This Data Processing Agreement (“DPA”) forms part of the Master Services Agreement or Terms of Service (the “Agreement”) between saas.group LLC, doing business as Prerender.io (“Prerender”, “Processor”) and the entity identified in the Agreement (“Customer”, “Controller”). This DPA applies to the extent that Prerender processes Personal Data on behalf of the Customer in connection with the Prerender Service.
This DPA is designed to ensure compliance with: (a) Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”); (b) the UK Data Protection Act 2018 and UK GDPR; (c) the Swiss Federal Act on Data Protection (“FADP”); and (d) any other applicable data protection laws (“Data Protection Laws”).
In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data.
“Personal Data” means any information relating to an identified or identifiable natural person that is processed by Prerender on behalf of the Customer in the course of providing the Service.
“Data Subject” means the identified or identifiable natural person to whom Personal Data relates.
“Subprocessor” means any third party engaged by Prerender to process Personal Data on behalf of the Customer.
“Security Incident” means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission (Implementing Decision (EU) 2021/914).
Terms not otherwise defined in this DPA shall have the meaning given to them in the Agreement or in the GDPR.
Prerender provides a JavaScript rendering service. The service acts as middleware: when a search engine bot or crawler requests a page, Prerender renders the JavaScript-heavy page and returns static HTML. The details of processing are as follows:
Processing of Personal Data necessary for the provision of the Prerender rendering service as described in the Agreement.
Processing shall continue for the duration of the Agreement. Upon termination, Prerender shall delete or return Personal Data in accordance with Section 10 of this DPA.
Due to the nature of the rendering service, the Personal Data processed is limited to:
Prerender does not separately collect or process end-user Personal Data. The Service renders publicly accessible pages that the Customer submits; any Personal Data appearing within that page content originates from and remains under the Customer’s control, is incidental to the rendering operation, and is processed only transiently in the course of executing the render (renders are stateless — see Annex II.D). Prerender does not use such content for any purpose other than returning the rendered output to the Customer
(a) Process Personal Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to a third country, unless required to do so by EU or Member State law. In such a case, Prerender shall inform the Customer of that legal requirement before processing, unless that law prohibits such notification on important grounds of public interest;
(b) Ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
(c) Implement and maintain appropriate technical and organizational measures as set out in Annex II to ensure a level of security appropriate to the risk, including as appropriate: (i) pseudonymization and encryption of Personal Data; (ii) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems; (iii) the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and (iv) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures;
(d) Assist the Customer, taking into account the nature of processing, by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Customer’s obligation to respond to requests for exercising Data Subject rights under Chapter III of the GDPR;
(e) Assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to Prerender;
(f) At the choice of the Customer, delete or return all Personal Data to the Customer after the end of the provision of Services relating to processing, and delete existing copies unless EU or Member State law requires storage of the Personal Data;
(g) Make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
The Customer provides Prerender with general written authorization to engage Subprocessors to process Personal Data on the Customer’s behalf. The current list of authorized Subprocessors is set out in Annex III and is also available at https://trust.prerender.io/subprocessors.
Prerender shall notify the Customer of any intended changes concerning the addition or replacement of Subprocessors at least thirty (30) days before such changes take effect. Notification shall be provided via email to the address associated with the Customer’s account.
If the Customer has a reasonable, documented objection to a new or replacement Subprocessor based on data protection grounds, the Customer may notify Prerender in writing within fifteen (15) days of receiving notification. The parties shall discuss the concern in good faith. If the parties cannot resolve the objection within thirty (30) days, the Customer may terminate the affected Service(s) without penalty by providing written notice.
Prerender shall ensure that each Subprocessor is bound by data protection obligations no less protective than those set out in this DPA. Prerender shall remain fully liable to the Customer for the performance of each Subprocessor’s obligations.
To the extent that the processing of Personal Data involves a transfer outside the EEA, the United Kingdom, or Switzerland to a country not recognized as providing adequate protection, Prerender shall ensure appropriate safeguards are in place, including:
Prerender’s primary data processing occurs in the United States and the European Union. Details of data processing locations are set out in Annex I.
Prerender shall notify the Customer without undue delay, and in any event within without undue delay, after becoming aware of a Security Incident affecting Personal Data processed on behalf of the Customer.
Such notification shall include, to the extent available:
Prerender shall cooperate with the Customer and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of the Security Incident.
Prerender shall make available to the Customer, on request, all information reasonably necessary to demonstrate compliance with this DPA. The Customer may exercise its audit rights as follows:
Upon termination or expiry of the Agreement:
Prerender shall assist the Customer by appropriate technical and organizational measures for the fulfillment of the Customer’s obligation to respond to Data Subject requests under Data Protection Laws, including rights of access, rectification, erasure, restriction, portability, and objection.
