Phụ lục xử lý dữ liệu

Last updated: July 31, 2026. This version supersedes the version last updated September 15, 2023.

Phụ lục Xử lý Dữ liệu này (“DPA”) là một thỏa thuận giữa bạn và tổ chức bạn đại diện (“Khách hàng”, “bạn” hoặc “của bạn”) và Mapsly LLC (“MAPSLY”). DPA này bổ sung cho Điều khoản Dịch vụ của MAPSLY có tại https://mapsly.com/terms, as updated from time to time between Customer and MAPSLY, or other agreements between Customer and MAPSLY that govern Customer’s use of the MAPSLY Services (the “Agreement”). “Customer” refers to the entity defined as “User” under the MAPSLY Terms of Service. This DPA applies to the extent MAPSLY processes Customer Data on Customer’s behalf in providing the Services.

Định nghĩa. Tất cả các thuật ngữ viết hoa được sử dụng trong DPA này sẽ có ý nghĩa được quy định dưới đây, trừ khi được định nghĩa khác trong Thỏa thuận:

“API” có nghĩa là giao diện lập trình ứng dụng.

“Applicable Data Protection Law” means all laws and regulations applicable to and binding on the processing of Customer Data by a party, including, as applicable, the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), and applicable United States federal and state privacy laws (including the California Consumer Privacy Act, as amended).

“Binding Corporate Rules” có nghĩa được quy định trong GDPR.

“Controller” có nghĩa được quy định trong GDPR.

“Controller-to-Processor Clauses” chỉ các điều khoản hợp đồng tiêu chuẩn giữa các Bên Kiểm soát và Bộ xử lý cho việc Chuyển dữ liệu, đã được Quyết định Thực hiện của Ủy ban Châu Âu (EU) 2021/914 ngày 4 tháng 6 năm 2021 phê duyệt.

“Customer Data” means the Personal Data that is uploaded to or generated within the Services under Customer’s MAPSLY accounts, excluding the End-User account and usage information described in Section 1.5.

“Data Privacy Framework” or “DPF” means, together, the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework, as administered by the U.S. Department of Commerce.

“Documentation” có nghĩa là tài liệu hiện hành vào thời điểm đó dành cho Dịch vụ nằm tại https://help.mapsly.com (và bất kỳ vị trí kế nhiệm nào do MAPSLY chỉ định).

“EEA” có nghĩa là Khu vực Kinh tế Châu Âu.

“End Users” có nghĩa là người dùng của tài khoản Mapsly của Khách hàng bao gồm nhân viên và nhà thầu của Khách hàng được Khách hàng chỉ định sử dụng Mapsly.

“GDPR” chỉ thị Quy định 2016/679 của Nghị viện và Hội đồng Châu Âu ngày 27 tháng 4 năm 2016 về bảo vệ các cá nhân liên quan đến việc xử lý dữ liệu cá nhân và về tự do lưu chuyển dữ liệu đó, đồng thời bãi bỏ Chỉ thị 95/46/EC (Quy định chung về bảo vệ dữ liệu).

“MAPSLY Network” có nghĩa là các máy chủ, thiết bị mạng và hệ thống phần mềm máy chủ (ví dụ: tường lửa ảo) nằm trong quyền kiểm soát của MAPSLY và được sử dụng để cung cấp Dịch vụ.

“MAPSLY Setup console” có nghĩa là phần Cài đặt trong dịch vụ Mapsly có sẵn dưới mục “Cài đặt” trong menu chính.

“Personal Data” nghĩa là dữ liệu cá nhân, thông tin cá nhân, thông tin định danh cá nhân hoặc thuật ngữ tương đương khác (từng thuật ngữ được định nghĩa trong Luật Bảo vệ Dữ liệu Áp dụng).

“Processing” có nghĩa được quy định trong GDPR và các từ “xử lý”, “quá trình xử lý” và “đã xử lý” sẽ được hiểu tương ứng.

“Processor” có nghĩa được quy định trong GDPR.

