Third Party Index

Snapshot 67117

Document
Data processing addendum
URL
https://www.explorium.ai/data-processing-addendum/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
153521 bytes
SHA-256 (raw)
665a1b2901800fbdb669c31916db0f6c163b01ee11a8e4d6f4e364605801ad5a
SHA-256 (normalized text)
6a3e7dacfd647efc18df8616f6e7b2f269fb223d9ffa97689b4f323f407b57ac

Normalized text

Scripts and page chrome removed; this is what change detection compares.

ֿData Processing Addendum
Updated November 2024
This Data Processing Addendum (“DPA”) applies as between Explorium, Inc. (“Explorium”) and the entity
engaging with Explorium as a customer (“Customer”), under the Order Form and Terms and Conditions
available here (the “Agreement”) pursuant to which Explorium provides Customer access to use
Explorium’s data science platform designed to help Customer to improve its data prediction models (the
“Platform”).
In consideration of the mutual obligations set out herein, the parties hereby agree that the terms and
conditions set out below:
Definitions.
1.1. “Data Protection Laws” means, to the extent applicable to the Customer: (i) Regulation (EU)
2016/679 General Data Protection Regulation (“GDPR”); (ii) the California Consumer Privacy Act
of 2018, the California Privacy Rights Act of 2020 and the regulations adopted thereunder Cal.
Civ. Code §§ 1798.100 et. seq. and 11 C.C.R §§7000 et. seq. (“California Privacy Law”).
1.2. “SCCs” means the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021
on standard contractual clauses for the transfer of personal data to third countries pursuant to
Regulation (EU) 2016/679 of the European Parliament and of the Council, incorporated hereto
by reference.
1.3. Capitalized terms used in this DPA but not defined herein or in the Agreement have the meaning
ascribed to them in the GDPR and the California Privacy Law.
Scope and responsibilities.
2.1. This DPA applies where Explorium Processes Personal Data as a Data Processor or Service
Provider on behalf of the Customer and under the Customer’s instructions, where the Customer
is a Data Controller subject to the GDPR with respect to the Personal Data that Explorium
Processes, or a Business subject to the California Privacy Law with respect to the Personal
Information that Explorium Processes. Whether the Customer is a Business as defined in the
California Privacy Law is determined according to the provisions of the California Privacy Law
and not this DPA. Nothing in this DPA shall be interpreted as a determination, representation,
acknowledgment, or admission that the Customer is a Business, or that the Customer, if not
otherwise subject to the California Privacy Law as a Business, voluntarily certifies that it is in
compliance with and agrees to be bound by the California Privacy Law.
2.2. Nothing in this DPA requires Explorium either to disclose to Customer or provide access to: (i)
any data of any other customer of Explorium; (ii) Explorium’s internal accounting or financial
information; (iii) any trade secret of Explorium; or (iv) any information that, in Explorium’s
discretion, could compromise the security of any of Explorium’s systems or premises or cause
Explorium to breach obligations under applicable law or its obligations to any third party.
2.3. The Customer and Explorium are each responsible for complying with Data Protection Laws as
applicable to them, in their roles as Data Controller (or Business (under the California Privacy
Law) and Data Processor (or Service Provider (under the California Privacy Law), respectively.
Customer represents and warrants to Explorium that Customer’s collection and Processing of
the Personal Data and its provision of the Personal Data to Explorium for Processing as per this
DPA, is made pursuant to legal basis recognized under the GDPR, fully complies with Data
Protection Laws and will continue to comply therewith throughout the duration of the
Customer’s use of the Platform.
2.4. Explorium will make available to Customer all reasonable information in its disposal necessary
to demonstrate compliance with the obligations under the Data Protection Laws.
2.5. Explorium will assist Customer with the preparation of data privacy impact assessments and
prior consultation as appropriate, provided, however, that if such assistance entails material
costs or expenses to Explorium, the parties shall first come to agreement on Customer
reimbursing Explorium for such costs and expenses.
2.6. Explorium will provide Customer prompt notice of any request it receives from authorities to
produce or disclose Personal Data it has Processed on Customer’s behalf, so that Customer may
contest or attempt to limit the scope of production or disclosure request.
Specifics of Processing.
3.1. The particulars of Explorium’s Processing activities as a Processor are specified in Appendix 1.
3.2. Explorium will Process the Personal Data only on Customer’s behalf and for as long as Customer
instructs Explorium to do so, for the purpose of providing the Platform to the Customer.
