Aboundo
Terms Privacy DPA Cookies MSA Sign in

Data Processing Agreement

Effective date: 2026-08-09  ·  Version 1.11

This Data Processing Agreement ("DPA") is incorporated by reference into the Terms of Service between you ("Controller" or "Customer") and Aboundo ("Processor"). By using the Service you agree to this DPA. For self-serve customers, no counter-signature is required; this DPA takes effect on account creation. Enterprise customers requiring a counter-signed DPA should contact legal@aboundo.example.

1. Definitions

2. Scope and Role

Aboundo processes Personal Data submitted through forms you create solely to provide the Service as described in the Terms of Service. We act exclusively as a data processor on your documented instructions. We do not process Personal Data for our own purposes beyond what is necessary to operate the Service. Where you use a Gated Document form, this scope also includes storing the document file you upload for distribution to your visitors — a factual extension of the same storage and processing already covered by this DPA, not a separate legal framework.

3. Controller Obligations

You represent and warrant that:

4. Processor Obligations

Aboundo agrees to:

5. Sub-processors

You grant general authorisation to engage sub-processors. We will provide notice (by email or in-app) before engaging a new sub-processor that handles your Personal Data, giving you the opportunity to object. Current sub-processors include:

6. Security Measures

We maintain technical and organisational measures appropriate to the risk, including:

7. International Data Transfers

Providing the Service involves transferring Personal Data outside the European Economic Area ("EEA") and the United Kingdom to Aboundo and, where applicable, its sub-processors and hosting infrastructure. This Section is the binding transfer mechanism for those transfers, not a statement of future intent.

EU transfers — Standard Contractual Clauses. For transfers of Personal Data from the EEA, the parties incorporate by reference, and this DPA constitutes the parties' agreement to, the Standard Contractual Clauses approved by the European Commission under Implementing Decision (EU) 2021/914 of 4 June 2021 (the "EU SCCs"), completed as follows:

UK transfers — International Data Transfer Addendum. For transfers of Personal Data from the United Kingdom, the parties incorporate by reference the UK Information Commissioner's International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0, in force 21 March 2022) (the "UK Addendum"). We use the UK Addendum, which attaches to and modifies the EU SCCs above for transfers subject to the UK GDPR, rather than a standalone International Data Transfer Agreement, since we have already incorporated the EU SCCs above and the Addendum is designed to attach directly to them; it serves the same function a standalone IDTA would. Where the UK Addendum calls for details not otherwise specified above, those details are as set out in the corresponding EU SCC Annex referenced above, read as applying under the UK GDPR.

EU-U.S. Data Privacy Framework. Aboundo is not currently a certified participant in the EU-U.S. Data Privacy Framework, its UK Extension, or the Swiss-U.S. Data Privacy Framework. We are not relying on any of these as a transfer mechanism today. If Aboundo becomes a certified participant, we will update this Section to say so and will rely on that certification as an additional or alternative transfer mechanism, as applicable; until then, the EU SCCs and UK Addendum incorporated above are the operative mechanism.

Sub-processor transfers. Where a sub-processor listed in Section 5 processes Personal Data outside the EEA or United Kingdom, we require that sub-processor to be bound by the EU SCCs, the UK Addendum, or an onward-transfer mechanism providing equivalent protection (such as its own EU SCCs with its customers, or a valid Data Privacy Framework certification), before we transfer Personal Data to it.

Other jurisdictions. For a transfer subject to a similar cross-border restriction under another jurisdiction's data protection law, we will use a comparable mechanism recognised under that law upon request.

8. Data Subject Rights; DPIA and Supervisory Authority Assistance

If you receive a data subject rights request relating to Personal Data processed through the Service, we will cooperate to the extent reasonably necessary. You remain responsible for responding to data subjects as controller.

We will also provide you with reasonable assistance, taking into account the nature of our processing and the information reasonably available to us, with: (a) data protection impact assessments under Article 35 GDPR relating to your use of the Service, where you have determined one is required, and (b) any resulting prior consultation with a supervisory authority under Article 36 GDPR. We will provide this assistance following your written request, at your expense (at our then-current standard rates, or as otherwise agreed between the parties). This Section does not require us to conduct the assessment or consultation on your behalf, or to disclose information about our other customers or our business generally; where the assistance you need is already addressed elsewhere in this DPA (for example, the security measures in Section 6 or the sub-processor details in Section 5), we will point you to that Section rather than duplicate it.

9. Data Retention and Deletion

Personal Data is retained for the duration of your subscription, including during any period where your subscription has lapsed for non-payment — a lapse by itself does not result in deletion of Personal Data. Upon termination, we will make your data available for export for 30 days. After that period, Personal Data is removed from our active production systems in the ordinary course, except where we are required or permitted by law to retain it longer, or where you and we have agreed otherwise in writing.

