This Data Processing Addendum, dated as of May 25, 2018 (“Addendum”), by and between the customer that electronically accepts or otherwise agrees or opts-in to this DPA (“Company”), and Dash Hudson Inc., a Canadian corporation (“Service Provider”) (collectively referred to as the “Parties”), sets forth the terms and conditions relating to the privacy, confidentiality and security of Personal Data (as defined below) associated with services to be rendered by Service Provider to Company.
Whereas, Company or its employees, agents, consultants or contractors (collectively, “Company Personnel”) shall provide Service Provider with access to Personal Data in connection with certain services performed by Service Provider for or on behalf of Company pursuant to the Master Agreement; and
Whereas, Company requires that Service Provider preserve and maintain the privacy, confidentiality and security of such Personal Data.
Now therefor, in consideration of the mutual covenants and agreements in this Addendum and the Master Agreement and for other good and valuable consideration, the sufficiency of which is hereby acknowledged, Company and Service Provider agree as follows:
(B) “Data Controller” means a person who alone or jointly with others determines the purposes and means of the Processing of Personal Data.
(C) “Data Processor” means a person who Processes Personal Data on behalf of the Data Controller.
(D) “Data Security Measures” means technical and organisational measures that are aimed at ensuring a level of security of Personal Data that is appropriate to the risk of the Processing, including protecting Personal Data against accidental or unlawful loss, misuse, unauthorised access, disclosure, alteration, destruction, and all other forms of unlawful Processing, including measures to ensure the confidentiality of Personal Data.
(E) “Data Subject” means an identified or identifiable natural person to which the Personal Data pertain.
(F) “Instructions” means this Addendum and any further written agreement or documentation through which the Data Controller instructs the Data Processor to perform specific Processing of Personal Data
(G) “Notification Related Costs” means Company’s and its affiliates’ internal and external costs associated with investigating, addressing and responding to a Personal Data Breach, including but not limited to: (i) preparation and mailing or other transmission of any notifications or other communications to customers, potential customers, clients, employees, agents or others as Company deems reasonably appropriate; (ii) establishment of a call center or other communications procedures in response to such Personal Data Breach (e.g., customer service FAQs, talking points and training); (iii) public relations and other similar crisis management services; (iv) legal, accounting, consulting and forensic expert fees and expenses associated with the Company’s and its affiliates’ investigation of and response to such Personal Data Breach; and (v) costs for commercially reasonable credit monitoring, identity protection services or similar services that Company determines are advisable under the circumstances.
(H) “Personal Data” means any information relating to an identified or identifiable natural person Processed by Service Provider in accordance with Company’s Instructions pursuant to this Addendum; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
(I) “Personal Data Breach” a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed.
(J) “Process”, “Processed”, or “Processing” means any operation or set of operations performed upon Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
(K) “Sub-Processor” means the entity engaged by the Data Processor or any further Sub-Processor to Process Personal Data on behalf and under the authority of the Data Controller.
II. Roles and Responsibilities of the Parties
(A) The Parties acknowledge and agree that Company is acting as a Data Controller, and has the sole and exclusive authority to determine the purposes and means of the Processing of Personal Data Processed under this Addendum, and Service Provider is acting as a Data Processor on behalf and under the Instructions of Company.
(B) Any Personal Data will at all times be and remain the sole property of Company and Service Provider will not have or obtain any rights therein.
III. Obligation of the Service Provider
Service Provider agrees and warrants to:
(A) Process Personal Data disclosed to it by Company only on behalf of and in accordance with the Instructions of the Data Controller and Annex  of this Addendum, unless Service Provider is otherwise required by Applicable Law, in which case Service Provider shall inform Company of that legal requirement before Processing the Personal Data, unless informing the Company is prohibited by law on important grounds of public interest. Service Provider shall immediately inform Company if, in Service Provider’s opinion, an Instruction provided infringes Applicable Law.
(B) Hold in strict confidence (i) the existence and terms of the Master Agreement (including this Addendum), and any related agreement, and (ii) any and all Personal Data.
(C) Ensure that any person authorised by Service Provider to Process Personal Data in the context of the Services is only granted access to Personal Data on a need-to-know basis, is subject to a duly enforceable contractual or statutory confidentiality obligation, and only processes Personal Data in accordance with the Instructions of the Data Controller.
