DPA Section 01
Effect and incorporation
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer identified in an applicable proposal, order form, Statement of Work, master services agreement, support agreement, or other written service agreement (“Customer”) and Kool&Tech LLC (“Kool&Tech”) under which Kool&Tech processes Personal Data for Customer.
This DPA applies only to processing in which Kool&Tech acts as a Processor, Service Provider, Contractor, or equivalent role on behalf of Customer. It does not govern processing for which Kool&Tech independently determines the purposes and essential means and acts as an independent Controller or Business.
Order of precedence: Mandatory transfer clauses and nonwaivable Data Protection Law control for the affected processing. Next, this DPA controls over conflicting general privacy or security terms. The service agreement controls commercial matters not specifically addressed by this DPA.
DPA Section 02
Definitions
Capitalized terms not defined here have the meanings given in the service agreement or applicable Data Protection Law.
- Applicable Data Protection Law: privacy, data protection, breach notification, and security laws that apply to the relevant processing.
- Controller, Business, Customer: the party that determines the purposes and means of processing or otherwise discloses Personal Data to a service provider.
- Processor, Service Provider, Contractor: the party processing Personal Data on behalf of another party under documented instructions.
- Personal Data: information relating to an identified or identifiable person, household, device, or other protected subject under applicable law.
- Processing: any operation performed on Personal Data, including collection, access, use, storage, transmission, alteration, retrieval, disclosure, deletion, or destruction.
- Subprocessor: another processor engaged by Kool&Tech to process Customer Personal Data.
- Personal Data Breach: a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
- Restricted Transfer: a transfer requiring an approved safeguard under applicable Data Protection Law.
DPA Section 03
Roles of the parties
Customer is the Controller, Business, or equivalent responsible party for Customer Personal Data. Kool&Tech is the Processor, Service Provider, Contractor, or equivalent recipient only to the extent Kool&Tech processes Customer Personal Data on Customer's behalf.
Customer determines the lawfulness, purpose, means, categories, data subjects, retention instructions, disclosures, and permitted use. Kool&Tech processes Customer Personal Data only to provide the contracted services, follow Customer's documented instructions, secure and support the services, comply with law, and perform activities expressly permitted for a processor or service provider.
If the parties jointly determine purposes and essential means for a particular activity, the parties will document any joint-controller arrangement required by applicable law.
DPA Section 04
Documented instructions
The service agreement, this DPA, Customer's authorized use and configuration of the services, approved support requests, and lawful written directions constitute Customer's documented instructions.
Kool&Tech will notify Customer if an instruction appears to violate applicable Data Protection Law, unless prohibited by law. Kool&Tech may suspend the affected processing until the parties clarify or modify the instruction.
If law requires processing beyond Customer's instructions, Kool&Tech will inform Customer before processing unless legally prohibited from doing so.
DPA Section 05
Processing details
Subject matterTechnology consulting, ERP, Odoo, Microsoft 365, websites, eCommerce, development, integrations, automation, migration, training, support, help desk, assessment, and related services.
DurationThe term of the applicable service agreement, plus limited periods required for transition, backups, legal retention, dispute handling, or secure deletion.
NatureAccessing, collecting, organizing, configuring, hosting where applicable, storing, retrieving, transmitting, synchronizing, importing, exporting, testing, troubleshooting, supporting, and deleting data.
PurposeProviding, securing, maintaining, supporting, improving, and documenting the specifically contracted services.
Project-specific details in a signed SOW, order form, data inventory, or schedule supplement these general processing details.
DPA Section 06
Categories of data subjects
Depending on the Customer and service, data subjects may include:
- Customer employees, workers, applicants, contractors, administrators, and authorized users.
- Customers, consumers, prospects, subscribers, website visitors, tenants, patients, students, residents, members, or end users of Customer.
- Vendors, suppliers, partners, distributors, resellers, service providers, consultants, and business contacts.
- Individuals communicating through CRM, email, SMS, support, forms, portals, eCommerce, events, appointments, or social channels.
- Other persons whose Personal Data Customer lawfully provides or makes accessible.
