데이터 처리 부속서
Last updated: July 31, 2026. This version supersedes the version last updated September 15, 2023.
본 데이터 처리 추가 계약서(“DPA”)는 귀하와 귀하가 대표하는 단체(“고객”, “귀하” 또는 “귀하의”) 및 Mapsly LLC(“MAPSLY”) 간의 계약입니다. 이 DPA는 MAPSLY 서비스 약관을 보완합니다. 약관은 다음에서 확인할 수 있습니다, https://mapsly.com/terms, as updated from time to time between Customer and MAPSLY, or other agreements between Customer and MAPSLY that govern Customer’s use of the MAPSLY Services (the “Agreement”). “Customer” refers to the entity defined as “User” under the MAPSLY Terms of Service. This DPA applies to the extent MAPSLY processes Customer Data on Customer’s behalf in providing the Services.
정의. 본 DPA에서 사용되는 모든 대문자 용어는 별도의 계약 조건이 없는 한 아래에 명시된 의미를 갖습니다:
“API” 응용 프로그래밍 인터페이스를 의미합니다.
“Applicable Data Protection Law” means all laws and regulations applicable to and binding on the processing of Customer Data by a party, including, as applicable, the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), and applicable United States federal and state privacy laws (including the California Consumer Privacy Act, as amended).
“Binding Corporate Rules” GDPR에서 부여된 의미를 갖습니다.
“Controller” GDPR에서 부여된 의미를 갖습니다.
“Controller-to-Processor Clauses” 2021년 6월 4일 유럽연합 집행위원회 결정(EU) 2021/914호에서 승인한 데이터 이전을 위한 관리자와 처리자 간의 표준 계약 조항을 의미합니다.
“Customer Data” means the Personal Data that is uploaded to or generated within the Services under Customer’s MAPSLY accounts, excluding the End-User account and usage information described in Section 1.5.
“Data Privacy Framework” or “DPF” means, together, the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework, as administered by the U.S. Department of Commerce.
“Documentation” 서비스에 대한 당시 현재 문서를 의미하며, 위치는 https://help.mapsly.com (및 MAPSLY가 지정한 모든 후속 위치).
“EEA” 유럽 경제 지역을 의미합니다.
“End Users” 고객의 Mapsly 계정 사용자로서, 고객이 Mapsly 사용을 위해 지정한 고객의 직원 및 계약자를 포함합니다.
“GDPR” 유럽 의회 및 이사회 2016년 4월 27일자의 2016/679 규정을 의미하며, 개인정보 처리와 관련하여 자연인의 보호 및 그러한 데이터의 자유로운 이동에 관한 사항을 포함하며, 95/46/EC 지침을 폐지하는 (일반 개인정보 보호 규정)입니다.
“MAPSLY Network” MAPSLY의 관리 하에 있으며 서비스 제공에 사용되는 서버, 네트워크 장비 및 호스트 소프트웨어 시스템(예: 가상 방화벽)을 의미합니다.
“MAPSLY Setup console” 메인 메뉴의 “설정”에서 이용 가능한 Mapsly 서비스의 설정 섹션을 의미합니다.
“Personal Data” 적용 가능한 데이터 보호법에 정의된 바와 같이 개인 데이터, 개인 정보, 개인 식별 정보 또는 기타 동등한 용어를 의미합니다.
“Processing” GDPR에서 부여된 의미를 가지며 “처리하다”, “처리”, “처리된”은 이에 따라 해석됩니다.
“Processor” GDPR에서 부여된 의미를 갖습니다.
프로세서 간 조항 means the standard contractual clauses between Processors for Data Transfers, as approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
보안 사고 MAPSLY의 보안 위반으로 고객 데이터의 우발적이거나 불법적인 파괴, 손실, 변경, 무단 공개 또는 접근이 발생하는 경우를 의미합니다.
서비스 제어 서비스가 제공하는 보안 기능과 기능을 포함한 제어를 의미하며, 이는 문서에 설명되어 있습니다.
