1. Scope and Incorporation
This Data Processing Addendum ("DPA") applies when Visibility Zone LLC ("Visibility Zone," "we," "us," or "Processor") processes personal data on behalf of a customer ("Customer," "you," or "Controller") in the course of providing the Visibility Zone platform or API service (the "Service").
This DPA is incorporated automatically as part of the Terms of Service between you and Visibility Zone. You are not required to execute a separate countersigned copy to be bound, but if you require one for compliance, audit, or contractual purposes, contact us at [email protected] with Attn: Legal, and we will provide an executed copy at no cost within thirty (30) days.
Order of precedence: If a conflict exists between this DPA and the Terms of Service, this DPA shall govern with respect to the processing, security, and lawfulness of personal data.
2. Definitions
Unless otherwise defined here, terms have the meanings given in the GDPR (Regulation (EU) 2016/679), the UK GDPR, the CCPA and CPRA (California Consumer Privacy Act and California Privacy Rights Act), and the Swiss Federal Act on Data Protection (FADP).
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" or "Process" means any operation performed on personal data (collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, transmission, erasure, or destruction).
- "Data Subject" means the natural person to whom personal data relates.
- "Controller" means the natural or legal person who, alone or jointly with others, determines the purposes and means of processing. You are the Controller; we are the Processor.
- "Processor" means Visibility Zone, the natural or legal person who processes personal data on behalf of the Controller.
- "Subprocessor" means any natural or legal person (other than an employee of the Processor) engaged by the Processor to process personal data.
- "Data Subject Request" means a request from a Data Subject exercising rights under applicable data protection law (e.g., right of access, rectification, erasure, portability, objection).
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access to personal data.
- "Service Provider" (under CPRA) means a for-profit entity that processes personal information on behalf of a business and is prohibited from selling or sharing that information.
3. Processing Details
The following table describes the scope of processing when you use the Service:
| Aspect | Description |
|---|---|
| Subject Matter | Processing of personal data you submit to the Visibility Zone Service, including text, images, audio, and metadata. |
| Duration | For the term of the Service agreement and as long as data is retained according to your account settings or applicable law. |
| Nature and Purpose | Analysis and processing to deliver visibility and monitoring features; AI-assisted evaluation; brand and reputation tracking; SEO monitoring; marketplace and app-store intelligence; generation of reports and insights for your account. |
| Categories of Data Subjects | Consumers, customers, employees, representatives, and persons mentioned in content you monitor (e.g., brand mentions, review authors, app reviewers, search result snippets). |
| Categories of Personal Data | Names, email addresses, phone numbers, IP addresses, location data, user identifiers, review text and ratings, social media profiles, public business information, brand mentions, images (including potentially faces or biometric identifiers), and audio content. |
| Special Categories | Images and audio you submit may contain biometric data, health information, or other special categories of personal data. You are responsible for ensuring you have a lawful basis and appropriate notices in place to process such data. Visibility Zone will process special-category data only on your documented instructions and with appropriate technical safeguards. |
4. Processor Obligations Under GDPR Article 28
Visibility Zone commits to the following obligations:
4.1 Documented Instructions
We process personal data only on your documented instructions, as reflected in this DPA, your account configuration, and written requests. We do not use personal data for purposes other than providing the Service, unless we have a separate lawful basis (such as our own legal obligations or legitimate interests disclosed in our Privacy Policy).
4.2 Confidentiality
We ensure that persons authorised to process personal data under our supervision have committed themselves to confidentiality or are under an appropriate legal obligation of confidentiality. All staff with access to customer data receive security awareness training on data protection obligations.
4.3 Security Measures
We implement technical and organisational measures to protect personal data as described in Section 7 below.
