* (n/a = not applicable)
** (optional; depends on the Customer’s configuration of the system, the connection to other systems, and the categories chosen by the Customer to be collected from Third Party Users)
| Categories of Personal Data | Categories of Data Subjects | Purpose of Processing | Categories of Data Recipients | Needed for Core Feature s | Proce ssing Locati on | Acquia Inc. acts as Processor |
|---|---|---|---|---|---|---|
| Website usage data (e.g., URLs visited, actions taken within the platform) | Users of the Acquia SEO platform | To enable the R&D team to improve the platform | Acquia Inc. and its sub-process ors | Yes | US | Yes |
| Search query data entered by users | Users of the Acquia SEO platform | To facilitate keyword research and competitive analysis | Acquia Inc. and its sub-process ors | Yes | US | Yes |
| Competitive intelligence data (data about competitor websites and performance) | Users of the Acquia SEO platform | To enable competitive research features in the platform | Acquia Inc. and its sub-process ors | Yes | US | Yes |
| User-specified keywords | Users of the Acquia SEO platform | To monitor and report on search engine rankings | Acquia Inc. and its sub-process ors | Yes | US | Yes |
| Objective | Technology / Measure |
|---|---|
| Anonymization and Pseudonymization | Customers can limit collection of personal data (e.g., by anonymizing user IPs or avoiding entry of PII). Minimal personal data (e.g., names, emails) is collected for user access control only. |
| Data confidentiality | TLS encryption for data in transit, AES-256 encryption at rest, role-based access control (RBAC), strict access controls, and VPN/firewall policies |
| Data integrity | Checksums, audit logging, version control, secure deployment pipelines (CI/CD), automated test coverage, and secure software development lifecycle (SDLC). |
| Data availability including restoring availability, restoring access to personal data, and data resilience | Redundant storage, automated backups, disaster recovery plans (DRP), high availability (HA) architecture, and RPO/RTO testing |
| Regular testing, assessing and evaluating of TOMs | Annual ISO 27001 audits, SOC 2 Type II assessments, internal ISMS reviews, vulnerability scanning, red team exercises, and penetration testing |
Conductor maintains ISO 27001:2022 and SOC 2 Type II
Customers may manage, update, retrieve, or request the erasure of individual Personal Data with the support of Acquia and Conductor, as applicable.
Conductor retains Personal Data only for as long as it is necessary to fulfill the purposes for which it was collected, including to provide the services, comply with legal obligations, resolve disputes, and enforce agreements. Data retention periods are defined in accordance with Conductor’s internal Data Retention Policy, and Customer data may be deleted or anonymized upon request or at the end of the contractual relationship, subject to applicable legal and regulatory requirements.
The specific list of Acquia’s sub-processors is available from: www.acquia.com/about-us/legal/subprocessors. Any current Acquia customer with a data processing agreement in place with Acquia may subscribe to receive notifications of new or changed sub-processors through the above website.
Data importer has implemented and will maintain appropriate administrative, physical, and technical safeguards for the protection of the security, confidentiality and integrity of Personal Data uploaded to the Services, as described in the Acquia Security Annex (available from https://www.acquia.com/about-us/legal/gdpr) applicable to the specific Services purchased by data exporter, as updated from time to time, and made available by data importer upon request. The data exporter is wholly responsible for implementing and maintaining security and data administration within any data exporter applications, configuration settings, or log settings used by data exporter in conjunction with the Services.
If this content did not answer your questions, try searching or contacting our support team for further assistance.
| Acquia Inc. and its sub-process ors |
| Yes |
| US |
| Yes |
If this content did not answer your questions, try searching or contacting our support team for further assistance.