Data Processing Addendum

Last updated: 2 September 2026 · Effective: 2 September 2026 · ODD Media LLC

This Data Processing Addendum ("DPA") forms part of the MapsHarvest Terms of Service (the "Agreement") between ODD Media LLC, doing business as MapsHarvest ("MapsHarvest", "we") and the customer that has accepted the Agreement ("Customer", "you"). It applies automatically, without signature, whenever Data Protection Laws apply to personal data that we process on your behalf. If you need a countersigned copy for your records, email mapsharvest@omdgrowth.com and we will provide one.

1. Definitions

"Data Protection Laws" means all laws that apply to the processing of personal data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended ("CCPA") and other US state privacy laws, Canada's PIPEDA and Quebec's Act respecting the protection of personal information in the private sector, Australia's Privacy Act 1988, and India's Digital Personal Data Protection Act 2023, in each case as amended or replaced.

"Customer Personal Data" means personal data that you upload to, store in or generate through the Service and that we process on your behalf — for example delivered results kept in your account, CRM records, campaign data, notes and the personal data of your own users. It does not include (a) data about you and your users that we process as a controller for our own purposes, which is governed by our Privacy Policy, or (b) Business Listing Data before it is delivered to you (see Section 2.3).

"Sub-processor" means a third party we engage to process Customer Personal Data on your behalf.

"Controller", "processor", "data subject", "personal data", "processing", "personal data breach" and "supervisory authority" have the meanings given in the GDPR; "business", "service provider", "sell" and "share" have the meanings given in the CCPA. Terms used in this DPA for one law are read as their equivalents under other Data Protection Laws.

2. Roles

2.1 You are the controller (or business) of Customer Personal Data and we are your processor (or service provider). You are responsible for having a lawful basis to collect and use Customer Personal Data, for the accuracy of your instructions, and for the notices, consents and assessments your use requires.

2.2 Your instructions. We process Customer Personal Data only on your documented instructions. The Agreement, this DPA, your configuration of the Service (queries, geographies, fields, integrations, webhooks) and your use of its features are your complete instructions. We will tell you if we believe an instruction breaches Data Protection Laws, and we may suspend the instruction until it is resolved; we are not obliged to review your instructions for legality.

2.3 Business Listing Data — independent controllers. When our systems collect information from public Google Maps listings, we determine the means of collection, what fields exist and the safeguards that apply; for that collection we act as an independent controller, as described in our Privacy Policy and Business Listing Notice. Once results are delivered to your account you become an independent controller of your copy, and we hold that copy in your account as your processor under this DPA. We are not joint controllers with you; each party is responsible for its own compliance in relation to its own processing. We will forward to you any objection or deletion request that we receive from a listed business whose details were delivered to you in the previous 30 days, and you must action it as the Agreement requires.

3. Details of processing

  • Subject matter and duration: provision of the Service for the term of the Agreement and the 30-day export period after it ends.
  • Nature and purpose: hosting, storing, organising, exporting, transmitting (including through webhooks and integrations you configure), and deleting Customer Personal Data so that you can use the Service's features; and supporting and securing the Service.
  • Categories of data subjects: business contacts contained in results and CRM records (including sole traders, professionals and business owners); your users and staff who access the Service; individuals you add to the CRM or campaigns.
  • Categories of personal data: business contact and listing details (name, business name, role, address, phone number, website, ratings and listing attributes); CRM notes, statuses and tags you create; your users' names, emails and activity; identifiers and technical data generated by the Service.
  • Special categories: none are intended. You must not upload special-category data, criminal-offence data, government identifiers or payment card data to the Service.

4. Our obligations

4.1 Confidentiality. We ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations and receive appropriate training.

4.2 Security. We implement the technical and organisational measures described in Annex 2, and we may update them provided the overall level of protection is not reduced.

4.3 Assistance with data subject requests. If we receive a request from a data subject relating to Customer Personal Data, we will tell you without undue delay and will not respond except to acknowledge receipt and direct the person to you, unless the law requires otherwise. Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures — in practice, through the export, correction and deletion functions of the Service, and where those are insufficient, by reasonable manual assistance.

4.4 Assistance with compliance. We will provide reasonable assistance with your data protection impact assessments and prior consultations with supervisory authorities, and with your security, breach-notification and transfer obligations, to the extent they relate to our processing and the information is available to us. We may charge a reasonable fee for assistance that goes beyond what the Service and this DPA provide as standard.

