Trust Center
Data protection and privacy
This page summarizes the commitments we make when we handle personal data on behalf of a customer. It complements, and does not replace, our Privacy Policy and Terms of Service. A Data Processing Addendum is available on request.
Key takeaways
- When we process personal data for a customer, we act as a processor and follow the customer documented instructions.
- A Data Processing Addendum, including standard contractual clauses where transfers require them, is available on request.
- We maintain a subprocessor list and commit to advance notice before material changes.
- We commit to notifying affected customers of a personal data breach without undue delay.
Our role
When a customer uses one of our platforms and provides personal data, we generally act as a data processor and handle that data on the customer behalf and on their documented instructions. For our own business relationships and our website, we act as a controller. Our Privacy Policy describes how we handle information as a controller.
Processor commitments
Where we act as a processor, we commit to the substance of the obligations set out in Article 28 of the GDPR and the equivalent expectations under United States state privacy laws. In practice this means we:
- process personal data only on the customer documented instructions;
- ensure that people authorized to process the data are bound by confidentiality;
- apply appropriate technical and organizational security measures;
- engage subprocessors only under written terms that carry the same protections, and give notice of changes;
- assist the customer, so far as possible, in responding to data subject and consumer rights requests;
- support the customer with security, breach notification, and any assessments required of them;
- delete or return personal data at the end of the engagement, subject to legal retention requirements.
California and United States state laws
Where the California Consumer Privacy Act, as amended by the CPRA, or a comparable state law applies, we act as a service provider or contractor. We do not sell or share personal data that we process on a customer behalf, and we use it only to provide the agreed service. Our California Privacy Rights notice sets out the rights available to California residents.
Subprocessors
We use a limited set of subprocessors to deliver our services, including established cloud infrastructure providers. A current subprocessor list is available on request. We commit to giving customers reasonable advance notice, typically at least thirty days, before adding or replacing a subprocessor that processes their personal data, so that they have the opportunity to object.
International transfers
Our operations are based in the United States. Where we receive personal data from the European Economic Area, the United Kingdom, or another region that restricts transfers, we put an appropriate transfer mechanism in place, such as the European Commission standard contractual clauses, as part of our Data Processing Addendum.
Retention and deletion
We keep personal data only for as long as it is needed for the purpose it was collected, for the duration of the customer engagement, or as required by law. On request at the end of an engagement, we return or delete personal data, subject to any legal obligation to retain it.
Breach notification
If we become aware of a personal data breach affecting a customer data, we will notify the customer without undue delay and provide the information they need to meet their own notification obligations, in line with our contracts and applicable law.
Requesting a Data Processing Addendum
A Data Processing Addendum is available to customers and prospective customers on request. Ask us through the documentation request on our Trust Center and we will provide it for review and signature. For the full terms that govern use of our sites and services, see our Terms of Service and Privacy Policy.
Questions and Answers
Questions from reviewers
Do you offer a Data Processing Addendum?
Do you sell personal data?
Where is data stored?
Vendor review
Need documentation for a review?
Security package, Data Processing Addendum, subprocessor list, accessibility VPAT, certificate of insurance, or a completed questionnaire. Tell us what your team needs.