Các điều khoản từ bộ xử lý đến bộ xử lý means the standard contractual clauses between Processors for Data Transfers, as approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

Sự cố bảo mật có nghĩa là vi phạm an ninh của MAPSLY dẫn đến việc phá hủy, mất mát, thay đổi, tiết lộ trái phép hoặc truy cập trái pháp luật đối với Dữ liệu Khách hàng.

Điều khiển Dịch vụ có nghĩa là các kiểm soát, bao gồm các tính năng và chức năng bảo mật, mà Dịch vụ cung cấp, như được mô tả trong Tài liệu.

“Standard Contractual Clauses” means (i) the Controller-to-Processor Clauses, or (ii) the Processor-to-Processor Clauses, as applicable in accordance with Sections 9.2.1 and 9.2.2, as supplemented, where applicable, by the UK Addendum (for Data Transfers subject to the UK GDPR) and by the Swiss adaptations described in Section 9.2.4 (for Data Transfers subject to the FADP).

Quốc gia thứ ba means a country outside the EEA, the United Kingdom, or Switzerland not recognized by the European Commission (or, as applicable, by the competent United Kingdom or Swiss authorities) as providing an adequate level of protection for personal data (as described in the GDPR, the UK GDPR, or the FADP, as applicable).

“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, in force 21 March 2022.

“UK GDPR” means the GDPR as it forms part of the law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018.

1. Data Processing

1.1 Scope and Roles. DPA này áp dụng khi MAPSLY xử lý Dữ liệu Khách hàng. Trong bối cảnh này, MAPSLY sẽ đóng vai trò là Bộ xử lý đối với Khách hàng, người có thể đóng vai trò là Người kiểm soát hoặc Bộ xử lý Dữ liệu Khách hàng.

1.2 Customer Controls. Khách hàng có thể sử dụng các Kiểm soát Dịch vụ để hỗ trợ khách hàng thực hiện các nghĩa vụ theo Luật Bảo vệ Dữ liệu Áp dụng, bao gồm nghĩa vụ phản hồi các yêu cầu từ các chủ thể dữ liệu. Xét đến tính chất của việc xử lý, Khách hàng đồng ý rằng rất ít khả năng MAPSLY sẽ nhận biết được Dữ liệu Khách hàng được chuyển giao theo các Điều khoản Hợp đồng Chuẩn không chính xác hoặc đã lỗi thời. Tuy nhiên, nếu MAPSLY nhận biết được rằng Dữ liệu Khách hàng được chuyển giao theo các Điều khoản Hợp đồng Chuẩn không chính xác hoặc đã lỗi thời, MAPSLY sẽ thông báo cho Khách hàng mà không chậm trễ không cần thiết. MAPSLY sẽ hợp tác với Khách hàng để xóa hoặc chỉnh sửa Dữ liệu Khách hàng không chính xác hoặc lỗi thời được chuyển giao theo các Điều khoản Hợp đồng Chuẩn bằng cách cung cấp các Kiểm soát Dịch vụ mà Khách hàng có thể sử dụng để xóa hoặc chỉnh sửa Dữ liệu Khách hàng.

1.3 Details of Data Processing.

1.3.1 Subject matter. Nội dung xử lý dữ liệu theo DPA này là Dữ liệu Khách hàng.

1.3.2 Duration. The processing continues for the Term of the Agreement and thereafter for the limited period necessary to return, delete, or lawfully retain Customer Data in accordance with Section 11.

1.3.3 Purpose. Mục đích xử lý dữ liệu theo DPA này là cung cấp Dịch vụ do Khách hàng khởi xướng theo từng thời điểm.

1.3.4 Nature of the processing. Compute, storage, geocoding, routing, synchronization with Customer’s connected systems, and such other Services as described in the Documentation and initiated by Customer from time to time, including, where Customer uses AI-based features of the Services, processing by AI model providers engaged as Sub-processors solely to provide the Services to Customer. MAPSLY does not use Customer Data to train generalized artificial intelligence or machine learning models.

