Data Processing Agreement
This Data Processing Agreement (the “DPA”) describes POWR’s obligations with respect to Personal Data Processed under the Agreement. This DPA is hereby incorporated into and made a part of the Agreement. The terms of this DPA will control to the extent inconsistent with the Agreement.
1. DEFINITIONS
Any capitalized terms not defined herein will have the definition used in the Agreement. For the purposes of this DPA:
-
“Controller” means the entity that determines the purposes and means of Processing Personal Data. Customer is the Controller of Personal Data processed through POWR Services.
-
“Data Breach” means a compromise of security leading to unauthorized Processing of Personal Data and the legal obligation to notify affected Data Subjects or a Supervisory Authority.
-
“Data Protection Laws” means all laws applicable to the Processing of Personal Data under this DPA, including but not limited to, the GDPR, UK GDPR, the California Consumer Privacy Act (“CCPA”), and any other applicable federal, state, local, or international data protection legislation.
-
“Data Subject” means an identified or identifiable individual whose Personal Data is processed under this DPA.
-
“Data Subject Request” means any communication from a Data Subject seeking to exercise any rights in Personal Data or the Processing thereof (including any request to limit the use or disclosure of Sensitive Data) under applicable Data Protection Laws.
-
“Personal Data” means any information relating to an identified or identifiable natural person that is processed by POWR on behalf of Customer through the Services.
-
“Processing” means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction. “Process,” “Processed,” and other grammatical variations of “Processing” have corresponding meanings, except that “Processor” has the meaning given to it below.
-
“Processor” means the entity that processes Personal Data on behalf of the Controller. POWR is the Processor.
-
“Sub-processor” means any third party engaged by POWR to process Personal Data on behalf of Customer.
-
“Supervisory Authority” means an agency, official, instrumentality, supervisory authority, or other governmental entity.
2. ROLES AND RESPONSIBILITIES
2.1 Roles of the Parties
The Parties acknowledge and agree that with respect to the Processing of Personal Data under this DPA, Customer acts as the Controller and POWR acts as a Processor. POWR shall process Personal Data only on behalf of and in accordance with Customer’s documented instructions, except where allowed or required to do otherwise by applicable Data Protection Law.
2.2 Customer Responsibilities as Controller
Customer is the Controller of Personal Data and is responsible for:
-
Ensuring it has a lawful basis for collecting and Processing Personal Data. Where Customer is subject to GDPR and relies on the “legitimate interests” basis under Article 6(1)(f) of GDPR, Customer shall conduct and document an appropriate legitimate interest assessment;
-
Providing clear privacy notices to Data Subjects in accordance with applicable Data Protection Law, which notices shall include, without limitation, the purposes of processing, the identity of the Controller and Processor, categories of data collected, data retention periods, international transfer safeguards, their rights under applicable Data Protection Law, and contact information for exercising those rights;
-
Obtaining necessary consents from Data Subjects where required;
-
Determining what Personal Data is collected through POWR apps;
-
Instructing POWR on how to process Personal Data;
-
Represent and warrant that their use of the Services does not involve collection of Personal Data from children under 13 (or applicable local age threshold) without verifiable parental consent as required by applicable law, including the US Children’s Online Privacy Protection Act (COPPA);
-
And/or ensuring compliance with Data Protection Laws in its use of the Services;
2.3 POWR Responsibilities as Processor
POWR is the Processor and will:
-
Process Personal Data only in accordance with Customer’s documented instructions and only to the extent necessary to provide the Services as described in this DPA and the Terms, except as otherwise agreed to by the parties or where required or allowed by applicable Data Protection Laws;
-
Not Process Personal Data for any purpose other than providing the Services, performing technical support and maintenance, ensuring security, and preventing fraud, or complying with this DPA, the Terms, or applicable law;
-
Reasonably assist Customer in meeting its obligations under Data Protection Laws;
-
Implement appropriate technical and organizational measures to protect Personal Data;
-
And/or inform Customer if, in POWR’s reasonable opinion, any instruction from Customer violates applicable Data Protection Laws;
2.4 CCPA-Specific Obligations
POWR additionally certifies that it:
-
Will not sell or share such Personal Data as those terms are defined under the CCPA, whether for monetary or other valuable consideration;
-
Will not retain, use, or disclose such Personal Data outside of the direct business relationship with Customer, including not retaining, using, or disclosing such Personal Data for any commercial purpose other than providing the Services;
-
Will not combine Personal Data received from Customer with personal information received from other customers, collected from POWR’s own interactions with individuals, or obtained from any other source;
-
Will notify Customer if POWR determines it can no longer meet its obligations under this Section 2.4;
-
And/or grants Customer the right to take reasonable and appropriate steps to ensure POWR uses Personal Data of California residents in a manner consistent with Customer’s obligations under CPRA, including the audit rights set forth in Section 10 of this DPA;
2.5 Processing Instructions
Customer instructs POWR to process Personal Data as necessary to:
-
Provide the Services as described in the Terms
-
Comply with Customer’s configuration and use of POWR apps
-
Perform technical support and maintenance
-
Comply with applicable laws
POWR will immediately inform Customer if, in POWR’s opinion, an instruction violates Data Protection Laws.
