Skip to main content

Data Processing Agreement

What personal data Okya processes, who our subprocessors are, and how we handle data.

Z
Written by Zachary Marble

Last updated: July 20, 2026

Key Terms

The key legal terms of the DPA are as follows:

  • Agreement This Data Processing Agreement supplements the Okya Limited — Cloud Service Agreement.

  • Approved Subprocessors Please refer to the list of subprocessors at this link.

  • Provider Security Contact [email protected] Universal Trade Centre, 29F Unit 2904-05, 3 Arbuthnot Road, Central, Hong Kong 999077

  • Security Policy As defined in the Agreement. Provider will maintain annually updated reports or annual certifications of compliance with the following: SOC 2 Type II.

  • Governing Law and Chosen Courts Notwithstanding the governing law or similar clauses of the Agreement, all interpretations and disputes about this DPA will be governed by the laws of the Governing State without regard to its conflict of laws provisions. In addition, and notwithstanding the forum selection, jurisdiction, or similar clauses of the Agreement, the parties agree to bring any legal suit, action, or proceeding about this DPA in, and each party irrevocably submits to the exclusive jurisdiction of, the courts of the Governing State.

    • Governing State means: Hong Kong.

  • Service Provider Relationship To the extent the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq ("CCPA") applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed below (see Nature and Purpose of Processing), which constitutes a limited and specified business purpose. Provider will not sell or share any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA.

  • Restricted Transfers Governing Member State — UK Transfers: England and Wales

  • Annex I(A) List of Parties

    • Data Exporter Name: the Customer signing this DPA Activities relevant to transfer: See Annex I(B) Role: Controller

    • Data Importer Name: the Provider signing this DPA Contact person: Carlos Herrera, CEO Address: Universal Trade Centre, 29F Unit 2904-05, 3 Arbuthnot Road, Central, Hong Kong 999077 Activities relevant to transfer: See Annex I(B) Role: Processor

  • Annex I(B) Description of Transfer and Processing Activities

    • Service The Service, Okya Limited, is a cloud-based SaaS platform that provides restaurants, hotels, and retail brands with integrated solutions to increase online and offline sales, enhance customer experiences, and improve operational efficiency.

    • Categories of Data Subjects: Customer's end users or customers

    • Categories of Personal Data

      • Name

      • Contact information such as email, phone number, or address

      • Transactional information such as account information or purchases

      • User activity and analysis such as device information or IP address

      • Location information

  • Special Category Data: Is special category data (as defined in Article 9 of the GDPR) Processed? No.

  • Frequency of Transfer: Continuous

  • Nature and Purpose of Processing

    • Receiving data, including collection, accessing, retrieval, recording, and data entry

    • Holding data, including storage, organization, and structuring

    • Using data, including analysis, consultation, testing, automated decision making, and profiling

    • Updating data, including correcting, adaptation, alteration, alignment, and combination

    • Protecting data, including restricting, encrypting, and security testing

    • Sharing data, including disclosure, dissemination, allowing access, or otherwise making available

    • Returning data to the data exporter or data subject

    • Erasing data, including destruction and deletion

  • Duration of Processing Provider will process Customer Personal Data as long as required (i) to conduct the Processing activities instructed in Section 2.2(a)–(d) of the Standard Terms, or (ii) by Applicable Laws.

  • Annex I(C)

    • Competent Supervisory Authority The supervisory authority will be the supervisory authority of the data exporter, as determined in accordance with Clause 13 of the EEA SCCs or the relevant provision of the UK Addendum.

  • Annex II

  • Annex III

  • Technical and Organizational Security Measures

    • See Security Policy, and the measures set out below.

  • Pseudonymization and encryption of personal data

    • Provider uses pseudonymization and encryption where it can be applied without affecting the efficiency of processes and/or where it is necessary to protect data if disclosure is required. Where possible as part of the disclosure process, anonymization is used. Data that can identify data subjects contained in pseudonymized data is stored separately and encrypted where possible.

    • Provider has a process for assessing internal data sharing and uses pseudonymization to limit the use of personal data for certain purposes.

  • Ensuring ongoing confidentiality, integrity, availability, and resilience

    • Provider takes reasonable measures to prevent Customer Personal Data from being used without authorization. These controls vary based on the nature of the processing undertaken and may include, among other controls, authentication via passwords and/or two-factor authentication, documented authorization processes, documented change management processes, and logging of access on several levels.

    • Provider takes reasonable measures to ensure Customer Personal Data is accessible and manageable only by properly authorised staff. Direct database query access is restricted and application access rights are established and enforced to ensure that persons entitled to use a data processing system only have access to the Customer Personal Data to which they have privilege of access, and that Customer Personal Data cannot be read, copied, modified, or removed without authorisation in the course of processing.