(D) Not transfer Personal Data outside the country from which Company or its Personnel originally delivered to Service Provider, or from which Service Provider otherwise accessed or obtained such Personal Data or, if it was originally delivered to a location inside the European Economic Area (“EEA”) or Switzerland, outside the EEA or Switzerland), for Processing without the explicit written consent of Company (where such consent is deemed to have been granted in respect of the jurisdictions listed in Annex 1). Service Provider shall enter into any written agreements as are necessary (in Company’s reasonable determination) to comply with Applicable Law concerning any cross-border transfer of Personal Data, whether to or from Service Provider.
(E) Inform Company promptly and without undue delay of any formal requests from Data Subjects exercising their rights of access, correction or erasure of their Personal Data, their right to restrict or to object to the Processing as well as their right to data portability, and not respond to such requests, unless instructed by the Company in writing to do so. Taking into account the nature of the Processing of Personal Data, Service Provider shall assist Company, by appropriate technical and organisational measures, insofar as possible, in fulfilling Company’s obligations to respond to a Data Subject’s request to exercise their rights with respect to their Personal Data.
(F) Notify Company immediately in writing of any subpoena or other judicial or administrative order by a government authority or proceeding seeking access to or disclosure of Personal Data. Company shall have the right to defend such action in lieu of and on behalf of Service Provider. Company may, if it so chooses, seek a protective order. Service Provider shall reasonably cooperate with Company in such defense.
(G) Provide reasonable assistance to Company, at Company’s cost, in complying with Company’s obligations under Applicable Law.
(H) Maintain internal record(s) of Processing activities, copies of which shall be provided to Company by Service Provider or to supervisory authorities upon request. Such records must contain at least: (i) the name and contact details of Service Provider; (ii) the categories of Processing activities carried out under this Addendum; (iii) information on data transfers to a third country or a third party, where applicable; and (iv) a general description of the Data Security Measures implemented to protect Personal Data Processed under this Addendum.
(A) Service Provider shall not share, transfer, disclose, make available or otherwise provide access to any Personal Data to any third party, or contract any of its rights or obligations concerning Personal Data, unless Company has authorised Service Provider to do so in writing. Where Service Provider, with the consent of Company, provides access to Personal Data to a third party, Service Provider shall enter into a written agreement with each such third party that imposes obligations on the third party that are the same as those imposed on Service Provider under this Addendum. Service Provider shall only retain third parties that are capable of appropriately protecting the privacy, confidentiality and security of the Personal Data.
V. Compliance with Applicable Laws
(A) Service Provider shall comply with all Applicable Laws.
(B) Service Provider represents and warrants that no Applicable Law, or legal requirement, or privacy or information security enforcement action, investigation, litigation or claim prohibits Service Provider from fulfilling its obligations under this Addendum.
(C) Service Provider shall in good faith negotiate any further data Processing agreement reasonably requested by Company for purposes of compliance with the Applicable Law. In case of any conflict between this Addendum and the Master Agreement, this Addendum shall prevail with regard to the Processing of Personal Data covered by it.
VI. Data Security
(A) Service Provider shall develop, maintain and implement a comprehensive written information security program that complies with Applicable Law including, but not limited to, the Data Security Measures described in Annex 2 of this Addendum. Service Provider’s information security program shall include appropriate administrative, technical, physical, organisational and operational safeguards and other security measures designed to (i) ensure the security and confidentiality of Personal Data; (ii) protect against any anticipated threats or hazards to the security and integrity of Personal Data; and (iii) protect against any Personal Data Breach, including, as appropriate:
- The pseudonymisation and encryption of the Personal Data;
- The ability to ensure the ongoing confidentiality, integrity, availability and resilience of Processing systems and services;
- The ability to restore the availability and access to the Personal Data in a timely manner in the event of a physical or technical incident; and
- A process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures adopted pursuant to this provision for ensuring the security of the Processing.
Service Provider shall adopt all reasonable recommendations Company may make concerning Data Security Measures, programs and procedures to ensure ongoing compliance with this Addendum provided, however, that any material changes to Company’s requirements shall be Processed through the Change Control Procedures.
(B) Service Provider shall supervise Service Provider personnel to the extent required to maintain appropriate privacy, confidentiality and security of Personal Data. Service Provider shall provide training, as appropriate, regarding the privacy, confidentiality and information security requirements set forth in this Addendum to all Service Provider personnel who have access to Personal Data.
