Data processing addendum
For customers who need a written record of the processor relationship. Agencies, mostly.
Updated
This document is a pre-launch draft. Every operational detail in it is final. The only values still bracketed are our registered company name, address and governing law, which are filled in before WellCited accepts a payment. It is published early so nobody has to ask what our position is going to be.
Scope
This addendum forms part of the terms of service between [LEGAL ENTITY NAME] (“processor”) and the account holder (“controller”). It applies where the controller's use of WellCited involves personal data covered by the data protection law that applies to the controller, including the UK GDPR and the EU GDPR where relevant.
For most WellCited accounts the personal data in scope is limited to the controller's own account details and any personal data the controller chooses to enter into site names, prompts or competitor labels.
Roles
The controller decides which domains are audited, which prompts are run and which competitors are tracked. WellCited processes that data only to provide the service, to bill for it, and to keep it secure.
WellCited does not use controller data to train models of its own and does not share it with other customers.
Subprocessors
The controller authorises the subprocessors listed in the privacy notice. We will give 30 days notice at the email address on the account before adding a new one, during which the controller may object and terminate without penalty if the objection cannot be resolved.
Security
Access to production data is limited to named administrators and audited. Data is encrypted in transit and at rest by the underlying providers. Row-level security isolates one account's data from another's at the database, not only in application code.
We will notify the controller without undue delay, and in any case within 72 hours, of a personal data breach affecting their data, with the facts known at that time.
International transfers
Where personal data is transferred out of the United States, the transfer relies on the European Commission's standard contractual clauses, together with the transfer safeguards each subprocessor publishes. The current processing locations are listed in the privacy notice.
Deletion and return
On termination the controller may export their data from the account page. We delete controller data within 30 days of account deletion, except where retention is required by law, in which case it stays isolated and is deleted at the end of the required period.
Audit
On reasonable written notice, and no more than once in any 12 month period, the controller may request the information needed to demonstrate compliance with this addendum. Requests go to privacy@well-cited.com.