Applies when incorporated into your customer agreement with the required processing details. Publication alone does not appoint Turnstile as a processor or authorize a new transfer.
Scope and roles
This Data Processing Addendum (DPA) forms part of the Master Subscription and Customer Agreement between Doorstop, Inc. (Turnstile) and Customer when incorporated in the accepted Order Form. Covered Personal Data means personal data Turnstile processes on Customer’s behalf to provide the contracted Service. Personal data, processing, controller, processor, and personal-data breach have the meanings given by applicable data-protection law.
Customer acts as controller of Covered Personal Data or, where identified in the processing annex, as a processor authorized by its controller to appoint Turnstile as a further processor. Customer determines its lawful instructions and is responsible for the notices, permissions, and other legal basis required for its collection and use.
This DPA does not govern a purpose independently determined by Turnstile, such as account administration or platform security, merely because that purpose involves a Service user. Any such processing must have its own lawful basis and accurate disclosure in the Privacy Notice. It does not enlarge Turnstile’s authority over Covered Personal Data.
The processing annex
The parties must agree the processing annex before covered processing begins. It forms part of this DPA and identifies the actual service configuration. A service description or list of possible integrations is not a completed processing or international-transfer annex.
- The contracted modules and organizations; subject matter, nature, purposes, duration, and frequency of processing.
- The relevant categories of people and personal data, including any expressly permitted sensitive categories and their additional safeguards.
- Customer’s documented instructions, rights and responsibilities, and any underlying controller authorization.
- The agreed security measures, authenticated contacts, and procedures for assistance, incidents, return, and deletion.
- Authorized subprocessors, their functions and locations, the applicable authorization procedure, and any required transfer instruments and supplementary measures.
Instructions and authorized personnel
Turnstile will process Covered Personal Data only on Customer’s documented lawful instructions, including the incorporated service scope and authorized use of its controls. Customer’s instructions cannot authorize access to another customer’s information or a use outside the contracted processing scope.
If law requires processing outside those instructions, Turnstile will inform Customer before that processing where legally permitted. Turnstile will promptly inform Customer if it considers an instruction unlawful and will not carry out the disputed instruction pending lawful clarification.
Turnstile will limit access to personnel who need it for their authorized responsibilities and who are bound by confidentiality obligations. Confidentiality and access restrictions continue to apply during support, export, and incident handling.
Security measures
Turnstile will implement the technical and organizational measures recorded in the security annex and those required by applicable law, appropriate to the processing and its risks. The annex addresses the actual deployment, including access controls, account security, tenant separation, logging, data protection, backups, recovery, testing, and privileged support access.
Customer will maintain the security responsibilities assigned to it, including appropriate account permissions and lawful configuration. Neither a feature description nor this DPA represents that an unlisted certification, audit report, or numerical service level exists.
Subprocessors
Turnstile may engage a subprocessor for Covered Personal Data only with Customer’s prior written authorization under the agreed annex. The authorized record identifies the provider, function, and processing location. A provider chosen directly by Customer is treated according to its actual role and agreement, rather than automatically classified as Turnstile’s subprocessor.
Unless the annex establishes a general authorization procedure, adding or replacing a subprocessor requires specific written authorization before affected processing. A general procedure must specify an advance notice channel, an opportunity to object on data-protection grounds, and how unresolved objections will be handled. The parties will follow that procedure before the affected change takes effect.
Turnstile will impose the applicable data-protection obligations on each engaged subprocessor in writing, limit its processing to the authorized function, and remain responsible for its performance as required by applicable law and the Agreement.
International transfers
Covered Personal Data may be processed only in the locations authorized by the processing annex. Before a transfer that requires a legal safeguard, the parties must establish the applicable transfer mechanism, complete its necessary particulars and annexes, and implement required supplementary measures.
This page does not itself incorporate completed standard contractual clauses, a UK transfer addendum, or a provider list. The applicable mechanism and its parties, transfer details, safeguards, and competent authorities must be identified in the executed arrangement. If a necessary safeguard cannot be maintained, the affected transfer must not proceed until a lawful arrangement is in place.
Requests and assistance
Taking account of the processing and information available, Turnstile will provide the assistance required by applicable law for individual-rights requests, security obligations, impact assessments, and regulator consultations. The parties will use authenticated contacts and practical procedures that preserve applicable deadlines.
Turnstile will refer a request concerning Covered Personal Data to Customer unless legally required or authorized to respond directly. Customer will determine the lawful response within its responsibility. Assistance does not authorize disclosing another person’s records, bypassing account security, or erasing unrelated organizations’ information.
Personal-data breaches
Turnstile will notify Customer without undue delay after becoming aware of a personal-data breach affecting Covered Personal Data. It will provide available information about the nature and likely consequences, the affected data and people where known, measures taken or planned, and a contact for follow-up. Information may be supplied in stages as it becomes available.
Turnstile will take reasonable steps to investigate, contain, and address the breach and cooperate with Customer’s legally required notifications. Customer remains responsible for notifications within its role unless law provides otherwise. The incident schedule identifies contacts and any additional agreed commitments; it does not reduce a statutory obligation.
Information and audits
Turnstile will provide information necessary to demonstrate compliance with its applicable processor obligations and allow and contribute to audits, including inspections, required by applicable data-protection law. Customer or its authorized auditor will use reasonable arrangements that protect other customers’ information, confidentiality, and service security.
The parties will coordinate scope, notice, access, and confidentiality through the agreed contacts. Those arrangements must not prevent an audit or regulator access required by law. This DPA does not represent that a particular independent certification or assurance report has been obtained.
Return, deletion, and protected retention
After the covered services end, Turnstile will, at Customer’s choice, return or delete Covered Personal Data and delete existing copies, except where applicable law requires retention. The agreed exit schedule identifies export scope and formats, authorized recipients, timing, and the handling and expiry of protected backup copies.
Any retained data remains subject to applicable confidentiality and security obligations, is limited to the justified purpose, and is not available for unrelated use. A technical safeguard that prevents deletion of financial or audit evidence is not authority for indefinite retention or an exemption from a lawful deletion obligation.
The parties will resolve instructions affecting pending transactions or other protected records according to their respective roles and applicable law. A separate lawful basis for a record maintained by Turnstile must be identified accurately; it cannot be created by relabeling all Customer Data as an operational record.
Duration and priority
This DPA continues for as long as Turnstile holds Covered Personal Data under the Agreement, including required return, deletion, or protected retention. Ending the subscription does not end the obligations that apply to retained data.
An applicable international-transfer instrument takes priority where its terms require. This DPA otherwise prevails over conflicting general service terms for covered processing. It does not limit an individual’s nonwaivable rights or a regulator’s authority. Questions and formal notices may be sent to legal@turnstileos.com, with the operational contacts recorded in the annex.