing restriction and will comply with it in accordance with the requirements of applicable U.S. Data Protection Laws.

e. Data Subject Access Requests. Provider will reasonably assist Client with any data subject access, erasure or opt-out requests and objections. If Provider receives any request from data subjects, authorities, or others relating to its data processing, Provider will without undue delay inform Client and reasonably assist Client with developing a response (but Provider will not itself respond other than to confirm receipt of the request, to inform the data subject, authority or other third party that their request has been forwarded to Client, and/or to refer them to Client, except per reasonable instructions from Client). Provider will also reasonably assist Client with the resolution of any request or inquiries that Client receives from data protection authorities relating to Provider, unless Provider elects to object such requests directly with such authorities.

5. Colorado Privacy Act

This section documents the safeguard standards imposed to protect Client information subject to the Colorado Privacy Act (6-1-1301) (“CPA”). To the extent Provider’s services constitute processing of personal information governed by CPA, these provisions shall apply.

Provider shall adhere to the instructions of the controller and assist the controller to meet its obligations under the CPA.

Taking into account the nature of processing and the information available to Provider, Provider shall assist the controller by:

Notwithstanding the instructions of the controller, Provider shall:

Taking into account the context of processing, Provider shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk and establish a clear allocation of the responsibilities between Provider and the controller to implement the measures.

Processing by Provider must be governed by a contract between the controller and Provider that is binding on both parties and that sets out:

6. Connecticut Privacy Act

This section documents the safeguard standards imposed to protect Client information subject to the Connecticut SB 12-2 (“Conn Act”). To the extent Provider’s services constitute processing of personal information governed by Conn Act, these provisions shall apply.

Provider shall adhere to the instructions of a controller and shall assist the controller in meeting the controller’s obligations under the Conn Act. Such assistance shall include:

Provider shall have a written contract with the controller that will govern the Provider’s data-processing procedures with respect to processing performed on behalf of the controller. The contract shall be binding and clearly set forth instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing and the rights and obligations of both parties. The contract shall also require that Provider:

Provider shall provide a report of such assessment to the controller upon request.

For purposes of the Conn Act, the following definitions apply:

7. New York SHIELD

Provider maintains a comprehensive, written information security program that contains administrative, technical, and physical safeguards that are appropriate to (a) the size, scope and type of Provider’s business; (b) the amount of resources available to Provider; (c) the type of information that Provider will store; and (d) the need for security and confidentiality of such information. The Security Exhibit may be updated by Provider from time-to-time.

Provider’s security program is designed to:

Without limiting the generality of the foregoing, Provider’s security program includes:

1. Security Awareness and Training. A mandatory security awareness and training program for all members of Provider’s workforce (including management), which includes:

2. Access Controls. Policies, procedures, and logical controls:

3. Physical and Environmental Security. Controls that provide reasonable assurance that access to physical servers at the production data center or the facility housing Provider’s SFTP Server, if applicable, is limited to properly authorized individuals and that environmental controls are established to detect, prevent and control destruction due to environmental extremes. These controls include:

4. Security Incident Procedures. A security incident response plan that includes procedures to be followed in the event of any Security Breach. Such procedures include:

5. Contingency Planning. Policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system failure, pandemic flu, and natural disaster) that could damage Customer Data or production systems that contain Customer Data. Such procedures include:

6. Audit Controls. Hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic information.

7. Data Integrity. Policies and procedures to ensure the confidentiality, integrity, and availability of Customer Data or Professional Services Data and protect it from disclosure, improper alteration, or destruction.

8. Storage and Transmission Security. Security measures to guard against unauthorized access to Customer Data or Professional Services Data that is being transmitted over a public electronic communications network or stored electronically. Such measures include requiring encryption of any Customer Data or Professional Services Data stored on desktops, laptops or other removable storage devices.

9. Secure Disposal. Policies and procedures regarding the secure disposal of tangible property containing Customer Data or Professional Services Data, taking into account available technology so that Customer Data or Professional Services Data cannot be practicably read or reconstructed.

10. Assigned Security Responsibility. Assigning responsibility for the development, implementation, and maintenance of its Information Security Program, including:

11. Testing. Regularly testing the key controls, systems and procedures of its information security program to validate that they are properly implemented and effective in addressing the threats and risks identified.

12. Monitoring. Network and systems monitoring, including error logs on servers, disks and security events for any potential problems. Such monitoring includes:

13. Change and Configuration Management. Maintaining policies and procedures for managing changes Provider makes to production systems, applications, and databases. Such policies and procedures include:

14. Program Adjustments. Provider monitors, evaluates, and adjusts, as appropriate, the security program in light of:

15. Devices. All laptop and desktop computing devices utilized by Provider and any subcontractors when accessing Customer Data or Professional Services Data:

Definitions

“Professional Services” means consulting or professional services provided to Customer under an agreement between the parties for the provision of consulting or professional services.

“Professional Services Data” means electronic data or information that is provided to Provider under a Professional Services engagement with Provider for the purpose of being input into the Provider Service, or Customer Data accessed within or extracted from the Customer’s tenant to perform the Professional Services.

“SFTP Server” means a Secure File Transfer Protocol server or its successor provided and controlled by Provider to transfer the Professional Services Data between Customer and Provider for implementation purposes.

8. Virginia Privacy Act

This section documents the safeguard standards imposed to protect Client information subject to the Code of Virginia Section 59.1-579 (“VPA”). To the extent Provider’s services constitute processing of personal information governed by VPA, these provisions shall apply:

a. This DPA sets forth instructions for the following:

b. With respect to the protected data, Provider shall:

Version history

VersionEffectiveStatus
Data Processing AgreementJuly 1, 2026Current — supersedes and replaces all prior versions. Entity name corrected to “The Boom Company” (no “Inc.”) on August 30, 2026 — typographical correction only; no change to terms.
Data Processing AgreementDecember 1, 2023Superseded July 1, 2026 (available on request)
← Back to Legal Hub