“Standard Contractual Clauses” means (i) the Controller-to-Processor Clauses, or (ii) the Processor-to-Processor Clauses, as applicable in accordance with Sections 9.2.1 and 9.2.2, as supplemented, where applicable, by the UK Addendum (for Data Transfers subject to the UK GDPR) and by the Swiss adaptations described in Section 9.2.4 (for Data Transfers subject to the FADP).
제3국 means a country outside the EEA, the United Kingdom, or Switzerland not recognized by the European Commission (or, as applicable, by the competent United Kingdom or Swiss authorities) as providing an adequate level of protection for personal data (as described in the GDPR, the UK GDPR, or the FADP, as applicable).
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, in force 21 March 2022.
“UK GDPR” means the GDPR as it forms part of the law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018.
1. Data Processing
1.1 Scope and Roles. 이 DPA는 MAPSLY가 고객 데이터를 처리할 때 적용됩니다. 이 문맥에서 MAPSLY는 고객의 프로세서로서 역할을 하며, 고객은 고객 데이터의 컨트롤러 또는 프로세서로서 행동할 수 있습니다.
1.2 Customer Controls. 고객은 관련 데이터 보호법에 따른 의무, 특히 데이터 주체의 요청에 대응할 의무를 이행하는 데 도움을 주기 위해 서비스 제어 기능을 사용할 수 있습니다. 처리의 성격을 고려할 때, 고객은 MAPSLY가 표준 계약 조항에 따라 전송된 고객 데이터가 부정확하거나 오래된 것임을 알게 될 가능성이 낮다는 데 동의합니다. 그럼에도 불구하고, MAPSLY가 표준 계약 조항에 따라 전송된 고객 데이터가 부정확하거나 오래된 것을 인지하게 되면, 지체 없이 고객에게 통지할 것입니다. MAPSLY는 고객이 고객 데이터를 삭제하거나 수정할 수 있도록 서비스 제어 기능을 제공함으로써, 표준 계약 조항에 따라 전송된 부정확하거나 오래된 고객 데이터를 삭제하거나 수정하는 데 고객과 협력할 것입니다.
1.3 Details of Data Processing.
1.3.1 Subject matter. 본 DPA에 따른 데이터 처리의 주제는 고객 데이터입니다.
1.3.2 Duration. The processing continues for the Term of the Agreement and thereafter for the limited period necessary to return, delete, or lawfully retain Customer Data in accordance with Section 11.
1.3.3 Purpose. 본 DPA에 따른 데이터 처리 목적은 고객이 때때로 시작하는 서비스 제공입니다.
1.3.4 Nature of the processing. Compute, storage, geocoding, routing, synchronization with Customer’s connected systems, and such other Services as described in the Documentation and initiated by Customer from time to time, including, where Customer uses AI-based features of the Services, processing by AI model providers engaged as Sub-processors solely to provide the Services to Customer. MAPSLY does not use Customer Data to train generalized artificial intelligence or machine learning models.
1.3.5 Type of Customer Data. Customer Data uploaded to or generated within the Services under Customer’s MAPSLY accounts, which may include contact and CRM records, addresses and other location data (including precise geolocation of End Users where Customer enables location tracking, check-in, or similar features), photos, notes, form responses, audio recordings and transcripts (where Customer uses voice or AI-based features), and automation and activity data.
1.3.6 Categories of data subjects. The data subjects could include Customer’s customers, prospects and leads, employees, suppliers and End Users.
1.4 Compliance with Laws. 각 당사자는 이 DPA를 이행하는 데 있어 해당 당사자에게 적용되고 구속력이 있는 모든 법률, 규칙 및 규정을 준수하며, 여기에는 적용 가능한 데이터 보호법이 포함됩니다.
1.5 Mapsly as Controller. Customer acknowledges that Mapsly collects certain information about Customer’s End Users — such as account, authentication, billing, support, and usage information — as described in the MAPSLY Privacy Policy (currently published at https://mapsly.com/privacy-policy). To the extent Mapsly determines the purposes and means of processing such information, Mapsly acts as an independent Controller of that information and processes it in accordance with the MAPSLY Privacy Policy and Applicable Data Protection Law; such information is not Customer Data processed under this DPA. Mapsly may disclose such information internally and to its service providers for legitimate business purposes relating to the operation, support, and improvement of the Services, such as billing, account management, technical support, and product development.
