Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Customer”) and Ans·Rev, Inc. (“Ans·Rev”) for use of the Service. It governs Ans·Rev’s processing of personal data on the Customer’s behalf and applies where the NDPA 2023, GDPR, UK GDPR, CCPA/CPRA, or similar laws apply. Capitalized terms not defined here have the meaning in the underlying agreement or the applicable law.
1. Roles of the parties
For personal data contained in Customer Content, connected CRM and mailbox data, and visitor events (“Customer Personal Data”), the Customer is the controller (or a processor acting for its own controller) and Ans·Rev is the processor. Ans·Rev processes Customer Personal Data only on the Customer’s documented instructions, including as set out in the agreement, this DPA, and the Customer’s use of the Service. For aggregated, k-anonymized Index benchmarks that do not identify individuals, Ans·Rev acts as an independent controller. Under CCPA, Ans·Rev is a “service provider” and does not sell or share Customer Personal Data.
2. Scope and nature of processing
- Subject matter: provision of the Ans·Rev Service — AI-visibility measurement, content generation, visitor resolution, enrichment, CRM/mailbox integration, and human-approved outreach.
- Duration: the term of the agreement, plus the deletion/return period in Section 8.
- Nature and purpose: hosting, storage, analysis, resolution, enrichment, transmission, and generation of derived outputs, solely to provide and support the Service.
- Categories of data subjects: Customer’s website visitors, prospects and leads, CRM contacts, and Customer’s own users.
- Categories of personal data: business contact details, professional and firmographic data, IP address and device/online identifiers, engagement and page-activity data, CRM record fields, and message metadata. The Service is not intended for special-category data; the Customer must not submit it unless separately agreed.
3. Customer obligations
The Customer warrants that it has a lawful basis and has provided all required notices and obtained all required consents for the processing instructed under this DPA — in particular for the pixel and for any person-level visitor resolution — and that its instructions comply with applicable law.
4. Subprocessors
The Customer authorizes Ans·Rev to engage subprocessors to process Customer Personal Data. Ans·Rev imposes data-protection obligations on each subprocessor no less protective than this DPA and remains responsible for their performance. Ans·Rev maintains the current list below and will give advance notice of any intended addition or replacement so the Customer has the opportunity to object on reasonable data-protection grounds; if an objection cannot be resolved, the Customer may terminate the affected Service.
| Subprocessor (category) | Purpose | Processing location |
|---|---|---|
| LLM / answer-engine providers | Run sweeps across answer engines and generate citation-engineered content drafts; no-training terms applied where offered. | US / global |
| SERP & web-data provider | Observe rankings and answer-engine citations across the tracked engines. | US / EU |
| Cloud hosting & infrastructure | Host, run, and store the Service and its databases. | US / EU |
| Data enrichment & IP-to-company | Resolve anonymous visits to company firmographics; enrich accounts. | US |
| Payment processor | Bill subscriptions and process plan payments. | US / global |
| Email delivery provider | Send transactional messages and human-approved outreach on the Customer’s behalf. | US / EU |
Named vendors and regions are finalized on request; the categories and purposes above are binding.
5. Security measures
Ans·Rev maintains technical and organizational measures appropriate to the risk, including:
- encryption of Customer Personal Data in transit and at rest;
- per-workspace logical isolation and strict tenant separation;
- least-privilege access controls, with support access via consented impersonation only;
- hash-chained, tamper-evident audit logging of privileged actions;
- secrets management, network controls, and vulnerability monitoring;
- personnel confidentiality obligations and security training;
- backup, resilience, and documented recovery procedures.
6. Assistance with data-subject requests
Taking into account the nature of the processing, Ans·Rev will provide the Customer reasonable assistance — through appropriate technical and organizational measures and self-service tooling — to respond to data-subject requests to exercise rights of access, rectification, erasure, restriction, portability, and objection under the NDPA, GDPR, CCPA, and similar laws. If Ans·Rev receives such a request directly, it will promptly refer the individual to the Customer and not respond except on the Customer’s instruction or as required by law.
7. Personal data breach notification
Ans·Rev will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its own notification obligations to regulators (such as the Nigeria Data Protection Commission or an EU supervisory authority) and affected individuals. Ans·Rev will take reasonable steps to contain and remediate the breach.
8. Deletion and return
On termination or expiry of the agreement, and at the Customer’s choice, Ans·Rev will delete or return Customer Personal Data within a commercially reasonable period, and delete existing copies except where retention is required by law. The Customer may also export data during the term using the Service’s tooling. Aggregated, de-identified data that cannot be linked to the Customer or individuals may be retained.
9. Audit
Ans·Rev will make available information necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow for and contribute to audits — satisfied first through third-party certifications, reports, and questionnaires, and, where those are insufficient, through a reasonable on-site or remote audit no more than once per year (or after a breach), at the Customer’s expense.
10. International transfers
Where Ans·Rev processes Customer Personal Data outside Nigeria, the EEA, or the UK, it relies on an appropriate transfer mechanism — the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, an adequacy decision, or an NDPA-recognized safeguard — together with supplementary measures where required. The SCCs, where applicable, are incorporated into this DPA by reference, with Ans·Rev as data importer and the Customer as data exporter.
11. General
This DPA supplements and forms part of the agreement. In case of conflict on data-protection matters, this DPA controls. If any provision is invalid, the rest remains in effect. This DPA is governed by the same law as the agreement.
Contact
Data-protection questions or to exercise DPA rights: [email protected]. Ans·Rev, Inc., Delaware, USA.