Third Party Index

Snapshot 64111

Document
Data processing addendum
URL
https://www.sidetrade.com/data-processing-addendum
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
browser
Size
163792 bytes
SHA-256 (raw)
6a4d6971cb2f4a6403654a103e3e714e8100d3b773f6284bfc1d2486575a11fc
SHA-256 (normalized text)
e18cce9e8155b42c42a1f162683ab028c201802c43e14675ee31032d4a60a369

Normalized text

Scripts and page chrome removed; this is what change detection compares.

We value your privacy
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.
Customize Consent Preferences
We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.
The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ...
Always Active
Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.
Cookie
_cfuvid
Duration
session
Description
No description
Cookie
wmc
Duration
1 year 1 month 4 days
Description
No description available.
Cookie
wpEmojiSettingsSupports
Duration
session
Description
WordPress sets this cookie when a user interacts with emojis on a WordPress site. It helps determine if the user's browser can display emojis properly.
Cookie
cookieyes-consent
Duration
1 year
Description
CookieYes sets this cookie to remember users' consent preferences so that their preferences are respected on subsequent visits to this site. It does not collect or store any personal information about the site visitors.
Cookie
BIGipServer*
Duration
session
Description
Marketo sets this cookie to collect information about the user's online activity and build a profile about their interests to provide advertisements relevant to the user.
Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.
Cookie
li_gc
Duration
6 months
Description
No description
Cookie
__cf_bm
Duration
1 hour
Description
This cookie, set by Cloudflare, is used to support Cloudflare Bot Management.
Cookie
bcookie
Duration
1 year
Description
LinkedIn sets this cookie from LinkedIn share buttons and ad tags to recognize browser ID.
Cookie
lidc
Duration
1 day
Description
LinkedIn sets the lidc cookie to facilitate data center selection.
Cookie
site_identity
Duration
1 year
Description
No description available.
Cookie
ytidb::LAST_RESULT_ENTRY_KEY
Duration
Never Expires
Description
The cookie ytidb::LAST_RESULT_ENTRY_KEY is used by YouTube to store the last search result entry that was clicked by the user. This information is used to improve the user experience by providing more relevant search results in the future.
Cookie
yt-remote-session-app
Duration
session
Description
The yt-remote-session-app cookie is used by YouTube to store user preferences and information about the interface of the embedded YouTube video player.
Cookie
yt-remote-cast-installed
Duration
session
Description
The yt-remote-cast-installed cookie is used to store the user's video player preferences using embedded YouTube video.
Cookie
yt-remote-session-name
Duration
session
Description
The yt-remote-session-name cookie is used by YouTube to store the user's video player preferences using embedded YouTube video.
Cookie
yt-remote-fast-check-period
Duration
session
Description
The yt-remote-fast-check-period cookie is used by YouTube to store the user's video player preferences for embedded YouTube videos.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.
Cookie
_gcl_au
Duration
3 months
Description
Provided by Google Tag Manager to experiment advertisement efficiency of websites using their services.
Cookie
_ga
Duration
1 year 1 month 4 days
Description
The _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors.
Cookie
_gid
Duration
1 day
Description
Installed by Google Analytics, _gid cookie stores information on how visitors use a website, while also creating an analytics report of the website's performance. Some of the data that are collected include the number of visitors, their source, and the pages they visit anonymously.
Cookie
_gat_UA-*
Duration
1 minute
Description
Google Analytics sets this cookie for user behaviour tracking.
Cookie
_ga_*
Duration
1 year 1 month 4 days
Description
Google Analytics sets this cookie to store and count page views.
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
No cookies to display.
Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.
Cookie
YSC
Duration
session
Description
YSC cookie is set by Youtube and is used to track the views of embedded videos on Youtube pages.
Cookie
VISITOR_INFO1_LIVE
Duration
6 months
Description
A cookie set by YouTube to measure bandwidth that determines whether the user gets the new or old player interface.
Cookie
test_cookie
Duration
15 minutes
Description
The test_cookie is set by doubleclick.net and is used to determine if the user's browser supports cookies.
Cookie
_mkto_trk
Duration
1 year 1 month 4 days
Description
This cookie, provided by Marketo, has information (such as a unique user ID) that is used to track the user's site usage. The cookies set by Marketo are readable only by Marketo.
Cookie
yt-remote-device-id
Duration
Never Expires
Description
YouTube sets this cookie to store the video preferences of the user using embedded YouTube video.
Cookie
yt-remote-connected-devices
Duration
Never Expires
Description
YouTube sets this cookie to store the video preferences of the user using embedded YouTube video.
Cookie
IDE
Duration
1 year 24 days
Description
Google DoubleClick IDE cookies are used to store information about how the user uses the website to present them with relevant ads and according to the user profile.
