Legal
Data Processing Agreement
On this page
The short version
- This agreement applies automatically to every customer covered by the GDPR, the UK GDPR, the Swiss FADP or Brazil's LGPD. There is nothing to sign; a countersigned copy is available on request.
- You are the controller of the comments and messages we handle for you. We are your processor and act only on your instructions.
- Your data stays in the European Union. The companies that help us run the Service are listed on one page, which we keep current.
This summary is for orientation only. The sections below are the agreement.
1Parties and scope#
This Data Processing Agreement (the "DPA") is between the customer who holds a CommentWatchDog account (the "Customer", "you") and GrowMeOrganic LLC, 30 N Gould St STE R, Sheridan, WY 82801, United States ("we", "us"), the operator of the Service described in the Terms of Service.
It applies whenever we process personal data on your behalf and that processing is subject to the EU General Data Protection Regulation (GDPR), the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection (FADP), or Brazil's Lei Geral de Proteção de Dados (LGPD). Under those laws you are the controller of that data and we are your processor. Where the LGPD uses the words controlador and operador, they mean the same roles.
"Customer Personal Data" means the personal data in the comments, messages and commenter profiles we fetch from the Facebook Pages and Instagram accounts you connect, the actions you take on them, and the personal data of the team members you invite, to the extent we process it on your instructions. Our own use of your account and billing data, and the ad measurement on our websites, are described in the Privacy Policy, where we act as a controller.
This DPA is part of the Terms of Service. For the subject it covers, it takes precedence over the Terms. No signature is needed: it binds both of us from the moment you use the Service.
2Details of the processing#
This section is the description of the processing that the GDPR requires, and serves as Annex I of the standard contractual clauses in section 6.
- Subject matter: moderating and answering the comments and messages on the Facebook Pages and Instagram accounts you connect to the Service.
- Duration: for as long as you keep an account, and afterwards until deletion is complete under section 10.
- Nature and purpose: fetching comments and messages through Meta's APIs, storing them, classifying them by the rules you set (by word, and by meaning through an AI provider), hiding, deleting, archiving or replying to them as you configure, showing them to your team in an inbox, and producing counts and insights about them.
- Categories of individuals: people who comment on or message your pages and accounts, people mentioned in those comments, and the members of your team.
- Categories of data: the text of comments and messages, the name and public profile picture of their author, Meta's identifiers for the author, the post and the comment, timestamps, the labels our rules assign, the actions taken and by whom, and, for team members, their name, email address and role.
- Special categories of data: none is requested. A comment may incidentally contain such data; we process it only to moderate the comment and for nothing else.
- Frequency: continuous, as comments and messages arrive.
- Location: servers operated by Hetzner Online GmbH in Germany, in the European Union.
3Our obligations as processor#
- Instructions. We process Customer Personal Data only on your documented instructions. Your instructions are the Terms of Service, this DPA, the rules, agents and automations you configure in the Service, and the actions your team takes in it. We will tell you if we believe an instruction breaks the law, and we may pause that instruction until it is resolved.
- Confidentiality. Only people who need access to operate the Service have it, and each of them is bound by a duty of confidentiality.
- Security. We keep the measures in section 7 in place and improve them as the state of the art moves.
- Assistance. We help you answer requests from individuals (section 8) and carry out data protection impact assessments and consultations with a supervisory authority, to the extent the information is in our hands.
- Deletion. We delete or return Customer Personal Data as described in section 9.
- Records and cooperation. We keep the records of processing the law requires, make the information needed to show compliance available to you, and cooperate with your supervisory authority when it asks.
- No other use. We never sell Customer Personal Data, never use it for advertising, and never use it to train AI models. Our AI providers process it under API terms that exclude training on customer content.
4Your obligations as controller#
- You have a lawful basis for the processing you instruct, and your instructions comply with the law that applies to you.
- The people who comment on and message your pages are informed, in the way your law requires, that you moderate with a tool that acts on your behalf.
- You configure the rules, agents and automations, and you are responsible for the moderation decisions they carry out.
- You comply with Meta's terms for the pages and accounts you connect.
- You use the controls in the Service (roles, page access, deletion) to keep the processing to what you need.
5Subprocessors#
You give us general authorisation to use the subprocessors listed on our Subprocessors page. That page serves as Annex III of the standard contractual clauses in section 6. It names each company, what it does for us, what data it handles and where.
We keep that page current: a subprocessor is added to it before it handles Customer Personal Data, one that stops handling it is removed, and the change log on the page records both with the date. The page is the notice of such changes; check it as often as your compliance process requires. By continuing to use the Service after a change, you accept the subprocessors listed there. Every subprocessor is bound by written terms that protect Customer Personal Data at least as well as this DPA.
