Data Processing Agreement

Last updated: July 2026 · Pursuant to GDPR Article 28

For a signed DPA: Enterprise customers who require a countersigned DPA for compliance purposes should contact support@map-layer.com. We will provide a signed PDF within 5 business days.

1. Definitions

"Controller" means the customer entity that has agreed to the MapLayer Terms of Service and is using the MapLayer service.

"Processor" means MapLayer, which processes personal data on behalf of the Controller.

"Personal Data" has the meaning given in GDPR Article 4(1).

"Processing" has the meaning given in GDPR Article 4(2).

2. Subject matter and duration

MapLayer processes personal data on behalf of the Controller for the purpose of providing the MapLayer field team map platform, as described in the Terms of Service. Processing continues for the duration of the Controller's active subscription and for any retention period specified in this Agreement.

3. Nature and purpose of processing

MapLayer processes personal data to:

  • Authenticate and manage user accounts within the Controller's organization
  • Store and display location data, visit statuses, and route information entered by users
  • Send transactional emails (invite links, password resets, billing notifications)
  • Enforce subscription plan limits and access controls

4. Categories of personal data processed

  • Identity data: full name, email address
  • Authentication data: hashed passwords, session tokens
  • Usage data: visit statuses, location notes, route plans, timestamps
  • Device data: IP address, browser type (for security and access logs)

5. Categories of data subjects

Employees and contractors of the Controller who are granted access to the MapLayer platform, including merchandisers, field sales representatives, regional managers, and administrators.

6. Obligations of the Processor (MapLayer)

MapLayer shall:

  • Process personal data only on documented instructions from the Controller
  • Ensure persons authorized to process the data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures (GDPR Article 32)
  • Assist the Controller in responding to data subject requests under GDPR Chapter III
  • Notify the Controller without undue delay after becoming aware of a personal data breach
  • Delete or return all personal data upon termination of the service at the Controller's choice
  • Make available all information necessary to demonstrate compliance with GDPR Article 28

7. Sub-processors

MapLayer uses the following sub-processors to deliver the service:

Sub-processor Purpose Location
Supabase (via AWS)Database and authenticationEU (Frankfurt, eu-central-1)
StripePayment processingEU/US (Stripe standard DPA)
VercelApplication hosting (frontend)EU edge nodes
Google Maps PlatformGeocoding and map displayEU (Google Cloud DPA)

MapLayer will notify the Controller of any intended changes to this sub-processor list with at least 14 days' notice, giving the Controller the opportunity to object.

8. International data transfers

All personal data is stored and processed within the European Economic Area (EEA). No personal data is transferred to third countries outside the EEA as part of the standard service. Sub-processors operating globally (Stripe, Google) process data under their own Standard Contractual Clauses (SCCs) in accordance with GDPR Chapter V.

9. Security measures

MapLayer implements the following security measures:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256 via Supabase/AWS)
  • Row-level security (RLS) ensuring users can only access their own personal data
  • Regular automated backups with point-in-time recovery
  • Access logs and anomaly detection at the infrastructure level
  • Hashed passwords (bcrypt) — MapLayer never stores plaintext passwords

10. Data retention and deletion

Upon termination of the service, the Controller's data is locked (not deleted) for 30 days, during which the Controller may request a data export. After 30 days, all personal data is permanently deleted from production systems. Backups are purged within 90 days of the termination date.

11. Audit rights

The Controller may, with at least 14 days' written notice, request an audit of MapLayer's data processing activities relevant to this Agreement. Audits shall be conducted during normal business hours, at the Controller's expense, and no more than once per calendar year unless a data breach has occurred.

12. Governing law

This Agreement is governed by the laws of the European Union and the GDPR. Any disputes shall be resolved under the jurisdiction applicable to the Controller's country of establishment within the EU.

13. Contact

For DPA-related inquiries, signed copies, or sub-processor notifications, contact: support@map-layer.com