Data Processing Agreement

Last updated: August 15, 2026

Overview

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between Galaxy Labs Limited, a company registered in New Zealand (company number 9439298), trading as Mapster ("Mapster", "we", "our", or "us"), and the customer that has agreed to those Terms ("Customer", "you", or "your").

It applies whenever you use Mapster to process personal data that is subject to Applicable Data Protection Law, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection, and the New Zealand Privacy Act 2020.

You do not need to sign anything. This DPA is incorporated into the Terms automatically and takes effect when you start using the Services to process personal data. If your procurement process requires a countersigned copy, email contact@mapster.io with your entity name and address and we will return a signed version of this document.

How we handle personal data for which we are the controller, such as your own account details, is described in our Privacy Policy rather than in this DPA.

1. Definitions

  • Applicable Data Protection Law means all privacy and data protection laws that apply to the processing of Customer Personal Data under this DPA.
  • Customer Personal Data means personal data that we process on your behalf through the Services, including survey responses and any user attributes you attach to them.
  • Data Subject means the individual to whom Customer Personal Data relates, typically one of your users, customers, or website visitors.
  • Sub-processor means a third party engaged by us to process Customer Personal Data.
  • Controller, Processor, Personal Data, Processing, and Personal Data Breach have the meanings given to them in the GDPR.
  • Standard Contractual Clauses or SCCs means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914.

2. Roles of the Parties

For Customer Personal Data, you are the Controller and we are the Processor. You decide which surveys to run, who sees them, which user attributes are attached to responses, and how long that data is kept in your account.

Where you are yourself acting as a processor on behalf of another controller, you confirm that you have the authority of that controller to enter into this DPA on their behalf, and references to you in this DPA include that controller where the context requires.

For account and billing data, and for data about visitors to our own website, we act as Controller. That processing is governed by our Privacy Policy.

3. Details of the Processing

This section serves as Annex I.B of the Standard Contractual Clauses where they apply.

  • Subject matter: provision of the Mapster survey platform, including delivery of surveys, collection and storage of responses, and analytics on those responses.
  • Duration: the term of your subscription, plus the deletion period described in section 10.
  • Nature and purpose: collection, recording, storage, organization, retrieval, analysis, export, and deletion of survey responses, for the purpose of providing the Services to you.
  • Frequency: continuous, for as long as your surveys are live.
  • Categories of Data Subjects: your end users, customers, employees, and website or product visitors who are shown or respond to a survey, and the members of your team who hold Mapster accounts.
  • Categories of Personal Data:
    • Survey answers submitted by respondents, including free text
    • User attributes you choose to attach to a response, for example email address, user ID, name, plan, role, company, or custom traits passed from your product or survey link
    • Approximate location derived from the respondent's IP address at submission time (country, region, city, approximate coordinates, and postal code where available)
    • A salted, survey-specific hash of the respondent's IP address, used for duplicate and abuse detection. The raw IP address is not stored with the response.
    • Device type, browser, operating system, language preference, a visitor identifier, response timestamps, completion time, and an automated bot-check result
    • Account data for your team members, such as name and email address
  • Special category data: the Services are not designed for special category data as defined in Article 9 of the GDPR. You decide what questions to ask, and you should not use the Services to collect special category data unless you have carried out your own assessment and have a lawful basis for doing so.

4. Our Obligations

We will:

  • Process Customer Personal Data only on your documented instructions. The Terms, this DPA, and your use of the features of the Services are your complete documented instructions. Any other instruction must be agreed in writing.
  • Tell you if, in our opinion, an instruction infringes Applicable Data Protection Law, and pause that processing until it is resolved.
  • Ensure that anyone we authorize to process Customer Personal Data is bound by an appropriate duty of confidentiality.
  • Implement and maintain the technical and organizational measures described in section 5.
  • Not sell Customer Personal Data, and not use it to train machine learning models, to build profiles, for advertising, or for any purpose other than providing and improving the Services as instructed by you.
  • Not disclose Customer Personal Data to any government or law enforcement body except where legally compelled, and where lawful, notify you first.

5. Security Measures

This section serves as Annex II of the Standard Contractual Clauses where they apply. Taking into account the state of the art, the costs of implementation, and the risks to Data Subjects, we maintain measures including:

  • Encryption of data in transit and at rest
  • Salted, survey-specific hashing of IP addresses on stored responses, so raw addresses are not retained with response records
  • Input validation and sanitization on all survey submissions
  • Role-based access controls, with access to production data restricted to personnel who need it
  • Authentication for customer accounts managed by a specialist identity provider
  • Hosting on infrastructure certified to SOC 2 Type II, with platform-level DDoS protection, automatic HTTPS, and infrastructure security patching
  • Logical separation of each customer's data, so no customer can access another customer's responses
  • Error monitoring and alerting to detect and respond to faults and abuse

Our current security practices are described in more detail on our security page. We may update these measures over time, provided the level of protection is not reduced.

