• Platform
  • Solutions
  • Resources
  • Pricing
  • Enterprise
  • Log in
  • Building at scale? Book a demo
  • Start free trial Start free trial
Platform
Build
Website builder
Create high-performing sites at scale
Vibe
Generate client-ready sites & web apps
AI Widget Builder
Build custom website elements with AI
Platform automation
Automate site building and management
Get found
SEO
Build sites that win more search traffic
AEO
Monitor and grow your clients’ AI Visibility
Convert
Bookings
Convert leads with integrated scheduling
eCommerce
Launch high-converting online stores
Professional tools
White label
Make Duda’s entire platform your own
Client management
Invite clients with role-based permissions
Team collaboration
Work alongside your teammates
App store
Extend your sites with powerful apps
Security
Rely on robust, enterprise-grade security
More from Duda
Templates
Made with Duda
Accessibility
Solutions
Duda for
Agencies
See why Duda is the top website builder for agency growth
Hosting platforms
Compliment your services with sites
 
Vertical SaaS
Integrate a white-label website builder
Point of Sale
Drive transaction volume with sites
Industry case studies
Property management
Travel & hospitality
Transportation

View all success stories
Resources
Start
Templates
Get started with beautiful templates
Inspiration
Browse real sites that clients already love
Developers
Discover APIs, extensions, and other tools
Hire an expert
Hire expert fulfillment services
Learn
Duda Academy
Take your skills to the next level
Blog
Get insights to grow your business
Webinars
Learn from experts, live or on-demand
Discvoer
Success Stories
Get inspired by real wins
Use cases
Explore integration examples with Duda
Product Updates
Discover Duda's latest releases
Get help
Support
System status
Pricing Enterprise
Contact sales Start free trial
Log in

Duda Data Processing Addendum

Effective Date: August 2026

This Data Processing Addendum (“DPA”) forms part of the Agreement, Order Form, Terms of Service, Master Services Agreement, or other written agreement governing the Customer’s use of the Services (the “Service Agreement”) between Duda, Inc. and/or the Duda affiliate identified in the Service Agreement (“Duda”) and the customer identified in the Service Agreement (“Customer”).

This DPA applies to Duda’s Processing of Customer Personal Data in connection with the Services. As of its effective date, it supersedes any prior generally applicable data processing addendum between the Parties concerning such Processing, unless the Parties have entered into a separately negotiated data processing agreement that expressly provides otherwise.

This DPA becomes effective upon the later of: (i) the Customer’s acceptance of or entry into the Service Agreement; and (ii) the effective date of this DPA in accordance with the amendment or update provisions of the Service Agreement. It remains in effect for as long as Duda Processes Customer Personal Data.

1. Definitions

“Applicable Data Protection Laws” means all laws and regulations applicable to the Processing of Customer Personal Data under the Service Agreement, including, as applicable, the EU GDPR, UK GDPR and Data Protection Act 2018, Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the California Privacy Rights Act, and other applicable U.S. state privacy laws.

“Authorized User” means an individual authorized by Customer or an End Customer to access or use the Services, including Customer team members and End Customer users.

“Customer Content” means content, data, prompts, instructions, files, website content, communications, form submissions, campaign data, generated outputs, and other materials submitted to, generated through, hosted by, or otherwise Processed through the Services by or on behalf of Customer, an End Customer, an Authorized User, or a Site Visitor.

“Customer Personal Data” means Personal Data contained in Customer Content or otherwise Processed by Duda on behalf of Customer in connection with the Services. Customer Personal Data excludes Personal Data that Duda Processes as an independent Controller for its own purposes as described in Duda’s Privacy Policy.

“Customer Site” means a website, application, page, form, chatbot, campaign, component, integration, or other digital property or functionality built, hosted, operated, or enabled through the Services.

“Data Privacy Framework” means the EU-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework, and Swiss-U.S. Data Privacy Framework, as applicable.

“End Customer” means a customer, client, reseller customer, site owner, or other person or entity to whom Customer provides access to or use of the Services or a Customer Site.

“EU GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended, supplemented, or replaced from time to time.

