Data Processing Agreement
⚠️ Need a signed copy? If you need a signed copy of a DPA for your organization, please contact us at feco@crowdintelligence.io.
This Data Processing Agreement ("Agreement") forms part of the Contract for Services under Crowd Intelligence's Terms and Conditions (the "Principal Agreement") between TinyMentions Inc., operating as Crowd Intelligence, 2810 N Church St PMB 37128 Wilmington, Delaware, 19802-4447 US, (referred to as the "Processor"), and the Company using Crowd Intelligence's services (referred to as the "Company").
This Agreement governs the specific requirements of Data Protection Laws to the extent that Company's use of Crowd Intelligence Services involves the processing of Personal Data.
This Agreement is complementary to, and should be read together with, our Privacy Policy, which serves as the primary reference for our data‑protection practices and measures.
WHEREAS
A) The Company acts as a Data Controller (the "Controller").
B) The Company wishes to subcontract certain Services (as defined below), which involve the processing of Personal Data, to Crowd Intelligence, acting as a Data Processor (the "Processor").
C) The Parties seek to implement a data‑processing agreement that complies with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 ("GDPR"), the UK GDPR, and other applicable Data Protection Laws.
D) The Parties wish to lay down their respective rights and obligations.
E) The Parties acknowledge and agree that the Standard Contractual Clauses reproduced in Schedule 1 (together with any UK or Swiss Addendum, as applicable) apply only to the extent that the Company transfers Company Personal Data that is subject to the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection (“European Data”) to the Processor (or its Sub-processors) in a jurisdiction that has not been deemed “adequate” under the relevant law. If no such transfer occurs, the SCCs (and related addenda) impose no additional obligations on either Party.
IT IS AGREED AS FOLLOWS:
1. Definitions and Interpretation
Unless otherwise defined herein, capitalised terms and expressions used in this Agreement shall have the meanings given in the GDPR (or other applicable Data‑Protection Law) and their cognate terms shall be construed accordingly.
1.1 Agreement means this Data Processing Agreement and all Annexes and Schedules.
1.2 Company Personal Data means any Personal Data relating to the Company or the Company's end‑users, customers or employees processed in connection with the Principal Agreement.
1.3 Contracted Processor means a Sub‑processor.
1.4 Data Protection Laws means the GDPR, UK GDPR, CCPA/CPRA and any other privacy or data‑protection laws applicable to the Processing.
1.5 Data Transfer means (i) a transfer of Company Personal Data from the Controller to the Processor or a Contracted Processor, or (ii) an onward transfer of Company Personal Data from the Processor to a Sub‑processor or between two establishments of a Sub‑processor.
1.6 Services means the cloud‑hosted software services provided by the Processor, including Crowd Intelligence's SERP Intelligence Engine, Precision AI, Crowd Intelligence and such other services as are made available under the Principal Agreement.
1.7 Sub‑processor means any third party appointed by or on behalf of the Processor to Process Personal Data on behalf of the Controller.
2. Processing of Company Personal Data
The Processor shall (a) comply with all applicable Data Protection Laws in the Processing of Company Personal Data; and (b) process Company Personal Data only on the documented instructions of the Controller, except where otherwise required by applicable law. The Controller issues the instructions set out in this Section 2 and in Annex I and may issue additional documented instructions that are consistent with the Agreement.
2.2 Mandatory Details of the Processing (GDPR Art 28 § 3 & ICO Guidance)
The Parties record the following information about the Processing activities:
| Item | Detail |
|---|---|
| Subject matter | Provision, maintenance, security, optimisation and support of the Crowd Intelligence SaaS platform and related professional services. |
| Nature & Purpose | Collection, storage, organisation, analysis, transmission and deletion of Personal Data to: (i) deliver and improve the Services; (ii) provide customer success, billing and technical support; (iii) detect and prevent misuse or security incidents; (iv) comply with legal obligations; (v) produce internal analytics and reporting. |
| Duration | For the term of the Principal Agreement (including any renewals) and for the post‑termination retention period set out in Section 9 and Annex I, after which Personal Data will be deleted or returned. |
| Types of Personal Data | Names, business‑email addresses, device/IP logs, usage‑event data (page views, button clicks, session‑replay data), support‑ticket contents and other data uploaded by the Controller to the Services. No special‑category data is intentionally collected. |
| Categories of Data Subjects | (i) Authorised users of the Controller's Crowd Intelligence workspace (employees and contractors); (ii) visitors to the Controller's websites or apps whose interactions are captured in analytics events, all as further described in Annex I. |
| Controller's obligations & rights | As set out in the Principal Agreement, this DPA (including Sections 6, 10 and 11) and applicable Data Protection Laws. |
The details in this table supplement and incorporate by reference Annex I. In the event of conflict, the table and Annex I shall prevail over other provisions of Section 2.
