1. Definitions & Scope
This Data Processing Addendum (“DPA”) supplements the Autometa Terms of Service between Autometa, Inc. (“Processor” or “Autometa”) and the customer entity agreeing to these terms (“Controller” or “Customer”).
This DPA applies to the processing of Personal Data provided by Customer in connection with their use of Autometa CRM and related B2B business services, to the extent such data is subject to Applicable Data Protection Laws (including EU GDPR, UK GDPR, and the Swiss Federal Act on Data Protection).
2. Processor Obligations & Instructions
Autometa shall process Personal Data solely on documented instructions from Customer (including with respect to transfers of Personal Data), unless required to do so by applicable statutory law. Customer’s configuration of the CRM services constitutes complete instructions for the processing of Personal Data.
- Confidentiality: Autometa ensures that all personnel authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Data Subject Requests: Taking into account the nature of processing, Autometa assists Customer through built-in self-service export, correction, and deletion features to fulfill obligations to respond to data subject requests under GDPR Chapter III.
3. Technical & Organizational Measures (TOMs)
Autometa implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as detailed in our Security & Trust Center , including:
- Encryption of Personal Data in transit (TLS 1.3) and at rest (AES-256).
- Multi-tenant logical database isolation keyed by organization ID.
- Measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems.
- Automated hourly backup replication and disaster recovery restoration procedures.
- A process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures.
4. Sub-processing Authorization & Notice
Customer provides general written authorization for Autometa to engage sub-processors to assist in delivering the Services.
Autometa shall impose data protection obligations on any sub-processor that are no less protective than those set out in this DPA. Our active sub-processor list is published and maintained on our Security Page . Autometa will provide notice of any new sub-processors at least 14 days prior to authorizing them to process customer data.
5. Security Incident Notification
In the event of a confirmed Security Incident resulting in unauthorized access to, alteration, disclosure, or destruction of Customer Personal Data, Autometa shall notify Customer without undue delay (and in any event within 48 hours of becoming aware of the incident).
Autometa shall provide reasonable assistance and information to enable Customer to notify relevant supervisory authorities and affected data subjects where required under Applicable Data Protection Law.
6. Audits & Standard Contractual Clauses
To the extent required by European Data Protection Law, where Personal Data is transferred outside the European Economic Area or UK, the parties hereby incorporate the European Commission’s Standard Contractual Clauses (Module Two: Controller to Processor).
Autometa shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in GDPR Article 28, including third-party SOC 2 Type II audit summary reports upon request under NDA.