Skip to main content
Back to home

Data Processing Addendum Template

Last updated: August 29, 2026

Execution required

This page is a review template, not a self-executing agreement. It becomes binding only when an Annot8 contracting entity and the customer execute it or an order form expressly incorporates this version. The executed copy must identify both legal entities, addresses, effective date, transfer modules, notice contacts, and any negotiated changes. Request an execution copy at privacy@annot8.app.

1. Roles and scope

This Data Processing Addendum ("DPA") supplements the agreement for the Annot8 Service. For Customer Personal Data, Customer is the controller or processor that appoints Annot8, and Annot8 is the processor or subprocessor, as applicable. "Customer Personal Data" means personal data processed by Annot8 on the customer’s documented instructions through customer workspaces, widgets, public links, portals, chat, Analytics, recordings, integrations, and customer-configured AI.

Annot8 remains an independent controller for its own account administration, billing, fraud/security, legal compliance, and business-contact processing as described in the Privacy Policy.

2. Instructions and purpose limitation

Annot8 will process Customer Personal Data only to provide, secure, support, and improve the contracted Service in accordance with the agreement, enabled configuration, customer use, support requests, and other documented instructions, unless law requires otherwise. Annot8 will inform Customer if an instruction appears to violate applicable data-protection law and may suspend the affected processing while the parties resolve it.

Customer is responsible for lawful instructions, notices, legal bases, consent, participant recording permission, data accuracy, rights responses, permitted data categories, and configuring roles, domains, retention, AI, Analytics, and integrations.

3. Confidentiality and personnel

Annot8 will limit access to authorized personnel with a need to know, bind them to confidentiality, provide appropriate privacy/security training, and remove access when no longer required. Support access to customer content will be limited to providing support, security, or legally required assistance.

4. Security

Annot8 will maintain measures appropriate to risk, including encrypted transport, managed authentication, role/workspace authorization, domain allowlists, short-lived origin-bound widget sessions, verified webhooks, encrypted integration credentials, restricted production access, dependency and vulnerability management, data minimization, backup/recovery controls, incident response, and deletion procedures. Measures may evolve without materially reducing overall protection.

5. Subprocessors

Customer gives general authorization for subprocessors on the published Subprocessors page. Annot8 will impose materially equivalent data-protection obligations and remains responsible for subprocessor performance to the extent required by law. Executed terms will specify change notice and a reasonable objection process. Customer-selected integrations are governed by the allocation described in the agreement and may not be Annot8 subprocessors.

6. Individual rights and regulatory assistance

Taking into account the nature of processing, Annot8 will provide reasonable technical and organizational assistance for access, correction, deletion, restriction, objection, portability, consent withdrawal, automated-decision safeguards, DPIAs, prior consultation, and regulator inquiries. Annot8 will direct a request concerning customer-controlled data to Customer unless law requires another response. Additional work beyond standard product controls may be subject to reasonable fees where legally permitted.

7. Incidents

Annot8 will notify Customer without undue delay after confirming a breach of Customer Personal Data and provide available information reasonably needed for Customer’s assessment and notification duties, including nature, affected data/people, likely consequences, containment, and contact. Notice is not an admission of fault. Customer is responsible for its authority and individual notifications unless the parties agree otherwise.

8. Return, deletion, and retention

During the term, Customer may use available export and deletion controls. On termination or documented request, Annot8 will delete or return Customer Personal Data according to the executed schedule, except data retained by law or in protected backups that age out under the applicable cycle. Shared content, external integration copies, billing records, security evidence, legal holds, and de-identified data are handled according to their documented role and exception. Annot8 will not actively process isolated backup data except for security, restoration, or legal requirements.

9. Audit information

Annot8 will provide information reasonably necessary to demonstrate compliance, such as security documentation, subprocessor/transfer information, and relevant independent reports when available. If that is insufficient, the executed DPA may permit a proportionate audit subject to confidentiality, security, scope, timing, frequency, and cost protections. Audits may not expose another customer’s data or compromise the Service.

10. International transfers

The execution copy must identify exporter/importer roles and incorporate the applicable 2021 EU Standard Contractual Clause module, UK Addendum or IDTA, and Swiss adaptations where required. The parties will complete the annexes, transfer description, security measures, competent authority, governing member-state law, and supplementary-measures assessment. Conflicting transfer clauses control for the restricted transfer only.

Annex A — processing details

  • Subject and duration: provision of the configured Service for the agreement term plus the approved deletion/backup period.
  • Nature and purposes: collect, host, organize, display, search, transmit, notify, analyze, transcribe, generate, integrate, secure, support, export, and delete customer-controlled data.
  • People: customer personnel, contractors, invitees, website visitors, feedback authors, portal users, chat participants, recording participants, and other people appearing in submitted content.
  • Data: identifiers/contact details; account/workspace roles; feedback/messages; page/DOM/device/diagnostic data; pseudonymous Analytics identifiers/events; screenshots, files, voice/video and transcripts; AI prompts/outputs; integration destinations; notification endpoints; and support/security metadata.
  • Sensitive data: not intended by default. Customer must not submit special-category, highly sensitive, child, payment, health, biometric, or government-ID data without an executed written schedule and appropriate safeguards.
  • Frequency: continuous or event-driven according to customer configuration and user actions.

Annex B — customer choices

The execution copy should record permitted domains/audience, approved countries, retention periods, whether public portals are enabled, consent mechanism, recording exclusions, AI/Analytics status, approved integrations, support-access contacts, deletion/export contacts, and any prohibited pages or data categories.