6International transfers#
Customer Personal Data is stored and processed in the European Union. Because we are a company in the United States, and some subprocessors process data there, the following safeguards apply to transfers out of the EEA, the United Kingdom and Switzerland:
- EEA: the standard contractual clauses adopted by the European Commission in Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into this DPA. You are the data exporter and we are the data importer. Clause 7 (the docking clause) applies; under clause 9 you give the general authorisation in section 5, and the Subprocessors page carries the notice of changes; under clause 11 the optional independent dispute resolution does not apply; under clause 13 the supervisory authority is the one of the EU member state where you are established; under clause 17 the clauses are governed by the law of Ireland; under clause 18 disputes go to the courts of Ireland. Annex I is section 2, Annex II is section 7 and Annex III is the Subprocessors page.
- United Kingdom: the International Data Transfer Addendum to the EU standard contractual clauses issued by the UK Information Commissioner, in force from March 21, 2022, is incorporated, with the tables completed by the same sections. Either party may end the Addendum as its section 19 allows.
- Switzerland: the EU clauses apply with the adaptations the Swiss Federal Data Protection and Information Commissioner requires: references to the GDPR read as references to the FADP, the Commissioner is the competent authority, and the clauses also protect the data of legal persons to the extent the FADP does.
- Brazil: where the LGPD applies, the EU clauses serve as the contractual safeguard for international transfers until the ANPD's own standard clauses replace them.
Where a subprocessor processes data outside those territories, the transfer relies on the same clauses in that subprocessor's data processing terms, or on an adequacy decision, as the Subprocessors page states for each of them.
7Security measures#
These are the technical and organisational measures in place today, and they serve as Annex II of the clauses in section 6. The Security page explains them in plain words.
- Hosting: all Service data lives on servers operated by Hetzner Online GmbH in Germany, in data centres certified to ISO 27001.
- Encryption in transit: every connection uses TLS, and browsers are told to use HTTPS only.
- Credentials: passwords are hashed with bcrypt and never stored in plain text. Page access tokens are kept server side, never sent to a browser, and deleted when a page or a Facebook account is disconnected. A password reset signs out every other session.
- Access control: access to production systems is limited to the people who operate the Service, over key-based SSH. In the Service, four roles and per-page access limit what each team member can see, and removing a member ends their access on every device at once.
- Backups and recovery: database backups are taken daily, copied to a second server, and roll off after 14 days.
- Least data to third parties: an AI provider receives the text of a comment, the author's display name where a rule needs it, and your rule notes, never your account details or page tokens. Our payment processor holds card details; we never see the full number.
- Monitoring: error monitoring runs on our own servers. When it records how a screen behaved during an error, every text is masked and every image is blocked.
- Deletion: you can delete a page, your Facebook connection or your whole account at any time without our involvement, and deletions are confirmed with a receipt.
8Requests from individuals#
If someone whose data is in your workspace contacts us to exercise a right (access, correction, deletion, restriction, objection or portability), we do not answer on the substance. We forward the request to the owner of your workspace within five business days, and we help you respond within the time your law allows, with the information that is in our hands. Most of what such a person may ask for is available to you directly in the Service: the comment, its author, the actions taken and the option to delete it.
9Return and deletion#
During the term you can export what the Service offers for export and delete any page, your Facebook connection or your whole account at any time, as the Data deletion page describes. Before deleting your account, you may ask us by email for a copy of the Customer Personal Data we hold, and we provide it in a common machine-readable format.
When your account is deleted, or when the Service ends, we delete all Customer Personal Data at once. It leaves the backup cycle within 14 days, and every trace is gone within 30 days at the latest. We keep only what the law requires us to keep, such as invoices and payment records, and the deletion receipts described in the Privacy Policy, which carry counts and a confirmation code but never content.
10Audits#
The Security page, the Subprocessors page and this DPA are our first answer to any question about how we protect your data. Beyond them, once a year and at no charge, we answer a reasonable written security questionnaire from you.
Where your law or your supervisory authority requires an audit, you or an independent auditor bound by confidentiality may carry one out, no more than once a year unless an authority requires otherwise, on at least 30 days' written notice, during business hours, at your cost, and in a way that does not disrupt the Service or expose other customers' data.
11Liability#
Each party is liable for the damage it causes by failing to comply with this DPA or with the law, as Article 82 of the GDPR and the equivalent provisions of the other laws in section 1 set out. The limits in the liability section of the Terms of Service apply to this DPA, except where the law does not allow them to.
12Term and changes#
This DPA lasts for as long as we process Customer Personal Data for you, and its duties survive the end of the Terms until deletion under section 9 is complete.
We may update this DPA when the law, our subprocessors or the Service change. For material changes we notify the owner of your workspace by email at least 14 days before they take effect. Every version carries its date at the top, and earlier versions are available on request.
13Signed copy and contact#
If your compliance process needs a countersigned copy, write to support@commentwatchdog.com from your account email with the subject "Signed DPA" and your company's legal name and address. We return this DPA as a signed PDF, with your details filled in, within five business days.
Questions about this DPA: support@commentwatchdog.com, or by post to GrowMeOrganic LLC, 30 N Gould St STE R, Sheridan, WY 82801, United States.
