By login in, you agree to have read and accept our terms and conditions.

Home Inspiration Legal
  • AI Builder
  • Templates
  • Plans
Book a Demo14-Day Free Trial
Log in
Book a Demo14-Day Free Trial

Platform

  • Platform OverviewCreate, personalize, and optimize interactive experiences
  • EnterpriseSecurity, control, and scale for enterprise teams
  • Data, Personalization & AnalyticsCapture data and improve performance with insights
  • FeaturesExplore all capabilities to build and launch experiences
  • IntegrationsConnect with your CRM and marketing tools

Services

  • Professional ServicesStrategy, design, and expert support for your interactive experiences
  • Agency PartnershipPartner with Dot.vu to create interactive experiences for your clients

BY USE CASE

  • Lead Generation & QualificationCapture and qualify high-intent leads
  • Product DiscoveryGuide users to the right product
  • Interactive PromotionsBoost engagement with interactive campaigns
  • Sales EnablementSupport sales with interactive tools
  • Content MarketingTurn content into engaging experiences
  • Customer EducationGuide users through interactive learning

BY INDUSTRY

  • SaaS & TechnologyAccelerate product understanding and adoption
  • Retail, eCommerce & Consumer GoodsDrive conversions and product discovery
  • Healthcare, Life Sciences & PharmaceuticalsEducate and engage with compliant experiences
  • Financial Services, Insurance & Real EstateBuild trust and simplify complex offerings
  • Entertainment & MediaIncrease audience engagement
  • ManufacturingSimplify products and capture qualified leads

Explore More

View All Solutions→

LEARN

  • BlogInsights on interactive experiences
  • Guides & PlaybooksDeep dives and best practices

SUPPORT

  • Help CenterDocumentation and tutorials
  • FAQQuick answers to common questions

COMPANY

  • About usOur mission and vision
  • Case StudiesSee how leading brands achieve results
  • Awards & RecognitionIndustry recognition and achievements
  • CareersJoin our team
  • News / PRLatest updates
  • ContactGet in touch
  • AI Builder
  • Platform

    • Platform OverviewCreate, personalize, and optimize interactive experiences
    • EnterpriseSecurity, control, and scale for enterprise teams
    • Data, Personalization & AnalyticsCapture data and improve performance with insights
    • FeaturesExplore all capabilities to build and launch experiences
    • IntegrationsConnect with your CRM and marketing tools

    Services

    • Professional ServicesStrategy, design, and expert support for your interactive experiences
    • Agency PartnershipPartner with Dot.vu to create interactive experiences for your clients
  • BY USE CASE

    • Lead Generation & QualificationCapture and qualify high-intent leads
    • Product DiscoveryGuide users to the right product
    • Interactive PromotionsBoost engagement with interactive campaigns
    • Sales EnablementSupport sales with interactive tools
    • Content MarketingTurn content into engaging experiences
    • Customer EducationGuide users through interactive learning

    BY INDUSTRY

    • SaaS & TechnologyAccelerate product understanding and adoption
    • Retail, eCommerce & Consumer GoodsDrive conversions and product discovery
    • Healthcare, Life Sciences & PharmaceuticalsEducate and engage with compliant experiences
    • Financial Services, Insurance & Real EstateBuild trust and simplify complex offerings
    • Entertainment & MediaIncrease audience engagement
    • ManufacturingSimplify products and capture qualified leads

    Explore More

    View All Solutions→
  • Templates
  • Plans
  • LEARN

    • BlogInsights on interactive experiences
    • Guides & PlaybooksDeep dives and best practices

    SUPPORT

    • Help CenterDocumentation and tutorials
    • FAQQuick answers to common questions

    COMPANY

    • About usOur mission and vision
    • Case StudiesSee how leading brands achieve results
    • Awards & RecognitionIndustry recognition and achievements
    • CareersJoin our team
    • News / PRLatest updates
    • ContactGet in touch
Book a Demo14-Day Free TrialLog in

Data Processing Addendum

  • Terms of Use
  • Terms of Service
  • Acceptable Use Policy
  • Privacy Policy
  • Cookie Policy
  • Data Processing Addendum
  • Incident Reporting

Need a signed copy of our DPA? You can get it here.