DPA Section 07
Categories of Personal Data
Depending on the engagement, Customer Personal Data may include:
- Identifiers and contact information, such as names, business addresses, telephone numbers, emails, account IDs, usernames, and signatures.
- Professional, employment, organizational, role, scheduling, training, and access information.
- CRM, sales, purchasing, inventory, accounting, invoicing, project, support, logistics, manufacturing, property, website, eCommerce, and service records.
- Device, browser, IP address, authentication, security, log, diagnostic, audit, cookie, and usage information.
- Communications, tickets, attachments, notes, recordings, meeting information, forms, and assessment responses.
- Transaction references, billing history, payment status, tax information, and limited financial records, excluding complete payment-card data unless expressly agreed.
- Configuration, integration, migration, import, export, backup, and operational data that may contain Personal Data.
DPA Section 08
Sensitive and regulated data
Customer must not provide highly sensitive or regulated information unless the service agreement expressly authorizes it and identifies applicable safeguards.
This includes protected health information, complete payment-card data, biometric identifiers, precise geolocation, genetic information, government identification numbers, financial account credentials, children's data, criminal records, union membership, religious or political beliefs, sexual-life information, or other special-category data.
Before such processing, the parties may require a Business Associate Agreement, specialized DPA, security addendum, data-residency arrangement, impact assessment, additional insurance, approved platform, or revised fees. Kool&Tech may reject data or processing that falls outside approved scope.
DPA Section 09
Customer obligations
Customer represents and warrants that Customer:
- Has a lawful basis, authority, and all required notices and consents for the processing and disclosure of Customer Personal Data.
- Will provide lawful, complete, and accurate instructions.
- Will not use the services to process prohibited data or for prohibited purposes.
- Will configure users, permissions, retention, consent, notices, exports, and integrations consistently with applicable law.
- Will respond to data-subject requests and regulatory inquiries as the responsible Controller or Business.
- Will identify sector-specific, localization, residency, government, children's, employment, healthcare, financial, education, or other special requirements before processing begins.
- Will maintain reasonable endpoints, networks, accounts, backups, and organizational safeguards under Customer control.
DPA Section 10
Kool&Tech processor obligations
Kool&Tech will:
- Process Customer Personal Data only on documented instructions and for limited, specified business purposes.
- Ensure persons authorized to process Customer Personal Data are subject to confidentiality obligations.
- Apply technical and organizational measures appropriate to the contracted processing and available platform capabilities.
- Assist Customer with rights requests, security, breach response, impact assessments, and regulator consultations to the extent required by law and reasonably possible.
- Notify Customer if Kool&Tech can no longer meet applicable obligations as a Processor or Service Provider.
- Provide information reasonably necessary to demonstrate compliance, subject to confidentiality, security, relevance, and audit limitations in this DPA.
DPA Section 11
U.S. state service-provider terms
For Personal Data subject to U.S. state privacy laws where Kool&Tech acts as a Service Provider or Contractor, Customer discloses Personal Data only for the specific business purposes documented in the service agreement and this DPA.
Kool&Tech will not sell or share Customer Personal Data; retain, use, or disclose it outside the direct business relationship or for an unrelated commercial purpose; or combine it with Personal Data from another source except where expressly permitted by applicable law.
Kool&Tech will provide the level of privacy protection required of an applicable Service Provider or Contractor, permit Customer to take reasonable steps to verify compliant use, and cooperate with reasonable remedial action if Customer identifies unauthorized processing.
Kool&Tech may use Customer Personal Data for permitted operational purposes such as security, fraud prevention, debugging, service delivery, internal quality, and legal compliance only to the extent allowed by applicable law.
DPA Section 12
Confidentiality
Kool&Tech will limit access to Customer Personal Data to authorized personnel and contractors with a need to process it for the services. Authorized persons must be bound by confidentiality duties through contract, policy, professional obligation, or law.
Confidentiality duties continue after access or engagement ends. Kool&Tech may disclose Customer Personal Data when legally required, subject to legally permitted notice and protective measures.
DPA Section 13
Technical and organizational measures
Security measures are risk-based and depend on the service, platform, hosting model, licensing, data, scope, and responsibilities allocated in the service agreement.
