Snapshot 67117
Normalized text
Scripts and page chrome removed; this is what change detection compares.
ֿData Processing Addendum Updated November 2024 This Data Processing Addendum (“DPA”) applies as between Explorium, Inc. (“Explorium”) and the entity engaging with Explorium as a customer (“Customer”), under the Order Form and Terms and Conditions available here (the “Agreement”) pursuant to which Explorium provides Customer access to use Explorium’s data science platform designed to help Customer to improve its data prediction models (the “Platform”). In consideration of the mutual obligations set out herein, the parties hereby agree that the terms and conditions set out below: Definitions. 1.1. “Data Protection Laws” means, to the extent applicable to the Customer: (i) Regulation (EU) 2016/679 General Data Protection Regulation (“GDPR”); (ii) the California Consumer Privacy Act of 2018, the California Privacy Rights Act of 2020 and the regulations adopted thereunder Cal. Civ. Code §§ 1798.100 et. seq. and 11 C.C.R §§7000 et. seq. (“California Privacy Law”). 1.2. “SCCs” means the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, incorporated hereto by reference. 1.3. Capitalized terms used in this DPA but not defined herein or in the Agreement have the meaning ascribed to them in the GDPR and the California Privacy Law. Scope and responsibilities. 2.1. This DPA applies where Explorium Processes Personal Data as a Data Processor or Service Provider on behalf of the Customer and under the Customer’s instructions, where the Customer is a Data Controller subject to the GDPR with respect to the Personal Data that Explorium Processes, or a Business subject to the California Privacy Law with respect to the Personal Information that Explorium Processes. Whether the Customer is a Business as defined in the California Privacy Law is determined according to the provisions of the California Privacy Law and not this DPA. Nothing in this DPA shall be interpreted as a determination, representation, acknowledgment, or admission that the Customer is a Business, or that the Customer, if not otherwise subject to the California Privacy Law as a Business, voluntarily certifies that it is in compliance with and agrees to be bound by the California Privacy Law. 2.2. Nothing in this DPA requires Explorium either to disclose to Customer or provide access to: (i) any data of any other customer of Explorium; (ii) Explorium’s internal accounting or financial information; (iii) any trade secret of Explorium; or (iv) any information that, in Explorium’s discretion, could compromise the security of any of Explorium’s systems or premises or cause Explorium to breach obligations under applicable law or its obligations to any third party. 2.3. The Customer and Explorium are each responsible for complying with Data Protection Laws as applicable to them, in their roles as Data Controller (or Business (under the California Privacy Law) and Data Processor (or Service Provider (under the California Privacy Law), respectively. Customer represents and warrants to Explorium that Customer’s collection and Processing of the Personal Data and its provision of the Personal Data to Explorium for Processing as per this DPA, is made pursuant to legal basis recognized under the GDPR, fully complies with Data Protection Laws and will continue to comply therewith throughout the duration of the Customer’s use of the Platform. 2.4. Explorium will make available to Customer all reasonable information in its disposal necessary to demonstrate compliance with the obligations under the Data Protection Laws. 2.5. Explorium will assist Customer with the preparation of data privacy impact assessments and prior consultation as appropriate, provided, however, that if such assistance entails material costs or expenses to Explorium, the parties shall first come to agreement on Customer reimbursing Explorium for such costs and expenses. 2.6. Explorium will provide Customer prompt notice of any request it receives from authorities to produce or disclose Personal Data it has Processed on Customer’s behalf, so that Customer may contest or attempt to limit the scope of production or disclosure request. Specifics of Processing. 3.1. The particulars of Explorium’s Processing activities as a Processor are specified in Appendix 1. 