Appearance
Data Processing Addendum
Effective Date: 2026-07-09 · Document ID: DPA-MMA-001 · Contact: info@mapsted.com · Contact UsVersion: 1.0
Preamble
This Data Processing Addendum ("DPA") is entered into between:
- The Licensee — the organisation or person identified in the applicable Commercial Agreement (the "Controller"); and
- Mapsted Corp., together with its subsidiaries, affiliates, and related entities (collectively, "Mapsted", "we", "us", "our") — a federally incorporated Canadian corporation headquartered in Ontario, Canada (registered office address available upon written request to info@mapsted.com) (the "Processor").
This DPA is incorporated into, and forms part of, the Commercial Agreement between the parties. In the event of any conflict between this DPA and the Commercial Agreement with respect to data-processing obligations, this DPA prevails. Capitalised terms not defined in this DPA have the meanings given to them in the Commercial Agreement or, where applicable, in the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK General Data Protection Regulation (as retained in UK law by the European Union (Withdrawal) Act 2018) ("UK GDPR").
This DPA comes into force on the date of execution of the Commercial Agreement and remains in force until the end of the term of the Commercial Agreement or, if longer, until all personal data processed under this DPA has been deleted or returned in accordance with §13.
1. Definitions
| Term | Meaning |
|---|---|
| Commercial Agreement | The signed written agreement between Mapsted Corp. and the Licensee governing production access to the Software. |
| Software | The @mapsted/maps-js-api npm package and CDN bundle, and the Mapsted backend services at maps.mapsted.com, deploy.mapsted.com, and filer.mapsted.com, as more particularly described in the Commercial Agreement. |
| Service | The Software, together with Mapsted's supporting infrastructure and the documentation site at docs.mapsted.com/maps-js-api. |
| End User | A natural person who uses the Controller's application or website that embeds the Software. |
| Personal Data | Any information relating to an identified or identifiable natural person processed by Mapsted on behalf of the Controller in connection with the Service, as further described in Annex I. |
| Processing | Any operation or set of operations performed on Personal Data, whether or not by automated means. |
| Sub-processor | Any third-party processor engaged by Mapsted to process Personal Data on behalf of the Controller in the context of the Service. |
| SCCs | The Standard Contractual Clauses for the transfer of personal data to third countries, adopted by the European Commission under Implementing Decision (EU) 2021/914 of 4 June 2021, Module 2 (Controller to Processor). |
| UK Addendum | The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the Information Commissioner's Office (ICO) and in force from 21 March 2022 (version B1.0). |
| TOMs | Technical and organisational measures, as further described in Annex II. |
| SL-MMA-001 | The Mapsted Subprocessor List, available at ./subprocessor-list.md. |
| SP-MMA-001 | The Mapsted Security Policy, available at ./security-policy.md. |
| Supervisory Authority | The competent data-protection supervisory authority for the Controller's jurisdiction, as designated under GDPR Art. 51, UK GDPR Art. 51, or equivalent applicable law. |
2. Subject Matter and Duration of Processing
2.1 Subject matter. Mapsted processes Personal Data on behalf of the Controller solely to the extent necessary to deliver the Service as described in the Commercial Agreement and as set out in Annex I to this DPA. Mapsted acts as a processor within the meaning of GDPR Art. 4(8) with respect to Personal Data processed under this DPA.
2.2 Scope of processing. The Service operates as follows: when an End User loads a page on which the Controller has embedded the Software, the End User's browser establishes connections to Mapsted's backend services. Those connections transmit the data categories set out in Annex I, §1. Navigation events that occur within the map (including routing requests, entity selections, floor changes, search queries, and promotion interactions) travel exclusively between the map iframe hosted at maps.mapsted.com and the Controller's embedding page via the browser's window.postMessage API. These navigation event payloads are not transmitted to or stored by any Mapsted backend service. Mapsted does not receive end-user names, email addresses, passwords, payment information, or any direct identifier beyond those listed in Annex I, §1.
2.3 Duration. Processing under this DPA commences on the effective date of the Commercial Agreement and continues until the earlier of: (a) termination or expiry of the Commercial Agreement; or (b) completion of return or deletion of Personal Data pursuant to §13.