This Dot.vu ("Vendor") Data Processing Addendum ("DPA") forms part of the agreement governing Company's use of the Services (the "Agreement"). The Agreement is either the Dot.vu Terms of Service available at https://dot.vu/terms-of-service or a separately signed master services agreement, order, or other agreement that incorporates this DPA and governs Company's use of the Services. This DPA governs Vendor's Processing of Company Personal Data on behalf of Company in connection with the Services.

We periodically update these terms. If you have an active Dot.vu subscription, we will let you know when we do via an email or in-app notification.

Capitalized terms not defined in this DPA have the meanings given in the Agreement.

Index

  1. Definitions
  2. Authority
  3. Processing of Company Personal Data
  4. AI-Assisted Editing Features
  5. Vendor and Vendor Affiliate Personnel
  6. Security
  7. Subprocessing
  8. Data Subject Rights
  9. Personal Data Breach
  10. Data Protection Impact Assessment and Prior Consultation
  11. Data Retention and Deletion
  12. Audit rights
  13. Restricted Transfers
  14. General Terms
  15. ANNEX 1: DETAILS OF PROCESSING OF COMPANY PERSONAL DATA
  16. ANNEX 2: TECHNICAL AND ORGANISATIONAL MEASURES


  1. Definitions

    1. In this Addendum, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:
      1. "EU GDPR" means Regulation (EU) 2016/679.
      2. "UK GDPR" means the EU GDPR as it forms part of the law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended.
      3. "Applicable Laws" means the laws and regulations applicable to a party's performance of the Agreement, including applicable Data Protection Laws;
      4. "Instruction" means the written, documented instruction, issued by Controller to Processor, and directing the same to perform a specific action with regard to Personal Data (including, but not limited to, depersonalizing, blocking, deletion, making available).
      5. "Company Affiliate" means an entity that owns or controls, is owned or controlled by, or is under common control or ownership with Company, where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise;
      6. "Company Group Member" means Company or any Company Affiliate;
      7. "Company Personal Data" means any Personal Data Processed by a Contracted Processor on behalf of a Company Group Member pursuant to or in connection with the Agreement;
      8. "Contracted Processor" means Vendor or a Subprocessor;
      9. "Data Protection Laws" means all data protection and privacy laws applicable to the Processing of Company Personal Data under the Agreement, including, where applicable, the EU GDPR, the UK GDPR, the UK Data Protection Act 2018, and applicable national laws implementing or supplementing them.
      10. "EEA" means the European Economic Area;
      11. "Restricted Transfer" means a transfer of Company Personal Data to a country that is not recognized as providing an adequate level of protection under the applicable Data Protection Laws, where the transfer would be prohibited without an approved transfer mechanism.
      12. "Services" means the services and other activities to be supplied to or carried out by or on behalf of Vendor for Company Group Members pursuant to the Agreement;
      13. "Standard Contractual Clauses" or "EU SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended, replaced, or superseded.
      14. "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office under section 119A of the Data Protection Act 2018, as amended, replaced, or superseded.
      15. "Subprocessor" means any person (including any third party and any Vendor Affiliate, but excluding an employee of Vendor or any of its sub-contractors) appointed by or on behalf of Vendor or any Vendor Affiliate to Process Personal Data on behalf of any Company Group Member in connection with the Agreement;
      16. "Vendor Affiliate" means an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Vendor, where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise.
      17. "Dot.vu Sub-Processors" means the list of Dot.vu Sub-Processors available at https://dot.vu/sub-processors
    2. The terms, "Commission", "Controller", "Data Subject", "Member State", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" shall have the same meaning as in the EU GDPR and, where applicable, the UK GDPR, and their cognate terms shall be construed accordingly.
    3. The word "include" shall be construed to mean include without limitation, and cognate terms shall be construed accordingly.
  2. Authority

    Vendor warrants and represents that, before any Vendor Affiliate Processes any Company Personal Data on behalf of any Company Group Member, Vendor's entry into this Addendum as agent for and on behalf of that Vendor Affiliate will have been duly and effectively authorised (or subsequently ratified) by that Vendor Affiliate.

