Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the CDN.MN Terms of Service or another agreement governing Customer's use of CDN.MN (the "Agreement") between NicNames, Inc., a Delaware corporation ("NicNames" or "Processor"), and the Customer identified in the Agreement ("Customer" or "Controller").
This DPA applies where NicNames processes Personal Data on Customer's behalf in connection with the Service and data-protection law requires processor, service-provider, contractor, or similar terms.
By accepting the Agreement or using the Service to process Personal Data, Customer accepts this DPA.
1. Definitions
Applicable Data Protection Law means privacy, data-protection, and data-security laws applicable to the Processing, including, where applicable, the GDPR, UK GDPR, Swiss Federal Act on Data Protection, California Consumer Privacy Act as amended, and other U.S. state comprehensive privacy laws.
Controller, Data Subject, Personal Data, Personal Data Breach, Processing, and Processor have the meanings given under Applicable Data Protection Law. "Personal Data" includes "personal information" and analogous protected information.
Customer Personal Data means Personal Data contained in Customer Content or CDN request and delivery data that NicNames Processes on Customer's behalf.
GDPR means Regulation (EU) 2016/679.
Restricted Transfer means a transfer of Personal Data that requires an approved transfer mechanism under Applicable Data Protection Law.
Standard Contractual Clauses or SCCs means the European Commission standard contractual clauses adopted by Implementing Decision (EU) 2021/914.
Subprocessor means another Processor engaged by NicNames to Process Customer Personal Data.
UK Addendum means the then-current International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the United Kingdom Information Commissioner's Office.
2. Scope and roles
2.1 Roles
Customer is the Controller or business, and NicNames is the Processor or service provider, for Customer Personal Data.
If Customer acts as a Processor for another Controller, Customer appoints NicNames as a subprocessor and represents that it has authority to do so and to give the instructions in this DPA.
2.2 Customer instructions
NicNames will Process Customer Personal Data only:
- to provide, secure, support, meter, and improve the Service as permitted by the Agreement;
- according to Customer's documented configuration and use of the Service;
- according to additional documented instructions agreed by the parties; and
- as required by law.
The Agreement, Customer's configuration, and Customer's documented requests are Customer's instructions.
If NicNames believes an instruction violates Applicable Data Protection Law, it will notify Customer unless prohibited by law and may suspend the affected Processing until the parties resolve the issue.
2.3 Customer responsibilities
Customer is responsible for:
- the lawfulness of Customer Personal Data and instructions;
- providing required notices;
- obtaining required consent or another lawful basis;
- honoring Data Subject rights;
- configuring URL paths, query strings, domains, access, retention, logging, and security appropriately;
- ensuring the Service is suitable for the Personal Data submitted;
- avoiding unsupported sensitive or regulated data; and
- maintaining a lawful relationship with Customer's end users, clients, and Controllers.
3. Details of Processing
The subject matter, duration, nature, purpose, categories of Data Subjects, and types of Personal Data are described in Annex I.
4. Confidentiality
NicNames will ensure that persons authorized to Process Customer Personal Data:
- are subject to an appropriate duty of confidentiality;
- receive access only where necessary for their role; and
- Process Customer Personal Data only under NicNames' instructions unless required by law.
5. Security
5.1 Measures
NicNames will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
The current principal measures are described in Annex II.
5.2 Customer security obligations
Customer must use available security controls, protect credentials, review Authorized Users and Agents, keep Origins and integrations secure, avoid secrets in public URLs, and maintain backup and rollback procedures.
5.3 Changes to measures
NicNames may update security measures if the update does not materially reduce the overall protection of Customer Personal Data.
6. Personal Data Breach
NicNames will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data and, where reasonably practicable, within seventy-two hours after confirmation.
The notice will include available information concerning:
- the nature of the breach;
- categories of affected data and Data Subjects;
- likely consequences;
- measures taken or proposed;
- a contact point; and
- information reasonably needed by Customer to meet notification obligations.
NicNames may provide information in phases as it becomes available.
Notification does not constitute an admission of fault or liability.
Customer is responsible for notifying regulators, Data Subjects, clients, or others unless Applicable Data Protection Law assigns that obligation directly to NicNames.
7. Data Subject requests
Taking into account the nature of Processing, NicNames will provide reasonable assistance to Customer with requests to access, correct, delete, restrict, object, or port Customer Personal Data.
If NicNames receives a request relating primarily to Customer-controlled data, it may direct the requester to Customer and notify Customer where appropriate.
Customer is responsible for responding to the request. NicNames may charge reasonable costs for extraordinary assistance not included in the Service, where permitted by law and agreed in advance.
8. Regulatory assistance
Taking into account the nature of Processing and information available, NicNames will provide reasonable assistance with:
- security obligations;
- breach notifications;
- data-protection impact assessments;
- prior consultations with regulators; and
- inquiries concerning NicNames' Processing.
Customer will reimburse reasonable costs for extraordinary assistance not caused by NicNames' breach, subject to advance agreement.
9. Subprocessors
9.1 General authorization
Customer gives NicNames general written authorization to engage Subprocessors.
The current Subprocessor List is incorporated into this DPA.
