1Scope and parties
This data processing addendum ("DPA") forms part of the agreement between Switas Tech Inc., 490 Post Street, Ste 500 PMB 2288, San Francisco, CA 94102, USA ("Spidot", "Processor", "we"), and the business customer or partner ("Customer", "you") under our Business terms or our Partner and reseller agreement (the "Agreement"). It applies where Spidot processes Customer Personal Data on the Customer's behalf in providing the services under the Agreement (the "Services").
It does not apply to personal data that Spidot processes as a controller, such as data of consumers who buy directly on spidot.com, or the Customer's account and billing contacts. That data is covered by our Privacy policy.
If this DPA conflicts with the Agreement, this DPA prevails for data protection matters. If it conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
2Definitions
- Data Protection Laws: all laws on personal data that apply to the processing under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act as amended ("CCPA").
- Customer Personal Data: personal data that Spidot processes on the Customer's behalf under the Agreement.
- Controller, processor, data subject, personal data, processing, personal data breach and supervisory authority have the meanings given in the GDPR. "Service provider" and "business" have the meanings given in the CCPA.
- Standard Contractual Clauses (SCCs): the clauses adopted by European Commission Implementing Decision (EU) 2021/914.
- UK Addendum: the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
- Sub-processor: any processor engaged by Spidot to process Customer Personal Data.
3Details of the processing
| Item | Description |
|---|---|
| Subject matter and purpose | Issuing travel eSIMs to the Customer's travellers or customers, delivering QR codes and activation details by email, providing support, and reporting eSIM status and data usage to the Customer |
| Nature of processing | Collection, storage, use, transmission by email, retrieval, reporting and deletion |
| Duration | For the term of the Agreement and until deletion under section 11 |
| Data subjects | The Customer's employees, contractors, customers and other travellers who receive eSIMs ("Travellers"); the Customer's staff who manage orders |
| Categories of personal data | Name, email address, eSIM identifiers (ICCID), order references, destination and plan, data usage and line status, support communications |
| Special categories | None. The Customer must not send special categories of data |
| Frequency | Continuous, for each order |
4Roles and instructions
The Customer is the controller (or, where it acts for another controller, a processor) and Spidot is the processor of Customer Personal Data. The Customer is responsible for the lawfulness of the processing, for giving Travellers the information required by Data Protection Laws, and for having a lawful basis to share Customer Personal Data with Spidot.
Spidot will process Customer Personal Data only on the Customer's documented instructions, which are set out in the Agreement, this DPA and the Customer's use of the Services, unless the law requires otherwise; in that case Spidot will inform the Customer before processing unless the law prohibits it. Spidot will tell the Customer if it believes an instruction breaks Data Protection Laws.
5Our obligations
Spidot will:
- make sure that people authorised to process Customer Personal Data are bound by confidentiality;
- implement the technical and organisational measures in section 8;
- taking into account the nature of the processing, help the Customer respond to requests from data subjects to exercise their rights, and promptly forward any such request it receives directly, without responding except to direct the data subject to the Customer;
- provide reasonable help with data protection impact assessments and consultations with supervisory authorities relating to the Services;
- make available the information reasonably needed to demonstrate compliance with this DPA, as described in section 10.
6Sub-processors
The Customer gives Spidot general authorisation to engage sub-processors. Spidot will put in place a written contract with each sub-processor that imposes data protection obligations no less protective than this DPA, and remains responsible to the Customer for its sub-processors' performance. The current sub-processors are:
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Website and application hosting | USA (global edge network) |
| Hostinger | Database hosting | Germany (EU) |
| MailerSend | Sending transactional emails (eSIM delivery, receipts) | EU and USA |
| Stripe, Inc. and affiliates | Payment processing for orders paid by card | USA and other countries |
| Google LLC | Sign in with Google for the Customer's users | USA |
| Wholesale eSIM supplier (name available to the Customer on request) | Issuing and managing eSIM lines. Receives only line identifiers (ICCID) and order reference notes, not names or email addresses | Outside the EEA |
Spidot will give the Customer at least 30 days' notice of a new or replacement sub-processor by updating this page and, where the Customer has asked to be notified, by email. The Customer may object on reasonable data protection grounds within that period by writing to support@spidot.com. The parties will discuss the objection in good faith; if they cannot resolve it, the Customer may end the affected Services and receive a refund of prepaid fees for eSIMs not yet delivered.
