Data Processing Agreement
Effective Date: September 22, 2026
Company Name: Aomark Digital LLC
Company Address: 75 E 3rd St, Sheridan, WY 82801, United States
Website: https://aomarkdigital.com/
Email: contact@aomarkdigital.com
On this page
- 1. Introduction and Scope
- 2. Definitions
- 3. Roles of the Parties
- 4. Customer Obligations
- 5. Processing Instructions
- 6. Confidentiality of Personnel
- 7. Security of Processing
- 8. Subprocessors
- 9. Data Subject Rights
- 10. Personal Data Breaches
- 11. Data Protection Impact Assessments and Prior Consultation
- 12. International Data Transfers
- 13. Audits and Information
- 14. Return and Deletion of Customer Personal Data
- 15. U.S. State Privacy Law Terms
- 16. Canada
- 17. Liability
- 18. Term and Termination
- 19. Order of Precedence
- 20. Governing Law and Dispute Resolution
- 21. Changes to This DPA
- 22. Contact
- Annex I: Details of Processing
- Annex II: Technical and Organizational Security Measures
- Annex III: Subprocessors
1. Introduction and Scope
This Data Processing Agreement (“DPA”) forms part of the agreement between Aomark Digital LLC, a Wyoming limited liability company (“Aomark Digital,” “Processor,” “we,” “us,” or “our”), and the client that has accepted our Terms of Service and/or Platform Terms of Use or entered into an Engagement Document with us (“Customer,” “you,” or “your”). In this DPA, those documents are together referred to as the “Agreement.”
This DPA applies whenever Aomark Digital processes Customer Personal Data on behalf of the Customer in the course of providing the Services or the Platforms. It reflects the parties’ agreement on the processing of Customer Personal Data in accordance with Applicable Data Protection Laws, including Article 28 of the GDPR and the UK GDPR, the CCPA and other U.S. state consumer privacy laws.
This DPA does not apply to personal data that Aomark Digital processes as an independent controller, such as the contact details of the Customer’s representatives, account and billing data, and data about visitors to our Websites. That processing is described in our Privacy Policy.
1.1 Acceptance
This DPA is incorporated into and becomes binding as part of the Agreement when the Customer accepts our Terms of Service or Platform Terms of Use, or enters into an Engagement Document. No separate signature is required. If the Customer requires a countersigned copy of this DPA for its records, it may request one by emailing contact@aomarkdigital.com. The person accepting the Agreement on behalf of the Customer represents that they are authorized to bind the Customer to this DPA.
2. Definitions
Capitalized terms not defined in this DPA have the meanings given in the Agreement. In this DPA:
- “Applicable Data Protection Laws” means all laws and regulations relating to data protection and privacy that apply to the processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, the UK GDPR, the Swiss FADP, the CCPA, other U.S. state consumer privacy laws and PIPEDA.
- “GDPR” means Regulation (EU) 2016/679 (General Data Protection Regulation).
- “UK GDPR” means the GDPR as retained in the law of the United Kingdom, together with the UK Data Protection Act 2018.
- “Swiss FADP” means the Swiss Federal Act on Data Protection and its implementing ordinances.
- “CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations.
- “PIPEDA” means Canada’s Personal Information Protection and Electronic Documents Act.
- “Customer Personal Data” means any personal data or personal information that Aomark Digital processes on behalf of the Customer in providing the Services or the Platforms, as further described in Annex I.
- “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR, and the equivalent terms under other Applicable Data Protection Laws (such as “business,” “service provider,” “contractor” and “consumer” under the CCPA) are to be read accordingly.
- “Subprocessor” means any third party engaged by Aomark Digital that processes Customer Personal Data on behalf of the Customer.
- “Restricted Transfer” means a transfer of Customer Personal Data from the European Economic Area (“EEA”), the United Kingdom or Switzerland to a country that has not been recognized as providing an adequate level of data protection under the Applicable Data Protection Laws of the exporting jurisdiction.
- “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries approved by European Commission Implementing Decision (EU) 2021/914.
- “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018.
3. Roles of the Parties
With respect to Customer Personal Data, the Customer is the Controller (or a “business” under the CCPA) and Aomark Digital is the Processor (or a “service provider” or “contractor” under the CCPA). Where the Customer is itself acting as a processor on behalf of a third-party controller, such as its own client, Aomark Digital acts as a Subprocessor, and the Customer is responsible for ensuring that the third-party controller has authorized the processing described in this DPA and that the Customer’s instructions are consistent with its obligations to that controller.