2. Customer Instructions
The parties agree that this DPA and the Agreement (including Customer providing instructions via configuration tools such as the MAPSLY Setup console and APIs made available by MAPSLY for the Services) constitute Customer’s documented instructions regarding MAPSLY’s processing of Customer Data (“Documented Instructions”). MAPSLY will process Customer Data only in accordance with Documented Instructions (which if Customer is acting as a Processor, could be based on the instructions of its Controllers). Additional instructions outside the scope of the Documented Instructions (if any) require prior written agreement between MAPSLY and Customer, including agreement on any additional fees payable by Customer to MAPSLY for carrying out such instructions. Where an additional instruction is required for Customer’s compliance with Applicable Data Protection Law and the parties are unable, within thirty (30) days, to reasonably agree on its implementation and any applicable fees, Customer may terminate the affected Services by written notice, and MAPSLY will refund Customer the prepaid fees prorated for the unused portion of the then-current Billing Period for the terminated Services. Taking into account the nature of the processing, Customer agrees that it is unlikely MAPSLY can form an opinion on whether Documented Instructions infringe Applicable Data Protection Law. If MAPSLY forms such an opinion, it will immediately inform Customer, in which case, Customer is entitled to withdraw or modify its Documented Instructions.
3. Confidentiality of Customer Data
MAPSLY는 고객 데이터에 접근하거나 사용하거나 제3자에게 공개하지 않습니다. 단, 각 경우에 서비스 유지 또는 제공을 위해 필요한 경우, 또는 법률 또는 정부 기관(소환장 또는 법원 명령 등)의 유효하고 구속력 있는 명령에 따라야 하는 경우에는 예외입니다. 정부 기관이 MAPSLY에 고객 데이터 요청을 보낼 경우, MAPSLY는 해당 기관이 고객으로부터 직접 데이터를 요청하도록 안내하려고 시도할 것입니다. 이 과정의 일환으로, MAPSLY는 정부 기관에 고객의 기본 연락처 정보를 제공할 수 있습니다. 고객 데이터를 정부 기관에 공개해야 하는 경우, MAPSLY는 고객이 보호 명령 또는 적절한 구제를 요청할 수 있도록 합리적인 통지를 고객에게 제공할 것이며, MAPSLY가 법적으로 이를 금지당한 경우는 제외됩니다.
4. Confidentiality Obligations of MAPSLY Personnel
MAPSLY는 MAPSLY의 승인 없이 고객 데이터를 처리하는 것을 직원에게 제한합니다. MAPSLY는 기밀 유지, 데이터 보호 및 데이터 보안과 관련된 적절한 계약상의 의무를 직원에게 부과합니다.
5. Security of Data Processing
5.1 MAPSLY has implemented and will maintain the appropriate technical and organizational measures to ensure the security and confidentiality of the Customer Data, as described in Annex A (Technical and Organizational Measures) to this DPA and in accordance with Mapsly’s security standards described in this DPA and within the MAPSLY Privacy Policy. MAPSLY may update the measures described in Annex A from time to time, provided that no update materially reduces the overall security of the Services.
5.2 Customer Responsibilities and Optional Security Features. MAPSLY는 고객이 고객 데이터를 더욱 안전하게 보호하기 위해 선택할 수 있는 다양한 서비스 제어를 제공합니다. 고객은 (a) 계정 인증 자격 증명의 보안을 포함하여 서비스를 안전하게 사용하는 것, (b) 서비스와 주고받는 고객 데이터의 보안을 보호하는 것, (c) 서비스에 업로드된 고객 데이터를 안전하게 암호화하거나 백업하기 위한 적절한 조치를 취하는 것, (d) 서비스 및 서비스 제어를 적절하게 구성하는 것, 그리고 (e) 고객 데이터의 보안, 보호 및 삭제를 보장하기 위해 고객이 적절하다고 생각하는 기타 조치를 취할 책임이 있습니다.
