1. Definitions and Scope of Processing
This Data Processing Agreement ("DPA") is entered into between the Controller and SEVA Systems LLC ("the Processor"). This DPA supplements the Controller's Project Agreement or subscription plan with the Processor. Its incorporation and term are addressed in Section 12.
1.1 Definitions
"Controller" means the client entering into this DPA with the Processor, in its capacity as the entity determining the purposes and means of processing personal data belonging to the Controller's own customers, users, or website visitors.
"Sub-Processor" means any third party, including the Processor's development and infrastructure partners, engaged by the Processor to assist in processing personal data on the Controller's behalf.
"Personal Data" has the meaning given to it under applicable data protection law, including the GDPR, UK GDPR, CCPA, and other applicable frameworks.
1.2 Scope
This DPA applies to personal data processed by the Processor on behalf of the Controller in connection with hosting Services, domain and mailbox Services, and, where applicable, Managed Marketing Services, including personal data accessed through advertising accounts, social media accounts, or email marketing platforms, provided under the Controller's Project Agreement, Managed Marketing Agreement, or subscription plan. It does not apply to the Processor's processing of the Controller's own personal data as its own customer, which is governed separately by the Processor's Privacy Policy.
1.3 Sensitive Data
The Processor does not support the processing of special category or sensitive personal data under this DPA, including but not limited to health data, genetic or biometric data, racial or ethnic origin, religious or philosophical beliefs, trade union membership, sexual orientation, or government-issued identification numbers such as Social Security numbers. The Controller agrees not to submit such data through the Services unless the Parties have entered into a separate written agreement addressing its processing. Where the Processor becomes aware that such data has been submitted in violation of this Section, the Processor may suspend or restrict access to that data.
2. Processing Instructions
The Processor will process personal data only on the Controller's documented instructions, including as set out in the applicable Project Agreement, unless otherwise required by law to which the Processor is subject, in which case the Processor will inform the Controller of that legal requirement before processing, unless the law prohibits such notice.
If the Processor reasonably believes an instruction from the Controller violates applicable data protection law, the Processor will promptly notify the Controller before carrying out that instruction.
The Processor will not process personal data for any purpose other than providing the Services, and will not use personal data for the Processor's own independent purposes, including marketing to the Controller's customers.
3. Confidentiality
The Processor will ensure that any person authorized to process personal data under this DPA, including the Processor's employees, contractors, and Sub-Processor personnel, is subject to a binding obligation of confidentiality, whether contractual or statutory, and processes personal data only as necessary to perform their role.
This obligation applies regardless of whether the authorized person is client-facing, such as an account executive, or performs backend technical work, and survives the termination of that person's engagement with the Processor or its Sub-Processors.
4. Security Measures
The Processor will implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage, taking into account the nature of the processing and the risk involved.
These measures include encrypted connections, role-based access controls limiting personnel access to what is necessary for their role, and secure infrastructure practices consistent with the Processor's data sovereignty and confidentiality commitments.
The Processor will notify the Controller promptly if it becomes aware that these measures are no longer adequate to address the risks of the processing.
5. Sub-Processors
5.1 General Authorization
The Controller provides general authorization for the Processor to engage Sub-Processors to assist in providing the Services. The Processor's current Sub-Processors, including their identity and country of location, are available to the Controller upon request.
5.2 Notice of New Sub-Processors
The Processor will provide the Controller with reasonable advance notice before engaging a new Sub-Processor. The Controller may object to a new Sub-Processor on reasonable data protection grounds within a reasonable time following that notice. If the Controller objects, the Processor and the Controller will work in good faith to resolve the objection; if no resolution is reached, either party may terminate the affected Service.
5.3 Flow-Down Obligations
The Processor will ensure that each Sub-Processor is bound by a written agreement imposing data protection obligations equivalent to those in this DPA, including confidentiality, security, and, where the Sub-Processor is located outside the Controller's jurisdiction, an appropriate international transfer mechanism.
5.4 Liability
The Processor remains fully liable to the Controller for the performance of its Sub-Processors' obligations under this DPA.
5.5 Confidentiality of Sub-Processor Information
Information disclosed under this Section regarding the Processor's Sub-Processors is confidential and may not be disclosed by the Controller to any third party without the Processor's prior written consent.
6. Assistance with Data Subject Rights
Taking into account the nature of the processing, the Processor will provide reasonable assistance to the Controller in responding to requests from data subjects exercising their rights under applicable data protection law, including access, correction, deletion, restriction, and portability of their personal data.
Where the Processor receives a request directly from an individual who is not the Controller, the Processor will not respond to that request directly and will instead refer it to the Controller, unless required to respond directly by applicable law.
The Processor will respond to the Controller's request for assistance within 7 business days, to allow the Controller reasonable time to meet its own response deadlines under applicable law.
7. Breach Notification
The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data processed under this DPA.
The Processor's notification will include, to the extent known at the time: a description of the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences of the breach, and the measures taken or proposed to address it.
Where this information is not available within the 48-hour window, the Processor will provide it in phases without undue further delay.
The Processor will provide reasonable cooperation and assistance to the Controller in connection with the Controller's own breach notification obligations to regulators and affected individuals.
8. Audit Rights
The Processor will make available to the Controller documentation reasonably necessary to demonstrate compliance with this DPA, upon reasonable written request, no more than once per year.
Following a security incident affecting the Controller's data under this DPA, the Processor will provide additional information reasonably necessary for the Controller to assess the incident's impact, beyond what is provided under Section 7.
9. International Transfers
Where the Processor or a Sub-Processor processes personal data outside the country or region in which it was originally collected, the Processor will ensure an appropriate transfer mechanism is in place, including Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Addendum, or an equivalent mechanism recognized under applicable law, before that transfer occurs.
This includes transfers to the Processor's Sub-Processors, regardless of whether the underlying hosting infrastructure is located within the Controller's own region.
10. Data Deletion or Return on Termination
Upon termination of the Services, the Processor will, at the Controller's choice, delete or return all personal data processed under this DPA, within the timeframe set out in Section 11.6 of SEVA's Terms of Service.
The Processor may retain personal data beyond that timeframe only to the extent required by applicable law, including the billing and payment record retention described in Section 11.6 of the Terms of Service, and only for that purpose.
11. Liability
Each party's liability arising under this DPA is subject to the limitations and exclusions set out in Section 9 (Limitation of Liability) of SEVA's Terms of Service, except that this limitation does not apply to the Processor's breach of its confidentiality obligations under this DPA, consistent with the confidentiality carve-out already established in that Section.
Nothing in this DPA limits either party's liability for matters that cannot be limited under applicable data protection law.
12. Term and Relationship to Project Agreement
This DPA takes effect on the date the Controller's Project Agreement or subscription plan with the Processor becomes effective, and remains in effect for as long as the Processor processes personal data on the Controller's behalf under that Project Agreement or subscription plan.
This DPA is incorporated into and forms part of the Controller's Project Agreement or subscription plan with the Processor. In the event of a conflict between this DPA and the Project Agreement or Terms of Service regarding the processing of personal data, this DPA controls.
Termination of this DPA does not relieve either party of obligations that by their nature survive termination, including confidentiality, data return or deletion under Section 10, and liability for acts occurring during the term.