DATA PROCESSING ADDENDUM
Version: September 11, 2026
This Data Processing Addendum (the “DPA”) is incorporated by reference into and forms part of the Terms of Service available at https://youscan.io/terms-of-service/ (the “Terms”), which, together with the applicable Order Form, constitute the services agreement (the “Services Agreement”) between YouScan Limited (“YouScan”) and the customer entering into the Services Agreement (“Client”). YouScan and Client are each a “Party” and together the “Parties”. This DPA takes effect when the Services Agreement incorporating it becomes effective or, where incorporated into an existing Services Agreement, on the date that incorporation takes effect in accordance with the Services Agreement (the “Effective Date”). This DPA is binding on the Parties as part of the Services Agreement and does not require a separate signature.
This DPA governs the Processing of Personal Data in connection with the Services and allocates data-protection roles by reference to the relevant Processing activity. In particular, it distinguishes between
Client Personal Data that YouScan Processes on behalf of Client;
YouScan Personal Data, including Public Web Personal Data and Historical Data that YouScan has historically collected, licensed, indexed or otherwise maintains independently as part of its multi-client social-listening data environment;
any specific and separable Processing of public-source Personal Data that YouScan expressly agrees to perform exclusively on Client's behalf pursuant to Client's documented instructions; and
Business Contact Data.
The Parties intend this allocation to reflect the factual circumstances of each Processing operation while establishing the contractual default that YouScan acts as an independent Controller for YouScan Personal Data and as Processor or Sub-processor for Client Personal Data, subject to the narrow Client-Directed Processing exception and mandatory Applicable Data Protection Laws.
This DPA prevails over the Services Agreement to the extent of a conflict solely with respect to its subject matter. The Standard Contractual Clauses and any mandatory jurisdiction-specific transfer terms prevail over this DPA to the extent required by their terms. Except as expressly stated in this DPA, the Services Agreement remains unchanged.
1. DEFINITIONS
"Affiliate" means an entity that directly or indirectly controls, is controlled by, or is under common control with a Party, where control means ownership of more than fifty percent (50%) of the voting interests or the legal power to direct the management of the entity.
"Applicable Law" means any law, statute, regulation, binding regulatory requirement, court order or other legally binding rule applicable to a Party, the Services or the relevant Processing.
"Applicable Data Protection Laws" means all privacy, data protection and data security laws and binding regulations applicable to the Processing of Personal Data under the Services Agreement, including, where applicable, the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, U.S. State Privacy Laws, and any law that amends, replaces or supplements them.
"Authorized User" means a User authorized by Client to access or use the Services in accordance with the Services Agreement.
"Business Contact Data" means Personal Data relating to Client personnel, Authorized Users, representatives and business contacts that YouScan Processes for account administration, contracting, billing, relationship management, security, service communications, support administration and similar business operations in accordance with YouScan's Privacy Policy.
"CCPA" means the California Consumer Privacy Act of 2018, Cal. Civ. Code Section 1798.100 et seq., as amended, including by the California Privacy Rights Act, and its implementing regulations, in each case as applicable and in effect from time to time.
"Client" means the entity identified as Client in the Services Agreement and, where the context requires, its Permitted Affiliates.
"Client-Directed Processing" means a specific and separable Processing operation that YouScan expressly agrees to perform exclusively on Client's behalf, solely pursuant to Client's documented instructions, and for which YouScan has no independent purpose. A Client-created topic, search query, keyword, filter, classification, date range, dashboard, alert, export request, Historical Data request or other Service parameter does not, by itself, constitute Client-Directed Processing or make the underlying collection, licensing, indexing, storage or maintenance of YouScan Data a Processor activity.
"Client Personal Data" means (a) Personal Data that Client or its Authorized Users submit, upload, transmit, import or otherwise make available to YouScan specifically for YouScan to Process on Client's behalf in connection with the Services; and (b) Public Web Personal Data only to the extent that a specific Processing operation qualifies as Client-Directed Processing under this DPA. Client Personal Data excludes YouScan Personal Data and Business Contact Data, except that the same underlying information may be Client Personal Data solely for a distinct Client-Directed Processing operation without changing the legal role applicable to YouScan's separate independent Processing of that information.
"Data Subject" means an identified or identifiable natural person to whom Personal Data relates, or the equivalent term under Applicable Data Protection Laws.
"EU SCCs" means the standard contractual clauses for transfers of Personal Data to third countries adopted by the European Commission under Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time.
"GDPR" means Regulation (EU) 2016/679 (General Data Protection Regulation).
"Historical Data" has the meaning given in the Terms and, as of the Effective Date of this DPA, refers to social-media mentions made prior to creation of the relevant topic in Client's Account. For purposes of this DPA, Historical Data is a description of the timing and Service functionality through which information may be accessed; it does not, by itself, determine whether either Party acts as Controller or Processor for any Processing operation.
"Independent Public Web Data" means the subset of Public Web Data that forms part of YouScan Data because YouScan collects, licenses, receives, retrieves, indexes, structures, stores, maintains, enriches or otherwise Processes it independently as part of the ordinary operation of its multi-client social-listening data environment, including Public Web Data held or indexed before Client's subscription or before creation of a Client topic, and Public Web Data that YouScan continues to collect or maintain independently of Client's particular instructions.
"Independent Public Web Personal Data" means YouScan Personal Data contained in Independent Public Web Data.
"Personal Data" means any information relating to an identified or identifiable natural person, and includes personal information, personally identifiable information and equivalent concepts under Applicable Data Protection Laws.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Client Personal Data Processed by YouScan or a Sub-processor in connection with the Services.
"Permitted Affiliate" means an Affiliate of Client that is permitted to use the Services under the Services Agreement, has not entered into a separate agreement with YouScan for the same Services, and acts as a Controller or Processor of Client Personal Data covered by this DPA.
"Public Web Data" means information originating from publicly accessible websites and online sources, social and online media platforms, and third-party platform or data providers that is collected, licensed, received, retrieved, indexed, analyzed or otherwise made available through the Services, together with associated metadata and YouScan-generated analytics. Public Web Data includes Historical Data where applicable and excludes data that Client independently uploads or imports into the Services.
"Public Web Personal Data" means Personal Data contained in Public Web Data.
"Restricted Transfer" means a transfer of Personal Data to a country or recipient for which Applicable Data Protection Laws require an adequacy mechanism, standard contractual clauses or another legally recognized transfer safeguard in the absence of an adequacy decision or equivalent finding.
"Sensitive Personal Data" means Personal Data designated as sensitive personal information, special categories of personal data, data relating to criminal convictions or offences, or an equivalent sensitive category under Applicable Data Protection Laws.
"Services" means the YouScan software-as-a-service platform and related services provided under the Services Agreement, including social and online media monitoring, analytics, reporting, integrations, APIs and related support as applicable to Client's subscription.
"Sub-processor" means a third party engaged by YouScan to Process Client Personal Data on YouScan's behalf in connection with the Services. A provider that does not have access to Client Personal Data, or that Processes Personal Data solely for YouScan in its capacity as an independent Controller, is not a Sub-processor for purposes of the Processor obligations in this DPA.
"Third-Party Content" means content, data or materials originating from a third party, including an online author, website, publisher, social or online media platform, or other data or platform provider, that may be accessed or analyzed through the Services. Third-Party Content may include Public Web Data and does not include YouScan's proprietary software, analytics logic or other proprietary technology and materials.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, Version B1.0 in force 21 March 2022, as amended, superseded or replaced from time to time.
"UK GDPR" means the GDPR as it forms part of the law of the United Kingdom under the European Union (Withdrawal) Act 2018, together with applicable UK data protection legislation.
"U.S. State Privacy Laws" means the CCPA and other comprehensive U.S. state privacy laws that apply to Client Personal Data and impose contractual obligations on a processor, service provider or contractor acting on behalf of a business or controller.
"YouScan Data" means data in YouScan's databases or data environment that YouScan collects, licenses, receives, retrieves, indexes, structures, stores, maintains, generates, derives, enriches or otherwise Processes independently in connection with the operation or provision of the Services, including Independent Public Web Data and Historical Data to the extent independently Processed by YouScan, but excluding Client Personal Data and Business Contact Data. Data does not cease to be YouScan Data merely because Client subsequently accesses, searches, filters, analyzes, receives or exports it through the Services.
"YouScan Personal Data" means Personal Data contained in YouScan Data.
The terms "Controller", "Processor", "Process", "Processing" and "Supervisory Authority" have the meanings given to them in the GDPR, or the corresponding meanings under Applicable Data Protection Laws. Terms such as "Business", "Service Provider", "Contractor", "Consumer", "Sell" and "Share" have the meanings assigned by the applicable U.S. State Privacy Law. Capitalized terms not defined in this DPA have the meanings given in the Services Agreement.
2. SCOPE AND DATA PROTECTION ROLES
Scope. This DPA applies only to Processing of Personal Data in connection with the Services and only to the extent Applicable Data Protection Laws apply to that Processing. It does not alter the ownership, licensing, source-access, content-use or warranty provisions of the Services Agreement except to the extent expressly stated for data-protection matters.
