1. Purpose
This DPA governs processing of personal data by Redefine Web on behalf of clients, in compliance with GDPR, CCPA, and similar privacy frameworks.
2. Scope of processing
We process personal data solely to deliver the services described in the client’s signed engagement, and only for the duration of that engagement.
3. Sub-processors
Current sub-processors are listed on this page and updated within 30 days of any change. Clients may object to new sub-processors within 15 days.
4. Security measures
All client data is encrypted at rest and in transit, access is restricted to named team members with two-factor authentication, and audit logs are retained for 12 months.
5. Data subject rights
We assist clients in responding to data subject requests (access, deletion, rectification) within 15 business days.
6. Contact
Email privacy@redefineweb.com.