3. Nature and Purpose of Processing
Mapsted processes Personal Data on behalf of the Controller for the following purposes only:
- Serving map tiles, building floor plans, and routing graphs in response to Software initialisation requests from End User browsers.
- Validating the API key and enforcing any usage parameters set out in the Commercial Agreement.
- Delivering Security updates, patches, and Software bundle updates to End User browsers.
- Performing internal security monitoring, fraud prevention, and infrastructure-health checks on Mapsted's own backend services.
- Processing crash telemetry (where the Controller has enabled opt-in error reporting) solely for quality-improvement purposes.
Mapsted shall not process Personal Data for any purpose other than those listed above or as expressly instructed in writing by the Controller.
4. Type of Personal Data and Categories of Data Subjects
The categories of Personal Data and data subjects are set out in Annex I to this DPA. In summary:
- Data subjects: End Users of the Controller's application or website who load a page embedding the Software.
- Personal data categories: IP addresses; HTTP user-agent strings; API keys (as a credential identifier); property ID and building ID parameters; and, if enabled, crash-telemetry stack traces and error codes. No special categories of personal data within the meaning of GDPR Art. 9 are intentionally processed.
5. Obligations of the Processor
Mapsted, as Processor, undertakes to comply with the following obligations, which correspond to GDPR Art. 28(3)(a)–(h):
5.1 Processing only on documented instructions (Art. 28(3)(a)). Mapsted shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by applicable law; in such a case, Mapsted shall notify the Controller of that legal requirement before processing, unless applicable law prohibits such notification on important grounds of public interest.
The instructions from the Controller are: (a) the terms of this DPA; (b) the terms of the Commercial Agreement; and (c) any written instructions issued by the Controller to Mapsted under this DPA. The Controller acknowledges that the technical operation of the Service constitutes a standing documented instruction to process the Personal Data categories set out in Annex I for the purposes set out in §3.
5.2 Confidentiality (Art. 28(3)(b)). Mapsted shall ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5.3 Security (Art. 28(3)(c)). Mapsted shall implement and maintain the TOMs described in Annex II to this DPA. Mapsted shall take all measures required pursuant to GDPR Art. 32, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons.
5.4 Sub-processing (Art. 28(3)(d)). Mapsted shall not engage a new Sub-processor without providing the Controller with prior written notice and the opportunity to object, in accordance with §7 of this DPA.
5.5 Assistance with data subject rights (Art. 28(3)(e)). Mapsted shall assist the Controller — by appropriate technical and organisational measures, insofar as practicable — in fulfilling the Controller's obligations to respond to requests from data subjects exercising their rights under GDPR Chapter III (and equivalent provisions of applicable law). Any data subject rights request received directly by Mapsted from an End User shall be forwarded to the Controller within five (5) business days of receipt. Mapsted will not respond substantively to data subject rights requests directed at Personal Data for which the Controller is the controller, except at the Controller's express written direction or as required by applicable law.
5.6 Assistance with controller obligations (Art. 28(3)(f)). Mapsted shall assist the Controller in ensuring compliance with the obligations pursuant to GDPR Arts. 32–36 (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to Mapsted, subject to the Controller's reasonable written request.
5.7 Return and deletion (Art. 28(3)(g)). At the choice of the Controller, Mapsted shall delete or return all Personal Data to the Controller after the end of the provision of Services relating to processing, and shall delete existing copies unless applicable law requires storage of the Personal Data. See §13.
5.8 Audit and inspection (Art. 28(3)(h)). Mapsted shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in GDPR Art. 28 and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to the conditions in §11.
6. Controller Obligations
The Controller represents and warrants that:
- It has a lawful basis under applicable law for the processing of Personal Data instructed under this DPA and has provided any required notices to, and obtained any required consents from, End Users.
- It has assessed the risks to data subjects arising from the processing and has determined that the TOMs set out in Annex II are appropriate.
- It will promptly notify Mapsted in writing of any changes to applicable law or regulatory guidance that materially affect the Controller's lawful basis for processing or the scope of instructions given under this DPA.
