Effective Date: January 02, 2026
This Incident Response Addendum (“Addendum”) forms part of the CPA Toolkit Terms and Conditions and Data Processing Addendum (“DPA”) and governs the procedures applicable in the event of a Security Incident.
Capitalized terms not defined in this Addendum have the meanings assigned in the Terms and Conditions or the DPA.
This Addendum applies solely to Security Incidents originating from systems under CPA Toolkit’s direct control.
This Addendum does not apply to incidents arising from:
CPA Toolkit maintains procedures designed to identify and assess suspected Security Incidents.
A Security Incident shall be deemed to have occurred only after CPA Toolkit has reasonably confirmed unauthorized access to Personal Data.
Upon confirmation of a Security Incident, CPA Toolkit will notify the affected Customer without undue delay and within a commercially reasonable timeframe.
Notification may include, to the extent reasonably available:
The Customer remains solely responsible for:
CPA Toolkit shall not communicate directly with Data Subjects unless required by law.
CPA Toolkit will take commercially reasonable steps to contain, investigate, and remediate confirmed Security Incidents within its control.
CPA Toolkit is not obligated to:
CPA Toolkit will reasonably cooperate with the Customer in connection with a Security Incident, subject to:
Any extraordinary assistance may be subject to additional fees.
Liability arising from a Security Incident is subject to the limitations, exclusions, and caps set forth in the CPA Toolkit Terms and Conditions.
CPA Toolkit shall not be liable for regulatory fines, penalties, notification costs, credit monitoring services, or reputational harm.
In the event of conflict between this Addendum and the Terms, Privacy Policy, or DPA, this Addendum controls solely with respect to incident response procedures.
Security or incident-related inquiries should be directed to:
Email:
[email protected]