4. Customer Obligations
The Customer is responsible for its compliance with Applicable Data Protection Laws as a Controller. In particular, the Customer represents, warrants and undertakes that:
- it has a valid legal basis under Applicable Data Protection Laws for the processing of Customer Personal Data and for disclosing it to Aomark Digital;
- it has provided all notices to Data Subjects and obtained all consents that are required by Applicable Data Protection Laws, including for email marketing, tracking technologies and the transfer of Customer Personal Data to Aomark Digital and its Subprocessors;
- Customer Personal Data has been collected lawfully and is accurate and up to date, and email contact lists provided to Aomark Digital have not been purchased, rented, scraped or harvested;
- its instructions to Aomark Digital comply with Applicable Data Protection Laws and will not cause Aomark Digital to breach them;
- it will not provide special categories of personal data, data relating to criminal convictions and offenses, or sensitive personal information to Aomark Digital, unless this is strictly necessary for the Services and Aomark Digital has agreed to it in writing in advance; and
- it will grant Aomark Digital access to Customer Personal Data only to the extent necessary for the Services, preferably through role-based user accounts with limited permissions, and will revoke that access when it is no longer needed.
5. Processing Instructions
Aomark Digital will process Customer Personal Data only on the documented instructions of the Customer, including with regard to transfers to a third country, unless required to do so by applicable law. In that case, Aomark Digital will inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
The Customer’s documented instructions at the date of this DPA are: (a) to process Customer Personal Data in accordance with the Agreement and this DPA; (b) to process it as necessary to perform the Services described in the applicable Engagement Documents and to provide the Platforms; and (c) to comply with other reasonable written instructions provided by the Customer, including by email, that are consistent with the Agreement. Additional instructions that are outside the scope of the Agreement require prior written agreement and may be subject to additional fees.
Aomark Digital will promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws. In that case, Aomark Digital may suspend the processing concerned until the Customer confirms or modifies the instruction, and Aomark Digital will not be liable for any delay in performing the Services resulting from such suspension.
6. Confidentiality of Personnel
Aomark Digital will ensure that all personnel and contractors authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality, whether contractual or statutory, are informed of the confidential nature of Customer Personal Data, and have access only to the Customer Personal Data they need to perform their duties.
7. Security of Processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of individuals, Aomark Digital will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. These measures are described in Annex II. Aomark Digital may update these measures from time to time, provided that the updates do not materially reduce the overall level of protection of Customer Personal Data.
The Customer is responsible for the security of its own systems, accounts, credentials and devices, and for configuring the Platforms and any third-party systems that it controls in a secure manner. Where Aomark Digital performs Services within systems owned or controlled by the Customer, such as the Customer’s website, content management system, customer relationship management system, email service provider, analytics or advertising accounts, the security of those systems is governed by the Customer and its providers, and Aomark Digital’s obligation is to use the access granted in accordance with this DPA.
8. Subprocessors
8.1 General Authorization
The Customer gives Aomark Digital a general authorization to engage Subprocessors to process Customer Personal Data. The categories of Subprocessors used by Aomark Digital are set out in Annex III. A current list of Subprocessors, including their names, locations and the processing activities they perform, is available on request by email to contact@aomarkdigital.com.
8.2 Subprocessor Obligations
Aomark Digital will: (a) enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective of Customer Personal Data than those in this DPA, to the extent applicable to the nature of the services provided by the Subprocessor; (b) carry out reasonable due diligence on each Subprocessor before engaging it; and (c) remain responsible to the Customer for the performance of each Subprocessor’s obligations in accordance with the Agreement.
8.3 New Subprocessors and Right to Object
Aomark Digital will notify the Customer by email at least 14 days before a new Subprocessor begins processing Customer Personal Data. The Customer may object to a new Subprocessor on reasonable data protection grounds by notifying Aomark Digital in writing within that period. If the Customer objects, the parties will discuss the concern in good faith. Aomark Digital may, at its option, offer a reasonable alternative, such as not using the new Subprocessor for the Customer’s Customer Personal Data. If no reasonable solution is found within 30 days after the objection, the Customer may terminate the affected Services by written notice and will receive a pro-rated refund of any prepaid fees for the terminated Services covering the period after termination. In an emergency, for example where a Subprocessor must be replaced urgently for security or continuity reasons, Aomark Digital may replace the Subprocessor immediately and will notify the Customer as soon as possible, and the Customer will retain the right to object as described in this Section.
