Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the terms of service at glassrecord.com/terms (the “Terms”) between [Company legal name] (“Glassrecord”, “we”) and the customer that accepted them (“Customer”, “you”). It applies whenever Glassrecord processes Customer Personal Data. Capitalized terms not defined here have the meaning the Terms give them.
This version takes effect on [Date]. It applies without a signature. A countersigned copy is available on request at [Privacy contact address].
1. Definitions
- Customer Personal Data means personal data in Customer Data that Glassrecord processes on Customer’s behalf under the Terms.
- Data Protection Laws means the laws that apply to the processing of Customer Personal Data under the Terms, including the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and United States state privacy laws such as the California Consumer Privacy Act as amended (“CCPA”).
- GDPR means Regulation (EU) 2016/679.
- Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- Sub-processor means a third party Glassrecord engages to process Customer Personal Data.
- SCCs means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
- UK Addendum means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
- Controller, processor, data subject, personal data, processing, and supervisory authority have the meanings Data Protection Laws give them. Service provider, contractor, sell, and share have the meanings the CCPA gives them.
2. Roles
- Customer is the controller of Customer Personal Data, or a processor acting for its own clients. Where Customer is a processor, for example an agency acting for a client, Glassrecord is Customer’s sub-processor, and Customer confirms that its client has authorized Glassrecord’s processing on the terms of this DPA.
- Glassrecord is the processor of Customer Personal Data, and a service provider or contractor under the CCPA.
- Glassrecord’s own data. Glassrecord is the controller of the personal data it processes for its own purposes, as its privacy policy at
glassrecord.com/privacydescribes: account administration, billing, security, product analytics, the free scan, and the crawler’s opt-out list. This DPA does not apply to that data. - Observations of public websites. Observations are the records the crawler makes of what a public web page loads and sends: the page’s requests, the third parties and hosts it contacts, the names of the cookies and storage keys set in the crawler’s own browser, and the page’s facts. They describe what a browser Glassrecord controls saw, and Glassrecord keeps them as its own data about the website, shared across every customer who monitors that site (section 11). They are not Customer Personal Data. Screenshots, page captures, and page markup a scan keeps for Customer are Customer Data and follow this DPA.
3. Processing on instructions
Glassrecord processes Customer Personal Data only on Customer’s documented instructions. Customer’s instructions are the Terms, this DPA, Customer’s configuration and use of the service, and any other written instruction the parties agree. Glassrecord will tell Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend the affected processing until Customer changes the instruction.
Glassrecord may process Customer Personal Data otherwise only where the law requires it, in which case it will tell Customer first unless the law forbids that.
Annex 1 describes the processing.
4. Customer’s obligations
Customer is responsible for:
- having a lawful basis, and giving any notice and obtaining any consent Data Protection Laws require, for the processing it instructs, including notice to visitors of its websites about Protection;
- having authority to scan each site it adds, as the Terms require;
- the accuracy of the data it enters, and not entering special categories of personal data or protected health information, except as a scanned page shows them;
- giving Glassrecord only test accounts for scan sign-in, holding no real person’s data beyond what the test needs.
5. Confidentiality
Glassrecord ensures that every person it authorizes to process Customer Personal Data is bound by confidentiality. Glassrecord staff reach Customer Data only as the Terms describe: under a time-limited grant recorded in Customer’s audit log, when Customer opens support access, or in the staff review of how scanned pages are classified, which shows pages from every customer’s scans.
6. Security
Glassrecord implements the technical and organizational measures in Annex 2, and keeps them appropriate to the risk. Glassrecord may change them if the change does not reduce the overall protection of Customer Personal Data.
7. Sub-processors
- Authorization. Customer gives Glassrecord general authorization to engage Sub-processors. The current list is at
glassrecord.com/subprocessors, and Customer approves the Sub-processors listed there on the date it accepts this DPA. - Terms. Glassrecord binds each Sub-processor by a written agreement with data protection obligations at least as protective as this DPA’s, and remains responsible to Customer for each Sub-processor’s performance.
- Notice. Glassrecord will add a new Sub-processor to the list at least 30 days before it begins processing Customer Personal Data, and will send notice to anyone who subscribes at [Sub-processor notice address].
- Objection. Customer may object to a new Sub-processor on reasonable data protection grounds by writing to [Privacy contact address] within those 30 days. The parties will discuss the objection in good faith, and Glassrecord may offer to stop using that Sub-processor for Customer Personal Data. If Glassrecord cannot resolve the objection within 30 days of receiving it, Customer may terminate the affected subscription by notice, and Glassrecord will refund prepaid fees for the unused period.
- Emergency replacement. Where Glassrecord must replace a Sub-processor at once for reasons outside its control, it will give notice as soon as it can, and Customer keeps its right to object.
8. Data subject requests
Glassrecord will tell Customer without undue delay if it receives a request from a data subject about Customer Personal Data, and will not answer it except to refer the person to Customer, unless the law requires otherwise. Taking into account the nature of the processing, Glassrecord will help Customer answer such requests. The service lets Customer export its organization’s records and each person’s own data, correct entered data, and delete members, sites, and the organization.
