Effective: May 10, 2026
This Data Processing Amendment (this “Amendment”) is part of the agreement between you as a Customer and Visitly and applies only to the extent Visitly receives, stores, or processes Personal Data in connection with the Terms of Service (ToS) and your capacity as Controller or Data Exporter, and Visitly’s capacity as Processor or Data Importer.
All capitalized terms in this DPA will have the meaning as defined by the applicable privacy and data protection laws and regulations to the extent they apply to each Party and to the Processing of Personal Data under this Agreement, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) (together, the “Data Protection Legislation”) unless the context requires otherwise.
This Data Processing Agreement (“DPA”) forms part of the Terms of Use (or other similarly titled written or electronic agreement addressing the same subject matter) (“Agreement”) between Customer (as defined in the Agreement) and Visitly Inc under which the Processor provides the Controller with the software and services (the “Services”). The Controller and the Processor are individually referred to as a “Party” and collectively as the “Parties”.
The Parties seek to implement this DPA to comply with the requirements of EU GDPR (defined hereunder) in relation to Processor’s processing of Personal Data (as defined under the EU GDPR) as part of its obligations under the Agreement.
If and insofar as the California Consumer Privacy Act of 2018 (“CCPA”) applies to this Agreement, the definition in the Agreement (including this DPA) of: “Controller” includes “Business”, “Processor” includes “Service Provider”, “Data Subject” includes “Consumer” and “Personal Data” includes “Personal Information”, in each case as defined under the CCPA.
Except for the changes made by this Addendum, the ToS between you and Visitly remains in full effect. If you do not agree to this DPA, you may discontinue the use of Visitly’s service and cancel your account.
The Customer instructs Visitly to Process the following Personal Data for the purpose of the Agreement and pursuant to the DPA:
Visitly, we, us, our, Data Importer, or Processor refers to the provider of Visitly website and services, (collectively referred to as Visitly Service).
You, Customer, Data Exported, or Controller refers to the company or organization that signs up to use Visitly Service to manage the relationships with your consumers or service users.
Party or Parties refers to Visitly and/or the Customer depending on the context.
Personnel refers to those individuals who are employed by or are under contract to perform a service on behalf of one of the parties. Personnel may have rights to their personal data (including business contact information) if they reside in the EU. It is important to be clear about how personnel’s rights are protected.
Sub-processor is a Third-party, independent contractor, vendor, and suppliers who provide specific services and products related to Visitly’s website and our services, such as hosting, credit card processing, fraud screening, and mailing list hosting (“third-party” or “outside contractor” shall have similar meanings).
Incident means (a) a complaint or a request with respect to the exercise of an individual’s rights under the GDPR; (b) an investigation into or seizure of the personal data by government officials, or a specific indication that such an investigation or seizure is imminent; or (c) any breach of the security and/or confidentiality as set out in this DPA leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, the personal data, or any indication of such breach having taken place or being about to take place.
Data Subject, Personal Data, Member State, Controller, Processor, and Processing shall have the same meaning as in the GDPR and applicable Data Protection Laws from time to time, and their cognate terms shall be construed accordingly.
Data Protection Laws means, as binding on either party or the services:
Data Subject has the meaning given in applicable Data Protection Laws from time to time.GDPR means the General Data Protection Regulation (EU) 2016/679.
International Organization has the meaning in the GDPR.
Personal Data Has the meaning given in applicable Data Protection Laws from time to time.
Personal Data Breach has the meaning given in applicable Data Protection Laws from time to time.
Processing has the meaning given in applicable Data Protection Laws from time to time (and related expressions, including process, processed, processing, and processes shall be construed accordingly).
Protected Data means Personal Data received from or on your behalf of and in connection with the performance of our obligations under the applicable Terms of Service.
Standard Contractual Clauses (SCCs) are the contractual clauses developed by the European Commission to ensure that any personal data leaving the European Economic Area (EEA) will be transferred in compliance with EU data protection laws and as may be amended by the European Commission from time to time.
Supervisory Authority means the relevant supervisory authority with responsibilities for privacy or data protection matters in the jurisdiction of the Controller.
The Standard Contractual Clauses will apply to all processing of Personal Data by Customer where the Personal Data is transferred from the EEA or the United Kingdom to outside the EEA or United Kingdom, from a Data Exporter acting as Controller to a Data Importer acting as Processor to any country or recipient: (i) not recognized by the European Commission as providing an adequate level of protection for Personal Data (as described in the Data Protection Legislation), and (ii) not covered by a suitable framework recognized by the relevant authorities or courts as providing an adequate level of protection for Personal Data.
All transfers of Personal Data to a third country or an international organization will be subject to appropriate safeguards and such transfers and safeguards will be documented according to Articles 46 and 30(2) described in the GDPR.
