Compliance
Data Processing Addendum
Effective date: August 28, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between Canvis Software LLC, which operates Mapperoni ("Mapperoni," "we," "us," or "Processor"), and the customer accepting the Agreement ("Customer" or "Controller"). It applies only where Mapperoni processes Personal Data on Customer's behalf in providing the Service. The Agreement controls for matters not addressed here; this DPA controls to the extent of a conflict about Processing Customer Personal Data.
1. Definitions and roles
"Applicable Data Protection Law" means data-protection laws applicable to the Processing of Customer Personal Data, including the GDPR where applicable. "GDPR" means Regulation (EU) 2016/679. "Personal Data," "Controller," "Processor," "Data Subject," "Processing," and "Personal Data Breach" have the meanings given in the GDPR.
"Customer Personal Data" means Personal Data that Customer, its users, or respondents submit to the Service or otherwise make available to Mapperoni for Processing on Customer's behalf. It does not include business-contact, billing, or account-administration information that Mapperoni processes as an independent controller.
For Customer Personal Data, Customer is the Controller and Mapperoni is the Processor. Customer is responsible for establishing the lawful basis for its Processing, giving required notices, and complying with Controller obligations. This DPA does not apply where Mapperoni acts as an independent Controller.
2. Documented instructions
Mapperoni will Process Customer Personal Data only on Customer's documented instructions, including the Agreement, this DPA, and Customer's use and configuration of the Service, unless Applicable Data Protection Law requires otherwise. If legally permitted, Mapperoni will notify Customer before Processing required by law. Mapperoni will promptly inform Customer if it believes an instruction infringes Applicable Data Protection Law.
Customer must not instruct Mapperoni to Process Customer Personal Data in violation of Applicable Data Protection Law. In particular, Customer is responsible for any special-category data under GDPR Article 9 and must ensure it has an appropriate lawful basis and any required explicit consent, authorization, or other condition before collecting or instructing Mapperoni to Process it.
3. Confidentiality and security
Mapperoni will ensure that persons authorized to Process Customer Personal Data are subject to confidentiality obligations or an appropriate statutory duty of confidentiality. Mapperoni will implement the technical and organizational measures described in Schedule 2, taking account of the nature, scope, context, and purposes of Processing and the risks to Data Subjects.
4. Assistance
Taking account of the nature of Processing, Mapperoni will provide reasonable assistance to Customer through the Service and, where reasonably necessary, other appropriate measures to help Customer respond to Data Subject requests. If Mapperoni receives a request directly from a Data Subject relating to Customer Personal Data, Mapperoni will not respond except as Customer instructs or Applicable Data Protection Law requires; it will direct the Data Subject to Customer or, where reasonably practicable, notify Customer.
Mapperoni will provide reasonable assistance, taking account of the nature of Processing and information available to Mapperoni, with Customer's obligations under GDPR Articles 32 to 36. Customer remains responsible for determining whether a notification, consultation, impact assessment, or other action is required.
5. Personal Data Breaches
Mapperoni will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will include information then available that Customer reasonably needs to meet its legal obligations. Mapperoni may provide information in phases as it becomes available. Customer is responsible for making notifications to supervisory authorities and Data Subjects unless Applicable Data Protection Law requires otherwise.
6. Subprocessors
Customer gives general authorization for Mapperoni to engage the subprocessors listed at mapperoni.com/subprocessors. Mapperoni will require each subprocessor to protect Customer Personal Data with obligations materially no less protective than those in this DPA, appropriate to the Processing it performs.
Mapperoni may add or replace subprocessors by updating that page at least 30 days before the change takes effect. Customer may object on reasonable data-protection grounds by emailing legal@mapperoni.com within that period. The parties will work in good faith to address the objection. If they cannot do so, Customer may terminate the affected Service without penalty before the new subprocessor begins Processing Customer Personal Data; this is Customer's sole remedy for the objection.
7. International transfers
Customer acknowledges that Mapperoni is a California company and its authorized administrator may access Customer Personal Data from the United States to operate, support, and secure the Service, even though the production database and backups are hosted in Germany. Where a transfer of Customer Personal Data from the EEA requires an approved transfer mechanism, the parties incorporate the European Commission's 2021 Standard Contractual Clauses ("EU SCCs"), Module Two (Controller to Processor), into this DPA. Transfers from the United Kingdom or Switzerland require the applicable UK or Swiss addendum or another valid transfer mechanism, where required by law.
