Third Party Index

Snapshot 34050

Document
Subprocessor list
URL
https://docs.google.com/document/d/1c9T4szpbbPYkiz-0BdeKwrkp2UGZQOkQ0P_dPxeQtc8/mobilebasic#subprocessors
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
409898 bytes
SHA-256 (raw)
6ccd5654c1f33b28c089cb48f27cb632e028c3543fce5ad350413c2132eebea5
SHA-256 (normalized text)
39a3bad6cd4806781ecedeb2a23887ec6e65b8e00562862e6ba0d51ee689ec2e

Normalized text

Scripts and page chrome removed; this is what change detection compares.

TeqBlaze Data Processing Agreement
Last Updated: April 09, 2025
These Data Processing Agreement (hereinafter – the “DPA”) is incorporated into and forms part of the TeqBlaze General Terms and Conditions (hereinafter – the “TC” or the “Terms”), a part of the public offer and the appropriate documentation relating to the services (the “Services”), which include, but not limited to the Platform (as stated below), to be provided by TEQBLAZE, LDA, a company duly incorporated under the laws of Portugal, having its registered office at Rua Braancamp, nº 9, 3º Esq, Distrito: Lisboa - Concelho: Lisboa - Freguesia: Santo António, 1250 048, Lisbon, Portugal (hereinafter - the “Company” or “TeqBlaze”) to the Client (whose details specified in the applicable Purchase Order Form), which are separately referred as the “party” or the “Party” and together referred as the “parties” or the “Parties”, as stipulated on the TeqBlaze’s website https://teqblaze.com/#services (hereinafter - the “Website”) as may be amended by TeqBlaze from time to time and together with the applicable Purchase Order Form (hereinafter - the “PO” or the “Order Form”) create a legally binding agreement (hereinafter - the “Agreement”) between TeqBlaze and Client.
BACKGROUND
A). The Client and TeqBlaze are parties to the Agreement for the provision of the Services which include, but not limited to the Platform, by TeqBlaze to the Client.
B). In connection with the provision of the Services by TeqBlaze to the Client, the parties acknowledge that TeqBlaze and/or the Client processes (as defined below) Personal Data (as defined below) of which TeqBlaze and/or the Client is either the Controller (as defined below) or Processor (as defined below) and/or pursuant to Data Protection Laws (as defined below).
C).The parties now wish to ensure that they both comply with Data Protection Laws, respect the fundamental data protection rights of the Data Subjects (as defined below) whose Personal Data will be Processed (as defined below), and ensure adequate safeguards are in place to protect such Personal Data when sharing such Personal Data pursuant to the Agreement.
1. General
2. Definitions
3. Client Responsibilities
4. TeqBlaze Obligations as Processor
5. Data Subject Requests
6. Sub-Processors
7. Data Transfers
8. Demonstration of Compliance
9. Additional Provisions for European Data
10. Additional Provisions for California Personal Information
11. Controller-to-Controller Terms
12. Transfer Mechanisms
13. Miscellaneous
14. Parties to this DPA
Annex 1(A) - Details of Processing - TeqBlaze as Processor
Annex 1(B) - Details of Processing - TeqBlaze as Controller
Annex 2 - Technical and organizational security measures
Annex 3 - Sub-Processors
General
The parties acknowledge and agree that this DPA is intended to be read in conjunction with the Agreement and shall amend and/or supersede any existing clauses or schedules relating to the processing of Personal Data in the Agreement.
Except as amended by this DPA, the Agreement and the relevant provisions contained therein will remain unchanged and in full force and effect.
For the avoidance of doubt, in the case of any conflict between the terms of the Agreement and this DPA, this DPA will take precedence.
Where there is more than one Agreement, all references below to the Client shall be deemed references to the Client Affiliate that is party to the relevant Agreement and all references below to TeqBlaze shall be deemed references to TeqBlaze Affiliate that is party to the relevant Agreement.
The term of this DPA will take effect on the Effective Date of the Agreement and will remain in effect until terminated by either party pursuant to termination in accordance with the Agreement and/or this DPA.
Sections 4 through 10 of this DPA apply solely to the extent that TeqBlaze is a Processor of Personal Data in connection with the Services.
Section 11 applies solely to the extent that Client uses the Services, the Newsletter insights campaigns, enrichment of TeqBlaze products, with data sharing enabled, and each party is considered a Controller under Data Protection Laws.
Definitions
“California Personal Information” means Personal Data that is subject to the protection of the CCPA.
"CCPA" means California Civil Code Sec. 1798.100 et seq. (also known as the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 or "CPRA").
"Consumer," "Business," "Sell," "Service Provider," and "Share" will have the meanings given to them in the CCPA.
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of Processing Personal Data.
"Controller Personal Data" means Personal Data that each party Processes as a Controller in connection with the Services, the Newsletter insights campaigns, enrichment of TeqBlaze products, with data sharing enabled and each party is considered a Controller under Data Protection Laws.
“Personal Data” means Personal Data contained within Client Data that TeqBlaze Processes as a Processor on behalf of the Client.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed by TeqBlaze and/or TeqBlaze’s Sub-Processors in connection with the provision of the Services. "Personal Data Breach" will not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems.
“Data Protection Laws” means all applicable worldwide legislation relating to data protection and privacy which applies to the Processing of Personal Data under the Agreement, including without limitation European Data Protection Laws, the CCPA, and other applicable U.S. federal and state privacy laws, and the data protection and privacy laws of Australia, Canada, Singapore, India, Israel, etc., in each case as amended, repealed, consolidated, or replaced from time to time.
“Data Subject” means the individual to whom Personal Data relates.
"Europe" means the European Union, the European Economic Area and/or their member states, Switzerland, and the United Kingdom.
“European Data” means Personal Data that is subject to the protection of European Data Protection Laws.
"European Data Protection Laws" means data protection laws applicable in Europe, including: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (General Data Protection Regulation) ("GDPR"); (ii) Directive 2002/58/EC concerning the processing of Personal Data and the protection of privacy in the electronic communications sector; and (iii) applicable national implementations of (i) and (ii); or (iii) GDPR as it forms parts of the United Kingdom domestic law by virtue of Section 3 of the European Union (Withdrawal) Act 2018 ("UK GDPR"); and (iv) Swiss Federal Data Protection Act and its Ordinance ("Swiss DPA"); in each case, as may be amended, superseded, or replaced.
“Instructions” means the written, documented instructions issued by Client to TeqBlaze, and directing TeqBlaze to perform a specific or general action with regard to Personal Data (including, but not limited to, depersonalizing, blocking, deletion, and making available).