Processing-activity principle and contractual default. The Parties acknowledge that Controller and Processor status is determined by the factual circumstances of the relevant Processing operation, including who determines its purposes and essential means. Consistent with the Services' operating model, YouScan Personal Data is treated by default as Personal Data for which YouScan acts as an independent Controller, while Client Personal Data is treated as Personal Data YouScan Processes as Processor or Sub-processor. The same underlying item of Personal Data may be subject to different legal roles for distinct Processing operations, but a Client's use of the Services does not by itself recharacterize YouScan Data as Client Personal Data. The narrow exception for Client-Directed Processing in Section 2.6 and any mandatory determination under Applicable Data Protection Laws remain applicable.
Client Personal Data. Where Client is a Controller of Client Personal Data, Client is the Controller and YouScan is the Processor. Where Client is itself a Processor acting for another Controller, YouScan acts as Client's Sub-processor, and Client represents that it is authorized by the relevant Controller to appoint YouScan and to give the instructions set out in this DPA.
YouScan Data and independent Public Web Processing. YouScan acts as an independent Controller for its Processing of YouScan Personal Data, including Independent Public Web Personal Data. In particular, YouScan determines the purposes and essential means of establishing and operating its multi-client public-data environment, including the service-wide source architecture and access methods, indexing and structuring, storage and retention criteria, enrichment and analytics, source and rights-management processes, security, and the general manner in which Public Web Data is maintained and made available. Client does not determine whether that underlying data environment is created or maintained, what historical information it already contains, or YouScan's general service-wide Processing of it. Where Client receives or is provided access to YouScan Personal Data, Client acts as an independent Controller for the Processing purposes and means it determines, subject to Applicable Data Protection Laws and the Services Agreement.
Historical Data. Historical Data shall not become Client Personal Data merely because Client creates a topic, selects a historical period, requests retrieval, searches, filters, analyzes or accesses it through the Services. In particular, Public Web Data already collected, licensed, received, retrieved, indexed or otherwise maintained by YouScan before the relevant Client instruction, topic or subscription forms part of YouScan Data to the extent YouScan Processes it independently. The use in the Terms or an Order Form of words such as "collection", "available", "unlimited", or a collection allowance in relation to Historical Data describes Service functionality and commercial limits only; it does not state that each historical item is newly collected solely on Client's behalf, create a minimum retention obligation, or guarantee continued availability of any particular Third-Party Content.
Client-Directed Processing of public-source data. Only where YouScan expressly agrees to perform a specific and separable Processing activity involving Public Web Personal Data exclusively on behalf of Client, solely pursuant to Client's documented instructions, and YouScan has no independent purpose for that Processing, YouScan shall act as Processor (or Sub-processor, as applicable) solely for that Client-Directed Processing activity and the Processor obligations in this DPA shall apply to that activity. Unless YouScan expressly agrees otherwise in writing, the creation or use of topics, keywords, queries, filters, classifications, date ranges, dashboards, alerts, export requests, Historical Data requests or other standard Service parameters does not constitute Client-Directed Processing and does not convert YouScan Data into Client Personal Data.
No automatic recharacterization. A subsequent search, analysis, export, receipt or other access by Client does not retroactively or prospectively convert YouScan Data, or YouScan's earlier or parallel independent collection, licensing, indexing, storage or maintenance of YouScan Personal Data, into Processing performed solely on Client's behalf. Conversely, where YouScan expressly agrees that a particular Processing operation falls within Section 2.6, the Processor obligations apply solely to that operation even if the relevant information originates from a public source, without changing the classification of factually distinct YouScan Data Processing.
Mandatory role determination. Sections 2.2 through 2.7 reflect the Parties' intended and actual operating model but do not override a mandatory determination under Applicable Data Protection Laws. If a competent authority or Applicable Data Protection Law requires a different role for a specific Processing operation, the Parties shall apply that role to the affected operation only to the extent legally required, without recharacterizing factually distinct Processing operations.
Third-Party Content and data-protection roles. The classification of either Party as Controller or Processor does not determine ownership of Third-Party Content and does not create any licence, warranty, representation, indemnity or responsibility regarding the underlying Third-Party Content. Nothing in this DPA expands Client's rights to Third-Party Content beyond the Services Agreement, applicable source terms and Applicable Law, or makes YouScan responsible for the accuracy, completeness, legality, non-infringement, availability, continued publication or downstream usability of Third-Party Content merely because it contains Personal Data.
Business Contact Data. YouScan acts as an independent Controller of Business Contact Data and Processes it under YouScan's Privacy Policy. Business Contact Data is not Client Personal Data merely because it relates to a Client Authorized User or representative.
Interaction with the Terms. The data-use restrictions, source limitations, Client responsibility for uploaded or imported datasets, and other protections in the Terms continue to apply. To the extent a provision of the Terms describes "consent" as the legal basis for Personal Data governed by this DPA, that requirement shall be read as requiring Client to have the consent, lawful basis, permission or other legal authorization required by the Applicable Data Protection Laws for the relevant Processing; this DPA does not require consent where Applicable Data Protection Laws permit another lawful basis. If the Terms and this DPA conflict on Controller/Processor allocation or mandatory Processor obligations, this DPA prevails for that data-protection issue.
Permitted Affiliates. Client enters into this DPA on behalf of its Permitted Affiliates to the extent required by Applicable Data Protection Laws. Client shall remain the primary point of contact and shall coordinate all instructions, requests and claims by Permitted Affiliates. Unless a Permitted Affiliate separately signs an agreement with YouScan, it does not become a separate contracting party, and all rights, claims and liabilities of Client and its Permitted Affiliates under this DPA are subject collectively to the Services Agreement, including its limitations and exclusions of liability.
3. PROCESSING OF CLIENT PERSONAL DATA
Documented instructions. YouScan shall Process Client Personal Data only on documented instructions from Client, including as necessary to provide, operate, maintain, secure and support the Services; to perform the Services Agreement and applicable Order Form; through Client's and its Authorized Users' use, configuration and administration of the Services; through Client-enabled integrations and APIs; and as otherwise agreed in writing by the Parties. This DPA, the Services Agreement and Client's authorized use of the Services constitute Client's complete documented instructions as of the Effective Date.
Additional instructions. Any additional or alternative instruction must be consistent with the Services Agreement, technically feasible, lawful, and agreed by YouScan. YouScan may charge reasonable fees for material assistance or changes required solely by an additional Client instruction, unless the need for that assistance results from YouScan's breach of this DPA.
Legal requirements. If Applicable Law requires YouScan to Process Client Personal Data other than on Client's instructions, YouScan may do so and, unless legally prohibited on important grounds of public interest, shall inform Client of that requirement before the Processing.
Unlawful instructions. YouScan shall immediately inform Client if, in YouScan's reasonable opinion, a Client instruction infringes Applicable Data Protection Laws. YouScan may suspend the affected Processing until Client modifies or confirms a lawful instruction. Nothing in this Section requires YouScan to perform a comprehensive legal review of Client's instructions.
Purpose limitation. YouScan shall not Process Client Personal Data for purposes unrelated to providing, operating, securing, supporting or maintaining the Services, except as permitted by Applicable Data Protection Laws or expressly agreed with Client. YouScan may use aggregated or de-identified information that does not identify Client or a natural person for service analytics, security, capacity planning and product improvement, subject to Applicable Data Protection Laws.
Confidentiality. YouScan shall ensure that personnel authorized to Process Client Personal Data are subject to binding confidentiality obligations or an appropriate statutory duty of confidentiality, and access shall be limited to personnel who require it for authorized purposes.
Sensitive Personal Data. The Services are not designed to require Client to submit Sensitive Personal Data and YouScan does not request such data as a standard feature of the Services. If Client intends to submit Sensitive Personal Data in a manner that materially changes the risk of the Processing, Client shall notify YouScan in advance. YouScan may reasonably refuse the Processing or require appropriate technical, contractual or operational restrictions, and Client remains responsible for establishing any additional lawful basis, condition or authorization required for that data.
Records. YouScan shall maintain records of its Processing activities as required of a Processor under Applicable Data Protection Laws.
4. CLIENT RESPONSIBILITIES
Compliance and lawfulness. Client is responsible for complying with Applicable Data Protection Laws in respect of its collection, disclosure, instructions and use of Client Personal Data, including establishing an appropriate lawful basis, providing required notices, obtaining required consents or authorizations, and responding to Data Subjects.
Authority and data quality. Client represents that it has the right and authority to provide Client Personal Data to YouScan and to instruct YouScan to Process it under the Services Agreement. Client is responsible for the accuracy, quality, relevance and legality of Client Personal Data and for the means by which Client obtained it.
Data minimization. Client shall use reasonable measures to avoid providing Personal Data that is unnecessary for Client's use of the Services and shall not use the Services to Process categories of Personal Data that are prohibited by the Services Agreement or that YouScan has expressly stated are unsupported.
Security of Client use. Client is responsible for its secure configuration and use of the Services, including management of Authorized Users, access credentials, identity-provider settings, permissions, integrations, exports and endpoints under Client's control. Client shall promptly notify YouScan of suspected unauthorized access to its account or credentials.
Client acting as Processor. If Client is a Processor, Client shall ensure that its instructions to YouScan are consistent with the instructions of the relevant Controller and shall provide or pass through information and assistance received from YouScan to that Controller as required by Applicable Data Protection Laws.
5. SECURITY AND PERSONAL DATA BREACHES
Security Measures. Taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of Processing and risk to Data Subjects, YouScan shall implement and maintain appropriate technical and organizational measures designed to protect Client Personal Data. The current measures are described in Annex 2.
