Data Processing Agreement

Introduction

This Data Processing Agreement is a schedule to and forms part of the Agreement between YOOBIC and Customer. It sets out the rights and obligations of the parties regarding the Processing of Personal Data pursuant to the Agreement.

  1. Definitions and Interpretation

The following definitions and rules of interpretation apply in this Agreement. Interpretations and defined terms set forth in the Master Agreement apply to the interpretation of this Agreement.

  1. Definitions:
  2. Business Purposes: the services to be provided by YOOBIC to the Customer as described in the Agreement including as further detailed in ANNEX A.
  3. Controller, Processor, Data Subject, Personal Data, Personal Data Breach and Processing: have the meanings given in the Data Protection Legislation.
  4. Data Protection Legislation: the UK GDPR, the EU GDPR, the Personal Information Protection and Electronic Documents Act (Canada) and applicable substantially similar Canadian provincial private sector privacy laws, and, to the extent applicable to the Processing of Personal Data under the Agreement, applicable U.S. federal, state and local privacy and data protection laws and regulations, including the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, and its implementing regulations, as well as other applicable comprehensive U.S. state privacy laws, including the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, the Oregon Consumer Privacy Act, the Montana Consumer Data Privacy Act, the Delaware Personal Data Privacy Act, the Iowa Consumer Data Protection Act, the Indiana Consumer Data Protection Act, the Tennessee Information Protection Act, the New Jersey Data Privacy Act, the New Hampshire privacy law, the Nebraska Data Privacy Act, the Kentucky Consumer Data Protection Act, the Rhode Island Data Transparency and Privacy Protection Act, the Maryland Online Data Privacy Act, the Minnesota Consumer Data Privacy Act and, where applicable, the Florida Digital Bill of Rights, and their respective implementing regulations.
  5. EU GDPR: the General Data Protection Regulation ((EU) 2016/679).
  6. EEA: the European Economic Area.
  7. Sub-Processor: any third party contracted or engaged by YOOBIC to carry out processing activities in relation to any Personal Data.
  8. Subprocessor List: the subprocessor list identifying the Subprocessors that are authorised to Process Personal Data accessible here: https://yoobic.com/subprocessors/
  9. UK GDPR: the EU General Data Protection Regulation 2016/679 as retained in UK law by the European Union (Withdrawal) Act 2018.
  10. CCPA/CPRA: the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, and its implementing regulations.
  11. Consumer: where required by applicable U.S. state privacy law, has the meaning given to that term, or to any analogous term, under such law.
  12. Canadian Privacy Laws: PIPEDA and any applicable substantially similar Canadian provincial private sector privacy laws.
  13. Service Provider/Contractor: where required by applicable U.S. state privacy law, including the CCPA/CPRA, means a service provider, contractor, processor or other equivalent recipient of Personal Data under such law.
    1. This DPA is subject to the terms of the Agreement and is incorporated into the Agreement. Interpretations and defined terms set forth in the Agreement apply to the interpretation of this Agreement.The Annexes form part of this DPA and will have effect as if set out in full in the body of this DPA. Any reference to this DPA includes the Annexes.A reference to writing or written excludes fax but not email.
    1. To the extent that the terms contained in this Agreement conflict with those contained in the Master Agreement, the terms in this Agreement shall prevail to the extent such conflict relates to the processing of Personal Data.
  14. Personal data types and processing purposes
    1. The Customer and YOOBIC agree and acknowledge that for the purpose of the Data Protection Legislation:
      1. The Customer is the Controller and YOOBIC is the Processor in respect of processing carried out to fulfil the Business Purposes. To the extent applicable U.S. state privacy law applies, the Customer is the business, controller or other equivalent regulated entity, and YOOBIC is the Service Provider/Contractor, processor or other equivalent recipient, in each case in respect of Processing carried out to fulfil the Business Purposes on behalf of the Customer. The parties further acknowledge that YOOBIC may process Personal Data as an independent Controller for its own legitimate business purposes and that such processing falls outside the scope of this DPA.the Customer retains control of the Personal Data and remains responsible for its compliance obligations under the Data Protection Legislation, including but not limited to, providing any required notices and obtaining any required consents, and for the written processing instructions it gives to YOOBIC.
      1. ANNEX A describes the subject matter, duration, nature and purpose of the processing and the Personal Data categories and Data Subject types in respect of which YOOBIC may process the Personal Data to fulfil the Business Purposes.
