Last revision of this Product Notice: October 20, 2025 Prior version(s) of this Product Notice: No prior version This Product Notice describes the privacy relevant aspects of the above-mentioned Acquia product/services.
About the Product/Services Acquia Edge Standard is a Web
Application
Firewall (WAF) service designed to provide essential protection against common DDoS and web application security threats for Acquia-hosted domains. The service is configurable through Acquia’s Edge Console, providing insights into site activity, and enabling customers to reduce the risk and impact of potential attacks against their protected domains.
Akamai is a Sub-processor for the Acquia Edge Standard web application firewall (WAF) service. For details about this Product, please refer to the Annex contained within the relevant Order Form or to the product description available online at https://docs.acquia.com/.
1. Processing Operation(s)
The objective of Processing of Personal Data by data importer is the performance of the Services pursuant to the Agreement. Processing of Personal Data to deliver its core functionalities required: ☒ yes ☐ no Optional features processing Personal Data: ☒ yes ☐ no The optional features are deactivated by default: ☒ yes ☐ no ☐ n/a* Processing of sensitive Personal Data: ☒ yes** ☐no ☐ n/a* Profiling of individuals based on personal characteristics: ☐ yes ** ☒no ☐ n/a* Automated decision making that produces legal or other significant impacts on individuals: ☐ yes ☒ no ☐ n/a* Processing via an AI tool available with the Product ☐ yes ☒ no The AI feature is deactivated by default: ☐ yes ☐ no ☒ n/a* The AI feature processes Personal Data: ☐ yes ☐ no ☒ n/a* The AI feature processes sensitive Personal Data ☐ yes ☐ no ☒ n/a* The Customer can control what data the AI tool processes: ☐ yes ☐ no ☒ n/a*
* (n/a = not applicable) ** (optional; depends on the Customer’s configuration of the system, the connection to other systems, and the categories chosen by the Customer to be collected from Third Party Users)
2. Details of Personal Data being processed
Categories of Personal Data
Categories of Data Subjects
Purpose of Processing
Categories of Data Recipients
Needed for Core Features
Processing Location
Acquia Inc. acts as Processor
Through the configuration, design, and administration of the Service, Customer in its sole discretion determines and controls the categories of personal data by the Service. These may be names, titles, position, employer, contact information (email, phone, fax, physical address, etc.), identification data, professional life data, personal life data, connection data, or localization data (including IP addresses).
Through the configuration, design, and administration of the service, Customer in its sole discretion determines and controls the categories of data subjects collected by the Service: Natural persons that (i) access or use the Customer’s domains, networks, websites, application programming interfaces (“APIs”), and applications, or (ii) are authorized users such as the Customers’ employees, agents, or contractors.
Data anonymization at Customer level optional for Customer
Data confidentiality (incl. encryption)
Access control measures Encryption at customer level Encryption at Acquia level Jurisdiction restrictions for (private) key storage and option to choose data center locations (see Security Annex and Product Description)
Data availability including restoring availability, restoring access to personal data, and data resilience
Business continuity and disaster recovery measures (see Security Annex)
Yes
N/A
Regular testing, assessing and evaluating TOMs
Regular security and process reviews (see also )
4. Certifications
Refer to Acquia’s security portal (security.acquia.com) for the Edge Standard services.. Your Acquia account team may supply you with copies of the relevant compliance documentation as applicable, upon request.
5. Data Subject Rights
Through the Product’s administration console the Customer may manage, update, retrieve, and erase individual Personal Data
6. (Personal) Data Retention Cycles
Customer Account Information - Customer Account Information includes customer registration and contact information, audit logs, and other logs and data about account configurations and settings. We store Customer Account Information as long as a Customer has an active account, and we set specific timeframes for retaining Customer Account Information following deletion of an account based on the reason for collection and applicable law. In addition, upon deletion of an account or upon receipt of an individual’s request to be forgotten, we may be required to retain the email address associated with the account for an extended period of time, and potentially block that email address from creating a new account in the future, in order to comply with legal obligations and our terms.
