Third Party Index

Snapshot 80018

Document
Data processing addendum
URL
https://logisense.com/img/LogiSense-DPA-20221220.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
197612 bytes
SHA-256 (raw)
16d651b9123bdf075d45b3402b4c99a5dc493aeed7d36f43b486cfe27a57e734
SHA-256 (normalized text)
b413c1d88c6ee50b596bf847b248b0f8e7475eb43bc21f5f675a362070168e9a

Normalized text

Scripts and page chrome removed; this is what change detection compares.

June 2022

THIS ADDENDUM is made on the same date as the Master Services Agreement.

BETWEEN:
(1)  Customer as described in the Master Services Agreement between Customer and LogiSense
     Corporation (the “Customer”); and

(2)     LOGISENSE CORPORATION, a corporation incorporated pursuant to the laws of Ontario,
        Canada, with its registered address at 278 Pinebush Drive, Unit 101, Cambridge, Ontario,
        Canada, N1T 1Z6 (the “LogiSense”)

(each a “Party” and together the “Parties”).

WHEREAS:

(A)     The Customer and LogiSense have entered into a Master Services Agreement                     (the
        “Agreement”).

(B)     In the course of providing services under the Agreement, LogiSense processes personal data
        on behalf of the Customer.

(C)     The Parties wish to amend the Agreement with effect from the date of the Agreement (the
        “Effective Date”) by adding the terms set out in this Addendum, which is supplemental to the
        Agreement.

NOW IT IS AGREED AS FOLLOWS:

1.      Supplemental Terms

1.1     With effect from the Effective Date, the following terms shall form part of the Agreement:

        1.      Data Protection

        1.1     For the purposes of this clause:

                “Data Protection Law” means all applicable data protection law, including the General
                Data Protection Regulation (Regulation (EU) 2016/679), the Data Protection Act 2018
                of the United Kingdom (the “Data Protection Act”) and the UK General Data Protection
                Regulation and any legislation which amends, extends, consolidates, re-enacts or
                replaces same, including any statutory instruments and regulations that may be made
                pursuant thereto from time to time.

                The terms ‘controller’, ‘personal data’, ‘personal data breach’, ‘processor’ and
                ‘process’ shall have the meanings given to them under Data Protection Law.

        1.2     LogiSense acknowledges that in performing its obligations under the Agreemen t
                LogiSense processes personal data on behalf of the Customer. In such circumstances,
                LogiSense acknowledges that the Customer is the controller or a processor acting on
                behalf of the controller and LogiSense is a processor or sub-processor, as each term is
                defined in Data Protection Law.

        1.3     LogiSense shall process the categories of personal data set out in the Appendix 1 to this
                Addendum in the context of performing its obligations under, and for the duration of,
                the Agreement. The obligations and rights of the Customer shall be as set out in this
                Addendum.
June 2022

        1.4   In respect of the personal data referred to in Clause 1.3:

              (a)     LogiSense shall process such personal data only in accordance with the
                      documented instructions of the Customer, including with regard to trans fers
                      of personal data to a third country and solely as necessary for the performance
                      of its obligations under the Agreement, unless required to do so by EU or EU
                      Member State law to which LogiSense is subject, or by UK law, as applicable,
                      in which case LogiSense shall inform the Customer of that legal requiremen t
                      before processing (unless that law prohibits such information on important
                      grounds of public interest);

              (b)     LogiSense shall ensure that the persons authorised by LogiSense to process
                      such personal data are bound by appropriate confidentiality obligations;

              (c)     LogiSense shall implement such technical and organisational security
                      measures as are required to comply with the data security obligations under
                      Data Protection Law, which may include, as appropriate:

                      (i)     the pseudonymisation and encryption of personal data;

                      (ii)    the ability to ensure the ongoing confidentiality, integrity, availability
                              and resilience of processing systems and services;

                      (iii)   the ability to restore the availability and access to personal data in a
                              timely manner in the event of a physical or technical incident;

                      (iv)    a process for regularly testing, assessing and evaluating the
                              effectiveness of technical and organisational measures for ensuring the
                              security of the processing;

              (b)     LogiSense is authorised to engage the sub-processors listed on Appendix 2 to
                      this Addendum to undertake processing on its behalf, provided that, upon
                      Customer’s request, it provides the Customer with prior notice in writing
                      containing details of the sub-processors that it engages and informs the
                      Customer of any intended changes concerning the addition or replacement of
                      such sub-processors and provides the Customer with a reasonable opportunity
                      to object to such changes;

              (c)     where any sub-processor engaged by LogiSense will be processing such
                      personal data, LogiSense shall ensure that a written contract exists between
                      LogiSense and the sub-processor containing clauses equivalent to those
                      imposed on LogiSense in this clause. In the event that any sub-processor fails
                      to meet its data protection obligations, LogiSense shall remain fully liable to
                      the Customer for the performance of the sub-processor’s obligations;

              (d)     LogiSense shall assist the Customer by implementing appropriate technical
                      and organisational measures to allow the Customer to comply with requests
                      from data subjects to exercise their rights under Data Protection Law;

              (e)     LogiSense shall, at the cost and expense of the Customer, assist the Customer
                      in ensuring compliance with applicable obligations in respect of security of
                      personal data, data protection impact assessments, and prior consultation
                      requirements under Data Protection Law;
June 2022

                (f)     LogiSense shall: (i) at the choice of the Customer, delete or return all such
                        personal data to the Customer when LogiSense ceases to provide services
                        relating to data processing; and (ii) delete all existing copies of such personal
                        data unless EU law or the laws of an EU Member State, or UK law, as
                        applicable, require storage of the personal data;

