Data Processing Agreement
This Data Processing Agreement outlines our technical and organizational security measures to ensure data security and compliance with applicable data protection laws, including GDPR, CCPA, and other relevant regulations.
Introduction
Collective Media Group, LLC ("True Kin", "we", "us", or "our") provides tools that help Shopify brands identify their true customers, run community and creator programs, and enrich customer intelligence using AI. This Data Processing Agreement ("DPA") describes our technical and organizational security measures for protecting personal data processed on behalf of our customers.
We are committed to maintaining the highest standards of data security and compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other relevant data protection regulations.
1. Access Control – Systems and Physical Access
We implement comprehensive access controls to ensure that personal data is only accessible to authorized personnel and systems.
Physical Security
Personal data is hosted in secure cloud data centers with robust physical security controls, including:
- On-site security personnel and 24/7 monitoring
- CCTV surveillance systems
- Biometric and key card access controls
- Secure, climate-controlled facilities with redundant power and network connectivity
Office Premises Security
Our office premises are secured by controlled access methods:
- Key card entry systems with access logging
- Visitor access logged and supervised
- Restricted access to areas containing sensitive information
System Access Controls
We maintain strict controls over system access:
- Unique user IDs assigned to all employees and service accounts requiring access to customer data
- Administrative access to production environments requires multi-factor authentication (MFA)
- Access is limited to essential personnel on a need-to-know basis
- All access attempts are logged and monitored
2. Data Access Control (Authorization)
We implement logical controls to ensure that customer data remains segregated and accessible only to authorized individuals.
Application-Level Controls
Our application architecture ensures:
- Logical segregation of each customer's data to prevent unauthorized access
- Role-based access control (RBAC) with granular permissions
- Customer data is isolated in multi-tenant environments through robust logical separation
Employee Access Management
Employee access to customer data is strictly controlled:
- Access is restricted to employees with a legitimate business need
- Support and engineering staff access customer data only when addressing specific issues, typically with customer permission
- Access requests are reviewed and approved by management
Authentication Measures
We enforce strong authentication practices:
- Strong password policies requiring complex passwords with regular rotation
- Single sign-on (SSO) utilized where possible for streamlined access management
- Multi-factor authentication (MFA) required for administrative access and sensitive operations
3. Transmission Control
We ensure that all data in transit is protected through encryption and secure communication protocols.
External Data Transmission
All data transmitted between customers and our platform is encrypted:
- HTTPS/TLS 1.2 or higher protocols for all customer connections
- Certificate-based encryption ensuring secure communication channels
- Regular security updates and patches to maintain encryption standards
Internal Service Communication
Internal service-to-service communication is secured:
- Encrypted channels for all service-to-service communication within the cloud environment
- Private secure networks (VPNs) for sensitive internal communications
- Network segmentation to isolate different service tiers
4. Input Control (Logging and Traceability)
We maintain comprehensive logging and audit trails to ensure accountability and traceability of all data processing activities.
Logging and Monitoring
We implement detailed logging for:
- All data modifications, including timestamps, user accounts, and actions performed
- Access attempts and authentication events
- Administrative actions on systems and applications
- Data access and retrieval activities
Audit Trail Management
Audit logs are maintained with:
- Secure storage of logs in tamper-proof systems
- Regular review of audit logs for anomalies and security incidents
- Retention periods in accordance with legal and compliance requirements
- Automated alerting for suspicious activities
5. Job/Process Control (Instructional Control)
We ensure that personal data is processed only in accordance with documented instructions from our customers.
Instruction Compliance
Our processes ensure:
- Personnel process customer personal data only in accordance with documented instructions from the customer
- Processing activities are clearly defined and documented
- Any deviation from customer instructions requires explicit customer consent
Employee Training and Awareness
We maintain comprehensive training programs:
- Employees are trained to use personal data solely for the specific tasks at hand
- Regular data protection and security awareness training
- Disciplinary measures in place for policy violations
- Regular review and updates of data handling procedures
6. Availability Control
We maintain high availability of our services through redundant infrastructure and comprehensive backup procedures.
