Data Processing Agreement
Last updated: January 23, 2025
This Data Processing Agreement ("DPA") forms part of the Wildfire Action Plan Terms of Service and applies to the extent that AACI Group, Inc. ("AACI", "we", "us", or "Processor") processes Personal Data on your behalf when you use the Wildfire Action Plan web application and related services (the "Service"). This DPA is designed to ensure that such processing is conducted in compliance with applicable data protection laws, including the EU/UK General Data Protection Regulation ("GDPR") and similar privacy laws, and to set out the responsibilities of both you and AACI.
For the purposes of this DPA, the terms "Personal Data", "Controller", "Processor", "Data Subject", "Processing", and "Personal Data Breach" shall have the meanings given to them in the GDPR or other applicable data protection law. Generally, "Personal Data" means any information relating to an identified or identifiable natural person, and "Processing" means any operation performed on such data (such as collection, use, storage, deletion, etc.).
1. Scope and Roles
Controller and Processor: This DPA applies only to the extent that AACI processes Personal Data on your behalf as part of providing the Service. In this context, you are acting as the Data Controller (the entity that determines the purposes and means of the processing of Personal Data), and AACI is acting as your Data Processor (the entity processing Personal Data on your behalf).
Applicability: Typically, this DPA will apply when you use the Service in the context of an organization, business, or other entity and upload or enter Personal Data about individuals (e.g., information about your employees, members, or other individuals) into the Service. It may not apply to personal use of the Service (for example, if you are an individual end-user creating a personal wildfire plan for your household, AACI is generally acting as a Controller for that data under our Privacy Policy). However, if required by law for individual consumers, AACI will extend similar protections to all Personal Data processed.
Both parties agree to comply with all applicable data protection laws in the performance of this DPA.
2. Customer (Controller) Obligations
As the Controller, you agree and warrant that:
Lawful Basis: You will ensure that you have a valid legal basis (e.g., consent, legitimate interests, contract necessity, etc.) for processing the Personal Data that you collect and instruct AACI to process via the Service. If consent is required, you will obtain it from the Data Subjects and document it as needed.
Compliance: You will comply with all laws and regulations applicable to your role as Controller, especially those related to data privacy and protection. This includes providing any required notices to Data Subjects (e.g., a privacy notice) and honoring Data Subject rights requests that pertain to data you control.
Instructions: You will only give AACI lawful, documented instructions regarding the processing of Personal Data. You shall ensure that your instructions to AACI (as conveyed through your use of the Service and this DPA) do not violate applicable laws. AACI will inform you if, in its opinion, an instruction infringes EU data protection laws (including the GDPR), and AACI will not be required to process any Personal Data in a way that it believes violates any law.
Accuracy and Minimization: The Personal Data you transfer to the Service shall be accurate and, where necessary, kept up to date. You should limit the Personal Data shared with AACI to what is necessary for the intended purpose. You agree not to upload any sensitive personal data (also known as "special categories of data" under GDPR, such as data about health, race, biometrics, etc.) or regulated data (like payment card info, social security numbers, personal health records) into the Service unless you have obtained prior written consent from AACI, due to the additional compliance requirements such data entails.
Data Subject Requests: You are responsible for handling any requests or inquiries from Data Subjects regarding their Personal Data that you control. For example, if an individual contacts you to access, correct, or delete their data, or to exercise any rights under privacy laws, you are responsible for responding to them. AACI will assist you as described in Section 3 below, but it is your obligation to determine the response and ensure compliance from the Controller side.
Use of Service in Compliance: You shall use the Service in a manner consistent with the Terms of Service and this DPA, and in a way that does not cause AACI to violate any applicable law. If a regulatory authority or law requires a change in how you use the Service or in AACI's processing of Personal Data, you agree to promptly work with AACI to implement such changes.
