Data Processing Addendum
This DPA supplements the Terms or order between the Customer and GDA TRUST Ltd., 11 Cherni vrah Blvd, 1421 Sofia, Bulgaria, VAT BG206736228, when GDA TRUST Ltd. processes personal data on the Customer's behalf through LiveFeed API.
1. Roles, scope and instructions
The Customer acts as controller and GDA TRUST Ltd. as processor unless the circumstances require different roles. Documented instructions consist of the contract, order, portal settings, authorised API use and later lawful written instructions. GDA TRUST Ltd. will inform the Customer if it believes an instruction infringes applicable law and may suspend that instruction pending clarification.
2. Processor obligations
GDA TRUST Ltd. processes data only to deliver, secure, support and maintain LiveFeed API under Customer instructions, unless law requires otherwise. Authorised persons are bound by confidentiality, access is limited by need, and the measures in Annex 2 are maintained.
3. Customer obligations
The Customer ensures lawful bases, notices and permissions; issues lawful instructions; minimises data; configures roles and credentials correctly; and does not submit special-category data, children's data, full payment credentials or secrets not required by the service.
4. Subprocessors
The Customer grants general authorisation for the providers in the public register. GDA TRUST Ltd. imposes substantially equivalent protection duties and remains responsible as required by law. Additions or replacements receive at least 30 days' notice, except urgent changes needed for security or continuity.
The Customer may object during that period on documented data-protection grounds. The parties will seek a reasonable solution; if none is available, the Customer may terminate the affected service component before the new provider becomes active.
5. Individual requests
Taking account of the processing, GDA TRUST Ltd. reasonably assists with access, rectification, erasure, restriction, portability and objection. A request received directly for Customer data is forwarded without a substantive response unless instructed or legally required. Extraordinary assistance may be charged by prior agreement.
6. Security and incidents
GDA TRUST Ltd. maintains safeguards appropriate to risk. It notifies the Customer of a confirmed breach without undue delay and, where reasonably possible, within 48 hours, providing available details on nature, impact, individuals, response and contact point. Notification is not an admission of liability.
7. DPIAs, authorities and audits
GDA TRUST Ltd. provides reasonably available information for impact assessments and authority consultations. Once per year it provides security documentation or answers a reasonable questionnaire. Additional audits require at least 30 days' notice, must protect other customers and systems, and are paid by the Customer unless required because of an attributable incident or authority order.
8. International transfers
Transfers outside the EEA use a valid mechanism, including adequacy decisions, the EU-U.S. Data Privacy Framework where applicable, or European Commission Standard Contractual Clauses. The parties will incorporate the applicable clauses and supplementary safeguards when required.
9. Return and deletion
On termination, at the Customer's choice and where technically available, GDA TRUST Ltd. returns or deletes personal data processed on its behalf within 30 days. Residual backup copies are isolated and erased through ordinary rotation, normally within 90 days. Data required by law remains restricted.
10. Term, liability and precedence
This DPA remains effective while GDA TRUST Ltd. processes data for the Customer. Liability limits in the Terms or order apply to this DPA to the extent allowed by law. This DPA prevails for personal-data conflicts; mandatory transfer clauses prevail for international transfers.
Annex 1: processing description
| Subject matter | LiveFeed API delivery through APIs, SSE, WebSocket, portal, customer administration, support, security and billing. |
|---|---|
| Duration | Contract term and the limited period required for deletion, backups and post-contract duties. |
| Nature and frequency | Collection, recording, organisation, consultation, transmission, restriction and erasure; continuous during service use. |
| Purposes | Authenticate users and integrations, apply permissions and limits, distribute authorised data, manage settings, support, security and continuity. |
| Individuals | Customer employees, contractors, administrators, operators and technical contacts; end users only if entered by the Customer in authorised systems. |
| Personal data | Name, role, email, username, client ID, IP, user agent, access and usage logs, permissions, settings, tickets and technical metadata. No special categories are intended. |
Annex 2: technical and organisational measures
- TLS for public traffic, HTTPS/WSS and encrypted administrative channels.
- Hashed passwords; individual, revocable API keys not redisplayed in clear text where avoidable.
- Server-side roles and scopes, logical customer separation, least privilege and restricted administrative access.
- Rate limiting, configurable whitelists, security logging and anomalous-use controls.
- Secrets separated from code, isolated environments and containers, firewall and repeated-attempt blocking.
- Backups and recovery procedures; updates, vulnerability management and change control.
- Minimised public telemetry; passwords, API keys and sensitive payloads excluded from analytics.
- Incident, credential-revocation, customer-termination and retention procedures.
Annex 3: authorised subprocessors
The current list and purposes are incorporated by reference from the Subprocessors page, which records its effective date and change history.
Acceptance
This DPA becomes binding when referenced in an order or accepted electronically by the Customer. For a countersigned copy, send authorised signatory details to marketing@gda-trust.com.