Back to Home

Legal Information

Review the terms that apply to using RESCUE ID and how we handle your personal information.

RESCUE ID, LLC - Data Processing Addendum

Effective Date: May 26, 2026

WE DO NOT PROVIDE EMERGENCY SERVICES.

IF YOU ARE EXPERIENCING AN EMERGENCY, IMMEDIATELY DIAL 911.

Data Processing Addendum

This Data Processing Addendum (this “DPA”) supplements the Master Services Agreement or other agreement that references and incorporates this DPA (the “Agreement”), and sets out the obligations of each Party with respect to the Processing of Client Personal Data in connection with the Agreement. Capitalized terms used, but not defined within, the body of this DPA (including Section 7 (Definitions)) shall have the meanings ascribed to them in the Agreement.

1.  SCOPE AND RELATIONSHIP OF THE PARTIES

a.Relationship. Client is the Controller and RESCUE ID is the Processor with respect to all Client Personal Data Processed under the Agreement.

b.Scope of Processing. RESCUE ID shall, except where required by Law, only Process Client Personal Data to deliver and improve the Services (including to train artificial intelligence, machine learning, and similar technologies) or on the documented instructions of the Client, including as set forth in this DPA and the remainder of the Agreement. The subject matter, duration, nature, and purpose of Processing are described in the Agreement and applicable Order.

2.  OBLIGATIONS OF RESCUE ID

a.Lawful Processing. Except as otherwise set forth in the Agreement or as required by Law, RESCUE ID shall: (i) ensure that Persons authorized to Process Client Personal Data are bound by appropriate confidentiality obligations; (ii) comply with all applicable Laws governing the Processing of Client Personal Data; (iii) not Sell or Share Client Personal Data; or (iv) not retain Client Personal Data for any commercial purpose outside the provision of Services under the Agreement. RESCUE ID shall promptly notify Client if it determines that any instruction infringes applicable Law.

b.No Independent Duty. Notwithstanding anything to the contrary in the Agreement (including this DPA), Client acknowledges and agrees RESCUE ID has no obligation to independently collect consent from or provide notice to any Data Subjects or to investigate the completeness, accuracy, or sufficiency of any instruction or Client Personal Data.

c.Cooperation. Taking into account the context and nature of the Processing by RESCUE ID, RESCUE ID shall reasonably cooperate with and provide reasonable assistance to Client as necessary for Client to fulfill its own obligations under applicable Law (such as documenting Processing activities, performing privacy impact assessments, etc.).

d.DSR Assistance. RESCUE ID will assist Client in fulfilling its obligation to respond to DSR requests under applicable Law by implementing appropriate technical measures within the Services to enable Client to ‘self-help’; provided, however, that if such self-help functionality does not enable Client to fulfill such DSR, then RESCUE ID shall provide all other reasonable assistance to Client upon request. To the extent RESCUE ID directly receives a DSR request from a Data Subject and that relates to Client Personal Data, then RESCUE ID shall not respond to the DSR request other than to instruct the Data Subject to submit such DSR request directly to Client.

e.Security. Taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of Processing, and the risks to Client Data, RESCUE ID will use commercially reasonable efforts to implement appropriate physical, technical, and organizational measures designed to protect Client Personal Data against unauthorized destruction, loss, alteration, disclosure thereof, or access thereto.

f.Breach Notification. RESCUE ID will notify Client of a Security Breach in accordance with, including within the timelines required by, applicable Law. In the event of any such Security Breach, the Parties shall cooperate to take commercially reasonable measures within each Party’s control to remedy or mitigate the effects of the Security Breach, including, in the case of RESCUE ID, that RESCUE ID will perform a root cause analysis designed to identify the cause of such Security Breach provide a summary of the steps taken to remedy the Security Breach and to prevent a reoccurrence, and identify the Client Personal Data affected by such Security Breach. As the Controller, Client acknowledges and agrees that it retains sole responsibility for determining what applicable Laws apply to the affected data and if a personal data breach has occurred under such laws, as well as for fulling its obligations as Controller in light thereof. Client also acknowledges that any Person’s access to its Emergency Profile(s) does not constitute a Security Breach.

g.Data Retention. Upon request, RESCUE ID will delete Client Personal Data in its (or its Subprocessors’) possession within 30 days, except as required to retain such data by Law or its data retention policies (until such period expires).

h.Subprocessors. Client grants RESCUE ID general authorization to engage Subprocessors to assist in providing the Services and performing its obligations under the Agreement. RESCUE ID shall impose data protection obligations on each Subprocessor that are at least equivalent to those in this DPA. RESCUE ID remains responsible to Client for the acts of its Subprocessors to the same extent as if such actions were taken by RESCUE ID. Where applicable Law so allows, Client is entitled to reasonably object to the appointment or replacement of a Subprocessor within 10 days of first becoming aware of such appointment or replacement. RESCUE ID will, at its election, either give Client an opportunity to pay for the Service without use of the objectionable Subprocessor (to the extent reasonable) or terminate, subject to the terms of the Agreement, the specific Service(s) affected by the Subprocessor at issue.