Security updates. YouScan may update or modify the Security Measures from time to time to reflect technological, operational or legal developments, provided that the overall level of security of the Services is not materially decreased during the applicable subscription term.
Personal Data Breach notice. YouScan shall notify Client without undue delay after becoming aware of a Personal Data Breach affecting Client Personal Data. The notice shall describe, to the extent reasonably available to YouScan and required by Applicable Data Protection Laws, the nature of the breach, the categories of affected data, likely consequences, measures taken or proposed, and an appropriate contact point. Where information is not available at the same time, YouScan may provide it in phases without undue further delay.
Cooperation. YouScan shall take reasonable steps to contain, investigate and remediate a Personal Data Breach within its control and shall provide Client with reasonable information and cooperation necessary for Client to meet its legally applicable notification obligations, taking into account the nature of the Processing and information available to YouScan.
No admission. Notification of, or response to, a Personal Data Breach does not constitute an admission by YouScan of fault, negligence or liability. Client remains responsible for determining whether notice to any Supervisory Authority, Data Subject or other third party is legally required, except to the extent Applicable Data Protection Laws impose a direct notification duty on YouScan.
6. DATA SUBJECT RIGHTS AND COMPLIANCE ASSISTANCE
Data Subject requests. Taking into account the nature of the Processing, YouScan shall provide reasonable assistance, including through available self-service functionality and appropriate technical and organizational measures, to enable Client to respond to requests by Data Subjects to exercise rights under Applicable Data Protection Laws in relation to Client Personal Data.
Requests received by YouScan. If YouScan receives a request from a Data Subject that reasonably identifies Client Personal Data and Client as the relevant Controller, YouScan may direct the Data Subject to Client and shall not independently fulfil the request except on Client's documented instruction or where required by Applicable Law. Where legally permitted and reasonably practicable, YouScan shall notify Client of the request.
Articles 32 to 36 and equivalent obligations. Taking into account the nature of Processing and information available to YouScan, YouScan shall provide reasonable assistance with Client's applicable obligations concerning security, breach assessment and notification, data protection impact assessments and prior consultation with a Supervisory Authority.
Regulatory enquiries. Each Party shall, to the extent legally permitted, reasonably cooperate with the other in responding to a Supervisory Authority enquiry that specifically concerns Processing governed by this DPA.
Costs. Routine assistance available through the Services and YouScan's standard compliance materials is included in the Services. To the extent permitted by Applicable Data Protection Laws, Client shall reimburse YouScan for reasonable, demonstrable costs of material, bespoke assistance requested by Client, unless such assistance is required because of YouScan's breach of this DPA.
7. SUB-PROCESSORS
General authorization. Client provides general written authorization for YouScan to engage Sub-processors to Process Client Personal Data in connection with the Services. YouScan maintains a current list of Sub-processors through the YouScan Trust Center or another location notified to Client.
Sub-processor obligations. Before a Sub-processor Processes Client Personal Data, YouScan shall enter into a written agreement imposing data protection obligations appropriate to the nature of the services and no less protective in substance than the obligations required of YouScan for that Processing under Applicable Data Protection Laws, including appropriate confidentiality, security and breach-notification obligations.
Responsibility. YouScan remains responsible for the performance of its Sub-processors' data protection obligations to the same extent required by Applicable Data Protection Laws, subject as between the Parties to the exclusions and limitations of liability in the Services Agreement.
Changes. YouScan shall provide advance notice of an intended addition or replacement of a Sub-processor that will Process Client Personal Data, normally at least fifteen (15) calendar days before that Sub-processor begins Processing. Where a shorter implementation period is reasonably necessary to address a security risk, legal requirement, service availability issue or other urgent operational need, YouScan may appoint the Sub-processor sooner and shall provide notice as soon as reasonably practicable.
Objections. Client may object to a new Sub-processor within ten (10) calendar days after notice, but only on reasonable and documented grounds relating to the protection of Client Personal Data. The Parties shall discuss the objection in good faith. YouScan may use commercially reasonable efforts to make available an alternative configuration or other reasonable solution. If YouScan cannot reasonably resolve the objection, either Party may terminate only the affected Service or feature that cannot be provided without the Sub-processor. Such termination is Client's sole contractual remedy under this Section and is otherwise subject to the Services Agreement.
Ancillary providers. Providers of ancillary services that do not Process Client Personal Data on YouScan's behalf are not Sub-processors for purposes of this DPA.
8. AUDITS AND COMPLIANCE INFORMATION
Compliance materials. Upon reasonable request and subject to appropriate confidentiality restrictions, YouScan shall make available information reasonably necessary to demonstrate its compliance with applicable Processor obligations, which may include current certifications, independent audit reports, penetration-test attestation letters, security documentation and completed standard security questionnaires available through the YouScan Trust Center.
Use of independent assurance. Client agrees to use then-current independent audit reports, certifications and compliance materials to satisfy audit or inspection requirements to the extent those materials reasonably address the requested control area. YouScan may redact information that is unrelated to Client, legally privileged, security-sensitive, or confidential to YouScan or another customer or third party.
Additional audit. If the materials in Section 8.1 are not reasonably sufficient to demonstrate compliance with an obligation applicable to YouScan under this DPA, and an additional audit is required by Applicable Data Protection Laws, YouScan shall allow and contribute to a reasonable audit of the relevant Processing. Unless a Personal Data Breach, binding regulatory request or Applicable Data Protection Law reasonably requires otherwise, such audit shall: (a) occur no more than once in any twelve (12) month period; (b) be requested on at least thirty (30) days' written notice; (c) occur during normal business hours; (d) be limited to systems and Processing relevant to Client Personal Data; and (e) be conducted so as to minimize disruption to YouScan's operations.
Auditor and restrictions. An auditor must be independent, suitably qualified, not a direct competitor of YouScan, and bound by confidentiality obligations reasonably acceptable to YouScan. No audit may provide access to another customer's information, source code, privileged materials, credentials, vulnerability details whose disclosure would create a security risk, or facilities operated by a third-party infrastructure provider beyond the access that provider permits. Client shall not conduct penetration testing, vulnerability scanning or similar intrusive testing of the Services without YouScan's prior written authorization.
Costs. To the extent permitted by Applicable Data Protection Laws, Client shall bear its own audit costs and reimburse YouScan for reasonable, demonstrable costs of an additional audit beyond YouScan's standard compliance materials, unless the audit identifies a material breach of this DPA by YouScan.
9. GOVERNMENT AND LEGALLY BINDING DISCLOSURE REQUESTS
Disclosure restriction. YouScan shall not disclose Client Personal Data to a law enforcement agency or government authority except on Client's documented instruction or as required by Applicable Law or a valid and binding legal process.
Redirect and notify. If a government authority requests Client Personal Data directly from YouScan, then, unless legally prohibited and where reasonably practicable, YouScan shall inform the requesting authority that YouScan acts as a Processor or service provider and attempt to redirect the request to Client. YouScan may provide Client's basic contact information for that purpose. If redirection is not practicable, YouScan shall take commercially reasonable steps to notify Client so that Client may seek a protective order or other appropriate remedy.
Review and minimization. If YouScan is legally compelled to respond, YouScan shall review the legal validity and scope of the request and, where commercially reasonable and legally available, consider whether grounds exist to challenge an overbroad or unlawful request. YouScan shall disclose only the minimum Client Personal Data that it reasonably determines is legally required.
Transfer clauses. Where the EU SCCs or UK Addendum apply, the mandatory government-access provisions of those terms apply in addition to this Section and prevail in the event of conflict.
10. RETURN AND DELETION OF CLIENT PERSONAL DATA
During the term. Subject to the functionality and technical limitations of the Services, Client may access, export, correct and delete Client Personal Data during the subscription term through available self-service tools.
End of Services. Upon expiration or termination of the affected Services, Client instructs YouScan to delete Client Personal Data unless Client submits a written request for return of such data within thirty (30) days after termination or another period expressly stated in the Services Agreement. Where a standard export remains technically available, YouScan may satisfy a return request by making that export available to Client.
Deletion. Following the applicable return period, YouScan shall delete Client Personal Data from active systems in accordance with its documented retention and deletion procedures, unless Applicable Law requires retention. Client Personal Data retained solely because of a legal requirement shall remain protected under this DPA and shall not be actively Processed except for the legally required purpose.
Backups. Client Personal Data contained in encrypted, access-restricted backup copies is deleted through YouScan's ordinary backup rotation rather than on demand. Until deletion, such data remains protected and is not restored to active systems except where necessary for disaster recovery, security or legal compliance.
Certification. On reasonable written request, YouScan shall provide confirmation of deletion to the extent required by Applicable Data Protection Laws and reasonably verifiable through YouScan's standard deletion processes.
Separation from YouScan Data. Return or deletion obligations applicable to Client Personal Data do not require YouScan to return, delete or cease independently lawful Processing of YouScan Data merely because the same or similar information was displayed, analyzed or otherwise used in connection with Client's Services. Where the same underlying record exists both in a Client-specific Processing layer and in YouScan's independently maintained data environment, the obligations in this Section apply to the Client-specific copy or Processing operation only, unless Applicable Data Protection Laws, a valid Data Subject request, source requirement or other legal obligation requires YouScan, in its capacity as Controller, to take broader action.