“International Transfer Requirements” means the requirements of Chapter V of the GDPR (Transfers of personal data to third countries or international organizations) and/or analogous provisions of the Data Protection Act 2018 (as applicable).
“Personal Data” means any information relating to an identified or identifiable individual where such information is protected similarly as personal data, personal information, or personally identifiable information under Data Protection Laws.
“Platform” means a white label technical solution, namely 1). Supply-Side Platform + Ad Exchange as a Service, created by TeqBlaze or 2). Demand-Side Platform as a Service created by TeqBlaze.
“Processing” means any operation or set of operations which is performed on Personal Data, encompassing the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction or erasure of Personal Data. The terms “Process,” “Processes,” and “Processed” will be construed accordingly.
“Processor” means a natural or legal person, public authority, agency, or other body which Processes Personal Data on behalf of the Controller.
“Restricted Transfer” means transfer of Personal Data originating from Europe to a country that does not provide an adequate level of protection within the meaning of applicable European Data Protection Laws.
“Standard Contractual Clauses” means the standard contractual clauses annexed to the European Commission’s Decision (EU) 2021/914 of 4 June 2021 currently found at https://eur lex.europa.eu/eli/dec_impl/2021/914 or such other standard contractual clauses approved by the EU authorities with respect to personal data transfers out of the EEA as may be amended, superseded, or replaced from time to time.
“Sub-Processor” means any Processor engaged by TeqBlaze or TeqBlaze Affiliates to assist in fulfilling TeqBlaze obligations with respect to the Processing of Personal Data under the Agreement. Sub-Processors may include third parties or TeqBlaze Affiliates but will exclude any TeqBlaze employee or consultant.
“UK Addendum” means the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018 currently found at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer addendum.pdf, as may be amended, superseded, or replaced.
Client Responsibilities
Compliance with Laws. Within the scope of the Agreement and the Client’s use of the Services, the Client will be responsible for complying with all requirements that apply to the Client under Data Protection Laws with respect to the Client’s Processing of Personal Data. In particular but without prejudice to the generality of the foregoing, the Client acknowledge and agree that the Client will be solely responsible for:
(i) the accuracy, quality, and legality of Personal Data and the means by which the Client acquired such data;
(ii) complying with all necessary transparency and lawfulness requirements under Data Protection Laws for the collection and use of Personal Data, including providing adequate notices, obtaining any necessary consents and authorizations, and honoring opt-out preferences (particularly for use by Client for marketing purposes);
(iii) ensuring the Client have the right to transfer, or provide access to, Personal Data to TeqBlaze for Processing in accordance with the terms of the Agreement (including this DPA);
(iv) complying with all laws applicable to content sent or managed through the Services (including those relating to obtaining consents); and
(v) ensuring that the Client’s use of Controller Personal Data complies with Data Protection Laws and is strictly limited to the purposes set out in the Agreement (including this DPA). The Client will inform TeqBlaze without undue delay if the Client is not able to comply with the Client's Responsibilities under this 'Compliance with Laws' section or Data Protection Laws.
Client Instructions. The Client is responsible for ensuring that the Client’s Instructions to TeqBlaze regarding the Processing of Personal Data comply with applicable laws, including Data Protection Laws. The parties agree that the Agreement (including this DPA), together with the Client’s use of the Services in accordance with the Agreement, constitute the Client’s complete Instructions to TeqBlaze in relation to TeqBlaze’s Processing of Personal Data.
The Client may provide additional instructions during the Term that are consistent with the Agreement and the nature and lawful use of the Services.
Security. The Client is responsible for independently determining whether the data security provided for in the Services adequately meets the Client’s obligations under Data Protection Laws. The Client is also responsible for the Client’s secure use of the Services, including protecting the security of Personal Data in transit to and from the Services (including to securely backup or encrypt such data).
TeqBlaze Obligations as Processor
Compliance with Instructions. TeqBlaze will only Process Personal Data for the purposes described in this DPA or as otherwise agreed within the scope of the Client’s lawful Instructions, except where and to the extent otherwise required by applicable law. TeqBlaze are not responsible for compliance with any Data Protection Laws applicable to the Client or the Client’s industry that are not generally applicable to TeqBlaze if otherwise by prior agreement of the parties.
Conflict of Laws. If TeqBlaze become aware that TeqBlaze cannot Process Personal Data in accordance with the Client’s Instructions due to a legal requirement under any applicable law, TeqBlaze will (i) promptly notify the Client of that legal requirement to the extent permitted by the applicable law; and (ii) where necessary, cease all Processing (other than merely storing and maintaining the security of the affected Personal Data) until such time as the Client issue new Instructions with which TeqBlaze are able to comply. If this provision is invoked, TeqBlaze will not be liable to the Client under the Agreement for any failure to perform the applicable Services until such time as the Client issues new lawful Instructions with regard to the Processing.
Security. TeqBlaze will implement and maintain appropriate technical and organizational security measures to protect Personal Data from Personal Data Breaches, as described under Annex 2 to this DPA (the "Security Measures"). Notwithstanding any provision to the contrary, TeqBlaze may modify or update the Security Measures at TeqBlaze discretion provided that such modification or update does not result in a material degradation in the protection offered by the Security Measures.
Confidentiality. TeqBlaze will ensure that any personnel whom TeqBlaze authorises to Process Personal Data on TeqBlaze behalf is subject to appropriate confidentiality obligations (whether a contractual or statutory duty) with respect to that Personal Data.
Personal Data Breaches. TeqBlaze will notify the Client without undue delay, and in any case not later than 72 hours after having become aware of a Personal Data Breach, unless such notification is not required under Article 33(1) of the GDPR. At the Client’s request, TeqBlaze will promptly provide the Client with such reasonable assistance as necessary to enable the Client to notify relevant Personal Data Breaches to competent authorities and/or affected Data Subjects, if the Client is required to do so under Data Protection Laws.
Deletion or Return of Personal Data. TeqBlaze will delete or return all Client Data, including Personal Data (including copies thereof) Processed pursuant to this DPA, on termination or expiration of the Services in accordance with the procedures set out in the Agreement, this DPA and agreements by the parties. This term will apply except where TeqBlaze is required by applicable law to retain some or all of the Client Data, or where TeqBlaze have archived Client Data on back-up systems, which data TeqBlaze will securely isolate and protect from any further Processing and delete in accordance with TeqBlaze deletion practices.
If the Client needs help retrieving the Client’s Client Data during the Term, TeqBlaze will provide reasonable assistance to the Client, at the Client’s cost, and in accordance with the additional service proposal from TeqBlaze.