Explorium shall not Process the Personal Data for any other purpose. However, with respect to
Personal Information subject to the California Privacy Law and not subject to the GDPR,
Explorium may engage in any other Processing activities that the California Privacy Law permits
Service Providers to engage in.
3.3. Explorium will Process the Personal Data only on documented instructions from the Customer,
including without limitation through the commercial agreement any applicable SOW or via the
Platform, or as required to enrich the Customer Data pursuant to the commercial agreement
unless Explorium is otherwise required to do so by law to which it is subject (and in such a case,
Explorium shall inform the Customer of that legal requirement before processing, unless that
law prohibits such information on important grounds of public interest). Customer’s instructions
to Explorium must be consistent with the nature of character of the Platform. The Customer is
solely responsible for determining the lawfulness of the data processing instructions it provides
to Explorium and shall provide Explorium only instructions that are lawful under the GDPR.
Explorium shall immediately inform the Customer if, in Explorium’s opinion, an instruction is in
violation the GDPR or if Explorium makes a determination that it can no longer meet its
obligations under the California Privacy Law.
3.4. Explorium deletes the Personal Data it has Processed on Customer’s behalf under this DPA from
its systems, shortly after the end of the term of the Agreement or upon written request from
Customer, and upon Customer’s request, will furnish written confirmation that the Personal
Data has been deleted pursuant to this section.
Data Subject rights.
4.1. Customer bears the sole and exclusive responsibility to comply with Data Subject rights,
including accessing their data, correcting it, restricting its processing or deleting it. Taking into
account the nature of Explorium’s Processing activities and the Platform, Explorium will assist
the Customer to accommodate Data Subjects’ requests to exercise their rights in relation to
their Personal Data. Explorium will pass on to Customer requests that it receives from Data
Subjects regarding their Personal Data Processed by Explorium.
Subprocessing.
5.1. Customer hereby extends its general authorization to Explorium to use third party
subprocessors for Processing Personal Data within the scope of the Platform. . The current
subprocessors are listed in Section 4.11 of Exhibit 2. The list will also be available online.
Explorium may update the list from time to time, adding, removing or replacing subprocessors.
The updated list of subprocessors posted online will indicate the date on which the list has
changed.
5.2. Explorium will procure that the subprocessors Process the Personal Data in a manner consistent
with Explorium’s obligations under this DPA and Data Protection Laws, particularly Article 28 of
the GDPR, with such obligations imposed on that subprocessor by way of a written contract, in
particular providing sufficient guarantees to implement appropriate technical and organizational
measures in such a manner that the processing will meet the requirements of the GDPR.
Explorium’s remains liable to the Customer for the subprocessors’ compliance with their
obligations.
Cross-border data transfers.
6.1. Customer acknowledges and agrees that Explorium and its subprocessors will only Process the
Personal Data in member states of the European Economic Area, in territories or territorial
sectors recognized by an adequacy decision of the European Commission as providing an
adequate level of protection for Personal Data pursuant to Articles 45 of the GDPR, or using
adequate safeguards as required under the GDPR’s provisions governing cross-border data
transfers (e.g., SCCs).
6.2. Explorium is situated in a territory not recognized by an adequacy decision of the European
Commission as providing an adequate level of protection for Personal Data pursuant to Articles
45 of the GDPR. Therefore, the parties hereby enter into MODULE TWO of the SCCs, as specified
in Appendix 2.
Data security.
7.1. In Processing Personal Data, Explorium will implement appropriate technical and organizational
measures to protect the Personal Data against accidental or unlawful destruction or accidental
loss, alteration, unauthorized disclosure or access, in accordance with Explorium’s ISO 27001
and SOC-2 certifications and in accordance with Cal. Civ. Code §1798.81.5. Explorium shall
perform regular internal or third-party assessments, audits, or other technical and operational
testing of its security procedures and practices at least once every 12 months.
7.2. Explorium will ensure that its staff authorized to Process the Personal Data have committed
themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
7.3. Explorium shall without undue delay notify Customer of any Personal Data Breach that it
becomes aware of regarding Personal Data of Data Subjects that Explorium Processes within the
scope of this DPA. Explorium will use commercial efforts to mitigate the breach and prevent its
recurrence. Customer and Explorium will cooperate in good-faith on issuing any statements or
notices regarding such breaches, to authorities and Data Subjects.
Audits.