2.3 Notification of Unlawful Instructions
If the Processor believes that an instruction from the Controller infringes Data Protection Laws, it shall promptly notify the Controller and may suspend the execution of the instruction until the Controller confirms or modifies it.
2.4 Permitted Processing
Without prejudice to Section 2.1, the Controller instructs the Processor to process Company Personal Data to: (a) provide the Services and related technical support; (b) fulfil legal or regulatory obligations; (c) perform internal tasks aimed at optimising security, privacy, confidentiality and functionality of the Services; (d) carry out internal reporting and financial administration.
2.5 Record‑keeping
The Processor shall maintain a written record of all categories of Processing activities carried out on behalf of the Controller, in accordance with GDPR Art 30(2).
3. Processor Personnel
Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor of any Contracted Processor who may have access to Company Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know / access the relevant Company Personal Data, as strictly necessary for the purposes of the Principal Agreement, and/or to comply with Data Protection Laws and other relevant legislation in the context of that individual's duties to the Contracted Processor, **and that before such access is granted each individual has:
• signed a written confidentiality agreement (or is otherwise under a statutory or professional obligation of confidentiality) that is no less protective than this Agreement and that remains in force both during and after the end of their engagement;
• been informed of the confidential nature of the Personal Data and received appropriate privacy-and-security training; and
• been notified that unauthorised disclosure or misuse of Personal Data may lead to disciplinary action, including termination of employment or contract;
Processor shall maintain written records evidencing the commitments in paragraph (1) and, upon reasonable request, make such records available to the Controller for inspection or audit in accordance with Section 10.
4. Security
In accordance with Article 32 (1) of the GDPR, the Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These measures shall be designed to protect the rights and freedoms of natural persons, considering the risks of varying likelihood and severity, including the risk of a Personal Data Breach.
The Processor shall also assess the risks associated with processing activities and apply measures that are consistent with the requirements set forth in Article 32 (1) GDPR, ensuring the security of Company Personal Data at all times.
5. Subprocessing
Subject to this Agreement, the Company grants general authorization to the Processor to engage Sub-processors and disclose or transfer Company Personal Data to them. The Company acknowledges and approves the list of Sub-processors outlined in the Sub-processors page in the Processor's website https://crowdintelligence.io/sub-processors, understanding that this list may be updated by the Processor regularly, in which case the company shall be informed by the Processor according to the sub-processors notification process. Furthermore, the Company authorizes the Processor to disclose and transfer Personal Data to any company within its corporate group.
Processor ensures that Sub-processors are subject to an agreement with Processor no less restrictive and protective than the present Agreement with respect to the protection of Company Personal Data to the extent applicable to the nature of the services provided by the Sub-processor.
Processor will remain liable for any breach of this agreement that is caused by an act, error, or omission of its sub-processors.
6. Data Subject Rights
6.1 Notification of Requests.
The Processor shall forward any Data Subject or Consumer request (including, without limitation, requests for access, deletion, correction, restriction, portability, or opt-out) to the Controller without undue delay and in any event within five (5) business days of receipt.
6.2 No Direct Response.
The Processor shall not itself respond to any such request except on the Controller’s documented instructions or where the Processor is legally required to do so; in that event, the Processor shall— to the extent permitted by applicable law—inform the Controller of that legal requirement before responding.
