Skip to main content

Data processing addendum

For customers who need a written record of the processor relationship — agencies, mostly.

Updated

This document is a pre-launch draft. Bracketed values are unresolved and will be filled before WellCited accepts a payment. It is published early so nobody has to ask what our position is going to be.

Scope

This addendum forms part of the terms of service between [LEGAL ENTITY NAME] (“processor”) and the account holder (“controller”). It applies where the controller's use of WellCited involves personal data covered by [APPLICABLE DATA PROTECTION LAW].

For most WellCited accounts the personal data in scope is limited to the controller's own account details and any personal data the controller chooses to enter into site names, prompts or competitor labels.

Roles

The controller decides which domains are audited, which prompts are run and which competitors are tracked. WellCited processes that data only to provide the service, to bill for it, and to keep it secure.

WellCited does not use controller data to train models of its own and does not share it with other customers.

Subprocessors

The controller authorises the subprocessors listed in the privacy notice. We will give [SUBPROCESSOR NOTICE PERIOD] notice at [SUBPROCESSOR NOTICE CHANNEL] before adding a new one, during which the controller may object and terminate without penalty if the objection cannot be resolved.

Security

Access to production data is limited to named administrators and audited. Data is encrypted in transit and at rest by the underlying providers. Row-level security isolates one account's data from another's at the database, not only in application code.

We will notify the controller without undue delay, and in any case within [BREACH NOTICE WINDOW], of a personal data breach affecting their data, with the facts known at that time.

International transfers

Where personal data is transferred out of [PRIMARY REGION], the transfer relies on [TRANSFER MECHANISM]. The current processing locations are listed in the privacy notice.

Deletion and return

On termination the controller may export their data from the account page. We delete controller data within [DELETION WINDOW] of account deletion, except where retention is required by law, in which case it stays isolated and is deleted at the end of the required period.

Audit

On reasonable written notice, and no more than [AUDIT FREQUENCY], the controller may request the information needed to demonstrate compliance with this addendum. Requests go to [PRIVACY EMAIL].