1. Scope and Purpose

This Data Processing Agreement (“DPA”) applies when you use our service to process personal data of EU/EEA data subjects, making us a data processor acting on your instructions as data controller.

2. Processing Details

Subject matter: Extraction of business contact data from Google Maps.
Duration: For the term of the service agreement.
Nature: Automated extraction and optional enrichment of publicly listed business data.
Purpose: B2B prospecting, market research, data enrichment as directed by controller.
Data subjects: Business owners, managers, and employees whose contact information appears in public business listings.
Personal data categories: Name, business email, phone number, job title, LinkedIn profile URL.

3. Controller Obligations

As data controller, you are responsible for: establishing a lawful basis for processing (typically legitimate interest for B2B prospecting), providing privacy notices where required, and honoring data subject rights requests for data within your systems.

4. Processor Obligations

We will: process personal data only on your documented instructions, ensure staff with data access are bound by confidentiality obligations, implement appropriate technical and organizational security measures, assist you in fulfilling data subject rights requests, and notify you within 72 hours of becoming aware of a personal data breach.

5. Sub-processors

We maintain a list of approved sub-processors at mapsapi.dev/legal/sub-processors. We will give you 30 days notice before adding new sub-processors. You may object to new sub-processors within that window.

6. International Transfers

Data may be transferred to the US via Standard Contractual Clauses (Module 2: Controller to Processor) incorporated by reference into this DPA. A copy of the SCCs is available on request.

7. Deletion

Upon termination of the service agreement, we will delete or return all personal data within 30 days and certify deletion in writing upon request.

8. Audit Rights

You may audit our compliance with this DPA once per year, with 30 days written notice, at your cost. In lieu of an on-site audit, we will provide our most recent SOC 2 Type II report or equivalent third-party audit summary.