Snapshot 31450
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Last Update: July 10, 2024 This Data Protection Addendum (this “DPA”) is entered into by and between, Browsi Mobile Ltd. (“Browsi”), and the entity identified as “Company” in the Order Form referencing this Agreement to which this Data Protection Addendum is attached, as of the Addendum Effective Date. Browsi and Company shall be referred herein each as a “Party” and together as the “Parties”. In consideration of the mutual obligations set out herein, the parties hereby agree that the terms and conditions set out below shall be added as an Addendum to the Master Service Agreement. Except where the context requires otherwise, references in this Addendum to the Master Service Agreement are to the Master Service Agreement as amended by, and including, this Addendum. 1. Definitions In this Addendum, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly: 1.1. “Data Protection Laws” means all such laws and regulations with respect to any Company Personal Data of which any Company Group Member is subject to, as applicable and including without limitation: (i) laws and regulations of the European Union, EU General Data Protection Regulation (Regulation 2016/679) (“GDPR”); (ii) the EU e-Privacy Directive (Directive 2002/58/EC), as amended (e- Privacy Law); (iii) the California Consumer Privacy Act (the “CCPA”); (iv) the New York Privacy Act and Privacy Shield; (v) any national data protection laws made under, pursuant to, replacing or succeeding (i) – (v); and (vi) any legislation replacing or updating any of the foregoing. 1.2. “CCPA” means the California Consumer Privacy Act (Cal. Civ. Code §§ 1798.100 – 1798.199) of 2018, as may be amended as well as all regulations promulgated thereunder from time to time. 1.3. “Company Data” means non indemnified data information processed by Browsi for purpose of providing the services to Company as further detailed under Annex A. 1.4. The terms “Controller”, “Processor”, “Data Subject”, “Processing” (and “Process“), “Personal Data Breach”, “Special Categories of Personal Data” and “Supervisory Authority”, shall all have the same meanings as ascribed to them in the EU Data Protection Law. The terms “Business”, “Business Purpose”, “Consumer”, “Service Provider,” “Sale” and “Sell” shall have the same meaning as ascribed to them in the CCPA. “Data Subject” shall also mean and refer to “Consumer”, as such term defined in the CCPA. 1.5. “EU Data Protection Law” means the (i) EU General Data Protection Regulation (Regulation 2016/679) (“GDPR”); (ii) Regulation 2018/1725; (iii) the EU e-Privacy Directive (Directive 2002/58/EC), as amended (e-Privacy Law); (iv) any national data protection laws made under, pursuant to, replacing or succeeding (i) and (ii); (v) any legislation replacing or updating any of the foregoing; and (vi) any judicial or administrative interpretation of any of the above, including any binding guidance, guidelines, codes of practice, approved codes of conduct or approved certification mechanisms issued by any relevant Supervisory Authority. 1.6. “Company Affiliate” means an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Company, where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise. 1.7. “Company Group Member” means Company or any Company Affiliate. 1.8. Unless otherwise defined in this DPA, all capitalized terms shall have the meaning given to them in the Agreement; and any reference to any statute, regulation or other legislation in this DPA shall be construed as meaning such statute, regulation or other legislation itself, together with any applicable judicial or administrative interpretation thereof (including any binding guidance, guidelines, codes of practice, approved codes of conduct or approved certification mechanisms issued by any relevant Supervisory Authority). 2. Parties’ Roles 2.1. The parties agree and acknowledge that under the performance of their obligations set forth in the Agreement, and with respect to the Processing of Company Data, Browsi is acting as a Data Processor and Company is acting as a Data Controller. For purpose of the CCPA (and to the extent applicable), Company is the Business and Browsi is the Service Provider. Each party shall be individually and separately responsible for complying with the obligations that apply to such party under applicable Data Protection Law. 2.2. The subject matter and duration of the Processing carried out by the Processor on behalf of the Controller, the nature and purpose of the Processing, the type of Data and categories of Data Subjects are described in Annex A attached hereto. 3. Representations and Warranties 3.1. Each Party hereby represents and warrants that: (a) it shall comply with all Data Protection Laws regulation and industry best practices, and any other data privacy laws and regulations, with regards to its performance and obligations under this Agreement. 