This Data Processing Addendum (“DPA”) forms part of the agreement between Chasvi Co Limited and a Stoneware business customer when Chasvi Co Limited processes personal information on that customer’s behalf.
If a separately signed DPA or customer agreement applies, that document takes priority over this public DPA to the extent of any conflict.
1. Roles
The customer determines the purposes for and means by which customer-controlled personal information is entered into and used within Stoneware. Chasvi Co Limited processes that information to provide Stoneware and the customer’s authorised instructions. Chasvi Co Limited may separately act as the responsible organisation for account administration, billing, security, service communications and other information processed for its own legitimate business purposes.
2. Processing instructions
We will process customer-controlled personal information only to provide, secure, support and maintain Stoneware; perform the agreement; comply with documented customer instructions; or meet legal obligations. If an instruction appears to require unlawful processing, we may pause the affected processing while the parties clarify the instruction.
3. Confidentiality and access
Personnel and contractors with access to customer-controlled personal information must be subject to appropriate confidentiality obligations and receive access only where reasonably necessary for their role.
4. Security measures
We will maintain reasonable technical and organisational measures appropriate to the risk, including access control, authentication and permission enforcement, company and tenant scoping, operational logging, secure software practices and measures intended to protect against unauthorised access, alteration, loss or disclosure.
5. Subprocessors
We may use subprocessors for infrastructure, hosting, security, communications, support, billing, integration and related service functions. We remain responsible for requiring subprocessors that process customer-controlled personal information to protect it consistently with applicable contractual and legal obligations. We may update subprocessors as the service evolves and will provide information about material subprocessors through reasonable customer channels.
6. International processing
Where processing involves overseas providers or disclosures, we will use safeguards appropriate to the circumstances and applicable New Zealand privacy requirements. Customers remain responsible for transfer choices created by integrations they independently configure.
7. Assistance with individual rights
Taking into account the nature of the processing, we will provide reasonable assistance to enable the customer to respond to lawful requests for access, correction or other applicable privacy rights relating to customer-controlled personal information.
8. Privacy and security incidents
We will take reasonable steps to investigate and contain confirmed incidents affecting customer-controlled personal information. Where the incident is relevant to the customer’s legal obligations, we will provide information reasonably available to us to assist the customer’s assessment and notifications. Chasvi Co Limited will also meet its own notification obligations where it is legally responsible to do so.
9. Return and deletion
Following termination or expiry, customer-controlled personal information will be returned, made available for export or deleted in accordance with the applicable service capability, agreement, retention requirements and lawful backup cycles. We may retain information where required by law or reasonably necessary for security, audit or dispute purposes.
10. Audit and compliance information
On reasonable request, we will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security and proportionality. Audits that require access to systems, facilities or confidential information must be agreed in advance and conducted in a way that does not compromise other customers or service security.
11. Processing schedule
12. Governing terms
This DPA is governed by the governing-law provisions of the applicable Stoneware agreement. If no separate agreement specifies governing law, New Zealand law applies.