Updated June 25 2025
This Data Processing Agreement (“DPA”) forms part of the overall agreement (“Agreement”) between the subscribing law enforcement agency (“Customer”) and FINDER Software Solutions (“FINDER”) for the provision of software and data-sharing services. This DPA governs how FINDER processes Customer Personal Data on behalf of the Customer, particularly under applicable data protection and public safety privacy laws.
1. Definitions
- Personal Data: Any information related to an identified or identifiable individual.
- Customer Personal Data: Personal Data submitted by or collected on behalf of Customer while using the FINDER platform.
- Processing: Any operation performed on Personal Data, such as collection, storage, or sharing.
- Controller: The entity (Customer) determining the purposes and means of Processing.
- Processor: The entity (FINDER) processing Personal Data on behalf of the Controller.
- Data Subject: The individual to whom the Personal Data relates.
- Sub-Processor: A third party engaged by FINDER to process Personal Data.
- Data Breach: Unauthorized access to, disclosure, or loss of Personal Data.
2. Roles and Scope
- The Customer acts as Controller, and FINDER acts as Processor.
- This DPA applies only to the extent that FINDER processes Customer Personal Data in the course of providing services.
- Both parties will comply with applicable data protection laws.
3. FINDER Obligations
- Processing Instructions: FINDER will only process Personal Data based on documented instructions from the Customer.
- Security Measures: FINDER will implement appropriate technical and organizational safeguards to protect Personal Data.
- Confidentiality: FINDER staff and contractors with access to Personal Data will be bound by confidentiality obligations.
- Sub-Processors: FINDER may use Sub-Processors and will ensure they meet equivalent security and privacy obligations.
- Data Breach Notification: FINDER will notify Customer without undue delay upon confirmation of a Data Breach involving Customer Personal Data.
- Return or Deletion: Upon termination of services, FINDER will delete or return Personal Data, unless otherwise required by law.
4. Customer Responsibilities
- Data Accuracy: Customer is responsible for ensuring the legality and accuracy of the data it provides.
- Compliance: Customer must obtain all required authorizations and consents prior to submitting Personal Data.
- Instructions: Customer is responsible for ensuring that its instructions to FINDER are lawful.
5. Sub-Processors
- FINDER maintains a list of its current Sub-Processors and will provide notice of material changes.
- Customer may object to a new Sub-Processor on reasonable data protection grounds.
- If unresolved, the Customer may suspend use of the affected service module.
6. Data Subject Requests
- FINDER will provide tools and assistance, as reasonably required, to enable Customer to fulfill individual rights requests (access, deletion, etc.).
- FINDER will not respond to any Data Subject requests directly unless legally required to do so, and will notify Customer of such requests.
7. Security and Compliance
- FINDER maintains policies aligned with CJIS security guidelines.
- Access to systems is restricted and monitored.
- FINDER undergoes internal and third-party security assessments as part of its operational protocol.
8. Data Transfers
- FINDER primarily stores and processes data within the United States.
- No data will be transferred internationally without lawful transfer mechanisms or Customer consent.
9. Audits and Demonstration of Compliance
- FINDER will provide documentation or audit reports upon reasonable request to verify compliance.
- In-person audits may be conducted if required by law or regulation, with reasonable notice and conditions.
10. Duration and Termination
- This DPA remains in effect for the duration of the Agreement.
- Obligations related to data retention and deletion survive termination as required by applicable law.
11. General
- In the event of a conflict between this DPA and the Agreement, this DPA shall govern regarding Personal Data Processing.
- Data contributed by the Customer (“Contributed Data”) remains the exclusive property of the Customer. FINDER may only use such data to fulfill its obligations under this Agreement and any related MOU.
- The Customer grants FINDER a limited license to store, access, display, and share Contributed Data with other authorized agencies and approved platforms in accordance with applicable law and as set forth in the governing MOU.
- FINDER is not responsible for the use or misuse of Contributed Data by third-party platforms or other authorized FINDER agencies.
- Customers may opt out of certain data-sharing pathways, including federal data exchange programs, by providing written notice in accordance with their MOU.
- The Customer is solely responsible for ensuring its use of FINDER, and any associated data sharing, complies with legal requirements, including proper notice, consent, and legal authority for any sensitive data.
- FINDER disclaims responsibility for RF data or other geo-positioning data collected by or through Customer agency systems. Agencies are solely liable for legal and regulatory compliance in their use of such data.
- Additional terms related to data access, sharing, and retention may also be governed by the agency’s Memorandum of Understanding (MOU) and the applicable user agreement.
- This DPA may be updated by FINDER to remain compliant with applicable data privacy regulations. Customer will be notified in advance of material changes.
12. Contact
For questions or notices under this DPA:
FINDER Software Solutions
Email: admin@findersoftware.com