11. YOUSCAN DATA AND PUBLIC WEB PERSONAL DATA - DEFAULT INDEPENDENT CONTROLLER ROLES
Default independent Controller relationship. For YouScan Personal Data made available to or accessed by Client, including Independent Public Web Personal Data, YouScan and Client act as independent Controllers in respect of the Processing each determines and carries out. Each Party is independently responsible for compliance with Applicable Data Protection Laws for its own Processing, including establishing an appropriate lawful basis where required, providing applicable transparency, implementing appropriate safeguards, honoring Data Subject rights, and complying with applicable source and platform restrictions. This is the contractual default allocation, subject only to the narrow Client-Directed Processing exception in Sections 2.6 and 11.5 and any mandatory determination under Applicable Data Protection Laws.
YouScan independent Processing. YouScan may collect, license, receive, retrieve, index, organize, structure, enrich, analyze, store, maintain, generate, derive and make YouScan Personal Data, including Independent Public Web Personal Data, available as part of the ordinary operation of the Services for purposes including social and online media monitoring, creation and maintenance of its searchable data environment, analytics, trends, statistics, service operation, security, data quality, source compliance, rights management and product improvement. YouScan provides information about its Processing of online-author data in its Author Privacy Policy at https://youscan.io/author-privacy-policy/.
Existing and Historical Data. YouScan Data may include Public Web Data that YouScan collected, licensed, received, retrieved, indexed or otherwise maintained before Client entered into the Services Agreement, before a topic was created, or before Client requested access to a particular historical period. Client's later access to, search of, analysis of, receipt of or export of such information does not make Client the Controller that instructed the original collection and does not make YouScan a Processor for YouScan's maintenance or other independent Processing of that pre-existing data environment. Historical Data forms part of YouScan Data where it meets the definition of YouScan Data; its historical character alone does not determine a data-protection role.
Ongoing independent collection. Public Web Data that YouScan continues to collect, license, receive, retrieve, index or maintain as part of its standard multi-client source coverage and data environment forms part of YouScan Data to the extent YouScan Processes it independently and remains subject to YouScan's independent Controller responsibilities, even where a Client topic or query causes a relevant item to be surfaced in Client's Account. This includes Processing that YouScan undertakes as part of its ordinary service-wide operations irrespective of a particular Client's downstream use of an item.
Narrow Client-Directed Processing exception. Processor status for Public Web Personal Data arises under this DPA only where YouScan expressly agrees to perform a specific and separable Processing activity exclusively on Client's behalf and the requirements of Section 2.6 are satisfied. In that case, Sections 3 through 10 and the applicable Processor terms apply solely to the agreed Client-Directed Processing activity. That limited role does not change YouScan's Controller role for YouScan Data or for any factually distinct independent collection, licensing, indexing, storage, maintenance, source compliance or other Processing of the same underlying information.
Client use. Client determines its own purposes for accessing and using Independent Public Web Personal Data and is responsible for ensuring that such use is lawful and consistent with the Services Agreement. Where Applicable Data Protection Laws require Client to provide information about the source of Public Web Personal Data, Client shall provide accurate source information and identify YouScan and/or the underlying public or Third-Party source as applicable. Without limiting the Services Agreement, Client shall not use Public Web Personal Data for unlawful discrimination, unlawful surveillance, or prohibited targeting, segmentation or profiling based on Sensitive Personal Data.
Public does not mean non-personal. The fact that information is publicly accessible or supplied by a Third-Party source does not, by itself, prevent that information from constituting Personal Data. Public Web Personal Data may incidentally contain Sensitive Personal Data or information from which sensitive characteristics could be inferred. YouScan does not intentionally collect such information for the purpose of enabling prohibited sensitive-person profiling. Each Party is responsible for any additional legal condition applicable to its intentional Processing of Sensitive Personal Data.
Data Subject requests. For Independent Public Web Personal Data, each Party is responsible for responding to Data Subject requests directed to it concerning its own Processing. Where a request is clearly intended for the other Party, the receiving Party may direct the Data Subject to the other Party or forward the request where legally permitted and reasonably practicable. For Client-Directed Processing, Section 6 applies. Nothing requires either Party to disclose confidential information or data that it is not legally permitted to disclose.
Removal and source restrictions. YouScan may remove, suppress, de-index, restrict or cease making Public Web Data available where required by Applicable Law, a valid Data Subject request, a source or platform requirement, a change in source availability, or YouScan's contractual obligations. Where YouScan notifies Client that specified Public Web Personal Data must be removed from Client-controlled copies or exports, Client shall promptly comply to the extent required by Applicable Law, the Services Agreement or applicable source terms. Historical Data availability does not override this Section.
Third-Party Content. Public Web Personal Data remains subject to the Third-Party Content provisions of the Services Agreement. Data-protection compliance for YouScan's own Processing is distinct from responsibility for the underlying content itself. Accordingly, nothing in this Section constitutes a representation that YouScan owns Third-Party Content or can grant rights that the relevant author, platform, publisher or other source has not made available, or a warranty regarding the content's accuracy, completeness, lawfulness, non-infringement, availability or suitability for Client's downstream use.
Incidents. Each Party is responsible for security incidents affecting Independent Public Web Personal Data within its own systems and control. A Party shall provide the other with reasonable notice and cooperation where an incident within the notifying Party's control materially affects the other Party's obligations under Applicable Data Protection Laws, to the extent legally permitted. Personal Data Breaches affecting Client Personal Data remain governed by Section 5.
12. INTERNATIONAL DATA TRANSFERS
Transfer compliance. Each Party shall comply with Applicable Data Protection Laws governing international transfers for the transfers it initiates or controls. No Party is required to use the EU SCCs or UK Addendum for a transfer that is covered by a valid adequacy decision or another lawful transfer mechanism.
EU SCCs. Where a Restricted Transfer subject to the GDPR occurs directly between the Parties and no other valid transfer mechanism applies, the EU SCCs are incorporated into this DPA by reference and apply automatically at the start of that Restricted Transfer using the module that corresponds to the Parties' roles: Module One for Controller-to-Controller transfers, Module Two for Controller-to-Processor transfers, Module Three for Processor-to-Processor transfers, and Module Four for Processor-to-Controller transfers.
Independent Public Web Personal Data. Without limiting Section 12.2, where YouScan, acting as Controller, makes a Restricted Transfer of Independent Public Web Personal Data to Client acting as an independent Controller, Module One applies. Historical Data is included only to the extent the relevant Processing is an independent Controller-to-Controller transfer; the Historical Data label alone does not determine the module.
Client Personal Data and Client-Directed Processing. Where Client Personal Data, including Personal Data subject to Client-Directed Processing where applicable, is subject to a Restricted Transfer directly between the Parties, Module Two, Module Three or Module Four applies as appropriate to the Parties' actual roles for that transfer. Where YouScan makes an onward Restricted Transfer of Client Personal Data to a Sub-processor, YouScan shall implement a transfer mechanism required by Applicable Data Protection Laws.
UK transfers. For a Restricted Transfer subject to the UK GDPR, the UK Addendum is incorporated into this DPA and applies together with the EU SCCs as completed in Annex 3.
Swiss transfers. For a Restricted Transfer subject to the Swiss Federal Act on Data Protection, the EU SCCs apply with the adaptations in Annex 3 to the extent required by Swiss law and recognized by the Swiss Federal Data Protection and Information Commissioner.
Transfer assessments and supplementary measures. Each Party shall provide the other with reasonable information within its control that is necessary to assess a Restricted Transfer. YouScan may rely on its security program, transfer assessments, Sub-processor diligence, contractual safeguards and other supplementary measures. Neither Party is required to disclose legally privileged, security-sensitive, or third-party confidential information where equivalent information can reasonably satisfy the requirement.
Precedence. If the EU SCCs, UK Addendum or mandatory transfer law conflicts with this DPA, the mandatory transfer terms prevail for the Restricted Transfer only. Nothing in this DPA modifies the EU SCCs in a manner that reduces the rights of Data Subjects or contradicts their mandatory provisions.
13. U.S. STATE PRIVACY LAWS
Application. This Section applies only where Client Personal Data is subject to a U.S. State Privacy Law and YouScan Processes that data as a Processor, Service Provider or Contractor on behalf of Client acting as a Controller or Business. The terms of this Section shall be interpreted to satisfy the applicable mandatory contractual requirements without expanding their scope.
Specific business purposes. Client discloses Client Personal Data to YouScan only for the limited and specific purposes of: (a) hosting, storing, operating, maintaining and supporting the Services; (b) authenticating users and administering accounts, permissions and access; (c) receiving, organizing, searching, analyzing, displaying, transmitting, exporting and otherwise Processing Client Personal Data as configured or instructed by Client; (d) operating Client-authorized integrations and APIs; (e) detecting, preventing and responding to security incidents, fraud, abuse and unlawful activity; (f) debugging, troubleshooting, quality assurance and maintaining the quality and safety of the Services; (g) generating aggregated or de-identified statistics and improving the Services using information that no longer constitutes Personal Data or personal information under the applicable law; and (h) complying with legal obligations directly related to provision of the Services.
Restrictions. To the extent required by the applicable U.S. State Privacy Law, YouScan shall not: (a) Sell or Share Client Personal Data; (b) retain, use or disclose Client Personal Data for a purpose other than the specific purposes in Section 13.2 or as otherwise permitted by the applicable law; (c) retain, use or disclose Client Personal Data outside the direct business relationship with Client; or (d) combine Client Personal Data with Personal Data received from or on behalf of another person, or collected from YouScan's own interaction with a Consumer, except as expressly permitted by Applicable Data Protection Laws.