Operational Metrics - Acquia stores server and network activity data and logs collected by the service in the course of operating the Service and our observations and analysis of traffic data (together, “Operational Metrics”) up to 12 months or as long as we have a legitimate business purpose for retention.
Edge Server Logs capture traffic delivery metadata on our edge servers that perform the customer traffic processing & proxying. We do not store the POST body, and we remain oblivious to the content we deliver on behalf of our customers at all times. Edge Server logs contain basic traffic metadata including: ● Client IP address, forward IP address, ● URL, ● HTTP method, Response code, ● Non-sensitive headers such as Host, Content-type, Accept Language, Content Length, ● A large number of Akamai-specific indicators for caching, mapping, and performance decisions. Potentially sensitive HTTP headers including Cookie, Referrer, and User-agent string are only logged if explicitly configured.
Long term storage depends on the type of log and the applicable requirements. For instance, logs containing personal information such as IP addresses (e.g., Edge Server logs above) are only kept for 45-90 days as GDPR mandates. Security event logs including Authgate accesses are kept for at least 1 year as required for various security compliance regimes.
7. Sub-Processing
The specific list of Acquia’s sub-processors is available from: https://www.acquia.com/about-us/legal/subprocessors. Any current Acquia customer with a data processing agreement in place with Acquia may subscribe to receive notifications of new or changed sub-processors through the above website.
8. Description of the technical and organizational security measures implemented by the data importer in accordance with Clauses 4(d) and 5(c) (or document/legislation attached)
Data importer has implemented and will maintain appropriate administrative, physical, and technical safeguards for the protection of the security, confidentiality and integrity of Personal Data uploaded to the Services, as described in the Acquia Security Annex (available from https://www.acquia.com/about-us/legal/gdpr) applicable to the specific Services purchased by data exporter, as updated from time to time, and made available by data importer upon request. The data exporter is wholly responsible for implementing and maintaining security and data administration within any data exporter applications, configuration settings, or log settings used by data exporter in conjunction with the Services.
Acquia Edge Standard Product Privacy Notice
Acquia Edge Standard
Last revision of this Product Notice: October 20, 2025 Prior version(s) of this Product Notice: No prior version This Product Notice describes the privacy relevant aspects of the above-mentioned Acquia product/services.
About the Product/Services Acquia Edge Standard is a Web
Application
Firewall (WAF) service designed to provide essential protection against common DDoS and web application security threats for Acquia-hosted domains. The service is configurable through Acquia’s Edge Console, providing insights into site activity, and enabling customers to reduce the risk and impact of potential attacks against their protected domains.
Akamai is a Sub-processor for the Acquia Edge Standard web application firewall (WAF) service. For details about this Product, please refer to the Annex contained within the relevant Order Form or to the product description available online at https://docs.acquia.com/.
1. Processing Operation(s)
The objective of Processing of Personal Data by data importer is the performance of the Services pursuant to the Agreement. Processing of Personal Data to deliver its core functionalities required: ☒ yes ☐ no Optional features processing Personal Data: ☒ yes ☐ no The optional features are deactivated by default: ☒ yes ☐ no ☐ n/a* Processing of sensitive Personal Data: ☒ yes** ☐no ☐ n/a* Profiling of individuals based on personal characteristics: ☐ yes ** ☒no ☐ n/a* Automated decision making that produces legal or other significant impacts on individuals: ☐ yes ☒ no ☐ n/a* Processing via an AI tool available with the Product ☐ yes ☒ no The AI feature is deactivated by default: ☐ yes ☐ no ☒ n/a* The AI feature processes Personal Data: ☐ yes ☐ no ☒ n/a* The AI feature processes sensitive Personal Data ☐ yes ☐ no ☒ n/a* The Customer can control what data the AI tool processes: ☐ yes ☐ no ☒ n/a*
* (n/a = not applicable) ** (optional; depends on the Customer’s configuration of the system, the connection to other systems, and the categories chosen by the Customer to be collected from Third Party Users)
2. Details of Personal Data being processed
Categories of Personal Data
Categories of Data Subjects
Purpose of Processing
Categories of Data Recipients
Needed for Core Features
Processing Location
Acquia Inc. acts as Processor
Through the configuration, design, and administration of the Service, Customer in its sole discretion determines and controls the categories of personal data by the Service. These may be names, titles, position, employer, contact information (email, phone, fax, physical address, etc.), identification data, professional life data, personal life data, connection data, or localization data (including IP addresses).
