# Data Processing Agreement (DPA)
**Effective Date:** September 6, 2026
**Last Updated:** September 6, 2026
**Between:** Core Durability, LLC (an Arizona limited liability company) doing business as WaterShield ("Data Processor", "Company") and The Customer ("Data Controller", "Facility")
**Incorporation:** This Data Processing Agreement ("DPA") forms an integral legal schedule to the WaterShield Master Platform Terms of Service.
---
## 1. Regulatory Roles & Instructions
**1.1 Regulatory Roles:** For the purposes of global data protection regulations (including GDPR, CPRA, and state data privacy statutes), the Customer is the **Data Controller** and Core Durability, LLC is the **Data Processor**.
**1.2 Documented Instructions & Scope:** Data Processor shall process Customer Data exclusively to provide environmental water quality compliance, IoT telemetry ingestion, and automated QMS documentation in accordance with Controller's documented instructions set forth in this DPA, the Master Terms of Service, and your active platform configuration. Scope of Customer Data includes facility schematics, water sampling logs, IoT sensor telemetry, biocide/temperature readings, and laboratory Certificate of Analysis (CoA) records. Commercial account billing data is governed separately by our Privacy Policy.
---
## 2. User Responsibilities & Controller Obligations
**2.1 Sampling Data Accuracy Responsibilities:** The Data Controller retains primary legal responsibility for the physical truthfulness, sampling chain-of-custody, lawfulness, completeness, and integrity of all Customer Data submitted to the Platform. This includes an affirmative obligation to ensure that all manual sampling logs, field measurements, and imported laboratory culture results accurately reflect physical facility conditions.
**2.2 Lawful Basis and Consents:** The Data Controller warrants that it has obtained all necessary rights, notices, and legal bases required to collect and transmit facility operational data and employee credential details to the Data Processor.
**2.3 Verification of Automated Lab Data Ingestion:** To ensure data integrity, the Data Controller is responsible for validating LIMS and EDD import feeds, and must manually verify all OCR and LLM PDF parsing outputs against official physical laboratory Certificate of Analysis (CoA) reports before taking clinical, operational, or public health actions.
---
## 3. Personnel Confidentiality
Core Durability, LLC ensures that all employees, contractors, and agents authorized to process Customer Data are bound by strict contractual confidentiality obligations and receive regular training on cybersecurity and privacy protocols.
---
## 4. Sub-processor Governance
**4.1 General Authorization:** The Data Controller grants general written authorization to the Data Processor to engage verified infrastructure sub-processors (Supabase, Vercel, Stripe, Resend) to support Platform operations.
**4.2 Flow-down of Obligations:** Processor imposes contractual obligations no less restrictive than this DPA upon all sub-processors.
**4.3 Sub-processor Notice & Objection Rights:** Processor maintains an up-to-date list of active sub-processors and provides thirty (30) days advance notice of any new sub-processor. The Data Controller may object on reasonable data protection grounds within fourteen (14) days. If unresolved, the Controller may terminate the Service without penalty.
---
## 5. Technical & Organizational Measures (TOMs) & 72-Hour Data Breach Notification
**5.1 Technical and Organizational Measures (TOMs):** The Data Processor implements and maintains rigorous security measures:
- Data in Transit: TLS 1.3 encryption across all public and internal service boundaries.
- Data at Rest: AES-256 encryption across all databases, storage volumes, and backups.
- Tenant Isolation: PostgreSQL Row-Level Security (RLS) policies guaranteeing cryptographic multi-tenant separation.
- Immutability: Automated database triggers (`tf_enforce_compliance_immutability`) preventing historical record tampering.
**5.2 72-Hour Statutory Data Breach Notification:** In the event of a confirmed security incident resulting in unauthorized access to, alteration of, or loss of Customer Data ("Data Breach"), the Data Processor shall notify the Data Controller without undue delay, and in no event later than 72 hours after confirming the incident. Data Processor shall provide technical cooperation and root-cause analysis to assist Controller in meeting statutory breach notification obligations.
---
## 6. Audit and Inspection Rights (SOC 2 & Certifications)
**6.1 Security Certifications & SOC 2:** Upon annual written request, the Data Processor shall provide the Controller with copies of our latest SOC 2 Type II audit report or third-party security assessments demonstrating compliance with GDPR Article 28 and industry security standards.
**6.2 Security Questionnaires:** If provided audit reports do not satisfy regulatory requirements, the Data Processor shall respond in good faith to reasonable security questionnaires submitted by the Controller.
---
## 7. Artificial Intelligence (AI) Zero-Retention & Zero-Training Warranty
**7.1 Zero Model Training:** Core Durability, LLC unequivocally guarantees that Customer Data, facility water parameters, and laboratory test reports shall NOT be used to train, fine-tune, or improve any public or proprietary AI or Large Language Model.
**7.2 Multimodal Zero-Retention:** All uploaded images (including PaddleVision paddle test photographs, equipment schematics, and scanned lab report PDFs) are processed transiently in volatile memory and are zero-retained by AI inference sub-processors operating under strict zero-data-retention enterprise agreements.
---
## 8. Limitation of Liability & Risk Allocation
**8.1 Liability Alignment:** Liability arising out of or related to this DPA, whether in contract, tort, or under any other theory, is strictly governed by and subject to the limitation of liability provisions set forth in Section 9 of the Master Terms of Service, including the Direct Damages Liability Cap ($500.00) and Data Breach Super-Cap (two times subscription fees paid in preceding 12 months).
**8.2 Exclusion of Physical Operations Liability:** The Data Processor is not liable for physical facility safety outcomes, microbiological pathogen proliferation, or regulatory non-compliance resulting from inaccurate data provided by the Data Controller or Controller's failure to execute physical water management plans.
---
## 9. Data Disposition Upon Termination & Regulatory Audit Retention
**9.1 Deletion Schedule:** Upon subscription termination, Controller has thirty (30) days to export compliance dossiers and operational records via standard export features. Following said thirty (30) days, Processor shall permanently sanitize and delete all operational Customer Data from active production databases in accordance with NIST SP 800-88 Rev. 1 media sanitization standards.
**9.2 Regulatory Audit Trail Carve-Out:** Notwithstanding Section 9.1 or any conflicting instruction from Controller, Data Processor shall retain cryptographically sealed audit trails, RFC 8785 SHA-256 Merkle root event logs, 21 CFR Part 11 compliant digital signature manifests, chain-of-custody records, and executed Business Associate Agreements (BAAs) for a minimum regulatory retention period of seven (7) years following contract termination (or such longer period required by applicable healthcare accreditation or statutory standards, including CMS Conditions of Participation, The Joint Commission EC.02.05.01, and HIPAA 45 CFR § 164.530(j)). All such retained records shall remain protected under immutable database storage policies and triggers, shall be isolated from operational processing, and shall be maintained exclusively for legal defense and surveyor inspection.