5.3 Security Incident Notification.
5.3.1 Security Incident. MAPSLY는 (a) 보안 사고를 인지한 후 지체 없이 고객에게 보안 사고를 통지하고, (b) 보안 사고를 해결하기 위한 적절한 조치를 취하며, 보안 사고로 인한 부정적인 영향을 완화하는 조치를 포함합니다.
5.3.2 MAPSLY Assistance. 고객이 감독 당국 또는 데이터 주체(해당되는 경우)에게 보안 사고를 통지할 수 있도록 하기 위해, MAPSLY는 처리의 성격, MAPSLY가 이용할 수 있는 정보 및 기밀성 등 정보 공개에 대한 제한 사항을 고려하여 MAPSLY가 고객에게 공개할 수 있는 보안 사고에 대한 정보를 통지에 포함시켜 고객과 협력하고 지원합니다. 처리의 성격을 고려하여 고객은 보안 사고의 예상 결과를 결정하는 데 가장 적합하다는 데 동의합니다.
5.3.3 Unsuccessful Security Incidents. 고객은 다음에 동의합니다:
(i) an unsuccessful Security Incident will not be subject to this Section 5.3. An unsuccessful Security Incident is one that results in no unauthorized access to Customer Data or to any of MAPSLY’s equipment or facilities storing Customer Data, and could include, without limitation, pings and other broadcast attacks on firewalls or edge servers, port scans, unsuccessful log-on attempts, denial of service attacks, packet sniffing (or other unauthorized access to traffic data that does not result in access beyond headers) or similar incidents; and
(ii) MAPSLY’s obligation to report or respond to a Security Incident under this Section 5.3 is not and will not be construed as an acknowledgment by MAPSLY of any fault or liability of MAPSLY with respect to the Security Incident.
5.3.4 Communication. 보안 사고에 대한 알림이 있을 경우, MAPSLY가 선택한 모든 수단(이메일 포함)을 통해 고객의 관리자 한 명 이상에게 전달됩니다. 고객 관리자가 항상 MAPSLY 설정 콘솔에서 정확한 연락처 정보를 유지하고 안전한 전송을 보장하는 것은 고객의 전적인 책임입니다.
5.3.5 Notification Obligations. MAPSLY가 고객에게 보안 사고를 통지하거나 고객이 우발적이거나 불법적인 파기, 손실, 변경, 무단 공개 또는 고객 데이터에 대한 접근을 인지하게 되는 경우, 고객은 (a) 해당 데이터 보호법에 따른 알림 또는 기타 의무가 있는지 여부를 결정하고 (b) 해당 의무를 준수하기 위한 필요한 조치를 취할 책임이 있습니다. 이는 본 섹션 5.3에 따른 MAPSLY의 의무를 제한하지 않습니다.
6. Sub-processing
6.1 Authorized Sub-processors. Customer provides general authorization to MAPSLY’s use of sub-processors to provide processing activities on Customer Data on behalf of Customer (“Sub-processors”) in accordance with this Section. The MAPSLY website (currently posted at https://mapsly.com/sub-processors/) lists Sub-processors that are currently engaged by MAPSLY. At least 30 days before MAPSLY engages a Sub-processor, MAPSLY will update the applicable website and provide Customer with a mechanism to obtain notice of that update. To object to a Sub-processor, Customer can: (i) cease using the functionality of the MAPSLY Service for which MAPSLY has engaged the Sub-processor, or (ii) terminate the Agreement pursuant to its terms. If Customer objects to a new Sub-processor on reasonable grounds relating to data protection and the parties are unable to resolve the objection within thirty (30) days, Customer may terminate the Agreement with respect to the affected Services by written notice, and MAPSLY will refund Customer the prepaid fees prorated for the unused portion of the then-current Billing Period following the effective date of termination. If the affected functionality cannot reasonably be separated from the remainder of the Services, Customer may terminate the Agreement in its entirety on the same terms.