- It will only instruct Mapsted to process Personal Data for the purposes and in the manner described in this DPA and the Commercial Agreement.
7. Sub-processors
7.1 Approved sub-processors. The Controller provides general written authorisation for Mapsted to engage the Sub-processors listed in Annex III to this DPA (which cross-references SL-MMA-001) for the purposes described therein.
7.2 Change notice. Mapsted shall inform the Controller of any intended addition of or replacement of a Sub-processor at least thirty (30) days before such addition or replacement takes effect ("Change Notice"), to allow the Controller time to object. Mapsted shall publish Change Notices on the SL-MMA-001 subprocessor list page and send written notice to the Controller at the email address associated with the Commercial Agreement.
7.3 Objection right. The Controller may object to the addition or replacement of a Sub-processor within fifteen (15) days of receiving a Change Notice by submitting a written objection to privacy@mapsted.com. The objection must state the specific data-protection grounds for the objection. Where the parties are unable to resolve the objection within thirty (30) days of receipt, either party may terminate the affected portion of the Service on written notice; the Controller shall not be entitled to any refund solely on grounds of a Change Notice objection unless otherwise provided in the Commercial Agreement.
7.4 Sub-processor obligations. Mapsted shall impose on each Sub-processor, by written contract, data-protection obligations equivalent to those imposed on Mapsted under this DPA. Mapsted remains fully liable to the Controller for the Sub-processor's performance.
8. International Transfers
8.1 Canada. Mapsted Corp. is established in Canada. The European Commission has issued an adequacy decision for Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) for commercial-sector processing (Implementing Decision 2002/2/EC). To the extent the Controller is subject to GDPR or UK GDPR and transfers Personal Data to Mapsted Corp. in Canada, that transfer is covered by the adequacy decision and does not require supplementary measures.
8.2 Onward transfers to Mapsted's Sub-processors. To the extent Mapsted's approved Sub-processors are located in countries that do not benefit from an adequacy decision, Mapsted relies on the SCCs and (for UK-origin transfers) the UK Addendum, as set out in SL-MMA-001 for each Sub-processor. By entering into this DPA, the Controller agrees that the SCCs (Module 2) are incorporated herein by reference with respect to any such onward transfer from Mapsted to a Sub-processor, with Mapsted as data exporter and the relevant Sub-processor as data importer. The Annex content for each Sub-processor transfer is as published in SL-MMA-001.
8.3 EU SCCs — Module 2. Where the SCCs apply to a transfer of Personal Data from the EEA to a country outside the EEA that does not benefit from an adequacy decision, the parties agree that:
- Clause 7 (Docking clause) — shall apply.
- Clause 9 (Use of sub-processors) — Option 2 (general written authorisation) shall apply, with the Change Notice period set to thirty (30) days as specified in §7.2 of this DPA.
- Clause 11 (Redress) — the optional language enabling data subjects to lodge complaints with an independent dispute-resolution body shall not apply.
- Clause 17 (Governing law) — the law of the EU Member State in which the Controller is established shall apply; if the Controller is not established in an EU Member State, the law of the Republic of Ireland shall apply.
- Clause 18 (Choice of forum and jurisdiction) — the courts of the EU Member State designated under Clause 17 shall have jurisdiction.
- Annexes I, II, and III of the SCCs are pre-filled as set out in Annex I, Annex II, and Annex III of this DPA respectively.
8.4 UK Addendum. Where the Controller is subject to UK GDPR and a transfer of Personal Data from the United Kingdom requires a transfer mechanism, the UK Addendum (version B1.0) is incorporated into this DPA and supplements the SCCs as described in §8.3. For the purposes of the UK Addendum:
- Table 1 — the Parties' details, key contact information, and start date are as set out in the Commercial Agreement.
- Table 2 — the SCCs version referenced is the EU Commission Implementing Decision (EU) 2021/914, Module 2.
- Table 3 — Annexes 1A, 1B, and II are as set out in Annexes I and II of this DPA.
- Table 4 — either party may end the UK Addendum as specified in the UK Addendum §19.
