Data Processing Addendum

Last updated 2026-09-28

This Data Processing Addendum (DPA) applies when the customer uses dejav to process personal data in a Target Site on behalf of that customer. It supplements the Terms of Service. The customer is the controller and the operator of dejav is the processor for that processing, unless applicable law assigns different roles.

1. Scope and instructions

We process personal data only to provide, secure, and support the Service, and only on the customer's documented instructions in the Terms, this DPA, and the customer's use of the Service. The processing may include collecting, recording, organizing, viewing, storing, retrieving, transmitting, and deleting data. It continues for the term of the customer's use of the Service.

The data subjects may include the customer's users, employees, contractors, and visitors. Personal data may include account details, page content, form values, screenshots, session replays, test results, and logs. The customer determines the nature and purpose of processing by configuring and running tests.

2. Customer responsibilities

The customer is responsible for having a lawful basis, giving required notices, obtaining required consents, and ensuring its instructions are lawful. The customer must not instruct us to process personal data in a way that violates applicable law.

3. Confidentiality and security

We limit access to people who need it to provide the Service and who are bound by confidentiality. We maintain technical and organizational measures appropriate to the risk, including access controls, encryption for stored site credentials, isolated test environments, network restrictions, and audit logging. The current measures are described in the Security Policy.

4. Subprocessors

The customer gives general authorization for our use of the service providers listed in the Privacy Policy as subprocessors where they process Target Site personal data. We impose written data-protection obligations on subprocessors appropriate to their role. We will provide notice of a material new subprocessor by updating the list in the Privacy Policy; a customer with a reasonable data-protection objection may stop using the affected feature or end the Service before it takes effect.

5. Assistance and incidents

Taking account of the nature of processing and information available to us, we will reasonably assist the customer with requests from data subjects and with security, breach, impact-assessment, and regulator obligations. If we become aware of a personal-data breach affecting Target Site personal data, we will notify the customer without undue delay and provide information reasonably available to us.

6. International transfers

The Service uses providers that may process data outside Japan, including in the United States. The countries and providers are listed in the Privacy Policy. Where a transfer mechanism is required, the parties will cooperate in good faith to implement an appropriate mechanism.

7. Return and deletion

During the account-deletion grace period, the customer can export its data from the Service. After the grace period, we delete or anonymize customer data as described in the Privacy Policy, unless retention is required by law or necessary to establish, exercise, or defend legal claims.

8. Audit information and precedence

On reasonable written request, we will provide information reasonably necessary to demonstrate compliance with this DPA, subject to protecting our security and other customers' confidential information. If this DPA conflicts with the Terms about processing Target Site personal data, this DPA controls to the extent of that conflict.

9. Contact

Questions, requests, and data-protection inquiries can be sent to [email protected].

Data Processing Addendum · dejav