4.4 Subprocessor Authorization and Management
We engage subprocessors to deliver the Service, as listed at Subprocessors. We obtain your general written authorization for subprocessors. You consent to our use of the subprocessors listed at the time you accept this DPA. We provide you with thirty (30) calendar days' written notice of any change to, addition of, or replacement of a subprocessor. If you object to a subprocessor change on reasonable data-protection grounds and the change is not resolved, you may terminate the affected service without penalty within thirty (30) days of receiving notice. We notify you of subprocessor changes via email to your account contact address.
4.5 Assistance with Data Subject Requests
To the extent we receive a Data Subject Request directly (e.g., an email to [email protected] with a request to exercise rights), we will promptly forward it to you and cooperate in fulfilling it. You may also direct Data Subjects to submit requests through your account's contact mechanisms. We will assist you, at no additional cost, in responding to verified Data Subject Requests within timelines required by law, provided you give us reasonable notice and clear instructions. We do not charge a fee for assistance unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative cost or decline to act.
4.6 Assistance with Articles 32–36
We will assist you, at no additional cost, in meeting your obligations under GDPR Articles 32 (security), 33 (breach notification), 34 (communication to data subjects), 35 (data protection impact assessments), and 36 (prior consultation with supervisory authorities). Such assistance includes providing information about our security measures, assisting in documenting impact assessments, and providing breach notification details.
4.7 Audit and Compliance
You may, once per calendar year and upon reasonable prior notice (not fewer than thirty (30) days), conduct an audit or inspection of our relevant systems and records to verify compliance with this DPA and applicable law. Audits may be conducted by your internal team or a qualified third-party auditor under strict confidentiality obligations. We will cooperate in good faith and provide access to relevant personnel, documentation, and systems. Audits will not unreasonably disrupt our operations. You bear the cost of any third-party audit.
4.8 Information and Documentation
We provide you with information necessary to demonstrate compliance with this DPA and GDPR Article 28, including our privacy and security practices, subprocessor details, security incident notifications, and assistance with your compliance obligations.
5. Subprocessors
A current list of our subprocessors is maintained at Subprocessors. This includes cloud infrastructure providers, CDN operators, AI model providers, and analytics services.
Notice of changes: We provide thirty (30) calendar days' written notice of any addition of or change to a subprocessor. Notice is sent to your account email address.
Your right to object: If you object to our use of a new or changed subprocessor on grounds relating to data protection or your specific business requirements, you may notify us in writing (to [email protected], Attn: Legal) within the thirty-day notice period. We will work with you in good faith to address your concern. If we cannot resolve it, you may terminate the affected service without penalty by written notice within thirty (30) days of the subprocessor's effective date. This is your sole remedy for subprocessor changes; termination of the service is not required unless you choose to exercise this right.
Visibility Zone's own use: Visibility Zone may use personal data internally for fraud detection, system security, and abuse prevention; to comply with law; and to improve the Service, subject to your privacy rights and this DPA.
6. International Data Transfers
Personal data you provide may be transferred to, stored in, and processed in the European Union, the United States, and other jurisdictions where Visibility Zone or its subprocessors operate. We use the following mechanisms to make such transfers lawful:
6.1 EU Standard Contractual Clauses
To the extent data transfers from the European Union or UK to the United States or other non-adequate countries are necessary, we rely on the EU Standard Contractual Clauses as set out in Commission Implementing Decision (EU) 2021/914 ("SCCs"). Specifically:
- Module Two (Controller to Processor): Applies when you (as a Controller in the EU/EEA) transfer data to Visibility Zone (as Processor).
- Module Three (Processor to Processor): Applies when Visibility Zone, acting as a Processor, transfers data to subprocessors outside the EU/EEA.
- Docking Clause (Clause 7): The docking clause applies, allowing third-party beneficiaries to accede to these SCCs.
- Subprocessor General Authorization (Clause 9(a) Option 2): You provide general written authorization for Visibility Zone to engage subprocessors, with thirty (30) days' notice and your right to object as set out in Section 5.
- Independent Dispute Resolution (Clause 11): Does not apply.