In addition to the TeqBlaze’s obligation to assist the Client pursuant to the above, TeqBlaze shall provide reasonable assistance to the Client in ensuring compliance with the following obligations, taking into account the nature of Process Personal Data and the information available to TeqBlaze:
the obligation to assist in an assessment of the impact of the envisaged Processing operations on the protection of Personal Data (a ‘data protection impact assessment’) where a type of Processing is likely to result in a high risk to the rights and freedoms of natural persons;
the obligation to consult the competent supervisory authority/ies prior to Processing where a data protection impact assessment indicates that the Processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk;
the obligation to ensure that Personal Data is accurate and up to date, by informing the Client without delay if Teqblaze becomes aware that Personal Data it is Processing is inaccurate or has become outdated;
the obligations in Article 32 GDPR.
Data Subject Requests
The Services provides the Client with a number of controls that the Client can use to retrieve, correct, delete, or restrict Personal Data, which the Client can use to assist itself in connection with the Client’s obligations under Data Protection Laws, including the Client’s obligations relating to responding to requests from Data Subjects to exercise their rights under Data Protection Laws ("Data Subject Requests").
To the extent that the Client are unable to independently address a Data Subject Request through the Services, then upon the Client’s written request TeqBlaze will provide reasonable assistance to the Client to respond to any Data Subject Requests or requests from data protection authorities relating to the Processing of Personal Data under the Agreement. The Client will reimburse TeqBlaze for the commercially reasonable costs arising from this assistance.
If a Data Subject Request or other communication regarding the Processing of Personal Data under the Agreement is made directly to TeqBlaze, TeqBlaze will promptly inform the Client and will advise the Data Subject to submit their request to the Client. The Client will be solely responsible for responding substantively to any such Data Subject Requests or communications involving Personal Data. TeqBlaze shall not respond to the request itself, unless authorised to do so by the Client.
To the extent required by applicable Data Protection Laws, TeqBlaze shall respond to Data Subject Requests without undue delay and, where feasible, within one month of receipt. The first response to such request shall be provided free of charge, unless the request is manifestly unfounded or excessive.
Sub-Processors
The Client agrees TeqBlaze may engage Sub-Processors to Process Personal Data on the Client behalf, and TeqBlaze does so in three ways:
TeqBlaze may engage Sub-Processors to assist TeqBlaze with hosting and infrastructure;
TeqBlaze may engage with Sub-Processors to support product features and integrations;
TeqBlaze may engage with TeqBlaze Affiliates as Sub-Processors for service and support.
Some Sub-Processors will apply to the Client as default, and some Sub-Processors will apply only if the Client opt in.
TeqBlaze has currently appointed, as Sub-Processors, the third parties and TeqBlaze Affiliates listed in Annex 3 to this DPA (the list of Sub-Processors). The parties shall keep the list of Sub-Processors up to date. Subject to compliance, TeqBlaze may engage an additional or replace an existing Sub-Processors to Process Personal Data provided that TeqBlaze will give the Client the opportunity to object to the engagement of new Sub-Processors on reasonable grounds relating to the protection of Personal Data within 30 (thirty) days of notifying the Client before such changes become effective. If the Client does notify TeqBlaze of such an objection, the parties will discuss the Client’s concerns in good faith with a view to achieving a commercially reasonable resolution. If no such resolution can be reached, TeqBlaze will, at TeqBlaze sole discretion, either not appoint the new Sub-Processor, or permit the Client to suspend or terminate the affected Services in accordance with the termination provisions of the Agreement without liability to either party (but without prejudice to any fees incurred by the Client prior to suspension or termination).
Where TeqBlaze engage Sub-Processors, TeqBlaze will impose data protection terms on the Sub-Processors that provide at least the same level of protection for Personal Data as those in this DPA, to the extent applicable to the nature of the services provided by such Sub Processors. TeqBlaze will remain responsible for each Sub-Processor’s compliance with the obligations of this DPA and for any acts or omissions of such Sub-Processor that cause TeqBlaze to breach any of its obligations under this DPA.
TeqBlaze will, where it engages any Sub-Processor:
prior to engagement, carry out appropriate due diligence on the Sub-Processor with regards to its data protection and security practices and provide the Client with evidence on request;
only use Sub-Processor that has provided sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of Data Protection Laws and the Agreement and ensure the protection of the rights of Data Subjects;
impose, through a legally binding contract between TeqBlaze and Sub-Processor, data protection obligations no less onerous than those set out in this DPA on Sub-Processor, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of Data Protection Laws; and
remain fully liable to the Client for the performance of Sub-Processor where it fails to fulfil its obligations in the contract between TeqBlaze and Sub-Processor.
Data Transfers
The Client acknowledge and agree that TeqBlaze may access and Process Personal Data on a global basis as necessary to provide the Services in accordance with the Agreement, and in particular that Personal Data may be transferred to and Processed by TeqBlaze in the United States, the European Union and to other jurisdictions where TeqBlaze Affiliates and Sub-Processors have operations. Wherever Personal Data is transferred outside its country of origin, each party will ensure such transfers are made in compliance with the requirements of Data Protection Laws.
Moreover any transfer of Personal Data to a third country by Processor shall be done only on the basis of documented instructions from Controller or in order to fulfil a specific requirement under Data Protection Laws to which Processor is subject and shall take place in compliance, including, but not limited to Chapter V of the GDPR.
Сontroller agrees that where Processor engages Sub-Processors for carrying out specific Processing activities (on behalf of Controller) and those Processing activities involve a transfer of Personal Data within the meaning of Chapter V of the GDPR, Processor and Sub-Processors can ensure compliance with Chapter V of the GDPR by using standard contractual clauses adopted by the Commission in accordance with of Article 46(2) GDPR, provided the conditions for the use of those standard contractual clauses are met.
The parties acknowledge and agree that the standard contractual clauses may not, in isolation, ensure that Processing complies with the International Transfer Requirements. Accordingly, the parties shall, promptly on the other party’s request and in any event prior to the Restricted Transfer, implement and maintain such supplementary measures in respect of the Restricted Transfer to ensure the Restricted Transfer complies the International Transfer Requirements (including applicable technical, contractual and organizational supplementary measures recommended by the European Data Protection Board as set out in its Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data adopted on 10 November 2020 as may be updated, amended or replaced from time to time), or such other measures or safeguards as may be otherwise required by the other party) (“Supplementary Measures”). To the extent that the party determines that the processing cannot comply with the International Transfer Requirements, it may at no additional cost and without further liability either:
suspend the relevant Restricted Transfer and require any Personal Data already transferred to the other party to be immediately returned and/or deleted, at the election of the party;
require the other party to only Process Personal Data within certain jurisdictions and/or subject to certain other restrictions, supplementary measures and/or safeguards; and/or
terminate the Services provided under the Agreement in whole or in part on thirty (30) calendar days’ prior written notice and where fees for the Services provided under this Agreement are paid in advance, it shall not be entitled to a refund in respect of fees paid for Services not provided in accordance with the Agreement as at the effective date of termination.
