Data Processing Agreement (DPA)
Data Processing Agreement (DPA)
1. BACKGROUND
1.1. The Customer and Chattermill Analytics Limited ("Chattermill", "we", "our" or "us") entered into a pricing plan incorporating our terms and conditions (together, the "Agreement").
1.2. This DPA is between Chattermill and the Customer (each a "Party" and collectively the "Parties"), pursuant to the Agreement.
1.3. In the event that we process any Authorised User Data and/or Customer End User Data of individuals located in the UK or the EEA, or of any Customer who is established in the UK or the EEA, this Data Processing Agreement (the "DPA") shall be supplemental to the Agreement and apply to the processing of such Authorised User Data and/or Customer End User Data. In the event of a conflict between any of the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA shall prevail.
1.4. The Parties agree that this DPA will replace any existing data protection agreement or similar agreement the Parties may have previously entered into in connection with the Services.
2. DEFINITIONS
2.1. Unless otherwise set out below, each capitalised term in this DPA shall have the meaning set out in the Agreement, and the following capitalised terms used in this DPA shall be defined as follows:
- personal data: as defined in UK GDPR or EU GDPR.
- Authorised User: the Customer's employees; any contract staff who are working for the Customer; and any other person working with, or on behalf of, the Customer.
- Authorised User Data: personal data relating to each Authorised User.
- Customer End User: an end user of the Customer.
- Customer End User Data: personal data relating to each Customer End User.
- Data Protection Laws: UK Data Protection Legislation and other relevant laws regarding personal data.
3. DATA PROCESSING
3.1. Customer as Controller. The Customer is the controller and Chattermill is the processor.
3.2. Customer Compliance. The Customer retains control of the personal data and remains responsible for compliance obligations under applicable Data Protection Laws.
3.3. Nature and Purpose of Processing. Annex A describes the subject matter, duration, nature and purpose of processing and the personal data categories.
3.4. Instructions for Data Processing.
- We will only process in accordance with the Customer’s written instructions unless required by law.
- We will comply with the Customer's instructions requiring amendments to data.
4. TRANSFER OF PERSONAL DATA
4.1. Authorised Sub-processors. Chattermill may engage sub-processors without further written authorisation from the Customer.
5. DATA SECURITY, AUDITS AND SECURITY NOTIFICATIONS
5.1. Chattermill Security Obligations. We will implement appropriate security measures to protect personal data.
5.2. Compliance. We will make available information necessary to demonstrate compliance with this DPA.
6. ACCESS REQUESTS AND DATA SUBJECT RIGHTS
6.1. Data Subject Requests. We will notify the Customer of any request from a data subject with respect to personal data included in Authorised User Data or Customer End User Data.
7. DATA RETURN AND DESTRUCTION
7.1. We will, at the Customer’s request, return any Customer Data/Authorised User Data in our standard format.
8. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION
8.1. We will provide reasonable assistance to the Customer with any data protection impact assessments.
9. LIABILITY
9.1. The Parties’ liabilities arising out of or in connection with this DPA will be subject to limitations set forth in the Agreement.
10. TERMINATION
10.1. This DPA will remain in effect while the Agreement remains in effect.
11. MISCELLANEOUS
11.1. This DPA and all non-contractual obligations arising from it are subject to the governing law provisions of the Agreement.
ANNEX A
PERSONAL DATA PROCESSING PURPOSES AND DETAILS
- Data Exporter: Customer
- Data importer: Chattermill
- Subject matter of processing: Processing needed to enable service provision.
- Duration of processing: For the duration of the Agreement.
- Nature of processing: Storage, transmission, and use to provide the Services.
- Business purpose: For the provision of Services.
- Personal data categories:
- Name, email address, online identifiers (IP address) of each Authorised User.
- Feedback and chat transcripts provided to Chattermill for each Customer End User.
ANNEX B
SUB-PROCESSORS
| # | Sub-processor | Address | Jurisdiction | Processing | Framework |
|---|---|---|---|---|---|
| 1 | Intercom | Intercom, Inc., 115 Sansome St. Suite 810 San Francisco, CA 94104 United States | EU | Name, email address, IP address of each Authorised User. | SCCs |
| 2 | Amazon Web Services | Amazon Web Services EMEA SARL, One Burlington Plaza, Dublin 4 | EU | Name, email address, IP address | N/A |
| 3 | Google (Google Cloud Platform) | Google Ireland Limited, Barrow St. Dublin 4 | EU | Name, email address | N/A |
ANNEX C
TECHNICAL AND ORGANISATIONAL MEASURES
- Access controls: Limit access to personal data.
- Encryption: Use encryption technology where appropriate.
- Physical security: Implement physical security measures.
- Staff training: Train staff on data security issues.