Algolia Search and Sync Data Processing Agreement
1. Scope
This Data Processing Agreement ("DPA") forms part of the Terms and Conditions for Algolia Search and Sync between Candid Leap LLC ("Candid Leap", "we", "us") and the customer using the App ("Customer").
This DPA applies where Candid Leap processes personal data on the Customer's behalf.
If this DPA conflicts with the Terms regarding processing of personal data, this DPA controls for that processing.
Terms such as personal data, controller, processor, data subject and personal data breach have the meanings given to them by applicable data protection law.
2. Roles
For personal data contained in Webflow CMS content that the Customer instructs the App to process, the Customer is the controller and Candid Leap is the processor.
If the Customer is itself acting as a processor for another controller, Candid Leap acts as the Customer's subprocessor.
The Customer is responsible for having the authority and lawful basis necessary to process and sync the personal data it provides to the App.
Candid Leap acts as an independent controller for operator and account information described in the Privacy Policy.
This DPA does not govern that processing.
Visitor search queries and Algolia Insights events that travel directly from the visitor's browser to the Customer's Algolia account are not processed through Candid Leap's backend.
3. Processing Details
Subject Matter
Synchronizing selected Webflow CMS content into the Customer's Algolia application and operating related App features.
Duration
For as long as Candid Leap processes personal data on the Customer's behalf, including any applicable deletion or provider-retention period.
Nature of Processing
Processing may include:
- reading selected Webflow CMS content;
- transmitting and transforming content;
- temporary in-memory processing;
- writing content to the Customer's Algolia index;
- processing Webflow webhooks;
- storing configuration and sync metadata; and
- deleting data where applicable.
Purpose
Providing the App according to the Customer's instructions.
Types of Personal Data
Depending on what the Customer places in mapped CMS fields, personal data may include:
- names;
- contact details;
- professional information;
- biographies;
- images; and
- similar website content.
The prohibited-data restrictions in the Terms continue to apply.
Categories of Data Subjects
Data subjects may include:
- staff;
- authors;
- contributors;
- customers;
- contacts; or
- other individuals described in the Customer's CMS content.
4. Customer Instructions and Candid Leap Obligations
Candid Leap will process personal data only on documented instructions from the Customer, unless applicable law requires otherwise.
The Customer's mapped Collections, field mappings, locales, sync configuration and other actions in the App are documented instructions for purposes of this DPA.
If we are required by law to process personal data outside those instructions, we will inform the Customer before doing so unless the law prohibits that notice.
Candid Leap will ensure that personnel authorized to process Customer personal data are subject to appropriate confidentiality obligations.
Taking into account the nature of processing and information available to us, we will provide reasonable assistance with the Customer's obligations regarding:
- data subject rights;
- security;
- breach response;
- data protection impact assessments; and
- regulatory consultation where required by applicable law.
5. Security
Candid Leap will maintain appropriate technical and organizational measures designed to protect Customer personal data.
Current measures are summarized in Annex A.
We may update security measures over time, provided that the overall level of protection is not materially reduced.
6. Subprocessors
The Customer gives Candid Leap general authorization to use subprocessors to provide the App.
Current subprocessors are listed in Annex B.
We will require subprocessors that process Customer personal data on our behalf to protect that data as required by applicable law.
We remain responsible for our obligations regarding those subprocessors to the extent required by law.
Where required by applicable law, we will provide reasonable prior notice of a new or replacement subprocessor so the Customer has an opportunity to raise a reasonable data-protection objection.
7. Data Subject Requests
Taking into account the nature of processing, Candid Leap will provide reasonable assistance where necessary for the Customer to respond to valid data subject requests.
Because synced content originates in the Customer's Webflow CMS and is written to the Customer's Algolia account, the Customer should normally make corrections or deletions in those systems and re-sync where appropriate.
If a data subject contacts Candid Leap directly about personal data that we process only on behalf of a Customer, we may refer the request to that Customer unless applicable law requires us to respond directly.
8. Personal Data Breaches
If Candid Leap becomes aware of a personal data breach affecting personal data processed on the Customer's behalf, we will notify the Customer without undue delay as required by applicable law.
We will provide information reasonably available to us about:
- the nature of the incident;
- affected data;
- likely consequences; and
- measures taken or proposed.
We will reasonably cooperate with the Customer's response.
A breach notification does not constitute an admission of fault or liability.