Notwithstanding clause above, TeqBlaze warrants, represents and undertakes that TeqBlaze and TeqBlaze Affiliates:
along with notifying the Client about any binding or voluntary request for disclosure, shall, where possible notify the relevant Data Subject and (if applicable) shall procure that TeqBlaze Affiliates shall, in each case, subject to applicable law, not send any Personal Data to such law enforcement agency without first challenging such request and allowing the Client and/or Data Subject a reasonable opportunity to challenge such request. For the avoidance of doubt in the event of a challenge, TeqBlaze shall not send Personal Data to such law enforcement authority until a court has decided on the merits of the challenge. Where it is not possible to challenge the particular order, TeqBlaze shall only disclose the minimum amount of Personal Data necessary to comply with the order. TeqBlaze shall not comply with any requests to provide Personal Data to a public authority on a voluntary basis without first obtaining the permission of the Client and relevant Data Subject;
shall provide such assistance as may be reasonably required by the Client and/or Data Subject to Data Subject to exercise his/her rights in respect of the processing of his/her personal data in the relevant jurisdiction of the TeqBlaze; and
shall comply with the Supplementary Measures.
Transfers to third parties. Without prejudice of the above, the Client acknowledges and agrees that Personal Data may be transferred to third parties in those locations set out in Annex 3 to this DPA, subject to TeqBlaze:
carrying out appropriate due diligence (in such form that is satisfactory to the Client) on the relevant third party (and the relevant third party’s jurisdiction) to assess the adequacy of the third party and its jurisdiction in light of the Court of Justice of the European Union judgment in the case of C-311/18 Facebook Ireland and Schrems (“Schrems ii”) and International Transfer Requirements and providing the Client with evidence of the results;
executing (acting on the Client’s behalf), and procuring the execution of by the relevant third party, the Standard Contractual Clauses;
complying, and procuring that the relevant third party complies, with TeqBlaze’s or the relevant third party’s respective obligations under the Standard Contractual Clauses;
notifying the Client of any notification from the third party pursuant to clauses 5(b) and/or 5(d) of the Standard Contractual Clauses; and
Where the parties rely on the Standard Contractual Clauses to transfer personal data from one party to another, to the extent a conflict arises in respect of the operative clauses of this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail. For the avoidance of doubt, nothing in this DPA is intended to vary, modify or contradict the provisions of the Standard Contractual Clauses.
Demonstration of Compliance
The parties shall be able to demonstrate compliance with the DPA.
The parties shall deal promptly and adequately with inquiries from each other about the processing of data in accordance with the DPA.
The parties shall make available to each other all information necessary to demonstrate compliance with the obligations that are set out in the DPA and stem directly from Data Protection Laws. At the Controller’s request, the Processor shall also permit and contribute to audits of the processing activities covered by the DPA, at reasonable intervals or if there are indications of non-compliance or unless required by a competent supervisory authority. In deciding on a review or an audit, the Controller may take into account relevant certifications held by the Processor.
The Controller may mandate an independent auditor. Audits may also include inspections at the premises or physical facilities of the processor and shall, where appropriate, be carried out with reasonable notice.
The Client acknowledge that the TeqBlaze software and Services may be hosted by TeqBlaze hosting Sub-Processors who maintain independently validated security programs (including SOC 2 and ISO 27001) and that their systems are audited annually as part of SOC 2 compliance and regularly tested by independent third-party penetration testing firms.
The Parties shall make the information referred to in this Clause, including the results of any audits, available to the competent supervisory authority/ies on request.
All reasonable costs of the audit shall be borne by the Controller, unless the audit reveals a material breach by the Processor.
Additional Provisions for European Data
Scope. This 'Additional Provisions for European Data' section will apply only with respect to European Data that TeqBlaze Processes on the Client behalf under the Agreement.
Roles of the Parties. When Processing European Data in accordance with the Client’s Instructions, the parties acknowledge and agree that the Client is acting either as the Controller, or as a Processor on behalf of another Controller, and TeqBlaze is the Processor under the Agreement.
Instructions. If TeqBlaze believes that the Client’s Instruction infringes European Data Protection Laws (where applicable), TeqBlaze will inform the Client without delay.
Data Protection Impact Assessments and Consultation with Supervisory Authorities. To the extent that the required information is reasonably available to TeqBlaze, and the Client does not otherwise has access to the required information, TeqBlaze will provide reasonable assistance to the Client with any data protection impact assessments, and prior consultations with supervisory authorities (for example, the French Data Protection Agency (CNIL), the Berlin Data Protection Authority (BlnBDI) and or other competent data privacy authorities to the extent required by European Data Protection Laws.
Data Transfers. TeqBlaze will not transfer European Data to any country or recipient not recognized as providing an adequate level of protection for Personal Data (within the meaning of applicable European Data Protection Laws), unless it first takes all such measures as are necessary to ensure the transfer is in compliance with applicable European Data Protection Laws. Such measures may include (without limitation): (i) transferring such data to a recipient that is covered by a suitable framework or other legally adequate transfer mechanism recognized by the relevant authorities or courts as providing an adequate level of protection for Personal Data; (ii) to a recipient that has achieved binding corporate rules authorization in accordance with European Data Protection Laws; or (iii) to a recipient that has executed the Standard Contractual Clauses in each case as adopted or approved in accordance with applicable European Data Protection Laws.
TeqBlaze confirms that it has appointed a Data Protection Officer (DPO), in accordance with Article 37 GDPR, who may be contacted at [email protected].
Additional Provisions for California Personal Information
Scope. The 'Additional Provisions for California Personal Information' section of the DPA will apply only with respect to California Personal Information that TeqBlaze Processes on the Client behalf under the Agreement.
Roles of the Parties. When processing California Personal Information in accordance with the Client’s Instructions, the parties acknowledge and agree that the Client is a Business and TeqBlaze is a Service Provider for the purposes of the CCPA.
Responsibilities. TeqBlaze certify that TeqBlaze will Process California Personal Information as a Service Provider strictly for the purpose of performing the Services and Consulting Services under the Agreement (the "Business Purpose") or as otherwise permitted by the CCPA, including as described in the TeqBlaze Privacy Policy. Further, TeqBlaze certify that TeqBlaze will not (i) Sell or Share California Personal Information; (ii) Process California Personal Information outside the direct business relationship between the parties, unless required by applicable law; or (iii) combine California Personal Information included in Client Data with Personal Data that TeqBlaze collect or receive from another source (other than information TeqBlaze receive from another source in connection with TeqBlaze obligations as a Service Provider under the Agreement).
