Last updated on .

Previous versions of this page are available.

Data Processing Addendum

Introduction

This Data Processing Addendum (the “DPA”) supplements the Agreement (as defined below) between Webrecorder Software LLC (“Webrecorder” or “Provider”) and the Webrecorder Customer identified in the applicable Agreement (“Customer”). This DPA sets out the additional terms, requirements, and conditions on which the Provider will obtain, handle, process, disclose, transfer, or store Personal Information when providing services under the Agreement.

1. Definitions and Interpretation

1.1 The following definitions and rules of interpretation apply in this DPA.

  • “Adequacy Decision” means a decision by a competent authority that a country, territory, sector or international organization ensures an adequate level of protection for personal data, including a decision under Article 45 of the EU GDPR or the equivalent UK or Swiss determination.
  • “Agreement” means any agreement between Customer and Webrecorder under which Webrecorder engages in the Processing of Personal Data in the course of providing such services.
  • “Business Purpose” means the services described in the Agreement or any other purpose specifically identified in Appendix A.
  • “Data Subject” means an individual who is the subject of the Personal Data and to whom or about whom the Personal Data relates or identifies, directly or indirectly.
  • “European Data Protection Law” means, as applicable, the EU GDPR (Regulation (EU) 2016/679), the UK GDPR and the UK Data Protection Act 2018, and the Swiss Federal Act on Data Protection (FADP).
  • “EU SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced.
  • “Personal Data” means any information the Provider processes for the Customer that
    • (a) identifies or relates to an individual who can be identified directly or indirectly from that data alone or in combination with other information in the Provider’s possession or control or that the Provider is likely to have access to, or
    • (b) the relevant Privacy and Data Protection Requirements otherwise define as protected personal information.
  • “Personnel” means the Provider’s employees and any individual independent contractors, temporary staff, agents, and other persons authorized by the Provider to access or Process the Personal Data.
  • “Processing, processes, or process” means any activity that involves the use of Personal Data or that the relevant Privacy and Data Protection Requirements may otherwise include in the definition of processing, processes, or process. It includes obtaining, recording, or holding the data, or carrying out any operation or set of operations on the data including, but not limited to, organizing, amending, retrieving, using, disclosing, erasing, or destroying it. Processing also includes transferring Personal Data to third parties.
  • “Privacy and Data Protection Requirements” means all applicable federal, state, and foreign laws and regulations relating to the processing, protection, or privacy of the Personal Data, including where applicable, the guidance and codes of practice issued by regulatory bodies in any relevant jurisdiction.
  • “Restricted Transfer” means a transfer (or onward transfer) of Customer Personal Data that is subject to European Data Protection Law from a data exporter to a data importer located in, or accessing the data from, a country that is not the subject of an applicable Adequacy Decision covering that recipient and transfer.
  • “Security Breach” means any act or omission that compromises the security, confidentiality, or integrity of Personal Data or the physical, technical, administrative, or organizational safeguards put in place to protect it. The loss of or unauthorized access, disclosure, or acquisition of Personal Data is a Security Breach whether or not the incident rises to the level of a security breach under the Privacy and Data Protection Requirements.
  • “Supplementary Measures” means technical, organizational and contractual measures adopted, where necessary, to ensure that transferred Customer Personal Data receives a level of protection essentially equivalent to that guaranteed within the EEA.
  • “Transfer Impact Assessment” or “TIA” means a documented assessment of whether the law and practice of the destination country prevent the data importer from complying with the relevant transfer mechanism, and of the Supplementary Measures required.
  • “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
    • 1.2 This DPA is subject to the terms of the Agreement and is incorporated into the Agreement. Interpretations and defined terms set forth in the Agreement apply to the interpretation of this DPA.
    • 1.3 The Appendices form part of this DPA and will have effect as if set out in full in the body of this DPA. Any reference to this DPA includes the Appendices.
    • 1.4 A reference to writing or written includes email.
    • 1.5 In the case of conflict or ambiguity between:
      • (a) any provision contained in the body of this DPA and any provision contained in the Appendices, the provision in the body of this DPA will prevail;
      • (b) the terms of any accompanying invoice or other documents annexed to this DPA and any provision contained in the Appendices, the provision contained in the Appendices will prevail; and
      • (c) any of the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA will prevail.

2. Personal Data Types and Processing Purposes

2.1 The Customer retains control of the Personal Data and remains responsible for its compliance obligations under the applicable Privacy and Data Protection Requirements, including providing any required notices and obtaining any required consents, and for the processing instructions it gives to the Provider.

