Enterprise customers can request a pre-signed Data Processing Agreement. Contact our legal team to receive a signed copy.
Request Signed DPA →This Data Processing Agreement ("DPA") forms part of the Terms of Service between Ledger Link, Inc. ("Processor") and the Customer ("Controller") and governs the processing of personal data in connection with the Services.
The Customer is the Controller of Personal Data. Ledger Link is the Processor, processing Personal Data on behalf of the Controller according to documented instructions.
This DPA applies to the processing of Personal Data as described in Annex 1.
Processor shall only process Personal Data:
Controller may provide additional processing instructions in writing. If Processor believes an instruction infringes Data Protection Laws, it shall promptly notify Controller.
Processor implements appropriate security measures including:
Detailed security measures are described in Annex 2.
Processor ensures that personnel authorized to process Personal Data are subject to confidentiality obligations and have received appropriate training.
Controller authorizes Processor to engage Subprocessors listed at ledgerlink.com/subprocessors.
Processor shall notify Controller at least 30 days before engaging new Subprocessors. Controller may object within 14 days on reasonable grounds.
Processor shall ensure Subprocessors are bound by data protection obligations substantially similar to those in this DPA.
Processor shall assist Controller in responding to Data Subject requests including:
Processor shall respond to Controller's requests for assistance within 10 business days, or sooner if required by law.
Processor shall notify Controller without undue delay (and within 48 hours) upon becoming aware of a Personal Data breach.
Notification shall include:
Processor shall cooperate with Controller in investigating, mitigating, and remediating the breach, and in making any required notifications.
For transfers of Personal Data outside the EEA, Processor relies on:
Processor implements supplementary technical and organizational measures to ensure an adequate level of protection following the Schrems II decision.
Controller may audit Processor's compliance with this DPA upon reasonable notice. Audits shall be conducted during normal business hours with minimal disruption.
Processor makes available relevant certifications, audit reports (SOC 2 Type II), and other documentation to demonstrate compliance.
This DPA remains in effect for the duration of the Services agreement and until all Personal Data has been deleted or returned.
Upon termination, Processor shall:
Each party's liability under this DPA is subject to the limitations set forth in the Terms of Service, except that limitations shall not apply to breaches of Data Protection Laws caused by a party's gross negligence or willful misconduct.
| Subject Matter | Provision of inventory management services |
| Duration | Duration of Services agreement |
| Nature of Processing | Collection, storage, organization, retrieval, use, disclosure, erasure |
| Purpose | Providing inventory management, user authentication, analytics, and support |
| Categories of Data Subjects | Customer employees, contractors, and authorized users |
| Types of Personal Data | Names, email addresses, job titles, user activity logs, IP addresses |
| Special Categories | None (by design) |
Legal Inquiries: legal@theledgerlink.com
Data Protection Officer: dpo@theledgerlink.com
Mail: Ledger Link, Inc.
Legal Department
785 Garden St
Bronx, NY 10460
This DPA is incorporated by reference into the Ledger Link Terms of Service. By using the Services, Customer agrees to this DPA.