Data Processing Agreement
Effective Date: January 1, 2026
This Data Processing Agreement (the “DPA”) forms part of the Terms of Service, any applicable online clickwrap or website terms, any Master Service Agreement, or other written or electronic agreement between L.B. Foster Company (“Company”) and the customer party to such agreement (“Customer”) governing Customer’s use of the Service (the “Agreement”).
This DPA applies to the extent Company processes Personal Data on behalf of Customer in connection with the Service.
1. Definitions
1.1 “Applicable Data Protection Law” means US federal and state privacy and data protection laws applicable to the processing of Personal Data under the Agreement.
1.2 “Customer Instructions” means the Agreement, this DPA, applicable Order Forms, Customer’s configuration of the Service, and Customer’s documented written directions regarding Company’s processing of Personal Data on Customer’s behalf.
1.3 “Permitted Business Purposes” means the purposes for which Company may process Personal Data under the Agreement and this DPA, including service delivery, security, support, audit, compliance, analytics, billing verification, and other business purposes expressly permitted by Applicable Data Protection Law and the Agreement.
1.4 “Personal Data” means personal data, personal information, personally identifiable information, or any similar term regulated under Applicable Data Protection Law and processed by Company on behalf of Customer in connection with the Service.
1.5 “Process” or “Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means.
1.6 “Security Incident” means a breach of security resulting in unauthorized or unlawful access, acquisition, destruction, use, modification, or disclosure of Personal Data processed by Company on behalf of Customer under this DPA.
1.7 “Subprocessor” means a third party authorized to process Personal Data on behalf of Company in connection with the Service.
1.8 Other Statutory Terms. “Controller,” “Processor,” “Business,” and “Service Provider” have the meanings given under Applicable Data Protection Law, as applicable.
2. Roles of the Parties
2.1 Customer and Company Roles. With respect to Personal Data processed under this DPA, Customer is the Controller or Business, as applicable, and Company is the Processor or Service Provider, as applicable.
2.2 Customer Data. Customer Data, as defined in the Agreement, generally means field IoT device, connected asset, endpoint, equipment, telemetry, configuration, diagnostic, performance, location where enabled, command history, and related operational data processed through the Service. Customer Data may include or constitute Personal Data depending on the nature of the data and the context in which it is processed.
This DPA applies to Personal Data processed by Company on behalf of Customer in connection with the Service, regardless of whether such Personal Data is contained in Customer Data, Usage Data, Derived Data, operational records, support records, audit records, or other service-related data. A data element’s classification as Customer Data, Usage Data, Derived Data, or another data category under the Agreement does not limit Company’s obligations under this DPA, Applicable Data Protection Law, or applicable contractual terms governing Personal Data.
2.3 Independent Controller or Business Activities. Company may act as an independent controller or business for its own business operations, including billing, security, fraud prevention, legal compliance, service analytics, audit, product improvement, support, and similar internal purposes permitted by law.
2.4 AI/ML Processing.
(a) Customer-Specific AI/ML Operation. To the extent the Service includes analytics, automation, anomaly detection, recommendations, alerts, classifications, predictions, or other AI/ML-enabled functionality, Company may process Personal Data as necessary to provide, operate, secure, maintain, support, and generate outputs from that functionality for Customer in accordance with the Agreement, Customer Instructions, this DPA, and Applicable Data Protection Law. Such processing is referred to in this DPA as “Customer-Specific AI/ML Operation.”
(b) AI/ML Training and Improvement. For purposes of this DPA, “AI/ML Training and Improvement” means the development, training, retraining, tuning, testing, validation, or improvement of AI/ML models, systems, features, automations, analytics, or related functionality, other than Customer-Specific AI/ML Operation.
(c) Personal Data Restriction. Company will not use Personal Data processed on behalf of Customer for AI/ML Training and Improvement unless expressly authorized in an Order Form, DPA schedule, administrative-console setting, or other written agreement between the parties and permitted by Applicable Data Protection Law.