- Governing Law and Jurisdiction (Clause 17): These SCCs are governed by and construed in accordance with the laws of Ireland, and any dispute arising from or related to the SCCs is submitted to the courts of Ireland.
- Redress (Clause 18(b)): Forum is Ireland.
These clauses are deemed incorporated into this DPA by reference and form binding contractual terms between you and Visibility Zone for all personal data transfers outside the EU/EEA.
6.2 UK International Data Transfer Addendum
For transfers from the United Kingdom, we rely on the International Data Transfer Addendum (IDTA) issued by the UK Information Commissioner's Office. The IDTA is incorporated by reference and shall apply in addition to the SCCs where UK personal data is transferred.
6.3 Swiss Data Protection Amendments
For personal data of Swiss data subjects, the SCCs shall be amended as required under Swiss Federal Act on Data Protection (FADP) and as interpreted by the Swiss Federal Data Protection and Information Commissioner. In particular, the definition of "personal data" shall include natural persons domiciled in Switzerland, and the definitions of competent authority and supervisory authority shall include the FDPIC.
7. Technical and Organisational Measures
Visibility Zone implements and maintains the following technical and organisational security measures to protect personal data:
| Measure | Implementation |
|---|---|
| Encryption in Transit | All data transmitted between you and Visibility Zone systems is encrypted using TLS 1.2 or higher. All API requests and responses are secured with TLS. |
| Encryption at Rest | Personal data stored on our infrastructure is encrypted at rest using industry-standard algorithms (AES-256 or equivalent). Encryption keys are managed with access controls. |
| Access Control | Role-based access control (RBAC) and principle of least privilege are applied. Personnel have access only to personal data necessary for their role. Administrative access requires multi-factor authentication (MFA). |
| Authentication and MFA | Strong authentication controls are implemented for administrative and sensitive system access. Multi-factor authentication is enforced for administrative accounts. |
| Network Security | Network segmentation, firewalling, and intrusion detection and prevention systems are deployed. Systems are protected by a Web Application Firewall (WAF) and DDoS mitigation provided by third-party security vendors. |
| Logging and Monitoring | Centralized logging and continuous monitoring of security events are maintained. Logs are retained and reviewed for anomalies and security incidents. |
| Patch Management | Operating systems, applications, and third-party software are regularly patched and updated to address known vulnerabilities. A documented patch management policy is in place. |
| Backup and Disaster Recovery | Regular backups are performed and tested. Backup and restore procedures are documented and tested regularly to ensure business continuity. |
| Secure Development | Code review and secure development practices are applied to the Service. Changes are tested before deployment to production. |
| Vendor Management | Subprocessors are selected based on their ability to implement appropriate security measures. Contracts with subprocessors include data protection and security requirements. |
| Personnel Security | All personnel with access to personal data are required to sign confidentiality agreements and receive data protection and security awareness training. Background checks are performed as appropriate. |
| Incident Response | A documented incident response plan is in place to identify, investigate, and respond to security incidents affecting personal data. |
Periodic Review: These measures are reviewed periodically and may be updated or enhanced to reflect advances in technology and new threats. Any updates will maintain or improve the overall level of protection, and material changes will be communicated to you.
8. Personal Data Breach Notification
If we become aware of a Personal Data Breach that affects personal data processed under this DPA, we will notify you as follows:
- Timing: Without undue delay and, where feasible, within forty-eight (48) hours of becoming aware of the breach.
- Content: The notification will include:
- A description of the nature and scope of the breach;
- The approximate time the breach occurred and the time it was discovered;
- Categories and approximate number of data subjects and personal data records affected;
- The likely consequences of the breach;
- Measures we have taken or propose to take to address the breach and mitigate harm;
- Contact information for our data protection representative or other relevant contact.
- Cooperation: We will cooperate with you and assist you in notifying affected data subjects, regulatory authorities, and media as required by applicable law.
