Data Processing Addendum (DPA)
Last Updated: September 1, 2025
This Data Processing Addendum (“DPA”) forms part of the Agreement between On2Air.com (as the “Processor”) and the customer signatory to the Agreement (as the “Controller”).
If your organization requires a countersigned copy for your records, email support@on2air.com and we will complete one for you.
1. Definitions
Section titled “1. Definitions”1.1. “Agreement” means the terms and conditions or other agreement governing the use of On2Air.com services.
1.2. “Data Protection Laws” means all laws and regulations, including laws and regulations of the European Union, the European Economic Area (“EEA”) and their member states, Switzerland and the United Kingdom, applicable to the Processing of Personal Data under the Agreement.
1.3. “GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation).
1.4. “Personal Data” means any information relating to an identified or identifiable natural person.
1.5. “Processing” means any operation or set of operations performed on Personal Data.
2. Processing of Personal Data
Section titled “2. Processing of Personal Data”2.1. Instructions: The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by Union or Member State law to which the Processor is subject.
2.2. Roles: The parties acknowledge and agree that with regard to the Processing of Personal Data, Controller is the data controller and Processor is the data processor.
2.3. Details of Processing: The duration, nature, and purpose of the processing, as well as the types of Personal Data and categories of Data Subjects, are set out in Annex I to this DPA.
3. Personnel
Section titled “3. Personnel”3.1. Confidentiality: The Processor shall ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4. Security
Section titled “4. Security”4.1. Security Measures: The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including the measures listed in Annex II.
4.2. Assistance: Taking into account the nature of processing and the information available to the Processor, the Processor shall assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR.
5. Sub-processing
Section titled “5. Sub-processing”5.1. Authorization: The Controller provides a general authorization to the Processor to engage sub-processors. The current list of sub-processors is available in Annex III.
5.2. Obligations: The Processor shall impose the same data protection obligations on any sub-processor as those set out in this DPA.
6. Data Subject Rights
Section titled “6. Data Subject Rights”6.1. Assistance: The Processor shall, insofar as this is possible, assist the Controller by appropriate technical and organizational measures for the fulfillment of the Controller’s obligation to respond to requests for exercising the data subject’s rights.
7. Personal Data Breach
Section titled “7. Personal Data Breach”7.1. Notification: The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data breach.
8. Deletion or Return of Personal Data
Section titled “8. Deletion or Return of Personal Data”8.1. Termination: Upon termination of the Agreement, the Processor shall, at the choice of the Controller, delete or return all the Personal Data to the Controller and delete existing copies unless Union or Member State law requires storage of the Personal Data.
8.2. Cloud Storage Clarification: For services involving the backup or sync of data to Controller-owned cloud storage accounts (e.g., Google Drive, Box, Dropbox, OneDrive), the Processor will remove Personal Data from its own servers and systems. However, any data already transferred to and stored within the Controller’s cloud storage account remains the responsibility of the Controller. Upon deletion of the Controller’s account data from the Processor’s systems, the Processor will no longer have access to the Controller’s cloud storage accounts.
9. Audit Rights
Section titled “9. Audit Rights”9.1. Compliance: The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
Annex I: Details of Processing
Section titled “Annex I: Details of Processing”1. Subject Matter and Duration:
The subject matter and duration of the processing of Personal Data are set out in the Agreement.
2. Nature and Purpose:
The nature and purpose of the processing is the provision of the On2Air.com services as defined in the Agreement.
3. Categories of Data Subjects:
The Personal Data transferred concern the following categories of data subjects:
- On2Air Customers
4. Types of Personal Data:
The Personal Data transferred concern the following categories of data:
- Contact details, account info, and data synced from Airtable
Annex II: Technical and Organizational Measures (TOMs)
Section titled “Annex II: Technical and Organizational Measures (TOMs)”The Processor has implemented the following measures (see our full Technical and Organizational Measures for more detail):
- Pseudonymization and encryption of personal data.
- Confidentiality, integrity, availability, and resilience of processing systems.
- Availability and access to personal data in a timely manner in the event of a physical or technical incident.
- Regular testing and evaluation of the effectiveness of security measures.
Annex III: List of Sub-processors
Section titled “Annex III: List of Sub-processors”The Processor uses the following sub-processors:
| Name | Purpose | Location |
|---|---|---|
| Cloudflare | Content Delivery & Security | Global |
| DigitalOcean | Cloud Hosting & Infrastructure | USA |
| Stripe | Payment Processing | USA |
| ProfitWell | Billing Analytics & Payment Recovery (receives data from Stripe) | USA |
| Mailgun | Transactional Email Services | USA |
| Mezmo (Logging) | Log Management & Monitoring | USA |
| Crisp | Customer Support Chat | France / EU |
| Rewardful | Affiliate Referral Tracking | USA |
This annex lists sub-processors that process Personal Data on our behalf. Advertising and marketing technologies used on our public website, such as the Meta (Facebook) Pixel, are not sub-processors of Customer Content and are disclosed in our Privacy Policy instead.
See also: Data Security · Technical and Organizational Measures · Privacy Policy · Terms of Use