Last revision of this Product Notice: [v1.2 – 30 June 2025 – AI details added to Processing Operations]
Prior version(s) of this Product Notice: [v1.1 – 17 May 2021 – hyperlinks updated]
[v1.0 – 05 March 2021 – initial version]
This Product Notices describes the privacy relevant aspects of the above-mentioned Acquia product/services.
For details about these Products, please refer to the Product Description available online at https://docs.acquia.com/guide.
The objective of Processing of Personal Data by data importer is the performance of the Services pursuant to the Agreement.
* (n/a = not applicable)
** (optional; depends on the Customer’s configuration of the system, the connection to other systems, and the categories chosen by the Customer to be collected from Third Party Users)
Categories of Personal Data | Categories of Data Subjects | Purpose of Processing | Categories of Data Recipients | Needed for Core Features | Processing Location | Acquia Inc. acts as Processor | |
Through the configuration, design, and administration of their own CDP instance, Customer in its sole discretion determines and controls the categories of data subjects collected by their CDP instance. Customer has full access and autonomy over what types of data is tracked and has access to this data and can manipulate it in various ways. Primarily, the categories of Personal Data could be individual identifiers, contact details, online identifiers, network activity, location data, travel data, expense and financial data, browsing information, and any sensitive data categories. | Through the configuration, design, and administration of their own CDP instance, Customer in its sole discretion determines and controls the categories of data subjects collected by their CDP instance. Customer has full access and autonomy over what types of data is tracked and has access to this data and can manipulate it in various ways. Primarily, the categories of Data Subjects could be Customer’s end-users including visitors to Customer’s website, online shop, or physical store. | Provision of the Services by Acquia to Customer | Customer’s personnel | Yes | Depends on the data centre location chosen by customer; data collected in a given region will exist only within that region. Subprocessors, Support: see Acquia Affiliates | Yes | |
Objective | Technology / Measure | Data at Rest | Data in Transit |
Anonymization and Pseudonymization | Data anonymization at Customer level optional for Customer | Yes | Yes |
Data confidentiality | Access control measures | Yes | Yes |
Encryption at customer level | No | No | |
Encryption at Acquia level (see Security Annex and Product Description) | Yes | Yes | |
Data integrity | Ant-tampering technology (see Security Annex) | Yes | Yes |
Data availability including restoring availability, restoring access to personal data, and data resilience | Business continuity and disaster recovery measures (see Security Annex) | Yes | Yes |
Regular testing, assessing and evaluating of TOMs | Regular security and process reviews (see also Security |
Personal data is retained at the Customer’s discretion. By default, data retention cycles exist only for time series data (e.g. transactions and events), but not other personal data (e.g. email address and name).
The specific list of Acquia’s sub-processors is available from: www.acquia.com/about-us/legal/subprocessors
Any current Acquia customer with a data processing agreement in place with Acquia may subscribe to receive notifications of new or changed sub-processors through the above website.
Data importer has implemented and will maintain appropriate administrative, physical, and technical safeguards for the protection of the security, confidentiality and integrity of Personal Data uploaded to the Services, as described in the Acquia Security Annex (available from https://www.acquia.com/about-us/legal/gdpr) applicable to the specific Services purchased by data exporter, as updated from time to time, and made available by data importer upon request. The data exporter is wholly responsible for implementing and maintaining security and data administration within any data exporter applications, configuration settings, or log settings used by data exporter in conjunction with the Services.
Annex)
Yes |
Yes |
If this content did not answer your questions, try searching or contacting our support team for further assistance.
Annex)
Yes |
Yes |
If this content did not answer your questions, try searching or contacting our support team for further assistance.