Equivalent protection and compliance. YouScan shall provide the same level of privacy protection for Client Personal Data as required of a Service Provider, Contractor or Processor under the applicable U.S. State Privacy Law. YouScan shall notify Client if it determines that it can no longer meet a material applicable obligation. If Client provides reasonable substantiation of unauthorized use of Client Personal Data, Client may require YouScan to take reasonable and appropriate steps to stop and remediate that use to the extent required by the applicable U.S. State Privacy Law.
Consumer rights and assessments. Taking into account the nature of Processing and information available to YouScan, YouScan shall provide reasonable assistance required by applicable U.S. State Privacy Laws for Client to respond to verified Consumer requests and, where legally applicable to the Services, to support Client's cybersecurity audit, risk assessment or assessment of automated decision-making activities. Such assistance is subject to Sections 6 and 8 and does not require YouScan to disclose information that Applicable Law permits it to withhold.
Monitoring compliance. The rights and procedures in Section 8 constitute Client's contractual right to take reasonable and appropriate steps to help ensure YouScan uses Client Personal Data consistently with Client's obligations under applicable U.S. State Privacy Laws, subject to any additional non-waivable legal right.
Subcontractors. YouScan shall require each Sub-processor Processing Client Personal Data subject to this Section to be bound by applicable contractual restrictions required of a downstream Service Provider, Contractor or Processor.
Certification. YouScan certifies that it understands and will comply with the restrictions applicable to it under this Section and the relevant U.S. State Privacy Laws.
14. GENERAL PROVISIONS
Order of precedence. For data protection matters, the order of precedence is: (a) mandatory provisions of the EU SCCs, UK Addendum or other mandatory transfer mechanism; (b) this DPA; and (c) the Services Agreement. A more specific written provision expressly agreed by the Parties for a particular Processing activity prevails over a general provision to the extent of that activity.
Liability. As between the Parties and to the maximum extent permitted by Applicable Law, all liability arising out of or relating to this DPA, including liability relating to a Restricted Transfer, is subject to the exclusions, limitations and allocation of liability in the Services Agreement. This Section does not limit any right of a Data Subject under the EU SCCs or UK Addendum, or any liability that cannot lawfully be limited.
Changes to this DPA. YouScan may update this DPA where reasonably necessary to reflect changes in Applicable Data Protection Laws, mandatory transfer mechanisms, regulatory requirements, the Services or YouScan's Processing operations. YouScan shall not use an update to materially reduce the overall protection of Client Personal Data during an existing subscription term. Where reasonably practicable, YouScan shall provide prior notice of a material change. A mandatory legal or regulatory change may take effect when required by law. Each updated version will identify its version date. Any notice of a material update will specify when that update takes effect for Client in accordance with the Services Agreement and this DPA.
Term and survival. This DPA becomes effective on the Effective Date and remains in force while YouScan Processes Personal Data governed by this DPA. Provisions that by their nature apply after termination, including confidentiality, deletion, liability and transfer provisions, survive for as long as necessary to give them effect.
Governing law and venue. Except where the EU SCCs, UK Addendum, Swiss transfer terms or mandatory Applicable Data Protection Laws require otherwise, the governing law and dispute-resolution provisions of the Services Agreement apply to this DPA.
No additional third-party beneficiaries. Except for rights expressly granted to Data Subjects under the EU SCCs, UK Addendum or Applicable Data Protection Laws, this DPA does not create third-party beneficiary rights.
Severability. If a provision of this DPA is held invalid or unenforceable, it shall be interpreted or modified to the minimum extent necessary to make it enforceable while preserving its purpose, and the remaining provisions remain in effect.
Electronic acceptance. This DPA is incorporated into the Services Agreement by reference and does not require a separate signature. The Parties’ execution or acceptance of the Services Agreement incorporating this DPA constitutes acceptance of this DPA, including its Annexes..
ANNEX 1 - DETAILS OF PROCESSING
A. CLIENT PERSONAL DATA - YOUSCAN AS PROCESSOR / SUB-PROCESSOR
Subject matter. Processing Client Personal Data to provide the Services under the Services Agreement and Client's documented instructions, including Client-Directed Processing where Section 2.6 of the DPA applies.
Duration. For the duration of the applicable Services and thereafter only for the limited return, deletion, backup rotation or legally required retention periods described in Section 10 of the DPA.
Frequency. Continuous or recurring during the subscription term, as initiated or configured by Client and its Authorized Users.
Nature of Processing. Receipt, collection from Client-authorized sources, hosting, storage, organization, structuring, retrieval, consultation, search, analysis, classification, display, transmission, export, support, security monitoring, correction, deletion and other Processing reasonably necessary to provide the Services. Where Section 2.6 of the DPA applies, this may include a specific collection or retrieval operation from a public or Third-Party source performed solely on Client's documented instructions.
Purposes. Providing, operating, maintaining, securing, supporting and troubleshooting the Services; performing Client-configured analytics and integrations; administering authorized access; carrying out Client-Directed Processing where applicable; and complying with legal obligations applicable to YouScan as a service provider.
Categories of Data Subjects. May include Client employees, Authorized Users and representatives; Client customers, prospects, partners, suppliers, contractors, vendors and other business contacts; individuals whose Personal Data Client imports, uploads or otherwise makes available; and, solely where Client-Directed Processing applies, individuals associated with the relevant public or Third-Party source.
Types of Personal Data. May include names, usernames and online identifiers; business and personal contact information; account and organization information; files, text, images, audio or video supplied by Client; labels, notes and classifications added by Client; message or integration data where an applicable feature is used; technical metadata associated with Client-submitted information; and Public Web Personal Data solely to the extent a specific operation qualifies as Client-Directed Processing. Independent Public Web Personal Data is excluded from this Part A.
Sensitive Personal Data. Not required or intended as a standard category of Client Personal Data. If Client elects to submit or specifically instruct Processing of Sensitive Personal Data, Section 3.7 of the DPA applies and Client controls the type and extent of such data for the relevant Processor activity.
Retention. As described in Section 10 of the DPA and YouScan's documented retention procedures, subject to legal retention obligations and backup rotation. This retention description does not apply to separate Independent Public Web Data maintained by YouScan as Controller.
B. YOUSCAN PERSONAL DATA / INDEPENDENT PUBLIC WEB PERSONAL DATA - INDEPENDENT CONTROLLERS
Data sources. Publicly accessible websites and online sources; social and online media platforms; and third-party platform or data providers that make information available to YouScan under applicable access arrangements. Not every source is a contractual data supplier to YouScan; source access may arise from contractual access, authorized APIs or comparable mechanisms, or indexing of information that is publicly accessible on the web, subject in each case to applicable source restrictions and law.
Historical Data. This Part includes Historical Data to the extent it forms part of YouScan Data, including information already collected, licensed, received, retrieved, indexed or maintained by YouScan before the Client relationship, topic creation or historical request, and information retrieved or maintained through YouScan's independently operated data environment. Historical Data limits or references to "unlimited" availability in the Terms concern Service functionality and collection allowances and do not create a minimum retention period or guarantee availability of a particular item.
Categories of Data Subjects. Individual authors and users of publicly available online content, including social-media users, bloggers, content creators, influencers, journalists, commenters and other individuals appearing in or associated with Public Web Data.
Types of Personal Data. Depending on the source, may include names, usernames, handles, user IDs, profile or account metadata, geographic area or location information, publicly posted text and comments, opinions, interests, engagement information, professional or educational information, publicly shared images, audio and video, links and URLs, and derived analytics such as language, sentiment, topic classifications and other inferences generated by the Services.
Sensitive Personal Data. Independent Public Web Personal Data may incidentally include information that constitutes Sensitive Personal Data or permits sensitive inferences. Such information is not intentionally collected for the purpose of enabling prohibited sensitive-person profiling, and the restrictions in the Services Agreement and Section 11 of the DPA apply.
YouScan purposes and essential means. YouScan determines the purposes and essential means of its Processing of YouScan Data described in this Part, including its independent collection, licensing, receipt, retrieval, indexing, structuring, maintenance, enrichment and provision of its multi-client Public Web Data environment, source architecture, service-wide retention criteria, security, data-quality and source-compliance processes. Purposes include social and online media monitoring, maintaining a searchable and analyzable data environment, generating statistics, trends and analytics, operating and securing the Services, source and platform compliance, rights management, handling Data Subject requests and improving the Services.
Client purposes. Client independently determines its own brand, media, market, consumer, reputation, competitive, research and analytics purposes and other lawful uses permitted under the Services Agreement.
Frequency and duration. Collection, licensing, receipt, retrieval and indexing may be continuous or recurring according to source availability and the ordinary operation of the Services. YouScan retains YouScan Personal Data described in this Part according to documented source-specific and operational criteria, applicable platform requirements, Applicable Data Protection Laws and its Author Privacy Policy. Client independently determines retention of copies it exports or otherwise controls, subject to the Services Agreement, source restrictions and Applicable Law.
C. CLIENT-DIRECTED PROCESSING OF PUBLIC WEB PERSONAL DATA - IF APPLICABLE
Application. This Part applies only where YouScan expressly agrees to perform a specific and separable Processing activity that qualifies as Client-Directed Processing under Section 2.6. It does not apply merely because Client creates a topic, selects keywords, requests Historical Data, applies a filter, requests an export or accesses information from YouScan's independently maintained data environment.
