Legal
Data Processing Addendum
Our standard terms for processing personal data on behalf of customers.
This Data Processing Addendum ("DPA") forms part of the agreement between Be Heard Labs, Inc. ("Gather," "Processor") and the customer entity ("Customer," "Controller") that has entered into an agreement for Gather's Services (the "Agreement"). This DPA reflects the parties' agreement on the processing of Personal Data in connection with the Services.
Effective date: the date of the Agreement, or the date this DPA is signed, whichever is later.
1. Definitions
Terms not defined here have the meaning given in the Agreement. "GDPR" means Regulation (EU) 2016/679 and, as applicable, the UK GDPR and the Swiss FADP. "CCPA" means the California Consumer Privacy Act as amended by the CPRA. "Personal Data," "Controller," "Processor," "Data Subject," "Processing," and "Personal Data Breach" have the meanings given under Data Protection Laws. "Customer Personal Data" means Personal Data that Gather Processes on behalf of Customer under the Agreement. "Subprocessor" means any processor engaged by Gather to Process Customer Personal Data. "Data Protection Laws" means all laws applicable to the Processing of Customer Personal Data, including GDPR and CCPA.
2. Roles of the Parties
With respect to Customer Personal Data, Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Gather is the Processor. Under CCPA, Gather acts as a Service Provider. Gather Processes Customer Personal Data only on Customer's documented instructions, including as set out in the Agreement, this DPA, and Customer's use of the Services.
3. Scope and Details of Processing
The subject matter, duration, nature, and purpose of Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex I.
4. Gather's Obligations
Gather will:
- Process Customer Personal Data only on Customer's documented instructions, including for international transfers, unless required by law, in which case Gather will inform Customer unless legally prohibited.
- Ensure that personnel authorized to Process Customer Personal Data are bound by confidentiality obligations.
- Implement and maintain the technical and organizational security measures set out in Annex II.
- Assist Customer, taking into account the nature of the Processing, in responding to Data Subject rights requests, and in meeting Customer's obligations regarding security, breach notification, data protection impact assessments, and prior consultation.
- Notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide information reasonably required for Customer to meet its notification obligations.
- At Customer's choice, delete or return Customer Personal Data at the end of the Services, and delete existing copies unless retention is required by law.
- Make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, subject to Section 8.
5. CCPA Service Provider Terms
With respect to Personal Data governed by the CCPA, Gather will:
- Process such Personal Data solely to provide the Services and for the business purposes specified in the Agreement, and not for any other purpose.
- Not sell or share such Personal Data, as "sell" and "share" are defined under the CCPA.
- Not retain, use, or disclose such Personal Data outside the direct business relationship or as otherwise prohibited by the CCPA.
- Not combine such Personal Data with Personal Data from other sources except as permitted by the CCPA.
- Comply with applicable obligations under the CCPA and provide the same level of privacy protection as required of businesses.
Gather certifies that it understands and will comply with these restrictions.
6. Subprocessors
Customer provides general authorization for Gather to engage Subprocessors to Process Customer Personal Data. Gather maintains a current list of Subprocessors at https://www.gatherhq.com/subprocessors and will give Customer a mechanism to receive notice of new Subprocessors before they begin Processing, allowing a reasonable opportunity to object on reasonable data protection grounds. Gather will impose data protection obligations on each Subprocessor that are no less protective than those in this DPA and remains responsible for its Subprocessors' performance.
7. International Transfers
Where Gather Processes Customer Personal Data subject to GDPR in a country without an adequacy decision, the parties agree that the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor, or Module Three: Processor to Processor, as applicable) are incorporated into this DPA by reference and completed as set out in Annex III. For UK transfers, the UK International Data Transfer Addendum applies. For Swiss transfers, the SCCs apply as adapted for the Swiss FADP.
8. Audits
Gather will make available information necessary to demonstrate compliance with this DPA. On reasonable prior written notice, no more than once per year unless required by a supervisory authority or following a Personal Data Breach, Customer may audit Gather's compliance, or Gather may satisfy this obligation by providing a then-current third-party audit report or security documentation.
9. Liability and Term
Each party's liability under this DPA is subject to the limitations in the Agreement. This DPA remains in effect for as long as Gather Processes Customer Personal Data. In the event of a conflict between this DPA and the Agreement on data protection matters, this DPA controls.
Annex I: Details of Processing
Categories of Data Subjects: Customer's prospects, customers, buyers, research participants, survey respondents, and other individuals whose data Customer submits to or generates through the Services.
Categories of Personal Data: identifiers and contact details; professional and employment information; responses, feedback, and opinions; audio, video, and voice recordings and transcripts from interviews; usage and device data.
Special categories of data: not intended to be Processed. Customer should not submit special category data except as expressly agreed and subject to additional safeguards.
Nature and purpose of Processing: to provide the customer intelligence and voice-of-customer Services described in the Agreement, including collecting, hosting, analyzing, and generating insights from Customer data.
Duration: for the term of the Agreement plus any retention required by law or agreed with Customer.
Annex II: Technical and Organizational Measures
Gather maintains measures including:
- encryption of Personal Data in transit and at rest;
- role-based access controls and least-privilege access;
- multi-factor authentication for administrative access;
- network security, logging, and monitoring;
- secure software development practices and change management;
- regular backups and a documented incident response process;
- personnel confidentiality obligations and security awareness practices;
- vendor and Subprocessor due diligence.
Annex III: Standard Contractual Clauses Details
Data exporter: Customer. Data importer: Be Heard Labs, Inc. Module: Two (Controller to Processor) or Three (Processor to Processor), as applicable. Clause 7 (docking): applies. Clause 9 (subprocessors): Option 2, general authorization, with notice as described in Section 6. Clause 11 (redress): optional language not used. Clause 17 (governing law): the law of Ireland, unless another EU member state law is required. Clause 18 (forum): the courts of Ireland. Annex I and II of the SCCs: as set out in Annex I and Annex II of this DPA.
Be Heard Labs, Inc. Signature: ________________________ Name / Title: ________________________ Date: ________________________
Customer Signature: ________________________ Name / Title: ________________________ Date: ________________________