This PageShield EU Data Act Addendum ("Addendum") supplements the PageShield Terms of Service ("Terms") between the Customer and CRAFTAC SRL ("PageShield"). It is incorporated into the Terms under Section 16A only within the scope stated below. Capitalised terms not defined in this Addendum have the meanings given in the Terms or, where applicable, Regulation (EU) 2023/2854.
This Addendum applies to a Customer in the European Union, or in the European Economic Area where the relevant EU Data Act provisions apply, and to any other Customer entitled to Chapter VI protection, only to the extent that Regulation (EU) 2023/2854 (the "EU Data Act") applies to PageShield as a provider of the relevant data processing service and to the affected Service or Plan. It does not constitute an unconditional acknowledgement that every PageShield feature, Plan or Customer relationship falls within Chapter VI.
This Addendum does not apply to a Service expressly supplied only as a non-production version for testing and evaluation for a limited period where Article 31(2) of the EU Data Act applies and PageShield informed the prospective Customer before contract formation. A normal trial of the production Service is not excluded merely because it is free or time-limited.
Where this Addendum applies, it governs switching, portability, transition, retrieval, deletion, exit support and related cooperation. It does not reduce a more favourable right available under mandatory law, the DPA or the Service interface.
PageShield makes this Addendum available before contractual acceptance in an electronic form that permits the Customer to store and reproduce it. The accepted version and effective date are recorded or made available with the contractual documentation in accordance with the Terms.
The Customer may submit a written switching request to support@pageshield.io with the subject line "EU Data Act Switching Request". The request must identify the Account and state whether the Customer intends to:
(a) switch all or an identified part of the applicable Service to a data processing service covering the same service type and offered by another provider;
(b) port the applicable Exportable Data and Portable Digital Assets to an on-premises ICT infrastructure; or
(c) terminate the applicable Service and request erasure of the Exportable Data and Portable Digital Assets without switching to another service.
Where another provider or representative is involved, the Customer must provide destination details, identify any authorised third party acting on its behalf and provide information, access permissions and security instructions reasonably necessary to perform the transfer. PageShield will acknowledge the request and identify material missing information without undue delay. A request becomes complete when PageShield has the information reasonably necessary to validate authority, scope and destination and to begin the switching process securely.
PageShield may apply a notice period before the switching process begins, but that notice period will not exceed two (2) months. The notice period will run from the date on which PageShield receives a switching request through the designated channel that identifies the relevant Account and states whether the Customer intends to switch to another provider, port the applicable data and digital assets to an on-premises ICT infrastructure, or terminate the affected Service and request erasure without switching.
PageShield will acknowledge the switching request without undue delay and will identify the applicable initiation date in that acknowledgement or in a follow-up notice provided without undue delay. PageShield may begin the switching process earlier where reasonably practicable.
PageShield may request information strictly necessary to verify the Customer’s authority, identify the relevant Account, define the scope of the request, validate the proposed destination or protect the security of the transfer. A request for clarification or additional information will not suspend, postpone or restart any statutory deadline running from the making of the switching request, except where the Customer materially changes the scope of the request or where applicable law expressly permits otherwise.
The transitional period for carrying out the switch will not exceed thirty (30) calendar days after the applicable notice period. If completion within that period is technically unfeasible, PageShield will notify the Customer within fourteen (14) working days of the making of the switching request, duly explain and substantiate the technical reasons and specify an alternative transitional period that will not exceed seven (7) months. PageShield bears the responsibility for demonstrating the technical unfeasibility of completing the switch within the mandatory transitional period.
The Customer may extend the transitional period once for a period that the Customer considers more appropriate for its own purposes. The Customer may exercise that right before or during the transitional period.
The Terms remain applicable during the notice and transitional periods. Standard Subscription fees remain payable, where applicable, only for the period during which the Service continues to be supplied. All payment transactions are administered through Lemon Squeezy as Merchant of Record.
After validating a switching request, PageShield and the Customer will document a Switching and Exit Plan proportionate to the affected Service. The Plan will identify the scope of the switch, the parties and designated contacts, the destination, target dates, the applicable notice, transitional and retrieval periods, the exportable categories, formats and interfaces, each party's responsibilities, security arrangements, known continuity risks and mitigations, technical restrictions, and any validation or test steps reasonably required to confirm that the export can be used in the destination environment.
