| USING THIS DPA | |
| This DPA has 2 parts: (1) the Key Terms on this Cover Page and (2) the Common Paper DPA Standard Terms Version 1 posted at commonpaper.com/standards/data-processing-agreement/1.0 ("DPA Standard Terms"), which is incorporated by reference. If there is any inconsistency between the parts of the DPA, the Cover Page will control over the DPA Standard Terms. Capitalized and highlighted words have the meanings given on the Cover Page. However, if the Cover Page omits or does not define a highlighted word, the default meaning will be "none" or "not applicable" and the correlating clause, sentence, or section does not apply to this Agreement. All other capitalized words have the meanings given in the DPA Standard Terms or the Agreement. A copy of the DPA Standard Terms is attached for convenience only. |
| Key Terms | |
|---|---|
| Agreement | Attached Cloud Services Agreement |
| Approved Subprocessors | Sub Processors are listed at https://app.chatprd.ai/subprocessors |
| Provider Security Contact | hello@chatprd.ai |
| Security Policy | Provider will use commercially reasonable efforts to secure the Service from unauthorized access, alteration, or use and other unlawful tampering. |
| Changes to the Agreement | |
|---|---|
| DPA Covered Claim | The Agreement includes an additional Provider Covered Claims for any action, proceeding, or claim arising out of or relating to (1) Provider's breach or alleged breach of the DPA, or (2) Provider's gross negligence or willful misconduct, in each case, that results in a Security Incident. |
| Service Provider Relationship | To the extent California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq ("CCPA") applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed below (see Nature and Purpose of Processing), which constitutes a limited and specified business purpose. Provider will not sell or share any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA. |
| Restricted Transfers | |
|---|---|
| Governing Member State | UK Transfers: England and Wales |
| Annex I(A) List of Parties | |
|---|---|
| Data Exporter | Name: the Customer signing this DPA Activities relevant to transfer: See Annex 1(B) Role: Controller |
| Data Importer | Name: the Provider signing this DPA Contact person: Claire Vo Lawless, CEO Address: 2261 Market St STE 10575, San Francisco, California 94114, USA Activities relevant to transfer: See Annex 1(B) Role: Processor |
| Annex I(B) Description of Transfer and Processing Activities | |
|---|---|
| Service | ChatPRD, an AI powered platform that assists teams in creating, refining, and managing product documents. |
| Categories of Data Subjects | Customer's employees |
| Categories of Personal Data | Name Contact information such as email, phone number, or address |
| Special Category Data | No |
| Frequency of Transfer | Continuous |
| Nature and Purpose of Processing | Receiving data, including collection, accessing, retrieval, recording, and data entry Holding data, including storage, organization, and structuring Using data, including analysis, consultation, testing, automated decision making, and profiling |
| Duration of Processing | Provider will process Customer Personal Data as long as required (i) to conduct the Processing activities instructed in Section 2.2(a)-(d) of the Standard Terms; or (ii) by Applicable Laws. |
| Annex I(C) | |
|---|---|
| Competent Supervisory Authority | The supervisory authority will be the supervisory authority of the data exporter, as determined in accordance with Clause 13 of the EEA SCCs or the relevant provision of the UK Addendum. |
| Annex II | |
|---|---|
| Technical and Organizational Security Measures | See Security Policy
|
Provider and Customer have not changed the DPA Standard Terms except for the details on the Cover Page above. By signing this Cover Page, each party agrees to enter into this DPA as of the last date of signature.
1.1 Provider as Processor. In situations where Customer is a Controller of the Customer Personal Data, Provider will be deemed a Processor that is Processing Personal Data on behalf of Customer.
1.2 Provider as Subprocessor. In situations where Customer is a Processor of the Customer Personal Data, Provider will be deemed a Subprocessor of the Customer Personal Data.
2.1 Processing Details. Annex I(B) on the Cover Page describes the subject matter, nature, purpose, and duration of this Processing, as well as the Categories of Personal Data collected and Categories of Data Subjects.
2.2 Processing Instructions. Customer instructs Provider to Process Customer Personal Data: (a) to provide and maintain the Service; (b) as may be further specified through Customer's use of the Service; (c) as documented in this Agreement, including this DPA; and (d) as further documented in any other written instructions given by Customer and acknowledged by Provider as constituting instructions under this DPA.
2.3 Processing by Provider. Provider will only Process Customer Personal Data in accordance with this DPA, including the details in the Cover Page. If Provider updates the Service to update existing or introduce new features, and those updates result in a material change to the Processing, Provider will update the relevant sections in the Cover Page accordingly. Provider will inform Customer of that change and Customer may object to such a change in accordance with the change management process in the Agreement.
2.4 Customer Processing. Where Customer is a Processor and Provider is a Subprocessor, Customer will comply with all Applicable Laws that apply to Customer's Processing of Customer Personal Data. Customer will ensure that its instructions for the Processing of Customer Personal Data comply with Applicable Laws, including Applicable Data Protection Laws. Customer will have sole responsibility for the accuracy, quality, and legality of the Customer Personal Data and the means by which Customer acquired the Customer Personal Data.
