Snapshot 50771
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Digital Samba
Data Processing Agreement
For the purposes of Article 28(3) of Regulation 2016/679 (the GDPR)
Last modified: 30 April, 2026
Changes: Incorporated clause 4.3 to address professional secrecy obligation.
his Data Processing Agreement (“DPA”) supplementstheDigital Samba Customer Agreement
T
(the “Agreement”). Capitalised terms not defined inthis DPA have the meanings given in the
Agreement. Terms such as Data Controller, Data Processor, personal data, and processing have
the meanings given in the GDPR.
his DPA only applies to the extent that the Customer instructs Digital Samba to process personal
T
data on Customer’s behalf in relation to the Services.
This Data Processing Agreement is between:
COMPANY NAME
REGISTRATION NUMBER
ADDRESS
POSTCODE, CITY
COUNTRY
(the “Customer”)
and
COMPANY NAME DIGITAL SAMBA, S.L.
REGISTRATION NUMBER B63229629
ADDRESS TRAVESSERA DE GRÀCIA, 98 BIS, 6/2
POSTCODE, CITY 08012 BARCELONA
COUNTRY SPAIN
(“Digital Samba”)
(each a “Party”; together the“Parties”)
1. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
1. Preamble
1 .1.These contractual clauses (the “Clauses”) setout the rights and obligations of the Customer
and Digital Samba, when processing personal data of persons who use the Services (“User” or
“Users”) on behalf of the Customer.
1 .2.The Clauses have been designed to ensure theParties’ compliance with Article 28(3) of
Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the
protection of natural persons with regard to the processing of personal data and on the free
movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation).
1 .3.In the context of the provision of the Services,Digital Samba will process Users’ personal data
on behalf of the Customer in accordance with the Clauses.
1 .4.In the event of any conflict relating to theprocessing of personal data, the following order of
precedence applies (highest first):
( a) any Standard Contractual Clauses that the Parties have expressly executed or expressly
incorporated by reference (including in electronic form);
(b) these Clauses (including their appendices);
(c) the Agreement (including any Orders and referenced policies).
or all other matters, the Agreement governs. Documented instructions may not reduce the
F
protections in these Clauses or any executed Standard Contractual Clauses.
1 .5.From their Effective Date, these Clauses replaceany prior data processing terms between the
Parties, and any later data-processing addendum referencing the Agreement supersedes these
Clauses from its Effective Date to the extent of conflict.
1.6.Four appendices are attached to the Clauses andform an integral part of the Clauses.
1 .7.Appendix A contains details about the processingof personal data, including the purpose and
nature of the processing, type of personal data, categories of data subject and duration of the
processing.
1 .8.Appendix B includes the current list of subprocessorsauthorised by the Customer. Appendix B
may be updated by Digital Samba in accordance with clause 6.
1 .9.Appendix C contains the Customer’s instructionswith regards to the processing of personal
data.
1.10.Appendix D contains provisions for other activitieswhich are not covered by the Clauses.
1 .11.The Clauses along with appendices shall be retainedin writing, including electronically, by
both Parties.
1 .12.The Clauses shall not exempt Digital Samba fromobligations to which Digital Samba is subject
pursuant to the General Data Protection Regulation (the GDPR) or other legislation.
2. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
1 .13.The Customer may use the Services either (a) as a controller, or (b) as a processor acting on
behalf of its own customers or end clients. Where the Customer acts as a processor, Digital Samba
acts as a sub-processor within the meaning of Article 28(4) GDPR. The Customer warrants that it
has all necessary authority to enter into this DPA, issue processing instructions to Digital Samba,
and authorise sub-processors, whether in its own capacity as controller or on behalf of the
relevant controller.
2. The rights and obligations of the Data Controller
.1.The Data Controller is responsible for ensuringthat the processing of personal data takes
2
place in compliance with the GDPR (see Article 24 GDPR), the applicable EU or Member State1 data
protection provisions and the Clauses.
.2.The Data Controller has the right and obligationto make decisions about the purposes and
2
means of the processing of personal data.
.3.The Data Controller shall be responsible, amongothers, for ensuring that the processing of
2
personal data, which Digital Samba is instructed to perform, has a legal basis.
.4.Where the Customer is not the Data Controller,the Customer warrants that (a) it acts with the
2
authority of, and on behalf of, the relevant Data Controller; (b) it has communicated the Data
Controller's instructions to Digital Samba; and (c) it will ensure that all instructions given to Digital
Samba are consistent with the Customer's own obligations to the Data Controller.
3. Digital Samba acts according to instructions
.1.Digital Samba shall process personal data onlyon documented instructions from the Customer,
3
unless required to do so by Union or Member State law to which Digital Samba is subject. Such
instructions shall be specified in appendices A and C. Subsequent instructions can also be given
by the Customer throughout the duration of the processing of personal data, but such instructions
shall always be documented and kept in writing, including electronically, in connection with the
Clauses.