(C) Promptly upon the expiration or earlier termination of the Master Agreement, or such earlier time as Company requests, Service Provider shall return to Company or its designee, or at Company’s request, securely destroy or render unreadable or undecipherable if return is not reasonably feasible or desirable to Company (which decision shall be based solely on Company’s written statement), each and every original and copy in every media of all Personal Data in Service Provider’s, its affiliates’ or their respective subcontractors’ possession, custody or control. Promptly following any return or alternate action taken to comply with this Clause VI(C), Service Provider shall provide to Company a completed certificate certifying that such return or alternate action occurred. In the event applicable law does not permit Service Provider to comply with the delivery or destruction of the Personal Data, Service Provider warrants that it shall ensure the confidentiality of the Personal Data and that it shall not use or disclose any Personal Data after termination of this Addendum.
VII. Data Breach Notification
(A) Service Provider shall immediately inform Company in writing of any Personal Data Breach of which Service Provider becomes aware, but in no case longer than twenty four (24) hours after it becomes aware of the Personal Data Breach. The notification to Company shall include all available information regarding such Personal Data Breach, including information on:
- The nature of the Personal Data Breach including where possible, the categories and approximate number of affected Data Subjects and the categories and approximate number of affected Personal Data records;
- The likely consequences of the Personal Data Breach; and
- The measures taken or proposed to be taken to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
Service Provider shall promptly take all necessary and advisable corrective actions, and shall cooperate fully with Company in all reasonable and lawful efforts to prevent, mitigate or rectify such Breach. Service Provider shall provide such assistance as required to enable Company to satisfy Company’s obligation to notify the relevant supervisory authority and Data Subjects of a personal data breach under Articles 33 and 34 of the GDPR. The content of any filings, communications, notices, press releases or reports related to any Personal Data Breach must be approved by Company prior to any publication or communication thereof. Service Provider shall be responsible for the costs and expenses associated with the performance of its obligations described in this paragraph, unless the Personal Data Breach is caused by the acts or omissions of Company or its affiliates.
(B) In the event of a Personal Data Breach involving Personal Data in Service Provider’s possession, custody or control or for which Service Provider is otherwise responsible, Service Provider shall reimburse Company on demand for all commercially reasonable Notification Related Costs incurred by Company arising out of or in connection with any such Personal Data Breach.
Service Provider shall on written request (but not more than once per year, other than in the event of a breach) make available to Company all information necessary to demonstrate compliance with the obligations set forth in this Addendum and, at the Company’s expense, allow for and contribute to audits, including inspections, conducted by Company or another auditor mandated by Company. Upon prior written request by Company (provided that it shall be not more than once per year other than in the event of a breach), Service Provider agrees to cooperate and, within reasonable time, provide Company with: (a) audit reports and all information necessary to demonstrate Service Provider’s compliance with the obligations laid down in this Addendum; and (b) confirmation that the audit has not revealed any material vulnerability in Service Provider’s systems, or to the extent that any such vulnerability was detected, that Service Provider has fully remedied such vulnerability. Service Provider’s failure to comply with this obligation shall entitle Company to suspend the Processing of Personal Data Processed by Service Provider, and to terminate any further Processing of Personal Data, this Addendum and/or the Master Agreement, if doing so is required to comply with Applicable Law.
IX. Injunctive Relief
Service Provider agrees that any Processing of Personal Data in violation of this Addendum, Company’s Instructions or any Applicable Law, or the occurrence of any Personal Data Breach, will cause immediate and irreparable harm to Company for which money damages will not constitute an adequate remedy. Therefore, Service Provider agrees that Company may seek and be granted specific performance and injunctive or other equitable relief for any such violation or incident, in addition to its remedies at law, without proof of actual damages.
Service Provider agrees to indemnify and hold Company harmless from and against any direct damages, fines, costs or expenses that it may incur or that arise out of or in connection with a third party claim relating to any violation of this Addendum.
XI. Governing Law
To the extent required by Applicable Law, this Addendum shall be governed by the law of Nova Scotia, Canada. In all other cases, this Addendum shall be governed by the laws of the jurisdiction specified in the Agreement.
ANNEX 1: SCOPE OF THE DATA PROCESSING
SCOPE OF THE DATA PROCESSING
This Annex forms part of the Data Processing Addendum between Company and Service Provider.
