Data Processing Addendum
How we process personal data on behalf of our customers.
Reference copy
This document is published for reference so prospective customers and procurement teams can review our standard terms. The operative version for any given customer is the one attached to and executed with their signed Order Form. Where the two differ, the executed version governs.
Data Processing Addendum
CrisisCommand, Inc.
Last updated: July 21, 2026
SCOPE AND ROLES. This Data Processing Addendum (“DPA”) supplements the Platform Agreement or other agreement between CrisisCommand, Inc. (“CrisisCommand”) and Customer governing Customer’s use of the Service (the “Agreement”). This DPA governs CrisisCommand’s processing of Personal Data on behalf of Customer to the extent required to provide the Service. Capitalized terms not defined herein have the meanings given in the Agreement. In the event of conflict between this DPA and the Agreement, this DPA controls with respect to its subject matter.
-
Roles. As between the parties, Customer is the Data Controller and CrisisCommand is the Data Processor, processing Personal Data on Customer’s behalf solely for the purpose of providing or maintaining the Service in accordance with Customer’s Instructions.
-
Categories of Personal Data. Personal Data contained within Customer Data and Content, which may include names, contact information, role descriptions, and organizational information. The Service is designed to operate with summarized situational information and organizational context, as described in Section 5.5 of the Agreement.
-
Categories of Data Subjects. Individuals identified or identifiable in Customer Data and Content, which may include Customer’s employees, designated crisis response team members, and stakeholders.
-
Duration. Personal Data will be processed for the term of the Agreement and deleted in accordance with Section 7.4 of the Agreement.
PROCESSING REQUIREMENTS. CrisisCommand will: (i) process Personal Data only on behalf of Customer, according to Customer’s Instructions, and only as necessary for the performance of the Service; (ii) promptly notify Customer if it cannot comply with this DPA or if, in CrisisCommand’s opinion, an Instruction infringes applicable Data Protection Law; and (iii) ensure that all persons authorized to process Personal Data are subject to a duty of confidentiality. Customer’s execution of the Agreement and use of the Service constitute Customer’s documented Instructions to CrisisCommand to process Personal Data as contemplated by the Agreement and this DPA.
CUSTOMER OBLIGATIONS. Customer represents and warrants that it has and will maintain all necessary rights, consents, and authorizations to provide Personal Data to CrisisCommand and to authorize the processing contemplated by this DPA. Customer is responsible for ensuring that data submitted to the Service complies with the Prohibited Data restrictions in Section 3.4 of the Agreement and does not include Protected Health Information, FERPA-protected student records, or other regulated data excluded under Section 12.3 of the Agreement.
SECURITY AND INCIDENT RESPONSE. CrisisCommand’s security obligations are set forth in Section 11.7 of the Agreement. CrisisCommand’s breach notification obligations are set forth in Section 11.8 of the Agreement. In the event of a Personal Data Breach, CrisisCommand will provide Customer with reasonably available information as required by applicable Data Protection Law.
NO TRAINING. CrisisCommand’s obligations regarding the prohibition on using Customer Data and Content to train AI or machine learning models are set forth in Section 5.6 of the Agreement and apply to all Personal Data processed under this DPA.
SUBPROCESSORS. CrisisCommand’s subprocessor obligations, including advance notification, Customer objection rights, and termination remedies, are set forth in Section 11.9 of the Agreement. CrisisCommand will enter into written agreements with each Subprocessor imposing data protection obligations no less protective than this DPA. CrisisCommand remains liable for the performance of each Subprocessor to the extent such Subprocessor fails to fulfill its data protection obligations under its agreement with CrisisCommand, subject to the limitations of liability set forth in the Agreement.
DATA SUBJECT REQUESTS. If CrisisCommand receives a request from a Data Subject to exercise their rights under applicable Data Protection Law (including rights of access, correction, deletion, restriction, portability, or objection), CrisisCommand will promptly notify Customer and will not respond to the request without Customer’s prior written authorization, except to direct the Data Subject to Customer. CrisisCommand will provide reasonable assistance to Customer in responding to such requests, taking into account the nature of the processing.
GOVERNMENT AND LAW ENFORCEMENT REQUESTS. CrisisCommand will, to the extent legally permitted, promptly notify Customer if CrisisCommand receives: (i) any legally binding request for disclosure of Personal Data by a law enforcement authority; (ii) any notice, inquiry, or investigation by a Supervisory Authority with respect to Personal Data; or (iii) any subpoena, court order, or other compulsory legal process seeking Personal Data. If CrisisCommand is legally prohibited from notifying Customer, CrisisCommand will use commercially reasonable efforts to obtain a waiver of the prohibition and will notify Customer once the prohibition is lifted.
REQUIRED PROCESSING. If CrisisCommand is required by applicable law to process Personal Data outside of Customer’s Instructions, CrisisCommand will inform Customer of this requirement in advance of any processing, unless CrisisCommand reasonably believes it is legally prohibited from doing so.
