ActiveLayer Data Processing Addendum

This DPA explains how ActiveLayer processes personal data contained in form submissions, comments, reviews, registrations, and related spam-detection signals on behalf of Customers.

Last updated: September 23, 2026

Contents

1. Scope and incorporation

This Data Processing Addendum ("DPA") forms part of the ActiveLayer Terms of Service at activelayer.com/terms or another written agreement governing Customer’s use of the Services (the "Agreement"). It applies when ActiveLayer processes Customer Personal Data on Customer’s behalf.

By accepting the Agreement or using the Services to process Customer Personal Data, Customer enters into this DPA on behalf of itself and any Customer Affiliate authorized to use the Services. If there is a conflict, the following order of precedence applies: first, the SCCs or other applicable international transfer terms; second, this DPA; and third, the Agreement.

ActiveLayer processes account, billing, relationship, support, security, and website or dashboard analytics data as an independent controller or business under the ActiveLayer Privacy Policy. That data is outside the scope of this DPA unless it is also Customer Personal Data processed on Customer’s behalf. Data stored only in Customer’s WordPress installation or other local systems remains under Customer’s control and is not processed by ActiveLayer.

2. Definitions

“ActiveLayer” means ActiveLayer LLC. “Customer” means the person or entity that accepted the Agreement. “Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with a party. “Customer Affiliate” means an Affiliate of Customer that is authorized to use the Services under the Agreement. “Services” means ActiveLayer’s spam detection API, application, integrations, and related services covered by the Agreement.

“Customer Personal Data” means Personal Data contained in data that Customer or its users submit to the Services, or that ActiveLayer collects through the Services on Customer’s behalf, including submission content and related technical and behavioral signals.

“Data Protection Laws” means privacy and data protection laws that apply to the processing under this DPA, including the EU General Data Protection Regulation 2016/679 ("EU GDPR"); Directive 2002/58/EC and its national implementations; the EU GDPR as incorporated into United Kingdom law ("UK GDPR") and the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection; the California Consumer Privacy Act as amended by the California Privacy Rights Act and other applicable United States state privacy laws; Canada’s Personal Information Protection and Electronic Documents Act; Brazil’s General Data Protection Law; Australia’s Privacy Act 1988; and South Africa’s Protection of Personal Information Act.

“Personal Data,” “Controller,” “Processor,” “Business,” “Service Provider,” “Contractor,” “Consumer,” “Data Subject,” “Processing,” “Sell,” “Share,” and “Supervisory Authority” have the meanings given by applicable Data Protection Laws. “Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

“Subprocessor” means a third party engaged by ActiveLayer to process Customer Personal Data. “SCCs” means the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914.

3. Roles and documented instructions

For Customer Personal Data protected by the EU GDPR, UK GDPR, or Swiss data protection law, Customer is the Controller and ActiveLayer is the Processor. For Customer Personal Data protected by applicable United States state privacy laws, Customer is the Business and ActiveLayer is its Service Provider or Contractor. Each party will comply with the obligations applicable to its role.

Customer instructs ActiveLayer to process Customer Personal Data to provide, secure, monitor, support, and improve the Services; prevent spam, fraud, abuse, and security threats; comply with Customer’s documented configuration and support requests; and comply with law. The Agreement, this DPA, Customer’s use and configuration of the Services, and documented support requests constitute Customer’s complete instructions.

ActiveLayer will notify Customer if, in ActiveLayer’s reasonable opinion, an instruction violates Data Protection Laws and may suspend the affected processing until the parties resolve the issue. ActiveLayer may process Customer Personal Data as required by law after providing advance notice, unless law prohibits that notice.

4. ActiveLayer obligations

ActiveLayer will:

  • process Customer Personal Data only for the documented purposes in this DPA and the Agreement;
  • ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive appropriate privacy and security guidance;
  • implement and maintain the technical and organizational measures described in Annex 3;
  • not disclose Customer Personal Data to a third party except as permitted by this DPA, instructed by Customer, or required by law;
  • not materially reduce the overall security of the Services during the term; and
  • provide information reasonably necessary to demonstrate compliance with this DPA.

