Snapshot 34052
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Amplemarket Data Processing Addendum
This Data Processing Addendum (the “DPA”), is entered into by and between Tagis, Inc. dba
Amplemarket, a Delaware company with its principal place of business at 2443 Fillmore St
#380-3880 San Francisco, CA 94115 (“Amplemarket”) and you, the user of the Service
(“Customer”), dated as of the Effective Date of the execution of a written agreement between
the Parties, including acceptance of the online Terms of Service located at
https://www.amplemarket.com/legal/terms (each individually a Party and collectively the
“Parties”). This DPA governs all agreements including any ordering document (“Order Form”)
between the Parties (collectively, the “Agreement”).
In consideration of the mutual promises and obligations set out herein, the Parties hereby agree
to the following terms:
1. Definitions. All terms not defined herein shall have the definitions set forth in the
Agreement.
1.1. “Adequacy decision,” “consumer,” “contractor,” “process,” “processing”,
“personal data,” “personal information”, “Sub-Processor,” and “third party”
shall have the meanings given in Data Protection Law.
1.2. “Affiliate” means any entity that directly or indirectly controls, is controlled by, or
is under common control with the subject entity.
1.3. “Business” and "Controller" shall have the meanings given in Data Protection
Law and shall be used interchangeably herein.
1.4. “Consumer” and “Data Subject” shall have the meanings ascribed to it in Data
Protection Law and shall be used interchangeably herein.
1.5. “Covered Data” means the data provided by Data Provider to Data Receiver as
detailed in the Agreement and for the purposes described in the Agreement.
1.6. “Customer Personal Data” means the personal data provided by Customer to
Amplemarket and processed by Amplemarket under the Agreement.
1.7. “Data Privacy Framework” means the EU-U.S. Data Privacy Framework, the
Swiss-U.S. Data Privacy Framework, and the UK Extension to the EU-U.S. Data
Privacy Framework self-certification programs (as applicable) operated by the
U.S. Department of Commerce; as may be amended, superseded or replaced.
1.8. "Data Protection Law" means all applicable laws and regulations, including laws
and regulations of the European Economic Area (“EEA”) and their member
states, Switzerland and the United Kingdom (“UK”), including without limitation,
the European and United Kingdom General Data Protection Regulation (“GDPR”)
and EU Directive 2002/58/EC on Privacy and Electronic Communications
(“e-Privacy Directive”) or, the superseding e-Privacy Regulation once effective,
and the United Kingdom’s General Data Protection Regulation (“UK GDPR”), and
as applicable, the laws and regulations of the United States, including without
limitation, the California Consumer Privacy Act of 2018 and its amendments
including the California Privacy Rights Act (collectively, the “CCPA”), the
Virginia’s Consumer Data Protection Act (“VCDPA”), the Colorado Privacy Act
(“CPA”), the Connecticut Data Privacy Act (“CTDPA”), the Utah Consumer
Privacy Act (“UCPA”), the Oregon Consumer Privacy Act (“OCPA”), the Texas
Data Privacy and Security Act (“TXDPSA”), the Florida Digital Bill of Rights
(“FDBR”), the Montana Consumer Data Privacy Act (“MTCDPA”), the Iowa
Consumer Data Protection Act (“IADPA”), the Delaware Personal Data Privacy
Act (“DEPDPA”), the Nebraska Data Privacy Act (“NEDPA”), the New Hampshire
Privacy Act (“NHPA”), the New Jersey Data Privacy Act (“NJDPA”), the
Tennessee Information Privacy Act (“TIPA”), the Minnesota Consumer Data
Privacy Act (“MNCDPA”), and the Maryland Online Data Privacy Act
(“MDODPA”), and the Indiana Consumer Data Protection Act (“INCDPA”), the
Kentucky Consumer Data Protection Act (“KYCDPA”), and the Rhode Island
Data Transparency and Privacy Protection Act (“RIDTPPA”).
1.9. “Data Provider” means the Party providing Covered Data to the other Party as
part of the Services.
1.10. “Data Receiver” means the Party receiving Covered Data as part of the
Services from the Data Provider.
1.11. “Data Subject Requests” means the exercising of any privacy rights granted to
Data Subjects under applicable Data Protection Law directed to a Party as
related to the Services.
1.12. “Member States” means a member of the EU.
1.13. “Personal Data” and “Personal Information” shall have the meanings ascribed
in Data Protection Laws and shall be used interchangeably herein.
1.14. “Processor” and “Service Provider” shall have the meanings given in Data
Protection Law and shall be used interchangeably herein.
1.15. “Services” means the services provided by the Parties as detailed in the
Agreement.
2. Relationship of the Parties. The Parties acknowledge and agree that with regard to the
Covered Data, each Party is an independent Controller (and independent Business
under the CCPA). Unless specified in a written agreement, each Party shall individually
determine the purposes and means of its processing of Covered Data.
3. Obligations.
3.1. Compliance.
3.1.1. Each Party shall comply with the obligations that apply to it under Data
Protection Law. If either Party becomes aware that processing for the
permitted purpose infringes Data Protection Law, such Party shall
promptly inform the other. Notwithstanding the foregoing, neither Party
shall be under any obligation to actively monitor the other Party's
compliance with Data Protection Law.
