Data Processing Agreement
Trade License HQ — Data Processing Agreement
Last Updated: May 1, 2026
This Data Processing Agreement ("DPA") is entered into between:
- Ritt & Royce, a company organized and operating under the laws of the State of Michigan, doing business as Ritt & Royce and Trade License HQ ("Processor" or "Trade License HQ"), and
- The customer entity that has accepted Trade License HQ's Terms of Service and is identified in the applicable account or order form ("Controller" or "Customer").
This DPA forms part of, and is incorporated by reference into, the Trade License HQ Terms of Service (the "Agreement"). In the event of any conflict between this DPA and the Agreement with respect to the subject matter of data protection, this DPA shall control.
By accepting the Agreement, or by signing an order form that references this DPA, the Controller agrees to the terms of this DPA on behalf of itself and, to the extent required under applicable Data Protection Law, on behalf of its Affiliates.
1. Definitions
For the purposes of this DPA, the following terms have the meanings set out below. Capitalized terms not otherwise defined herein shall have the meaning given to them in the Agreement.
1.1 "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. "Control" means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
1.2 "Controller" means the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. In the context of this DPA, the Customer is the Controller.
1.3 "Data Protection Law" means all applicable laws and regulations relating to the Processing, privacy, and use of Personal Data, including without limitation: (a) the General Data Protection Regulation (EU) 2016/679 ("GDPR"); (b) the UK General Data Protection Regulation and the UK Data Protection Act 2018 (collectively, "UK GDPR"); (c) the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ("CCPA/CPRA"); (d) other applicable U.S. state privacy laws; and (e) any applicable implementing legislation, regulations, or guidance issued by a competent Supervisory Authority, in each case as amended or updated from time to time.
1.4 "Data Subject" means an identified or identifiable natural person to whom Personal Data relates. In the context of the Services, Data Subjects include the Controller's employees, subcontractors, authorized users, and other individuals whose Personal Data is submitted to or processed through the Services.
1.5 "EEA" means the European Economic Area.
1.6 "Personal Data" means any information relating to an identified or identifiable natural person that is Processed by the Processor on behalf of the Controller in connection with the provision of the Services, including information that is subject to protection under applicable Data Protection Law.
1.7 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed by the Processor.
1.8 "Processing" (and its cognates, including "Process" and "Processed") means any operation or set of operations performed on Personal Data or sets of Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
1.9 "Processor" means a natural or legal person, public authority, agency, or other body that Processes Personal Data on behalf of the Controller. In the context of this DPA, Trade License HQ is the Processor.
1.10 "Services" means the Trade License HQ software-as-a-service compliance management platform, including all features, functionality, and support services provided by Trade License HQ to the Customer pursuant to the Agreement.
1.11 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of Personal Data to third countries annexed to the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, and/or the International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs issued by the UK Information Commissioner's Office, as applicable, each as may be amended or replaced by a competent authority from time to time.
1.12 "Sub-processor" means any third-party Processor engaged by the Processor to carry out specific Processing activities on behalf of the Controller in connection with the Services.
1.13 "Supervisory Authority" means an independent public authority that is established by an EU Member State pursuant to Article 51 of the GDPR, or the applicable regulatory or supervisory authority responsible for enforcing Data Protection Law in any relevant jurisdiction (including, for the United Kingdom, the Information Commissioner's Office).
1.14 "Technical and Organizational Measures" or "TOMs" means the security measures and procedures implemented by the Processor as described in Section 6 of this DPA.
2. Scope and Roles
2.1 Applicability. This DPA applies to all Personal Data that the Processor Processes on behalf of the Controller in connection with the provision of the Services, as described in Section 3 (Details of Processing) below.
2.2 Role of the Controller. The Controller is solely responsible for determining the purposes and means of Processing of Personal Data submitted to or generated through the Controller's account on the Services. The Controller represents and warrants that it has all necessary rights, consents, and authorizations to submit Personal Data to the Services and to instruct the Processor to Process such Personal Data in accordance with this DPA.