9. Data Subject Rights
Taking into account the nature of the processing, Aomark Digital will assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws, such as access, rectification, erasure, restriction, portability, objection and opt-out requests.
If Aomark Digital receives a request directly from a Data Subject relating to Customer Personal Data, it will promptly forward the request to the Customer, where it can identify the Customer, and will not respond to the request itself except to confirm that it has been forwarded, unless the Customer instructs it to do so or it is required by law. The Customer is responsible for responding to Data Subject requests. Where assistance requires significant effort beyond the normal functionality of the Services and Platforms, Aomark Digital may charge a reasonable fee, agreed in advance.
10. Personal Data Breaches
Aomark Digital will notify the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will be sent to the email address associated with the Customer’s engagement or Account and will, to the extent then known, describe:
- the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and records concerned;
- the name and contact details of the person at Aomark Digital from whom more information can be obtained;
- the likely consequences of the Personal Data Breach; and
- the measures taken or proposed to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
Where it is not possible to provide all information at the same time, it may be provided in phases without undue further delay. Aomark Digital will take reasonable steps to contain, investigate and remedy the Personal Data Breach and will provide reasonable assistance to the Customer in meeting its obligations to notify Supervisory Authorities and affected Data Subjects. The Customer is responsible for deciding whether to notify, and for making notifications to, Supervisory Authorities and Data Subjects. Notification of or response to a Personal Data Breach by Aomark Digital is not an acknowledgment of fault or liability.
Unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as pings, port scans, failed login attempts or denial-of-service attacks that do not result in access to Customer Personal Data, are not Personal Data Breaches for the purposes of this Section.
11. Data Protection Impact Assessments and Prior Consultation
Taking into account the nature of the processing and the information available to it, Aomark Digital will provide reasonable assistance to the Customer, where required by Applicable Data Protection Laws, in carrying out data protection impact assessments and prior consultations with Supervisory Authorities that relate to the processing of Customer Personal Data by Aomark Digital. Aomark Digital may charge a reasonable fee, agreed in advance, for assistance that goes beyond providing the information in this DPA and its Annexes.
12. International Data Transfers
12.1 Location of Processing
Aomark Digital is established in the United States. The Customer acknowledges that Customer Personal Data will be processed in the United States and may be processed in other countries where Aomark Digital, its personnel or its Subprocessors are located, in accordance with this DPA.
12.2 Transfers from the EEA
To the extent that the provision of the Services or Platforms involves a Restricted Transfer from the EEA to Aomark Digital, the Standard Contractual Clauses are incorporated into this DPA by reference and apply as follows:
- Module Two (Controller to Processor) applies where the Customer is a Controller, and Module Three (Processor to Processor) applies where the Customer is a Processor;
- the Customer is the “data exporter” and Aomark Digital is the “data importer”;
- in Clause 7, the optional docking clause does not apply;
- in Clause 9, Option 2 (general written authorization) applies, and the time period for prior notice of Subprocessor changes is set out in Section 8.3 of this DPA;
- in Clause 11, the optional language does not apply;
- in Clause 13, the competent Supervisory Authority is the Supervisory Authority determined in accordance with Clause 13(a) and Annex I.C of the SCCs, based on the data exporter’s establishment or, where it is not established in the EEA, its representative or the Data Subjects concerned;
- in Clause 17, Option 1 applies, and the SCCs are governed by the law of Ireland;
- in Clause 18(b), disputes are resolved before the courts of Ireland; and
- Annexes I, II and III of the SCCs are completed with the information set out in Annexes I, II and III of this DPA.
12.3 Transfers from the United Kingdom
To the extent that the provision of the Services or Platforms involves a Restricted Transfer from the United Kingdom, the SCCs as set out in Section 12.2, as amended by the UK Addendum, apply. Tables 1 to 3 of the UK Addendum are completed with the information in this DPA and its Annexes, and for Table 4, either party may end the UK Addendum as set out in its Section 19.
12.4 Transfers from Switzerland
To the extent that the provision of the Services or Platforms involves a Restricted Transfer from Switzerland, the SCCs as set out in Section 12.2 apply with the following amendments: references to the GDPR are to be read as references to the Swiss FADP to the extent the transfer is subject to it; the competent Supervisory Authority is the Swiss Federal Data Protection and Information Commissioner; and references to “Member State” are to be read to include Switzerland, so that Data Subjects in Switzerland can bring claims in their place of habitual residence.
