Snapshot 63491
Normalized text
Scripts and page chrome removed; this is what change detection compares.
DATA PROCESSING ADDENDUM
Background. M-Files and the Customer have agreed on the performance by M-Files Other terms that have been capitalized but not defined in this DPA shall have the same
of certain services for the Customer (identified either as “Services” or otherwise in the meaning as in the Agreement.
applicable service or license agreement(s), and hereinafter defined as “Services”), with
the scope agreed in any applicable order, SOW, services agreement, and license Processing of Personal Data. The Parties agree that with regard to the processing of
agreement(s) (each, the "Agreement" and, collectively, the “Agreements”). The personal data, Customer is the controller, M-Files is the processor and that M-Files may
Agreements set out certain duties and responsibilities of the Parties (as defined in the engage Sub-processors pursuant to the requirements set forth in the Section entitled
Agreements) including the responsibilities of M-Files and the Customer relating to the "Sub-Processors". To the extent any personal data processed pursuant to the
services provided by M-Files. Agreement is within the scope of the CCPA, Customer is a "business" and M-Files is a
"service provider" as those terms are defined in the CCPA. Customer shall, in its use
Scope & Purpose. The Services may include processing of personal data by M-Files,
of the Services, process personal data in accordance in all material respects with the
on behalf of the Customer, within the scope described in the Agreements and in
requirements of Privacy and Security Laws and Customer will ensure that its
accordance with Appendix 1. The purpose of this Data Processing Addendum (“DPA”)
is to set forth the terms and conditions governing such processing by M-Files in instructions for the processing of personal data shall comply in all material respects with
compliance with the requirements set by the GDPR and other applicable data Privacy Privacy and Security Laws. Customer shall have sole responsibility for the accuracy,
and Security Laws (as defined below). Customer enters into this DPA on its own behalf quality, and legality of personal data and the means by which Customer acquired
and on behalf of those of the Customer’s group companies that function as a controller personal data. M-Files shall only process personal data on behalf of and in accordance
with respect to personal data being processed by M-Files under this DPA and the with Customer’s written instructions and shall treat any Customer personal data as
Agreements. For the purposes of this DPA only, and except as otherwise specified, the confidential information. Customer instructs M-Files to process personal data for the
term "Customer" shall include Customer and Customer’s group companies under the following purposes: (i) processing in accordance with any material respects of the
direct or indirect control of Customer and subject to the Agreements. In the event of any Agreement and applicable orders; and (ii) processing to comply in any material respects
conflicts in the terms and conditions of this DPA and any appendices hereto or any with other reasonable written instructions provided by Customer (e.g., via a support
terms of the Agreements, the terms of this DPA shall prevail. In the course of providing ticket) as long as such instructions are consistent with the terms of the Agreement.
the Services to Customer pursuant to the Agreements, M-Files may process personal When filing a support ticket or other service request, Customer may not transmit
data on behalf of Customer and the Parties agree to comply in all material respects with
personal data to M-Files without a prior notification. If personal data is necessary for the
the terms and conditions herein and to act at all times relevant in a commercially
incident management process or processing other service request, Customer may
reasonable manner and in good faith.
choose to anonymize that personal data before any transmission of the incident
Term & Termination. This DPA shall become effective upon the effectiveness of any message to M-Files. In connection with the Agreement, M-Files will not: (i) Sell personal
applicable Agreement and shall remain in force during the validity of the applicable data unless permitted under the Agreement or duly authorized by under applicable laws;
Agreement and thereafter for as long as necessary for the finalization of the agreed or (ii) retain, use, or disclose personal data for any purpose other than for the specific
processing of Customer's personal data. business purpose of performing the Services for Customer, including retaining, using,
or disclosing the personal data for a commercial purpose other than providing the
DEFINITIONS. The terms “personal data”, “personal information,” “data subject”, Services for Customer. The parties agree that any transfer or disclosure of personal
“personal data breach”, “processing”, “controller”, “processor” and data between M-Files and Customer under the Agreement is not for monetary or other
“supervisory authority” as used in this DPA have the meanings given in the valuable consideration and does not constitute a sale of personal data under the Privacy
applicable Privacy and Security Laws. In addition, the term "controller" shall mean any and Security Laws. The subject-matter and details of the processing of personal data
applicable M-Files’ customer, and the terms “data importer” and “data exporter” shall by M-Files are described in Agreement.