2.3 Role of the Processor. The Processor shall Process Personal Data only as a data processor acting on behalf of the Controller, strictly in accordance with the Controller's documented instructions as set out in this DPA, the Agreement, and any other documented instructions provided by the Controller in writing (including via the Services' administrative features). The Processor shall not Process Personal Data for any purpose other than those described in this DPA, except to the extent required to comply with applicable law (in which case the Processor shall inform the Controller of such legal requirement prior to Processing, unless prohibited from doing so by applicable law).
2.4 Controller Instructions. This DPA, together with the Agreement and any applicable order forms or addenda, constitutes the Controller's complete and final instructions to the Processor with respect to the Processing of Personal Data. Any additional or different instructions shall require a written amendment to this DPA or the Agreement, signed by authorized representatives of both parties.
3. Details of Processing
The following describes the subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects relevant to the Processing activities carried out by the Processor on behalf of the Controller.
3.1 Subject Matter. The provision of a cloud-based compliance management SaaS platform to trade businesses (including, without limitation, electricians, plumbers, and general contractors) for tracking employee licences, certifications, company-level certifications, and job-site permits.
3.2 Duration of Processing. The Processor shall Process Personal Data for the duration of the Agreement, unless otherwise instructed in writing by the Controller, or as required by applicable law. Section 10 governs the return and deletion of Personal Data following termination.
3.3 Nature and Purpose of Processing. The Processor Processes Personal Data for the following purposes, all of which are undertaken on behalf of and in accordance with the instructions of the Controller:
- (a) Hosting, storing, and organizing compliance-related data and documents uploaded by the Controller and its authorized users, including employee licence records, certifications, and permit files;
- (b) Providing authorized users with access to the Services and their stored data through the web application interface;
- (c) Sending automated email reminder notifications to designated recipients regarding upcoming licence, certification, or permit expiry dates;
- (d) Processing uploaded document files (PDF, JPG, PNG) using optical character recognition ("OCR") technology to extract relevant data fields, as further described in the Agreement;
- (e) Generating compliance reports and enabling data export by the Controller;
- (f) Operating AI and automated processing services in connection with the Services, which may Process uploaded document content and compliance data;
- (g) Processing billing and payment information through the Stripe payment processing integration;
- (h) Providing customer support and responding to inquiries from the Controller and its authorized users;
- (i) Maintaining and improving the security, reliability, and functionality of the Services.
3.4 Types of Personal Data Processed. The categories of Personal Data that the Processor may Process on behalf of the Controller include:
- Employee full names and job titles;
- Trade licence and certification numbers and types;
- Licence, certification, and permit expiry and issuance dates;
- Issuing authority names and details;
- Email addresses of employees, subcontractors, and authorized users;
- Job site addresses and project-related location information;
- Uploaded document files (PDF, JPG, PNG), which may contain any of the above categories of data as well as photographs or other document images;
- Subcontractor portal submission data (names, licence details, uploaded documents);
- Data processed through AI and automated processing services, which may include uploaded document content and compliance-related information submitted by authorized users;
- User account information (name, email address, password hash, account preferences);
- Billing information processed via Stripe (note: Trade License HQ does not store full payment card numbers; payment card data is processed directly by Stripe as a PCI-DSS-compliant payment processor).
3.5 Categories of Data Subjects. The categories of Data Subjects whose Personal Data may be Processed include:
- The Controller's employees and field workers;
- Subcontractors and independent contractors who submit information through the subcontractor guest upload portal;
- The Controller's authorized users and account administrators;
- Any other individuals whose Personal Data is submitted to the Services by the Controller or its authorized users.
4. Obligations of the Processor
4.1 Processing on Instructions. The Processor shall Process Personal Data only on documented instructions from the Controller, including with regard to international data transfers, unless Processing is required by applicable EU or EU Member State law or other applicable law to which the Processor is subject. In such cases, the Processor shall inform the Controller of that legal requirement before Processing, unless such law prohibits such notice on important grounds of public interest. The Processor shall promptly notify the Controller if, in the Processor's reasonable opinion, any instruction from the Controller would require the Processor to act in violation of applicable Data Protection Law.
4.2 Confidentiality of Processing. The Processor shall ensure that all personnel authorized to Process Personal Data on behalf of the Controller are subject to appropriate confidentiality obligations (whether by contract or by operation of applicable law) with respect to the Personal Data. Access to Personal Data is limited to those personnel who have a need to access such data in connection with the provision of the Services.
