Data Protection Agreement This Data Protection Agreement (the “DPA”) becomes effective on May 25, 2018. The Customer shall make available to the Company and the Customer authorizes the Company to process information including Personal Data for the provision of the Services under the Agreement. The parties have agreed to enter into this DPA to confirm the data protection provisions relating to their relationship and so as to meet the requirements of the applicable Data Protection Law.
1.1. For the purposes of this DPA: “Personal Data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; “Data Protection Law” mean all applicable laws, regulations, and other legal requirements relating to
(a) privacy, data security, consumer protection, marketing, promotion, and text messaging, email, and other communications; and
(b) the use, collection, retention, storage, security, disclosure, transfer, disposal, and other processing of any Personal Data.; “the Company Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the Company. “Control,” for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity; “Services” means any of the following services provided by the Company:
(a) Company-branded product offerings made available via the website of the Company,
(b) consulting or training services provided by the Company either remotely via the Internet or in person, and (c) any support services provided by the Company, including access to Company’s help desk; the terms “data controller”, “data processor”, “data subject”, “personal data”, “processing” and “appropriate technical and organisational measures” shall have the meanings given to them under applicable Data Protection Law
2.1. The subject matter, nature and purpose of the processing of Personal Data under this DPA is Company performance of the Services as further instructed in writing by the Customer in its use of the Services, unless required to do so otherwise by the Data Protection Law, in which case to the extent permitted by the Data Protection Law, the Company shall inform the Customer of this legal requirement prior to carrying out the processing. The Company shall only collect or process Personal Data for the period of rendering of the Services to the extent, and in such a manner, as is necessary for provision of the Services and in accordance with the DPA and the Data Protection Law applicable to the Company.
3.1. The processing of Personal Data will be carried out by the Company while Services Account of the Customer is in existence or as needed for the performance of the obligations and rights between the Company and the Customer unless otherwise agreed upon in writing.
4.1. The Customer may submit Customer Personal Data to the Services, the extent of which is determined and controlled by the Customer in its sole discretion, and which may include, but is not limited to the following categories of Personal Data: • Account Information. When the Customer signs up for a Services Account, it is required certain information such as the name and email. The Customer may update or correct its information and email preferences at any time by visiting the Services Account. The Company can provide the Customer with additional support to access, correct, delete, or modify the information the Customer provided to the Company and associated with the Customer’s Services Account. To protect the security, the Company takes reasonable steps (such as requesting any legal information) to verify the identity of the Customer before making corrections. The Customer is responsible for maintaining the secrecy of the password and information of the Customer’s Services Account at all times. • Additional Profile Information. The Customer may choose to provide additional information as part of its profile. Profile information helps the Customer to get more from the Services. It’s the Customer’s choice whether to include sensitive information on its profile. • Other Information. The Customer may otherwise choose to provide the Company information when the Customer fills in a form, conducts a search, updates or adds information to its Services Account, responds to surveys, posts to community forums, participates in promotions, or uses other features of the Services platform.
5.1. The Customer agrees and/or warrants: (a) that the processing, including the transfer itself, of the Personal Data has been and will continue to be carried out in accordance with the relevant provisions of the Data Protection Law and does not violate the relevant provisions; (b)that it has instructed and throughout the duration of the personal data-processing services will instruct the Company to process the Personal Data transferred only on the Customer’s behalf and in accordance with the Data Protection Law and the DPA; (c) that the Company will provide sufficient guarantees in respect of the technical and organizational security measures specified in Appendix 1 to this DPA; (d)that after assessment of the requirements of the Data Protection Law, the security measures are appropriate to protect Personal Data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing, and that these measures ensure a level of security appropriate to the risks presented by the processing and the nature of the data to be protected having regard to the state of the art and the cost of their implementation; (e) that it will ensure compliance with the security measures; (f) to access and use the Services only for legal, authorized, and acceptable purposes. The Customer will not use (or assist others in using) the Services in ways that: (a) violate, misappropriate, or infringe the rights of the Company, its users, or others, including privacy, publicity, intellectual property, or other proprietary rights; (b) are illegal, obscene, defamatory, threatening, intimidating, harassing, hateful, racially, or ethnically offensive, or instigate or encourage conduct that would be illegal, or otherwise inappropriate; (c) involve publishing falsehoods, misrepresentations, or misleading statements; (d) impersonate someone; (e) involve sending illegal or impermissible communications such as bulk messaging, auto-messaging, auto-dialing, and the like; or (f) involve any other use of the Services prescribed in this DPA unless otherwise authorized by the Company; (g) do not to (or assist others to) access, use, copy, adapt, modify, prepare derivative works based upon, distribute, license, sublicense, transfer, display, perform, or otherwise exploit the Services platform in impermissible or unauthorized manners, or in ways that burden, impair, or harm the Company, the Services platform, systems, other users, or others, including that the Customer will not directly or through automated means: (a) reverse engineer, alter, modify, create derivative works from, decompile, or extract code from the Services platform; (b) send, store, or transmit viruses or other harmful computer code through or onto the Services platform; (c) gain or attempt to gain unauthorized access to the Services platform or systems; (d) interfere with or disrupt the integrity or performance of the Services platform; (e) create accounts for the Services platform through unauthorized or automated means; (f) collect the information of or about other users in any impermissible or unauthorized manner; (g) sell, resell, rent, or charge for the Services platform; or (h) distribute or make the Services platform available over a network where it could be used by multiple devices at the same time; (h)that the Customer is responsible for keeping the Customer’s Services Account safe and secure, and the Customer will notify the Company promptly of any unauthorized use or security breach of the Customer’s Account or the Services platform; (i) that the Company grants the Customer a limited, revocable, non-exclusive, non-sublicensable, and nontransferable license to use the Services platform. This license is for the sole purpose of enabling the Customer to use the Services platform, in the manner permitted by this DPA. No licenses or rights are granted to the Customer by implication or otherwise, except for the licenses and rights expressly granted to the Customer