have the meanings given in the standard contractual clauses approved by the European
Union concerning the transfer of personal data to outside the EU/EEA (the “SCCs”). For Processor Obligations. Customer has at any given moment electronic access to the
clarity, unless expressly stated otherwise in this DPA, the term “personal data” also Services environment that holds personal data enabling Customer to respond to data
includes personal information. In this DPA, unless stated otherwise herein: subject's requests to exercise their rights under applicable data protection law, including
"CCPA" means Cal. Civ. Code 1798.100, et seq. § 1798.100, as amended and requests to access, erase, restrict, rectify, transfer, or object to processing of specific
revised from time to time as well as any related regulations promulgated by the personal data or sets of personal data. To the extent Customer, in its use of the
California Attorney General and entered into effect. Services, does not have the ability to correct, amend or delete personal data or restrict
"GDPR" means EU General Data Protection Regulation (679/2016) concerning the its processing, as required by Privacy and Security Laws, M-Files shall comply with any
processing of personal data.
commercially reasonable request by Customer to facilitate such actions to the extent
"UK GDPR" means the GDPR as implemented in the United Kingdom under Data
M-Files is legally permitted to do so. M-Files shall, to the extent legally permitted,
Protection Act of 2018.
"Privacy and Security Laws" means: (i) all applicable national, international, promptly notify Customer if it receives a request from a data subject for access to,
federal, state, provincial, and local laws, rules, regulations, directives, and governmental correction, amendment or deletion of that person’s personal data. M-Files shall provide
requirements currently in effect and as they become effective relating in any way to the Customer with commercially reasonable cooperation and assistance in relation to
privacy, confidentiality, and/or security of personal data, including, but not limited to, the handling of a data subject’s request for access to that person’s personal data, in
GDPR, UK GDPR and CCPA; and (ii) all applicable industry standards or rules required accordance with the terms of the Agreement. Upon written request by Customer, M-
to followed by M-Files concerning the privacy, confidentiality, and/or security of personal Files shall provide Customer with reasonable cooperation and assistance to fulfill
data. Customer's obligations under the Privacy and Security Laws to carry out any applicable
"Sell" or "Selling" means selling, renting, releasing, disclosing, disseminating, data protection impact assessment related to the Customer's use of M-Files Services,
making available, transferring, or otherwise communicating orally, in writing, or by to the extent relevant information is not otherwise accessible to the Customer. In the
electronic or other means, personal data to another business or a third party for event that coordination or prior consultation with any supervisory authority is required
monetary or other valuable consideration. from Customer, M-Files shall provide reasonable assistance to Customer for such
"Sub-processors" means third parties authorized under this DPA to have logical
cooperation or prior consultation. Any assistance under this Section "Processor
access to and process personal data in order to provide parts of the Services. The term
Sub-processor is equated with the term processor under applicable Privacy and Obligations" shall be subject to the rates applicable in the Agreement or at M-Files'
Security Laws and shall be interpreted herein accordingly. prevailing service rates.