Infrastructure Resilience
Our infrastructure is designed for high availability:
- Redundant systems and failover mechanisms to ensure service continuity
- Fault-tolerant architecture with automatic failover capabilities
- Load balancing and distributed systems to prevent single points of failure
- Regular disaster recovery testing and updates
Data Backup and Recovery
We maintain comprehensive backup procedures:
- Regular automated data backups performed according to defined schedules
- Backups are encrypted and stored in geographically separate locations
- Backup restoration procedures tested regularly to ensure recoverability
- Retention of backups in accordance with business and legal requirements
7. Separation Control
We ensure that data collected for different purposes is processed separately and that development environments are isolated from production.
Data Separation
We maintain clear separation of data:
- Data collected for different purposes is processed separately
- Robust logical separation in multi-tenant environments to prevent data leakage
- Clear data classification and handling procedures for different data types
Environment Separation
Development and testing environments are segregated:
- Development and testing environments are completely segregated from production
- Live personal data is not used in development or testing environments unless necessary and with equivalent protections
- Access controls are enforced differently for each environment
- Clear policies governing the movement of data between environments
8. Audit and Compliance Measures
We conduct regular assessments and maintain compliance with industry standards and data protection regulations.
Security Assessments
We perform regular security evaluations:
- Regular internal assessments of security controls and procedures
- Periodic vulnerability scanning to identify and remediate security weaknesses
- Annual penetration testing conducted by independent security experts
- Continuous monitoring of security threats and industry best practices
Compliance and Standards
Our security program aligns with industry standards:
- Continuous pursuit of compliance with relevant data protection regulations (GDPR, CCPA, etc.)
- Alignment with industry-standard security frameworks
- Regular review and updates of security policies and procedures
- Documentation of security measures and compliance activities
9. Data Breach Notification
In the event of a personal data breach, we will notify affected customers and relevant authorities as required by applicable law.
Notification Procedures
Our breach notification process includes:
- Prompt assessment and containment of any security incident
- Notification to affected customers without undue delay, and where feasible, within 72 hours of becoming aware of the breach
- Notification to relevant supervisory authorities as required by applicable law
- Detailed documentation of the incident, impact assessment, and remediation measures
10. Data Subject Rights
We assist our customers in fulfilling data subject rights requests in accordance with applicable data protection laws.
Support for Data Subject Rights
We provide support for:
- Right of access: Assisting customers in providing access to personal data
- Right to rectification: Supporting correction of inaccurate personal data
- Right to erasure: Facilitating deletion of personal data upon customer request
- Right to data portability: Enabling export of personal data in a structured format
- Right to object: Supporting customers in handling objections to processing
11. Sub-Processors
We may engage sub-processors to assist in providing our services. All sub-processors are subject to appropriate data protection obligations.
Sub-Processor Management
Our sub-processor management includes:
- Evaluation and due diligence of all sub-processors before engagement
- Contractual obligations requiring sub-processors to implement appropriate technical and organizational measures
- Maintenance of a list of current sub-processors available upon request
- Notification to customers of any changes to sub-processors with reasonable advance notice
12. International Data Transfers
Personal data may be transferred to and processed in countries outside the customer's jurisdiction, including the United States, Canada, or other locations where our service providers operate.
Transfer Safeguards
We implement appropriate safeguards for international transfers:
- Use of Standard Contractual Clauses (SCCs) where applicable
- Compliance with adequacy decisions and other lawful transfer mechanisms
- Ensuring that sub-processors provide equivalent levels of data protection
- Regular assessment of transfer mechanisms to ensure ongoing compliance
13. Data Retention and Deletion
We retain personal data only as long as necessary to provide services or as required by law, and delete data in accordance with customer instructions or applicable legal requirements.
Retention Policy
Our data retention practices include:
- Retention of personal data only for as long as necessary to provide services to customers
- Deletion of personal data upon customer request or at the end of the service relationship
- Retention for longer periods only when required by applicable law or for legitimate business purposes
- Secure deletion methods that ensure data cannot be recovered
14. Updates to this DPA
We may update this Data Processing Agreement from time to time to reflect changes in our security measures, legal requirements, or business practices. Material changes will be communicated to customers with reasonable advance notice.
Customers will be notified of material changes to this DPA, and continued use of our services after such changes constitutes acceptance of the updated terms.
15. Contact Us
For questions about this Data Processing Agreement or our data security measures, please contact us:
Collective Media Group, LLC
Attn: Privacy Officer / Data Protection Officer
Email: [email protected]
Address: 13101 Washington Blvd., Suite 428, Los Angeles, California 90066