Third Party Index

Snapshot 34052

Document
Data processing addendum
URL
https://drive.google.com/uc?export=download&id=1ydExei9fzllAHJ6BZDRE7MqnwbOMfH0T
Fetched
HTTP status
200
Content type
application/octet-stream
Fetch mode
pdf
Size
122633 bytes
SHA-256 (raw)
2bfef2e002bdafc9f6c6ded762e1ccb51778d37746a1e277d498dce9605904d3
SHA-256 (normalized text)
04e711873b1c3025d6862398eca57ea376a6fe026c17699cfd0a23119f6d2f62

Normalized text

Scripts and page chrome removed; this is what change detection compares.

                          Amplemarket Data Processing Addendum

This Data Processing Addendum (the “DPA”), is entered into by and between Tagis, Inc. dba
Amplemarket, a Delaware company with its principal place of business at 2443 Fillmore St
#380-3880 San Francisco, CA 94115 (“Amplemarket”) and you, the user of the Service
(“Customer”), dated as of the Effective Date of the execution of a written agreement between
the Parties, including acceptance of the online Terms of Service located at
https://www.amplemarket.com/legal/terms (each individually a Party and collectively the
“Parties”). This DPA governs all agreements including any ordering document (“Order Form”)
between the Parties (collectively, the “Agreement”).

In consideration of the mutual promises and obligations set out herein, the Parties hereby agree
to the following terms:

 1.​   Definitions. All terms not defined herein shall have the definitions set forth in the
       Agreement.

       1.1.​   “Adequacy decision,” “consumer,” “contractor,” “process,” “processing”,
               “personal data,” “personal information”, “Sub-Processor,” and “third party”
               shall have the meanings given in Data Protection Law.

       1.2.​   “Affiliate” means any entity that directly or indirectly controls, is controlled by, or
               is under common control with the subject entity.

       1.3.​   “Business” and "Controller" shall have the meanings given in Data Protection
               Law and shall be used interchangeably herein.

       1.4.​   “Consumer” and “Data Subject” shall have the meanings ascribed to it in Data
               Protection Law and shall be used interchangeably herein.

       1.5.​   “Covered Data” means the data provided by Data Provider to Data Receiver as
               detailed in the Agreement and for the purposes described in the Agreement.

       1.6.​   “Customer Personal Data” means the personal data provided by Customer to
               Amplemarket and processed by Amplemarket under the Agreement.

       1.7.​   “Data Privacy Framework” means the EU-U.S. Data Privacy Framework, the
               Swiss-U.S. Data Privacy Framework, and the UK Extension to the EU-U.S. Data
               Privacy Framework self-certification programs (as applicable) operated by the
               U.S. Department of Commerce; as may be amended, superseded or replaced.

       1.8.​   "Data Protection Law" means all applicable laws and regulations, including laws
               and regulations of the European Economic Area (“EEA”) and their member
               states, Switzerland and the United Kingdom (“UK”), including without limitation,
               the European and United Kingdom General Data Protection Regulation (“GDPR”)
               and EU Directive 2002/58/EC on Privacy and Electronic Communications
               (“e-Privacy Directive”) or, the superseding e-Privacy Regulation once effective,
               and the United Kingdom’s General Data Protection Regulation (“UK GDPR”), and
                 as applicable, the laws and regulations of the United States, including without
                 limitation, the California Consumer Privacy Act of 2018 and its amendments
                 including the California Privacy Rights Act (collectively, the “CCPA”), the
                 Virginia’s Consumer Data Protection Act (“VCDPA”), the Colorado Privacy Act
                 (“CPA”), the Connecticut Data Privacy Act (“CTDPA”), the Utah Consumer
                 Privacy Act (“UCPA”), the Oregon Consumer Privacy Act (“OCPA”), the Texas
                 Data Privacy and Security Act (“TXDPSA”), the Florida Digital Bill of Rights
                 (“FDBR”), the Montana Consumer Data Privacy Act (“MTCDPA”), the Iowa
                 Consumer Data Protection Act (“IADPA”), the Delaware Personal Data Privacy
                 Act (“DEPDPA”), the Nebraska Data Privacy Act (“NEDPA”), the New Hampshire
                 Privacy Act (“NHPA”), the New Jersey Data Privacy Act (“NJDPA”), the
                 Tennessee Information Privacy Act (“TIPA”), the Minnesota Consumer Data
                 Privacy Act (“MNCDPA”), and the Maryland Online Data Privacy Act
                 (“MDODPA”), and the Indiana Consumer Data Protection Act (“INCDPA”), the
                 Kentucky Consumer Data Protection Act (“KYCDPA”), and the Rhode Island
                 Data Transparency and Privacy Protection Act (“RIDTPPA”).

