| Categories of Personal Data | Categories of Data Subjects | Purpose of Processing | Categories of Data Recipients | Needed for Core Features | Processing Location | Acquia Inc. acts as Processor |
|---|---|---|---|---|---|---|
| Through the configuration, design, and administration of its own Drupal application, Customer, in its sole discretion, determines and controls the categories of personal data collected by their Drupal Application and, thus, provided to Acquia for processing. These may be individual identifiers, contact details, online identifiers, network activity, location data, and any sensitive data categories. | Through the configuration, design, and administration of its own Drupal application, Customer in its sole discretion determines and controls the categories of data subjects collected by their Drupal Application. Primarily, these would be Customer’s site administrators and end-users, such as visitors to Customer’s website. | Provision of the Services by Acquia to Customer | Site administrat ors; Acquia Service Providers and Subprocess ors; | Yes | US-East*** EU-Central*** | Yes |
*** Alternative data centre locations are not supported at this time.
3. Privacy Enhancements
| Objective | Technology / Measure | Data at Rest | Data in Transit |
|---|---|---|---|
| Anonymization and Pseudonymization | Data anonymization at Customer level optional for Customer | Partial (Individual CMS accounts excluded) | Partial (Individual CMS accounts excluded) |
| Data confidentiality | Access control measures Encryption at Acquia level | Yes Yes Yes | Yes Yes Yes |
| Data integrity | Anti-tampering technology (see Security Annex) | Yes | Yes |
| Data availability including restoring availability, restoring access to personal data, and data resilience | Business continuity and disaster recovery measures (see Security Annex) | Yes | N/A |
| Regular testing, assessing and evaluating of TOMs | Regular security and process reviews (see also Security Annex) | Yes | N/A |
Working toward SOC2 Type 2
Through the Product’s administration console and through the Customer’s own Drupal application, the Customer may manage,
update, retrieve, and erase individual Personal Data.
The retention of data in the Product is managed by the Customer and may be stored during the entire term of the Services. Latest 90
days after the end of the contractual term of the Services, Acquia will purge any customer data in the Services including personal
data from its systems.
The specific list of Acquia’s sub-processors is available from: www.acquia.com/about-us/legal/subprocessors
Any current Acquia customer with a data processing agreement in place with Acquia may subscribe to receive notifications of new or
changed sub-processors through the above website.
Data importer has implemented and will maintain appropriate administrative, physical, and technical safeguards for the protection of
the security, confidentiality and integrity of Personal Data uploaded to the Services, as described in the Acquia Security Annex
(available from https://www.acquia.com/sites/default/files/legal/acquia-security-annex.pdf) applicable to the specific Services
purchased by data exporter, as updated from time to time, and made available by data importer upon request. The data exporter is
wholly responsible for implementing and maintaining security and data administration within any data exporter applications,
configuration settings, or log settings used by data exporter in conjunction with the Services.
If this content did not answer your questions, try searching or contacting our support team for further assistance.
If this content did not answer your questions, try searching or contacting our support team for further assistance.