“Personal Data” means information relating to an identified or identifiable natural person, or information otherwise defined as personal data, personal information, or a similar term under Applicable Data Protection Laws.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Duda.

“Restricted Transfer” means a transfer of Personal Data subject to the EU GDPR, UK GDPR, or Swiss Federal Act on Data Protection to a country that is not recognized as providing an adequate level of protection and that requires an approved transfer mechanism.

“Services” means the website building, hosting, operation, management, ecommerce, form, communication, marketing automation, artificial intelligence, application, integration, support, and related services supplied by Duda under the Service Agreement.

“Site Visitor” means an individual who accesses or interacts with a Customer Site.

“Standard Contractual Clauses” means the European Commission standard contractual clauses adopted by Implementing Decision (EU) 2021/914.

“Subprocessor” means a third party or Duda affiliate engaged by Duda to Process Customer Personal Data on behalf of Customer.

Capitalized terms not defined in this DPA have the meanings given in the Service Agreement or Applicable Data Protection Laws. “Controller”, “Processor”, “Business”, “Service Provider”, “Contractor”, “Process”, “Sell”, and “Share” have the meanings given under Applicable Data Protection Laws.

2. Scope and Roles of the Parties

  1. Customer is the Controller and Duda is the Processor of Customer Personal Data. If Customer Processes Customer Personal Data on behalf of another Controller, including where Customer resells, white-labels, or otherwise provides the Services to an End Customer, Customer is a Processor and Duda is a Subprocessor. References in this DPA to Customer as Controller will be interpreted accordingly.
  2. Customer and, where applicable, its End Customers determine the purposes and essential means of Processing through Customer Sites and customer-configured functionality. Duda Processes Customer Personal Data only to provide, secure, support, and maintain the Services in accordance with Customer’s documented instructions.
  3. Duda is an independent Controller for personal data it Processes for its own account administration, billing, legal compliance, fraud and abuse prevention, corporate security, business relationship management, direct marketing, and other purposes described in Duda’s Privacy Policy. Duda will Process such personal data in accordance with applicable data protection laws. Such Processing is outside the scope of this DPA.
  4. Use of artificial intelligence features, marketing automation, forms, chatbots, ecommerce, integrations, customer-created functionality, or communications tools does not by itself change the Parties’ roles. Duda remains a Processor where it Processes Customer Personal Data solely on Customer’s documented instructions to provide the Services.

3. Customer Instructions and Responsibilities

  1. Customer instructs Duda to Process Customer Personal Data as necessary to provide the Services, as described in the Service Agreement and Exhibit A, and in accordance with additional lawful written instructions agreed by the Parties.
  2. If Duda is required by law to Process Customer Personal Data other than on Customer’s instructions, Duda will inform Customer before the Processing unless legally prohibited.
  3. Duda will inform Customer if, in Duda’s opinion, an instruction infringes Applicable Data Protection Laws. Duda may suspend the affected Processing until the Parties resolve the issue.
  4. Customer is responsible for:
    1. ensuring that its instructions and use of the Services comply with Applicable Data Protection Laws and other laws applicable to the relevant Customer Site or functionality;
    2. establishing and documenting an appropriate lawful basis and, where required, obtaining valid consent for the collection and use of Customer Personal Data;
    3. providing all required privacy, cookie, direct marketing, recording, and artificial intelligence notices and disclosures to Site Visitors and other data subjects;
    4. configuring the Services, including consent, opt-in, suppression, retention, access, permissions, and integration settings, in a manner appropriate to Customer’s use case and applicable law;
    5. ensuring that Customer is authorized to provide Customer Personal Data to Duda and to appoint Duda as Processor or Subprocessor;
    6. reviewing, testing, configuring, and approving code, content, applications, chatbots, integrations, campaigns, and other functionality generated or enabled through the Services before deployment; and
    7. responding to data subjects and regulators, except to the extent Duda is required to assist under this DPA.
  5. Duda may provide default settings, templates, sample language, notices, consent wording, disclosures, or other compliance-related features for Customer’s convenience. Such materials and configurations are general tools only and do not constitute legal advice or a representation that Customer’s use of the Services complies with applicable law. Customer is responsible for reviewing, configuring, and updating them as necessary to reflect Customer’s processing activities, purposes, audience, jurisdictions, legal bases, and applicable legal requirements.

4. Duda Processing Obligations

  1. Duda will Process Customer Personal Data only on Customer’s documented instructions, as set out in the Service Agreement, this DPA, including Exhibit A, and any other lawful written instructions agreed by the Parties, and in accordance with Applicable Data Protection Laws applicable to Duda in its capacity as Processor or Subprocessor.
  2. Duda will ensure that persons authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations and access Customer Personal Data only as necessary for their duties.
  3. Duda will not use Customer Personal Data for Duda’s own advertising to Site Visitors, cross-customer profiling, Sale, Sharing, or training of general-purpose or cross-customer artificial intelligence models. Duda may perform such Processing solely on Customer’s documented instructions where it is part of the Services, does not constitute Duda’s independent use of Customer Personal Data, and is permitted by Applicable Data Protection Laws. This restriction does not prevent use of data that has been irreversibly anonymized in accordance with Section “Anonymized and Aggregated Data”.
  4. Duda may generate and use service telemetry, diagnostic data, security logs, and similar operational information necessary to operate, protect, maintain, and improve the Services. To the extent such information contains Customer Personal Data, Duda will Process it in accordance with this DPA.

5. Security and Confidentiality

  1. Taking into account the state of the art, costs of implementation, and the nature, scope, context, purposes, and risks of the Processing, Duda will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
  2. Duda’s technical and organizational measures are described at this link: https://support.duda.co/hc/en-us/articles/28489936427415-Security-Measures as updated from time to time. Duda may update them during the term, provided that any update does not materially decrease the overall level of protection for Customer Personal Data.
  3. Customer acknowledges that the Services permit Customer to configure access rights, permissions, retention, integrations, and other settings. Customer is responsible for using available security and privacy controls appropriately, securing its credentials, and managing its Authorized Users.
  4. Duda will maintain documented incident response, business continuity, disaster recovery, vulnerability management, access control, and supplier management processes appropriate to the Services.

6. Subprocessors

  1. Customer grants Duda general written authorization to engage Subprocessors. Duda’s current Subprocessor list is available at https://www.duda.co/legal/privacy/subprocessors and is incorporated into this DPA by reference.
  2. Customers may subscribe to receive advance notices of intended additions or replacements by contacting legal@duda.co. Duda will provide subscribed Customers with such notice at least fifteen (15) days before the relevant Subprocessor begins Processing Customer Personal Data. Customers that do not subscribe remain responsible for periodically reviewing the Subprocessor list.
  3. Customer may object to a new Subprocessor during the notice period on reasonable grounds relating to data protection. The Parties will work in good faith to resolve the objection. If they cannot do so, Duda may elect not to use the Subprocessor for Customer, offer a commercially reasonable alternative, or permit Customer to terminate the affected Service without penalty for the unused portion of prepaid fees, unless otherwise stated in the Service Agreement.
  4. Duda will enter into a written agreement with each Subprocessor imposing data protection obligations that provide at least substantially the same level of protection for Customer Personal Data as this DPA, to the extent applicable to the Subprocessor’s services. Duda remains responsible to Customer for the performance of its Subprocessors’ obligations as required by Applicable Data Protection Laws.
  5. Third-party applications, integrations, widgets, scripts, or services selected, installed, enabled, or directed by Customer are not Duda Subprocessors solely because they interoperate with the Services. Customer is responsible for evaluating and authorizing such third parties and for the lawfulness of disclosures to them, unless Duda expressly identifies the provider as a Duda Subprocessor.

7. Data Subject Requests

  1. Taking into account the nature of the Processing, Duda will provide reasonable assistance through appropriate technical and organizational measures, insofar as possible, to enable Customer to respond to requests from data subjects to exercise their rights under Applicable Data Protection Laws.
  2. If Duda receives a request relating to Customer Personal Data, Duda will, without undue delay, notify or redirect the requester to Customer where Duda can identify the relevant Customer. Duda will not substantively respond except on Customer’s documented instructions or where required by law.
  3. Duda may require Customer to use available self-service functionality, user interfaces, or APIs before requesting additional assistance. Customer will reimburse Duda for reasonable costs of assistance that is materially beyond the ordinary provision of the Services, provided Duda informs Customer in advance where practicable.

8. Assistance with Compliance

  1. Taking into account the nature of the Processing and the information available to Duda, Duda will reasonably assist Customer with its obligations relating to security, Personal Data Breach notifications, data protection impact assessments, prior consultation with supervisory authorities, and other legally required privacy or security assessments.
  2. Duda’s assistance may include providing available documentation concerning the Services, Processing activities, Subprocessors, transfer mechanisms, security measures, retention, and privacy controls. Customer remains responsible for determining whether its particular use requires a data protection impact assessment or other assessment and for completing that assessment.
  3. Duda may make generally applicable assessment materials or compliance documentation available to multiple customers. Such materials do not replace Customer’s assessment of its specific purposes, configurations, data subjects, legal bases, and risks.

9. Personal Data Breach

  1. Duda will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
  2. To the extent available, Duda’s notification will include:
    1. a description of the nature of the Personal Data Breach, including the categories and approximate number of affected data subjects and records where known;
    2. a description of the likely consequences;
    3. a description of measures taken or proposed to contain, investigate, remediate, and mitigate the Personal Data Breach; and
    4. a contact point for further information.
  3. Duda may provide information in phases as it becomes available. Duda will reasonably cooperate with Customer’s legally required notifications and will document relevant facts, effects, and remedial action. Notification is not an admission of fault or liability.
  4. Customer is responsible for notifying supervisory authorities, data subjects, customers, or other parties unless Applicable Data Protection Laws require Duda to make a notification directly.

10. Information and Audits

  1. Duda will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits as required by Applicable Data Protection Laws.
  2. Duda may satisfy audit requests in the first instance by providing current third-party certifications, audit reports, security summaries, questionnaires, or other documentation. Customer will treat such materials as Duda’s Confidential Information.
  3. If the information provided is not reasonably sufficient, Customer may conduct an audit itself or through an independent auditor that is not Duda’s competitor and is bound by confidentiality. Unless a competent authority requires otherwise or there is credible evidence of material noncompliance or a Personal Data Breach, audits will:
    1. occur no more than once in any twelve-month period;
    2. be subject to at least thirty (30) days’ prior written notice;
    3. occur during normal business hours and without unreasonable disruption;
    4. be limited to systems, records, personnel, and facilities relevant to Processing Customer Personal Data; and
    5. not require access to other customers’ data, source code, vulnerability information that would create security risk, or unrelated confidential information.
  4. Customer will bear its audit costs and Duda’s reasonable costs of cooperation beyond ordinary document production. If an audit establishes a material breach of this DPA by Duda, Duda will reimburse reasonable external audit costs directly attributable to establishing that breach.

11. Return, Deletion, and Retention

  1. During the term, Customer may access, export, or delete Customer Personal Data using available functionality, APIs, or documented support channels, subject to the Service Agreement and technical limitations of the relevant Service.
  2. Upon termination or expiration of the affected Services, Duda will, at Customer’s choice, make Customer Personal Data available for return during the applicable export period and thereafter delete it within a commercially reasonable period in accordance with Duda’s documented deletion and retention procedures. If Customer does not request return during the applicable export period, Duda may proceed with deletion.
  3. Duda may retain Customer Personal Data:
    1. in immutable or routine backups, operational and security logs, and disaster-recovery systems until overwritten or deleted through Duda’s ordinary retention cycle;
    2. where required by law, legal process, or a documented legal hold; or
    3. as necessary to establish, exercise, or defend legal claims.
  4. Any Customer Personal Data retained under Subsection 3 of this Section “Return, Deletion, and Retention” will remain subject to this DPA. Duda will restrict further Processing to the applicable retention purpose and will delete or render the data inaccessible through its ordinary retention processes. Duda will not restore deleted Customer Personal Data from backup except where necessary for business continuity, disaster recovery, or security. If restored, the data will remain subject to the original deletion instruction and will be deleted again through the applicable process.
  5. For the avoidance of doubt, this Section “Return, Deletion, and Retention” does not require Duda to return or delete data that has been irreversibly anonymized in accordance with Applicable Data Protection Laws so that it no longer constitutes Personal Data. Duda will not attempt to re-identify such data.

12. International Transfers

  1. Customer authorizes Duda and its Subprocessors to Process Customer Personal Data in countries where Duda or its Subprocessors maintain facilities or personnel, subject to this DPA and Applicable Data Protection Laws.
  2. For transfers of Customer Personal Data to Duda in the United States that are covered by Duda’s active certification under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, or the Swiss-U.S. Data Privacy Framework, as applicable, Duda will rely on the relevant framework as the transfer mechanism.
  3. Customer acknowledges that the Services may use distributed cloud, content-delivery, edge, support, and communications infrastructure. Even where primary hosting is provided in a selected region, website content and related request data may be routed, cached, secured, or delivered through global infrastructure according to the location of Site Visitors and technical requirements of the Services.

13. Anonymized and Aggregated Data

  1. Duda may create and use aggregated or irreversibly anonymized data derived from Customer Personal Data for analytics, statistics, security, research, service improvement, and other lawful business purposes, provided that the data cannot reasonably identify or be associated with an individual and Duda does not attempt to re-identify it.
  2. Data that remains Personal Data, including pseudonymized or merely de-identified data, remains subject to this DPA.

14. Artificial Intelligence Features

  1. Where Customer enables an artificial intelligence feature, Customer instructs Duda to Process relevant prompts, instructions, files, website content, contextual data, and generated outputs as necessary to provide that feature.
  2. Duda will not use Customer Personal Data submitted to or generated by artificial intelligence features to train general-purpose or cross-customer models, and will require relevant model providers acting as Subprocessors not to do so, unless Customer expressly authorizes such Processing in writing.
  3. Duda may Process Customer Personal Data within artificial intelligence features for inference, retrieval, generation, security, abuse prevention, troubleshooting, and customer-specific configuration or improvement, solely as necessary to provide and protect the Services and in accordance with Customer’s instructions.
  4. Unless expressly permitted by the applicable Service documentation or otherwise approved by Duda in writing, Customer will not intentionally include Personal Data in prompts, uploads, instructions, or other inputs submitted to artificial intelligence features. Customer will not submit special category data, highly sensitive personal data, payment-card data, protected health information, government identification numbers, Personal Data concerning children, passwords, authentication credentials, API keys, access tokens, or other secrets to an artificial intelligence feature unless the feature is expressly designed and approved for such data.
  5. Customer is responsible for the lawfulness, accuracy, and appropriateness of its prompts, source materials, generated outputs, and deployment decisions. Customer will review and test generated outputs before deploying or relying on them.
  6. Where Customer uses the Services to create or deploy an AI chatbot or other artificial intelligence functionality that interacts directly with individuals, Customer is responsible for providing any legally required artificial intelligence disclosures and for ensuring that the use, configuration, operation, and outputs of the functionality comply with applicable artificial intelligence, privacy, consumer-protection, accessibility, and sector-specific laws.
  7. Where Customer-created functionality subsequently collects or Processes Personal Data, that Personal Data constitutes Customer Personal Data to the extent it is hosted, stored, transmitted, or otherwise Processed through the Services. If Customer directs generated functionality to disclose Personal Data directly to a customer-selected third party, Subsection 5 of Section “Subprocessors” applies.

15. Marketing Automation and Communications

  1. Where Customer enables marketing automation or communications functionality, Customer instructs Duda to Process subscriber and lead data, communication preferences, consent and opt-in records, suppression records, campaign content, delivery data, engagement information, and related technical data as necessary to provide the functionality.
  2. Customer determines the recipients, purposes, timing, content, legal basis, and communication channels and is responsible for obtaining and documenting any required consent or other authorization and for complying with applicable direct-marketing, electronic-communications, telemarketing, consumer-protection, and privacy laws.
  3. Duda may provide configurable consent, preference, unsubscribe, suppression, or recordkeeping functionality in connection with certain Services. Customer is responsible for determining whether to enable and how to configure such functionality, and whether it satisfies the requirements applicable to Customer’s audience and communications. Any default or sample wording is subject to Subsection 4 of Section “Customer Instructions and Responsibilities”.
  4. Duda will not independently use recipient-level Customer Personal Data for Duda’s own marketing, advertising, cross-customer profiling, or targeted advertising.

16. U.S. State Privacy Terms

  1. To the extent U.S. state privacy laws apply, Duda acts as a Service Provider, Contractor, or Processor, as applicable, with respect to Customer Personal Data. The limited and specified purposes of Processing are those set out in the Service Agreement, this DPA, and Exhibit A.
  2. Duda will not:
    1. Sell or Share Customer Personal Data;
    2. retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a commercial purpose other than the limited and specified purposes permitted by the Service Agreement and Applicable Data Protection Laws;
    3. combine Customer Personal Data with personal information received from or on behalf of another person, or collected from Duda’s own interaction with a consumer, except as permitted by Applicable Data Protection Laws; or
    4. use Customer Personal Data for targeted advertising or profiling in furtherance of decisions producing legal or similarly significant effects, except on Customer’s documented instructions where legally permitted.
  3. Duda certifies that it understands and will comply with the restrictions in this Section “U.S. State Privacy Terms”. Duda will notify Customer if it determines that it can no longer meet its applicable obligations. Customer may take reasonable and appropriate steps to stop and remediate unauthorized Processing, subject to the audit and cooperation provisions of this DPA.

17. Government and Legal Requests

  1. If Duda receives a legally binding request from a public authority for Customer Personal Data, Duda will, unless prohibited by law:
    1. notify Customer and provide available information about the request;
    2. inform the authority that Duda is acting as a Processor or Subprocessor and direct the authority to Customer where appropriate;
    3. review the legality and scope of the request and challenge it where Duda reasonably concludes there are grounds to do so; and
    4. disclose only the minimum Customer Personal Data legally required.
  2. Duda will maintain appropriate policies and training concerning government access requests and international-transfer obligations.

18. General

  1. If there is a conflict between this DPA and the Service Agreement concerning Processing of Customer Personal Data, this DPA prevails. If there is a conflict between this DPA and the Standard Contractual Clauses or another mandatory transfer mechanism, the mandatory transfer mechanism prevails.
  2. Liability arising under or in connection with this DPA is subject to the exclusions and limitations of liability in the Service Agreement, except to the extent such limitations are prohibited by Applicable Data Protection Laws or the Standard Contractual Clauses.
  3. Duda may update this DPA in accordance with the amendment or update provisions of the Service Agreement, including where reasonably necessary to reflect changes in Applicable Data Protection Laws, regulatory guidance, transfer mechanisms, or the Services, provided that Duda does not materially reduce the protection of Customer Personal Data during the term without an appropriate contractual basis.
  4. If any provision is invalid or unenforceable, the remaining provisions remain in effect, and the invalid provision will be interpreted or replaced to achieve its intended lawful purpose as closely as possible.
  5. The governing law and jurisdiction provisions of the Service Agreement apply to this DPA, except where Applicable Data Protection Laws or a transfer mechanism require otherwise.
  6. Duda’s privacy contact is privacy@duda.co.

Exhibit A - Description of Processing

Subject matter Processing Customer Personal Data as necessary to provide, host, operate, secure, maintain, support, and improve the Services in accordance with Customer’s documented instructions.
Duration For the term of the Service Agreement and thereafter only for applicable deletion, backup, legal, security, and retention periods described in this DPA and Duda’s documented retention procedures.
Frequency Continuous or as initiated by Customer, its End Customers, Authorized Users, Site Visitors, integrations, automated workflows, or customer-configured campaigns during use of the Services.
Nature of Processing Collection, receipt, recording, organization, structuring, hosting, storage, retrieval, consultation, use, display, generation, modification, transmission, routing, caching, content delivery, communication delivery, analysis at Customer’s direction, security monitoring, troubleshooting, support access, disclosure to authorized Subprocessors, export, restriction, anonymization, and deletion.
Purposes Providing website building, hosting, operation, management, ecommerce, forms, communications, marketing automation, customer and content management, AI-assisted website, code, and content generation, chatbots and customer-created functionality, integrations, analytics at Customer’s direction, technical support, security, fraud prevention, service monitoring, and other features ordered or enabled by Customer.
1. Categories of Data Subjects
  1. Customer employees, contractors, representatives, administrators, and other Authorized Users;
  2. End Customer employees, contractors, representatives, administrators, clients, members, and users;
  3. Site Visitors, leads, prospects, customers, subscribers, purchasers, members, chatbot users, and other individuals who interact with Customer Sites;
  4. individuals identified in Customer Content, uploaded files, website content, support materials, or generated outputs; and
  5. other individuals whose Personal Data Customer or an End Customer elects to Process through the Services.
2. Categories of Customer Personal Data

Depending on the Services selected and Customer’s configuration, Customer Personal Data may include:

  1. Account and identity data: name, business contact details, username, credentials, organization, role, permissions, locale, and account identifiers;
  2. Website and content data: text, images, video, audio, files, business contact information, HTML, CSS, JavaScript, metadata, and content displayed publicly or through restricted pages;
  3. Form, lead, and communication data: names, email addresses, telephone numbers, addresses, company and role information, inquiries, messages, survey responses, attachments, and other form fields configured by Customer;
  4. Ecommerce and transaction data: purchaser details, shipping and billing details, order information, transaction history, product selections, and payment-related tokens or references. Full payment-card data is processed only where supported by an authorized payment provider;
  5. Member and end-user data: registration details, profile information, account activity, preferences, and content submitted through members-only or customer-configured features;
  6. Marketing automation data: lead and subscriber records, communication preferences, consent and opt-in evidence, suppression and unsubscribe records, campaign content, audience segments, delivery status, and engagement events;
  7. AI feature data: prompts, instructions, uploaded or selected source materials, relevant website context, generated code, generated content, outputs, and associated usage metadata;
  8. Technical and usage data: IP address, device and browser information, timestamps, URLs, referrer data, activity events, application and access logs, diagnostic information, and security signals;
  9. Support data: tickets, correspondence, call or meeting content where applicable, troubleshooting files, screenshots, and data disclosed by Customer during support; and
  10. Other Personal Data that Customer or an End Customer chooses to submit to or collect through the Services.
3. Special Categories and Restricted Data

The Services are not generally intended for special category data, highly sensitive personal data, protected health information, full payment-card data, government identification numbers, authentication secrets, or children’s data unless a particular Service is expressly designed and authorized for such Processing. Customer is responsible for ensuring that any such Processing is lawful and supported by appropriate safeguards and instructions.

4. Data Classification and Retention
  1. Customer Content: data managed in the context of Customer Sites, generally retained for the duration of the Services unless deleted earlier by Customer;
  2. Service Data: information required to provide the Services, including user identities, permissions, form responses, ecommerce data, member data, and related records, generally retained for the duration of the Services unless deleted earlier or required for a longer lawful period; and
  3. Operational Data: access logs, application logs, backups, analytics, diagnostics, and security records, generally retained according to Duda’s documented operational schedules. Certain operational records may be retained for up to twelve (12) months, while some indexed logs may be retained for shorter periods.
5. Processing Locations

Customer Personal Data may be Processed in the United States, Israel, the European Economic Area, the United Kingdom, Canada, and other countries in which Duda or its authorized Subprocessors operate, as identified in the Subprocessor list. Content-delivery and edge infrastructure may route or cache website content and related request data globally based on Site Visitor location and service performance requirements.

Exhibit B - Technical and Organizational Measures

Duda’s technical and organizational measures are described in the Security Measures available at https://support.duda.co/hc/en-us/articles/28489936427415-Security-Measures, as updated from time to time. The Security Measures are incorporated into this DPA by reference. Duda may update them during the term, provided that any update does not materially decrease the overall level of protection for Customer Personal Data.

Exhibit C - International Data Transfer Terms

1. EU Restricted Transfers
  1. For a Restricted Transfer subject to the EU GDPR that is not covered by the Data Privacy Framework, an adequacy decision, or another valid transfer mechanism, the Standard Contractual Clauses are incorporated by reference. Module Two applies where Customer is a Controller and Duda is a Processor; Module Three applies where Customer is a Processor and Duda is a Subprocessor.
  2. Clause 7 (Docking Clause) applies. In Clause 9, Option 2 (general written authorization) applies with the notice period in Subsection 2 of Section “Subprocessors” of this DPA. The optional language in Clause 11 does not apply. In Clause 17, Option 2 applies and the governing law is Ireland. Under Clause 18, the courts of Ireland have jurisdiction.
  3. For Annex I: Customer is the data exporter and Duda is the data importer; the Parties’ contact details are those in the Service Agreement; the transfer details are described in Exhibit A; and the competent supervisory authority is determined under Clause 13 and, where no other authority is applicable, the Irish Data Protection Commission.
  4. For Annex II, the technical and organizational measures are described in Exhibit B. For Annex III, the authorized Subprocessors are listed at https://www.duda.co/legal/privacy/subprocessors.
2. United Kingdom Restricted Transfers
  1. For Restricted Transfers subject to the UK GDPR, the Standard Contractual Clauses apply as modified by the UK International Data Transfer Addendum issued by the Information Commissioner’s Office. The tables are completed using the information in this DPA and the Service Agreement. Either Party may end the Addendum as permitted by Section 19 of the Mandatory Clauses if the approved Addendum changes, subject to replacement with another lawful transfer mechanism.
3. Swiss Restricted Transfers
  1. For Restricted Transfers subject to the Swiss Federal Act on Data Protection, the Standard Contractual Clauses apply with references to the EU GDPR interpreted to include Swiss law, references to the EU or Member State interpreted to include Switzerland, and references to the competent authority and courts interpreted as the Swiss Federal Data Protection and Information Commissioner and competent Swiss courts, as applicable.
4. Supplementary Measures and Public-Authority Access
  1. Duda will implement the measures in Exhibit B and will use reasonable efforts, consistent with applicable law, to challenge disproportionate public-authority requests and provide transparency regarding such requests where legally permitted.
  2. If a transfer mechanism relied upon by the Parties is invalidated or becomes unavailable, the Parties will cooperate in good faith to implement an alternative lawful mechanism. Processing may continue under another valid mechanism where available.
    • Platform
    • Website Builder
    • Team Collaboration Tools
    • Client Management
    • The Simple Editor
    • White Label
    • SEO
    • AI Stack
    • AI Visibility
    • Automation
    • Security
    • Full Feature Index
    • Solutions
    • Duda for Agencies
    • Duda for SaaS
    • Duda for Hosts
    • Duda for POS
    • Duda for Enterprise
    • Use Cases
    • Key Features
    • App Store
    • eCommerce
    • Membership
    • Templates
    • Personalization
    • AI Widget Builder
    • Accessibility
    • Client Billing
    • Bookings
    • Compare
    • Duda vs. WordPress
    • Duda vs. Squarespace
    • Duda vs. Wix
    • Duda vs. Webflow
    • Duda vs. Lovable
    • About Us
    • Our Story
    • Management
    • Press
    • Reviews
    • Careers
    • Support
    • Support Portal
    • System Health Check
    • Resources
    • Blog
    • Duda Academy
    • Webinars
    • Product Updates
    • Made with Duda
    • Success Stories
    • Developer Portal
    • Duda Experts
    • Duda Community
    • Affiliate Program
English Español Português
globe
English Español Português Français Italiano Deutsche
arrow
Duda © 2026
Privacy Terms GDPR CA Privacy Notice
facebook facebook twitter twitter linkedin linkedin youtube youtube