Last updated: September 28, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Import.io Corporation (“Import.io”) and the customer (“Customer”) for the Service (the “Agreement”). It applies where Import.io processes personal data on Customer’s behalf.
1. Roles
Customer is the controller and Import.io is the processor of personal data processed through the Service on Customer’s behalf (“Customer Personal Data”). Each party will comply with the data protection laws that apply to it, including the GDPR, the UK GDPR and the California Consumer Privacy Act (“Data Protection Law”). Customer is responsible for having a lawful basis for the processing it instructs.
2. Instructions
Import.io processes Customer Personal Data only on Customer’s documented instructions, which are the Agreement, Customer’s configuration and use of the Service, and any other written instructions agreed between the parties. Import.io will tell Customer if it believes an instruction breaks Data Protection Law.
3. Confidentiality
Import.io ensures that everyone authorised to process Customer Personal Data is bound by confidentiality.
4. Security
Import.io implements appropriate technical and organisational measures to protect Customer Personal Data, as summarised in Annex 2.
5. Sub-processors
Customer authorises Import.io to use sub-processors. The current list appears in Annex 3 of this agreement. Import.io will give notice before adding or replacing a sub-processor, and Customer may object on reasonable data protection grounds; the parties will then work in good faith to resolve the objection. Import.io imposes data protection terms on each sub-processor that are no less protective than this DPA and remains responsible for them.
6. Assistance
Taking into account the nature of the processing, Import.io will reasonably assist Customer in responding to requests from individuals exercising their rights, and with security, breach notification, data protection impact assessments and consultations with supervisory authorities.
7. Personal data breaches
Import.io will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information Customer reasonably needs to meet its own obligations.
8. International transfers
Where Customer Personal Data is transferred from the EEA, the UK or Switzerland to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914 (Module 2, and Module 3 where Customer is itself a processor), together with the UK International Data Transfer Addendum and the adjustments required for Switzerland. The details required by the clauses are set out in Annex 1.
9. Audits
Import.io will make available the information reasonably necessary to demonstrate compliance with this DPA. Customer may audit Import.io’s compliance once a year, or after a breach, on reasonable notice and at its own cost, in a way that does not disrupt the Service or compromise other customers’ data.
10. Deletion and return
When the Agreement ends, Import.io will, at Customer’s choice, return or delete Customer Personal Data within 30 days, unless the law requires it to be kept.
11. California
For personal information covered by the CCPA, Import.io acts as a service provider. It will not sell or share that personal information, or retain, use or disclose it outside the direct business relationship with Customer, except as the CCPA permits.
12. Liability and precedence
Liability under this DPA is subject to the limits in the Agreement. If this DPA conflicts with the Agreement on data protection, this DPA prevails; if it conflicts with the Standard Contractual Clauses, the clauses prevail.
Annex 1 — Details of processing
- Subject matter and duration: provision of the Service for the term of the Agreement.
- Nature and purpose: collecting, structuring, storing, transforming and delivering web data as configured by Customer.
- Data subjects: individuals whose information appears in the web sources Customer chooses to collect from, and Customer’s users of the Service.
- Personal data: as determined by Customer’s use of the Service, typically names, contact details, professional information and content published online. Special categories of data are not intended to be processed unless agreed in writing.
- Frequency: continuous, in line with Customer’s schedules.
- Parties to the clauses: Customer as data exporter; Import.io Corporation as data importer. Competent supervisory authority: as determined under the clauses.
Annex 2 — Security measures
- Encryption of data in transit and at rest.
- Role-based access control, least-privilege access and logging of administrative access.
- Personal data detection and removal tools available within the Service.
- Backups, monitoring and incident response procedures.
- Vulnerability management and a published process for reporting security findings.
- Confidentiality obligations and security awareness for staff.
Annex 3 — Sub-processors
The current sub-processor list is maintained in the executed agreement provided to each customer. Contact legal@import.io for the current list.