Updated on June 25 2026.
This Data Processing Agreement (DPA) is a part of the agreement for the provision of the service whose terms and conditions have been laid out in the service’s general Terms and Conditions (as provided at https://www.addsearch.com/terms/) or such other agreement that may have been specifically concluded (such agreement hereinafter the Customer Agreement) between AddSearch and the client (Customer).
AddSearch and Customer are each individually referred to as a Party and together as the Parties.
1 GENERALÂ
1.1 This DPA forms an integral part of the Customer Agreement and shall apply to all processing of personal data under the Customer Agreement. Where applicable and when this DPA does not explicitly state otherwise, the terms of the Customer Agreement, such as governing law and dispute resolution, shall be applied to this DPA. If the Customer Agreement or any other document regulating the relationship between AddSearch and the Customer as set out in the Customer Agreement contains provisions that are in conflict with this DPA, this DPA shall have precedence.Â
1.2 If and to the extent that the Customer submits data to the Service and such data constitutes or contains personal data, the Customer shall be considered the controller under the EU regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR) and AddSearch processes, by providing the Service to the Customer, such personal data on behalf of the Customer as a processor for the purposes of the Customer Agreement during the term thereof. If and to the extent that the Customer acts as a data processor in relation to other data controllers, AddSearch shall act as a subprocessor under this DPA. As used herein, personal data means such personal data that AddSearch processes on behalf of the Customer as the Customer’s data processor or subprocessor. The processing is specified as follows:Â
1.3 The Customer acknowledges that due to the nature of the service, AddSearch cannot control and has no obligation to verify the personal data Customer submits to the service for processing on behalf of Customer when the Customer uses the service. The Customer acknowledges that it shall be responsible for having a legal ground to process the personal data submitted to AddSearch for processing on behalf of the Customer. Further, the Customer is responsible for its lawful collection, processing and use of the personal data submitted to AddSearch for processing on behalf of the Customer, and for the accuracy thereof, as well as for preserving the rights of the individuals concerned. The Customer shall ensure that the relevant data subjects have been informed of the processing as required by applicable data protection legislation.Â
2 PROCESSING OF PERSONAL DATAÂ
2.1 AddSearch shall only process personal data in accordance with this DPA and documented instructions from Customer, unless required to do so by European Union or Member State law to which AddSearch is subject. In such cases AddSearch shall inform the Customer of that legal requirement before processing unless that law prohibits such information on important grounds of public interest.Â
2.2 Customer’s instructions must be commercially reasonable, compliant with applicable data protection laws and consistent with this DPA.Â
The Customer shall primarily use the functionalities of the service to provide AddSearch with any instructions. In case the Customer’s instructions require additional measures or work to be performed by AddSearch, AddSearch has the right to charge an hourly consulting fee to the Customer for complying with such Customer’s instructions in accordance with AddSearch’s then current price for consulting services, subject to the Customer’s prior approval of such additional costs.
2.4 AddSearch shall immediately notify the Customer in writing, if, in its opinion, an instruction of the Customer infringes applicable data protection legislation. In case the instructions of the Customer are not compliant with the GDPR or any other applicable data protection legislation, AddSearch is not required to comply with such instructions.Â
3 DATA SECURITYÂ
3.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of AddSearch’s processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, AddSearch shall implement and maintain appropriate technical and organizational security measures in order to safeguard the personal data against unauthorized or unlawful processing and damage, and in particular against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. Such security measures include but are not limited to practices listed under Annex 1 of this DPA.
3.2 AddSearch shall, without undue delay after having become aware of it, inform the Customer in writing about any data breaches relating to the Customer’s personal data. AddSearch’s notification about the breach to the Customer shall include at least the following: i) description of the nature of the breach; ii) name and contact details of AddSearch’s contact point where more information can be obtained; iii) description of the likely consequences of the breach; iv) description of the measures taken by AddSearch to address the breach, including, where appropriate, measures to mitigate its possible adverse effects. AddSearch shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken.
3.3 AddSearch shall ensure that individuals processing personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4 ASSISTANCE OBLIGATIONSÂ
4.1 To respond to requests from data subjects exercising their rights under applicable data protection legislation, such as the right of access and the right to rectification or erasure, AddSearch shall promptly notify Customer of any such request submitted to AddSearch. AddSearch may not respond to such requests in the absence of Customer’s written approval. Taking into account the nature of the processing, AddSearch shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer’s obligation to respond to requests for exercising the data subject’s rights under Chapter III of the GDPR.
4.2 Taking into account the nature of the processing and the information available to AddSearch, AddSearch shall further provide the Customer with assistance in ensuring compliance with the Customer’s obligations set out in Articles 32 to 36 of the GDPR (e.g. to perform security and data protection impact assessments, breach notifications and prior consultations of the competent supervisory authority).Â
4.3 In case such assistance requires measures from AddSearch, AddSearch has the right to charge an hourly consulting fee to the Customer for handling such assistance requests in accordance with AddSearch’s then current price for consulting services, subject to the Customer’s prior approval of such additional costs.