Identity and accessLeast privilege, identifiable accounts, role-based access, MFA where supported, administrative-access control, and timely access removal.
Data protectionSecure transmission, platform-provided encryption where available, minimization, appropriate retention, and controlled transfer methods.
Secure deliveryTesting, staging where available, controlled deployment, source control, secret handling, validation, error handling, and rollback planning.
ResilienceLogging, monitoring, backups, recovery planning, incident response, vendor-supported infrastructure, and continuity measures as included.
The current public Security & Trust Center describes Kool&Tech's general approach. Project-specific commitments require express written inclusion.
DPA Section 14
Subprocessors
Customer grants Kool&Tech general written authorization to engage Subprocessors as reasonably necessary to deliver the services. Subprocessors may include cloud, hosting, ERP, Microsoft 365, communications, support, payment, analytics, source-control, development, backup, security, and other service providers selected for the engagement.
Kool&Tech will impose written data-protection obligations appropriate to the Subprocessor's role and applicable law. Kool&Tech remains responsible for its Subprocessors' performance of the data-protection obligations assigned to them, subject to the service agreement and applicable law.
Where required, Kool&Tech will make available a current Subprocessor list or provide notice of material additions or replacements. Customer may object on reasonable, documented data-protection grounds within the stated notice period. The parties will work in good faith on a commercially reasonable solution; if none is available, either party may terminate the affected service without terminating unrelated services.
DPA Section 15
International and cross-border transfers
Customer authorizes processing in the United States and other countries where Kool&Tech or approved Subprocessors operate, subject to applicable transfer restrictions.
For a Restricted Transfer, the parties will rely on a valid mechanism required by the applicable jurisdiction, which may include an adequacy decision, recognized certification, approved standard contractual clauses, binding corporate rules, consent or necessity where lawfully available, or another approved mechanism.
Where the European Commission Standard Contractual Clauses are required, the appropriate module applies based on party roles. This DPA and the service agreement populate the relevant annex information to the extent sufficient, and the parties will complete additional details reasonably required. The SCCs prevail over conflicting terms for the Restricted Transfer.
For UK, Switzerland, Canada, Brazil, Australia, New Zealand, Asia-Pacific, Latin American, African, Middle Eastern, or other regional transfers, applicable addenda, model clauses, or mandatory transfer terms are incorporated or executed when legally required.
DPA Section 16
Government access requests
If Kool&Tech receives a legally binding government request for Customer Personal Data, Kool&Tech will, where legally permitted, notify Customer, review the request for validity and scope, seek clarification or challenge disproportionate requests where reasonable, and disclose only information legally required.
Kool&Tech will document requests as required and may provide available information reasonably necessary for a transfer assessment, subject to law, security, confidentiality, and protection of third-party rights.
DPA Section 17
Data-subject requests
Customer is responsible for receiving, verifying, and responding to requests to access, correct, delete, restrict, object, opt out, limit, or port Personal Data.
Taking into account the nature of processing, Kool&Tech will provide commercially reasonable assistance through available service functionality or scoped support. If Kool&Tech receives a request relating to Customer Personal Data, Kool&Tech will direct the requester to Customer or forward the request where appropriate, unless prohibited by law.
Assistance requiring custom development, extensive searches, restoration of backups, legal analysis, or material resources may be treated as additional services unless the work results from Kool&Tech's breach of this DPA.
DPA Section 18
Personal Data Breach
Kool&Tech will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data for which Kool&Tech is responsible. Notice may be delivered in phases as information becomes available.
To the extent reasonably available, notice will describe the nature of the incident, affected data and data subjects, likely consequences, containment or remediation, and a contact point. Notification is not an admission of fault or liability.
Kool&Tech will take reasonable steps to contain, investigate, remediate, document, and cooperate with Customer. Customer remains responsible for determining whether notice to individuals, regulators, insurers, partners, or others is required, unless applicable law assigns that duty directly to Kool&Tech.
DPA Section 19
Compliance assistance
Taking into account the nature of processing and information available, Kool&Tech will reasonably assist Customer with:
- Security of processing and risk review.
- Personal Data Breach assessment and notification.
- Data protection impact assessments and prior regulatory consultation.