.2.Digital Samba shall immediately inform the Customerif instructions given by the Customer, in
3
the opinion of Digital Samba, contravene the GDPR or the applicable EU or Member State data
protection provisions.
4. Confidentiality
.1.Digital Samba shall only grant access to thepersonal data being processed on behalf of the
4
Customer to persons under Digital Samba’s authority who have committed themselves to
confidentiality or are under an appropriate statutory obligation of confidentiality and only on a
need to know basis. The list of persons to whom access has been granted shall be kept under
periodic review. On the basis of this review, such access to personal data can be withdrawn, if
1
References to ”Member States” made throughout the Clauses shall be understood as references to “EEA Member States”.
3. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
ccess is no longer necessary, and personal data shall consequently not be accessible anymore to
a
those persons.
.2.Digital Samba shall at the request of the Customerdemonstrate that the concerned persons
4
under Digital Samba’s authority are subject to the abovementioned confidentiality.
.3.Digital Samba shall act as a subprocessor insupport of activities carried out by professionals
4
who are subject to statutory obligations of professional secrecy. Digital Samba, and in particular its
employees, shall, being aware of the criminal consequences of any breach, preserve the
confidentiality of all third-party secrets and confidential information to which they are granted
access in the course of the performance of the Clauses.
here Digital Samba engages subprocessors in accordance with clause 6, Digital Samba shall
W
ensure that such subprocessors are bound in text form to confidentiality obligations. Digital Samba
shall further ensure, by appropriate contractual or organisational measures, that any persons
acting for such subprocessors who may gain access to confidential information or third-party
secrets are informed of the confidential nature of such information and of the legal consequences
of any breach, including, where applicable, criminal consequences under Sections 203 and 204 of
the German Criminal Code.
he obligation of confidentiality under this clause 4.3 shall survive termination of the Clauses and
T
shall continue for an unlimited period.
he foregoing confidentiality obligations shall not apply to the extent that Digital Samba is required
T
to disclose confidential information of the Customer pursuant to a binding order or decision of a
competent authority or court. To the extent legally permissible and practicable in the individual
case, Digital Samba shall inform the Customer in advance of any such obligation to disclose.
igital Samba shall ensure that all processing activities are carried out exclusively by personnel
D
who are duly bound by confidentiality obligations.
5. Security of processing
.1.Article 32 GDPR stipulates that - taking intoaccount the state of the art - the costs of
5
implementation and the nature, scope, context and purposes of processing as well as the risk of
varying likelihood and severity for the rights and freedoms of natural persons, the Customer and
Digital Samba shall implement appropriate technical and organisational measures to ensure a level
of security appropriate to the risk.
he Customer shall evaluate the risks to the rights and freedoms of natural persons inherent in the
T
processing and implement measures to mitigate those risks. Depending on their relevance, the
measures may include the following:
5.1.1.Pseudonymisation and encryption of personaldata;
.1.2.The ability to ensure ongoing confidentiality,integrity, availability and resilience of
5
processing systems and services;
.1.3.Ability to restore the availability and accessto personal data in a timely manner in the
5
event of a physical or technical incident;
4. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
.1.4.A process for regularly testing, assessing and evaluating the effectiveness of
5
technical and organisational measures for ensuring the security of the processing.
.2.According to Article 32 GDPR, Digital Samba shallalso – independently from the Customer –
5
evaluate the risks to the rights and freedoms of natural persons inherent in the processing and
implement measures to mitigate those risks. To this effect, the Customer shall provide Digital
Samba with all information necessary to identify and evaluate such risks.
.3.Furthermore, Digital Samba shall assist the Customerin ensuring compliance with the
5
Customer’s obligations pursuant to Articles 32 GDPR, by inter alia providing the Customer with
information concerning the technical and organisational measures already implemented by Digital
Samba pursuant to Article 32 GDPR along with all other information necessary for the Customer to
comply with the Customer’s obligations under Article 32 GDPR.
If subsequently- in the assessment of the Customer- mitigation of the identified risks requires
further measures to be implemented by Digital Samba, than those already implemented by Digital
Samba pursuant to Article 32 GDPR, the Customer shall specify these additional measures to be
implemented in Appendix C.
6. Use of subprocessors
.1. General authorisation.The Customer grants ageneral written authorisation for Digital Samba
6
to engage subprocessors. Digital Samba shall maintain a current list of authorised subprocessors
in Appendix B.
.2. Engagement & change management.Digital Sambashall meet the requirements specified in
6
Article 28(2) and (4) GDPR in order to engage another processor (a subprocessor).
.2.1. Notice of change.Digital Samba shall notifythe Customer in writing at least thirty (30) days
6
before any intended addition or replacement of a subprocessor becomes effective. This
notification of a change in the subprocessor list (“Change Notice”) shall be sent to the Customer
and shall identify, at a minimum, the subprocessor’s name, role/services, country(ies) of
processing, the effective date of the change, and (if applicable) the transfer mechanism for
restricted transfers.
