Third Party Index

Snapshot 52962

Document
Data processing addendum
URL
https://cdn.prod.website-files.com/5d2de39fb78ea83a4885e732/5e52f81e16879c495ac80b13_Data%20Processing%20Agreement%20v1.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
179797 bytes
SHA-256 (raw)
f2efe51302f0ef88dfd268227ce0f9467f85aa6ecbb3b7c9c53830c3ef5a1f0e
SHA-256 (normalized text)
2384294ee777a10a1b8c07f51ddf18ab1b124b5f015216dfd9c59aafdb4c5e23

Normalized text

Scripts and page chrome removed; this is what change detection compares.

V1 – 23/02/2020

          Data Processing Agreement (Just Add Features, Ltd. Trading as “Instant Marketing”)

Definition: JAF refers to Just Add Features, Ltd. also trading as “Instant Marketing”.

Acknowledgement of Similarity to Oracle’s Data Processing Agreement: JAF is widely sold along-
side Oracle services, so we have updated this document to be deliberately similar. This is intended to
simplify customers’ review process when they view the documents together. This does not in any
way imply authorization of this document by Oracle, and we will modify the language of these terms
in future editions to remove this similarity if asked to do so by Oracle.

    1. Scope and Applicability
       1.1 This Data Processing Agreement applies to JAF’s Processing of Personal Information on
           Your behalf as a Processor for the provision of the Services specified in Your Services
           Agreement. Unless otherwise expressly stated in Your Services Agreement, this version
           of the Data Processing Agreement shall be effective and remain in force for the term of
           Your Services Agreement
    2. Responsibility for Processing of Personal Information and Your instructions
       2.1 You are a Controller and JAF is a Processor for the Processing of Personal Information as
           part of the provision of the Services. Each party is responsible for compliance with its
           respective obligations under Applicable Data Protection Law.
       2.2 JAF will Process Personal Information solely for the purpose of providing the Services in
           accordance with the Services Agreement and this Data Processing Agreement.
       2.3 In addition to Your instructions incorporated into the Services Agreement, You may
           provide additional instructions in writing to JAF with regard to Processing of Personal
           Information in accordance with Applicable Data Protection Law. JAF will promptly
           comply with all such reasonable instructions to the extent necessary for JAF to (i) comply
           with its Processor obligations under Applicable Data Protection Law; or (ii) assist You to
           comply with Your Controller obligations under Applicable Data Protection Law relevant
           to Your use of the Services.
       2.4 JAF will follow Your reasonable instructions at no additional cost to You and within the
           timeframes reasonably necessary for You to comply with your obligations under
           Applicable Data Protection Law. To the extent JAF expects to incur additional charges or
           fees not covered by the fees for Services payable under the Services Agreement, such as
           additional license or third party contractor fees, it will promptly inform You thereof
           upon receiving Your instructions. Without prejudice to JAF’s obligation to comply with
           Your instructions, the parties will then negotiate in good faith with respect to any such
           charges or fees.
       2.5 Unless otherwise specified in the Services Agreement, You may not provide JAF with any
           sensitive or special Personal Information that imposes specific data security or data
           protection obligations on JAF in addition to or different from those specified in the Data
           Processing Agreement or Services Agreement.
    3. Privacy Inquiries and Requests from Individuals
V1 – 23/02/2020

        3.1 If You receive a request or inquiry from an Individual related to Personal Information
            processed by JAF for the provision of Services, You can contact your Account Manager
            with detailed written instructions to JAF on how to assist You with such request.
        3.2 If JAF directly receives any requests or inquiries from Individuals that have identified You
            as the Controller, it will promptly pass on such requests to You without responding to
            the Individual. Otherwise, JAF will advise the Individual to identify and contact the
            relevant controller(s).
   4.   JAF Affiliates and Third Party Subprocessors
        4.1 To the extent JAF engages Third Party Subprocessors and/or Affiliates to Process
            Personal Information, such entities shall be subject to the same level of data protection
            and security as JAF under the terms of the Services Agreement. JAF is responsible for the
            performance of the JAF Affiliates’ and Third Party Subprocessors’ obligations in
            compliance with the terms of this Data Processing Agreement and Applicable Data
            Protection Law.
   5.   Cross-border data transfers
        5.1 Without prejudice to any applicable regional data center restrictions for hosted Services
            specified in Your Services Agreement, JAF may Process Personal Information globally as
            necessary to perform the Services.
        5.2 To the extent such global access involves a transfer of Personal Information subject to
            cross-border transfer restrictions under Applicable Data Protection Law, such transfers
            shall be subject to Applicable Data Protection Law and all applicable JAF security and
            data privacy policies and standards globally.
   6.   Security and Confidentiality
        6.1 JAF has implemented and will maintain appropriate technical and organizational security
            measures for the Processing of Personal Information designed to prevent accidental or
            unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal
            Information. These security measures govern all areas of security applicable to the
            Services, including physical access, system access, data access, transmission and
            encryption, input, data backup, data segregation and security oversight, enforcement
            and other security controls and measures. Please review the “Master Security
            Whitepaper” at https://instant.marketing/compliance
        6.2 All JAF employees, as well as any Third Party Subprocessors that Process Personal
            Information, are subject to appropriate written confidentiality arrangements, including
            confidentiality agreements, regular training on information protection, and compliance
            with JAF policies concerning protection of confidential information
   7.   Integrations
        7.1 A number of JAF applications are designed to invoke a target-system. For example: our
            SMS product allows you to enter the API key for a SMS sender, and data will then be
            sent to this provider via. API call as necessary to send the SMS. In these cases, JAF is
            acting as a systems-integrator and these services may also be a Processor, not a Third
            Party Subprocessor to JAF. You should establish a separate Data Processing Agreement
            with these vendors. If required, you may ask JAF for a list of services which are invoked
            by a given product.
        7.2 Our Instant Extensions products allow you to enter arbitrary code. You are fully
            responsible for all aspects of running this code.
   8.   Incident Management and Breach Notification
        8.1 If a data breach is suspected JAF will promptly define escalation paths to investigate
            such incidents in order to confirm if a Personal Information Breach has occurred, and to
V1 – 23/02/2020