Notification will be provided via email to the primary account contact for your organisation. If you need to reach us urgently regarding a breach, contact [email protected] with Attn: Security Incident.
9. Data Subject Requests
Data Subjects may contact you directly to exercise rights under applicable data protection law (right of access, rectification, erasure, portability, objection, etc.). We will support you as follows:
- Direct requests to us: If a Data Subject contacts Visibility Zone directly (e.g., via [email protected]) with a request, we will promptly forward it to you and ask you to respond.
- Your requests: You may submit a Data Subject Request to us on behalf of a Data Subject, with proper verification. We will process verified requests in accordance with timelines required by law.
- Assistance: We will cooperate in responding to requests, including providing information about how data is processed, assisting in exporting or deleting data where technically feasible, and documenting our cooperation.
- Objections: Where a Data Subject objects to processing on grounds of your own legitimate interests, we will forward the objection to you for resolution. We will cease processing as instructed by you, unless we have a separate lawful basis.
10. Deletion and Return of Data
Upon termination of your Service agreement:
- Export period: You may export or retrieve your personal data and account information for thirty (30) days after termination.
- Deletion: After the thirty-day export period, all personal data associated with your account will be securely deleted from our production systems within a further thirty (30) days, except:
- Data we are legally required to retain (e.g., tax records, legal holds);
- Data in archival or backup systems, which will be deleted in accordance with our standard retention and archival policies;
- Aggregated or de-identified data, which may be retained for analytics and service improvement.
- Certification: Upon request, we will certify deletion within a reasonable timeframe and provide a report documenting what was deleted and any exceptions.
11. CCPA/CPRA Addendum
To the extent the California Consumer Privacy Act (CCPA) or California Privacy Rights Act (CPRA) applies to personal information you process using the Service, the following additional terms apply:
11.1 Visibility Zone as a Service Provider
Visibility Zone acts as a "Service Provider" under CPRA and, where applicable, the CCPA. Visibility Zone will:
- Process personal information only for the specific business purposes set out in this DPA and your account configuration;
- Not sell personal information as defined by the CPRA;
- Not share personal information as defined by the CPRA (sharing means processing for targeted advertising);
- Not retain, use, or disclose personal information except as necessary to provide the Service, or as otherwise permitted by the CPRA;
- Certify that it understands and will comply with these restrictions.
11.2 Service Provider Restrictions
Visibility Zone will not, and will ensure subprocessors do not, combine personal information received from or on behalf of you with personal information received from other sources, except as permitted by the CPRA for Service Providers.
11.3 Consumer Rights Assistance
We will assist you in responding to consumer requests for access, deletion, and opt-out rights under the CPRA, in the same manner as described for Data Subject Requests in Section 9.
12. Liability and Term
12.1 Limitation of Liability
Visibility Zone's liability for breach of this DPA is subject to the limitations in the Terms of Service. However, Visibility Zone shall not be exempt from liability for processing personal data in violation of applicable data protection law.
12.2 Term
This DPA remains in effect for the duration of the Service agreement and for as long as Visibility Zone retains personal data on your behalf, except where a longer retention period is required by law.
12.3 Amendments
Visibility Zone may amend this DPA to comply with changes in applicable law. Material changes will be notified to you at least thirty (30) days in advance. If you do not accept the amendment, you may terminate your Service without penalty within thirty (30) days of notice.
12.4 Contact
For questions about this DPA, data processing practices, or to exercise any rights described herein, contact us at:
Visibility Zone LLC
Attn: Legal / Privacy
[email protected]
For data protection complaints, you may also contact your applicable supervisory authority:
- EU: Your local data protection authority (https://edpb.ec.europa.eu/about-edpb/board/members_en)
- UK: Information Commissioner's Office (www.ico.org.uk)
- California: California Privacy Protection Agency (www.cppa.ca.gov)
- Switzerland: Swiss Federal Data Protection and Information Commissioner (www.edoeb.admin.ch)