数据处理附录
Last updated: July 31, 2026. This version supersedes the version last updated September 15, 2023.
本《数据处理附录》(“DPA”)是您与您所代表的实体(“客户”、“您”或“您的”)与 Mapsly LLC(“MAPSLY”)之间的协议。本 DPA 补充了 MAPSLY 在以下位置提供的服务条款, https://mapsly.com/terms, as updated from time to time between Customer and MAPSLY, or other agreements between Customer and MAPSLY that govern Customer’s use of the MAPSLY Services (the “Agreement”). “Customer” refers to the entity defined as “User” under the MAPSLY Terms of Service. This DPA applies to the extent MAPSLY processes Customer Data on Customer’s behalf in providing the Services.
定义。本DPA中使用的所有大写术语,除非协议另有定义,否则具有以下所赋予的含义:
“API” 表示应用程序编程接口。
“Applicable Data Protection Law” means all laws and regulations applicable to and binding on the processing of Customer Data by a party, including, as applicable, the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), and applicable United States federal and state privacy laws (including the California Consumer Privacy Act, as amended).
“Binding Corporate Rules” 具有GDPR中赋予的含义。
“Controller” 具有GDPR中赋予的含义。
“Controller-to-Processor Clauses” 指数据控制方与处理方之间用于数据传输的标准合同条款,该条款已获欧洲委员会于2021年6月4日批准的实施决定(EU)2021/914。
“Customer Data” means the Personal Data that is uploaded to or generated within the Services under Customer’s MAPSLY accounts, excluding the End-User account and usage information described in Section 1.5.
“Data Privacy Framework” or “DPF” means, together, the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework, as administered by the U.S. Department of Commerce.
“Documentation” 指当时当前位于以下位置的服务文档 https://help.mapsly.com (以及MAPSLY指定的任何继任位置)。
“EEA” 意指欧洲经济区。
“End Users” 指客户的 Mapsly 账户用户,包括客户指派使用 Mapsly 的客户员工和承包商。
“GDPR” 指欧洲议会和理事会于2016年4月27日颁布的2016/679号法规,关于保护自然人就其个人数据的处理及该等数据的自由流通,并废除指令95/46/EC(通用数据保护条例)。
“MAPSLY Network” 指位于 MAPSLY 控制范围内并用于提供服务的服务器、网络设备和主机软件系统(例如虚拟防火墙)。
“MAPSLY Setup console” 指的是 Mapsly 服务中主菜单“设置”下的设置部分。
“Personal Data” 指个人数据、个人信息、可识别个人身份的信息或其他等效术语(各自均根据适用的数据保护法律定义)。
“Processing” 具有GDPR中赋予的含义,“处理”、“处理过程”和“已处理”将相应地进行解释。
“Processor” 具有GDPR中赋予的含义。
处理器到处理器条款 means the standard contractual clauses between Processors for Data Transfers, as approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
安全事件 指MAPSLY的安全漏洞,导致客户数据意外或非法的销毁、丢失、篡改、未经授权的披露或访问。
服务控制 指服务提供的控制,包括安全功能和功能,如文档中所述。
“Standard Contractual Clauses” means (i) the Controller-to-Processor Clauses, or (ii) the Processor-to-Processor Clauses, as applicable in accordance with Sections 9.2.1 and 9.2.2, as supplemented, where applicable, by the UK Addendum (for Data Transfers subject to the UK GDPR) and by the Swiss adaptations described in Section 9.2.4 (for Data Transfers subject to the FADP).
第三国 means a country outside the EEA, the United Kingdom, or Switzerland not recognized by the European Commission (or, as applicable, by the competent United Kingdom or Swiss authorities) as providing an adequate level of protection for personal data (as described in the GDPR, the UK GDPR, or the FADP, as applicable).
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, in force 21 March 2022.
“UK GDPR” means the GDPR as it forms part of the law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018.
