SERVICES AGREEMENT
Last Modified: May 1, 2023
NOTE REGARDING NEW SUB-PROCESSORS & OTHER PRIVACY UPDATES: Please sign up here to receive notices of new Sub-processor, Processing locations, or material changes to the Privacy Notice (“Privacy Updates”) after executing this DPA.
If you sign up for Privacy Updates, we will notify you (via email) at least 30 days prior to onboarding any new Sub-processor. From the date of notification, you will have 10 days to object to having any Personal Data of your Data Subjects Processed by that Sub-processor in accordance with Paragraph 11 of this DPA.
This Data Processing Agreement (the “DPA“, as updated from time to time) is a legal agreement between You (“Customer”, “You”, “Your”) and Company (each a “party” and collectively the “parties”) and defines the terms and conditions under which Personal Data will be processed by Company (as defined below).
The Parties agree as follows:
|
Details of the Processing (Annex I of the EU SCCs and Tables 1 - 4 of the UK IDTA) |
||
| Details of the Parties | ||
| Customer | Company | |
| 1.1 Organization Details | As specified under the applicable ordering document(s). | As specified under the applicable ordering document(s). |
| 1.2 Key Contact (Contact person for data protection matters) | As specified under the applicable ordering document(s), unless otherwise specified in writing between the parties. |
Full Name: Ben Hayes Job Title: Chief Privacy Officer Email: bhayes@zetaglobal.com |
| 1.3 Role in the Processing | Controller | Processor |
| 2. Details of the Processing | ||
| 2.1 Categories of Data Subjects | As described in Attachment 2. | |
| 2.2 Categories of Personal Data | As described in Attachment 2. | |
| 2.3 Sensitive or Special Category Data Processing, if applicable | N/A. The Agreement does not allow the processing of special categories of personal data, as defined by GDPR. | |
| 2.4 Transfer Frequency | As described in Attachment 2. | |
| 2.5 Categories of Processing Operations | As described in Attachment 2. | |
| 2.6 Purpose(s) of the data transfer and further Processing | As described in Attachment 2. | |
| 2.7 Data Retention Period | For the duration of the Agreement, unless or until Customer requests deletion, including by its own actions within the Services | |
| 2.8 For transfers to (sub-) processors, also specify subject matter, nature and duration of the Processing | Transfers to Sub-processors are for the duration of the Agreement, unless or until Customer requests deletion, including by its own actions within the Services. | |
| 3. Transfer Mechanisms | ||
| 3.1 Roles of the Parties | For the purposes of this DPA and the EU SCCs, Company shall be the "data exporter" and Customer (and/or the Authorized Affiliates, as applicable) is the "data importer.” | |
| 3.2 Applicable Modules to the EU SCCs | Module 1 | No |
| Module 2 | No | |
| Module 3 | No | |
| Module 4 | Yes | |
| 3.3 Use of Sub-processors | For the purposes of Clause 9 (Use of subprocessors), the Parties agree that General Written Authorization will apply, according to the language agreed upon under Paragraph 11 of this DPA. | |
| 3.4 The Docking Clause | The optional language of Clause 11 will not apply. | |
| 3.5 Competent Supervisory Authority (Annex I.C) | The competent supervisory authority according to Clause 13 of the EU SCCs will be Belgium. For the UK IDTA, the competent supervisory authority will be the UK Information Commissioner’s Office | |
| 3.6 Jurisdiction and Forum | For the purposes of Clauses 17 and 18, the applicable jurisdiction and forum will be Belgium. | |
| 3.7 Details of the Processing | The contents of Appendices I, II, and III for Module 2 are included in this DPA, under this Attachment. | |
| 3.8 Is personal data received from the Importer combined with personal data collected by the Exporter? (UK IDTA Table 2) | No | |
| Which Parties may end this Addendum as set out in Section 19: | ||
| 3.9 Ending this Addendum when the Approved Addendum changes (UK IDTA Table 4) | Importer | |
| Exporter | ||
| X | neither Party | |
| Security Measures | Selligent | Grow | Loyalty | Liveclicker |
|---|---|---|---|---|
| Measures of pseudonymisation and encryption of personal data | X | X | X | X |
| Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services | X | X | X | X |
| Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident | X | X | X | X |
| Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures in order to ensure the security of the processing | X | X | X | X |
| Measures for user identification and authorisation | X | X | X | X |
| Measures for the protection of data during transmission | X | X | X | X |
| Measures for the protection of data during storage | X | X | X | X |
| Measures for ensuring physical security of locations at which personal data are processed | X | X | X | X |
| Measures for ensuring events logging | X | X | X | X |
| Measures for ensuring system configuration, including default configuration | X | X | X | X |
| Measures for internal IT and IT security governance and management | X | X | X | X |
| Measures for certification/assurance of processes and products | ||||
| Measures for ensuring data minimisation | X | X | X | X |
| Measures for ensuring data quality | ||||
| Measures for ensuring limited data retention | X | X | X | X |
| Measures for ensuring accountability | X | X | X | X |
| Measures for allowing data portability and ensuring erasure | X | X | X | X |