4.3 Security Measures. The Processor shall implement and maintain the Technical and Organizational Measures set out in Section 6 of this DPA, or such other measures as provide an equivalent or higher level of protection, taking into account: (a) the state of the art; (b) the costs of implementation; (c) the nature, scope, context, and purposes of Processing; and (d) the risks of varying likelihood and severity to the rights and freedoms of natural persons. The Processor may update or modify the Technical and Organizational Measures from time to time, provided that such updates and modifications do not materially decrease the overall level of security afforded to Personal Data.
4.4 Assistance with Data Subject Rights. Taking into account the nature of the Processing and to the extent technically feasible, the Processor shall assist the Controller by implementing appropriate technical and organizational measures to fulfill the Controller's obligations to respond to Data Subject rights requests under applicable Data Protection Law, including rights of access, rectification, erasure, restriction of Processing, data portability, and objection. The Processor shall:
- (a) Promptly notify the Controller upon receiving a Data Subject request that appears to relate to the Controller's Personal Data;
- (b) Refrain from responding directly to such Data Subject requests on the Controller's behalf, except as expressly authorized in writing by the Controller or as required by applicable law;
- (c) Cooperate with the Controller, at the Controller's reasonable written request, to fulfill any such Data Subject rights requests, at the Controller's reasonable expense if such cooperation requires significant effort beyond the ordinary provision of the Services.
4.5 Assistance with Controller Compliance Obligations. The Processor shall assist the Controller in ensuring compliance with the Controller's obligations under Articles 32 through 36 of the GDPR (or equivalent obligations under applicable Data Protection Law), including obligations relating to:
- (a) The security of Processing;
- (b) Notification of Personal Data Breaches to Supervisory Authorities and affected Data Subjects;
- (c) Data protection impact assessments ("DPIAs") where required by Article 35 of the GDPR; and
- (d) Prior consultations with Supervisory Authorities where required by Article 36 of the GDPR.
Such assistance shall be provided at the Processor's standard support rates unless otherwise agreed, and only to the extent that such assistance is reasonably related to the Processing of Personal Data by the Processor on behalf of the Controller.
4.6 Sub-processors. The Processor shall not engage any Sub-processor to carry out specific Processing activities on behalf of the Controller without the prior written authorization of the Controller, except as set out in Section 5 of this DPA (which provides for general written authorization in accordance with applicable Data Protection Law). Where a Sub-processor is engaged, the Processor shall impose data protection obligations on the Sub-processor that are substantially equivalent to those imposed on the Processor under this DPA, by way of a written contract. The Processor shall remain fully liable to the Controller for the acts and omissions of its Sub-processors to the same extent as if the Processor had performed the Processing directly.
4.7 No Sale of Personal Data. The Processor shall not sell, rent, lease, or otherwise make available Personal Data to any third party for that third party's own independent commercial purposes, except as necessary to provide the Services pursuant to this DPA and the Agreement.
4.8 Return and Deletion of Personal Data. Upon the termination or expiry of the Agreement for any reason, the Processor shall, at the Controller's election:
- (a) Securely delete or destroy all Personal Data Processed on behalf of the Controller (including all copies thereof); or
- (b) Return all Personal Data to the Controller in a commonly used, machine-readable format;
in either case, within sixty (60) days following the date of termination or expiry. The Controller shall have a period of thirty (30) days following termination (the "Export Window") during which the Controller may access the Services solely to export its Personal Data. After the Export Window, the Processor shall proceed with deletion in accordance with this Section 4.8, unless otherwise required by applicable law. The Processor shall certify in writing that all Personal Data has been deleted or returned upon the Controller's written request. Notwithstanding the foregoing, the Processor may retain Personal Data to the extent required by applicable law, provided that such retained data shall continue to be subject to the confidentiality obligations of this DPA.
4.9 Demonstration of Compliance. The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations set out in this DPA, including the obligations of Article 28 of the GDPR, and shall cooperate with and support audits conducted in accordance with Section 9 of this DPA.
4.10 Notification of Unlawful Instructions. If the Processor becomes aware that any instruction of the Controller violates applicable Data Protection Law, the Processor shall promptly inform the Controller. In such circumstances, the Processor shall be entitled to suspend performance of the relevant Processing pending revised instructions from the Controller.
