This Data Processing Addendum ("DPA") forms part of the Terms whenever a Customer is a controller or processor of personal data in Customer Content and SMASHING DIVS processes that data on the Customer's behalf. GDPR terms such as controller, processor, personal data, processing, data subject, and personal data breach have the meanings given in GDPR.
23.1 Roles, scope, and instructions
The Customer is the controller or a processor authorized by the relevant controller. SMASHING DIVS is the processor or subprocessor. We will process personal data only on the Customer's documented instructions, including these Terms, the Customer's use and configuration of the Services, an order form, and written support instructions, unless EU or Member State law requires other processing. If legally permitted, we will notify the Customer before processing required by law. We will promptly tell the Customer if we believe an instruction infringes applicable data protection law and may suspend the affected processing while the parties resolve it.
23.2 Customer responsibilities
The Customer confirms that its instructions are lawful and that it has provided all required notices and obtained all necessary rights and lawful bases. The Customer will minimize personal data, configure appropriate access and retention, respond to data subjects, and not submit special-category or criminal-offence data unless the processing is lawful, necessary, risk-assessed, and protected by appropriate safeguards.
23.3 Confidentiality
We ensure that persons authorized to process Customer personal data are bound by confidentiality or an appropriate statutory duty and access it only as needed for their role.
23.4 Security
Taking account of the state of the art, implementation cost, and the nature, scope, context, purposes, and risks of processing, we will maintain appropriate technical and organizational measures under Article 32 GDPR. Current measures include TLS in transit; identity, tenant, role, and row-level access controls; scoped API and integration credentials; restricted administrator access; audit and operational logging; environment separation; backups and recovery procedures; vulnerability and dependency review; and incident response procedures.
The Customer is responsible for secure endpoints, passwords, API keys, permissions, lawful configurations, and its own backups or exports. We may update measures as technology and risk change without materially reducing overall protection.
23.5 Subprocessors
The Customer gives general written authorization for us to use subprocessors needed to provide the Services. Current provider categories and principal providers are listed in the Subprocessor Register. We will impose data protection obligations on a subprocessor that provide substantially the protection required by this DPA, and we remain responsible for its performance to the extent required by Article 28 GDPR.
Where required, we will give notice of a new subprocessor before it begins processing Customer personal data. The Customer may object within 14 days on reasonable, documented data protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate only the affected feature or Service, and we will refund prepaid fees for the unused terminated period where appropriate.
23.6 International transfers
We will not transfer Customer personal data outside the EEA except under a lawful transfer mechanism. Where the European Commission Standard Contractual Clauses are required for a transfer by us to a subprocessor, we will enter into the applicable module with that recipient and complete the required options and annex information. We will conduct and support transfer assessments and supplementary measures where required. The Privacy Policy describes known location variability, including search grounding and model routing.
23.7 Assistance
Taking account of the nature of processing and information available to us, we will reasonably assist the Customer with data subject requests, security duties, personal data breach assessments and notifications, data protection impact assessments, and prior consultation with a supervisory authority. If a data subject contacts us about Customer personal data, we will refer the request to the Customer and will not respond substantively unless instructed or legally required.
23.8 Personal data breaches
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data. As information becomes available, we will provide the nature of the breach, likely consequences, affected data and data subjects where known, contact point, and mitigation taken or proposed. Our notice is not an admission of fault. The Customer is responsible for notifications it must make as controller.
23.9 Return and deletion
During the contract, available controls and support requests can delete or export certain data. At the Customer's choice after the relevant Service ends, we will delete or return Customer personal data and delete remaining copies, unless law requires storage. Data may remain in isolated backups until normal rotation and may be retained where necessary for legal claims, in each case protected and excluded from further ordinary processing. The Customer should request a return before account closure.
23.10 Demonstrating compliance and audits
We will provide information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow an audit by the Customer or an independent auditor bound by confidentiality. An audit must normally be requested at least 30 days in advance, occur no more than once per year, avoid access to other customers' data, and not unreasonably disrupt the Services. These limits do not apply where a supervisory authority requires otherwise or credible evidence of a material breach justifies an additional audit. The Customer pays its audit costs unless the audit identifies our material breach.
23.11 Processing details
- Subject matter. Providing AI agent, workflow, storage, collaboration, integration, support, and App services selected and configured by the Customer.
- Duration. The term of the Services plus the limited deletion, backup, and legal retention period described above.
- Nature and purpose. Collecting, recording, organizing, structuring, storing, retrieving, consulting, transmitting, generating, transforming, embedding, comparing, evaluating, making available, securing, supporting, deleting, and other processing needed to perform Customer instructions.
- Data subjects. Customer Users, personnel, clients, prospects, contractors, collaborators, end users, website visitors, correspondents, document authors and subjects, job applicants, matter participants, and other people whose data the Customer submits.
- Personal data. Identifiers, contact and professional data, account and permission data, communications, document and file content, prompts and Outputs, usage and technical data, integration content, employment and education data, audio or voice recordings, and any other category submitted by the Customer.
- Sensitive data. The Services are not designed for biometric identification or medical records, but Customer Content can incidentally include special-category data or criminal-offence data. The Customer must apply section 23.2 and any additional safeguards required by law.
- Frequency. Continuous for stored data and each time a User, API, schedule, integration, agent, workflow, or support instruction initiates processing.
23.12 Conflict and liability
This DPA controls over the rest of the Terms for its subject. An applicable Standard Contractual Clause controls over this DPA where they conflict. Contractual liability limits apply between the parties to the extent permitted, but do not limit a data subject's rights or liability that GDPR or an applicable Standard Contractual Clause does not allow the parties to limit.