import type { Metadata } from "next"; import Link from "next/link"; import { LegalLayout, type LegalSection } from "@/components/marketing/legal-layout"; export const metadata: Metadata = { title: "Data Processing Addendum", description: "Fetcha's Data Processing Addendum: roles, sub-processors, security measures, breach notification and international transfers for personal data handled through the web access API.", alternates: { canonical: "/legal/dpa" }, }; const sections: LegalSection[] = [ { id: "introduction", title: "Introduction and application", body: ( <>
This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other agreement (the “Agreement”) between Fetcha, operated from Québec, Canada (“Fetcha”), and the customer identified in the account (“Customer”). It applies whenever Fetcha processes personal data on Customer’s behalf in the course of providing the Services, and it reflects the requirements of Québec’s Law 25, Canada’s PIPEDA, the EU General Data Protection Regulation (“GDPR”), the UK GDPR and the Swiss FADP (together, “Data Protection Law”).
This DPA is accepted automatically by all customers as part of the Agreement. Customers who need a signed copy, or who require the EU Standard Contractual Clauses or UK Addendum executed, can request them at legal@fetcha.co. Terms such as “controller”, “processor”, “personal data”, “processing”, “data subject” and “personal data breach” have the meanings given in Data Protection Law.
> ), }, { id: "roles", title: "Roles of the parties", body: ( <>Two categories of data are handled by the Services, and the parties act in different capacities for each.
When Customer instructs Fetcha to retrieve a URL, the request parameters Customer supplies (URL, headers, cookies, body) and the content returned by the target website (“Transiting Content”) may include personal data. For Transiting Content, Customer is the controller (or a processor acting for its own controller) and Fetcha is a processor, acting only on Customer’s documented instructions, which are given through the API and dashboard. Fetcha does not determine which websites are accessed, which data is collected or for what purpose, and does not retain response bodies by default.
Personal data about Customer’s personnel and the operation of the account (names, email addresses, credentials, audit logs, request metadata, billing information) is processed by Fetcha as an independent controller to provide, secure and bill the Services, as described in the Privacy Policy. This DPA does not govern that processing except where expressly stated.
> ), }, { id: "details", title: "Details of processing", body: ( <>| Item | Description |
|---|---|
| Subject matter | Retrieval of web resources designated by Customer through shared network infrastructure. |
| Duration | The term of the Agreement. Transiting Content is processed only for the duration of each request; request metadata is retained for the plan’s retention period (3, 7, 30 or 90 days, or as agreed for Enterprise). |
| Nature and purpose | Transmission, routing, retrying and returning of HTTP requests and responses; redaction of sensitive headers; logging of request metadata for Customer’s own use, billing and security. |
| Types of personal data | Determined by Customer. May include any personal data present in requested URLs, headers, cookies, request bodies or in the content of target pages (for example names, contact details, identifiers, online identifiers, IP addresses). |
| Categories of data subjects | Determined by Customer. Typically users or publishers of the websites Customer accesses, and Customer’s own end users where their data appears in requests. |
| Special categories | Not intended. Customer must not direct the Services at special-category data without a documented lawful basis and prior written notice to Fetcha. |
Customer is responsible for the lawfulness of the processing it instructs, including having a valid legal basis, providing any required notices to data subjects, honouring data-subject rights, and ensuring that access to each target website and use of its content complies with Data Protection Law, the website’s terms and the Acceptable Use Policy. Customer’s instructions must be lawful; Fetcha will inform Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend processing of that instruction.
Customer will not use the Services to collect personal data at scale about identifiable individuals without a documented assessment of necessity and proportionality, and will conduct any data protection impact assessment that Data Protection Law requires. Fetcha will provide reasonable information to assist.