.2.2. Right to object.Upon receiving a Change Notice,if the Customer has specific, reasonable
6
grounds that engagement of the proposed subprocessor would: (i) cause the Customer to breach
applicable data-protection law; (ii) result in a material reduction in the level of security or
compliance applicable to the processing of personal data under these Clauses; (iii) involve a
Restricted Transfer without a valid transfer mechanism and appropriate supplementary measures;
or (iv) conflict with a binding order or instruction of a competent supervisory authority applicable
to the Customer, then the Customer may submit a written objection (“Objection”) to Digital Samba
within fifteen (15) days of receipt of the Change Notice (“Objection Period”). The Objection must
set out the legal basis relied upon, the facts giving rise to the concern, and the processing at issue.
Objections based solely on commercial considerations, vendor preference, or speculative harms
do not constitute reasonable grounds. If Digital Samba does not receive an Objection within the
Objection Period, the proposed addition or replacement of the subprocessor described in the
Change Notice shall be deemed accepted by the Customer and may take effect on the effective
date specified therein.
5. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
.2.3. Good-faith resolution.Upon receipt of an Objection within the Objection Period, the Parties
6
shall discuss in good faith to address the Customer’s concerns. Without limitation, Digital Samba
may (a) provide additional information or independent attestations, (b) implement additional
appropriate technical and organisational measures, or (c) isolate, re-route or otherwise
re-configure the processing for the Customer to avoid use of the disputed subprocessor where
reasonably feasible.
.2.4. No unreasonable withholding.The Customer shallnot submit an Objection unreasonably,
6
or unreasonably withhold, condition, or delay acceptance of the Change Notice, where the
proposed subprocessor affords at least a materially equivalent level of protection as required
under these Clauses and applicable Data Protection Laws (including, if applicable, a valid transfer
mechanism and any necessary supplementary measures for any Restricted Transfer). The
Customer must specify in writing any residual, concrete non-compliance or material risk, with
reference to specific facts and applicable law.
.2.5. No resolution.If, after the Parties’ good-faithdiscussions under Clause 6.2.3, an Objection
6
is not resolved within fifteen (15) days of Digital Samba’s receipt (the “Resolution Period”), either
Party may, by written notice, terminate the Agreement in accordance with Clause 13.5.
.2.6. Emergency replacement.Where Digital Sambareasonably determines that an immediate
6
subprocessor change is necessary to maintain confidentiality, integrity or availability of the
services (including to address a security incident, service disruption or legal requirement), it may
replace or add a subprocessor without prior notice, provided it issues a Change Notice without
undue delay (and where legally restricted, as soon as permitted). The Customer may object under
clause 6.2.2, and clauses 6.2.3–6.2.5 shall apply.
.2.7. Clarification.For clarity, a change of subprocessorin accordance with this Section 6 does
6
not, by itself, constitute a breach of the Agreement or these Clauses.
.3. Imposed obligations.Where Digital Samba engagesa subprocessor for carrying out specific
6
processing activities on behalf of the Customer, the same data protection obligations as set out in
the Clauses shall be imposed on that subprocessor by way of a contract or other legal act under
EU or Member State law, in particular providing sufficient guarantees to implement appropriate
technical and organisational measures in such a manner that the processing will meet the
requirements of the Clauses and the GDPR. Digital Samba shall therefore be responsible for
requiring that the subprocessor at least complies with the obligations to which Digital Samba is
subject pursuant to the Clauses and the GDPR.
.4. Liability.If the subprocessor does not fulfilits data protection obligations, Digital Samba shall
6
remain fully liable to the Customer as regards the fulfilment of the obligations of the subprocessor.
This does not affect the rights of the data subjects under the GDPR – in particular, those foreseen
in Articles 79 and 82 GDPR – against the Data Controller and the Data Processor, including the
subprocessor.
.5. Third-country transfers.Where a subprocessoris located outside the EEA (or otherwise
6
engages in a restricted transfer), Digital Samba shall ensure a valid transfer mechanism and
implement supplementary measures as required by GDPR and applicable laws.
6. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
.6. Transparency.Upon reasonable request, Digital Samba shall provide information reasonably
6
necessary to demonstrate the subprocessor’s compliance with this Section 6, subject to
confidentiality.
. Transfer of data to third countries or international
7
organisations
.1.Any transfer of personal data to third countriesor international organisations by Digital Samba
7
shall only occur on the basis of documented instructions from the Customer and shall always take
place in compliance with Chapter V GDPR.
.2.In case transfers to third countries or internationalorganisations, which Digital Samba has not
7
been instructed to perform by the Customer, is required under EU or Member State law to which
Digital Samba is subject, Digital Samba shall inform the Customer of that legal requirement prior to
processing unless that law prohibits such information on important grounds of public interest.