6. Sub-processors

You give us general written authorization to engage Sub-processors. Our current Sub-processors, and what each one is used for, are listed on our security page. That list serves as Annex III of the Standard Contractual Clauses where they apply.

Before adding or replacing a Sub-processor, we will update that page and give you at least 30 days notice by email to the address on your account. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected Services and receive a pro rata refund of any prepaid fees for the unused term.

Each Sub-processor is bound by written terms that impose data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.

7. Data Subject Requests

The Services let you handle most requests yourself: you can view, export, and delete individual responses and their attached attributes from your dashboard at any time.

Where a Data Subject request cannot be resolved with those tools, we will provide reasonable assistance to help you meet your obligations under Articles 12 to 23 of the GDPR, taking into account the nature of the processing.

If a Data Subject contacts us directly about data we process on your behalf, we will not respond substantively unless you instruct us to. We will tell them to contact you, and forward the request to you promptly where we can identify the relevant account.

8. Personal Data Breaches

We will notify you without undue delay, and where feasible within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. Where we cannot provide all of that at once, we will provide it in phases as the information becomes available.

We will take reasonable steps to contain and remediate the breach, and will assist you with your own notification obligations under Articles 33 and 34 of the GDPR. Notifying you is not an acknowledgement of fault or liability.

9. Impact Assessments

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with any data protection impact assessment or prior consultation with a supervisory authority that you are required to carry out under Articles 35 and 36 of the GDPR.

10. Deletion and Return of Data

You can delete responses, surveys, and attached attributes at any time from your dashboard, and export your data in CSV format before you do.

On termination or expiry of your account, we will delete Customer Personal Data within 30 days, unless we are required to retain it by law. Backups are overwritten on a rolling cycle and any residual copies remain protected by this DPA until they are overwritten.

If you ask us in writing before the end of that period, we will return a copy of your Customer Personal Data in a commonly used machine-readable format first.

11. Audits and Information

We will make available the information reasonably necessary to demonstrate compliance with this DPA, including responding to reasonable security questionnaires and providing the certifications or reports available to us from our infrastructure providers.

Where that information is not sufficient, you may audit our compliance once in any 12 month period, on at least 30 days written notice, during business hours, and in a way that does not disrupt our operations or compromise the confidentiality of other customers' data. You bear the cost of the audit and any auditor you appoint must be bound by confidentiality obligations and must not be a competitor of ours. Additional audits may be carried out where required by a supervisory authority or following a confirmed Personal Data Breach.

12. International Transfers

We are established in New Zealand, which the European Commission recognizes as providing an adequate level of data protection. Our Sub-processors may store and process Customer Personal Data in other countries, including the United States.

Where a transfer of Customer Personal Data from the EEA, the United Kingdom, or Switzerland requires a transfer mechanism, the Standard Contractual Clauses are incorporated into this DPA by reference and apply as follows:

  • Module Two (controller to processor) applies, with you as data exporter and us as data importer.
  • Clause 7 (the docking clause) applies.
  • In Clause 9(a), Option 2 (general written authorization) applies, with the notice period set out in section 6 of this DPA.
  • The optional redress wording in Clause 11(a) does not apply.
  • In Clause 17, the Clauses are governed by the law of Ireland. In Clause 18(b), disputes will be resolved before the courts of Ireland.
  • Annex I.A is populated with the parties identified in this DPA, Annex I.B with section 3, Annex II with section 5, and Annex III with the Sub-processor list on our security page.
  • The competent supervisory authority in Annex I.C is the authority of the EEA member state in which you are established or, where you are not established in the EEA, in which your Article 27 representative is established.

For UK transfers, the International Data Transfer Addendum issued by the Information Commissioner's Office applies to the Standard Contractual Clauses. For Swiss transfers, the Clauses apply with the amendments set out by the Federal Data Protection and Information Commissioner, including references to the Swiss Federal Act on Data Protection and to the FDPIC as competent authority.

13. Your Obligations

You are responsible for:

  • Having a lawful basis for the personal data you collect through surveys and for the user attributes you attach to responses.
  • Providing the notices and obtaining any consents required from your Data Subjects, including disclosing your use of Mapster in your own privacy notice.
  • Deciding what questions to ask and what attributes to send, and not sending more personal data than you need.
  • Configuring and using the Services in line with Applicable Data Protection Law, and keeping your account credentials secure.

If it is useful, we publish a privacy policy template covering the survey-related disclosures.

14. Precedence, Liability, and Governing Law

If there is a conflict, the Standard Contractual Clauses take precedence over this DPA, and this DPA takes precedence over the Terms, in each case only in respect of the processing of Customer Personal Data.

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms, except where Applicable Data Protection Law does not permit that limitation.

This DPA is governed by the laws of New Zealand and subject to the courts of Auckland, New Zealand, except for the Standard Contractual Clauses, which are governed as set out in section 12.

15. Contact

For privacy questions, a countersigned copy of this DPA, or a completed security questionnaire, contact us at contact@mapster.io.

Galaxy Labs Limited, company number 9439298, New Zealand.