1. Data Processing
1.1 Scope and Roles. 当 MAPSLY 处理客户数据时,本 DPA 适用。在此情境中,MAPSLY 将作为客户的数据处理者,而客户可作为客户数据的控制者或处理者。
1.2 Customer Controls. 客户可以使用服务控制来协助其履行适用数据保护法下的义务,包括回应数据主体请求的义务。考虑到处理的性质,客户同意 MAPSLY 不太可能意识到根据标准合同条款转移的客户数据不准确或过时。然而,如果 MAPSLY 意识到根据标准合同条款转移的客户数据不准确或过时,它将毫不拖延地通知客户。MAPSLY 将通过提供客户可用来删除或更正客户数据的服务控制,与客户合作删除或更正根据标准合同条款转移的不准确或过时的客户数据。
1.3 Details of Data Processing.
1.3.1 Subject matter. 本DPA下数据处理的主题是客户数据。
1.3.2 Duration. The processing continues for the Term of the Agreement and thereafter for the limited period necessary to return, delete, or lawfully retain Customer Data in accordance with Section 11.
1.3.3 Purpose. 本DPA项下数据处理的目的是提供客户不时发起的服务。
1.3.4 Nature of the processing. Compute, storage, geocoding, routing, synchronization with Customer’s connected systems, and such other Services as described in the Documentation and initiated by Customer from time to time, including, where Customer uses AI-based features of the Services, processing by AI model providers engaged as Sub-processors solely to provide the Services to Customer. MAPSLY does not use Customer Data to train generalized artificial intelligence or machine learning models.
1.3.5 Type of Customer Data. Customer Data uploaded to or generated within the Services under Customer’s MAPSLY accounts, which may include contact and CRM records, addresses and other location data (including precise geolocation of End Users where Customer enables location tracking, check-in, or similar features), photos, notes, form responses, audio recordings and transcripts (where Customer uses voice or AI-based features), and automation and activity data.
1.3.6 Categories of data subjects. The data subjects could include Customer’s customers, prospects and leads, employees, suppliers and End Users.
1.4 Compliance with Laws. 各方将遵守适用于其并对其有约束力的所有法律、规则和法规,以履行本DPA,包括适用的数据保护法律。
1.5 Mapsly as Controller. Customer acknowledges that Mapsly collects certain information about Customer’s End Users — such as account, authentication, billing, support, and usage information — as described in the MAPSLY Privacy Policy (currently published at https://mapsly.com/privacy-policy). To the extent Mapsly determines the purposes and means of processing such information, Mapsly acts as an independent Controller of that information and processes it in accordance with the MAPSLY Privacy Policy and Applicable Data Protection Law; such information is not Customer Data processed under this DPA. Mapsly may disclose such information internally and to its service providers for legitimate business purposes relating to the operation, support, and improvement of the Services, such as billing, account management, technical support, and product development.
2. Customer Instructions
The parties agree that this DPA and the Agreement (including Customer providing instructions via configuration tools such as the MAPSLY Setup console and APIs made available by MAPSLY for the Services) constitute Customer’s documented instructions regarding MAPSLY’s processing of Customer Data (“Documented Instructions”). MAPSLY will process Customer Data only in accordance with Documented Instructions (which if Customer is acting as a Processor, could be based on the instructions of its Controllers). Additional instructions outside the scope of the Documented Instructions (if any) require prior written agreement between MAPSLY and Customer, including agreement on any additional fees payable by Customer to MAPSLY for carrying out such instructions. Where an additional instruction is required for Customer’s compliance with Applicable Data Protection Law and the parties are unable, within thirty (30) days, to reasonably agree on its implementation and any applicable fees, Customer may terminate the affected Services by written notice, and MAPSLY will refund Customer the prepaid fees prorated for the unused portion of the then-current Billing Period for the terminated Services. Taking into account the nature of the processing, Customer agrees that it is unlikely MAPSLY can form an opinion on whether Documented Instructions infringe Applicable Data Protection Law. If MAPSLY forms such an opinion, it will immediately inform Customer, in which case, Customer is entitled to withdraw or modify its Documented Instructions.
