Data Processing Agreement
Last updated: 26 May 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Agreement”) between LLC “CR Visual Lab” (“CR Maps”, “we”, the “Processor”) and the customer (“Customer”, the “Controller”) and applies to the processing of personal data carried out by CR Maps on the Customer’s behalf in the course of providing the Service. Terms not defined here have the meaning given in the Terms of Service.
1. Definitions
- “Data Protection Laws” — the GDPR (Regulation (EU) 2016/679) and applicable Ukrainian data-protection legislation, as amended.
- “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach”, “Supervisory Authority” — as defined in the GDPR.
- “Sub-processor” — any third party engaged by CR Maps to process Personal Data on the Customer’s behalf.
- “Standard Contractual Clauses” / “SCCs” — the clauses approved by the European Commission for transfers of personal data to third countries (Decision 2021/914), Module Two (controller-to-processor).
- “Customer Personal Data” — Personal Data processed by CR Maps on the Customer’s behalf under the Agreement (e.g., enquiries submitted through the Customer’s interactive maps).
2. Roles and scope of processing
2.1. The Customer is the Controller and CR Maps is the Processor of Customer Personal Data. The details of processing (subject matter, duration, nature and purpose, types of data and categories of data subjects) are set out in Schedule A.
2.2. CR Maps processes Customer Personal Data only on the Customer’s documented instructions, including as set out in the Agreement and this DPA, unless required to do otherwise by law (in which case CR Maps informs the Customer, unless legally prohibited).
2.3. CR Maps does not control, and is generally unaware of, the content of the Personal Data the Customer chooses to process through the Service.
3. Compliance with laws
Each party complies with its obligations under Data Protection Laws. The Customer is responsible for the lawfulness of the Personal Data it provides and of its processing instructions.
4. Processor obligations
CR Maps will:
- (a) process Customer Personal Data only as described in clause 2;
- (b) ensure that persons authorised to process the data are bound by confidentiality;
- (c) implement appropriate technical and organisational security measures (Annex II);
- (d) taking into account the nature of processing, assist the Customer in responding to Data Subject requests (clause 9) and in complying with the Controller’s obligations under Articles 32–36 GDPR (security, breach notification, DPIAs, prior consultation);
- (e) notify the Customer of a Personal Data Breach in accordance with clause 10;
- (f) make available information necessary to demonstrate compliance and allow for audits (clause 12);
- (g) on termination, return or delete Customer Personal Data (clause 14).
5. Customer obligations
- (a) ensure it has a lawful basis and any required consents for the processing it instructs;
- (b) provide notice to Data Subjects as required by Data Protection Laws;
- (c) ensure its instructions to CR Maps are lawful;
- (d) be responsible for the accuracy, quality and legality of Customer Personal Data.
6. Confidentiality
CR Maps treats Customer Personal Data as confidential and ensures its personnel are subject to appropriate confidentiality obligations.
7. Security
CR Maps implements and maintains the technical and organisational measures described in Annex II, designed to ensure a level of security appropriate to the risk.
8. Sub-processors
8.1. The Customer grants CR Maps general authorisation to engage Sub-processors to process Customer Personal Data, provided CR Maps imposes data-protection obligations on each Sub-processor substantially equivalent to those in this DPA.
8.2. The categories of Sub-processors currently engaged are listed in Schedule B; the current list of specific Sub-processors is available to the Customer on request.
8.3. CR Maps will give the Customer at least ten (10) business days’ notice (for example, by email or by updating Schedule B) before adding or replacing a Sub-processor. The Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Customer’s sole remedy is to terminate the affected Service.
8.4. CR Maps remains responsible for its Sub-processors’ performance of their data-protection obligations.
9. Data subject requests
CR Maps will, without undue delay, notify the Customer if it receives a request from a Data Subject to exercise their rights (access, rectification, erasure, restriction, portability, objection). CR Maps will not respond to such a request itself except on the Customer’s documented instructions or as required by law, and will provide reasonable assistance to the Customer in responding.
10. Personal Data Breach notification
CR Maps will notify the Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, its likely consequences, and the measures taken or proposed. CR Maps will take reasonable steps to mitigate the breach.
11. Assistance
Taking into account the nature of processing and the information available to it, CR Maps provides the Customer with reasonable assistance with data protection impact assessments and prior consultations with Supervisory Authorities under Articles 35–36 GDPR.
12. Audits
CR Maps makes available information reasonably necessary to demonstrate compliance with this DPA. Where required by Data Protection Laws or a Supervisory Authority, the Customer (or a mandated independent auditor bound by confidentiality) may audit CR Maps’ relevant processing, at the Customer’s expense, on reasonable prior written notice, during business hours, and without unreasonable disruption to CR Maps’ operations.
13. International transfers
13.1. Ukraine is the primary place of processing. Where CR Maps transfers Customer Personal Data from the EEA, the UK or Switzerland to a country without an adequacy decision, such transfer is governed by the Standard Contractual Clauses (Module Two, controller-to-processor), the UK International Data Transfer Addendum and/or the Swiss adaptations, as applicable, which are incorporated into this DPA by reference.
13.2. The same safeguards apply to onward transfers by Sub-processors.
14. Return and deletion of data
On termination of the Agreement, or earlier on the Customer’s written request, CR Maps will return or securely delete Customer Personal Data within a reasonable period, unless retention is required by law. CR Maps may retain anonymised or aggregated data that no longer identifies a Data Subject.
15. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
16. Term
This DPA takes effect when the Customer accepts the Agreement and remains in force for as long as CR Maps processes Customer Personal Data, and thereafter until such data is returned or deleted.
17. Governing law
This DPA is governed by the laws of Ukraine. Where the SCCs apply, the governing law and forum provisions of the SCCs prevail for matters within their scope.
18. Order of precedence
In case of conflict between this DPA and the rest of the Agreement regarding the processing of Personal Data, this DPA prevails. In all other respects the Agreement remains in full force.
Schedule A — Details of Processing
- Subject matter: provision of the CR Maps interactive-map Service to the Customer.
- Duration: for the term of the Agreement and until data is returned or deleted.
- Nature and purpose: hosting, storage and processing of enquiries and related data submitted through the Customer’s interactive maps, in order to provide the Service.
- Types of Personal Data: identification and contact data of the Customer’s visitors/leads (e.g., name, email, phone, message) and related metadata.
- Categories of Data Subjects: the Customer’s website visitors and prospective buyers who submit enquiries.
- Special categories: none intended; the Customer must not submit special-category data unless separately agreed.
Schedule B — Sub-processors
CR Maps engages Sub-processors in the following categories:
- cloud hosting / infrastructure provider(s);
- email / message-delivery provider(s);
- authentication provider(s) (sign-in).
The current list of specific Sub-processors, including their names and locations, is available to the Customer on request to info@createrender.com.
Annex II — Technical and Organisational Measures
CR Maps maintains measures including:
- access controls and role-based access to systems holding Personal Data;
- encryption of Personal Data in transit;
- logging and monitoring of access;
- regular backups and resilience measures;
- confidentiality obligations for personnel with access;
- incident-response procedures and periodic review of these measures.