2.5 Consent to Processing. Customer has complied with and will continue to comply with all Applicable Data Protection Laws concerning its provision of Customer Personal Data to Provider and/or the Service. If consent is the legal basis on which Customer or its Controller relies for providing Customer Personal Data to Provider, Customer will, at all times, maintain a record of such consent in compliance with Applicable Laws (including Applicable Data Protection Laws).
3.1 Provider will not provide, transfer, or hand over any Customer Personal Data to a Subprocessor unless Customer has approved the Subprocessor. The current list of Approved Subprocessors includes the identities of those Subprocessors, and a mechanism to receive notice of any updates to the list of Subprocessors.
3.2 When engaging a Subprocessor, Provider will have a written agreement with the Subprocessor that ensures the Subprocessor only accesses and uses Customer Personal Data (i) to the extent required to perform the obligations subcontracted to it, and (ii) consistent with the terms of the Agreement including this DPA.
3.3 If the GDPR applies to the Processing of Customer Personal Data, (i) the data protection obligations described in this DPA (as referred to in Article 28(3) of the GDPR, if applicable) are also imposed on the Subprocessor by way of a contract or other legal act under Union or Member State law, providing sufficient guarantees to implement appropriate technical and organizational measures in a manner that the Processing will meet the requirements of the GDPR; and (ii) Provider will ensure each Subprocessor performs the obligations under this DPA and the GDPR as they apply to the Processing of Customer Personal Data.
3.4 Provider remains fully liable for all obligations subcontracted to its Subprocessors, including the acts and omissions of its Subprocessors in Processing Customer Personal Data. Provider will notify Customer of any changes to the list of Approved Subprocessors. If Customer objects to the change, the parties will work together in good faith to find a resolution. If no resolution is found, Customer may terminate the Agreement under the terms of the Agreement.
4.1 Authorization. Customer agrees that Provider may transfer Customer Personal Data outside the EEA, the United Kingdom, or other relevant geographic territory as necessary to provide the Service. If Provider transfers Customer Personal Data to a Restricted Transfer territory, Provider will ensure these transfers are made in compliance with the applicable requirements of Applicable Data Protection Laws, including by executing appropriate data transfer mechanisms as necessary.
4.2 Ex-EEA Transfers. Customer and Provider agree that if the GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the EEA to Provider outside of the EEA, and there is no applicable adequacy decision by the European Commission, the EEA SCCs form part of this DPA and will be deemed entered into and completed as follows:
For each module, the following applies (when applicable):
4.3 Ex-UK Transfers. Customer and Provider agree that if the UK GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the United Kingdom to Provider outside of the United Kingdom, and there is no applicable adequacy decision by the relevant authority, the UK Addendum forms part of this DPA and takes precedence over the rest of this DPA as set forth in the UK Addendum.
4.4 Other International Transfers. For Personal Data transfers where Swiss law (and not the law in any EEA member state or the United Kingdom) applies to the international nature of the transfer, references to the GDPR in Clause 4 of the EEA SCCs are, to the extent legally required, amended to refer to the Swiss Federal Act on Data Protection or its successor instead, and the concept of supervisory authority will include the Swiss Federal Data Protection and Information Commissioner.
Upon becoming aware of any Security Incident, Provider will: (a) notify Customer without undue delay when feasible, but no later than 72 hours after becoming aware of the Security Incident; (b) provide timely information relating to the Security Incident as it becomes known or as Customer reasonably requests; and (c) promptly take reasonable steps to contain, investigate, and mitigate any Security Incident.
6.1 Audit Rights. Provider will give Customer all information reasonably necessary to demonstrate its compliance with this DPA and Provider will allow for and contribute to audits, including inspections by Customer, in order to assess Provider's compliance with this DPA.
6.2 Security Reports. Customer acknowledges that Provider is regularly audited against the standards defined in the Security Policy by independent third-party auditors. Upon written request, Provider will supply (on a confidential basis) a summary copy of its Report to Customer, so that Customer can verify Provider's compliance with this DPA.
6.3 Security Due Diligence. In addition to the Report, Provider will respond to reasonable requests for information made by Customer to confirm Provider's compliance with this DPA, including responses to information security, due diligence, and audit questionnaires, by making additional information available regarding its information security program upon Customer's written request.
7.1 Response to Inquiries. If Provider receives any inquiry or request from anyone else about the Processing of Customer Personal Data, Provider will notify Customer about the request and Provider will not respond to the request without Customer's prior written consent, unless legally compelled to do so. If Provider is required to respond to such inquiry or request, Provider will promptly notify Customer and provide Customer with a copy of the request unless legally prohibited from doing so.
7.2 DPIAs and DTIAs. If required by Applicable Data Protection Laws, Provider will reasonably assist Customer in conducting any mandated data protection impact assessments or data transfer impact assessments and related consultations with any supervisory authorities.