3.2. Explorium will Process the Personal Data only on Customer’s behalf and for as long as Customer instructs Explorium to do so, for the purpose of providing the Platform to the Customer. Explorium shall not Process the Personal Data for any other purpose. However, with respect to Personal Information subject to the California Privacy Law and not subject to the GDPR, Explorium may engage in any other Processing activities that the California Privacy Law permits Service Providers to engage in. 3.3. Explorium will Process the Personal Data only on documented instructions from the Customer, including without limitation through the commercial agreement any applicable SOW or via the Platform, or as required to enrich the Customer Data pursuant to the commercial agreement unless Explorium is otherwise required to do so by law to which it is subject (and in such a case, Explorium shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest). Customer’s instructions to Explorium must be consistent with the nature of character of the Platform. The Customer is solely responsible for determining the lawfulness of the data processing instructions it provides to Explorium and shall provide Explorium only instructions that are lawful under the GDPR. Explorium shall immediately inform the Customer if, in Explorium’s opinion, an instruction is in violation the GDPR or if Explorium makes a determination that it can no longer meet its obligations under the California Privacy Law. 3.4. Explorium deletes the Personal Data it has Processed on Customer’s behalf under this DPA from its systems, shortly after the end of the term of the Agreement or upon written request from Customer, and upon Customer’s request, will furnish written confirmation that the Personal Data has been deleted pursuant to this section. Data Subject rights. 4.1. Customer bears the sole and exclusive responsibility to comply with Data Subject rights, including accessing their data, correcting it, restricting its processing or deleting it. Taking into account the nature of Explorium’s Processing activities and the Platform, Explorium will assist the Customer to accommodate Data Subjects’ requests to exercise their rights in relation to their Personal Data. Explorium will pass on to Customer requests that it receives from Data Subjects regarding their Personal Data Processed by Explorium. Subprocessing. 5.1. Customer hereby extends its general authorization to Explorium to use third party subprocessors for Processing Personal Data within the scope of the Platform. . The current subprocessors are listed in Section 4.11 of Exhibit 2. The list will also be available online. Explorium may update the list from time to time, adding, removing or replacing subprocessors. The updated list of subprocessors posted online will indicate the date on which the list has changed. 5.2. Explorium will procure that the subprocessors Process the Personal Data in a manner consistent with Explorium’s obligations under this DPA and Data Protection Laws, particularly Article 28 of the GDPR, with such obligations imposed on that subprocessor by way of a written contract, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of the GDPR. Explorium’s remains liable to the Customer for the subprocessors’ compliance with their obligations. Cross-border data transfers. 6.1. Customer acknowledges and agrees that Explorium and its subprocessors will only Process the Personal Data in member states of the European Economic Area, in territories or territorial sectors recognized by an adequacy decision of the European Commission as providing an adequate level of protection for Personal Data pursuant to Articles 45 of the GDPR, or using adequate safeguards as required under the GDPR’s provisions governing cross-border data transfers (e.g., SCCs). 6.2. Explorium is situated in a territory not recognized by an adequacy decision of the European Commission as providing an adequate level of protection for Personal Data pursuant to Articles 45 of the GDPR. Therefore, the parties hereby enter into MODULE TWO of the SCCs, as specified in Appendix 2. Data security. 7.1. In Processing Personal Data, Explorium will implement appropriate technical and organizational measures to protect the Personal Data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, in accordance with Explorium’s ISO 27001 and SOC-2 certifications and in accordance with Cal. Civ. Code §1798.81.5. Explorium shall perform regular internal or third-party assessments, audits, or other technical and operational testing of its security procedures and practices at least once every 12 months. 7.2. Explorium will ensure that its staff authorized to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. 7.3. Explorium shall without undue delay notify Customer of any Personal Data Breach that it becomes aware of regarding Personal Data of Data Subjects that Explorium Processes within the scope of this DPA. Explorium will use commercial efforts to mitigate the breach and prevent its recurrence. Customer and Explorium will cooperate in good-faith on issuing any statements or notices regarding such breaches, to authorities and Data Subjects. Audits. 