8.1. Notwithstanding the foregoing, to the extent Explorium has undergone a third party
independent audit based on SOC 2, Type II or similar standards, then any audit or inspection
right exercisable by the Customer shall be first satisfied by Explorium providing the Customer
with a report of such audit. If Customer, is not satisfied on reasonable grounds by the
independent audit report, then Customer may request that a reputable auditor perform an
audit or inspection pursuant to Section ‎8.2 below and Explorium shall not unreasonably deny
that request. If Explorium nevertheless denies such audit or inspection, then Customer shall
have the right to terminate the Agreement with immediate effect.
8.2. Subject to Section ‎8.1 above, Explorium shall, not more than once per annum (unless otherwise
required by a data protection authority or Data Protection Law), allow for and contribute to
audits, including carrying out inspections conducted by a reputable auditor mandated by
Customer, during normal business hours and subject to a prior notice to Explorium of at least 30
days as well as appropriate confidentiality undertakings by the auditor covering such
inspections, in order to establish Explorium’s compliance with this DPA and the provisions of the
Data Protection Laws as regards the Personal Data that Explorium Processes on behalf of
Customer. Such audits and inspection must reasonably limit any disruption to Explorium’s
business, and the Customer shall avoid (and ensure that each of its auditors avoids) causing (or,
if it cannot avoid, minimize) any damage, injury or disruption to Explorium’s premises,
equipment, personnel and business while its personnel are on those premises in the course of
such audit or inspection. If such audits or inspections entail material costs or expenses to
Explorium, the parties shall first come to agreement on Customer reimbursing Explorium for
such costs and expenses.
California Privacy Law.
This Section 9 applies to the extent that the Customer is a Business subject to the California Privacy Law.
9.1. The Parties acknowledge and agree that Explorium is a Service Provider. The provisions of this
DPA also apply to Explorium’s Processing of Personal Information as a Service Provider of the
Customer.
9.2. The Parties agree that the Customer is disclosing the Personal Information to Explorium only for
the following limited and specified Business Purpose: the provision of Explorium’s data analysis
and enrichment platform. Explorium shall not Sell or Share the Personal Information.
9.3. Explorium is prohibited from retaining, using or disclosing Customer’s Personal Information for:
9.3.1. Any commercial purpose other than the foregoing Business Purposes, unless expressly
permitted by the California Privacy Law.
OR
9.3.2. Outside the direct business relationship between Customer and Explorium, unless
expressly permitted by the California Privacy Law.
9.4. Explorium shall comply with all applicable sections of the California Privacy Law.
9.5. Explorium grants the Customer the right to take reasonable and appropriate steps, in
accordance with this DPA, to ensure that the Explorium uses the Personal Information it Collects
pursuant to this DPA in a manner consistent with Explorium’s obligations under the California
Privacy Law.
9.6. Explorium grants the Customer the right, upon notice, to take reasonable and appropriate steps,
in accordance with this DPA, to stop and remediate Explorium’s unauthorized use of Personal
Information.
9.7. If Explorium receives a request from a California Consumer of the Customer, about his or her
Personal Information, Explorium shall inform the Customer thereof, shall not comply with the
request itself unless instructed to in writing by the Customer, and in the absence of Customer’s
instructions to the contrary, shall inform the Consumer that the request cannot be acted upon
because the request has been sent to a Service Provider.
Miscellaneous.
10.1. Explorium’s liability under this DPA shall be as per the limitations, exclusions and caps specified
in the Agreement.
10.2. This DPA shall prevail in the event of inconsistencies between it and the Agreement or
subsequent agreements entered into or purported to be entered into by the parties after the
date of this DPA – except where explicitly agreed otherwise in writing.
10.3. This DPA is governed by the governing law specified in the Agreement, and disputes arising
under this DPA shall be adjudicated as specified in the Agreement.
10.4. This DPA terminated upon the termination of the Agreement.
Appendix 1
Nature and purpose of the Processing
The nature and purpose of Processing is the provision of Explorium’s data science platform that helps Customer to improve its data prediction models.
Duration of Processing
The duration of Processing is coterminous with the term of the Agreement and to Customer’s instructions to cease and discontinue Processing.
Categories of Personal Data Processed
Names, contact details, business affiliation
Special categories of Personal Data Processed
None
Categories of Data Subjects
Representatives of the customers and prospective customers of the Customer.
Processing operations
The Processing operations entailed in the provision of the Platform are: organization and structuring, analysis, adaptation or alteration, storage, retrieval, consultation, use, enrichment from external sources, transmission, dissemination or otherwise making available, alignment or combination, and erasure.
