Effective: with the agreement it forms part of
Plain-English summary
When a customer’s use of GAEZLA involves other people’s personal information (their employees, their systems’ users), this Addendum limits what we may do with it: we process it only on the customer’s instructions, protect it, use only the listed sub-processors, report incidents within 72 hours, and delete it when the contract ends. Written to satisfy CCPA/CPRA service-provider requirements; governed by Delaware law.
1. Scope and roles
This Addendum forms part of the agreement between the Customer and T1P5M4RK, LLC (“Company”) — whether formed by checkout acceptance of the Terms of Service or by signed Order Form — and takes effect with it, taking precedence over the Terms for Personal Information. “Business”, “Service Provider”, “Personal Information”, and “Sensitive Personal Information” have their CCPA meanings (Cal. Civ. Code § 1798.140, as amended); equivalent terms in other applicable US state privacy laws apply correspondingly. The Customer is the Business; Company is the Service Provider. A “Security Incident” is a confirmed unauthorised acquisition of, access to, or disclosure of unencrypted Personal Information in Company’s possession.
Company processes Personal Information only on the Customer’s documented instructions — this Addendum, the Terms or Order Form, and the Customer’s configuration of the Service. If Company believes an instruction would violate applicable US privacy law, it will notify Customer promptly and may suspend that instruction pending resolution.
2. Service-provider commitments (CCPA/CPRA)
Company will:
(a) process Personal Information only to perform the Service or as CCPA § 1798.140(ag)(2) permits — and will not sell or share it, retain, use, or disclose it for any other purpose or outside the direct business relationship, or combine it with Personal Information from other sources except as 11 CCR § 7050 permits; (b) ensure personnel processing it are bound by confidentiality obligations; (c) maintain the security measures in Annex II; (d) engage sub-processors only under Section 4; (e) reasonably assist Customer in responding to verifiable consumer requests (access, deletion, correction, opt-outs); (f) notify Customer promptly if it can no longer meet its CCPA obligations; and (g) on reasonable written request, provide information demonstrating compliance, and permit one reasonable audit per year at Customer’s cost on 30 days’ notice, subject to confidentiality and operational security.
3. Customer obligations
Customer warrants that it has given all required notices and holds a lawful basis under applicable US privacy law for the Personal Information it provides; that it will not configure the Service to ingest Sensitive Personal Information without first agreeing additional written safeguards with Company; and that it will promptly inform Company of any change to its instructions.
4. Sub-processors
Customer authorises the sub-processors listed at /legal/sub-processors. Company will give at least 30 days’ notice of any addition or replacement; if Customer objects and Company cannot accommodate the objection, Customer may terminate the affected subscription without penalty on 30 days’ notice. Company binds each sub-processor in writing to obligations at least as protective as this Addendum and remains liable for their acts.
Where Customer configures a bring-your-own AI integration, Company is not a Service Provider for data Customer sends to that provider.
5. Security Incident notification
On becoming aware of a Security Incident, Company will notify Customer without undue delay and within 72 hours of confirmation, describe the nature, scope, likely consequences, and measures taken or proposed, and cooperate reasonably with Customer’s response and US state notification obligations.
6. Deletion
On termination or expiry of the subscription, Company deletes Customer Data from production within 30 days and from backups within 90 days, except as US law requires retention, and will certify deletion in writing on request.
7. Non-US regimes and governing law
Company does not undertake compliance with non-US privacy regimes (including the EU/UK GDPR, Swiss FADP, EU Standard Contractual Clauses, or UK IDTA) in this Addendum; customers subject to them are responsible for their own assessment and may negotiate separate written terms. This Addendum is governed by Delaware law; exclusive venue is the state and federal courts of New Castle County, Delaware.
Annex I — Details of processing
| Item | Detail |
|---|---|
| Parties | Business: the Customer. Service Provider: T1P5M4RK, LLC, 1111B S Governors Ave Ste 90229, Dover, DE 19904, USA |
| Subject matter and duration | Personal Information within Customer Data — including data the Service ingests from the Customer Estate on Customer’s authorisation — for the subscription term, plus 30 days (production) / 90 days (backups) |
| Nature and purpose | Ingestion, storage, analysis, and presentation of Customer Estate data, and execution of Customer-Authorized Actions, to provide the GAEZLA Service |
| Consumers | Customer’s employees, contractors, administrators, and users of systems the Service is configured to observe or act on |
| Categories | Identifiers (usernames, emails, account IDs); device and network identifiers (hostnames, serials, MAC/IP); network telemetry; log entries; configuration data; ticketing metadata; whatever else Customer configures the Service to ingest |
| Sensitive Personal Information | Not processed by default; Customer must not ingest it without additional written safeguards |
| Location | Cloudflare’s global network; no regional-storage commitment |
Annex II — Technical and organisational measures
| Measure | Implementation |
|---|---|
| Encryption | TLS 1.2+ in transit; AES-256 at rest (Cloudflare R2) |
| Access control | Production access restricted, hardware-key MFA; least-privilege service identities; encrypted secrets |
| Tenant isolation | Per-tenant identifiers; no shared-runtime customer code execution |
| Network | Cloudflare global edge, DDoS protection, bot management |
| Logging | Security-relevant events recorded with timestamp and acting identity |
| Vulnerability management | Automated dependency scanning; expedited critical patching |
| Resilience | Cloudflare global failover; automated backups |
| Sub-processors | Bound by equivalent written obligations |