5. Sub-processors
5.1 General Authorization. By accepting this DPA, the Controller provides general written authorization for the Processor to engage the Sub-processors listed in Section 5.2 below, and such additional Sub-processors as may be listed in the Processor's Sub-processor Register (maintained at the Processor's Privacy Policy page, accessible at the Services website). The Controller acknowledges that this general authorization satisfies the requirements of Article 28(2) of the GDPR with respect to the Sub-processors listed herein and in the Sub-processor Register.
5.2 Current Sub-processors. As of the Effective Date, the Processor engages the following Sub-processors to Process Personal Data in connection with the Services:
| Sub-processor | Registered Address | Purpose of Processing | Data Transferred |
|---|---|---|---|
| Stripe, Inc. | 354 Oyster Point Blvd, South San Francisco, CA 94080, USA | Payment processing and billing management | Billing and payment information; account identifiers |
| Twilio Inc. (SendGrid) | 375 Beale Street, Suite 300, San Francisco, CA 94105, USA | Transactional email delivery (automated licence expiry reminders; account notifications) | Email addresses; name; notification content |
| AI/Automated Processing Providers | United States (as applicable) | Uploaded document content and compliance data (as applicable) | Internal AI-assisted processing and analysis on behalf of Controller (no current user-facing AI features; future features subject to Policy updates) |
| [Hosting Provider] | [Address TBD] | Cloud infrastructure; hosting of application, databases, and stored files | All categories of Personal Data described in Section 3.4 |
5.3 Changes to Sub-processors. The Processor shall notify the Controller of any intended addition of a new Sub-processor or replacement of an existing Sub-processor at least thirty (30) days before the intended change takes effect. Such notification shall be provided by email to the Controller's account administrator address or through an in-application notice. The Controller shall have fourteen (14) days from the date of such notification to object to the new or replacement Sub-processor in writing.
5.4 Objection to New Sub-processors. If the Controller reasonably objects in writing to the engagement of a new or replacement Sub-processor within the fourteen (14)-day objection period, the parties shall negotiate in good faith to resolve the Controller's objection. If the parties are unable to resolve the objection within thirty (30) days of the Controller's written objection, the Controller may, as its sole and exclusive remedy with respect to such objection, terminate the affected component of the Services by providing written notice to the Processor. Where the objection relates to a Sub-processor that performs core processing activities, the Controller may terminate the Agreement in its entirety. In such case, the Processor shall refund any prepaid fees covering the remainder of the then-current subscription term on a pro-rata basis.
5.5 Sub-processor Obligations. The Processor shall enter into a written agreement with each Sub-processor that imposes data protection obligations on the Sub-processor that are substantially equivalent to those imposed on the Processor under this DPA, including with respect to confidentiality, security, and restrictions on further sub-processing. The Processor shall ensure that Sub-processors Process Personal Data solely for the purposes set out in Section 5.2 above (or as otherwise described in any updated Sub-processor Register) and in accordance with the Processor's documented instructions.
5.6 Liability for Sub-processors. The Processor shall remain fully liable to the Controller for the performance of any Sub-processor's obligations under this DPA. Where a Sub-processor fails to fulfill its data protection obligations, the Processor shall remain liable to the Controller for the Sub-processor's failure as if the Processor had performed the Processing directly.
6. Security Measures
6.1 General Commitment. The Processor shall implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, having regard to the state of the art, the costs of implementation, the nature and scope of the Processing, and the risks to the rights and freedoms of Data Subjects.
6.2 Specific Technical and Organizational Measures. Without limiting the generality of Section 6.1, the Processor implements and maintains the following measures:
-
(a) Encryption in Transit. All data transmitted between end-users and the Services is encrypted using Transport Layer Security (TLS) with a minimum protocol version of TLS 1.2. HTTPS is enforced for all connections to the Services.
-
(b) Password Security. User account passwords are never stored in plaintext. Passwords are hashed using a strong cryptographic hashing algorithm (bcrypt via Werkzeug security utilities) with appropriate cost factors to resist brute-force attacks.
-
(c) Database Access Controls. Access to databases containing Personal Data is restricted to authorized personnel and services through role-based access control. Database credentials are not embedded in application code and are managed through secure environment variable configurations.
