1. Scope and Role of Parties

This DPA supplements the Terms of Service. Pursuant to the GDPR, the Customer is the "Data Controller" and CloudStore is the "Data Processor."

2. Security and Auditing

CloudStore shall implement and maintain rigorous Technical and Organizational Measures (TOMs), including mandatory AES-256-GCM encryption at rest and TLS 1.3 in transit. CloudStore maintains active ISO/IEC 27001:2022 and SOC 2 Type II certifications. Upon thirty (30) days written notice, Enterprise Customers may request an executive summary of our latest third-party penetration test and SOC 2 audit reports under a Non-Disclosure Agreement (NDA).

3. Sub-processors

CloudStore maintains a strict whitelist of authorized sub-processors. The Controller will be notified via email thirty (30) days prior to the engagement of any new sub-processor. The Controller may object to such changes on reasonable, documented data protection grounds.

4. Breach Notification

In the event of a verified Security Incident compromising Customer Data, CloudStore shall notify the Controller without undue delay, and in no event later than 36 hours from the point of authoritative discovery, providing all requisite details required under Art. 33 of the GDPR.