  3. Processing of Company Personal Data

    1. Vendor and each Vendor Affiliate shall:
      1. comply with all applicable Data Protection Laws in the Processing of Company Personal Data; and
      2. not Process Company Personal Data other than on the relevant Company Group Member’s documented instructions unless Processing is required by Applicable Laws to which the relevant Contracted Processor is subject, in which case Vendor or the relevant Vendor Affiliate shall to the extent permitted by Applicable Laws inform the relevant Company Group Member of that legal requirement before the relevant Processing of that Personal Data.
    2. Each Company Group Member:
      1. instructs Vendor and each Vendor Affiliate (and authorises Vendor and each Vendor Affiliate to instruct each Subprocessor) to
        1. Process Company Personal Data in accordance with the Agreement, this DPA, and Company's documented use and configuration of the Services; and
        2. make any Restricted Transfer only in accordance with the section titled "Restricted Transfers."
      2. warrants and represents that it is and will at all relevant times remain duly and effectively authorised to give the instruction set out in section 3.2.1 on behalf of each relevant Company Affiliate.
    3. Annex 1 describes the subject matter and duration, nature and purpose, types of Personal Data, and categories of Data Subjects relevant to Vendor's Processing of Company Personal Data. Company may provide additional documented instructions where reasonably necessary to reflect its use of the Services, provided those instructions are consistent with the Agreement and do not materially change the scope or cost of the Services without the parties' agreement. Annex 1 forms part of this DPA and does not authorize Processing for purposes other than those permitted by the Agreement and this DPA.
  4. AI-Assisted Editing Features

    1. Scope and instructions. "AI-Assisted Editing Features" means AI-powered functionality made available to authorized users within Vendor's editing application to generate, explain, summarize, configure, or revise interactive components, configurations, or code. For purposes of this section, "AI-Assisted Editing Data" means inputs, relevant conversation context, uploaded images or files, generated responses, configurations or code, error information, and related monitoring records processed in connection with these features. AI-Assisted Editing Features are not intended for the Processing of Personal Data. Company shall not include Personal Data in AI-Assisted Editing Data unless Company is authorized to submit it and has complied with applicable Data Protection Laws. If and to the extent AI-Assisted Editing Data contains Company Personal Data, Company instructs Vendor to Process that Company Personal Data to provide, maintain, secure, monitor, and troubleshoot the features.
    2. Access boundaries. AI-Assisted Editing Features operate on content actively submitted by an authorized user and the conversation context required for the user's request. They do not automatically access project content, product feeds, or Personal Data collected from Company's end users unless the relevant feature expressly identifies that access and Company enables or directs it. A generated component may subsequently interact with other Services or Company-configured data sources; that later interaction is not model processing unless the feature expressly states otherwise.
    3. AI service providers and locations. Vendor may disclose the minimum AI-Assisted Editing Data necessary to the Subprocessors identified on the Dot.vu Sub-Processors page. Vendor will configure model inference and model-service storage for these features to occur in the European Union. Vendor-operated monitoring may occur in the EEA or United Kingdom. Vendor will not materially change these location commitments without updating its disclosures, providing any notice required under the section titled "Subprocessing," and implementing a lawful transfer mechanism where required. Personnel access and service metadata remain subject to the other provisions of this DPA.
    4. No model training. Vendor will not use, or permit an AI service provider to use, Company Personal Data submitted to or generated by AI-Assisted Editing Features to train, fine-tune, or otherwise improve any model for Vendor, the provider, or other customers. Customer-specific training or fine-tuning may occur only if separately agreed and instructed by Company in writing.
    5. Retention. Vendor retains AI-assisted conversations and their associated prompts, uploads, responses, and error information in the live application database for no longer than 24 months after the most recent interaction with the relevant conversation. A new interaction resets that period for that conversation and its associated records. Content that an authorized user accepts or incorporates into a project is thereafter retained as project content under the Data Retention Policy. Monitoring traces, which may contain prompts, uploads, responses, generated code, and error information, are retained for no longer than one month from creation. Encrypted routine backups may retain deleted records for up to ten days, during which they are isolated from ordinary use and are re-deleted if restored. Following termination or cessation of the relevant Services, the Data Retention Policy applies.
    6. Deletion. Deleting a conversation, associated component, project, or account removes the associated AI-assisted conversation records and uploads from the live application database. Deletion from monitoring records and encrypted backups occurs through the expiry periods in paragraph 5, unless a shorter period is required by Data Protection Laws. A documented Company deletion request under the section titled "Data Retention and Deletion" applies to AI-Assisted Editing Data across those systems, subject to the same expiry and isolation controls.
    7. Operational changes. Vendor may change models, model versions, or technical routing without amending this DPA, provided the change does not materially expand the categories or purposes of Processing, reduce the protections in this section, or violate the location commitment above. New Subprocessors remain subject to the section titled "Subprocessing."
  5. Vendor and Vendor Affiliate Personnel

    Vendor and each Vendor Affiliate shall take reasonable steps to ensure the reliability of any employee, agent or contractor of any Contracted Processor who may have access to the Company Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know or access the relevant Company Personal Data, as strictly necessary for the purposes of the Agreement, and to comply with Applicable Laws in the context of that individual's duties to the Contracted Processor, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.