.3.Without documented instructions from the Customer,Digital Samba therefore cannot within
7
the framework of the Clauses:
.3.1Transfer personal data to a Data Controlleror a Data Processor in a third country or in
7
an international organisation
7.3.2Transfer the processing of personal data toa subprocessor in a third country
7.3.3Have the personal data processed by DigitalSamba in a third country
.4.The Customer’s instructions regarding the transferof personal data to a third country
7
including, if applicable, the transfer tool under Chapter V GDPR on which they are based, shall be
set out in Appendix C.6.
.5.The Clauses shall not be confused with standarddata protection clauses within the meaning of
7
Article 46(2)(c) and (d) GDPR, and the Clauses cannot be relied upon by the Parties as a transfer
tool under Chapter V GDPR.
8. Assistance to the Customer
.1.Taking into account the nature of the processing,Digital Samba shall assist the Customer by
8
appropriate technical and organisational measures, insofar as this is possible, in the fulfilment of
the Customer’s obligations to respond to requests for exercising the data subject’s rights laid down
in Chapter III GDPR.
his entails that Digital Samba shall, insofar as this is possible, assist the Customer in compliance
T
with:
8.1.1.The right to be informed when collecting personaldata from the data subject
.1.2.The right to be informed when personal datahave not been obtained from the data
8
subject
7. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
8.1.3.The right of access by the data subject
8.1.4.The right to rectification
8.1.5The right to erasure ("the right to be forgotten”)
8.1.6.The right to restriction of processing
.1.7.Notification obligation regarding rectificationor erasure of personal data or restriction
8
of processing
8.1.8The right to data portability
8.1.9.The right to object
.1.10.The right not to be subject to a decisionbased solely on automated processing,
8
including profiling
.2.In addition to Digital Samba’s obligation toassist the Customer pursuant to Clause 5.3, Digital
8
Samba shall furthermore, taking into account the nature of the processing and the information
available to Digital Samba, assist the Customer in ensuring compliance with:
.2.1.The obligation to notify the personal databreach to the competent supervisory
8
authority without undue delay and, where feasible, not later than 48 hours after having
become aware of it, unless the personal data breach is unlikely to result in a risk to the
rights and freedoms of natural persons;
.2.2.The obligation to without undue delay communicatethe personal data breach to the
8
data subject, when the personal data breach is likely to result in a high risk to the rights and
freedoms of natural persons;
.2.3.The obligation to carry out an assessment ofthe impact of the envisaged processing
8
operations on the protection of personal data (a data protection impact assessment);
.2.4.The obligation to consult the competent supervisoryauthority prior to processing
8
where a data protection impact assessment indicates that the processing would result in a
high risk in the absence of measures taken by the Customer to mitigate the risk.
.3.The Parties shall define in Appendix C the appropriatetechnical and organisational measures
8
by which Digital Samba is required to assist the Customer as well as the scope and the extent of
the assistance required. This applies to the obligations foreseen in Clause 8.1. and 8.2.
9. Notification of personal data breach
.1.In case of any personal data breach, DigitalSamba shall, without undue delay after having
9
become aware of it, notify the Customer of the personal data breach.
.2.Digital Samba’s notification to the Customershall, if possible, take place within 24 hours after
9
Digital Samba has become aware of the personal data breach to enable the Customer to comply
with its notification obligations.
8. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
.3.In accordance with Clause 8(2)(a), Digital Samba shall assist the Customer in notifying the
9
personal data breach, meaning that Digital Samba is required to assist in obtaining the information
listed below which, pursuant to Article 33(3)GDPR, shall be stated in the notification to the
competent supervisory authority:
.3.1.The nature of the personal data including wherepossible, the categories and
9
approximate number of data subjects concerned and the categories and approximate
number of personal data records concerned;
9.3.2.The likely consequences of the personal databreach;
.3.3.The measures taken or proposed to be takenby the controller to address the
9
personal data breach, including, where appropriate, measures to mitigate its possible
adverse effects.
.4.The Parties shall define in Appendix C all theelements to be provided by Digital Samba when
9
assisting the Customer in the notification of a personal data breach to the competent supervisory
authority.
10. Erasure and return of data
1 0.1.On termination of the provision of personaldata processing services, Digital Samba shall be
under obligation to delete all personal data processed on behalf of the Customer and certify to the
Customer that it has done so unless Union or Member State law requires storage of the personal
data.
11. Audit and inspection
1 1.1.Digital Samba shall make available to the Customerall information necessary to demonstrate
compliance with the obligations laid down in Article 28 and the Clauses and allow for and
contribute to audits, including inspections, by the Customer or another auditor mandated by the
Customer.
1 1.2.Procedures applicable to the Customer’s audits,including inspections, are specified in
Appendix C.7.