  15. YOOBIC’s obligations
    1. YOOBIC will only process the Personal Data as a Processor to the extent, and in such a manner, as is necessary for the Business Purposes in accordance with the Customer’s written instructions. Written instructions may be provided by Customer’s authorised representatives as notified to YOOBIC in writing from time to time. YOOBIC will promptly notify the Customer if, in its opinion, the Customer’s instructions do not comply with the Data Protection Legislation.To the extent applicable U.S. state privacy law, including the CCPA/CPRA, applies, YOOBIC will act as a Service Provider/Contractor, processor or other equivalent recipient and will Process Personal Data only on the Customer’s documented instructions and for the limited and specified Business Purposes, unless otherwise required or permitted by applicable law. YOOBIC will ensure that each person authorised to Process Personal Data is subject to a duty of confidentiality, will impose substantially equivalent data protection obligations on any authorised Subprocessor by written contract, will assist the Customer as reasonably necessary to enable the Customer to meet its obligations under applicable U.S. state privacy law, and will make available to the Customer information reasonably necessary to demonstrate compliance with such obligations. Without limiting the foregoing, YOOBIC will not: (i) sell or share Personal Data; (ii) retain, use or disclose Personal Data for any purpose other than the Business Purposes, or as otherwise permitted by applicable law; or (iii) retain, use or disclose Personal Data outside the direct business relationship between the parties, except as otherwise permitted by applicable law. YOOBIC will provide the same level of privacy protection required by applicable Data Protection Legislation and will notify the Customer if it determines that it can no longer meet its obligations under such legislation.YOOBIC will comply promptly with any Customer written instructions requiring the YOOBIC to amend, transfer, delete or otherwise process the Personal Data, or to stop, mitigate or remedy any unauthorised processing.YOOBIC will maintain the confidentiality of the Personal Data and will not disclose the Personal Data to third-parties unless the Customer or this Agreement specifically authorises the disclosure, or as required by law, court or regulator. If a law, court or regulator requires YOOBIC to process or disclose the Personal Data to a third-party, YOOBIC must first inform the Customer of such legal or regulatory requirement and give the Customer an opportunity to object or challenge the requirement, unless the law prohibits the giving of such notice.
    1. YOOBIC will reasonably assist the Customer, at no additional cost to the Customer, with meeting the Customer’s compliance obligations under the Data Protection Legislation, taking into account the nature of YOOBIC’s processing and the information available to YOOBIC, including in relation to Data Subject rights, data protection impact assessments and reporting to and consulting with the competent supervisory authority under the Data Protection Legislation. Such assistance will also include, to the extent required by applicable U.S. state privacy law or Canadian Privacy Laws, reasonable assistance with consumer requests, access and correction requests, and inquiries or investigations by regulators.
  16. YOOBIC’s personnel
    1. YOOBIC will ensure that all employees, contractors, subcontractors and other persons authorised to access or process the Personal Data (“Personnel”) are informed of the confidential nature of the Personal Data and are bound by written confidentiality obligations and use restrictions in respect of the Personal Data and have undertaken training on the Data Protection Legislation and how it relates to their handling of the Personal Data and how it applies to their particular duties.
  17. Security
    1. YOOBIC must at all times implement appropriate technical and organisational measures against accidental, unauthorised or unlawful processing, access, copying, modification, reproduction, display or distribution of the Personal Data, and against accidental or unlawful loss, destruction, alteration, disclosure or damage of Personal Data.
    1. YOOBIC must implement such measures to ensure a level of security appropriate to the risk involved, including as appropriate:
      1. the pseudonymisation and encryption of personal data;the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; and
      1. a process for regularly testing, assessing and evaluating the effectiveness of the security measures.
  18. Personal data breach
    1. YOOBIC will without undue delay notify the Customer in writing if it becomes aware of:
      1. the loss, unintended destruction or damage, corruption, or unusability of part or all of the Personal Data. YOOBIC will restore such Personal Data at its own expense as soon as possible.any accidental, unauthorised or unlawful processing of the Personal Data; orany Personal Data Breach.
      Where YOOBIC becomes aware of (a), (b) and/or (c) above, it will, without undue delay, also provide the Customer with the following written information:
      1. description of the nature of (a), (b) and/or (c), including the categories of in-scope Personal Data and approximate number of both Data Subjects and the Personal Data records concerned;the likely consequences;a description of the measures taken or proposed to be taken to address (a), (b) and/or (c), including measures to mitigate its possible adverse effects; andthe name and contact details of YOOBIC’s data protection officer or other contact point from whom further information may be obtained.