(d) Permitted Non-Personal and Opt-In Data. Company may use Aggregated Data, De-identified Data, Derived Data, Usage Data, and Customer Data for which Customer has provided any opt-in required by the Agreement for AI/ML Training and Improvement, provided that any Personal Data contained in such data remains subject to this DPA, Applicable Data Protection Law, and any applicable customer opt-in or opt-out right.
(e) Customer Responsibilities. Customer is responsible for providing legally adequate notices, obtaining legally required consents or authorizations, identifying any required legal basis, and satisfying any other legal requirements applicable to Customer’s use of AI/ML-enabled Service functionality, including where Customer enables functionality that involves monitoring, profiling, automated recommendations, automated actions, or processing of employee, contractor, end-user, or third-party Personal Data.
3. Scope and Instructions
3.1 Processing Scope. Company will process Personal Data solely to provide the Service, perform its obligations under the Agreement, perform Permitted Business Purposes, comply with Customer Instructions, and as otherwise required or permitted by Applicable Data Protection Law.
3.2 Customer Instructions. Customer Instructions constitute Customer’s complete instructions to Company regarding the processing of Personal Data, unless otherwise agreed in writing. Customer instructs Company to process Personal Data as necessary for the purposes described in Section 3.1.
3.3 Lawfulness. Customer represents and warrants that it has provided all notices and obtained all rights, permissions, and consents necessary for Company to process Personal Data in accordance with the Agreement and this DPA.
4. Restrictions on Use of Personal Data
To the extent required by Applicable Data Protection Law, Company will not:
sell or share Personal Data;
retain, use, or disclose Personal Data for any purpose other than the Permitted Business Purposes, Customer-Specific AI/ML Operation, compliance with Customer Instructions, or as otherwise permitted by Applicable Data Protection Law;
use Personal Data for AI/ML Training and Improvement unless expressly authorized in an Order Form, DPA schedule, administrative-console setting, or other written agreement between the parties and permitted by Applicable Data Protection Law;
disclose Personal Data or Customer Data to third-party model providers for AI/ML Training and Improvement unless otherwise expressly agreed in writing by Customer and permitted by Applicable Data Protection Law;
retain, use, or disclose Personal Data outside the direct business relationship between Company and Customer, except as otherwise permitted by Applicable Data Protection Law; or
combine Personal Data received from Customer with personal data received from another source, except as permitted by Applicable Data Protection Law.
Company certifies that it understands and will comply with the restrictions set forth in this Section.
5. Personnel and Confidentiality
Company will ensure that persons authorized to process Personal Data are subject to appropriate confidentiality obligations.
6. Security
Taking into account the nature of the processing, Company will implement and maintain reasonable administrative, technical, and physical safeguards designed to protect Personal Data against unauthorized or unlawful access, acquisition, destruction, use, modification, or disclosure.
7. Subprocessors
7.1 Authorization. Customer authorizes Company to engage Subprocessors to process Personal Data on Company’s behalf in connection with the Service.
7.2 Obligations. Company will impose data protection obligations on each Subprocessor that are no less protective than the obligations applicable to Company under this DPA, as appropriate to the nature of the services provided.
7.3 Liability. Company remains responsible for its Subprocessors’ performance of their data protection obligations to the extent required by Applicable Data Protection Law and the Agreement.
8. Assistance to Customer
Taking into account the nature of the processing and the information available to Company, Company will provide reasonable assistance to Customer, upon written request, to help Customer comply with applicable obligations relating to privacy rights requests, security incidents, data protection assessments, and regulator inquiries. Such assistance will be provided at Customer’s cost to the extent legally permitted and only to the extent Company is legally required to provide such assistance.
9. Security Incidents
9.1 Notice. Company will notify Customer without undue delay after confirming a Security Incident affecting Personal Data processed under this DPA.
9.2 Cooperation. Company will provide information reasonably available to Company regarding the nature of the Security Incident and steps taken or recommended to mitigate its effects.