8.5 Transfer Impact Assessment. A Transfer Impact Assessment (TIA) has been completed by Mapsted for the relevant Sub-processor transfer chains and is available to the Controller upon written request to privacy@mapsted.com.
8.6 EU-US Data Privacy Framework. Mapsted Corp. is not currently self-certified under the EU-US Data Privacy Framework. Transfers from EEA Licensees rely on the Canadian adequacy decision (primary) and SCCs (fallback).
9. Data Subject Rights
9.1 Forwarding. If Mapsted receives any request, correspondence, or complaint from an End User purporting to exercise rights as a data subject (including rights of access, rectification, erasure, restriction, portability, objection, or rights relating to automated decision-making) in respect of Personal Data for which the Controller is the controller, Mapsted shall forward that request to the Controller at the contact address specified in the Commercial Agreement within five (5) business days of receipt. Mapsted shall not respond substantively to the data subject except to acknowledge receipt and advise the data subject to contact the Controller directly.
9.2 Technical assistance. Mapsted shall, at the Controller's written request and at the Controller's expense (unless the request arises from Mapsted's breach of this DPA), provide reasonable technical assistance to help the Controller fulfil a verified data subject rights request within the timescales required by applicable law.
9.3 No independent action. Mapsted shall take no independent substantive action on a data subject rights request without the Controller's written authorisation, unless required to do so by applicable law.
10. Security and Data Protection Impact Assessment
10.1 TOMs. Mapsted shall implement and maintain the technical and organisational security measures described in Annex II to this DPA and in SP-MMA-001. Mapsted shall review and, where necessary, update those measures at reasonable intervals to maintain their effectiveness.
10.2 DPIA assistance. Where the Controller is required to carry out a Data Protection Impact Assessment (DPIA) under GDPR Art. 35 or equivalent applicable law in connection with the processing activities under this DPA, Mapsted shall provide the Controller with reasonable assistance — including relevant information about Mapsted's processing operations and TOMs — upon written request.
10.3 Record of processing activities. Mapsted maintains a Record of Processing Activities (RoPA) as required by GDPR Art. 30(2) covering its processor-mode activities under this DPA.
11. Audit Rights
11.1 Information requests. Mapsted shall, upon the Controller's written request, provide the Controller with all information reasonably necessary to demonstrate compliance with this DPA and with GDPR Art. 28, subject to reasonable confidentiality protections.
11.2 On-site audit. The Controller may conduct, or commission an independent third-party auditor to conduct, an audit of Mapsted's data-processing activities under this DPA no more than once per calendar year, subject to:
- at least thirty (30) days' prior written notice to Mapsted;
- agreement on the scope, timing, and reasonable confidentiality protections;
- the audit being conducted during Mapsted's normal business hours in a manner that does not unreasonably disrupt Mapsted's operations; and
- any third-party auditor executing a non-disclosure agreement in favour of Mapsted.
The costs of such an audit shall be borne by the Controller, unless the audit reveals a material breach of this DPA by Mapsted, in which case Mapsted shall bear its own reasonable costs of facilitating the audit.
11.3 Assurance reports. Mapsted is not currently ISO 27001 or SOC 2 Type II certified. Mapsted's controls are modelled on ISO 27001:2022 Annex A and SOC 2 Trust Services Criteria; certification is planned. In the interim, Mapsted may satisfy the audit obligation in §11.2, in whole or in part, by providing the Controller with a documented internal security review summary or equivalent assurance documentation covering the relevant processing activities, upon written request to security@mapsted.com.
11.4 Additional audits. Where a Supervisory Authority requires access to Mapsted's premises or records in connection with this DPA, Mapsted shall cooperate with such access. The foregoing does not limit any rights of the Supervisory Authority under applicable law.
12. Security Incident and Breach Notification
12.1 Notification to Controller. In the event of a Personal Data breach (within the meaning of GDPR Art. 4(12)) affecting Personal Data processed under this DPA, Mapsted shall notify the Controller without undue delay and within 48 hours of Mapsted becoming aware of the confirmed breach. This notification timeline is intended to allow the Controller sufficient time to fulfil its own breach-notification obligations under GDPR Art. 33 (72 hours to Supervisory Authority) and equivalent applicable law.