      Following any accidental, unauthorised or unlawful Personal Data processing or Personal Data Breach, YOOBIC will provide the Customer with reasonable cooperation and assistance in the Customer’s handling of the matter, taking into account the nature of the processing and the information available to YOOBIC.
    1. YOOBIC will cover all reasonable expenses associated with the performance of the obligations under clause 6.1 to clause 6.3 unless the matter arose from the Customer’s specific written instructions, negligence, wilful default or breach of this Agreement, in which case the Customer will cover all reasonable expenses.
  19. Transfers of personal data
    1. If Data Protection Legislation has prescribed specific mechanisms for the transfer of Customer Personal Data to YOOBIC and/or contract clauses for Processing of Customer Personal Data by Yoobic (collectively, a “Transfer Mechanism”), YOOBIC shall make such specific Transfer Mechanism available (to the extent generally supported by YOOBIC) such as the Standard Contractual Clauses approved pursuant to Commission Decision (EU) 2021/91 of 4 June 2021 and the International Data Transfer Addendum issued by the Information Commissioner’s Office under s.119(A) of the UK Data Protection Act 2018. A Transfer Mechanism shall not apply and shall not be incorporated into this DPA if it is not applicable to (i) transfers from Customer to YOOBIC (including where no such transfer occurs), or (ii) Processing by YOOBIC of Customer Personal Data. If a Transfer Mechanism is, or becomes applicable under Data Protection Legislation, it shall be deemed to be signed by the Parties and is incorporated into this DPA. Subject to Section 7.2 below, Yoobic may only remove an applicable Transfer Mechanism if the Transfer Mechanism has ceased being valid under the Data Protection Legislation or YOOBIC is offering an alternative, then-currently valid Transfer Mechanism.
    1. YOOBIC shall notify Customer of changes to its Transfer Mechanisms by notifying Customer and/or posting a summary and date of the relevant changes.
  20. Subprocessors
    1. Customer hereby grants YOOBIC general written authorisation (within the meaning of Article 28(2) of the EU GDPR and UK GDPR) for it and its Affiliates to engage Subprocessors, subject to the conditions of this clause 8. YOOBIC or its Affiliates will enter into a written contract with the Subprocessor that contain terms substantially the same as those set out in this DPA, including in particular, the security obligations set out in Clause 5 of this DPA. Where the Subprocessor fails to fulfil its obligations under the written agreement with YOOBIC or its Affiliate which contains terms substantially the same as those set out in this DPA, YOOBIC remains fully liable to the Customer for the Subprocessor’s performance of its obligations.YOOBIC shall make available to Customer a Subprocessor List and provide Customer with a mechanism to obtain notice of any updates to such Subprocessor List. At least 30 days before YOOBIC authorises a new Subprocessor to Process Customer Personal Data, YOOBIC will provide notice to Customer by updating such Subprocessor List.
    1. The Customer may object to the appointment of a new Subprocessor on reasonable grounds within 14 working days after YOOBIC notifies the Customer of the Subprocessor appointment in accordance with clause 8.2. In such event, the parties will discuss those objections in good faith with a view to achieving resolution. If it can be reasonably demonstrated to YOOBIC that the new Subprocessor is unable to Process Customer Personal Data in compliance with the terms of this DPA and YOOBIC cannot provide an alternative Subprocessor, or the Parties are not otherwise able to achieve resolution, Customer, as its sole and exclusive remedy, may terminate the Agreement with respect to only those aspects which cannot be provided by YOOBIC without the use of the new Subprocessor by providing advance written notice to YOOBIC of such termination.
  21. Complaints, data subject requests and third-party rights
    1. At the Customer’s cost, YOOBIC will take such technical and organisational measures as may be appropriate, and promptly provide such information to the Customer as the Customer may reasonably require, to enable the Customer to comply with:
      1. the rights of Data Subjects under the Data Protection Legislation, including, but not limited to, subject access rights, the rights to rectify, port and erase personal data, object to the processing and automated processing of personal data, and restrict the processing of personal data; and, to the extent applicable, the rights of Consumers or other individuals under applicable U.S. state privacy laws or Canadian Privacy Laws, including rights to access, correct, delete or obtain information regarding the Processing of Personal Data; andinformation or assessment notices served on the Customer by the competent supervisory authority under the Data Protection Legislation.
      YOOBIC will notify the Customer promptly if it receives a request from a Data Subject for access to their Personal Data or to exercise any of their other rights under the Data Protection Legislation. YOOBIC will also notify the Customer promptly if it receives any request, complaint or inquiry from a Consumer or other individual under applicable U.S. state privacy law or Canadian Privacy Laws relating to Personal Data processed under the Agreement.
