Waygo Inc.
This Data Processing Addendum (the "DPA") forms part of the agreement between Waygo Inc., an Ontario corporation with a place of business at 41 Windhaven Terrace, Thornhill, Ontario, Canada L4J 7N8 ("Waygo"), and the customer identified in the applicable Order Form ("Customer") governing Customer's use of the Services (the "Agreement"). It is incorporated into the Agreement by reference. It sets out the terms on which Waygo processes personal data on Customer's behalf.
Customer enters into this DPA on behalf of itself and, to the extent required under Applicable Data Protection Law, on behalf of any affiliates that use the Services under the Agreement.
1. Definitions
Capitalised terms not defined in this DPA have the meanings given in the Agreement. In this DPA:
- "Applicable Data Protection Law" means all laws and regulations applicable to the processing of Customer Personal Data under the Agreement, including, as applicable: (a) Regulation (EU) 2016/679 (the "GDPR") and the laws of EU Member States implementing it; (b) the GDPR as incorporated into the law of the United Kingdom by the European Union (Withdrawal) Act 2018 (the "UK GDPR") and the Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection (the "FADP"); (d) the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 and its regulations (the "CCPA"), and all other United States state laws governing the processing of personal data (together with the CCPA, "US State Privacy Laws"); (e) the Personal Information Protection and Electronic Documents Act (Canada) ("PIPEDA") and provincial legislation deemed substantially similar to it, including the Act respecting the protection of personal information in the private sector (Quebec); and (f) the Personal Information Protection Act of the Republic of Korea ("PIPA"); in each case as amended, replaced or superseded from time to time.
- "Customer Data" has the meaning given in the Agreement.
- "Customer Personal Data" means Personal Data contained in Customer Data that Waygo processes on behalf of Customer in providing the Services.
- "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "processing" (and its cognates) and "Supervisory Authority" have the meanings given in the GDPR. Where Applicable Data Protection Law uses different terms for equivalent concepts — including "business", "service provider" and "consumer" under the CCPA; "organisation" and "individual" under PIPEDA; and "personal information controller" and "outsourcee" under PIPA — those terms are to be read accordingly.
- "Services" means the services Waygo provides to Customer under the Agreement.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries annexed to European Commission Implementing Decision (EU) 2021/914.
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force from 21 March 2022.
- "Sub-processor" means any third party engaged by Waygo to process Customer Personal Data on Waygo's behalf in connection with the Services.
2. Scope, roles and precedence
- This DPA applies to Waygo's processing of Customer Personal Data in providing the Services. The subject matter, duration, nature and purpose of the processing, and the categories of Data Subjects and Personal Data, are described in Annex 1.
- As between the parties, Customer is the Controller and Waygo is the Processor of Customer Personal Data, except as set out in Section 15.
- If there is a conflict between this DPA and the Agreement with respect to the processing of Customer Personal Data, this DPA prevails. If there is a conflict between this DPA and the Standard Contractual Clauses or the UK Addendum, the Standard Contractual Clauses or the UK Addendum prevail to the extent of the conflict.
- Nothing in this DPA reduces any protection afforded to Data Subjects under Applicable Data Protection Law.
3. Customer obligations
- Customer is responsible for the lawfulness of its own processing and of the instructions it gives to Waygo, including for establishing a lawful basis for the processing of Customer Personal Data and for providing all notices to, and obtaining all consents from, Data Subjects that Applicable Data Protection Law requires — including in respect of event attendees, registrants, exhibitors, speakers and other individuals whose Personal Data Customer causes to be processed through the Services or through any integration Customer connects.
- Customer shall not, and shall not permit any user to, submit to the Services any Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic data; biometric data; data concerning health, sex life or sexual orientation; government-issued identification numbers; payment card data; or Personal Data relating to criminal convictions or offences, unless Waygo has agreed in writing in advance to receive it.
- Customer is responsible for the accuracy, quality and legality of Customer Personal Data and for the means by which Customer acquired it.
- Customer shall configure and use the Services, including any user accounts, API keys and integrations, in a manner consistent with Applicable Data Protection Law.
4. Processing on documented instructions
- Waygo shall process Customer Personal Data only on Customer's documented instructions, including with regard to transfers of Customer Personal Data to a third country, unless required to do so by law to which Waygo is subject. In that case Waygo shall inform Customer of the legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
- The Agreement, this DPA, and Customer's use and configuration of the Services (including the connection of any integration and the settings Customer applies within the platform) together constitute Customer's complete and documented instructions. Additional or alternative instructions must be agreed in writing.