1 1.3.Digital Samba shall be required to provide thesupervisory authorities, which pursuant to
applicable legislation have access to the Customer’s and Digital Samba’s facilities, or
representatives acting on behalf of such supervisory authorities, with access to Digital Samba’s
physical facilities on presentation of appropriate identification.
12. The Parties’ agreement on other terms
1 2.1.The Parties may agree to other clauses concerningthe provision of the personal data
processing services specifying e.g. liability, as long as they do not contradict directly or indirectly
the Clauses or prejudice the fundamental rights or freedoms of the data subject and the protection
afforded by the GDPR.
9. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
13. Commencement and termination
13.1.The Clauses shall become effective on the dateof both Parties’ signature.
1 3.2.Both Parties shall be entitled to require theClauses renegotiated if changes to the law or
inexpediency of the Clauses should give rise to such renegotiation.
1 3.3.The Clauses shall apply for the duration ofthe provision of personal data processing
services. For the duration of the provision of personal data processing services, the Clauses
cannot be terminated unless other Clauses governing the provision of personal data processing
services have been agreed between the Parties.
1 3.4.Upon expiry or termination of the Agreement,or earlier if the processing of Personal Data
under the Agreement ends, and once Digital Samba has returned or deleted Personal Data in
accordance with Clause 10.1 and Appendix C.4, these Clauses automatically terminate, without
further notice, to the extent they relate to such processing. Provisions that by their nature survive
(including confidentiality and return/deletion obligations) continue in force.
1 3.5.Notwithstanding clause 13.3, where the Customerhas submitted an Objection within the
Objection Period that meets the requirements of Clause 6.2.2 and the Parties have not resolved the
Objection within the Resolution Period, either Party may terminate the Agreement (and, as a
consequence, these Clauses) by written notice. This termination is no-fault and without penalty:
(a) no refunds or credits are due, (b) no early-termination fees or further charges accrue after the
termination effective date, and (c) except for fees accrued and payable up to the termination
effective date, neither Party shall have any further liability to the other arising out of or in
connection with the unresolved Objection, the subprocessor change, or the termination under this
clause; provided that nothing in this clause limits a Party’s liability for amounts due and owing,
fraud, wilful misconduct, or breaches occurring before the termination effective date. The Parties
shall promptly cease the affected processing, and Digital Samba shall return or delete Personal
Data in accordance with Clause 10.1 and Appendix C.4. Termination under this Clause is the
Parties’ sole and exclusive remedy for an unresolved Objection.
10. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
14. Contact points and notices
1 4.1. Designated contacts.The Parties designate thecontact points below for communications
under these Clauses. Notices under Clause 6 (including Change Notices and Objections) must be
sent to the “Notice Email” listed below. Email notice is sufficient.
1 4.2. Deemed receipt.An email notice is deemed receivedwhen sent, provided the sender does
not receive an automatic non-delivery message. If sent outside the recipient’s business hours at its
principal place of business, it is deemed received at the start of the next business day.
1 4.3. Updates.Each Party shall keep its contact detailsup to date and may update them by
emailing the other Party. Notices sent to the last notified contact details are valid until an update
takes effect.
Customer contact details
FULL NAME
POSITION
TELEPHONE
NOTICE EMAIL
Digital Samba contact details
FULL NAME ROBERT STROBL
POSITION CEO, DIGITAL SAMBA
TELEPHONE +34 937 370 415
NOTICE EMAIL [email protected]
11. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
15. Execution and signatures
1 5.1.These Clauses shall become effective on thedate of the last signature executed below (the
"Effective Date"). The Parties agree that electronicsignatures shall have the same legal force and
effect as original handwritten signatures.
15.2.Each signatory represents that they are dulyauthorised to bind the Party they represent.
Signed for and on behalf of the Customer
COMPANY NAME
FULL NAME
POSITION
DATE
SIGNATURE
Signed for and on behalf of Digital Samba
COMPANY NAME DIGITAL SAMBA, S.L.
FULL NAME ROBERT STROBL
POSITION CEO, DIGITAL SAMBA
DATE
SIGNATURE
12. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
Appendix A:
Information about the processing
1. The nature and purpose of the processing
ersonal data is processed for the purpose of providing the Services to Users. The specific
P
purposes are as follows:
1 .1. To provide and operate the Services.We processpersonal data to deliver the Services,
including authenticating Users, enabling participation in sessions, storing and delivering session
content, and maintaining the operational functionality of the Services.
1 .2. To provide analytics and reporting.We processusage and session data to provide the
Customer with analytics, statistics, and reporting features within the Services.
1 .3. To provide customer support.If the Customerchooses to engage us for supporting their
Users, we process User information to resolve technical issues, respond to requests for
assistance, and diagnose service problems.
1 .4. To deliver data to the Customer.We process personaldata to transmit session events,
participant activity, and other data to the Customer's systems via webhooks and the API, as
configured by the Customer.
