Third Party Index

Snapshot 64813

Document
Data processing addendum
URL
https://drive.google.com/file/d/12sKw8V2PKSo_fehTUunfvMA4euSX79Yn/view
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
266651 bytes
SHA-256 (raw)
7cf5bb2ce8ad20febd36c0c52f57b741767a99c4c25abedb3d8ea00017576fee
SHA-256 (normalized text)
7d846f2ebd091ad5d5e79263681105f10b5a0d49064b6109a7ebb5bd2149c2d8

Normalized text

Scripts and page chrome removed; this is what change detection compares.

DATA PROCESSING AGREEMENT (DPA).pdf
DownloadCtrl+D
DetailsD
PrintCtrl+P
Show
Comments
Zoom
FindCtrl+F
Send feedback to Google
Report abuse
Keyboard shortcutsCtrl+/
Page
/5
Approve
Reject
View Details
Request a review
Learn more
Signature pending
Sign
Reject
View details
Review
Not Spam
Remove forever
Not Spam
{"id": "12sKw8V2PKSo_fehTUunfvMA4euSX79Yn", "title": "DATA PROCESSING AGREEMENT (DPA).pdf", "mimeType": "application\/pdf"}
Page 1 of 5
DATA PROCESSING AGREEMENT (DPA)
Between
Squivr, Inc. (“Squivr”)
and
Customer (“Customer”)
Effective Date: [Insert Effective Date]
Governing Law: State of Colorado, United States
1. Purpose and Scope
This Data Processing Agreement (“Agreement”) sets forth the terms and conditions governing
the handling, protection, and security of data in connection with Squivr’s Salesforce-native
applications (“Services”).
Squivr does not process or store Customer Data directly. All Customer Data is managed within
Salesforce’s secure infrastructure. This Agreement is designed to:
• Demonstrate Squivr’s adherence to applicable data protection and privacy laws;
• Clarify the respective responsibilities of Squivr and Customer; and
• Provide transparency regarding Squivr’s architecture, use of subprocessors, and security
controls.
This Agreement supplements and forms part of any existing master subscription, licensing, or
service agreement between the parties.
2. Definitions
For the purposes of this Agreement:
• “Applicable Law” means all data protection and privacy laws applicable to the parties,
including the GDPR, CCPA, and related regulations.
• “Customer Data” means any data or information entered, uploaded, or otherwise
provided by Customer into the Salesforce environment in connection with Squivr’s
applications.
Page 2 of 5
• “Salesforce” refers to Salesforce, Inc., the platform provider hosting and processing all
Customer Data under its own compliance frameworks.
• “Subprocessor” means any third party engaged by Squivr to support the delivery of its
applications.
• “Force Majeure Event” means circumstances beyond a party’s reasonable control that
prevent or delay performance, such as natural disasters, acts of war, pandemics, or
internet outages.
3. Roles and Responsibilities
3.1 Customer Role
Customer retains ownership and control over all Customer Data and acts as the data controller
for any personal data processed within its Salesforce environment.
3.2 Squivr Role
Squivr acts as a software provider, not as a data processor or controller. Squivr’s Salesforce- native applications execute entirely within the Customer’s Salesforce instance, using the
Customer’s own data access permissions. Squivr does not store, export, or process personal data
outside Salesforce.
3.3 Salesforce Role
Salesforce acts as the hosting and processing entity for Customer Data. Salesforce is responsible
for maintaining compliance with its own certifications and frameworks, including ISO 27001,
SOC 2, GDPR, and CCPA requirements.
4. Data Protection and Security
Squivr implements security measures consistent with industry best practices and applicable
standards, including:
• Secure Development: All applications follow OWASP and NIST frameworks to
minimize vulnerabilities.
• Access Controls: Role-based access controls (RBAC) limit access to development
environments to authorized personnel only.
• Endpoint Security: Encryption, antivirus, and EDR tools are deployed on all endpoints.
Page 3 of 5
• Incident Management: Squivr maintains a structured process for identifying, assessing,
and resolving security incidents that could indirectly impact Customer Data.
Squivr’s security commitments are continuously reviewed and updated in line with regulatory
developments and Salesforce platform changes.
5. Artificial Intelligence and Machine Learning (AI/ML)
Squivr’s approach to artificial intelligence (“AI”) and automation—including any use of
Salesforce Agentforce or similar rule-based AI functionality—is designed and operated in full
compliance with applicable privacy and data protection laws.
• Rule-Based AI Only: Squivr’s applications utilize rule-based AI systems that operate
through deterministic logic and predefined workflows within the Salesforce environment.
These systems do not involve generative AI, predictive modeling, or autonomous
learning components.
• No External Model Use: Squivr does not use external AI or ML models, third-party data- training services, or external inference engines in connection with its Services.
• No Data Transfer or External Training: Squivr does not use Customer Data to train or
improve any AI/ML model, nor does it transfer or replicate such data outside the
Salesforce environment.
• Operational Transparency and Control: Any AI-enabled functionality is fully transparent,
rule-based, and configurable by the Customer, ensuring complete visibility into its
operation and logic.
Squivr remains committed to ensuring that all AI-related activity adheres to the principles of
lawfulness, fairness, transparency, accountability, and auditability, consistent with global privacy
standards and Salesforce’s governance framework.
6. Liability and Indemnification
Each party’s total aggregate liability under this Agreement shall not exceed the total fees paid by
Customer to Squivr under the main services agreement during the twelve (12) months preceding
the event giving rise to the claim.
Neither party shall be liable for indirect, consequential, or punitive damages, including loss of
profits, revenue, or business opportunities.
Displaying DATA PROCESSING AGREEMENT (DPA).pdf. Page 1 of 5