7International transfers
Switas Tech Inc. is established in the United States. To the extent Customer Personal Data subject to the GDPR is transferred to Spidot or onward to a sub-processor in a country without an adequacy decision, the parties agree that the SCCs are incorporated into this DPA by reference, as follows:
- Module 2 (controller to processor) applies where the Customer is a controller, and Module 3 (processor to processor) where the Customer is a processor.
- Clause 7 (docking clause) applies. In Clause 9, option 2 (general authorisation) applies with the notice period in section 6. The optional wording in Clause 11 does not apply.
- In Clauses 17 and 18, the law and courts of Ireland apply.
- Annex I is completed by section 3 of this DPA (with the Customer as data exporter and Spidot as data importer, and the competent supervisory authority determined under Clause 13), Annex II by section 8, and Annex III by the list in section 6.
For transfers subject to the UK GDPR, the UK Addendum applies, with Tables 1 to 3 completed by the information in this DPA and either party able to end it as allowed in Table 4. For transfers subject to Swiss law, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection and the Swiss Federal Data Protection and Information Commissioner as a competent authority. If Spidot or a sub-processor is certified under the EU-US Data Privacy Framework or its extensions, the parties may rely on that certification instead.
8Security measures
Spidot maintains at least the following technical and organisational measures (Annex II to the SCCs):
- Encryption: all traffic to the Services uses TLS (HTTPS). Data is encrypted at rest by our hosting and database providers. Secrets and API keys are kept in environment variables, never in source code.
- Access control: access to production systems and data is limited to authorised personnel on a need-to-know basis, protected by strong authentication. The administration panel is access-controlled.
- Payment data: card data is handled only by Stripe (PCI DSS Level 1). Spidot does not store full card numbers.
- Data minimisation: our wholesale eSIM supplier receives no Traveller names or email addresses. Order pages are reached through unguessable links.
- Availability and resilience: managed hosting with automated backups of the database; monitoring of order delivery with automatic retries and alerts.
- Software security: dependencies are kept up to date; changes are reviewed before release; signed webhooks are verified.
- Personnel: staff and contractors with access are bound by confidentiality and trained on data protection.
- Incident management: a documented process for detecting, investigating and notifying personal data breaches.
- Sub-processor management: sub-processors are assessed and bound by written data protection terms.
Spidot may update these measures, provided it does not reduce the overall level of protection.
9Personal data breaches
Spidot will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Spidot will provide further information as it becomes available, take reasonable steps to contain the breach, and help the Customer meet its own notification obligations. A notice is not an admission of fault.
10Information and audits
On request, Spidot will provide written answers to reasonable security questionnaires and any available third-party certifications or reports of its sub-processors. If that is not enough to demonstrate compliance, or a supervisory authority requires it, the Customer may carry out an audit, not more than once a year, with at least 30 days' notice, during business hours, at its own cost, and through an auditor bound by confidentiality, in a way that does not unreasonably disrupt Spidot's business or compromise the data of other customers.
11Return and deletion
When the Services end, Spidot will, at the Customer's choice, return Customer Personal Data or delete it within 30 days, unless the law requires Spidot to keep it (for example, order records kept for tax purposes), in which case Spidot will keep it confidential and process it only for that purpose. Data in backups is deleted in the normal backup cycle.
12US state privacy laws
Where the CCPA or similar US state laws apply, Spidot acts as the Customer's service provider or processor and will not: sell or share Customer Personal Data; retain, use or disclose it for any purpose other than providing the Services, or outside the direct business relationship with the Customer; or combine it with personal data it receives from others, except as those laws allow. Spidot will comply with those laws, provide the same level of protection they require, and notify the Customer if it can no longer meet its obligations. The Customer may take reasonable steps to stop and remediate unauthorised use. Spidot certifies that it understands and will comply with these restrictions.
13Liability and term
Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Data Protection Laws or the SCCs do not allow this. This DPA lasts as long as Spidot processes Customer Personal Data under the Agreement. Spidot may update this DPA to reflect changes in law or its Services, provided the changes do not reduce the protection of Customer Personal Data; material changes will be notified at least 30 days in advance.
A countersigned copy of this DPA is available on request at support@spidot.com.
14Contact us
For data protection questions, breach reports and sub-processor notices, contact us. We have not appointed a data protection officer.
- Email: support@spidot.com
- Post: Switas Tech Inc., 490 Post Street, Ste 500 PMB 2288, San Francisco, CA 94102, USA
- Contact form: spidot.com/legal/contact
Questions about this page?Contact us