Last updated July 16, 2026
Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement between MobApp Labs LLC, operating as WebMoment, and the customer using WebMoment.
Capture websites, preserve every version, and create timelines you can revisit, compare, and share.
Create your free accountCapture Desktop, Tablet, and Mobile together, so you can see how a Page truly responds across devices.
Legal
Data processing terms for WebMoment customers.
Last updated July 16, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between MobApp Labs LLC, operating as WebMoment, and the customer using WebMoment.
This DPA applies where WebMoment processes personal data on behalf of a customer in connection with the Services.
For Customer Data processed through Workspaces, Pages, Moments, Trackings, Replay archives, comments, uploads, and APIs:
Customer determines what URLs are submitted, what content is captured, and how Customer Data is used.
WebMoment processes Personal Data to provide the Services, including:
Automated website Capture, Replay preservation, scheduled Tracking, collaboration, storage, APIs, and related SaaS services.
For the term of the Agreement and any post-termination retention period required by the Agreement, law, backups, or legitimate operational needs.
Data subjects may include:
Personal Data may include:
Processing may include collection, storage, hosting, retrieval, transmission, organization, deletion, export, analysis for security, and technical support.
WebMoment will process Personal Data only according to Customer's documented instructions, including the Agreement, product settings, API requests, and support instructions.
WebMoment will notify Customer if it believes an instruction violates applicable data protection law, unless prohibited by law.
Customer is responsible for:
WebMoment will ensure personnel authorized to process Personal Data are bound by confidentiality obligations or are subject to appropriate statutory duties.
WebMoment will maintain appropriate technical and organizational measures designed to protect Personal Data.
Measures may include:
Security practices are summarized in Security.
Customer authorizes WebMoment to engage Subprocessors to provide the Services.
Current Subprocessors are listed in Subprocessors.
WebMoment remains responsible for Subprocessor performance of data protection obligations required by this DPA.
WebMoment may add or replace Subprocessors as the Services evolve. Where required by law or agreement, notice will be provided before a material change takes effect.
If Customer objects and WebMoment cannot reasonably accommodate the objection, either party may terminate affected Services according to the Agreement.
WebMoment will provide reasonable assistance for data subject requests where Customer cannot fulfill the request through the Services.
Customer is responsible for verifying and responding to requests where Customer is the Controller.
WebMoment will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Data.
Notice will include available information reasonably needed for Customer to meet legal obligations, subject to ongoing investigation and legal restrictions.
WebMoment will provide reasonable information to help Customer complete data protection impact assessments and regulator consultations where required and where the information is not otherwise available.
Upon termination or written request, WebMoment will delete or return Customer Data according to the Agreement, product functionality, legal requirements, and backup retention.
Deletion from backups may occur on normal backup rotation cycles.
WebMoment will make available information reasonably necessary to demonstrate compliance with this DPA.
Audits must:
Where available, third-party reports or security documentation may satisfy audit requests.
WebMoment and Subprocessors may process Personal Data outside Customer's jurisdiction.
Where required, transfers will rely on appropriate mechanisms, such as SCCs, UK transfer mechanisms, adequacy decisions, or other lawful transfer tools.
Where SCCs are required, the parties agree that the applicable SCCs are incorporated by reference and apply to transfers of Personal Data from the EEA, UK, or Switzerland to countries without an adequacy decision.
The parties will complete SCC details as required by applicable law and the parties' roles.
Where CCPA or similar U.S. privacy laws apply, WebMoment acts as a service provider or processor for Customer Data.
WebMoment will not sell Customer Data or use it for cross-context behavioral advertising as those terms are defined by applicable law.
If this DPA conflicts with the Agreement, this DPA controls only for Personal Data processing matters.
DPA questions may be sent through our contact page.