Data Processing Addendum
DATA PROCESSING ADDENDUM
PRV Technologies
Last updated: June 22, 2026
This Data Processing Addendum (“DPA”) forms part of, and is incorporated into, the Terms of Service or other written agreement (the “Agreement”) between PRV Tech, a company registered in the Republic of Korea (Business Registration No. 727-86-02960), operating under the brand name “PRV Technologies” (“PRV Technologies”, “we”, “us” or “our”), and the customer identified in the Agreement (“Customer”, “you” or “your”). This DPA governs the processing of Personal Data that we carry out on your behalf as a processor in connection with the Services.
If there is any conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls. Capitalized terms not defined here have the meaning given in the Agreement or our Privacy Policy.
1. Definitions
“Data Protection Laws” means all privacy and data protection laws applicable to the processing of Personal Data under this DPA, including, as applicable, the Republic of Korea Personal Information Protection Act (“PIPA”), the EU General Data Protection Regulation (“EU GDPR”), the UK GDPR and Data Protection Act 2018 (“UK GDPR”), and U.S. state privacy laws such as the California Consumer Privacy Act as amended (“CCPA/CPRA”).
“Personal Data” means any information relating to an identified or identifiable natural person that is contained within Customer Content and that we process on your behalf under the Agreement.
“Customer Content” means the data, files, and other content that you (or your end users) store, run, transmit, or otherwise process using the Services.
“Data Subject” means the individual to whom Personal Data relates.
“Processing” (and “process”) means any operation performed on Personal Data, such as collection, storage, use, transmission, or deletion.
“Sub-processor” means any third party engaged by us to process Personal Data on your behalf in connection with the Services.
“Standard Contractual Clauses” or “SCCs” means the standard data protection clauses approved by the European Commission, and, for UK transfers, the UK International Data Transfer Addendum, as applicable to a given transfer.
“Controller”, “processor”, and “personal data breach” have the meanings given to them in the EU GDPR, and equivalent terms under other Data Protection Laws are construed accordingly.
2. Roles of the Parties
As between the parties, you are the controller of the Personal Data contained in Customer Content, and we act as your processor. Where you are yourself acting as a processor on behalf of a third-party controller, you warrant that you have the authority and instructions necessary for us to process the Personal Data as a sub-processor, and references to your instructions include those of that controller.
For other personal information that we determine the purposes and means of processing — such as account registration, billing, fraud-prevention, and website analytics and advertising data — we act as a controller, and that processing is described in our Privacy Policy rather than this DPA.
3. Scope and Processing Instructions
We will process Personal Data only on your documented instructions, including with regard to international transfers, unless required to act otherwise by applicable law (in which case we will, where legally permitted, inform you of that legal requirement before processing).
Your instructions are set out in this DPA and the Agreement, and include your configuration and use of the Services through the customer portal, account settings, and APIs. The subject matter, duration, nature, and purpose of the processing, and the types of Personal Data and categories of Data Subjects, are described in Annex A.
You are responsible for the accuracy, quality, and legality of Customer Content, for the means by which you acquired Personal Data, and for ensuring you have a lawful basis to provide it to us for processing. The Services are unmanaged, and we do not access Customer Content except as needed to provide, secure, and support the Services, to comply with law, or as otherwise instructed by you.
4. Confidentiality
We will ensure that personnel authorized to process Personal Data are bound by appropriate obligations of confidentiality and process Personal Data only as necessary to provide, secure, and support the Services. We limit access to Personal Data to personnel who require access for those purposes.
5. Security Measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of processing, we implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Depending on the system and the sensitivity of the data, these measures include:
Encryption of data in transit and, where appropriate, at rest;
Access controls and the principle of least privilege, including support for multi-factor authentication;
Logical separation of customer environments;
Logging and monitoring of relevant systems; and
Procedures for restoring availability and access to Personal Data in a timely manner following an incident.
You are responsible for the security of the operating systems, applications, credentials, and content that you deploy or manage on the Services, and for configuring the security features made available to you, as described in the Agreement.
6. Sub-processors
You provide a general authorization for us to engage Sub-processors to process Personal Data in connection with the Services. We currently engage Sub-processors within the following categories:
Cloud and data-center infrastructure providers;
Content-delivery and security providers;
Payment processors;
Fraud-prevention and identity-verification providers;
Communications providers (such as email and SMS delivery);
Performance- and error-monitoring providers; and
Customer-support and operational tooling providers.
A current list naming our Sub-processors is available to customers on written request to privacy@prvtechnologies.com. We do not publish the named list in this document.
We will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible for the performance of each Sub-processor's obligations. We will give you at least thirty (30) days' advance notice (by email or through the customer portal) of the addition or replacement of a Sub-processor before that Sub-processor begins processing Personal Data, except where a shorter period is required to address a security risk or legal obligation, in which case we will give as much notice as is reasonably practicable. If you have a reasonable, data-protection-related objection to a new Sub-processor, you may notify us within a reasonable period after our notice, and the parties will work together in good faith to address the objection; if it cannot be resolved, you may terminate the affected Services as your remedy.
