FOODVERIX LEGAL
DATA PROCESSING AGREEMENT
FoodVerix Platform
This Data Processing Agreement (the “DPA”) is entered into by and between:
(1) RMP Services LLC, a Florida limited liability company, doing business as FoodVerix, with a principal address at 2310 SW 63rd Terrace, Miramar, FL 33023, United States (the “Processor”); and
(2) the customer that accepts the Principal Agreement (as defined below) and on whose behalf the Processor processes Customer Personal Data (the “Controller” or “Customer”).
Each a “party” and together the “parties.”
Background
(A) FoodVerix, operated by RMP Services LLC, a Florida limited liability company, is a cloud-based software platform through which food safety managers and Preventive Controls Qualified Individuals document food safety compliance, including HACCP plans, monitoring logs, training records, corrective actions, and audit evidence (the “Services”).
(B) In the course of providing the Services, the Processor processes certain personal data on behalf of, and under the instructions of, the Customer.
(C) The parties have entered into a subscription agreement, order, or terms of service governing the Customer’s use of the Services (the “Principal Agreement”). This DPA forms part of, and is incorporated by reference into, the Principal Agreement and governs the processing of Customer Personal Data.
(D) The parties wish to set out the terms on which the Processor will process Customer Personal Data on behalf of the Customer.
1. Definitions and Interpretation
1.1 In this DPA, capitalized terms have the meanings given below. Capitalized terms not defined here have the meaning given in the Principal Agreement.
1.2 “Applicable Data Protection Laws” means all federal and state laws and regulations of the United States relating to privacy, data protection, and data security that apply to the processing of Customer Personal Data under this DPA, as amended from time to time.
1.3 “Customer Personal Data” means the personal data described in Annex 1 that the Processor processes on behalf of the Customer in connection with the Services.
1.4 “Data Subject” means an identified or identifiable natural person to whom Customer Personal Data relates.
1.5 “Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular natural person or household.
1.6 “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Customer Personal Data processed by the Processor or a Subprocessor.
1.7 “Processing” (and “process”) means any operation performed on Customer Personal Data, whether or not by automated means, including collection, recording, storage, use, disclosure, transmission, and deletion.
1.8 “Subprocessor” means any third party engaged by the Processor to process Customer Personal Data on the Processor’s behalf in connection with the Services.
2. Roles and Scope of Processing
2.1 As between the parties, the Customer is the controller of Customer Personal Data and the Processor is the processor. The Processor processes Customer Personal Data on behalf of and under the documented instructions of the Customer, and functions as a third-party agent that maintains, stores, or processes Customer Personal Data on the Customer’s behalf.
2.2 The subject matter, nature and purpose of the processing, the duration, the types of Customer Personal Data, and the categories of Data Subjects are described in Annex 1.
2.3 The Processor does not sell Customer Personal Data, does not retain, use, or disclose Customer Personal Data for any purpose other than performing the Services or as otherwise permitted by this DPA, and does not process Customer Personal Data outside the direct business relationship between the parties, except as required by law.
2.4 This DPA governs only the processing of Customer Personal Data. It does not create, expand, or modify any obligation of the Processor regarding the content, accuracy, completeness, or regulatory sufficiency of the food safety records, compliance records, or other materials that the Customer creates, uploads, or maintains through the Services, which are governed solely by the Principal Agreement. This DPA addresses only the privacy and security of personal data relating to natural persons, and the Processor assumes no responsibility under it for the administrative, regulatory, or food safety validity or sufficiency of the Customer’s records before any authority, including the U.S. Food and Drug Administration or any other regulator. The Customer remains solely responsible for its own food safety practices and regulatory compliance.
3. Processing Instructions
3.1 The Processor processes Customer Personal Data only on the documented instructions of the Customer, including the instructions set out in the Principal Agreement and this DPA, and as necessary to provide the Services, unless required to process by applicable law, in which case the Processor will, where legally permitted, inform the Customer of that legal requirement before processing.
3.2 The Customer instructs the Processor to process Customer Personal Data as reasonably necessary to provide, maintain, secure, and support the Services, and confirms that its instructions comply with Applicable Data Protection Laws.