9.3 No Admission. Notification of a Security Incident is not an admission of fault or liability.
10. Privacy Rights Requests
If Company receives a request from an individual seeking to exercise privacy rights relating to Personal Data processed on behalf of Customer, Company will, to the extent legally permitted, notify Customer and direct the individual to submit the request to Customer. Company may assist Customer in responding to such request as described in Section 8.
11. Deletion and Return
11.1 Deletion or Return. Following expiration or termination of the Agreement, Company will delete or return Personal Data processed on behalf of Customer within ninety (90) days after receiving Customer’s written deletion or return request, unless retention is required by applicable law or reasonably necessary for backup, archival, security, legal, compliance, or dispute-resolution purposes.
11.2 Customer Data. If Customer Data contains Personal Data processed on behalf of Customer, such Personal Data will be handled in accordance with Section 11.1.
11.3 Usage Data, Derived Data, Aggregated Data, and De-identified Data. Company may retain and continue to use Usage Data, Derived Data, Aggregated Data, and De-identified Data after expiration or termination for lawful business purposes in accordance with the Agreement, the Privacy Policy, this DPA, and applicable law, provided that any Personal Data contained in such data continues to be processed in accordance with applicable law, the Privacy Policy, and this DPA.
11.4 Model and Output Carveout. Deletion of Customer Data or Personal Data will not require Company to delete, retrain, roll back, modify, or cease use of models, systems, features, automations, analytics, outputs, learnings, Derived Data, Usage Data, model parameters, weights, or other outputs created or improved before deletion, except to the extent required by applicable law or expressly agreed in writing.
12. Audit Rights
To the extent required by Applicable Data Protection Law, Company will make available to Customer information reasonably necessary to demonstrate Company’s compliance with this DPA. If such information is insufficient under Applicable Data Protection Law, Customer may request, no more than once annually and upon reasonable prior written notice, an audit or inspection of Company’s relevant policies, procedures, and records, subject to reasonable confidentiality, security, and scope limitations, and only to the extent required by Applicable Data Protection Law.
13. Cross-Border Data Transfers
If the parties transfer Personal Data across borders and Applicable Data Protection Law requires additional safeguards, the parties will implement appropriate safeguards as required by Applicable Data Protection Law. EU/UK transfers are governed by Section 15.11 and Annex 4 to the extent applicable.
14. Termination and Conflict
This DPA will remain in effect for as long as Company processes Personal Data on behalf of Customer under the Agreement. If there is a conflict between this DPA and the Agreement with respect to processing of Personal Data, this DPA will control to the extent of the conflict. If both online clickwrap terms and an MSA could apply to the relationship, the MSA will govern over the online terms to the extent of any inconsistency, and this DPA will be read consistently with that order of precedence.
15. EU/UK Data Protection Addendum
15.1 Application. This Section 15 applies to the extent Company processes Personal Data on behalf of Customer that is subject to the GDPR, UK GDPR, the UK Data Protection Act 2018, EU Member State data protection laws, or other applicable European Economic Area, Swiss, or United Kingdom data protection laws (collectively, “EU/UK Data Protection Laws”).
15.2 EU/UK Definitions. For purposes of this Section 15, “controller,” “processor,” “personal data,” “personal data breach,” “processing,” “data subject,” “supervisory authority,” “special categories of personal data,” and “subprocessor” have the meanings given under EU/UK Data Protection Laws. “GDPR” means Regulation (EU) 2016/679. “UK GDPR” means the GDPR as incorporated into United Kingdom law. “EEA” means the European Economic Area. “SCCs” means the then-current standard contractual clauses approved by the European Commission for restricted transfers of personal data. “UK Transfer Addendum” means the then-current international data transfer addendum approved by the UK Information Commissioner’s Office for use with the SCCs, or any successor UK transfer mechanism.
15.3 Article 28 Processor Obligations. For EU/UK Personal Data, Customer is the controller and Company is the processor unless the parties expressly agree otherwise in writing. Company will process EU/UK Personal Data only on Customer’s documented instructions, including with respect to international transfers, unless Company is required to do so by applicable law. Customer Instructions constitute Customer’s documented instructions. Company will promptly notify Customer if Company believes an instruction violates EU/UK Data Protection Laws, unless prohibited by law. If Company is required by law to process EU/UK Personal Data other than on Customer’s instructions, Company will inform Customer of that legal requirement before processing unless prohibited by law on important grounds of public interest.