5 INTERNATIONAL TRANSFERSÂ
5.1 The Customer accepts that AddSearch may transfer personal data to its subprocessors outside the European Economic Area (“EEA”) to provide the service. Before any personal data is transferred by AddSearch from the EEA for processing in any country outside the EEA that is not recognized by the European Commission as providing an adequate level of protection for personal data, AddSearch shall comply with Chapter V of the GDPR and use transfer tools which ensure appropriate safeguards for protection of the personal data, including (but not necessarily limited to) applying the EU-US Data Privacy Framework (or its successor) or entering into the standard contractual clauses for processor-to-processor transfers (Module 3) adopted by the European Commission (by the implementing decision (EU) 2021/914 and as amended) and carrying out a transfer impact assessment. AddSearch shall implement additional safeguards where necessary. For the avoidance of doubt, AddSearch shall have the right and obligation to independently execute any necessary transfer impact assessments that are possibly required by the applicable transfer tools.
6 AUDITSÂ
6.1 The Customer or an auditor appointed by the Customer shall with the assistance of AddSearch have the right to audit the processing activities of AddSearch under this DPA to assess the compliance of AddSearch with its contractual obligations under this DPA and applicable data protection legislation during ordinary business hours of AddSearch and with 30 days’ prior written notice. The Customer shall be responsible for the costs incurred by AddSearch or the Customer in relation to the audit.Â
6.2 Where an audit may, in AddSearch’s sole opinion, lead to the disclosure of business or trade secrets of AddSearch or threaten the intellectual property rights of AddSearch, the Customer shall employ an independent auditor, that is not a competitor of AddSearch, to carry out the audit, and the auditor shall agree to be bound by confidentiality to AddSearch’s benefit.
6.3 AddSearch makes available to the Customer, at the Customer’s request, information necessary to demonstrate compliance with the GDPR. In case the aforementioned request by the Customer requires measures or work to be performed by AddSearch, AddSearch has the right to charge an hourly consulting fee in accordance with its then current price for consulting services for handling such requests, subject to the Customer’s prior approval of such additional costs.Â
7 SUBPROCESSORSÂ
7.1 The Customer gives its general authorization to allow AddSearch to engage subcontractors as subprocessors to process personal data in connection with the provision of the service.
7.2 AddSearch is free to choose and change its subprocessors.Â
7.3 The transfer of Customer’s personal data to the subcontractor and the subcontractor’s first action shall only be permitted if all the prerequisites for subcontracting are met. The subcontractors approved by Customer at the time of conclusion of the contract are listed in AddSearch’s sub-processor list, available at https://www.addsearch.com/legal/subprocessors/. If the subcontractor provides the agreed service outside the EU/EEA, AddSearch shall ensure the admissibility with regard to data protection law by means of appropriate measures.
7.4 In case there is a later change of a subprocessor (addition or replacement), AddSearch shall notify the Customer of such change, thereby giving the Customer the opportunity to object to such change within 14 days. If AddSearch is not willing to change the subprocessor the Customer has objected to, both Parties shall have the right to terminate the Customer Agreement and this DPA.Â
7.5 Where AddSearch engages a subprocessor for carrying out specific processing activities on behalf of the Customer, the same data protection obligations as set out in this DPA shall be included in the DPA between AddSearch and that subprocessor. Where a subprocessor fails to fulfill its data protection obligations, AddSearch shall remain fully liable to the Customer for the performance of the subprocessor’s obligations.Â
8 ERASURE OR RETURN OF PERSONAL DATA
8.1 At the choice of Customer, AddSearch deletes or returns all the personal data to Customer after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data.
8.2 AddSearch shall, without explicit request, prove to Customer in text form with date indication that it has returned all data carriers and other documents to Customer or that he has destroyed or deleted them in accordance with data protection regulations and has therefore not retained any of Customer’s personal data.
8.3 AddSearch shall be entitled to keep any and all documentation which serves as evidence of the orderly and lawful data processing for Customer beyond the end of the contract.Â
Annex 1
Company: AddSearch Oy
Last Updated: 2026-03-26
Review Frequency: Annual
Scope & processing context: AddSearch processes technical web usage data to provide site search. Data subjects: customer website visitors. Data categories: IP address, search queries, device identifiers, browser/OS, timestamps, URLs. Purpose: deliver search and analytics features. Retention: For the duration of service provision; data deleted upon contract termination unless retention required by applicable law.
1.1 Physical Access Control
1.2 System Access Control
1.3 Data Access Control
1.4 Separation Control
1.5 Pseudonymization and Encryption
2.1 Transfer Control
2.2 Input Control
3.1 Availability Control
3.2 Resilience and Rapid Recovery
4.1 Data Protection Management
4.2 Incident Response Management
4.3 Data Protection Organization
4.4 Monitoring and Audit
Protection needs / risk classes
Risk area | Level | Primary measures |
Confidentiality | Medium | TLS 1.2+/1.3; encryption at rest; MFA; least privilege; logging |
Integrity | Low–Medium | Change control; code review; input validation; audit logs |
Availability | Medium | Cloud redundancy; backups; RTO/RPO; DR/BCP |
Privacy risk (tracking) | Low | Cookies disabled by default |