- Waygo shall inform Customer without undue delay if, in Waygo's opinion, an instruction infringes Applicable Data Protection Law. Waygo may suspend performance of the affected instruction until Customer confirms or modifies it.
- Waygo shall not process Customer Personal Data for its own purposes except as expressly permitted in Section 15.
5. Personnel
- Waygo shall limit access to Customer Personal Data to those personnel who need that access to provide, support and secure the Services.
- Waygo shall ensure that all personnel authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and have received training appropriate to their role.
- Waygo is responsible for the acts and omissions of its personnel in relation to Customer Personal Data as for its own.
6. Security
- Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Waygo shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including the measures described in Annex 2.
- Waygo may update the measures in Annex 2 from time to time, provided that any update does not materially reduce the overall level of protection of Customer Personal Data.
7. Sub-processors
- Customer provides general written authorisation for Waygo to engage Sub-processors to process Customer Personal Data in connection with the Services.
- Waygo maintains a current list of Sub-processors, including each Sub-processor's identity, location and the nature of the processing it performs, at waygomaps.com/legal/subprocessors. The list as at the effective date of this DPA is reproduced in Annex 3.
- Waygo shall notify Customer of any intended addition or replacement of a Sub-processor at least thirty (30) days before that Sub-processor begins processing Customer Personal Data, by email to Customer's designated account contact and by updating the list referred to in Section 7.2.
- Customer may object to a new Sub-processor on reasonable grounds relating to data protection by notifying Waygo in writing within thirty (30) days of the notice. The parties shall discuss the objection in good faith. If Waygo cannot reasonably accommodate the objection, Customer may terminate the affected Services on written notice without penalty, and Waygo shall refund any fees prepaid for the terminated Services in respect of the period after termination.
- Waygo shall enter into a written agreement with each Sub-processor imposing data-protection obligations that are no less protective of Customer Personal Data than those in this DPA, to the extent applicable to the services the Sub-processor provides.
- Waygo remains fully liable to Customer for the performance of each Sub-processor's obligations.
8. Data Subject requests
- Taking into account the nature of the processing, Waygo shall assist Customer, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling Customer's obligation to respond to requests by Data Subjects to exercise their rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making.
- If Waygo receives a request from a Data Subject relating to Customer Personal Data, Waygo shall not respond to it except to acknowledge receipt and to direct the Data Subject to Customer, and shall forward the request to Customer within five (5) business days of receipt, unless prohibited by law.
- The Services provide Customer with the ability to access, correct, export and delete Customer Personal Data. To the extent a request cannot be fulfilled by Customer using the Services, Waygo shall provide reasonable assistance on written request. Waygo may charge a reasonable fee for assistance that is manifestly excessive or that requires significant manual effort, and shall inform Customer of any such fee in advance.
9. Personal Data Breach
- Waygo shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
- The notification shall, to the extent the information is available to Waygo at the time, describe: (a) the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address it, including measures to mitigate its possible adverse effects; and (d) a point of contact at Waygo. Where it is not possible to provide all of this information at the same time, Waygo shall provide it in phases without undue further delay.
- Waygo shall cooperate with Customer and take such reasonable steps as Customer may direct to assist in the investigation, mitigation and remediation of the Personal Data Breach, and shall provide such further information as Customer reasonably requires to meet its own notification obligations to Supervisory Authorities and Data Subjects.
- Waygo's notification of, or response to, a Personal Data Breach is not an acknowledgement by Waygo of any fault or liability.
10. Assistance with impact assessments and consultation
Taking into account the nature of the processing and the information available to Waygo, Waygo shall provide Customer with reasonable assistance in carrying out data protection impact assessments and in consulting with Supervisory Authorities where Customer reasonably considers this to be required by Applicable Data Protection Law in relation to the processing of Customer Personal Data by Waygo.
11. Deletion and return
- During the term of the Agreement, Customer may access, export and delete Customer Personal Data using the functionality of the Services.
- Following termination or expiry of the Agreement, Waygo shall make Customer Data available to Customer for export through the Services for a period of thirty (30) days (the "Retrieval Period").
