Data Processing Addendum
Data Processing Addendum
Contents
- Data Processing and Protection
- 1.1. Limitations on Use
- 1.2. Instructions
- 1.3. Compliance
- 1.4 – 1.8. Additional Obligations
- Data Processing Assistance
- 2.1. Data Subject Rights Assistance
- 2.2. Security Assistance
- 2.3. Security Incident Notice and Assistance
- 2.4. Data Protection Impact Assessment (DPIA) and Prior Consultation Assistance
- Audits
- 3.1. Company Audits
- 3.2. Customer Audits
- 3.3. Confidentiality
- Subprocessors
- 4.1. Appointment of Subprocessors
- 4.2. Objection Right for New Subprocessors
- 4.3. Liability
- Data Transfers
- Limitation of Liability
- Miscellaneous
1. Data Processing and Protection
1.1. Limitations on Use
Company will Process Customer Personal Data only: (a) pursuant to Customer's documented instructions as specified under Section 1.2 (Instructions), including with regard to transfers of Customer Personal Data to a third country; (b) as otherwise required by applicable laws; and (c) to improve the Services, to conduct research and development activities and to comply with Company's own legal obligations (provided such Processing does not conflict with applicable law).
1.2. Instructions
Customer instructs Company to Process Customer Personal Data as necessary to provide the Services and as otherwise authorized or permitted under this DPA, the Agreement, including as specified in Attachment 2 (Scope of Processing).
1.3. Compliance
Each party will comply with its obligations under Data Protection Law.
1.4 – 1.8. Additional Obligations
1.4. Confidentiality. Company will ensure that persons authorized by Company to Process any Customer Personal Data are subject to appropriate confidentiality obligations.
1.5. Security. Company will use commercially reasonable efforts to implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against Security Incidents and provide the level of protection required by Data Protection Law.
1.6. Disposal. At the choice of Customer, Company will delete all Customer Personal Data after expiry or termination of the Agreement.
1.7. Additional Uses. Where permitted by Data Protection Law, Company may Process Customer Personal Data to detect Security Incidents.
1.8. Deidentified Data. Company may Process Deidentified Data for its lawful business purposes.
2. Data Processing Assistance
2.1. Data Subject Rights Assistance
Customer shall be responsible for responding to requests from individuals to exercise rights under Data Protection Law relating to Customer Personal Data.
2.2. Security Assistance
Company will provide commercially reasonable efforts to assist Customer in Customer's efforts to comply with Customer's obligations to secure Customer Personal Data by providing the information and assistance described in Section 3 (Audits).
2.3. Security Incident Notice and Assistance
Company will notify Customer without undue delay and within the time frame required under Data Protection Laws after becoming aware of a Security Incident.
2.4. Data Protection Impact Assessment (DPIA) and Prior Consultation Assistance.
Company will provide commercially reasonable assistance to Customer in ensuring compliance with the obligations related to DPIAs and consulting with regulatory authorities.
3. Audits
3.1. Company Audits.
Company may procure audits by third parties to assess Company's adherence to the following standards or requirements.
3.2. Customer Audits.
Customer may carry out an audit or assessment of Company's policies, procedures, and records relevant to the Processing of Customer Personal Data.
3.3. Confidentiality.
The audit findings and Reports will be considered Company's "Confidential Information".
4. Subprocessors
4.1. Appointment of Subprocessors.
Customer authorizes Company to use subcontractors to Process Customer Personal Data.
4.2. Objection Right for New Subprocessors.
Company will notify Customer of its intent to update the Subprocessor List at least 15 days prior to engaging a new Subprocessor.
4.3. Liability.
Company will impose data protection obligations upon any Subprocessor that are no less protective of Customer Personal Data than those included in this DPA.
5. Data Transfers
Customer authorizes Company and its Subprocessors to transfer Customer Personal Data across international borders.
6. Limitation of Liability
Each party's and all of its affiliates' liability, taken together in the aggregate, arising out of or related to this DPA, is subject to the limitation of liability in the Agreement.
7. Miscellaneous
To the extent there is any conflict between the terms of this DPA, on the one hand, and the applicable SCCs or UK IDTA, on the other hand, the SCCs or UK IDTA, as appropriate, will control.
Attachment 1: Definitions
"Customer Personal Data" means Personal Data that Company Processes on behalf of Customer in connection with providing the Services as described in Attachment 2.
"Data Protection Law" means applicable data privacy, data protection, and cybersecurity laws, rules and regulations.
"Services" means the Platform Services provided by Company pursuant to the Agreement.
Attachment 2: Scope of Processing
Data exporter: Customer. Data importer: Company.
Subject-Matter and Duration of Processing: Company Processes Customer Personal Data as provided by Customer.
Nature and Purpose of Processing: Processing of Customer Personal Data in connection with Company providing the Services to Customer.
Types of Customer Personal Data: Contact information, device identification data, hours worked.
Categories of Data Subjects: Customer's clients, employees/personnel.
Frequency of Transfers: Company will import Customer Personal Data on a continuous basis.
Period of Data Retention: Company will retain the Personal Data until the termination of the Agreement.
Attachment 3: Data Security Exhibit
Program. Company will implement and maintain an information security program containing safeguards appropriate to the risks posed.
Company will abide by the "principle of least privilege".
Account Management. Company will manage the creation, use, and deletion of all account credentials.
Security Segmentation. Company will monitor, detect, and restrict the flow of information.
Company will use data loss prevention measures.
Encryption. Company transmits or sends wirelessly using encryption.
Physical Safeguards. Company will maintain physical access controls.
Attachment 4: Subprocessor List
- Check Inc.
- Stripe
- Google Cloud Platform
- AWS
- Heroku
- Stitch
- Hubspot
- Salesforce
- QuickBooks Online
- Segment
- RedisCloud
- Datadog
- Vercel
- ConvertAPI
- Metabase
- Fullstory
- Clay
- Sentry
- Zapier
- OpenAI
- Churnzero
- Intercom