ActiveLayer will not permit an AI Subprocessor to use Customer Personal Data to train that Subprocessor’s general-purpose or shared models. ActiveLayer may use deidentified or aggregated data as described in Section 14.

5. Customer obligations

Customer will:

  • provide all notices and obtain all consents or other lawful bases required to collect and submit Customer Personal Data to ActiveLayer;
  • configure and use the Services in compliance with Data Protection Laws and this DPA;
  • ensure that its instructions are lawful and that Customer has the right to submit Customer Personal Data;
  • respond to Data Subject requests and regulator inquiries for which Customer is responsible; and
  • use reasonable safeguards for its accounts, API keys, integrations, endpoints, and local copies of submissions.

The Services are not designed to process protected health information subject to HIPAA, payment card data subject to PCI DSS, authentication secrets, government identifiers, or children’s data. Customer will not intentionally submit those data, or special-category or highly sensitive data, unless the parties first agree in writing on the required instructions and safeguards. Free-text submissions may nevertheless contain sensitive data; when they do, the protections in this DPA continue to apply.

6. United States state privacy terms

For Customer Personal Data subject to United States state privacy laws, ActiveLayer acts as a Service Provider or Contractor for the limited and specified business purposes described in this DPA. ActiveLayer will comply with applicable obligations and provide the same level of privacy protection required of Customer for that processing.

ActiveLayer will not:

  • Sell or Share Customer Personal Data;
  • retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a commercial purpose other than the limited purposes in this DPA;
  • use Customer Personal Data for cross-context behavioral advertising or targeted advertising; or
  • combine Customer Personal Data with personal data received from another person or collected from ActiveLayer’s own interaction with a Consumer, except as permitted by applicable law to perform the Services.

Customer may take reasonable and appropriate steps to help ensure that ActiveLayer uses Customer Personal Data consistently with Customer’s obligations, including the audit rights in Section 11. ActiveLayer will notify Customer if it determines it can no longer meet its obligations under this Section. Customer may take reasonable steps to stop and remediate unauthorized use. ActiveLayer certifies that it understands and will comply with these restrictions.

7. Subprocessors

Customer gives ActiveLayer general written authorization to use the Subprocessors listed in Annex 2. ActiveLayer will enter into a written agreement with each Subprocessor that imposes data protection obligations appropriate to the processing and will remain responsible for each Subprocessor’s performance to the extent required by Data Protection Laws.

ActiveLayer will give Customer at least 30 days’ prior notice by email, in-product notice, or a documented subscription mechanism before authorizing a new Subprocessor that will process Customer Personal Data. Customer may object within 15 days after notice on reasonable data protection grounds. The parties will work in good faith to resolve the objection. If no reasonable solution is available, Customer may stop using the affected feature or terminate the affected Services without penalty and receive a pro rata refund of prepaid fees for the unused period.

8. Security

ActiveLayer will maintain a security program designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current technical and organizational measures are described in Annex 3. ActiveLayer may update those measures where the update does not materially reduce the overall level of protection.

Customer is responsible for assessing whether the Services and the measures in Annex 3 are appropriate for Customer’s processing and risks.

9. Security Incidents

ActiveLayer will notify Customer without undue delay and, where practicable, within 48 hours after becoming aware of a Security Incident affecting Customer Personal Data. Notice will include, as information becomes available, the nature of the incident, the categories of affected data and Data Subjects, likely consequences, measures taken or proposed, and a contact for follow-up.

ActiveLayer will take reasonable steps to contain, investigate, mitigate, and remediate the Security Incident and will provide reasonable cooperation. ActiveLayer’s notice or response is not an admission of fault or liability. Customer is responsible for notices to Data Subjects, regulators, or others unless law requires ActiveLayer to provide them.

Failed login attempts, unsuccessful probes, blocked attacks, and other events that do not compromise Customer Personal Data are not Security Incidents under this DPA.