Compliance. TeqBlaze will (i) comply with the obligations applicable to TeqBlaze as a Service Provider under the CCPA; (ii) provide the same level of protection for California Personal Information as is required by the CCPA; and (iii) notify the Client if TeqBlaze make a determination that TeqBlaze `can no longer meet TeqBlaze obligations as a Service Provider under the CCPA.
CCPA Audits. The Client will have the right to take reasonable and appropriate steps to help ensure that TeqBlaze uses California Personal Information in a manner consistent with the Client’s obligations under the CCPA. Upon notice, the Client will have the right to take reasonable and appropriate steps in accordance with the Agreement to stop and remediate unauthorized use of California Personal Information.
Not a Sale. The parties acknowledge and agree that the disclosure of California Personal Information by Client to TeqBlaze does not form part of any monetary or other valuable consideration exchanged between the parties.
Controller-to-Controller Terms
Scope. This 'Controller-to-Controller Terms' section will apply to the extent that the parties Process Controller Personal Data in connection with the Client’s use of the Services, the Newsletter insights campaigns, the Client Needs Analysis, other enrichment of TeqBlaze products, with data sharing enabled.
Role of the Parties. The parties acknowledge and agree that they act as Controllers of Controller Personal Data and will comply with their respective obligations under Data Protection Laws when Processing Controller Personal Data. For clarity, nothing in the Agreement or this 'Controller-to-Controller Terms' section shall restrict TeqBlaze in any way from collecting, using, or sharing data that TeqBlaze would otherwise Process independently of Client's use of the Newsletter insights campaigns, the Client Needs Analysis, other enrichment of TeqBlaze products, with data sharing enabled in order to provide and/or receive the Services.
Compliance with Laws. Each party will ensure that the Controller Personal Data it shares or makes available to the other party has been collected in compliance with Data Protection Laws, including (i) providing adequate notices and obtaining any required consents from Data Subjects; (ii) establishing a lawful basis for its Processing of Controller Personal Data; (iii) implementing appropriate technical and organizational measures to protect Controller Personal Data; and (iv) complying with any reporting obligations concerning personal data breaches involving Controller Personal Data. As between the parties, the Client is responsible for providing all necessary notices, consents, and opt-out mechanisms for the use of the Newsletter insights campaigns, the Client Needs Analysis, other enrichment of TeqBlaze products, with data sharing enabled, and ensuring that its utilization of the Services discloses the use of third-party tracking technology in compliance with Data Protection Laws. If a Data Subject contacts either party to exercise their rights under Data Protection Laws, the contacted party shall either fulfill the request directly or, if this is not feasible, promptly notify and coordinate with the other party to ensure the request is fulfilled in accordance with Data Protection Laws. The Client agrees immediately notify TeqBlaze about it and delete the datа for the Newsletter insights campaigns, the Client Needs Analysis, other enrichment of TeqBlaze products if Client determines that Client does not have any independent lawful basis (or substantively similar terms) for Processing such data under Data Protection Laws.
Demonstration of Compliance. If either party receives any complaint, notice, or communication from a supervisory authority or other governmental authority which relates to the other party's: (i) Processing of Controller Personal Data; or (ii) potential failure to comply with Data Protection Laws with respect to the Processing of Controller Personal Data, that party shall direct the supervisory authority or governmental authority to the other party and, in the case of intertwined obligations, claims, or Controller Personal Data at issue, shall provide reasonable assistance to the other party in responding to the supervisory authority or governmental authority.
Security. TeqBlaze will implement and maintain reasonable Security Measures to protect Controller Personal Data. All Controller Personal Data is protected using appropriate physical, technical, and organizational measures.
CCPA Compliance. To the extent that the CCPA applies to the Processing of Controller Personal Data, each party acknowledges and agrees that: (i) such Controller Personal Data is made available to the other party solely for the limited and specified purposes set forth in the Agreement; (ii) the party receiving such Controller Personal Data shall comply with and provide the same level of privacy protection as is required by the CCPA; (iii) the party receiving such Controller Personal Data shall promptly notify the other party if it determines it can no longer meet its obligations under the CCPA; and (iv) the party providing such Controller Personal Data shall have the right, upon reasonable notice, to take reasonable and appropriate steps to ensure that the receiving party uses the Controller Personal Data in a manner consistent with its obligations under the CCPA and stop and remediate unauthorized uses of the Controller Personal Data.
Transfer Mechanisms
Where the transfer of Personal Data or Controller Personal Data between the parties involves a Restricted Transfer and European Data Protection Laws require putting in place appropriate safeguards, TeqBlaze and Client will comply with the following:
Standard Contractual Clauses. If European Data Protection Laws require that appropriate safeguards are put in place, the Standard Contractual Clauses will be incorporated by reference and form part of the Agreement as follows:
In relation to Personal Data that TeqBlaze Processes as a Processor (i) the Module Two terms apply to the extent Client is a Controller and the Module Three terms apply to the extent Client is a Processor of Personal Data; (ii) in Clause 7, the optional docking clause applies; (iii) in Clause 9, Option 2 applies and changes to Sub Processors will be notified in accordance with the ‘Sub-Processors’ section of this DPA; (iv) in Clause 11, the optional language is deleted; (v) in Clauses 17 and 18, the parties agree that the governing law and forum for disputes for the Standard Contractual Clauses will be determined in accordance with the 'GOVERNING LAW AND VENUE’ section of the Terms or, if such section does not specify an EU Member State, Portugal (without reference to conflicts of law principles); (vi) the Annexes of the Standard Contractual Clauses will be deemed completed with the information set out in the Annexes of this DPA; and (vii) the supervisory authority that will act as competent supervisory authority will be determined in accordance with GDPR.
In relation to Controller Personal Data for which TeqBlaze and Client are each a Controller (i) the Module One terms apply; (ii) in Clause 7, the optional docking clause applies; (iii) in Clause 11, the optional language is deleted; (iv) in Clauses 17 and 18, the parties agree that the governing law and forum for disputes for the Standard Contractual Clauses will be determined in accordance with the 'GOVERNING LAW AND VENUE’ section of the Terms or, if such section does not specify an EU Member State, Portugal (without reference to conflicts of law principles); (v) the Annexes of the Standard Contractual Clauses will be deemed completed with the information set out in the Annexes of this DPA; and (vi) the supervisory authority that will act as competent supervisory authority will be The Comissão Nacional de Protecção de Dados "CNPD" (national Data Protection Authority for Portugal).
