▓▒░ LEGAL / DPA
Data Processing Addendum
1. Applicability
This Data Processing Addendum (“DPA”) shall apply to the services agreement (“Services Agreement”) by and between Qualifire Ltd. and its affiliates (“Qualifire”) and Customer, to the extent that Qualifire processes Personal Data (as defined below).
2. Definitions
- Terms used in this DPA but not defined herein (whether or not capitalized) shall have the meanings assigned to such terms in the Applicable Data Protection Laws.
- “Applicable Data Protection Laws” shall mean, to the extent applicable to Qualifire's processing of Personal Data hereunder (with respect to each data subject): (i) General Data Protection Regulations (European Parliament and Council of European Union (2016) Regulation (EU) 2016/679) (EU GDPR); (ii) EU GDPR as it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act 2018 and UK Data Protection Act 2018 (UK GDPR); (iii) California Consumer Privacy Act of 2018 (CCPA) and the California Privacy Rights Act of 2020 (CPRA); (iv) Protection of Privacy Law (Israel); (vi) any similar laws to any of the foregoing in any jurisdiction that may be enacted from time to time; and (vii) any rules or regulations that amend and/or replace any of the aforementioned Data Protection Laws.
- “Personal Data” refers to the definition of that term or any other similar term defined under the Applicable Data Protection Laws.
- “Standard Contractual Clauses or SCCs” shall mean: where the EU GDPR applies, the standard contractual clauses pursuant to the EU Commission's Implementing Decision 2021/914 of 4 June 2021 currently set out at: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj (“EU SCCs”); (ii) where the UK GDPR applies, the EU SCCs together with the UK Information Commissioner’s Office addendum, under S119A(1) of the Data Protection Act 2018 (“UK Addendum”); or any other Standard Contractual Clauses which amended and/or replace such Standard Contractual Clauses in accordance with Applicable Data Protection Law.
3. Processing of Personal Data on Behalf of Customer
- Qualifire acts as a processor/service provider for Customer, and performs processing operations on behalf of Customer and upon the instructions of Customer as a controller/business, as set forth herein, in the Services Agreement, and any additional agreement entered into between Customer and Qualifire (collectively, the “Terms”), pursuant to which Customer may provide Personal Data to Qualifire (“Contracted Business Purpose”).
- Sensitive Data. The Parties agree that the provision of the services under the Agreement is not intended for the processing of Sensitive Data. For the avoidance of doubt, this DPA will not apply to Sensitive Data and Qualifire shall have no liability whatsoever for Sensitive Data, whether in connection with a Personal Data Breach or otherwise.
4. Customer Representations
Customer sets forth the details, including the purpose, the means and the ways in which Qualifire shall process Personal Data, as required by Applicable Data Protection Laws in Appendix A (Details of Processing of Processed Personal Data), attached hereto, and Customer represents and warrants that:
- It complies with personal data security and other obligations prescribed by Applicable Data Protection Laws for controller/business, and that the provision of Personal Data to Qualifire is in strict compliance with Applicable Data Protection Laws;
- It only processes Personal Data that has been collected in accordance with the Applicable Data Protection Laws;
- It has in place procedures in case an individual whose Personal Data is collected, wishes to exercise the individual’s rights in accordance with the Applicable Data Protection Laws;
- It provides Personal Data to Qualifire for the Contracted Business Purpose in accordance with the representations Customer makes to individuals in Customer's privacy policy, and Customer does not sell Personal Data to Qualifire;
- It shall have the sole responsibility for the accuracy, quality, and legality of such Customer’s Personal Data;
- It shall provide Qualifire as a processor/service provider, or otherwise have Qualifire (or anyone on its behalf) process such Personal Data which is explicitly permitted under Applicable Data Protection Laws (“Permitted Personal Data”). Solely Customer shall be liable for any data which is made available to Qualifire in excess of the Permitted Personal Data (“Non-Permitted Data”). Qualifire's obligations under the Terms shall not apply to any such Non-Permitted Data and Customer shall be fully responsible and liable for any damages, claims, or losses arising from or relating to the submission or use of Non-Permitted Data.
