DATA PROCESSING AGREEMENT/ADDENDUM (US)

WHEREAS,           Shield FC shall provide the services set forth in the Agreement (collectively, the “Services”) for Client, as described in the Agreement; and

WHEREAS,            In the course of providing the Services pursuant to the Agreement, Shield FC may process Personal Data on Client behalf, in the capacity of a “Data Processor”; and the Parties wish to set forth the arrangements concerning the Processing of Personal Data (defined below) within the context of the Services and agree to comply with the following provisions with respect to any Personal Data, each acting reasonably and in good faith.

NOW THEREFORE, in consideration of the mutual promises set forth herein and other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged by the Parties, the parties, intending to be legally bound, agree as follows:

  1. INTERPRETATION AND DEFINITIONS

The headings contained in this DPA are for convenience only and shall not be interpreted to limit or otherwise affect the provisions of this DPA. References to clauses or sections are references to the clauses or sections of this DPA unless otherwise stated. Words used in the singular include the plural and vice versa, as the context may require. Capitalized terms not defined herein shall have the meanings assigned to such terms in the Agreement. Definitions:

  • Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. “Control”, for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
    • Collect” means buying, renting, gathering, obtaining, receiving, or accessing any Personal Data pertaining to a consumer by any means; and has such additional meaning provided by applicable Privacy Laws. This term includes receiving information from the consumer, either actively or passively, or by observing the consumer’s behavior.
    • Combine” means to combine or aggregate Personal Data Processed in connection with the Agreement with any other Personal Data that We receive from a third party or that was separately collected by Us apart from this Agreement.
    • Commercial Purposes” means to advance a person’s commercial or economic interests, such as by inducing another person to buy, rent, lease, join, subscribe to, provide, or exchange products, goods, property, information, or services, or enabling or effecting, directly or indirectly, a commercial transaction; and has such additional meaning provided by applicable Privacy Laws.
    • Company Data” means data acquired directly or indirectly from or created about Client (including its Affiliates) and data generated, collected, or developed in connection with Our provision of the Services or Hosted Environment.  Company Data includes any Personal Data Processed in connection with the Services.
    • Controller” or “Data Controller” means the entity which determines the purposes and means of the Processing of Personal Data, as provided under applicable Privacy Law.
    • Data Subject” means the identified or identifiable person to whom the Personal Data relates.
    • Personal Data” means an information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual, consumer or household. Personal Data further includes (i) information that if compromised (e.g., the information is subject to unauthorized acquisition or access) would give rise to a notification obligation under applicable Privacy Law, and (ii) information subject to or protected by applicable Privacy Law, such as the California Consumer Privacy Act.
    • Privacy Laws” means the privacy laws and regulations of the US, to the extent applicable to the Processing of Personal Data under the Agreement.
    • Process(ing)” means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. Without limiting the generality of the foregoing, this term includes remote access to data and systems that process data.
    • Processor” or “Data Processor” means the entity which Processes Personal Data on behalf of the Controller.
    • Security Documentation” means the Security Documentation applicable to the specific Services purchased by Client, as updated from time to time. Client shall send a request to [email protected] to receive a copy of the Security Documentation.
    • Sell” means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s Personal Data for monetary or other valuable consideration; and has such additional meaning provided by applicable Privacy Laws.
    • Share” means sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s Personal Data for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, including transactions in which no money is exchanged.
    • Sub-processor” means any Processor engaged by Shield FC and/or Shield FC Affiliate to Process Personal Data on behalf of Client.
  • PROCESSING OF PERSONAL DATA
  • Roles of the Parties. The Parties acknowledge and agree that with regard to the Processing of Personal Data under this DPA Shield FC is the Data Processor. Shield FC may engage Sub-processors pursuant to the requirements set forth in Section ‎4 “Authorization Regarding Sub-processors” below. For clarity, this DPA shall not apply with respect to Shield FC processing activity as a Data Controller of its own Personal Data.