3. Confidentiality of Customer Data
MAPSLY 不会访问、使用或向任何第三方披露任何客户数据,除非在每种情况下,为维护或提供服务所必需,或为遵守法律或政府机构(例如传票或法院命令)的有效且具有约束力的命令所必需。如果政府机构向 MAPSLY 发送客户数据的请求,MAPSLY 将尝试引导该政府机构直接向客户请求该数据。作为这一努力的一部分,MAPSLY 可能会向政府机构提供客户的基本联系信息。如果被迫向政府机构披露客户数据,MAPSLY 将合理通知客户该请求,以便客户寻求保护令或其他适当的救济,除非法律禁止 MAPSLY 这样做。
4. Confidentiality Obligations of MAPSLY Personnel
MAPSLY 限制其人员在未获得 MAPSLY 授权的情况下处理客户数据。MAPSLY 对其人员施加适当的合同义务,包括有关保密、数据保护和数据安全的相关义务。
5. Security of Data Processing
5.1 MAPSLY has implemented and will maintain the appropriate technical and organizational measures to ensure the security and confidentiality of the Customer Data, as described in Annex A (Technical and Organizational Measures) to this DPA and in accordance with Mapsly’s security standards described in this DPA and within the MAPSLY Privacy Policy. MAPSLY may update the measures described in Annex A from time to time, provided that no update materially reduces the overall security of the Services.
5.2 Customer Responsibilities and Optional Security Features. MAPSLY 提供多项服务控制,客户可以选择使用以进一步增强客户数据的安全性。客户负责 (a) 安全使用服务,包括保护其账户认证凭据的安全,(b) 保护传输至服务及从服务传输的客户数据的安全,(c) 采取适当措施安全加密或备份上传至服务的客户数据,(d) 正确配置服务和服务控制,及 (e) 采取客户认为适当的其他措施以确保客户数据的安全、保护和删除。
5.3 Security Incident Notification.
5.3.1 Security Incident. MAPSLY将在知晓安全事件后,(a)及时通知客户安全事件的发生,并且(b)采取适当措施应对安全事件,包括减轻安全事件可能导致的不利影响的措施。
5.3.2 MAPSLY Assistance. 为了使客户能够向监管机构或数据主体(如适用)通报安全事件,MAPSLY将与客户合作并协助客户,在通报中包含MAPSLY能够向客户披露的有关安全事件的信息,同时考虑处理的性质、MAPSLY可用的信息及信息披露的任何限制,如保密性。考虑到处理的性质,客户同意其最有能力确定安全事件可能带来的后果。
5.3.3 Unsuccessful Security Incidents. 客户同意:
(i) an unsuccessful Security Incident will not be subject to this Section 5.3. An unsuccessful Security Incident is one that results in no unauthorized access to Customer Data or to any of MAPSLY’s equipment or facilities storing Customer Data, and could include, without limitation, pings and other broadcast attacks on firewalls or edge servers, port scans, unsuccessful log-on attempts, denial of service attacks, packet sniffing (or other unauthorized access to traffic data that does not result in access beyond headers) or similar incidents; and
(ii) MAPSLY’s obligation to report or respond to a Security Incident under this Section 5.3 is not and will not be construed as an acknowledgment by MAPSLY of any fault or liability of MAPSLY with respect to the Security Incident.
5.3.4 Communication. 如果有安全事件的通知,将通过MAPSLY选择的任何方式(包括电子邮件)发送给客户的一位或多位管理员。客户有唯一责任确保其管理员在MAPSLY设置控制台上保持准确的联系信息,并始终保证传输安全。
5.3.5 Notification Obligations. 如果MAPSLY通知客户安全事件,或客户以其他方式获悉任何客户数据的意外或非法销毁、丢失、篡改、未授权披露或访问,客户将负责 (a) 确定是否根据适用的数据保护法律存在任何通知或其他义务,以及 (b) 采取必要措施履行这些义务。本条款不限制MAPSLY在第5.3节下的义务。
6. Sub-processing
6.1 Authorized Sub-processors. Customer provides general authorization to MAPSLY’s use of sub-processors to provide processing activities on Customer Data on behalf of Customer (“Sub-processors”) in accordance with this Section. The MAPSLY website (currently posted at https://mapsly.com/sub-processors/) lists Sub-processors that are currently engaged by MAPSLY. At least 30 days before MAPSLY engages a Sub-processor, MAPSLY will update the applicable website and provide Customer with a mechanism to obtain notice of that update. To object to a Sub-processor, Customer can: (i) cease using the functionality of the MAPSLY Service for which MAPSLY has engaged the Sub-processor, or (ii) terminate the Agreement pursuant to its terms. If Customer objects to a new Sub-processor on reasonable grounds relating to data protection and the parties are unable to resolve the objection within thirty (30) days, Customer may terminate the Agreement with respect to the affected Services by written notice, and MAPSLY will refund Customer the prepaid fees prorated for the unused portion of the then-current Billing Period following the effective date of termination. If the affected functionality cannot reasonably be separated from the remainder of the Services, Customer may terminate the Agreement in its entirety on the same terms.
