Updated on June 25 2026.

ADDSEARCH DATA PROCESSING AGREEMENT

This Data Processing Agreement (DPA) is a part of the agreement for the provision of the service whose terms and conditions have been laid out in the service’s general Terms and Conditions (as provided at https://www.addsearch.com/terms/) or such other agreement that may have been specifically concluded (such agreement hereinafter the Customer Agreement) between AddSearch and the client (Customer).

AddSearch and Customer are each individually referred to as a Party and together as the Parties.

1 GENERAL 

1.1 This DPA forms an integral part of the Customer Agreement and shall apply to all processing of personal data under the Customer Agreement. Where applicable and when this DPA does not explicitly state otherwise, the terms of the Customer Agreement, such as governing law and dispute resolution, shall be applied to this DPA. If the Customer Agreement or any other document regulating the relationship between AddSearch and the Customer as set out in the Customer Agreement contains provisions that are in conflict with this DPA, this DPA shall have precedence. 

1.2 If and to the extent that the Customer submits data to the Service and such data constitutes or contains personal data, the Customer shall be considered the controller under the EU regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR) and AddSearch processes, by providing the Service to the Customer, such personal data on behalf of the Customer as a processor for the purposes of the Customer Agreement during the term thereof. If and to the extent that the Customer acts as a data processor in relation to other data controllers, AddSearch shall act as a subprocessor under this DPA. As used herein, personal data means such personal data that AddSearch processes on behalf of the Customer as the Customer’s data processor or subprocessor. The processing is specified as follows: 

  1. Subject matter and duration of the processing: Processing of technical data relating to Customer website visitors during the term of the Customer Agreement.
  2. Nature and purpose of the processing: Temporary storage and other processing necessary in order to provide the Service.
  3. Type of personal data: IP address; search queries; device and device identification number; operating system; time of visit; browser type and version; language settings; URL route and search history on the page.
  4. Categories of data subjects: Customer representatives and Customer website visitors.

1.3 The Customer acknowledges that due to the nature of the service, AddSearch cannot control and has no obligation to verify the personal data Customer submits to the service for processing on behalf of Customer when the Customer uses the service. The Customer acknowledges that it shall be responsible for having a legal ground to process the personal data submitted to AddSearch for processing on behalf of the Customer. Further, the Customer is responsible for its lawful collection, processing and use of the personal data submitted to AddSearch for processing on behalf of the Customer, and for the accuracy thereof, as well as for preserving the rights of the individuals concerned. The Customer shall ensure that the relevant data subjects have been informed of the processing as required by applicable data protection legislation. 

2 PROCESSING OF PERSONAL DATA 

2.1 AddSearch shall only process personal data in accordance with this DPA and documented instructions from Customer, unless required to do so by European Union or Member State law to which AddSearch is subject. In such cases AddSearch shall inform the Customer of that legal requirement before processing unless that law prohibits such information on important grounds of public interest. 

2.2 Customer’s instructions must be commercially reasonable, compliant with applicable data protection laws and consistent with this DPA. 

The Customer shall primarily use the functionalities of the service to provide AddSearch with any instructions. In case the Customer’s instructions require additional measures or work to be performed by AddSearch, AddSearch has the right to charge an hourly consulting fee to the Customer for complying with such Customer’s instructions in accordance with AddSearch’s then current price for consulting services, subject to the Customer’s prior approval of such additional costs.

2.4 AddSearch shall immediately notify the Customer in writing, if, in its opinion, an instruction of the Customer infringes applicable data protection legislation. In case the instructions of the Customer are not compliant with the GDPR or any other applicable data protection legislation, AddSearch is not required to comply with such instructions. 

3 DATA SECURITY 

3.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of AddSearch’s processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, AddSearch shall implement and maintain appropriate technical and organizational security measures in order to safeguard the personal data against unauthorized or unlawful processing and damage, and in particular against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. Such security measures include but are not limited to practices listed under Annex 1 of this DPA.

3.2 AddSearch shall, without undue delay after having become aware of it, inform the Customer in writing about any data breaches relating to the Customer’s personal data. AddSearch’s notification about the breach to the Customer shall include at least the following: i) description of the nature of the breach; ii) name and contact details of AddSearch’s contact point where more information can be obtained; iii) description of the likely consequences of the breach; iv) description of the measures taken by AddSearch to address the breach, including, where appropriate, measures to mitigate its possible adverse effects. AddSearch shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken.

3.3 AddSearch shall ensure that individuals processing personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4 ASSISTANCE OBLIGATIONS 

4.1 To respond to requests from data subjects exercising their rights under applicable data protection legislation, such as the right of access and the right to rectification or erasure, AddSearch shall promptly notify Customer of any such request submitted to AddSearch. AddSearch may not respond to such requests in the absence of Customer’s written approval. Taking into account the nature of the processing, AddSearch shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer’s obligation to respond to requests for exercising the data subject’s rights under Chapter III of the GDPR.