- Within thirty (30) days after the end of the Retrieval Period, Waygo shall delete all Customer Personal Data from its production systems, or, where Customer has so elected in writing before the end of the Retrieval Period, return Customer Personal Data to Customer in a commonly used, machine-readable format and then delete it. Customer Personal Data held in backups shall be deleted in accordance with Waygo's ordinary backup rotation cycle, and in any event within [90] days after deletion from production systems.
- Waygo shall certify deletion in writing on Customer's request.
- Waygo may retain Customer Personal Data only to the extent and for the period required by law to which Waygo is subject, or under a documented legal hold that Waygo has notified to Customer, in which case Waygo shall continue to protect the retained data in accordance with this DPA and shall process it only for the purpose of the legal requirement.
12. Audit and information
- Waygo shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations in this DPA.
- Waygo shall allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer and reasonably acceptable to Waygo, subject to the following conditions: (a) Customer shall give at least thirty (30) days' written notice, except where an audit is required by a Supervisory Authority or follows a Personal Data Breach; (b) audits shall take place no more than once in any twelve-month period, except in the circumstances described in (a); (c) audits shall be conducted during normal business hours, in a manner that does not unreasonably disrupt Waygo's operations, and subject to reasonable confidentiality obligations; and (d) Customer shall bear its own costs and Waygo's reasonable costs of any audit that exceeds one business day.
- Where Waygo holds a current independent third-party attestation or certification covering the Services (such as a SOC 2 report or ISO/IEC 27001 certificate), Waygo may provide it in satisfaction of an audit request, and Customer shall rely on it unless it has reasonable grounds to believe the report does not address the matter of concern.
- Waygo shall promptly inform Customer if it becomes aware that it can no longer meet its obligations under this DPA.
13. International transfers
- Waygo processes Customer Personal Data in Canada (Google Cloud Platform, region northamerica-northeast2, and MongoDB Atlas, Google Cloud Platform northamerica-northeast2) and in the locations of its Sub-processors as identified in the list referred to in Section 7.2.
- Customer authorises Waygo to transfer Customer Personal Data to, and process it in, those locations, subject to the safeguards in this Section 13 and Section 14.
- Where a transfer of Customer Personal Data from a jurisdiction to another jurisdiction requires a transfer mechanism under Applicable Data Protection Law, the parties shall rely on the mechanism identified in Section 14 and Annex 4 for that jurisdiction, or on any other mechanism recognised under Applicable Data Protection Law as agreed between the parties.
- Waygo shall not transfer Customer Personal Data to any Sub-processor located outside the jurisdictions identified under Section 7.2 without ensuring that an appropriate transfer mechanism is in place.
14. Jurisdiction-specific terms
The terms in this Section 14 apply to the extent Applicable Data Protection Law of the relevant jurisdiction applies to the processing of Customer Personal Data.
14.1 European Economic Area and Switzerland
- Waygo is subject to PIPEDA, in respect of which the European Commission has adopted an adequacy decision (Decision 2002/2/EC). To the extent that decision applies to a transfer of Customer Personal Data to Waygo, the parties rely on it.
- To the extent a transfer of Customer Personal Data subject to the GDPR is not covered by an adequacy decision or another appropriate safeguard, the parties enter into the Standard Contractual Clauses, Module Two (transfer controller to processor), which are incorporated into this DPA by reference and completed as set out in Annex 4, with Customer as data exporter and Waygo as data importer.
- For Customer Personal Data subject to the FADP, the Standard Contractual Clauses apply with the modifications set out in Annex 4, including that references to the GDPR are read as references to the FADP, the Federal Data Protection and Information Commissioner is the competent supervisory authority, and Data Subjects in Switzerland may enforce their rights before Swiss courts.
14.2 United Kingdom
- To the extent a transfer of Customer Personal Data subject to the UK GDPR is covered by adequacy regulations made under the Data Protection Act 2018 (including in respect of Canada), the parties rely on those regulations.
- To the extent such a transfer is not so covered, the parties enter into the Standard Contractual Clauses as modified by the UK Addendum, which is incorporated into this DPA by reference and completed as set out in Annex 4.
14.3 United States
- To the extent Waygo processes Customer Personal Data on behalf of Customer as a "business" (or equivalent term) under any US State Privacy Law, Waygo acts as a "service provider", "processor" or "contractor" (as those terms are defined under the applicable law), and this Section 14.3 applies.
