Snapshot 16873
Normalized text
Scripts and page chrome removed; this is what change detection compares.
COVER PAGE
Attached please find Habla, Inc. (“Olark”)’s Data Processing Agreement (“DPA”) addressing the parties’
obligations and rights in relation to the processing of personal data. This DPA forms part of the Services
Agreement or other written agreement between you and Olark. To complete this DPA, we request that
you complete the information in the signature box, sign this document, and submit via DocuSign.
If you have questions about this DPA, please contact Olark support or email [email protected].
OLARK’S DATA PROCESSING AGREEMENT
DPA Version 2.4
This Data Processing Agreement (“DPA”) is entered into between Habla, Inc. d/b/a Olark ("Olark") and
Customer (jointly “the Parties”), and forms a part of the Services Agreement between the Parties, and
reflects the Parties’ agreement with regard to the Processing of Personal Data in accordance with the
requirements of the Data Protection Laws.
By signing this DPA, Customer enters into this DPA on behalf of itself and, to the extent required under
applicable Data Protection Laws, in the name and on behalf of its Authorized Affiliates, if and to the
extent Olark Processes Personal Data for which such Authorized Affiliates qualify as the Controller (or
for the purposes of the CCPA - as defined below - as a Business). For the purposes of this DPA only, and
except where indicated otherwise, the term "Customer" shall include Customer and Authorized
Affiliates.
This DPA is effective on the date that it has been duly executed by both Parties (“Effective Date”), and
amends, supersedes and replaces any prior data processing agreements that the Parties may have
been entered into. Any modifications to the terms of this DPA (whether handwritten or otherwise) will
render this DPA ineffective unless Olark has separately agreed to those modifications in writing.
1. Definitions
1.1. “Affiliate” means any entity that directly or indirectly controls, is controlled by or is
under common control with the subject entity. “Control,” for purposes of this
definition, means direct or indirect ownership or control of more than 50% of the
voting interests of the subject entity.
1.2. “Authorized Affiliate” means Customer's Affiliate(s) which are subject to the data
protection laws and regulations of the European Union, the European Economic Area
and/or their member states, Switzerland and/or the United Kingdom Customer shall
be responsible for the acts and omissions of its Authorized Affiliates under this
Agreement to the same extent Customer would be responsible for its own acts and
omissions under the same.
1.3. “CCPA” means the California Consumer Privacy Act, as amended by the California
Privacy Rights Act,and any implementing, derivative, or related legislation, rule,
regulation, or regulatory guidance, as amended, extended, repealed and replaced, or
re-enacted.
1.4. “Covered Services” or “Services” means the services that are ordered by the Customer
from Olark involving the Processing of Personal Data on behalf of the Customer.
1.5. “Customer” means the entity that signed the Services Agreement and that determines
the purposes and means of Processing of Personal Data. The Customer is considered
the “Controller” of the Personal Data provided pursuant to this DPA.
1.6. “Data Breach” means a breach of security leading to the accidental or unlawful
destruction, loss, alteration, unauthorized disclosure of, or access to, Customer’s
Personal Data transmitted, stored or otherwise Processed.
1.7. “Data Protection Laws” means any applicable law, statute, law, regulation or order by
governmental authority of competent jurisdiction, or any judgment, decision, decree,
injunction, writ, order, subpoena, or like action of any court, arbitrator or other
government entity, and at all times during the term of the Service Agreement,
including the laws of the UK Data Protection Act 2018 and the UK GDPR (collectively,
the “UK GDPR”) and the EU General Data Protection Regulation (the “EU GDPR” and
together with the UK GDPR, the “GDPR”), and comprehensive United States state
privacy laws (including the CCPA), as amended or replaced from time to time, and any
other foreign or domestic laws to the extent that they are applicable to a party in the
course of its performance of the Service Agreement.
1.8. “Personal Data” or “Personal Information” means any information relating to an
identified or identifiable natural person (‘Data Subject’) that is subject to the Data
Protection Laws, which is provided by or on behalf of Customer and Processed by
Olark pursuant to the Services Agreement.
1.9. “Regulator” means any supervisory authority with authority under Data Protection
Laws over all or any part of the provision or receipt of the Services or the Processing of
Personal Data.
1.10. “Services Agreement” means any agreement between Olark and Customer under
which Covered Services are provided by Olark to Customer.