- It is and will remain duly and effectively authorized to give the instruction set out herein and any additional instructions as provided pursuant to the Terms, at all relevant times and at least for as long as the Terms are in effect and for any additional period during which Qualifire is lawfully processing Personal Data.
5. Qualifire Obligations
- Qualifire carries out the processing of Personal Data on Customer's behalf.
- Pursuant to the provisions of Article 28 of the GDPR, to the extent applicable with respect to each data subject, Qualifire agrees that it will:
- process Personal Data solely on Customer's behalf and in compliance with Customer's instructions, including instructions in this DPA and all Terms, unless required to do so by EU or applicable Member State law;
- implement appropriate technical and organizational measures to provide an appropriate level of security, including, as appropriate and applicable, the measures referred to in Article 32(1) of the GDPR;
- take reasonable steps to ensure that access to the processed Personal Data is limited on a need to know/access basis, and that all Qualifire personnel receiving such access are subject to confidentiality undertakings or professional or statutory obligations of confidentiality in connection with their access/use of Personal Data;
- it shall provide reasonable assistance to Customer with any data protection impact assessments or prior consultations with supervising authorities in relation to processing of Personal Data by the processor/service provider, as required under any Applicable Data Protection Laws, at the written request of the Customer, and at Customer's sole expense; and
- Pursuant to the CCPA, to the extent applicable with respect to each data subject, Qualifire agrees that:
- Qualifire is acting solely as a service provider with respect to Personal Data;
- Qualifire shall not retain, use or disclose Personal Data for any purpose other than for the Contracted Business Purpose;
- Qualifire may de-identify or aggregate Personal Data as part of performing the services specified in the Terms; and
- Qualifire will limit personal information collection, use, retention, and disclosure to activities reasonably necessary and proportionate to achieve the Contracted Business Purposes or another compatible operational purpose.
6. Sub-Processing
- Customer authorizes Qualifire to appoint sub-processors in accordance with the provision of the Terms. Any sub-processor used must qualify as a service provider under the Applicable Data Protection Laws and Qualifire cannot make any disclosures to a subcontractor that the CCPA would treat as a sale.
- Qualifire may continue to use those sub-processors already engaged by Qualifire as of the date of this DPA. Customer acknowledges and agrees that as of the date of this DPA Qualifire uses certain sub-processors; a list of such sub-processors is attached hereto in Appendix A.
- Qualifire may appoint new sub-processors and shall give reasonable notice of the appointment of any new sub-processor. Customer's continued use of the applicable services after such notification constitutes Customer's acceptance of the new sub-processor.
7. Data Subjects' Rights
- Customer shall be solely responsible for compliance with any statutory obligations concerning requests to exercise data subject rights under Applicable Data Protection Laws (e.g., for access, rectification, deletion of processed Personal Data, etc.). Qualifire shall reasonably endeavor to assist Customer insofar as feasible, to fulfil Customer's said obligations with respect to such data subject requests, as applicable, at Customer's sole expense.
- Qualifire shall (i) without undue delay notify Customer if it receives a request from a data subject under any Applicable Data Protection Laws in respect of processed personal data; and (ii) not respond to that request, except on the written instructions of Customer or as required by Applicable Data Protection Laws, in which case Qualifire shall, to the extent permitted by Applicable Data Protection Laws, inform Customer of that legal requirement before it responds to the request.
8. Personal Data Breach
- Qualifire shall notify Customer without undue delay upon Qualifire becoming aware of any personal data breach within the meaning of Applicable Data Protection Laws relating to Personal Data of the Customer which may require a notification to be made to a supervisory authority or data subject under Applicable Data Protection Laws (“Personal Data Breach”).
- At the written request of the Customer and at Customer's sole expense, Qualifire shall provide reasonable co-operation and assistance to Customer in respect of Customer's obligations regarding the investigation of any Personal Data Breach and the notification to the supervisory authority and data subjects in respect of such a Personal Data Breach.
