SPB Git forge

spb/fetcha

Public
11commits 1branches 0releases
1.5 MBsize
maindefault branch
16 days agolast push
TypeScript 97.5% SQL 1.4% Python 0.8%
16.3 KB · 179 lines tsx
Raw Blame History
1import type { Metadata } from "next";2import Link from "next/link";3import { LegalLayout, type LegalSection } from "@/components/marketing/legal-layout";45export const metadata: Metadata = {6  title: "Data Processing Addendum",7  description: "Fetcha's Data Processing Addendum: roles, sub-processors, security measures, breach notification and international transfers for personal data handled through the web access API.",8  alternates: { canonical: "/legal/dpa" },9};1011const sections: LegalSection[] = [12  {13    id: "introduction",14    title: "Introduction and application",15    body: (16      <>17        <p>18          This Data Processing Addendum (<strong>“DPA”</strong>) forms part of the <Link href="/legal/terms">Terms of Service</Link> or other agreement (the <strong>“Agreement”</strong>) between Fetcha, operated from Québec, Canada (<strong>“Fetcha”</strong>), and the customer identified in the account (<strong>“Customer”</strong>). It applies whenever Fetcha processes personal data on Customer’s behalf in the course of providing the Services, and it reflects the requirements of Québec’s Law 25, Canada’s PIPEDA, the EU General Data Protection Regulation (<strong>“GDPR”</strong>), the UK GDPR and the Swiss FADP (together, <strong>“Data Protection Law”</strong>).19        </p>20        <p>This DPA is accepted automatically by all customers as part of the Agreement. Customers who need a signed copy, or who require the EU Standard Contractual Clauses or UK Addendum executed, can request them at <a href="mailto:legal@fetcha.co">legal@fetcha.co</a>. Terms such as “controller”, “processor”, “personal data”, “processing”, “data subject” and “personal data breach” have the meanings given in Data Protection Law.</p>21      </>22    ),23  },24  {25    id: "roles",26    title: "Roles of the parties",27    body: (28      <>29        <p>Two categories of data are handled by the Services, and the parties act in different capacities for each.</p>30        <h3>Transiting content: Fetcha as processor</h3>31        <p>When Customer instructs Fetcha to retrieve a URL, the request parameters Customer supplies (URL, headers, cookies, body) and the content returned by the target website (<strong>“Transiting Content”</strong>) may include personal data. For Transiting Content, <strong>Customer is the controller</strong> (or a processor acting for its own controller) and <strong>Fetcha is a processor</strong>, acting only on Customer’s documented instructions, which are given through the API and dashboard. Fetcha does not determine which websites are accessed, which data is collected or for what purpose, and does not retain response bodies by default.</p>32        <h3>Account data: Fetcha as controller</h3>33        <p>Personal data about Customer’s personnel and the operation of the account (names, email addresses, credentials, audit logs, request metadata, billing information) is processed by Fetcha as an <strong>independent controller</strong> to provide, secure and bill the Services, as described in the <Link href="/legal/privacy">Privacy Policy</Link>. This DPA does not govern that processing except where expressly stated.</p>34      </>35    ),36  },37  {38    id: "details",39    title: "Details of processing",40    body: (41      <>42        <table>43          <thead>44            <tr>45              <th>Item</th>46              <th>Description</th>47            </tr>48          </thead>49          <tbody>50            <tr><td>Subject matter</td><td>Retrieval of web resources designated by Customer through shared network infrastructure.</td></tr>51            <tr><td>Duration</td><td>The term of the Agreement. Transiting Content is processed only for the duration of each request; request metadata is retained for the plan’s retention period (3, 7, 30 or 90 days, or as agreed for Enterprise).</td></tr>52            <tr><td>Nature and purpose</td><td>Transmission, routing, retrying and returning of HTTP requests and responses; redaction of sensitive headers; logging of request metadata for Customer’s own use, billing and security.</td></tr>53            <tr><td>Types of personal data</td><td>Determined by Customer. May include any personal data present in requested URLs, headers, cookies, request bodies or in the content of target pages (for example names, contact details, identifiers, online identifiers, IP addresses).</td></tr>54            <tr><td>Categories of data subjects</td><td>Determined by Customer. Typically users or publishers of the websites Customer accesses, and Customer’s own end users where their data appears in requests.</td></tr>55            <tr><td>Special categories</td><td>Not intended. Customer must not direct the Services at special-category data without a documented lawful basis and prior written notice to Fetcha.</td></tr>56          </tbody>57        </table>58      </>59    ),60  },61  {62    id: "customer-obligations",63    title: "Customer obligations",64    body: (65      <>66        <p>Customer is responsible for the lawfulness of the processing it instructs, including having a valid legal basis, providing any required notices to data subjects, honouring data-subject rights, and ensuring that access to each target website and use of its content complies with Data Protection Law, the website’s terms and the <Link href="/legal/acceptable-use">Acceptable Use Policy</Link>. Customer’s instructions must be lawful; Fetcha will inform Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend processing of that instruction.