4.2 Taking into account the nature of the processing and the information available to AddSearch, AddSearch shall further provide the Customer with assistance in ensuring compliance with the Customer’s obligations set out in Articles 32 to 36 of the GDPR (e.g. to perform security and data protection impact assessments, breach notifications and prior consultations of the competent supervisory authority). 

4.3 In case such assistance requires measures from AddSearch, AddSearch has the right to charge an hourly consulting fee to the Customer for handling such assistance requests in accordance with AddSearch’s then current price for consulting services, subject to the Customer’s prior approval of such additional costs.

5 INTERNATIONAL TRANSFERS 

5.1 The Customer accepts that AddSearch may transfer personal data to its subprocessors outside the European Economic Area (“EEA”) to provide the service. Before any personal data is transferred by AddSearch from the EEA for processing in any country outside the EEA that is not recognized by the European Commission as providing an adequate level of protection for personal data, AddSearch shall comply with Chapter V of the GDPR and use transfer tools which ensure appropriate safeguards for protection of the personal data, including (but not necessarily limited to) applying the EU-US Data Privacy Framework (or its successor) or entering into the standard contractual clauses for processor-to-processor transfers (Module 3) adopted by the European Commission (by the implementing decision (EU) 2021/914 and as amended) and carrying out a transfer impact assessment. AddSearch shall implement additional safeguards where necessary. For the avoidance of doubt, AddSearch shall have the right and obligation to independently execute any necessary transfer impact assessments that are possibly required by the applicable transfer tools.

6 AUDITS 

6.1 The Customer or an auditor appointed by the Customer shall with the assistance of AddSearch have the right to audit the processing activities of AddSearch under this DPA to assess the compliance of AddSearch with its contractual obligations under this DPA and applicable data protection legislation during ordinary business hours of AddSearch and with 30 days’ prior written notice. The Customer shall be responsible for the costs incurred by AddSearch or the Customer in relation to the audit. 

6.2 Where an audit may, in AddSearch’s sole opinion, lead to the disclosure of business or trade secrets of AddSearch or threaten the intellectual property rights of AddSearch, the Customer shall employ an independent auditor, that is not a competitor of AddSearch, to carry out the audit, and the auditor shall agree to be bound by confidentiality to AddSearch’s benefit.

6.3 AddSearch makes available to the Customer, at the Customer’s request, information necessary to demonstrate compliance with the GDPR. In case the aforementioned request by the Customer requires measures or work to be performed by AddSearch, AddSearch has the right to charge an hourly consulting fee in accordance with its then current price for consulting services for handling such requests, subject to the Customer’s prior approval of such additional costs. 

7 SUBPROCESSORS 

7.1 The Customer gives its general authorization to allow AddSearch to engage subcontractors as subprocessors to process personal data in connection with the provision of the service.

7.2 AddSearch is free to choose and change its subprocessors. 

7.3 The transfer of Customer’s personal data to the subcontractor and the subcontractor’s first action shall only be permitted if all the prerequisites for subcontracting are met. The subcontractors approved by Customer at the time of conclusion of the contract are listed in AddSearch’s sub-processor list, available at https://www.addsearch.com/legal/subprocessors/. If the subcontractor provides the agreed service outside the EU/EEA, AddSearch shall ensure the admissibility with regard to data protection law by means of appropriate measures.

7.4 In case there is a later change of a subprocessor (addition or replacement), AddSearch shall notify the Customer of such change, thereby giving the Customer the opportunity to object to such change within 14 days. If AddSearch is not willing to change the subprocessor the Customer has objected to, both Parties shall have the right to terminate the Customer Agreement and this DPA. 

7.5 Where AddSearch engages a subprocessor for carrying out specific processing activities on behalf of the Customer, the same data protection obligations as set out in this DPA shall be included in the DPA between AddSearch and that subprocessor. Where a subprocessor fails to fulfill its data protection obligations, AddSearch shall remain fully liable to the Customer for the performance of the subprocessor’s obligations. 

8 ERASURE OR RETURN OF PERSONAL DATA

8.1 At the choice of Customer, AddSearch deletes or returns all the personal data to Customer after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data.

8.2 AddSearch shall, without explicit request, prove to Customer in text form with date indication that it has returned all data carriers and other documents to Customer or that he has destroyed or deleted them in accordance with data protection regulations and has therefore not retained any of Customer’s personal data.

8.3 AddSearch shall be entitled to keep any and all documentation which serves as evidence of the orderly and lawful data processing for Customer beyond the end of the contract. 

Annex 1

Technical and Organisational Measures

Company: AddSearch Oy
Last Updated: 2026-03-26
Review Frequency: Annual

Scope & processing context: AddSearch processes technical web usage data to provide site search. Data subjects: customer website visitors. Data categories: IP address, search queries, device identifiers, browser/OS, timestamps, URLs. Purpose: deliver search and analytics features. Retention: For the duration of service provision; data deleted upon contract termination unless retention required by applicable law.