6.3 Assistance.
Taking into account the nature of the Processing, the Processor shall provide commercially reasonable assistance—including through self-service tooling where available—to enable the Controller to fulfil its obligations to respond to Data Subject or Consumer requests within the time limits set out in the GDPR, CPRA/CCPA, VCDPA, CPA, UCPA and any other applicable Data-Protection Laws.
7. Personal Data Breach
The Processor shall manage any Personal Data Breach in compliance with applicable Data Protection Laws and its internal Personal Data Breach procedures. In the event of a Personal Data Breach affecting Company Personal Data, the Processor shall notify the Company promptly and, in any event, without undue delay after becoming aware of the breach, and no later than forty-eight (48) hours unless a shorter period is mandated by applicable Data-Protection Laws. The notice shall contain sufficient information to enable the Company to meet its obligations under Articles 33 and 34 GDPR (or equivalent provisions of other Data-Protection Laws), including the nature of the breach, likely consequences, and any mitigation steps taken.
Where notification to the Company within 48 hours is not possible, the Processor shall provide the reasons for the delay and shall notify the Company as soon as reasonably practicable thereafter.
Processor shall co-operate with Company and take reasonable commercial steps as are directed by Company to assist in the investigation, mitigation and remediation of each such Personal Data Breach.
Each party shall bear the costs of the investigation, remediation, mitigation, and other related costs to the extent a Data Breach is caused by such party.
Each party shall bear the costs of any fines, penalties, damages, or other related amounts imposed by an authorized regulatory body, governmental agency, or court of competent jurisdiction to the extent arising from such party's breach of its obligations under this Agreement.
8. Data Protection Impact Assessment and Prior Consultation
Processor shall provide reasonable assistance to Company with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, which Controller reasonably considers to be required by article 35 or 36 of the GDPR or equivalent provisions of any other Data Protection Law, in each case solely in relation to Processing of Company Personal Data by, and taking into account the nature of the Processing and information available to, the Contracted Processors.
9. Deletion or return of Company Personal Data
9.1 Timing.
Within thirty (30) calendar days of (a) the Controller’s written instruction, or (b) the termination or expiry of the Principal Agreement (whichever occurs first), Processor shall, at the Controller’s choice, erase or return all Company Personal Data (including copies) that it Processes on behalf of the Controller.
9.2 Back-ups & Legal Holds.
Where Union, Member-State, or other applicable law requires retention beyond the 30-day period—or where the data reside solely in encrypted back-ups that are overwritten on a rolling basis not exceeding thirty (30) additional days—Processor may retain such data solely for the required period. During that time it will continue to apply this Agreement’s security and confidentiality obligations and will delete the data immediately after the retention requirement ends.
9.3 Format of Return.
If the Controller elects return, Processor will provide the data in a commonly used, machine-readable format (e.g., JSON or CSV) via secure download.
9.4 Certification.
Upon completion of deletion or return, Processor shall provide the Controller with a written certification that it has fulfilled its obligations under this Section 9.
10. Audit rights
Subject to this section 10, Processor shall make available to Company on request all information necessary to demonstrate compliance with this Agreement, and shall allow for and contribute to audits, including inspections, by Company or an auditor mandated by Company in relation to the Processing of the Company Personal Data by the Contracted Processors. Company shall not exercise its audit rights more than once per calendar year except following a Personal Data Breach or an instruction by a regulatory authority. Company shall give Processor at least sixty (60) days prior written notice of its intention to audit Processor pursuant to this Agreement. Audit shall be conducted during Processor's business hours, shall not disrupt Processor's operations and shall ensure the protection of the Company's, Processor's and other Data Subjects' Personal Data. Processor and Company shall mutually agree in advance on the date, scope, duration and security and confidentiality controls applicable to the audit. Company acknowledges that the signing of a non-disclosure agreement may be required by the Controller prior to the conduction of the audit.
Information and audit rights of Company only arise under section 10 to the extent that the Agreement does not otherwise give them information and audit rights meeting the relevant requirements of Data Protection Law.
11. Data Transfer
11.1 International Transfers Subject to Data Transfer Restrictions
12. U.S. State Privacy Laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, ICDPA, INCDPA)
The Parties acknowledge that, in addition to the GDPR, certain U.S. state privacy laws impose controller/processor (or business/service‑provider) requirements that must be set out in a written contract. For purposes of this Section 12, the Company is the Business / Controller, and the Processor is the Service Provider / Processor.