3. DETAILS OF PROCESSING
3.1 Nature and Purpose of Processing
POWR processes Personal Data to provide website application functionality to Customer, as more formally set out in a statement of work or other order document.
3.2 Duration of Processing
POWR will process Personal Data for the duration of Customer’s subscription to the Services and for the retention periods specified in Section 9 of this DPA.
3.3 Categories of Data Subjects
Personal Data may relate to the following categories of Data Subjects: Employees, users, customers, clients, partners, contractors, and any other individuals whose data Customer chooses to collect through POWR apps.
3.4 Types of Personal Data
POWR may process the following types of Personal Data on behalf of Customer, depending on Customer’s use of the Services:
Contact Information:
-
Names (first, last, full)
-
Email addresses
-
Phone numbers
-
Mailing addresses
-
Company names
Technical Information:
-
IP addresses
-
Browser type and version
-
Device identifiers
-
Cookie data
-
Geographic location data (country, city)
-
Referring website URLs
User-Generated Content:
-
Form responses and submissions
-
Survey responses
-
Comments and feedback
-
File uploads
Transaction Data:
-
Payment information (processed by third-party payment processors; POWR does not store full credit card details)
-
Purchase history
-
Order details
Behavioral Data:
-
Website interaction data
-
Page views and navigation patterns
-
Email engagement metrics (opens, clicks)
Other Data:
- Any other Personal Data that Customer chooses to collect through configuration of POWR apps
3.5 Special Categories of Data
Customer must not use POWR Services to collect Special Categories of Personal Data as defined under GDPR Article 9 (e.g., health data, biometric data, genetic data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation) or Sensitive Personal Information/Sensitive Personal Data under U.S. state Data Protection Laws (e.g., Social Security numbers, driver’s license numbers, passport numbers, financial account credentials, precise geolocation, contents of private communications) unless Customer has:
-
Obtained explicit written authorization from POWR
-
Implemented additional security measures as required by applicable law
-
Obtained all necessary consents from Data Subjects
POWR explicitly prohibits the collection of:
-
Credit card numbers, CVV codes, or full payment credentials
-
Social Security numbers, Tax ID numbers
-
Driver’s license numbers, passport numbers
-
Medical records or health information
-
Biometric data (fingerprints, facial recognition data)
Violation of this Section 3.5 constitutes a material breach of this DPA and may result in immediate suspension or termination of Customer’s account.
4. SECURITY MEASURES
4.1 Technical and Organizational Measures
Taking into account the state of the art, costs of implementation, POWR's size, the nature of POWR's business, the categories of Personal Data Processed, and the purposes for which the Personal Data will be Processed, POWR shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including protection of Personal Data from unauthorized access, use, modification, disclosure, or other unauthorized Processing.
A current description of POWR's technical and organizational security measures is maintained at https://www.powr.io/security and is incorporated into this DPA by reference. Customers requiring additional security documentation may contact [email protected].
4.2 Security Updates
POWR reserves the right to update and modify security measures from time to time, provided that such updates do not result in a material degradation of the overall security posture applicable to Personal Data processed under this DPA.
5. SUB-PROCESSORS
5.1 Authorization to Use Sub-processors
Customer authorizes POWR to engage Sub-processors to process Personal Data on Customer’s behalf. POWR maintains a current list of Sub-processors at https://www.powr.io/subprocessors.
5.2 Sub-processor Obligations
POWR will:
-
Enter into a written agreement with each Sub-processor imposing data protection obligations substantially similar to those in this DPA
-
Remain liable to Customer for any Sub-processor’s failure to fulfill its data protection obligations
5.3 Notice of New Sub-processors
POWR will provide Customer with prior written notice of the addition or replacement of any Sub-processor by:
-
Updating the Sub-processor list at https://www.powr.io/subprocessors
-
Sending email notification to Customer’s account email address
5.4 Right to Object
Customer may object to POWR’s appointment of a new Sub-processor on reasonable data protection grounds by notifying POWR in writing within 30 days of receiving notice of the change.
