Data Processing Addendum

Last Modified: 23rd June 2026

This Data Processing Addendum (“Addendum”) forms part of the Terms of Service (the “Agreement”) between Litmap Limited (NZ company number 6019409) of Level 5, Rutherford House, 33 Bunny Street, Pipitea, Wellington 6011 New Zealand, (“Litmaps”, “Processor”), and the customer entity agreeing to the Agreement (“Customer”, “Controller”).

Litmaps’ data-protection contact: privacy@litmaps.com

This Addendum applies where Litmaps processes Personal Data on behalf of Customer.

1. Definitions

  • “Personal Data” means any information relating to an identified or identifiable natural person.
  • “Processing” has the meaning given under applicable Data Protection Laws.
  • "Data Protection Laws" means all applicable data protection and privacy laws, including the EU GDPR (Regulation (EU) 2016/679), the UK GDPR and UK Data Protection Act 2018, and the New Zealand Privacy Act 2020.
  • "Personal Data Breach" has the meaning in Art. 4(12) GDPR — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
  • "Subprocessor" means any third party engaged by Litmaps to process Personal Data on Customer's behalf.
  • "Standard Contractual Clauses (SCCs)" means the clauses approved under Commission Implementing Decision (EU) 2021/914.

2. Roles of the Parties

  • Customer is the Controller of Personal Data.
  • Litmaps is the Processor of Personal Data.

Litmaps will process Personal Data only on documented instructions from Customer unless required by law.

3. Nature and Purpose of Processing

3.1 Nature of Processing

Litmaps provides a literature discovery and research mapping platform.

Processing may include:

  • collection
  • storage
  • retrieval
  • analysis
  • synchronization with third-party integrations (e.g. reference managers)

3.2 Purpose of Processing

To provide and improve the Litmaps platform, including:

  • account management
  • research mapping and visualization
  • citation and paper tracking
  • integration with third-party tools (e.g. Zotero)

3.3 Categories of Data Subjects

  • Researchers
  • Students
  • Academic staff
  • Customer personnel

3.4 Types of Personal Data

  • Name and contact details (e.g. email)
  • Account and authentication data
  • Usage and activity data
  • Content submitted by users (e.g. saved papers, annotations, metadata)

4. Duration of Processing

Litmaps will process Personal Data for the duration of the Agreement and until deletion in accordance with Section 11.

5. Confidentiality

Litmaps ensures that personnel authorized to process Personal Data are bound by confidentiality obligations.

6. Security Measures

Litmaps implements appropriate technical and organisational measures, including:

  • Encryption of data in transit (TLS)
  • Encryption of data at rest (where applicable)
  • Access controls based on least privilege
  • Authentication and authorization controls
  • Monitoring and logging of system activity
  • Regular backups and recovery processes

7. Subprocessors

7.1 General Authorization

Customer provides general authorization for Litmaps to engage subprocessors to process Personal Data on its behalf.

7.2 List of Subprocessors

A current list of subprocessors, including each subprocessor's corporate name, registered address, the processing activity performed, the categories of Personal Data processed, and the country of processing, is set out in Annex 3 and maintained at https://www.litmaps.com/legal/subprocessors. Litmaps keeps the Annex and the online list consistent.

7.3 Obligations

Litmaps will:
(a) enter into a written agreement with each subprocessor imposing data protection obligations no less protective than those set out in this Addendum; and
(b) remain fully liable for the performance of each subprocessor.

7.4 Changes to Subprocessors

Litmaps may update its subprocessors from time to time. Litmaps will provide notice of any material changes by updating the subprocessor list.

7.5 Objections

Customer may reasonably object to a new subprocessor on data protection grounds by notifying Litmaps within 14 days of the update. In such case, the parties will work in good faith to resolve the concern. If the parties cannot resolve the objection within 30 days, Customer may suspend or terminate the affected part of the Services.

8. Data Subject Rights

8.1 Assistance with Data Subject Requests

Taking into account the nature of the Processing, Litmaps will assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests from data subjects exercising their rights under Data Protection Laws, including the rights of:

  • access (Art. 15) — Litmaps provides authenticated users self-service access to their profile and account data and can supply an extract on request;
  • rectification (Art. 16) — users may correct their account data in-product; Litmaps will action corrections it cannot self-serve;
  • erasure (Art. 17) — Litmaps provides account deletion that removes the user record and cascades to associated workspaces, maps, collections, searches, documents and notes, and deletes the corresponding identity record from the authentication provider (AWS Cognito); residual copies in backups are purged on the standard backup-expiry cycle;
  • restriction (Art. 18) — Litmaps can suspend Processing of an identified account on documented instruction;
  • data portability (Art. 20) — Litmaps will provide the data subject's Personal Data in a structured, commonly used, machine-readable format on request; (see open item — self-service export not yet automated)
  • objection (Art. 21) and rights related to automated decision-making (Art. 22) — Litmaps does not carry out automated decision-making producing legal or similarly significant effects on data subjects.

8.2 Requests Received Directly by Litmaps

If a data subject contacts Litmaps directly regarding their Personal Data, Litmaps will notify Customer without undue delay and within 5 business days, and will not respond except on Customer's documented instructions or as required by law. 

8.3 Cost of Assistance

Litmaps provides this assistance at no additional charge, except where a request is manifestly unfounded, excessive or repetitive, in which case reasonable charges are agreed in advance.