9. Deletion or Return of Processed Personal Data
- Subject to the terms hereof, Qualifire shall promptly and in any event within up to sixty (60) days (unless a sooner time period is required by Applicable Data Protection Laws) return and then destroy the Personal Data, except such copies as authorized including under this DPA or required to be retained in accordance with Applicable Data Protection Laws.
- Qualifire may retain Personal Data to the extent authorized or required by Applicable Data Protection Laws, provided that Qualifire shall ensure the confidentiality of such Personal Data and shall ensure that it is only processed for such legal purpose(s).
- Upon Customer's prior written request, Qualifire shall provide written certification to Customer that it has complied with this Section 9.
10. Audit Rights
- Not more than once a year, at the cost of Customer, upon reasonable prior notice and mutual coordination, Qualifire shall allow for audits by a reputable auditor mandated by the Customer in relation to the processing of the Personal Data by Qualifire, provided that such third-party auditor shall be subject to confidentiality obligations in favor of Qualifire. In such an audit Qualifire shall make available relevant information reasonably necessary to demonstrate compliance with this DPA.
- Customer shall use (and ensure that its mandated auditor uses) its best efforts to avoid causing any damage, injury or disruption in the course of such an audit.
11. International Data Transfers
- To the extent that Qualifire transfers Personal Data to countries outside of the European Economic Area and/or outside of the United Kingdom (UK), which do not provide an adequate level of data protection, as determined by the European Commission pursuant to Article 45 of GDPR, and by the Secretary of State, pursuant to Section 17A of the United Kingdom Data Protection Act 2018, respectively, or other adequate authority as determined by the EU and the UK (“Adequacy Decisions”), and to the extent applicable with respect to each data subject, such transfer of Customer’s Personal Data to other countries, where the application of the SCCs is required under Applicable Data Protection Laws shall be subject to: (i) Adequacy Decisions; (ii) exemptions under Article 49 of the GDPR; or (iii) the Standard Contractual Clauses are incorporated into this DPA by reference, which shall be implemented as follows:
- In the case of transfer of Personal Data between Customer to Qualifire, the parties shall implement Module II - “Controller to Processor”, of the Standard Contractual Clauses, with modifications detailed under this Section 11.1.1, in which case Qualifire shall be deemed as a "Data Importer" and Customer shall be deemed as a "Data Exporter". The parties are deemed to have accepted and executed the SCCs, including the associated annexes. The contents of Annex I of the SCCs are included within Appendix A to this DPA. The contents of Annex II of the SCCs are included within Appendix B to this DPA. The parties further agree to the following implementation choices under the SCCs:
- The Parties agree that for the purpose of transfer of Personal Data between Qualifire (Data Importer) and the Customer (Data Exporter), the following shall apply:
- Clause 7: shall not be applicable.
- Clause 9(a): The parties choose Option 2, “General Written Authorization” and specify a time period of thirty (30) days. Appendix A shall be updated accordingly.
- Clause 11: The parties choose not to include the optional language relating to the use of an independent dispute resolution body.
- Clause 17: The parties select Option 1 and specify the law of Ireland.
- Clause 18(b): The parties specify the courts of Ireland.
- In the case of transfer of Personal Data between Qualifire and its Sub-Processors for the purposes of carrying out specific Processing activities (on behalf of Customer) the Partis will enter into Module III (“Processor-to-Processor”) of the Standard Contractual Clauses. For the purpose of such engagement, Qualifire shall be deemed as the Data Exporter and the Sub-Processor shall be deemed as the Data Importer; all other Modules are not applicable.
- If the applicable Data Exporter, under Section 11.1.1 or 11.1.2, is transferring Personal Data governed by the UK GDPR, the parties agree to implement the applicable SCCs, as modified by the UK Addendum. The information required by Table 1 of the UK Transfer Addendum appears within Appendix A to this DPA. In addition, the parties adopt the SCCs, as modified by the UK Transfer Addendum, as to applicable international transfers of UK Personal Data in exactly the same manner set forth in Section 11.1 above, subject to the following:
- Clause 13: The UK Information Commissioner’s Office (“ICO") shall be the competent supervisory authority.
