Snapshot 18838
Normalized text
Scripts and page chrome removed; this is what change detection compares.
UserWay Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the UserWay Terms of Service and applies where UserWay processes Personal Information on behalf of Customer in connection with the Services.
1. Definitions
For purposes of this DPA:
"Agreement" means the UserWay Terms of Service and any applicable order forms, statements of work, or other ordering documents referencing or incorporating this DPA.
"Business" means an entity that determines the purposes and means of processing Personal Information, as defined under applicable U.S. state privacy laws.
"Contractor" means an entity that processes Personal Information on behalf of a Business for a business purpose under applicable U.S. state privacy laws.
"Controller" means an entity thatdeterminesthe purposes and means of processing Personal Information, as defined under applicable Data Protection Laws.
"Customer" means the individual or entity using or purchasing the Services.
"Customer Content" means content, data, information, materials, website content, code, files, pages, URLs, reports, support materials, or other information submitted, uploaded, made available, scanned, monitored, processed, or otherwise provided by or on behalf of Customer through the Services.
"Data Protection Laws" means applicable privacy, data protection, and data security laws, including where applicable the EU GDPR, UK GDPR, Swiss data protection law, U.S. state privacy laws, Israeli privacy law, Canadian privacy law, and other similar laws applicable to the processing of Personal Information under the Agreement.
"EU GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).
“EU Standard Contractual Clauses" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission pursuant to the EU GDPR, as may be updated or replaced from time to time.
"Personal Information" means personal data, personal information, personally identifiable information, or similar information protected under applicable Data Protection Laws.
"Processor" means an entity that processes Personal Information on behalf of a Controller or Business, as defined under applicable Data Protection Laws."
"Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Information processed by UserWay on Customer's behalf.
"Sensitive Personal Information" means Personal Information subject to heightened protection under applicable Data Protection Laws, including where applicable health or medical information, disability-related information, government identifiers, account credentials, children’s data, biometric information, or other legally protected sensitive information.
"Service Provider" means an entity that processes Personal Information on behalf of a Business for a business purpose under applicable U.S. state privacy laws.
"Services" has the meaning given in the Agreement and includes UserWay products, widgets, scanners, monitoring tools, support, remediation, professional services, AI-enabled features, and related functionality.
"Subprocessor" means a third party engaged by UserWayto process Personal Information on Customer’s behalf in connection with the Services.
"UK GDPR" means the EU GDPR as incorporated into United Kingdom law by operation of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019.
"UK International Data Transfer Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office under section 119A of the UK Data Protection Act 2018, as may be updated or replaced from time to time.
"UserWay" means UserWay, Inc. and its applicable affiliates providing Services under the Agreement.
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
2. Roles of the Parties
Customer is the Controller, Business, or equivalent entity under applicable Data Protection Laws for Personal Information processed on Customer’s behalf through the Services.
UserWay is the Processor, Service Provider, Contractor, or equivalent entity under applicable Data Protection Laws to the extent it processes Personal Information on Customer’s behalf in connection with providing the Services.
Each party remains responsible for complying with the obligations that apply to it under applicable Data Protection Laws.
3. Customer Responsibilities
Customer is responsible for:
determining whether and how to use the Services on Customer’s websites, applications, systems, or other properties;
ensuring that Customer has all rights, notices, consents, permissions, authorizations, and lawful bases required for Customer’s collection, use, submission, and disclosure of Personal Information through or in connection with the Services;
providing all required privacy notices to individuals whose Personal Information may be processed through Customer’s use of the Services;
responding to requests from individuals exercising rights under applicable Data Protection Laws, unless otherwise required by law;
ensuring that Customer Content does not violate applicable law or third-party rights; and
using the Services in accordance with the Agreement, this DPA, and applicable law.
Customer acknowledges that UserWay does not control the content, configuration, or legal basis for Customer’s websites, applications, or other environments in which the Services are deployed.
4. Scanner, Monitoring, and Telemetry Functionality
Customer understands that the provision of the Services may involve the processing of Personal Information provided to UserWay through the Customer’s use of the Services.
