Oomnitza Data Processing Addendum.pdf
OOMNITZA DATA PROCESSING ADDENDUM
Last Updated: February 23, 2024
This Data Processing Addendum, including its Exhibits, (“DPA”) forms part of the Enterprise Terms, SaaS Subscription Agreement, or other written or electronic agreement between Oomnitza, Inc. (“Oomnitza”) and Customer for the purchase of online services from Company (identified as the “Services” in the applicable agreement, and hereinafter defined as “Services”) (the “Agreement”), which involves the Processing of Personal Data subject to Applicable Data Protection Laws (each as defined below). The purpose of this DPA is to set forth the terms under which Company Processes Personal Data on behalf of Customer.
This DPA consists of the main body and Exhibits A and B.
HOW TO EXECUTE THIS ADDENDUM:
This Addendum has been pre-signed on behalf of Oomnitza.
To complete this Addendum, Customer must:
- Complete the information in the signature box and sign on page 5.
- Send the signed Addendum to Oomnitza by email to security@oomnitza.com
- Except as otherwise expressly provided in the Agreement, this Addendum will become legally binding upon receipt by Oomnitza of the validly completed Addendum at this email address.
1. Definitions. Capitalized terms used but not defined in this DPA have the meanings set forth in the Agreement. The terms controller, data subject, processor and supervisory authority have the meanings set forth in the Applicable Data Protection Laws.
- a. “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where “control” refers to the power to direct or cause the direction of the subject entity, whether through ownership of voting securities, by contract or otherwise.
- b. “Applicable Data Protection Laws” means the privacy, data protection and data security laws and regulations of any jurisdiction applicable to the Processing of Personal Data under the Agreement, including, without limitation, European Data Protection Laws, UK GDPR and the United States including the CCPA.
- c. “CCPA” means the California Consumer Privacy Act of 2018 and any regulations promulgated thereunder, in each case, as amended from time to time, including the California Privacy Rights Act of 2020, and any regulations promulgated thereunder.
- d. “Customer” means the entity that executed the Agreement together with its Affiliates (for so long as they remain Affiliates) which have signed Order Forms.
- e. “EEA” means the European Economic Area.
- f. “European Data Protection Laws” means the GDPR and other data protection laws and regulations of the EEA and European Union, and the Member States of each of the foregoing, to the extent applicable to the Processing of Personal Data under the Agreement.
- g. “EU – US Data Privacy Framework” or “EU/US DPF” means the Commission Implementing Decision dated July 10, 2023, pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate level of protection of personal data under the EU-US Data Privacy Framework.
- h. “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) which includes the EU/US DPF.
- i. “Information Security Incident” means a confirmed breach of Company’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Company’s possession, custody or control.
- j. “Personal Data” means Customer Data that constitutes “personal data,” “personal information,” or “personally identifiable information” defined in Applicable Data Protection Laws, or information of a similar character regulated thereby, provided that such data is electronic data and information submitted by or for Customer.
- k. “Processing” or “Process” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- l. “Public Authority” means a government agency or law enforcement authority, including judicial authorities.
2. Duration and Scope of DPA.
This DPA will remain in effect so long as Company Processes Personal Data, notwithstanding the expiration or termination of the Agreement. Exhibit B to this DPA applies solely to Processing subject to the CCPA to the extent Customer is a “business” (as defined in CCPA) with respect to such Processing.
3. Customer Instructions.
Company will Process Personal Data only in accordance with Customer’s instructions to Company. This DPA is a complete expression of such instructions, and Customer’s additional instructions will be binding on Company only pursuant to an amendment to this DPA signed by both parties. Customer instructs Company to Process Personal Data via the Services and as authorized by the Agreement. Company shall inform Customer immediately: (a) if, in its opinion, an instruction from Customer constitutes a breach of any Applicable Data Protection Laws; (b) if Company is unable to follow Customer’s instructions for the Processing of Personal Data; or (c) if Company has reason to believe that Company is subject to changes in Applicable Data Protection Laws.
4. Security of Personal Data.
- a. Company Security Measures. Company may update the Security Measures from time to time, so long as the updated measures do not materially decrease the overall protection of Personal Data.
- b. Information Security Incidents. Company will notify Customer without undue delay of any Information Security Incident of which Company becomes aware. Such notifications will describe available details of the Information Security Incident, including steps taken to mitigate the potential risks and steps Company recommends the Customer take to address the Information Security Incident.
- c. Audits of Compliance DPIAs. Customer uses external auditors to verify the adequacy of its security measures, including the security of the physical facilities from which Customer provides the Services. At Customer’s written request, Company will provide Customer with a copy of the Audit Report so that Customer can verify Company’s compliance with its obligations under this DPA. Customer agrees that the Audit Report, together with any third-party certification maintained by Company, will be used to satisfy any audit or inspection requests by or on behalf of Customer and to demonstrate compliance with this DPA.
