Data Processing Addendum
Data Processing Addendum
Available Documents:
- Privacy Policy
- End User License Agreement
- Master Subscription Agreement
- Independent Contractor Agreement
Data Processing Addendum
This Data Processing Addendum (the “Addendum”) is made a part of the Master Subscription Agreement (“Agreement”) and Statement(s) of Work (“SOWs”) between the customer (“Customer”) and Boomtown Network, Inc. dba OvationCXM (“SUBPROCESSOR” or “OvationCXM”). This Data Processing Addendum shall apply to all processing of Customer Personal Data by SUBPROCESSOR.
Schedule 1 – Data Protection
In Schedules 1-4, the following defined terms shall mean:
"Data Processing Addendum"
Personal Information (otherwise known as Personal Data) which is to be Processed under the Agreement, as more particularly described in Schedule 2.
“Data Protection Laws”
Any applicable data protection laws in force from time to time that relates to data protection, the processing of personal data and privacy, including: U.S. data privacy laws, including the California Privacy Rights Act, California Consumer Protection Act, and the EU General Data Protection Regulation 2016/679 of the European Parliament and of the Council (“GDPR”) and any data protection laws substantially amending, replacing or superseding the GDPR following any exit by the United Kingdom from the European Union, or, and to the extent applicable, the data protection or privacy laws of any other Member State of the European Economic Area or Switzerland. Nothing in this Addendum, however, shall be interpreted to infer or imply that either Customer or SUBPROCESSOR is itself subject to the GDPR or to the jurisdiction of any European regulatory body for these purposes.
(a) references to “Controller”, “Business”, “Data Subjects”, “Personal Data”, “Personal Information”, “Process”, “Processed”, “Processing”, “Processor”, “Service Provider”, and “Supervisory Authority” have the meanings set out in, and will be interpreted in accordance with, such laws.
"Data Security Incident"
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Addendum Personal Information transmitted, stored or otherwise Processed.
"International Transfer"
A transfer to a country outside the European Economic Area of Addendum Personal Information which is undergoing Processing or which is intended to be Processed after transfer.
"Standard Contractual Clause"
means Commission Decision C(2010)593 Standard Contractual Clauses (processors) for the purposes of Article 26(2) of Directive 95/46/EC for the transfer of personal data to processors established in third countries which do not ensure an adequate level of data protection, as amended, updated or replaced from time to time.
“Sub-Processor”
Any third party appointed by SUBPROCESSOR to Process Addendum Personal Information.
1. DATA PROTECTION AND INFORMATION SECURITY
1.1 Customer authorizes SUBPROCESSOR to Process the Addendum Personal Information during the term of the Agreement as a Processor for the purpose set out in Schedule 2.
1.2 Customer warrants to SUBPROCESSOR that to the best of its knowledge and belief:
- 1.2.1 it has all necessary rights to authorize SUBPROCESSOR to Process Addendum Personal Information in accordance with the Addendum and the Data Protection Laws; and
- 1.2.2 its instructions to SUBPROCESSOR relating to Processing of Addendum Personal Information will not cause SUBPROCESSOR to be in breach of Data Protection Laws, including with regard to International Transfers.
1.3 If SUBPROCESSOR reasonably considers that any instructions from Customer relating to Processing of Addendum Personal Information may directly or indirectly cause SUBPROCESSOR to be in breach or violation of Data Protection Laws, SUBPROCESSOR shall immediately inform Customer, and SUBPROCESSOR will be entitled not to carry out that Processing and will not be in breach of the Agreement or otherwise liable to Customer as a result of its failure to carry out that Processing, unless Customer varies its instructions, or provides further information to SUBPROCESSOR as to why the instructions are not in violation of any Data Protection Law.
1.4 SUBPROCESSOR shall not retain, use, or disclose the personal information for any purpose other than for the specific purpose of performing the services specified in the Agreement, and SUBPROCESSOR shall not Process Addendum Personal Information other than on Customer’s documented instructions to perform the Services set forth in the Agreement or as provided on Schedule 2, unless Processing is required by Data Protection Laws to which SUBPROCESSOR is subject, in which case SUBPROCESSOR, to the extent permitted by Data Protection Laws, shall inform Customer of that legal requirement before Processing Addendum Personal Information.
1.5 Customer authorizes SUBPROCESSOR to engage the Sub-Processors listed at Schedule 4 for the processing of Addendum Personal Information. SUBPROCESSOR will inform Customer 30 days in advance of any intended changes concerning the addition or replacement of Sub-Processors, thereby giving Customer the opportunity to object to such changes.
1.6 If SUBPROCESSOR appoints a Sub-Processor in compliance with paragraph 1.5 above, SUBPROCESSOR will put a written contract in place between SUBPROCESSOR and the Sub-Processor that specifies the Sub-Processor’s Processing activities and imposes on the Sub-Processor the same terms to those imposed on SUBPROCESSOR in this Addendum. SUBPROCESSOR will remain liable to Customer for performance of the Sub-Processor’s obligations.
1.7 SUBPROCESSOR will:
- 1.7.1 Process the Addendum Personal Information only on documented instructions from Customer (unless SUBPROCESSOR or the relevant Sub-processor is required to Process Addendum Personal Information to comply with applicable laws to which the SUBPROCESSOR is subject, in which case SUBPROCESSOR will notify Customer of such legal requirement prior to such Processing).
- 1.7.2 ensure that any individual authorized to Process Addendum Personal Information is subject to contractual confidentiality obligations equivalent to those set out in the Addendum or is under an appropriate statutory obligation of confidentiality.
- 1.7.3 not transfer Addendum Personal Information outside the United States absent Customer’s advance written consent.
1.8 SUBPROCESSOR will:
- 1.8.1 implement appropriate technical and organizational measures to protect the Addendum Personal Information from a Data Security Incident.
- 1.8.2 notify Customer without undue delay upon SUBPROCESSOR or any approved Sub-processor becoming aware of a Data Security Incident involving Addendum Personal Information.
- 1.8.3 provide such commercially reasonable cooperation as Customer may request in complying with any Customer obligations under the Data Protection Laws relating to the security of Processing Addendum Personal Information.
1.9 SUBPROCESSOR will:
- 1.9.1 make available to Customer all information necessary to demonstrate compliance with the obligations set out in this Addendum; and
- 1.9.2 allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer.
1.10 Unless otherwise required by applicable laws, following termination or expiration of the Agreement, SUBPROCESSOR shall, without undue delay, at Customer’s option, delete or return any retained Addendum Personal Information and all copies to Customer.
1.11 In the event of any inconsistency between this Addendum and the Agreement with respect to Addendum Personal Information, this Addendum shall prevail.
1.12 As specified above, nothing in this Addendum shall be interpreted to imply that Customer or SUBPROCESSOR is subject to the GDPR or to the jurisdiction of any European regulatory body for these purposes.
Schedule 2 - Addendum Personal Information
Subject Matter of Processing
The subject matter of Processing of Personal Data by OvationCXM is the provision of the SaaS and product support services to Customer that involves the processing of Personal Data.
Duration of Processing
The Processing will continue until the expiration or termination of the Agreement, unless otherwise agreed upon in writing by OvationCXM and Customer.
Nature of Processing and Purpose of Processing
The Processing will involve Processing for the provision of SaaS and Product Support services by OvationCXM for Customer, as further specified in the Agreement and Statement(s) of Work and as instructed by Customer in its use of the SaaS and product support services.
Type of Personal Data
In its use of the SaaS and product support services, Customer may submit Personal Data to OvationCXM, the extent of which is determined and controlled by Customer in its sole discretion. This Personal Data may include, but is not limited to:
- First and Last Name
- Business Name
- E-mail Address
- Phone Number
- Street Address, City, State, Zip Code, Country
- Merchant Identification Number
Categories of Data Subject
Personal Data, the extent of which is determined and controlled by Customer in its sole discretion, may include, but is not limited to the following categories of data subjects:
- Prospects, customers, business partners, and vendors of Customer
- Employees or contact persons of Customer’s prospects customers, business partners, and vendors
- Employees, agents, advisors, freelancers of Customer
- Authorized Customer Users
Schedule 3 – Technical and Organizational Security Measures
SUBPROCESSOR has implemented and will maintain reasonable and appropriate technical and organizational security measures to protect Addendum Personal Information against accidental or unauthorized loss, destruction, alteration, disclosure or access. These measures include:
- It will take all reasonable measures to control who gets to access Addendum Personal Information.
- It will implement appropriate technical and organizational measures designed to ensure against unauthorized or unlawful access.
- It will not retain Addendum Personal Information unless pursuant to other legal requirements.
- It will audit user behavior for any abnormal or suspicious activities.
- It will implement best practice protections against any threats to security.
Schedule 4 - Authorized Sub-Processors
| Purpose | Entity | Country |
|---|---|---|
| Hosting center provider for the OvationCXM Software. | Iron Mountain Data Centers, LLC | United States |
| Cloud service provider for the OvationCXM Software. | Google LLC | United States |
| Cloud service provider for the OvationCXM Software | DigitalOcean, Inc. | United States |
| SMS text messaging for OvationCXM Software | Twilio, Inc. | United States |
| Data and analytics platform for the OvationCXM Software. | GoodData Corporation | United States |
| Contact center software provider integrated with the OvationCXM Software. | RingCentral, Inc. | United States |
| Third-party logging platform that OvationCXM uses for ingesting, parsing, querying and performing analytics. | Datalog, Inc. | United States |
| Customer relationship management (CRM) system of record | Salesforce | United States |
| Internal communications as well as external communications with clients and vendors (where authorized via Slack Connect) | Slack Technologies, LLC | United States |
| Marketing Automation Platform | ActiveCampaign, LLC | United States |
| File Storage | Dropbox, Inc | United States |
| Onboarding and Customer Success Platform | Wrike, Inc. | United States |
| Integration and automated workflows | Zapier, Inc | United States |
| Integration and automated workflows | Breakout Platforms, Inc. dba Cobalt | United States |