- Waygo shall process Customer Personal Data solely for the business purposes described in Annex 1 and shall not: (a) sell or share Customer Personal Data (as "sell" and "share" are defined under the CCPA), or otherwise disclose it for monetary or other valuable consideration or for cross-context behavioural or targeted advertising; (b) retain, use or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement and this DPA, including any commercial purpose other than providing the Services; (c) retain, use or disclose Customer Personal Data outside the direct business relationship between Waygo and Customer; or (d) combine Customer Personal Data with Personal Data that Waygo receives from or on behalf of another person, or collects from its own interaction with a consumer, except as permitted by the CCPA and its regulations for the performance of a business purpose.
- Waygo shall comply with all applicable obligations under US State Privacy Laws and shall provide the same level of privacy protection as those laws require of Customer.
- Waygo shall notify Customer without undue delay if Waygo determines that it can no longer meet its obligations under this Section 14.3.
- Customer has the right, on reasonable notice, to take reasonable and appropriate steps to ensure that Waygo uses Customer Personal Data in a manner consistent with Customer's obligations under US State Privacy Laws, and to stop and remediate any unauthorised use of Customer Personal Data.
- Waygo shall assist Customer in responding to verifiable consumer requests in accordance with Section 8, and shall, at Customer's direction, delete or enable Customer to delete Customer Personal Data about a consumer and instruct its Sub-processors to do the same, except to the extent retention is permitted by an exemption under the applicable law.
- Waygo shall ensure that each Sub-processor that processes Customer Personal Data is bound by a written contract containing the obligations in this Section 14.3.
- Waygo certifies that it understands the restrictions in this Section 14.3 and will comply with them.
14.4 Canada
- For the purposes of PIPEDA and substantially similar provincial legislation, Waygo processes Customer Personal Data as a service provider on Customer's behalf, and Customer remains accountable for Customer Personal Data in Waygo's custody. This DPA constitutes the contractual means by which Customer ensures a comparable level of protection while Customer Personal Data is being processed by Waygo.
- Waygo has appointed a Privacy Representative who is accountable for Waygo's compliance with Applicable Data Protection Law and this DPA, whose contact details are set out in Section 18. Waygo shall notify Customer of any change of Privacy Representative.
- Customer acknowledges that Customer Personal Data may be processed and stored outside Canada in the locations identified under Section 13.1, and confirms that it has provided any notices and obtained any consents required under Applicable Data Protection Law for that processing.
- If Waygo or a Sub-processor receives a demand for disclosure of Customer Personal Data from a court, government authority or other person outside Canada that would not be permitted under Applicable Data Protection Law (a "Foreign Demand"), Waygo shall, unless prohibited by law, notify Customer of the Foreign Demand before disclosing any Customer Personal Data, cooperate with Customer in seeking to limit or resist the disclosure, and disclose only the minimum Customer Personal Data required. Nothing in this Section prevents Waygo from complying with an order of a court of competent jurisdiction in Canada.
- Where Customer is subject to the Act respecting the protection of personal information in the private sector (Quebec), Customer is responsible for conducting any privacy impact assessment required before communicating Customer Personal Data outside Quebec, and Waygo shall provide the information reasonably necessary for that assessment on request.
- Waygo's notification obligations under Section 9 are intended to enable Customer to comply with its breach-reporting and record-keeping obligations under section 10.1 of PIPEDA and equivalent provincial provisions. Where Waygo has an independent reporting obligation under Applicable Data Protection Law, Waygo shall comply with it and shall coordinate with Customer to the extent practicable.
14.5 Republic of Korea
- For the purposes of PIPA, Customer is the personal information controller and Waygo is the outsourcee to which Customer entrusts the processing of Customer Personal Data. This DPA constitutes the written outsourcing agreement required by Article 26 of PIPA, and the parties agree that: (a) the purpose and scope of the outsourced processing are as described in Annex 1; (b) Waygo shall not further entrust the processing to a third party except in accordance with Section 7; (c) Waygo shall implement the technical and administrative safeguards described in Annex 2, including restrictions on access to Customer Personal Data; (d) Customer may supervise Waygo's processing in accordance with Section 12, including by inspection; (e) Waygo is liable for damage caused to Data Subjects by Waygo's breach of this DPA in accordance with Section 16; and (f) Waygo shall not use Customer Personal Data beyond the scope of the outsourced processing or provide it to a third party except as permitted by this DPA.
- Customer consents to Waygo's disclosure of the existence and content of the outsourcing arrangement as required by PIPA, and Waygo consents to being identified by Customer as its outsourcee in any disclosure Customer is required to make under Article 26 of PIPA.