> ), }, { id: "fetcha-obligations", title: "Fetcha obligations as processor", body: ( <>With respect to Transiting Content, Fetcha will:
Customer gives general written authorisation for Fetcha to engage sub-processors in the following categories:
Fetcha imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains liable for their performance. Fetcha will notify Customer of any intended addition or replacement of a sub-processor category or of a partner handling Transiting Content at least 30 days in advance by email or dashboard notice. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Services and receive a pro-rated refund of prepaid fees.
> ), }, { id: "security", title: "Security measures", body: ( <>Fetcha maintains technical and organisational measures appropriate to the risk, including:
Authorization, Cookie and similar headers redacted before any log is written; debug attempt data retained only when Customer enables it and only for the plan retention period.Fetcha may update these measures provided the overall level of protection is not reduced. A more detailed security overview is available to Enterprise customers on request.
> ), }, { id: "breach", title: "Personal data breach notification", body: ( <>Fetcha will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Transiting Content or Customer’s account data. The notification, sent to the account owner’s email address and any security contact Customer has registered, will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. Information may be provided in phases as the investigation progresses.
Fetcha will cooperate reasonably with Customer’s own notifications to authorities and data subjects and will not name Customer in any public statement about a breach without consent, unless required by law. Fetcha’s notification is not an admission of fault or liability.
> ), }, { id: "audits", title: "Audits and assistance", body: ( <>On written request no more than once per year (or more often after a breach or at the request of a supervisory authority), Fetcha will make available information reasonably necessary to demonstrate compliance with this DPA, such as security documentation, sub-processor lists under NDA, and summaries of internal or third-party assessments. If this information is insufficient, Customer or an independent auditor bound by confidentiality may conduct an audit at Customer’s expense, during business hours, on at least 30 days’ notice, in a manner that does not disrupt Fetcha’s operations or compromise the confidentiality of other customers or network partners.
If a data subject contacts Fetcha directly about Transiting Content, Fetcha will, where the data subject can be associated with Customer, redirect the request to Customer and will not respond substantively except as required by law. Requests for assistance beyond what is described in this DPA may be subject to reasonable fees.
> ), }, { id: "deletion", title: "Return and deletion", body: ( <>Because Transiting Content is not retained, there is generally nothing to return at the end of the Agreement. Request metadata can be exported by Customer from the dashboard at any time during the retention window. On termination or deletion of the account, Fetcha will delete remaining request metadata and account data within 30 days, after a 7-day grace period during which Customer may cancel the deletion, except for data that must be retained under applicable law (such as invoicing records), which will remain protected under this DPA and be deleted when the legal retention period ends. Encrypted backups are overwritten within 35 days.
> ), }, { id: "transfers", title: "International transfers", body: ( <>Fetcha stores account data and request metadata in Canada, a jurisdiction recognised by the European Commission as providing adequate protection. Transiting Content is, by the nature of the Services, transmitted through the geography Customer selects for each request and through the location of the target website; Customer determines those locations by its instructions.
Where Fetcha or a sub-processor transfers personal data from the EEA, the UK or Switzerland to a country without an adequacy decision, the transfer is protected by the EU Standard Contractual Clauses (Module Two, controller-to-processor, or Module Three, processor-to-processor, as applicable), the UK International Data Transfer Addendum, and the Swiss amendments, which are incorporated by reference and which Fetcha will execute on request. Fetcha carries out the assessment required by Québec’s Law 25 before communicating personal information outside Québec.
> ), }, { id: "general", title: "Liability, precedence and changes", body: ( <>Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except to the extent Data Protection Law prohibits such limitation. In the event of conflict, this DPA prevails over the Agreement with respect to processing of personal data, and the Standard Contractual Clauses prevail over this DPA where they apply. Fetcha may update this DPA to reflect changes in law or the Services; the version and effective date appear at the top of this page, and material changes are notified at least 30 days in advance. This DPA is governed by the law of the Agreement (Québec, Canada), except where the Standard Contractual Clauses require otherwise.
Contact for all matters under this DPA: privacy@fetcha.co (privacy officer) and legal@fetcha.co (contracts).
> ), }, ]; export default function DpaPage() { return