1.11. “Standard Contractual Clauses” means (i) with respect to the UK GDPR, the
International Data Transfer Addendum to the EU Commission Standard Contractual
Clauses, and (ii) with respect to the EU GDPR, the standard contractual clauses
(controller to processor module) set out in the European Commission’s Decision
2021/914 of 4 June 2021, in each case as may be amended, updated, or replaced from
time to time. .
1.12. “Subprocessor” means any Processor engaged by Olark to Process Personal Data on
behalf of Olark.
1.13. Terms such as “Aggregate Consumer Information”, “Business”, Business Purpose”,“Data
Subject”, “Deidentified”, “Processing”, “Controller”, “Processor”, “Service Provider”,
and “Supervisory Authority” shall have the meaning ascribed to them in the Data
Protection Laws.
2. Services Agreement
2.1. This DPA supplements the Services Agreement and in the event of any conflict
between the terms of this DPA and the terms of the Services Agreement, the terms of
this DPA prevail with regard to the specific subject matter of this DPA.
3. Data Protection Laws
3.1. Roles of the Parties. The Parties acknowledge and agree that Olark will Process the
Personal Data in the capacity of a Processor (or, for the purposes of the CCPA, as a
Service Provider)and that Customer will be the Controller of the Personal Data (or, for
purposes of the CCPA, will be a Business).
3.2. DPO. To the extent required by the GDPR, will each designate a data protection officer
(a “DPO”) and provide their contact details to the other Party where required by the
Data Protection Laws.
4. Obligations of the Controller
4.1. Instructions. Customer warrants that the instructions it provides to Olark pursuant to
this DPA will comply with Data Protection Laws.
4.2. Data Subject and Regulator Requests. Customer shall be responsible for
communications and leading any efforts to comply with all requests made by Data
Subjects under Data Protection Laws and all communications from Regulators that
relate to the Personal Data, in accordance with Data Protection Laws. To the extent
such requests or communications require Olark’s assistance, Customer shall
immediately notify Olark in writing of the Data Subject’s or Regulator’s request.
4.3. Notice, Consent and Other Authorizations. Customer agrees that the Personal Data
will be collected in compliance with Data Protection Laws, including all legally
required consents, approvals and authorizations. Upon Olark’s request, Customer shall
provide adequate proof of having properly obtained all such necessary consents,
authorizations and required permissions. Customer shall have sole responsibility for
the accuracy, quality, and legality of the Personal Data and the means by which
Customer acquired the Personal Data.
4.4. CCPA. The parties acknowledge and agree that the Personal Information it discloses to
Olark for Processing pursuant to the Services Agreement is for a Business Purpose.
5. Details of Processing Activities
5.1. The following table sets out the details of Processing:
Nature and ● Olark will Process Personal Data for the purpose of providing the
Purposes for Covered Services described in the Services Agreement.
which Personal Customer may submit Personal Data to the Services, and may
Data shall be request for its customers (“End Users”) to submit Personal Data
Processed to the Services, the extent of which is determined and controlled
by the Customer in its sole discretion
Duration of ● For the duration of Olark’s provision of the Services and
Processing thereafter in accordance with the Services Agreement or
Customer’s instructions.
Description of ● Natural persons who submit personal data to Customer via use
the categories of of the Services;
the data subjects ● Natural persons who are employees, representatives, or other
business contacts of Customer
Description of ● Personal Data processed includes: name, email address, phone
the categories of number, credit card and/or other billing information;
Personal Data ● Personal Data about End Users that Customer provides to the
Service or through your End User’s interaction with the Services;
● Personal Data from Add-ons and other third-party services you
use in conjunction with our Services;
● Data about Customers and End Users' use of the Services, such
as but not limited to interactions with the user interface to the
Services, chat content, and the Internet Protocol Address for the
computers with which you use to connect to the Service.
6. Obligations of the Processor
6.1. Scope of Processing. Olark will Process the Personal Data on documented
instructions from Customer in such manner as is necessary for the provision of
Services under the Service Agreement, except as may be required to comply with any
legal obligation to which Olark is subject. Olark may make reasonable effort to inform
Customer if, in its opinion, the execution of an instruction relating to the Processing of
Personal Data could infringe on any Data Protection Laws based on Olark’s actual
knowledge of Customer’s Processing of Personal Data. In the event Olark must Process
or cease Processing Personal Data for the purpose of complying with a legal obligation,
Olark will inform the Customer of that legal requirement before Processing or ceasing
to Process, unless prohibited by the law. Olark shall also notify Customer in the event
Olark makes a determination that it can no longer meet its obligations under Data
Protection Laws, and Olark grants Customer the right, upon prior notice, to take
reasonable and appropriate steps to stop and remediate Olark’s unauthorized use of
Personal Data. Subject to Section 7, Customer may take reasonable and appropriate
steps to ensure that Olark Processes Personal Data in a manner consistent with
Customer’s obligations under Data Protection Laws.