-
(d) Application Security. The Services implement Cross-Site Request Forgery (CSRF) protection on all state-changing requests. Input validation and output encoding are applied throughout the application to mitigate injection and cross-site scripting risks. Session management follows industry-standard security practices.
-
(e) Access Management. Access to production systems and Personal Data is limited to personnel who require such access to perform their job functions. Privileged access is reviewed periodically and revoked promptly upon role change or departure.
-
(f) Data Minimization. The Processor collects and retains only the Personal Data necessary for the purposes described in this DPA. The Services are designed to store only user-provided or user-confirmed data; OCR extraction results are held temporarily in the user's browser and are not transmitted to the Processor's servers unless and until the user reviews and explicitly confirms the extracted data.
-
(g) Security Review. The Processor conducts periodic reviews of its security practices and infrastructure. The Processor will perform periodic vulnerability assessments and will address identified vulnerabilities on a risk-prioritized basis.
-
(h) Incident Response. The Processor maintains an internal incident response process to detect, investigate, contain, and remediate Personal Data Breaches and other security incidents affecting the Services.
-
(i) Sub-processor Security. The Processor ensures, through contractual commitments, that Sub-processors maintain security standards substantially equivalent to those described in this Section 6.
6.3 Updates to Security Measures. The Processor may update or modify the Technical and Organizational Measures from time to time. Such updates shall not materially reduce the overall level of security afforded to Personal Data during the term of this DPA.
7. Personal Data Breach Notification
7.1 Notification by Processor. In the event that the Processor becomes aware of a Personal Data Breach affecting Personal Data Processed on behalf of the Controller, the Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours of becoming aware of such breach, to the extent feasible. Notification shall be provided by email to the Controller's account administrator address or such other contact as the Controller may specify in writing.
7.2 Content of Notification. The notification provided pursuant to Section 7.1 shall, to the extent then known, include:
- (a) A description of the nature of the Personal Data Breach, including the categories of Personal Data affected and the approximate number of Data Subjects and records concerned;
- (b) The name and contact details of the Processor's data protection point of contact from whom further information may be obtained;
- (c) A description of the likely consequences of the Personal Data Breach;
- (d) A description of the measures taken or proposed to be taken by the Processor to address the Personal Data Breach, including measures to mitigate its possible adverse effects.
7.3 Phased Notification. Where information cannot be provided simultaneously, it may be provided in phases without further undue delay, as it becomes available.
7.4 Controller's Obligations. The Controller is solely responsible for determining whether and how to notify relevant Supervisory Authorities, affected Data Subjects, or other third parties of any Personal Data Breach, in accordance with applicable Data Protection Law. The Processor shall provide reasonable assistance to the Controller in fulfilling such notification obligations, at the Controller's written request.
7.5 No Admission. A notification made pursuant to this Section 7 shall not constitute an admission of fault, negligence, or liability on the part of the Processor.
8. International Data Transfers
8.1 Location of Processing. Personal Data Processed by the Processor under this DPA is stored and Processed in the United States of America, using servers and infrastructure operated by [Hosting Provider]. By accepting this DPA, the Controller acknowledges and authorizes such Processing in the United States.
8.2 Transfers from the EEA and UK. Where the Processing of Personal Data involves a transfer of Personal Data from the EEA or the United Kingdom to the United States or any other country not recognized by the European Commission or UK Information Commissioner's Office (as applicable) as providing an adequate level of protection for Personal Data, such transfers shall be governed by the applicable Standard Contractual Clauses as follows:
-
(a) EU Transfers. For transfers of Personal Data subject to the GDPR from within the EEA to the Processor in the United States, the EU Standard Contractual Clauses (Module Two: Controller to Processor) issued pursuant to European Commission Implementing Decision 2021/914 of 4 June 2021 ("EU SCCs") are incorporated into and form part of this DPA. The relevant details required by the EU SCCs (including Annexes I, II, and III) are set out in Exhibit A to this DPA. The Controller's acceptance of this DPA constitutes its execution of the EU SCCs.