Roles. For the affected operation, Client acts as Controller (or Processor for another Controller) and YouScan acts as Processor (or Sub-processor), subject to Sections 3 through 10. The role is limited to that operation and does not alter YouScan's role for factually distinct Independent Public Web Processing.
Processing details. The categories of Data Subjects and Personal Data are determined by the Client instruction and the relevant source and may include the categories described in Part B. The nature, purposes, frequency and duration are limited to the Client-Directed Processing necessary to perform the applicable Service or instruction and are subject to Section 10.
D. BUSINESS CONTACT DATA
Business Contact Data is outside the Processor relationship in Parts A and C. YouScan Processes Business Contact Data as an independent Controller for the purposes described in YouScan's Privacy Policy at https://youscan.io/privacy-policy/.
ANNEX 2 - TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
This Annex 2 forms part of the DPA. Where the EU SCCs apply, Annex II of the EU SCCs is completed by the measures set out below to the extent applicable to the relevant transfer.
YouScan has implemented and shall maintain an information security program aligned with the ISO/IEC 27000 family of standards. The controls below describe YouScan's current measures for the systems supporting the Services. They are not intended to require use of a particular technology where an equivalent or stronger control is implemented. YouScan may update or modify the measures in accordance with Section 5.2 of the DPA.
A. MEASURES OF PSEUDONYMISATION AND ENCRYPTION OF PERSONAL DATA
YouScan implements encryption to protect Personal Data using:
industry-standard encryption protocols designed to provide effective protection against active and passive attacks, including attacks using resources reasonably known to be available to public authorities;
trustworthy public-key certification authorities and infrastructure;
effective encryption algorithms and parameterization, including a minimum of 256-bit key lengths for symmetric encryption (AES-256) and a minimum of 2048-bit RSA or 256-bit ECC key lengths for asymmetric algorithms;
encryption of Personal Data at rest across storage, database and backup services using keys managed within a dedicated cloud key management service;
encryption of Personal Data in transit over public networks using TLS 1.2 or higher, with legacy protocol versions and weak cipher suites disabled; and
centrally enforced full-disk encryption on corporate endpoints with access to production systems or Personal Data through mobile device management.
Where the nature of Processing permits, YouScan applies pseudonymization, tokenization, masking and aggregation techniques, including:
de-identification or masking of Client Personal Data used in non-production, development and testing environments;
use of internal, non-descriptive identifiers in place of directly identifying attributes within processing pipelines where identification is not required; and
aggregation and anonymization of data used for analytics, product telemetry and reporting where identification of an individual is not required.
Where Public Web Personal Data is processed in the form in which it was publicly published or supplied by an authorized source, preserving the original content may be necessary for source fidelity and delivery of the Services. Pseudonymization of such content may therefore be technically infeasible or inconsistent with the applicable processing purpose. Such data remains protected by the encryption, access-control and logging measures in this Annex.
B. MEASURES FOR ENSURING ONGOING CONFIDENTIALITY, INTEGRITY, AVAILABILITY AND RESILIENCE
YouScan enhances the security of production systems and services by:
operating a documented secure software development lifecycle, including security requirements definition, threat consideration at the design stage, and a change control process under which all changes to production environments require human approval granted by an authorized owner of that environment;
performing automated static analysis, software composition analysis, secrets detection, container-image scanning and infrastructure-as-code scanning within the CI/CD pipeline, with defined blocking thresholds;
maintaining a vulnerability-management program with risk-based remediation service levels and automated patch management for operating systems and dependencies;
maintaining strict logical separation between development, testing and production environments, with Client Personal Data excluded from non-production environments unless de-identified;
enforcing multi-tenant logical isolation so each Client's data is segregated and accessible only within that Client's tenancy;
deploying preventative and detective controls, including a web application firewall, DDoS protection, network intrusion detection, endpoint protection and DNS filtering;
validating integrity of stored and transmitted data through cryptographic checksums and platform-level integrity verification; and
restricting the ability to input, read, alter and delete Personal Data through a documented authorization model, with actions attributable to a uniquely identified individual or service identity.
YouScan operates the Services on redundant, high-availability infrastructure deployed across multiple availability zones within a primary European Union region, with capacity in a secondary European Union region. Infrastructure is monitored for capacity, performance and availability, with automated alerts to on-call personnel and a public status page at https://status.youscan.io.
C. MEASURES FOR TIMELY RESTORATION AFTER A PHYSICAL OR TECHNICAL INCIDENT
YouScan implements measures designed to protect Personal Data from accidental destruction or loss, including:
a documented Business Continuity Plan and Disaster Recovery Plan, reviewed and tested at least annually through tabletop and technical exercises, with documented results and corrective actions;
internal recovery objectives for business-critical production systems targeting a Recovery Time Objective of 24 hours or less and a Recovery Point Objective of 24 hours or less. These are internal continuity targets and do not create a separate service-level commitment or supersede any SLA in the Services Agreement;
automated daily backups of customer and system data, encrypted to the same standard as live production data;
geographic separation of backups, replicated to a secondary region within the same jurisdiction;
immutability protection applied to backup data to reduce the risk of unauthorized or malicious alteration or deletion during the retention period;
automated monitoring of backup execution, with backup failures generating alerts and incident records;
periodic restoration testing to verify that backups are usable and recovery procedures function as documented;
redundant infrastructure at the hosting layer, including power, network and storage redundancy provided by certified infrastructure providers; and
a documented Incident Response Plan with defined roles, severity classification, escalation paths and post-incident review, tested at least annually.
D. PROCESSES FOR REGULAR TESTING, ASSESSMENT AND EVALUATION OF SECURITY MEASURES
YouScan's technical and organizational measures are subject to continuous and periodic evaluation, including:
annual penetration testing of the production platform and public-facing web application by an independent qualified third-party testing firm, with findings tracked to remediation and attestation letters made available to Client on request subject to confidentiality restrictions;
continuous automated control monitoring through a governance, risk and compliance platform covering personnel, infrastructure, access and policy controls, with automated alerting on control failure;
continuous automated vulnerability scanning of code, dependencies, container images, infrastructure and external attack surface;
an annual information-security risk assessment covering the ISMS scope, with treatment plans, risk owners and residual-risk acceptance recorded in a maintained risk register;
an internal audit program conducted by an independent internal auditor against ISO/IEC 27001 requirements;
annual management review of the ISMS by executive leadership;
annual review and approval of information-security policies;
external audit by an accredited independent certification body; and
security assessment of vendors and Sub-processors before engagement and periodically thereafter, proportionate to the risk of the engagement.
E. MEASURES FOR USER IDENTIFICATION AND AUTHORISATION
YouScan implements user-authentication and privilege-management measures including:
a documented access-control policy based on role-based access control and least privilege;
provisioning access only on documented approval by the resource owner, and revoking access promptly upon role change or termination;
centralized single sign-on with mandatory multi-factor authentication for personnel access to production systems, administrative interfaces and systems containing Personal Data;
prohibiting shared or generic production accounts except where technically unavoidable, in which case accounts are individually approved, credential-vaulted and monitored;
a zero-trust model in which access decisions use verified user identity and device posture rather than network location alone;
time-bound, approval-based privileged and administrative access, with such access logged and reviewed;
periodic reviews of user access rights and privileged accounts, with findings remediated and documented;
password complexity and length requirements consistent with current guidance and use of an enterprise password manager; and
automatic session termination and device locking after defined inactivity periods.
F. MEASURES FOR PROTECTION OF DATA DURING TRANSMISSION
YouScan protects Personal Data during transmission by:
enforcing TLS 1.2 or higher for Personal Data transmitted over public networks, with HTTP Strict Transport Security applied to web interfaces;
encrypting service-to-service communication within the production environment;
using trustworthy public-key certification authorities and automated certificate lifecycle management;
requiring authentication and authorization on application programming interfaces, with input validation and rate limiting;
protecting sending and receiving systems through firewalls, a web application firewall, DDoS mitigation and network access controls;
securely generating, storing, rotating and destroying encryption keys within a dedicated key management service, with access restricted to authorized roles and key operations logged;
prohibiting transmission of Client Personal Data through unapproved channels through policy and data-loss-prevention controls; and
logging, monitoring and alerting on relevant data transmissions and egress patterns.
G. MEASURES FOR PROTECTION OF DATA DURING STORAGE
YouScan protects Personal Data during storage by:
encrypting Personal Data at rest using AES-256 or an equivalent industry-standard algorithm;
storing Personal Data processed in the provision of the Services within data centers located in the European Union;
securely generating, storing and protecting encryption keys within a dedicated key management service separate from encrypted data, with documented lifecycle management covering creation, use, rotation, revocation and destruction;
restricting access to data stores to authorized systems and identified, authenticated users operating under least-privilege authorization;
enforcing network-level restrictions so data stores are not directly reachable from the public internet;
applying secure baseline configurations to systems storing Personal Data and testing them for vulnerabilities and misconfiguration;
maintaining personnel policies, onboarding and recurring training concerning access rights and Personal Data handling obligations;
logging, monitoring and alerting on access to data-processing and storage systems, including administrator access; and
performing controlled and documented destruction of data at the end of the applicable retention period, including cryptographic erasure of storage media and endpoints where applicable.