The Processing of Personal Data concerns the following categories of Data Subjects:
- Customer users
- Instagram end-users with public profiles who directly interact with the Customer’s (brand’s) instagram handle(s) using the Instagram API
The Processing concerns the following categories of Personal Data:
- Customer users login information and usage within the Dash Hudson platform
- Photos, comments, hashtags, @ mentions directly of Instagram end-users with public profiles who have directly interacted with the Customer’s (brand’s) instagram handle(s), accessed through the Instagram API
The Processing concerns the following categories of Sensitive Data:
Sensitive Data means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, data concerning health, sex life or sexual orientation.
Race and/or ethnicity contained in photos created by instagram end-users with public profiles who have directly interacted with the Customer’s (brand’s) instagram handle(s), accessed through the Instagram API
The Processing concerns the following categories of data Processing activities (i.e., purposes of Processing):
- Purpose of processing Customer user login and Dash Hudson platform solely to provide the Dash Hudson services.
- Purpose of processing Instagram end-user photos, hashtags, comments and @mentions who have a public profile and have directly interacted with the Customer’s instagram handle(s) accessed through the Instagram API, solely to provide Dash Hudson services, analytics and insights to the Customer
Service Provider uses the following Sub-Processors:
Service Provider may transfer and process personal information to and in the following jurisdictions outside of the EU:
Canada, United States
ANNEX 2: DATA SECURITY MEASURES
This Annex forms part of the Data Processing Addendum between Company and the Service Provider. Taking into account the state of the art, the costs of implementation and the nature, scope, content and purpose of the Processing, Service Provider agrees to implement the following Data Security Measures:
- Physical access control
Technical and organisational measures to prevent unauthorised persons from gaining access to the data Processing systems available in premises and facilities (including databases, application servers and related hardware), where Personal Data are Processed, including:
- Establishing security areas, restriction of access paths;
- Establishing access authorisations for employees and third parties;
- Access control system (ID reader, magnetic card, chip card);
- Key management, card-keys procedures;
- Door locking (electric door openers etc.);
- Security staff, janitors;
- Surveillance facilities, video/CCTV monitor, alarm system;
- Securing decentralised data Processing equipment and personal computers.
Technical and organisational measures to prevent data Processing systems from being used by unauthorised persons, including:
- User identification and authentication procedures;
- ID/password security procedures (special characters, minimum length, change of password);
- Automatic blocking (e.g., password or timeout);
- Monitoring of break-in-attempts and automatic turn-off of the user ID upon several erroneous passwords attempts;
- Creation of one master record per user, user master data procedures, per data Processing environment;
- Encryption and Pseudonymisation.
Technical and organisational measures to ensure that persons entitled to use a data Processing system gain access only to such Personal Data in accordance with their access rights, and that Personal Data cannot be read, copied, modified or deleted without authorisation, including:
- Internal policies and procedures;
- Control authorisation schemes;
- Differentiated access rights (profiles, roles, transactions and objects);
- Monitoring and logging of accesses;
- Disciplinary action against employees who access personal data without authorisation;
- Reports of access;
- Access procedure;
- Change procedure;
- Deletion procedure;
- Encryption and Pseudonymisation.
Technical and organisational measures to ensure that Personal Data cannot be read, copied, modified or deleted without authorisation during electronic transmission, transport or storage on storage media (manual or electronic), and that it can be verified to which companies or other legal entities Personal Data are disclosed, including:
- Transport security;
- Encryption and Pseudonymisation.
Technical and organisational measures to monitor whether data have been entered, changed or removed (deleted), and by whom, from data Processing systems, including:
- Logging and reporting systems;
- Audit trails and documentation
Technical and organisational measures to ensure that Personal Data are Processed solely in accordance with the Instructions of the Controller, including:
- Unambiguous wording of the contract;
- Formal commissioning (request form);
- Criteria for selecting the Processor.
Technical and organisational measures to ensure that Personal Data are protected against accidental destruction or loss (physical/logical), including:
- Backup procedures;
- Mirroring of hard disks;
- Uninterruptible power supply;
- Remote storage;
- Anti-virus/firewall systems;
- Disaster recovery plan.
Technical and organisational measures to ensure that Personal Data collected for different purposes can be Processed separately, including:
- Separation of databases;
- “Internal client” concept / limitation of use;
- Segregation of functions (production/testing);
- Procedures for storage, amendment, deletion, transmission of data for different purposes.