4.5 Personal data breach. If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay and in any event within 48 hours of becoming aware, with the information available at the time (nature of the breach, categories and approximate numbers of data subjects and records, likely consequences, measures taken or proposed) and will supplement it as more becomes available. Our notification is not an admission of fault. We will cooperate with your investigation and remediation.

4.6 Deletion and return. You can export and delete Customer Personal Data at any time through the Service. When the Agreement ends, we keep your data available for export for 30 days and then delete it, unless we must retain it under applicable law, in which case we isolate it from further processing. Deleted result files are removed 30 days after the scrape completes regardless of the Agreement's term. Backups are overwritten in the ordinary course within 35 days.

4.7 Audits. We will make available the information reasonably necessary to demonstrate compliance with this DPA — including this DPA, our security documentation and any third-party reports or certifications we hold — on request no more than once a year (or additionally after a personal data breach or at a supervisory authority's request). Where that information is insufficient to meet a legal requirement, you may conduct, or appoint an independent auditor bound by confidentiality to conduct, an audit at your cost, on at least 30 days' notice, during business hours, without disrupting our operations, and subject to our reasonable security and confidentiality requirements. We will address confirmed material non-compliance promptly.

4.8 Records and cooperation. We maintain records of our processing activities as required by Article 30 GDPR and will cooperate with supervisory authorities as required by law.

5. Sub-processors

5.1 Authorisation. You give general authorisation for us to engage Sub-processors. Our current Sub-processors are listed in Annex 3, which we keep updated at mapsharvest.com/dpa.

5.2 Notice and objection. We will give you at least 30 days' notice before a new Sub-processor processes Customer Personal Data, by updating Annex 3 and emailing the account owner (or through a notification mechanism in the Service). If you have reasonable data-protection grounds to object, tell us in writing within the notice period; we will work with you in good faith to resolve the concern and, if we cannot, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees.

5.3 Flow-down and liability. We impose data-protection obligations on each Sub-processor that are at least as protective as those in this DPA, by written contract, and we remain liable for our Sub-processors' performance.

6. International transfers

6.1 We and our Sub-processors process Customer Personal Data in the United States, the United Kingdom and the European Union, as set out in Annex 3.

6.2 Where Customer Personal Data protected by the GDPR, the UK GDPR or Swiss law is transferred to a country without an adequacy decision, the parties rely on the following, in this order of precedence: (a) a valid adequacy decision (including the EU adequacy decision for the United Kingdom); (b) the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Data Privacy Framework, where the importer is certified; (c) the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914 ("SCCs"), Module Two (controller to processor), which are incorporated into this DPA by reference with the options in Annex 4, together with, for UK transfers, the UK International Data Transfer Addendum issued by the Information Commissioner, and for Swiss transfers the amendments required by the Swiss data protection authority. Where the SCCs apply, you are the data exporter and we are the data importer, and the Annexes to this DPA serve as the annexes to the SCCs.

6.3 If a transfer mechanism is invalidated or a supervisory authority requires a different one, the parties will cooperate in good faith to implement a replacement promptly.

7. United States state privacy laws

To the extent the CCPA or another US state privacy law applies to Customer Personal Data, we act as a service provider or processor and: (a) we will not sell or share Customer Personal Data; (b) we will not retain, use or disclose it for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship between us; (c) we will not combine it with personal data we receive from other sources except as permitted for service providers; (d) we will comply with the law's obligations and provide the same level of privacy protection it requires; (e) we will notify you if we can no longer meet these obligations, and you may take reasonable steps to stop and remediate unauthorised use; and (f) we certify that we understand and will comply with these restrictions.

8. Other jurisdictions

Where PIPEDA, Quebec's private-sector privacy law, Australia's Privacy Act or India's DPDP Act applies, we will process Customer Personal Data only for the purposes you instruct, protect it as this DPA requires, notify you of breaches as set out above, and provide the assistance you need to comply with your obligations to individuals and regulators. You are responsible for any assessment those laws require before you disclose personal data to us or transfer it outside your jurisdiction.

9. Liability, precedence and term

9.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, and the parties' aggregate liability under the Agreement and this DPA together is subject to a single cap. Nothing limits either party's liability to data subjects or supervisory authorities where Data Protection Laws do not permit it.

9.2 If this DPA conflicts with the Agreement, this DPA prevails on data-protection matters. If the SCCs conflict with this DPA, the SCCs prevail.