8.1. Notwithstanding the foregoing, to the extent Explorium has undergone a third party independent audit based on SOC 2, Type II or similar standards, then any audit or inspection right exercisable by the Customer shall be first satisfied by Explorium providing the Customer with a report of such audit. If Customer, is not satisfied on reasonable grounds by the independent audit report, then Customer may request that a reputable auditor perform an audit or inspection pursuant to Section 8.2 below and Explorium shall not unreasonably deny that request. If Explorium nevertheless denies such audit or inspection, then Customer shall have the right to terminate the Agreement with immediate effect. 8.2. Subject to Section 8.1 above, Explorium shall, not more than once per annum (unless otherwise required by a data protection authority or Data Protection Law), allow for and contribute to audits, including carrying out inspections conducted by a reputable auditor mandated by Customer, during normal business hours and subject to a prior notice to Explorium of at least 30 days as well as appropriate confidentiality undertakings by the auditor covering such inspections, in order to establish Explorium’s compliance with this DPA and the provisions of the Data Protection Laws as regards the Personal Data that Explorium Processes on behalf of Customer. Such audits and inspection must reasonably limit any disruption to Explorium’s business, and the Customer shall avoid (and ensure that each of its auditors avoids) causing (or, if it cannot avoid, minimize) any damage, injury or disruption to Explorium’s premises, equipment, personnel and business while its personnel are on those premises in the course of such audit or inspection. If such audits or inspections entail material costs or expenses to Explorium, the parties shall first come to agreement on Customer reimbursing Explorium for such costs and expenses. California Privacy Law. This Section 9 applies to the extent that the Customer is a Business subject to the California Privacy Law. 9.1. The Parties acknowledge and agree that Explorium is a Service Provider. The provisions of this DPA also apply to Explorium’s Processing of Personal Information as a Service Provider of the Customer. 9.2. The Parties agree that the Customer is disclosing the Personal Information to Explorium only for the following limited and specified Business Purpose: the provision of Explorium’s data analysis and enrichment platform. Explorium shall not Sell or Share the Personal Information. 9.3. Explorium is prohibited from retaining, using or disclosing Customer’s Personal Information for: 9.3.1. Any commercial purpose other than the foregoing Business Purposes, unless expressly permitted by the California Privacy Law. OR 9.3.2. Outside the direct business relationship between Customer and Explorium, unless expressly permitted by the California Privacy Law. 9.4. Explorium shall comply with all applicable sections of the California Privacy Law. 9.5. Explorium grants the Customer the right to take reasonable and appropriate steps, in accordance with this DPA, to ensure that the Explorium uses the Personal Information it Collects pursuant to this DPA in a manner consistent with Explorium’s obligations under the California Privacy Law. 9.6. Explorium grants the Customer the right, upon notice, to take reasonable and appropriate steps, in accordance with this DPA, to stop and remediate Explorium’s unauthorized use of Personal Information. 9.7. If Explorium receives a request from a California Consumer of the Customer, about his or her Personal Information, Explorium shall inform the Customer thereof, shall not comply with the request itself unless instructed to in writing by the Customer, and in the absence of Customer’s instructions to the contrary, shall inform the Consumer that the request cannot be acted upon because the request has been sent to a Service Provider. Miscellaneous. 10.1. Explorium’s liability under this DPA shall be as per the limitations, exclusions and caps specified in the Agreement. 10.2. This DPA shall prevail in the event of inconsistencies between it and the Agreement or subsequent agreements entered into or purported to be entered into by the parties after the date of this DPA – except where explicitly agreed otherwise in writing. 10.3. This DPA is governed by the governing law specified in the Agreement, and disputes arising under this DPA shall be adjudicated as specified in the Agreement. 