6.2 Sub-processor Obligations. 当 MAPSLY 授权子处理方,如第6.1节所述:
(i) MAPSLY will restrict the Sub-processor’s access to Customer Data only to what is necessary to provide or maintain the Services in accordance with the Documentation, and MAPSLY will prohibit the Sub-processor from accessing Customer Data for any other purpose;
(ii) MAPSLY will enter into a written agreement with the Sub-processor and, to the extent that the Sub-processor performs the same data processing services provided by MAPSLY under this DPA, MAPSLY will impose on the Sub-processor the same contractual obligations that MAPSLY has under this DPA; and
(iii) MAPSLY will remain responsible for its compliance with the obligations of this DPA and for any acts or omissions of the Sub-processor that cause MAPSLY to breach any of MAPSLY’s obligations under this DPA.
7. MAPSLY Assistance with Data Subject Requests
考虑到处理的性质,服务控制是MAPSLY协助客户履行其根据适用数据保护法律对数据主体请求做出响应的义务所采取的技术和组织措施。如果数据主体向MAPSLY提出请求,MAPSLY在确认请求来自客户负责的数据主体后,将立即将该请求转发给客户。客户授权代表其本人及其作为处理方时的控制者,授权MAPSLY向任何向MAPSLY提出请求的数据主体确认MAPSLY已将请求转发给客户。双方同意,客户使用服务控制以及MAPSLY根据本节将数据主体请求转发给客户,代表了客户所需协助的范围和程度。
8. Compliance Verification
8.1 MAPSLY Audits. MAPSLY uses external auditors to verify the adequacy of its security measures. This audit: (a) will be performed at least annually; (b) will be performed according to a widely recognized standard (such as SOC 2 Type II); (c) will be performed by independent third-party security professionals at MAPSLY’s selection and expense; and (d) will result in the generation of an audit report (“Report”), which will be MAPSLY’s Confidential Information.
8.2 Audit Reports. 根据客户的书面请求,且双方签有适用的保密协议,MAPSLY 将向客户提供报告副本,以使客户能够合理地核实 MAPSLY 是否遵守该数据保护协议中的义务。
8.3 Privacy Impact Assessment and Prior Consultation. 考虑到处理的性质及MAPSLY可获得的信息,MAPSLY将通过提供本第8节下MAPSLY提供的信息,协助客户遵守客户关于数据保护影响评估和先行咨询的义务。
9. Transfers of Personal Data
9.1 Locations. MAPSLY stores and processes Customer Data within the MAPSLY Network in the USA. MAPSLY personnel and Sub-processors may remotely access Customer Data from other countries in which they operate solely as necessary to provide, maintain, and support the Services; any such access constitutes a Data Transfer governed by this Section 9. MAPSLY will not otherwise transfer Customer Data outside of the EEA, the United Kingdom, Switzerland, and the USA except as necessary to provide the Services initiated by Customer, or as necessary to comply with the law or valid and binding order of a governmental body.
9.2 Application of Standard Contractual Clauses. Subject to Section 9.3, the Standard Contractual Clauses will only apply to Customer Data subject to the GDPR, the UK GDPR, or the FADP that is transferred, either directly or via onward transfer, to any Third Country (each a “Data Transfer”).