If Customer objects:
-
POWR will use reasonable efforts to accommodate the objection and provide an alternative solution.
-
If no alternative solution is available, Customer may terminate the affected Services by providing written notice to POWR within 30 days.
6. DATA SUBJECT RIGHTS
6.1 Assistance with Data Subject Requests
POWR will provide reasonable assistance to Customer in the fulfillment of its obligations in relation to a Data Subject Request or in responding to a Supervisory Authority. To the extent POWR receives a Data Subject Request directly from a Data Subject regarding data Processed under this DPA, then POWR shall not respond to such Data Subject Request, except as required by applicable Data Protection Law or in order to direct the Data Subject to contact Customer in relation to the Data Subject Request. POWR shall not delete any Personal Data held on Customer’s behalf unless authorized in writing by Customer, unless in POWR’s good faith belief, POWR is prohibited from seeking such authorization or is obligated to delete such Personal Data without or before any such authorization is granted.
6.2 Customer’s Responsibility
Customer is primarily responsible for responding to Data Subject Requests. Customer will:
-
Verify the identity of Data Subjects making requests
-
Determine the validity and scope of requests
-
Communicate directly with Data Subjects regarding their requests
-
Use POWR’s self-service tools to access, correct, or delete data where available
6.3 POWR Platform Features
POWR provides the following self-service capabilities to assist Customers:
-
Dashboard access to view and export form submissions and collected data
-
Ability to delete individual records or entire datasets
-
Data export functionality in CSV/Excel format
-
Account deletion option that removes all associated Personal Data
6.4 Fees for Assistance Requests
Customer will bear POWR’s reasonable costs and expenses incurred in providing assistance under section 6.1. POWR reserves the right, in its sole discretion, to waive all or part of such costs and expenses where POWR determines the assistance is routine, limited in scope, or would result in de minimis costs or expenses.
7. INTERNATIONAL DATA TRANSFERS
Personal Data processed by POWR may be transferred to and stored in the United States and internationally.
7.1 Transfers Outside the EEA
To the extent that POWR processes Personal Data originating from the European Economic Area (“EEA”), United Kingdom, or Switzerland in countries that have not been granted an adequacy decision by the European Commission, Customer and POWR hereby incorporate the European Commission’s Standard Contractual Clauses (Module Two: Controller to Processor), mutatis mutandis, as amended from time to time. For Personal Data originating from the United Kingdom, Customer and POWR hereby incorporate the UK Addendum to the EU Standard Contractual Clauses or the International Data Transfer Agreement (IDTA) as applicable, mutatis mutandis, as if set forth fully herein.
Where required, the following details shall be deemed incorporated into the above-referenced agreements:
-
Module: Module Two (Controller to Processor).
-
Clause 7 Docking Clause: The option under this clause shall not apply.
-
Clause 9(a) Option: Option 2 (general written authorization for Sub-processor engagement with notification mechanism as per Section 5).
-
Clause 11(a) Optional Language: The option under this clause shall not apply.
-
Clause 17 Governing Law: The governing law for purposes of this clause shall be the governing law of the Agreement. If the Agreement is not governed by EU Member State law, the SCCs shall be either (i) the laws of Ireland, or (ii) where the Agreement is governed by the laws of the United Kingdom, the laws of England and Wales.
-
Clause 18 Jurisdiction: The courts under this clause shall be those designated in the Agreement. If the Agreement does not designate an EU Member State court as having exclusive jurisdiction to resolve any dispute arising out of or in connection with the Agreement, then the parties agree that the courts of the Republic of Ireland shall have exclusive jurisdiction to resolve any dispute arising from the SCCs.
-
Additional Information: The information set forth in Appendices A and B hereto shall be deemed incorporated into the above-referenced agreements as applicable.
8. DATA BREACH NOTIFICATION
8.1 Notification Obligation
POWR will notify Customer via email or notice in the POWR account dashboard, without undue delay, and, in any event, within 24 hours, after becoming aware of a Data Breach affecting Customer’s Personal Data. Thereafter, POWR and Customer shall provide reasonable cooperation to the other party in the other party’s investigation of the Data Breach.
8.2 Cooperation
POWR will:
-
provide information necessary for Customer to meet its own breach notification obligations under Data Protection Laws
-
cooperate with Customer and regulatory authorities, as necessary.
