DATA PROCESSING ADDENDUM
This Data Processing Addendum (the “DPA”) is entered into by and between you (“Customer”, “you,” and “yours”) (collectively, with its Affiliates, “Customer”) and Ruby Receptionists, Inc., our subsidiary Pure Chat, Inc., (collectively, “Ruby,” “us,” “we,” or “our”). This DPA supplements and is incorporated into the existing agreement between Customer and Provider (the “Agreement”) pursuant to which Provider will provide services (“Services”) to Customer and has the same Effective Date as the Agreement. In the course of providing the Services to Customer, Provider may Process Personal Data on behalf of Customer, and the parties agree to comply with the following provisions with respect to any Personal Data.
1. Definitions
“Affiliate” means with respect to an entity, any other entity that, now or in the future, either directly or through one or more intermediaries, controls, is controlled by, or is under common control with, that entity or any of its successors.
“CCPA” means the California Consumer Privacy Act of 2018, California Civil Code § 1798.100, as amended by the California Privacy Rights Act, and implementing regulations.
“Controller” means the definition of a controller, business, or equivalent term under Data Protection Laws.
“Customer Personal Data” means any Personal Data Processed by Provider (or a Sub-processor) on behalf of Customer pursuant to or in connection with the Agreement. Customer Personal Data does not include data or information derived from the Processing that does not constitute Personal Data or Personal Data collected by Provider as an independent controller.
“Data Protection Laws” means any applicable international, national, federal, state, local, municipal, or territorial law, regulation, rule, guideline, guidance, or industry standard concerning or relating to data privacy, security, or breach notification, including, but not limited to, the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), the CCPA, the Colorado Privacy Act, the Connecticut Data Privacy Act, the GDPR, the Mexican Federal Data Protection Law, the Utah Consumer Privacy Act, the UK GDPR, the Virginia Consumer Data Protection Act, and any other applicable state privacy law.
“Data Subject” means the definition of a data subject, consumer, or an equivalent term under Data Protection Laws.
“GDPR” means the General Data Protection Regulation, Regulation (EU) 2016/679.
“Personal Data” means (i) information that identifies or reasonably could identify a natural person; or (ii) information that constitutes personal data, personal information, personally identifiable information, nonpublic personal information, personal health information, or an equivalent term under Data Protection Laws.
“Process” or “Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction, and any other action that constitutes as “processing” or an equivalent term under Data Protection Laws.
“Processor” means the definition of a processor, service provider, or an equivalent term under Data Protection Laws.
“Security Incident” means any confirmed unauthorized access, disclosure, misappropriation, theft, loss, acquisition, use, modification, or altering the availability of Personal Data.
“Sub-processor” means any person appointed by or on behalf of Provider to Process Personal Data on behalf of Customer under the Agreement.
“UK GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27th April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).
2. Term.
The term of this DPA will commence on the Effective Date and will continue as long as Provider Processes Customer Personal Data.
3. Processing of Customer Personal Data
3.1 Roles of the Parties.
The parties acknowledge and agree that with regard to the Processing of Customer Personal Data, Customer is the Controller and Provider is the Processor.
3.2 Customer Authority.
Customer represents and warrants that it is and will at all relevant times remain duly and effectively authorized to give the instructions set forth in Section 3.3 below on behalf of itself.
3.3 Provider’s Processing of Customer Personal Data.
(a) Provider shall only Process Customer Personal Data for the purpose of providing the Services and in accordance with Customer’s written instructions, including the provisions of this DPA.
(b) Provider is prohibited from Processing Customer Personal Data for any purpose or in any manner not authorized by this DPA or necessary to perform the Services under the Agreement. Provider may Process Customer Personal Data for the following purposes:
(i) For internal use by the Provider to build or improve the quality of its services.
(ii) To detect Security Incidents or protect against fraudulent or illegal activity;
(iii) To comply with federal, state, or local laws;
(iv) To comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by federal, state, or local authorities;
(v) To cooperate with law enforcement agencies concerning conduct or activity that the Customer, Provider, or Sub-processor(s) reasonably and in good faith believe may violate federal, state, or local law; and
(vi) To exercise or defend legal claims.
(c) Provider is prohibited from selling, renting, leasing, licensing, or sharing for purposes of cross-contextual or targeted advertising any Customer Personal Data.
(d) Provider will comply with Data Protection Laws and will immediately notify Customer if Provider decides it can no longer meet its obligations under Data Protection Laws.
3.4 Details of the Processing.
The details of this Processing are further specified in Exhibit A of this DPA.
3.5 Customer’s Responsibility.
Customer is solely responsible for its compliance with all Data Protection Laws applicable to it.
4. Provider Personnel
Provider shall restrict its employees from Processing Customer Personal Data without authorization by Provider and shall limit the Processing to that which is needed for the specific individual’s job duties in connection with Provider’s provision of the Services.