8.1 Deletion by Customer. Provider will enable Customer to delete Customer Personal Data in a manner consistent with the functionality of the Services. Provider will comply with this instruction as soon as reasonably practical and within a maximum period of 180 days, unless Applicable Laws require storage.
8.2 Deletion at DPA Expiration.
After the DPA expires, Provider will return or delete Customer Personal Data at Customer's instruction unless further storage of Customer Personal Data is required or authorized by Applicable Law. If return or destruction is impracticable or prohibited by Applicable Law, Provider will take measures to block such Customer Personal Data from any further Processing (except to the extent necessary for its continued hosting or Processing as required by Applicable Law) and will continue to appropriately protect the Customer Personal Data remaining in its possession, custody, or control.
If Customer and Provider have entered the EEA SCCs or the UK Addendum as part of this DPA, Provider will only give Customer the certification of deletion of Personal Data described in Clause 8.1(d) and Clause 8.5 of the EEA SCCs (as applicable) when Provider has fully deleted the Customer Personal Data in accordance with this DPA.
9.1 Liability Caps and Damages Waiver. To the maximum extent permitted under Applicable Data Protection Laws, each party's total cumulative liability to the other party arising out of or related to this DPA may be limited by the Agreement.
9.2 Related-Party Claims. Any claims made against Provider or its Affiliates arising out of or related to this DPA may only be brought by the Customer entity that is a party to the Agreement.
9.3 Exceptions. This DPA does not limit any liability to an individual about the individual's data protection rights under Applicable Data Protection Laws. In addition, this DPA does not limit any liability for a Provider breach of its confidentiality obligations.
This DPA forms part of and supplements the Agreement. If there is any inconsistency between this DPA, the Agreement, or any of their parts, the part listed earlier will control over the part listed later: (a) the Cover Page; (b) the DPA Standard Terms; (c) the Agreement; and (d) any exhibits, schedules, or attachments to the Cover Page, the DPA Standard Terms, or the Agreement. If this DPA is inconsistent with any privacy-related terms previously negotiated between the parties, this DPA will control.
This DPA will start when Provider and Customer agree to a Cover Page for the DPA and sign or electronically accept the Agreement and will continue until the Agreement expires or is terminated. However, this DPA will remain in effect for so long as Provider Processes Customer Personal Data.
"Applicable Laws" means the laws, rules, regulations, court orders, and other binding requirements of a relevant government authority that apply to or govern a party.
"Applicable Data Protection Laws" means the Applicable Laws that govern how the Service may process or use an individual's personal information, personal data, personally identifiable information, or other similar term.
"Controller" will have the meaning(s) given in the Applicable Data Protection Laws for the company that determines the purpose and extent of Processing Personal Data.
"Cover Page" means a document that is signed or electronically accepted by the parties that incorporates these DPA Standard Terms and identifies Provider, Customer, and the subject matter and details of the data processing.
"Customer Personal Data" means Personal Data that Customer uploads or provides to Provider as part of the Service and that is governed by this DPA.
"DPA" means these DPA Standard Terms, the Cover Page between Provider and Customer, and the policies and documents referenced in or attached to the Cover Page.
"EEA SCCs" means the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the European Council.
"European Economic Area" or "EEA" means the member states of the European Union, Norway, Iceland, and Liechtenstein.
"GDPR" means European Union Regulation 2016/679 as implemented by local law in the relevant EEA member nation.
"Personal Data" will have the meaning(s) given in the Applicable Data Protection Laws for personal information, personal data, or other similar term.
"Processing" or "Process" will have the meaning(s) given in the Applicable Data Protection Laws for any use of, or performance of a computer operation on, Personal Data, including by automatic methods.
"Processor" will have the meaning(s) given in the Applicable Data Protection Laws for the company that Processes Personal Data on behalf of the Controller.
"Report" means audit reports prepared by another company according to the standards defined in the Security Policy on behalf of Provider.
"Restricted Transfer" means (a) where the GDPR applies, a transfer of personal data from the EEA to a country outside of the EEA which is not subject to an adequacy determination by the European Commission; and (b) where the UK GDPR applies, a transfer of personal data from the United Kingdom to any other country which is not subject to adequacy regulations adopted pursuant to Section 17A of the United Kingdom Data Protection Act 2018.
"Security Incident" means a Personal Data Breach as defined in Article 4 of the GDPR.
"Service" means the product and/or services described in the Agreement.
"Special Category Data" will have the meaning given in Article 9 of the GDPR.
"Subprocessor" will have the meaning(s) given in the Applicable Data Protection Laws for a company that, with the approval and acceptance of Controller, assists the Processor in Processing Personal Data on behalf of the Controller.
"UK GDPR" means European Union Regulation 2016/679 as implemented by section 3 of the United Kingdom's European Union (Withdrawal) Act of 2018 in the United Kingdom.
"UK Addendum" means the international data transfer addendum to the EEA SCCs issued by the Information Commissioner for Parties making Restricted Transfers under S119A(1) Data Protection Act 2018.