International Data Processing Addendum
Last updated 8 August 2026 · Version 1.0
This Data Processing Addendum (“DPA”) forms part of the agreement between the business customer identified in an order (“Customer”) and the MapsDoc provider identified in the Terms (“MapsDoc”) whenever MapsDoc processes personal information on the Customer’s behalf.
1. Definitions and roles
“Customer Data” means personal data or personal information processed by MapsDoc on the Customer’s behalf. “Data Protection Law” means privacy and data-protection law applicable to that processing, including GDPR, UK GDPR where applicable, Canadian private-sector privacy law, the Australian Privacy Act 1988, the New Zealand Privacy Act 2020 and applicable US state privacy laws.
The Customer is the controller or business and MapsDoc is its processor, service provider or contractor for Customer Data. Each party is an independent controller for information it processes for its own billing, security, compliance, personnel and business administration.
2. Processing instructions
MapsDoc will process Customer Data only:
- to provide and secure the services;
- on documented instructions contained in the agreement, account settings, connected integrations, approval settings and authorized Requests;
- as otherwise documented and agreed by the parties; or
- where required by applicable law, in which case MapsDoc will notify the Customer beforehand unless prohibited.
MapsDoc will inform the Customer if it reasonably believes an instruction violates applicable Data Protection Law and may pause that instruction while the parties address it. The Customer is responsible for the lawfulness, accuracy, notices, consent and scope of its instructions.
3. Processing details
Subject matter: managed business-visibility services and the enabled review, reputation, content, listing, citation, reporting, communication and support workflows. Duration: the service term plus the deletion or return period and any legally required retention. Purpose: operating the Customer’s enabled workflows, publishing approved materials, communicating as instructed, reporting, securing and supporting the service.
Data subjects may include: Customer personnel and contractors; Customer customers and prospects; reviewers and people interacting with Customer profiles; and other people whose information the Customer lawfully submits.
Data may include: names, business contact details, communications, review and interaction data, delivery status, profile content, approved media, technical identifiers and audit records.
Sensitive data: not intended or permitted unless separately agreed in writing. The Customer must not submit patient or health data, payment-card data, government identifiers or other high-risk information through ordinary workflows.
4. Confidentiality and personnel
MapsDoc will ensure that persons authorized to handle Customer Data are bound by confidentiality, receive access only as needed for their role and are subject to appropriate privacy and security instructions.
5. Security
MapsDoc will maintain technical and organizational measures appropriate to the processing risk, including as applicable:
- role-based, least-privilege access and removal of access when no longer needed;
- server-side authorization and customer/organization separation;
- multifactor authentication for privileged systems where supported;
- TLS encryption in transit and infrastructure-provider encryption at rest;
- secrets and privileged credentials kept outside client code;
- backups, recovery procedures and controlled production changes;
- logging, monitoring, input validation and webhook verification;
- retention, deletion and log-redaction controls;
- provider due diligence and contractual protection; and
- incident response and personnel confidentiality.
MapsDoc may update these measures without materially reducing the overall protection of Customer Data.
6. Subprocessors
The Customer gives general authorization for MapsDoc to use subprocessors needed to provide the service. MapsDoc will provide its current customer-confidential subprocessor schedule through an authenticated legal/compliance area, on written request, or with the agreement, and will:
- perform reasonable privacy and security diligence;
- impose written obligations appropriate to the processing;
- remain responsible for subprocessor performance as required by applicable law; and
- provide notice of a new subprocessor that will materially process Customer Data.
The identities and commercial roles of MapsDoc’s subprocessors are confidential operational information. The Customer may use that information for legitimate privacy, security, procurement and compliance purposes and may disclose it where required by law, but must not otherwise publish or use it to circumvent MapsDoc’s services. This restriction does not limit data-subject notices or regulatory disclosures required by applicable law.
The Customer may object within 14 days of notice on reasonable, documented data-protection grounds. The parties will try to resolve the concern. If no reasonable solution exists, the Customer may terminate only the materially affected service component without penalty before the new subprocessor begins processing, and MapsDoc will refund any prepaid fee allocable to the unused terminated period.
