Data Processing Agreement (Template)
This Data Processing Agreement ("DPA") forms part of the agreement between the client organization ("Client," acting as data Controller) and Think4Ei LLC ("Think4Ei," acting as data Processor) governing Think4Ei's processing of personal data on Client's behalf through the Think4Ei platform.
1. Roles
For personal data that Client submits to, or has ingested into, the Think4Ei platform in the course of using the Service, Client is the Controller and Think4Ei is the Processor (or "Service Provider," to the extent that term applies under a given data-protection law). Think4Ei will process such data only on Client's documented instructions, including as set out in the underlying services agreement and this DPA, unless otherwise required by law.
2. Scope, subject matter & duration
The subject matter of processing is the operation of the Think4Ei platform for Client, including the systems and features Client has subscribed to. The duration of processing is the term of the underlying services agreement, plus any post-termination period described in Section 8 below. The categories of data subjects and personal data involved are those Client submits or configures through its use of the platform (which, depending on Client's configuration, may include Client's own employees, students, vendors, or other individuals whose records Client manages on the platform).
3. Processor obligations
- Process personal data only on Client's documented instructions, unless required to do otherwise by law (in which case Think4Ei will inform Client before processing, unless the law prohibits doing so).
- Ensure personnel authorized to process personal data are subject to confidentiality obligations.
- Implement appropriate technical and organizational security measures — see Section 5.
- Assist Client, taking into account the nature of processing, in responding to data-subject requests and in meeting Client's own obligations regarding security, breach notification, and data-protection impact assessments, to the extent Think4Ei is able to do so given the nature of the platform.
- Make available information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to reasonable audits, including inspections, conducted by Client or an auditor mandated by Client, subject to reasonable confidentiality, scheduling, and scope limits.
4. Subprocessors
Client authorizes Think4Ei to engage the subprocessors listed at think4ei.com/subprocessors, which is kept current as our vendor set changes. Think4Ei will impose data-protection obligations on each subprocessor that are no less protective than those in this DPA, and remains responsible for each subprocessor's performance of its data-protection obligations. Where a client-specific notice period for new subprocessors is agreed in a signed DPA, Think4Ei will honor that notice period.
5. Security measures
Think4Ei maintains the technical and organizational measures described in real, specific terms at our Trust Center, including tenant-scoped access controls, audit logging, encryption in transit, and document-integrity sealing for ingested records. The Trust Center uses plain status labels (Implemented and internally verified / Independently assessed / In progress / Planned) rather than absolute claims, and this DPA incorporates that page's current status by reference — we will not describe a control here in stronger terms than we describe it there.
6. Data subject requests
Where an individual contacts Think4Ei directly to exercise a data-subject right regarding data Client controls, Think4Ei will promptly forward the request to Client and provide reasonable assistance in responding, since Client, as Controller, is generally best positioned to fulfill it.
7. Breach notification
Think4Ei will notify Client without undue delay, and in any event within 72 hours of becoming aware, of a confirmed personal-data breach affecting Client's data, and will provide information reasonably available to assist Client in meeting its own notification obligations. This commitment applies regardless of whether a specific law requires that timeline for the data in question — we consider it good practice either way.
8. Deletion or return of data on termination
Upon termination or expiration of the underlying services agreement, and upon Client's request, Think4Ei will delete or return Client's personal data, and delete existing copies, within a reasonable period, unless applicable law requires continued storage (for example, financial or audit-record retention requirements). Where the underlying services agreement specifies a different data-retention or export process, that process controls.
9. International transfers
Think4Ei's infrastructure is hosted in the United States (see Subprocessors). Where Client's data originates outside the United States, Client and Think4Ei will cooperate in good faith to put in place any additional transfer mechanism required by applicable law.
10. Liability
Liability under this DPA is subject to the limitations and exclusions of liability set out in the underlying services agreement between Client and Think4Ei, unless the parties expressly agree otherwise in a signed DPA or enterprise agreement.
11. Governing law
This DPA is governed by the same governing law as the underlying services agreement, generally the laws of the State of Florida, unless a signed enterprise agreement states otherwise.
12. Execution
This template becomes binding between Client and Think4Ei only when a signed order form, services agreement, or standalone DPA incorporating these terms (or terms substantially similar to them) is executed by both parties, with the effective date, Client's legal name, and any client-specific annex (such as sector-specific terms for education clients) completed at that time. Contact sales@think4ei.com to begin that process.