Geckoboard DPA 2022.pdf

THIS DATA PROCESSING AGREEMENT

This DPA is entered into between the Data Controller and the Data Processor and is incorporated into and governed by the terms of the Agreement.

1 GENERAL

1.1 Definitions

Any capitalised term not defined in this DPA shall have the meaning given to it in the Agreement:

Term Definition
Affiliate Any entity that directly or indirectly controls, is controlled by, or is under common control of a party.
Agreement The agreement between the Data Controller and the Data Processor for the provision of the Services.
CCPA The California Consumer Privacy Act of 2018, along with its regulations and as amended from time to time.
Data Controller The Customer named in the Agreement.
Data Processor Datachoice Solutions Limited t/a Geckoboard, with company number 05958505 whose registered office is at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ.
Data Protection Legislation All laws and regulations applicable to the processing of Personal Data.
DPA This data processing agreement together with its exhibits.
Data Subject Has the same meaning as in Data Protection Law; also means a “Consumer” as defined in the CCPA.
EEA The European Economic Area.
EU GDPR Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data.
FDPA The Swiss Federal Act on Data Protection of 19 June 1992.
Personal Data Has the same meaning as in Data Protection Legislation.
Personal Data Breach A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
Restricted Transfer Means a transfer of Personal Data to any country or recipient outside of the EEA not subject to an adequacy determination.
Services All services and software applications provided to the Data Controller by the Data Processor under the Agreement.
Security Policy The Data Processor's security document as updated from time to time set out in Exhibit 2 of this DPA.
Sub-Processors Any third party engaged directly by the Data Processor to process Personal Data under this DPA.
SCCs Standard contractual clauses for the transfer of personal data to third countries.
Supervisory Authority A governmental body having binding legal authority over a party.
UKGDPR The EU GDPR as it forms part of the law of the UK.

1.2 Agreement Purpose

Pursuant to and in consideration for the continued provision of the Services by the Data Processor for the benefit of the Data Controller, the parties have entered into this DPA.

2 PURPOSE AND SCOPE

2.1 Processing Conditions

The Data Processor shall process Personal Data only to the extent necessary to provide the Services in accordance with the terms of the Agreement, this DPA and the Data Controller’s documented instructions.

2.2 Compliance of Data Controller

The Data Controller represents and warrants compliance with its obligations under this DPA and Data Protection Legislation, including any necessary permissions.

3 TECHNICAL AND ORGANISATIONAL MEASURES

3.1 Technical Measures

The Data Controller must:

4 DATA PROCESSOR’S OBLIGATIONS

4.1 Confidentiality and Training

The Data Processor shall ensure that all employees, agents, and contractors involved in handling Personal Data:

4.2 Personal Data Usage

The Data Processor shall not:

5 DATA SUBJECT ACCESS REQUESTS

5.1 Assistance in Requests

The Data Processor shall assist the Data Controller in dealing with Data Subject requests and shall notify the Data Controller of any relevant compliant or communication.

6 PERSONAL DATA BREACH

6.1 Breach Notification

The Data Processor shall notify the Data Controller without undue delay of any Personal Data Breach and take reasonable measures to secure the data.

7 SUB-PROCESSORS

7.1 Engagement of Sub-Processors

8 RESTRICTED TRANSFERS

8.1 Agreement on Restricted Transfers

The parties agree that Restricted Transfers shall be subject to the applicable SCCs and comply with legal safeguards.

9 COMPLIANCE, COOPERATION AND RESPONSE

9.1 Confidentiality Obligation

The Data Processor shall maintain confidentiality and notify the Data Controller of any legal requirement to disclose Data.

10 AUDIT

10.1 Audit Rights

The Data Processor shall provide reasonable information to demonstrate compliance with this DPA.

11 LIABILITY

11.1 Limitations on Liability

The limitations on liability in the Agreement apply to all claims made under this DPA.

12 TERM AND TERMINATION

12.1 Duration

This DPA remains effective as long as the Data Processor provides Services or retains Personal Data under the Agreement.

13 DELETION AND RETURN OF PERSONAL DATA

13.1 Data Return and Deletion

Upon termination or a written request, Personal Data shall be returned or deleted within specified timeframes.

14 MISCELLANEOUS PROVISIONS

14.1 Entire Agreement

This DPA is the complete understanding between the parties regarding the subject matter herein.

EXHIBIT 1

List of Parties

The Data Controller:

Description Details
Address As set out in the Agreement.
Contact As provided by the Customer.
Role Data Exporter.

The Data Processor:

Description Details
Address 71-75 Shelton Street, Covent Garden, London WC2H 9JQ.
Contact Luis Hernandez, Head of Data Privacy, privacy@geckoboard.com.
Role Data Importer.

EXHIBIT 2

Technical and Organisational Security Measures

Full details of the Data Processor’s technical and organisational security measures are available at https://support.geckoboard.com/hc/en-us/articles/203759278-Geckoboard-Security