12.1 Purpose Limitation & Instruction Fidelity
The Processor shall not collect, retain, use, or disclose Company Personal Data ("CPD") for any purpose other than those specified in Section 2.2 of this Agreement or as otherwise permitted by the relevant state privacy law (e.g., to detect security incidents, prevent fraud, or comply with law). Processor will process CPD only on documented instructions from the Company.
12.2 No Sale, Share, or Targeted Advertising
Processor certifies that it (a) does not and will not Sell or Share CPD, as those terms are defined in Cal. Civ. Code § 1798.140 and analogous provisions of VCDPA, CPA, CTDPA, UCPA, ICDPA and INCDPA; and (b) will not use CPD for Targeted Advertising, profiling, or any other purpose outside the scope of this Agreement. Processor further certifies that it understands these restrictions and will comply with them.
12.3 Assistance with Consumer / Data‑Subject Requests
Taking into account the nature of the processing, Processor will provide reasonable assistance to the Company in fulfilling verified consumer/data‑subject requests to exercise rights of access, deletion, correction, opt‑out (sale, share, targeted advertising, or profiling), and data portability, including by:
Making available self‑service tooling or, where tooling is insufficient, processing Company’s written instructions within 10 business days to acknowledge; 45 days to fulfil (90 max with notice).
Promptly forwarding to Company (without responding) any request Processor receives directly from a consumer or data subject, unless legally required to respond.
12.4 Onward Transfers (Sub‑processor Flow‑Down)
Processor shall ensure that each authorised Sub‑processor:Qualifies as a Service Provider / Processor under the applicable state privacy law; and Enters into a written contract that (i) contains the same or more restrictive obligations as this Section 12, including the purpose limitation and no sale/share commitment, and (ii) otherwise complies with Cal. Civ. Code § 1798.140, Va. Code § 59.1‑579, Colo. Rev. Stat. § 6‑1‑1305, Conn. Gen. Stat. § 42‑522, Utah Code § 13‑61‑302, Utah Code § 13-61-302, Iowa Code ch. 715D (ICDPA), Ind. Code § 24-15 (INCDPA).
Processor remains fully liable for any act or omission of its Sub‑processors.
12.5 Security & Confidentiality
Processor shall implement and maintain reasonable administrative, technical, and physical safeguards designed to protect CPD as described in Annex II; ensure that persons authorised to process CPD are bound by appropriate confidentiality obligations; and notify Company of a security incident involving CPD without undue delay (see Section 7).
12.6 Assessments & Audits
Upon Company’s reasonable written request, Processor will (a) make available information reasonably necessary to demonstrate compliance with this Section 12, and (b) allow and cooperate with audits as set forth in Section 10. Any information disclosed under this clause is Confidential Information.
12.7 Deletion or Return of Data
Upon termination or expiration of the Principal Agreement, Processor will delete or return CPD in accordance with Section 9 of this DPA, unless retention is required by law.
12.8 Notice of Inability to Comply
Processor shall notify Company without undue delay if it makes a determination that it can no longer meet its obligations under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CPRA”), or any other applicable U.S. state privacy law. Upon receiving such notice, Company may direct Processor to take reasonable and appropriate steps to stop and remediate any unauthorised Processing of Company Personal Data.
13. General Terms
Compliance with Applicable Laws.
Processor will process Company Personal Data in accordance with this Agreement and Data Protection Laws applicable to its role under this Agreement. Processor is not responsible nor liable for complying with Data Protection Laws solely applicable to Company by virtue of its business or industry.
Confidentiality.
Each party must keep any information it receives about the other party and its business in connection with this Agreement ("Confidential Information") confidential and must not use or disclose that Confidential Information without the prior written consent of the other party except to the extent that:
(a) disclosure is required by law;
(b) the relevant information is already in the public domain through no fault of the Parties.