2. The types of personal data processed
ersonal data is processed as a consequence of using the Services, inputting data into the
P
Services, providing data via the API, or providing data to us outside the Services. The types of
personal data processed depend on the capacity in which the User interacts with the Services, as
described below.
.1. Account registration and management data.WhenUsers create accounts to access the
2
Services, we collect and process registration information including email address and password
credentials. To complete their account profile, Users may provide their name, phone number,
company name, job title, industry, and country. Country may be derived from the User's IP address
at the time of registration; the IP address itself is not stored as part of this process. Where Users
enable two-factor authentication, we process the associated authentication secret. Where Users
generate API credentials, we process and store the associated keys. We also process team
membership data, including roles and invitation status, where multiple Users manage a single
account.
.2. Participant identification data.When Users joina session, identification data is collected to
2
enable participation. This includes a display name and, optionally, initials. The Customer may also
provide a participant identifier via the API (external ID) to correlate session participants with users
in the Customer's own systems. A randomly generated browser identifier is stored to support
13. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
ession continuity and moderation features such as participant bans. This identifier is not derived
s
from the User's device or browser characteristics.
.3. Content created during sessions.Users may createcontent during sessions, including chat
2
messages, questions and answers, poll and quiz responses, shared notes, and files or documents
uploaded for presentation. Where recording is enabled, audio and video recordings of the session
are created and stored. Where captioning is enabled, speech-to-text transcripts are generated and
stored. Where session summaries are enabled, an AI-generated summary is derived from the
transcript and stored.
.4. Data generated automatically during sessions.The Services automatically collect technical
2
and usage data during sessions. This includes per-connection data such as device and browser
metadata (browser name and version, operating system, and device type) and session
participation records (join time, leave time, and duration), as well as aggregate usage statistics
(such as total minutes of video, audio, and screen sharing). Per-connection records are stored
alongside the participant identification data described in Section 2.2.
.5. Telephony data.Where telephony dial-in is enabled,the phone number and caller
2
identification of Users who connect via the public telephone network are processed as part of call
handling. This data is recorded in call detail record log files and is not stored at the application
level.
.6. Data returned to the Customer.Where the Customerconfigures webhooks or uses the API to
2
retrieve session data, personal data - including participant names, identifiers, and session activity
- is transmitted to the Customer's own systems. The Services do not retain a separate copy of data
transmitted via webhooks; the source data resides in the records described in Sections 2.2
through 2.4.
.7. Information provided through support channels.If the Customer chooses to engage us for
2
supporting their Users, Users may choose to submit information regarding a question or problem
they are experiencing with the Services. Whether the User designates themselves as a technical
contact, opens a support ticket, speaks to one of our representatives directly or otherwise
engages with our support team, the User will be asked to provide contact information, a summary
of the problem they are experiencing, and any other documentation, screenshots or information
that would be helpful in resolving the issue.
.8. Server-side technical data.The Services generateand process server access logs for
2
connection handling, security monitoring, and troubleshooting. The only personal data contained in
these logs is the User's IP address. No other personally identifiable information is recorded in
server access logs. This data is not stored at the application level and is processed by Digital
Samba as an independent controller (see Appendix A, Section 5).
3. The categories of data subjects being processed.
.1. Users.Persons who use the Services, includingaccount holders and participants in sessions
3
hosted through the Services. The types of personal data processed depend on the capacity in
which a User interacts with the Services, as described in Section 2.
14. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
4. The duration of the processing
ow long personal data is retained depends on the type of data, as described below. When
H
personal data is deleted - whether by User action, Customer action, or upon termination of the
Agreement - it is removed from the application immediately. Residual copies in backup archives
and server logs are purged within ninety (90) days through standard rotation. During this period,
backup and log data is securely stored and isolated from any further use.
.1. Account registration and management data.Accountdata (Section 2.1) is retained for as long
4
as the account remains active. When a User deletes their account, all associated personal data is
removed from the application immediately.
.2. Participant identification data.Participantidentification data (Section 2.2) is retained as part
4
of the session record. The Customer may delete session records at any time through the Services
or the API, at which point all participant personal data within the deleted records is removed from
the application immediately. Where a participant has been banned from a session, the browser
identifier and associated data are retained until the ban expires or is revoked by the Customer.
.3. Content created during sessions.Session content(Section 2.3) is retained until the Customer
4
deletes it. The Customer may delete session content and recordings at any time through the
Services or the API, at which point the personal data within the deleted content is removed from
the application immediately.
.4. Data generated automatically during sessions.When session records are deleted (see
4
Section 4.2), participant identification data (Section 2.2) is removed from the per-connection
records. The remaining non-identifying statistical data (Section 2.4) is retained to support the
Customer's analytics and reporting needs.
.5. Telephony data.Call detail record log filescontaining telephony data (Section 2.5) are
4
retained for a maximum of ninety (90) days and then automatically purged through log rotation.
