Geckoboard DPA 2022.pdf
THIS DATA PROCESSING AGREEMENT
This DPA is entered into between the Data Controller and the Data Processor and is incorporated into and governed by the terms of the Agreement.
1 GENERAL
1.1 Definitions
Any capitalised term not defined in this DPA shall have the meaning given to it in the Agreement:
| Term | Definition |
|---|---|
| Affiliate | Any entity that directly or indirectly controls, is controlled by, or is under common control of a party. |
| Agreement | The agreement between the Data Controller and the Data Processor for the provision of the Services. |
| CCPA | The California Consumer Privacy Act of 2018, along with its regulations and as amended from time to time. |
| Data Controller | The Customer named in the Agreement. |
| Data Processor | Datachoice Solutions Limited t/a Geckoboard, with company number 05958505 whose registered office is at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. |
| Data Protection Legislation | All laws and regulations applicable to the processing of Personal Data. |
| DPA | This data processing agreement together with its exhibits. |
| Data Subject | Has the same meaning as in Data Protection Law; also means a “Consumer” as defined in the CCPA. |
| EEA | The European Economic Area. |
| EU GDPR | Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data. |
| FDPA | The Swiss Federal Act on Data Protection of 19 June 1992. |
| Personal Data | Has the same meaning as in Data Protection Legislation. |
| Personal Data Breach | A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data. |
| Restricted Transfer | Means a transfer of Personal Data to any country or recipient outside of the EEA not subject to an adequacy determination. |
| Services | All services and software applications provided to the Data Controller by the Data Processor under the Agreement. |
| Security Policy | The Data Processor's security document as updated from time to time set out in Exhibit 2 of this DPA. |
| Sub-Processors | Any third party engaged directly by the Data Processor to process Personal Data under this DPA. |
| SCCs | Standard contractual clauses for the transfer of personal data to third countries. |
| Supervisory Authority | A governmental body having binding legal authority over a party. |
| UKGDPR | The EU GDPR as it forms part of the law of the UK. |
1.2 Agreement Purpose
Pursuant to and in consideration for the continued provision of the Services by the Data Processor for the benefit of the Data Controller, the parties have entered into this DPA.
2 PURPOSE AND SCOPE
2.1 Processing Conditions
The Data Processor shall process Personal Data only to the extent necessary to provide the Services in accordance with the terms of the Agreement, this DPA and the Data Controller’s documented instructions.
2.2 Compliance of Data Controller
The Data Controller represents and warrants compliance with its obligations under this DPA and Data Protection Legislation, including any necessary permissions.
3 TECHNICAL AND ORGANISATIONAL MEASURES
3.1 Technical Measures
The Data Controller must:
- Implement appropriate measures to protect Personal Data, including:
- Pseudonymisation and encryption of Personal Data.
- Ensuring confidentiality, integrity, and availability of processing systems.
- Restoration processes in the event of incidents.
4 DATA PROCESSOR’S OBLIGATIONS
4.1 Confidentiality and Training
The Data Processor shall ensure that all employees, agents, and contractors involved in handling Personal Data:
- Are aware of its confidential nature and are bound to keep it confidential and protected.
- Have received appropriate training on their responsibilities.
4.2 Personal Data Usage
The Data Processor shall not:
- Sell Personal Data.
- Retain or disclose Personal Data for purposes other than providing the Services.
5 DATA SUBJECT ACCESS REQUESTS
5.1 Assistance in Requests
The Data Processor shall assist the Data Controller in dealing with Data Subject requests and shall notify the Data Controller of any relevant compliant or communication.
6 PERSONAL DATA BREACH
6.1 Breach Notification
The Data Processor shall notify the Data Controller without undue delay of any Personal Data Breach and take reasonable measures to secure the data.
7 SUB-PROCESSORS
7.1 Engagement of Sub-Processors
- Affiliates of the Data Processor may be used as Sub-processors.
- The Data Controller may object to new Sub-processors.
8 RESTRICTED TRANSFERS
8.1 Agreement on Restricted Transfers
The parties agree that Restricted Transfers shall be subject to the applicable SCCs and comply with legal safeguards.
9 COMPLIANCE, COOPERATION AND RESPONSE
9.1 Confidentiality Obligation
The Data Processor shall maintain confidentiality and notify the Data Controller of any legal requirement to disclose Data.
10 AUDIT
10.1 Audit Rights
The Data Processor shall provide reasonable information to demonstrate compliance with this DPA.
11 LIABILITY
11.1 Limitations on Liability
The limitations on liability in the Agreement apply to all claims made under this DPA.
12 TERM AND TERMINATION
12.1 Duration
This DPA remains effective as long as the Data Processor provides Services or retains Personal Data under the Agreement.
13 DELETION AND RETURN OF PERSONAL DATA
13.1 Data Return and Deletion
Upon termination or a written request, Personal Data shall be returned or deleted within specified timeframes.
14 MISCELLANEOUS PROVISIONS
14.1 Entire Agreement
This DPA is the complete understanding between the parties regarding the subject matter herein.
EXHIBIT 1
List of Parties
The Data Controller:
| Description | Details |
|---|---|
| Address | As set out in the Agreement. |
| Contact | As provided by the Customer. |
| Role | Data Exporter. |
The Data Processor:
| Description | Details |
|---|---|
| Address | 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. |
| Contact | Luis Hernandez, Head of Data Privacy, privacy@geckoboard.com. |
| Role | Data Importer. |
EXHIBIT 2
Technical and Organisational Security Measures
Full details of the Data Processor’s technical and organisational security measures are available at https://support.geckoboard.com/hc/en-us/articles/203759278-Geckoboard-Security