10. Assistance and Data Subject requests

Taking into account the nature of the processing and information available to ActiveLayer, ActiveLayer will provide reasonable assistance for Customer to respond to Data Subject requests; conduct data protection impact assessments and prior consultations; maintain records; and meet breach notification and regulator-cooperation obligations.

If ActiveLayer receives a request from a Data Subject concerning Customer Personal Data, ActiveLayer will direct the requester to Customer and will not respond on Customer’s behalf unless Customer instructs it to do so or law requires it. Customer is responsible for verifying the request and giving ActiveLayer the information needed to locate the data.

If a public authority or law enforcement agency demands Customer Personal Data, ActiveLayer will, where legally permitted and reasonably practicable, redirect the requester to Customer; promptly notify Customer and provide a copy of the demand; review the demand’s legal authority; challenge an unlawful or overbroad demand where reasonable grounds exist; and disclose only the minimum Customer Personal Data legally required. If notice is prohibited, ActiveLayer will use reasonable efforts to obtain permission to notify Customer and will provide lawful aggregate information about government demands where practicable.

ActiveLayer may charge reasonable fees for assistance that is unusually burdensome, repetitive, or unrelated to a failure by ActiveLayer to comply with this DPA, after giving Customer advance notice of the expected fees.

11. Information and audits

On written request, ActiveLayer will make available information reasonably necessary to demonstrate compliance with this DPA. Customer will first use current third-party reports, certifications, questionnaires, and other information that ActiveLayer makes available.

If that information is insufficient, Customer may conduct one audit in any 12-month period, and an additional audit after a Security Incident or where a Supervisory Authority requires it. Audits must be conducted by an independent, qualified auditor bound by confidentiality, on at least 30 days’ notice, during normal business hours, without accessing another customer’s data or unreasonably disrupting the Services. The parties will agree on scope, timing, and safeguards in advance.

Customer bears its audit costs and ActiveLayer’s reasonable support costs unless the audit identifies a material breach by ActiveLayer, in which case ActiveLayer will bear its reasonable support costs. Information disclosed for an audit is ActiveLayer Confidential Information.

12. International data transfers

ActiveLayer may process Customer Personal Data in the United States and other countries where its authorized Subprocessors operate. ActiveLayer will use a lawful transfer mechanism when Data Protection Laws restrict a transfer, including an adequacy decision or framework, the SCCs, the UK International Data Transfer Addendum, or another legally recognized safeguard.

Where Customer transfers Customer Personal Data protected by the EU GDPR to ActiveLayer in a country without an adequacy decision and no other valid mechanism applies, Module Two of the SCCs is incorporated into this DPA and completed as stated in Annex 4. The equivalent UK and Swiss transfer terms in Annex 4 apply where relevant.

If a transfer mechanism is invalidated or no longer available, the parties will cooperate in good faith to implement a valid replacement. ActiveLayer will provide information reasonably necessary for Customer’s transfer impact assessment, subject to confidentiality and security restrictions.

13. Return and deletion

During the term, Customer may access or export Customer Personal Data using available Service features. Spam detection logs containing Customer Personal Data are retained for up to 90 days, or a shorter period selected by Customer where the Services provide that setting, unless law requires a longer period.

At Customer’s written instruction or when the Agreement ends, ActiveLayer will delete or return Customer Personal Data, at Customer’s choice, within 90 days, except to the extent law requires retention. Customer must request a return before the Agreement ends or within 30 days afterward. Data in backups will be isolated from active use and deleted or overwritten through the ordinary backup cycle within a further 90 days.

If law requires continued retention, ActiveLayer will protect the retained data, process it only for the legally required purpose, and delete it when the requirement ends. ActiveLayer may retain deidentified or aggregated data that no longer constitutes Personal Data as described in Section 14.

14. Deidentified and aggregated data

ActiveLayer may create and use deidentified or aggregated data for security, service analytics, and the testing and improvement of ActiveLayer’s spam detection models and algorithms only after taking reasonable measures so the data cannot reasonably be linked to Customer, a website, or an end user. ActiveLayer will maintain the data in deidentified form, will not attempt to reidentify it, and will require recipients to observe equivalent restrictions.