15.4 Security Measures. Company will implement and maintain appropriate technical and organizational measures designed to protect EU/UK Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure. Such measures are further described in Annex 2.
15.5 Subprocessors. Customer provides a general authorization for Company to engage subprocessors to process EU/UK Personal Data in connection with the Service. Company will maintain a current list of subprocessors and will provide notice of new subprocessors as required by EU/UK Data Protection Laws or the Agreement. Customer may object to a new subprocessor on reasonable data protection grounds within the notice period specified by Company. Company will impose data protection obligations on each subprocessor that are no less protective in substance than those imposed on Company under this DPA, as applicable to the subprocessor’s processing activities. Company remains responsible for each subprocessor’s performance of its data protection obligations to the extent required by EU/UK Data Protection Laws.
15.6 Data Subject Rights Assistance. Taking into account the nature of the processing, Company will provide reasonable assistance to Customer, by appropriate technical and organizational measures where feasible, to help Customer respond to requests from data subjects exercising rights under EU/UK Data Protection Laws. If Company receives a data subject request relating to EU/UK Personal Data processed on Customer’s behalf, Company will, to the extent legally permitted, notify Customer and will not respond substantively except on Customer’s documented instructions or as required by law.
15.7 Personal Data Breach Notice. Company will notify Customer without undue delay after becoming aware of a personal data breach affecting EU/UK Personal Data processed by Company on behalf of Customer. Company will provide information reasonably available to Company regarding the nature of the breach, affected data, likely consequences, and measures taken or proposed to address or mitigate the breach. Company will reasonably cooperate with Customer to support Customer’s assessment of any notification obligations under EU/UK Data Protection Laws. Company’s notice of or response to a breach is not an admission of fault or liability.
15.8 DPIA and Supervisory Authority Assistance. Taking into account the nature of the processing and the information available to Company, Company will provide reasonable assistance to Customer, at Customer’s cost unless otherwise required by law, with data protection impact assessments, prior consultations with supervisory authorities, and regulatory inquiries relating to Company’s processing of EU/UK Personal Data on Customer’s behalf.
15.9 Deletion and Return. At the end of the provision of the Service, Company will, at Customer’s choice and subject to the Agreement, delete or return EU/UK Personal Data processed on Customer’s behalf and delete existing copies, unless applicable law requires storage. Company may retain EU/UK Personal Data in backup or archival systems until overwritten in accordance with ordinary retention cycles, provided such data remains protected and is not actively processed except as required for backup, archival, security, legal, compliance, or disaster-recovery purposes. The Usage Data and Derived Data carveouts in this DPA apply to EU/UK Personal Data only to the extent such data no longer contains Personal Data or continued processing is otherwise lawful under EU/UK Data Protection Laws, the Agreement, and this DPA.
15.10 Audits and Records. Company will make available information reasonably necessary to demonstrate compliance with this Section 15 and will allow for and contribute to audits, including inspections, as required by EU/UK Data Protection Laws. Customer must first request available certifications, audit summaries, security documentation, or questionnaire responses before requesting an onsite or invasive audit. Any audit must be conducted on reasonable prior notice, during normal business hours, subject to confidentiality and security controls, without access to other customers’ data, and in a manner that does not unreasonably interfere with Company’s operations. Unless required by law or following a confirmed personal data breach, audits may not occur more than once annually.
15.11 International Transfers. To the extent Company transfers EU/UK Personal Data to a country or recipient not subject to an adequacy decision or other valid transfer mechanism, the parties will rely on an applicable lawful transfer mechanism as described in Annex 4. Company will provide reasonable cooperation for transfer impact assessments and will use commercially reasonable efforts to notify Customer of legally binding government access requests for EU/UK Personal Data unless prohibited by law.