3.3 The Processor will inform the Customer if, in the Processor’s reasonable opinion and to the extent the Processor is aware, an instruction infringes Applicable Data Protection Laws. This does not oblige the Processor to conduct a legal review of the adequacy of the Customer’s instructions.
3.4 The Customer is responsible for the Customer Personal Data it submits to the Services and represents that it has a lawful basis to submit it. The Customer may record limited information reasonably necessary to investigate a food safety complaint or incident, but will not submit to the Services medical records, diagnoses, treatment information, insurance information, or other protected health information, and will minimize or de-identify personal information wherever reasonably possible. The Customer will not submit biometric or genetic data, precise geolocation, financial account or government identification numbers, or any personal data relating to minors, unless the parties separately agree in writing. The Customer is solely responsible for any data it submits in breach of this section, and the Processor has no liability arising from it.
4. Confidentiality
4.1 The Processor treats Customer Personal Data as confidential and ensures that persons authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality, whether by contract or by a statutory duty of confidentiality.
4.2 The Processor limits access to Customer Personal Data to personnel and authorized persons who need access to perform the Services.
5. Security Measures
5.1 The Processor implements and maintains reasonable technical and organizational measures designed to protect and secure Customer Personal Data in electronic form against a Personal Data Breach, taking into account the nature of the Services, the state of the art, and the risks presented by the processing.
5.2 The measures in effect as of the date of this DPA are described in Annex 3. The Processor may update those measures from time to time, provided that the updated measures do not materially reduce the overall level of protection of Customer Personal Data.
5.3 The Customer is responsible for its own use of the Services, including maintaining the confidentiality of its account credentials, configuring available security features such as multi-factor authentication and access controls, and determining that the Services meet the Customer’s security requirements.
6. Subprocessors
6.1 The Customer grants the Processor general authorization to engage the Subprocessors listed in Annex 2 to process Customer Personal Data in connection with the Services.
6.2 The Processor imposes on each Subprocessor, by written contract, data protection and security obligations that are substantially similar to and no less protective than those set out in this DPA, to the extent applicable to the services provided by that Subprocessor.
6.3 The Processor remains responsible to the Customer for the performance of each Subprocessor’s obligations relating to Customer Personal Data to the same extent the Processor would be responsible if performing those services itself.
6.4 The Processor will notify the Customer before adding or replacing a Subprocessor that processes Customer Personal Data, giving the Customer a reasonable opportunity to object on reasonable data protection grounds. If the Customer objects on such grounds and the parties cannot reach a resolution, the Customer may, as its sole remedy, terminate the affected Services in accordance with the Principal Agreement.
7. Personal Data Breach Notification
7.1 The Processor notifies the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay after the Processor determines, or has reason to believe, that a Personal Data Breach has occurred, and in any event no later than ten (10) days after the Processor first determines, or has reason to believe, that a Personal Data Breach has occurred. The Processor will not delay notification in order to complete its investigation, and will provide information in phases as it becomes available.
7.2 The notification will, to the extent then known and available to the Processor, describe the nature of the Personal Data Breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. The Processor will provide further information in phases as it becomes available.
7.3 The Processor reasonably cooperates with, and provides reasonable assistance to, the Customer in connection with the Customer’s investigation of the Personal Data Breach and the Customer’s obligations to notify affected individuals, regulators, or other third parties. As between the parties, the Customer is responsible for determining whether any such notification is required and for making it.
7.4 The Processor’s notification of, or response to, a Personal Data Breach is not an acknowledgment or admission of fault or liability by the Processor.
8. Assistance with Data Subject Rights
8.1 Taking into account the nature of the processing, the Processor provides reasonable assistance to the Customer, by appropriate technical and organizational measures and insofar as possible, to enable the Customer to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws, including rights of access, correction, deletion, and portability, to the extent such rights apply.
8.2 If the Processor receives a request from a Data Subject relating to Customer Personal Data, the Processor will, unless legally prohibited, promptly forward the request to the Customer and will not respond to the request directly except on the Customer’s documented instructions or as required by law.
9. Assistance with Compliance
9.1 Taking into account the nature of the processing and the information available to the Processor, the Processor provides the Customer with reasonable assistance in relation to the Customer’s obligations regarding security of processing, Personal Data Breach notification, and any data protection assessments that the Customer is required to carry out under Applicable Data Protection Laws.