- Records of processing and information necessary for Customer's documented obligations.
- Reasonable regulator or supervisory-authority inquiries concerning the services.
Assistance is limited to the processing performed by Kool&Tech and may be subject to fees for material work not caused by Kool&Tech's noncompliance.
DPA Section 20
Audits and compliance information
Kool&Tech will make available information reasonably necessary to demonstrate compliance with this DPA. Customer should first rely on public documentation, the Security & Trust Center, available policies, questionnaires, summaries, vendor reports, certifications of relevant Subprocessors, or other existing evidence.
If additional verification is legally required, Customer may conduct no more than one audit in a twelve-month period, unless a confirmed incident or regulator requires otherwise. Audits require reasonable advance notice, must occur during normal business hours, must minimize disruption, must protect confidentiality and security, and must be limited to relevant systems and processing.
Customer may not access unrelated client data, source code, exploit details, penetration-test systems without written permission, or require disclosure that would weaken security. Customer bears audit costs unless the audit identifies a material breach by Kool&Tech. Extensive questionnaires, custom evidence, or onsite reviews may incur reasonable fees.
DPA Section 21
Return, deletion, and retention
At the end of services involving processing, Customer may request return or deletion of Customer Personal Data in a reasonably available format, subject to the agreement, platform capability, and applicable fees.
Kool&Tech will delete or render inaccessible remaining Customer Personal Data within a commercially reasonable period unless law, contract, dispute preservation, security, insurance, backup rotation, accounting, or legitimate compliance requirements require retention.
Residual data may remain temporarily in backups, logs, archives, email, tickets, or technical systems where immediate deletion is impractical. Such data remains protected and is not restored for ordinary use except for recovery, legal, security, or compliance purposes.
DPA Section 22
Records and accountability
Each party will maintain records required by applicable Data Protection Law for the processing under its responsibility. Customer is responsible for its processing inventory, lawful basis, notices, consent records, retention schedule, data-subject communications, and Controller obligations.
Kool&Tech will maintain relevant Processor records where required, including categories of processing, applicable transfers, Subprocessors, and security information appropriate to Kool&Tech's role.
DPA Section 23
Children and protected populations
Customer must not use services to process children's Personal Data, student education records, vulnerable-person data, or similarly protected information unless expressly authorized and supported by a documented lawful basis, required notices and consents, age-appropriate controls, and any additional contractual safeguards.
Customer remains responsible for age verification, parental or guardian consent, school or institutional authorization, and restrictions on profiling, advertising, disclosure, or retention.
DPA Section 24
Health, payment, and regulated sectors
This DPA alone does not make services compliant with HIPAA, GLBA, PCI DSS, FERPA, COPPA, CJIS, FedRAMP, CMMC, export controls, financial-services rules, or other sector-specific requirements.
If a project requires regulated processing, the requirement must be identified before contracting and may require a Business Associate Agreement, approved hosting, restricted architecture, dedicated environment, specialized vendor, additional technical controls, compliance evidence, or separate pricing.
Complete payment-card data should be handled by a PCI-compliant payment provider and should not be submitted to Kool&Tech through ordinary forms, tickets, email, chat, or SMS unless expressly approved.
DPA Section 25
Artificial intelligence and automated processing
Kool&Tech will not use Customer Personal Data to train a publicly available foundation model unless Customer expressly authorizes that use and applicable law permits it.
Where AI, machine-assisted tools, scoring, summarization, extraction, or automated decision support are included, the service agreement should identify the purpose, data flow, provider, human review, retention, and applicable restrictions. Customer remains responsible for determining whether automated processing requires notice, consent, opt-out, explanation, impact assessment, or human intervention.
Kool&Tech will not make legally or similarly significant decisions about individuals on Customer's behalf unless the service agreement expressly provides for that processing.
DPA Section 26
Liability and indemnity alignment
The liability, exclusions, indemnities, disclaimers, claim procedures, and remedies in the service agreement and Terms & Conditions apply to this DPA to the maximum extent permitted by applicable law.
Nothing in this DPA expands either party's aggregate liability beyond an expressly agreed cap, creates a separate unlimited liability pool, or excludes liability that cannot lawfully be limited. Mandatory statutory remedies remain available only to the extent required by applicable law.