9.2.1 当客户作为数据控制者时,控制者与处理者条款将适用于数据传输。
9.2.2 当客户作为处理者行事时,处理者对处理者条款将适用于数据传输。考虑到处理的性质,客户同意MAPSLY不太可能知道客户的控制者身份,因为MAPSLY与客户的控制者没有直接关系,因此,客户将履行MAPSLY根据处理者对处理者条款对客户的控制者承担的义务。
9.2.3 For Data Transfers subject to the UK GDPR, the Standard Contractual Clauses apply as supplemented by the UK Addendum, completed as set forth in Section 9.4.
9.2.4 For Data Transfers subject to the FADP, the Standard Contractual Clauses apply with the following adaptations: (i) references to the GDPR are to be read as references to the FADP; (ii) the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; (iii) the term “Member State” is interpreted to include Switzerland, so that data subjects in Switzerland may enforce their rights in their place of habitual residence; and (iv) references to EU law are to be read as references to Swiss law where the transfer is exclusively subject to the FADP.
9.3 Alternative Transfer Mechanism. To the extent MAPSLY has adopted a valid alternative transfer mechanism recognized under Applicable Data Protection Law — including MAPSLY’s certification under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework — such mechanism will apply to a Data Transfer in place of the Standard Contractual Clauses for so long as it remains valid. If such alternative mechanism is invalidated, suspended, withdrawn, or otherwise ceases to provide a lawful basis for a Data Transfer, the Standard Contractual Clauses (as completed in Section 9.4) will automatically apply to that Data Transfer without further action by either party. MAPSLY will maintain its Data Privacy Framework certification for so long as it relies on the Data Privacy Framework for Data Transfers.
9.4 Completion of the Standard Contractual Clauses. For each Data Transfer to which the Standard Contractual Clauses apply, the Standard Contractual Clauses are deemed completed as follows: (i) Module Two (transfer controller to processor) applies where Customer acts as a Controller, and Module Three (transfer processor to processor) applies where Customer acts as a Processor; (ii) in Clause 7, the optional docking clause does not apply; (iii) in Clause 9, Option 2 (general written authorisation) applies, and the time period for prior notice of Sub-processor changes is thirty (30) days, in accordance with Section 6.1; (iv) in Clause 11, the optional language does not apply; (v) in Clauses 17 and 18, the governing law and the competent courts are those of Ireland; and (vi) Annex I of the Standard Contractual Clauses is deemed completed with the information set out in Annex B to this DPA, Annex II is deemed completed with Annex A to this DPA, and Annex III is deemed completed with the Sub-processor list referenced in Section 6.1. Where the UK Addendum applies: Table 1 is deemed completed with the parties’ details under the Agreement; Table 2 with the Standard Contractual Clauses as completed above; Table 3 with the Annex information above; and, for Table 4, neither party may end the UK Addendum as set out in Section 19 of the UK Addendum.
10. Termination of the DPA
This DPA will continue in force until the termination of the Agreement (the “Termination Date”).
11. Deletion of Customer Data
Upon termination or expiration of the Agreement, MAPSLY shall delete Customer Data from its active systems at Customer’s request, and in any event not later than within a 90-day period after termination, except and to the extent MAPSLY is required by applicable law to retain some or all of the Customer Data, in which case MAPSLY shall securely isolate this Data, protect it from any further processing, and delete it in accordance with applicable retention periods. Customer Data held in backup systems will be deleted or overwritten in the ordinary course of MAPSLY’s backup rotation cycles following deletion from active systems and will be protected from any further processing until deleted.