Appendix 2
In Section II (Obligations of the Parties), Clause 9(a) for MODULE TWO: GENERAL WRITTEN AUTHORISATION. The data importer has the data exporter’s general authorisation for the engagement of sub-processor(s) from an agreed list.
In Section IV (Final Provisions), Clause 17 for MODULE TWO: Transfer controller to processor: The parties agree that this shall be the law of Ireland.
In Section IV (Final Provisions), Clause 18(b) for MODULE TWO: Transfer controller to processor: The parties agree that those shall be the courts of Ireland.
In Annex I, for MODULE TWO: Transfer controller to processor:
Data Exporter: Customer.
Activities relevant to the data transferred under these Clauses: an organization using the Platform
Role: controller
Data Importer: Explorium.
Activities relevant to the data transferred under these Clauses: provider and operator of the Platform.
Role: processor.
Description of Transfer: personal data transferred in the course of and for the purpose of providing the Platform.
Categories of personal data transferred: See Appendix 1.
Categories of data subjects whose personal data is transferred: See Appendix 1.
Sensitive data transferred: See Appendix 1.
The frequency of the transfer: ongoing.
Nature of the processing: See Appendix 1.
Purpose(s) of the data transfer and further processing: See Appendix 1.
The period for which the personal data will be retained: See Appendix 1.
Transfers to (sub-) processors:
List of Explorium Sub-Processors
Infrastructure Sub-processors
Entity Name	Subprocessing Activities	Country of Storage	Duration of transfer
Amazon Web Services	Cloud hosting and storage	United States	As specified in 4.10 above
Google Cloud Platform	Cloud hosting and API Services	United States	As specified in 4.10 above
Databricks Inc.	Data analytics platform	United States	As specified in 4.10 above
DataDog	Monitoring and observability	United States	As specified in 4.10 above
CloudFlare, Inc.	Content delivery network, security	United States	As specified in 4.10 above
Pusher Ltd.	Real-time messaging services	United States	As specified in 4.10 above
Auth0 By Okta, inc.	Authentication services	United States	As specified in 4.10 above
MongoDB, Inc.	Database management	United States	As specified in 4.10 above
Product Communications Sub-processors
Entity Name	Subprocessing Activities	Country of Storage	Duration of transfer
SendGrid	Email delivery service	United States	As specified in 4.10 above
FullStory	Session replay and user analytics	United States	As specified in 4.10 above
MixPanel	Product analytics platform	United States	As specified in 4.10 above
HubSpot	CRM and marketing automation	United States	As specified in 4.10 above
Gong	sales call recording, and analytics	United States	As specified in 4.10 above
Metadata, inc.	marketing and campaign automation, management	United States	As specified in 4.10 above
Outreach	Sales engagement platform	United States	As specified in 4.10 above
Zapier Inc.	Workflow automation	United States	As specified in 4.10 above
Zoom Video Communications, Inc.	Video conferencing, virtual meetings	United States	As specified in 4.10 above
Serp.API, LLC	Data product	United Stated	As specified in 4.10 above
Nimble, Inc.	Data Product	United States	As specified in Section 4.10 above.
Hertza LLC (Zerobounce)	Email validation	United Stated/ EU	As specified in Section 4.10 above.
Open.ai	LLM engine	United States	As specified in Section 4.10 above.
Anthropic	LLM engine	United States	As specified in Section 4.10 above.
Gemini	LLM engine	United States	As specified in Section 4.10 above.
Product Monitoring and Testing Sub-processors
Entity Name	Subprocessing Activities	Country of Storage	Duration of transfer
Atlassian	Collaboration and issue tracking	United States	As specified in Section 4.10 above.
Monday	Project management platform	United States	As specified in Section 4.10 above.
LambdaTest	Cross-browser testing	United States	As specified in Section 4.10 above.
Customer Support Sub-processors
Entity Name	Subprocessing Activities	Country of Storage	Duration of transfer
Slack	communication tool	United States	As specified in Section 4.10 above.
Competent Supervisory Authority: the supervisory authority in the EU member state where the data exporter is established or where its EU representative under Article 27 of the GDPR is located.
In Annex II, for MODULE TWO: Transfer controller to processor: as detailed in the data importer’s ISO 27001 and SOC-2 reports and certifications (subject to data importer’s right to redact from such report any information that would identify another customer or expose confidential information of another client).