Cookie
yt.innertube::requests
Duration
Never Expires
Description
This cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen.
Cookie
yt.innertube::nextId
Duration
Never Expires
Description
This cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen.
Cookie
slireg
Duration
7 days
Description
No description available.
Cookie
sliguid
Duration
1 year
Description
No description available.
Cookie
slirequested
Duration
1 year
Description
No description available.
Cookie
VISITOR_PRIVACY_METADATA
Duration
6 months
Description
YouTube sets this cookie to store the user's cookie consent state for the current domain.
Cookie
guest_id
Duration
1 year 1 month
Description
Twitter sets this cookie to identify and track the website visitor. It registers if a user is signed in to the Twitter platform and collects information about ad preferences.
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
No cookies to display.
Powered by
O2C Intelligence
[Column]
O2C AGENTS
Aimie Agents
Customer Agents
Agent Builder Studio
--separator--
O2C Apps
Credit Risk Expert
E-Order and E-Invoicing Automation
Augmented Collection
Digital Case
Cash App
Deductions and Claims
Customer Experience Center
Analytics
[Column]
Aimie IQ
Conversational Engagement
-- separator --
Technology
Agentic Framework
Core Platform
Intelligence Foundation
O2C Execution Layer
Arrange a demo
[Column]
O2C Data Lake
Real-time, predictive payment intelligence
Industries
Construction & Mining
CPG
Financial Services
Info & com technology
Life Sciences
Manufacturing
Retail
Services
Transport & Logistics
Utilities & Environment
Customers
Who we work with
Case studies
Resources
Datasheets
Infographics
Videos
Webinars
Whitepapers
Training and Certification
Blog
Company
About Us
CSR
Leadership
News
Careers
Investors
Contact
en fr de
Data processing Addendum
November 2022
This Data Processing Addendum ( “DPA”) is supplemental to the Subscription Agreement to Sidetrade Service and/or to the BPO General Terms and Conditions and/or to the Professional Services Order and/or T&Cs for online training (Capsule offers) (the “Agreement”) and sets out additional terms that apply when personal data is processed by Sidetrade under the Agreement and in the context of the services performed under the Agreement (here-after the “Services”). The purpose of the Data Processing Addendum is to ensure such processing is conducted in accordance with applicable laws including the Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“General Data Protection Regulation” or GDPR).
In this addendum, “processing”, “controller”, “processor”, “data subject”, “personal data” and “personal data breach” shall have the same meaning as in the GDPR.
I – PERSONAL DATA PROCESSED BY SIDETRADE ON CUSTOMER’S BEHALF
PROCESSING OF CUSTOMER PERSONAL DATA
1.1 Role of the Parties – The Parties acknowledge and agree that with regard to the processing of personal data, Customer is the controller and appoints Sidetrade as a processor to process personal data on Customer’s behalf.
1.2 Duration of processing – Sidetrade will process personal data under the provisions of this Data Processing Addendum until the earliest of (i) termination of the Agreement or (ii) the date upon which Customer informs Sidetrade that it is no longer necessary in relation to the purposes defined by Customer (such event having no effect on Customer other possible contractual commitments, in particular with regard to financial subscriptions).
1.3 Nature and purpose of processing – Sidetrade will process personal data as necessary to perform the Services pursuant to the Agreement and as further instructed by Customer in its use of the Services where such instructions are consistent with the terms of the Agreement. Sidetrade will act only on instructions from Customer and shall comply with such instructions received from Customer from time to time.
1.4 Type of Personal Data – Customer may submit personal data to the Services, the extent of which is determined and controlled by Customer and which may include, but is not limited to the following categories of personal data: First and last name, Title/position, Employer, Contact information (company, e-mail, phone, physical business address, social networking address).
1.5 Categories of data subjects – Customer may submit personal data to the Services, the extent of which is determined and controlled by Customer and which may include, but is not limited to personal data related to the following categories of data subjects: customers, employees, prospects, business partners.
1.6 Record of processing activity – Subject to the applicability of the conditions set forth in article 30 of the GDPR, Sidetrade shall maintain a record of all categories of processing activities carried out on behalf of Customer.
SIDETRADE PERSONNEL
2.1 Confidentiality – Sidetrade shall ensure that the members of its personnel engaged in the processing of personal data are informed of the confidential nature of the personal data and have received appropriate training on their responsibilities.
2.2 Reliability – Sidetrade shall take reasonable steps to ensure the reliability of any employee who may have access to Customer personal data and to limit access to those individuals who need to know/access the relevant personal data for the enforcement of the Agreement.