    • Client’s Processing of Personal Data. Client shall, in its use of the Services, Process Personal Data in accordance with the requirements of applicable Privacy Laws. For the avoidance of doubt, Client’s instructions to Shield FC for the Processing of Personal Data shall comply with applicable Privacy Laws. Without limitation, Client shall comply with any and all transparency-related obligations (including, without limitation, displaying any and all relevant and required privacy notices or policies) and shall at all times have any and all required ongoing legal bases in order to collect, Process and transfer to Shield FC the Personal Data and to authorize the Processing by Shield FC of the Personal Data which is authorized in this DPA.
  • Shield FC’s Processing of Personal Data.
    • Subject to the Agreement, Shield FC shall Process Personal Data that is subject to this DPA only in accordance with Client’s documented instructions as necessary for the performance of the Services and the Agreement, unless required to otherwise by applicable law to which Shield FC is subject. In such case, Shield FC shall notify the Client of the legal requirement before Processing, unless that law prohibits such notification on important grounds of public interest. The duration of the Processing, the nature and purposes of the Processing, as well as the types of Personal Data Processed and categories of Data Subjects under this DPA are further specified in Schedule 1 to this DPA. Shield FC (i) will retain Personal Data only for so long as is necessary to perform the Services, (ii) will not retain, use or disclose Personal Data outside the direct business relationship between Client and Shield FC, and (iii) will Process Personal Data for the purpose of performing the Services specified in the Agreement.
    • To the extent that Shield FC cannot comply with a request (including, without limitation, any instruction, direction, code of conduct, certification, or change of any kind) from Client and/or its authorized users relating to Processing of Personal Data or where Shield FC considers such a request to be unlawful, Shield FC (i) shall inform Client, providing relevant details of the problem (but not legal advice), (ii) Shield FC may temporarily cease all Processing of the affected Personal Data (other than securely storing those data), and (iii) if the Parties do not agree on a resolution to the issue in question and the costs thereof, each Party may, as its sole remedy, terminate the Agreement and this DPA with respect to the affected Processing, and Client shall pay to Shield FC all the amounts owed to Shield FC or due before the date of termination. Client will have no further claims against Shield FC (including, without limitation, requesting refunds for Services) due to the termination of the Agreement and/or the DPA in the situation described in this paragraph (excluding the obligations relating to the termination of this DPA set forth below).
    • Shield FC will not be liable in the event of any claim brought by a third party, including, without limitation, a Data Subject, arising from any act or omission of Shield FC to the extent that such is a direct result of Client’s instructions.
    • In accordance with Section 1798.140(w)(2)(B) of the California Consumer Privacy Act (“CCPA”) and any other applicable Privacy Laws, Shield FC certifies that it has (from the date of its initial Processing) and will (for so long as it Processes Personal Data pursuant to the Agreement) comply with the terms and conditions of this DPA.  Shield FC will certify to Client, upon request once annually, that Shield FC has and will Process Personal Data in accordance with applicable Privacy Laws. Shield FC shall not further Collect, Sell, Share, Combine or use Personal Data without Client’s prior express written consent, and only as necessary to perform the stated business purpose.
  • RIGHTS OF DATA SUBJECTS. If Shield FC receives a request from a Data Subject to exercise its rights under applicable Privacy Law (“Data Subject Request”), Shield FC shall, to the extent legally permitted, promptly notify and forward such Data Subject Request to Client. Taking into account the nature of the Processing, Shield FC shall use commercially reasonable efforts to assist Client by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Client’s obligation to respond to a Data Subject Request under applicable Privacy Laws, including promptly informing Company if Service Provider is unable to delete Personal Data or otherwise implement the Data Subject Request. Client shall be responsible for any reasonable costs arising from Shield FC’s provision of such assistance. Shield FC may reasonably charge Client for costs and expenses incurred by Shield FC in the provision of such assistance to Client to ensure Client’s compliance.
  • SHIELD FC PERSONNEL
    • Shield FC shall, in accordance with and subject to applicable Privacy Laws and the Agreement, grant access to the Personal Data to persons under its authority (including, without limitation, its personnel) only on a need to know basis and ensure that such persons engaged in the Processing of Personal Data are adequately trained on proper data handling and are under appropriate, binding and enforceable confidentiality, privacy and security obligations to Shield FC, including obligations necessary for Shield FC to comply with the Agreement .
    • Shield FC may disclose and Process the Personal Data (a) as permitted hereunder, (b) to the extent required by a court of competent jurisdiction or other applicable governmental authority as required by applicable privacy laws, and (c) on a “need-to-know” basis under an obligation of confidentiality to legal counsel and its data protection advisor(s).
  • AUTHORIZATION REGARDING SUB-PROCESSORS
