1. Scope and roles
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Vuong Tich (LineProTrack) ("Processor", "we") and the Customer ("Controller", "you"). It applies where we process personal data on your behalf in providing the service.
You are the controller of that personal data and are responsible for the lawfulness of the data you put into the service and of the instructions you give us. We are the processor and act only on your documented instructions.
Terms such as "personal data", "processing", "data subject", "controller" and "processor" have the meaning given in the GDPR (Regulation (EU) 2016/679), and equivalent meanings under other applicable data protection law.
2. Processing instructions
We process personal data only (a) as set out in Annex I, (b) as necessary to provide, secure and support the service, and (c) on your further documented instructions. Using the service constitutes an instruction to process personal data accordingly.
If we believe an instruction infringes applicable data protection law, we will inform you without undue delay. If we are required by law to process personal data other than on your instructions, we will inform you beforehand unless the law forbids it.
We do not use your personal data for our own purposes. Specifically, we do not use it to train machine learning models, to build profiles, or for marketing.
3. Confidentiality
We ensure that persons authorised to process personal data are bound by confidentiality obligations, receive access strictly on a need-to-know basis, and have that access removed when it is no longer required.
4. Security measures
We implement appropriate technical and organisational measures under Article 32 GDPR, described in Annex II and in more detail on our Security page. We may update these measures over time provided the level of protection is not reduced.
5. Sub-processors
You give general authorisation for us to engage sub-processors. The current list is in Annex III. Each sub-processor is bound by data protection obligations no less protective than those in this DPA, and we remain fully liable for their performance.
We will give you at least [[notice period — to be confirmed, e.g. 30 days]] notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds, we will work with you to find a solution; if none is found, you may terminate the affected part of the service without penalty for the unused prepaid period.
On-premise deployments involve no sub-processors, because no data leaves your infrastructure.
6. Assistance to the Customer
We will assist you, taking into account the nature of the processing:
- in responding to requests from data subjects exercising their rights — the service also lets you access, correct, export and delete data directly;
- in carrying out data protection impact assessments and prior consultations with supervisory authorities;
- in meeting your own security and breach notification obligations.
If a data subject contacts us directly about data we process on your behalf, we will refer them to you and will not respond substantively ourselves unless you instruct us to.
7. Personal data breach
We will notify you without undue delay, and in any event within [[notification window — to be confirmed, e.g. 48 hours]] of becoming aware of a personal data breach affecting your data. The notification will describe the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken or proposed. We will provide further information as the investigation progresses.
8. Return and deletion
On termination of the service, and at your choice, we will return your personal data in a commonly used format or delete it, and delete existing copies, within [[period — to be confirmed, e.g. 30 days]] — unless applicable law requires us to keep it longer, in which case we will tell you what we must keep and for how long. Backup copies are deleted in the ordinary backup rotation, within [[backup rotation period — to be confirmed]].
9. Audits
We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will allow and contribute to audits conducted by you or an auditor you appoint, at your cost, no more than once per year (or after a personal data breach), subject to reasonable notice, confidentiality obligations, and minimum disruption to our operations. Where available, providing an independent audit report satisfies this obligation.
10. International transfers
Where we transfer personal data protected by the GDPR outside the EEA, the transfer is made under the European Commission's Standard Contractual Clauses, which are incorporated into this DPA by reference, with Annexes I, II and III below serving as the corresponding annexes to those clauses. Where other national transfer rules apply, we will implement an equivalent lawful transfer mechanism.
11. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. If there is a conflict, this DPA prevails over the Terms of Service in relation to the processing of personal data, and the Standard Contractual Clauses prevail over both.
Annex I — Details of processing
| Subject matter | Provision of the LineProTrack production scheduling service |
| Duration | The term of the subscription, plus the deletion period in clause 8 |
| Nature and purpose | Hosting, storage, computation of production schedules and delay forecasts, display to authorised users, generation of reports and exports |
| Types of personal data | Business contact details of authorised users (name, work email, phone, role, employer); user identifiers and sign-in logs; any personal data the Controller includes in production records, such as names of planners, operators or supplier contacts |
| Categories of data subjects | The Controller's employees and contractors; employees of the Controller's suppliers and customers who are granted Viewer access |
| Special categories | None. The service is not designed for special category data and the Controller must not upload it |
| Frequency | Continuous, for the duration of the subscription |
Annex II — Technical and organisational measures
- Access control. Role-based authorisation enforced server-side on every request; four roles with least-privilege defaults; unique accounts per user.
- Authentication. Short-lived access tokens; refresh tokens in
httpOnlycookies; passwords hashed with scrypt and unique salts; constant-time comparison; rate limiting on sign-in. - Tenant isolation. The tenant identifier is derived exclusively from the server-signed token, never from client input; computation caches are request-scoped.
- Transmission security. HTTPS/TLS for the hosted service; HSTS enabled.
- Application hardening. Strict Content Security Policy with hash-pinned scripts; no inline event handlers; no third-party scripts or CDNs; input validation against path traversal and prototype pollution.
- Data minimisation in responses. API responses are filtered so that internal computation parameters are never returned.
- Availability. Backups of the hosted service [[frequency and retention — to be confirmed]].
- Organisational. Access limited to personnel who need it; confidentiality obligations for all personnel; changes reviewed before deployment.
- Current limitations are stated openly on our Security page, including the absence of an independent penetration test and of a user-level audit log at the date of this document.
Annex III — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| [[hosting provider — to be confirmed]] | Infrastructure hosting and storage | Singapore |
| [[email provider — to be confirmed]] | Transactional email delivery | Singapore |
No sub-processors are involved in on-premise deployments.
Questions about this document? Write to lineprotrack@gmail.com.