</p>67        <p>Customer will not use the Services to collect personal data at scale about identifiable individuals without a documented assessment of necessity and proportionality, and will conduct any data protection impact assessment that Data Protection Law requires. Fetcha will provide reasonable information to assist.</p>68      </>69    ),70  },71  {72    id: "fetcha-obligations",73    title: "Fetcha obligations as processor",74    body: (75      <>76        <p>With respect to Transiting Content, Fetcha will:</p>77        <ul>78          <li>process personal data only on Customer’s documented instructions (the API call and its parameters constitute the instruction), unless required by law, in which case Fetcha will inform Customer before processing unless legally prohibited;</li>79          <li>not retain response bodies beyond completion of the request, except transiently in processing memory, and not use Transiting Content for any purpose of its own, including model training or analytics on content;</li>80          <li>ensure that personnel authorised to process personal data are bound by confidentiality obligations and receive appropriate training, and limit access to what is strictly necessary for operations and support;</li>81          <li>implement the technical and organisational measures described in section 7;</li>82          <li>engage sub-processors only under the conditions of section 6;</li>83          <li>assist Customer, taking into account the nature of the processing, in responding to data-subject requests and in meeting its obligations regarding security, breach notification, impact assessments and prior consultation;</li>84          <li>at the end of the Agreement, delete personal data in accordance with section 10;</li>85          <li>make available the information necessary to demonstrate compliance and allow audits as set out in section 9.</li>86        </ul>87      </>88    ),89  },90  {91    id: "sub-processors",92    title: "Sub-processors",93    body: (94      <>95        <p>Customer gives general written authorisation for Fetcha to engage sub-processors in the following categories:</p>96        <ul>97          <li><strong>Hosting and infrastructure providers</strong> (compute, database, object storage, content delivery), located in Canada;</li>98          <li><strong>Upstream network partners</strong> that provide exit capacity for the datacenter, residential, ISP and mobile network classes. These partners transmit request traffic between Fetcha and the target website. They receive the target URL and traffic content in transit but not Customer’s identity, API key or Fetcha request id. Partner identities are confidential; a list is available to Customer under a non-disclosure agreement on request;</li>99          <li><strong>Transactional email delivery</strong> (account data only, not Transiting Content);</li>100          <li><strong>Payment processing</strong> (account data only, when checkout launches).</li>101        </ul>102        <p>Fetcha imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains liable for their performance. Fetcha will notify Customer of any intended addition or replacement of a sub-processor category or of a partner handling Transiting Content at least 30 days in advance by email or dashboard notice. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Services and receive a pro-rated refund of prepaid fees.</p>103      </>104    ),105  },106  {107    id: "security",108    title: "Security measures",109    body: (110      <>111        <p>Fetcha maintains technical and organisational measures appropriate to the risk, including:</p>112        <ul>113          <li><strong>Encryption</strong>: TLS 1.2 or higher for all connections to the API and dashboard and between Fetcha components; encryption of databases and backups at rest.</li>114          <li><strong>Credential protection</strong>: passwords and API keys stored only as salted hashes; keys displayed in full only at creation; scoped keys and optional expiry; rotation and revocation in the dashboard.</li>115          <li><strong>Data minimisation</strong>: response bodies not stored by default; <code>Authorization</code>, <code>Cookie</code> and similar headers redacted before any log is written; debug attempt data retained only when Customer enables it and only for the plan retention period.</li>116          <li><strong>Network controls</strong>: SSRF protection blocking private, link-local, metadata and internal hosts with re-validation on every redirect; segmentation between the public API, routing engine and databases; rate limiting, concurrency limits and circuit breakers.</li>117          <li><strong>Access control</strong>: role-based access, least privilege, multi-factor authentication for administrative systems, audit logging of administrative actions, prompt de-provisioning of departing personnel.</li>118          <li><strong>Operations</strong>: monitored health checks and status page, vulnerability and dependency monitoring, tested backups with 35-day rotation, documented incident-response procedure.</li>119          <li><strong>Retention</strong>: automatic deletion of request metadata at the end of the plan retention window; deletion of account data within 30 days of account deletion after a 7-day grace period.