                (g)     LogiSense shall: (i) make available to the Customer all information reasonably
                        necessary to demonstrate compliance with the obligations laid down in this
                        clause; and (ii) at the cost and expense of the Customer, allow for and assist
                        with audits, including inspections, conducted by the Customer or another
                        party mandated by the Customer, in order to ensure compliance with the
                        obligations laid down in this clause, including its data security obligations
                        under Data Protection Law. The Customer shall take into account adherence
                        by LogiSense to an approved code of conduct or an approved certification
                        mechanism to aid demonstration by LogiSense that it is compliant with the
                        provisions of this clause;

                (h)     LogiSense shall inform the Customer immediately if, in its opinion, it receives
                        an instruction from the Customer in connection with clause 1.4(i) which
                        infringes Data Protection Law; and

                (i)     LogiSense shall notify the Customer without undue delay after becomin g
                        aware of any breach of security leading to the accidental or unlawful
                        destruction, loss, alteration, unauthorised disclosure of, or access to, such
                        personal data and shall provide the Customer with such co-operation and
                        assistance as may be reasonably required to comply with any notification or
                        reporting obligations which may apply in respect of, any such personal data
                        breach.

2.      Miscellaneous

2.1     Capitalised terms not otherwise defined in this Addendum shall have the meanings set forth
        in the Agreement.

2.2     Save to the extent explicitly amended by this Addendum, the Agreement shall continue in full
        force and effect. To the extent that there is a conflict or inconsistency between the terms of this
        Addendum and the Agreement, such conflict or inconsistency shall be resolved by giving
        precedence to this Addendum.

2.3     This Addendum and the Agreement shall together constitute the entire agreement between the
        Parties with respect to their subject matter, supersede all previous drafts, arrangements ,
        understandings or agreements between the Parties with respect to their subject matter and may
        not be modified except by an instrument in writing signed by the duly authorised
        representatives of the Parties. Each of the Parties acknowledges and agrees that in entering
        into this Addendum it does not rely on and shall have no remedies in respect of, any
        undertaking, promise, assurance, statement, representation, warranty or understanding
        (whether in writing or not) of any person (whether party to this Addendum or not) relating to
        the subject matter of this Addendum, other than as expressly set out in this Addendum.

2.4     This Addendum may be executed in any number of counterparts, each of which when executed
        and delivered by one or more of the Parties to this Addendum is an original, but all the
        counterparts together constitute the same document provided that this Addendum shall not
        be effective until each party has executed and delivered at least one counterpart. The Parties
        agree that this Addendum may be executed electronically. Transmission of an executed
        counterpart of this Addendum (but for the avoidance of doubt not just a signature page) by (a)
June 2022

        fax or (b) email (in PDF, JPEG or other agreed format) shall also constitute delivery of an
        executed counterpart of the Addendum.

2.5     This Addendum shall be governed by and construed in accordance with the laws of the
        governing law of the Agreement.
June 2022

IN WITNESS WHEREOF the Parties have executed this Addendum on the date written above

 SIGNED for and on behalf of
 [CUSTOMER]
 by

 (Name)

 (Title)

 (Date)

 SIGNED for and on behalf of:
 LOGISENSE CORPORATION
 by

 Kevin Fox

 Director, Security & Technical Operations

 (Date)
June 2022

                             Appendix 1 – Details of Data Processing

 Subject matter, nature   Subject matter of processing: personal data, as defined under Data
 and purpose of the       Protection Law.
 processing
                          Nature of Processing: the scope, nature and purpose of the processing is
                          the provision of services by LogiSense to Customer as set forth in the
                          Agreement.

 Duration                 Duration of the Agreement.

 Categories of data       Customer’s customers; end users of Customer’s customers.
 subjects

 Types of personal        Demographic Data        name
 data i.e. any
 information relating     Contact Details         Personal/work email address
 to an identified or                              Personal/work telephone number
 identifiable person.                             Work postal address

                          Digital Identifiers     meta data

                          Special Categories of   Not applicable.
                          Data
                                                  For additional clarity, Customer agrees that it
                                                  will not make available the following categories
                                                  of information to LogiSense: government issued
                                                  personal identification numbers, consumer
                                                  financial account information, credit and
                                                  payment card information, personal health
                                                  information, or information deemed “sensitive”
                                                  under applicable Data Protection Law (such as
                                                  racial or ethnic origin, political opinions, or
                                                  religious or philosophical beliefs) except with
                                                  LogiSense’s prior written approval. For the
                                                  purpose of clarity examples of governmen t
                                                  issued personal identification numbers are
                                                  drivers’ license numbers, Social Security
                                                  Numbers (U.S)/ Social Insurance Number
                                                  (Canada) or the equivalent in the European
                                                  Union, passport numbers, etc., but not
                                                  information that is typically included in billing
                                                  systems such as taxation numbers, company
                                                  numbers, address, etc.

                          Other                   Not Applicable
June 2022

                                   Appendi x 2 – List of Sub-Processors

The Customer has authorised the use of the following sub-processors:

 Sub-Processor      Purpose              Country        DPA Reference

 Amazon      Web    Application Cloud    USA            https://aws.amazon.com/blogs/security/aws -gdpr-data-
 Services Inc.      infrastructure                      processing-
                                                        addendum/#:~:text=Data%20Processing%20Addendum(.
                                                        pdf

 Spreedly           Payment              USA            https://www.spreedly.com/gdpr#:~:text=of%20which%2
                    Processing     and                  0is-,hosted%20here.,-This%20DPA%20provides
                    Gateway
                    Integration

 Workato            Workflow       and   USA            https://www.workato.com/legal/dpa
                    Integration
                    Automation

 Critical River     Implementation       USA
                    and    Onboarding
                    Services

 Anita Middleton    Technical Support    USA
 LLC                services for the
                    platform
June 2022