Data remains Customer Personal Data and subject to this DPA until it meets the deidentification standard in this Section. Pseudonymization, hashing, or removal of direct identifiers alone does not place data outside this DPA if a person or Customer can still reasonably be identified.

15. Duration, liability, and changes

This DPA remains in effect while ActiveLayer processes Customer Personal Data. The confidentiality, security, deletion, transfer, and audit obligations survive for as long as ActiveLayer retains that data.

The Agreement’s limitations of liability, exclusions, governing law, and dispute provisions apply to this DPA to the fullest extent permitted by Data Protection Laws. Nothing in this DPA limits a Data Subject’s rights or a Supervisory Authority’s powers under applicable law.

ActiveLayer may update this DPA to comply with law or reflect changes to the Services. ActiveLayer will not materially reduce Customer’s data protection rights during a current paid subscription and will provide notice of material changes as required by the Agreement or Data Protection Laws.

16. Contact

Privacy questions and requests under this DPA may be sent to [email protected]. ActiveLayer’s address is ActiveLayer LLC, 400 Executive Center Drive, Suite 208, West Palm Beach, Florida 33401, United States.

Annex 1 — Details of processing

ItemDescription
Subject matter and purposeProviding spam, bot, fraud, and abuse detection; returning classification results and signals; securing, monitoring, supporting, and improving the Services under Customer’s instructions.
DurationFor the Agreement term and the retention and deletion periods in Section 13, unless law requires longer retention.
Nature and operationsCollection, transmission, validation, normalization, analysis by rules, machine learning, and AI; deriving domain and network reputation information; caching; storage; classification; logging; display and export to Customer; correction feedback; support; security monitoring; deletion and return.
FrequencyContinuous or occasional, whenever Customer or its integrations submit a spam check, use related Service features, or send correction feedback.
Data SubjectsVisitors and users of Customer websites or applications; form submitters; commenters; reviewers; registrants; suspected bots or abusive users; Customer administrators, personnel, and authorized users where their data appears in Service requests.
Personal DataName; email address; message, comment, review, registration, or other free-text submission content; website URL and domain; client IP address; user agent; timestamp; locale; form, post, page, site, and integration metadata; behavioral interaction signals such as timing, keypress counts, pointer, touch, and scroll activity; browser and environment signals; honeypot and integrity signals; links found in content; detection scores, reasons, classifications, and corrected labels; site URL, WordPress version, and active plugin names, slugs, and versions when an integration key is verified.
Sensitive dataNot intentionally required. Free-text may contain special-category, sensitive, or criminal-offence data. Customer must avoid submitting highly sensitive data unless separately agreed and lawful. The safeguards in this DPA apply if sensitive data is incidentally included.
Customer instructionsThe Agreement, this DPA, Customer’s configurations and API requests, and documented support requests.
Return and deletionAs stated in Section 13. Local copies stored in Customer’s WordPress installation or other systems are controlled and deleted by Customer.

Annex 2 — Authorized Subprocessors

The following Subprocessors are authorized to process Customer Personal Data. Account, billing, marketing, and dashboard analytics providers that do not receive Customer submission content are described separately in the ActiveLayer Privacy Policy.

SubprocessorPurposeCustomer Personal DataPrimary location / safeguard
Google LLC (Google Cloud)Cloud hosting and managed infrastructure, including Cloud Run compute, Cloud SQL database storage, networking, managed cache, task queueing, and service logging.Customer Personal Data submitted to and generated by the Services; operational and security telemetry.United States and other provider locations; applicable adequacy framework and/or SCCs.
OpenAI, L.L.C.AI-assisted spam classification when the OpenAI analyzer is invoked.Data type; name; email; message or submission content; client IP address; user agent; website URL; relevant site or form context; URLs found in the message.United States; applicable adequacy framework and/or SCCs. API inputs and outputs are not used to train OpenAI models by default.
TypeSafe AI, Inc. (Jev)AI-assisted spam classification when the Jev analyzer is invoked.Data type; name; message or submission content; website URL; user agent.United States; DPA and SCCs or another valid transfer mechanism as applicable. Customer Personal Data is not used to train TypeSafe AI models.
Functional Software, Inc. d/b/a SentryError monitoring, diagnostics, and service reliability.Error context, request or detection identifiers, technical metadata, performance telemetry, and limited Customer Personal Data if present in diagnostic context.United States; applicable adequacy framework and/or SCCs.

