Partner Data Processing Addendum

Last Updated: August 31, 2026

1. Purpose and Scope

This Partner DPA forms part of the Partner Agreement between the Parties and governs the Partner’s processing of personal data in connection with the Partner Program or BMR Partner Program.

It sets out each Party’s respective obligations under applicable data protection laws.

As part of the Program, IDrive® may provide Partner with customer account, operational, support, administrative, and related service information, including names, email addresses, account identifiers, and usage information, for referral tracking, reporting, commission administration, account management, support, service administration, monitoring, recovery, troubleshooting, and related operational activities.

BMR Partners may receive administrative access to BMR appliances, related accounts, backup environments, and associated systems to provide authorized administration, monitoring, support, backup, restore, recovery, troubleshooting, and related services on behalf of IDrive® and/or the End User. Depending on the services configured and permissions granted, such access may include the technical ability to view, browse, restore, download, recover, or otherwise process customer backup data or related system data where necessary for authorized support, administration, recovery, or service delivery.

The Parties’ respective roles under applicable data protection laws will depend on the relevant processing activity. Where Partner processes personal data on behalf of IDrive®, Partner acts as a Processor or sub-processor, as applicable. Where Partner processes personal data on behalf of an End User pursuant to the End User’s authorization or instructions, the Parties’ respective roles will be determined by the applicable processing relationship and data protection law.

2. Partner Data Processing Obligations

The Partner shall:


1. Process under instructions – process personal data only in accordance with documented instructions from IDrive® and/or the applicable End User, as applicable to the relevant processing activity and authorization, unless otherwise required by applicable law.


2. Confidentiality – ensure authorized personnel are bound by confidentiality obligations.


3. Security Measures – implement appropriate technical and organizational measures in line with GDPR Art. 32.


4. Sub-processing – where Partner processes personal data on behalf of IDrive®, Partner shall not engage a sub-processor without IDrive’s prior written consent and a written contract imposing equivalent data protection obligations. Where Partner processes personal data on behalf of an End User, Partner shall comply with any applicable sub-processing requirements arising from its relationship with that End User and applicable law.


5. Data-subject rights – promptly notify IDrive® of any data-subject request relating to personal data processed on behalf of IDrive® and assist IDrive® in responding as required by applicable law. Where the request relates to processing performed on behalf of an End User, Partner shall handle or escalate the request in accordance with the applicable processing relationship and legal requirements.


6. Breach notification – notify IDrive® without undue delay (no later than 24 hours) after becoming aware of a personal-data breach.


7. Government requests – notify IDrive® of any legally binding disclosure request unless prohibited by law and seek to limit the disclosure.


8. Deletion/Return – upon termination of the applicable processing relationship or on request, delete or return the applicable personal data unless retention is required by law.


9. Use restrictions – not use personal data for marketing, resale, profiling, or any other unauthorized purpose.


10. BMR access – when applicable, Partner shall not access, view, browse, restore, download, copy, disclose, or otherwise process End User backup content or system data except where reasonably necessary and authorized for support, administration, troubleshooting, restore, recovery, migration, maintenance, or service delivery, and in accordance with applicable documented instructions and applicable law.


11. Authorization obligations – Partner represents and warrants that it has obtained and will maintain all necessary authorizations, permissions, rights, and lawful instructions from End Users for activities performed on their behalf through the Services and, where required by applicable data protection law, will maintain appropriate contractual data protection terms governing such processing.


3. IDrive's Role

  • IDrive® processes personal data in accordance with its applicable customer agreements, Data Processing Addendum, this Partner DPA, and applicable data protection laws.
  • Except for the limited rights necessary to perform authorized services under the applicable agreements, no ownership rights or independent licenses in End User data are granted to Partner.
  • IDrive® may revoke, suspend, or restrict Partner access where reasonably necessary for security, operational, contractual, legal, compliance, customer-requested, or service-related purposes, without affecting commissions properly earned under the Partner Agreement.

4. Compliance with Laws

Partner must comply with all applicable data protection laws, including, where applicable, the GDPR, UK GDPR, Data Protection Act 2018, CCPA/CPRA, and other applicable data protection laws.


CCPA/CPRA Service-Provider Terms

  • Partner will not sell or share personal information.
  • Partner will not retain, use, or disclose personal information for any purpose other than those authorized under the applicable agreements, instructions, and permitted business purposes.
  • Partner certifies that it understands and will comply with these obligations and will promptly notify IDrive® if it cannot do so.
  • IDrive® may take reasonable steps to ensure Partner’s processing is consistent with IDrive’s CPRA obligations.

Partner shall promptly notify IDrive® if it becomes subject to any investigation, complaint, or order relating to data protection.


5. Liability and Indemnification

  • The Partner is responsible for any misuse of personal data or unauthorized actions.
  • For BMR administrative access, Partner is responsible for misuse of its administrative rights or unauthorized handling of End User data.
  • Partner shall indemnify and hold harmless IDrive® and its affiliates from any claims, damages, penalties, or liabilities (including regulatory fines and reasonable attorney fees) arising from Partner’s breach of this DPA or applicable data-protection laws.

6. Audit Rights

  • Upon thirty (30) days’ written notice, IDrive® may audit Partner’s compliance once per year, or more frequently if required by law or after a data incident.
  • Partner shall co-operate and make relevant records available.
  • Audits will ordinarily be limited to documentation and remote assessments; on-site reviews may be conducted only if necessary to verify compliance.

7. International Transfers

Where Partner processes or transfers personal data outside the jurisdiction in which it was originally collected, Partner shall comply with applicable international data-transfer requirements and implement appropriate safeguards where required by applicable data protection law.


Where applicable, such safeguards may include the EU–U.S. Data Privacy Framework, its UK Extension, the Swiss–U.S. Data Privacy Framework, the Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Addendum, or other legally recognized transfer mechanisms.


Where the Standard Contractual Clauses are required for an applicable restricted transfer, the Parties will apply the appropriate SCC module based on their respective roles and complete or provide any information required for the applicable transfer.


8. Term and Termination

  • This DPA remains in effect for as long as the Partner processes personal data subject to this DPA.
  • Upon termination of the applicable processing relationship, Partner shall cease the applicable processing and delete or return personal data in accordance with Section 2(8), unless retention is required by applicable law.

9. Governing Law

This DPA is governed by the laws of the State of California, USA, unless applicable data protection law or an applicable international data transfer mechanism requires otherwise.


10. Order of Precedence

In the event of a conflict between this Partner DPA and the Partner Agreement, this Partner DPA shall prevail with respect to the processing of personal data.

Where applicable, the Standard Contractual Clauses or other applicable international data transfer mechanism shall prevail to the extent required by their terms or applicable law.


Annex A – Details of Processing

  • Subject matter: Processing of customer account and related service information and, for BMR Partners, administrative access to BMR appliances, backup environments, related systems, and associated service environments.
  • Nature and purpose: Referral tracking, reporting, commission administration, account management, monitoring, support, backup administration, restore and recovery, troubleshooting, migration, maintenance, and related service delivery activities.
  • Duration: For the duration of the applicable processing relationship or until deletion or return of the applicable personal data in accordance with this Partner DPA.
  • Types of personal data: Names, email addresses, account identifiers, usage data, appliance identifiers, endpoint backup reports, device and system metadata, backup status information, restore and recovery information, and, where reasonably necessary and authorized for BMR support, administration, restore, recovery, troubleshooting, migration, or service delivery, customer backup content and related system data.
  • Categories of data subjects: End Users and other individuals whose personal data may be contained in or associated with the applicable accounts, systems, or backup data.