3. AACI (Processor) Obligations
When processing Personal Data on your behalf, AACI commits to the following obligations:
Processing on Documented Instructions: AACI will process Personal Data only on your documented instructions and for the following purposes: (a) to provide the Service in accordance with the Terms of Service and any specific settings or features you utilize (which constitute your instructions), (b) as further instructed by you via your use of the Service or in written form, and (c) to comply with other reasonable instructions provided by you (e.g., via support requests) that are consistent with the terms of the Agreement. AACI will not retain, use, disclose, or otherwise process the Personal Data for any purpose other than as instructed, nor for its own commercial purposes, except as permitted under applicable law. If any applicable law requires AACI to process Personal Data beyond your instructions (for example, if AACI is compelled by a legal order), AACI will notify you (unless legally prohibited from doing so) and will limit the processing to what is required by law.
Confidentiality: AACI will ensure that any personnel (employees, contractors, etc.) authorized to process Personal Data on our behalf are bound by strict confidentiality obligations. This obligation continues even after the engagement has ended. AACI ensures that access to Personal Data is limited to individuals who need the access to deliver the Service and who are subject to confidentiality agreements or professional obligations.
Security Measures: AACI will implement and maintain appropriate technical and organizational security measures to protect Personal Data from unauthorized or unlawful processing, and against accidental loss, destruction, damage, theft, alteration, or disclosure. These measures are outlined in our Privacy Policy (and can include encryption, access controls, pseudonymization, regular security assessments, etc.). Specifically, AACI will take into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risk to individuals to ensure a level of security appropriate to the risk, as required by GDPR Article 32. (Examples of measures include: using TLS encryption for data in transit, encrypting Personal Data at rest, maintaining up-to-date software and firewall protections, employee training on data security, and incident response planning.) AACI will regularly monitor compliance with these measures and will not materially decrease the overall security of the Service during the term of our agreement.
Data Breach Notification: In the event AACI becomes aware of a Personal Data Breach affecting Personal Data processed on your behalf, AACI will notify you without undue delay. Such notification will describe (to the extent feasible) the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed by AACI to address the breach and mitigate its effects. AACI will promptly investigate any such incident and provide you with updates as more information becomes available. We will cooperate with you in communicating to affected Data Subjects or regulatory authorities, as may be required, and in any remediation efforts. (It is understood that as Controller, you are responsible for determining whether to notify authorities and individuals, but AACI will assist you in meeting these obligations as needed.)
Assistance with Data Subject Rights: Taking into account the nature of the processing and the information available to us, AACI will assist you in fulfilling your obligation to respond to Data Subject requests to exercise their rights (such as access, rectification, erasure, restriction, data portability, objection, and not being subject to automated decision-making) under applicable data protection laws. Our Service provides features that allow you to retrieve, correct, or delete Personal Data (for example, you can access and edit information in the app, or delete user records). Where such functionality is not available or insufficient, upon your request AACI will make commercially reasonable efforts to help you access, correct, or delete Personal Data or to suppress processing of certain data, as needed. If AACI directly receives a request from a Data Subject of yours, we will promptly inform you and await your instruction (unless prohibited by law from informing you). AACI will not independently address Data Subject requests without your direction, except to acknowledge receipt of the request.
Assistance with Compliance and DPIAs: AACI will provide reasonable assistance to you in ensuring compliance with your obligations under Articles 32 to 36 of the GDPR (and similar obligations under other laws), which include: maintaining security of processing, notifying breaches to authorities and individuals, conducting Data Protection Impact Assessments (DPIAs) when required, and consulting with supervisory authorities. For example, AACI can provide you with relevant information about our processing activities and security measures for use in a DPIA, and we will assist in answering any regulator or auditor inquiries that you forward to us relating to the Service.
Subprocessing: AACI's obligations regarding engaging other processors (subprocessors) are set forth in Section 4 below. In summary, we will not share Personal Data with subprocessors unless they are bound by equivalent data protection obligations.
