Snapshot 60832
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Data Processing Agreement
Version Effective Date: August 1, 2025
This Data Processing Agreement (“DPA”) forms part of the SaaS Cloud Services Terms of Service between customer
(“Customer”) and Cloud Maven, Inc. (“Provider”) for the purchase of certain cloud services (the “Services”) and related
technical support by Customer (as amended from time to time, the “Agreement”). Capitalized terms not defined herein are
defined in the Agreement.
This DPA is intended to ensure the protection and lawful processing of Personal Data in accordance with the General Data
Protection Regulation (EU) 2016/679 (“GDPR”), the Delaware Online Privacy and Protection Act, the Minnesota Government
Data Practices Act, and any other applicable data protection laws and regulations.
1. DEFINITIONS. For the purposes of this Agreement, the following terms have the following meanings:
1.1 “Agreement” means the Agreement between Customer and Provider for the provision of Services.
1.2 “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” and “Supervisory Authority”
shall have the meanings given in the GDPR.
1.3 “Applicable Data Protection Laws” means all federal, New Jersey, and Delaware statutes, regulations, and
other legal requirements that govern the collection, use, disclosure, storage, security, or other processing of Personal
Information, including, without limitation: (a) the Delaware Personal Data Privacy Act, 6 Del. C. ch. 12D (effective January 1
2025); (b) Delaware’s Breach of Security of Computerized Data statute, 6 Del. C. ch. 12B; (c) the Delaware Online Privacy and
Protection Act, 6 Del. C. ch. 12C; (d) to the extent applicable, the New Jersey Data Privacy Act and any comparable data
protection and breach notification statutes and regulations; and (e) any amendments, rules, or successor provisions to the
foregoing.
1.4 “Sub-processor” means any third party engaged by Processor to process Personal Data on behalf of
Controller.
2. ROLES OF THE PARTIES. The Parties acknowledge and agree that, with regard to the Processing of Personal Data,
Customer acts as the Controller and Provider acts as the Processor.
3. SUBJECT MATTER, DURATION, NATURE, AND PURPOSE OF PROCESSING
3.1 Subject Matter. The Processing of Personal Data as necessary to provide the Services under the Agreement.
3.2 Duration. For the term of the Agreement and any applicable retention period as required by law or this
DPA.
3.3 Nature and Purpose. The Processing is limited to what is necessary to provide the Services, including
hosting, storage, support, maintenance, and related activities.
3.4 Types of Personal Data. Limited to the categories of Personal Data provided by Customer or its Authorized
Users in connection with the Services, which may include names, contact details, user credentials, social security numbers,
date of birth, sex, and other data as described in the Agreement.
3.5 Categories of Data Subjects. Customer’s employees, contractors, agents, Customer’s clients and other
individuals whose Personal Data is provided to Provider in connection with the Services.
Data Processing Agreement
625 Broad St Suite 240, Newark, NJ 07102, USA | www.cloudmaveninc.com | Page 1
4. OBLIGATIONS OF THE PROCESSOR. Processor shall:
4.1 Process Personal Data only on documented instructions from Controller, including with regard to transfers
of Personal Data to a third country, unless required to do so by applicable law. In such case, Processor shall inform Controller
of that legal requirement before Processing, unless prohibited by law.
4.2 Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or
are under an appropriate statutory obligation of confidentiality.
4.3 Implement appropriate technical and organizational measures to ensure a level of security appropriate to
the risk, as required by Applicable Data Protection Laws.
4.4 Assist Controller, insofar as possible, in fulfilling Controller’s obligations to respond to requests for
exercising Data Subjects’ rights under Applicable Data Protection Laws.
4.5 Assist Controller in ensuring compliance with Controller’s obligations under Applicable Data Protection
Laws, including with respect to security, breach notification, data protection impact assessments, and prior consultations
with supervisory authorities.
4.6 At Controller’s choice, delete or return all Personal Data to Controller after the end of the provision of
Services relating to Processing, and delete existing copies unless applicable law requires storage of the Personal Data.
4.7 Make available to Controller all information necessary to demonstrate compliance with the obligations set
forth in this DPA and allow for and contribute to audits, including inspections, conducted by Controller or another auditor
mandated by Controller, provided that such audits are subject to reasonable advance notice and confidentiality obligations.
Audits may be conducted no more than once in any twelve (12) month period unless a Personal Data Breach or material non-
compliance is suspected and shall be conducted during regular business hours in a manner that minimizes disruption to
Processor’s business operations.
5. SUB-PROCESSORS.
5.1 Controller authorizes Processor to engage Sub-processors as necessary for the provision of the Services.
Processor shall ensure that any Sub-processor is bound by data protection obligations no less protective than those set forth
in this DPA. Processors shall maintain the following list of Sub-processors:
https://cloudmaven.atlassian.net/wiki/spaces/APPS/pages/528941069/Cloud+Maven+Integrations+and+data+sources
5.2 Processor shall provide Controller with advance notice of any intended changes concerning the addition or
replacement of Sub-processors, thereby giving Controller the opportunity to object on reasonable grounds.
6. INTERNATIONAL DATA TRANSFERS. Processor shall not transfer Personal Data outside the European Economic Area
unless such transfer is subject to appropriate safeguards in accordance with Applicable Data Protection Laws, such as the
Standard Contractual Clauses or other approved mechanisms.
7. DATA SECURITY AND BREACH NOTIFICATION.
7.1 Processor shall implement and maintain appropriate technical and organizational measures to protect
Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Processor’s
security measures are detailed here, which may be amended from time to time in the Processor’s sole discretion:
https://cloudmaven.atlassian.net/wiki/spaces/APPS/pages/472875009/Cloud+Maven+Due+Diligence
Data Processing Agreement
625 Broad St Suite 240, Newark, NJ 07102, USA | www.cloudmaveninc.com | Page 2
7.2 Processor shall notify Controller without undue delay after becoming aware of a Personal Data Breach
affecting Controller’s Personal Data. Such notification shall include all information reasonably required by Controller to
comply with its obligations under Applicable Data Protection Laws.
8. DATA SUBJECT RIGHTS. Processor shall, to the extent legally permitted, promptly notify Controller if it receives a
request from a Data Subject to exercise their rights under Applicable Data Protection Laws. Processor shall not respond to
such requests except on the documented instructions of Controller or as required by law.
9. LIABILITY. The liability of each Party under this DPA shall be subject to the limitations and exclusions of liability set
forth in the Agreement, except as otherwise required by Applicable Data Protection Laws.
10. TERM AND TERMINATION. This DPA shall remain in effect for as long as Processor processes Personal Data on behalf
of Controller under the Agreement.
11. GOVERNING LAW AND JURISDICTION. This DPA shall be governed by and construed as specified in the Agreement,
and any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the courts specified in the Agreement.
12. MISCELLANEOUS.
12.1 In the event of any conflict between this DPA and the Agreement, the terms of this DPA shall prevail with
respect to the subject matter herein.
12.2 This DPA may be amended only by a written agreement signed by both Parties.
Data Processing Agreement
625 Broad St Suite 240, Newark, NJ 07102, USA | www.cloudmaveninc.com | Page 3