Data Processing Addendum
Privacy-law contract terms for partners receiving personal information and for vendors processing it for TortMatics.
Effective Sep 23, 2026
Part A — Partners receiving personal information (third parties)
Where TortMatics sells or discloses personal information to Partner, as required by Cal. Civ. Code §1798.100(d), 11 CCR §7053, and similar state laws, Partner agrees that:
- It receives personal information only for the limited and specified purposes in the Data Usage Policy.
- It will comply with the CCPA and other applicable privacy laws and provide the same level of protection they require.
- TortMatics may take reasonable steps to ensure Partner uses the information consistently with these obligations, including requesting attestations and audits, and to stop and remediate unauthorized use.
- It will notify TortMatics within 5 business days if it can no longer meet these obligations.
- It will honor opt-out, deletion, correction, and consent-withdrawal requests forwarded by TortMatics.
- For consumer health data (Washington, Nevada, Connecticut), it will process data only as authorized by the consumer, keep sale authorizations for six years, and not further sell or share the data.
- It will not attempt to re-identify de-identified data.
Part B — Vendors processing for TortMatics (service providers / processors)
Vendors that process personal information on TortMatics' behalf (for example hosting, database, email, consent certification, call center) agree to process it only on documented instructions and for the business purpose of the engagement, and to:
- not sell or share it, or retain, use, or disclose it outside the direct business relationship;
- not combine it with information from other sources except as permitted by law;
- keep it confidential and secure, with personnel bound by confidentiality;
- flow these terms down to subprocessors and give notice of new subprocessors;
- assist with consumer requests and data protection assessments;
- delete or return it at the end of the engagement; and
- certify compliance and permit reasonable audits.
Security standards
Encryption in transit and at rest, multi-factor authentication for administrative access, access logging, vulnerability management, and an incident response plan with notice to TortMatics within 48 hours.