cloud-itonami — Data Processing Addendum
Effective / last updated: 2026-07-24
This DPA forms part of the cloud-itonami Terms and each applicable Order Form between the Customer as controller and AWAI Network, L.L.C. as processor. It applies where AWAI processes personal data in Customer Data on Customer’s behalf.
1. Instructions and purpose
AWAI processes Customer Data only on documented Customer instructions, including the Terms and Order Form, to provide, secure, support and terminate the Service. AWAI will notify Customer if an instruction appears unlawful, unless prohibited from doing so.
2. Duration and data
Processing continues for the service term and the export/deletion periods in the Terms. Data may include business contact, workforce, communications, CRM, contract, invoice, finance and audit information about Customer personnel, customers and counterparties. Customer determines data subjects and lawful basis and will not provide data it lacks authority to process.
3. Confidentiality and security
Authorized persons are bound by confidentiality. AWAI maintains measures appropriate to risk, including tenant separation, capability-scoped access, authenticated writes, TLS in transit, provider encryption at rest, credential controls, logging and human approval for external, financial or destructive effects.
4. Subprocessors
Customer authorizes the subprocessors listed in the Privacy Policy: Cloudflare; Gftd Japan K.K. and net-kotobase; Stripe; and Resend where enabled. AWAI remains responsible for materially equivalent data-protection obligations from subprocessors and will give reasonable advance notice of a material new subprocessor. Customer may object on documented data-protection grounds.
5. Assistance and incidents
AWAI will reasonably assist Customer with data-subject requests, security assessments, breach obligations and legally required consultations. AWAI will notify Customer without undue delay after confirming a personal-data breach affecting Customer Data and provide available information reasonably needed for Customer’s obligations.
6. Return and deletion
On termination, AWAI provides the export window in the Terms and then deletes or irrecoverably de-identifies Customer Data, except for audit, accounting, dispute or legal records that must be retained. Protected backups are deleted through their normal lifecycle and remain restricted meanwhile.
7. International transfers
Where EU or UK GDPR requires a transfer mechanism, the applicable controller-to-processor Standard Contractual Clauses and UK addendum are incorporated by reference, with this DPA supplying the processing description and safeguards.
8. Audit information
On reasonable request, AWAI will provide information necessary to demonstrate compliance. Audits first use current reports and documentation, avoid other customers’ data, occur no more than annually absent a breach or regulator request, and remain confidential.
9. Priority and acceptance
This DPA controls over conflicting processing terms. It becomes effective when Customer accepts the Terms or an incorporating Order Form; no separate signature is required unless the Order Form requires one.