Skip to main content

Data Processing Addendum

Last updated: 2026-09-04

This Data Processing Addendum ("DPA") forms part of the agreement — the Terms of Service and any Service Order — between MspCoreX SRL ("Processor") and the subscribing organization ("Controller") for the use of the MspCoreX platform. It sets out the terms under which the Processor processes Personal Data on behalf of the Controller, in accordance with Article 28 of the EU General Data Protection Regulation (GDPR).

1. Scope and roles

  • The Controller (your organization) determines the purposes and means of processing personal data.
  • The Processor (MspCoreX SRL) processes personal data on behalf of the Controller.
  • This DPA applies to all personal data processed through the MspCoreX platform.

2. Data processed

Categories of personal data processed include:

  • User identification data (name, email, role).
  • Authentication data (hashed passwords, MFA tokens).
  • Operational data (tickets, time entries, notes, attachments).
  • Client and contact data managed by the Controller within the platform.
  • Technical data (IP addresses, device information, access logs).

3. Processing instructions

  • The Processor shall process personal data only on documented instructions from the Controller.
  • Processing is limited to what is necessary to provide the MspCoreX platform services.
  • The Processor shall not process personal data for any other purpose without prior written consent.
  • Personnel authorized to process personal data are bound by confidentiality obligations.

4. Security measures

The Processor implements the following technical and organizational measures:

  • Encryption in transit (TLS 1.2+) and at rest.
  • Passwords stored only as salted cryptographic hashes; MFA available on all accounts.
  • Multi-tenant data isolation at the application and database level.
  • Automated session expiration and idle timeout.
  • Audit trail for all data-modifying operations.
  • Access controls based on role-based policies.
  • Regular security reviews and patch management.

The full list of technical and organizational measures is on our Security page.

5. Sub-processors

The Controller grants the Processor general authorization to engage sub-processors strictly necessary to run the service. That authorization reaches the entries recorded as Platform in the Scope column of the sub-processor register at /legal/subprocessors, which records each sub-processor's purpose, location, scope and transfer basis. That register, rather than any description in this section, is the operative list. An entry recorded as Tenant-selected processes personal data only where the Controller connects it, ordinarily under the Controller's own account or API key.

  • The Controller will be notified of any material changes to sub-processors at least 30 days in advance.
  • The Controller may object to a new sub-processor within 14 days of notification.
  • The Processor shall not engage a Platform sub-processor without a written contract imposing data protection obligations no less protective than those of this DPA, and remains liable to the Controller for that sub-processor's performance of them. A recipient that receives personal data under a legal obligation is outside that undertaking.
  • Where the Controller connects a Tenant-selected sub-processor, the Processor's obligations under this DPA continue to apply to the personal data the Processor transmits to it and receives from it on the Controller's instructions.

6. Data subject rights

The Processor shall assist the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) within the timeframes required by the GDPR. Requests received directly by the Processor that concern data processed on the Controller's behalf will be forwarded to the Controller without undue delay.

7. Data breach notification

  • The Processor shall notify the Controller of any personal data breach without undue delay and no later than 48 hours after becoming aware of it.
  • Notification shall include the nature of the breach, categories of data affected, estimated number of records, and measures taken or proposed.

8. Data retention and deletion

  • Personal data is retained for the duration of the service agreement.
  • The Controller may request export of its data in a structured, machine-readable format within 30 days of termination.
  • Upon termination, the Processor shall delete all personal data within 90 days, except where retention is required by law. Backups are overwritten on a rolling 30-day window.

9. Audit rights

The Controller has the right to audit the Processor's compliance with this DPA. Audits shall be conducted with reasonable notice and during normal business hours. The Processor shall cooperate and provide necessary documentation.

10. International transfers

Personal data is stored and processed within the European Union. Where a sub-processor processes data outside the EU/EEA, the transfer mechanism the Processor relies on for that sub-processor — an adequacy decision, or Standard Contractual Clauses (SCCs) with supplementary measures — is recorded in the Transfer basis column of the sub-processor register at /legal/subprocessors. Where that column reads pending, the transfer impact assessment and the clauses for that sub-processor are still being finalised.

11. Term and termination

This DPA is effective for the duration of the service agreement. The data processing obligations survive termination until all personal data has been deleted or returned.

12. Contact

For DPA-related inquiries:
MspCoreX SRL
CUI 55420060 · Reg. Com. J2026049623008 · EUID ROONRC.J2026049623008
Aleea Sinaia nr. 6, Sector 2, Bucharest, Romania
Email: privacy@mspcorex.com
Web: www.mspcorex.com