.6. Data returned to the Customer.Once personaldata has been transmitted to the Customer via
4
webhooks or the API (Section 2.6), the transmitted copy is under the Customer's control. As no
separate copy is retained by the Services, the retention of the underlying source data is governed
by the applicable provisions in Sections 4.2 through 4.4.
.7. Information provided through support channels.Support data (Section 2.7) is retained in our
4
support ticketing system for the duration of the business relationship with the Customer. Upon
termination of the Agreement, support tickets and associated personal data are removed within
ninety (90) days. Certain support data may be retained beyond this period where required to
comply with legal obligations or to resolve outstanding disputes.
.8. Server-side technical data.Server access logs(Section 2.8) are retained for a maximum of
4
ninety (90) days and then automatically purged through log rotation. This data is processed by
Digital Samba as an independent controller, as described in Section 5.
.9. Termination.Upon termination or expiry of theAgreement, Digital Samba will remove all
4
personal data processed on behalf of the Customer from the application. Residual copies in
backup archives and server logs are purged within ninety (90) days, unless retention is required by
applicable law.
15. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
5. Digital Samba as an independent controller
or certain limited operational purposes, Digital Samba processes personal data as an independent
F
controller. These purposes include: (a) security monitoring and abuse prevention, including the
processing of IP addresses in server access logs (retained for a maximum of 90 days, legal basis:
Article 6(1)(f) GDPR); (b) service improvement through Digital Samba's own aggregated,
de-identified usage analytics; (c) compliance with legal obligations; and (d) account administration
and billing. This processing arises from Digital Samba's own legal and operational obligations and
is not subject to the Customer's instructions under these Clauses.
16. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
Appendix B: Authorised subprocessors
1. Approved subprocessors
n commencement of the Clauses, the Customer authorises the engagement of the following
O
subprocessors:
egistration
R
Name Address Description of processing
Number
EASEWEB DEUTSCHLAND HRB 89607
L EASEWEB DEUTSCHLAND GMBH G
L erman hosting partner with data
GMBH KLEYERSTRASSE 75-87 centres located in Germany.
60326 FRANKFURT AM MAIN
EASEWEB NETHERLANDS 30141839
L EASEWEB NETHERLANDS B.V.
L utch hosting partner with data
D
B.V. HESSENBERGWEG 95 centres located in the Netherlands.
1101 CX AMSTERDAM
NETHERLANDS
SCALEWAY SAS FR35433115904 CALEWAY SAS
S rench hosting partner with data
F
8 RUE DE LA VILLE L’EVÊQUE centres located in Europe.
75008 PARIS
FRANCE
KENES SA
A CHE-423.524.322 AKENES SA wiss hosting partner for
S
("Exoscale") BOULEVARD DE GRANCY 19A on-demand infrastructure scaling
1006 – LAUSANNE in Europe.
SWITZERLAND
GreenPT B.V. 97084360 REENPT B.V.
G utch provider of AI speech-to-text
D
PLOMPETORENGRACHT 4 (transcriptions, captions) and LLM
3512CC UTRECHT services (translations, summaries,
NETHERLANDS prompts).
HUBSPOT, INC. 000955519 UBSPOT, INC.
H OPTIONALCOMPONENT
25 FIRST STREET
CAMBRIDGE, MA 02141 In certain cases, you may ask us to
USA provide direct support to Users of
the Services. Data entered into
support tickets is processed and
stored in Hubspot.
s part of the Services, we may
A
also redirect Users to experience
feedback forms. Data entered in
those forms is processed and
stored in Hubspot. This feature can
be disabled.
17. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
Appendix C:
Instructions on the use of personal data
1. The subject of/instruction for the processing
igital Samba’s processing of personal data on behalf of the Customer shall be carried out by
D
Digital Samba performing the following:
● Personal data of Users is processed for the purpose of providing the Services to Users.
2. Security of processing
he level of security that shall be taken into account: Processing involves a large volume of
T
personal data which is why a “high” level of security should be established.
igital Samba shall hereafter be entitled and under obligation to make decisions about the
D
technical and organisational security measures that are to be applied to create the necessary (and
agreed) level of data security.
igital Samba shall, however– in any event, and at a minimum– implement the following measures
D
that have been agreed with the Customer:
.1. Information security policies.A set of policiesfor information security is defined, approved by
2
management, published, and communicated to employees and relevant external parties.
.2. Organisation of information security.Informationsecurity responsibilities are defined and
2
allocated.
.3. Human resource security.Background verificationchecks are carried out in accordance with
2
relevant laws and regulations and contractual agreements state the responsibilities for information
security. All team members receive appropriate awareness education and regular updates in
organisational policies.
.4. Asset management.An inventory of informationassets and processing facilities is maintained
2
and rules for acceptable use are documented and implemented. Information is classified and
procedures for the handling of assets in accordance with the classification scheme are
implemented.