- Customer is responsible for establishing a lawful basis under Article 28-8 of PIPA for the transfer of Customer Personal Data outside the Republic of Korea, whether by obtaining the separate consent of Data Subjects, by disclosure in Customer's privacy policy where the transfer is necessary for the performance of a contract with the Data Subject, or by another basis permitted under PIPA. Waygo shall provide Customer, on request, with the information Customer is required to notify to Data Subjects or to disclose for that purpose, including the identity of the recipient, the country of transfer, the purpose of transfer, the items of Personal Data transferred, and the period and method of retention and use.
- Waygo shall apply to Customer Personal Data originating from the Republic of Korea a level of protection equivalent to that required under PIPA.
15. Waygo's independent processing
- Account Data. Waygo processes Personal Data relating to Customer's users of the Services — including names, business email addresses, roles, authentication credentials, and records of their use of the Services ("Account Data") — as an independent Controller, for the purposes of providing, securing, administering and improving the Services and communicating with users about them. Waygo's processing of Account Data is described in the Waygo Privacy Policy at waygomaps.com/legal/privacy.
- Aggregate Data. Waygo may create and use data derived from Customer Data that has been aggregated across customers or de-identified such that it does not identify, and could not reasonably be used to identify, any individual, household, Customer, or event ("Aggregate Data"), for the purposes of operating, analysing, developing and improving the Services and Waygo's other products. Waygo shall (a) implement technical measures that prohibit re-identification; (b) publicly commit to maintain and use Aggregate Data only in de-identified form and not to attempt to re-identify it; and (c) contractually obligate any recipient of Aggregate Data to comply with the same restrictions. Aggregate Data is not Customer Personal Data. Waygo shall not use Aggregate Data in any manner that would constitute a sale or sharing of Personal Data under Applicable Data Protection Law.
16. Liability
- Each party's liability arising out of or relating to this DPA, whether in contract, tort or under any other theory of liability, is subject to the exclusions and limitations of liability set out in the Agreement, and any reference in the Agreement to a party's liability means the aggregate liability of that party under the Agreement and this DPA together.
- Nothing in this Section 16 limits the liability of either party to Data Subjects under the Standard Contractual Clauses or the UK Addendum, or any liability that cannot be limited under Applicable Data Protection Law.
17. Term, changes and general
- This DPA takes effect on the later of the effective date of the Agreement and the effective date of this version of the DPA, and remains in force for as long as Waygo processes Customer Personal Data.
- Waygo may update this DPA from time to time by publishing a new version at waygomaps.com/legal/dpa and notifying Customer's designated account contact by email at least thirty (30) days before the new version takes effect, provided that no update shall materially reduce the protection afforded to Customer Personal Data. If Customer reasonably considers that an update materially reduces that protection, Customer may object in writing within the notice period, in which case the parties shall discuss the objection in good faith and, if it is not resolved, Customer may terminate the Agreement on written notice without penalty. Previous versions of this DPA remain available at the address above.
- If any provision of this DPA is held invalid or unenforceable, that provision shall be limited to the minimum extent necessary and the remaining provisions shall remain in full force.
- This DPA is governed by the law governing the Agreement, except that the Standard Contractual Clauses and the UK Addendum are governed by the law specified in them.
- Waygo shall provide a countersigned copy of this DPA on Customer's request. In the event of any inconsistency between the published version of this DPA and a countersigned copy, the countersigned copy prevails as between the parties.
- This DPA is drafted in English. Any translation is provided for convenience only, and the English version prevails.
18. Contact
Notices to Waygo under this DPA, requests for assistance, and Data Subject requests should be sent to legal@waygomaps.com. Waygo's Privacy Representative is Matthew Isen, CEO, who can be reached at the same address.
Annex 1 — Details of processing
A. Parties
- Data exporter / Controller: Customer, as identified in the Order Form. Activities relevant to the transfer: use of the Services to create, manage and publish interactive maps of events and venues, and to manage related content and reservations. Role: Controller.
- Data importer / Processor: Waygo Inc., 41 Windhaven Terrace, Thornhill, Ontario, Canada L4J 7N8. Contact: legal@waygomaps.com. Activities relevant to the transfer: provision of the Services. Role: Processor.
B. Description of the processing
- Subject matter: the provision by Waygo of an interactive mapping and reservation platform for events and venues, including map creation, content management, search, wayfinding, reservations, and integrations with third-party platforms that Customer connects.