9.3 This DPA lasts as long as we process Customer Personal Data. It is governed by the law and dispute-resolution provisions of the Agreement, except where the SCCs require otherwise.


Annex 1 — Parties and description of transfer (for the SCCs)

Data exporter: the Customer, at the name, address and contact details in its MapsHarvest account. Role: controller. Activities: use of the MapsHarvest Service for business lead generation, market research and related purposes.

Data importer: ODD Media LLC (MapsHarvest), 30 N Gould St, Ste 4000, Sheridan, WY 82801, USA, mapsharvest@omdgrowth.com. Role: processor. Activities: provision of the Service as described in the Agreement.

Data subjects, categories of data, special categories, nature and purpose, duration: as set out in Section 3 of this DPA. Frequency: continuous, for the term of the Agreement. Retention: as set out in Section 4.6. Transfers to Sub-processors: as set out in Annex 3, for the purposes described there.

Competent supervisory authority: the authority of the EU member state in which the data exporter is established or, if it is not established in the EU, the authority of the member state in which its EU representative is established, or otherwise the member state whose data subjects are concerned. For UK transfers, the Information Commissioner's Office.

Annex 2 — Technical and organisational measures

  • Access control: unique accounts for all staff; multi-factor authentication on infrastructure, database, hosting, payment and email-provider consoles; least-privilege roles; access reviewed when roles change and revoked on departure. Two founders hold administrator access; no shared accounts.
  • Application security: row-level security on every database table so that customers can only read and write their own data; server-side enforcement of plan limits; API keys stored only as SHA-256 hashes and shown once; download links signed and time-limited; webhook destinations validated against internal and reserved address ranges; input validation and parameterised queries; regular dependency updates.
  • Encryption: TLS 1.2 or higher for all data in transit; encryption at rest for the database, file storage and backups provided by our infrastructure providers; passwords hashed with a modern algorithm by our authentication provider.
  • Infrastructure: hosting with providers that maintain independent security certifications (SOC 2 Type II and/or ISO 27001); the collection engine and the customer database run in separate environments; production configuration separated from development; secrets held in provider-managed secret stores, not in code.
  • Logging and monitoring: authentication, administrative and API activity logged with timestamps; an administrator audit log for privileged actions; alerting on deployment failures and abnormal error rates; logs retained as stated in the Privacy Policy.
  • Resilience: automated database backups from our database provider; deployment with health-check rollback; documented restore procedure.
  • Data minimisation and deletion: only the listing fields the customer's plan includes are collected and stored; result files deleted 30 days after completion; account data deleted 30 days after termination; deletion routines run automatically.
  • Incident response: a documented procedure for detecting, assessing, containing and notifying incidents, with customer notification within 48 hours of awareness of a breach affecting Customer Personal Data.
  • Sub-processor management: due diligence before engagement, written data-processing terms, transfer safeguards, and periodic review of certifications.
  • Personnel: confidentiality obligations for everyone with access; data-protection and security awareness as part of onboarding.

Annex 3 — Sub-processors

Sub-processorPurposeLocationTransfer mechanism
Supabase, Inc.Authentication, database, file storageEuropean Union (Ireland)n/a (EU data); UK Addendum for UK transfers
Vercel Inc.Application hosting and content deliveryUnited States (global edge)Data Privacy Framework; SCCs
Hostinger International Ltd.Collection-engine and API serversUnited KingdomUK adequacy (from EU); n/a (UK data)
Stripe, Inc.Payment processing and billing (processes customer-account data, not result data)United States / EUData Privacy Framework; SCCs
Resend, Inc.Transactional email delivery (processes account holders' email addresses)United StatesSCCs

Google LLC, Meta Platforms and Microsoft Corporation (Clarity) provide analytics and advertising services in relation to our website visitors and account holders as described in our Privacy Policy; they do not process Customer Personal Data held in results or CRM records.

Annex 4 — SCC options

Clause 7 (docking): included. Clause 9(a): Option 2 (general written authorisation) with a 30-day notice period. Clause 11(a): the independent dispute-resolution option is not selected. Clause 13: the supervisory authority is as identified in Annex 1. Clause 17: the SCCs are governed by the law of Ireland. Clause 18: disputes are resolved by the courts of Ireland. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum (version B1.0) applies with Tables 1–3 completed by reference to this DPA and Table 4 allowing either party to end the Addendum as set out in section 19 of the Addendum. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss FADP, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and data subjects in Switzerland may enforce their rights in Switzerland.