Data Processing Agreement (DPA)

Data Processing Agreement (DPA)

1. BACKGROUND

1.1. The Customer and Chattermill Analytics Limited ("Chattermill", "we", "our" or "us") entered into a pricing plan incorporating our terms and conditions (together, the "Agreement").

1.2. This DPA is between Chattermill and the Customer (each a "Party" and collectively the "Parties"), pursuant to the Agreement.

1.3. In the event that we process any Authorised User Data and/or Customer End User Data of individuals located in the UK or the EEA, or of any Customer who is established in the UK or the EEA, this Data Processing Agreement (the "DPA") shall be supplemental to the Agreement and apply to the processing of such Authorised User Data and/or Customer End User Data. In the event of a conflict between any of the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA shall prevail.

1.4. The Parties agree that this DPA will replace any existing data protection agreement or similar agreement the Parties may have previously entered into in connection with the Services.

2. DEFINITIONS

2.1. Unless otherwise set out below, each capitalised term in this DPA shall have the meaning set out in the Agreement, and the following capitalised terms used in this DPA shall be defined as follows:

3. DATA PROCESSING

3.1. Customer as Controller. The Customer is the controller and Chattermill is the processor.

3.2. Customer Compliance. The Customer retains control of the personal data and remains responsible for compliance obligations under applicable Data Protection Laws.

3.3. Nature and Purpose of Processing. Annex A describes the subject matter, duration, nature and purpose of processing and the personal data categories.

3.4. Instructions for Data Processing.

4. TRANSFER OF PERSONAL DATA

4.1. Authorised Sub-processors. Chattermill may engage sub-processors without further written authorisation from the Customer.

5. DATA SECURITY, AUDITS AND SECURITY NOTIFICATIONS

5.1. Chattermill Security Obligations. We will implement appropriate security measures to protect personal data.

5.2. Compliance. We will make available information necessary to demonstrate compliance with this DPA.

6. ACCESS REQUESTS AND DATA SUBJECT RIGHTS

6.1. Data Subject Requests. We will notify the Customer of any request from a data subject with respect to personal data included in Authorised User Data or Customer End User Data.

7. DATA RETURN AND DESTRUCTION

7.1. We will, at the Customer’s request, return any Customer Data/Authorised User Data in our standard format.

8. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION

8.1. We will provide reasonable assistance to the Customer with any data protection impact assessments.

9. LIABILITY

9.1. The Parties’ liabilities arising out of or in connection with this DPA will be subject to limitations set forth in the Agreement.

10. TERMINATION

10.1. This DPA will remain in effect while the Agreement remains in effect.

11. MISCELLANEOUS

11.1. This DPA and all non-contractual obligations arising from it are subject to the governing law provisions of the Agreement.

ANNEX A

PERSONAL DATA PROCESSING PURPOSES AND DETAILS

ANNEX B

SUB-PROCESSORS

# Sub-processor Address Jurisdiction Processing Framework
1 Intercom Intercom, Inc., 115 Sansome St. Suite 810 San Francisco, CA 94104 United States EU Name, email address, IP address of each Authorised User. SCCs
2 Amazon Web Services Amazon Web Services EMEA SARL, One Burlington Plaza, Dublin 4 EU Name, email address, IP address N/A
3 Google (Google Cloud Platform) Google Ireland Limited, Barrow St. Dublin 4 EU Name, email address N/A

ANNEX C

TECHNICAL AND ORGANISATIONAL MEASURES