1. Measures to Ensure Confidentiality (Art. 32(1)(b) GDPR)

1.1 Physical Access Control

  • Data center physical security managed by infrastructure subprocessors (AWS, Microsoft Azure) with certified facilities
  • Customer data prohibited from download to personal devices

1.2 System Access Control

  • Multi-Factor Authentication (MFA) enabled across all systems where technically feasible
  • Identity Provider (IDP) used for centralized identity and access management
  • Root accounts secured with strict controls; no root logins permitted
  • Individual account allocation mandatory; account sharing strictly prohibited
  • Strong password requirements enforced across all systems
  • Enterprise-grade password management system for secure credential storage

1.3 Data Access Control

  • Principle of least privilege enforced for all system access
  • Access rights reviewed and adjusted during employee onboarding and offboarding processes
  • Role-based access control aligned with job functions

1.4 Separation Control

  • Customer data is logically separated by tenant identifiers at the application and database layers. Authorization checks enforce per-tenant access on every request. Administrative tooling restricts data views to the customer’s tenant. No cross-tenant queries are possible through supported interfaces, and access is further constrained by least-privilege roles and per-user accounts.

1.5 Pseudonymization and Encryption

  • Hard disk encryption is mandatorily enabled on all hardware
  • Data is encrypted at rest and in transit
  • In transit: TLS 1.2+ for all external traffic; mutual TLS or private networking for service-to-service traffic where feasible.
  • At rest: Managed encryption via cloud KMS (AES-256 equivalent). Encryption is enabled for databases, object storage, and backups.
  • Key management: Keys stored and rotated using cloud KMS with restricted access; access events are logged.

2. Measures to Ensure Integrity (Art. 32(1)(b) GDPR)

2.1 Transfer Control

  • All data transfers occur over encrypted channels (HTTPS/TLS). Access to production data paths is logged; distribution via CDN follows the provider’s security controls and HTTPS enforcement.

2.2 Input Control

  • All user actions through personal accounts are fully logged
  • Activity logs maintain a clear record of user activities for an audit trail
  • Production changes require code review and approval
  • Automated testing is performed in the staging environment before production deployment
  • Rollback procedures available for failed deployments

3. Measures to Ensure Availability and Resilience (Art. 32(1)(b) GDPR)

3.1 Availability Control

  • Infrastructure hosted on enterprise cloud providers (AWS, Microsoft Azure) with high availability architecture
  • Automated backups with retention: daily (5 days), weekly (3 weeks), monthly (12 months)
  • All backups are encrypted and stored in geographically separate locations from primary data
  • Recovery Point Objective: 24h. Recovery Time Objective: 24h for critical services. 
  • Backups are test-restored annually.

3.2 Resilience and Rapid Recovery

  • Workstation operating system security patches applied automatically
  • Server OS patches applied monthly
  • Documented Disaster Recovery and Business Continuity procedures define roles, communication, and restoration steps; critical components are deployed with cloud-native redundancy. 

4. Processes for Regular Testing, Assessment and Evaluation (Art. 32(1)(d) GDPR)

4.1 Data Protection Management

  • Annual review of technical and organizational measures
  • Access rights review during employee lifecycle events
  • SDKs and libraries ship with cookies and tracking disabled by default. Customers can enable features explicitly.

4.2 Incident Response Management

  • Personal data breach notification procedures as defined in Section 3.2 of DPA
  • Documentation of all personal data breaches maintained
  • A documented Incident Response Plan defines classification, escalation, forensics, containment, and post-incident reviews. Personal-data breach handling follows DPA §3.2.

4.3 Data Protection Organization

  • Employee confidentiality obligations enforced through signed agreements
  • Data protection and security training provided during onboarding and annually
  • Background checks conducted for personnel with production system access (where legally permitted)
  • Access credentials revoked immediately upon termination

4.4 Monitoring and Audit

  • Activity logging enabled for accountability and audit purposes
  • Customer audit rights as defined in Section 6 of DPA
  • Vulnerability scanning: monthly; findings triaged by severity with defined SLAs.
  • Penetration testing: at least annually by an independent party.
  • Control reviews: annual SOC 2 Type II audit scope includes security, availability, confidentiality.

5. Subprocessor Management

  • Subprocessor list maintained and updated
  • Same data protection obligations imposed on subprocessors per Section 7.5 of DPA
  • Infrastructure subprocessors provide certified data center facilities meeting international security standards.

6. Risk assessment

Protection needs / risk classes

Risk area

Level

Primary measures

Confidentiality

Medium

TLS 1.2+/1.3; encryption at rest; MFA; least privilege; logging

Integrity

Low–Medium

Change control; code review; input validation; audit logs

Availability

Medium

Cloud redundancy; backups; RTO/RPO; DR/BCP

Privacy risk (tracking)

Low

Cookies disabled by default