10.4. This DPA terminated upon the termination of the Agreement. Appendix 1 Nature and purpose of the Processing The nature and purpose of Processing is the provision of Explorium’s data science platform that helps Customer to improve its data prediction models. Duration of Processing The duration of Processing is coterminous with the term of the Agreement and to Customer’s instructions to cease and discontinue Processing. Categories of Personal Data Processed Names, contact details, business affiliation Special categories of Personal Data Processed None Categories of Data Subjects Representatives of the customers and prospective customers of the Customer. Processing operations The Processing operations entailed in the provision of the Platform are: organization and structuring, analysis, adaptation or alteration, storage, retrieval, consultation, use, enrichment from external sources, transmission, dissemination or otherwise making available, alignment or combination, and erasure. Appendix 2 In Section II (Obligations of the Parties), Clause 9(a) for MODULE TWO: GENERAL WRITTEN AUTHORISATION. The data importer has the data exporter’s general authorisation for the engagement of sub-processor(s) from an agreed list. In Section IV (Final Provisions), Clause 17 for MODULE TWO: Transfer controller to processor: The parties agree that this shall be the law of Ireland. In Section IV (Final Provisions), Clause 18(b) for MODULE TWO: Transfer controller to processor: The parties agree that those shall be the courts of Ireland. In Annex I, for MODULE TWO: Transfer controller to processor: Data Exporter: Customer. Activities relevant to the data transferred under these Clauses: an organization using the Platform Role: controller Data Importer: Explorium. Activities relevant to the data transferred under these Clauses: provider and operator of the Platform. Role: processor. Description of Transfer: personal data transferred in the course of and for the purpose of providing the Platform. Categories of personal data transferred: See Appendix 1. Categories of data subjects whose personal data is transferred: See Appendix 1. Sensitive data transferred: See Appendix 1. The frequency of the transfer: ongoing. Nature of the processing: See Appendix 1. Purpose(s) of the data transfer and further processing: See Appendix 1. The period for which the personal data will be retained: See Appendix 1. Transfers to (sub-) processors: List of Explorium Sub-Processors Infrastructure Sub-processors Entity Name Subprocessing Activities Country of Storage Duration of transfer Amazon Web Services Cloud hosting and storage United States As specified in 4.10 above Google Cloud Platform Cloud hosting and API Services United States As specified in 4.10 above Databricks Inc. Data analytics platform United States As specified in 4.10 above DataDog Monitoring and observability United States As specified in 4.10 above CloudFlare, Inc. Content delivery network, security United States As specified in 4.10 above Pusher Ltd. Real-time messaging services United States As specified in 4.10 above Auth0 By Okta, inc. Authentication services United States As specified in 4.10 above MongoDB, Inc. Database management United States As specified in 4.10 above Product Communications Sub-processors Entity Name Subprocessing Activities Country of Storage Duration of transfer SendGrid Email delivery service United States As specified in 4.10 above FullStory Session replay and user analytics United States As specified in 4.10 above MixPanel Product analytics platform United States As specified in 4.10 above HubSpot CRM and marketing automation United States As specified in 4.10 above Gong sales call recording, and analytics United States As specified in 4.10 above Metadata, inc. marketing and campaign automation, management United States As specified in 4.10 above Outreach Sales engagement platform United States As specified in 4.10 above Zapier Inc. Workflow automation United States As specified in 4.10 above Zoom Video Communications, Inc. Video conferencing, virtual meetings United States As specified in 4.10 above Serp.API, LLC Data product United Stated As specified in 4.10 above Nimble, Inc. Data Product United States As specified in Section 4.10 above. Hertza LLC (Zerobounce) Email validation United Stated/ EU As specified in Section 4.10 above. Open.ai LLM engine United States As specified in Section 4.10 above. Anthropic LLM engine United States As specified in Section 4.10 above. Gemini LLM engine United States As specified in Section 4.10 above. Product Monitoring and Testing Sub-processors Entity Name Subprocessing Activities Country of Storage Duration of transfer Atlassian Collaboration and issue tracking United States As specified in Section 4.10 above. Monday Project management platform United States As specified in Section 4.10 above. LambdaTest Cross-browser testing United States As specified in Section 4.10 above. Customer Support Sub-processors Entity Name Subprocessing Activities Country of Storage Duration of transfer Slack communication tool United States As specified in Section 4.10 above. Competent Supervisory Authority: the supervisory authority in the EU member state where the data exporter is established or where its EU representative under Article 27 of the GDPR is located. In Annex II, for MODULE TWO: Transfer controller to processor: as detailed in the data importer’s ISO 27001 and SOC-2 reports and certifications (subject to data importer’s right to redact from such report any information that would identify another customer or expose confidential information of another client).