9. Deletion
When the Customer disconnects or uninstalls the App, Candid Leap will stop further processing through that connection and delete the site's stored credentials, configuration, mappings and sync history from its active database, subject to the limited exceptions below.
The Customer's Algolia index and records remain in the Customer's own Algolia account and are not deleted by Candid Leap.
Queue messages already accepted before deletion may remain until processed or expired, for up to 14 days.
They contain content identifiers rather than CMS field values and cannot use deleted credentials.
Operational logs, analytics records, email delivery records and other provider-held records may remain for their normal retention periods or where retention is required by law.
This DPA continues to apply to Customer personal data for as long as Candid Leap retains it.
10. International Transfers
Candid Leap is based in the United States and may process Customer personal data in the United States and other locations where our subprocessors operate.
Where applicable data protection law requires a specific safeguard for an international transfer, the parties will cooperate to put an appropriate transfer mechanism in place.
If the Customer's use of the App involves a restricted transfer from the European Economic Area, United Kingdom, Switzerland, or another jurisdiction requiring additional transfer safeguards, the Customer should contact Candid Leap before using the App to process personal data subject to those restrictions.
Nothing in this DPA represents that a particular international transfer mechanism applies unless it has been validly entered into or incorporated between the parties.
11. Compliance Information and Audits
Upon reasonable request, Candid Leap will provide information reasonably necessary to demonstrate compliance with this DPA.
Where applicable law requires additional audit rights and available information is insufficient, the parties will cooperate in good faith on a reasonable audit or review that:
- protects the security and confidentiality of other customers; and
- does not unnecessarily disrupt operations.
12. Liability and Duration
Liability arising under this DPA is subject to the limitations in the Terms except where applicable data protection law does not permit those limitations.
This DPA remains in effect for as long as Candid Leap processes personal data on the Customer's behalf.
Confidentiality, security, deletion and other obligations that by their nature must survive continue for as long as Candid Leap retains applicable personal data.
13. Contact
Processor / Data Importer
Candid Leap LLC
1417 N Catalina St
Los Angeles, CA 90027
United States
Email: algolia-support@candidleap.com
Annex A — Technical and Organizational Measures
Encryption at Rest
Webflow OAuth tokens and Algolia sync keys are encrypted using AES-256-GCM before storage.
Encryption keys are held separately in the server environment.
Encryption in Transit
Application and service-provider connections use HTTPS/TLS.
MongoDB production connectivity must remain configured to use Atlas TLS/SRV connectivity.
Webhook Integrity
Incoming Webflow webhooks are HMAC-SHA256 verified with replay protection before processing.
Unverified requests are rejected.
Access Control
API access uses:
- short-lived tokens derived from Webflow-verified identity;
- rate limiting;
- per-site authorization checks; and
- internal shared-secret authentication for service-to-service requests.
Tenant Isolation
Requests and database operations are scoped to the authenticated site so one customer cannot access another customer's configuration, credentials or history through the application.
Credential Protection
Sensitive credentials are not returned by application APIs and are redacted from application logs and analytics.
Logging
Normal application logs exclude request bodies and query strings and redact credentials, tokens and email fields.
Logs may include:
- request metadata;
- client IP addresses;
- site identifiers; and
- server error details.
Product Analytics
PostHog runs in the backend and Designer extension only.
Session replay, autocapture, heatmaps, pageview tracking and surveys are disabled.
Analytics events are designed not to include CMS content or credentials.
Release Security
Changes pass automated tests and dependency-vulnerability checks in CI.
Public script releases require explicit human approval and are published with package provenance.
Incident Response
Candid Leap maintains operational monitoring, alerting and manual procedures to investigate and respond to service and security incidents.
Annex B — Subprocessors
Subprocessor
Purpose
Processing Location
MongoDB, Inc. (Atlas)
Primary database
United States
Railway Corp.
Backend application hosting and operational logs
United States
Cloudflare, Inc.
Webhook verification, edge processing and queueing
Global edge network
PostHog, Inc.
Product analytics and operational telemetry
United States
Postmark
Transactional email delivery
Provider infrastructure
Customer-Directed Services
Webflow and Algolia are not Candid Leap subprocessors for the customer's own platform accounts.
The Customer connects and controls its own accounts and agreements with those providers.
Candid Leap reads selected Webflow content and writes it to the Customer's Algolia account according to the Customer's instructions.
npm and jsDelivr distribute the public front-end script.
They do not receive CMS content from Candid Leap as part of the sync process, although jsDelivr may receive ordinary technical request information from site visitors when the script is loaded.