1.3.5 Type of Customer Data. Customer Data uploaded to or generated within the Services under Customer’s MAPSLY accounts, which may include contact and CRM records, addresses and other location data (including precise geolocation of End Users where Customer enables location tracking, check-in, or similar features), photos, notes, form responses, audio recordings and transcripts (where Customer uses voice or AI-based features), and automation and activity data.

1.3.6 Categories of data subjects. The data subjects could include Customer’s customers, prospects and leads, employees, suppliers and End Users.

1.4 Compliance with Laws. Mỗi bên sẽ tuân thủ tất cả các luật, quy định và quy tắc áp dụng và ràng buộc đối với mình trong việc thực hiện DPA này, bao gồm cả Luật Bảo vệ Dữ liệu Áp dụng.

1.5 Mapsly as Controller. Customer acknowledges that Mapsly collects certain information about Customer’s End Users — such as account, authentication, billing, support, and usage information — as described in the MAPSLY Privacy Policy (currently published at https://mapsly.com/privacy-policy). To the extent Mapsly determines the purposes and means of processing such information, Mapsly acts as an independent Controller of that information and processes it in accordance with the MAPSLY Privacy Policy and Applicable Data Protection Law; such information is not Customer Data processed under this DPA. Mapsly may disclose such information internally and to its service providers for legitimate business purposes relating to the operation, support, and improvement of the Services, such as billing, account management, technical support, and product development.

2. Customer Instructions

The parties agree that this DPA and the Agreement (including Customer providing instructions via configuration tools such as the MAPSLY Setup console and APIs made available by MAPSLY for the Services) constitute Customer’s documented instructions regarding MAPSLY’s processing of Customer Data (“Documented Instructions”). MAPSLY will process Customer Data only in accordance with Documented Instructions (which if Customer is acting as a Processor, could be based on the instructions of its Controllers). Additional instructions outside the scope of the Documented Instructions (if any) require prior written agreement between MAPSLY and Customer, including agreement on any additional fees payable by Customer to MAPSLY for carrying out such instructions. Where an additional instruction is required for Customer’s compliance with Applicable Data Protection Law and the parties are unable, within thirty (30) days, to reasonably agree on its implementation and any applicable fees, Customer may terminate the affected Services by written notice, and MAPSLY will refund Customer the prepaid fees prorated for the unused portion of the then-current Billing Period for the terminated Services. Taking into account the nature of the processing, Customer agrees that it is unlikely MAPSLY can form an opinion on whether Documented Instructions infringe Applicable Data Protection Law. If MAPSLY forms such an opinion, it will immediately inform Customer, in which case, Customer is entitled to withdraw or modify its Documented Instructions.

3. Confidentiality of Customer Data

MAPSLY sẽ không truy cập hoặc sử dụng, hoặc tiết lộ cho bên thứ ba bất kỳ Dữ liệu Khách hàng nào, ngoại trừ trong mỗi trường hợp cần thiết để duy trì hoặc cung cấp Dịch vụ, hoặc khi cần thiết để tuân thủ pháp luật hoặc lệnh hợp lệ và ràng buộc của cơ quan chính phủ (chẳng hạn như trát hầu tòa hoặc lệnh của tòa án). Nếu cơ quan chính phủ gửi yêu cầu Dữ liệu Khách hàng đến MAPSLY, MAPSLY sẽ cố gắng hướng cơ quan đó yêu cầu dữ liệu trực tiếp từ Khách hàng. Là một phần của nỗ lực này, MAPSLY có thể cung cấp thông tin liên hệ cơ bản của Khách hàng cho cơ quan chính phủ. Nếu bị buộc phải tiết lộ Dữ liệu Khách hàng cho cơ quan chính phủ, MAPSLY sẽ thông báo hợp lý cho Khách hàng về yêu cầu để Khách hàng có thể tìm kiếm lệnh bảo vệ hoặc phương pháp khắc phục thích hợp khác, trừ khi MAPSLY bị pháp luật cấm làm như vậy.