9. Personal Data Breaches

9.1 Notification

Litmaps will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

9.2 Contents of Notification

The notification will describe, to the extent known: (a) the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address it and mitigate adverse effects; and (d) a contact point for further information. Where the information cannot be provided at once, it may be provided in phases without further undue delay.

9.3 Cooperation

Litmaps will reasonably cooperate with Customer and take reasonable remediation steps, and will not make any public statement attributing the breach to Customer without prior consultation, except as required by law.

10. Further Assistance

Taking into account the nature of Processing and information available, Litmaps will reasonably assist Customer with: security of Processing (Art. 32); breach notification to authorities and data subjects (Arts. 33–34); data protection impact assessments (Art. 35); and prior consultation (Art. 36).

11. Deletion or Return of Data

Upon termination of the Agreement, Litmaps will, at Customer’s choice:

  • delete Personal Data, or
  • return Personal Data to Customer

unless retention is required by law.

Backup systems may retain data for a limited period consistent with standard retention practices.

Litmaps will delete or return Personal Data within 30 days of termination and, on Customer's written request, certify completion.

12. International Data Transfers

Litmaps is established in New Zealand, which benefits from a European Commission adequacy decision, so transfers of Personal Data from the EEA to Litmaps do not require additional safeguards. Where Litmaps or its subprocessors process Personal Data in a country without an adequacy decision (including the United States, where the platform is hosted), the transfer is protected by the EU Standard Contractual Clauses (2021/914) and, for UK data, the UK International Data Transfer Addendum, as reflected in Annex 3, together with supplementary technical measures.

13. Audit Rights

Litmaps will make available information reasonably necessary to demonstrate compliance with this Addendum.

Customer may conduct audits (including inspections), subject to:

  • reasonable notice
  • no more than once annually (unless required by law)
  • confidentiality obligations

Audits via third-party reports/certifications and are at the Customer’s expense.

14. Limitation of Liability

Liability under this Addendum is subject to the limitations set out in the Agreement.

15. Governing Law

This Addendum is governed by the same law as the Agreement unless otherwise required by applicable Data Protection Laws.

16. Order of Precedence

In case of conflict, this Addendum prevails over the Agreement with respect to data protection matters. Where the Standard Contractual Clauses apply, they prevail over any conflicting term of this Addendum or the Agreement.

Annex 1: Details of Processing

Subject Matter

Provision of Litmaps services

Duration

For the duration of the Agreement

Nature and Purpose

As described in Section 3

Categories of Data Subjects

As described in Section 3

Types of Personal Data

As described in Section 3

Frequency

Continuous, for the duration of the agreement

Annex 2: Security Measures

Litmaps maintains the following technical and organisational measures pursuant to Article 32 GDPR. Measures are reviewed periodically and may be updated provided the level of protection is not reduced.

1. Pseudonymisation & encryption of Personal Data

  • Encryption in transit: TLS for all external connections; HTTPS-only ingress (insecure connections rejected); TLS for database and cache connections.
  • Encryption at rest: platform storage encrypted at rest via the cloud provider (Azure-managed disk/storage encryption; AWS server-side encryption for object storage and identity data).
  • Credential protection: user passwords stored only as salted bcrypt hashes; never in plaintext.

2. Confidentiality (access control)

  • Authentication: centralised identity via AWS Cognito; signed JWT access tokens with issuer verification; separate user pools for end-users and internal staff; federated sign-in (Google, ORCID).
  • Authorisation: role-based access control across teams and workspaces with an entitlements model; least-privilege access for personnel.
  • Network: application runs in an isolated Azure virtual network; secrets held in the platform secret store, not in code.
  • Abuse prevention: API rate limiting; CAPTCHA on sensitive operations (e.g. email change, sharing, team operations).
  • Personnel: staff authorised to process Personal Data are bound by confidentiality obligations (Addendum in Section 5).

3. Integrity

Per-request tracing identifiers and request logging; input validation; change management through version control, peer code review and an automated CI/CD pipeline.

4. Availability & resilience

Managed, redundant cloud infrastructure with horizontal auto-scaling of application and worker services; application and infrastructure monitoring and metrics (Prometheus / OpenTelemetry); documented incident-response procedures.

5. Restoration / backup

Regular automated backups of the primary database with point-in-time restore via the managed database service; tested recovery processes.

6. Regular testing, assessment & evaluation

Ongoing security monitoring and logging; routine software updates and dependency patching; periodic review of these measures.

7. Data minimisation, retention & deletion

Collection limited to data needed to provide the service; soft-delete followed by cascading hard-deletion on account closure; backups purged on standard expiry; documented retention practices.

Annex 3: Subprocessors

Verified: 22nd June 2026

Subprocessor
Purpose
Location
Transfer safeguard
Amazon Web Services, Inc.
Cloud identity & authentication, transactional email, file/document storage
USA
EU SCCs + UK Addendum
Brevo SAS
Marketing email
EU (France)
Processed within the EEA
Hotjar Ltd
In-app session replay & product analytics (sampled; text fields masked)
EU (Malta)
Procesed within the EEA
Intercom, Inc.
In-app customer support messaging
USA
EU SCCs + UK Addendum
Microsoft (Azure)
Cloud hosting — application, database, cache, storage, logging
USA
EU SCCs + UK Addendum
Mixpanel, Inc.
Product usage analytics
USA
EU SCCs + UK Addendum
Stripe, Inc.
Payment & subscription processing
USA
EU SCCs + UK Addendum