12.2 Content of notification. Mapsted's initial notification shall, to the extent known at the time of notification, include: (a) a description of the nature of the breach including the categories and approximate number of data subjects concerned and the categories and approximate number of Personal Data records concerned; (b) the contact details of Mapsted's designated contact for the incident; (c) a description of the likely consequences of the breach; and (d) a description of the measures taken or proposed by Mapsted to address the breach. Information may be provided in phases as it becomes available.
12.3 Controller obligations. The Controller is responsible for notifying the relevant Supervisory Authority and, where required, data subjects, in accordance with applicable law. Mapsted shall provide the Controller with reasonable cooperation and further information as the investigation progresses.
12.4 Regulator notification SLAs.
- GDPR / UK GDPR: The Controller must notify the relevant Supervisory Authority within 72 hours of becoming aware of the breach (GDPR Art. 33). Mapsted's 48-hour processor notification is designed to support this timeline.
- PIPEDA (Canada): Where Mapsted becomes aware of a breach of security safeguards involving Personal Data of individuals in Canada that creates a real risk of significant harm, Mapsted shall also notify the Controller as soon as feasible to enable the Controller to fulfil its obligations under the PIPEDA Breach of Security Safeguards Regulations (SOR/2018-64) where applicable.
- Québec Law 25: Where a breach involves Personal Data of individuals residing in Québec that presents a risk of serious injury, Mapsted shall notify the Controller promptly so the Controller can notify the Commission d'accès à l'information (CAI) and affected individuals without delay.
12.5 Security posture. Mapsted's general security posture is described in SP-MMA-001, which is incorporated into this DPA by reference for informational purposes.
13. Return and Deletion of Personal Data
13.1 On termination. Upon expiry or termination of the Commercial Agreement, or at any time upon the Controller's written request, Mapsted shall, at the Controller's election: (a) return to the Controller a copy of the Personal Data processed under this DPA in a structured, commonly used, machine-readable format; or (b) securely delete the Personal Data and provide the Controller with written confirmation of deletion within thirty (30) days of the effective date of termination or receipt of the request (whichever is earlier).
13.2 Early deletion. The Controller may request earlier deletion of Personal Data at any time during the term by written notice to privacy@mapsted.com. Mapsted shall use commercially reasonable efforts to action such requests within thirty (30) days of receipt.
13.3 Exceptions. Mapsted shall not be obliged to delete Personal Data to the extent that applicable law requires continued storage of that data. Mapsted shall notify the Controller of any such retention obligation and shall restrict further processing of the retained data to the minimum necessary to comply with that obligation.
13.4 Retention schedule. Personal Data processed under this DPA is subject to the retention periods set out in the Privacy Policy (PP-MMA-001) §6. In summary: server access logs containing IP addresses and user-agent strings are retained for thirty (30) days. No navigation event data is transmitted to or retained by Mapsted's backend (see §2.2). Crash telemetry (opt-in) is retained for twelve (12) months. API-key audit logs are retained for twelve (12) months.
14. Governing Law and Jurisdiction
This DPA shall be governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, without regard to conflict-of-laws principles, except that the SCCs and UK Addendum shall be governed by the law specified in those instruments. Any dispute arising out of or relating to this DPA shall be resolved exclusively in the courts of the Province of Ontario, and each party irrevocably consents to the personal jurisdiction of those courts. This clause does not limit either party's right to seek injunctive, declaratory, or other equitable relief in any court of competent jurisdiction.
15. Miscellaneous
15.1 Order of precedence. In the event of any conflict or inconsistency between this DPA and the Commercial Agreement with respect to the processing of Personal Data, this DPA shall prevail. In the event of any conflict between this DPA and the SCCs (or UK Addendum), the SCCs (or UK Addendum) shall prevail.
15.2 Entire agreement on data processing. This DPA, together with the SCCs and UK Addendum (where applicable) and the annexes attached hereto, constitutes the entire agreement between the parties with respect to the processing of Personal Data under the Commercial Agreement and supersedes all prior or contemporaneous agreements, representations, or understandings relating to such subject matter.