Requirements for California Consumer Privacy Act, of 2018 Cal. Civ. Code §§ 1798.100 et seq. (CCPA);
Sidetrade shall use and disclose Customer’s personal data solely for the purposes for which such personal data was provided to it, as stipulated in the Agreement and this DPA.
Sidetrade agrees to refrain from “selling” as such term is defined in the CCPA, any personal data processed hereunder, without the prior written consent of Customer.
SECURITY
4.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Sidetrade shall implement technical and organizational measures appropriate to the risks and designed to protect the personal data from accidental or unlawful destruction, loss, alteration, unauthorized disclosure, access or use, in accordance with Sidetrade’ security standards.
PERSONAL DATA BREACH
5.1 After becoming aware of a personal data breach, Sidetrade shall notify Customer without undue delay. Sidetrade shall provide such timely information as Customer may reasonably require enabling Customer to fulfil any data breach reporting obligations under EU data protection legislation.
5.2 Sidetrade shall make reasonable efforts to identify the cause of such personal data incident and take those steps as Sidetrade deems necessary and reasonable in order to remediate the cause of such incident, to the extent the remediation is within Sidetrade’s reasonable control. The obligation herein shall not apply to incidents that are caused by Customer or Customer’s Users.
DATA SUBJECT RIGHTS
6.1 Taking into account the nature of the processing, Sidetrade shall assist Customer by implementing appropriate technical and organizational measures, insofar as it is possible, for the fulfilment of Customer’s obligations to respond to requests made by data subjects to exercise their rights.
6.2 To the extent that Customer does not have the ability to address a data subject request, upon Customer’s request, Sidetrade shall provide reasonable assistance to Customer, insofar as it is possible, at Customer’s costs to the extent legally permitted.
COOPERATION
7.1 Sidetrade shall provide Customer reasonable assistance in relation to any investigations or enquiries made by any supervisory authority relating to Customer’s obligations under data protection legislation.
7.2 Sidetrade shall provide Customer reasonable assistance in relation to all information necessary to demonstrate compliance with the obligations laid down in article 28 of the GDPR.
SUB-PROCESSING
8.1 Customer agrees that Sidetrade may engage third party sub-processors in connection with the provision of the Services. Sidetrade makes available to Customer the current list of sub-processors for the Services at https://www.sidetrade.com/sidetrade-sub-processors-list/.. Sidetrade shall impose on such sub-processors data protection terms that protect the personal data to the same standard provided for by Sidetrade.
8.2 Customer may find on the agreed Sidetrade’s on-line page the sub-processor documentation as well as a device to receive notifications of new sub-processors for the relevant services. If Customer subscribes, Sidetrade shall provide Customer a notification for new sub-processors. Customer may object to Sidetrade’s choice by notifying Sidetrade by letter with acknowledgement of receipt within fifteen (15) days after receipt of Sidetrade’s notice, in explaining the detailed reasons of the objection. In such a case, Sidetrade will use reasonable efforts to propose to Customer a commercially rational change to Customer’s configuration or use of the Services.
AUDIT RIGHTS
9.1 Subject to the confidentiality obligations set forth in the Agreement and with a maximum of a yearly frequency, Sidetrade allows Customer or an auditor contractually mandated by Customer to conduct on-site audits or inspections during normal business hours, with fifteen (15) working days-notice, to verify Sidetrade’s compliance with data protection legislation.
9.2 Before the commencement of any such audit, Customer and Sidetrade shall mutually agree upon the scope, timing and duration of the audit whichshall not exceed one (1) business day. If the auditor’ identity may result in a conflict of interest or a competition trouble, Sidetrade will have the right to ask for the choice of another neutral auditor by Customer.
9.3 Customer will take all necessary measures to ensure that the audit will not cause any damage to Sidetrade’s equipment, data, business, personnel and premises. Customer shall be entitled to have access only to information strictly and exclusively related to the Services delivered to the Customer and shall use the information received for no other purpose than for the purpose of the audit.
DELETION AND RETURN OF CUSTOMER DATA
10.1 Save to the extent that Sidetrade is required by the applicable law to retain some or all of the personal data, upon termination or expiration of the Agreement and its related Order Form, Sidetrade shall delete all Customer’s relevant personal data, within forty-five (45) days from the said termination or expiration.
10.2 During the above mentioned forty-five (45) days period, Customer may, by written notice to Sidetrade, ask specifically for a return of a complete copy of all relevant personal data, in a reasonable format. Sidetrade may, in its sole discretion, accept to proceed to such a return, in accordance with conditions to be determined by mutual agreement between the Parties.
DATA TRANSFERS
11.1 Customer acknowledges and accepts that the provision of the Services may require the processing of personal data by sub-processors outside the European Economic Area.