  6. Security

    1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Vendor and each Vendor Affiliate shall in relation to the Company Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the EU GDPR.
    2. In assessing the appropriate level of security, Vendor and each Vendor Affiliate shall take account in particular of the risks that are presented by Processing, in particular from a Personal Data Breach.
    3. Vendor's applicable technical and organisational measures are described in Annex 2 to this DPA.
  7. Subprocessing

    1. Each Company Group Member authorises Vendor and each Vendor Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 7 to appoint) Subprocessors in accordance with this section 7 and any restrictions in the Agreement.
    2. Vendor and each Vendor Affiliate may continue to use those Subprocessors already engaged by Vendor or any Vendor Affiliate as at the date of this Addendum, subject to Vendor and each Vendor Affiliate in each case as soon as practicable meeting the obligations set out in section 7.4.
    3. Vendor shall provide Company at least 30 days' prior written notice of a new Subprocessor that will Process Company Personal Data, including the Subprocessor's name, the location of Processing, and the nature of the services and Processing it will perform. Company may object within that period on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If they cannot resolve it, Vendor will use commercially reasonable efforts to make available a reasonable change to the affected Service or, if that is not feasible, Company may terminate the affected Service without penalty upon written notice.
    4. With respect to each Subprocessor, Vendor or the relevant Vendor Affiliate shall:
      1. before the Subprocessor first Processes Company Personal Data (or, where relevant, in accordance with section 7.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Company Personal Data required by the Agreement;
      2. ensure that the arrangement between on the one hand (a) Vendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, is governed by a written contract including obligations that provide a level of protection for Company Personal Data no less protective in all material respects than the obligations applicable to Vendor under this DPA, as relevant to the services performed by that Subprocessor, and meet the requirements of article 28(3) of the EU GDPR;
      3. if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) Vendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the relevant Company Group Member(s) (and Company shall procure that each Company Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and
      4. on Company's reasonable written request, provide information reasonably necessary to demonstrate compliance with this section, which may include a summary or relevant redacted extracts of the applicable data protection terms. Vendor may withhold commercial information unrelated to data protection and information it is prohibited from disclosing, provided it supplies sufficient information to demonstrate compliance.
    5. Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs the obligations under sections 3.1, 4 where applicable, 5, 6, 8.1, 9.2, 10 and 12.1, as they apply to Processing of Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of Vendor. Vendor remains responsible to Company for each Subprocessor's performance of its data-protection obligations.
  8. Data Subject Rights

    1. Taking into account the nature of the Processing, Vendor and each Vendor Affiliate shall assist each Company Group Member by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Company Group Members' obligations, as reasonably understood by Company, to respond to requests to exercise Data Subject rights under the Data Protection Laws.
    2. Vendor shall:
      1. promptly notify Company if any Contracted Processor receives a request from a Data Subject under any Data Protection Law in respect of Company Personal Data; and
      2. ensure that the Contracted Processor does not respond to that request except on the documented instructions of Company or the relevant Company Affiliate or as required by Applicable Laws to which the Contracted Processor is subject, in which case Vendor shall to the extent permitted by Applicable Laws inform Company of that legal requirement before the Contracted Processor responds to the request.
  9. Personal Data Breach

    1. Vendor shall follow the Standard Operating Procedure available at https://dot.vu/incident-reporting including to notify Company within 24 hours upon Vendor or any Subprocessor becoming aware of a Personal Data Breach affecting Company Personal Data, providing Company with sufficient information to allow each Company Group Member to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Laws. Where all required information is not available at the same time, Vendor may provide it in phases without undue further delay. Notification of a Personal Data Breach is not an acknowledgement of fault or liability.
    2. Vendor shall co-operate with Company and each Company Group Member and take such reasonable commercial steps as are directed by Company to assist in the investigation, mitigation and remediation of each such Personal Data Breach.
  10. Data Protection Impact Assessment and Prior Consultation

    Vendor and each Vendor Affiliate shall provide reasonable assistance to each Company Group Member with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, which Company reasonably considers to be required of any Company Group Member by article 35 or 36 of the EU GDPR or equivalent provisions of any other Data Protection Law, in each case solely in relation to Processing of Company Personal Data by, and taking into account the nature of the Processing and information available to, the Contracted Processors.