4. Confidentiality Obligations of MAPSLY Personnel

MAPSLY hạn chế nhân sự của mình xử lý Dữ liệu Khách hàng mà không có sự ủy quyền của MAPSLY. MAPSLY áp đặt các nghĩa vụ hợp đồng phù hợp đối với nhân sự, bao gồm các nghĩa vụ liên quan đến bảo mật, bảo vệ dữ liệu và an ninh dữ liệu.

5. Security of Data Processing

5.1 MAPSLY has implemented and will maintain the appropriate technical and organizational measures to ensure the security and confidentiality of the Customer Data, as described in Annex A (Technical and Organizational Measures) to this DPA and in accordance with Mapsly’s security standards described in this DPA and within the MAPSLY Privacy Policy. MAPSLY may update the measures described in Annex A from time to time, provided that no update materially reduces the overall security of the Services.

5.2 Customer Responsibilities and Optional Security Features. MAPSLY cung cấp nhiều Kiểm soát Dịch vụ mà Khách hàng có thể lựa chọn sử dụng để tăng cường bảo mật Dữ liệu Khách hàng. Khách hàng chịu trách nhiệm về (a) việc sử dụng dịch vụ một cách an toàn, bao gồm bảo vệ thông tin xác thực tài khoản của mình, (b) bảo vệ tính bảo mật của Dữ liệu Khách hàng khi truyền đi và nhận từ Dịch vụ, (c) thực hiện các bước phù hợp để mã hóa hoặc sao lưu Dữ liệu Khách hàng được tải lên Dịch vụ một cách an toàn, (d) cấu hình chính xác Dịch vụ và các Kiểm soát Dịch vụ, và (e) thực hiện các bước khác mà Khách hàng cho là đủ để đảm bảo an ninh, bảo vệ và xóa Dữ liệu Khách hàng.

5.3 Security Incident Notification.

5.3.1 Security Incident. MAPSLY sẽ (a) thông báo cho Khách hàng về sự cố An ninh mà không chậm trễ sau khi biết về sự cố đó, và (b) thực hiện các biện pháp thích hợp để giải quyết sự cố An ninh, bao gồm các biện pháp giảm thiểu bất kỳ tác động tiêu cực nào phát sinh từ sự cố An ninh.

5.3.2 MAPSLY Assistance. Để cho phép Khách hàng thông báo một Sự cố Bảo mật cho các cơ quan giám sát hoặc các đối tượng dữ liệu (nếu áp dụng), MAPSLY sẽ hợp tác và hỗ trợ Khách hàng bằng cách bao gồm trong thông báo các thông tin về Sự cố Bảo mật mà MAPSLY có thể tiết lộ cho Khách hàng, cân nhắc tính chất của việc xử lý, thông tin mà MAPSLY có được, và các hạn chế trong việc tiết lộ thông tin, chẳng hạn như tính bảo mật. Cân nhắc tính chất của việc xử lý, Khách hàng đồng ý rằng họ là người có khả năng xác định hậu quả có thể xảy ra của một Sự cố Bảo mật.

5.3.3 Unsuccessful Security Incidents. Khách hàng đồng ý rằng:

(i) an unsuccessful Security Incident will not be subject to this Section 5.3. An unsuccessful Security Incident is one that results in no unauthorized access to Customer Data or to any of MAPSLY’s equipment or facilities storing Customer Data, and could include, without limitation, pings and other broadcast attacks on firewalls or edge servers, port scans, unsuccessful log-on attempts, denial of service attacks, packet sniffing (or other unauthorized access to traffic data that does not result in access beyond headers) or similar incidents; and

(ii) MAPSLY’s obligation to report or respond to a Security Incident under this Section 5.3 is not and will not be construed as an acknowledgment by MAPSLY of any fault or liability of MAPSLY with respect to the Security Incident.