6.2 Sub-processor Obligations. MAPSLY가 6.1절에 설명된 대로 하위 처리자를 승인하는 경우:
(i) MAPSLY will restrict the Sub-processor’s access to Customer Data only to what is necessary to provide or maintain the Services in accordance with the Documentation, and MAPSLY will prohibit the Sub-processor from accessing Customer Data for any other purpose;
(ii) MAPSLY will enter into a written agreement with the Sub-processor and, to the extent that the Sub-processor performs the same data processing services provided by MAPSLY under this DPA, MAPSLY will impose on the Sub-processor the same contractual obligations that MAPSLY has under this DPA; and
(iii) MAPSLY will remain responsible for its compliance with the obligations of this DPA and for any acts or omissions of the Sub-processor that cause MAPSLY to breach any of MAPSLY’s obligations under this DPA.
7. MAPSLY Assistance with Data Subject Requests
처리의 성격을 고려할 때, 서비스 제어는 MAPSLY가 고객이 적용 가능한 데이터 보호법에 따른 데이터 주체의 요청에 응답하는 의무를 이행할 수 있도록 지원하는 기술적 및 조직적 조치입니다. 데이터 주체가 MAPSLY에 요청을 하면 MAPSLY는 해당 요청이 고객이 책임지는 데이터 주체로부터 온 것임을 확인한 후 즉시 해당 요청을 고객에게 전달합니다. 고객은 자신과 처리자로서 행동할 때 자신의 관리자를 대신하여 MAPSLY가 MAPSLY에 요청을 하는 모든 데이터 주체에게 고객에게 요청을 전달했음을 확인하는 답변을 하도록 승인합니다. 당사자들은 고객의 서비스 제어 사용 및 MAPSLY가 본 조항에 따라 데이터 주체의 요청을 고객에게 전달하는 것이 고객이 제공해야 할 지원의 범위와 정도를 나타내는 데 동의합니다.
8. Compliance Verification
8.1 MAPSLY Audits. MAPSLY uses external auditors to verify the adequacy of its security measures. This audit: (a) will be performed at least annually; (b) will be performed according to a widely recognized standard (such as SOC 2 Type II); (c) will be performed by independent third-party security professionals at MAPSLY’s selection and expense; and (d) will result in the generation of an audit report (“Report”), which will be MAPSLY’s Confidential Information.
8.2 Audit Reports. 고객의 서면 요청 및 당사자들이 적용 가능한 NDA를 체결한 경우에 한해, MAPSLY는 고객이 본 DPA에 따른 MAPSLY의 의무 준수를 합리적으로 확인할 수 있도록 보고서 사본을 제공할 것입니다.
8.3 Privacy Impact Assessment and Prior Consultation. 처리의 성격과 MAPSLY가 이용할 수 있는 정보를 고려하여, MAPSLY는 고객이 데이터 보호 영향 평가 및 사전 협의에 관한 의무를 준수할 수 있도록 본 8절에 따라 MAPSLY가 제공하는 정보를 제공함으로써 지원합니다.
9. Transfers of Personal Data
9.1 Locations. MAPSLY stores and processes Customer Data within the MAPSLY Network in the USA. MAPSLY personnel and Sub-processors may remotely access Customer Data from other countries in which they operate solely as necessary to provide, maintain, and support the Services; any such access constitutes a Data Transfer governed by this Section 9. MAPSLY will not otherwise transfer Customer Data outside of the EEA, the United Kingdom, Switzerland, and the USA except as necessary to provide the Services initiated by Customer, or as necessary to comply with the law or valid and binding order of a governmental body.
9.2 Application of Standard Contractual Clauses. Subject to Section 9.3, the Standard Contractual Clauses will only apply to Customer Data subject to the GDPR, the UK GDPR, or the FADP that is transferred, either directly or via onward transfer, to any Third Country (each a “Data Transfer”).
9.2.1 고객이 관리자 역할을 하는 경우, 관리자-처리자 조항이 데이터 전송에 적용됩니다.
