Contrack

Data Processing Agreement

Effective date: 2026-05-18 · Last updated: 2026-05-18

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Contrack ("Processor") and governs the processing of personal data that you upload to the Service on behalf of your customers, employees, or other individuals.

1. Definitions

Terms defined in the GDPR (Regulation (EU) 2016/679) and the Irish Data Protection Acts 1988–2018 have the same meaning in this DPA. "Personal Data" means any information you submit to Contrack that relates to an identifiable natural person, such as customer names, addresses, email addresses, and phone numbers.

2. Roles

You are the Data Controller: you determine the purposes and means of processing Personal Data you submit to Contrack. Contrack is the Data Processor: we process Personal Data only on your documented instructions and only to provide the Service.

3. Processor obligations

Contrack shall:

  • Process Personal Data only on your documented instructions (including these Terms)
  • Ensure that personnel authorised to process Personal Data are bound by confidentiality
  • Implement appropriate technical and organisational security measures (Article 32 GDPR)
  • Assist you in responding to data subject rights requests to the extent technically feasible
  • Notify you without undue delay (and within 72 hours where feasible) of any personal data breach
  • Delete or return all Personal Data upon termination of the Service, at your choice
  • Provide all information necessary to demonstrate compliance with Article 28 GDPR

4. Sub-processors

By accepting this DPA you grant general authorisation for Contrack to engage the sub-processors listed below. We will notify you of any intended additions or replacements at least 14 days in advance, giving you the opportunity to object:

  • Stripe, Inc. — payment processing
  • Twilio SendGrid — transactional email delivery
  • PostHog, Inc. — product analytics (EU region, activated only with user consent)

5. International transfers

Where Personal Data is transferred to sub-processors outside the EEA, Contrack ensures that appropriate safeguards are in place — such as Standard Contractual Clauses (SCCs) adopted by the European Commission — before any transfer takes place.

6. Security measures

Contrack's technical and organisational security measures include, but are not limited to: encryption of data in transit (TLS 1.2+) and at rest, role-based access controls, multi-factor authentication for administrative access, automated vulnerability scanning, and regular security reviews.

7. Audit rights

You may audit Contrack's compliance with this DPA upon 30 days' written notice, no more than once per calendar year, and provided the audit is conducted during business hours and does not disrupt Contrack's operations. Contrack may satisfy this obligation by providing up-to-date third-party audit reports (e.g. SOC 2) in lieu of an on-site audit.

8. Liability

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. Nothing in this DPA limits either party's liability to data subjects or supervisory authorities as required by the GDPR.

9. Governing law

This DPA is governed by the laws of Ireland. The supervisory authority is the Data Protection Commission (Ireland).

10. Contact

Questions about this DPA or data protection matters? Email privacy@contrack.ie. See also our Privacy Policy.