Data Processing Agreement
This Data Processing Agreement ("DPA") is incorporated by reference into the Terms of Service between you ("Controller" or "Customer") and Aboundo ("Processor"). By using the Service you agree to this DPA. For self-serve customers, no counter-signature is required; this DPA takes effect on account creation. Enterprise customers requiring a counter-signed DPA should contact legal@aboundo.example.
1. Definitions
- Personal Data: any information relating to an identified or identifiable natural person submitted through your forms.
- Processing: any operation performed on Personal Data (storage, retrieval, transmission, deletion).
- Controller: you, the Customer, who determines the purposes and means of processing.
- Processor: Aboundo, acting on your instructions.
- Sub-processor: a third party engaged by the Processor to assist in processing (see Section 5).
2. Scope and Role
Aboundo processes Personal Data submitted through forms you create solely to provide the Service as described in the Terms of Service. We act exclusively as a data processor on your documented instructions. We do not process Personal Data for our own purposes beyond what is necessary to operate the Service. Where you use a Gated Document form, this scope also includes storing the document file you upload for distribution to your visitors — a factual extension of the same storage and processing already covered by this DPA, not a separate legal framework.
3. Controller Obligations
You represent and warrant that:
- You have a lawful basis for collecting Personal Data through your forms.
- You have provided form visitors with an appropriate privacy notice.
- You will not instruct us to process Personal Data in a manner that violates applicable data protection law.
- You will promptly inform us of any changes to your instructions that may affect our processing obligations.
4. Processor Obligations
Aboundo agrees to:
- Process Personal Data only on your documented instructions.
- Ensure that personnel authorised to process Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organisational security measures (see Section 6).
- Notify you without undue delay after becoming aware of a Personal Data breach affecting your data, and where feasible within 48 hours, so that you have a meaningful window to meet your own 72-hour notification duty to a supervisory authority under Article 33 GDPR. Our notification will include, to the extent known at the time and updated as further information becomes available: a description of the nature of the incident; the categories and approximate number of data subjects and records concerned; the categories of Personal Data affected; the likely consequences of the breach; and the measures we have taken or propose to take to address it and mitigate its possible adverse effects.
- Assist you in fulfilling data subject rights requests (access, rectification, erasure, portability) to the extent we hold the relevant data.
- Provide reasonable assistance with your data protection impact assessments and any resulting prior consultation with a supervisory authority (Articles 35 and 36 GDPR), as described further in Section 8.
- Delete or return all Personal Data in our active production systems on termination of the Service, at your choice, within 30 days; Personal Data retained in automated backup archives follows the backup-specific timeline in Section 9, since a backup archive cannot be selectively edited without compromising its integrity for disaster-recovery purposes.
- Make available information necessary to demonstrate compliance with this DPA, and allow you to audit that compliance, subject to the following:
- You will first rely on our then-current security documentation and any third-party security certifications or audit reports we make available (for example, a SOC 2 report or ISO 27001 certification, to the extent and for the periods we hold one) to satisfy your audit rights, before requesting a further audit.
- If that documentation does not reasonably satisfy your audit rights, you may conduct a further audit, including an on-site inspection of facilities we control, no more than once in any 12-month period — except following a Personal Data breach affecting your data, or where a supervisory authority or applicable law requires a further audit.
- Before any audit, the parties will agree in advance on its scope, timing, and duration; each party's personnel involved will be bound by confidentiality (including a mutual non-disclosure agreement, if requested); and the audit will be conducted during business hours in a manner designed to minimise disruption to our business and other customers.
- You are responsible for the costs of an audit under this Section, except that we will bear our own reasonable costs of an audit that identifies a material breach of this DPA by us.
- We are not required to provide access to the systems, data, or premises of another customer (this Service is multi-tenant infrastructure shared across customers), or to disclose information subject to attorney-client privilege or a confidentiality obligation owed to a third party.
- Immediately inform you if, in Aboundo's opinion, an instruction you give infringes the GDPR or another applicable data protection provision — without suspending performance of that instruction unless you confirm, withdraw, or modify it, or applicable law otherwise requires us to stop.