ASSISTANCE AND AUDITS. Upon Customer’s written request, CrisisCommand will provide reasonable assistance regarding:
-
Customer’s obligations to respond to Data Subject Requests;
-
Customer’s preparation of data protection impact assessments with respect to the Service, and where necessary, consultations with any Supervisory Authority; and
-
information or documentation reasonably necessary to confirm that CrisisCommand is processing Personal Data in a manner consistent with this DPA. Customer may request such documentation no more than once per twelve (12) month period, unless a Personal Data Breach has occurred or an audit is required by applicable Data Protection Law or Supervisory Authority. CrisisCommand will make its then-current SOC 2 report (when available) or equivalent security documentation available to satisfy audit requests. All reports and documentation provided are CrisisCommand’s Confidential Information.
US STATE PRIVACY OBLIGATIONS. To the extent applicable under US State Privacy Law, CrisisCommand certifies that it understands and will comply with its obligations to:
-
process Personal Data only for the purposes set out in this DPA and the Agreement, unless otherwise permitted by law;
-
not “sell” or “share” (as defined by applicable US State Privacy Law) Personal Data;
-
not retain, use, or disclose Personal Data outside of the direct business relationship between CrisisCommand and Customer, unless otherwise required or permitted by law;
-
not combine Personal Data with personal data received from or on behalf of third parties, except as permitted under applicable US State Privacy Law or as directed by Customer;
-
not attempt to reidentify any deidentified data, except solely to verify that deidentification processes comply with applicable Data Protection Law; and
-
grant Customer the right to take reasonable and appropriate steps to ensure that CrisisCommand uses Personal Data in a manner consistent with applicable Data Protection Law, and to stop and remediate unauthorized use of Personal Data.
CROSS-BORDER DATA TRANSFERS. Customer acknowledges that CrisisCommand processes Personal Data exclusively in the United States. The Service is intended for subscription by entities organized under the laws of the United States or a State thereof; the parties do not contemplate that Customer is established in, or that the Service will be used to process Personal Data subject to data-residency or localization requirements of, the EEA, the United Kingdom, Switzerland, or any other non-U.S. jurisdiction. To the extent Customer’s authorized users located in the EEA, the United Kingdom, or Switzerland access the Service in connection with Customer’s U.S.-based subscription, and such access results in a transfer of Personal Data that requires a lawful transfer mechanism under applicable Data Protection Law, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two (Controller-to-Processor)) are hereby incorporated into this DPA by reference and deemed executed by the parties, completed as follows: Customer is the data exporter and CrisisCommand is the data importer; the governing-law and forum options default to the law of Ireland unless otherwise required; and the subject matter, duration, nature, and purpose of processing are as described in Section 1 of this DPA. For transfers subject to UK Data Protection Law, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (issued under Section 119A of the UK Data Protection Act 2018) is incorporated by reference and completed using the corresponding information above. This Section does not extend the Service to customers domiciled outside the United States, and CrisisCommand assumes no obligations under non-U.S. data-localization or residency laws.
FUTURE AI REGULATIONS. If new legislation or regulations specifically governing the use of artificial intelligence require modifications to this DPA, both parties will negotiate in good faith to make necessary amendments. If such regulations render continued provision of the Service infeasible or unlawful, either party may terminate the Agreement upon reasonable written notice without penalty, subject to CrisisCommand’s obligation to refund any prepaid unused Fees.
DEFINITIONS.
-
“Data Controller” means the person or entity that determines the purposes and means of processing Personal Data, including equivalent concepts under Data Protection Law (e.g., “Business” as defined by CCPA).
-
“Data Processor” means the person or entity that processes Personal Data on behalf of the Data Controller, including equivalent concepts under Data Protection Law (e.g., “Service Provider” as defined by CCPA).
-
“Data Protection Law” means privacy and data protection laws applicable in connection with Customer’s use of the Service, which may include the European Union General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the UK Data Protection Act 2018 and UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), the Texas Data Privacy and Security Act (“TDPSA”), and other applicable US state privacy laws.
-
“Data Subject” means an identified or identifiable natural person to which Personal Data relates.
-
“Instructions” means any documented communication from Customer, including Customer’s use of and configuration of the Service, the Agreement, applicable Order Forms, and the Documentation.
-
“Personal Data” means any information relating to an identifiable natural person that is protected under Data Protection Law and processed in connection with Customer’s use of the Service, including equivalent concepts such as “personal information” as defined under CCPA.
-
“Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Personal Data.
-
“Supervisory Authority” means an independent public authority with jurisdiction over data protection matters in the applicable jurisdiction.
-
“US State Privacy Law” means all state laws relating to the protection and processing of Personal Data in effect in the United States, which may include the CCPA, the TDPSA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and other applicable state privacy laws.