Backup archives. The timeline above describes our active production systems. Aboundo also maintains automated backup archives for disaster-recovery purposes. We do not selectively remove Personal Data from an existing backup archive — doing so would compromise the archive's integrity for its intended disaster-recovery purpose. Instead, from the point Personal Data is deleted from our active production systems: (a) it is immediately isolated from production use and rendered un-indexed and inaccessible in the ordinary course of business; and (b) it is permanently and securely overwritten no later than our standard backup rotation schedule, which does not exceed 90 days. We will not restore Personal Data from a backup except to recover from data loss, a security incident, or as otherwise necessary to operate the Service or comply with law; if Personal Data you asked us to delete is inadvertently restored as part of such a recovery, we will delete it again promptly.

10. Liability; Order of Precedence

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. Nothing in this DPA limits either party's liability to data subjects or supervisory authorities under applicable data protection law.

This DPA is incorporated into, and forms part of, the Terms of Service (and, where applicable, the Master Subscription Agreement). If there is a conflict between this DPA and the Terms of Service (or Master Subscription Agreement) regarding the processing of Personal Data — including breach notification timing, data retention or deletion periods, or security controls — the terms of this DPA prevail to the extent of that conflict. For any other matter not concerning the processing of Personal Data (for example, fees, general limitation of liability, or governing law), the Terms of Service (or Master Subscription Agreement, if applicable) prevails.

11. Governing Law

This DPA is governed by the same law as the Terms of Service. For customers subject to GDPR, this DPA is also intended to satisfy the requirements of Article 28 of the GDPR.

12. CCPA/CPRA Service Provider Terms

To the extent Aboundo processes Personal Data as a "service provider" on Customer's behalf under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), Aboundo certifies that it understands the restrictions in Cal. Civ. Code § 1798.140(ag) and will comply with them. Specifically, Aboundo will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than performing the Service under this DPA and the Terms of Service, including any commercial purpose other than performing that service; (c) retain, use, or disclose Personal Data outside the direct business relationship between Aboundo and Customer; or (d) combine Personal Data with personal information Aboundo receives from or on behalf of another source, except as permitted under the CCPA/CPRA. Aboundo will notify Customer if it determines it can no longer meet its obligations under this Section. This Section applies only to Personal Data Aboundo processes on Customer's behalf as a service provider (i.e., Visitor Data); it does not apply to Customer's own account and billing information, which Aboundo processes as a business in its own right, as described in the Privacy Policy.

13. Contact

Data protection enquiries: privacy@aboundo.example.


Schedule 1: Details of Processing (GDPR Article 28(3))

This Schedule sets out the details required by Article 28(3) GDPR for the processing Aboundo carries out as Processor of Personal Data submitted through the forms you (Controller) build using the Service ("Visitor Data"). It does not cover your own account, billing, or user-administration data, which Aboundo processes as a business/controller in its own right — see the Privacy Policy.

1. Subject matter of processing. Aboundo's provision of a hosted and/or embeddable lead-capture and Gated Document form platform, which collects, stores, organises, displays, exports, and — only where you configure it — forwards Visitor Data to a third-party integration, on your instructions.

2. Duration of processing. For the duration of your subscription, including any period where it has lapsed for non-payment but has not been terminated, and thereafter for the 30-day post-termination export window described in Section 9, after which Personal Data is removed from our systems in the ordinary course, except where we are required or permitted by law to retain it longer.

3. Nature and purpose of processing. Collection (via form submission), storage, organisation, retrieval, and display (in your dashboard and exports), and — only where you configure it — transmission to a third-party integration (currently Salesforce). Processing is carried out by automated means, for the sole purpose of providing the Service to you as described in the Terms of Service; Aboundo does not process Visitor Data for its own separate purposes, profiling, or advertising.

4. Categories of data subjects. Visitors and leads who submit a form you have built using the Service — your forms' respondents, prospective customers, or other individuals you choose to collect information from. This does not include your own Authorised Users (your staff who log in to the admin application), whose account data Aboundo processes as a business/controller in its own right, as described in the Privacy Policy.

5. Categories of personal data. The specific fields collected are determined by you, the Controller, through the fields you add to each form; Aboundo does not dictate or limit which categories you may collect beyond the acceptable-use restrictions in the Terms of Service. In practice, this typically includes: identifiers such as first name, last name, email address, and phone number (available as predefined fields you can add to any form); commercial/business information such as company name; free-text content in any message or custom text/textarea field you add; and responses to any custom field you define (of type text, email, phone, number, select, checkbox, or textarea). For Gated Document forms, it also includes the fact that a named visitor downloaded a specific document. Where you upload a document for a Gated Document form, Aboundo stores that file as instructed but does not inspect, index, or otherwise process its contents, which may contain personal data of your own choosing or origin. Aboundo does not request or require special categories of personal data (Art. 9 GDPR), and, per Section 3 (Controller Obligations) and the Terms of Service, you must not collect such data through the Service without an appropriate legal basis and safeguards. Aboundo's underlying infrastructure/hosting provider may incidentally log visitors' IP addresses as part of ordinary web-server request logging; the Service's application layer does not store IP address as a submission field or make it available to you.

The obligations and rights of the Controller in respect of this processing are set out in Sections 3, 4, and 8 of this DPA.