2.2 For the purposes of the Privacy and Data Protection Requirements, the Customer is the “controller” (and, under applicable U.S. state privacy laws, the “business”) and the Provider is the “processor” (and, under applicable U.S. state privacy laws, the “service provider”) with respect to the Personal Data. Each Module of the EU SCCs applies according to these roles.

2.3 Appendix A describes the general Personal Data categories and related types of Data Subjects the Provider may process to fulfill the Business Purposes of the Agreement. The Customer discloses Personal Data to the Provider only for the limited and specified Business Purposes.

3. Provider’s Obligations

3.1 The Provider will only process, retain, use, or disclose the Personal Data to the extent, and in such a manner, as is necessary for the Business Purposes in accordance with the Customer’s instructions. The Provider will not process, retain, use, or disclose the Personal Data for any other purpose, outside of the parties’ business relationship, or in a way that does not comply with this DPA or the Privacy and Data Protection Requirements. The Provider must promptly notify the Customer if, in its opinion, the Customer’s instruction would not comply with the Privacy and Data Protection Requirements. The Agreement and this DPA (including Appendix A) constitute the Customer’s complete and final documented instructions to the Provider for the Processing of Personal Data as of the effective date; any additional or different instruction must be agreed by the parties in writing.

3.2 The Provider must promptly comply with any Customer request or instruction requiring the Provider to amend, transfer, or delete the Personal Data, or to stop, mitigate, or remedy any unauthorized processing.

3.3 The Provider will maintain the confidentiality of all Personal Data and will not sell it to anyone, share it for cross-contextual (targeted) advertising with anyone, or disclose it to third parties without specific authorization from the Customer or this DPA, unless required by law. If a law requires the Provider to process or disclose Personal Data, the Provider must first inform the Customer of the legal requirement and give the Customer an opportunity to object or challenge the requirement, unless the law prohibits such notice on important grounds of public interest.

3.4 The Provider will reasonably assist the Customer with meeting the Customer’s compliance obligations under the Privacy and Data Protection Requirements, taking into account the nature of the Provider’s processing and the information available to the Provider. Such assistance includes, taking into account the nature of Processing and the information available to the Provider, assisting the Customer with:

  • (a) responding to Data Subject requests;
  • (b) the security of Processing (Article 32 of the EU GDPR and equivalent requirements);
  • (c) personal data breach notification to, and communication with, supervisory authorities and Data Subjects (Articles 33 and 34); and
  • (d) data protection impact assessments and prior consultation with supervisory authorities (Articles 35 and 36).

3.5 The Provider must promptly notify the Customer of any changes to Privacy and Data Protection Requirements, or its ability to meet those obligations, that may adversely affect the Provider’s performance of the Agreement or this DPA.

3.6 The Customer acknowledges that the Provider is under no duty to investigate the completeness, accuracy, or sufficiency of any specific Customer instructions from the Customer or its authorized representatives or the Personal Data other than as required under the Privacy and Data Protection Requirements.

3.7 The Provider will comply with all applicable requirements of the California Consumer Privacy Act and the other Privacy and Data Protection Requirements, and will provide the same level of privacy protection with respect to the Personal Data as is required of businesses (or controllers) by those requirements. The Provider certifies that it understands and will comply with the restrictions and obligations set out in this Section 3.

3.8 The Provider will not combine or update the Personal Data with personal information that it receives from, or on behalf of, any other person, or that it collects from its own interaction with any Data Subject, except as expressly permitted by the applicable Privacy and Data Protection Requirements.

3.9 The Provider will provide reasonable cooperation, information, and assistance to enable the Customer to meet its obligations relating to cybersecurity audits, risk assessments, and automated decision-making technology under the Privacy and Data Protection Requirements, and will promptly give effect to any consumer or Data Subject rights request (including any request to opt out of the sale or sharing of, or to limit the use of, Personal Data, and any access, correction, or deletion request) that the Customer transmits to the Provider.

4. Provider’s Personnel

4.1 The Provider will limit Personal Data access to:

  • (a) those Personnel who require Personal Data access to meet the Provider’s obligations under this DPA and the Agreement; and
  • (b) the part or parts of the Personal Data that those Personnel strictly require for the performance of their duties.

4.2 The Provider will ensure that all Personnel:

  • (a) are informed of the Personal Data’s confidential nature and use restrictions and are obliged to keep the Personal Data confidential;
  • (b) have undertaken training on the Privacy and Data Protection Requirements relating to handling Personal Data and how it applies to their particular duties; and
  • (c) are aware of both the Provider’s duties and their personal duties and obligations under the Privacy and Data Protection Requirements and this DPA.