5. Sub-processors
5.1 Approval of Sub-processors.
Customer provides Provider with a general authorization to engage Sub-Processors.
5.2 Sub-processing Agreement; Liability.
Provider has or shall enter into a written agreement with each Sub-processor (the “Sub-processing Agreement”) containing data protection obligations not less protective than those in this DPA with respect to Customer Personal Data.
5.3 Copies of Sub-Processor Agreements.
Provider shall provide to Customer for review copies of the Sub-processor agreements as Customer may reasonably request from time to time.
6. Security
Provider shall implement and maintain technical, organizational, and physical security measures necessary to protect the availability, confidentiality, and integrity of Customer Personal Data.
7. Cross-Border Transfers
7.1 To the extent that Customer Personal Data is transferred under the Agreement from the European Economic Area or the United Kingdom to a country that has not received an adequacy determination from the EU Commission, including transfers to the United States
7.2 Where a Restricted Transfer is made from the UK,
7.3 To the extent that the parties determine that a different version of the SCCs should apply.
8. Data Subject Rights
8.1 Cooperation for Data Subject Requests.
Provider shall assist and cooperate with Customer in responding to any Data Subject requests received by Customer.
8.2 Responding to Data Subjects.
In the event that Provider or a Sub-processor receives a Data Subject request relating to Customer Personal Data, Provider shall notify Customer in writing within 3 days.
9. Security Incident Response
9.1 Provider shall report a Security Incident to Customer as soon as practicable, but no later than seventy-two (72) hours after becoming aware of such Security Incident.
9.2 Immediately following Provider’s notification to Customer of a Security Incident, the parties shall coordinate with each other to investigate the Security Incident.
10. Data Protection Impact Assessment and Prior Consultation
Provider shall reasonably cooperate with Customer regarding any data protection assessment.
11. Return or Destruction of Personal Data
At Customer’s election, made by written notice, the Provider shall, and ensure that all Sub-processors shall return a complete copy of all Customer Personal Data to Customer.
12. Audit
12.1 Report on Compliance.
At Customer’s written request, Provider will provide Customer all information necessary to demonstrate compliance with Data Protection Laws and this DPA.
12.2 Audit.
Provider shall allow for and contribute to audits, including inspections, by Customer or an auditor mandated by Customer.
13. Jurisdiction and Governing Law
This DPA and all non-contractual obligations arising out of or in connection with it are governed by the laws of the Commonwealth of Virginia.
14. Indemnification; Limitations on Liability; Remedies.
Customer’s indemnification will be subject to an aggregate limitation of liability equal to the lesser of: (i) your pro-rated monthly service charge; or (ii) five hundred dollars ($500.00) (“Liability Cap”).
15. Severance.
If any provision of this DPA is or becomes illegal, invalid, or unenforceable, the legality, validity and enforceability of any other provision of this DPA shall not be affected.
EXHIBIT A: DETAILS OF PROCESSING
- Subject matter and duration of the Processing: The subject matter is the Personal Data that Processor Processes on behalf of Provider in connection with the execution of the Agreement. The duration of the Processing is determined by the contractual agreement between the Processor and the Provider.
- Nature and purpose of the Processing: Secure processing of Personal Data to facilitate the business services.
- Types of Customer Personal Data: The Personal Data to be Processed under the Agreement includes: Full Name, Phone number, Email, Physical address, Social security number, Date of birth.
- Categories of Data Subjects: The Processing of Personal Data will be conducted for the following Categories of Data Subjects: Provider’s customers, Provider’s customer’s customers, Provider’s employees.
EXHIBIT B: TECHNICAL, ORGANIZATIONAL, AND PHYSICAL SECURITY MEASURES
I. Confidentiality
Physical Access Control. Relevant controls to prevent unauthorized access to data processing facilities have been implemented.
Electronic Access Control. Relevant controls to prevent unauthorized use of data processing and storage systems have been implemented.
Internal Access Control. Relevant controls to prevent unauthorized reading, copying, changes or deletions of data have been implemented.
II. Integrity
Data Transfer Control. Measures to prevent unauthorized reading, copying, changes or deletions of data with electronic transfer or transport have been implemented.
Data Entry Control. Measures for the verification of personal data entries, changes or deletions have been implemented.
III. Availability and Resilience
- Availability Control. Measures to prevent accidental or willful destruction or loss of information have been implemented.
IV. Rapid Recovery
Measures to ensure the ability to restore the availability of services in a timely manner in the event of a physical or technical incident have been implemented.
V. Procedures for Regular Testing, Assessment and Evaluation of the Effectiveness of Measures
- At least annual risk assessment and security policy review.
VI. Order or Contract Control
Measures to prevent third party data processing other than upon instruction from the controller have been implemented.
VII. Organizational Control
Relevant technical and organizational measures have been implemented to ensure that, by default, only personal data which are necessary are processed.