-
(b) UK Transfers. For transfers of Personal Data subject to the UK GDPR from within the United Kingdom to the Processor in the United States, the International Data Transfer Agreement ("IDTA") issued by the UK Information Commissioner's Office, or the UK Addendum to the EU SCCs (as applicable), are incorporated into and form part of this DPA. The Controller's acceptance of this DPA constitutes its execution of the relevant transfer mechanism.
8.3 Alternative Transfer Mechanisms. In the event that any transfer mechanism referenced in this Section 8 is invalidated, suspended, or otherwise rendered unavailable by a competent authority or court, the parties shall cooperate in good faith to implement an alternative transfer mechanism that lawfully authorizes the relevant transfer, such as binding corporate rules, an approved certification mechanism, or a new adequacy decision.
8.4 Onward Transfers by Sub-processors. The Processor shall ensure that any transfers of Personal Data by its Sub-processors to third countries are subject to appropriate transfer mechanisms as required by applicable Data Protection Law.
9. Audit Rights
9.1 General Right. The Controller may, at its own expense and no more than once per calendar year, conduct an audit of the Processor's compliance with its obligations under this DPA, or commission an independent third-party auditor acceptable to the Processor (acting reasonably) to conduct such an audit on the Controller's behalf.
9.2 Notice and Scheduling. The Controller shall provide the Processor with at least thirty (30) days' prior written notice of its intent to conduct an audit. The audit shall be scheduled at a mutually agreed time during the Processor's normal business hours (Monday through Friday, 9:00 AM to 5:00 PM ET, excluding public holidays) and shall be conducted in a manner that minimizes disruption to the Processor's operations.
9.3 Scope and Conduct. Audits shall be limited in scope to the Processor's Processing of Personal Data on behalf of the Controller in connection with the Services. The Controller and its auditor shall comply with the Processor's reasonable confidentiality, security, and access requirements. The Controller shall not have access to systems, data, or information belonging to other customers of the Processor.
9.4 Reports in Lieu of On-Site Audits. The Processor may, at its discretion, satisfy the Controller's audit request in whole or in part by providing the Controller with a copy of a current third-party audit report, certification, or SOC 2 Type II report (or equivalent) obtained by the Processor, provided that such report is reasonably relevant to the Controller's audit objectives and was completed within the twelve (12) months preceding the request.
9.5 Audit Costs. All costs associated with an audit, including the Controller's and any third-party auditor's fees and expenses, shall be borne by the Controller, unless the audit reveals a material breach of this DPA by the Processor, in which case the Processor shall bear its own reasonable costs associated with facilitating the audit.
9.6 Confidentiality of Audit Results. The Controller shall treat all information obtained during an audit as Confidential Information of the Processor (as defined in the Agreement) and shall not disclose such information to any third party without the Processor's prior written consent, except as required by applicable law.
10. Term and Termination
10.1 Effective Date. This DPA is effective as of the date the Controller accepts the Agreement (or, if later, May 1, 2026) and shall remain in force for the duration of the Agreement.
10.2 Termination. This DPA shall automatically terminate upon the termination or expiry of the Agreement for any reason. Termination of this DPA shall not affect any rights or obligations of either party that arose prior to termination.
10.3 Survival. The obligations of the Processor under Section 4.8 (Return and Deletion of Personal Data), Section 6 (Security Measures), Section 7 (Personal Data Breach Notification) with respect to breaches that occurred prior to termination, and Section 9 (Audit Rights) with respect to audits related to the term of the DPA, shall survive the termination or expiry of this DPA for a period of twelve (12) months, unless a longer period is required by applicable Data Protection Law.
11. Liability
11.1 Application of Agreement Liability Provisions. Each party's total aggregate liability to the other party under or in connection with this DPA, whether arising in contract, tort (including negligence), breach of statutory duty, or otherwise, is subject to the limitations and exclusions set out in the Limitation of Liability provisions of the Agreement, which are incorporated herein by reference.
11.2 Processor Liability to Data Subjects. Nothing in this DPA shall limit either party's liability to Data Subjects or Supervisory Authorities under applicable Data Protection Law to the extent such liability cannot be limited or excluded by law.
11.3 Indemnification. Each party shall indemnify, defend, and hold harmless the other party from and against any third-party claims, losses, damages, fines, penalties, and expenses (including reasonable attorneys' fees) arising from such party's material breach of this DPA or violation of applicable Data Protection Law, subject to the limitations in Section 11.1 and the Agreement.
