The Salsita SDK Data Processing Addendum: how Salsita processes personal data on your behalf when you use the SDK, Salsita Studio and the Salsita platform.
1.1 This Data Processing Addendum ("DPA") forms part of the Salsita SDK Terms, or any other agreement between the customer ("Customer") and Salsita s.r.o., Štefánikova 18/25, 150 00 Prague 5, Czech Republic, Company ID 272 04 201 ("Salsita"), that references it (the "Agreement"). It is incorporated into the Agreement and needs no separate signature.
1.2 This DPA applies where Salsita processes Customer Personal Data on Customer's behalf in providing the SDK, Salsita Studio and the Salsita platform (together, the "Services").
1.3 If this DPA conflicts with the Agreement, this DPA prevails for the processing of Customer Personal Data. If it conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
1.4 Salsita may update this DPA by publishing a new version at this address. An update will not reduce the overall protection of Customer Personal Data. Material changes take effect 30 days after notice to Customer.
Terms such as "controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in the GDPR.
3.1 For Customer Personal Data, Customer is the controller (or a processor acting for its own customers) and Salsita is the processor (or sub-processor).
3.2 Salsita is a controller, not a processor, for personal data it collects for its own purposes: account holders' details, billing and support contacts, and usage information about the SDK and Studio. Salsita's Privacy Policy at https://salsita.ai/privacy-policy covers that data. This DPA does not.
3.3 Salsita may use technical data generated by the Services (such as logs, error reports and IP addresses) to operate, secure, debug and maintain the Services. For that limited purpose Salsita acts as an independent controller. It will not use the data for marketing or profiling, and it keeps the data no longer than set out in Annex 1.
3.4 Customer is responsible for having a lawful basis for the processing, for informing its Users, and for obtaining any consent that applies to cookies or similar technologies the SDK uses in Customer's application. Salsita documents those technologies in its developer documentation.
4.1 Salsita processes Customer Personal Data only on Customer's documented instructions, unless EU or Member State law requires otherwise. In that case Salsita will inform Customer first, unless the law prohibits it.
4.2 The Agreement, this DPA and Customer's configuration and use of the Services are Customer's complete instructions. Additional instructions must be in writing and consistent with the Agreement.
4.3 Salsita will tell Customer promptly if it believes an instruction infringes Data Protection Laws. It may suspend that processing until the instruction is confirmed or changed.
4.4 Salsita ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality obligations.
5.1 Salsita implements the technical and organisational measures in Annex 2 to protect Customer Personal Data, as required by Article 32 GDPR.
5.2 Salsita may update those measures as technology and risks change, provided the overall level of protection does not decrease.
5.3 Customer is responsible for the security of its own systems, accounts and API keys, and for configuring the Services appropriately for the data it processes.
6.1 Customer gives Salsita general authorisation to engage Sub-processors. The current list is in Annex 3 of this DPA, which Salsita keeps up to date at https://salsita.ai/dpa.
6.2 Salsita will give at least 30 days' notice before adding or replacing a Sub-processor, by updating Annex 3 and notifying the account owner by email.
6.3 Customer may object on reasonable data protection grounds within that notice period. The parties will discuss the objection in good faith. If it cannot be resolved, Customer may terminate the affected Services, and Salsita will refund any prepaid fees for the unused period.
6.4 Salsita imposes data protection obligations on each Sub-processor that are no less protective than this DPA, and remains liable to Customer for each Sub-processor's performance.
7.1 Salsita is established in the EU. Customer's applications are hosted in the United States, or in the EU (Germany) where agreed with Customer. Customer Personal Data may also be processed in the United States and other countries where Salsita or its Sub-processors operate, as shown in Annex 3.
7.2 Where Customer Personal Data is transferred outside the EEA, the UK or Switzerland to a country without an adequacy decision, Salsita ensures a valid transfer mechanism is in place. In order of preference:
7.3 If a transfer mechanism is invalidated, Salsita will rely on an alternative valid mechanism or suspend the affected transfer.
7.4 Where Customer is established outside the EEA and receives Customer Personal Data back from Salsita, the parties agree that Module 4 (processor to controller) of the Standard Contractual Clauses applies to the extent required.
8.1 Data subject requests. Salsita will, taking into account the nature of the processing, help Customer respond to requests from data subjects to exercise their rights. If Salsita receives such a request directly, it will forward it to Customer without undue delay and will not respond itself except to direct the data subject to Customer.
8.2 Other assistance. Salsita will give Customer reasonable help with data protection impact assessments and prior consultations with supervisory authorities, to the extent they relate to the Services and the information is available to Salsita.
8.3 Personal data breaches. Salsita will notify Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include, as far as known: the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed. Salsita will provide further information as it becomes available and will take reasonable steps to contain the breach.
8.4 Notifying a breach is not an admission of fault or liability.
9.1 Salsita will make available to Customer, on written request, the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR. This may include completed security questionnaires, summaries of its security measures and Sub-processors' certifications or audit reports.
9.2 If that information is not sufficient, or a supervisory authority requires it, Customer may audit Salsita's compliance, itself or through an independent auditor bound by confidentiality, on at least 30 days' notice. Audits are limited to once in any 12 months, take place during business hours, and must not unreasonably disrupt Salsita's operations. Customer bears its own costs and Salsita's reasonable costs of the audit.
10.1 Deletion and return. When the Services end, Salsita will delete Customer Personal Data within 90 days, unless EU or Member State law requires it to be kept. Before the end of the Services Customer can export its data using the Services' standard features. Backups are overwritten in the normal backup cycle and remain protected under this DPA until then.
10.2 Liability. Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Data Protection Laws or the Standard Contractual Clauses do not allow them to apply.
10.3 Term. This DPA applies for as long as Salsita processes Customer Personal Data, and ends automatically once all Customer Personal Data has been deleted or returned.
10.4 Governing law. This DPA is governed by the law that governs the Agreement, except where the Standard Contractual Clauses require otherwise.
_dd_s, for browser logging. It holds a random session identifier and timestamps, and expires after 15 minutes of inactivity and at most 4 hours. They also store a random visitor identifier (user_id) and configurator access and session tokens in the browser's local storage; the tokens are needed for the application to work.Salsita's own use of Datadog and Clerk for Studio accounts falls under the Privacy Policy, not this list.
More legal