6.2. Data Subject and Regulator Requests. Olark will promptly notify Customer in writing
of any complaints, questions or requests received from Data Subjects or Regulators
regarding the Personal Data. Taking into account the nature of the Processing and to
the extent reasonably possible, Olark will assist Customer in fulfilling Customer’s
obligations in relation to Articles 13 and 14 of the GDPR, and Data Subject requests,
under applicable Data Protection Laws.
6.3. Retention. Upon Customer’s written request, Olark will destroy all Personal Data in its
possession or return the Personal Data to Customer, as requested. Notwithstanding
the foregoing, any return or destruction shall be subject to all applicable laws
(including, without limitation, Data Protection Laws) and regulations.
6.4. Disclosure to Third Parties. Except as expressly provided in this DPA, Olark will not
disclose Personal Data to any third party without Customer’s consent. If requested or
required by a competent governmental authority to disclose the Personal Data, to the
extent legally permissible and practicable, Olark will provide Customer with sufficient
prior written notice in order to permit Customer the opportunity to oppose any such
disclosure.
6.5. Confidentiality. Olark will restrict access to the Personal Data to its personnel (and
the personnel of its Affiliates) and to its Subprocessors who need access to meet Olark
’s obligations under the Services Agreement. Further, Olark will ensure that all such
personnel and Subprocessors are informed of the confidential nature of the Personal
Data and have undertaken training on how to handle such data. Olark will ensure that
personnel authorized to Process the Personal Data are subject to binding
confidentiality obligations or are under an appropriate statutory obligation of
confidentiality.
6.6. GDPR Articles 32-36. Taking into account the nature of the Processing and the
information available to Olark, Olark will provide reasonable assistance to Customer in
complying with its obligations under GDPR Articles 32-36, which address obligations
with regard to security, breach notifications, data protection impact assessments, and
prior consultation.
6.7. CCPA. Olark shall not (a) sell or share (as such terms are defined under the CCPA)
Personal Information; (ii) retain, use, or disclose Personal Information for any purpose
other than for the specific purpose of performing the Services, including retaining,
using, or disclosing Personal Information for a commercial purpose other than
providing the Services; and (iii) retain, use, or disclose Personal Information outside of
the direct business relationship between the Customer and Olark. Unless
contemplated by the Services, Olark shall not combine the Personal Information with
any other personal information. By agreeing to this DPA, Olark certifies that it
understands its restrictions with regard to the CCPA. The restrictions of this Section do
not apply to Deidentified or Aggregate Consumer Information.
6.8. Deidentification. To the extent Olark receives Deidentified or Aggregate Consumer
Information from Customer, or the Services contemplate the deidentification or
aggregation of Personal Data, Olark shall not reidentify, attempt to reidentify, or direct
any other party to reidentify any data that has been deidentified or aggregated.
6.9. FERPA Records. If Olark creates, accesses, transmits or stores Personal Information
that is subject to the Family Educational Rights and Privacy Act ("FERPA"), 20 U.S.C.
Section 1232g ("FERPA Records"), Olark acknowledges and agrees that Olark is under
the direct control of Customer with respect to the use and maintenance of the FERPA
records and further represents, warrants, and agrees that it will (i) hold the FERPA
Records in strict confidence and will not use or disclose the FERPA Records except as
permitted or required by the Services Agreement, required by law, or otherwise
authorized by Customer in writing; (ii) safeguard the FERPA Records according to
commercially reasonable administrative, physical and technical standards that are no
less rigorous than the standards by which Olark protects its own comparable
confidential information; (iii) continually monitor its operations and take any action
necessary to assure that the FERPA Records are safeguarded in accordance with the
terms of the Services Agreement and this DPA; (iv) not read the contents of any FERPA
Records, and restrict access by Olark’s employees to FERPA records, except as
necessary to provide, repair, and maintain the Services, process the transactions, or
store the data as required under the Services Agreement; (v) use and retain FERPA
Records only for the purposes for which they were intended; and (vi) at the request of
Customer, provide Customer with a written summary of the procedures Olark uses to
safeguard the FERPA Records. For the purposes of performing the services to be
provided hereunder only, Olark shall be identified by Customer as a school official with
a legitimate educational interest in any FERPA Records created, accessed, transmitted,
or stored by Olark.