The Plan supplements this Addendum and does not extend a statutory period unless the EU Data Act permits the extension and the parties record it. The parties will update the Plan where material circumstances change. At the Customer's reasonable request, PageShield will support a proportionate export-validation test; any issue identified will be assessed in good faith and reflected in the Plan.
During the switching process, PageShield will, to the extent required by the EU Data Act:
(a) provide reasonable assistance to the Customer and third parties authorised by the Customer;
(b) act with due care to maintain business continuity and continue contracted functions during the applicable transitional period;
(c) provide clear information about known risks to continuity that may arise from switching;
(d) maintain an appropriate level of security for the Service and data during transfer and retrieval;
(e) provide capabilities, information, documentation and technical support reasonably necessary to enable export;
(f) support the Customer's exit strategy by providing information reasonably necessary to plan, validate and complete the switch;
(g) where Article 30(2) of the EU Data Act applies to PageShield for the relevant data processing service, make open interfaces, including a documented authenticated export API or equivalent open machine-to-machine interface where appropriate, available free of charge and on an equal basis to Customers and concerned destination providers, with sufficient technical information to enable software to communicate with the Service for portability and interoperability, subject only to proportionate identity, authority, authentication and security controls; and
(h) notify the Customer without undue delay of any significant security or business-continuity incident that materially affects the switching process, transfer or retrieval, provide available information on impact and mitigation, and coordinate that notice with any Personal Data Breach obligations under the DPA.
(i) not impose or maintain commercial, contractual, technical or organisational obstacles that prevent or unreasonably hinder a switch, porting to an on-premises ICT infrastructure or, where relevant, the simultaneous use of another data processing service, except for proportionate authentication, security, integrity and legal-compliance controls permitted by applicable law.
PageShield is not required to rebuild the Service in a destination environment, develop a new service or technology solely for a particular switch, perform import or implementation in the destination environment, or disclose assets protected by intellectual property rights, trade secrets or security requirements, except to the extent mandatory law expressly requires otherwise.
The Customer is responsible for:
(a) cooperating in good faith and taking reasonable steps to complete the switch within the applicable period;
(b) selecting and coordinating with the destination provider or on-premises environment;
(c) identifying, validating, downloading, importing and implementing exported data and assets in the destination environment, unless otherwise agreed in writing;
(d) protecting credentials, export files, tokens and confidential information and using secure transfer methods;
(e) ensuring that any authorised third party complies with the Terms, this Addendum, applicable confidentiality obligations and PageShield intellectual property and security requirements; and
(f) notifying PageShield without undue delay when the switch has been successfully completed or if a material transfer problem is identified.
The Customer remains responsible for acts and omissions of an authorised third party acting on its behalf. PageShield is not responsible for compatibility, security, availability or performance of a destination provider or the Customer's on-premises infrastructure, without limiting obligations that cannot lawfully be excluded.
"Exportable Data" means input and output data, including metadata, directly or indirectly generated or co-generated by the Customer's use of the applicable Service, excluding the categories stated exhaustively in Section 7. "Portable Digital Assets" means digital elements for which the Customer has a right of use independent of the continuing PageShield contractual relationship and that are required to use the Exportable Data effectively in a destination environment, to the extent technically portable without disclosing excluded assets.
The following list is the exhaustive specification, as of this version, of categories that can be ported during the switching process, to the extent they remain retained under applicable retention rules when switching begins:
(a) Customer-provided Account and organisation information held by PageShield;
(b) Protected Domains, Protected Pages, protected URLs, Redirect Destinations, authorised-domain lists and exclusions;
(c) Customer-created protection profiles, including profiles that are inactive solely because they exceed the applicable Plan limit, together with redirect modes, triggers, percentages, schedules, alert settings and other Customer configurations;
(d) webhook and integration destination settings, excluding passwords, private keys, access tokens or other secrets that cannot be exported securely; generic webhook alert payloads do not contain full URLs, referrers, user-agent strings, IP addresses or profile names;
(e) Detection Event records, including retained approximate country and city fields and bot/human/unknown Classification Results, Heartbeat records, reports and other Customer-specific output records retained when export begins;
(f) customer-facing Notification Suppression Rule records and the available rule metadata generated and retained by the Service, to the extent included in the then-current export schema, including a separate non-secret record identifier where generated, but excluding raw source IP addresses, HMAC keys or secrets, HMAC-derived matching values, rotating salts, internal ASN-list match signals and internal classification or matching logic;
(g) Customer-created export files and configuration assets for which the Customer has a right of use independent of the continuing PageShield contractual relationship and which are technically portable.
