Soft-Master
ServicesCloud DriveWhy usClientsAboutContact
ENעב
Get in touch

Data Processing Addendum (DPA)

1. Scope and Role

This DPA applies to the processing of personal data by Soft-Master LTD on behalf of the Client within the scope of providing IaaS services.

  • Client (Controller/Owner): Determines the purposes and means of processing.
  • Soft-Master LTD (Processor/Holder): Processes data only according to the Client’s instructions (by providing the hosting infrastructure).

Group Compliance Disclosure: Soft-Master LTD operates its information security and privacy management systems (ISMS/PIMS) in coordination with SDefender, a specialized security entity within our corporate group. All infrastructure security, data protection controls, and regulatory compliance (including ISO 27001 and ISO 27701) are managed and maintained by SDefender on behalf of Soft-Master LTD.

2. Provider Obligations

Soft-Master LTD hereby commits to:

  • Processing Instructions: Process personal data only on documented instructions from the Client, unless required by law.
  • Confidentiality: Ensure that all personnel authorized to handle infrastructure management have signed strict non-disclosure and confidentiality agreements.
  • Security Measures: Implement technical and organizational measures as defined in our ISO 27001/27701 certifications to ensure a level of security appropriate to the risk.
  • Sub-processing: Not engage another processor without informing the Client. All sub-processors (e.g., data centers) must meet the same security standards.

3. Data Subject Rights

Soft-Master LTD will assist the Client, insofar as possible, in fulfilling their obligation to respond to requests from individuals exercising their rights (access, deletion, correction) under GDPR or Israeli law. Since the Provider has no direct access to the Client's databases, the Client remains responsible for executing these actions within their systems.

4. Incident Notification

In the event of a confirmed data breach within the infrastructure managed by Soft-Master LTD, the Provider will notify the Client without undue delay and provide reasonable assistance in investigating and mitigating the incident.

5. Audit Rights

Soft-Master LTD shall make available to the Client information necessary to demonstrate compliance with these obligations. This is primarily fulfilled by providing evidence of valid ISO 27001 and ISO 27701 certifications and, where applicable, infrastructure security logs (Syslog).

6. Termination and Deletion

Upon termination of services, Soft-Master LTD shall, at the choice of the Client, delete or return all account-related personal data, unless applicable law requires continued storage. Data within the Client’s virtual instances is deleted automatically upon decommissioning of the service.

← Back to site
softmaster

IT infrastructure, under control — since 1993.

Services

Public, Private & Protected CloudNetwork & VirtualizationIT SecurityPhone Systems & VoIPSoftware DevelopmentWeb Design & Development

Company

Cloud DriveWhy usClientsAboutContact

Contact

sales@soft-master.com +972 (72) 212 07 00+972 (74) 714 07 99 Israel ↗
© 1993–2026 Soft-Master Ltd. All rights reserved. Privacy SLA DPA

We use cookies for anonymous analytics to improve this site.