Limitation of Liability
Except for the Exclusions in paragraph 2 below, each party’s total aggregate liability to the other party arising out of or in connection with this Agreement—whether in contract, tort (including negligence), breach of statutory duty or otherwise—shall not exceed the lesser of:(a) one‑hundred‑thousand U.S. dollars (USD $100,000); or(b) the total fees paid or payable by the Company to the Processor under the Principal Agreement in the twelve (12) months preceding the event giving rise to the claim (the “Cap”).
Exclusions from the Cap. The Cap shall not apply to liability for:(i) death or personal injury caused by a party’s negligence;(ii) a party’s fraud or fraudulent misrepresentation;(iii) wilful misconduct or gross negligence;(iv) amounts payable under Section 7 (Personal Data Breach) in respect of third‑party claims or regulatory fines imposed directly on the other party as a result of the first party’s breach;(v) infringement of the other party’s intellectual‑property rights; or(vi) any liability that cannot legally be limited or excluded under applicable law.
Aggregation with Principal Agreement. Where the Principal Agreement contains a broader limitation‑of‑liability clause that applies to the same subject matter, that clause and this Section 13 (Limitation of Liability) shall be read together so that liability is capped in the aggregate and not duplicated across agreements.
Children & Sensitive Data
Age restriction. The Crowd Intelligence Services are not directed to children under sixteen (16) years of age, and neither Party intends for the platform to be used to collect personal data from such individuals (in compliance with COPPA and equivalent child‑protection laws).
Sensitive data exclusion. The Services are not intended to process “special categories of personal data” or other sensitive data within the meaning of GDPR Art 9, UK GDPR, or analogous U.S. state privacy statutes (e.g., data revealing racial or ethnic origin, health status, sexual orientation, union membership, genetic or biometric identifiers, or precise geolocation). Controller agrees that it will not, and will not permit its users to, intentionally submit such data to the Services unless the Parties first execute a written amendment that expressly governs that processing.
Notices.
All notices and communications given under this Agreement must be in writing and will be sent by email. Controller shall be notified by email sent to the address related to its use of the Services under the Principal Agreement. Processor shall be notified by email sent to the address: feco@crowdintelligence.io
EU & UK GDPR Representative (Art 27 GDPR/UK GDPR).
Pursuant to Article 27 GDPR and its UK equivalent, the Processor has appointed Federico Pascual, Wolliner Straße 64, Berlin, Germany (feco@crowdintelligence.io), as its representative in the European Union and in the United Kingdom. Data subjects and supervisory authorities may contact the Processor via these representatives on all issues related to processing under this Agreement. The Processor may update these details by written notice to the Controller or by publishing the new details at https://crowdintelligence.io/privacy.
Governing Law and Jurisdiction.
This Agreement shall be governed by governed by the laws of the State of Delaware, USA, without regard to the choice or conflicts of law provisions of any jurisdiction to the contrary, and disputed, actions, claims or causes of action arising out of or in connection with this Agreement, an order form, any document incorporated by reference, Crowd Intelligence technology, or the Services shall be subject to the exclusive jurisdiction of Delaware, US.
