Datasert Data Processing Addendum (DPA)
This Data Processing Addendum (“DPA”) forms part of the Terms of Service or Master Services Agreement (the “Agreement”) between Datasert (“Datasert”, “Processor”, “we”, “us”) and the customer entity entering into the Agreement (“Customer”, “Controller”). This DPA applies to the extent Datasert processes Personal Data on behalf of Customer in connection with the Services.
Roles of the Parties
Customer is the Controller of Personal Data processed through the Services and is responsible for determining the purposes and means of processing.
Datasert is the Processor of such Personal Data and processes it only on behalf of and in accordance with Customer’s documented instructions, as set out in this DPA and the Agreement.
Scope of Processing
Datasert provides tools that primarily connect to Salesforce to query, export, and process data. Customer determines what data is accessed and how it is used. Processing details are described in Appendix A.
Customer Instructions
Customer instructs Datasert to process Personal Data solely as necessary to provide the Services under the Agreement, including to connect to Salesforce, run queries, generate exports, and perform processing actions initiated by Customer or Authorized Users. Customer may also direct exports to third-party services (see Section 12).
Datasert Obligations
- process Personal Data only on documented instructions from Customer;
- ensure persons authorized to process Personal Data are bound by confidentiality;
- take appropriate measures to help secure Personal Data (see Section 5);
- assist Customer, as reasonably requested and taking into account the nature of processing, in meeting Customer’s obligations under applicable data protection law;
- notify Customer if Datasert believes an instruction violates applicable law.
Security Measures
Datasert will maintain appropriate administrative, physical, and technical safeguards designed to protect the security, confidentiality, and integrity of Personal Data. Measures may include access controls, logging/monitoring, encryption in transit where supported, vulnerability management, and secure development practices. Datasert will not materially reduce the overall security of the Services during the Subscription Period.
Sub-processors
Customer authorizes Datasert to engage Sub-processors as listed in Appendix B. Datasert will impose data protection obligations on Sub-processors that are no less protective than those set out in this DPA.
Datasert may update its Sub-processor list from time to time. Where required by applicable law, Datasert will provide reasonable notice (posted in the DPA page) of material changes and Customer may object on reasonable data protection grounds.
Data Subject Requests
To the extent Customer receives a request from a data subject to exercise rights (access, deletion, rectification, etc.), Customer is responsible for responding. Datasert will provide reasonable assistance, as appropriate and legally permitted, taking into account the nature of processing and available information.
Security Incidents
Datasert will notify Customer without undue delay after becoming aware of a confirmed Personal Data breach (a “Security Incident”) affecting Customer Data. Datasert will provide information reasonably necessary to help Customer meet its notification obligations and will take reasonable steps to contain and remediate the incident.
International Transfers
If applicable law requires a lawful transfer mechanism for cross-border transfers of Personal Data (e.g., SCCs), the parties will implement such mechanism to the extent required for the Services.
Standard Contractual Clauses (SCCs)
To the extent that the processing of Personal Data under this Data Processing Addendum involves transfers of Personal Data from the European Economic Area (EEA), the United Kingdom, or Switzerland to a country that has not been deemed to provide an adequate level of data protection, the Standard Contractual Clauses adopted by the European Commission (Module Two – Controller to Processor) are hereby incorporated by reference and shall apply automatically, without the need for further action by the parties.
For purposes of the Standard Contractual Clauses, the Customer acts as the data exporter and Datasert acts as the data importer. The technical and organizational measures described in this DPA and the Services documentation shall apply to such transfers.
Where required by applicable law, the UK International Data Transfer Addendum or other approved transfer mechanism shall apply to transfers subject to UK data protection law.
Desktop Products
For Datasert desktop products, the Services are designed so that Salesforce data accessed via the product is processed locally on the user’s machine and is not sent to Datasert systems, except where Customer explicitly enables features that require network transmission (if any) or where required to provide support requested by Customer.
Online Products and Storage
For Datasert online products, Customer may choose to store Salesforce data within the Services through explicit Customer action (for example, saving exports, snapshots, or job outputs). Where stored, Datasert will retain such data only as necessary to provide the functionality selected by Customer and may periodically clean up stored data in accordance with product retention settings or published policies.