4.3 The Provider will take reasonable steps to ensure the reliability, integrity, and trustworthiness of all of the Provider’s Personnel with access to the Personal Data.

4.4 The Provider will ensure that each of its Personnel is bound by written obligations of confidentiality (or an appropriate statutory duty of confidentiality) and complies with the obligations of this Section 4. Each individual independent contractor Processes the Personal Data solely under the Provider’s authority and on its documented instructions, exclusively for the Provider’s benefit, and not for the contractor’s own or any third party’s purposes; accordingly, such contractors act as the Provider’s Personnel and not as separate Subprocessors.

5. Security

5.1 The Provider must at all times implement appropriate technical and organizational measures designed to safeguard Personal Data against unauthorized or unlawful processing, access, copying, modification, storage, reproduction, display, or distribution, and against accidental loss, destruction, unavailability, or damage.

5.2 The Provider will immediately notify the Customer if it becomes aware of any advance in technology and methods of working, which indicate that the parties should adjust their security measures.

5.3 The Provider must take reasonable precautions to preserve the integrity of any Personal Data it processes and to prevent any corruption or loss of the Personal Data, including but not limited to establishing effective back-up and data restoration procedures.

6. Security Breaches and Personal Data Loss

6.1 The Provider will promptly notify the Customer if any Personal Data is lost or destroyed or becomes damaged, corrupted, or unusable. The Provider will restore such Personal Data at its own expense.

6.2 The Provider will notify Customer, without undue delay and in any event within forty-eight (48) hours after becoming aware, of:

  • (a) any unauthorized or unlawful processing of the Personal Data; or

  • (b) any Security Breach.

    6.3 Immediately following any unauthorized or unlawful Personal Data processing or Security Breach, the parties will co-ordinate with each other to investigate the matter. The Provider will reasonably co-operate with the Customer in the Customer’s handling of the matter, including:

  • (a) providing Customer with sufficient information to allow Customer to meet any obligations to report or inform Data Subjects of the Security Breach under the Data Protection requirements, which information will, to the extent available to the Provider, include the nature of the Security Breach, the categories and approximate number of Data Subjects and Personal Data records concerned, the likely consequences of the Security Breach, and the measures taken or proposed by the Provider to address it; and

  • (b) taking reasonable steps as are directed by Customer to assist in the investigation, mitigation, and remediation of the Security Breach.

6.4 The Provider will not inform any third party of a Security Breach without first obtaining the Customer’s prior written consent, except when law or regulation requires it.

6.5 The Provider agrees that the Customer has the sole right to determine:

  • (a) whether to provide notice of the Security Breach to any Data Subjects, regulators, law enforcement agencies, or others, as required by law or regulation or in the Customer’s discretion, including the contents and delivery method of the notice; and
  • (b) whether to offer any type of remedy to affected Data Subjects, including the nature and extent of such remedy.

7. Cross-Border Transfers of Personal Data

7.1 General

  • (a) The parties acknowledge that the Provider is established outside the EEA and the United Kingdom, and that certain Customer Personal Data processed under this DPA may be subject to European Data Protection Law. Transfers of such Personal Data to a third country may constitute Restricted Transfers. Each party shall comply with European Data Protection Law in respect of any Restricted Transfer it makes or authorizes.
  • (b) This Section applies only to Customer Personal Data that is subject to European Data Protection Law. It does not extend the requirements of European Data Protection Law to personal data that is not otherwise subject to it.

7.2 Order of transfer mechanisms

  • (a) Provider shall not transfer, and shall not permit any Subprocessor to transfer or access, Customer Personal Data in a manner that constitutes a Restricted Transfer unless it has first ensured that at least one of the following applies for the duration of the processing:
    • (i) an applicable Adequacy Decision covers the recipient and the transfer; or
    • (ii) an appropriate safeguard under Article 46 of the EU GDPR (or its UK/Swiss equivalent) is in place, which the parties agree shall be the EU SCCs (as completed under Section 7.3), together with the UK Addendum and/or Swiss amendments under Section 7.4 to the extent the transferred data is subject to UK or Swiss law; or
    • (iii) a derogation under Article 49 of the EU GDPR applies, which the parties shall rely upon only on an exceptional, non-repetitive basis and only where documented in advance.

