Last updated: July 2026 · Pursuant to GDPR Article 28
"Controller" means the customer entity that has agreed to the MapLayer Terms of Service and is using the MapLayer service.
"Processor" means MapLayer, which processes personal data on behalf of the Controller.
"Personal Data" has the meaning given in GDPR Article 4(1).
"Processing" has the meaning given in GDPR Article 4(2).
MapLayer processes personal data on behalf of the Controller for the purpose of providing the MapLayer field team map platform, as described in the Terms of Service. Processing continues for the duration of the Controller's active subscription and for any retention period specified in this Agreement.
MapLayer processes personal data to:
Employees and contractors of the Controller who are granted access to the MapLayer platform, including merchandisers, field sales representatives, regional managers, and administrators.
MapLayer shall:
MapLayer uses the following sub-processors to deliver the service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase (via AWS) | Database and authentication | EU (Frankfurt, eu-central-1) |
| Stripe | Payment processing | EU/US (Stripe standard DPA) |
| Vercel | Application hosting (frontend) | EU edge nodes |
| Google Maps Platform | Geocoding and map display | EU (Google Cloud DPA) |
MapLayer will notify the Controller of any intended changes to this sub-processor list with at least 14 days' notice, giving the Controller the opportunity to object.
All personal data is stored and processed within the European Economic Area (EEA). No personal data is transferred to third countries outside the EEA as part of the standard service. Sub-processors operating globally (Stripe, Google) process data under their own Standard Contractual Clauses (SCCs) in accordance with GDPR Chapter V.
MapLayer implements the following security measures:
Upon termination of the service, the Controller's data is locked (not deleted) for 30 days, during which the Controller may request a data export. After 30 days, all personal data is permanently deleted from production systems. Backups are purged within 90 days of the termination date.
The Controller may, with at least 14 days' written notice, request an audit of MapLayer's data processing activities relevant to this Agreement. Audits shall be conducted during normal business hours, at the Controller's expense, and no more than once per calendar year unless a data breach has occurred.
This Agreement is governed by the laws of the European Union and the GDPR. Any disputes shall be resolved under the jurisdiction applicable to the Controller's country of establishment within the EU.
For DPA-related inquiries, signed copies, or sub-processor notifications, contact: support@map-layer.com