5.3.4 Communication. Thông báo về Sự cố An ninh, nếu có, sẽ được gửi đến một hoặc nhiều quản trị viên của Khách hàng bằng bất kỳ phương thức nào do MAPSLY chọn, bao gồm qua email. Đây là trách nhiệm duy nhất của Khách hàng để đảm bảo các quản trị viên của họ duy trì thông tin liên hệ chính xác trên bảng điều khiển Cài đặt MAPSLY và đảm bảo truyền tải an toàn mọi lúc.

5.3.5 Notification Obligations. Nếu MAPSLY thông báo cho Khách hàng về một Sự cố Bảo mật, hoặc Khách hàng biết được bất kỳ việc phá hoại, mất mát, thay đổi, tiết lộ trái phép hoặc truy cập trái phép nào đối với Dữ liệu Khách hàng, Khách hàng sẽ chịu trách nhiệm (a) xác định xem có bất kỳ nghĩa vụ thông báo hoặc nghĩa vụ nào khác theo Luật Bảo vệ Dữ liệu Áp dụng không và (b) thực hiện các hành động cần thiết để tuân thủ các nghĩa vụ đó. Điều này không giới hạn các nghĩa vụ của MAPSLY theo Mục 5.3 này.

6. Sub-processing

6.1 Authorized Sub-processors. Customer provides general authorization to MAPSLY’s use of sub-processors to provide processing activities on Customer Data on behalf of Customer (“Sub-processors”) in accordance with this Section. The MAPSLY website (currently posted at https://mapsly.com/sub-processors/) lists Sub-processors that are currently engaged by MAPSLY. At least 30 days before MAPSLY engages a Sub-processor, MAPSLY will update the applicable website and provide Customer with a mechanism to obtain notice of that update. To object to a Sub-processor, Customer can: (i) cease using the functionality of the MAPSLY Service for which MAPSLY has engaged the Sub-processor, or (ii) terminate the Agreement pursuant to its terms. If Customer objects to a new Sub-processor on reasonable grounds relating to data protection and the parties are unable to resolve the objection within thirty (30) days, Customer may terminate the Agreement with respect to the affected Services by written notice, and MAPSLY will refund Customer the prepaid fees prorated for the unused portion of the then-current Billing Period following the effective date of termination. If the affected functionality cannot reasonably be separated from the remainder of the Services, Customer may terminate the Agreement in its entirety on the same terms.

6.2 Sub-processor Obligations. Khi MAPSLY ủy quyền cho một Đơn vị xử lý phụ như mô tả trong Mục 6.1:

(i) MAPSLY will restrict the Sub-processor’s access to Customer Data only to what is necessary to provide or maintain the Services in accordance with the Documentation, and MAPSLY will prohibit the Sub-processor from accessing Customer Data for any other purpose;

(ii) MAPSLY will enter into a written agreement with the Sub-processor and, to the extent that the Sub-processor performs the same data processing services provided by MAPSLY under this DPA, MAPSLY will impose on the Sub-processor the same contractual obligations that MAPSLY has under this DPA; and

(iii) MAPSLY will remain responsible for its compliance with the obligations of this DPA and for any acts or omissions of the Sub-processor that cause MAPSLY to breach any of MAPSLY’s obligations under this DPA.