9. Security Incidents
Glassrecord will notify Customer without undue delay, and in any case within [48] hours, after becoming aware of a Security Incident affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Glassrecord will provide further information as it becomes known, take reasonable steps to contain and remedy the incident, and help Customer meet its own notification duties. Notice is sent to Customer’s Owners by email [and to any security contact Customer names in the app]. Notice is not an admission of fault.
10. Assistance
Taking into account the nature of the processing and the information available to it, Glassrecord will give Customer reasonable help with data protection impact assessments and prior consultations with supervisory authorities that concern the service.
11. Aggregate data, observations, and service improvement
- Aggregate data. Glassrecord may create de-identified, aggregated statistics from the service, such as how often a kind of tracker loads before consent across many sites, and use and publish them, as long as they identify no person, no Customer, and no Customer’s site.
- Observations. As section 2 describes, observations of public websites are Glassrecord’s data. Glassrecord uses them to provide the service to every customer who monitors a site and for free scans. Glassrecord never shows one customer another customer’s findings, notes, fixes, or settings.
- Training and evaluation. Glassrecord may select a limited set of records from the service to train and evaluate the rules and models that detect third parties, classify pages, drive consent banners, and attribute requests. Each selected record holds extracted features, never a page’s HTML: for page classification, the page address without its query string, headings, form labels, a text excerpt, and a label; for third-party classification, the domain, ownership data, script hash, and a label; for attribution, a sample of network records and tag manager containers; for consent banners, the banner’s markup and the outcome; and Protection’s counts. Each record first passes the same redaction as all stored data, which removes cookie values, form contents, query strings, and email addresses and similar patterns. Selected records carry their source, date, region, and how they were labeled, are kept under their own retention policy, reviewed at least every quarter, and are never used to identify a person. Glassrecord will not sell selected records or disclose them outside Glassrecord and its Sub-processors. [Confirm that no model provider Glassrecord uses trains on its inputs, and state it here.]
12. International transfers
- Locations. Glassrecord’s primary database and stored files are in the United States. The Sub-processor list names each Sub-processor’s location.
- EEA. To the extent Glassrecord’s processing involves a transfer of Customer Personal Data from the European Economic Area to a country without an adequacy decision, the SCCs are incorporated into this DPA as follows: Module Two where Customer is a controller and Module Three where Customer is a processor; clause 7 applies; in clause 9, option 2 applies with the notice period in section 7 of this DPA; the optional wording in clause 11 does not apply; in clause 13, the supervisory authority is the one competent for Customer, or where Customer has none in the EEA, [the supervisory authority of Ireland]; in clauses 17 and 18, the law and courts are those of [Ireland]. Annex I of the SCCs is completed by Annex 1 of this DPA, Annex II by Annex 2, and Annex III by the Sub-processor list.
- United Kingdom. For transfers from the United Kingdom, the UK Addendum applies. Table 1 is completed with the parties’ details in this DPA, Table 2 by the SCCs as incorporated above, Table 3 by Annexes 1 and 2 and the Sub-processor list, and in Table 4 either party may end the UK Addendum as its section 19 allows.
- Switzerland. For transfers from Switzerland, the SCCs apply as above with these changes: the competent supervisory authority is the Federal Data Protection and Information Commissioner, references to the GDPR include the Swiss Federal Act on Data Protection, and “Member State” includes Switzerland so that data subjects there can bring claims in their place of habitual residence.
- Alternative mechanisms. If Glassrecord adopts another lawful transfer mechanism, such as certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions, it may rely on that mechanism instead. [Remove or complete once the transfer mechanism is decided.]
- Precedence. If the SCCs or the UK Addendum conflict with this DPA, they prevail.
13. United States state privacy laws
As a service provider or contractor, Glassrecord will not:
- sell or share Customer Personal Data;
- retain, use, or disclose it for any purpose other than the business purposes in the Terms and this DPA, or outside the direct business relationship with Customer;
- combine it with personal data Glassrecord receives from others or collects itself, except as the CCPA allows a service provider to do.
Glassrecord will comply with the CCPA’s obligations that apply to it, give Customer’s personal data the same level of privacy protection the CCPA requires, and tell Customer if it can no longer meet them. Customer may take reasonable steps to stop unauthorized use of Customer Personal Data. Glassrecord certifies that it understands these restrictions.
14. Audits
Glassrecord will make available to Customer the information reasonably needed to show that it meets this DPA, including answers to reasonable security questionnaires once a year. If that information is not enough to meet Customer’s obligations, or a supervisory authority requires it, Customer may audit Glassrecord’s compliance with this DPA, no more than once a year, on at least 30 days’ written notice, during business hours, at Customer’s cost, through an independent auditor bound by confidentiality, and without access to other customers’ data. [Glassrecord holds no third-party audit report or certification as of this draft.]
15. Return and deletion
- During the subscription. Customer can export its organization’s records and evidence at any time, and delete sites, members, and the organization.
