1. Purpose
This Data Processing Addendum gives customers a plain-English summary of how Online Audience handles personal data when we act as a processor for hosted customer data. It should be read with the Privacy Policy, Terms of Service and the customer’s service order.
2. Roles
For customer websites, apps, databases, email accounts, radio services, listener tools or hosted content, the customer normally decides what personal data is collected and why. In that context, the customer is usually the controller and Online Audience is usually the processor. For our own account, billing, support and website data, Online Audience is usually the controller.
3. Processing instructions
We process hosted customer data to provide, secure, maintain, troubleshoot and support the ordered services. Customers must not ask us to process data unlawfully or in a way that breaches our policies or applicable law.
4. Security measures
We use practical security measures appropriate to the service, which may include account controls, server hardening, SSL/TLS, monitoring, backups, access limitation, support verification and administrative controls. Customers remain responsible for their own passwords, software updates, access permissions and content security.
5. Sub-processors
We may use sub-processors such as infrastructure providers, software vendors, domain/DNS providers, backup providers, payment providers and support tools where needed to deliver the service. We aim to use providers that offer suitable contractual and security protections.
6. Personal data breach support
If we become aware of a personal data breach affecting hosted customer data, we will take reasonable steps to investigate, mitigate and notify the affected customer without undue delay where required. Customers are responsible for assessing any notification duties to their own users, regulators or other parties.
7. Data subject requests
If we receive a request from an end user about hosted customer data, we may direct the request to the customer. We will provide reasonable assistance where technically possible and proportionate.
8. Deletion and return
When a service ends, hosted data may be deleted according to the service lifecycle, backup rotation and account status. Customers should download or migrate data before cancellation or expiry. Backup copies may remain for a limited time before being overwritten or removed.