    1. YOOBIC will give the Customer its full co-operation and assistance in responding to any complaint, notice, communication or Data Subject request.
  22. Term and termination
    1. This DPA will remain in full force and effect so long as the Agreement remains in effect or YOOBIC retains any of the Personal Data related to the Agreement in its possession or control.
  23. Data return and destruction
    1. Following termination or expiry of the Agreement, the Customer may request return of its Personal Data in YOOBIC’s standard export format within 30 days of termination or expiry. YOOBIC may securely delete or destroy any Personal Data remaining in its possession after that 30 day period.
    1. Personal Data held on backup or archive media will be deleted in accordance with YOOBIC’s standard backup rotation schedule. YOOBIC may retain Personal Data where required by applicable law for the duration so required, after which it shall be securely deleted.
  24. Records
    1. YOOBIC will keep detailed, accurate and up-to-date written records regarding any processing of the Personal Data, including but not limited to, the access, control and security of the Personal Data, the processing purposes, categories of processing, and a general description of the technical and organisational security measures referred to in Clause 5.1 and 5.2 (Records).
    1. The YOOBIC will ensure that the Records are sufficient to enable the Customer to verify the YOOBIC’s compliance with its obligations under this Agreement and the YOOBIC will provide the Customer with copies of the Records upon request.
  25. Audit
    1. No more than once per calendar year, the Customer may request an audit of YOOBIC’s documentation evidencing compliance with this DPA by providing YOOBIC with no less than 30 days’ prior written notice. The parties shall mutually agree in advance the reasonable start date, scope, duration, and applicable security and confidentiality controls of any such audit. YOOBIC may charge a reasonable fee reflecting the resources expended by YOOBIC in connection with the audit.YOOBIC may satisfy the Customer’s audit right in whole or in part by providing copies of relevant third-party audit reports, certifications or summaries (such as ISO 27001 or SOC 2 reports) where these reasonably address the Customer’s audit request. A live audit shall only be required to the extent such certifications do not reasonably satisfy the Customer’s request. For the avoidance of doubt, the audit rights granted under this clause do not include the right to conduct or commission penetration testing, vulnerability scanning, or any other active security testing of the YOOBIC’s systems or infrastructure.Any audit shall be conducted by an appropriately qualified third-party auditor (the “Auditor“). The Auditor may be required to execute a separate confidentiality agreement with YOOBIC prior to commencing any review. YOOBIC may object in writing to a proposed Auditor where, in YOOBIC ‘s reasonable opinion, the Auditor is not suitably qualified or is a direct competitor of YOOBIC, in which case the Customer shall appoint a replacement Auditor. All costs and expenses of the Auditor shall be borne exclusively by the Customer.Following a confirmed Personal Data Breach directly affecting the Customer’s Personal Data, the annual frequency restriction in clause 13.1 shall not apply, but the notice period and mutual agreement requirements shall continue to apply.YOOBIC shall, on reasonable notice, cooperate with and provide access to any competent supervisory authority conducting an audit or inspection of YOOBIC ‘s processing of Personal Data on behalf of the Customer.
    1. The reports, findings and any information arising from any audit shall constitute YOOBIC’s Confidential Information and may not be shared with any third party without YOOBIC ‘s prior written consent.
  1. Personal Data processing purposes and details
Required DetailsDescription
Nature and Purpose of Processing:YOOBIC will process Customer Personal Data as a Processor for the purpose of providing the SaaS Services to the Customer and its Affiliates in accordance with the terms of the Agreement. Such Business Purposes include hosting, storing, organising, accessing, using and disclosing Customer Personal Data only as necessary to provide, support, secure and improve the SaaS Services for the Customer, and otherwise Processing Customer Personal Data only as necessary to perform the Agreement or as otherwise permitted by applicable Data Protection Legislation. For the avoidance of doubt, this DPA governs only the Processing carried out by YOOBIC in its capacity as Processor. Where YOOBIC Processes Customer Personal Data for its own purposes and under its own legal basis (including but not limited to account management, billing, service improvement, security operations, and compliance obligations) YOOBIC acts as an independent Controller in respect of such Processing. Such Processing falls outside the scope of this DPA and is governed by applicable data protection legislation.
Personal Data CategoriesFull name, email address, phone number, usernames combined with passwords, photos, location information, cookies and online identifiers
Data Subject TypesAuthorised Users