7.3 Incorporation of the EU SCCs

  • (a) Where the EU SCCs apply, they are incorporated into this Agreement by reference and are deemed executed by the parties (and, where Provider contracts on behalf of a Subprocessor, procured by Provider), completed as follows:
    • (i) Module: Module Three (processor-to-processor) applies to transfers by Provider to a Subprocessor; Module Two (controller-to-processor) applies to any transfer by Customer as controller directly to Provider as importer, as the context requires;
    • (ii) Clause 7 (docking clause) applies;
    • (iii) Clause 9: Option 2 (general written authorization) applies, with the minimum notice period for Subprocessor changes specified in Section 8.1(a) of this Agreement;
    • (iv) Clause 11: the optional independent-dispute-resolution language does not apply;
    • (v) Clause 17 (governing law): the law of the Netherlands;
    • (vi) Clause 18 (forum and jurisdiction): the courts of the Netherlands; and Annexes I, II and III to the EU SCCs are populated by Appendix B (“Subprocessor Annex”) to this Agreement and Appendix C (“Security Measures”), which the parties agree satisfy the corresponding requirements. Annex I.A (list of parties) and Annex I.C (competent supervisory authority) are completed as set out in Appendix D to this Agreement.
  • (b) In the event of any conflict between the EU SCCs and the remainder of this Agreement, the EU SCCs prevail with respect to the subject matter of the Restricted Transfer.

7.4 UK and Swiss transfers

  • (a) For Customer Personal Data subject to the UK GDPR, the EU SCCs as incorporated above apply as varied by the UK Addendum, which is incorporated by reference; Tables 1 to 3 are completed by the corresponding EU SCC selections above and Table 4 selects “neither party” as the party entitled to terminate.
  • (b) For Customer Personal Data subject to the Swiss FADP, the EU SCCs apply with the following amendments: references to the EU GDPR are read as references to the FADP where the FADP applies; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and the term “member state” must not be interpreted to exclude data subjects in Switzerland from enforcing their rights in their place of habitual residence.

7.5 Transfer impact assessments and Supplementary Measures

  • (a) Prior to making or authorizing a Restricted Transfer in reliance on the EU SCCs, Provider shall carry out and document a Transfer Impact Assessment, and shall implement any Supplementary Measures identified as necessary. Provider shall make each TIA available to Customer on reasonable request.
  • (b) Provider shall keep each TIA under review and shall reassess it upon becoming aware of any change in the law or practice of a destination country that may affect the importer’s ability to comply.

7.6 Government access requests

  • (a) To the extent permitted by law, Provider shall, and shall require each relevant Subprocessor to, promptly notify Customer of any legally binding request from a public authority for Customer Personal Data, challenge requests that are unlawful or overbroad, and provide only the minimum amount of data necessary when responding to a valid request.

7.7 Importers subject to the GDPR (Article 3(2))

  • (a) The parties acknowledge that where a data importer’s processing is itself directly subject to the EU GDPR under Article 3(2), the EU SCCs are not, on their face, designed for that scenario. Pending adoption by the European Commission of standard contractual clauses addressing such transfers, the parties shall apply the EU SCCs to the extent they are relevant and shall, acting reasonably, adopt any additional or replacement clauses issued for that purpose promptly after they become available.

8. Subprocessors

8.1 The Provider may only authorize a third party (Subprocessor) to process the Personal Data if:

  • (a) the Customer is given an opportunity to object within 14 days after the Provider supplies the Customer with full details regarding such Subprocessor;
  • (b) the Provider enters into a written contract with the Subprocessor that contains terms substantially the same as those set out in this DPA and, upon the Customer’s written request, provides the Customer with copies of such contracts;
  • (c) the Provider maintains control over all Personal Data it entrusts to the Subprocessor; and
  • (d) the Subprocessor’s contract terminates automatically on termination of this DPA for any reason.

8.2 Individuals who Process the Personal Data solely under the Provider’s authority and for the Provider’s benefit (including the Provider’s employees and individual independent contractors described in Section 4) are the Provider’s Personnel and are not Subprocessors for the purposes of this Section 8, and their access to Personal Data from outside the EEA does not by itself constitute a Restricted Transfer requiring an Article 46 mechanism. This Section 8 applies to Subprocessors that are separate legal persons acting as processors on the Provider’s behalf.

8.3 The Provider remains fully liable to the Customer for the performance of each Subprocessor’s data-protection obligations and for the acts and omissions of each Subprocessor as if they were the Provider’s own.

8.4 Upon any instruction from the Customer to delete or return Personal Data, and upon expiry or termination of the Term, the Provider will notify each relevant Subprocessor and require it to delete or return the relevant Personal Data in accordance with Section 11.