12.5 Alternative Transfer Mechanisms
If Aomark Digital adopts an alternative lawful transfer mechanism, such as certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions, that mechanism will apply instead of the SCCs to the extent it covers the relevant transfer. If a transfer mechanism is invalidated or ceases to be available, the parties will cooperate in good faith to implement an alternative mechanism.
12.6 Onward Transfers
Aomark Digital will ensure that any onward transfer of Customer Personal Data to a Subprocessor that constitutes a Restricted Transfer is subject to appropriate safeguards required by Applicable Data Protection Laws.
13. Audits and Information
Aomark Digital will make available to the Customer, on written request, the information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR, including written responses to reasonable security and data protection questionnaires, no more than once per calendar year unless a Supervisory Authority requires otherwise or a Personal Data Breach has occurred.
If the information provided is not sufficient to demonstrate compliance, the Customer may conduct an audit, including an inspection, of Aomark Digital’s processing of Customer Personal Data, subject to the following conditions:
- the Customer gives at least 30 days’ written notice, stating the proposed scope, duration and start date of the audit;
- audits take place no more than once in any 12-month period, except where required by a Supervisory Authority or following a Personal Data Breach;
- audits are conducted during normal business hours, remotely where possible, in a manner that does not unreasonably disrupt Aomark Digital’s operations, and are limited to the processing of Customer Personal Data;
- the audit is carried out by the Customer or an independent auditor that is not a competitor of Aomark Digital and that is bound by confidentiality obligations;
- the audit does not require access to the data of other customers, trade secrets or information subject to legal privilege; and
- the Customer bears the costs of the audit, including a reasonable fee for Aomark Digital’s time, agreed in advance, unless the audit reveals a material breach of this DPA by Aomark Digital, in which case Aomark Digital will bear its own costs.
Where the SCCs apply, nothing in this Section modifies or limits the rights of the Customer or any Supervisory Authority under the SCCs, and this Section describes how audits under Clause 8.9 of the SCCs are to be carried out.
14. Return and Deletion of Customer Personal Data
Upon termination or expiration of the Services, or on the Customer’s earlier written request, Aomark Digital will, at the Customer’s choice, return Customer Personal Data to the Customer in a commonly used format where technically feasible, or delete it. If the Customer does not make a choice within 30 days after the end of the Services, Aomark Digital will delete Customer Personal Data. Deletion will be completed within 90 days after the end of the Services, except for copies in backups, which will be deleted in the normal course of backup rotation and will remain protected in accordance with this DPA until deleted.
Aomark Digital may retain Customer Personal Data to the extent and for as long as required by applicable law, provided that it will continue to protect the retained data in accordance with this DPA and will process it only for the purpose for which it must be retained. On request, Aomark Digital will confirm in writing that deletion has been completed.
Customer Personal Data stored in systems owned or controlled by the Customer, such as the Customer’s website, customer relationship management system, email service provider or advertising accounts, remains under the Customer’s control. In respect of those systems, Aomark Digital’s obligation is to cease using the access granted to it and to delete any copies it has made outside those systems, and the Customer is responsible for revoking Aomark Digital’s access.
15. U.S. State Privacy Law Terms
To the extent that the CCPA or other U.S. state consumer privacy laws apply to the processing of Customer Personal Data, Aomark Digital acts as a service provider, contractor or processor, and in addition to the other terms of this DPA:
- Customer Personal Data is disclosed to Aomark Digital only for the limited and specified business purposes of providing the Services and Platforms described in the Agreement and Annex I;
- Aomark Digital will not sell or share Customer Personal Data, as those terms are defined in the CCPA;
- Aomark Digital will not retain, use or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement, including for any commercial purpose other than providing the Services and Platforms, or outside the direct business relationship between Aomark Digital and the Customer, except as permitted by Applicable Data Protection Laws;
- Aomark Digital will not combine Customer Personal Data with personal data it receives from or on behalf of another person or collects from its own interactions with individuals, except as permitted by Applicable Data Protection Laws;
- Aomark Digital will comply with the obligations applicable to it under the CCPA and other U.S. state consumer privacy laws and will provide the same level of privacy protection as required of businesses by those laws;
- Aomark Digital will notify the Customer if it determines that it can no longer meet its obligations under those laws;
- the Customer may, upon notice, take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data, and to ensure that Aomark Digital uses Customer Personal Data in a manner consistent with the Customer’s obligations under those laws;
- Aomark Digital will make available to the Customer, as described in Section 13, the information necessary to demonstrate compliance with its obligations under those laws; and
- Aomark Digital certifies that it understands and will comply with the restrictions set out in this Section.
