Data Processing Addendum
This Addendum forms part of the agreement between SIP and Customer and governs the processing of personal data by SIP on Customer's behalf, in compliance with the GDPR and other applicable data-protection laws.
Introduction & scope
This Data Processing Addendum ("DPA") supplements the SIP Terms of Service ("Agreement") between SIP Intelligence, Inc. ("SIP," "Processor") and the customer identified in the Agreement ("Customer," "Controller").
This DPA applies where SIP processes Customer Personal Data on Customer's behalf in the course of providing the Service, and to the extent such processing is subject to the GDPR, UK GDPR, or other applicable data-protection laws ("Data Protection Laws").
Definitions
Capitalized terms not defined here have the meaning in the Agreement or Data Protection Laws.
- Personal Data — any information relating to an identified or identifiable natural person, processed by SIP on Customer's behalf.
- Processing — any operation performed on Personal Data, as defined by the GDPR.
- Data Subject — the individual to whom Personal Data relates.
- Subprocessor — a third party engaged by SIP to process Personal Data.
- SCCs — the EU Standard Contractual Clauses for international transfers.
Roles of the parties
The parties acknowledge that, for Customer Personal Data, Customer is the Controller and SIP is the Processor. Where Customer is itself a processor acting on behalf of a third-party controller, SIP acts as a subprocessor. SIP will process Personal Data only on documented instructions from Customer, including as set out in the Agreement and this DPA.
Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the SIP Service |
| Duration | The term of the Agreement, plus applicable retention |
| Nature & purpose | Hosting, processing, and securing Customer Data to deliver the Service |
| Types of data | Account, contact, and usage data of Customer's authorized users |
| Data subjects | Customer's employees and authorized users |
Subprocessors
Customer provides general authorization for SIP to engage Subprocessors to process Personal Data. SIP will impose data-protection obligations on each Subprocessor no less protective than those in this DPA and remains liable for their performance.
SIP maintains a current list of Subprocessors and will give Customer notice of intended changes, allowing Customer a reasonable opportunity to object on legitimate data-protection grounds.
Security measures
SIP implements and maintains appropriate technical and organizational measures to protect Personal Data, as described on our Security & Compliance page, including encryption in transit and at rest, access controls, logging, and regular testing of measures.
Assistance with data subject rights
Taking into account the nature of the processing, SIP will assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligations to respond to Data Subject requests to exercise their rights under Data Protection Laws.
Personal data breach
SIP will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its own notification obligations. SIP will take reasonable steps to mitigate and, where possible, remediate the breach.
Audits
SIP will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including third-party audit reports (such as SOC 2). Where required by Data Protection Laws, SIP will allow for and contribute to audits, subject to reasonable notice, confidentiality, and frequency limits.
International data transfers
Where SIP transfers Personal Data outside the EEA, UK, or Switzerland to a country without an adequacy decision, such transfers are governed by the EU Standard Contractual Clauses, which are incorporated into this DPA by reference, together with the UK Addendum where applicable.
Return & deletion of data
Upon termination or expiry of the Agreement, SIP will, at Customer's choice, delete or return Customer Personal Data, and delete existing copies unless retention is required by law. Customer Data is available for export for 30 days following termination.
Liability & order of precedence
Each party's liability under this DPA is subject to the limitations of liability in the Agreement. In case of conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA prevails. Where the SCCs apply and conflict with this DPA, the SCCs prevail.
Contact
To request a countersigned copy of this DPA or to raise data-processing questions, contact legal@sipintel.com or SIP Intelligence, Inc., 130 Water Street, New York, NY 10005.