Data Processing Agreement

    USING THIS DPA
    This DPA has 2 parts: (1) the Key Terms on this Cover Page and (2) the Common Paper DPA Standard Terms Version 1 posted at commonpaper.com/standards/data-processing-agreement/1.0 ("DPA Standard Terms"), which is incorporated by reference. If there is any inconsistency between the parts of the DPA, the Cover Page will control over the DPA Standard Terms. Capitalized and highlighted words have the meanings given on the Cover Page. However, if the Cover Page omits or does not define a highlighted word, the default meaning will be "none" or "not applicable" and the correlating clause, sentence, or section does not apply to this Agreement. All other capitalized words have the meanings given in the DPA Standard Terms or the Agreement. A copy of the DPA Standard Terms is attached for convenience only.
    Key Terms
    AgreementAttached Cloud Services Agreement
    Approved SubprocessorsSub Processors are listed at https://app.chatprd.ai/subprocessors
    Provider Security Contacthello@chatprd.ai
    Security PolicyProvider will use commercially reasonable efforts to secure the Service from unauthorized access, alteration, or use and other unlawful tampering.
    Changes to the Agreement
    DPA Covered ClaimThe Agreement includes an additional Provider Covered Claims for any action, proceeding, or claim arising out of or relating to (1) Provider's breach or alleged breach of the DPA, or (2) Provider's gross negligence or willful misconduct, in each case, that results in a Security Incident.
    Service Provider RelationshipTo the extent California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq ("CCPA") applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed below (see Nature and Purpose of Processing), which constitutes a limited and specified business purpose. Provider will not sell or share any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA.
    Restricted Transfers
    Governing Member StateUK Transfers: England and Wales
    Annex I(A) List of Parties
    Data Exporter

    Name: the Customer signing this DPA

    Activities relevant to transfer: See Annex 1(B)

    Role: Controller

    Data Importer

    Name: the Provider signing this DPA

    Contact person: Claire Vo Lawless, CEO

    Address: 2261 Market St STE 10575, San Francisco, California 94114, USA

    Activities relevant to transfer: See Annex 1(B)

    Role: Processor

    Annex I(B) Description of Transfer and Processing Activities
    ServiceChatPRD, an AI powered platform that assists teams in creating, refining, and managing product documents.
    Categories of Data SubjectsCustomer's employees
    Categories of Personal Data

    Name

    Contact information such as email, phone number, or address

    Special Category DataNo
    Frequency of TransferContinuous
    Nature and Purpose of Processing

    Receiving data, including collection, accessing, retrieval, recording, and data entry

    Holding data, including storage, organization, and structuring

    Using data, including analysis, consultation, testing, automated decision making, and profiling

    Duration of ProcessingProvider will process Customer Personal Data as long as required (i) to conduct the Processing activities instructed in Section 2.2(a)-(d) of the Standard Terms; or (ii) by Applicable Laws.
    Annex I(C)
    Competent Supervisory AuthorityThe supervisory authority will be the supervisory authority of the data exporter, as determined in accordance with Clause 13 of the EEA SCCs or the relevant provision of the UK Addendum.
    Annex II
    Technical and Organizational Security Measures

    See Security Policy

    • Pseudonymization and encryption of personal data
    • Ensuring ongoing confidentiality, integrity, availability, and resilience of processing systems and services
    • Ability to restore the availability of and access to the Customer Personal Data in a timely manner following a physical or technical incident
    • Regular testing, assessment, and evaluation of the effectiveness of technical and organizational measures used to secure Processing
    • User identification and authorization process and protection
    • Protecting Customer Personal Data during transmission (in transit)
    • Protecting Customer Personal Data during storage (at rest)
    • Events logging
    • Systems configuration, including default configuration

    Provider and Customer have not changed the DPA Standard Terms except for the details on the Cover Page above. By signing this Cover Page, each party agrees to enter into this DPA as of the last date of signature.


    DPA Standard Terms

    1. Processor and Subprocessor Relationships

    1.1 Provider as Processor. In situations where Customer is a Controller of the Customer Personal Data, Provider will be deemed a Processor that is Processing Personal Data on behalf of Customer.

    1.2 Provider as Subprocessor. In situations where Customer is a Processor of the Customer Personal Data, Provider will be deemed a Subprocessor of the Customer Personal Data.