- Clause 17: The SCCs, as modified by the UK Transfer Addendum, shall be governed by the laws of England and Wales.
- Clause 18: The parties agree that any dispute arising from the SCCs, as modified by the UK Transfer Addendum, shall be resolved by the courts of England and Wales. A UK Data Subject may also bring legal proceedings against the Data Exporter and/or Data Importer before the courts of any country in the UK. The parties agree to submit themselves to the jurisdiction of such courts.
- In the case of transfer of Personal Data between Customer to Qualifire, the parties shall implement Module II - “Controller to Processor”, of the Standard Contractual Clauses, with modifications detailed under this Section 11.1.1, in which case Qualifire shall be deemed as a "Data Importer" and Customer shall be deemed as a "Data Exporter". The parties are deemed to have accepted and executed the SCCs, including the associated annexes. The contents of Annex I of the SCCs are included within Appendix A to this DPA. The contents of Annex II of the SCCs are included within Appendix B to this DPA. The parties further agree to the following implementation choices under the SCCs:
- Appendixes A, B, and C attached to this DPA shall also apply in connection with the processing of Personal Data, subject to Applicable Data Protection Law.
- Qualifire reserves the right to adopt an alternative compliance standard to the SCCs for the lawful transfer of Personal Data, provided it is recognized under Data Protection Law. Qualifire will provide 30 days’ advance notice of its adoption of an alternative compliance standard.
12. General Terms
- Governing Law and Jurisdiction. All disputes with respect to this DPA shall be determined in accordance with the governing law provisions set forth in the Services Agreement.
- Conflict. In the event of any conflict or inconsistency between this DPA and any other agreements between the parties, including agreements entered into after the date of this DPA, the provisions of this DPA shall prevail.
- Changes in Applicable Data Protection Laws. Customer may by at least forty-five (45) calendar days' prior written notice to processor/service provider, request in writing any changes to this DPA, if they are required, as a result of any change in any Applicable Data Protection Law, regarding the lawfulness of the processing of Personal Data. If Customer provides its modification request, Qualifire shall make commercially reasonable efforts to accommodate such modification request, and Customer shall not unreasonably withhold or delay agreement to any consequential changes to this DPA to protect the Qualifire against any additional risks, and/or to indemnify and compensate Qualifire for any further costs associated with the changes made hereunder.
- Severance. Should any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall either be (i) amended as necessary to ensure its validity and enforceability, while preserving the parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.
Appendix A
Identification of Parties
"Data Exporter": Customer.
"Data Importer": Qualifire.
Description of Transfer
| Categories of Personal Data | Name, Email Address, IP Address. Other Personal Data which is not required by Qualifire and may be included in Customer Data disclosed or otherwise made available by Customer to Qualifire in the context using of the Services |
|---|---|
| Categories of data subjects: | Customer Employees Other data subjects which may be included in Customer Data disclosed or otherwise made available by Customer to Qualifire in the context of using the Services. |
| Special Categories of Data/Sensitive Personal Information | The Parties do not intend for Sensitive Data to be transferred. |
| Nature of Processing | Providing the services to Customer under the Agreement; Acting upon Customer’s written instructions in accordance with the Agreement and the DPA; Complying with applicable laws and regulations. |
| Frequency of Transfer | Continuous Basis |
| Purpose of the transfer and further processing | As described in the Agreement |
| Retention period | Personal Data will be retained for the term of the Agreement. |
Sub-Processors:
| Sub-Processor Name | Purpose of Processing | Location | Type of Personal Data Processed |
|---|---|---|---|
| Google Cloud Platform (GCP) | Cloud hosting and storage | United States | All categories stored in infrastructure |
| Hubspot | CRM | United States | First name, last name, email address, phone number, company name, and any other information collected during the registration to Qualifire’s platform. |
| AWS | Cloud hosting and storage | United States | All categories stored in infrastructure |
Appendix B
Technical and Organizational Measures to Ensure the Security of the Data
Qualifire is SOC 2 certified