5. Sub-processors
You grant general authorisation to engage sub-processors. We will provide notice (by email or in-app) before engaging a new sub-processor that handles your Personal Data, giving you the opportunity to object. Current sub-processors include:
- Salesforce, Inc. — CRM integration; engaged only if you configure the Salesforce integration. Salesforce acts as a further sub-processor under your control. Data is transferred to Salesforce's servers subject to Salesforce's own DPA.
- Stripe, Inc. — payment processing and subscription billing for your account with us. Billing actions redirect your browser to a page hosted entirely on Stripe's own domain; we do not embed Stripe scripts, tags, or payment fields on our own pages, and no billing or payment data passes through our servers as a result. Stripe collects and processes your (the Customer's) billing contact and payment information directly, on that page, as part of our own billing relationship with you; it does not process Personal Data submitted through your forms by your visitors.
- Resend — Transactional email (verification and password-reset emails to your users only; visitor submission data is not shared with Resend).
- Infrastructure / hosting provider — Database and compute hosting. Details available on request.
6. Security Measures
We maintain technical and organisational measures appropriate to the risk, including:
- Encryption in transit using TLS 1.2 or higher.
- Encryption at rest for sensitive credentials (OAuth tokens, integration secrets) using Fernet symmetric encryption, and — for the automated backup archives described in Section 9, once implemented — encryption at rest for those archives as well.
- Role-based access control within the Service itself: every user is assigned a role (tenant administrator, form builder, or, for our own personnel, provider) that determines which actions and data they can access, enforced on every request.
- Multi-factor authentication required for our personnel's administrative access to production systems and infrastructure.
- Access controls limiting data access to personnel who require it to perform their duties.
- A vulnerability management practice: monitoring for known vulnerabilities in the software components the Service relies on and applying security patches on a risk-based basis.
- Audit logging of administrative actions.
- Regular review of security practices.
7. International Data Transfers
Providing the Service involves transferring Personal Data outside the European Economic Area ("EEA") and the United Kingdom to Aboundo and, where applicable, its sub-processors and hosting infrastructure. This Section is the binding transfer mechanism for those transfers, not a statement of future intent.
EU transfers — Standard Contractual Clauses. For transfers of Personal Data from the EEA, the parties incorporate by reference, and this DPA constitutes the parties' agreement to, the Standard Contractual Clauses approved by the European Commission under Implementing Decision (EU) 2021/914 of 4 June 2021 (the "EU SCCs"), completed as follows:
- Module: Module Two (Controller to Processor) — reflecting your role as Controller and Aboundo's role as Processor under Section 2 of this DPA.
- Clause 7 (Docking clause): Not used.
- Clause 9 (Use of sub-processors): Option 2 (general written authorisation), consistent with Section 5 of this DPA.
- Clause 11(a) (Independent redress body): The optional wording is not used.
- Clause 17 (Governing law): The laws of the EU member state in which you, as data exporter, are established; if you are not established in an EU member state, the laws of Ireland.
- Clause 18(b) (Choice of forum and jurisdiction): The courts of the member state identified under Clause 17.
- Annex I.A (List of Parties): You (Customer) as data exporter, and Aboundo as data importer, as identified in the introductory paragraph of this DPA.
- Annex I.B (Description of Transfer): As set out in Schedule 1 (Details of Processing) to this DPA.
- Annex I.C (Competent Supervisory Authority): The supervisory authority of the EU member state identified under Clause 17, determined in accordance with Clause 13 of the EU SCCs.
- Annex II (Technical and Organisational Measures): As set out in Section 6 (Security Measures) of this DPA.
- Annex III (List of Sub-processors): As set out in Section 5 (Sub-processors) of this DPA.
