Sacramento, California Mon to Fri, 9:00 AM to 6:00 PM Pacific
DotNet Holdings

Trust Center

Data protection and privacy

This page summarizes the commitments we make when we handle personal data on behalf of a customer. It complements, and does not replace, our Privacy Policy and Terms of Service. A Data Processing Addendum is available on request.

Key takeaways

  • When we process personal data for a customer, we act as a processor and follow the customer documented instructions.
  • A Data Processing Addendum, including standard contractual clauses where transfers require them, is available on request.
  • We maintain a subprocessor list and commit to advance notice before material changes.
  • We commit to notifying affected customers of a personal data breach without undue delay.

Our role

When a customer uses one of our platforms and provides personal data, we generally act as a data processor and handle that data on the customer behalf and on their documented instructions. For our own business relationships and our website, we act as a controller. Our Privacy Policy describes how we handle information as a controller.

Processor commitments

Where we act as a processor, we commit to the substance of the obligations set out in Article 28 of the GDPR and the equivalent expectations under United States state privacy laws. In practice this means we:

  • process personal data only on the customer documented instructions;
  • ensure that people authorized to process the data are bound by confidentiality;
  • apply appropriate technical and organizational security measures;
  • engage subprocessors only under written terms that carry the same protections, and give notice of changes;
  • assist the customer, so far as possible, in responding to data subject and consumer rights requests;
  • support the customer with security, breach notification, and any assessments required of them;
  • delete or return personal data at the end of the engagement, subject to legal retention requirements.

California and United States state laws

Where the California Consumer Privacy Act, as amended by the CPRA, or a comparable state law applies, we act as a service provider or contractor. We do not sell or share personal data that we process on a customer behalf, and we use it only to provide the agreed service. Our California Privacy Rights notice sets out the rights available to California residents.

Subprocessors

We use a limited set of subprocessors to deliver our services, including established cloud infrastructure providers. A current subprocessor list is available on request. We commit to giving customers reasonable advance notice, typically at least thirty days, before adding or replacing a subprocessor that processes their personal data, so that they have the opportunity to object.

International transfers

Our operations are based in the United States. Where we receive personal data from the European Economic Area, the United Kingdom, or another region that restricts transfers, we put an appropriate transfer mechanism in place, such as the European Commission standard contractual clauses, as part of our Data Processing Addendum.

Retention and deletion

We keep personal data only for as long as it is needed for the purpose it was collected, for the duration of the customer engagement, or as required by law. On request at the end of an engagement, we return or delete personal data, subject to any legal obligation to retain it.

Breach notification

If we become aware of a personal data breach affecting a customer data, we will notify the customer without undue delay and provide the information they need to meet their own notification obligations, in line with our contracts and applicable law.

Requesting a Data Processing Addendum

A Data Processing Addendum is available to customers and prospective customers on request. Ask us through the documentation request on our Trust Center and we will provide it for review and signature. For the full terms that govern use of our sites and services, see our Terms of Service and Privacy Policy.

Questions and Answers

Questions from reviewers

Do you offer a Data Processing Addendum?
Yes. A DPA is available to customers on request and includes standard contractual clauses where a data transfer requires them.
Do you sell personal data?
No. When we process personal data on a customer behalf we act as a service provider or processor, and we use that data only to deliver the agreed service. We do not sell or share it.
Where is data stored?
Our operations are based in the United States and we use established cloud infrastructure providers. Specific residency for an engagement can be discussed during onboarding.

Vendor review

Need documentation for a review?

Security package, Data Processing Addendum, subprocessor list, accessibility VPAT, certificate of insurance, or a completed questionnaire. Tell us what your team needs.