7. International Data Transfers
We are based in the Republic of Korea, and Personal Data may be processed in other countries where we or our Sub-processors operate, including the United States. We will only transfer Personal Data to a country outside its country of origin in compliance with the cross-border-transfer requirements of applicable Data Protection Laws.
Where a transfer is subject to the EU or UK GDPR and is made to a country that has not received an adequacy decision, the transfer is made under the Standard Contractual Clauses or another lawful transfer mechanism, which are incorporated into this DPA by reference and completed with the details set out in Annex A and the Sub-processor information available on request. Where the processing is subject to PIPA, cross-border transfers are carried out in accordance with PIPA's requirements, including providing notice to and, where required, obtaining the consent of Data Subjects.
8. Data Subject Requests
Taking into account the nature of the processing, we will provide reasonable assistance, through appropriate technical and organizational measures and insofar as possible, to help you respond to requests from Data Subjects to exercise their rights under Data Protection Laws. If we receive such a request directly from a Data Subject in relation to Customer Content, we will, where legally permitted, advise the Data Subject to submit the request to you, and will not otherwise respond except on your instructions or as required by law.
9. Assistance with Compliance
Taking into account the nature of processing and the information available to us, we will provide you with reasonable assistance with your obligations relating to the security of processing, personal data breach notification, data protection impact assessments, and prior consultation with supervisory authorities, to the extent these obligations apply to the processing under this DPA.
10. Personal Data Breach Notification
We will notify you without undue delay after becoming aware of a personal data breach affecting Personal Data processed under this DPA. The notification will include, to the extent then known and reasonably available to us, the nature of the breach, the likely consequences, and the measures taken or proposed to address it. Our notification is not an acknowledgment of fault or liability. You are responsible for any notifications you are required to make to authorities or affected individuals.
11. Return and Deletion of Customer Content
Upon termination or expiry of the Agreement, you may, for a limited retrieval period following termination as set out in the Agreement, retrieve Customer Content that remains accessible through the Services. At your choice, we will delete or return Personal Data contained in Customer Content following that period. After the retrieval period, we will delete Personal Data within our control in the ordinary course, except to the extent we are required to retain it by applicable law, in which case we will continue to protect it and limit further processing to the purpose of that retention.
12. Records and Audits
We will make available to you information reasonably necessary to demonstrate compliance with this DPA. Where Data Protection Laws give you a right to audit, you may exercise it by requesting the information described above and, where a further audit is required, by a mutually agreed audit conducted on reasonable prior written notice, during business hours, no more than once per year (except where required by a supervisory authority or following a personal data breach), subject to confidentiality obligations and in a manner that does not compromise the security or operation of the Services or other customers' data.
13. Liability and Governing Law
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA is governed by the laws of the Republic of Korea, and the parties submit to the jurisdiction set out in the Agreement (the Incheon District Court), without prejudice to any mandatory rights a Data Subject may have under Data Protection Laws.
14. Term
This DPA takes effect when you accept the Agreement (or when you first use the Services) and remains in force for as long as we process Personal Data on your behalf. Provisions that by their nature should survive termination will survive.
Annex A – Details of Processing
Item | Description |
|---|---|
Subject matter | Provision of bare metal dedicated servers, virtual machines, and related cloud infrastructure services to the Customer under the Agreement. |
Duration | For the term of the Agreement, plus any period during which we retain Personal Data as permitted or required under Section 11 of this DPA. |
Nature and purpose | Hosting, storage, transmission, and processing of Customer Content on infrastructure provided by us, and related security, support, and operational activities, all on the Customer's behalf. |
Types of Personal Data | Any Personal Data contained in Customer Content as determined and controlled by the Customer. This may include identifiers and contact details, account and login data, and any other categories the Customer chooses to process using the Services. |
Categories of Data Subjects | Any individuals whose Personal Data is contained in Customer Content, as determined by the Customer (for example, the Customer's own users, customers, employees, or contacts). |
Sensitive data | The Services are general-purpose infrastructure and are not intended for special categories of data unless the Customer has implemented appropriate safeguards; the Customer is responsible for determining the suitability of the Services for any sensitive data it processes. |
Frequency of processing | Continuous, for the duration of the Customer's use of the Services. |
Transfer mechanism: Where required for transfers subject to the EU or UK GDPR, the Standard Contractual Clauses (and, for the UK, the International Data Transfer Addendum) apply, with PRV Technologies acting as data importer (processor) and the Customer as data exporter, completed consistently with the details in this Annex and the Sub-processor information available on request.
Contact for data protection matters: Joon Young Park, Chief Privacy Officer — privacy@prvtechnologies.com
PRV Tech (operating as “PRV Technologies”), Suite 3-704, 495 Parang-ro, Seo-gu, Incheon 22770, Republic of Korea.