Data Processing Agreement
Using This DPA
This DPA has 2 parts: (1) the Key Terms on this Cover Page and (2) the Common Paper DPA Standard Terms Version 1 posted at commonpaper.com/standards/data-processing-agreement/1.1 (“DPA Standard Terms”), which is incorporated by reference. If there is any inconsistency between the parts of the DPA, the Cover Page will control over the DPA Standard Terms. Capitalized and highlighted words have the meanings given on the Cover Page. However, if the Cover Page omits or does not define a highlighted word, the default meaning will be “none” or “not applicable” and the correlating clause, sentence, or section does not apply to this Agreement. All other capitalized words have the meanings given in the DPA Standard Terms or the Agreement. A copy of the DPA Standard Terms is attached for convenience only.
Cover Page
Key Terms
The key legal terms of the DPA are as follows:
| Term | Details |
|---|---|
Agreement |
Reference to sales contract will be set when sending agreement |
Approved Subprocessors |
|
Provider Security Contact |
|
Security Policy |
Security Policy available at: Provider will maintain annually updated reports or annual certifications of compliance with the following: SOC 2 Type I SOC 2 Type II Penetration Testing |
| Changes to the Agreement | |
Service Provider Relationship |
To the extent California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq (“CCPA”) applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed below (see Nature and Purpose of Processing), which constitutes a limited and specified business purpose. Provider will not sell or share any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA. |
| Restricted Transfers | |
Governing Member State |
EEA Transfers: Netherlands UK Transfers: England and Wales |
| Annex I(A) List of Parties | |
Data Exporter |
Name: Customer (the entity that accesses or uses the Service) Activities relevant to transfer: See Annex 1(B) Role: Controller |
Data Importer |
Name: the Provider signing this DPA Contact person: Imran Patel, CEO Address: 4101 Dublin Blvd Ste F #3123, Dublin, California 94568, USA Activities relevant to transfer: See Annex 1(B) Role: Processor |
| Annex I(B) Description of Transfer and Processing Activities | |
Service |
The Service is: Syft Data Platform |
Categories of Data Subjects |
|
Categories of Personal Data |
Submitted Data
Graph Data
|
Special Category Data Is special category data (as defined in Article 9 of the GDPR) Processed? |
No |
Frequency of Transfer |
Continuous |
Nature and Purpose of Processing |
Receiving data, including collection, accessing, retrieval, recording, and data entry Holding data, including storage, organization, and structuring Using data, including analysis, consultation, testing, automated decision making, and profiling Updating data, including correcting, adaption, alteration, alignment, and combination Protecting data, including restricting, encrypting, and security testing Sharing data, including disclosure, dissemination, allowing access, or otherwise making available Returning data to the data exporter or data subject Erasing data, including destruction and deletion |
Duration of Processing |
Provider will process Customer Personal Data as long as required (i) to conduct the Processing activities instructed in Section 2.2(a)-(d) of the Standard Terms; or (ii) by Applicable Laws. |
| Annex I(C) | |
Competent Supervisory Authority |
The supervisory authority will be the supervisory authority of the data exporter, as determined in accordance with Clause 13 of the EEA SCCs or the relevant provision of the UK Addendum. |
| Annex II | |
Technical and Organizational Security Measures |
See Security Policy |
Other Changes to the DPA Standard Terms Additional modifications or customizations |
Add-on ServicesCertain optional features ("Add-ons") may be activated by Customer's authorized administrator within the Service. Activation of an Add-on incorporates by reference the corresponding Add-on Addendum, which becomes part of this DPA upon activation. Current Add-on Addendums are published at syftdata.com/dpa/addendums. Customer's authorized administrator's affirmative consent at the point of activation, as recorded in the Service, constitutes Customer's acceptance of the corresponding Add-on Addendum. Customer is solely responsible for ensuring that only authorized administrators activate Add-ons on Customer's behalf. Graph Data ObligationsWhere the Service delivers Graph Data to Customer (as defined in the Service Provider Relationship section of this Cover Page), Customer agrees to: |
Provider and Customer have not changed the DPA Standard Terms except for the details on the Cover Page above. This DPA is accepted and becomes effective as set out below.
Acceptance
By creating an account, accessing, or using the Service, Customer accepts this DPA. The Effective Date is the date Customer first accepts these terms or first uses the Service, whichever is earlier.
Provider: Syft Data, Inc.
Imran Patel, CEO
4101 Dublin Blvd Ste F #3123, Dublin, California 94568, United States of America
privacy@syftdata.com
Customer: The entity that accesses or uses the Service. Customer's authorized administrator's affirmative consent (or first use of the Service) constitutes Customer's acceptance.