6.10. Information Security. Taking into account the costs of implementation and the
nature, scope, context and purposes of processing as well as the risks of varying
likelihood and severity for the rights and freedoms of Data Subjects, Olark will take
appropriate steps to implement and maintain adequate organizational and technical
measures designed to protect the confidentiality, integrity and availability of the
Personal Data it Processes on Customer’s behalf (the “Security Measures”). All of the
Personal Data Olark Processes is stored in the cloud. Olark uses only top-tier cloud
providers that have confirmed they have implemented and maintain Security
Measures in compliance with Article 32 of the GDPR, in storing and keeping secure
Personal Data.
7. Audit
7.1. Scope. Olark will maintain records of its Processing activities as required by the Data
Protection Laws and will make available to Customer information reasonably
necessary to demonstrate its compliance with the obligations set out in this DPA.
Customer’s inspection rights under this DPA do not extend to Olark’s employee payroll,
personnel records or any portions of its sites, books, documents, records, or other
information that do not relate to the Services or to the extent they pertain to third
parties.
7.2. Process. Subject to reasonable written notice from Customer and at the Customer's
additional expense, Olark will permit audits conducted by an independent third-party
auditor that is not a competitor to Olark acting on Customer’s behalf to enable
Customer to verify that Olark is in compliance with material obligations under this
DPA. Audits and inspections will be carried out at mutually agreed times during
regular business hours and no more than once annually.
7.3. Confidentiality. All information obtained during any such request for information or
audit will be considered Olark’s confidential information under the Services
Agreement and this DPA. The results of the inspection and all information reviewed
during such inspection will be deemed Olark’s confidential information. The third
party auditor may only disclose to Customer specific violations of this DPA if any, and
the basis for such findings, and shall not disclose any of the records or information
reviewed during the inspection.
8. Contracting with Subprocessors
8.1. Customer hereby consents generally to Olark’s engagement of Subprocessors in
connection with the processing of the Personal Data. Upon written request from
Customer, Olark will make the list of applicable Subprocessors available to Customer.
Customer may reasonably object to any such Subprocessor within 15 days of receiving
such list, in which case Olark will use reasonable efforts to make a change in the
Service or recommend a commercially reasonable change to avoid Processing by such
Subprocessor. If Olark is unable to provide an alternative, Customer may terminate
the Services. Olark will enter into written agreements with each Subprocessor
containing reasonable provisions relating to the implementation of technical and
organizational measures in compliance with the Data Protection Laws. In relation to
Customer, Olark will remain liable for acts and omissions of its Subprocessors in
connection with the provision of the Services.
8.2. Customer understands that the Services may include one or more artificial intelligence
features that leverage generative and/or machine-learning functionality (“AI
Technology”). Such AI Technology may include, but is not limited to, OpenAI or
technologies licensed by similar third-party services (“AI Suppliers”)
9. Transfers Outside of the European Economic Area
9.1. Customer acknowledges that Olark may, without Customer’s prior written consent,
process the Personal Data in a foreign jurisdiction outside the United Kingdom and
European Economic Area, provided such transfer is either (i) to a country or territory
which has been formally recognized by the European Commission or the United
Kingdom (as applicable) as affording the Personal Data an adequate level of protection
or (ii) the transfer of such personal data is, as between Olark (as data importer) and
Customer (as data exporter), undertaken pursuant to the applicable Standard
Contractual Clauses, the terms of which are incorporated into this DPA by reference.
9.2. In the event of inconsistencies between the provisions of the applicable Standard
Contractual Clauses and this DPA or other agreements between the Parties, the
Standard Contractual Clauses shall take precedence, but only with respect to Personal
Data transferred outside of the EEA. The information set forth in Exhibit A constitutes
the information required to be included in the schedules and appendices to the
Standard Contractual Clauses, and the Parties’ signatures to this Addendum are
deemed to also constitute signature of the Standard Contractual Clauses to the extent
the same may be required to be separately executed. Olark shall provide a signed copy
of the Standard Contractual Clauses upon request.
9.3. In connection with any transfer of Personal Data undertaken pursuant to the Standard
Contractual Clauses, Olark has undertaken the Transfer Impact Assessment set forth in
Exhibit B.
10. Information Obligations and Incident Management
10.1. Data Breach. Olark will notify Customer of any Data Breach of which it becomes aware
without undue delay consistent with measures necessary to determine the scope of
the breach and to restore the integrity of Olark’s systems. Olark will use reasonable
efforts to investigate the Data Breach and take any actions that are reasonably
necessary to mitigate damage, as required by law and as appropriate under the
circumstances.