15.3 Severability. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.
15.4 Amendments. Mapsted may amend this DPA from time to time to reflect changes in applicable law, regulatory guidance, or the structure of the Service. Material amendments will be communicated to Controllers under the Commercial Agreement at least thirty (30) days before they take effect. Where an amendment is required by changes in applicable law, it shall take effect on the date the relevant change in law comes into force regardless of notice period.
15.5 Liability. Each party's liability under this DPA is subject to the limitations and exclusions set out in the Commercial Agreement, except that nothing in this DPA limits either party's liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) any liability that cannot be excluded or limited by applicable law.
15.6 Contact for data-protection enquiries. The Controller may direct data-protection enquiries relating to this DPA to privacy@mapsted.com.
Annex I — Details of Processing
(Corresponds to Annex I of the EU 2021 SCCs, Module 2)
Section A — List of Parties
Data exporter (Controller):
- Name: As specified in the Commercial Agreement.
- Address: As specified in the Commercial Agreement.
- Contact person's name, position and contact details: As specified in the Commercial Agreement.
- Activities relevant to the data transferred: Operating an application or website that embeds the
@mapsted/maps-js-apiSoftware, causing End User browsers to connect to Mapsted's backend services to retrieve indoor map data. - Signature and date: See Execution block below.
- Role: Controller.
Data importer (Processor):
- Name: Mapsted Corp. and its subsidiaries, affiliates, and related entities (collectively, "Mapsted").
- Address: Ontario, Canada (registered office address available upon written request to info@mapsted.com).
- Contact person's name, position and contact details: Privacy Lead — privacy@mapsted.com.
- Activities relevant to the data transferred: Operating the backend services (
maps.mapsted.com,deploy.mapsted.com,filer.mapsted.com) that receive and process HTTP requests from End User browsers when they load a page embedding the Software; serving map tiles, building-data assets, and Software bundle updates in response to those requests. - Signature and date: See Execution block below.
- Role: Processor.
Section B — Description of Transfer
Categories of data subjects:
End Users — natural persons who use the Controller's application or website that embeds the Software, and whose browsers therefore make requests to Mapsted's backend services.
Categories of personal data transferred:
| Data category | Source | Purpose |
|---|---|---|
| IP address | HTTP request headers received by Mapsted's backend services | Routing, fraud prevention, regional compliance, security logging |
| User-agent string | HTTP request headers | Compatibility, debugging, security monitoring |
| API key | Request authentication header or query parameter | Licence validation, quota management |
| Property ID and building ID | init() call parameters embedded in requests | Serving the correct building map data |
| Crash telemetry (stack traces, error codes) — opt-in only | In-Software error-reporting mechanism, if enabled by the Controller | Quality improvement |
Navigation event data that is NOT transferred to Mapsted: User interactions inside the map iframe — including entity selections, floor changes, routing requests, search queries, promotion interactions, and navigation lifecycle events — travel exclusively via browser window.postMessage between the map iframe and the Controller's embedding page. These event payloads are not transmitted to, processed by, or retained by any Mapsted backend service.
Sensitive data transferred:
None intended. No special categories of personal data within the meaning of GDPR Art. 9 (including health data, racial or ethnic origin, biometric data, or location data enabling precise tracking of movements) are processed by Mapsted's backend services in connection with the Service. IP addresses may be considered sensitive in certain jurisdictions and are processed solely as described above.
Frequency of transfer: Continuous — each time an End User browser loads a page embedding the Software, a connection is made to Mapsted's backend services.
Nature of processing: Automated — HTTP request handling, API key validation, serving of map data assets, server access logging, and (where enabled) crash telemetry aggregation.
Purpose(s) of transfer and further processing: Delivery of the Software service to the Controller's End Users as described in §3 of this DPA.
Retention period: As set out in §13.4 of this DPA and in PP-MMA-001 §6. Server access logs: thirty (30) days. Crash telemetry (opt-in): twelve (12) months. API-key audit logs: twelve (12) months.