       1.9.​     “Data Provider” means the Party providing Covered Data to the other Party as
                 part of the Services.

      1.10.​     “Data Receiver” means the Party receiving Covered Data as part of the
                 Services from the Data Provider.

      1.11.​     “Data Subject Requests” means the exercising of any privacy rights granted to
                 Data Subjects under applicable Data Protection Law directed to a Party as
                 related to the Services.

      1.12.​     “Member States” means a member of the EU.

      1.13.​     “Personal Data” and “Personal Information” shall have the meanings ascribed
                 in Data Protection Laws and shall be used interchangeably herein.​

      1.14.​     “Processor” and “Service Provider” shall have the meanings given in Data
                 Protection Law and shall be used interchangeably herein.

      1.15.​     “Services” means the services provided by the Parties as detailed in the
                 Agreement.

2.​    Relationship of the Parties. The Parties acknowledge and agree that with regard to the
       Covered Data, each Party is an independent Controller (and independent Business
       under the CCPA). Unless specified in a written agreement, each Party shall individually
       determine the purposes and means of its processing of Covered Data.

3.​    Obligations.

       3.1.​     Compliance.

               3.1.1.​   Each Party shall comply with the obligations that apply to it under Data
                        Protection Law. If either Party becomes aware that processing for the
                        permitted purpose infringes Data Protection Law, such Party shall
                        promptly inform the other. Notwithstanding the foregoing, neither Party
                        shall be under any obligation to actively monitor the other Party's
                        compliance with Data Protection Law.

              3.1.2.​   Each Party shall promptly inform the other if it is unable to comply with
                        this DPA or Data Protection Law. If the non-complying Party cannot
                        comply within a reasonable period of time, or is in substantial or persistent
                        breach of this DPA, the complying Party shall be entitled to remediate the
                        non-compliant action and/or terminate the DPA and the Agreement
                        insofar as it concerns processing of Covered Data.

      3.2.​     Processing Instructions. In connection with the performance of the Services,
                the Parties shall process the Covered Data for any purposes specified in the
                Agreement, applicable Order Form or this DPA, or as otherwise agreed on in
                writing by the Parties. Each Party grants to the other Party all rights and licenses
                associated with the Covered Data under the Agreement for use with the
                applicable Services.

      3.3.​     Cooperation and Consumer Rights. Each Party shall cooperate with the other
                in complying with Data Protection Law. As it pertains to Covered Data, each
                Party shall be responsible for responding to enquiries from regulators and for
                responding to Data Subject Requests and shall implement mechanisms to
                facilitate such enquiries and requests. With respect to objection or opt-out
                requests related to the onward transfer or ‘sale’ of Covered Data, each Party
                shall forward, or make available, to the other Party any applicable Data Subject
                Requests within fifteen (15) days of receipt by that Party, and comply with any
                such Data Subject Requests within fifteen (15) days of receipt from the other
                Party. In the event any request, correspondence, enquiry or complaint is made
                directly to a Party by a regulator under Data Protection Law related to the
                Services or Agreement between the Parties, then that Party shall promptly inform
                the other Party of such regulator request, correspondence, enquiry or complaint.