H. PHYSICAL SECURITY OF PROCESSING LOCATIONS
Personal Data processed in the provision of the Services is hosted in third-party data centers operated by infrastructure providers certified to ISO/IEC 27001 or equivalent international standards and located within the European Union. YouScan does not operate its own data centers and does not process Client Personal Data on premises under its physical control.
Physical security at these facilities is maintained by the infrastructure provider and includes, as applicable:
secured perimeters and secure areas with protected and restricted access paths;
documented access authorization for personnel and third parties, with access logged, monitored and reviewed;
24-hour on-site security, video surveillance, intrusion alarm systems and multi-factor physical access controls;
environmental controls including fire detection and suppression, climate control, and redundant power and network supply; and
secure and documented destruction of decommissioned storage media.
The infrastructure providers' physical controls are validated through independent audit and certification programs reviewed by YouScan as part of vendor assessment. YouScan operates as a fully remote organization. Personnel access production systems only from managed endpoints enforcing full-disk encryption, screen lock, endpoint protection, automated patching and device-posture validation, centrally administered through mobile device management with remote wipe capability. Corporate policy prohibits local storage of Client Personal Data on endpoints.
I. MEASURES FOR EVENT LOGGING
YouScan operates logging and monitoring designed to record, monitor and track access to Personal Data, including administrator access, and to support verification of authorized Processing through:
central collection of application, infrastructure, network, identity and administrative audit logs into a security information and event management platform;
attribution of logged actions to a uniquely identified individual or service identity;
maintenance of up-to-date records of identities holding administrative privileges;
retention of security-relevant audit logs for a minimum of twelve (12) months in storage protected against unauthorized modification and deletion;
automated detection rules and alerting for high-risk anomalies, with escalation to on-call security personnel; and
testing of logging configuration, monitoring, alerting and incident-response processes at least annually.
J. SYSTEM CONFIGURATION, INCLUDING DEFAULT CONFIGURATION
YouScan maintains documented secure baseline configurations for systems supporting the production Processing environment, including third-party systems. Baselines are aligned with recognized industry benchmarks such as Center for Internet Security (CIS) benchmarks and cloud-provider security baselines.
Production infrastructure is defined and deployed as code, with automated mechanisms that enforce baseline configuration and prevent unauthorized changes. Configuration drift is detected through continuous posture monitoring and remediated through change management.
Baselines are configured on least-privilege principles. Access configurations default to deny-all. Default credentials must be changed before a system enters service. System clocks are synchronized to a common authoritative time source, and the ability to modify time data is restricted to authorized personnel.
Changes to production systems are subject to a documented change-management process requiring peer review and approval before deployment. Changes are auditable, version-controlled and revertible. Emergency changes follow a defined expedited procedure with retrospective review and approval.
K. INTERNAL IT AND INFORMATION SECURITY GOVERNANCE
YouScan maintains a formal Information Security Management System (ISMS) designed to protect confidentiality, integrity, authenticity and availability of YouScan data and information systems and to support effective security controls over the systems supporting the Services.
The ISMS is governed by executive management, with a designated Chief Information Security Officer accountable for the security program and defined security roles and responsibilities assigned throughout the organization. Information-security objectives, risk appetite and risk-treatment plans are reviewed by management at least annually.
YouScan maintains documented policies addressing information security, acceptable use, access control, data classification, data protection, retention, encryption, network security, logging and monitoring, vulnerability management, asset management, change management, secure development, backup, physical security, vendor management, incident response, business continuity and disaster recovery. Policies are reviewed and approved at least annually and are formally acknowledged by personnel as applicable.
In respect of personnel, YouScan:
conducts background screening before engagement to the extent permitted by Applicable Law;
requires binding confidentiality obligations that survive termination of engagement;
requires security and privacy awareness training on onboarding and at least annually thereafter, with completion tracked centrally;
provides role-specific training, including secure-development training for engineering personnel;
maintains a documented disciplinary process for security-policy violations; and
operates a documented offboarding process for prompt access revocation and return or wiping of corporate assets.
YouScan maintains an asset inventory covering information assets, endpoints, cloud resources and software, with assigned ownership and classification. Data is classified under a documented Data Classification Policy and handling requirements are applied according to classification. YouScan maintains documentation of the measures in this Annex for audit and preservation of evidence and takes reasonable steps to ensure relevant personnel understand and comply with them.
L. CERTIFICATION AND ASSURANCE
YouScan's information-security management system and related risk-management processes are subject to independent external assessment. Current certifications and assurance information are made available through the YouScan Trust Center at https://trust.youscan.io. Independent penetration-test attestation letters and, subject to applicable confidentiality restrictions, relevant audit reports and completed security-assessment documentation may be made available to Client through the Trust Center or on request.
M. MEASURES FOR ENSURING DATA MINIMISATION
For Client Personal Data, YouScan applies data-minimization requirements as part of secure design and the Processing performed under Client's documented instructions, including:
limiting collection and Processing to fields and functions reasonably required for the specified processing purpose;
restricting fields and attributes exposed to internal roles on a need-to-know basis;
de-identifying or excluding Client Personal Data from non-production environments, telemetry and analytics where identification is not required; and
reviewing new features and material data flows for privacy impact before release.
For Public Web Personal Data, the data-minimization measures applied by YouScan take account of the source, the social-listening purpose, source fidelity, platform requirements and applicable legal obligations; they do not require alteration of public content where doing so would defeat the legitimate Processing purpose.
N. MEASURES FOR ENSURING DATA QUALITY
Client retains responsibility for accuracy, quality and legality of Client Personal Data it provides. YouScan supports data quality through input validation, integrity verification of stored and transmitted data, monitoring ingestion and processing pipelines for failures and anomalies, and functionality that enables Client to correct, update or delete Client Personal Data where supported. Public Web Data quality is necessarily dependent in part on the underlying source and third-party platform information.
O. MEASURES FOR ENSURING LIMITED DATA RETENTION
YouScan maintains a documented Data Retention Policy defining retention criteria by data category and classification. Client Personal Data is retained for the duration of the Services and thereafter only as described in Section 10 of the DPA or as required by Applicable Law.
Client Personal Data contained in immutable backup copies is deleted according to the applicable backup-rotation cycle rather than on demand and remains protected by the encryption and access-control measures in this Annex until expiry of that cycle.
Public Web Personal Data is retained according to documented source-specific and operational retention criteria, platform and provider requirements, Applicable Data Protection Laws, and YouScan's Author Privacy Policy.
P. MEASURES FOR ENSURING ACCOUNTABILITY
YouScan demonstrates accountability through:
a designated Chief Information Security Officer and defined privacy and security roles with documented responsibilities;
records of Processing activities maintained as required by Applicable Data Protection Laws, including Processor records under GDPR Article 30(2) where applicable;
a maintained risk register, statement of applicability and control inventory subject to periodic review;
continuous automated control monitoring with evidence collection;
documented internal audit, management-review and corrective-action processes;
public security and privacy contact points at security@youscan.io and privacy@youscan.io;
a documented Personal Data Breach procedure providing for notice to Client without undue delay after YouScan becomes aware of a Personal Data Breach, with information reasonably available to support Client's obligations; and
a documented vendor and Sub-processor management process including security and data-protection assessment before engagement, contractual flow-down of required protections and periodic reassessment.
Q. MEASURES FOR DATA PORTABILITY AND ERASURE
The Services provide Client with self-service functionality to search, access, export and delete Client Personal Data within its tenancy to the extent supported by the applicable feature, including export in structured or commonly used formats where available. Where Client cannot reasonably action a Data Subject request through the Services, YouScan provides assistance in accordance with Section 6 of the DPA. Erasure requests actioned through the Services are propagated to applicable primary production data stores, with backup copies handled under Section O above.
R. SUB-PROCESSOR MEASURES SUPPORTING CONTROLLER ASSISTANCE
Sub-processor selection and assessment. Sub-processors are subject to documented security and data-protection assessment before engagement, including review of relevant certifications, audit reports, data locations and contractual safeguards, with periodic reassessment proportionate to risk.
Contractual flow-down. Sub-processors are engaged under written terms requiring data-protection obligations appropriate to the Processing, including security, confidentiality, breach notification and assistance obligations required by Applicable Data Protection Laws.
Self-service rights support. Client can generally search, export, correct and delete Client Personal Data within its own tenancy without direct Sub-processor involvement.
Breach notification. Sub-processors are required to notify YouScan of applicable Personal Data Breaches without undue delay so YouScan can meet its obligations to Client.
Sub-processor transparency. YouScan maintains a current Sub-processor list and provides notice of additions or replacements in accordance with Section 7 of the DPA.
ANNEX 3 - INTERNATIONAL TRANSFER TERMS
This Annex completes the EU SCCs, UK Addendum and Swiss adaptations when they apply under Section 12 of the DPA. It does not create a Restricted Transfer where one would not otherwise exist under Applicable Data Protection Laws. The applicable transfer module follows the Parties' actual roles for the specific transfer and is not determined solely by whether the data is Public Web Data, Historical Data or Client Personal Data.
A. EU SCC SELECTIONS
Commencement. The applicable EU SCC module takes effect automatically when the relevant Restricted Transfer begins and remains in effect only for so long as that Restricted Transfer requires the EU SCCs.
Docking. Clause 7 (Docking Clause) applies.