</li>120        </ul>121        <p>Fetcha may update these measures provided the overall level of protection is not reduced. A more detailed security overview is available to Enterprise customers on request.</p>122      </>123    ),124  },125  {126    id: "breach",127    title: "Personal data breach notification",128    body: (129      <>130        <p>Fetcha will notify Customer <strong>without undue delay, and in any event within 72 hours</strong>, after becoming aware of a personal data breach affecting Transiting Content or Customer’s account data. The notification, sent to the account owner’s email address and any security contact Customer has registered, will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. Information may be provided in phases as the investigation progresses.</p>131        <p>Fetcha will cooperate reasonably with Customer’s own notifications to authorities and data subjects and will not name Customer in any public statement about a breach without consent, unless required by law. Fetcha’s notification is not an admission of fault or liability.</p>132      </>133    ),134  },135  {136    id: "audits",137    title: "Audits and assistance",138    body: (139      <>140        <p>On written request no more than once per year (or more often after a breach or at the request of a supervisory authority), Fetcha will make available information reasonably necessary to demonstrate compliance with this DPA, such as security documentation, sub-processor lists under NDA, and summaries of internal or third-party assessments. If this information is insufficient, Customer or an independent auditor bound by confidentiality may conduct an audit at Customer’s expense, during business hours, on at least 30 days’ notice, in a manner that does not disrupt Fetcha’s operations or compromise the confidentiality of other customers or network partners.</p>141        <p>If a data subject contacts Fetcha directly about Transiting Content, Fetcha will, where the data subject can be associated with Customer, redirect the request to Customer and will not respond substantively except as required by law. Requests for assistance beyond what is described in this DPA may be subject to reasonable fees.</p>142      </>143    ),144  },145  {146    id: "deletion",147    title: "Return and deletion",148    body: (149      <>150        <p>Because Transiting Content is not retained, there is generally nothing to return at the end of the Agreement. Request metadata can be exported by Customer from the dashboard at any time during the retention window. On termination or deletion of the account, Fetcha will delete remaining request metadata and account data within 30 days, after a 7-day grace period during which Customer may cancel the deletion, except for data that must be retained under applicable law (such as invoicing records), which will remain protected under this DPA and be deleted when the legal retention period ends. Encrypted backups are overwritten within 35 days.</p>151      </>152    ),153  },154  {155    id: "transfers",156    title: "International transfers",157    body: (158      <>159        <p>Fetcha stores account data and request metadata in Canada, a jurisdiction recognised by the European Commission as providing adequate protection. Transiting Content is, by the nature of the Services, transmitted through the geography Customer selects for each request and through the location of the target website; Customer determines those locations by its instructions.</p>160        <p>Where Fetcha or a sub-processor transfers personal data from the EEA, the UK or Switzerland to a country without an adequacy decision, the transfer is protected by the EU Standard Contractual Clauses (Module Two, controller-to-processor, or Module Three, processor-to-processor, as applicable), the UK International Data Transfer Addendum, and the Swiss amendments, which are incorporated by reference and which Fetcha will execute on request. Fetcha carries out the assessment required by Québec’s Law 25 before communicating personal information outside Québec.</p>161      </>162    ),163  },164  {165    id: "general",166    title: "Liability, precedence and changes",167    body: (168      <>169        <p>Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except to the extent Data Protection Law prohibits such limitation. In the event of conflict, this DPA prevails over the Agreement with respect to processing of personal data, and the Standard Contractual Clauses prevail over this DPA where they apply. Fetcha may update this DPA to reflect changes in law or the Services; the version and effective date appear at the top of this page, and material changes are notified at least 30 days in advance. This DPA is governed by the law of the Agreement (Québec, Canada), except where the Standard Contractual Clauses require otherwise.</p>170        <p>Contact for all matters under this DPA: <a href="mailto:privacy@fetcha.co">privacy@fetcha.co</a> (privacy officer) and <a href="mailto:legal@fetcha.co">legal@fetcha.co</a> (contracts).</p>171      </>172    ),173  },174];175176export default function DpaPage() {177  return <LegalLayout title="Data Processing Addendum" current="/legal/dpa" summary="How Fetcha processes personal data on your behalf. Fetcha is a processor for content transiting the API and a controller for account data; sub-processors are hosting, unnamed upstream network partners and email delivery; breaches are notified within 72 hours; data stays in Canada with SCCs where needed." sections={sections} />;178}179