- d. Data Protection Impact Assessments (DPIAs). Upon Customer’s written request, Company will provide Customer with reasonable cooperation and assistance needed to fulfil Customer’s obligation under Applicable Data Protection Laws to carry out a data protection impact assessment related to Customer’s use of the Services.
5. Customer’s Responsibilities.
- a. Customer Obligations. Customer shall have sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which Customer acquired Personal Data. Customer is solely responsible for its use of the Services, including making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Personal Data.
- b. Prohibited Data. Customer represents and warrants to Company that Customer Data does not include any prohibited personal information without Company’s prior written consent, including social security numbers, protected health information, or information subject to restrictions under Applicable Data Protection Laws.
6. Compliance with Laws & Data Subject Rights.
- a. Compliance with Laws. Each party will comply with all Applicable Data Protection Laws.
- b. Personal Data Disclosures & Government Requests. Company will not disclose Personal Data to any third party except as necessary to comply with Applicable Data Protection Laws.
- c. Data Subject Request Assistance. Company will provide Customer with assistance reasonably necessary for Customer to perform its obligations under Applicable Data Protection Laws regarding data subject requests with respect to Personal Data in Company’s possession.
- d. Customer’s Responsibility for Requests. Company will not respond to a Data Subject Request, except where Customer authorizes Company to redirect the Data Subject Request as necessary.
7. EU/US DPF; UK, Switzerland, Changes in Laws.
- a. EU/US DPF. As of the Effective Date, Company is registered with the United States for, and complies with, the EU/US DPF.
- b. The United Kingdom, Switzerland. Customer may transfer Personal Data to Company from such countries during the Term of this DPA.
- c. Changes in Applicable Data Protection Laws. Company shall use reasonable efforts to make necessary changes to facilitate compliance with changes in Applicable Data Protection Laws.
8. Subprocessors.
- a. Consent to Subprocessor Engagement. Customer authorizes the engagement of designated Subprocessors to Process Personal Data.
- b. Requirements for Subprocessor Engagement. Company will enter into a written contract with such Subprocessors containing data protection obligations.
- c. Subprocessor Changes. Company will update the Subprocessor Site when engaging new Subprocessors.
- d. Opportunity to Object to Subprocessor Changes. Customer may object to Subprocessor engagement and work with Company to resolve objections.
9. Return or Deletion of Personal Data.
Upon request by Customer made within 60 days after the effective date of termination or expiration of this DPA, Company will delete or return Customer Data within a reasonable period of time.
10. Miscellaneous.
Except as expressly modified by the DPA, the terms of the Agreement remain in full force and effect. Notwithstanding anything in the Agreement or any order form, the parties acknowledge that Company’s access to Personal Data does not constitute part of the consideration exchanged by the parties. Customer is responsible for ensuring that email addresses for notices are valid.
CUSTOMER: _____________________________ OOMNITZA, INC.
By: ___________________________________ By: _______________________________________
Jon Davis Name: ________________________________ Name: ____________________________________ Chief Information Security Officer Title: _________________________________ Title: _____________________________________
2/23/2024 Date: _________________________________ Date: _____________________________________
EXHIBIT A
SECURITY MEASURES
Company processes all Personal Data received from Controller under this DPA in conformity with the following technical and organizational measures:
- Information Security Policy. Company shall maintain a written information security policy applicable to all authorized personnel.
- Training. Company will provide role-based information security training.
- Access Control. Company will maintain access control consistent with industry standards, limiting access to Personal Data to those with a need-to-know.
- Logical Separation. Company will ensure Personal Data is logically separated from other Company client data.
- Encryption. Company will utilize industry standard encryption technologies with respect to Personal Data.
- Password Management. Company will maintain a password management policy designed to ensure strong passwords.
- Incident Response Plan. Company will maintain an incident response plan that addresses Information Security Incident handling.
- Penetration Testing. Company will retain an independent third-party to carry out an annual penetration test of Company’s key systems.
- Backups of Personal Data. Company will maintain a backup system for timely recovery in the event of service interruption.
- Disaster Recovery and Business Continuity Plans. Company will maintain disaster recovery and business continuity plans consistent with industry standards.
EXHIBIT B
UNITED STATES EXHIBIT
A. The parties acknowledge that Customer discloses Personal Data to Company for specified purposes. B. Customer shall have the right to take appropriate steps to stop unauthorized use of Personal Data. C. Company will not retain, use, disclose, sell, or share the Personal Data other than to provide the Services specified by Customer’s instructions. D. The parties acknowledge that Company’s retention, use, and disclosure of personal information authorized by Customer’s instructions are integral to Company’s provision of the Services.