Data Processing Addendum

Last updated June 2026.

This summarizes how CustodyLinx processes operator data as a processor. It is a plain-English overview of the addendum terms.

Roles

For the personal data within an operator's account, the operator is the controller and CustodyLinx is the processor. We process that data only to provide the service and on the operator's documented instructions, including filing to the government systems of record the operator directs.

Scope and purpose of processing

We process account data for the operator's users and the operational and compliance records the operator enters or generates (packages, manifests, custody events, lab results, incidents, documents, and the telemetry needed to run trips). Processing is limited to operating the service, maintaining the evidentiary record, and meeting the recordkeeping and reporting obligations of controlled-substance logistics.

Security measures

Tenant isolation via row-level security on a default-deny model enforced in the database; an append-only, hash-chained custody log that is tamper-evident; private document storage with short-lived signed access; and an immutable audit log capturing actor, source, and time for every mutating action. Access is least-privilege.

Subprocessors

We use a small set of infrastructure subprocessors under confidentiality and security terms, listed and kept current at /subprocessors. We remain responsible for their performance of the obligations in this addendum.

International transfers

Where operator data is processed across borders, we rely on appropriate transfer safeguards and process it consistent with this addendum and applicable law. The cross-border movement features keep custody continuity across jurisdictions as a product capability, separate from the legal transfer mechanism for personal data.

Data-subject requests

We support the operator (as controller) in responding to access, correction, and deletion requests, subject to law. Some records are required regulatory evidence and cannot be deleted; we will say so plainly rather than imply a deletion that compliance law forbids.

Breach notification

We will notify the affected operator without undue delay after becoming aware of a personal-data breach involving their data, with the information needed to meet their own notification obligations.

Return and deletion

On termination, and subject to mandatory controlled-substance retention rules, we return or delete operator personal data on request. Append-only compliance records retained for legal recordkeeping are an explicit exception, retained only as long as the law requires.

This page is a summary, not the executed agreement. A countersigned Data Processing Addendum, including the registered contracting entity and any region-specific standard contractual clauses, is provided and signed during contracting, after counsel review.