           take reasonable measures designed to identify the root cause(s) of the Personal
           Information Breach, mitigate any possible adverse effects and prevent a recurrence.
       8.2 JAF will notify you of a confirmed Personal Information Breach without undue delay but
           at the latest within 24 hours. As information regarding the Personal Information Breach
           is collected or otherwise reasonably becomes available to JAF, JAF will also provide You
           with (i) a description of the nature and reasonably anticipated consequences of the
           Personal Information Breach; (ii) the measures taken to mitigate any possible adverse
           effects and prevent a recurrence; and (iii) where possible, information about the types
           of Personal Information that were the subject of the Personal Information Breach. You
           agree to coordinate with Oracle on the content of Your intended public statements or
           required notices for the affected Individuals and/or notices to the relevant Regulators
           regarding the Personal Information Breach.
   9. Return and Deletion of Personal Information
       9.1 Upon termination of the Services, JAF will promptly return, including by providing
           available data retrieval functionality, or delete any remaining copies of Personal
           Information on JAF systems or Services environments, except as otherwise stated in the
           Services Agreement.
       9.2 For Personal Information held on Your systems or environments, or for Services for
           which no data retrieval functionality is provided by JAF as part of the Services, You are
           advised to take appropriate action to back up or otherwise store separately any Personal
           Information while the production Services environment is still active prior to
           termination.
   10. Audit Rights
       10.1 Subject to this section 10, JAF shall make available to the Company on request all
           information necessary to demonstrate compliance with this Agreement, and shall allow
           for and contribute to audits, including inspections, by the Company or an auditor
           mandated by the Company in relation to the Processing of the Company Personal Data
           by the Contracted Processors.
   11. Legal Requirements
       11.1 JAF may be required by law to provide access to Personal Information, such as to
           comply with a subpoena or other legal process, or to respond to government requests,
           including public and government authorities for national security and/or law
           enforcement purposes.
       11.2 JAF will promptly inform You of requests to provide access to Personal Information,
           unless otherwise required by law.
   12. Definitions

   “Applicable Data Protection Law” means all data privacy or data protection laws or regulations
   globally that apply to the Processing of Personal Information under this Data Processing
   Agreement, which may include Applicable European Data Protection Law.

   “Applicable European Data Protection Law” means (i) the EU General Data Protection
   Regulation EU/2016/679, as supplemented by applicable EU Member State law and as
   incorporated into the EEA Agreement; (ii) the Swiss Federal Act of 19 June 1992 on Data
   Protection, as amended; and (iii) the UK Data Protection Act 2018. “Europe” means for the
   purposes of this Data Processing Agreement (i) the European Economic Area, consisting of the
   EU Member States, Iceland, Lichtenstein and Norway; (ii) Switzerland and (iii) the UK after it
   withdraws from the EU.
V1 – 23/02/2020

   “Individual” shall have the same meaning as the term “data subject” or the equivalent term
   under Applicable Data Protection Law.

   “Process/Processing”, “Controller”, “Processor” and “Binding Corporate Rules” (or the
   equivalent terms) have the meaning set forth under Applicable Data Protection Law.

   “Personal Information” shall have the same meaning as the term “personal data”, “personally
   identifiable information (PII)” or the equivalent term under Applicable Data Protection Law.

   “Personal Information Breach” means a breach of security leading to the misappropriation or
   accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to,
   Personal Information transmitted, stored or otherwise Processed on JAF systems or the Services
   environment that compromises the security, confidentiality or integrity of such Personal
   Information.

   “Regulator” shall have the same meaning as the term “supervisory authority”, “data protection
   authority” or the equivalent term under Applicable Data Protection Law.

   “Services” or the equivalent terms “Service Offerings” or “services” means the Cloud, Advanced
   Customer Support, Consulting, or Global Technical Support services specified in the Services
   Agreement.

   “Services Agreement” means (i) the applicable order for the Services you have purchased from
   Oracle; (ii) the applicable master agreement referenced in the applicable order, and (iii) the
   Service Specifications.

   “Third Party Subprocessor” means a third party which Oracle subcontracts with and which may
   Process Personal Information as set forth in Section 4.

   “You” means the customer entity that has executed the Services Agreement. Other capitalized
   terms have the definitions provided for them in the Services Agreement.