Section C — Competent Supervisory Authority
For EEA-origin transfers: the Supervisory Authority of the EU Member State in which the Controller is established, or, if the Controller is not established in an EU Member State, the Irish Data Protection Commission (DPC). Mapsted's designated lead supervisory authority for EU-origin transfers is the Irish Data Protection Commission (DPC), Ireland.
For UK-origin transfers: the Information Commissioner's Office (ICO).
Annex II — Technical and Organisational Measures
(Corresponds to Annex II of the EU 2021 SCCs, Module 2; drawn from SP-MMA-001)
The following technical and organisational measures are implemented and maintained by Mapsted Corp. with respect to the processing of Personal Data under this DPA. These measures reflect Mapsted's security posture as described in SP-MMA-001 and are reviewed and updated on a regular basis.
Measure 1 — Pseudonymisation and encryption of personal data
All data in transit between End User browsers and Mapsted's backend services is encrypted using TLS 1.3 (preferred); TLS 1.2 (minimum). TLS 1.0 and TLS 1.1 are not supported. Data at rest on Mapsted-operated infrastructure is encrypted using AES-256 via the Google Cloud Platform default encryption service. API keys are transmitted exclusively in HTTP request headers; they are not embedded in URL query strings in log-retaining paths or logged in plaintext in application logs.
Measure 2 — Ongoing confidentiality, integrity, availability, and resilience
Mapsted's backend services are hosted on Google Cloud Platform (GCP) with high-availability configuration. GCP provides platform-level infrastructure resilience including redundant networking, storage replication, and documented disaster-recovery procedures. Mapsted maintains internal operational procedures for its backend services.
Measure 3 — Timely restoration of availability and access following incidents
GCP managed-infrastructure controls include automated backups and point-in-time restoration capabilities for storage systems used by the Service. Mapsted maintains an Incident Response Plan (IRP) covering detection, triage, containment, remediation, and post-incident review.
Measure 4 — Regular testing and evaluation of TOMs
Mapsted conducts periodic internal security reviews and uses the OWASP Top 10 as an internal reference framework for web application security development and review. Vulnerability reports received via the responsible-disclosure process described in SP-MMA-001 are triaged and remediated per the response timeline in SP-MMA-001 §6. Mapsted conducts internal security testing on a recurring basis and commissions external penetration testing at least annually.
Measure 5 — User identification and authorisation
Access to Mapsted's backend infrastructure and data stores is restricted by role-based access controls (RBAC). Only authorised Mapsted personnel with a documented need have access to Personal Data processed under this DPA. Access is logged.
Measure 6 — Protection of data during transmission
TLS 1.3 (preferred) / TLS 1.2 (minimum) for all application-layer transfers between End User browsers and Mapsted's backend services. GCP network controls govern internal service-to-service communication.
Measure 7 — Protection of data during storage
GCP default AES-256 encryption-at-rest is applied to all storage volumes used by Mapsted's backend services. Customer-managed encryption keys (CMEK) are not currently supported. Mapsted uses standard cloud-provider-managed encryption at rest (GCP CMEK-compatible infrastructure). Future CMEK support may be introduced in Enterprise tiers.
Measure 8 — Physical security of processing locations
Mapsted does not operate its own data centres. Physical security is governed by Google Cloud Platform, whose data-centre security controls are described at https://cloud.google.com/security/overview/whitepaper.
Measure 9 — Event logging
Mapsted's backend services produce access logs capturing the data categories set out in Annex I. Authentication events and API-key usage are logged. Logs are retained in accordance with the schedule in §13.4.
Measure 10 — System configuration management
Mapsted uses infrastructure-as-code and automated deployment tooling for its backend services. Configuration changes are version-controlled and subject to internal review.
Measure 11 — IT security governance and management
Mapsted maintains internal IT governance policies and designated responsibility for security. Mapsted's Privacy Lead has overall accountability for data-protection compliance under PIPEDA and is the designated point of contact for data-protection matters under this DPA.