  11. Data Retention and Deletion

    1. Retention. Vendor and each Vendor Affiliate shall retain and delete Company Personal Data in accordance with the Data Retention Policy. The default retention period is six months from cessation of the relevant Services, unless Company configures a different period within the allowable maximum specified in that policy. While AI-Assisted Editing Features are active, the feature-specific retention periods in the section titled "AI-Assisted Editing Features" apply. Following cessation, the Data Retention Policy applies.
    2. Deletion or Return of Personal Data. At any time during the retention period, the Company may, by written notice to Vendor, require Vendor and each Vendor Affiliate to:
      • (a) Return a copy of Company Personal Data then held in the Services in a commonly used, machine-readable format, where technically feasible; and/or
      • (b) Delete all copies of Company Personal Data processed by any Contracted Processor.
      Vendor shall comply without undue delay and within the timeframes stated in the Data Retention Policy. Deletion from live systems will be completed promptly. Copies maintained in monitoring systems or routine backups will be isolated from ordinary use and deleted through their documented expiry cycles, and, if restored, will be subject again to the deletion instruction. Nothing in this paragraph extends a shorter period required by Data Protection Laws.
    3. Retention Required by Applicable Laws. Notwithstanding the foregoing, each Contracted Processor may retain Company Personal Data to the extent required by Applicable Laws, but only for such period and to the extent required by such laws. Vendor and each Vendor Affiliate shall ensure the confidentiality of all such retained Company Personal Data and shall process it only as necessary for the purposes specified in the Applicable Laws.
    4. Certification and Notification. On Company's reasonable written request following completion of a return or deletion request, Vendor shall confirm in writing that it has complied with the applicable requirements of this section. Vendor is not required to issue an individual notice each time data expires automatically under the Data Retention Policy.
  12. Audit rights

    1. Subject to sections 12.2 to 12.4, Vendor and each Vendor Affiliate shall make available to each Company Group Member on request all information necessary to demonstrate compliance with this Addendum, and shall allow for and contribute to audits, including inspections, by any Company Group Member or an auditor mandated by any Company Group Member in relation to the Processing of the Company Personal Data by the Contracted Processors.
    2. Where available, Vendor may first satisfy an audit request by providing current independent audit reports, certifications, security documentation, or responses to a reasonable written questionnaire. If that information is not reasonably sufficient to demonstrate compliance, Company may conduct an audit in accordance with this section. Audits shall be subject to reasonable confidentiality, security, and safety requirements and shall not give Company access to information concerning other customers.
    3. Information and audit rights of the Company Group Members only arise under section 12.1 to the extent that the Agreement does not otherwise give them information and audit rights meeting the relevant requirements of Data Protection Law (including, where applicable, article 28(3)(h) of the EU GDPR).
    4. Company or the relevant Company Affiliate undertaking an audit shall give Vendor or the relevant Vendor Affiliate reasonable notice of any audit or inspection to be conducted under section 12.1 and shall make (and ensure that each of its mandated auditors makes) reasonable endeavours to avoid causing (or, if it cannot avoid, to minimize) any damage, injury or disruption to the Contracted Processors' premises, equipment, personnel and business while its personnel are on those premises in the course of such an audit or inspection. A Contracted Processor need not give access to its premises for the purposes of such an audit or inspection:
      1. to any individual unless he or she produces reasonable evidence of identity and authority;
      2. outside normal business hours at those premises, unless the audit or inspection needs to be conducted on an emergency basis and Company or the relevant Company Affiliate undertaking an audit has given notice to Vendor or the relevant Vendor Affiliate that this is the case before attendance outside those hours begins; or
      3. for the purposes of more than one audit or inspection, in respect of each Contracted Processor, in any calendar year, except for any additional audits or inspections which:
        1. Company reasonably considers necessary because of genuine concerns as to Vendor's or the relevant Vendor Affiliate’s compliance with this Addendum; or
        2. A Company Group Member is required or requested to carry out by Data Protection Law, a Supervisory Authority or any similar regulatory authority responsible for the enforcement of Data Protection Laws in any country or territory,
      4. where Company or the relevant Company Affiliate undertaking an audit has identified its concerns or the relevant requirement or request in its notice to Vendor or the relevant Vendor Affiliate of the audit or inspection.
    5. Company shall bear its audit costs and reimburse Vendor's reasonable costs for an audit, except where the audit identifies a material breach of this DPA by Vendor or is required following a Personal Data Breach attributable to Vendor.
  13. Restricted Transfers

