This Data Processing Addendum ("DPA") sets out how Widgetjoy ("we") processes Customer Data for the Customer ("you"). It uses the words defined in the Terms, and data protection terms — controller, processor, personal data, processing, personal data breach — as the GDPR defines them. "Data protection law" means every law on personal data that applies, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection and the CCPA.
Roles and instructions
For Customer Data, you are the controller and we are your processor. If you use Widgetjoy for your own clients, you may be their processor and we your sub-processor. For your own account data we are a controller, and our Privacy Policy applies.
We process Customer Data only on your documented instructions: this DPA, the Terms, and what you set in Widgetjoy — the Widgets you publish, what they ask, who is notified, and what you export or delete. We will tell you if we believe an instruction breaks data protection law, or if the law requires us to process Customer Data otherwise, unless it forbids telling you. You are responsible for having a lawful basis for what your Widgets collect, and for informing your Visitors.
Our obligations
We will:
- let only the people who need it reach Customer Data, and bind them to confidentiality;
- protect it with the measures in Annex 2;
- use sub-processors only as set out below;
- help you answer your Visitors' requests — Widgetjoy lets you find, download and delete what they sent — and pass on to you any request that reaches us;
- help you with security, breach notification, impact assessments and consulting authorities, as far as we can;
- tell you without undue delay about a personal data breach affecting Customer Data;
- delete Customer Data at the end, as below;
- give you the information you need to check all this, and allow audits as below.
Sub-processors
You authorise the sub-processors on our sub-processors page. Before we add or replace one, we update that page and email every Workspace owner at least 30 days in advance, or as soon as we can in an emergency. You may object on reasonable data protection grounds within those 30 days; if we cannot find a solution, you may close your Workspace before the change. We remain responsible to you for what our sub-processors do with Customer Data.
Transfers outside the EU
We store Customer Data in the European Union. Requests to Widgetjoy and the emails we send pass through Cloudflare, which is based in the United States, under the EU–US Data Privacy Framework and the Standard Contractual Clauses in Cloudflare's data processing addendum. Where a transfer from you to us is a restricted transfer, the European Commission's Standard Contractual Clauses (Decision 2021/914, Module Two or Three) apply, with the UK Addendum or the Swiss adjustments where needed, completed by Annexes 1 and 2.
California
Under the CCPA we are your service provider: we will not sell or share personal information, or use it for anything but providing Widgetjoy to you.
End of service, audits and liability
You can download all Customer Data at any time from Settings → General → Download everything. When you delete your Workspace or stop using Widgetjoy, we delete Customer Data from our live systems at once, unless the law requires us to keep it.
We answer reasonable questions about how we protect Customer Data. If that is not enough, you may audit us once a year, on 30 days' notice, at your cost and without access to other Customers' data; a supervisory authority may audit us whenever the law allows.
Liability under this DPA follows the Terms, as far as data protection law allows. For Customer Data, this DPA takes precedence over the Terms.
Annex 1: details of the processing
- Parties
- The Customer, as controller (or processor for its own client); Widgetjoy, [email protected], as processor
- Data subjects
- Visitors who use the Customer's Widgets, and anyone else whose personal data the Customer puts into Widgetjoy
- Personal data
- What the Customer's Widgets ask for — today the Contact Form's fields: name, email address, phone number, subject, message, other text and choices — with the page path and time of each message; and, to deliver Widgets and stop abuse, the Visitor's IP address, held briefly in memory and never stored
- Sensitive data
- None intended; the Customer must not ask for it
- Processing
- Receiving, storing, showing in the Dashboard, notifying by email, exporting and deleting, and delivering Widgets to Visitors' browsers, to provide Widgetjoy to the Customer
- Duration
- Continuously, until the Customer deletes the data or its Workspace
Annex 2: security measures
- Every connection uses HTTPS with Strict Transport Security, and email leaves over an encrypted connection.
- Every read and write is checked against the Workspace it belongs to.
- Only the people who operate Widgetjoy can reach its servers and database. Passwords, agent tokens and reset links are stored only as hashes, and sessions use a cookie that scripts cannot read.
- Sign-in, password resets and messages sent through Widgets are rate limited, and every new Contact Form carries a spam trap.
- No analytics or tracking of Visitors, no stored IP addresses, and logs without IP addresses, email addresses or what Visitors wrote.
- Every change in a Workspace is recorded with who made it.