-
preserve evidence of the Data Breach for investigation and regulatory purposes.
8.3 Customer’s Obligations
Customer is responsible for:
-
determining whether the Data Breach must be reported to supervisory authorities or Data Subjects.
-
providing any required notifications to supervisory authorities and Data Subjects.
-
determining appropriate remedial actions for affected Data Subjects.
8.4 Limitations
POWR’s notification under this Section 8 will not constitute an acknowledgment of fault or liability by POWR.
9. DATA RETENTION AND DELETION
9.1 Retention During Active Subscription
POWR will retain Personal Data for as long as Customer maintains an active subscription to the Services and as necessary to provide the Services.
9.2 Retention Periods After Account Termination
Upon Termination or Expiration of Services:
-
Active Data: Customer may export data within 30 days of termination. Customers can access the POWR dashboard to download all form submissions, contacts, and collected data in CSV format.
-
Grace Period: POWR will retain Personal Data for 30 days after termination to allow for data recovery if Customer renews subscription.
-
Permanent Deletion: After the 30-day grace period, POWR will delete or anonymize all Personal Data within 90 days, except as specified below.
Backup Retention:
-
Personal Data in backups will be retained , then permanently deleted according to POWR’s backup rotation schedule.
-
Backup data cannot be selectively deleted but will be automatically purged according to the retention schedule.
Legal and Compliance Retention: POWR may retain certain data for longer periods where required by law.
Aggregated and Anonymized Data: POWR may indefinitely retain data that has been aggregated or anonymized such that it can no longer identify individuals and does not constitute Personal Data under Data Protection Laws. POWR will not attempt to re-identify Personal Data that has been anonymized or aggregated.
9.3 Customer-Initiated Deletion
Customer may request deletion of specific Personal Data at any time during the subscription by:
-
Using the delete function in the POWR dashboard
-
Contacting POWR support at [email protected]
POWR will process such deletion requests within 10 business days.
9.4 Deletion Certification
Upon written request from Customer within 30 days of termination, POWR will provide written certification that Personal Data has been deleted in accordance with this Section 9.
10. AUDITS AND COMPLIANCE
10.1 Customer’s Audit Rights
Customer has the right to audit POWR’s compliance with this DPA, subject to the following conditions:
Audit Frequency: No more than once per year unless:
-
Required by Data Protection Laws
-
POWR has suffered a Data Breach affecting Customer’s Personal Data
-
Customer has reasonable grounds to believe POWR is not complying with this DPA
Audit Scope: Audits are limited to verification of POWR’s compliance with this DPA and applicable Data Protection Laws.
Audit Process:
-
Customer must provide at least 30 days’ written notice of intent to audit
-
Audits must be conducted during POWR’s normal business hours
-
Customer must use a qualified, independent third-party auditor approved by POWR (approval not to be unreasonably withheld)
-
Auditor must sign POWR’s standard confidentiality agreement
-
Audits must not unreasonably interfere with POWR’s business operations
Costs: Customer bears all costs associated with audits unless the audit reveals material non-compliance by POWR.
10.2 Alternative Compliance Verification
In lieu of an on-site audit, POWR may, at its discretion, provide Customer with:
-
Copies of relevant third-party audit reports or certifications (e.g., SOC 2, ISO 27001)
-
Summary audit reports prepared by POWR’s internal or external auditors
-
Completed information security questionnaires
-
Other evidence of compliance reasonably requested by Customer
10.3 Remediation
If an audit reveals non-compliance, POWR will:
-
Acknowledge the findings in writing within 10 business days
-
Provide a remediation plan within 30 days
-
Implement necessary corrective measures within a reasonable timeframe agreed upon with Customer
-
Provide evidence of remediation upon completion
10.4 Regulatory Inspections
POWR will reasonably cooperate with supervisory authority inspections concerning Customer’s Personal Data, subject to applicable legal requirements and POWR’s confidentiality obligations to other customers.
11. LIABILITY AND INDEMNIFICATION
11.1 POWR’s Liability
Each party’s liability under this DPA is subject to the limitations of liability set forth in the Terms. Nothing in this DPA reduces or limits POWR’s liability under the Terms.
11.2 Allocation of Responsibility
To the extent permitted by Data Protection Laws:
-
POWR is liable only for damages caused by processing where POWR has not complied with obligations specifically directed to Processors under Data Protection Laws or has acted outside or contrary to Customer’s lawful instructions
-
Customer is liable for damages caused by processing where Customer has not complied with its obligations as a Controller under Data Protection Laws
12. RETURN AND DELETION OF PERSONAL DATA
12.1 Return and Destruction of Data
Customer has access to its Personal Data and may elect to retrieve or delete its Personal Data at any time. Upon termination or expiration of the Services within the timeframes specified in Section 9.2. POWR may retain Personal Data only to the extent required by law.
