This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“you”) and Peko Prospects LLC (“we,” “us”). It applies automatically, without signature, whenever we process personal data on your behalf that is subject to Data Protection Laws. If you need a countersigned copy, email contact@vaneit.com.
1. Definitions
Data Protection Laws means the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (CCPA) and its regulations, and other US state privacy laws, in each case as they apply to the processing. Customer Personal Data means personal data in Customer Data (as defined in the Terms) that we process for you. Terms such as controller, processor, data subject, personal data breach, business, service provider and consumer have the meanings given in the Data Protection Laws.
2. Roles
You are the controller (or business) of Customer Personal Data, and we are your processor (or service provider). We act as an independent controller only for account, billing, and security and abuse-prevention data, as described in our Privacy Policy.
3. Our commitments as processor
We will:
- Follow your instructions. Process Customer Personal Data only on your documented instructions (which are the Terms, this DPA and your use and settings of the Service), including for international transfers, unless the law requires otherwise, in which case we will tell you first unless the law forbids it. We will tell you if we think an instruction breaks Data Protection Laws.
- Confidentiality. Make sure anyone we authorize to process it is bound by confidentiality.
- Security. Apply the measures in Annex 2, appropriate to the risk.
- Subprocessors. Use only the subprocessors on our Subprocessors page, which you authorize generally. We will give at least 30 days’ notice of a new subprocessor by updating that page and emailing account holders, and you may object on reasonable data-protection grounds; if we cannot resolve the objection you may end the affected service and receive a pro-rata refund of prepaid fees. We impose data-protection terms on each subprocessor that are at least as protective as this DPA and remain responsible for them.
- Help with requests. Help you, taking into account the nature of the processing, to answer data subject requests (the Service lets you export and delete data yourself), and forward to you any request we receive about your vanes within 5 business days without answering it ourselves unless you ask us to.
- Help with compliance. Give you reasonable help with security, breach notification, data protection impact assessments and prior consultation (GDPR Articles 32 to 36).
- Breaches. Notify you without undue delay, and in any event within 48 hours, after confirming a personal data breach affecting Customer Personal Data, with the information you reasonably need to meet your own obligations, and keep you updated.
- Deletion. At the end of the service, delete Customer Personal Data (after the 30-day export window in the Terms), unless the law requires us to keep it. Copies in backups are deleted as those backups expire.
- Audits. Make available the information reasonably needed to show compliance with this DPA, including by answering a written security questionnaire once every 12 months, and allow audits by you or an auditor you appoint, on reasonable notice, at your cost, and subject to confidentiality.
4. International transfers
Where Customer Personal Data from the EU, EEA, UK or Switzerland is transferred to us in the United States or onward to a subprocessor, the transfer is covered by: (a) the EU-US Data Privacy Framework and its UK and Swiss extensions where the recipient is certified; or otherwise (b) the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914 (“SCCs”), which are incorporated by reference: Module 2 (controller to processor) where you are a controller and Module 3 (processor to processor) where you are a processor; Clause 7 (docking) applies; Clause 9 option 2 (general authorization) with the notice period in section 3.4; Clause 11 optional wording does not apply; Clause 17 and 18 governing law and courts are those of Ireland; and Annexes I and II are completed by Annexes 1 and 2 of this DPA. For UK transfers, the UK International Data Transfer Addendum (version B1.0) applies, with the SCCs as the Approved EU SCCs. For Swiss transfers, references to the GDPR mean the Swiss Federal Act on Data Protection and the competent authority is the Swiss FDPIC.
5. California and other US state laws
Where we process personal information as your service provider or processor under the CCPA or other US state privacy laws, we:
- process it only for the business purposes of providing the Service to you: hosting your vanes and surveys, recording, tallying and displaying answers, reporting and exporting results to you, generating share images, and security and abuse prevention;
- do not sell or share it (as those terms are defined in the CCPA);
- do not retain, use or disclose it for any purpose other than those business purposes, including any commercial purpose, or outside our direct business relationship with you;
- do not combine it with personal information we receive from anyone else, except as the CCPA regulations permit;
- comply with the obligations that apply to us and give it the same level of privacy protection the law requires of you;
- allow you to take reasonable steps to make sure we use it consistently with your obligations, and to stop and remediate unauthorized use;
- notify you if we determine we can no longer meet our obligations; and
- help you respond to consumer requests.
We certify that we understand and will comply with these restrictions.
6. Liability and precedence
Each party’s liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws or the SCCs do not allow it. If this DPA conflicts with the Terms, this DPA prevails; if it conflicts with the SCCs, the SCCs prevail.
Annex 1: Details of processing
- Subject matter and duration: providing the Service, for the term of your account and the export and deletion period afterwards.
- Nature and purpose: collecting, storing, tallying, displaying, exporting and deleting answers to vanes and surveys; generating share images; security and abuse prevention.
- Data subjects: people who answer your vanes and surveys (Visitors).
- Categories of data: answers (choices, numbers, positions, rankings, free text), time of answer, the vane or survey answered, share-platform choice, the website address where a vane loads, and short-lived IP pseudonyms. No special category data is intended; the Acceptable Use Policy forbids asking for it.
- Frequency: continuous, while your vanes are live.
- Retention: as set out in the Privacy Policy.
- Parties: data exporter: the customer, as identified in its account. Data importer: Peko Prospects LLC, contact@vaneit.com, processor.
Annex 2: Security measures
Encryption in transit (TLS) for all connections; encryption at rest by our infrastructure providers; database row-level security separating each customer’s data; visitor access only through narrow functions that return one live vane at a time; server-side validation and rate limits on all public writes; passwordless sign-in (we store no passwords); least-privilege administrative access with multi-factor authentication on provider accounts; soft deletion with a 30-day recovery window; an audit log of changes; encrypted backups; security headers and a content security policy on our website; and a breach response process with customer notification within 48 hours.
Annex 3: Subprocessors
As listed on our Subprocessors page.