    • Shield FC’s current list of Sub-processors is included in Schedule 2 and is hereby approved by Data Controller, including as to the services provided and data storage locations of each such approved Sub-processor. The Sub-processor List as of the date of execution of this DPA is hereby authorized by Client. Shield FC shall use commercially reasonable efforts to ensure that neither it nor any of its then-approved Sub-processor will disclose, share or provide Personal Data to any third party to Process such data on Shield FC’s behalf unless and until such third party becomes an approved Sub-processor in accordance with this Section 4.
    • Shield FC shall provide notification of any new Sub-processor(s) before authorizing such new Sub-processor(s) (including any change to services provided and data storage locations) to Process Personal Data in connection with the provision of the Services.
    • Client may object to Shield FC’s new or modified use of a Sub-processor by notifying Shield FC promptly in writing within three (3) business days after receipt of Shield FC’s notice in accordance with the mechanism set out in Section 4.2. Such written objection shall include the reasons related to Privacy Laws for objecting to Shield FC’s use of such Sub-processor. Failure to object to such Sub-processor in writing within three (3) business days following Shield FC’s notice shall be deemed as acceptance of the Sub-Processor. In the event Client objects to a Sub-processor, as permitted in the preceding sentences, Shield FC will use reasonable efforts to make available to Client a change in the Services or recommend a commercially reasonable change to Client’s use of the Services to avoid Processing of Personal Data by the objected-to Sub-processor without unreasonably burdening the Client. If Shield FC is unable to make available such change within a reasonable period of time, which shall not exceed thirty (30) days, Client may, as a sole remedy, terminate the applicable Agreement with respect only to those Services which cannot be provided by Shield FC without the use of the objected-to Sub-processor by providing written notice to Shield FC provided that all amounts due under the Agreement before the termination date with respect to the Processing at issue shall be duly paid to Shield FC. Until a decision is made regarding the Sub-processor, Shield FC may temporarily suspend the Processing of the affected Personal Data. Client will have no further claims against Shield FC due to the termination of the Agreement (including, without limitation, requesting refunds) and/or the DPA in the situation described in this paragraph.
  • SECURITY
    • Controls for the Protection of Personal Data. Taking into account the state of the art, the costs of implementation, the scope, the context, the purposes of the Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Shield FC shall maintain all industry-standard technical and organizational measures required pursuant to applicable Privacy Laws for protection of the security (including protection against unauthorized or unlawful Processing and against accidental or unlawful destruction, loss or alteration or damage, unauthorized disclosure of, or access to, Personal Data), confidentiality, availability and integrity of Personal Data, including such requirements as set forth in the Security Documentation .  For the avoidance of doubt, if Privacy Laws or industry standards require more robust or more protective safeguards and controls to protect Personal Data than are included in the Security Documentation, such obligations required by Privacy Laws and industry standards shall govern and control and be deemed requirements incorporated into this Agreement.
    • Third-Party Certifications and Audits. Upon Client’s written request at reasonable intervals but not more than once every 12 months, and subject to the confidentiality obligations set forth in the Agreement and this DPA, Shield FC shall make available to Client that is not a competitor of Shield FC (or Client’s independent, third-party auditor that is not a competitor of Shield FC) a copy of Shield FC’s then most recent third-party audits and certifications, as applicable (provided, however, that such audits, certifications and the results therefrom, including the documents reflecting the outcome of the audit and/or the certifications, shall only be used by Client to assess compliance with this DPA, and shall not be used for any other purpose or disclosed to any third party without Shield FC’s prior written approval and, upon Shield FC’s first request, Client shall return all records or documentation in Client’s possession or control provided by Shield FC in the context of the audit and/or the certification). At Client’s cost and expense, Shield FC shall allow for and contribute to audits, including inspections of Shield FC, conducted by the controller or another auditor mandated by the controller (who is not a direct or indirect competitor of Shield FC) provided that the parties shall agree on the scope, methodology, timing and conditions of such audits and inspections. Notwithstanding anything to the contrary, such audits and/or inspections shall not contain any information, including without limitation, personal data that does not belong to Client. Client shall be responsible for any costs arising from Shield FC’s provision of such assistance. Shield FC may reasonably charge Client for costs and expenses incurred by Shield FC in the provision of assistance to Client in the performance of any audits or inspections.
  • PERSONAL DATA INCIDENT MANAGEMENT AND NOTIFICATION