13. TERM AND TERMINATION
13.1 Term
This DPA will commence on the Effective Date and continue in full force and effect for as long as POWR processes Personal Data on behalf of Customer.
13.2 Termination
This DPA will automatically terminate upon:
-
Termination or expiration of the Terms
-
Completion of all Services involving Personal Data processing
-
Final deletion of all Personal Data in accordance with Section 9
14. GENERAL PROVISIONS
14.1 Entire Agreement
This DPA, together with the Terms and any additional terms incorporated herein, constitutes the entire agreement between the parties regarding data processing and supersedes all prior agreements, understandings, and representations.
15. ACCEPTANCE AND EXECUTION
15.1 Electronic Acceptance
By clicking “I Accept” or “I Agree” during account creation or upgrade, or by continuing to use the Services after being notified of this DPA, Customer agrees to be bound by the terms of this DPA.
15.2 Signing Authority
The individual accepting this DPA on behalf of Customer represents and warrants that they have the authority to bind Customer to this DPA.
15.3 Effective Date
This DPA becomes effective on the date Customer accepts POWR's Terms of Service and remains in effect for as long as POWR processes Personal Data on behalf of Customer in connection with the Services.
APPENDIX A: STANDARD CONTRACTUAL CLAUSES
The European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two: Controller to Processor) are incorporated into this DPA by reference. The official text is available at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0914.
ANNEX I-A: LIST OF PARTIES
This annex identifies the data exporter (Customer) and data importer (POWR) for purposes of the Standard Contractual Clauses.
Data Exporter (Controller / Customer)
| Field | Details |
|---|---|
| Name | Customer's legal entity name as registered with POWR |
| Address | Customer's registered address on file with POWR |
| Contact person name | Customer's account holder |
| Contact email | Customer's account email address |
| Activities relevant to transfer | Customer uses POWR’s website application services to collect and manage personal data of website visitors and end users through POWR-powered forms, popups, and other widgets embedded on Customer’s website. |
| Signature and date | Accepted electronically upon acceptance of POWR's Terms of Service at https://www.powr.io/terms |
| Role (Controller/Processor) | Controller |
Data Importer (Processor / POWR)
| Field | Details |
|---|---|
| Name | POWR, Inc. |
| Delaware Entity Number | 5497930 |
| Registered Agent Address | 1209 Orange St, Wilmington, DE 19801, USA |
| Principal Place of Business | 4460 Redwood Hwy, Suite 16-659, San Rafael, CA 94903, USA |
| Contact person name | Puru Dahal |
| Contact person role | Head of Engineering, Security & Infrastructure |
| Contact email (privacy) | [email protected] |
| Activities relevant to transfer | POWR provides website application services (forms, popups, social feeds, e-commerce widgets, and related functionality) to merchants. In doing so, POWR processes personal data of Customer’s website visitors and end users on Customer’s behalf. |
| Authorized signatory | Kyle Bennett, Chief Executive Officer |
| Role (Controller/Processor) | Processor |
ANNEX I-B: DESCRIPTION OF THE TRANSFER
This annex describes the categories of data subjects, types of personal data, and purposes of the transfer covered by the SCCs.
Categories of Data Subjects
| Category | Description |
|---|---|
| Website visitors | Individuals who visit Customer’s website on which POWR widgets are embedded |
| Form submitters | Individuals who submit data through POWR-powered forms on Customer’s website |
| Email subscribers | Individuals who subscribe to email lists through POWR widgets |
| Purchasers | Individuals who make purchases through Customer’s website using POWR e-commerce functionality |
| Other end users | Any other individuals whose personal data Customer collects through POWR apps |
Categories of Personal Data
| Category | Examples |
|---|---|
| Contact information | Names, email addresses, phone numbers, mailing addresses, company names |
| Technical information | IP addresses, browser type, device identifiers, cookie data, geolocation (country/city), referring URLs |
| User-generated content | Form responses, survey answers, comments, file uploads |
| Transaction data | Purchase history, order details (payment processing delegated to PCI DSS-certified processors) |
| Behavioral data | Website interaction data, page views, navigation patterns, email engagement metrics |
Sensitive Data
The transfer does not as a general matter involve sensitive categories of data as defined under GDPR Article 9. Customers are contractually prohibited under the DPA from collecting special categories of data through POWR’s services without explicit written authorization from POWR.
Frequency of Transfer
Continuous — personal data is transferred on an ongoing basis as Customer’s website visitors interact with POWR-powered widgets.
Nature of Processing
| Activity | Description |
|---|---|
| Collection | POWR collects personal data entered by end users into Customer-configured widgets |
| Storage | Data stored in GCP-managed databases in US regions |
| Organization | Data organized by Customer account and widget configuration |
| Retrieval | Customer accesses data via POWR dashboard |
| Disclosure | Data disclosed to Customer; to sub-processors as listed in Annex III; not to third parties |
| Deletion | Customer-initiated or automatic deletion per retention schedule |
Purpose of the Transfer
The transfer is necessary for POWR to provide its website application services to Customer, including operating forms, popups, social media feeds, e-commerce functionality, and related widgets embedded on Customer’s website, and to store and make accessible the personal data collected through those widgets.
Retention Period
| Scenario | Retention Period |
|---|---|
| Active subscription | Duration of active subscription |
| Post-termination grace period | 30 days |
| Post-termination permanent deletion | Within 90 days after grace period |
| Backup data | Up to 12 months from backup creation date |
| Billing and tax records | 7 years (legal retention obligation) |
| Legal claims | Until resolution of relevant claims |
ANNEX III: TRANSFERS TO SUB-PROCESSORS
POWR transfers data to the sub-processors listed in Appendix C. Each sub-processor is engaged under a written agreement with data protection obligations substantially equivalent to those in the SCCs.
APPENDIX B: TECHNICAL AND ORGANIZATIONAL MEASURES
POWR's current technical and organizational security measures are maintained at https://www.powr.io/security and are incorporated into this DPA by reference. The security measures described at that page constitute Annex II to the Standard Contractual Clauses incorporated herein. For additional security documentation, contact [email protected].
B.2 System Access Controls
-
Multi-factor authentication (MFA) required for all employee access to POWR business systems, with passkeys (WebAuthn) required for privileged and production system access.
-
Role-based access control (RBAC) limiting data access by role
-
Regular access reviews (annually)
-
Automated deprovisioning upon employee termination
-
Session timeout policies
-
IP whitelisting for sensitive systems
B.3 Data Access Controls
-
Encryption at rest using AES-256
-
Encryption in transit using TLS 1.2+
-
Database-level access controls
-
Audit logging of all data access
-
Data minimization principles applied
-
POWR operates a four-tier data classification framework. Customer Personal Data is classified as Restricted — the highest tier — subject to the most stringent access, storage, and handling controls.
B.4 Transmission Controls
-
Secure file transfer protocols (SFTP, HTTPS)
-
Email encryption for sensitive communications
-
Data loss prevention controls monitoring and restricting unauthorized external sharing of data and credentials
B.5 Input Controls
-
Data validation and sanitization
-
Input filtering to prevent injection attacks
-
Form validation on client and server side
-
Rate limiting to prevent abuse
B.6 Availability Controls
-
Daily automated backups
-
Geographically redundant backup storage
-
Disaster recovery plan with RTO/RPO targets
-
DDoS mitigation and load balancing
B.7 Separation Controls
-
Logical separation of customer data in multi-tenant environment
-
Customer data isolation through database partitioning
-
Separate development, staging, and production environments
-
Network segmentation
B.8 Organizational Measures
-
Information security policy reviewed annually
-
Security awareness training for all employees (annually)
-
Confidentiality agreements signed by all personnel
-
Incident response plan and procedures
-
Designated security team
-
Google Cloud Platform (GCP) infrastructure is covered by GCP’s SOC 2 / ISO 27001 program; POWR conducts periodic internal application-level security reviews and vulnerability assessments.
-
Vulnerability scanning (weekly)
B.9 Logging and Monitoring
-
Centralized logging of security events
-
Real-time alerting for suspicious activities
-
Log retention for 1 year
-
SIEM (Security Information and Event Management) tools deployed
B.10 Pseudonymization and Encryption
-
Customer data encrypted at rest and in transit
-
Pseudonymization is available for certain data types upon request
-
Data at rest is encrypted using AES-256 via Google Cloud’s default encryption-at-rest mechanism with Google-managed encryption keys and automatic key rotation managed by GCP.
APPENDIX C: LIST OF SUB-PROCESSORS
See the current list maintained at:
https://www.powr.io/subprocessors