To the extent UserWay processes Personal Information on behalf of the Customer in connection with the Services, it does so as the Customer’s processor or service provider, as applicable. The Customer is responsible for ensuring that it has an appropriate legal basis and has provided any required notices for such processing.
The Services are not intended to be used primarily for the collection or processing of Sensitive Personal Information. Customers should avoid intentionally providing such data through the Services unless they have determined that such use is appropriate and compliant with applicable requirements, and any necessary additional arrangements with UserWay are in place.
5. Processing Instructions
UserWay will process Personal Information on Customer’s behalf only:
to provide, secure, maintain, support, and improve the Services as permitted by the Agreement;
in accordance with Customer’s documented instructions, including this DPA;
as required by applicable law; or
as otherwise permitted under applicable Data Protection Laws.
If UserWay believes that an instruction from Customer violates applicable Data Protection Laws, UserWay will notify Customer unless prohibited by law.
UserWay may also process and disclose Personal Information where required to comply with applicable law, regulation, or a binding request from a competent authority.
6. Confidentiality
UserWay will ensure that personnel authorized to process Personal Information are subject to appropriate confidentiality obligations.
7. Security Measures
UserWay will implement and maintainappropriate technical and organizational measures designed to protect Personal Information against unauthorized or unlawful processing, and against accidental loss, destruction, damage, alteration, or disclosure.
Such measures may include, as appropriate, access controls, encryption, logging and monitoring, vulnerability management, secure development practices, personnel training, incident response processes, supplier risk management, and administrative, physical, and technical safeguards appropriate to the nature of the Services and the Personal Information processed.
UserWay will ensure that any Subprocessors engaged in connection with the Services are subject to data protection and security obligations that are consistent with this section and applicable law.
Data transmitted through the Services will be protected using TLS 1.2 or higher or comparable to secure transmission standards.
8. Security Incidents
UserWay will notify Customer without undue delay after becoming aware of a Security Incident affecting Personal Information processed on Customer’s behalf.
UserWay will take reasonable steps to contain, investigate, and remediate the Security Incident.
UserWay’s notice will include information reasonably available to UserWay to help Customer meet its obligations under applicable Data Protection Laws. UserWay’s notification of a Security Incident is not an acknowledgment of fault or liability.
Customer is responsible fordetermining whether the Security Incident triggers any notification, reporting, or other obligations under applicable law.
9. Subprocessors
Customer authorizes UserWay to engage Subprocessors to provide the Services.
UserWay will require Subprocessors to protect Personal Information in a manner consistent with this DPA and applicable Data Protection Laws.
UserWayremains responsible for the acts and omissions of its Subprocessors to the extent required by applicable law, subject to the limitations of liability set forth in the Agreement.
Certain Services may use third-party providers, including AI providers, to provide features such as image recognition, text summarization, chat, issue analysis, or related functionality. Where such providers process Personal Information on Customer’s behalf, they are treated as Subprocessors under this DPA.
UserWay will provide at least fifteen (15) days' advance notice of material changes to Subprocessors through a reasonable mechanism (such as posting to a subprocessor list or email notification). If Customer reasonably objects to a new Subprocessor on data protection grounds, Customer may notify UserWay in writing within the notice period, and the parties will work in good faith to resolve the objection. If the parties are unable to resolve the objection, Customer may terminate the affected Services upon written notice without penalty.
10. Assistance with Individual Rights and Compliance
Taking into account the nature of the processing and the information available, UserWay will provide reasonable assistance to Customer, where required by applicable Data Protection Laws, at Customer's expense (except to the extent such assistance is included as part of the Services at no additional charge), with:
responding to individual rights requests;
meeting security obligations;
conducting data protection impact assessments or similar assessments; and
Consulting with supervisory authorities where required.
Customer is responsible for receiving, evaluating, and responding to requests from individuals, unless applicable law requires otherwise. If UserWay receives a request directly from an individual relating to Personal Information processed on Customer’s behalf, UserWay may direct the individual to Customer or otherwise handle the request as permitted by applicable law.