    2. Processing

    2.1 Processing Details. Annex I(B) on the Cover Page describes the subject matter, nature, purpose, and duration of this Processing, as well as the Categories of Personal Data collected and Categories of Data Subjects.

    2.2 Processing Instructions. Customer instructs Provider to Process Customer Personal Data: (a) to provide and maintain the Service; (b) as may be further specified through Customer's use of the Service; (c) as documented in this Agreement, including this DPA; and (d) as further documented in any other written instructions given by Customer and acknowledged by Provider as constituting instructions under this DPA.

    2.3 Processing by Provider. Provider will only Process Customer Personal Data in accordance with this DPA, including the details in the Cover Page. If Provider updates the Service to update existing or introduce new features, and those updates result in a material change to the Processing, Provider will update the relevant sections in the Cover Page accordingly. Provider will inform Customer of that change and Customer may object to such a change in accordance with the change management process in the Agreement.

    2.4 Customer Processing. Where Customer is a Processor and Provider is a Subprocessor, Customer will comply with all Applicable Laws that apply to Customer's Processing of Customer Personal Data. Customer will ensure that its instructions for the Processing of Customer Personal Data comply with Applicable Laws, including Applicable Data Protection Laws. Customer will have sole responsibility for the accuracy, quality, and legality of the Customer Personal Data and the means by which Customer acquired the Customer Personal Data.

    2.5 Consent to Processing. Customer has complied with and will continue to comply with all Applicable Data Protection Laws concerning its provision of Customer Personal Data to Provider and/or the Service. If consent is the legal basis on which Customer or its Controller relies for providing Customer Personal Data to Provider, Customer will, at all times, maintain a record of such consent in compliance with Applicable Laws (including Applicable Data Protection Laws).

    3. Subprocessors

    3.1 Provider will not provide, transfer, or hand over any Customer Personal Data to a Subprocessor unless Customer has approved the Subprocessor. The current list of Approved Subprocessors includes the identities of those Subprocessors, and a mechanism to receive notice of any updates to the list of Subprocessors.

    3.2 When engaging a Subprocessor, Provider will have a written agreement with the Subprocessor that ensures the Subprocessor only accesses and uses Customer Personal Data (i) to the extent required to perform the obligations subcontracted to it, and (ii) consistent with the terms of the Agreement including this DPA.

    3.3 If the GDPR applies to the Processing of Customer Personal Data, (i) the data protection obligations described in this DPA (as referred to in Article 28(3) of the GDPR, if applicable) are also imposed on the Subprocessor by way of a contract or other legal act under Union or Member State law, providing sufficient guarantees to implement appropriate technical and organizational measures in a manner that the Processing will meet the requirements of the GDPR; and (ii) Provider will ensure each Subprocessor performs the obligations under this DPA and the GDPR as they apply to the Processing of Customer Personal Data.

    3.4 Provider remains fully liable for all obligations subcontracted to its Subprocessors, including the acts and omissions of its Subprocessors in Processing Customer Personal Data. Provider will notify Customer of any changes to the list of Approved Subprocessors. If Customer objects to the change, the parties will work together in good faith to find a resolution. If no resolution is found, Customer may terminate the Agreement under the terms of the Agreement.

    4. Restricted Transfers

    4.1 Authorization. Customer agrees that Provider may transfer Customer Personal Data outside the EEA, the United Kingdom, or other relevant geographic territory as necessary to provide the Service. If Provider transfers Customer Personal Data to a Restricted Transfer territory, Provider will ensure these transfers are made in compliance with the applicable requirements of Applicable Data Protection Laws, including by executing appropriate data transfer mechanisms as necessary.

    4.2 Ex-EEA Transfers. Customer and Provider agree that if the GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the EEA to Provider outside of the EEA, and there is no applicable adequacy decision by the European Commission, the EEA SCCs form part of this DPA and will be deemed entered into and completed as follows:

    For each module, the following applies (when applicable):

    4.3 Ex-UK Transfers. Customer and Provider agree that if the UK GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the United Kingdom to Provider outside of the United Kingdom, and there is no applicable adequacy decision by the relevant authority, the UK Addendum forms part of this DPA and takes precedence over the rest of this DPA as set forth in the UK Addendum.

    4.4 Other International Transfers. For Personal Data transfers where Swiss law (and not the law in any EEA member state or the United Kingdom) applies to the international nature of the transfer, references to the GDPR in Clause 4 of the EEA SCCs are, to the extent legally required, amended to refer to the Swiss Federal Act on Data Protection or its successor instead, and the concept of supervisory authority will include the Swiss Federal Data Protection and Information Commissioner.

