Last Modified: 23rd June 2026
This Data Processing Addendum (“Addendum”) forms part of the Terms of Service (the “Agreement”) between Litmap Limited (NZ company number 6019409) of Level 5, Rutherford House, 33 Bunny Street, Pipitea, Wellington 6011 New Zealand, (“Litmaps”, “Processor”), and the customer entity agreeing to the Agreement (“Customer”, “Controller”).
Litmaps’ data-protection contact: privacy@litmaps.com
This Addendum applies where Litmaps processes Personal Data on behalf of Customer.
Litmaps will process Personal Data only on documented instructions from Customer unless required by law.
Litmaps provides a literature discovery and research mapping platform.
Processing may include:
To provide and improve the Litmaps platform, including:
Litmaps will process Personal Data for the duration of the Agreement and until deletion in accordance with Section 11.
Litmaps ensures that personnel authorized to process Personal Data are bound by confidentiality obligations.
Litmaps implements appropriate technical and organisational measures, including:
Customer provides general authorization for Litmaps to engage subprocessors to process Personal Data on its behalf.
A current list of subprocessors, including each subprocessor's corporate name, registered address, the processing activity performed, the categories of Personal Data processed, and the country of processing, is set out in Annex 3 and maintained at https://www.litmaps.com/legal/subprocessors. Litmaps keeps the Annex and the online list consistent.
Litmaps will:
(a) enter into a written agreement with each subprocessor imposing data protection obligations no less protective than those set out in this Addendum; and
(b) remain fully liable for the performance of each subprocessor.
Litmaps may update its subprocessors from time to time. Litmaps will provide notice of any material changes by updating the subprocessor list.
Customer may reasonably object to a new subprocessor on data protection grounds by notifying Litmaps within 14 days of the update. In such case, the parties will work in good faith to resolve the concern. If the parties cannot resolve the objection within 30 days, Customer may suspend or terminate the affected part of the Services.
Taking into account the nature of the Processing, Litmaps will assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests from data subjects exercising their rights under Data Protection Laws, including the rights of:
If a data subject contacts Litmaps directly regarding their Personal Data, Litmaps will notify Customer without undue delay and within 5 business days, and will not respond except on Customer's documented instructions or as required by law.
Litmaps provides this assistance at no additional charge, except where a request is manifestly unfounded, excessive or repetitive, in which case reasonable charges are agreed in advance.
Litmaps will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notification will describe, to the extent known: (a) the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address it and mitigate adverse effects; and (d) a contact point for further information. Where the information cannot be provided at once, it may be provided in phases without further undue delay.
Litmaps will reasonably cooperate with Customer and take reasonable remediation steps, and will not make any public statement attributing the breach to Customer without prior consultation, except as required by law.
Taking into account the nature of Processing and information available, Litmaps will reasonably assist Customer with: security of Processing (Art. 32); breach notification to authorities and data subjects (Arts. 33–34); data protection impact assessments (Art. 35); and prior consultation (Art. 36).
Upon termination of the Agreement, Litmaps will, at Customer’s choice:
unless retention is required by law.
Backup systems may retain data for a limited period consistent with standard retention practices.
Litmaps will delete or return Personal Data within 30 days of termination and, on Customer's written request, certify completion.
Litmaps is established in New Zealand, which benefits from a European Commission adequacy decision, so transfers of Personal Data from the EEA to Litmaps do not require additional safeguards. Where Litmaps or its subprocessors process Personal Data in a country without an adequacy decision (including the United States, where the platform is hosted), the transfer is protected by the EU Standard Contractual Clauses (2021/914) and, for UK data, the UK International Data Transfer Addendum, as reflected in Annex 3, together with supplementary technical measures.
Litmaps will make available information reasonably necessary to demonstrate compliance with this Addendum.
Customer may conduct audits (including inspections), subject to:
Audits via third-party reports/certifications and are at the Customer’s expense.
Liability under this Addendum is subject to the limitations set out in the Agreement.
This Addendum is governed by the same law as the Agreement unless otherwise required by applicable Data Protection Laws.
In case of conflict, this Addendum prevails over the Agreement with respect to data protection matters. Where the Standard Contractual Clauses apply, they prevail over any conflicting term of this Addendum or the Agreement.
Provision of Litmaps services
For the duration of the Agreement
As described in Section 3
As described in Section 3
As described in Section 3
Continuous, for the duration of the agreement
Litmaps maintains the following technical and organisational measures pursuant to Article 32 GDPR. Measures are reviewed periodically and may be updated provided the level of protection is not reduced.
Per-request tracing identifiers and request logging; input validation; change management through version control, peer code review and an automated CI/CD pipeline.
Managed, redundant cloud infrastructure with horizontal auto-scaling of application and worker services; application and infrastructure monitoring and metrics (Prometheus / OpenTelemetry); documented incident-response procedures.
Regular automated backups of the primary database with point-in-time restore via the managed database service; tested recovery processes.
Ongoing security monitoring and logging; routine software updates and dependency patching; periodic review of these measures.
Collection limited to data needed to provide the service; soft-delete followed by cascading hard-deletion on account closure; backups purged on standard expiry; documented retention practices.
Verified: 22nd June 2026