9. Data Subject Requests, Complaints, and Third Party Rights

9.1 The Provider must promptly notify the Customer if it receives a request from a Data Subject to exercise any rights the individual may have regarding their Personal Data, such as access, correction, deletion, or to opt-out of or limit certain activities like sales, disclosures, or other processing actions.

9.2 The Provider must notify the Customer promptly if it receives any other complaint, notice, or communication that directly or indirectly relates to the Personal Data processing or to either party’s compliance with the Privacy and Data Protection Requirements.

9.3 The Provider will give the Customer its full co-operation and assistance in responding to any complaint, notice, communication, or Data Subject request.

9.4 The Provider must not disclose the Personal Data to any Data Subject or to a third party unless the disclosure is either at the Customer’s request or instruction, permitted by this DPA, or is otherwise required by law.

10. Term and Termination

10.1 This DPA will remain in full force and effect so long as:

  • (a) the Agreement remains in effect; or
  • (b) the Provider retains any Personal Data related to the Agreement in its possession or control (the “Term”).

10.2 Any provision of this DPA that expressly or by implication should come into or continue in force on or after termination of the Agreement in order to protect Personal Data will remain in full force and effect.

11. Data Return and Destruction

11.1 At the Customer’s request, the Provider will give the Customer a copy of or access to all or part of the Customer’s Personal Data in its possession or control in the format and on the media reasonably specified by the Customer.

11.2 On termination of the Agreement for any reason or expiration of its term, the Provider will securely destroy or, if directed in writing by the Customer, return and not retain, all or any Personal Data related to this agreement in its possession or control.

11.3 If any law, regulation, or government or regulatory body requires the Provider to retain any documents or materials that the Provider would otherwise be required to return or destroy, it will notify the Customer in writing of that retention requirement, giving details of the documents or materials that it must retain, the legal basis for retention, and establishing a specific timeline for destruction once the retention requirement ends. The Provider may only use this retained Personal Data for the required retention reason or audit purposes.

12. Records

12.1 The Provider will keep detailed, accurate, and up-to-date records regarding any processing of Personal Data it carries out for the Customer, including but not limited to, the access, control, and security of the Personal Data, approved Subprocessors and affiliates, the processing purposes, and any other records required by the applicable Privacy and Data Protection Requirements (the “Records”).

12.2 The Provider will ensure that the Records are sufficient to enable the Customer to verify the Provider’s compliance with its obligations under this DPA.

13. Audit

13.1 The Provider will permit the Customer and its third-party representatives to audit the Provider’s compliance with its DPA obligations, upon at least 30 days’ notice, during the Term and for 1 year after this DPA terminates. The Provider will give the Customer and its third-party representatives all necessary assistance to conduct such audits. The assistance may include, but is not limited to:

  • (a) physical access to, remote electronic access to, and copies of the Records and any other information held at the Provider’s premises or on systems storing Personal Data;
  • (b) access to and meetings with any of the Provider’s personnel reasonably necessary to provide all explanations and perform the audit effectively; and
  • (c) inspection of all Records and the infrastructure, electronic data, or systems, facilities, equipment, or application software used to store, process, or transport Personal Data.

14. Notice

14.1 Any notice or other communication given to a party under or in connection with this DPA must be in writing, by email. Customer shall be notified by email sent to the address set forth in the Agreement. Provider shall be notified by email sent to: privacy@webrecorder.org.


Appendix A

Personal Data Processing Purposes and Details

Business Purposes

The Personal Data will be processed as necessary to provide the Services pursuant to the Agreement as instructed by the Customer, including:

  • hosting website archives at the direction of the Customer; and
  • displaying archived websites to Customer’s authorized users, upon request.

Personal Information Categories

The Personal Data archived in the course of using the Service is determined and controlled by the Customer, and may include any Personal Data of Data Subjects contained on websites archived by the Customer using the Services.

Data Subject Types

Individuals whose Personal Data is publicly displayed on websites archived by the Customer using the Services.

Processing Duration

Archived data is retained for the period specified by the Customer, or until termination of the Agreement.

Approved Subcontractors

  • As set forth in Appendix B (“Subprocessor Annex”)

Countries where the Provider may receive, access, transfer or store Personal Information:

  • As set forth in Appendix B (“Subprocessor Annex”)

Appendix B

Subprocessor Annex

The following sub-processors are authorized under Section 8 (Sub-processors) of this Agreement. For each, the applicable international-transfer status and mechanism is identified. This Annex also serves to populate Annex I.B and Annex III of the EU SCCs where those clauses apply.