For the EU SCCs: the Customer is the data exporter; Canvis Software LLC is the data importer; the optional docking clause is not used; general written authorization for subprocessors applies with the notice and objection process in Section 6; the data importer may use the subprocessors in the public list; and the processing and safeguards in Schedules 1 and 2 complete Annexes I and II. The governing law and courts under Clauses 17 and 18 are those of Ireland. The competent supervisory authority is determined under Clause 13 of the EU SCCs. The parties will make reasonable supplementary arrangements if needed for a valid transfer under Applicable Data Protection Law.
This section is a transfer mechanism. It does not change the Controller-Processor allocation in this DPA or Customer's Article 28 responsibilities.
8. Return, deletion, and retention
During the Subscription Term, Customer can export project data using the Service. On termination or at Customer's instruction, Mapperoni will delete or return Customer Personal Data from active systems, unless Applicable Data Protection Law requires retention. Customer may delete projects, teams, and individual submissions in the Service, subject to applicable subscription constraints. Deletion from active systems does not immediately remove data from encrypted backups; backup copies are overwritten and pruned under Mapperoni's backup lifecycle as described in the Privacy Policy. Mapperoni may retain the minimum information needed to meet legal obligations, resolve disputes, enforce the Agreement, or maintain security, and will protect it under this DPA for as long as retained.
9. Compliance information and audits
Upon reasonable written request no more than once in any 12-month period, Mapperoni will provide information reasonably necessary to demonstrate compliance with this DPA. If that information is insufficient, Customer may request a remote audit or inspection by an independent auditor bound by confidentiality, with at least 30 days' written notice, during normal business hours, and without unreasonable interference with Mapperoni's operations or access to other customers' information. Customer bears its audit costs and will use an existing audit report or equivalent information where reasonably sufficient. Additional audits are permitted where required by a supervisory authority or following a confirmed Personal Data Breach materially affecting Customer Personal Data.
10. Duration and liability
This DPA begins when Customer accepts the Agreement and remains in effect while Mapperoni Processes Customer Personal Data. The parties' liability under this DPA is subject to the limitations and exclusions in the Agreement, to the extent permitted by Applicable Data Protection Law.
Schedule 1: Processing details
| Item | Description |
|---|---|
| Subject matter | Provision of Mapperoni's survey, form-builder, collaborative-map, team-management, and related support services. |
| Duration | For the Subscription Term and thereafter only as necessary for deletion, backup expiry, legal retention, security, or dispute resolution. |
| Nature and purpose | Hosting, storing, organizing, transmitting, displaying, securing, supporting, exporting, and deleting Customer Personal Data as directed through Customer's use of the Service. |
| Data Subjects | Customer's authorized users and team members; respondents and prospective respondents; and any individuals whose Personal Data Customer elects to include in projects, forms, map features, or responses. |
| Categories of Personal Data | Account and team details; project, form, map, and configuration content; response answers; identifiers; contact details; approximate or precise location data; device or session identifiers; and any other data Customer elects to collect. Customer controls the fields and content of its projects. |
| Special categories | Customer may configure fields that collect special-category data. Customer must not do so unless it has met all requirements of Applicable Data Protection Law, including an Article 9 condition where the GDPR applies. |
| Processing operations | Collection through Customer-configured projects, storage in the Service, access according to Customer's permissions, export by authorized users, support and security operations, and deletion or anonymization as described in the Agreement and this DPA. |
Schedule 2: Technical and organizational measures
Mapperoni maintains measures appropriate to the Service and the risks of Processing, including:
- HTTPS/TLS for the production Service, with Caddy-managed certificates and strict transport security.
- Production application and PostgreSQL database hosting in Germany through Hetzner, with encrypted database backups stored in a separate Hetzner Germany location.
- Application authentication and server-side authorization controls. Team roles restrict administrative and project actions, and project visibility, access, and contribution settings are configurable by Customer.
- Session protection, CSRF protection, secure production cookies, and content-security-policy and security headers in the application.
- Project-data export available only to authorized team users. Individual submission deletion permanently removes response and map-feature content from active application data and tombstones the submission record; project and team deletion use database cascades for associated project data. Account deletion deletes the account and authentication tokens but anonymizes associated contribution records to preserve a Customer's project dataset.
- Daily database backups with integrity checks. The local backup repository retains seven daily snapshots; the remote repository retains seven daily, four weekly, and twelve monthly snapshots before pruning. Backup copies are encrypted by the backup system.
- Production application, database, and backup logs are size-limited. Mapperoni does not log exported response values or CSV contents.
These measures describe the controls in place as of the effective date and may be updated, provided that Mapperoni does not materially decrease the overall security of the Service.