ActiveLayer configures error monitoring to avoid sending personal data by default and limits diagnostic context to what is reasonably necessary. ActiveLayer will not permit OpenAI or TypeSafe AI to use Customer Personal Data to train general-purpose or shared models.

Annex 3 — Technical and organizational measures

Access control and confidentiality

  • Role-based access controls and least-privilege access for personnel and service components.
  • Unique user accounts, session controls, and optional multi-factor authentication for Customer accounts.
  • Confidentiality obligations for personnel authorized to process Customer Personal Data.
  • API authentication, scoped credentials, rate limits, and tenant or account-level authorization checks.

Encryption and credential protection

  • HTTPS/TLS for API and application traffic in transit.
  • Managed cloud encryption at rest for production storage and backups where supported by the service.
  • Passwords hashed using bcrypt; API tokens stored as SHA-256 hashes; multi-factor authentication secrets encrypted at rest.
  • Secrets maintained outside source code and restricted to authorized services and personnel.

Infrastructure and availability

  • Managed cloud infrastructure with network isolation, firewall controls, service identity, and provider physical security.
  • Backups, redundancy, queueing, and recovery procedures appropriate to the Services.
  • Capacity, availability, and error monitoring, with alerting for material service failures.
  • Separation of production access from ordinary development activities.

Secure development and operations

  • Code review, automated testing, dependency management, and security updates appropriate to the change.
  • Input validation, output encoding, authenticated endpoints, and controls against common application attacks.
  • Centralized operational logging with efforts to minimize Customer Personal Data in diagnostic events.
  • Incident response procedures for investigation, containment, remediation, and notice.

Data lifecycle and oversight

  • Retention controls and deletion procedures for active systems, caches, queues, and backups.
  • Subprocessor diligence and written data protection obligations.
  • Periodic review of access, security measures, and material changes to the processing.
  • Reasonable assistance with Data Subject requests, audits, and regulatory obligations.

Annex 4 — International transfer terms

European Economic Area

For restricted transfers governed by the EU GDPR, the parties enter into Module Two (Controller to Processor) of the SCCs. Clause 7 (docking) applies. Under Clause 9, Option 2 applies with a 30-day notice period. The optional language in Clause 11 does not apply. For Clause 17, the SCCs are governed by the law of Ireland. For Clause 18, disputes are resolved by the courts of Ireland.

For Annex I.A of the SCCs, Customer is the data exporter and the contact details are those in the Agreement; ActiveLayer is the data importer and its details are in Section 16. Each party’s role is described in Section 3. Annex I.B is completed by Annex 1 of this DPA. The competent Supervisory Authority under Annex I.C is the authority determined under Clause 13; where no authority is identified by that clause, it is the Irish Data Protection Commission. Annex II is completed by Annex 3, and Annex III is completed by Annex 2.

United Kingdom

For restricted transfers governed by the UK GDPR, the then-current International Data Transfer Addendum to the EU Commission SCCs issued by the UK Information Commissioner is incorporated by reference. The information required for its tables is supplied by the Agreement and Annexes 1–3 of this DPA. The parties select neither party as having an unilateral right to end the Addendum solely because the Information Commissioner issues a revised approved addendum.

Switzerland

For restricted transfers governed by the Swiss Federal Act on Data Protection, the SCCs apply with references to the EU GDPR understood to include the Swiss law where appropriate; references to EU Member States include Switzerland; Data Subjects may enforce their rights in Switzerland; and the competent authority is the Swiss Federal Data Protection and Information Commissioner.

If incorporation by reference is not legally effective in a jurisdiction, the parties will promptly execute the applicable official transfer clauses on request. The official text of the SCCs controls over any inconsistent summary in this Annex.