7. International transfers
For restricted transfers from the EEA, MapsDoc will use a valid GDPR Chapter V mechanism, including an adequacy decision, applicable Data Privacy Framework certification or the European Commission Standard Contractual Clauses (“EU SCCs”), with supplementary measures where required.
Where the EU SCCs are needed, they are incorporated by reference as follows: Module Two applies where the Customer is a controller and MapsDoc is a processor; Module Three applies where the Customer is a processor and MapsDoc is a subprocessor; the optional docking clause applies; subprocessor authorization is general with the notice period in Section 6; the optional independent dispute-resolution language does not apply; the governing law is Germany; the chosen courts are Germany; the competent authority is determined under Clause 13; Annex I is completed by the agreement and Section 3; Annex II is Section 5; and Annex III is the current subprocessor list. The official EU SCC text controls over a conflict.
For transfers subject to other Data Protection Law, the parties will use the contractual and due-diligence protections required by that law. MapsDoc will provide reasonable information about applicable transfer safeguards on request.
8. Individual rights
Considering the nature of the processing, MapsDoc will reasonably assist the Customer in responding to access, correction, deletion, portability, restriction, objection and opt-out requests applicable to Customer Data.
If MapsDoc receives a request concerning identifiable Customer Data, it will refer the person to the Customer or notify the Customer unless prohibited by law. MapsDoc will not respond on the Customer’s behalf without authorization or legal obligation.
9. Security incidents
MapsDoc will notify the Customer without undue delay after becoming aware of a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Customer Data.
MapsDoc will provide available information about the nature of the incident, affected data and people, likely consequences, mitigation and a response contact. Information may be provided in phases. Notification is not an admission of fault. The Customer is responsible for regulatory or individual notifications unless law assigns that duty to MapsDoc.
10. Compliance assistance
Considering the processing and information available, MapsDoc will reasonably assist the Customer with security, breach response, data-protection impact assessments and regulator consultation required by applicable law. Customer-specific work beyond standard service may be charged at an agreed rate where legally permitted; urgent incident cooperation is not conditional on advance payment.
11. Return and deletion
At the end of the services, MapsDoc will delete or return Customer Data at the Customer’s choice where technically and legally feasible, unless retention is required by law. The Customer must make a timely export request before account closure. Data in secured backups is deleted through the ordinary rotation cycle and remains protected and unavailable for other use until deletion.
12. Information and audits
MapsDoc will provide information reasonably necessary to demonstrate compliance, such as relevant policy summaries, provider information and independent assurance materials if available.
If that information is insufficient, the Customer may audit the relevant processing no more than once per year, or additionally after a material incident or regulator request, on reasonable written notice. An audit must protect other customers, security and confidentiality; occur during ordinary business hours; minimize disruption; and use an independent qualified auditor where appropriate. The Customer bears reasonable costs of a customer-specific audit unless it identifies a material breach by MapsDoc.
13. US service-provider restrictions
Where applicable US state privacy law treats MapsDoc as a service provider, processor or contractor, MapsDoc will not:
- sell Customer Data or share it for cross-context behavioral advertising;
- retain, use or disclose Customer Data outside the specified business purposes and direct business relationship, except as permitted by law;
- combine Customer Data with personal information received from another person or collected through MapsDoc’s own consumer interaction except as permitted by law; or
- process Customer Data contrary to the Customer’s lawful instructions.
MapsDoc will provide the same level of privacy protection required by applicable law, notify the Customer if it can no longer meet that obligation, and permit reasonable steps to stop and remediate unauthorized use.
14. Customer obligations
The Customer will provide lawful instructions, minimize Customer Data, maintain required notices and consent, respond to individuals, secure its accounts and avoid prohibited sensitive data. The Customer represents that MapsDoc’s processing as instructed is lawful.
15. Liability, priority and duration
Liability is governed by the agreement and mandatory law. This DPA prevails over conflicting general terms concerning Customer Data. Applicable EU SCCs prevail over conflicting terms. This DPA lasts while MapsDoc processes Customer Data on the Customer’s behalf.
16. Parties and acceptance
The parties and their contact details are those stated in the order and Terms. The DPA is accepted when the Customer accepts the agreement or signs an order incorporating it. Privacy contact: hello@mapsdoc.com.