3.  OBLIGATIONS OF CLIENT

Client (including its Authorized Users) shall comply with all applicable Laws attendant upon its Processing of Client Personal Data or its performance under the Agreement with respect to Client Personal Data. Without limiting the foregoing, Client shall: (i) not Process, provide or otherwise instruct RESCUE ID to Process Client Personal Data unless it has all necessary rights and complied with all requirements under applicable Laws to do so (such as providing notices or obtaining consents as required by applicable Laws), including that Client shall not Process, provide or otherwise instruct RESCUE ID to Process Sensitive Data without obtaining the Data Subject’s consent as required by applicable Law; (ii) conduct and maintain all required internal and external documentation, including data protection assessments, privacy impact assessments, records of Processing activities, as required by Law; (iii) fulfill all DSRs as required by Law; (iv) implement all security measures and other safeguards as required by applicable Law, including prior to Transferring or in order to Transfer Client Personal Data to RESCUE ID.

4.  INTERNATIONAL DATA TRANSFERS

Client shall not Transfer Client Personal Data to RESCUE ID and RESCUE ID shall not Transfer Client Personal Data onwards except to the extent permitted by applicable Law. If applicable Law requires the participation of RESCUE ID to legitimize the Transfer, such as the execution of standard contractual clauses, Client shall notify RESCUE ID and the Parties will cooperate in good faith to implement the required transfer mechanism prior to any Transferring of that data.

5.  AUDITS AND INSPECTIONS

RESCUE ID will allow for and contribute to audits conducted by Client or an external auditor selected by Client by, in lieu of onsite or remote-access audits, (i) responding to an information security questionnaire, including providing a pre-populated security questionnaire in an industry recognized format, no more than once per calendar year. Client retains the right to conduct a direct audit not more than once per calendar year if any material deficiencies are identified in such responses; provided, however, that: (1) Client shall provide RESCUE ID with reasonable prior notice of not less than 30 days; (2) such audit shall be conducted during normal business hours and shall not unreasonably interfere with RESCUE ID’s business; (3) such audit shall be conducted at Client’s expense; (4) the Parties shall agree to negotiate, in good faith, a statement of work that outlines the scope, time frames, and confidentiality obligations of such audit.

6.  GENERAL PROVISIONS

The terms of the Agreement govern this DPA, including the confidentiality, indemnification, limitations of liability, disclaimer of warranties, governing law, and miscellaneous provisions. In the event of conflict between this DPA and the remainder of the Agreement, they should be read as closely together as possible and, to the extent they cannot, the DPA terms prevail solely with respect to the Processing of Client Personal Data (and shall otherwise have no other effect). In addition to the other construction and interpretation terms set forth in the Agreement, defined terms in this DPA include all analogous terms under separate Laws even if such laws use a different defined term (such as, for example, the defined term of “Processor” includes the analogous term of “service provider” used by separate applicable Laws).

7.  DEFINITIONS

a.“DSR” means the rights over their Personal Data afforded to Data Subjects under applicable Law, such as the rights: to confirm the Processing thereof by a Controller, to access a copy (which may include a portable copy), correct, delete, or opt-out of certain Processing of such Personal Data.

b.“Client Personal Data” means the Personal Data that Client or its Authorized Users provides for Rescue ID to Process on behalf of Client in connection with the Services. Client Personal Data does not include Usage Statistics.

c.“Controller” means the Person(s) that determines the purpose and means of Processing Personal Data.

d.“Processor” means a Person that Processes Personal Data on behalf of a Controller.

e.“Security Breach” means a confirmed breach of RESCUE ID’s (or its Subprocessor’s) security that results in the unauthorized destruction, loss, alteration, disclosure of, or access to Client Personal Data where such breach of security is likely to result in a significant risk of harm to Data Subject(s) or where RESCUE ID is otherwise required by applicable Law to notify Client thereof.

f.“Share” means the sharing, disclosing, or transferring of Personal Data for cross-context behavioral advertising, provided that such prohibitions on Sharing apply solely to the extent required by applicable Law.

g.“Sell” means the sharing, disclosing, or transferring of Personal Data for monetary or other valuable consideration to a third party, provided that such prohibitions on Selling apply solely to the extent required by applicable Law. Sell does not include the sharing, disclosing, or transferring of Personal Data: (i) to a Subprocessor or affiliate; (ii) to provide a product or service requested by the Data Subject or Controller; (iii) to the Data Subject; or (iv) as part of a merger or acquisition.

h.“Subprocessor” means a Subcontractor used by RESCUE ID to the extent that such Subcontractor Processes Client Personal Data on behalf of RESCUE ID.

i.“Transfer” means the transfer of Client Personal Data across geographic borders.