15.12 Special Categories and Sensitive Data. Customer will not submit to the Service any special categories of personal data, criminal-offense data, or other Sensitive Data subject to heightened protection under EU/UK Data Protection Laws unless expressly authorized in an Order Form, DPA schedule, or other written agreement. If such data is authorized, Customer is responsible for identifying and satisfying any applicable lawful basis, Article 9 condition, Article 10 requirement, transparency obligation, and data minimization requirement. Company may reject, restrict, or delete unauthorized special categories of personal data, criminal-offense data, or Sensitive Data to the extent permitted by law and the Agreement.
15.13 AI/ML Restrictions for EU/UK Personal Data. Company will not use EU/UK Personal Data for AI/ML training, model development, model retraining, tuning, testing, validation, or improvement unless expressly authorized in an Order Form, DPA schedule, administrative console setting, or other written agreement and permitted by EU/UK Data Protection Laws. Customer is responsible for providing legally adequate notices, identifying an appropriate lawful basis, and satisfying any additional requirements applicable to profiling, automated decision-making, or similar processing. Company will not use EU/UK Personal Data for automated decision-making that produces legal or similarly significant effects concerning an individual unless expressly agreed in writing and permitted by EU/UK Data Protection Laws.
Annex 1: Description of Processing
Subject Matter: Provision of Anatomy, also referred to as L.B. Foster’s Anatomy Asset Management System or Anatomy Asset Intelligence.
Duration: For the term of the Agreement and any post-termination retention period permitted by the Agreement and applicable law.
Nature of Processing: Hosting, storage, transmission, analysis, monitoring, remote administration, remote control, configuration management, remediation, patching, restart, shutdown, lock, wipe, settings changes, support, security, logging, Customer-Specific AI/ML Operation, generation of Customer-specific analytics, alerts, recommendations, classifications, predictions, automations, outputs, and Derived Data, and related processing necessary to provide, secure, support, and maintain the Service. AI/ML Training and Improvement involving Personal Data processed on behalf of Customer will occur only if expressly authorized in an Order Form, DPA schedule, administrative-console setting, or other written agreement between the parties and permitted by Applicable Data Protection Law.
Purpose of Processing: To provide, operate, secure, support, maintain, and improve the Service; perform Customer-Specific AI/ML Operation; comply with Customer Instructions; perform the Permitted Business Purposes set forth in the Agreement and this DPA; and, only where expressly authorized and legally permitted, conduct AI/ML Training and Improvement involving Personal Data processed on behalf of Customer.
Categories of Data Subjects: Customer personnel, end users, contractors, vendors, device users, and other individuals whose Personal Data is processed in connection with the Service.
Categories of Personal Data: Identifiers, contact information, account information, device and asset information, network information, usage data, support communications, and other Personal Data processed in connection with the Service.
Special Categories of Personal Data: None, unless expressly authorized in an Order Form, DPA schedule, or other written agreement.
Transfers: Transfers may occur as necessary to provide the Service and as described in the Agreement, this DPA, and Annex 4.
Subprocessors: Company’s authorized subprocessors as described in Section 7 and Section 15.5.
Annex 2: Technical and Organizational Measures
Company will maintain technical and organizational measures appropriate to the nature of the Service and the processing, which may include, as applicable:
access controls and authentication controls;
encryption in transit and at rest;
logging and monitoring;
vulnerability management;
backup and recovery measures;
incident response procedures;
personnel security and confidentiality obligations;
availability and resilience measures; and
periodic testing, assessment, and evaluation of security controls.
Annex 3: Subprocessors
Company may engage subprocessors as permitted under this DPA. Company will maintain or make available a current list of subprocessors for the Service as required by applicable law or the Agreement.
Annex 4: International Transfer Terms
For EEA transfers, the SCCs are incorporated by reference and apply as required by EU/UK Data Protection Laws. For UK transfers, the UK Transfer Addendum or other applicable UK transfer mechanism is incorporated by reference and applies as required by UK GDPR. The parties will complete and interpret the SCCs, UK Transfer Addendum, and any related annexes consistently with the processing details, security measures, and subprocessor terms in this DPA.