3.2. The Company represents and warrants that: (i) its Processing instructions shall comply with applicable Data Protection Law, and the Company acknowledges that, taking into account the nature of the Processing, Browsi is not in a position to determine whether the Company’s instructions infringe applicable Data Protection Law; and (ii) it will comply with EU Data Protection Law, specifically with regards to the lawful basis principal for Processing Company Data; and (iii) due to the nature of the Services, Browsi does not monitor or control the Company Content and thus, the type of Personal Data or Categories of the Data Subjects processed by the Company are subject to the Company’s sole discretion. 3.3. Browsi represents and warrants that it shall Process Company Data, as set forth under Article 28(3) of the GDPR, on behalf of the Company, solely for the purpose of providing the Service, and for the pursuit of a Business Purpose as set forth under the CCPA, all in accordance with Company’s written instructions including the Agreement and this DPA. Notwithstanding the above, in the event Browsi is required under applicable laws, including Data Protection Law or any union or member state regulation, to Process Company Data other than as instructed by Company, Browsi shall make its best efforts to inform the Company of such requirement prior to Processing such Company Data, unless prohibited under applicable law. In addition, the Company shall provide reasonable cooperation and assistance to Browsi in ensuring compliance with its obligation to carry out data protection impact assessments with respect to the Processing of its Company Data and to consult with the Supervisory Authority (as applicable). 3.4.If the EU Data Protection Law or the CCPA do not apply to the Company, then the Company must abide by any other Data Protection Law and data security laws and regulations that apply to it, and at a minimum Company shall: (i) obtain and maintain any and all authorizations, permissions and informed consents, as may be necessary under applicable laws and regulations, in order to allow Browsi to lawfully use the processed data within the scope of the Service; (ii) substantiate the legal basis and legitimize, pursuant to applicable law, the collection of the Company Data through the Service; (iii) have, properly publish and abide by an appropriate privacy policy that complies with all applicable Data Protection Law. 3.5. Notwithstanding the above, in the event the Company is an Israeli establishment or Company Data includes processing of Israeli data subjects, or in any event that the IL Law shall apply, the parties hereby undertake that they comply with the aforesaid regulations as well as comply with the DPA. 4. Processing of Personal Data and Compliance with Data Protection Law As between the parties, the Company undertakes, accepts and agrees that the Data Subjects do not have a direct relationship with Browsi and that Browsi relies on Company’s lawful basis (as required under Data Protection Law). In the event consent is needed under Data Protection Law, the Company shall ensure that it obtains a proper act of consent from Data Subjects and present all necessary and appropriate notices in accordance with applicable Data Protection Law and other relevant privacy requirements in order to Process Company Data and enable the lawful transfer and Processing of Company Data to and by the Company, as well as where applicable, provide the Data Subjects with the ability to opt out. In the event Data Subject consent is required under Data Protection Law, Company shall be fully responsible to support and transmit to Browsi, the parameter of consent, or opt-out, as applicable. The Company shall maintain a record of all consents obtained from a Data Subject, including the time and date on which consent was obtained, the information presented to the Data Subject in connection with their giving consent, and details of the mechanism used to obtain consent, as well as a record of the same information in relation to all withdrawals of consent by Data Subject. Company shall make these records available to Browsi promptly upon request. 5. Rights of Data Subjects and Parties Cooperation Obligations 5.1. It is agreed that where Browsi receives a request from a Data Subject or an applicable authority in respect of Company Data Processed by Browsi, where relevant, Browsi will direct the Data Subject or the applicable authority to the Company in order to enable the Company to respond directly to the Data Subject’s or the applicable authority’s request, unless otherwise required under applicable laws. Parties shall provide each other with commercially reasonable cooperation and assistance in relation to the handling of a Data Subject’s or applicable authority’s request, to the extent permitted under Data Protection Law. 5.2. Where applicable, Browsi shall assist the Company in ensuring that Company Data Processed is accurate and up to date, by informing the Company without delay if Browsi becomes aware of the fact that the Company Data it is Processing is inaccurate or has become outdated. 