High Frequency Compute
Redundant NVMe Storage
Optimized for Performance
1-Click CDN and LSCache
Proactive Server Monitoring
99.9% Uptime, 24/7 Support
Offsite Backup, SSL
IP Blacklist Protection
Last Updated: August 23, 2023
This Data Processing Agreement ("DPA"), as updated from time to time, supplements and its term and conditions are subject to MechanicWeb's Terms of Service ("TOS"), by and between MechanicWeb and Customer, which are incorporated herein by this reference, and governs MechanicWeb's use of Customer's Data (as defined herein) (as a controller of such data). MechanicWeb and Customer may be individually referred to as a "Party" or collectively, the "Parties."
The Parties have agreed to enter into this DPA to safeguard Personal Data with respect to the requirements of the General Data Protection Regulation ("GDPR") of the European Union.
The following definitions are used in this DPA. Unless otherwise defined herein, all capitalized terms used in this DPA will have the meanings given in the TOS:
The Parties acknowledge and agree to comply with this DPA where and only to the extent of either Party's processing of Customer Data, which is subject to Data Protection Laws of the European Union (EU), the European Economic Area (EEA), and/or their member states, Switzerland and/or the United Kingdom.
MechanicWeb shall process Customer Data as "Processor" to Customer or any Affiliate of Customer who may act either as "Controller" or "Processor" with respect to Customer Data. Nothing in this DPA shall prevent MechanicWeb from using or sharing any data that MechanicWeb may otherwise collect and process independently of Customer's use of the Services.
MechanicWeb shall process Customer Data in the course of providing the Services in accordance with Customer’s Documented Instructions as outlined in this DPA, as necessary to comply with applicable law, or as otherwise agreed in writing. MechanicWeb provides Customer with several controls, including security features and functionalities, to retrieve, correct, delete or restrict Customer Data. Without prejudice to Section 5.1, Customer may use these controls as technical and organizational measures to assist it concerning its obligations under the GDPR and all other applicable Data Protection Laws, including its obligations relating to responding to requests from Data Subjects.
Customer will not provide (or cause to be provided) any Sensitive Data to MechanicWeb for processing. MechanicWeb will have no liability whatsoever for Sensitive Data, whether in connection with a Security Incident or otherwise, and this DPA does not apply to Sensitive Data.
The Parties agree that the TOS and this DPA, including the provision of instructions via configuration tools such as any MechanicWeb control panel, management console, and APIs made available by MechanicWeb to provide Services, constitute Customer's Documented Instructions regarding MechanicWeb's processing of Customer Data ("Documented Instructions"). MechanicWeb will process Customer Data only in accordance with Documented Instructions. Additional instructions concerning processing Customer Data outside the scope of the Documented Instructions (if any) require a prior written agreement between Customer and MechanicWeb.
MechanicWeb will not access or use, or disclose to any third party, any Customer Data, except, in each case, as necessary to provide the Services, or as necessary, to comply with the law or a valid and binding order of a governmental body (such as a preservation request, warrant, subpoena or court order). If compelled to disclose Customer Data to a government body, MechanicWeb will notify Customer unless MechanicWeb is legally prohibited from doing so. If the SCCs apply, nothing in this Section varies or modifies the SCCs.
MechanicWeb restricts its personnel, including staff and Sub-processors, from processing Customer Data without authorization by MechanicWeb. MechanicWeb shall ensure that any personnel authorized by MechanicWeb to process Customer Data (including its employees, agents, and subcontractors) shall be under appropriate obligations, including relevant obligations regarding confidentiality, data protection, and data security (whether a contractual or statutory duty).
Notwithstanding anything to the contrary in the TOS and this DPA, Customer acknowledges that MechanicWeb has the right to use and disclose data related to and/or obtained in the course of providing the Services for its legitimate business purposes, such as sales, billing, support, account management, and marketing. MechanicWeb shall process such data in compliance with Data Protection Laws to the extent any such data is considered Customer Data under Data Protection Laws.
MechanicWeb shall implement and maintain adequate technical and organizational security measures to protect Customer Data from Security Incidents and to preserve the security and confidentiality of Customer Data. In assessing the security level, MechanicWeb shall consider the risks from a Personal Data breach that Processing presents.
Customer acknowledges that the Security Measures are subject to technical progress and development, and that MechanicWeb may update or modify the Security Measures from time to time.
MechanicWeb shall promptly take reasonable steps to contain and investigate any Security Incident upon becoming aware of such. MechanicWeb's notification of or response to a Security Incident under this Section shall not be construed as an acknowledgment by MechanicWeb of any fault or liability concerning the Security Incident.
MechanicWeb shall notify Customer without undue delay, and where feasible, within forty-eight (48) hours of awareness of a Security Incident or a Personal Data breach affecting Customer’s Personal Data, with timely information related to the Security Incident as it becomes known or as is reasonably requested by Customer, to meet any obligations to report or inform Data Subjects of the Personal Data breach under the Data Protection Laws.