9.2.2 고객이 처리자로서 행동할 경우, 처리자 간 조항이 데이터 전송에 적용됩니다. 처리의 성격을 고려할 때, MAPSLY는 고객의 관리자의 신원을 알 가능성이 낮다는 점에 고객이 동의하며, 이는 MAPSLY가 고객의 관리자와 직접적인 관계가 없기 때문이며, 따라서 고객은 처리자 간 조항에 따라 고객의 관리자에 대한 MAPSLY의 의무를 이행할 것입니다.
9.2.3 For Data Transfers subject to the UK GDPR, the Standard Contractual Clauses apply as supplemented by the UK Addendum, completed as set forth in Section 9.4.
9.2.4 For Data Transfers subject to the FADP, the Standard Contractual Clauses apply with the following adaptations: (i) references to the GDPR are to be read as references to the FADP; (ii) the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; (iii) the term “Member State” is interpreted to include Switzerland, so that data subjects in Switzerland may enforce their rights in their place of habitual residence; and (iv) references to EU law are to be read as references to Swiss law where the transfer is exclusively subject to the FADP.
9.3 Alternative Transfer Mechanism. To the extent MAPSLY has adopted a valid alternative transfer mechanism recognized under Applicable Data Protection Law — including MAPSLY’s certification under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework — such mechanism will apply to a Data Transfer in place of the Standard Contractual Clauses for so long as it remains valid. If such alternative mechanism is invalidated, suspended, withdrawn, or otherwise ceases to provide a lawful basis for a Data Transfer, the Standard Contractual Clauses (as completed in Section 9.4) will automatically apply to that Data Transfer without further action by either party. MAPSLY will maintain its Data Privacy Framework certification for so long as it relies on the Data Privacy Framework for Data Transfers.
9.4 Completion of the Standard Contractual Clauses. For each Data Transfer to which the Standard Contractual Clauses apply, the Standard Contractual Clauses are deemed completed as follows: (i) Module Two (transfer controller to processor) applies where Customer acts as a Controller, and Module Three (transfer processor to processor) applies where Customer acts as a Processor; (ii) in Clause 7, the optional docking clause does not apply; (iii) in Clause 9, Option 2 (general written authorisation) applies, and the time period for prior notice of Sub-processor changes is thirty (30) days, in accordance with Section 6.1; (iv) in Clause 11, the optional language does not apply; (v) in Clauses 17 and 18, the governing law and the competent courts are those of Ireland; and (vi) Annex I of the Standard Contractual Clauses is deemed completed with the information set out in Annex B to this DPA, Annex II is deemed completed with Annex A to this DPA, and Annex III is deemed completed with the Sub-processor list referenced in Section 6.1. Where the UK Addendum applies: Table 1 is deemed completed with the parties’ details under the Agreement; Table 2 with the Standard Contractual Clauses as completed above; Table 3 with the Annex information above; and, for Table 4, neither party may end the UK Addendum as set out in Section 19 of the UK Addendum.
10. Termination of the DPA
This DPA will continue in force until the termination of the Agreement (the “Termination Date”).
11. Deletion of Customer Data
Upon termination or expiration of the Agreement, MAPSLY shall delete Customer Data from its active systems at Customer’s request, and in any event not later than within a 90-day period after termination, except and to the extent MAPSLY is required by applicable law to retain some or all of the Customer Data, in which case MAPSLY shall securely isolate this Data, protect it from any further processing, and delete it in accordance with applicable retention periods. Customer Data held in backup systems will be deleted or overwritten in the ordinary course of MAPSLY’s backup rotation cycles following deletion from active systems and will be protected from any further processing until deleted.
12. Duties to Inform
고객 데이터가 MAPSLY에서 처리되는 동안 제3자가 파산 또는 지급불능 절차나 유사한 조치로 압류 대상이 되는 경우, MAPSLY는 지체 없이 고객에게 알립니다. MAPSLY는 지체 없이 이러한 조치에 관련된 모든 당사자(예: 채권자, 파산 관리자)에게 해당 절차의 대상이 되는 모든 고객 데이터가 고객의 소유이며 책임 영역에 속하며 고객의 단독 처분 권한임을 통지합니다.