    1. Vendor shall not make a Restricted Transfer unless it has implemented a transfer mechanism permitted by applicable Data Protection Laws and any supplementary measures reasonably required in light of the transfer.
    2. For a Restricted Transfer of Company Personal Data protected by the EU GDPR to Vendor, the EU SCCs are incorporated into this DPA by reference and apply as follows: (a) Module Two applies where Company is a Controller and Vendor is a Processor; (b) Module Three applies where Company is a Processor and Vendor is a subprocessor; (c) Clause 7 applies; (d) in Clause 9, Option 2 applies and the notice period is the period stated in the section titled "Subprocessing"; (e) the optional wording in Clause 11 does not apply; (f) for Clause 17, Option 1 applies and the law of Denmark governs; and (g) under Clause 18(b), the courts of Denmark have jurisdiction. Annex I is completed using the information in the Agreement, Annex 1 to this DPA, and the Dot.vu Sub-Processors page. Annex II to the EU SCCs is completed by the technical and organisational measures described in Annex 2 to this DPA.
    3. For a Restricted Transfer of Company Personal Data protected by the UK GDPR, the EU SCCs as completed under paragraph 2 apply together with the UK Addendum, which is incorporated by reference. The information required by Tables 1 to 3 of the UK Addendum is supplied by the Agreement, this DPA, and the materials identified in paragraph 2. For Table 4, the Importer may end the UK Addendum as set out in Section 19 of the UK Addendum.
    4. If an applicable authority adopts a replacement transfer mechanism, that mechanism will apply to the extent necessary, and the parties will cooperate in good faith to implement required updates.
    5. If more than one transfer mechanism applies, the mechanism that provides a valid basis for the relevant transfer will control. Nothing in this section modifies the EU SCCs or UK Addendum except as they expressly permit.
  14. General Terms

    1. Governing law and jurisdiction
    2. Without prejudice to the governing-law and forum provisions of the EU SCCs or UK Addendum where they apply:
      1. the parties to this Addendum hereby submit to the choice of jurisdiction stipulated in the Agreement with respect to any disputes or claims howsoever arising under this Addendum, including disputes regarding its existence, validity or termination or the consequences of its nullity; and
      2. this Addendum and all non-contractual or other obligations arising out of or in connection with it are governed by the laws of the country or territory stipulated for this purpose in the Agreement.
    3. Order of precedence
    4. In the event of a conflict concerning the protection or Processing of Company Personal Data, the following order of precedence applies: (a) the EU SCCs or UK Addendum, but only for the Restricted Transfer to which they apply; (b) this DPA; and (c) the Agreement. This DPA prevails only to the extent of the conflict and only with respect to its subject matter. Where the Agreement contains an express order of precedence applicable to this DPA, that agreed order of precedence applies.
    5. Liability
    6. Except to the extent prohibited by applicable law or the EU SCCs or UK Addendum, each party's liability arising out of or relating to this DPA, including liability relating to AI-Assisted Editing Features and each party's indemnification obligations, is subject to the exclusions, limitations, and aggregate liability cap set out in the Agreement. Nothing in this paragraph limits any rights of Data Subjects or Supervisory Authorities that cannot lawfully be limited by contract.
    7. Changes in Data Protection Laws, etc.
    8. If a change in Data Protection Laws, a binding decision of a competent authority, or a replacement transfer mechanism requires an amendment to this DPA, the parties shall cooperate in good faith to implement the amendment reasonably necessary for compliance. Neither party may modify the EU SCCs or UK Addendum except as those instruments permit. Vendor may update this DPA on notice where reasonably necessary to comply with Data Protection Laws, provided that the update does not materially reduce the protection of Company Personal Data. Any other amendment must be agreed in writing in accordance with the Agreement.
    9. Severance
    10. Should any provision of this Addendum be invalid or unenforceable, then the remainder of this Addendum shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability, while preserving the parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.