PageShield is not required to restore data already deleted or irreversibly anonymised before the switching request in accordance with the Terms, DPA, Privacy Policy or applicable law.
The following list is the exhaustive specification, as of this version, of categories excluded from Exportable Data and Portable Digital Assets, to the extent their transfer would disclose PageShield or third-party intellectual property, trade secrets or security-sensitive information and provided that the exclusion does not impede or delay switching contrary to applicable law:
(a) source code, object code, software libraries, proprietary APIs not made available to Customers and internal technical documentation;
(b) algorithms, classification and detection logic, internal ASN or provider lists, internal models, scoring methods, security rules, matching logic and abuse-prevention mechanisms;
(c) provider credentials, encryption keys, HMAC keys or secrets, HMAC-derived matching values, rotating salts, other cryptographic secrets, infrastructure configurations, deployment information and vulnerability-sensitive data;
(d) internal operational logs, internal debugging records, internal risk signals and internal incident-response materials that are not Customer-specific Service output;
(e) aggregated or irreversibly anonymised statistics and Service Usage Data that do not constitute Customer-generated Exportable Data; and
(f) third-party data, software or materials that PageShield is not authorised to transfer.
The Starter free tier does not include the ordinary commercial dashboard CSV-export feature, including where the Account previously had a paid Subscription. That Plan limitation does not restrict a switching right under this Addendum. For ordinary product exports on an eligible paid Plan, once the relevant functionality is enabled and has generated retained records, the then-current CSV export package includes retained approximate country and city and the bot/human/unknown Classification Result with Detection Event records, and includes customer-facing Notification Suppression Rule records with available scope and lifecycle metadata, whether in the Detection Event CSV or a separate rules CSV. Any exported rule identifier is a separate non-secret record identifier and not the internal HMAC-derived matching value. For a valid switching request, PageShield will provide the applicable Exportable Data and Portable Digital Assets through a secure export in one or more structured, commonly used and machine-readable formats. The then-current supported formats, packaging method, field names and delivery mechanism will be identified in the public switching documentation and the Switching and Exit Plan. Where Article 30(2) of the EU Data Act applies to PageShield for the relevant software data processing service, PageShield will make open interfaces available free of charge and on an equal basis to Customers and concerned destination providers to facilitate switching, with sufficient documentation to enable software to communicate with the Service for data portability and interoperability, subject to identity, authority and destination verification and proportionate authentication and security controls. Delivery may use an authenticated dashboard flow or an access-controlled link. Each download link expires after seven (7) days and may be regenerated throughout the retrieval period. No fee applies solely because the Customer uses a free Plan. Where a relevant common specification or harmonised standard becomes applicable, PageShield will implement compatibility within the period required by law.
Notification Suppression Rules are exported as customer-facing configuration records together with the available scope and lifecycle metadata generated and retained by the Service, including a separate non-secret rule-record identifier, Customer or profile scope, status, creation time, last-match time and expiry time where those fields are generated and retained under the then-current export schema. The exported rule-record identifier is not the HMAC-derived matching value used internally to recognise a future source. Raw source IP addresses, HMAC keys or secrets, HMAC-derived matching values, rotating salts, transient ASN values, internal ASN-list match signals, internal data-centre/residential signals and internal classification or matching logic are not exported. Because PageShield does not retain the raw source IP address and future matching depends on PageShield-controlled HMAC key material, an exported rule record may be preserved as configuration history or evidence but cannot ordinarily be reactivated for future source matching by another provider without a new destination-provider identifier or a new instruction based on data lawfully available to the Customer. Only the resulting bot/human/unknown Classification Result, and not the transient ASN, network-type signal or technical reasons, is included with the Detection Event. These technical limitations will be described in the public switching documentation and Switching and Exit Plan and will not be used to withhold other Exportable Data.
PageShield makes the information required for switching available at https://pageshield.io/eu-data-act-addendum.html and in any linked technical switching documentation. The public information describes the switching procedure, the Switching and Exit Plan process, the then-current formats, packaging methods and interfaces, relevant standards or open interoperability specifications, authentication and security requirements, known restrictions and technical limitations, and the estimated time ordinarily required for export. Where an open interface applies, the documentation contains sufficient technical information to enable software to communicate with that interface for portability and interoperability. The Customer may also request the information from support@pageshield.io.
The affected Service contract, or the affected part of the Service where a partial switch is permitted, will be deemed terminated automatically upon successful completion of the switching process.