4.​   Security.

      4.1.​     The Parties shall implement and maintain appropriate technical and
                organizational measures in order to protect the Covered Data from: (i) accidental
                or unlawful destruction; (ii) loss, alteration, unauthorized disclosure of, or access
                to the Covered Data or Customer Personal Data (a “Security Incident”); (iii)
                confidentiality of Covered Data; and (iv) integrity of Covered Data. Each Party
                shall ensure that any person it authorizes to process the Covered Data (an
                “Authorized Person”) is bound by an appropriate obligation of confidentiality
                (whether statutory or contractual).

      4.2.​     Security Incidents. If either Party becomes aware of a confirmed Security
              Incident related to Covered Data, that Party shall inform the other Party without
              undue delay (and, in any event, within seventy two (72) hours) and shall provide
              reasonable information and cooperation to fulfill any data breach reporting
              obligations it may have under (and in accordance with the timescales required
              by) Data Protection Law. Further, the Party reporting the Security Incident shall,
              at its own cost and expense, take such reasonably necessary measures and
              actions to remedy or mitigate the effects of the Security Incident and shall keep
              the other Party informed of all material developments in connection with the
              Security Incident.

5.​   Subcontracting. Either Party permits the use of any processors or subcontractors to
      process Covered Data, subject to a written agreement between the Parties that imposes
      obligations on the processor or subcontractor that are no less restrictive and at least
      equally protective of Covered Data than those referenced under this DPA and the
      Agreement. The subcontracting Party is responsible for ensuring the compliance of the
      processors or subcontractors with Data Protection Law in connection with the processing
      of Covered Data.

6.​   Audit. With a minimum of thirty (30) days written request, the Parties shall provide, if
      available, any compliance reports or audit reports that assess the effectiveness of the
      Party’s compliance with Data Protection Law and this DPA. Should these reports be
      deemed materially insufficient, and upon reasonable advance written notice, the auditing
      Party may, during normal business hours, not more than once per year, at its own
      expense, audit the other Party’s systems, procedures, and processing of Covered Data,
      and compliance with this DPA, the Agreement, and applicable Order Form. Additionally,
      the auditing Party has the right to take reasonable and appropriate steps to stop and
      remediate unauthorized use of Covered Data.

7.​   Cross-Border Transfers. If the Services involves the transfer of Personal Data of Data
      Subjects in the EEA or the UK, to a country or territory outside of those regions which
      has not received an applicable adequacy decision, the Parties will comply with any
      requirements under Data Protection Law regarding the transfers.

      7.1.​   Data Privacy Framework. At the time of the execution of the Agreement,
              Amplemarket participates in and certifies compliance with the Data Privacy
              Framework. As required by the Data Privacy Framework, Amplemarket will: (i)
              provide at least the same level of privacy protection as is required by the Data
              Privacy Framework principles; (ii) notify Controller if Amplemarket makes a
              determination it can no longer meet its obligation to provide the same level of
              protection as is required by the Data Privacy Framework principles (in which
              event Amplemarket will cease such processing or take other reasonable and
              appropriate steps to remediate). Where and to the extent that the Data Privacy
              Framework applies, Amplemarket will use the Data Privacy Framework to lawfully
              receive Customer Personal Data and/or Personal Data in the United States.

8.​   Miscellaneous.
8.1.​   Termination and Survival. This DPA and all provisions herein shall survive so
        long as, and to the extent that, Data Receiver processes or retains Covered
        Data. Upon termination, you will no longer be authorized to access the Service or
        use any associated data and must promptly delete any Covered Data without
        undue delay.

8.2.​   Conflicts. In case of contradictions between this DPA and the provisions of the
        Agreement, the provisions of this DPA shall prevail.

8.3.​   Governing Law and Jurisdiction. The applicable law and jurisdiction as set
        forth in the Agreement apply to this DPA.