ANNEX 1: DETAILS OF PROCESSING OF COMPANY PERSONAL DATA

Subject matter and duration of the Processing

Vendor Processes Company Personal Data to provide the Services described in the Agreement. Processing continues for the term of the Agreement and any period during which Vendor retains Company Personal Data in accordance with the Agreement, this DPA, or applicable law.

Nature and purpose of the Processing

The Processing may include collection, recording, organization, structuring, hosting, storage, retrieval, consultation, use, display, transmission, integration, analysis, restriction, deletion, and other operations necessary to: provide and administer the Services; host and publish Company-configured interactive content; collect and make available end-user submissions and interaction data as configured by Company; provide analytics, integrations, support, security, maintenance, and troubleshooting; and provide AI-Assisted Editing Features where enabled by Company. Vendor Processes Company Personal Data only on Company's documented instructions, including instructions given through Company's and its authorized users' use and configuration of the Services, except where otherwise required by applicable law.

Types of Company Personal Data

Depending on Company's use and configuration of the Services, Company Personal Data may include: identifiers and business contact details; account, role, and access information processed on Company's behalf; online and technical identifiers; responses, submissions, interaction and engagement information collected through Company-configured interactive content; project content, media, documents, and other materials submitted to the Services; and any other Personal Data that Company or its authorized users submit to or collect through the Services. Company determines the specific Personal Data submitted or collected.

AI-Assisted Editing Features are not intended for the Processing of Personal Data. If and to the extent AI-Assisted Editing Data contains Personal Data, only the Personal Data contained in that material constitutes Company Personal Data. The applicable categories of Personal Data and Data Subjects depend on the content submitted by Company or its authorized users.

Special categories of Personal Data

The Services do not require Company to submit special categories of Personal Data. Company shall not submit such data unless its use is permitted by the Agreement, Company has established a lawful basis and any required safeguards, and any additional written terms or configurations required by Vendor are in place.

Categories of Data Subjects

Depending on Company's use of the Services, Data Subjects may include: Company's authorized users, editors, employees, contractors, and representatives; individuals who visit or interact with content created or published through the Services; Company's customers, prospective customers, contacts, employees, applicants, suppliers, or other individuals whose Personal Data Company or its authorized users submit to or collect through the Services; and individuals depicted or identified in uploaded content.

Frequency of Processing

Continuous or intermittent, depending on Company's and its authorized users' use and configuration of the Services.

Obligations and rights of Company

Company's obligations and rights are set out in the Agreement and this DPA. Company is responsible for the lawfulness of its instructions, the Personal Data it submits or collects, required notices and consents, and its configuration and use of the Services. Vendor remains responsible for complying with its own obligations as Processor under this DPA and applicable Data Protection Laws.

ANNEX 2: TECHNICAL AND ORGANISATIONAL MEASURES

Vendor's then-current Technical and Organisational Measures Schedule ("TOM Schedule") is incorporated into and forms part of this DPA. The TOM Schedule is maintained as a versioned document and will be provided to Company upon written request.

The TOM Schedule constitutes Vendor's confidential information and may be used by Company solely to assess Vendor's compliance with this DPA and applicable Data Protection Laws. This confidentiality restriction does not prevent disclosure where required by applicable law, a Supervisory Authority, the EU SCCs, the UK Addendum, or to Company's professional advisers who are subject to appropriate confidentiality obligations.

Vendor may update the TOM Schedule from time to time to reflect changes to the Services, security practices, technologies, or legal requirements, provided that an update does not materially reduce the overall security of the Services or the protection of Company Personal Data.

Stay in the loop

Get the latest insights, trends, and interactive marketing ideas straight to your inbox.

 

Platform

  • How it works
  • Interactive Demo
  • Integrations
  • Plans
  • Help center

Interactive Experiences

  • Marketplace
  • AI Interactive Builder
  • Interactive Presentation
  • Interactive Flipbook
  • Interactive Video
  • Guided Selling
  • View All

Resources

  • Blog
  • Case studies
  • News
  • FAQ

Company

  • About us
  • Agency services
  • Career
  • Contact

Compare

  • Ion Interactive Alternative
  • Ceros Alternative
  • Qualifio Alternative
  • Outgrow Alternative
  • Apester Alternative
  • Prezi Alternative
Privacy Policy | | Terms

© 2026 Dot Marketing ApS. All rights reserved.