- Duration: the term of the Agreement, plus the Retrieval Period and deletion period described in Section 11.
- Nature and purpose: collection (via Customer's upload and via integrations Customer connects), storage, organisation, structuring, retrieval, display, transmission to Customer's authorised users and to end users of Customer's published maps, and deletion — solely to provide, configure, operate, maintain, support and secure the Services for Customer.
- Categories of Data Subjects:
- Customer's employees, contractors and representatives who administer or use the Services;
- exhibitors, vendors, sponsors and their representatives whose information Customer places on maps;
- speakers, session participants and other individuals featured in event content;
- attendees and registrants of Customer's events, to the extent Customer causes their information to be processed through the Services or a connected integration, or to the extent they interact with Customer's published maps.
- Categories of Personal Data:
- identification and contact data: name, business email address, telephone number, organisation, job title or role;
- event-related data: booth, stand or session assignments; reservation records; profile descriptions; images and logos submitted by or relating to the individual;
- account data for Customer's users: authentication credentials (stored in hashed form), role and permission assignments, and records of use of the Services;
- end-user interaction data generated when an individual uses a published map: search terms entered, map locations viewed, and route requests made. Waygo does not associate this interaction data with any persistent identifier of the individual (such as a cookie identifier, device identifier, IP address or account), and it is not linked to the identity of an attendee or registrant.
- Special categories of Personal Data: none. Customer has agreed under Section 3.2 not to submit special categories of Personal Data to the Services.
- Frequency of the processing: continuous for the duration of the Agreement.
- Retention: Customer Personal Data is retained for the duration of the Agreement and deleted in accordance with Section 11. End-user interaction data described in item 4 above is retained for 13 months from the date of collection and then deleted. Application and security logs are retained for 90 days. Backups are retained in accordance with Section 11.3.
- Sub-processors and transfers: as described in Section 7, Section 13 and Annex 3.
C. Competent Supervisory Authority (for the Standard Contractual Clauses)
The supervisory authority of the EU Member State in which the data exporter is established or, where the data exporter is not established in the EU, the supervisory authority of the Member State in which the data exporter's representative is established or in which the Data Subjects whose Personal Data is transferred are located, as determined in accordance with Clause 13 of the Standard Contractual Clauses.
Annex 2 — Technical and organisational measures
Waygo implements the following measures to protect Customer Personal Data. These measures are supplemented by the security measures of Waygo's Sub-processors, each of which maintains independent certifications (including SOC 2 and ISO/IEC 27001) covering the infrastructure services it provides.
Encryption
- All data in transit between users and the Services, between the Services and Sub-processors, and between the Services and connected integrations is encrypted using TLS.
- All Customer Data at rest in Waygo's database and object storage is encrypted using the encryption-at-rest capabilities of the underlying infrastructure providers.
- User passwords are stored only in salted, hashed form using an adaptive key-derivation function, and are never stored or transmitted in plaintext. API keys are stored only in hashed form and are displayed to the Customer once, at creation.
Access control
- Access to Customer Data through the Services is governed by role-based access control. Customer administers the roles assigned to its own users.
- Programmatic access is governed by API keys with defined permission scopes, which are issued and managed by Customer's administrators.
- Customer Data is logically segregated by customer account in all data stores, and every query against Customer Data is scoped to the account on whose behalf it is made.
- Waygo personnel access to production systems and Customer Data is restricted to individuals with a need to know for providing, supporting and securing the Services, is granted on the principle of least privilege, and is bound by confidentiality obligations.
- Sessions are authenticated using short-lived access tokens.
Infrastructure and operations
- The Services are hosted on infrastructure operated by Waygo's Sub-processors, which maintain physical and environmental security controls, network security controls and availability controls for their data centres.
- Production systems are logically separated from development and test systems.
- Application and security logs are collected centrally and retained for the period described in Annex 1.
- Customer Data is backed up on a regular automated schedule, and backups are encrypted and retained in accordance with Section 11.3.
Secure development and vulnerability management
- Changes to the Services are made through version-controlled source code and are deployed through a controlled build and release process.
- Waygo monitors its software dependencies for published vulnerabilities and applies security updates in a timely manner appropriate to the severity of the vulnerability.
- Waygo conducts periodic security reviews of the Services and remediates identified findings according to their severity.
