Third Party Index

Snapshot 43911

Document
Data processing addendum
URL
https://www.usertour.io/legal/dpa-self-hosted.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
47685 bytes
SHA-256 (raw)
8298f95439351b6977b60835bbcba8aa009900b41baff147d36bac68e7e5ced7
SHA-256 (normalized text)
34f3dfc07ffd124433b58cf3d0cad3e456654991efc9965d4ca262a2dd97b07f

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Data Processing Addendum (DPA)
Self-Hosted Deployment
This Data Processing Addendum (“DPA”) applies to the self-hosted deployment of the Usertour
software (“Software”) and forms part of the agreement between:

Customer (Data Controller): The entity deploying and using the Software
Usertour (Software Provider): Usertour

This DPA may be accepted electronically and shall not require handwritten signatures to be legally
binding.

1. Roles of the Parties
For the purposes of applicable data protection laws, including the EU General Data Protection
Regulation (“GDPR”):

The Customer acts as the Data Controller.

Usertour does not act as a Data Processor for self-hosted deployments and does not process
Personal Data on behalf of the Customer.

2. Scope of Processing
In a self-hosted deployment:

  •    All data is processed solely within systems controlled by the Customer.

  •    Usertour does not host, receive, store, or transmit Personal Data.

  •    Usertour has no access to Customer data by default.

3. Access
Usertour shall have no remote or direct access to Customer systems or data unless explicitly
authorized in writing by the Customer for limited technical support purposes.

Any such access shall be temporary and limited in scope.

4. Security Responsibilities
The Customer is solely responsible for:

  •    Infrastructure security
  •    Access control

  •    Encryption

  •    Network and application security

Usertour may provide general security guidance but does not control the Customer’s environment.

5. Sub-processors
Usertour does not appoint any sub-processors to process Personal Data in self-hosted deployments.

6. International Data Transfers
Usertour does not transfer or store Personal Data outside of the Customer’s controlled environment.

7. Data Subject Rights
The Customer is solely responsible for handling Data Subject requests.

Usertour shall provide reasonable technical assistance upon request.

8. Audits
Upon reasonable written request, Usertour shall make available documentation reasonably
necessary to demonstrate compliance with this DPA.

On-site audits are not required.

9. Term
This DPA remains in effect for as long as the Customer uses the self-hosted version of the Software.

Upon termination, no data return or deletion obligations apply to Usertour, as it does not store or
control Customer data.

10. Liability
To the maximum extent permitted by law, Usertour shall not be liable for data protection incidents
arising from Customer-controlled infrastructure, hosting, or miscon guration.

11. Governing Law
                                                         fi
This DPA shall be governed by the same law and jurisdiction as the primary License or Subscription
Agreement between the parties.

Signatures
Customer (Data Controller)
Name:
Title:
Date:
Signature:

Usertour (Software Provider)
Name:
Title:
Date:
Signature: