Q: Domain Linits & DPA
1) Hi, im interested in the highest tier ;) Id love to see more domains than 50 (please ;). My clients sites will be faaaaar away from the 2M monthly sessions or any other limit, but i could use it for a few more smaller clients sites that don`t have a lot of traffic but need to be compliant as well.
2) Also Is there a written and signed DPA that you offer for your GDPR clients? Im usually singning contracts aka DPAs (Datenweiterverarbeitungsvereinbarungen) with every external company i`m involved with, in compliance with the gdpr.
3) I read that your not offering data hosing exclusively within the EU. Is that on the roadmap?
4) are all stored ips 7 sessions obfuscated?
Thanks!
Dash_Concord
Aug 30, 2024A: Hi Philipp. Thanks for the great questions. I know we connected via Intercom and covered the items above, but adding the answers here as well for other folks:
1(a). If you want more than 50 domains via the AppSumo deal, we can work with you to combine multiple purchases (up to 100 domains via two Tier 10 packages).
1(b). If you aren’t sure when and how often you will need extra items like domains, we do currently allow all lifetime members to add on additional metered billing for sessions if needed and the same goes for any of our add-ons as well (domains, users, data systems, etc.). We have agreed to guaranteed discounts on domains, users, and data systems add-ons when needed for AppSumo members.
2. The European Commission issued modernized standard Standard Contractual Clauses (SCCs) in June of 2021 that our legal team utilizes in our agreements. We offer this to all customers via our Data Protection Agreement, and the DPA and the associated sub-processors details can be found here:
https://www.concord.tech/legal/data-protection-agreement
https://www.concord.tech/legal/sub-processors
We use clickwrap agreements on sign-up so the additional signing of contracts there isn't required.
3. Yeah, that is correct. As of a few years ago, the modernized SCCs are compliant and it is no longer necessary to host in the EU to comply with GDPR. Not everyone is familiar with that change, so we do get that question occasionally and there are also other companies that have asked about it for other reasons so we do still have it on the roadmap. It is just currently lower in priority since it is no longer a specific requirement. If anyone is reading this and looking for this on your side, please send us the details at [email protected] so that we can include that in our roadmap planning sessions.
4. Yes, we anonymize all IP addresses during both session creation and the updating of sessions.
Dash, if someone purchases 2 tier10 codes will some of the other non-domain attributes also double? like 4M monthly sessions, 14, 000 data requests, etc?
Mavener
Yes, we would double those allocations as well.