Successful completion may be established by:
(a) the Customer’s written confirmation;
(b) confirmation from the destination provider or an authorised third party acting on the Customer’s behalf;
(c) the successful completion of any technical verification procedure agreed between the parties; or
(d) other objective evidence reasonably demonstrating that the applicable Exportable Data and Portable Digital Assets have been delivered or made available in accordance with the agreed switching process and that the Customer or the destination provider is able to retrieve them.
The Customer must cooperate in good faith and notify PageShield without undue delay when the switch has been completed successfully. PageShield may request reasonable confirmation or evidence of completion but will not unreasonably withhold, condition or delay recognition of successful completion. The absence of a separate formal confirmation from the Customer will not, by itself, allow the affected Service contract to remain in force indefinitely where successful completion is established by objective evidence.
Upon successful completion of the switching process, PageShield will notify the Customer without undue delay, on a durable medium, that the affected Service contract or the affected part of the Service has terminated and will state the effective date of termination.
Where the Customer elects erasure without switching to another provider or porting to an on-premises ICT infrastructure, the affected Service contract will be deemed terminated automatically at the end of the applicable maximum notice period, and PageShield will notify the Customer of the termination on a durable medium.
After the agreed transitional period ends, the Exportable Data and Portable Digital Assets will remain available for retrieval for at least thirty (30) calendar days, unless a longer period is agreed or required by applicable law. Access during the retrieval period may be limited to the functionality reasonably necessary to retrieve the applicable data and assets.
After successful completion of the switching process and expiry of the retrieval period, or any longer period agreed in writing, PageShield will erase all Exportable Data and Portable Digital Assets generated directly by or relating directly to the Customer, subject only to retention required by applicable law. PageShield will provide confirmation of deletion upon reasonable request.
Return and deletion of Customer Personal Data remain governed by the DPA and applicable Data Protection Laws. Personal data processed independently by PageShield as controller remain governed by the Privacy Policy and may be retained only for the separate lawful purposes and periods stated in that Policy.
PageShield does not impose switching charges for standard assistance, interfaces and export functionality required by applicable law. PageShield voluntarily applies this no-charge policy from the effective date of this Addendum, including during the period in which Article 29 of the EU Data Act would otherwise permit reduced cost-based switching charges before 12 January 2027. Standard Subscription fees may continue only for periods in which the Service continues to be supplied, including an agreed extension requested by the Customer. No fee applies to a free Plan solely because a switching request is made.
Additional bespoke assistance that goes beyond PageShield's mandatory switching obligations may be charged only where the Customer requests it and accepts scope and price in advance. Every payment, credit or refund relating to the Service or such additional assistance will be processed through Lemon Squeezy as Merchant of Record.
Where Article 28 of the EU Data Act applies, PageShield makes available and keeps updated at https://pageshield.io/eu-data-act-addendum.html and in any linked technical documentation: (a) the jurisdictions to which the ICT infrastructure used for the individual Service is subject; and (b) a general description of technical, organisational and contractual measures used to prevent international governmental access to or transfer of non-personal data held in the European Union where that access or transfer would conflict with Union law or the law of a Member State. The main application environment, active database and backups are hosted with Hetzner in Germany. Cloudflare provides authoritative DNS and basic DNS-layer protection, is not configured as an application reverse proxy and does not receive application, API, Protection Snippet, detection or switching payloads through the Service flow; it may process limited Account, zone and DNS-operational data under its applicable documentation.
Personal-data disclosure and international transfers remain subject to the GDPR, DPA and other applicable Data Protection Laws. This Addendum does not itself create a lawful basis for disclosure of personal data to a destination provider or representative.
If this Addendum conflicts with the Terms, this Addendum controls only for switching, portability, transition, retrieval, deletion, exit support and related matters within its stated scope. The DPA and mandatory Data Protection Laws control processing, protection, disclosure, transfer, return and deletion of Customer Personal Data. The Terms control in all other respects.
The governing law, jurisdiction, notice, assignment, severability, waiver and other general provisions of the Terms apply to this Addendum. Questions and switching requests may be sent to support@pageshield.io with the subject line "EU Data Act Switching Request".
CRAFTAC SRL
Romanian Trade Register no.: J22/725/2024
Unique identification code (CUI): 49662167
Str. Bisericii 9, Bl. 65, Sc. A, Et. 4, Ap. 15, Cod 707085, Sat Lunca Cetatuii, Judetul Iasi, Romania