Ralco ralco.ai ← Back to ralco.ai

Data Processing Agreement

DATA PROCESSING AGREEMENT

This Data Processing Agreement (“DPA”) is entered into as of February 1, 2026 by and between:

Controller: [Client Name], [entity type], 17 Percy Place, Dublin 4, D04 V250, Ireland (the “Controller”); and

Processor: Ralco Compliance Limited, a company incorporated in Ireland (company number 759312), with its registered office at 17 Percy Place, Dublin 4, D04 V250, Ireland (the “Processor”).

This DPA governs the Processing of Personal Data by the Processor on behalf of the Controller in connection with the workforce management services provided under the parties’ services agreement (the “Principal Agreement”). This DPA is incorporated into and forms part of the Principal Agreement.

1. Definitions

Capitalized terms not defined herein have the meanings given in the Principal Agreement. In this DPA:

“Applicable Data Protection Laws”means all laws relating to the processing of Personal Data applicable to the Services, including the GDPR, CCPA/CPRA, BIPA, and any other applicable data protection or biometric privacy laws.

“Biometric Data”means biometric identifiers and biometric information as defined under BIPA, including fingerprint scans and facial geometry scans.

“Data Breach”means a breach of security leading to the unauthorized access to, or destruction, loss, or alteration of, Personal Data.

“Personal Data”means any information relating to an identified or identifiable natural person that is Processed by the Processor in connection with the Services, as described in Annex 1.

“Processing”means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.

“Sub-processor”means any third party engaged by the Processor to Process Personal Data on behalf of the Controller.

2. Roles and Scope

2.1 TheController is the controller of the Personal Data and determines the purposes and means of Processing. The Processor Processes Personal Data solely on behalf of the Controller and in accordance with the Controller’s documented instructions as set out in this DPA and the Principal Agreement.

2.2 TheProcessor shall not Process Personal Data for any purpose other than providing the Services, unless required by applicable law (in which case the Processor shall inform the Controller before Processing, unless prohibited by law).

2.3 Thedetails of the Processing are set out in Annex 1.

3. Controller Responsibilities

The Controller is responsible for: (a) ensuring it has a lawful basis for the Processing; (b) providing all required notices to data subjects; (c) obtaining all necessary consents, including written consent for Biometric Data collection to the extent required by BIPA or other applicable law; and (d) implementing the end-user consent flow for Biometric Data using the clickwrap mechanism provided by the platform.

4. Processor Obligations

The Processor shall:

(a) ProcessPersonal Data only in accordance with the Controller’s documentedinstructions;

(b) ensurethatpersonsauthorized to Process Personal Data are subject to confidentialityobligations;

(c) implementappropriate technical and organizational security measures to protect Personal Data, as described in Section5;

(d) complywith the sub-processor requirements in Section6;

(e) assistthe Controller in responding to data subject requests under Applicable Data ProtectionLaws;

(f) assistthe Controller in complying with its security, breach notification, and data protection impact assessmentobligations;

(g) atthe Controller’s choice, return or delete all Personal Data after the end of the Services (subject to any legal retention requirements); and

(h) makeavailable information necessary to demonstrate compliance with this DPA and allow for audits as described in Section 7.

5. Security

5.1 TheProcessor shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized Processing, accidental loss, destruction, or damage. Such measures shall be appropriate to the sensitivity of the data, including enhanced measures for Biometric Data.

5.2 Inthe event of a Data Breach, the Processor shall notify the Controller without undue delay, including: (a) a description of the breach and data affected; (b) the likely consequences; and (c) measures taken or proposed to address the breach. The Processor shall cooperate with the Controller in investigating and remediating the breach.

6. Sub-processors

6.1 TheController provides general written authorization for the Processor to engage Sub-processors. Current Sub-processors are listed in Annex 2.

6.2 TheProcessor shall notify the Controller at least 30 days before engaging a new Sub-processor. If the Controller objectsonreasonable data protection grounds within 15 days, the parties shall discuss in good faith. If unresolved, the Controller may terminate the affected Services without penalty on 30 days’ notice.

6.3 TheProcessor shall impose data protection obligations on each Sub-processor no less protective than this DPA and shall remain liable for each Sub-processor’s performance.

7. Audits

7.1 TheProcessor shall make available to the Controller, on reasonable request and no more than once per year (unless a Data Breach has occurred), information necessary to demonstrate compliance with this DPA.

7.2 TheProcessor may satisfy an audit request by providing a current SOC 2 Type II report or comparable certification. If the report does not address the Controller’s concerns, the Controller may conduct an on-site audit on 30 days’ notice during business hours.

8. Biometric Data

To the extent the Services involve Biometric Data, the Processor shall: (a) not sell, lease, or profit from Biometric Data except as necessary to provide the Services; (b) not disclose Biometric Data to third parties except approved Sub-processors, with data subject/Controller consent, or as required by law; (c) protect Biometric Data with a standard of care no less protective than that applied to other confidential information; and (d) permanently destroy Biometric Data when the purpose for collection is satisfied or within 3 years of the data subject’s last interaction with the Services, whichever is first.

9. International Data Transfers

Personal Data is stored in the United States (Amazon Web Services). Processor personnel in Ireland may access Personal Data remotely in connection with the Services. To the extentany suchaccess constitutes an international transfer under the GDPR, the parties rely on the Sub-processor’s Standard Contractual Clauses and data processing addenda, or such other transfer mechanism as the parties agree is appropriate.

10. Liability

Liability under this DPA is subject to the limitations and exclusions set out in the Principal Agreement.

11. Term and Termination

11.1 ThisDPA is effective for the duration of the Principal Agreement and for so long thereafter as the Processor continues to Process Personal Data.

11.2 Upontermination of the Principal Agreement, the Processor shall, at the Controller’s election, return all Personal Data in a machine-readable format or securely deleteit,within 30 days. The Processor may retain Personal Data where required by law, subject to continued compliance with this DPA.

12. General

12.1GoverningLaw.This DPA is governed by the laws of the State of New York. For GDPR compliance matters, EU/EEA law applies to the extent required.

12.2Conflict.In the event of conflict between this DPA and the Principal Agreement, this DPA prevails with respect to Personal Data Processing.

12.3Amendments.This DPA may only be amended in writing signed by both parties.

_______________________________________________

ANNEX 1 – Description of Processing

ANNEX 2 – Approved Sub-processors

Note:Confirm whether additional third-party services touch Personal Data (e.g., push notifications, SMS/email providers, analytics, crash reporting, payroll integrations) and add them here.

© 2026 Ralco Technologies, Inc. All rights reserved. 515 Madison Avenue, New York