Glassrecord

Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the terms of service at glassrecord.com/terms (the “Terms”) between [Company legal name] (“Glassrecord”, “we”) and the customer that accepted them (“Customer”, “you”). It applies whenever Glassrecord processes Customer Personal Data. Capitalized terms not defined here have the meaning the Terms give them.

This version takes effect on [Date]. It applies without a signature. A countersigned copy is available on request at [Privacy contact address].

1. Definitions

2. Roles

3. Processing on instructions

Glassrecord processes Customer Personal Data only on Customer’s documented instructions. Customer’s instructions are the Terms, this DPA, Customer’s configuration and use of the service, and any other written instruction the parties agree. Glassrecord will tell Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend the affected processing until Customer changes the instruction.

Glassrecord may process Customer Personal Data otherwise only where the law requires it, in which case it will tell Customer first unless the law forbids that.

Annex 1 describes the processing.

4. Customer’s obligations

Customer is responsible for:

5. Confidentiality

Glassrecord ensures that every person it authorizes to process Customer Personal Data is bound by confidentiality. Glassrecord staff reach Customer Data only as the Terms describe: under a time-limited grant recorded in Customer’s audit log, when Customer opens support access, or in the staff review of how scanned pages are classified, which shows pages from every customer’s scans.

6. Security

Glassrecord implements the technical and organizational measures in Annex 2, and keeps them appropriate to the risk. Glassrecord may change them if the change does not reduce the overall protection of Customer Personal Data.

7. Sub-processors

8. Data subject requests

Glassrecord will tell Customer without undue delay if it receives a request from a data subject about Customer Personal Data, and will not answer it except to refer the person to Customer, unless the law requires otherwise. Taking into account the nature of the processing, Glassrecord will help Customer answer such requests. The service lets Customer export its organization’s records and each person’s own data, correct entered data, and delete members, sites, and the organization.

9. Security Incidents

Glassrecord will notify Customer without undue delay, and in any case within [48] hours, after becoming aware of a Security Incident affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Glassrecord will provide further information as it becomes known, take reasonable steps to contain and remedy the incident, and help Customer meet its own notification duties. Notice is sent to Customer’s Owners by email [and to any security contact Customer names in the app]. Notice is not an admission of fault.

10. Assistance

Taking into account the nature of the processing and the information available to it, Glassrecord will give Customer reasonable help with data protection impact assessments and prior consultations with supervisory authorities that concern the service.

11. Aggregate data, observations, and service improvement

12. International transfers

13. United States state privacy laws

As a service provider or contractor, Glassrecord will not:

Glassrecord will comply with the CCPA’s obligations that apply to it, give Customer’s personal data the same level of privacy protection the CCPA requires, and tell Customer if it can no longer meet them. Customer may take reasonable steps to stop unauthorized use of Customer Personal Data. Glassrecord certifies that it understands these restrictions.

14. Audits

Glassrecord will make available to Customer the information reasonably needed to show that it meets this DPA, including answers to reasonable security questionnaires once a year. If that information is not enough to meet Customer’s obligations, or a supervisory authority requires it, Customer may audit Glassrecord’s compliance with this DPA, no more than once a year, on at least 30 days’ written notice, during business hours, at Customer’s cost, through an independent auditor bound by confidentiality, and without access to other customers’ data. [Glassrecord holds no third-party audit report or certification as of this draft.]

15. Return and deletion

16. Liability and precedence

Each party’s liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws or the SCCs do not allow a limitation. If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer Personal Data. This DPA lasts as long as Glassrecord processes Customer Personal Data.

Annex 1. Details of the processing

Parties. Data exporter: Customer, as identified in its account, a controller or processor. Data importer: [Company legal name], [Address], [Privacy contact address], a processor.

Subject matter and purpose. Providing the Glassrecord service under the Terms: scanning Customer’s websites, recording what third parties load and receive under each consent choice, producing findings, fixes, proof records, reports, and shared links, running the Google Tag Manager and other integrations Customer connects, running Protection on Customer’s websites, and supporting Customer.

Nature. Collection by the crawler and by Protection, storage, organization, analysis, retrieval, disclosure to Customer and to recipients Customer chooses, and deletion.

Duration. The subscription, plus the periods in section 15.

Frequency. Continuous, while Customer uses the service.

Categories of data subjects.

Categories of personal data.

Special categories. None intended. A scanned page may show them, for example on a health provider’s site. Glassrecord classifies pages as health, finance, or account pages, which describes the page, not a person.

Sub-processors. As listed at glassrecord.com/subprocessors.

Annex 2. Technical and organizational measures