Sub-processor / recipientServiceProcessing location(s)Transfer statusTransfer mechanism & supplementary measures
Independent contractors (individuals)Support, development and/or operations personnel with access to Customer Personal DataUnited States, CanadaNot a separate transfer — personnel under Provider’s authority (Arts. 29, 32(4))N/A. Individual contractors act solely under the Provider’s authority and for the Provider’s benefit. Access from outside the EEA is bound by written confidentiality and documented instructions and managed as an access risk through the technical, organizational, and supplementary measures in Appendix C (role-based access, data minimization, prohibition on local storage/download, and government-access safeguards).
Independent contractors (individuals)Support, development and/or operations personnel with access to Customer Personal DataGermany (EEA)Not a Restricted Transfer (intra-EEA)No Article 46 mechanism required (intra-EEA). Individuals acting solely under the Provider’s authority and for the Provider’s benefit. Bound by confidentiality and documented instructions under Section 4.
Digital OceanCloud hosting and compute for the SaaS platformNetherlands (EEA)Not a Restricted Transfer (intra-EEA)Data at rest in the EEA. No Article 46 mechanism required. Article 28 terms apply.
GoogleEmail (including customer support)USRestricted TransferEU SCCs, Module Three, as incorporated in the Google data processing agreement.
BackblazeArchival data storageNetherlands (EEA), USRestricted TransferEU SCCs, Module Three, as incorporated in the Backblaze data processing agreement. Measure: encryption of backups in transit and at rest.
Wasabi (Wasabi Technologies)Backup / archival object storageCanada (data centre)Restricted TransferEU SCCs, Module Three, as incorporated in the Wasabi data processing agreement. Measure: encryption of backups at rest.

Appendix C

Security Measures (EU SCCs Annex II)

The Provider implements and maintains at least the following technical and organizational measures to protect the Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing (to be confirmed and tailored by the Provider to reflect its actual controls):

  • (a) Encryption of Personal Data in transit (e.g., TLS) and at rest, and use of pseudonymization where appropriate;
  • (b) access controls enforcing least privilege and role-based access,
  • (c) unique user credentials, and multi-factor authentication for access to processor systems;
  • (d) measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
  • (e) measures to restore the availability of and access to Personal Data in a timely manner after a physical or technical incident, including tested backup and restoration procedures;
  • (f) logging, monitoring, and alerting for security-relevant events;
  • (g) vulnerability management, secure configuration, and timely patching;
  • (h) secure software development practices and change management;
  • (i) an incident-response and breach-notification process;
  • (j) due diligence and contractual controls for Subprocessors;
  • (k) data-minimization and retention controls; and
  • (l) a process for regularly testing, assessing, and evaluating the effectiveness of these technical and organizational measures.

Appendix D

EU SCCs Annex I.A / I.C

Annex I.A (List of Parties). Data exporter: the Customer identified in the Agreement, acting as controller (or, where applicable, processor), whose contact details, role, and processing activities relevant to the transfer are as set out in the Agreement and Appendix A. Data importer: Webrecorder Software LLC, acting as processor (or subprocessor), whose activities relevant to the transfer are the provision of the Services described in Appendix A; contact point for data protection: privacy@webrecorder.org. The parties’ signatures to the Agreement constitute signature of this DPA and Annex I.A.

Annex I.C (Competent Supervisory Authority). The competent supervisory authority is determined under Clause 13 of the EU SCCs: where the data exporter is established in an EEA member state, the supervisory authority of that member state; where the data exporter is not established in the EEA and is not required to appoint a representative under Article 27, the supervisory authority of one of the EEA member states in which the data subjects whose personal data is transferred are located. For data subject to the UK GDPR, the Information Commissioner’s Office is the competent authority; for data subject to the Swiss FADP, the Swiss Federal Data Protection and Information Commissioner.

Article 27 Representatives. The Provider has determined that it is not required to appoint a representative under Article 27 of the EU GDPR or under Article 27 of the UK GDPR. The Provider is not established in the EEA or the United Kingdom, and its processing under this DPA does not fall within Article 3(2) of the EU GDPR (or the equivalent UK provision): the Provider offers its services to the Customer and other organizations, not to data subjects, and does not monitor the behavior of data subjects in the Union or the United Kingdom. The Provider will keep this determination under review and will appoint a representative promptly if the basis for it changes (for example, if the Provider begins offering its services directly to data subjects in the Union or the United Kingdom).