7. MAPSLY Assistance with Data Subject Requests

Xem xét đến tính chất của việc xử lý, Công cụ Kiểm soát Dịch vụ là các biện pháp kỹ thuật và tổ chức mà MAPSLY sẽ hỗ trợ Khách hàng trong việc hoàn thành nghĩa vụ của Khách hàng để phản hồi các yêu cầu từ chủ thể dữ liệu theo Luật Bảo vệ Dữ liệu Áp dụng. Nếu một chủ thể dữ liệu gửi yêu cầu đến MAPSLY, MAPSLY sẽ nhanh chóng chuyển tiếp yêu cầu đó tới Khách hàng ngay khi MAPSLY xác định rằng yêu cầu đó đến từ chủ thể dữ liệu mà Khách hàng chịu trách nhiệm. Khách hàng ủy quyền thay mặt mình, và thay mặt các bộ điều khiển của mình khi Khách hàng đóng vai trò là Bộ xử lý, cho MAPSLY để phản hồi bất kỳ chủ thể dữ liệu nào gửi yêu cầu đến MAPSLY, nhằm xác nhận rằng MAPSLY đã chuyển tiếp yêu cầu đó đến Khách hàng. Các bên đồng ý rằng việc Khách hàng sử dụng Công cụ Kiểm soát Dịch vụ và MAPSLY chuyển tiếp các yêu cầu từ chủ thể dữ liệu đến Khách hàng theo phần này đại diện cho phạm vi và mức độ hỗ trợ cần thiết của Khách hàng.

8. Compliance Verification

8.1 MAPSLY Audits. MAPSLY uses external auditors to verify the adequacy of its security measures. This audit: (a) will be performed at least annually; (b) will be performed according to a widely recognized standard (such as SOC 2 Type II); (c) will be performed by independent third-party security professionals at MAPSLY’s selection and expense; and (d) will result in the generation of an audit report (“Report”), which will be MAPSLY’s Confidential Information.

8.2 Audit Reports. Theo yêu cầu bằng văn bản của Khách hàng, và với điều kiện các bên có thỏa thuận NDA áp dụng, MAPSLY sẽ cung cấp cho Khách hàng một bản sao Báo cáo để Khách hàng có thể kiểm tra hợp lý việc MAPSLY tuân thủ các nghĩa vụ của mình theo DPA này.

8.3 Privacy Impact Assessment and Prior Consultation. Xem xét tính chất của việc xử lý và thông tin MAPSLY có được, MAPSLY sẽ hỗ trợ Khách hàng trong việc tuân thủ các nghĩa vụ của Khách hàng liên quan đến đánh giá tác động bảo vệ dữ liệu và tham vấn trước bằng cách cung cấp các thông tin mà MAPSLY cung cấp theo Mục 8 này.

9. Transfers of Personal Data

9.1 Locations. MAPSLY stores and processes Customer Data within the MAPSLY Network in the USA. MAPSLY personnel and Sub-processors may remotely access Customer Data from other countries in which they operate solely as necessary to provide, maintain, and support the Services; any such access constitutes a Data Transfer governed by this Section 9. MAPSLY will not otherwise transfer Customer Data outside of the EEA, the United Kingdom, Switzerland, and the USA except as necessary to provide the Services initiated by Customer, or as necessary to comply with the law or valid and binding order of a governmental body.

9.2 Application of Standard Contractual Clauses. Subject to Section 9.3, the Standard Contractual Clauses will only apply to Customer Data subject to the GDPR, the UK GDPR, or the FADP that is transferred, either directly or via onward transfer, to any Third Country (each a “Data Transfer”).

9.2.1 Khi Khách hàng đóng vai trò là Người kiểm soát, các Điều khoản từ Người kiểm soát tới Người xử lý sẽ áp dụng cho Việc chuyển dữ liệu.

9.2.2 Khi Khách hàng hoạt động như một Bộ xử lý, các Điều khoản Bộ xử lý-đến-Bộ xử lý sẽ áp dụng cho Việc Chuyển dữ liệu. Xem xét đến tính chất của việc xử lý, Khách hàng đồng ý rằng MAPSLY khó có thể biết được danh tính của các Bộ điều khiển của Khách hàng vì MAPSLY không có mối quan hệ trực tiếp với các Bộ điều khiển của Khách hàng và do đó, Khách hàng sẽ thực hiện các nghĩa vụ của MAPSLY đối với các Bộ điều khiển của Khách hàng theo các Điều khoản Bộ xử lý-đến-Bộ xử lý.

9.2.3 For Data Transfers subject to the UK GDPR, the Standard Contractual Clauses apply as supplemented by the UK Addendum, completed as set forth in Section 9.4.