Through the configuration, design, and administration of the service, Customer in its sole discretion determines and controls the categories of data subjects collected by the Service: Natural persons that (i) access or use the Customer’s domains, networks, websites, application programming interfaces (“APIs”), and applications, or (ii) are authorized users such as the Customers’ employees, agents, or contractors.
Data anonymization at Customer level optional for Customer
Data confidentiality (incl. encryption)
Access control measures Encryption at customer level Encryption at Acquia level Jurisdiction restrictions for (private) key storage and option to choose data center locations (see Security Annex and Product Description)
Data availability including restoring availability, restoring access to personal data, and data resilience
Business continuity and disaster recovery measures (see Security Annex)
Yes
N/A
Regular testing, assessing and evaluating TOMs
Regular security and process reviews (see also )
4. Certifications
Refer to Acquia’s security portal (security.acquia.com) for the Edge Standard services.. Your Acquia account team may supply you with copies of the relevant compliance documentation as applicable, upon request.
5. Data Subject Rights
Through the Product’s administration console the Customer may manage, update, retrieve, and erase individual Personal Data
6. (Personal) Data Retention Cycles
Customer Account Information - Customer Account Information includes customer registration and contact information, audit logs, and other logs and data about account configurations and settings. We store Customer Account Information as long as a Customer has an active account, and we set specific timeframes for retaining Customer Account Information following deletion of an account based on the reason for collection and applicable law. In addition, upon deletion of an account or upon receipt of an individual’s request to be forgotten, we may be required to retain the email address associated with the account for an extended period of time, and potentially block that email address from creating a new account in the future, in order to comply with legal obligations and our terms.
Operational Metrics - Acquia stores server and network activity data and logs collected by the service in the course of operating the Service and our observations and analysis of traffic data (together, “Operational Metrics”) up to 12 months or as long as we have a legitimate business purpose for retention.
Edge Server Logs capture traffic delivery metadata on our edge servers that perform the customer traffic processing & proxying. We do not store the POST body, and we remain oblivious to the content we deliver on behalf of our customers at all times. Edge Server logs contain basic traffic metadata including: ● Client IP address, forward IP address, ● URL, ● HTTP method, Response code, ● Non-sensitive headers such as Host, Content-type, Accept Language, Content Length, ● A large number of Akamai-specific indicators for caching, mapping, and performance decisions. Potentially sensitive HTTP headers including Cookie, Referrer, and User-agent string are only logged if explicitly configured.
Long term storage depends on the type of log and the applicable requirements. For instance, logs containing personal information such as IP addresses (e.g., Edge Server logs above) are only kept for 45-90 days as GDPR mandates. Security event logs including Authgate accesses are kept for at least 1 year as required for various security compliance regimes.
7. Sub-Processing
The specific list of Acquia’s sub-processors is available from: https://www.acquia.com/about-us/legal/subprocessors. Any current Acquia customer with a data processing agreement in place with Acquia may subscribe to receive notifications of new or changed sub-processors through the above website.
8. Description of the technical and organizational security measures implemented by the data importer in accordance with Clauses 4(d) and 5(c) (or document/legislation attached)
Data importer has implemented and will maintain appropriate administrative, physical, and technical safeguards for the protection of the security, confidentiality and integrity of Personal Data uploaded to the Services, as described in the Acquia Security Annex (available from https://www.acquia.com/about-us/legal/gdpr) applicable to the specific Services purchased by data exporter, as updated from time to time, and made available by data importer upon request. The data exporter is wholly responsible for implementing and maintaining security and data administration within any data exporter applications, configuration settings, or log settings used by data exporter in conjunction with the Services.