Data Return/Deletion: Upon termination or expiration of your account or upon your written request, AACI will delete or return to you all Personal Data processed on your behalf, except to the extent retention is required by applicable law. This is further described in our User Data Deletion Policy and the Terms. At your election, we can provide you with a copy of the data (in a common machine-readable format) before deletion. After confirming deletion, AACI will delete existing copies (including in backups, within a reasonable timeframe as per our data retention policy). If return or deletion of certain data is technically infeasible or prohibited by law, AACI will extend the protections of this DPA to that data and limit any further processing to only those purposes that make the return/deletion infeasible.
Records and Audit: AACI will maintain records of processing activities as required by GDPR Article 30(2) (for processors). This includes recording details such as the categories of processing carried out on behalf of each Controller, transfers of Personal Data, and a general description of technical and organizational security measures. We will make these records available to competent supervisory authorities on request.
4. Subprocessors
Use of Subprocessors: You authorize AACI to engage Subprocessors (other companies contracted by AACI to process Personal Data) as needed to support delivery of the Service. Common examples include cloud infrastructure providers (for data hosting), email delivery services, analytics services, and customer support software.
List of Subprocessors: AACI will maintain an up-to-date list of the Subprocessors involved in the processing of Personal Data for the Service. This list will be made available to you upon request (for example, by contacting us or through our website). It will include the identities of those Subprocessors and their functions.
New Subprocessors: AACI will inform you of any intended addition or replacement of Subprocessors by updating the list and, if practical, notifying you (e.g., via email or an in-app notification) prior to the change. If you have a reasonable basis to object to AACI's use of a new Subprocessor (for example, if using that Subprocessor would violate applicable law or weaken the protections for Personal Data), you must notify AACI promptly in writing within 10 days of learning of the change. We will then work with you in good faith to address your objection, which may include reviewing the Subprocessor's measures or finding an alternative solution. If we cannot resolve the objection to your reasonable satisfaction, you may have the right to terminate the Service (and this DPA) with respect to the impacted processing, and we will refund any prepaid fees for the period after termination.
Subprocessor Obligations: AACI will enter into a written agreement with each Subprocessor imposing data protection obligations that are no less protective than those set forth in this DPA (in particular, providing sufficient guarantees that the Subprocessor will implement appropriate technical and organizational measures to meet GDPR requirements). This includes obligations to process Personal Data only on AACI's instructions (which are effectively the same as your instructions to AACI), to keep data confidential, and to cooperate in providing data subjects' rights and security of data. Where the GDPR or equivalent laws apply, AACI will also ensure that any international data transfers by Subprocessors are done in compliance with Section 5 below.
Liability for Subprocessors: AACI remains fully liable to you for the performance of any Subprocessor that fails to fulfill its data protection obligations with respect to your Personal Data. In other words, if a Subprocessor we engage causes a breach or otherwise fails to protect Personal Data as required, AACI will be responsible to you as if the breach or failure was caused by AACI.
5. International Data Transfers
Because AACI is based in the United States, using our Service may involve transferring Personal Data to the U.S. (and potentially to other countries where we or our Subprocessors operate). The U.S. and these other countries may not have data protection laws equivalent to those in your jurisdiction (such as the EEA).
Transfers from EEA/UK/Switzerland: If you are subject to GDPR (or UK/Swiss equivalents) and the Personal Data that AACI processes on your behalf involves transfers from the European Economic Area, the United Kingdom, or Switzerland to countries which the European Commission (or relevant authority) has not deemed to have an adequate level of data protection, the following will apply:
We agree that such transfers will be governed by the appropriate Standard Contractual Clauses ("SCCs") as approved by the European Commission (or UK/Swiss authorities, as applicable). By entering into this DPA, you (as "data exporter") and AACI (as "data importer"), and any relevant Subprocessors, are deemed to have signed the applicable SCCs, which are hereby incorporated by reference. AACI will, upon request, provide a copy of the SCCs including the relevant Annexes (such as Annex I, II, III describing details of processing, technical measures, and Subprocessors) filled out to reflect the processing under this DPA. Where the SCCs apply, if there is any conflict between the SCCs and this DPA, the SCCs will prevail.
