Corporate Data Processing Addendum (DPA)

Version dated 28 August 2026. This DPA applies when an agreement, order, or connection form with Analytical Agency Era of Changes, LLC incorporates it and a legal entity provides employee, representative, or end-client personal data for the Portfolio feature.

1. Parties and roles

“Customer” is the legal entity in the applicable agreement or order. “Provider” is exclusively Analytical Agency Era of Changes, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, USA. For end-client data, Customer is the controller/record holder and Provider is the processor. Analytical Agency Era of Changes LLC (Kyrgyz Republic) is not a party to this DPA, processor, or subprocessor and does not receive portfolio data. An agreement only with the Kyrgyz Company does not activate this DPA or include the Portfolio service.

2. Subject, duration, and instructions

Processing continues for the main agreement and the return/deletion period. Its subject is secure receipt, storage, synchronisation, display, and analytical processing of portfolios, alerts, and support. Documented instructions consist of the main agreement, Customer settings, this DPA, and lawful written instructions. Provider informs Customer if it reasonably believes an instruction violates applicable law.

3. Individuals and data

Individuals include Customer representatives, employees, users, and end clients. Data includes identifiers and contacts, organisation and authority; broker/exchange/crypto platform and masked account; positions, instruments, quantities, value, balances, transactions, valuations, risk profile and sync metadata; pseudonymous external identifiers, a reference to a secret in the separate broker-secrets-only store and non-reversible digests; access and request logs. Special-category data and trading/online-banking passwords must not be submitted.

4. Provider obligations

5. Technical and organisational measures

A managed database separated from WordPress; private networking and exact firewall rules; mutual TLS; short-lived subject-bound signed tokens; existing portfolio values retained in their current protected environment; automatic-connection secrets isolated in a separate broker-secrets-only Vault with no access to existing portfolio keys; separate read, write, sync, and owner roles; no broker-secret access for the read service; access logging; step-up owner access; backups; update controls; and cross-user isolation testing.

6. Subprocessors and transfers

Customer gives general written authorisation for subprocessors on the published list. Material new subprocessors are notified at least 15 days in advance unless an urgent security replacement requires less time. Customer may reasonably object; the parties seek an alternative, otherwise the affected feature may end. Provider imposes equivalent obligations. International transfers use an applicable mechanism, including contractual safeguards and EU Standard Contractual Clauses for EEA data where required.

7. Incidents

After confirming a personal-data breach, Provider notifies Customer without undue delay, provides known data/individual categories, likely consequences, mitigation, and a coordination contact, and supplies updates as the investigation progresses. Notification is not an admission of fault.

8. Requests and authorities

Provider refers a direct end-client request to Customer and does not respond substantively without instruction unless required by law. Provider assists with access, correction, portability, restriction, and erasure. A compulsory authority request is disclosed to Customer unless prohibited and is answered only to the minimum lawful extent.

9. Return, deletion, and audit

At termination, Customer may request a machine-readable export in an available format. Operational data is erased on documented instruction or service end unless law requires otherwise; after provider-confirmed disconnection, active secrets are deleted or revoked without undue delay. Deleted data may temporarily remain in isolated backups until scheduled automatic replacement and is unavailable to ordinary operations. Security logs are kept only as long as needed for security, legal compliance and claims. No more than annually, Provider supplies reasonable compliance evidence; an on-site audit is available after a material incident or mandatory requirement while protecting other customers and security secrets.

10. Customer obligations and priority

Customer determines lawful purposes and bases, provides notices, maintains accuracy and minimisation, administers user rights, and submits data only with authority. This DPA prevails over the main agreement on personal-data processing; applicable Standard Contractual Clauses prevail over the DPA to the extent of conflict.

Data contact: admin@eraperemen.info.


Share: