This Data Processing Addendum (this "DPA") forms part of, and is incorporated into, the Terms of Use between Parallax ("we", "us" or "our") and the customer accepting those Terms of Use ("you" or "your"). It applies where we process Customer Personal Data on your behalf in connection with the Services.
Capitalised terms used but not defined in this DPA have the meanings given in the Terms of Use.
Introduction and Scope
What this DPA covers. This DPA governs our processing of personal data contained in Customer Data, which we process on your behalf as a processor. It does not govern personal data for which we act as a controller, including your Account, billing, support and marketing data, which is addressed in the Privacy Policy.
Effectiveness. This DPA takes effect when you accept the Terms of Use. No separate signature is required for it to bind both parties. If you require an executed copy, you may request one by contacting [email protected], and we will provide a copy for signature reflecting the then-current version of this DPA.
Order of precedence. The Standard Contractual Clauses and the UK Addendum prevail over the remainder of this DPA to the extent they apply. This DPA prevails over the Terms of Use and the Privacy Policy in respect of the processing of Customer Personal Data. The Terms of Use otherwise prevail, in accordance with Clause 1.4 of the Terms of Use.
Term. This DPA applies for the duration of the Terms of Use and continues for so long as we process Customer Personal Data. Clauses 10 (Deletion and Return), 12 (International Transfers), 14 (Liability) and 15 (General) survive its termination or expiry, together with any other provision which by its nature is intended to survive.
Definitions
In this DPA:
"Customer Personal Data" means personal data contained within Customer Data that we process on your behalf in providing the Services. It does not include personal data for which we act as a controller.
"Data Subject Request" means a request from, or on behalf of, a data subject to exercise rights under Data Protection Laws.
"Documented Instructions" has the meaning given at Clause 3.4.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise processed by us or a Sub-processor.
"Restricted Transfer" means a transfer of Customer Personal Data that is subject to restrictions on international transfers under Data Protection Laws.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914, as amended or replaced.
"Sub-processor" means any third party engaged by us to process Customer Personal Data in connection with the Services, including model providers, cloud hosting and infrastructure providers.
"UK Addendum" means the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner, or the UK International Data Transfer Agreement, as applicable.
The terms "controller", "processor", "data subject", "personal data" and "processing" have the meanings given in the GDPR, and equivalent terms under other Data Protection Laws are construed accordingly.
Roles and Instructions
Roles of the parties. In respect of Customer Personal Data, and consistent with Clause 2.2 of the Privacy Policy:
where you determine the purposes and means of processing, you act as the controller and we act as your processor; and
where you process Customer Personal Data on behalf of, and on the instructions of, a third party — for example where you are an adviser conducting a due diligence exercise for a client — you act as a processor and we act as your sub-processor.
Application. References in this DPA to our obligations as processor apply equally to our role as sub-processor under Clause 3.1(b), and references to your role as controller apply equally to your role as processor under that Clause, in each case with the necessary changes.
Your warranties. You represent, warrant and undertake, on a continuing basis, that: (a) you have complied and will comply with Data Protection Laws in respect of your collection, use and disclosure of Customer Personal Data, including in making it available to us; (b) you have established a valid legal basis for the processing and have provided all notices required in respect of individuals named in Customer Data, as contemplated by Clause 2.3 of the Privacy Policy, and have obtained all consents, authorisations and permissions necessary for us and our Sub-processors to process Customer Personal Data as contemplated by this DPA and the Terms of Use; (c) where you act as a processor under Clause 3.1(b), you have obtained all authorisations required from the relevant controller for our engagement as sub-processor, and your instructions to us are consistent with your obligations to that controller; (d) your instructions do not require us to process Customer Personal Data in breach of Data Protection Laws; and (e) during the Beta Period, and unless we have expressly agreed otherwise in writing in advance, Customer Personal Data does not include personal data the processing of which is subject to the General Data Protection Regulation (Regulation (EU) 2016/679) or the UK General Data Protection Regulation. These warranties are in addition to, and do not limit, your warranties at Clause 7.4 of the Terms of Use.
Documented Instructions. Your "Documented Instructions" comprise: (a) the Terms of Use, this DPA and the Privacy Policy; (b) your and your Authorised Users’ use and configuration of the Services, including the upload of Customer Data, the submission of prompts, questions, theses and instructions, and the generation, editing, export and deletion of Outputs; and (c) any further written instructions agreed between the parties.
Processing on instructions only. We will process Customer Personal Data only in accordance with your Documented Instructions, including in respect of any transfer of Customer Personal Data to a third country or an international organisation, except where required to do otherwise by law to which we are subject. Where we are so required, we will inform you of that requirement before processing, unless the law prohibits us from doing so on important grounds of public interest.
Unlawful instructions. If we consider, acting reasonably, that an instruction infringes Data Protection Laws, we will inform you without undue delay. We may suspend the affected processing until the instruction is confirmed, amended or withdrawn.
Details of processing. The subject matter, duration, nature and purposes of the processing, and the categories of personal data and data subjects, are set out in Annex 1.
Our Obligations as Processor
Compliance with Data Protection Laws. We will comply with the obligations applicable to us as a processor under Data Protection Laws in respect of our processing of Customer Personal Data. We will notify you without undue delay if we determine that we are no longer able to meet those obligations or our obligations under this DPA, in which case you may instruct us to cease or suspend the affected processing, or terminate the affected Services in accordance with the Terms of Use.
Purpose limitation. We will process Customer Personal Data solely for the purpose of providing, maintaining, securing and supporting the Services in accordance with your Documented Instructions, and for no other purpose. We will not process Customer Personal Data for our own purposes. This Clause 4.2 concerns our own processing; the purposes for which a model provider engaged as a Sub-processor may process Customer Personal Data during the Beta Period are addressed at Clauses 4.3, 4.4 and 5.5.
Model training. Consistent with Clause 3 of the Privacy Policy, we do not own, operate, host or train artificial intelligence models. Accordingly we do not use Customer Personal Data, Customer Data or Outputs to train, fine-tune, develop or otherwise improve any artificial intelligence or machine learning model of our own, and we do not sell, license or otherwise make Customer Personal Data available to any third party for the purpose of model development. During the Beta Period, Outputs are generated using third-party model providers and routing configurations which we may vary from time to time, and we do not represent or warrant that every such provider excludes Customer Personal Data from its own model training or development, or applies zero data retention; each provider's processing is governed by the terms on which we engage it. A commitment (if any) concerning the use of Customer Personal Data or Customer Data for model training, provider retention periods or zero data retention after the Beta Period applies only to the extent expressly agreed in a customer agreement or Order Form entered into after that period.
Model providers. In order to generate Outputs, the Platform transmits Customer Data to third-party model providers through their application programming interfaces. Those providers act as our Sub-processors and are subject to Clause 5. Model providers may retain Customer Personal Data transmitted to them in accordance with their own retention practices, which vary between providers and which, during the Beta Period, we do not warrant to be limited to any particular period, for the purposes of, among others, abuse monitoring, security and compliance with their own legal obligations, in accordance with their terms.
Improvement of the Services. We may use Service Metadata, Feedback and de-identified or aggregated data to analyse, maintain, secure, develop and improve the Services, as described at Clause 3.4 of the Privacy Policy. That activity does not involve the use of Customer Personal Data in identifiable form, and we will not seek to re-identify data we have de-identified.
Confidentiality of personnel. We will ensure that persons authorised to process Customer Personal Data are bound by appropriate obligations of confidentiality, whether contractual or statutory, and are granted access only to the extent necessary to perform their duties.
Security. We will implement and maintain the technical and organisational measures described in Annex 2, which are consistent with Clause 8.5 of the Terms of Use and Clause 11.1 of the Privacy Policy. We may update those measures from time to time provided that the level of protection is not materially degraded.
Records. We will maintain records of our processing activities carried out on your behalf as required by Data Protection Laws, and will make available to you information reasonably necessary to demonstrate compliance with this DPA in accordance with Clause 11.
Sub-processors
General authorisation. You give us general written authorisation to engage Sub-processors to process Customer Personal Data in connection with the Services. The categories of Sub-processor we engage are set out at Clause 5.2. During the Beta Period we do not maintain a formal sub-processor register, and we do not commit to maintaining, publishing or updating any list of Sub-processors. On written request to [email protected] we will, on a reasonable-efforts basis, provide information about the Sub-processors engaged by us at the time of the request, including the category of service each provides and, where known to us, the locations in which it processes data.
Categories of Sub-processor. Our Sub-processors include providers of cloud hosting and infrastructure, artificial intelligence model providers, analytics, email delivery, support tooling and payment processing. The identity of the model providers we engage, and the locations in which they process data, may vary over time and according to which models are used, as contemplated by Clause 10.3.3 of the Terms of Use and, during the Beta Period, Clause 5.6.
Notice of changes and objection. Except during the Beta Period, we will give you at least thirty (30) days' notice before a new Sub-processor begins processing Customer Personal Data. You may object on reasonable data protection grounds by notifying us in writing within that period. The parties will discuss the objection in good faith and we will use reasonable efforts to make available an alternative arrangement. If we are unable to do so within a reasonable period, you may terminate the affected Services on written notice, and we will refund a pro rata portion of any Fees prepaid for the unexpired portion of the then-current subscription term.
Urgent replacement. Where a change of Sub-processor is required urgently to preserve the security, availability or continuity of the Services, or to comply with law, we may make the change with immediate effect and will notify you promptly afterwards. Your objection rights under Clause 5.3 then apply from the date of that notice.
Flow-down and liability. We will impose on each Sub-processor, by written contract, data protection obligations that are materially equivalent to those in this DPA, including the security obligations at Clause 4.7 and Annex 2 and appropriate transfer mechanisms where required. During the Beta Period, where a Sub-processor, including a model provider or a cloud infrastructure provider, is engaged on that provider's own standard or published terms, those terms apply in place of materially equivalent obligations, and may permit the provider to retain or use Customer Personal Data on a basis wider than this DPA would otherwise permit, as described at Clauses 4.3 and 4.4.
Beta Period. During the Beta Period we may add, remove or replace Sub-processors, including model providers, and may change model routing, at any time and without prior notice, including in order to test routing configurations or to respond to a provider's failure, unavailability, degradation or underperformance. Clauses 5.3 and 5.4 do not apply during the Beta Period, except that we will give any advance notice that is strictly required by applicable law or by an approved transfer mechanism applicable to the relevant processing. Information about the Sub-processors engaged at any time is available in accordance with Clause 5.1. Any commitment to a fixed set of Sub-processors or model providers, to advance notice of changes, or to objection or alternative-routing rights, applies only to the extent expressly agreed in an Order Form or other written agreement entered into after the Beta Period. This Clause 5.6 is subject to Clause 12.6 where the Standard Contractual Clauses apply.
Data Subject Requests
Assistance. Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as reasonably possible, to enable you to fulfil your obligations to respond to Data Subject Requests. During the Beta Period that assistance is provided manually, on a reasonable-efforts basis and subject to applicable technical and legal constraints, rather than through self-service functionality within the Platform.
Requests received by us. If we receive a Data Subject Request relating to Customer Personal Data, we will not respond to it on its merits except to acknowledge receipt and explain our role as processor, or as otherwise required by law; we will refer the request to you without undue delay; and we will provide reasonable assistance to enable you to respond.
Requests from individuals named in Customer Data. You acknowledge that individuals whose personal data appears in Customer Data, including directors, officers, employees, shareholders and counterparties of a company under review, may contact us directly. Consistent with Clause 9.4 of the Privacy Policy, in responding to such contact we will not confirm to the requester the identity of any customer, the existence of any Account, or whether any particular Customer Data is held on the Platform, in order to preserve the confidentiality of your due diligence activities. We will instead refer the request to you and assist you in accordance with Clause 6.1.
Your responsibility. You are responsible for responding to any Data Subject Request relating to Customer Personal Data, for determining what may lawfully be disclosed, and for providing any notice required under Clause 2.3 of the Privacy Policy.
Government and Law Enforcement Requests
Notification. If we receive a legally binding request from a public authority, including a law enforcement, regulatory, judicial, tax or national security authority, for the disclosure of or access to Customer Personal Data, we will notify you of that request without undue delay so that you may seek to protect the data, unless we are prohibited from doing so by law.
Where notification is prohibited. Where we are prohibited from notifying you, we will use reasonable efforts to obtain a waiver of that prohibition with a view to communicating as much information to you as we can and as soon as we can, and we will be able to demonstrate those efforts on your request.
Challenging requests. We will review the legality of each such request and, where we conclude on a reasonable assessment that there are grounds to do so, we will challenge it, including by seeking interim measures with a view to suspending its effect until a competent authority has decided on the merits. We will not disclose Customer Personal Data until required to do so under the applicable procedural rules.
Minimum disclosure. In any event, we will disclose only the minimum amount of Customer Personal Data permissible in response to the request, based on a reasonable interpretation of it.
No direct or voluntary access. We will not provide any public authority with direct, indirect, blanket or unrestricted access to Customer Personal Data, and will not voluntarily disclose Customer Personal Data to any public authority except where required by law.
Records. We will document each request received, the response given and the basis on which any disclosure was made, and will make that record available to you on request, to the extent permitted by law.
Relationship with the Standard Contractual Clauses. Where the Standard Contractual Clauses apply, this Clause 7 operationalises, and does not limit, Clauses 14 and 15 of those Clauses.
Personal Data Breach
Notification. We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
Content of notification. Our notification will include, to the extent known and available to us at the time: a description of the nature of the Personal Data Breach, including where possible the categories and approximate number of data subjects and records concerned; its likely consequences; the measures taken or proposed to address it, including to mitigate its possible adverse effects; and a contact point for further information. Where it is not possible to provide all such information at once, we may provide it in phases as it becomes available, without further undue delay.
Cooperation. We will provide reasonable cooperation and assistance to enable you to meet your own notification obligations under Data Protection Laws.
External communications. You are responsible for determining whether to notify any supervisory authority or data subject in respect of Customer Personal Data, and for making any such notification, except where we are independently required by law to do so. Neither party will name the other in any external communication concerning a Personal Data Breach without prior consultation, except where required by law.
No admission. Our notification of, or response to, a Personal Data Breach is not an acknowledgment of fault or liability.
Assistance and Cooperation
Assistance. Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to you with data protection impact assessments relating to your use of the Services and with prior consultations with supervisory authorities arising from them. That assistance will primarily take the form of documentation we make generally available, including this DPA, Annex 2, the Privacy Policy and the Sub-processor information available in accordance with Clause 5.1. Where you request assistance that is materially more extensive, we may charge reasonable fees notified to you in advance.
Cooperation with supervisory authorities. We will cooperate, on request, with any supervisory authority having jurisdiction over your processing of Customer Personal Data in the performance of that authority’s tasks. Where a supervisory authority contacts us directly in relation to Customer Personal Data, we will notify you without undue delay unless we are prohibited from doing so by law.
Deletion and Return
Beta Period. During the Beta Period, you may request the export or deletion of Customer Data and Outputs, including in respect of archived matters, by contacting us at [email protected]. On archiving, Customer Data and Outputs are removed from active views within the Platform and are not used in generating further Outputs. We will action export and deletion requests manually, on a reasonable-efforts basis and subject to applicable technical and legal constraints. We do not during the Beta Period commit to self-service export or deletion functionality, to the irreversible deletion of all copies, to any fixed period for responding to or completing a request, or to the deletion of copies contained in routine backups.
Inactive Accounts. Where an Account has been inactive for a continuous period of twelve (12) months, we may delete or remove Customer Data associated with it in accordance with Clause 3.4 of the Terms of Use and Clause 8.2 of the Privacy Policy, having used reasonable efforts to give prior notice.
Return or deletion on termination. On termination or expiry of the Terms of Use you may request, by written notice to us at [email protected], that we make Customer Data and Outputs available to you for export, that we delete them, or both. In the absence of such a request, Customer Data and Outputs are archived, meaning that they are removed from active views within the Platform and are not used in generating further Outputs, and are retained in that state until we action a subsequent request from you or delete them in accordance with our practices in force from time to time. During the Beta Period we will action export and deletion requests manually, on a reasonable-efforts basis and subject to applicable technical and legal constraints, and we do not commit to self-service export or deletion functionality, to hard or irreversible deletion, to any fixed export window, to the export of Customer Data or Outputs in any particular format or in complete form, to any fixed period for completing deletion, to the deletion of copies contained in routine backups, in application, operational or security logs or in de-identified or aggregated data derived from Customer Data, or to procuring deletion by our Sub-processors within any fixed period. We will instruct our Sub-processors to delete Customer Personal Data in accordance with their own capabilities and terms, in each case in accordance with Clause 3.6 of the Terms of Use.
Exceptions. Clause 10.3 does not apply to the extent that we are required by law to retain some or all of the Customer Personal Data, in which case we will retain it only for so long as required and will continue to protect it in accordance with this DPA; to copies contained in routine backups or other non-active storage, which during the Beta Period are not deleted on any fixed cycle and will not be restored except for disaster recovery purposes; to application, operational or security logs; to de-identified or aggregated data derived from Customer Data which does not identify any individual; to copies retained by a Sub-processor in accordance with its own terms, as described at Clauses 4.4 and 5.5; or where retention is necessary for the establishment, exercise or defence of legal claims.
Certification. During the Beta Period we do not provide written certification of deletion. We may confirm by email that a deletion request has been actioned, on a reasonable-efforts basis and without warranting the completeness of the deletion.
Where you act as processor. Where you act as a processor under Clause 3.1(b), we will act on your instructions alone in respect of deletion and return, and you are responsible for ensuring that those instructions are consistent with your obligations to the relevant controller.
Audit and Demonstration of Compliance
Information and questionnaires. We will make available to you information reasonably necessary to demonstrate compliance with this DPA, Annex 2, the Privacy Policy, the Sub-processor information available in accordance with Clause 5.1, and responses to reasonable written questions or a standard security questionnaire, no more than once in any twelve (12) month period absent a Personal Data Breach or a regulatory requirement.
Audit reports. Where and once available, we will make available summaries of independent third-party audit reports or certifications, subject to confidentiality. We do not hold any such certification as at the date of this DPA.
Inspection. Where Clauses 11.1 and 11.2 do not reasonably satisfy your obligations under Data Protection Laws, or where required by a supervisory authority, you may audit or inspect our processing on at least thirty (30) days’ prior written notice, during normal business hours, in a manner causing minimum disruption, limited to systems and information relevant to the processing of Customer Personal Data, subject to appropriate confidentiality undertakings, not conducted by a competitor of ours, and no more than once in any twelve (12) month period unless required following a Personal Data Breach or by a supervisory authority. Audits are at your cost, save that we will bear our own reasonable costs where the audit identifies material non-compliance with this DPA.
Relationship with the SCCs. Where the Standard Contractual Clauses apply, this Clause 11 operationalises, and does not limit, the audit rights conferred by those Clauses.
International Transfers
Locations of processing. Consistent with Clause 7.1 of the Privacy Policy, Customer Personal Data may be hosted, stored and processed in a jurisdiction other than where we are incorporated and in the jurisdictions in which our Sub-processors operate. Because the Platform relies on third-party model providers, Customer Personal Data may be transmitted to and processed in the jurisdictions in which those providers operate, which may vary according to which models are used and may change over time.
Transfer mechanisms. Where a Restricted Transfer occurs, we will ensure an appropriate transfer mechanism is in place before the transfer, applying in order: (a) reliance on a finding of adequacy or equivalent recognition by the exporting jurisdiction, where available; (b) for transfers subject to the GDPR, the Standard Contractual Clauses, which are incorporated into this DPA by reference and completed in accordance with Clause 12.3; (c) for transfers subject to the UK GDPR, the UK Addendum, completed in accordance with Clause 12.4; and (d) for transfers subject to any other Data Protection Laws, any other mechanism recognised by those laws, in each case together with any supplementary measures required in the circumstances.
Completion of the Standard Contractual Clauses. Subject to Clause 12.7, where the Standard Contractual Clauses apply, they are incorporated and completed as follows: Module Two (controller to processor) applies where you act as controller under Clause 3.1(a), and Module Three (processor to processor) applies where you act as processor under Clause 3.1(b); the optional docking clause at Clause 7 applies; Option 2 (general written authorisation) applies at Clause 9, with a notice period of thirty (30) days, which applies notwithstanding Clause 5.6; the optional independent dispute resolution provision at Clause 11 does not apply; the Clauses are governed by the law of Ireland and disputes are resolved by the courts of Ireland; and Annex I and Annex II to the Clauses are completed by Annex 1 and Annex 2 to this DPA respectively, with the list of sub-processors being the information referred to at Clause 5.1
UK Addendum. Subject to Clause 12.7, where the UK Addendum applies, it is incorporated by reference: Table 1 is completed with the parties’ details as set out in Annex 1; Table 2 identifies the Standard Contractual Clauses as completed under Clause 12.3; Table 3 is completed by Annexes 1 and 2 to this DPA; and in Table 4, neither party may end the Addendum as set out in Section 19 of it.
Onward transfers. We will ensure that onward transfers of Customer Personal Data to Sub-processors are made under an appropriate transfer mechanism in accordance with Clause 12.2 and the flow-down obligation at Clause 5.5.
Precedence. Where the Standard Contractual Clauses or the UK Addendum apply and conflict with this DPA, those instruments prevail.
Beta Period scope. During the Beta Period the Services are made available on the basis that Customer Personal Data will not include personal data the processing of which is subject to the General Data Protection Regulation (Regulation (EU) 2016/679) or the UK General Data Protection Regulation, unless we have expressly agreed otherwise in writing in advance. Clauses 12.3 and 12.4 apply only where we have so agreed or after the Beta Period, and where we have not so agreed the Standard Contractual Clauses and the UK Addendum are not incorporated into this DPA.
United States State Privacy Laws
Service provider status. Where the California Consumer Privacy Act as amended by the California Privacy Rights Act (the "CCPA") applies to your use of the Services, we act as a "service provider" and, under other applicable United States state privacy laws, as a "processor", in respect of Customer Personal Data, and we will process that data only for the business purposes set out in this DPA and your Documented Instructions.
Restrictions. We will not: (a) sell or share Customer Personal Data, as those terms are defined under the CCPA, consistent with Clause 6.7 of the Privacy Policy; (b) retain, use or disclose Customer Personal Data for any purpose other than the business purposes specified in this DPA, or otherwise permitted by the CCPA, including outside the direct business relationship between us; or (c) combine Customer Personal Data with personal information received from or on behalf of any third party, or collected from our own interactions with data subjects, except as permitted under the CCPA.
Compliance and notification. We will comply with the obligations applicable to us as a service provider under the CCPA and will provide the same level of privacy protection as required of businesses under it. We will notify you if we determine that we can no longer meet those obligations, and you may, on notice, take reasonable and appropriate steps to stop and remediate unauthorised use of Customer Personal Data. We certify that we understand the restrictions in this Clause 13 and will comply with them.
Liability
Limitation. Each party’s liability arising out of or in connection with this DPA, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is subject to the exclusions and limitations of liability set out at Clause 12 of the Terms of Use, and any reference in the Terms of Use to a party’s liability includes its liability under this DPA. This Clause 14 does not limit or exclude the rights of data subjects under the Standard Contractual Clauses or Data Protection Laws, or any liability which cannot lawfully be limited or excluded.
General
Changes in law. We may amend this DPA on notice to you where required to reflect a change in Data Protection Laws, a decision of a competent authority, or the replacement or amendment of an approved transfer mechanism, provided that any such amendment does not materially reduce the protections afforded to Customer Personal Data. Other amendments follow the mechanics at Clause 13.1 of the Terms of Use.