9.2 Subprocessor obligations
NicNames will impose data-protection obligations on each Subprocessor that are no less protective in substance than the obligations applicable to NicNames under this DPA, to the extent relevant to the Subprocessor's services.
NicNames remains responsible for its Subprocessors' performance of those obligations to the extent required by Applicable Data Protection Law.
9.3 Changes and objections
NicNames will publish an updated Subprocessor List and provide at least fifteen days' notice before a new Subprocessor begins Processing Customer Personal Data, except where urgent replacement is reasonably necessary for security or service continuity.
Customer may object during that period on reasonable data-protection grounds by emailing privacy@cdn.mn and explaining the concern.
The parties will attempt in good faith to resolve the objection. If no reasonable alternative is available, Customer may stop using the affected Service and terminate it without penalty before the new Subprocessor begins Processing. This is Customer's sole remedy for an unresolved Subprocessor objection.
10. International transfers
10.1 General
NicNames may Process Customer Personal Data in the United States and other countries where NicNames or its Subprocessors operate.
NicNames will use a lawful transfer mechanism where required.
10.2 European Economic Area transfers
For a Restricted Transfer subject to the GDPR where no adequacy decision or other valid transfer mechanism applies, the SCCs are incorporated as follows:
- Module Two (Controller to Processor) applies when Customer is a Controller;
- Module Three (Processor to Processor) applies when Customer is a Processor;
- Clause 7, the optional docking clause, applies;
- in Clause 9, Option 2 applies with a fifteen-day notice period;
- in Clause 11, the optional independent dispute-resolution language does not apply;
- in Clause 17, Option 1 applies and the governing law is the law of Ireland;
- under Clause 18, the courts of Ireland have jurisdiction;
- Annex I is completed by Annex I of this DPA;
- Annex II is completed by Annex II of this DPA; and
- Annex III is completed by the Subprocessor List.
If the parties' roles require a different SCC module, the legally appropriate module applies.
10.3 United Kingdom transfers
For a Restricted Transfer subject to the UK GDPR, the SCCs as completed above apply together with the UK Addendum.
For purposes of the UK Addendum:
- the parties' details are those in the Agreement and Annex I;
- the selected SCC module is as stated above;
- the information in the tables is completed by this DPA;
- either party may end the UK Addendum as permitted by it; and
- NicNames may update the incorporated form to remain consistent with mandatory UK requirements.
10.4 Switzerland
For transfers subject to Swiss data-protection law, references in the SCCs to the GDPR and European Union will be interpreted to include the applicable Swiss law and Switzerland as required, and the Swiss Federal Data Protection and Information Commissioner will be the competent supervisory authority where applicable.
10.5 Transfer assessments
NicNames will provide information reasonably necessary for Customer to assess a Restricted Transfer, subject to confidentiality, security, and legal limitations.
11. U.S. state privacy terms
To the extent NicNames Processes Customer Personal Data as a service provider, contractor, or processor under U.S. state privacy law:
- NicNames Processes the data only for the limited and specified purposes in the Agreement and Customer's instructions.
- NicNames will not sell or share Customer Personal Data for cross-context behavioral advertising.
- NicNames will not retain, use, or disclose Customer Personal Data outside the direct business relationship except as permitted by Applicable Data Protection Law.
- NicNames will not combine Customer Personal Data with personal information received from another person or from NicNames' own direct interaction with the Data Subject, except as permitted by law.
- NicNames will provide the same level of privacy protection required of Customer for the covered Processing.
- Customer may take reasonable and appropriate steps to help ensure that NicNames uses Customer Personal Data consistently with Customer's obligations.
- NicNames will notify Customer if it determines it can no longer meet an applicable obligation.
- Customer may take reasonable and appropriate steps to stop and remediate unauthorized use.
- NicNames will require covered Subprocessors to meet applicable service-provider, contractor, or processor requirements.
12. Return and deletion
During the term, Customer may use available export and deletion functions or request assistance.
Upon termination or Customer's documented request, NicNames will delete or return Customer Personal Data as required by the Agreement and Applicable Data Protection Law, unless law requires retention.
Deletion is subject to:
- edge invalidation and propagation;
- operational cache removal;
- backup rotation;
- billing and tax retention;
- security and abuse records;
- legal holds; and
- data that has been aggregated or deidentified.
The CDN.MN Data Retention Schedule provides additional detail.
13. Audits and information
13.1 Information
Upon reasonable request, NicNames will make available information necessary to demonstrate compliance with this DPA, which may include:
- security documentation;
- architecture and control summaries;
- Subprocessor information;
- relevant third-party audit or assessment reports when available; and
- responses to a reasonable security questionnaire.
13.2 Audit conditions
If information under Section 13.1 is insufficient and Applicable Data Protection Law requires an audit, Customer may conduct one audit in a twelve-month period, unless a regulator or confirmed Personal Data Breach requires more.
The audit must:
- be scheduled with at least thirty days' notice;
- occur during normal business hours;
- avoid disruption;
- be conducted by an independent auditor bound by confidentiality;
- exclude access to other customers' data, source code, security secrets, and information that would create risk;
- be limited to systems relevant to Customer Personal Data; and
- be at Customer's expense unless the audit identifies a material breach by NicNames.