6. Company Personnel Browsi shall take reasonable steps to ensure: (i) the reliability of its staff and any other person acting under its supervision who may come into contact with, or otherwise have access to and Process Company Data; (ii) that persons authorized to process the Company Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality; and (iii) that such personnel are aware of their responsibilities under this DPA and any applicable Data Protection Laws. 7. No Sale of Personal Information It is hereby agreed that any sharing of Personal Data between the parties is made solely in order to fulfill a Business Purpose and Browsi does not receive or process any Personal Data in consideration for the Service. Thus, such Processing of Personal Data shall not be considered as a “Sale” of Personal Information under the CCPA. 8. Sub-Processor The Company acknowledges that Browsi does not transfer Company Data to and otherwise interact with third party data Processors (“Sub-Processor”). 9. Technical and Organizational Measures 9.1. Taking into account the state of the art, the costs of implementation and the nature, scope, context, and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, and without prejudice to any other security standards agreed upon by the parties, Browsi hereby confirms that it has implemented and will maintain appropriate physical, technical and organizational measures to protect the Company Data as required under Data Protection Laws to ensure lawful processing of Company Data and safeguard Company Data from unauthorized, unlawful or accidental processing, access, disclosure, loss, alteration or destruction. The parties acknowledge that security requirements are constantly changing and that effective security requires the frequent evaluation and regular improvement of outdated security measures. 9.2. The security measures are further detailed in Annex B. 10. Data Transfer 10.1. The Company acknowledges and agrees that in order to be provided with the Service, Browsi may access and Process the Company Data from territories that are not part of the EEA. Moreover, the Company further agrees that Browsi may use third party server services (such as AWS) which is not established in the EEA , only for purpose of storing the Collected Data for used only to provide the Browsi Services to Publisher, and Browsi relies upon the security and reputation of such known third party’s measurements on securing the Data. 10.2. The purpose and description of the transfer is set forth in Annex A. 11. Term & Termination 11.1. This DPA shall be effective as of the Effective Date and shall remain in force until the Agreement terminates. 11.2. Browsi shall be entitled to terminate this DPA or terminate the Processing of Company Data in the event that Processing of Company Data under the Customer’s instructions or this DPA infringe applicable legal requirements. 11.3. Following the termination of this DPA, Browsi shall, at the choice of the Customer, delete all Company Data processed on behalf of the Customer and certify to the Customer that it has done so, or, return all Company Data to the Company and delete existing copies, unless applicable law or regulatory requirements requires that Browsi continue to store Company Data. Until the Company Data is deleted or returned, the parties shall continue to ensure compliance with this DPA. Annex A Details of Processing and Transferring of Company Data This Annex includes certain details of the Processing and transferring of Personal Data as required by Article 28(3) GDPR and the Standard Contractual Clauses. The subject matter and duration of the Processing carried out by the Processor on behalf of the Controller, the nature and purpose of the Processing, the type of Data and categories of Data Subjects are described in Annex A attached hereto. 1. Categories of data subjects whose personal data is processed or transferred: No personal data of any data subject is processed or transferred. 2. Categories of personal data processed and transferred: No personal data collected or processed. 3. Data type processed: Non personal, unidentified data as follows: – aggregated data for purpose of improving the algorithm optimizing the Publisher’s advertising Inventory – browser data available by Publisher extracting the end user country from the IP address without retention of the IP, in order to comply with the applicable territorial data privacy laws (for example whether it is EU, or USA etc.) 4. Sensitive data processed or transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measure: No Collection or process of sensitive data. 5. Nature of the processing and transfer: Data as described above and only for purpose of providing the services to and on behalf of Publisher. no transfer of Company Data . 6. Duration of the processing: For as long as is necessary to provide the Service by the Company; provided there is no legal obligation to retain the Data past termination. Annex B Technical and Organizational Measures Except for such data descried under Annex A (the “Data”), Company does not collect and/or process any personal data. Data is stored within AWS under and subject to the AWS security measures. We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent. Cookie SettingsAccept All Manage consent