In relation to Personal Data and Controller Personal Data that is subject to the UK GDPR, the Standard Contractual Clauses will apply in accordance with sub-section (A) and the following modifications (i) the Standard Contractual Clauses will be modified and interpreted in accordance with the UK Addendum, which will be incorporated by reference and form an integral part of the Agreement; (ii) Tables 1, 2 and 3 of the UK Addendum will be deemed completed with the information set out in the Annexes of this DPA and Table 4 will be deemed completed by selecting “neither party”; and (iii) any conflict between the terms of the Standard Contractual Clauses and the UK Addendum will be resolved in accordance with Section 10 and Section 11 of the UK Addendum.
In relation to Personal Data and Controller Personal Data that is subject to the Swiss DPA, the Standard Contractual Clauses will apply in accordance with sub-section (A) and the following modifications (i) references to "Regulation (EU) 2016/679" will be interpreted as references to the Swiss DPA; (ii) references to "EU," "Union," and "Member State law" will be interpreted as references to Swiss law; and (iii) references to the "competent supervisory authority" and "competent courts" will be replaced with the "the Swiss Federal Data Protection and Information Commissioner" and the "relevant courts in Switzerland."
In relation to Personal Data that TeqBlaze Processes as a Processor, the Client agree that by complying with TeqBlaze obligations under the 'Sub-Processors' section of this DPA, TeqBlaze fulfills its obligations under Section 9 of the Standard Contractual Clauses. For the purposes of Clause 9(c) of the Standard Contractual Clauses, the Client acknowledge that TeqBlaze may be restricted from disclosing Sub-Processor agreements but TeqBlaze will use reasonable efforts to require any Sub-Processor TeqBlaze appoint to permit it to disclose the Sub-Processor agreement to the Client and will provide (on a confidential basis) all information TeqBlaze reasonably can. The Client also acknowledges and agrees that the Client will exercise the Client’s audit rights under Clause 8.9 of the Standard Contractual Clauses by instructing TeqBlaze to comply with the measures described in the 'Demonstration of Compliance' section of this DPA.
If and to the extent the Standard Contractual Clauses conflict with any provision of this DPA, the Standard Contractual Clauses will prevail to the extent of such conflict. If TeqBlaze cannot comply with its obligations under the Standard Contractual Clauses for any reason, and the Client intend to suspend or terminate the transfer of Personal Data to TeqBlaze, the Client agrees to provide TeqBlaze with reasonable notice to enable TeqBlaze to cure such non-compliance and reasonably cooperate with TeqBlaze to identify what additional safeguards, if any, may be implemented to remedy such noncompliance. If TeqBlaze has not or cannot cure the non-compliance, the Client may suspend or terminate the affected part of the Services in accordance with the Agreement without liability to either party (but without prejudice to any fees the Client has incurred prior to such suspension or termination).
Alternative Transfer Mechanism. In the event that TeqBlaze is required to adopt an alternative transfer mechanism under European Data Protection Laws, in addition to or other than the mechanisms described above, such alternative transfer mechanism will apply automatically instead of the mechanisms described in this DPA (but only to the extent such alternative transfer mechanism complies with European Data Protection Laws), and the Client agree to execute such other documents or take such action as may be reasonably necessary to give legal effect such alternative transfer mechanism.
Miscellaneous
Amendments. Notwithstanding anything else to the contrary in the Agreement and without prejudice to the ‘Compliance with Instructions’ or ‘Security’ sections of this DPA, TeqBlaze reserve the right to make any updates and changes to this DPA and the terms that apply in the ‘Amendments’ section of the Terms will apply.
Severability. If any individual provisions of this DPA are determined to be invalid or unenforceable, the validity and enforceability of the other provisions of this DPA will not be affected.
Limitation of Liability. Each party's liability, taken in aggregate, arising out of or related to this DPA (including any other data processing agreements between the parties) and the Standard Contractual Clauses, where applicable, whether in contract, tort or under any other theory of liability, will be subject to the limitations and exclusions of liability set out in the 'Disclaimer. Limitation of Liability' section of the Terms and any reference in such section to the liability of a party means aggregate liability of that party under the Agreement (including this DPA). In no event will either party's liability be limited with respect to any individual's data protection rights under this DPA (including any other DPAs between the parties and the Standard Contractual Clauses, where applicable) or otherwise.
Indemnification. A party’s liability towards the other party shall also extend to any fines imposed on the other party, insofar as such fines are attributable to the culpable breach of the party's obligations under data protection law by the party, its employees or its agents. If, as a result of such a breach of obligation, an order imposing a fine on the other party becomes final, the party shall indemnify the other party, and hold the other party harmless, from the fine imposed, with the amount of such release determined in accordance with the internal proportion of liability in relation between the Parties if applicable. The proportion of the fine to be borne by the party shall depend on its share of responsibility for the breach sanctioned by the fine. In any event, the aforementioned liability on the part of the party shall be subject to the condition precedent that the other party notifies the party in writing without undue delay of any such case, does not acknowledge the alleged breach, and conducts any judicial or extrajudicial dispute, including any out-of-court settlement, only in consultation with the party. The party may in particular request that the other party have any fine notices judicially reviewed by all available competent bodies, in which case the party shall be obligated to indemnify the other party, and hold one party harmless, from the legal costs incurred in the amount of the statutory fees.
Persons authorised to issue instructions. Insofar as the parties deem it necessary, they shall designate in writing to each other those persons (including their respective contact details) who shall be exclusively authorised on its side to issue processing instructions to each other in accordance with the provisions of the DPA and the Agreement. Insofar as the parties make use of this right, only instructions from these persons and via the communication channels determined by the parties shall be legally binding within the meaning of the provisions of the DPA and the Agreement. The parties shall notify each other of any changes with regard to the persons authorised to issue instructions on the part of each other or their respective contact details.
Governing Law. This DPA will be governed by and construed in accordance with law of England and Wales, unless required otherwise by Data Protection Laws.
Other Rights. The parties agree that the Client will, when reviewing TeqBlaze compliance with this DPA pursuant to the ‘Demonstration of Compliance’ section, take all reasonable measures to limit any impact on TeqBlaze by combining several audit requests carried out on behalf of the Client entity that is the contracting party to the Agreement in one single audit.
The use of the Terms. All issues that are not settled hereunder shall, where possible, be regulated by default on the basis of the provisions of the Terms, unless otherwise expressly provided for in this DPA.
Annex 1A - Details of Processing - TeqBlaze as Processor
A. List of Parties
Data exporter:
Name: the Client (whose details specified in the applicable Purchase Order Form).