10. Return or Deletion of Customer Personal Data
10.1 During the term of the Principal Agreement and any applicable access period following expiry or termination, the Customer may export Customer Personal Data through the features made available in the Services. It is the Customer’s responsibility to export any Customer Personal Data it wishes to retain before the end of that access period.
10.2 Following expiry or termination of the Principal Agreement, the Processor removes Customer Personal Data from active systems promptly, and any remaining copies held in routine backups expire within the Processor’s rolling thirty (30) day backup cycle, subject to any information the Processor is legally required to retain. This does not create an additional retention period beyond the backup cycle.
10.3 Deletion under this section is carried out using methods designed to render Customer Personal Data unreadable, unrecoverable, or otherwise unusable as the relevant systems and backups are cleared or overwritten in the ordinary course. Backup copies remain subject to the confidentiality and security obligations of this DPA until deleted.
10.4 The Processor will, on the Customer’s written request, confirm in writing that it has complied with this section.
11. Data Retention
11.1 During the term of the Principal Agreement, the Processor retains Customer Personal Data only for as long as necessary to provide the Services or as otherwise required by applicable law. The Customer may export Customer Personal Data and may direct deletion or retention through documented instructions. The Services allow the Customer to export its data, but do not provide general self-service deletion of completed and locked compliance records, which are preserved to protect audit integrity. Deletion and retention are therefore handled in accordance with the Customer’s documented instructions, subject to legally required retention, completed-record locking, audit integrity, and any applicable data subject rights.
12. Records and Audit
12.1 The Processor maintains records reasonably sufficient to demonstrate its compliance with this DPA and makes available to the Customer information reasonably necessary to demonstrate such compliance.
12.2 Where the Customer reasonably requires additional information or an audit to verify compliance, the Processor may satisfy that requirement by providing relevant documentation, security summaries, or third-party reports. Any on-site audit is limited to no more than once per year absent a Personal Data Breach or regulatory requirement, is conducted on reasonable prior written notice and during business hours, is subject to confidentiality, does not unreasonably disrupt the Processor’s operations, and is carried out at the Customer’s cost.
13. Liability and Indemnification
13.1 Each party is responsible for its own compliance with Applicable Data Protection Laws in respect of the roles it performs under this DPA.
13.2 The Processor will defend and indemnify the Customer against third-party claims, and resulting damages and reasonable costs finally awarded or agreed in settlement, to the extent arising from the Processor’s material breach of this DPA or its violation of Applicable Data Protection Laws in its capacity as processor of Customer Personal Data.
13.3 The Customer will defend and indemnify the Processor against third-party claims, and resulting damages and reasonable costs finally awarded or agreed in settlement, to the extent arising from the Customer’s instructions, the Customer’s use of the Services in violation of the Principal Agreement or Applicable Data Protection Laws, or the Customer’s role as controller of Customer Personal Data.
13.4 The party seeking indemnification will promptly notify the other of the claim, allow the indemnifying party to control the defense and settlement (provided any settlement that imposes non-monetary obligations on the indemnified party requires its consent), and provide reasonable cooperation.
14. Limitation of Liability
14.1 Each party’s total aggregate liability arising out of or related to this DPA is subject to, and counts toward, the exclusions and limitations of liability set out in the Principal Agreement. The parties intend that the aggregate liability caps and exclusions in the Principal Agreement apply to liability under this DPA and under the Principal Agreement in the aggregate, and not separately. A personal data breach or a breach of confidentiality or data protection obligations is subject to the enhanced but capped limit set out in the Principal Agreement for such claims, and in no event is either party’s liability under this DPA and the Principal Agreement uncapped.
15. Term and Termination
15.1 This DPA takes effect on the effective date of the Principal Agreement and remains in force for as long as the Processor processes Customer Personal Data on behalf of the Customer. Provisions that by their nature should survive termination, including sections 4, 10, 13, and 14, survive.
16. Governing Law and Venue
16.1 This DPA is governed by the laws of the State of Florida, without regard to its conflict of laws rules, and the parties submit to the jurisdiction of the state and federal courts located in the State of Florida, consistent with the Principal Agreement.