- After the subscription ends. Customer’s records stay readable, and exportable, for one year after its plan ends, and are then deleted. If an Owner deletes the organization, it becomes inaccessible at once and is purged 30 days later.
- Retention during the subscription. Glassrecord deletes page captures and page markup 90 days after anything last cited them, and screenshots and other evidence after Customer’s retention period, one year by default, unless an open finding, a proof record, or a legal hold still cites them.
- Scan sign-in credentials are deleted when Customer removes the test account, its site, or the organization.
- Exceptions. Deletion does not reach observations of public websites or aggregate data (section 11), records selected under section 11 once de-identified, a file another customer’s finding or proof record also cites, or copies the law requires Glassrecord to keep. Copies in backups are deleted as the backups expire, within [backup retention period], and are protected under this DPA until then.
- Certification. On request, Glassrecord will confirm deletion in writing.
16. Liability and precedence
Each party’s liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws or the SCCs do not allow a limitation. If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer Personal Data. This DPA lasts as long as Glassrecord processes Customer Personal Data.
Annex 1. Details of the processing
Parties. Data exporter: Customer, as identified in its account, a controller or processor. Data importer: [Company legal name], [Address], [Privacy contact address], a processor.
Subject matter and purpose. Providing the Glassrecord service under the Terms: scanning Customer’s websites, recording what third parties load and receive under each consent choice, producing findings, fixes, proof records, reports, and shared links, running the Google Tag Manager and other integrations Customer connects, running Protection on Customer’s websites, and supporting Customer.
Nature. Collection by the crawler and by Protection, storage, organization, analysis, retrieval, disclosure to Customer and to recipients Customer chooses, and deletion.
Duration. The subscription, plus the periods in section 15.
Frequency. Continuous, while Customer uses the service.
Categories of data subjects.
- Customer’s members and invited users.
- Client contacts an agency enters.
- People whose personal data appears on a page of Customer’s website that a scan loads, such as staff named on a contact page.
- People whose data is in a test account Customer provides for scan sign-in, which should be none.
- People who receive reports, fix notices, or shared links Customer sends.
- Visitors to Customer’s websites, whose page views Protection counts. Protection records no identifier, so its counts are not expected to be personal data.
Categories of personal data.
- Names, email addresses, roles, and actions in the audit log of members and client contacts.
- Comments, notes, fix assignments, and dispute answers.
- Screenshots, text excerpts, and markup of scanned pages, which can include personal data the page shows.
- Scan sign-in usernames and passwords, sealed to a key only the crawler holds.
- Protection’s daily counts of page views by consent state and third-party host, with no cookie values, IP addresses, visitor or session identifiers, form contents, page addresses, or URL parameters.
Special categories. None intended. A scanned page may show them, for example on a health provider’s site. Glassrecord classifies pages as health, finance, or account pages, which describes the page, not a person.
Sub-processors. As listed at glassrecord.com/subprocessors.
Annex 2. Technical and organizational measures
- Encryption in transit. Traffic to the app, the crawler, Protection, and between Glassrecord’s services uses TLS.
- Encryption at rest. Stored data is encrypted at rest by Glassrecord’s hosting providers. [Confirm Neon’s and Cloudflare R2’s encryption at rest from their documentation.] Integration access tokens are also encrypted with AES-256-GCM under keys only Glassrecord’s servers hold, with key rotation. Scan sign-in passwords are sealed with RSA-OAEP to a key only the crawler holds.
- Secrets not stored in the clear. Share links, invitation links, and session tokens are stored only as SHA-256 hashes. Sign-in codes and recovery codes are stored as keyed hashes.
- Access control. Roles per organization (Owner, Admin, Member, Viewer) with access by site or client. Two-step verification for members of organizations that require it, and for every staff session. Staff reach customer data only under time-limited grants or customer-opened support access, recorded in the customer’s audit log. Tenancy is enforced in every query of the application’s data layer.
- Separation of environments. Beta and production run on separate database branches, storage buckets, and Workers.
- Data minimization in the crawler. The crawler never stores cookie or storage values, form contents, or query strings beyond a short list of parameters that show what a request sent. Evidence downloads blank cookie headers.
- Data minimization in Protection. Its reports are checked against a fixed schema that refuses unknown fields and any field for cookies, IP addresses, identifiers, form contents, or addresses. Only daily counts are stored.
- Network restrictions. The crawler refuses private, loopback, and link-local addresses. The European crawler server’s firewall allows outbound traffic to public addresses only and inbound SSH and ping only.
- Monitoring. Errors are reported to an error monitoring service with tokens removed. Service logs are kept by the hosting provider.
- Retention. Deletion schedules as in section 15, run by an automatic sweep. [The sweep deletes on production from its first deploy; on beta it runs as a dry run.]
- Personnel. Confidentiality obligations for everyone with access. [Describe security training once in place.]
- Incident response. [Breach notification procedure to be written and rehearsed before launch.]
- Backups. Point-in-time recovery of the database through the database provider, [retention window].