10.2. Notification. Olark’s notification of a Data Breach, to the extent known, will include:
(a) the nature of the Data Breach; (b) the date and time upon which the Data Breach
took place and was discovered; (c) the number of Data Subjects affected by the
incident; (d) the categories of Personal Data involved; (e) the measures – such as
encryption, or other technical or organizational measures – that were taken to address
the incident, including measures to mitigate the possible adverse effects; (f) the name
and contact details of the data protection officer or other contact; and (g) a description
of the likely consequences of the Data Breach.
10.3. Coordination. Olark will reasonably assist Customer in fulfilling its obligations to
notify Data Subjects and the relevant authorities in relation to a Data Breach, provided
that nothing in this section shall prevent either Party from complying with its
obligations under Data Protection Laws. The Parties agree to coordinate in good faith
on developing the content of any related public statements.
11. Obligations Post- Termination
Termination or expiration of this DPA shall not discharge the Parties from their obligations that
by their nature may reasonably be deemed to survive the termination or expiration of this DPA.
12. Liability and Indemnity
Any claims brought under this DPA will be subject to the same terms and conditions, including
the exclusions and limitations of liability, as are set out in the Services Agreement.
13. Severability
Any provision of this DPA that is prohibited or unenforceable in any jurisdiction shall, as to
such jurisdiction, be ineffective to the extent of such prohibition or unenforceability without
invaliding the remaining provisions hereof, and any such prohibition or unenforceability in any
jurisdiction shall not invalidate or render unenforceable such provision in any other
jurisdiction. The Parties will attempt in good faith to agree upon a valid and enforceable
provision that is a reasonable substitute and shall incorporate such substitute provision into
this Agreement.
14. Mutual Notice
Any notice, consent, instruction or communication related to this DPA will be provided in
writing to the Company email address specified in the signature block below. All notices to
Olark must be provided via email to [email protected].
The Parties’ authorized signatories have duly executed this DPA.
Signed Signed
for and on behalf of the Customer for and on behalf of Olark
Print name: Print name: Matthew Pizzimenti
Company email address: Company email address: [email protected]
Company name: Company name: Habla, Inc. d/b/a Olark
Title: Title: COO
Date: Date: July 11, 2023
Exhibit A
Details of the Processing of Personal Data
Data exporter
The Data Exporter is _____________________________
Insert Company Name
The Data Importer is Habla Inc., d/b/a Olark.
Nature and purpose of processing
See Section 5.1 of the DPA. Categories of data subjects
The personal data transferred concern the following categories of data subjects (please specify):
See Section 5.1 of the DPA
Categories of personal data transferred
The personal data transferred concern the following categories of data (please specify):
See Section 5.1 of the DPA
Special categories of data (if appropriate)
The personal data transferred concern the following special categories of data (please specify):
None.
Frequency of transfer
Continuous basis.
Data retention period
See Section 5.1 of the DPA
Subject matter, nature, and duration of Processing for transfers to Subprocessors
The subject matter of the subprocessing is for the provision of Services under the Service Agreement. The
nature of the subprocessing is to assist Olark in providing the Services to Customer under the Services
Agreement. The duration of the subprocessing will occur for the duration of Processing by Olark in the
context of the provision of the Services under the Services Agreement, unless Olark earlier terminates
and/or replaces the Suprocessor.
Competent Supervisory Authority
European Union
The competent supervisory authority is the lead supervisory authority of the Data Exporter. The EU
Standard Contractual Clauses shall be governed by the law of the EU Member State in which the Data
Exporter is established, and any disputes arising from the EU Standard Contractual Clauses shall be
governed by the courts of the EU member State in which the Data Exporter is established.
United Kingdom
The competent supervisory authority is the UK Information Commissioner. The UK International Data
Transfer Addendum shall be governed by the laws of England and Wales, and any dispute arising from the
same shall be resolved by the courts of England and Wales.
Additional Clarification
Clause 7 (Docking Clause) is not included. The audits described in Clause 8.9 of the Standard Contractual
Clauses under the EU GDPR shall be performed in accordance with Section 7 of this DPA. Section 8 of this
DPA shall constitute the procedures for Olark to request general authorization for Subprocessors under
Clause 9(a)(Option 2) of the Standard Contractual Clauses under the EU GDPR. The optional language in
Section 11(a) of the Standard Contractual Clauses under the EU GDPR shall not be included. For the
Standard Contractual Clauses under the EU GDPR: (a) Option 1 of Clause 17 shall apply, and it shall be
governed by the laws of Ireland; and (b) Ireland shall be the appropriate EU Member State for Clause 18(b).