Subject to the terms of the Agreement, Shield FC shall, at the choice of Client, delete, return the Personal Data to Client after the end of the provision of the Services relating to Processing, and shall delete existing copies unless applicable law requires storage of the Personal Data. In any event, to the extent required or allowed by applicable law, Shield FC may retain one copy of the Personal Data for evidence purposes and/or for the establishment, exercise or defence of legal claims and/or to comply with applicable laws and regulations. If the Client requests the Personal Data to be returned, the Personal Data shall be returned in the format generally available for Shield FC’s clients.

  • RETURN AND DELETION OF PERSONAL DATA. Subject to the Agreement, Shield FC shall, at the choice of Client, delete or return the Personal Data to Client after the end of the provision of the Services relating to Processing or at such earlier time requested by Client, and shall delete existing copies unless applicable law requires storage of the Personal Data. In any event, to the extent required by applicable law, Shield FC may retain one copy of the Personal Data for evidence purposes and/or for the establishment, exercise or defence of legal claims and/or to comply with applicable laws and regulations, whereupon Shield FC shall notify Client in writing of the Personal Data being retained and the basis therefore. If the Client requests the Personal Data to be returned, the Personal Data shall be returned in the industry standard format generally available for Shield FC’s Clients. Shield FC shall ensure and guaranty the confidentiality and protection of Personal Data to the extent retained by Shield FC.
  • AUTHORIZED AFFILIATES

The Parties acknowledge and agree that, by executing the DPA, the Client enters into the DPA on behalf of itself and, as applicable, in the name and on behalf of its authorized Affiliates, thereby establishing a separate DPA between Shield FC. Each authorized Affiliate agrees to be bound by the obligations under this DPA. All access to and use of the Services by authorized Affiliates must comply with the terms and conditions of the Agreement and this DPA and any violation of the terms and conditions therein by an authorized Affiliate shall be deemed a violation by Client.

The Client shall remain responsible for coordinating all communication with Shield FC under the Agreement and this DPA and shall be entitled to make and receive any communication in relation to this DPA on behalf of its authorized Affiliates.