9.2.4 For Data Transfers subject to the FADP, the Standard Contractual Clauses apply with the following adaptations: (i) references to the GDPR are to be read as references to the FADP; (ii) the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; (iii) the term “Member State” is interpreted to include Switzerland, so that data subjects in Switzerland may enforce their rights in their place of habitual residence; and (iv) references to EU law are to be read as references to Swiss law where the transfer is exclusively subject to the FADP.

9.3 Alternative Transfer Mechanism. To the extent MAPSLY has adopted a valid alternative transfer mechanism recognized under Applicable Data Protection Law — including MAPSLY’s certification under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework — such mechanism will apply to a Data Transfer in place of the Standard Contractual Clauses for so long as it remains valid. If such alternative mechanism is invalidated, suspended, withdrawn, or otherwise ceases to provide a lawful basis for a Data Transfer, the Standard Contractual Clauses (as completed in Section 9.4) will automatically apply to that Data Transfer without further action by either party. MAPSLY will maintain its Data Privacy Framework certification for so long as it relies on the Data Privacy Framework for Data Transfers.

9.4 Completion of the Standard Contractual Clauses. For each Data Transfer to which the Standard Contractual Clauses apply, the Standard Contractual Clauses are deemed completed as follows: (i) Module Two (transfer controller to processor) applies where Customer acts as a Controller, and Module Three (transfer processor to processor) applies where Customer acts as a Processor; (ii) in Clause 7, the optional docking clause does not apply; (iii) in Clause 9, Option 2 (general written authorisation) applies, and the time period for prior notice of Sub-processor changes is thirty (30) days, in accordance with Section 6.1; (iv) in Clause 11, the optional language does not apply; (v) in Clauses 17 and 18, the governing law and the competent courts are those of Ireland; and (vi) Annex I of the Standard Contractual Clauses is deemed completed with the information set out in Annex B to this DPA, Annex II is deemed completed with Annex A to this DPA, and Annex III is deemed completed with the Sub-processor list referenced in Section 6.1. Where the UK Addendum applies: Table 1 is deemed completed with the parties’ details under the Agreement; Table 2 with the Standard Contractual Clauses as completed above; Table 3 with the Annex information above; and, for Table 4, neither party may end the UK Addendum as set out in Section 19 of the UK Addendum.

10. Termination of the DPA

This DPA will continue in force until the termination of the Agreement (the “Termination Date”).

11. Deletion of Customer Data

Upon termination or expiration of the Agreement, MAPSLY shall delete Customer Data from its active systems at Customer’s request, and in any event not later than within a 90-day period after termination, except and to the extent MAPSLY is required by applicable law to retain some or all of the Customer Data, in which case MAPSLY shall securely isolate this Data, protect it from any further processing, and delete it in accordance with applicable retention periods. Customer Data held in backup systems will be deleted or overwritten in the ordinary course of MAPSLY’s backup rotation cycles following deletion from active systems and will be protected from any further processing until deleted.

12. Duties to Inform

Khi Dữ liệu Khách hàng trở thành đối tượng bị tịch thu trong các thủ tục phá sản hoặc vỡ nợ hoặc các biện pháp tương tự bởi bên thứ ba trong quá trình được xử lý bởi MAPSLY, MAPSLY sẽ thông báo cho Khách hàng mà không chậm trễ không cần thiết. MAPSLY sẽ, không chậm trễ không cần thiết, thông báo cho tất cả các bên liên quan trong hành động đó (ví dụ, chủ nợ, quản tài viên phá sản) rằng bất kỳ Dữ liệu Khách hàng nào bị tác động bởi các thủ tục đó là tài sản và trách nhiệm của Khách hàng và Dữ liệu Khách hàng thuộc quyền kiểm soát duy nhất của Khách hàng.