NicNames may satisfy an on-site request with a remote review or independent report where legally sufficient.
14. Government requests
If NicNames receives a legally binding request for Customer Personal Data, it will:
- review the request for legal validity;
- disclose only data legally required;
- challenge overbroad or unlawful requests where reasonable;
- notify Customer where legally permitted; and
- document the response as appropriate.
15. Limitation and priority
The liability limits and exclusions in the Agreement apply to this DPA to the maximum extent permitted by Applicable Data Protection Law.
If this DPA conflicts with the Agreement on processing of Customer Personal Data, this DPA controls. The SCCs control over this DPA where the SCCs require it.
16. Term
This DPA remains effective while NicNames Processes Customer Personal Data.
17. Contact
Privacy and DPA matters:
privacy@cdn.mn
NicNames, Inc. Attention: Privacy 131 Continental Drive, Suite 301 Newark, Delaware 19713 United States
Annex I - Description of Processing
A. Parties
Data exporter / Customer: The Customer identified in the Agreement. Customer's contact information is maintained in its CDN.MN Account or Order.
Data importer / Processor: NicNames, Inc., 131 Continental Drive, Suite 301, Newark, Delaware 19713, United States; privacy@cdn.mn.
B. Categories of Data Subjects
Depending on Customer's use:
- Customer employees, contractors, representatives, and Authorized Users;
- Customer clients and their personnel;
- visitors and users of Customer websites, applications, or services;
- persons whose Personal Data appears in image metadata, URLs, request headers, Customer Content, or support records;
- Agent users and approvers; and
- persons involved in abuse, infringement, legal, or security matters.
C. Categories of Customer Personal Data
Depending on configuration:
- IP address;
- approximate geographic region;
- URL, hostname, path, and query information;
- timestamp;
- user agent, browser, device, protocol, referrer, and request headers;
- response status, bytes, cache status, latency, and diagnostic information;
- images and embedded metadata, including EXIF or location metadata;
- Site, Workspace, user, and Agent identifiers;
- Origin and domain information;
- Agent instructions, scopes, approvals, audit events, and tool activity;
- repository and deployment metadata;
- support and communication information; and
- other Personal Data that Customer submits in supported Customer Content.
D. Sensitive Personal Data
The Service is not intended for highly sensitive or specially regulated data unless the parties expressly agree in an Order. Customer must not place credentials, payment-card data, health data, government identifiers, or other secrets in public URLs.
E. Frequency and nature
Processing is continuous or event-driven according to requests, cache operations, configuration, Agent activity, analytics, and support.
Operations may include collection, transmission, retrieval, validation, transformation, compression, resizing, caching, storage, delivery, metering, analysis, support, deletion, and security monitoring.
F. Purpose
To provide, secure, meter, support, troubleshoot, and maintain CDN.MN according to Customer's instructions.
G. Duration
For the term of the Agreement and the deletion, retention, backup, legal, and security periods described in the Privacy Policy and Data Retention Schedule.
Annex II - Technical and Organizational Measures
NicNames maintains measures designed for the risk and nature of the Service, including:
1. Access and identity
passwordless, rate-limited email-code authentication;
keyed protection of low-entropy one-time codes;
server-side, revocable sessions;
secure, HttpOnly, host-restricted session cookies;
least-privilege staff and service access;
separate production and nonproduction environments;
scoped and expiring Agent tokens;
cryptographic hashes of session, device, and Agent tokens;
explicit approval for designated sensitive actions; and
administrative access logging.
2. Network and Origin security
TLS for public Service connections;
managed certificates for supported delivery hostnames;
private network segmentation;
restricted infrastructure access;
Origin ownership verification;
private, loopback, link-local, reserved, and metadata-address blocking;
DNS resolution and connect-time validation;
redirect revalidation;
restricted methods, protocols, and ports; and
origin-secret controls between edge and application services.
3. Tenant and cache isolation
tenant-scoped cache identity;
normalized transformation parameters;
bounded width, DPR, format, and quality variants;
separate Workspace and Site authorization;
fail-closed behavior for unknown or suspended hostnames;
purge and invalidation controls; and
configuration history and rollback.
4. Processing safety
encoded source-size limits;
decoded-memory and pixel limits;
output-pixel limits;
processing timeout;
bounded concurrency;
same-variant single-flight behavior;
per-tenant and per-IP rate limits;
input type validation; and
structured error handling.
5. Logging, monitoring, and response
audit events for material human and Agent actions;
application and infrastructure logging;
raw CDN access logs;
service-health and resource alarms;
security and abuse monitoring;
incident-response procedures;
production release controls; and
backup and recovery processes.
6. Data protection
encryption at rest for managed storage and databases where supported;
TLS in transit;
secrets stored in managed secret storage;
payment-card processing delegated to a payment processor;
retention and lifecycle controls;
data export and deletion procedures; and
confidentiality obligations for authorized personnel.
Annex III - Subprocessors
The current CDN.MN Subprocessor List is incorporated into this DPA and published as a separate document.