"Security, Privacy and Architecture Documentation" means the security, privacy
M-Files Personnel & Contact. M-Files shall ensure that its personnel engaged in the
and architecture documentation applicable to the specific Services purchased by
Customer, as updated from time to time, and provided to Customer as part of the processing of personal data are informed of the confidential nature of the personal data,
documentation delivered under or in connection with the Agreements, or made available have received appropriate training on their responsibilities and have executed written
by M-Files or as requested by Customer. confidentiality agreements or are subject to statutory obligations of confidentiality. M-
"Parties" means the Customer and M-Files collectively and "Party" means the Files shall ensure that such confidentiality obligations survive the termination of the
Customer or M-Files individually. personnel engagement with M-Files. M-Files shall ensure that M-Files' access to
www.m-files.com
DATA PROCESSING ADDENDUM
personal data is limited to only to such personnel needing to know such information to impede the obligations of M-Files or its subcontractors in regard to any third parties.
perform or support the Services in accordance with the Agreement. The appointed M- Prior to any audit process, the representatives of Customer and the auditor agree to be
Files data privacy contact can be reached at: privacy@m-files.com or through any subject to and sign, if needed, M-Files' form of non-disclosure agreement. M-Files shall
contact included in the notice provision of the Agreement. provide Customer free of charge any documentation or other materials reasonably
available to M-Files and necessary for the purposes of the Customer's audit or
Sub-Processors. inspection. Further audit or inspection activities required by Customer shall be subject
to the prevailing M-Files service rates set out in the applicable price list. If applicable, in
Permitted use. Customer authorizes M-Files to subcontract the processing
the event that M-Files provides the Customer with an audit report by a third-party auditor
of personal data to Sub-processors and in accordance with the Agreement. M-Files
that reasonably meets in any material respects the purpose of Customer's audit request
shall be liable for any material defaults or breaches caused by its Sub-processors in
based on the applicable circumstances, then the audit right hereunder shall be deemed
accordance with the terms of the Agreement. M-Files shall ensure that any Sub-
satisfied. The Customer shall be responsible for its own expenses caused by the audit
processors are bound by a written agreement that require them to provide at least the
or inspection, unless a material default or breach of the Agreement is uncovered, in
same level of data protection required by M-Files as a processor under this DPA. M-
which event M-Files shall be responsible for the reasonable and documented out-of-
Files shall evaluate the security, privacy and confidentiality practices of a Sub-processor
pocket costs that Customer incurred in reviewing M-Files' security activities and data
prior to its selection. Sub-processors may have security certifications that evidence their
privacy practices.
use of appropriate security measures. If not, M-Files will periodically evaluate each Sub-
processor’s security practices relating to processing of personal data. A list of Sub- Personal Data Breach; Deletion & Retention; Liability & Other. M-Files shall notify
processors is available at the appropriate location on the M-Files web page or other Customer without undue delay upon becoming aware of any material breach of Privacy
location as designated by M-Files from time to time. and Security Laws relating to personal data (each an “Incident”). Subject to applicable
laws, such notification shall: (i) describe the nature of the Incident including, where
New Sub-processors. M-Files’ use of Sub-processors is at its discretion,
possible, the categories and approximate number of data subjects concerned, and the
provided that information about Sub-processors, including their name, country and
categories and approximate number of personal data records concerned; (ii) provide
processing activities, is available at the appropriate location on the M-Files web page
the name and contact details where more information about the Incident can be
or other location as designated by M-Files from time to time. M-Files will notify Customer
obtained; and (iii) describe the measures taken or proposed to be taken to address the
of changes to the list of Sub-processors by providing Customer with a mechanism to
Incident including, where appropriate, measures to mitigate its possible adverse effects.
subscribe to notifications of changes to the list of Sub-processors.