  1. TERMINATION. This DPA shall automatically terminate upon the termination or expiration of the Agreement. Sections, 2.2, 2.3.3, 8 and 11, and such other obligations in the Agreement related to Shield FC’s protection and other Processing of Personal Data and Company Data shall survive the termination or expiration of this DPA for so long as such data remains in Shield FC’s possession or control. This DPA cannot, in principle, be terminated separately to the Agreement, except where the Processing ends before the termination of the Agreement, in which case, this DPA shall automatically terminate.
  1. RELATIONSHIP WITH AGREEMENT. In the event of any conflict between the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA shall prevail over the conflicting provisions of the Agreement. Notwithstanding anything to the contrary in the Agreement and/or in any agreement between the parties and to the maximum extent permitted by law: (A) Shield FC (including Shield FC’s Affiliates’) entire, total and aggregate liability, related to personal data or information, privacy, or for breach of, this DPA and/Privacy Laws, including, without limitation, if any, any indemnification obligation or applicable law regarding data protection or privacy, shall be limited to the amounts paid to Shield FC under the Agreement within twelve (12) months preceding the event that gave rise to the claim. This limitation of liability is cumulative and not per incident; (B) In no event will Shield FC and/or Shield FC Affiliates and/or their third-party providers, be liable under, or otherwise in connection with this DPA for: (i) any indirect, exemplary, special, consequential, incidental or punitive damages; (ii) any loss of profits, business, or anticipated savings;  (iii) any loss of, or damage to data, reputation, revenue or goodwill; and/or (iv) the cost of procuring any substitute goods or services; and (C) The foregoing exclusions and limitations on liability set forth in this Section shall apply: (i) even if Shield FC, Shield FC Affiliates or third-party providers, have been advised, or should have been aware, of the possibility of losses or damages; (ii) even if any remedy in this DPA fails of its essential purpose; and (iii) regardless of the form, theory or basis of liability (such as, but not limited to, breach of contract or tort).
  1. AMENDMENTS. This DPA may be amended at any time by a written instrument duly signed by each of the Parties.
  1. LEGAL EFFECT. Either Party may assign this DPA or its rights or obligations hereunder to any Affiliate thereof, or to a successor or any Affiliate thereof, in connection with a merger, consolidation or acquisition of all or substantially all of its shares, assets or business relating to this DPA or the Agreement.  Neither Party may otherwise assign, voluntarily or by operation of law, any of its rights or obligations under this Agreement without the prior written consent of the other Party and any such assignment not so approved shall be null and void.
  1. SIGNATURE. The Parties represent and warrant that they each have the power to enter into, execute, perform and be bound by this DPA. You, as the signing person on behalf of Client, represent and warrant that you have, or you were granted, full authority to bind the Organization to this DPA. If you cannot, or do not have authority to, bind the Organization, you shall not supply or provide Personal Data to Shield FC.  

List of Schedules

SCHEDULE 1 – DETAILS OF THE PROCESSING

Subject matter. Shield FC will Process Personal Data only as necessary to perform the Services pursuant to the Agreement, as further instructed by Client in its use of the Services.

Nature and Purpose of Processing.

  1. Providing the Service(s) to Client; Performing the Agreement, this DPA and/or other contracts executed by the Parties;
  2. Providing support and technical maintenance, if agreed in the Agreement;
  3. Resolving disputes; enforcing the Agreement, this DPA and/or defending Shield FC’s rights under the Agreement;
  4. Management of the Agreement, the DPA and/or other contracts executed by the Parties, including fees payment, account administration, accounting, tax, management, litigation; and
  5. Subject to the requirements of the DPA, complying with applicable laws and regulations.
  6.  

Duration of Processing. Subject to any Section of the DPA and/or the Agreement dealing with the duration of the Processing and the consequences of the expiration or termination thereof, Shield FC will Process Personal Data for the duration of the Agreement, unless otherwise agreed upon in writing.

Type of Personal Data. Client may submit Personal Data to the Services, the extent of which is determined and controlled by Client in its sole discretion, and which may include, but is not limited to the following categories of Personal Data:

  • Electronic communications
  • Name
  • Email address
  • Any other Personal Data or information that the Client decides to provide to Shield FC or the Services.

Categories of Data Subjects. Those individuals to whom the Personal Data relates.

SCHEDULE 2 – SUB-PROCESSORS LIST