11.2 To the extent any processing of personal data by Sidetrade takes place in any country outside the European Economic Area (and outside an “adequate country”), the Parties agree that the European Commission’s Standard Contractual Clauses for the transfer of Personal Data as set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 as well as other the standard contractual clauses approved by the European Commission, the UK Information Commissioner’s Office or another relevant data protection authority from time to time time will apply in respect of that processing between Sidetrade and the sub-processor. In this case, Sidetrade will be authorized to execute these standard contractual clauses approved by the EU authorities under EU data protection laws in the name and on behalf of Customer.
CUSTOMER’S OBLIGATIONS
12.1 Customer will deal with all requests from a data subject relating to his right to access, rectify, erase, oppose, benefit from a data portability or any other right in respect of such personal data.
12.2 Customer shall provide Sidetrade with reasonable information in relation to any processing of personal data and, in the case Customer changes the purposes and means of the processing of personal data, it shall inform Sidetrade accordingly so that the processing continues to take into account the nature, scope, context and purposes of processing. In particular, Customer must not process special categories of personal data covered by article 9 of the GDPR or process data with high likelihood and severity for the rights and freedoms of natural persons, without warning accordingly Sidetrade, in writings and in advance. To the extent legally permitted, Customer shall be responsible for any possible cost arising from such a situation.
BUSINESS CONTACT DATA.
Sidetrade processes personal data, as the controller, for the purpose of managing the contractual and administrative relationships with its clients (invoicing, contractual and pre-sales processes). The data collected are essential for the processing and are intended for the departments concerned of Sidetrade and, if applicable, for its subcontractors and providers. The data collected may be transferred to Supplier’s parent company or to third companies. Data transfer agreements have been implemented to manage these transborder flows and guarantee a sufficient level of protection. In accordance with the GDPR, the Customer contributors have a right to inquire about, access and rectify all of their data and to object to their processing on legitimate grounds. Customer contributors may exercise these rights by sending an e-mail at privacy@sidetrade.com, together with a copy of an identity document
GENERAL TERMS
14.1 Except as amended by this Data Processing Addendum, the Agreement will remain in full force and effect.
14.2 If there is an express conflict between the General Terms and Conditions of the Agreement and this Data Processing Addendum, the term of this Data Processing Addendum shall prevail.
II – PERSONAL DATA CONVEYED BY SIDETRADE TO CUSTOMER
For personal data conveyed by Sidetrade, from its own databases, to Customer, Sidetrade will grant Customer a non-exclusive, non-sublicensable, non-assignable, non-transferable right to access personal data for the agreed limited term, for the European Union and for the sole purpose of Customer’s professional direct marketing B2B (business to business) activity for its own products and services.
In using the personal data conveyed by Sidetrade, Customer acts as a controller. In consequence, Customer must take every necessary measure and ensure that its use of the personal data will comply with the European data protection laws regarding, in particular, the principles relating to processing of personal data, the information of data subjects and the exercise of their rights by data subjects. In particular, Customer:
a) will not make the personal data available to any unauthorized third party or license, sell, rent, lease, transfer, assign, republish, distribute or display them in any manner not expressly permitted by Sidetrade under the Agreement,
b) has appropriate operational and technical processes in place in line with industry standard practice to safeguard personal data against any unauthorized access, loss, destruction, theft, use or disclosure and will ensure the entire protection and safeguard of the conveyed personal data,
c) will not use the personal data for any purposes or in any manner that is illegal or improper, in particular to illegally spam directly or indirectly anyone,
d) will comply with all relevant direct marketing legislation or regulation and in particular with article 95 of the GDPR and Directive 2002/58/EC of the European Parliament and of the council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector or any future Regulation repealing Directive 2002/58/EC (clear indication of its full identity in any direct marketing message, existence of a direct link with the professional activities of the recipients, information of the recipients that they have the right to object, free of charge and through an easy to use mechanism, …) and any possible subsequent legislation,
e) will immediately stop from using all personal data concerned by an exercised right to object and inform Sidetrade of any objection.
Sidetrade may update the personal data, from time to time, depending on exercised right to object, available data sources or obligation to comply with an order, instruction or request of an administrative authority or a court.
Customer acknowledges that Sidetrade has no control over the actual use that Customer makes, under its sole responsibility, of the personal data.
Sidetrade gives no warranties that the personal data will be complete or will meet Customer’s expectations or requirements. Sidetrade shall not be liable for any claim arising out of inappropriate or unauthorized use of the personal data, including spamming. Customer is liable to Sidetrade for any damage (direct, indirect, material or immaterial) caused to Sidetrade or to any third party resulting from the non-compliance of its legal and contractual obligations relating to its B2B direct marketing activities.
↑