13. Entire Agreement; Conflict; Amendment
This DPA incorporates the Standard Contractual Clauses by reference. Except as amended by this DPA, the Agreement will remain in full force and effect. If there is a conflict among the Standard Contractual Clauses, this DPA, and the Agreement concerning the processing of Customer Data, the Standard Contractual Clauses will control first, this DPA will control second, and the Agreement will control third. For all other matters, the Agreement controls. Nothing in this document varies or modifies the Standard Contractual Clauses. This DPA may be amended in accordance with Section 14.1 of the Agreement, provided that MAPSLY will provide Customer with advance notice of any amendment that materially reduces the protections afforded to Customer Data under this DPA.
14. Google Workspace API Data
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Annex A — Technical and Organizational Measures
MAPSLY maintains the following technical and organizational measures to protect Customer Data. MAPSLY may update these measures from time to time, provided that no update materially reduces the overall security of the Services.
- Hosting and resilience: the Services are hosted on Amazon Web Services in the United States across multiple availability zones; backups are taken daily and stored in a separate availability zone; backup restoration is tested at least annually.
- Encryption: Customer Data is encrypted at rest and in transit using industry-standard encryption protocols.
- Access control: access to production systems is role-based, restricted to authorized personnel on a least-privilege basis, revoked promptly upon role change or termination, and reviewed periodically.
- Authentication: single sign-on and multi-factor authentication are supported.
- Secure development: documented secure development practices, including code review and segregation of development, testing, and production environments.
- Vulnerability management: periodic vulnerability scanning and at least annual penetration testing by independent third parties, with remediation according to documented severity-based timelines.
- Logging and monitoring: security-relevant events are logged, retained, and monitored.
- Personnel: personnel are bound by confidentiality obligations and receive security awareness training.
- Incident response: a documented incident response plan is maintained; Security Incidents are handled in accordance with Section 5.3.
- Business continuity: documented business continuity and disaster recovery plans are maintained.
- Governance: a documented information security policy suite is maintained and reviewed periodically; personnel accept applicable policies.
- Independent assurance: security controls are audited at least annually by independent third parties against a widely recognized standard (currently SOC 2 Type II).
Annex B — Standard Contractual Clauses Information
For the purposes of Annex I of the Standard Contractual Clauses, the following information applies to each Data Transfer:
- Data exporter: Customer (name, address, and contact details as provided in Customer’s MAPSLY account and the Agreement), acting as a Controller or as a Processor on behalf of its Controllers, as described in Section 9.2. Contact: Customer’s administrator contact on record.
- Data importer: Mapsly LLC, 440 N Barranca Ave #4985, Covina, CA 91723, USA; [email protected]; acting as a Processor.
- Signature and date: each party is deemed to have signed the Standard Contractual Clauses, including their Annexes, upon acceptance or execution of the Agreement, with effect from the effective date of the Agreement.
- Categories of data subjects: as described in Section 1.3.6.
- Categories of personal data: as described in Section 1.3.5.
- Sensitive data: the Services are not specifically designed to require special categories of personal data. To the extent Customer chooses to submit such data, Customer is responsible for its compliance with Applicable Data Protection Law in doing so, and the data is processed only in accordance with Customer’s Documented Instructions and protected by the measures described in Annex A.
- Frequency of the transfer: continuous, for the duration described in Section 1.3.2.
- Nature and purpose of the processing: as described in Sections 1.3.3 and 1.3.4. Transfers to Sub-processors: as described in Section 6, for the same duration.
- Retention period: as described in Section 11.
- Competent supervisory authority (Clause 13): where the data exporter is established in an EEA Member State, the supervisory authority of that Member State; where the data exporter is not established in the EEA but falls within the territorial scope of the GDPR and has appointed an EU representative, the supervisory authority of the Member State in which the representative is established; where the data exporter falls within the territorial scope of the GDPR under Article 3(2) but has not appointed an EU representative, the supervisory authority of one of the Member States in which the data subjects whose personal data is transferred are located. For Data Transfers subject to the UK GDPR, the UK Information Commissioner’s Office; for Data Transfers subject to the FADP, the Swiss Federal Data Protection and Information Commissioner.