12. Miscellaneous
12.1 Order of Precedence. In the event of any inconsistency or conflict between this DPA and the Agreement with respect to the subject matter of data protection and privacy, the terms of this DPA shall prevail. In the event of any inconsistency between this DPA and the SCCs, the SCCs shall prevail with respect to international data transfers.
12.2 Amendments. No amendment to this DPA shall be valid unless made in writing and signed by authorized representatives of both parties, except that the Processor may update the Sub-processor list in the manner described in Section 5.3. The Processor reserves the right to update this DPA to comply with changes in applicable Data Protection Law upon thirty (30) days' prior written notice to the Controller; if the Controller objects to such changes, the Controller's sole remedy shall be to terminate the Agreement upon written notice.
12.3 Severability. If any provision of this DPA is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction, the remaining provisions shall continue in full force and effect.
12.4 Governing Law. This DPA shall be governed by and construed in accordance with the laws of the State of Michigan, United States, without regard to its conflict of laws principles, except to the extent that mandatory provisions of Data Protection Law (including the GDPR) impose different requirements, in which case such mandatory provisions shall apply.
12.5 Entire Agreement. This DPA, together with the Agreement and any exhibits or addenda hereto, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior negotiations, representations, warranties, and understandings between the parties regarding the Processing of Personal Data under the Agreement.
12.6 Contact. Questions or notices regarding this DPA should be directed to Trade License HQ at: info@tradelicensehq.com.
Exhibit A — Standard Contractual Clauses: Supplementary Information
This Exhibit sets out the information required to populate the Annexes of the EU Standard Contractual Clauses (Module Two: Controller to Processor) pursuant to European Commission Implementing Decision 2021/914.
Annex I.A — List of Parties
Data exporter:
| Field | Details |
|---|---|
| Name | The Customer, as identified in the Trade License HQ account or order form |
| Role | Controller |
| Signature/date | As of the Customer's acceptance of the Agreement incorporating this DPA |
Data importer:
| Field | Details |
|---|---|
| Name | Ritt & Royce, doing business as Trade License HQ |
| Address | Michigan, United States |
| Contact | info@tradelicensehq.com |
| Role | Processor |
| Signature/date | As of the Effective Date of this DPA |
Annex I.B — Description of Transfer
| Field | Details |
|---|---|
| Categories of data subjects | Customer's employees, subcontractors, authorized users (see Section 3.5 of DPA) |
| Categories of personal data | Employee names, job titles, licence/certification numbers and types, expiry/issuance dates, email addresses, job site addresses, uploaded document files, data processed through AI and automated processing services, user account information (see Section 3.4 of DPA) |
| Sensitive data | None intended; Controller shall not submit special category data without prior written agreement |
| Frequency of transfer | Continuous, for the duration of the Agreement |
| Nature of processing | Hosting, storage, organization, access, notification, OCR processing, report generation, AI and automated processing services (see Section 3.3 of DPA) |
| Purpose of transfer | Provision of the Trade License HQ compliance management Services to the Controller |
| Retention period | Duration of the Agreement, plus up to 60 days post-termination for deletion (see Section 4.8 of DPA) |
| Sub-processors | As listed in Section 5.2 of DPA |
Annex I.C — Competent Supervisory Authority
The competent supervisory authority for the purposes of the EU SCCs shall be determined in accordance with Clause 13 of the EU SCCs, based on the Member State in which the data exporter (Controller) is established or, where the data exporter is not established in the EU, the Member State in which the EU representative (if applicable) is established, or the Member State in which the Data Subjects whose Personal Data is transferred are located.
Annex II — Technical and Organizational Measures
The technical and organizational security measures implemented by the Processor are as described in Section 6 of this DPA (Security Measures), which is incorporated herein by reference.
Annex III — List of Sub-processors
The list of Sub-processors authorized by the Controller is as set out in Section 5.2 of this DPA, as updated from time to time in accordance with Section 5.3.
This Data Processing Agreement was last updated on May 1, 2026.
Trade License HQ is a product of Ritt & Royce. For questions regarding this DPA, please contact info@tradelicensehq.com.