Incident response
- Waygo maintains an incident response procedure for identifying, assessing, containing and remediating security incidents, and for notifying affected customers in accordance with Section 9.
Personnel
- Waygo personnel with access to Customer Personal Data are bound by confidentiality obligations and receive training appropriate to their role.
- Access rights are reviewed periodically and are removed when no longer required.
Data minimisation and end-user privacy
- Waygo does not collect or store IP addresses, device identifiers, cookie identifiers or other persistent identifiers of end users who interact with Customer's published maps, and does not associate end-user interaction data with the identity of any attendee or registrant.
- Waygo does not use Customer Personal Data to build profiles of individuals.
Annex 3 — Sub-processors
The current list of Sub-processors, including any changes made after the effective date of this DPA, is maintained at waygomaps.com/legal/subprocessors. The list as at the effective date of this version of the DPA is:
- Google LLC (Google Cloud Platform) — 1600 Amphitheatre Parkway, Mountain View, California 94043, United States. Service: cloud hosting, object storage and logging. Data: all Customer Data. Location: northamerica-northeast2.
- MongoDB, Inc. (MongoDB Atlas) — 1633 Broadway, 38th Floor, New York, New York 10019, United States. Service: managed database hosting. Data: all Customer Data at rest. Location: northamerica-northeast2.
- Mapbox, Inc. — 740 15th Street NW, 5th Floor, Washington, DC 20005, United States. Service: map tile hosting and rendering. Data: content labels and content attributes that Customer publishes to its maps. Location: United States.
- Resend, Inc. — 2261 Market Street #5039, San Francisco, CA 94114, United States. Service: transactional email delivery. Data: names and email addresses of Customer's users. Location: United States.
Third-party platforms that Customer chooses to connect to the Services (such as event-registration or ticketing systems) are Customer's own service providers, not Sub-processors of Waygo. Data exchanged with those platforms is transmitted on Customer's instruction, and the terms of Customer's agreement with each such platform govern that platform's processing.
Annex 4 — Transfer mechanisms
A. Standard Contractual Clauses (EU)
Where Section 14.1 applies, the Standard Contractual Clauses are incorporated into this DPA and completed as follows:
- Module: Module Two (transfer controller to processor).
- Clause 7 (docking clause): applies.
- Clause 9 (use of sub-processors): Option 2, general written authorisation. The time period for prior notice of Sub-processor changes is thirty (30) days.
- Clause 11(a) (redress): the optional language is not included.
- Clause 13 (supervision): the competent supervisory authority is as identified in Annex 1, Part C.
- Clause 17 (governing law): Option 1. The Clauses are governed by the law of Ireland.
- Clause 18 (choice of forum): disputes shall be resolved before the courts of Ireland.
- Annex I.A (list of parties) and I.B (description of transfer): as set out in Annex 1 of this DPA.
- Annex I.C (competent supervisory authority): as set out in Annex 1, Part C of this DPA.
- Annex II (technical and organisational measures): as set out in Annex 2 of this DPA.
- Annex III (list of sub-processors): as set out in Annex 3 of this DPA and the list referred to in Section 7.2.
B. Swiss modifications
Where the FADP applies to a transfer, the Standard Contractual Clauses apply with the following modifications: references to "the GDPR" are read as references to the FADP; references to "Member State" are read as including Switzerland; the Federal Data Protection and Information Commissioner is the competent supervisory authority under Clause 13; Data Subjects in Switzerland may bring proceedings in Switzerland under Clause 18; and the Clauses protect the data of legal entities to the extent the FADP so requires.
C. UK Addendum
Where Section 14.2 applies, the UK Addendum is incorporated into this DPA and completed as follows:
- Table 1 (parties): as set out in Annex 1, Part A of this DPA. Key contact for each party: as set out in the Order Form (Customer) and Section 18 (Waygo).
- Table 2 (selected SCCs, modules and clauses): the Standard Contractual Clauses as completed in Part A of this Annex 4, Module Two, with the selections made in Part A.
- Table 3 (appendix information): Annex 1A and 1B as set out in Annex 1 of this DPA; Annex II as set out in Annex 2 of this DPA; Annex III as set out in Annex 3 of this DPA.
- Table 4 (ending the Addendum when the approved Addendum changes): the data importer may end the UK Addendum as set out in Section 19 of the UK Addendum.
Previous versions: none. This is the first published version.
Countersigned copy: available on request to legal@waygomaps.com.
Download: [LINK TO PDF]