12. Duties to Inform
当客户数据在由第三方进行的破产或资不抵债程序或类似措施中处于被扣押状态时,且由MAPSLY处理时,MAPSLY将不延误地通知客户。MAPSLY将不延误地通知该行动中所有相关方(例如,债权人、破产受托人),任何受该程序影响的客户数据均为客户的财产和责任范围,且客户数据由客户独自支配。
13. Entire Agreement; Conflict; Amendment
This DPA incorporates the Standard Contractual Clauses by reference. Except as amended by this DPA, the Agreement will remain in full force and effect. If there is a conflict among the Standard Contractual Clauses, this DPA, and the Agreement concerning the processing of Customer Data, the Standard Contractual Clauses will control first, this DPA will control second, and the Agreement will control third. For all other matters, the Agreement controls. Nothing in this document varies or modifies the Standard Contractual Clauses. This DPA may be amended in accordance with Section 14.1 of the Agreement, provided that MAPSLY will provide Customer with advance notice of any amendment that materially reduces the protections afforded to Customer Data under this DPA.
14. Google Workspace API Data
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Annex A — Technical and Organizational Measures
MAPSLY maintains the following technical and organizational measures to protect Customer Data. MAPSLY may update these measures from time to time, provided that no update materially reduces the overall security of the Services.
- Hosting and resilience: the Services are hosted on Amazon Web Services in the United States across multiple availability zones; backups are taken daily and stored in a separate availability zone; backup restoration is tested at least annually.
- Encryption: Customer Data is encrypted at rest and in transit using industry-standard encryption protocols.
- Access control: access to production systems is role-based, restricted to authorized personnel on a least-privilege basis, revoked promptly upon role change or termination, and reviewed periodically.
- Authentication: single sign-on and multi-factor authentication are supported.
- Secure development: documented secure development practices, including code review and segregation of development, testing, and production environments.
- Vulnerability management: periodic vulnerability scanning and at least annual penetration testing by independent third parties, with remediation according to documented severity-based timelines.
- Logging and monitoring: security-relevant events are logged, retained, and monitored.
- Personnel: personnel are bound by confidentiality obligations and receive security awareness training.
- Incident response: a documented incident response plan is maintained; Security Incidents are handled in accordance with Section 5.3.
- Business continuity: documented business continuity and disaster recovery plans are maintained.
- Governance: a documented information security policy suite is maintained and reviewed periodically; personnel accept applicable policies.
- Independent assurance: security controls are audited at least annually by independent third parties against a widely recognized standard (currently SOC 2 Type II).
Annex B — Standard Contractual Clauses Information
For the purposes of Annex I of the Standard Contractual Clauses, the following information applies to each Data Transfer:
- Data exporter: Customer (name, address, and contact details as provided in Customer’s MAPSLY account and the Agreement), acting as a Controller or as a Processor on behalf of its Controllers, as described in Section 9.2. Contact: Customer’s administrator contact on record.
- Data importer: Mapsly LLC, 440 N Barranca Ave #4985, Covina, CA 91723, USA; [email protected]; acting as a Processor.
- Signature and date: each party is deemed to have signed the Standard Contractual Clauses, including their Annexes, upon acceptance or execution of the Agreement, with effect from the effective date of the Agreement.
- Categories of data subjects: as described in Section 1.3.6.
- Categories of personal data: as described in Section 1.3.5.
- Sensitive data: the Services are not specifically designed to require special categories of personal data. To the extent Customer chooses to submit such data, Customer is responsible for its compliance with Applicable Data Protection Law in doing so, and the data is processed only in accordance with Customer’s Documented Instructions and protected by the measures described in Annex A.
- Frequency of the transfer: continuous, for the duration described in Section 1.3.2.
- Nature and purpose of the processing: as described in Sections 1.3.3 and 1.3.4. Transfers to Sub-processors: as described in Section 6, for the same duration.
- Retention period: as described in Section 11.
- Competent supervisory authority (Clause 13): where the data exporter is established in an EEA Member State, the supervisory authority of that Member State; where the data exporter is not established in the EEA but falls within the territorial scope of the GDPR and has appointed an EU representative, the supervisory authority of the Member State in which the representative is established; where the data exporter falls within the territorial scope of the GDPR under Article 3(2) but has not appointed an EU representative, the supervisory authority of one of the Member States in which the data subjects whose personal data is transferred are located. For Data Transfers subject to the UK GDPR, the UK Information Commissioner’s Office; for Data Transfers subject to the FADP, the Swiss Federal Data Protection and Information Commissioner.