This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between you ("Customer," "Data Controller") and RetentUp.com ("Processor," "we," "us," "our") for the use of the RetentUp.com platform (the "Service").
This DPA reflects the parties' agreement with respect to the processing of Personal Data in accordance with the requirements of Data Protection Laws, including the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.
In this DPA:
The Customer is the Data Controller, and the Processor is the Data Processor with respect to Personal Data processed through the Service. The Processor shall process Personal Data only on behalf of and in accordance with the Customer's documented instructions.
The Processor processes Personal Data for the purpose of providing the Service, which includes:
The Personal Data processed may include:
The Data Subjects are individuals whose Personal Data is uploaded or synced by the Customer to the Service, including:
The Processor shall process Personal Data only in accordance with the Customer's documented instructions, unless required to do so by applicable law. If the Processor believes an instruction violates Data Protection Laws, it shall inform the Customer.
The Processor shall ensure that persons authorized to process Personal Data are bound by confidentiality obligations.
The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
The Customer authorizes the Processor to engage Sub-processors to process Personal Data. The Processor shall:
Categories of Sub-processors include:
The Processor shall, to the extent possible, assist the Customer in responding to requests from Data Subjects to exercise their rights under Data Protection Laws, including:
The Processor shall notify the Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach. The notification shall include:
The Processor shall assist the Customer with:
The Processor shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice and confidentiality obligations.
The Customer shall ensure it has a lawful basis for processing Personal Data and for transferring Personal Data to the Processor.
The Customer is responsible for obtaining any necessary consents from Data Subjects for the processing of their Personal Data, including consent for communications via email, calls, iMessage, Telegram, and SMS where required by law.
The Customer shall ensure that Personal Data provided to the Processor is accurate and up to date.
The Customer shall provide clear and lawful instructions for the processing of Personal Data.
If Personal Data is transferred outside the EU/EEA or UK, the Processor shall ensure appropriate safeguards are in place, such as:
To the extent required, the parties agree that the European Commission's Standard Contractual Clauses for the transfer of Personal Data to third countries are incorporated by reference into this DPA.
The Processor shall retain Personal Data for the duration of the Service agreement or as instructed by the Customer.
Upon termination of the Service or upon the Customer's request, the Processor shall (at the Customer's choice):
The Processor may retain Personal Data to the extent required by applicable law, in which case it shall continue to protect the Personal Data in accordance with this DPA.
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms and Conditions.
The Processor shall indemnify the Customer against any claims, losses, damages, or fines arising from the Processor's material breach of this DPA or Data Protection Laws.
This DPA shall remain in effect for as long as the Processor processes Personal Data on behalf of the Customer. Upon termination of the Service agreement, the provisions of Section 6 (Data Retention and Deletion) shall apply.
The Processor may amend this DPA to reflect changes in Data Protection Laws or regulatory guidance, provided that such amendments do not materially reduce the Processor's obligations. The Processor shall notify the Customer of any material changes.
This DPA is governed by the laws of England and Wales. Any disputes arising from this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.
For questions regarding this DPA or data protection matters, please contact:
RetentUp.com
Email: dpo@retentup.com