Data Processing Agreement (DPA)
Data Processing Agreement (DPA)
Data Processing Agreement (DPA)
1. BACKGROUND
1.1. The Customer and Chattermill Analytics Limited (" Chattermill", " we", " our" or " us") entered into a pricing plan incorporating our terms and conditions (together, the " Agreement").
1.2. This DPA is between Chattermill and the Customer (each a " Party" and collectively the " Parties"), pursuant to the Agreement.
1.3. In the event that we process any Authorised User Data and/or Customer End User Data of individuals located in the UK or the EEA, or of any Customer who is established in the UK or the EEA, this Data Processing Agreement (the " DPA") shall be supplemental to the Agreement and apply to the processing of such Authorised User Data and/or Customer End User Data. In the event of a conflict between any of the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA shall prevail.
1.4. The Parties agree that this DPA will replace any existing data protection agreement or similar agreement the Parties may have previously entered into in connection with the Services.
2. DEFINITIONS
2.1. Unless otherwise set out below, each capitalised term in this DPA shall have the meaning set out in the Agreement, and the following capitalised terms used in this DPA shall be defined as follows:
- personal data: shall have the meaning given to it in the UK GDPR or EU GDPR (as applicable).
- Authorised User: means the Customer's employees; any contract staff who are working for the Customer; and any other person working with, or on behalf of, the Customer who are granted access to the Services exclusively on the Customer's behalf and with the Customer's prior authorisation.
- Customer End User: means an end user of the Customer.
... (additional definitions follow) ...
3. DATA PROCESSING
3.1. Customer as Controller. The Customer and Chattermill acknowledge that for the purpose of Data Protection Laws, the Customer is the controller and Chattermill is the processor.
3.2. Customer Compliance. The Customer retains control of the personal data and remains responsible for its compliance obligations under applicable Data Protection Laws.
... (additional processing clauses follow) ...
4. TRANSFER OF PERSONAL DATA
4.1. Authorised Sub-processors. Chattermill is authorized to engage sub-processors without obtaining further written authorization from Customer.
... (additional clauses about transfers follow) ...
5. DATA SECURITY, AUDITS AND SECURITY NOTIFICATIONS
5.1. Chattermill Security Obligations. We will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
5.2. Compliance. Upon request by the Customer, we will make available all information necessary to demonstrate compliance with this DPA.
... (additional security clauses follow) ...
6. ACCESS REQUESTS AND DATA SUBJECT RIGHTS
6.1. Data Subject Requests. We will notify the Customer of any request received regarding personal data in the Authorised User Data or Customer End User Data.
... (additional rights clauses follow) ...
7. DATA RETURN AND DESTRUCTION
7.1. Return. We will return any Customer Data/Authorised User Data in our standard format at Customer’s request.
7.2. Deletion/Destruction. On termination of the Agreement, we will cease processing Authorised User Data and Customer End User Data.
8. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION
... (impact assessment clauses follow) ...
9. LIABILITY
9.1. The Parties' liabilities arising from this DPA will be subject to limitations as set forth in the Agreement.
... (additional liability clauses follow) ...
10. TERMINATION
10.1. This DPA will terminate immediately upon termination of the Agreement.
11. MISCELLANEOUS
11.1. This DPA is subject to the governing law and jurisdiction provisions of the Agreement.
... (additional miscellaneous clauses follow) ...
ANNEX A
PERSONAL DATA PROCESSING PURPOSES AND DETAILS
- Data Exporter: Customer
- Data importer: Chattermill
- Subject matter of processing: Needed for the provision of Services pursuant to the Agreement.
- Duration of processing: For the duration of the Agreement.
- Nature of processing: Storage, transmission and use in order to provide the Services.
- Business purpose: To provide Services as per the Agreement.
- Personal data categories:
- Name, email address, online identifiers.
- Information contained in feedback or chat transcripts.
ANNEX B
SUB-PROCESSORS
| # | Sub-processor | Address | Jurisdiction | Processing | Framework |
|---|---|---|---|---|---|
| 1 | Intercom | Intercom, Inc., 115 Sansome St., Suite 810, San Francisco, CA 94104, United States | EU | Name, email and IP address of each Authorised User. | SCCs |
| 2 | AWS | Amazon Web Services EMEA SARL, Dublin | EU | Name, email and IP address of each Authorised User. | N/A |
| ... | ... | ... | ... | ... | ... |
ANNEX C
TECHNICAL AND ORGANISATIONAL MEASURES
- We maintain policies and procedures to secure any personal data processed by us.
- Appropriate access controls are implemented to limit access to personal data.
- Regularly back-up data and store it securely.
- Processes for securely removing personal data before disposing of IT systems.
- Employees are trained on data security and privacy issues.