UK transfers — International Data Transfer Addendum. For transfers of Personal Data from the United Kingdom, the parties incorporate by reference the UK Information Commissioner's International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0, in force 21 March 2022) (the "UK Addendum"). We use the UK Addendum, which attaches to and modifies the EU SCCs above for transfers subject to the UK GDPR, rather than a standalone International Data Transfer Agreement, since we have already incorporated the EU SCCs above and the Addendum is designed to attach directly to them; it serves the same function a standalone IDTA would. Where the UK Addendum calls for details not otherwise specified above, those details are as set out in the corresponding EU SCC Annex referenced above, read as applying under the UK GDPR.
EU-U.S. Data Privacy Framework. Aboundo is not currently a certified participant in the EU-U.S. Data Privacy Framework, its UK Extension, or the Swiss-U.S. Data Privacy Framework. We are not relying on any of these as a transfer mechanism today. If Aboundo becomes a certified participant, we will update this Section to say so and will rely on that certification as an additional or alternative transfer mechanism, as applicable; until then, the EU SCCs and UK Addendum incorporated above are the operative mechanism.
Sub-processor transfers. Where a sub-processor listed in Section 5 processes Personal Data outside the EEA or United Kingdom, we require that sub-processor to be bound by the EU SCCs, the UK Addendum, or an onward-transfer mechanism providing equivalent protection (such as its own EU SCCs with its customers, or a valid Data Privacy Framework certification), before we transfer Personal Data to it.
Other jurisdictions. For a transfer subject to a similar cross-border restriction under another jurisdiction's data protection law, we will use a comparable mechanism recognised under that law upon request.
8. Data Subject Rights; DPIA and Supervisory Authority Assistance
If you receive a data subject rights request relating to Personal Data processed through the Service, we will cooperate to the extent reasonably necessary. You remain responsible for responding to data subjects as controller.
We will also provide you with reasonable assistance, taking into account the nature of our processing and the information reasonably available to us, with: (a) data protection impact assessments under Article 35 GDPR relating to your use of the Service, where you have determined one is required, and (b) any resulting prior consultation with a supervisory authority under Article 36 GDPR. We will provide this assistance following your written request, at your expense (at our then-current standard rates, or as otherwise agreed between the parties). This Section does not require us to conduct the assessment or consultation on your behalf, or to disclose information about our other customers or our business generally; where the assistance you need is already addressed elsewhere in this DPA (for example, the security measures in Section 6 or the sub-processor details in Section 5), we will point you to that Section rather than duplicate it.
9. Data Retention and Deletion
Personal Data is retained for the duration of your subscription, including during any period where your subscription has lapsed for non-payment — a lapse by itself does not result in deletion of Personal Data. Upon termination, we will make your data available for export for 30 days. After that period, Personal Data is removed from our active production systems in the ordinary course, except where we are required or permitted by law to retain it longer, or where you and we have agreed otherwise in writing.
Backup archives. The timeline above describes our active production systems. Aboundo also maintains automated backup archives for disaster-recovery purposes. We do not selectively remove Personal Data from an existing backup archive — doing so would compromise the archive's integrity for its intended disaster-recovery purpose. Instead, from the point Personal Data is deleted from our active production systems: (a) it is immediately isolated from production use and rendered un-indexed and inaccessible in the ordinary course of business; and (b) it is permanently and securely overwritten no later than our standard backup rotation schedule, which does not exceed 90 days. We will not restore Personal Data from a backup except to recover from data loss, a security incident, or as otherwise necessary to operate the Service or comply with law; if Personal Data you asked us to delete is inadvertently restored as part of such a recovery, we will delete it again promptly.
10. Liability; Order of Precedence
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. Nothing in this DPA limits either party's liability to data subjects or supervisory authorities under applicable data protection law.
This DPA is incorporated into, and forms part of, the Terms of Service (and, where applicable, the Master Subscription Agreement). If there is a conflict between this DPA and the Terms of Service (or Master Subscription Agreement) regarding the processing of Personal Data — including breach notification timing, data retention or deletion periods, or security controls — the terms of this DPA prevail to the extent of that conflict. For any other matter not concerning the processing of Personal Data (for example, fees, general limitation of liability, or governing law), the Terms of Service (or Master Subscription Agreement, if applicable) prevails.