3.1.2. Each Party shall promptly inform the other if it is unable to comply with
this DPA or Data Protection Law. If the non-complying Party cannot
comply within a reasonable period of time, or is in substantial or persistent
breach of this DPA, the complying Party shall be entitled to remediate the
non-compliant action and/or terminate the DPA and the Agreement
insofar as it concerns processing of Covered Data.
3.2. Processing Instructions. In connection with the performance of the Services,
the Parties shall process the Covered Data for any purposes specified in the
Agreement, applicable Order Form or this DPA, or as otherwise agreed on in
writing by the Parties. Each Party grants to the other Party all rights and licenses
associated with the Covered Data under the Agreement for use with the
applicable Services.
3.3. Cooperation and Consumer Rights. Each Party shall cooperate with the other
in complying with Data Protection Law. As it pertains to Covered Data, each
Party shall be responsible for responding to enquiries from regulators and for
responding to Data Subject Requests and shall implement mechanisms to
facilitate such enquiries and requests. With respect to objection or opt-out
requests related to the onward transfer or ‘sale’ of Covered Data, each Party
shall forward, or make available, to the other Party any applicable Data Subject
Requests within fifteen (15) days of receipt by that Party, and comply with any
such Data Subject Requests within fifteen (15) days of receipt from the other
Party. In the event any request, correspondence, enquiry or complaint is made
directly to a Party by a regulator under Data Protection Law related to the
Services or Agreement between the Parties, then that Party shall promptly inform
the other Party of such regulator request, correspondence, enquiry or complaint.
4. Security.
4.1. The Parties shall implement and maintain appropriate technical and
organizational measures in order to protect the Covered Data from: (i) accidental
or unlawful destruction; (ii) loss, alteration, unauthorized disclosure of, or access
to the Covered Data or Customer Personal Data (a “Security Incident”); (iii)
confidentiality of Covered Data; and (iv) integrity of Covered Data. Each Party
shall ensure that any person it authorizes to process the Covered Data (an
“Authorized Person”) is bound by an appropriate obligation of confidentiality
(whether statutory or contractual).
4.2. Security Incidents. If either Party becomes aware of a confirmed Security
Incident related to Covered Data, that Party shall inform the other Party without
undue delay (and, in any event, within seventy two (72) hours) and shall provide
reasonable information and cooperation to fulfill any data breach reporting
obligations it may have under (and in accordance with the timescales required
by) Data Protection Law. Further, the Party reporting the Security Incident shall,
at its own cost and expense, take such reasonably necessary measures and
actions to remedy or mitigate the effects of the Security Incident and shall keep
the other Party informed of all material developments in connection with the
Security Incident.
5. Subcontracting. Either Party permits the use of any processors or subcontractors to
process Covered Data, subject to a written agreement between the Parties that imposes
obligations on the processor or subcontractor that are no less restrictive and at least
equally protective of Covered Data than those referenced under this DPA and the
Agreement. The subcontracting Party is responsible for ensuring the compliance of the
processors or subcontractors with Data Protection Law in connection with the processing
of Covered Data.
6. Audit. With a minimum of thirty (30) days written request, the Parties shall provide, if
available, any compliance reports or audit reports that assess the effectiveness of the
Party’s compliance with Data Protection Law and this DPA. Should these reports be
deemed materially insufficient, and upon reasonable advance written notice, the auditing
Party may, during normal business hours, not more than once per year, at its own
expense, audit the other Party’s systems, procedures, and processing of Covered Data,
and compliance with this DPA, the Agreement, and applicable Order Form. Additionally,
the auditing Party has the right to take reasonable and appropriate steps to stop and
remediate unauthorized use of Covered Data.
7. Cross-Border Transfers. If the Services involves the transfer of Personal Data of Data
Subjects in the EEA or the UK, to a country or territory outside of those regions which
has not received an applicable adequacy decision, the Parties will comply with any
requirements under Data Protection Law regarding the transfers.
7.1. Data Privacy Framework. At the time of the execution of the Agreement,
Amplemarket participates in and certifies compliance with the Data Privacy
Framework. As required by the Data Privacy Framework, Amplemarket will: (i)
provide at least the same level of privacy protection as is required by the Data
Privacy Framework principles; (ii) notify Controller if Amplemarket makes a
determination it can no longer meet its obligation to provide the same level of
protection as is required by the Data Privacy Framework principles (in which
event Amplemarket will cease such processing or take other reasonable and
appropriate steps to remediate). Where and to the extent that the Data Privacy
Framework applies, Amplemarket will use the Data Privacy Framework to lawfully
receive Customer Personal Data and/or Personal Data in the United States.
8. Miscellaneous.
8.1. Termination and Survival. This DPA and all provisions herein shall survive so
long as, and to the extent that, Data Receiver processes or retains Covered
Data. Upon termination, you will no longer be authorized to access the Service or
use any associated data and must promptly delete any Covered Data without
undue delay.
8.2. Conflicts. In case of contradictions between this DPA and the provisions of the
Agreement, the provisions of this DPA shall prevail.
8.3. Governing Law and Jurisdiction. The applicable law and jurisdiction as set
forth in the Agreement apply to this DPA.