.5. Access control.An access control policy is established,documented, and reviewed and
2
access to information and applications is restricted accordingly. Processes for user registration
and deregistration as well as access provisioning are implemented. Access rights are reviewed at
regular intervals.
.6. Cryptography.A policy on the use of cryptographiccontrols for the protection of information
2
is implemented.
18. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
.7. Physical security.Systems are exclusively hosted in data centres providing adequate
2
standards for information security.
.8. Operations security.Operating procedures aredocumented and changes to information
2
processing facilities are controlled. Development, testing, and operational environments are
separated to reduce the risk of unauthorised changes to the operational environment. Controls to
protect against malware are implemented and backups of information are taken and tested
regularly. Event logs recording system administrator activities and security events are produced
and regularly reviewed. Information about technical vulnerabilities of information systems is
obtained in a timely fashion and appropriate measures to address the associated risk are taken.
.9. Communications security.Networks are managedand controlled to protect information and
2
groups of information services are segregated on networks. Communication with applications
utilised cryptographic controls such as TLS to protect the information in transit over public
networks. Stateful firewalls, web application firewalls, and DDoS protection are used to prevent
attacks.
.10. System acquisition, development, and maintenance.Information security requirements are
2
taken into consideration for new information systems or enhancements to existing information
systems. Rules for the secure development of software and systems are established and applied
and testing of security functionality is carried out at regular intervals.
.11. Incident management.Incident management responsibilitiesand procedures are established
2
to ensure a quick, effective and orderly response to security incidents.
3. Assistance to the Customer
igital Samba shall insofar as this is possible assist the Customer by implementing the following
D
technical and organisational measures:
.1.Measures for ensuring ongoing confidentiality,integrity, availability, and resilience of
3
processing systems and services
.2.Measures for ensuring the ability to restorethe availability and access to personal data in a
3
timely manner in the event of a physical or technical incident
.3.Processes for regularly testing, assessing, andevaluating the effectiveness of technical and
3
organisational measures to ensure the security of the processing
3.4.Measures for User identification and authorisation
3.5.Measures for the protection of data during transmission
3.6.Measures for the protection of data during storage
3.7.Measures for ensuring the physical security oflocations at which personal data are processed
3.8.Measures for ensuring events logging
3.9.Measures for internal IT and IT security governanceand management
19. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
3.10.Measures for certification/assurance of processes and products
3.11.Measures for ensuring data minimisation
3.12.Measures for ensuring data quality
3.13.Measures for ensuring limited data retention
3.14.Measures for ensuring accountability
3.15.Measures for allowing data portability and ensuringerasure
4. Storage period/erasure procedures
ersonal data is stored for the time of providing the Services to Users after which the personal
P
data is automatically erased by Digital Samba.
pon termination of the provision of personal data processing services, Digital Samba shall either
U
delete or return the personal data in accordance with Clause 10.1., unless the Customer - after the
signature of the contract – has modified the Customer’s original choice. Such modification shall be
documented and kept in writing, including electronically, in connection with the Clauses.
5. Processing location
rocessing of the personal data under the Clauses cannot be performed at other locations than the
P
following without the Customer’s prior written authorisation:
E
● urope
● United States (OPTIONAL)
uropean B2B customers can choose a configuration (by excluding the optional components listed
E
in Appendix B) where all personal data processing is performed exclusively in European locations.
. Instruction on the transfer of personal data to third
6
countries
s recommended by the European Data Protection Board (EDPB), when personal data is
A
transferred to third countries, appropriate transfer tools are verified in accordance with Chapter V
GDPR (the transfer tools listed under Articles 46 GDPR). Additionally, the law or practice of the
third country is assessed, and supplementary measures are identified and adopted to bring the
level of protection of the data transferred up to the EU standard of essential equivalence. The level
of protection is reevaluated at appropriate intervals.
If the Customer does not in the Clauses or subsequently provide documented instructions
pertaining to the transfer of personal data to a third country, Digital Samba shall not be entitled
within the framework of the Clauses to perform such transfer.
20. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
. Procedures for the Customer’s audits, including
7
inspections, of the processing of personal data being
performed by Digital Samba
s required pursuant to article 28(3)(h) GDPR, Digital Samba will allow for and contribute to audits,
A
including inspections, conducted by the Customer or another auditor mandated by the Customer
required pursuant to article 28(3)(h) GDPR. The Customer shall give Digital Samba reasonable
notice of any audit or inspection to be conducted and shall make (and ensure that each of its
mandated auditors makes) reasonable effort to avoid any damage, injury or disruption to Digital
Samba, its premises, equipment, personnel and business. Under all circumstances, all costs
concerning an audit are borne by the Customer.
21. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.
Appendix D:
Terms of agreements on other subjects
There are no additional terms.
22. Digital Samba Data Processing Agreement © Digital Samba, SL. All rights reserved.