Annex I – Details of the Transfer (SCC 2021 Appendix)
A. List of Parties (Clause 13 & Annex I-A)
| Role | Party | Address | Contact | Activities relevant to the transfer |
|---|---|---|---|---|
| Data Exporter (Controller) | [Customer legal name] | [Street, City, Country] | [Name / e-mail / phone] | Uses Crowd Intelligence SaaS to create, analyse and store SEO and marketing-content, and views associated analytics dashboards. |
| Data Importer (Processor) | TinyMentions Inc. d/b/a Crowd Intelligence | 2810 N Church St PMB 37128, Wilmington, DE 19802-4447, USA | feco@crowdintelligence.io | Provides cloud-hosted SEO services to the exporter under the Principal Agreement. |
B. Description of Transfer (Annex I-B)
| Item | Description |
|---|---|
| Categories of data subjects | • Authorised users of the Exporter's Crowd Intelligence workspace (employees, contractors) • Website/app visitors whose on-site actions are captured in analytics events. |
| Categories of personal data | • Names, e-mail addresses, usage data (page views, button clicks, IP-based log data). • Session-replay recordings. These re-render the end-user’s on-screen interactions (mouse movements, clicks, scrolls, and typed text) and may incidentally capture personal information displayed or entered during a session. The Controller must configure masking/redaction and must not intentionally transmit special-category or sensitive data (e.g., payment-card details, government IDs, health information, passwords) via the Services. • Support-ticket contents (including chat transcripts). |
| Sensitive data | None expected. Exporter must not input special categories unless Processor is first notified in writing. |
| Frequency of transfer | Continuous and on-demand via secure API calls while the Subscription Service is active. |
| Nature & purpose of processing | Collecting, storing, organising, analysing, and providing dashboards for the above data in order to deliver, maintain, secure and improve Crowd Intelligence services; provide support; generate usage reports; and detect misuse. |
| Retention period | • Unless the Controller invokes § 9 to request deletion or return sooner, Processor retains the categories of data below for the periods stated. • Marketing & account-management contact data (names, business e-mails, usage history): retained for 24 months after the most recent customer interaction (extendable to 36 months for active sales discussions), unless the data subject objects earlier or a longer statutory obligation applies. • Support tickets, chat transcripts, and product-content data: retained for 360 days after account closure to facilitate bug investigation or legal defence, then deleted or anonymised. • Encrypted disaster-recovery backups: retained for up to 30 days on rolling rotation, after which the data is deleted. |
| Onward transfers | Limited to vetted Sub-processors listed in Processor's Privacy Policy and any others added in accordance with Section 5 of the DPA. |
C. Competent Supervisory Authority (Annex I-C)
The supervisory authority of the EU/EEA Member State in which the Data Exporter is established (or, if the exporter is not established in the EEA, the Irish Data Protection Commission by default).
Annex II – Technical & Organisational Measures (GDPR Art. 32 & SCC Annex II)
The Processor operates a proportionate information‑security programme inspired by recognised frameworks such as ISO 27001 and SOC 2 and appropriate to a seed‑stage SaaS business. Measures are reviewed regularly and will evolve as the company scales.
| Control Domain | Measures Implemented |
|---|---|
| Governance & Risk Management | Executive‑level oversight of security; documented security and privacy policies reviewed at least annually; risk‑assessment exercise performed at least once per year; third‑party risk management for key vendors. |
| Access Control | Password‑based authentication with strong complexity requirements; access is revoked promptly (target ≤ 24 h) on role change or termination. |
| Network Security | Segmented VPCs; Web Application Firewall (WAF); HTTPS enforced site‑wide; least‑privilege security‑group rules; automated alerts for unusual traffic patterns. |
| Logging & Monitoring | Centralised log aggregation with tamper‑resistant storage; automated alerting on defined security events. |
| Vulnerability & Patch Management | Routine vulnerability scans; operating‑system and dependency patches applied in a timely manner; critical CVEs addressed with an internal target of ≤ 24 h where feasible. |
| Business Continuity & Disaster Recovery | Backups stored in GCP; recovery‑point objective (RPO) 24 h, recovery‑time objective (RTO) 12 h; restoration procedures tested at least annually. |
| Incident Response | Documented playbooks; post‑incident root‑cause analysis; breach notification to Controller without undue delay and within 72 h of confirmation. |
| Sub‑processor Oversight | Due‑diligence review prior to engagement; contractual privacy and security obligations; periodic reassessment of sub‑processor controls. |
Annex III – Authorised Sub-Processors
Crowd Intelligence's list of sub-processors is available at https://crowdintelligence.io/sub-processors.
Schedule 1 – 2021 EU Standard Contractual Clauses (Controller → Processor & Processor → Sub‑processor)
The complete text of the European Commission’s Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 (Commission Implementing Decision (EU) 2021/914 of 4 June 2021) is reproduced verbatim on pages S‑1 to S‑23 of this Schedule. No in‑line amendments have been made. Module 2 (Controller → Processor) applies to transfers from the Company to TinyMentions Inc.; Module 3 applies to onward transfers from TinyMentions Inc. to authorised Sub‑processors. If you are viewing an HTML version of this Agreement, please download the PDF version to see Schedule 1 in full. The PDF is available at https://crowdintelligence.io/static/legal/dpa‑scc.pdf or on request via feco@crowdintelligence.io.