    5. Security Incident Response

    Upon becoming aware of any Security Incident, Provider will: (a) notify Customer without undue delay when feasible, but no later than 72 hours after becoming aware of the Security Incident; (b) provide timely information relating to the Security Incident as it becomes known or as Customer reasonably requests; and (c) promptly take reasonable steps to contain, investigate, and mitigate any Security Incident.

    6. Audit & Reports

    6.1 Audit Rights. Provider will give Customer all information reasonably necessary to demonstrate its compliance with this DPA and Provider will allow for and contribute to audits, including inspections by Customer, in order to assess Provider's compliance with this DPA.

    6.2 Security Reports. Customer acknowledges that Provider is regularly audited against the standards defined in the Security Policy by independent third-party auditors. Upon written request, Provider will supply (on a confidential basis) a summary copy of its Report to Customer, so that Customer can verify Provider's compliance with this DPA.

    6.3 Security Due Diligence. In addition to the Report, Provider will respond to reasonable requests for information made by Customer to confirm Provider's compliance with this DPA, including responses to information security, due diligence, and audit questionnaires, by making additional information available regarding its information security program upon Customer's written request.

    7. Coordination & Cooperation

    7.1 Response to Inquiries. If Provider receives any inquiry or request from anyone else about the Processing of Customer Personal Data, Provider will notify Customer about the request and Provider will not respond to the request without Customer's prior written consent, unless legally compelled to do so. If Provider is required to respond to such inquiry or request, Provider will promptly notify Customer and provide Customer with a copy of the request unless legally prohibited from doing so.

    7.2 DPIAs and DTIAs. If required by Applicable Data Protection Laws, Provider will reasonably assist Customer in conducting any mandated data protection impact assessments or data transfer impact assessments and related consultations with any supervisory authorities.

    8. Deletion of Customer Personal Data

    8.1 Deletion by Customer. Provider will enable Customer to delete Customer Personal Data in a manner consistent with the functionality of the Services. Provider will comply with this instruction as soon as reasonably practical and within a maximum period of 180 days, unless Applicable Laws require storage.

    8.2 Deletion at DPA Expiration.

    After the DPA expires, Provider will return or delete Customer Personal Data at Customer's instruction unless further storage of Customer Personal Data is required or authorized by Applicable Law. If return or destruction is impracticable or prohibited by Applicable Law, Provider will take measures to block such Customer Personal Data from any further Processing (except to the extent necessary for its continued hosting or Processing as required by Applicable Law) and will continue to appropriately protect the Customer Personal Data remaining in its possession, custody, or control.

    If Customer and Provider have entered the EEA SCCs or the UK Addendum as part of this DPA, Provider will only give Customer the certification of deletion of Personal Data described in Clause 8.1(d) and Clause 8.5 of the EEA SCCs (as applicable) when Provider has fully deleted the Customer Personal Data in accordance with this DPA.

    9. Limitation of Liability

    9.1 Liability Caps and Damages Waiver. To the maximum extent permitted under Applicable Data Protection Laws, each party's total cumulative liability to the other party arising out of or related to this DPA may be limited by the Agreement.

    9.2 Related-Party Claims. Any claims made against Provider or its Affiliates arising out of or related to this DPA may only be brought by the Customer entity that is a party to the Agreement.

    9.3 Exceptions. This DPA does not limit any liability to an individual about the individual's data protection rights under Applicable Data Protection Laws. In addition, this DPA does not limit any liability for a Provider breach of its confidentiality obligations.

    10. Conflicts Between Documents

    This DPA forms part of and supplements the Agreement. If there is any inconsistency between this DPA, the Agreement, or any of their parts, the part listed earlier will control over the part listed later: (a) the Cover Page; (b) the DPA Standard Terms; (c) the Agreement; and (d) any exhibits, schedules, or attachments to the Cover Page, the DPA Standard Terms, or the Agreement. If this DPA is inconsistent with any privacy-related terms previously negotiated between the parties, this DPA will control.

    11. Term of Agreement

    This DPA will start when Provider and Customer agree to a Cover Page for the DPA and sign or electronically accept the Agreement and will continue until the Agreement expires or is terminated. However, this DPA will remain in effect for so long as Provider Processes Customer Personal Data.

    12. Definitions