If the SCCs are replaced, updated, or supplemented (e.g., by the new EU/US Data Privacy Framework or UK addendums), the parties will work together promptly in good faith to comply with the new requirements. AACI may also adopt an alternative lawful transfer mechanism (such as Binding Corporate Rules or an approved certification) if available, in order to maintain compliance for cross-border data transfers.
Transfers to Other Jurisdictions: For other regions (e.g., Brazil under LGPD, Canada under PIPEDA, etc.), if Personal Data is transferred to a country that does not have adequate protections, AACI will ensure that such transfers are performed in compliance with applicable laws. This may involve obtaining your consent, utilizing contracts that mirror data protection obligations, or any other method prescribed by relevant law.
AACI will not "remote access" or transfer data to a jurisdiction solely for convenience without ensuring compliance with transfer requirements. Any access to Personal Data from outside of the country of origin by AACI or its Subprocessors will be done with appropriate safeguards in place.
6. Audits and Certifications
AACI will provide you with reasonable information and cooperation to demonstrate compliance with the obligations set forth in this DPA. Specifically:
Documentation: Upon written request, AACI will provide you with relevant documentation or summaries of audit reports (under NDA, if necessary) that verify our compliance with this DPA. For example, we might share executive summaries of third-party security audits, penetration testing results, or industry certifications (if we have them) that are applicable to the Service.
Audits: You (or an independent auditor mandated by you and acceptable to AACI, both acting reasonably) may perform an on-site inspection of AACI's applicable operations, policies, and technical measures to audit compliance with this DPA and applicable data protection law, up to once annually. This audit must be conducted during regular business hours, with reasonable advance notice to AACI (at least 30 days), and subject to reasonable confidentiality procedures. You will bear any costs of the audit. AACI will cooperate by providing access to relevant knowledgeable personnel and records. The scope of the audit will be limited to documents and facilities relevant to the processing of Personal Data under this DPA.
Minimize Disruption: Both parties will work together to ensure that audit activities are not disruptive to AACI's business and are conducted efficiently. Any findings from the audit will be discussed and, if any material non-compliance is identified, AACI will take prompt action to address those issues.
Regulatory Audits: If a regulatory authority (with jurisdiction over you) wishes to conduct an audit of the processing activities covered by this DPA, AACI will cooperate to the extent legally required. You and AACI will attempt to coordinate any audits or inspections by regulators so that they are conducted in a manner that protects the confidentiality of other customers and the security of our systems.
7. Data Subject Request Handling
As noted in Section 3, AACI will assist with Data Subject Requests. Here we clarify the process: If AACI receives a request from a Data Subject directly (and the request can be identified as pertaining to data you control), AACI will:
- Promptly forward the request to you and not respond directly (unless required by law to respond, in which case AACI will inform you, if legally permitted).
- Provide you with relevant information and tools (if available) that would help you fulfill the request. For example, if a user requests deletion of their data that you control within the Service, we will either direct them to contact you or confirm with you how to handle it; if you instruct us to delete data, we will do so.
- Await your instructions on how to proceed, and, where possible, enable you to self-serve the request (like using the app interface to export or delete data). If you need AACI to export data in a special format or perform an action, we will do so upon your documented request.
You are responsible for the ultimate decision on handling the Data Subject's request and for communicating with the Data Subject, except where law requires AACI to communicate directly (rare cases).
