The processing terms between your organisation as controller and DITA as processor. This is the document your governance team will want.
Your organisation is the controller of your readers' personal data. AM Consulting LLC, doing business as DITA ("DITA"), is the processor, acting only on your documented instructions. Using the platform as described in the terms of service constitutes those instructions.
We process reader data for as long as your library exists, plus 30 days after cancellation. The purpose is operating a digital library: enrolling readers, lending titles, syncing reading position, and reporting usage to you in aggregate.
We do not process special category data. The platform has no field for it and no integration that would supply it.
We use sub-processors for hosting, storage and payment. They are bound by equivalent obligations. We will tell you before adding or replacing one, and you may object.
The current list is available on request and will be published here once the review is complete.
Reader data stays in the hosting region chosen when your library is set up. Where a transfer outside that region would otherwise be necessary, it does not happen without your instruction and an appropriate legal mechanism.
If we become aware of a personal data breach affecting your readers, we will notify you without undue delay and in any event within 72 hours, with what we know at the time and what we are doing about it. We will not wait until the picture is complete.
At any point you can export catalogue records, collections, reader list and loan history in open formats. On termination we delete reader data after the 30-day recovery window, or return it first if you ask.
If your governance process needs this signed as a standalone document, ask and we will send an executable copy.