Sub-processors. For Modules Two and Three, Clause 9(a), Option 2 (General Written Authorization), applies. The notice period is the period stated in Section 7.4 of the DPA, subject to the urgent appointment exception in that Section to the extent permitted by Applicable Data Protection Laws.
Optional redress. The optional wording in Clause 11(a) is not selected.
Governing law. For Clause 17, Option 1 applies and the governing law is the law of the Republic of Cyprus.
Forum. For Clause 18(b), the courts of the Republic of Cyprus are selected.
Annex II. Where YouScan is the data importer, Annex II of the EU SCCs is completed by the applicable measures in Annex 2 of this DPA. Where Client is the data importer under Module One, the Parties shall document and incorporate into the applicable SCC Appendix the technical and organizational measures implemented by Client for the relevant Processing before the Restricted Transfer begins. Annex 2 describes YouScan’s measures and does not replace the description of Client’s measures.
Annex III. For Modules Two and Three, the list of authorized Sub-processors is the then-current Sub-processor list made available through the YouScan Trust Center or another location notified to Client.
B. ANNEX I.A TO THE EU SCCS - LIST OF PARTIES
Module One - Data Exporter. YouScan Limited, 2 Agias Elenis, 6th Floor, 1060 Nicosia, Cyprus. Contact: Data Protection Officer / Privacy Team, privacy@youscan.io. Activities: independent collection, licensing, receipt, retrieval, indexing, maintenance and provision of YouScan Personal Data described in Annex 1, Part B, including Independent Public Web Personal Data, through the Services. Role: Controller.
Module One - Data Importer. Client, at the address and contact details stated in the Order Form or Services Agreement, where Client receives or is provided access to YouScan Personal Data described in Annex 1, Part B as an independent Controller. Activities: accessing and using that Personal Data for Client's independently determined purposes. Role: Controller.
Modules Two and Three - Data Exporter. Client, at the address and contact details stated in the Order Form or Services Agreement. Activities: use of the Services and provision or instruction of Client Personal Data, including Client-Directed Processing where applicable. Role: Controller for Module Two; Processor for Module Three.
Modules Two and Three - Data Importer. The YouScan entity, Affiliate or other recipient identified for the relevant direct Restricted Transfer. Contact: privacy@youscan.io unless another contact is specified for that recipient. Activities: provision of the Services and Processing of Client Personal Data. Role: Processor for Module Two; Processor/Sub-processor for Module Three.
Module Four - Data Exporter. YouScan Limited or the relevant YouScan entity acting as Processor. Activities: return, transmission or making Client Personal Data available to Client in connection with the Services. Role: Processor.
Module Four - Data Importer. Client at the address and contact details in the Order Form or Services Agreement. Activities: receipt and use of Client Personal Data in connection with the Services. Role: Controller.
Alternative role. If Client demonstrates that it has a different legally relevant role for a particular Restricted Transfer of Public Web Personal Data, the Parties shall use the EU SCC module or other lawful transfer mechanism corresponding to the actual roles for that transfer, without changing the role allocation for other Processing operations.
The Parties are deemed to have signed the applicable EU SCC module by entering into the Services Agreement or otherwise accepting this DPA to the extent electronic incorporation is legally permitted. Any additional entity that validly docks into the EU SCCs must provide the information required by Clause 7.
C. ANNEX I.B TO THE EU SCCS - DESCRIPTION OF TRANSFERS
Module One - Categories of Data Subjects. The categories in Annex 1, Part B.
Module One - Categories of Personal Data. The categories in Annex 1, Part B.
Module One - Historical Data. Historical Data may be included where it forms part of YouScan Personal Data described in Annex 1, Part B. Its historical character does not itself determine the transfer module.
Module One - Sensitive data. Independent Public Web Personal Data may incidentally include Sensitive Personal Data as described in Annex 1, Part B. Applicable safeguards include purpose restrictions, Client use restrictions, role-based access, encryption, logging, source and rights-management processes, and the Security Measures in Annex 2.
Module One - Frequency. Continuous or recurring access and transfer during the subscription term, depending on Client usage, source availability and the relevant independent processing.
Module One - Nature and purposes. YouScan makes YouScan Personal Data described in Annex 1, Part B, including Independent Public Web Personal Data, available through the Services so Client may search, access, analyze and use it for lawful purposes permitted by the Services Agreement. YouScan's independent Processing purposes are described in Annex 1, Part B.
Module One - Retention. YouScan retention follows Annex 1, Part B. Client independently determines retention of data it receives or exports, subject to Applicable Data Protection Laws, the Services Agreement and source restrictions.
Modules Two and Three - Categories of Data Subjects. The categories in Annex 1, Part A and, where Client-Directed Processing applies, Part C.
Modules Two and Three - Categories of Personal Data. The categories in Annex 1, Part A and, where Client-Directed Processing applies, Part C, the type and extent of which are determined by Client for the relevant Processor activity.
Modules Two and Three - Sensitive data. Not intended as a standard category. If Client submits or specifically instructs Processing of Sensitive Personal Data, the restrictions in Section 3.7 and Security Measures in Annex 2 apply, together with any additional safeguards agreed for the applicable feature.
Modules Two and Three - Frequency. Continuous or recurring during the subscription term as initiated or configured by Client for the relevant Processor activity.
Modules Two and Three - Nature and purposes. The Processing described in Annex 1, Part A and, where applicable, Part C, for purposes of providing, operating, securing and supporting the Services under Client's documented instructions.
Modules Two and Three - Retention. As described in Section 10 and Annex 1, Parts A and C, as applicable.
Module Four. The categories, Processing, purposes and retention criteria are those in Annex 1, Parts A and C, as applicable, to the extent Client Personal Data is transferred or made available by YouScan as Processor to Client as Controller in a Restricted Transfer.
Sub-processor transfers. Where a Sub-processor is the importer under a separate transfer mechanism entered into by YouScan, the subject matter, nature and duration are limited to the Sub-processor services necessary to support the Services and are governed by YouScan's agreement with that Sub-processor.
D. ANNEX I.C TO THE EU SCCS - COMPETENT SUPERVISORY AUTHORITY
For Modules One, Two and Three, the competent Supervisory Authority is determined in accordance with Clause 13 of the EU SCCs. Where YouScan Limited is the data exporter and is established in Cyprus, the competent Supervisory Authority is the authority competent for YouScan under the GDPR. Where Client is the data exporter, the competent authority is determined by Client's establishment or other criteria in Clause 13. Module Four does not use Annex I.C unless required by the applicable module terms.
E. UK ADDENDUM
Incorporation. For a UK Restricted Transfer, the UK Addendum is incorporated into this DPA and the applicable EU SCC module is the Approved EU SCCs for purposes of that Addendum.
Table 1. The Start Date is the date the relevant UK Restricted Transfer begins. The Parties, addresses and key contacts are those stated in Annex 3, Part B and the Services Agreement. The Parties may enter into the UK Addendum by accepting the Services Agreement and this DPA to the extent permitted by the UK Addendum.
Table 2. The version of the Approved EU SCCs is the EU SCCs defined in this DPA, using the applicable module and selections in Part A of this Annex.
Table 3. Annex 1A information is in Part B of this Annex; Annex 1B information is in Part C; Annex II information is in Annex 2 of the DPA; and Annex III information is the Sub-processor list described in Section 7 and Part A.8 of this Annex.
Table 4. "Neither Party" is selected for purposes of ending the UK Addendum under Section 19 solely because the ICO issues a revised Approved Addendum. The Parties shall nevertheless cooperate in good faith to implement any replacement transfer mechanism required by UK law.
F. SWISS RESTRICTED TRANSFERS
Recognition and adaptation. The Parties intend to rely on the EU SCCs as recognized by the Swiss Federal Data Protection and Information Commissioner (FDPIC) for transfers subject to the Swiss Federal Act on Data Protection (FADP), with the adaptations required by Swiss law for the relevant transfer.
Swiss-only transfers. Where a Restricted Transfer is subject only to the FADP and not the GDPR: (a) references in the EU SCCs to the GDPR shall be understood as references to the corresponding requirements of the FADP to the extent necessary; (b) the FDPIC is the competent Supervisory Authority; (c) references to an EU Member State shall be understood to include Switzerland where required to give effect to the SCCs under Swiss law; (d) Clause 17 shall be governed by Swiss law; and (e) disputes under Clause 18 shall be subject to the competent courts of Switzerland, without limiting any mandatory place of jurisdiction available to a Data Subject under the FADP.
Dual GDPR/FADP transfers. Where a transfer is subject to both the GDPR and the FADP, the EU SCCs remain governed and supervised as required by the GDPR, and the Swiss adaptations apply additionally only to the extent necessary to satisfy the FADP without reducing GDPR protection.
G. TRANSFER INFORMATION AND CHANGES
Transfer mechanism hierarchy. An adequacy decision, approved framework or other legally valid transfer mechanism may be used in place of the EU SCCs, UK Addendum or Swiss SCC adaptations to the extent it lawfully covers the transfer.
Replacement clauses. If a competent authority adopts mandatory replacement or supplemental transfer clauses, the Parties shall cooperate to implement them where necessary. YouScan may update this Annex to incorporate such mandatory terms in accordance with Section 14.3.
No broader transfer right. Nothing in this Annex authorizes a transfer that is prohibited by Applicable Data Protection Laws or expands either Party's right to use Personal Data beyond the Services Agreement and this DPA.