11. Governing Law
This DPA is governed by the same law as the Terms of Service. For customers subject to GDPR, this DPA is also intended to satisfy the requirements of Article 28 of the GDPR.
12. CCPA/CPRA Service Provider Terms
To the extent Aboundo processes Personal Data as a "service provider" on Customer's behalf under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), Aboundo certifies that it understands the restrictions in Cal. Civ. Code § 1798.140(ag) and will comply with them. Specifically, Aboundo will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than performing the Service under this DPA and the Terms of Service, including any commercial purpose other than performing that service; (c) retain, use, or disclose Personal Data outside the direct business relationship between Aboundo and Customer; or (d) combine Personal Data with personal information Aboundo receives from or on behalf of another source, except as permitted under the CCPA/CPRA. Aboundo will notify Customer if it determines it can no longer meet its obligations under this Section. This Section applies only to Personal Data Aboundo processes on Customer's behalf as a service provider (i.e., Visitor Data); it does not apply to Customer's own account and billing information, which Aboundo processes as a business in its own right, as described in the Privacy Policy.
13. Contact
Data protection enquiries: privacy@aboundo.example.
Schedule 1: Details of Processing (GDPR Article 28(3))
This Schedule sets out the details required by Article 28(3) GDPR for the processing Aboundo carries out as Processor of Personal Data submitted through the forms you (Controller) build using the Service ("Visitor Data"). It does not cover your own account, billing, or user-administration data, which Aboundo processes as a business/controller in its own right — see the Privacy Policy.
1. Subject matter of processing. Aboundo's provision of a hosted and/or embeddable lead-capture and Gated Document form platform, which collects, stores, organises, displays, exports, and — only where you configure it — forwards Visitor Data to a third-party integration, on your instructions.
2. Duration of processing. For the duration of your subscription, including any period where it has lapsed for non-payment but has not been terminated, and thereafter for the 30-day post-termination export window described in Section 9, after which Personal Data is removed from our systems in the ordinary course, except where we are required or permitted by law to retain it longer.
3. Nature and purpose of processing. Collection (via form submission), storage, organisation, retrieval, and display (in your dashboard and exports), and — only where you configure it — transmission to a third-party integration (currently Salesforce). Processing is carried out by automated means, for the sole purpose of providing the Service to you as described in the Terms of Service; Aboundo does not process Visitor Data for its own separate purposes, profiling, or advertising.
4. Categories of data subjects. Visitors and leads who submit a form you have built using the Service — your forms' respondents, prospective customers, or other individuals you choose to collect information from. This does not include your own Authorised Users (your staff who log in to the admin application), whose account data Aboundo processes as a business/controller in its own right, as described in the Privacy Policy.
5. Categories of personal data. The specific fields collected are determined by you, the Controller, through the fields you add to each form; Aboundo does not dictate or limit which categories you may collect beyond the acceptable-use restrictions in the Terms of Service. In practice, this typically includes: identifiers such as first name, last name, email address, and phone number (available as predefined fields you can add to any form); commercial/business information such as company name; free-text content in any message or custom text/textarea field you add; and responses to any custom field you define (of type text, email, phone, number, select, checkbox, or textarea). For Gated Document forms, it also includes the fact that a named visitor downloaded a specific document. Where you upload a document for a Gated Document form, Aboundo stores that file as instructed but does not inspect, index, or otherwise process its contents, which may contain personal data of your own choosing or origin. Aboundo does not request or require special categories of personal data (Art. 9 GDPR), and, per Section 3 (Controller Obligations) and the Terms of Service, you must not collect such data through the Service without an appropriate legal basis and safeguards. Aboundo's underlying infrastructure/hosting provider may incidentally log visitors' IP addresses as part of ordinary web-server request logging; the Service's application layer does not store IP address as a submission field or make it available to you.
The obligations and rights of the Controller in respect of this processing are set out in Sections 3, 4, and 8 of this DPA.