8. Liability and Indemnification
Liability Cap: Each party's liability arising out of or related to this DPA (whether in contract, tort or under any other theory of liability) is subject to the limitations and exclusions of liability set forth in the Terms of Service. You agree that any liability incurred by AACI in connection with Personal Data processed under this DPA (including any costs, claims, fines, or damages due to your instructions or compliance failures) will count toward and not exceed the limitations of liability that apply under the main Terms. In no event will either party be liable for indirect, consequential, punitive, or special damages to the extent that such limitations are permitted by law, and AACI's total aggregate liability under this DPA will not exceed the amount you paid (if any) for the Service in the 12 months prior to the event giving rise to the liability.
Indemnity: You agree to indemnify and hold AACI harmless from damages, fines, and expenses (including reasonable legal fees) that AACI incurs due to your breach of this DPA or your failure to comply with data protection laws as a Controller. For example, if you violate a law and it causes AACI to also be in violation or incur costs, you will cover those costs. AACI likewise indemnifies you for damages or fines incurred due to AACI's breach of this DPA or failure to comply with applicable data protection laws (to the extent AACI acted outside of your lawful instructions or was grossly negligent or engaged in willful misconduct).
9. Term and Termination of the DPA
This DPA commences once you agree to it (which happens automatically when you agree to the Terms of Service and use the Service in a manner that involves processing Personal Data on your behalf) and remains in effect as long as AACI processes Personal Data on your behalf. If you terminate your use of the Service and delete your account, or if the Terms of Service are terminated, this DPA will automatically terminate after the processing of Personal Data is complete.
Upon termination of the DPA, AACI will ensure that your Personal Data is deleted or returned in accordance with Section 3 (Data Return/Deletion) above. The obligations in this DPA that by their nature should survive termination (such as confidentiality, limitations of liability, and any provisions required to interpret or enforce the DPA) will remain in effect.
10. Miscellaneous Provisions
Confidentiality of DPA: This DPA (and any records or information related to it, such as audit reports) shall be considered AACI's confidential information. You may not disclose it to third parties without AACI's consent, except as required by law or to your legal advisers or auditors who are bound to confidentiality.
Conflict with Other Agreements: In the event of any conflict between the provisions of this DPA and the Terms of Service or other agreements between the parties, the provisions of this DPA shall prevail with respect to the parties' data protection obligations for Personal Data. However, the Terms of Service remain in effect and apply to matters beyond data protection.
Variations: No modification of this DPA is effective unless agreed in writing (including electronic form) by both parties, except that updates to this DPA may occur as described in the Terms of Service (e.g., if we notify you of changes to these data protection terms and you continue to use the Service).
Severability: If any provision of this DPA is found to be invalid or unenforceable, the remainder of this DPA shall remain in full force, and the invalid provision shall be either (i) amended as necessary to ensure its validity and enforceability while preserving the intent of the provision, or (ii) if it cannot be amended, construed in a manner as if the invalid part were not included.
Governing Law: This DPA is governed by the same governing law and dispute resolution terms as set forth in the Terms of Service, except to the extent that mandatory data protection laws (like GDPR) require otherwise.
Entire Agreement: This DPA and the Terms of Service (including all applicable policies like the Privacy Policy) together constitute the entire agreement between the parties with respect to the subject matter and supersede any prior agreements, understandings, or communications, written or oral, relating to processing of Personal Data. In case of ambiguity between this DPA and any related agreements, this DPA will be interpreted in a manner that allows both to be effective to the extent possible.
11. Contact and Acceptance
By using the Wildfire Action Plan Service and agreeing to the Terms of Service, you are deemed to have agreed to this DPA. Each party's acceptance of the Terms of Service (whether by click-through acceptance or other agreement) shall constitute signature and acceptance of this DPA, to the extent applicable.
If you have questions about this DPA or need to reach out for any data protection matters, you can contact:
AACI Group, Inc. – Data Protection Officer / Privacy Team
Email: legal@wildfireactionplan.com
Address: 2001 Clayton Road, Suite 200, Concord, CA 94520
Both AACI and you (the Customer) acknowledge and agree to the terms of this Data Processing Agreement as of the date of your acceptance of the Wildfire Action Plan Terms of Service.