Address: The Client's address, as set out in the applicable Purchase Order Form.
Contact person’s name, position and contact details: The Client's contact details, as set out in the Purchase Order Form.
Activities relevant to the data transferred under these Clauses: Processing of Personal Data in connection with the Client's use of the Services and the Platform under the Terms and the Agreement
Role: Controller (either as the Controller; or acting in the capacity of a Controller, as a Processor, on behalf of another Controller)
Data importer:
Name: TEQBLAZE, LDA
Address: Rua Joaquim António de Aguiar 43, R/C Esq., 1070 150 Lisboa, Portugal
Contact person’s name, position and contact details: TeqBlaze contact details, as set out in the Purchase Order Form.
Activities relevant to the data transferred under these Clauses: Processing of Personal Data in connection with the Client's use of the Services and the Platform under the Terms and the Agreement
Role: Processor
B. Description of Transfer
Categories of Data Subjects whose Personal Data is Transferred
The Client may submit Personal Data in the course of using the Services and the Platform, the extent of which is determined and controlled by the Client in its own discretion (or the Controller’s), and which may include, but is not limited to Personal Data relating to the following categories of Data Subjects:
The Client’s customers’ and End Users (individuals who explore the publishers’ websites and/or applications and receive advertisements).
Data Subjects may also include individuals attempting to communicate with or transfer Personal Data to the Client’s End Users.
Categories of Personal Data Transferred
The Client may submit Personal Data to the Services and the Platform, the extent of which is determined and controlled by the Client in its own discretion, and which may include but is not limited to the following categories of Personal Data:
The Client’s contacts Information
End Users Identifiers: Identifier for Advertising (IFA; IDFA; GAID); User ID; Buyer ID; Device ID, IP address
Cookie Syncing data
Any other Personal Data submitted by, sent to, or received by the Client, or the Client’s End Users, via the Services and the Platform
Sensitive Data Transferred and Applied Restrictions or Safeguards
The processing of Sensitive Data is subject to the scope limitations, restrictions, and safeguards mutually agreed upon by the parties, as reflected in the Agreement.
Frequency of the Transfer
Continuous
Nature of the Processing
Personal Data will be Processed in accordance with the Agreement (including this DPA) and may be subject to the following Processing activities:
1. Storage and other Processing necessary to provide, maintain and improve the Services and the Platform provided to the Client; and/or
2. Disclosure in accordance with the Agreement (including this DPA) and/or as compelled by applicable laws.
Purpose of the Transfer and Further Processing
TeqBlaze will Process Personal Data as necessary to provide the Services and the Platform pursuant to the Agreement, as further specified in the Order Form, and as further instructed by the Client in its use of the Services and the Platform.
Period for which Personal Data will be retained
Subject to the 'Deletion or Return of Personal Data' section of this DPA, TeqBlaze will Process Personal Data for the duration of the Agreement, unless otherwise agreed in writing.
Annex 1B - Details of Processing - TeqBlaze as Controller
A. List of the parties
Data exporter/importer:
Name: the Client (whose details specified in the applicable Purchase Order Form).
Address: The Client's address, as set out in the applicable Purchase Order Form.
Contact person’s name, position and contact details: The Client's contact details, as set out in the Purchase Order Form.
Activities relevant to the data transferred under these Clauses: Processing of Personal Data in connection with the Client's use of the Services and the Platform under the Terms and the Agreement
Role (controller/processor): Controller
Data exporter/importer:
Name: TEQBLAZE, LDA
Address: Rua Joaquim António de Aguiar 43, R/C Esq., 1070 150 Lisboa, Portugal
Contact person’s name, position and contact details: TeqBlaze contact details, as set out in the Purchase Order Form.
Activities relevant to the data transferred under these Clauses: Processing of Personal Data in connection with the Client's use of the Services and the Platform under the Terms and the Agreement
Role (controller/processor): Controller
B. Description of Transfer
Categories of Data Subjects whose Personal Data is Transferred:
Employees and other personnel authorized to use and have access to the Services of TeqBlaze;
End Users (individuals who explore the publishers’ websites and/or applications and receive advertisements).
Categories of Personal Data Transferred:
Professional data, which may include, but is not limited to, first and last name, business email address, business employer, business role, professional title, IP address, online identifiers, personnel contact details (first name, last name, email, country (region), address, telephone and Skype) and other similar information.
The users data on the use of the Platform, unique user ID, device screen resolution, device type (unique device identifiers), operating system, and browser type, console logs and errors, geographic location (country only), preferred language, mouse events (movements, location and clicks), keypresses (suppressed by default), referring URL and domain, pages visited, date and time when the Platform was accessed and specific event on the Platform occurred, user attributes, any Personal Data provided in the feedback, survey or poll response, any Personal Data shared in the research screener responses, other Personal Data as may be seen on the Platform, etc.
Sensitive Data Transferred and Applied Restrictions or Safeguards:
The parties do not anticipate the transfer of sensitive data.
Frequency of the Transfer:
Continuous
Nature of the Processing:
Controller Personal Data will be Processed in accordance with the Agreement and may be subject to the following Processing activities:
(1) storage and other Processing of the Controller Personal Data by TeqBlaze necessary to provide, maintain, append, improve, and develop TeqBlaze the Services and the Platform; and/or
(2) disclosure in accordance with the Agreement and/or as compelled by applicable laws.
TeqBlaze processes such Controller Personal Data solely in aggregated or pseudonymized form unless otherwise required by applicable law. Where technically feasible, direct re-identification is prevented to safeguard Data Subject privacy.
Purpose(s) of the Transfer and Further Processing:
Controller Personal Data will be transferred for the purposes contemplated in the Agreement, including to provide the Client with business information and to provide, maintain, append, improve, enhance, and develop the Services and the Platform.
Period for which Personal Data will be Retained: Controller Personal Data will be Processed and retained by the parties in accordance with their respective data retention policies or as otherwise set out under the Agreement.
Annex 2 - Technical and organizational security measures
The Company currently observes the technical and organizational security measures described in this Annex 2. All capitalized terms not otherwise defined herein will have the meanings as set forth in the Terms and DPA.
Measures of pseudonymisation and encryption of personal data
The Company uses encryption and/or pseudonymization in its operations to mitigate data protection risks where it deems it appropriate. Encryption and pseudonymization methods may vary for different services depending on the requirements of the service and the assessment of data protection risks. Detailed information on the measures used is available upon request to the Company in accordance with the Company's counterpart service.
Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services
The Company has implemented measures to ensure the integrity, availability and security of personal information, including vulnerability scans. The Company maintains personal data availability through a variety of technical, physical, and administrative measures. Examples of these measures include: secured and monitored operational sites; processes and policies for topics such as incident response and review, and vendor review.
Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
Where required and technically feasible, the Company may implement backup functionality with all organizational precautions for storage and handling of such data.
Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures in order to ensure the security of the processing
At least once a year, security measures relevant to the processing of personal data are reviewed and tested for alignment with industry good practices.
Measures for user identification and authorisation
The Company has in place procedures that comply with applicable law to authenticate requests from data subjects who have submitted rights request. The Company has operational and technical controls in place to ensure that access to systems that process personal data is only granted to authorized personnel with a "need to know".
Measures for the protection of data during transmission
The Company has in place (where it is necessary) procedures that:
- use the encryption algorithms to prevent unauthorised access; - use secure communication protocols to secure data in transit by encrypting the data and verifying the identity of the parties involved in the transmission;
- develop and enforce security policies and procedures that outline how data in transit should be handled and protected; - train employees on data security best practices;
- regularly monitor and update security systems for potential vulnerabilities and update them as needed to keep up with the latest threats.
Measures for the protection of data during storage
The Company does not process any sensitive personal information, personal data processing is limited in scope and cannot be directly identified with a natural person by The Company. Data is only stored for as long as necessary for legitimate business purposes.
Measures for ensuring physical security of locations at which personal data are processed
Facilities involved in the processing of data are accessible only by authorized personnel. Technical controls in place to secure processing facilities include access controls, firewalls and anti-malware. Personal data can only be accessed by personnel who have a need-to-know and whose access to such information is required in order to deliver services under the Principle Agreement. The Company provides personnel who access personal data with appropriate information security and data protection training.
The Company hosts the Services and the Platform with outsourced cloud infrastructure providers. Additionally, the Company maintains contractual relationships with vendors in order to provide the Services the Platform in accordance with the DPA. The Company relies on contractual agreements, privacy policies, and vendor compliance programs in order to protect data processed or stored by these vendors.
The Company hosts its product infrastructure with multi-tenant, outsourced infrastructure providers. Production servers and client-facing applications are logically and physically secured from the Company’s internal corporate information systems. The infrastructure providers' physical and environmental security controls are audited for SOC 2 Type II and ISO 27001 compliance, among other certifications.
Measures for internal IT and IT security governance and management
The Company has in place (where it is necessary) procedures that use secure communication protocols to secure data, develop and enforce security policies and procedures on how data should be handled and protected, also the Company trains employees on data security best practices.
Measures for certification/assurance of processes and products
Measures and certification may be taken where necessary to work in accordance with industry standards such as TCF, etc.
Measures for ensuring data minimisation
The Company enforces internal data minimization policies and role-based access controls to ensure that only data strictly necessary for each processing purpose is collected and retained. The Company only collects personal data that the Company actually needs for specified purposes. The Company has sufficient personal data to properly fulfill those purposes. The Company periodically reviews the data it holds, and deletes anything the Company doesn't need.
Measures for ensuring data quality
The data quality aspects which the Company uses are the characteristics or attributes that define the quality of the data, such as accuracy, completeness, consistency, timeliness, reliability, and uniqueness. Depending on the use of the data, some aspects may be more important than others.
Measures for ensuring limited data retention
Personal data is stored only for as long as it is necessary and usable. The Company does not store data unless the Company needs to. Data use and storage lifecycle depends on the data classification.
Measures for ensuring accountability
The Company has implemented a privacy program that is appropriate to the scope and nature of personal data processed that includes at least a personal data breach policy and appointment of a data protection officer (DPO). The foregoing measures are regularly reviewed (at least once a year) and updated to ensure alignment with applicable law and industry standards.
Measures for allowing data portability and ensuring erasure
The Company has implemented and maintains procedures to ensure data portability and erasure that comply with data protection laws.
Where possible and where it is required to do so, the Company will provide the data subject with the right to receive personal data concerning him or her that he or she has provided to the controller in a structured, commonly used and machine-readable format. By exercising the right to data portability, the Company grants the data subject the right to have his or her personal data transmitted directly from one controller to another, where technically feasible.
Annex 3 - Sub-Processors
Last Modified: December 23, 2024
This Sub-Processors Annex is incorporated into the DPA and Agreement. This Annex explains how TeqBlaze engages with Sub-Processors.
Third Party Sub-Processor
Purpose
Applicable Service
Data Center Sub-Processor Location:
OpenAI, L.L.C.
AI Products
Used for
HubSpot AI
Products
United States
Google LLC
Cloud Provider / Infrastructure / Google Workspace, Analytics, Marketing, Advertising
Email, Users and Productivity Tools, Search Console, Ad Words
United States/EU
HubSpot, Inc.
CRM system
HubSpot Products
United States
Atlassian
Task tracker & knowledge base
Jira, Confluence
United States/EU
Slack
Corporate messenger
Corporate chats/calls for internal team
United States
Test Rail
Test suite management
Used to manage test suites that are used for the testing of the platforms
United States/EU
HQ Host
Data center
Infrastructure
United States
Termius
SSH platform
Secured access to the infrastructure by Devops team
United States
Keeper
Password manager
Сorporate password manager for internal team
United States/EU
PW push
Secured credentials transfer service
Used to receive sensitive credentials (passwords, files, certificates) by TeqBlaze to avoid exposing.
United States
Sybill
Analytics platform
Customer behavior tracking
United States/EU
Calendly
Scheduling and calendar management
Scheduling meetings
United States/EU
Zoom
Video conferencing and communication
Internal and external video meetings
United States/EU
Dripify
LinkedIn automation platform
Lead generation and LinkedIn outreach
United States/EU
Linkedin Sales Nav
Sales prospecting and lead management
Sales and networking
United States/EU
Sendpuls
Marketing email automation platform
Email campaign management
United States/EU
Clickease
Click tracking and campaign analytics
Tracking campaign performance
United States/EU
Zappier
Workflow automation tool
Integration and automation of apps and services
United States/EU
LinkedIn Campaign Manager
Online campaign management for LinkedIn ads
Advertising and targeting
United States/EU
Cookiebot
Cookie consent management platform
GDPR and privacy compliance
United States/EU
Microsoft Clarity
Analytical marketing tool
User behavior analytics tool
United States/EU
Due to the nature of TeqBlaze global business and ongoing efforts to delight the clients, the TeqBlaze’s business needs and services providers may change from time to time. For example, TeqBlaze may deprecate a service provider to consolidate and minimize use of service providers. Similarly, TeqBlaze may add a service provider if TeqBlaze believes that doing so will enhance TeqBlaze’s ability to deliver the Services.