# Data Processing Agreement (DPA)
**Last Updated:** June 10, 2026
**Between:** Core Durability, LLC ("Data Processor", "Company") and The Customer ("Data Controller", "Facility")
This Data Processing Agreement ("DPA") forms a legally binding schedule to the Master Terms of Service between the Data Controller and the Data Processor. This DPA establishes the strict parameters, technical and organizational security measures, and liability flows under which Core Durability, LLC is permitted to process facility water quality and Legionella compliance data on your behalf.
---
## 1. Data Processing Agreement Scope and Regulatory Roles
**1.1 Regulatory Roles:** For the purposes of global privacy regulations including GDPR, CPRA, and state privacy statutes, the Customer is the **Data Controller** and Core Durability, LLC is the **Data Processor**.
**1.2 Documented Instructions:** We shall process Customer Data exclusively on your behalf and in accordance with your documented instructions set forth in this DPA, the Master Terms of Service, and your active configuration of the Platform.
**1.3 Scope of Data:** This DPA strictly governs "Customer Data," defined as facility schematics, water sampling logs, IoT telemetry, biocide concentration records, temperature readings, and laboratory Certificate of Analysis (COA) records uploaded to or ingested by the Platform. Commercial account billing data is governed separately by our Privacy Policy.
---
## 2. User Responsibilities & Controller Obligations
**2.1 Sampling Data Accuracy Responsibilities:** The Data Controller retains primary legal responsibility for the accuracy, lawfulness, completeness, and integrity of all Customer Data submitted to the Platform. This includes an affirmative obligation to ensure that all manual sampling logs, field measurements, and imported laboratory culture results accurately reflect physical facility conditions.
**2.2 Lawful Basis and Consents:** The Data Controller warrants that it has obtained all necessary rights, notices, and legal bases required to collect and transmit facility operational data and employee credential details to the Data Processor.
**2.3 Verification of Automated Lab Data Ingestion:** To ensure data integrity, the Data Controller is responsible for validating LIMS and EDD import feeds, and must manually verify all OCR and LLM PDF parsing outputs against official laboratory Certificate of Analysis (COA) reports before taking health or safety actions.
---
## 3. Personnel Confidentiality
Core Durability, LLC ensures that all personnel authorized to process Customer Data are bound by strict contractual confidentiality obligations and receive regular training on cybersecurity and privacy protocols.
---
## 4. Sub-processor Governance
**4.1 General Authorization:** The Data Controller grants general written authorization to the Data Processor to engage sub-processors (e.g., Supabase, Vercel, AWS, Stripe, Resend) to support Platform operations.
**4.2 Contractual Flow-down:** We execute binding agreements with all sub-processors imposing data protection obligations no less restrictive than those in this DPA.
**4.3 Sub-processor Notice & Objection Rights:** We maintain a list of active sub-processors and will provide thirty (30) days advance notice of any new sub-processor. The Data Controller may object on reasonable data protection grounds within fourteen (14) days. If unresolved, the Controller may terminate the Service without penalty.
---
## 5. Technical Security & 72-Hour Data Breach Notification
**5.1 Technical and Organizational Measures (TOMs):** The Data Processor implements robust security measures including TLS 1.3 encryption in transit, AES-256 encryption at rest, Row-Level Security (RLS) policies, multi-tenant data isolation, and strict role-based access control (RBAC).
**5.2 72-Hour Data Breach Notification:** In the event of a confirmed security incident resulting in unauthorized access to, alteration of, or loss of Customer Data ("Data Breach"), the Data Processor shall notify the Data Controller without undue delay, and in no event later than 72 hours after confirming the breach. We will provide full technical cooperation to assist the Controller in meeting statutory breach notification obligations.
---
## 6. Audit and Inspection Rights
**6.1 SOC 2 / Security Certifications:** Upon annual written request, the Data Processor shall provide the Controller with copies of our latest SOC 2 Type II audit report or third-party security assessments.
**6.2 Security Questionnaires:** If provided audit reports do not satisfy regulatory requirements, the Data Processor shall respond in good faith to reasonable security questionnaires submitted by the Controller.
---
## 7. Artificial Intelligence (AI) and Large Language Models (LLM) Zero-Retention Policy
**7.1 Zero Model Training:** Core Durability, LLC unequivocally guarantees that Customer Data, facility water parameters, and laboratory Legionella culture reports shall NOT be used to train, fine-tune, or improve any public or proprietary AI/LLM models.
**7.2 Zero-Retention API Operations:** Any automated PDF parsing or RAG functionality utilizing LLM APIs operates under strict zero-data-retention enterprise agreements preventing third-party model training or persistent data storage.
---
## 8. Limitation of Liability & Allocation of Risk
**8.1 Liability Alignment:** Liability arising out of or related to this DPA, whether in contract, tort, or under any other theory, is subject to the limitation of liability provisions set forth in Section 9 of the Master Terms of Service, including the Direct Damages Liability Cap and Data Breach Super-Cap.
**8.2 Exclusion of Physical Operations Liability:** The Data Processor is not liable for physical facility safety outcomes, Legionella outbreaks, or regulatory non-compliance resulting from inaccurate data provided by the Data Controller or the Controller's failure to execute physical water management plans.
---
## 9. Data Disposition Upon Termination
Upon termination of the Service, the Data Controller may export all Customer Data via standard export features. Within thirty (30) days following subscription termination, the Data Processor shall permanently delete all Customer Data from production systems, unless retention is required by applicable law.