Data Processing Agreement
For guest data you are the controller and we are the processor. This says what that means.
This agreement applies between you (the host, acting as data controller) and Compass Tech Labs LLC (acting as data processor) for personal data relating to your guests that is processed through Cimyah. It forms part of the Terms of Service and takes effect when you accept them.
Where data protection law does not apply to you, this document costs you nothing and changes nothing.
1. Roles
You decide what goes into your guides and that their usage will be measured. That makes you the controller. We process it only to provide the service, on your instructions. That makes us the processor.
For your own account data — your email address, your billing details — we are the controller, and the Privacy Policy governs it rather than this agreement.
2. What we process on your behalf
Subject matter: providing a digital guest guide service.
Duration: for as long as your account exists. The daily totals behind your analytics last that long; the individual event rows behind them are deleted after 400 days.
Categories of person: the guests who open your guides, and anyone whose details you choose to put into a guide.
Categories of data:
- Guide usage events: property, timestamp, event type, page key, target, entry method, language, and a per-visit session identifier that is discarded when the browser tab closes.
- Any personal data you choose to write into a guide — for example a cleaner's phone number or a neighbour's name.
We do not collect guests' names, email addresses, phone numbers, IP addresses or device information: the table these events live in has no column that could hold any of them. The usage data above does not identify anyone.
3. Our obligations
- We process guest personal data only on your documented instructions, which for these purposes are the settings you choose in the product and this agreement, unless the law requires otherwise.
- Our personnel with access are bound by confidentiality.
- We keep appropriate technical and organisational security measures, including row-level access control on every table, encryption of credentials at rest, and encryption in transit.
- We will help you respond to a guest exercising their rights, and with data protection impact assessments and consultations, to the extent it is reasonable and we are able.
- We will tell you without undue delay after becoming aware of a personal data breach affecting your data, with what we know.
- At the end of the agreement we delete your data, except where we are required to keep it.
4. Sub-processors
You give general authorisation for us to use sub-processors. Those currently in use are listed in the Privacy Policy, with what each one receives. We impose data protection obligations on them no less protective than these, and we remain responsible for their performance.
We will give reasonable notice before adding or replacing a sub-processor, and you may object on reasonable data protection grounds. If we cannot resolve the objection, you may end the affected part of the service.
5. International transfers
Our providers operate in the United States and elsewhere. Where personal data of people in the EEA, Switzerland or the UK is transferred outside those regions, the transfer relies on the standard contractual clauses adopted by the European Commission and the UK Addendum, as applicable.
6. Audit
On reasonable written request, and not more than once a year unless a supervisory authority requires otherwise, we will make available the information reasonably necessary to demonstrate compliance with this agreement.
7. Your obligations
You are responsible for having a lawful basis for what you put into a guide, for telling your guests what they are entitled to be told, and for the accuracy and lawfulness of the content — which is the same responsibility set out in the Terms of Service.
In particular, if you write another person's personal data into a guide, it is your responsibility to be entitled to.
8. General
Where this agreement conflicts with the Terms of Service in respect of guest personal data, this agreement prevails. It is governed by the laws of the Commonwealth of Massachusetts, United States, without prejudice to any mandatory data protection law that applies to you.
Questions, or a signed copy: hello@cimyah.com.