13. Entire Agreement; Conflict; Amendment

This DPA incorporates the Standard Contractual Clauses by reference. Except as amended by this DPA, the Agreement will remain in full force and effect. If there is a conflict among the Standard Contractual Clauses, this DPA, and the Agreement concerning the processing of Customer Data, the Standard Contractual Clauses will control first, this DPA will control second, and the Agreement will control third. For all other matters, the Agreement controls. Nothing in this document varies or modifies the Standard Contractual Clauses. This DPA may be amended in accordance with Section 14.1 of the Agreement, provided that MAPSLY will provide Customer with advance notice of any amendment that materially reduces the protections afforded to Customer Data under this DPA.

14. Google Workspace API Data

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Annex A — Technical and Organizational Measures

MAPSLY maintains the following technical and organizational measures to protect Customer Data. MAPSLY may update these measures from time to time, provided that no update materially reduces the overall security of the Services.

  • Hosting and resilience: the Services are hosted on Amazon Web Services in the United States across multiple availability zones; backups are taken daily and stored in a separate availability zone; backup restoration is tested at least annually.
  • Encryption: Customer Data is encrypted at rest and in transit using industry-standard encryption protocols.
  • Access control: access to production systems is role-based, restricted to authorized personnel on a least-privilege basis, revoked promptly upon role change or termination, and reviewed periodically.
  • Authentication: single sign-on and multi-factor authentication are supported.
  • Secure development: documented secure development practices, including code review and segregation of development, testing, and production environments.
  • Vulnerability management: periodic vulnerability scanning and at least annual penetration testing by independent third parties, with remediation according to documented severity-based timelines.
  • Logging and monitoring: security-relevant events are logged, retained, and monitored.
  • Personnel: personnel are bound by confidentiality obligations and receive security awareness training.
  • Incident response: a documented incident response plan is maintained; Security Incidents are handled in accordance with Section 5.3.
  • Business continuity: documented business continuity and disaster recovery plans are maintained.
  • Governance: a documented information security policy suite is maintained and reviewed periodically; personnel accept applicable policies.
  • Independent assurance: security controls are audited at least annually by independent third parties against a widely recognized standard (currently SOC 2 Type II).

Annex B — Standard Contractual Clauses Information

For the purposes of Annex I of the Standard Contractual Clauses, the following information applies to each Data Transfer:

  • Data exporter: Customer (name, address, and contact details as provided in Customer’s MAPSLY account and the Agreement), acting as a Controller or as a Processor on behalf of its Controllers, as described in Section 9.2. Contact: Customer’s administrator contact on record.
  • Data importer: Mapsly LLC, 440 N Barranca Ave #4985, Covina, CA 91723, USA; [email protected]; acting as a Processor.
  • Signature and date: each party is deemed to have signed the Standard Contractual Clauses, including their Annexes, upon acceptance or execution of the Agreement, with effect from the effective date of the Agreement.
  • Categories of data subjects: as described in Section 1.3.6.
  • Categories of personal data: as described in Section 1.3.5.
  • Sensitive data: the Services are not specifically designed to require special categories of personal data. To the extent Customer chooses to submit such data, Customer is responsible for its compliance with Applicable Data Protection Law in doing so, and the data is processed only in accordance with Customer’s Documented Instructions and protected by the measures described in Annex A.
  • Frequency of the transfer: continuous, for the duration described in Section 1.3.2.
  • Nature and purpose of the processing: as described in Sections 1.3.3 and 1.3.4. Transfers to Sub-processors: as described in Section 6, for the same duration.
  • Retention period: as described in Section 11.
  • Competent supervisory authority (Clause 13): where the data exporter is established in an EEA Member State, the supervisory authority of that Member State; where the data exporter is not established in the EEA but falls within the territorial scope of the GDPR and has appointed an EU representative, the supervisory authority of the Member State in which the representative is established; where the data exporter falls within the territorial scope of the GDPR under Article 3(2) but has not appointed an EU representative, the supervisory authority of one of the Member States in which the data subjects whose personal data is transferred are located. For Data Transfers subject to the UK GDPR, the UK Information Commissioner’s Office; for Data Transfers subject to the FADP, the Swiss Federal Data Protection and Information Commissioner.