After the expiry or termination of the Agreement, in accordance with the Agreement
Objection to New Sub-Processor. If Customer has a reasonable and including applicable Privacy and Security Laws, M-Files shall provide Customer with a
substantiable basis to object to any new Sub-processors’ processing of Customer's copy of any Hosted Data and delete all Customer Data and installations, including
personal data, Customer may notify M-Files in writing via email to the data privacy personal data, unless applicable law requires the retention of the personal data or
contract herein within 14 days of the listing of any new Sub-processors. For any such permits such retention in accordance with M-Files' applicable business continuity and
objections, M-Files may: (i) discontinue its use the Sub-processor or (ii) take the disaster recovery practices. Liability of each Party, taken together in the aggregate,
corrective steps requested to eliminate the basis for Customer's objection to use the arising out of or related to this DPA, whether in contract, tort or under any other theory
Sub-processor. If such objection cannot be resolved and Customer continues to have of liability, shall be exclusively subject to the limitation of liability and other liability terms
a reasonable and substantiated basis to object, then either party may exercise any and conditions set out in the applicable Agreement. The DPA is interpreted, construed
applicable default and termination rights set forth in the Agreement. and governed in accordance with the applicable choice of law provision and any other
general provisions set forth in the applicable Agreement, including resolving any
Processing Outside of EU/EEA. M-Files and its Sub-processors may transfer or disputes concerning the interpretation or application of the DPA in accordance with any
process personal data outside the EU/EEA area as required to provide Services under applicable dispute resolution provisions included in such Agreement.
the Agreement. In case such transfers or processing take place, M-Files ensures that
►Only if required due to unique circumstances, changes may be submitted via the email consent of the
the SCCs, or a similar legal safeguard approved by the GDPR, shall apply to such Parties or as set forth below:
transfer or processing.
Cloud-based Services. In the event that under the Agreement a cloud-based service Notwithstanding any terms or conditions in the above to the contrary, the Parties agree to additional
provisions below, which provisions shall be incorporated herein by reference and shall apply in the event
shall be delivered by a third-party provider (AWS, Microsoft, Google or other), the of any conflicts in interpretation with the above provisions of this DPA:
Parties acknowledge that any Customer personal data processed within the cloud
service shall be governed by the terms and conditions for the cloud service as stipulated
1.
and amended from time to time by the cloud service provider.
2.
Security Controls. M-Files shall maintain appropriate technical and organizational
measures for protection of the security (including protection against unauthorized or 3.
unlawful processing and against accidental or unlawful destruction, loss or alteration or
damage, unauthorized disclosure of, or access to, personal data), confidentiality and
integrity of personal data, as set forth in the Security, Privacy and Architecture
Documentation. M-Files regularly monitors compliance with these measures. M-Files
will maintain and not materially decrease the overall security of the Services during any
applicable subscription term in the Agreement.
Third-Party Certifications and Audits. The Customer or an auditor authorized by
Customer (however, not a competitor of the M-Files) shall be entitled to inspect and/or
audit the data privacy and security activities of M-Files pursuant to the DPA. The Parties
shall agree on the time, scope and process of the inspection or audit at latest 30 days
before the inspection or audit. The audit shall be carried out in a way that does not
www.m-files.com
DATA PROCESSING ADDENDUM
Appendix 1: Subject Matter and Details of the Data Processing
Purpose of the processing of personal data: implementation of the Agreement.
The duration of the processing of personal data: The Processing shall begin on the Effective Date of the Agreement and shall take place for an indefinite period until the
termination of the Agreement.
Type of processing: The following types of data processing are performed: storage, adjustment, transmission, restriction, deletion or destruction of data.
Categories of Data Subjects:
Customer may submit personal data to the Services, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not
limited to personal data relating to the following categories of data subjects:
• Prospects, customers, business partners and vendors of Customer (who are natural persons)
• Employees or contact persons of Customer’s prospects, customers, business partners and vendors
• Employees, agents, advisors, freelancers of Customer (who are natural persons)
• Customer’s Users authorized by Customer to use the Services
Type of Personal Data:
Customer may submit personal data to the Services, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not
limited to the following categories of personal data:
• Customer details such as name, title, telephone, business address and mobile numbers and email address
• Corporate customer, partner and vendor details such as name, title, business address, telephone and mobile numbers and email address
• Employment and human resources details such as name, addresses, contact details, age, details relating to the employment of the data subject
• Financial and transactional details
• IT management details such as details of equipment data related to the services provided including technical identifiers, user name, location, contact details,
communication data and metadata
• Security details such as security log information
• Connection data
• Localization data
www.m-files.com