Severability. If any provision of this DPA is held invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable or, if that is not possible, severed, and the remaining provisions continue in full force.
Governing law. This DPA is governed by the law specified at Clause 13.10 of the Terms of Use, except that the Standard Contractual Clauses and the UK Addendum are governed as set out at Clauses 12.3 and 12.4.
Notices. Notices concerning data protection may be sent to [email protected].
ANNEX 1 — DETAILS OF PROCESSING
Parties. The data exporter is the customer accepting the Terms of Use, acting as controller under Clause 3.1(a) or as processor under Clause 3.1(b). The data importer is Parallax, acting as processor or sub-processor accordingly. The contact point for the data exporter is the contact notified by the customer for its Account; the contact point for the data importer is [email protected].
Subject matter. The provision of the Services, being an artificial intelligence-assisted platform supporting due diligence workflows.
Duration. The term of the Terms of Use, together with the export and deletion arrangements set out at Clause 10.
Nature of the processing. Collection, storage, hosting, transmission (including to third-party model providers), organisation, analysis, retrieval, generation of Outputs, export and erasure. Outputs may describe, assess or draw inferences about individuals named in Customer Data, as described at Clause 5.3 of the Privacy Policy.
Purposes. Providing, maintaining, securing and supporting the Services, and generating Outputs, in each case in accordance with the Documented Instructions.
Frequency. Continuous for the duration of the term.
Categories of data subject. Customer Personal Data may relate to the following categories of data subject, as determined by the customer through the Customer Data it uploads:
(a) the customer’s personnel and Authorised Users, to the extent appearing within Customer Data;
(b) directors, officers, senior managers and employees of a company that is the subject of a due diligence exercise;
(c) shareholders, beneficial owners and investors in such a company;
(d) counterparties, customers, suppliers, lenders and advisers of such a company, and their personnel; and
(e) any other individuals whose personal data appears in documents or information uploaded by the customer.
Categories of personal data. Identity and contact data; professional and employment data, including roles, appointments and directorships; corporate records data, including shareholdings and register entries; contractual and commercial data; financial data appearing in diligence materials; and any other personal data contained in documents or information uploaded by the customer.
Special-category and sensitive data. The Services are not intended for the processing of special-category data, criminal-offence data or equivalent sensitive data. Clause 7.5.3 of the Terms of Use prohibits the submission of such data except as expressly agreed with us in writing in advance, in which case additional safeguards will be agreed.
Sub-processors. The categories of Sub-processor engaged are set out at Clause 5.2. Information about the Sub-processors engaged at any time is available in accordance with Clause 5.1. Where the Standard Contractual Clauses apply, that information constitutes the list of sub-processors for the purposes of Clause 9 of those Clauses.
Competent supervisory authority. Where the Standard Contractual Clauses apply, determined in accordance with Clause 13 of those Clauses.
ANNEX 2 — TECHNICAL AND ORGANISATIONAL MEASURES
The measures below describe the technical and organisational measures in place as at the effective date of this DPA. They are consistent with Clause 8.5 of the Terms of Use and Clause 11.1 of the Privacy Policy.
Measure |
Description |
Encryption |
Customer Personal Data is encrypted in transit and at rest. |
Access control |
Role-based access controls and least-privilege principles are used. Production access is limited to authorised personnel with a business need. |
Authentication |
Individual named accounts are used for personnel access. |
Logging |
Basic application and operational logs are maintained for service operation and troubleshooting. |
Network and infrastructure |
Managed cloud infrastructure provided by Amazon Web Services, with segregation of environments and network access controls. |
Segregation |
Customer Data is logically segregated between Accounts using account-scoped access controls. |
Personnel |
Access is granted on a need-to-know basis. Personnel with access to Customer Personal Data are subject to documented confidentiality obligations. |
Certifications |
We hold no security certifications as at the effective date of this DPA. |
The measures described above are those in place as at the effective date of this DPA and are not an exhaustive description of our internal practices. We may update these measures from time to time to reflect changes in technology, threats or our infrastructure, provided that the level of protection is not materially degraded.