Measure 12 — Certification and assurance
Mapsted is not currently ISO 27001 or SOC 2 Type II certified. Mapsted's controls are modelled on ISO 27001:2022 Annex A and SOC 2 Trust Services Criteria. Certification is planned; timing is subject to change. Mapsted can provide a summary of its security programme to Controllers upon written request to security@mapsted.com.
Measure 13 — Data minimisation
Mapsted processes only the data categories listed in Annex I §B, which are the minimum required to operate the Service. No end-user names, email addresses, passwords, payment information, search terms, navigation events, or other direct identifiers are processed by Mapsted's backend. The Software's postMessage architecture is specifically designed to keep navigation event data client-side only.
Measure 14 — Data quality and accuracy
IP addresses and user-agent strings are as received from the HTTP request; they are not enriched or combined with other data sources by Mapsted.
Measure 15 — Limited data retention
Server access logs are deleted on a rolling thirty (30) day cycle. Crash telemetry (opt-in) is deleted after twelve (12) months. API-key audit logs are deleted after twelve (12) months. Automated retention-enforcement processes are in place.
Measure 16 — Accountability
Mapsted maintains a Record of Processing Activities (RoPA) under GDPR Art. 30 covering its processor-mode activities under this DPA. Data subject rights requests forwarded under §9 are tracked and logged.
Measure 17 — Data portability and erasure
Mapsted's data retention systems support targeted deletion and portability upon verified Controller request within the timeline set out in §13.
Annex III — Approved Sub-processors
(Corresponds to Annex III of the EU 2021 SCCs, Module 2)
The current list of approved Sub-processors is maintained in the Subprocessor List (SL-MMA-001) at ./subprocessor-list.md, which is incorporated into this Annex by reference.
As of the effective date of this DPA, the approved Sub-processors include:
| Sub-processor | Service | Processing location(s) | Transfer mechanism |
|---|---|---|---|
| Google LLC (Google Cloud Platform) | Cloud infrastructure hosting (compute, storage, networking) for maps.mapsted.com, deploy.mapsted.com, filer.mapsted.com | United States (us-central1, us-east1); Canada (northamerica-northeast1, northamerica-northeast2) | EU SCCs 2021 Module 2; UK Addendum B1.0; Google Cloud DPA |
| Cloudflare, Inc. | CDN edge delivery, DDoS mitigation, TLS termination for the Software CDN bundle (mapi.mapsted.com) and documentation site | Global edge network; EU/UK data residency features activated for applicable tenants | EU SCCs 2021 Module 2; UK Addendum B1.0; Cloudflare DPA |
| npm, Inc. (a Microsoft subsidiary) | Distribution of the @mapsted/maps-js-api npm package to Licensee developers | United States | EU SCCs 2021 Module 2; GitHub/Microsoft DPA |
For full details of each Sub-processor, including contact information, data categories processed, retention periods, and sub-processor DPA URLs, see ./subprocessor-list.md.
Mapsted will provide the Controller with thirty (30) days' advance written notice before any new Sub-processor that may process Personal Data covered by this DPA is added, in accordance with §7 of this DPA.
Execution
This DPA is entered into as of the effective date of the Commercial Agreement. The parties' authorised representatives have executed or agreed to this DPA as indicated below (or, where the Commercial Agreement provides for electronic or click-through acceptance, by such mechanism of acceptance).
Mapsted Corp. (Processor)
| Field | Detail |
|---|---|
| Entity name | Mapsted Corp. and its subsidiaries, affiliates, and related entities |
| Registered address | Ontario, Canada (full address available upon written request to info@mapsted.com) |
| Authorised signatory name | [Authorised signatory] |
| Title | [Title] |
| Signature | _________________________ |
| Date | _________________________ |
Licensee (Controller)
| Field | Detail |
|---|---|
| Entity name | [Licensee legal entity name] |
| Registered address | [Licensee address] |
| Authorised signatory name | [Signatory name] |
| Title | [Title] |
| Signature | _________________________ |
| Date | _________________________ |
Related documents
- Privacy Policy — PP-MMA-001
- Security Policy — SP-MMA-001
- Subprocessor List — SL-MMA-001
- Terms of Service — TOS-MMA-001
- Licence Agreement — LA-MMA-001
- Legal Hub