17. Order of Precedence
17.1 This DPA forms part of the Principal Agreement. In the event of a conflict between this DPA and the Principal Agreement with respect to the processing of Customer Personal Data, this DPA prevails. In all other respects, the Principal Agreement remains in full force and effect.
18. Miscellaneous
18.1 This DPA, together with its Annexes and the Principal Agreement, constitutes the entire agreement between the parties concerning the processing of Customer Personal Data and supersedes any prior arrangements on that subject.
18.2 Any amendment to this DPA must be in writing. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions remain in full force and effect. This DPA does not create any third-party beneficiary rights.
Signatures
Agreed and accepted by the parties. Where the Customer accepts the Principal Agreement electronically, this DPA is accepted together with it and a manual signature is not required.
PROCESSOR RMP Services LLC d/b/a FoodVerix Name: Title: Date: |
CUSTOMER (CONTROLLER) Customer entity Name: Title: Date: |
|---|
Annex 1: Details of the Processing
| Item | Description |
|---|---|
| Subject matter | Provision of the FoodVerix food safety compliance documentation platform to the Customer. |
| Nature and purpose | Hosting, storage, processing, and making available of food safety compliance documentation and related account data, so that the Customer can create, maintain, and retrieve compliance records through the Services. |
| Duration | For the term of the Principal Agreement and until Customer Personal Data is returned or deleted in accordance with section 10. |
| Categories of Data Subjects | The Customer’s authorized users and personnel (for example, food safety managers, Preventive Controls Qualified Individuals, and other employees), and any other individuals whose personal data the Customer includes in records entered into the Services. |
| Categories of Customer Personal Data | Account and contact data (name, business email, role, login identifiers) and operational compliance records that may reference identifiable personnel, such as training records, monitoring logs, corrective actions, and audit evidence. Records may include limited information reasonably necessary to investigate a food safety complaint or incident. The Services are not intended for the processing of medical records, diagnoses, treatment or insurance information, other protected health information, or data of children, and such information should be minimized or de-identified wherever reasonably possible. |
| Frequency of processing | Continuous, for the duration of the Customer’s use of the Services. |
Annex 2: Approved Subprocessors
As of the date of this DPA, the Processor engages the following Subprocessors to process Customer Personal Data in connection with the Services. The Processor and its Subprocessors are based in the United States and process Customer Personal Data primarily in the United States. Certain infrastructure providers may route or process limited traffic through their global networks depending on their configuration, as noted below.
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloudflare | Cloud hosting, content delivery, and network security for the Services. | United States, with traffic potentially routed through Cloudflare’s global network unless regional controls are configured. |
| Auth0 | User authentication and login, including multi-factor authentication. | United States |
| Backblaze B2 | Encrypted backup storage. | United States |
| Google LLC (Google Workspace) | Business email and customer-support communications. | Governed by Google’s applicable data-processing terms. |
Payment processing is not performed by a Subprocessor under this DPA. Square acts as an independent payment processor and handles payment card information through its own hosted checkout under its own terms and privacy notices. The Processor does not collect or store complete payment card numbers or card security codes. The Processor may receive limited transaction information from Square, such as payment status, amount, and transaction identifiers. That payment card processing is governed by Square’s own terms rather than by this DPA, and Square is therefore not listed as a Subprocessor above.
The Processor will update this Annex as its Subprocessors change, in accordance with section 6. Additional providers will be added here when they become active in the Services.
Annex 3: Technical and Organizational Security Measures
The Processor maintains the following technical and organizational security measures in connection with the Services, as confirmed by the Processor as of the date of this DPA:
Encryption of Customer Personal Data in transit using industry-standard protocols (HTTPS/TLS).
Encryption of Customer Personal Data at rest, including separately stored backups, which are encrypted before being uploaded.
Multi-factor authentication available where supported by the active authentication-provider plan and enabled for the applicable account.
Role-based access controls that restrict access to Customer Personal Data to authorized users and personnel based on their role.
Regular backups of Customer Personal Data on a standard schedule.
Confidentiality obligations binding personnel and other authorized persons who have access to Customer Personal Data.