16. Canada
To the extent that PIPEDA or substantially similar Canadian provincial laws apply to the processing of Customer Personal Data, Aomark Digital will process Customer Personal Data only for the purposes of providing the Services and Platforms, will protect it with security safeguards appropriate to its sensitivity as described in Annex II, and will provide a comparable level of protection to that required by those laws while the Customer Personal Data is being processed by Aomark Digital.
17. Liability
Each party’s liability arising out of or relating to this DPA, whether in contract, tort or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to the liability of a party means the aggregate liability of that party under the Agreement and this DPA together. Nothing in this Section limits either party’s liability to Data Subjects under the SCCs or under Applicable Data Protection Laws to the extent that such liability cannot be limited by law.
18. Term and Termination
This DPA takes effect when the Agreement is accepted and remains in effect for as long as Aomark Digital processes Customer Personal Data on behalf of the Customer. The obligations in this DPA that by their nature should continue, including those relating to confidentiality, deletion and security of retained data, survive the termination of the Agreement until all Customer Personal Data has been returned or deleted.
19. Order of Precedence
If there is a conflict between the documents that govern the processing of Customer Personal Data, the following order of precedence applies: (a) the SCCs and UK Addendum, where applicable; (b) this DPA; and (c) the rest of the Agreement. Otherwise, the Agreement remains unchanged and in full force and effect.
20. Governing Law and Dispute Resolution
Except as required by the SCCs, the UK Addendum or Applicable Data Protection Laws, this DPA is governed by the laws of the State of Wyoming, United States, and disputes arising out of or relating to this DPA will be resolved in accordance with the dispute resolution provisions of the Agreement.
21. Changes to This DPA
Aomark Digital may update this DPA to reflect changes in Applicable Data Protection Laws, guidance from Supervisory Authorities, transfer mechanisms or its processing activities. The updated version will be posted on our Websites with a new Effective Date. Aomark Digital will notify active Customers by email at least 30 days before any update that materially reduces the protection of Customer Personal Data takes effect, and no such update will apply to a Customer that objects in writing within that period until the end of its current engagement or Subscription term, unless the update is required by law.
22. Contact
Questions and requests relating to this DPA, including requests for the Subprocessor list, audit information or a countersigned copy, should be sent to:
- Company Name: Aomark Digital LLC
- Company Address: 75 E 3rd St, Sheridan, WY 82801, United States
- Website: https://aomarkdigital.com/
- Email: contact@aomarkdigital.com
Annex I: Details of Processing
A. List of Parties
- Data exporter: the Customer, as identified in the Agreement or the Customer’s Account. Contact details: as provided in the Agreement or Account. Activities relevant to the transfer: receipt of the Services and use of the Platforms. Role: Controller or, where applicable, Processor.
- Data importer: Aomark Digital LLC, 75 E 3rd St, Sheridan, WY 82801, United States. Contact: contact@aomarkdigital.com. Activities relevant to the transfer: provision of the Services and Platforms described in the Agreement. Role: Processor or, where applicable, Subprocessor.
- Signature and date: each party is deemed to have signed this Annex I on the date on which the Customer accepts the Agreement.
B. Description of Processing
- Subject matter: the provision of digital marketing and technology Services, including search engine optimization, link building, web development, paid advertising management, email marketing, analytics and automation, and the provision of the Platforms.
- Duration: for the term of the Agreement and until Customer Personal Data is returned or deleted in accordance with Section 14.
- Nature of processing: collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, analysis, transmission, alignment, combination within the Customer’s own datasets, restriction, erasure and destruction, as necessary to perform the Services.
- Purpose of processing: to perform the Services and provide the Platforms in accordance with the Agreement and the Customer’s documented instructions, including website development and maintenance, campaign setup and management, audience and list management, email campaign delivery, reporting, analytics, workflow automation, technical support and troubleshooting.
- Frequency of the transfer: continuous for the duration of the Services, or on a one-off basis for individual projects, depending on the Services ordered.
C. Categories of Data Subjects
Depending on the Services ordered and the Customer’s instructions, Customer Personal Data may relate to the following categories of Data Subjects:
- the Customer’s customers and prospective customers;
- subscribers to the Customer’s email lists and newsletters;
- leads and individuals who submit forms on the Customer’s websites or landing pages;
- visitors and users of the Customer’s websites and online stores;
- the Customer’s business contacts, and employees or contractors of the Customer’s customers; and
- other individuals whose personal data the Customer instructs Aomark Digital to process.