Customer remains responsible for deciding what Salesforce data to store and for configuring retention and access controls where such settings are available.
Customer-Directed Exports
Customer may direct the Services to export Salesforce data to third-party services (for example, Google Sheets or Microsoft Office 365). Such exports are initiated by Customer, and Customer is responsible for ensuring it has the necessary rights, consents, and agreements with the applicable third-party provider. Datasert is not responsible for third-party services’ security, privacy, or data practices.
Return and Deletion
Upon termination or expiration of the Agreement, Datasert will, upon Customer’s request and where applicable, make Customer Data available for export for a limited period (if supported by the Services). Thereafter, Datasert will delete or anonymize Customer Data from its systems in accordance with the retention periods set forth below, unless retention is required by law.
Data Retention Periods:
- Application Configuration: Retained until Customer deletes it or until the Tenant is inactivated.
- Salesforce Data in Datasert Servers: Retained for 30 days to 1 year depending on the Runs history configuration selected by Customer.
- Application Logs: Retained for up to 30 days.
- Backup Data: Backup data may be retained for a reasonable period after deletion to enable recovery, but will be deleted in accordance with Datasert's backup retention schedule.
Audits and Compliance
Upon reasonable request, Datasert will provide Customer with information reasonably necessary to demonstrate compliance with this Data Processing Addendum, such as security documentation, policies, or third-party audit reports where available, subject to confidentiality obligations.
Any on-site audit must be mutually agreed in advance, limited in scope, conducted during normal business hours, and no more than once annually, unless otherwise required by applicable law or following a Security Incident.
Operational Impact. Any audit shall be conducted in a manner that does not unreasonably interfere with Datasert’s business operations, security, or obligations to other customers.
Priority and Terms
In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA will control. All other terms of the Agreement remain unchanged.
Appendix A — Processing Details
- Subject Matter
- Processing of Salesforce data (including Personal Data) as directed by Customer through the Services for querying, exporting, processing, and optional storage.
- Duration
- For the Subscription Period (and any additional time required for return/deletion consistent with Section 13 and backup retention).
- Nature and Purpose
- (i) Connect to Salesforce; (ii) run customer-configured queries; (iii) generate exports and reports; (iv) process data to provide requested features; (v) if explicitly enabled by Customer, store outputs temporarily and clean up periodically.
- Types of Personal Data
- May include names, emails, user identifiers, record metadata, audit/log data, and other data contained in Salesforce objects selected by Customer.
- Categories of Data Subjects
- Customer employees, contractors, end users, prospects/customers, and other individuals whose data is stored in Customer’s Salesforce instance.
- Special Categories
- Customer should avoid submitting special categories of data unless necessary and supported by the Services and Customer has a lawful basis to do so.
Contact
- Security:
- security@datasert.com
- Legal:
- legal@datasert.com
- Address:
- 4900 Hopyard Rd #100, Pleasanton CA 94588, USA
- Website:
- https://www.datasert.com
- Governing Law:
- California, United States
Appendix B — Sub-processors
The sub-processors listed below are authorized to process Customer Data (including Personal Data, if applicable) for the limited purposes described. Datasert will maintain written agreements with sub-processors that are no less protective than the obligations in the DPA.
| Sub-processor | Service | Purpose | Data categories | Location |
|---|---|---|---|---|
| Zepto | Transactional Email Delivery | Send transactional emails (e.g., verification, alerts, notices). | Email address, name (if provided), message metadata. | US |
| Stripe | Payment Processing | Process subscription payments and manage billing information. | Name, email address, billing address, payment card information (processed by Stripe, not stored by Datasert). | US |
| Amazon Web Services (AWS) | Cloud Infrastructure | Host and operate the Services (compute, networking, monitoring). | Service telemetry; Customer Data as processed within the Services. | US-West-2 |
| AWS DynamoDB / Amazon RDS | Application Data Storage | Store application data required to provide the Services. | Customer Data and related metadata stored by Customer action/config. | US-West-2 |
| Amazon S3 | Application File Storage | Store files/exports/artifacts created through the Services. | Customer Data files and generated outputs. | US-West-2 |
Updates. Datasert may update this list from time to time. Where required by applicable law, Datasert will provide reasonable notice of material changes and Customer may object on reasonable data protection grounds.