UK International Data Transfer Addendum Tables
Table 1: Table 1 shall be satisfied by the information in this Exhibit A (as applicable).
Table 2: The version of the Approved EU Standard Contractual Clauses shall be the version referenced in
Section 1.11(ii) of the DPA.
Table 3: Table 3 shall be satisfied by the information in this Exhibit A.
Table 4: Data Importer and Data Exporter shall have the rights outlined in Section 19 of the UK International
Data Transfer Addendum.
Technical and organizational measures
Data Importer implements and maintains industry standard technical and organizational measures to
protect the security of Personal Data that it processes in connection with its Services. Such measures
include, as appropriate to the nature of the Personal Data processed, but are not limited, to:
· Firewall protections
· Access controls
· Protections against viruses and malware
· Implementation of security settings
· Implementation of updates to fix bugs and security vulnerabilities
· Regular data backups
Exhibit B
Transfer Impact Assessment
Questions Relevant Information About Processing
1 What does Olark Our platform provides live chat software for sales and customer support.
do?
2 Where is Olark We are located in the United States.
located?
3 What types of We process personal data such as names, email addresses, phone numbers,
personal data does IP addresses and device IDs, along with information that our customer’s end
Olark process, and users input via our live chat tool..
what does it do with
it?
4 What measures To the extent we process personal data, we employ industry standard
does Olark technical and organizational security measures to protect it.
implement to
protect the security To the extent we engage sub-processors in connection with our performance
of personal data it of the Services, we execute DPAs to ensure such sub-processors comply with
processes? terms that are consistent with those we agree with our customers via our
DPA.
5 Is personal data Personal data may be transferred to, and processed in, the United States.
transferred outside
of the EEA?
6 What is the For transfers of personal data which is subject to the GDPR, to third countries
mechanism relied outside the European Economic Area, we rely upon the Standard Contractual
upon by Olark for Clauses (Controller to processor module), together with the additional
international safeguards referenced in Section 4 above.
transfers of
personal data to
third countries?
7 Is Olark subject to Given the broad definition of electronic communications service provider, we,
US government like most US organizations, may theoretically be subject to US government
surveillance laws or surveillance laws, such as Section 702 of the Foreign Intelligence Surveillance
other laws Act (“FISA 702”), and National Security Letter requests issued by the FBI
requiring it to under Executive Order 12333 (“EO 12333” and together with FISA 702, “US
disclose personal Government Surveillance Laws”).
data to US national
security agencies? However, given the limited nature of the personal data we process, it is
If yes, are any legal unlikely that we will be subject to demands under such US Government
remedies afforded Surveillance Laws. US government commitments and policies restrict
to impacted intelligence collection to what is required for foreign intelligence purposes
individuals in the and expressly prohibit the collection of information for other purposes,
EU? including commercial advantage. As such, we have no reason to believe that
our data transfers present risks under US Government Surveillance Laws. In
addition, we do not voluntarily allow US government access to personal data
transferred to us, for example in response to requests made under EO1233.
To the extent we are ever subject to such an order, we expect government
bodies and law enforcement agencies to follow applicable laws and
regulations, in addition to ensuring due process for all data requests[1].
8 Does Olark believe No. Considering the nature of the personal data we process on behalf of our
that US customers, it is unlikely that we will be subject to demands under US
Government Government Surveillance Laws and, to date and to our knowledge, we have
Surveillance Laws not received any such demands or requests.
prevent it from
complying with the In the unlikely event we do receive such a request or demand, we will provide
Standard data only when legally bound by an order or subpoena issued by a court or
Contractual Clauses legal body with proper jurisdiction. If such demand for data from a
in its capacity as a government body is received, we will attempt to redirect the government
data importer? body to request that data directly from the applicable data exporter. If
compelled to disclose data to a government body, we will give the applicable
data exporter reasonable notice of the demand so that they can seek a
protective order or other appropriate remedy, unless legally prohibited from
doing so. In addition, and as discussed above, we have implemented and
maintained additional safeguards in relation to our processing activities,
such as processing the minimum amount of data necessary.
[1] For more information regarding the process for such orders, see
https://www.commerce.gov/sites/default/files/2020-09/SCCsWhitePaperFORMATTEDFINAL508COMPLIANT.PDF