D. Categories of Personal Data
- identification and contact data, such as name, email address, phone number, company, job title and postal address;
- email marketing data, such as subscription status, consent records, list membership, email engagement data (opens, clicks, bounces and unsubscribes) and preferences;
- customer relationship management data, such as lead source, lead status, notes, communication history and deal information;
- form submission data, such as the content of inquiries and form fields defined by the Customer;
- e-commerce and transaction data made available through the Customer’s systems, such as order history, products purchased and order values, excluding full payment card data;
- online identifiers and usage data, such as IP addresses, cookie identifiers, device and browser information, pages viewed and conversion events; and
- advertising audience data, such as hashed customer lists used for audience matching on advertising platforms.
E. Sensitive Data
The parties do not intend Aomark Digital to process special categories of personal data or sensitive personal information. If the Customer provides such data with Aomark Digital’s prior written agreement, it will be processed with the additional safeguards agreed in writing, such as restricted access and additional security measures.
F. Retention
Customer Personal Data is retained for the duration of the Services and then returned or deleted as described in Section 14.
G. Transfers to Subprocessors
The subject matter, nature and duration of processing by Subprocessors are the same as described above, limited to the services each Subprocessor provides to Aomark Digital, as described in Annex III.
Annex II: Technical and Organizational Security Measures
Aomark Digital implements the following technical and organizational measures, which are appropriate to the size of its business and the nature of the processing:
- Encryption in transit: Customer Personal Data transmitted to and from the Platforms and Aomark Digital’s systems is protected by HTTPS/TLS encryption.
- Encryption at rest: Customer Personal Data stored in the Platforms and business systems is hosted with providers that offer encryption at rest.
- Access control: access to Customer Personal Data is limited to personnel and contractors who need it to perform the Services, on the principle of least privilege, and access rights are removed when no longer needed.
- Authentication: unique user accounts are used for each individual, passwords for Platform accounts are stored in hashed form, and multi-factor authentication is used on key business systems where available.
- Credential management: access credentials provided by Customers are stored in a secure password manager or access-controlled system and are not shared by insecure means. Role-based access through user invitations is preferred to shared credentials.
- Data minimization: Customer Personal Data is accessed and exported only to the extent necessary for the Services, and working copies are deleted when no longer needed.
- Confidentiality: personnel and contractors are bound by confidentiality obligations and are instructed on the handling of personal data.
- Device security: devices used to access Customer Personal Data are protected by passwords or biometric locks, kept up to date with security updates and use reputable security software where appropriate.
- Vendor management: Subprocessors are selected with regard to their security practices and are bound by written data protection obligations.
- Backups and availability: data in the Platforms is backed up by hosting providers in accordance with their backup processes, to support recovery in the event of an incident.
- Logging and monitoring: access and security events in the Platforms are logged where technically available, and logs are reviewed when investigating suspected incidents.
- Incident response: Aomark Digital maintains a procedure to identify, contain, investigate and report Personal Data Breaches in accordance with Section 10.
- Payment data: full payment card data is processed only by PCI DSS compliant payment processors and is not stored by Aomark Digital.
- Deletion: Customer Personal Data is deleted in accordance with Section 14 using the deletion functions of the relevant systems.
Annex III: Subprocessors
Aomark Digital uses Subprocessors in the following categories, to the extent necessary for the Services and Platforms ordered by the Customer:
- Cloud hosting and infrastructure providers: hosting of the Platforms, websites and related data.
- Email and communication providers: business email, messaging and video conferencing used to communicate with the Customer and exchange project materials.
- Productivity, file storage and project management tools: storage and management of project files, documents and tasks.
- Password management tools: secure storage of access credentials provided by the Customer.
- Artificial intelligence and language processing providers: processing of content and data submitted to Platform features or used in the Services that rely on such technology, where applicable.
- Analytics and reporting tools: preparation of performance reports and dashboards.
- Automation and integration tools: connection of the Customer’s systems and execution of automated workflows.
- Independent contractors: specialists engaged by Aomark Digital to perform part of the Services under confidentiality and data protection obligations.
Third-party platforms that the Customer owns or selects and to which it grants Aomark Digital access, such as its content management system, customer relationship management system, email service provider, analytics and advertising accounts, are the Customer’s own processors and are not Subprocessors of Aomark Digital. A current list of Subprocessors, including names and locations, is available on request by email to contact@aomarkdigital.com.