If Prerender receives a request from a Data Subject directly, Prerender shall promptly redirect such request to the Customer and shall not respond directly unless instructed by the Customer or required by applicable law.
The liability of each party under this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA shall limit either party’s liability for breaches of Data Protection Laws to the extent such limitation is not permitted under applicable law.
This DPA shall come into effect on the date of the Agreement and shall remain in force for as long as Prerender processes Personal Data on behalf of the Customer. The obligations imposed on Prerender under this DPA shall survive for as long as Prerender retains any Personal Data.
This DPA shall be governed by the governing law and jurisdiction provisions of the Agreement, provided that: (a) where the SCCs apply, Clause 17 of the SCCs shall designate the law of the EU Member State in which the data exporter is established; and (b) where the UK Addendum applies, English law shall govern.
This DPA is entered into and becomes binding upon execution of the Agreement. The parties’ authorized signatories have executed this DPA as of the date set forth above.
Role | Details |
|---|---|
Data Exporter (Controller) | The Customer as identified in the Agreement |
Data Importer (Processor) | saas.group LLC (Prerender.io), 304 South Jones Boulevard, #1205, Las Vegas, Nevada 89107, USA
Contact: privacy@prerender.io
|
Element | Description |
|---|---|
Subject matter | Rendering of JavaScript web pages for search engine optimization and bot delivery |
Nature of processing | Automated rendering, caching, storage, and delivery of web page content; account management; support communications |
Purpose | Provision of the Prerender rendering service as described in the Agreement |
Duration | Duration of the Agreement plus data retention periods specified in Section 10 |
Data subjects | Customer employees/administrators; end users whose data appears on publicly accessible rendered pages |
Personal data types | URLs (which may contain identifiers); publicly accessible page content; account data (name, email, billing info, IP); support communications |
Sensitive data | None expected. If Customer pages contain sensitive data, Customer is responsible for ensuring a lawful basis. |
Processing locations | United States (primary), European Union (rendering nodes). See Annex III for Subprocessor locations. |
Prerender implements and maintains the following technical and organizational measures to protect Personal Data:
The following Subprocessors are authorized as of the effective date of this DPA. An up-to-date list is maintained at https://trust.prerender.io/subprocessors.
Subprocessor | Purpose | Location | Data Processed |
|---|---|---|---|
Amazon Web Services | Cloud hosting, storage, CDN | USA / EU | Rendered page content, account data |
Apollo.io | Marketing | USA | Customer and prospect contact |
DigitalOcean LLC | Kubernetes hosting (DOKS), database hosting | USA / EU | Application data, account metadata |
Cloudflare Inc. | CDN, DNS, DDoS protection, WAF | Global (edge) | URLs, HTTP headers |
Chargebee Inc. | Subscription billing and invoicing | USA | Account data, billing information |
HubSpot Inc. | CRM, marketing, and sales operations | USA / EU | Name, email, company, usage data |
Grafana Labs | Infrastructure monitoring and observability | USA / EU | System logs (may contain URLs) |
Mixpanel Inc. | Product analytics | EU | Anonymized usage events, account metadata |
Google LLC | Workspace (email, calendar, drive) | USA / EU | Email, internal documents |
Docusign Inc | Contracts and e-signature | USA | Contract information |
Lempire (Lemlist) | Sales & Lead Generation | EU | Name, email, company |
Stripe LLC | Payment Processing | USA | Name, email, company |
Usersnap GmbH | Customer Analytics | EU | User feedback |
Captiwate Inc. | Sales & Lead Generation | USA | Name, email, company |
Fathom Video Inc. | Meeting Intelligence | USA | Name, email, company |
Strategy11, LLC (Formidable Forms) | Marketing & Advertising | USA | Name, email, company details (size, website, phone number) |
Granola Inc. | Meeting Intelligence | USA | Name, email |
wespond UG (haftungsbeschränkt) (Jamie) | Meeting Intelligence | EU | Name, email |
Productboard Inc. | Customer Data & Analytics | USA | Name, email, company name, User feedback |
Tremendous | Customer contact info | USA | Name, email |
Note: Hetzner provides bare-metal server hosting for rendering infrastructure. These providers supply physical hardware only and do not have logical access to Personal Data.
Changes to Subprocessors: Prerender will notify the Customer at least 30 days before adding or replacing a Subprocessor, as described in Section 6.2 of this DPA.