DPA Section 27
Term and survival
This DPA becomes effective when Customer and Kool&Tech enter an agreement involving covered processing, and remains effective while Kool&Tech processes Customer Personal Data.
Obligations concerning confidentiality, security, Restricted Transfers, government requests, audits, deletion, liability, and retained data survive termination for as long as relevant Personal Data remains under a party's control or as otherwise required by law.
DPA Section 28
Governing law and mandatory jurisdictions
The governing law and dispute-resolution provisions of the service agreement apply to this DPA, generally Florida law for Kool&Tech agreements.
Where mandatory Data Protection Law, supervisory-authority jurisdiction, or approved transfer clauses require a different law, forum, regulator, or data-subject right for particular processing, those mandatory provisions apply only to that processing and do not displace the agreement for unrelated matters.
DPA Section 29
Annex I: Processing specification
Exporter / CustomerThe Customer entity identified in the applicable service agreement, including its contact and authorized signatory.
Importer / ProcessorKool&Tech LLC, Florida, United States; info@koolandtech.com; +1 850 403 5551.
FrequencyContinuous, recurring, periodic, project-based, event-driven, or one-time, as required by the contracted service.
RetentionFor the service term and limited post-termination periods described in this DPA, the agreement, platform settings, and applicable law.
Data subjectsAs described in “Categories of data subjects” and any project-specific SOW.
Personal DataAs described in “Categories of Personal Data,” excluding unapproved sensitive or regulated data.
OperationsCollection, access, storage, organization, transmission, migration, synchronization, configuration, support, analysis, testing, and deletion as required for services.
Supervisory authorityThe authority determined under applicable Data Protection Law and any mandatory transfer clauses.
DPA Section 30
Annex II: Security measures
Depending on scope, platform, licensing, and risk, measures may include:
- Access control, least privilege, role assignments, identifiable accounts, MFA where supported, and controlled privileged access.
- Secure transmission and vendor-provided encryption at rest where available and appropriately configured.
- Confidentiality obligations, approved tools, onboarding, offboarding, and access removal.
- Development, staging, testing, source control, change authorization, validation, error handling, and rollback planning.
- Secret, key, token, and credential handling appropriate to the platform.
- Logging, monitoring, incident triage, vulnerability handling, and communication procedures.
- Backups, restoration, continuity, and disaster-recovery measures where included or provided by the hosting platform.
- Vendor and Subprocessor review appropriate to the service and data involved.
- Data minimization, retention, deletion, isolation, and controlled transfer methods.
Measures are proportionate to the processing and do not imply certification, zero risk, or inclusion of every listed control in every engagement.
DPA Section 31
Annex III: Subprocessor framework
The applicable Subprocessor list may vary by service. Categories may include:
- ERP and application platforms, including Odoo environments selected for the project.
- Microsoft cloud, identity, email, collaboration, device-management, and support services.
- Hosting, infrastructure, database, DNS, domain, CDN, backup, monitoring, and security providers.
- Communications providers used for email, SMS, voice, meetings, appointments, and support.
- Payment processors, source-control platforms, development tools, analytics, AI, and authorized client-selected applications.
The specific Subprocessors involved depend on Customer configuration and the contracted service. Kool&Tech may publish or provide a current list where required.
DPA Section 32
Execution and electronic acceptance
This DPA may be accepted by signature, electronic signature, click acceptance, incorporation into an order or SOW, or execution of a service agreement that references it. Electronic counterparts are treated as originals where permitted by law.
Kool&Tech LLCFlorida Document L24000173044
Name: __________________________
Title: ___________________________
Signature / Date CustomerLegal name: _____________________
Name: __________________________
Title: ___________________________
Signature / Date DPA Section 33
DPA updates
Kool&Tech may update this public DPA to reflect legal, regulatory, service, vendor, or operational changes. An update will not materially reduce protection for covered processing during an active service term without notice where applicable.
If mandatory law requires different terms, the parties will cooperate in good faith to implement the required amendment, transfer mechanism, or supplemental schedule for the affected processing.