11. Return and Deletion
Upon termination or expiration of the Agreement, UserWay will delete or return Personal Information processed on Customer’s behalf in accordance with the Agreement, applicable law, and UserWay’s retention and deletion practices.
UserWay will retain Personal Information only for as long as necessary to fulfill the purposes for which it was collected, comply with applicable legal obligations, resolve disputes, and enforce agreements. Upon termination of the Services, UserWay will delete or return Personal Information as required by applicable law or as agreed upon in this DPA.
UserWay will delete or return Personal Information within a reasonable period following termination, subject to applicable law and standard backup and retention processes.
12. Audits and Information
UserWay will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and operational limitations.
UserWay will ordinarily satisfy its audit obligations by making available certifications, third-party audit reports (such as SOC 2 or ISO 27001), or similar documentation. Where required by applicable Data Protection Laws and where such documentation is insufficient to demonstratecompliance, Customer may request an audit of UserWay’srelevant processing activities.Any such audit may be conducted no more than once annually (except where required by a supervisory authority or following a material Security Incident affecting Customer's Personal Information), upon reasonable prior written notice of at least thirty (30) days, during normal business hours, and in a manner that minimizes disruption to UserWay'soperations and does not compromise the confidentiality or security of other customers' data. Customer will bear its own costs and expenses in connection with any such audit, including any reasonable costs incurred by UserWayin facilitatingthe audit.
Customer may engage an independent third-party auditor, subject to UserWay’s prior approval (not to be unreasonably withheld) and appropriate confidentiality safeguards.
13. International Transfers
Customer acknowledges that UserWay and its Subprocessors may process Personal Information in the United States and other jurisdictions where UserWay, its affiliates, or its Subprocessors operate.
Where Personal Information protected by EU, UK, Swiss, or other applicable transfer restrictions is transferred internationally, the parties will rely on appropriate transfer mechanisms, which may include adequacy decisions, standard contractual clauses, the UK International Data Transfer Addendum, intra-group arrangements, or other lawful transfer mechanisms.
Where the EU Standard Contractual Clauses or UK transfer terms are requiredand applicable, they are hereby incorporated by reference into the DPA. To the extent additionalexecution or documentation is required, such terms will be made available through applicable data processing terms, purchase documentation, or another written mechanism.
14. U.S. State Privacy Laws
To the extent UserWay processes Personal Information on behalf of Customer under U.S. state privacy laws, including the California Consumer Privacy Act as amended, UserWay acts as Customer’s Service Provider, Contractor, Processor, or equivalent role, as applicable.
UserWay will not sell or share Personal Information processed on Customer’s behalf, retain, use, or disclose such Personal Information outside the direct business relationship with Customer, or retain, use, or disclose such Personal Information for any purpose other than the business purposes described in the Agreement, this DPA, or as otherwise permitted by applicable law.
UserWay will provide the same level of privacy protection required ofService Providers, Contractors, Processors, or equivalent entities under applicable U.S. state privacy laws.
Customer is responsible for providing any required notices and honoring any applicable consumer rights relating to Personal Information processed through Customer’s use of the Services.
15. AI Features
Certain Services may include AI-enabled features. Customer acknowledges that inputs submitted to AI-enabled features may be processed to provide the relevant functionality.
UserWay will not use Personal Information processed on Customer’s behalf for AI model training or improvement except as permitted by the Agreement, this DPA, or Customer’s documented instructions, and in compliance with applicable law.
16. Order of Precedence
If there is a conflict between this DPA and the Agreement regarding the processing of Personal Information on Customer’s behalf, this DPA will control to the extent of the conflict.
If there is a conflict between this DPA and applicable standard contractual clauses or other mandatory transfer terms, the standard contractual clauses or mandatory transfer terms will control to the extent of the conflict.
17. Nature and Scope of Processing
The subject matter, duration, nature, and purpose of the processing arise from the Customer’s use of the Services as described in the Agreement.
Processing may include the collection, access, use, storage, analysis, transmission, and deletion of Personal Information contained in Customer Content or otherwise made available through the Services.
The types of Personal Information and categories of data subjects depend on the Customer’s use of the Services and may include, for example, information relating to website visitors, end users, or Customer personnel.