Customer agrees that, except as provided by this DPA, Customer is responsible for its secure use of the Services, securing Customer Account authentication credentials, protecting the security of Customer Data when in transit to and from the Services, and to securely encrypt or backup any Customer Data uploaded to the Services.
Customer consents that MechanicWeb may engage Sub-processors to carry out Processing activities on Customer Data on behalf of Customer to fulfill contractual obligations or to provide Services on its behalf. The Sub-processors list can be found here.
MechanicWeb shall notify Customer with reasonable advance notice if it adds or removes Sub-processors. MechanicWeb may update the Sub-processor list and may provide Customer with a mechanism to obtain notice of that update.
Customer may object in writing to MechanicWeb of any new Sub-processors on reasonable data protection grounds within five (5) calendar days of receiving such notice following Section 6.3 of this DPA. The Parties shall discuss such concerns in good faith to achieve a commercially reasonable resolution. If no solution can be achieved, either Party may terminate the affected Services per the termination provisions in the TOS without liability to either Party and without prejudice to any fees incurred by Customer prior to termination.
Taking into account the nature of the Processing, MechanicWeb shall, in so far as is possible, at Customer's expense, provide reasonable cooperation to assist Customer by appropriate technical and organizational measures, to the extent that Customer is unable to independently access the relevant Customer Data within the Services, to respond to any requests from individuals or applicable data protection authorities relating to the processing of Customer Data as per the TOS. In the event that any such request is made to MechanicWeb directly, MechanicWeb shall not respond to such communication directly without Customer’s prior authorization, except legally required. If MechanicWeb is required to respond to such a request, MechanicWeb shall, unless legally prohibited from doing so, where Customer is identified or identifiable from the request, promptly notify Customer and provide Customer with a copy of the request. For the avoidance of doubt, nothing in the Agreement (including this DPA) shall restrict or prevent MechanicWeb from responding to any Data Subject or data protection authority requests in relation to personal data for which MechanicWeb is a controller.
To the extent required under applicable Data Protection Laws, MechanicWeb shall, at Customer's expense, provide all reasonably requested information regarding MechanicWeb's processing of Customer Data to enable Customer to carry out data protection impact assessments or prior consultations with data protection authorities as required by Data Protection Laws.
Customer agrees that MechanicWeb may process, transfer and store Customer Data to and in the United States and anywhere else in the world where MechanicWeb, its Affiliates, and/or its Sub-processors maintain data processing operations in accordance with the requirements of Data Protection Laws and this DPA. MechanicWeb shall ensure that such Processing complies with the requirements of Data Protection Laws and this DPA to protect Customer Data.
Notwithstanding Section 8.1, to the extent that MechanicWeb processes or transfers Customer Data from the European Union (EU), the European Economic Area (EEA) and/or their member states, Switzerland and/or the United Kingdom, whether directly or via onward transfer, in or to countries that do not ensure an appropriate level of data protection in respect to applicable Data Protection Laws, MechanicWeb shall be deemed to take adequate measures by having aligned its operational policies with the requirements of applicable Data Protection Laws and this DPA to protect Customer Data. Customer hereby authorizes any transfer to, or access to Customer Data from such destinations outside the EU subject to any of these measures having been taken.
Upon termination or deactivation of the Services, MechanicWeb shall store Customer Data for no longer than 10 years from receipt, subject to an individual's right to be forgotten at any time, except that this requirement shall not apply to the extent MechanicWeb is required by applicable law to retain some or all of Customer Data, or to Customer Data it has archived on back-up systems, which such Customer Data MechanicWeb shall securely isolate, protect from any further processing, except to the extent required by applicable law.
In the event of any conflict or inconsistency between this DPA and the TOS, the provisions of the following documents (in order of precedence) shall prevail to the extent of the conflict: this DPA; and then the TOS.
This DPA is a part of and incorporated into the TOS. References to TOS in the TOS shall include this DPA.
No one other than a Party to this DPA, its successors and permitted assignees shall have any right to enforce any of its terms.
This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, unless required otherwise by applicable Data Protection Laws.
This DPA is entered into with effect from the earlier date of use of the Services.
This DPA shall remain in effect for as long as MechanicWeb carries out Customer Data processing operations on behalf of Customer or until termination of the Agreement.
This DPA may be amended in any respect at any time by MechanicWeb upon the posting of the amended DPA on the mechanicweb.com website. Your continued use of the Services will be deemed consent to any such amended DPA. If you do not wish to continue to use the Services as a result of any such amendments, you may provide notice of your wish to terminate your Services to MechanicWeb.
We use cookies to enable essential site functionality, remember your preferences and repeat visits, and analyze our traffic. By clicking "Accept", you consent to our use of cookies. Learn more.
Accept