Data Processing Agreement (DPA)
Last updated: September 18, 2025
This Data Processing Agreement ("DPA") is an addendum to the Defensible Space Score Terms of Service (the "Main Agreement") between AACI Group, Inc. ("Company" or "Processor"), as the owner and operator of the Defensible Space Score digital service, and you, the Customer (or "Controller").
1. Definitions
For the purposes of this DPA, the terms below have the meanings defined in the Main Agreement, or as follows:
- "Controller" means the entity that determines the purposes and means of the processing of Personal Data.
- "Processor" means the entity that processes Personal Data on behalf of the Controller.
- "Personal Data" means any information relating to an identified or identifiable natural person ('data subject') processed by Processor on behalf of Controller pursuant to or in connection with the Main Agreement.
- "Data Subject" means the individual to whom Personal Data relates.
- "Processing" means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- "Sub-processor" means any Processor engaged by Processor to carry out specific processing activities on behalf of the Controller.
- "Supervisory Authority" means an independent public authority which is established by a Member State pursuant to the GDPR.
- "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
2. Scope and Applicability
This DPA applies to the processing of Personal Data by AACI Group, Inc. on behalf of the Customer in connection with the Defensible Space Score Service. It is intended to ensure compliance with Article 28 of the GDPR and other applicable data protection laws.
3. Processing of Personal Data
AACI Group, Inc. will process Personal Data only on documented instructions from the Customer, unless required to do so by Union or Member State law to which the Processor is subject; in such a case, the Processor shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The instructions from the Customer are defined in the Main Agreement and Customer’s use of the Service.
- Subject Matter: The subject matter of the processing under this DPA is the Personal Data relating to Data Subjects provided by the Controller to Processor for the purpose of using the Defensible Space Score Service.
- Duration: As between Controller and Processor, the duration of the data processing under this DPA is determined by the Main Agreement.
- Purpose: The purpose of the data processing under this DPA is to provide the Defensible Space Score Service to the Controller, which includes processing data to generate wildfire risk assessments and defensible space readiness scores.
- Categories of Data Subjects: The categories of Data Subjects are the Controller’s end-users, such as homeowners and property owners who use the Defensible Space Score Service.
- Types of Personal Data: The types of Personal Data processed may include names, email addresses, property addresses, and any other information provided by the Controller or its end-users through the Service (including uploaded photos and insurance documents).
4. Confidentiality
AACI Group, Inc. shall ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5. Security
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, AACI Group, Inc. shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:
- the pseudonymization and encryption of Personal Data;
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident;
- a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.
In assessing the appropriate level of security, account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored or otherwise processed.
6. Use of Sub-processors
The Customer agrees that AACI Group, Inc. may engage Sub-processors to process Personal Data on its behalf, provided that AACI Group, Inc. informs the Customer of any intended changes concerning the addition or replacement of other Sub-processors, thereby giving the Customer the opportunity to object to such changes. AACI Group, Inc. shall ensure that any Sub-processor is bound by data protection obligations consistent with those in this DPA.
7. Data Subject Rights
AACI Group, Inc. shall provide reasonable assistance to the Customer in responding to requests from Data Subjects to exercise their rights under the GDPR, including the rights to access, correct, erase, restrict processing, data portability, and object.
8. Data Breach Notification
AACI Group, Inc. shall notify the Customer without undue delay after becoming aware of a Personal Data breach. Such notification shall at least:
- describe the nature of the Personal Data breach including where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
- communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- describe the likely consequences of the Personal Data breach;
- describe the measures taken or proposed to be taken to address the Personal Data breach, including, where appropriate, measures to mitigate its possible adverse effects.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
9. Return or Deletion of Data
Upon termination of the Main Agreement, AACI Group, Inc. shall, at the choice of the Customer, return or delete all Personal Data, unless required by Union or Member State law to store the Personal Data.
10. Audit
AACI Group, Inc. shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
By using the Defensible Space Score Service or otherwise agreeing to the Main Agreement, the parties acknowledge and agree to this Data Processing Agreement. If you have any questions about this DPA or need a signed copy for your records, please contact us at:
AACI Group, Inc.
Email: legal@defensiblespacescore.com
Phone: (925) 237-1285
Mailing Address: 2001 Clayton Road, Suite 200, Concord, CA 94520