Data Processing Addendum
EconomicsAPI · Effective September 4, 2026
Data Processing Agreement (Global)
Effective as of September 4, 2026
This Data Processing Agreement ("DPA") applies where EconomicsAPI ("Processor") processes personal data on behalf of a customer ("Controller") through our API and console (the "Service"). It incorporates these terms into the Terms of Use between the parties and, for EEA/UK transfers, incorporates the EU Standard Contractual Clauses (Module Two: Controller-to-Processor) and the UK International Data Transfer Addendum, which the parties execute by executing this DPA through use of the Service.
1. Roles; scope of processing
Subject matter: processing of data submitted by Controller via the API. Duration: for the term of the Controller's account. Nature and purpose: collection, storage, transmission, and processing of submitted data to produce the Service's output and usage records. Categories of data subjects: end users whose data Controller submits (e.g., email addresses, IP addresses, device signals). Categories of personal data: as submitted by Controller, which may include identifiers, online identifiers, and device/network data. Special categories: none. Controller must not submit special-category personal data (Art. 9 GDPR) or government ID numbers via the API.
2. Processor obligations
Processor will:
- process personal data only on documented instructions from Controller (these Terms plus the Service configuration constitute such instructions) unless required by law, in which case Processor will notify Controller before complying unless legally prohibited;
- ensure persons authorized to process personal data are bound by confidentiality obligations;
- implement and maintain appropriate technical and organizational measures, including: encryption in transit (TLS 1.2+) and at rest; access controls with least privilege; audit logging of administrative access; and internal security-review procedures;
- obtain prior written authorization before engaging subprocessors, and maintain a current list of subprocessors (hosting, email delivery, payment processing, analytics) available on request. Processor will give Controller 30 days' prior notice of new subprocessors, during which Controller may object on reasonable data-protection grounds; if unresolved, Controller may terminate the affected Service;
- assist Controller, taking into account the nature of processing, in responding to data-subject requests (access, deletion, portability) to the extent Controller cannot fulfill them independently through the Service;
- notify Controller without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting Controller's data, and provide information reasonably required for Controller's regulatory notifications;
- delete or return personal data at Controller's choice upon termination of the account, unless retention is required by law (API logs are deleted or anonymized within 90 days after termination);
- make available information reasonably necessary to demonstrate compliance and allow for audits: once per year, on 30 days' notice, Controller may review Processor's compliance documentation (e.g., security summaries, audit reports); on-site audits only where such documentation is insufficient under applicable law.
3. Transfers
Personal data originating in the EEA, UK, or Switzerland may be transferred to France. Transfers rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), the UK IDTA/Addendum, and the Swiss adaptations, as applicable, with Processor as data importer. The clauses' liability caps do not apply to data-subject claims.
4. General terms
In case of conflict between this DPA and the Terms of Use, this DPA controls for processing of Controller's personal data. This DPA is governed by the same law as the Terms of Use, without prejudice to data-subject rights under the Standard Contractual Clauses.
Contact
Privacy inquiries and subprocessor lists: hello@economicsapi.com.