In addition to the obligations under this section, the parties agree to the following additional safeguards:
To the extent any new or further measures are legally required by relevant Data Protection Legislation to be implemented by Processor to ensure ongoing compliance with the Standard Contractual Clauses, Processor shall implement such measures within a reasonable time.
You agree to indemnify and hold Visitly, its officers, employees, agents, and representatives harmless, including costs and attorneys’ fees, from any claim or demand made by any third party arising directly or indirectly out of (i) your access to or use of Visitly’s platform, (ii) your violation of the Terms of Service or this Addendum, (iii) your infringement, or the infringement by any third party using your registration information, of any intellectual property, or other right of any person or entity, including but not limited to any third party claims relating to your use, disclosure, or transfer of Personal Data to Visitly, and (iv) the Data or any other materials provided to Visitly.
Definitions
Terms not otherwise defined herein shall have the meaning given to them in the EU GDPR or the Agreement. The following terms shall have the corresponding meanings assigned to them below:
Purpose of this Agreement
This DPA sets out various obligations of the Processor in relation to the Processing of Personal Data and shall be limited to the Processor’s obligations under the Agreement. If there is a conflict between the provisions of the Agreement and this DPA, the provisions of this DPA shall prevail.
Categories of Personal Data and Data Subjects
The Controller authorizes permission to the Processor to process the Personal Data to the extent of which is determined and regulated by the Controller. The current nature of the Personal Data is specified in Annex I to Schedule 1 to this DPA.
Purpose of Processing
The objective of Processing of Personal Data by the Processor shall be limited to the Processor’s provision of the Services to the Controller and or its Client, pursuant to the Agreement.
Duration of Processing
The Processor will Process Personal Data for the duration of the Agreement, unless otherwise agreed upon in writing by the Controller.
Data Controller’s Obligations
Data Processor’s Obligations
Data Secrecy
Audit Rights
Mechanism of Data Transfers
Any Data Transfer for the purpose of Processing by the Processor in a country outside the European Economic Area (the “EEA”) shall only take place in compliance as detailed in Schedule 1 to the DPA. Where such model clauses have not been executed at the same time as this DPA, the Processor shall not unduly withhold the execution of such template model clauses, where the transfer of Personal Data outside of the EEA is required for the performance of the Agreement.
Sub-processors
Here are a list of processors:
Personal Data Breach Notification
Return and Deletion of Personal Data
Technical and Organizational Measures
Having regard to the state of technological development and the cost of implementing any measures, the Processor will take appropriate technical and organizational measures against the unauthorized or unlawful processing of Personal Data and against the accidental loss or destruction of, or damage to, Personal Data to ensure a level of security appropriate to: (a) the harm that might result from unauthorized or unlawful processing or accidental loss, destruction or damage; and (b) the nature of the data to be protected.
Client
By: ____________________________
Name:
Title:
Date:
Visitly LLC
By: ____________________________
Name:
Title:
Date:
SCHEDULE 1
ANNEX I
TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
Description of the technical and organisational security measures implemented by Visitly LLC as the data processor/data importer to ensure an appropriate level of security, taking into account the nature, scope, context, and purpose of the processing, and the risks for the rights and freedoms of natural persons.
Security Management System
Personnel Security.
Visitly LLC personnel are required to conduct themselves in a manner consistent with the company’s guidelines regarding confidentiality, business ethics, appropriate usage, and professional standards. Visitly LLC conducts reasonably appropriate background checks on any employees who will have access to client data under this Agreement, including in relation to employment history and criminal records, to the extent legally permissible and in accordance with applicable local labor law, customary practice and statutory regulations.
Personnel are required to execute a confidentiality agreement in writing at the time of hire and to protect Customer Personal Data at all times. Personnel must acknowledge receipt of, and compliance with, Visitly LLC’s confidentiality, privacy and security policies. Personnel are provided with privacy and security training on how to implement and comply with the Information Security Program. Personnel handling Customer Personal Data are required to complete additional requirements appropriate to their role (e.g., certifications). Visitly LLC’s personnel will not process Customer Personal Data without authorization.
Access Controls
Data Center and Network Security
Networks and Transmission
Data Storage, Isolation, Authentication, and Destruction.
Visitly LLC stores data in a multi-tenant environment on AWS servers. Data, the Services database and file system architecture are replicated between multiple availability zones on AWS. Visitly LLC logically isolates the data of different customers. A central authentication system is used across all Services to increase uniform security of data. Visitly LLC ensures secure disposal of Client Data through the use of a series of data destruction processes.
Data Processing Officer: Luv Bedi
Address: 2261 Market St #5206 San Francisco, California 94114, US
Contact emailt: support@visitly.io