    • Provider systems are housed in zones commensurate with their security, depending on function, information classification, and risk. Provider's network security architecture consists of multiple zones with more sensitive systems, like database servers, in Provider's most trusted zones. Depending on the zone, additional security monitoring and access controls will apply. DMZs are utilised between the internet and internally between the different zones of trust.

    • Provider's network is protected through the use of key AWS security services, regular audits, and network intelligence technologies, which monitor and/or block known malicious traffic and network attacks. Provider utilises network security scanning to provide quick identification of potentially vulnerable systems, in addition to Provider's extensive internal scanning and testing program. Provider has a multi-layer approach to DDoS mitigation, utilising network edge defenses along with scaling and protection tools.

    • Provider has not built any backdoors or other methods into its Services to allow government authorities to circumvent its security measures to gain access to Customer Personal Data.

  • Ability to restore the availability of and access to the Customer Personal Data in a timely manner following a physical or technical incident:

    • Provider maintains a publicly available system-status webpage, which includes system availability details, scheduled maintenance, service incident history, and relevant security events, at status.okya.co.

    • Provider employs service clustering and network redundancies to eliminate single points of failure. Our strict backup regime and/or Provider's Enhanced Disaster Recovery service offering allows us to deliver a high level of service availability, as Customer Personal Data is replicated across available zones. Provider's Disaster Recovery program ensures that Provider's Services remain available and are easily recoverable in the case of a disaster, through building a robust technical environment.

  • Regular testing, assessment, and evaluation of the effectiveness of technical and organizational measures used to secure Processing:

    • The Provider security program includes documented policies and standards of administrative, technical, physical, and organisational safeguards, which govern the handling of Customer Personal Data in compliance with applicable law. The security program is designed to protect the confidentiality and integrity of Customer Personal Data, appropriate to the nature, scope, context, and purposes of processing and the risks involved in the processing for the data subjects.

    • Provider reserves the right to update its security program from time to time; provided, however, that any update will not materially reduce the overall protections set forth in this document.

  • User identification and authorization process and protection:

    • User identification and authorization will be rigorously managed. Unique identifiers and strong authentication methods, including multi-factor authentication, will be mandatory. Least privilege will be applied to user access, and access control mechanisms like RBAC, ABAC, and time-based controls will be implemented. Secure session management, strong password policies, and regular monitoring of access logs will enhance security. User accounts will be promptly deactivated when no longer required.

  • Protecting Customer Personal Data during transmission (in transit):

    • Provider takes reasonable measures to ensure the ability to check and establish which entities are transferred Customer Personal Data by means of data transmission facilities, so that Customer Personal Data cannot be read, copied, modified, or removed without authorisation during electronic transmission or transport. Customer Personal Data is encrypted in transit over public networks when communicating with Provider user interfaces (UIs) and application programming interfaces (APIs) via industry standard HTTPS/TLS (TLS 1.2 or higher). Exceptions to encryption in transit may include any non-Provider Service that does not support encryption, which the data controller may link to through the Enterprise Services at its election.

    • Provider takes reasonable measures to provide the ability to check and establish whether and by whom Customer Personal Data has been entered into data processing systems, modified, or removed, and that any transfer of Customer Personal Data to a third-party service provider is made via a secure transmission.

  • Protecting Customer Personal Data during storage (at rest):

    • Customer Personal Data is encrypted at rest by Provider's Subprocessor and managed services provider, Amazon Web Services Inc., via AES-256.

    • Regular and secure backups of Customer Personal Data will be performed to ensure data availability and integrity in case of data loss or corruption. Backup data will also be encrypted and stored separately from the primary data storage.

  • Physical security where Customer Personal Data is processed:

    • Provider hosts Customer Personal Data primarily in AWS data centers that have been certified as ISO 27001, PCI DSS Service Provider Level 1, and/or SOC 2 compliant. AWS infrastructure services include backup power, HVAC systems, and fire suppression equipment to help protect servers and ultimately your data. AWS on-site security includes a number of features such as security guards, fencing, secured feeds, intrusion detection technology, and other security measures.

  • Events logging

    • Each year, Provider employs third-party security experts to perform a broad penetration test across the Provider Protection and Corporate Networks. Provider utilises a Security Incident Event Management (SIEM) system, which gathers logs from important network devices and host systems. The SIEM alerts on triggers that notify the Security team based on correlated events for investigation and response. Service ingress and egress points are instrumented and monitored to detect anomalous behavior, including 24/7 system monitoring.

  • Systems configuration, including default configuration:

    • Provider will establish and uphold stringent security configurations for all systems and services handling Personal Data, including baseline configurations based on industry standards, with regular updates to counter emerging threats. Hardening measures like disabling unnecessary features, restricting admin access, and applying least privilege will be enforced. A robust patch management process will ensure timely updates, while systems will be configured with secure defaults and undergo vulnerability scans. A formal change management process will govern system modifications, and configurations will be monitored for anomalies.

  • Internal IT and IT security governance and management:

    • Provider's security program includes documented policies and standards of administrative, technical, physical, and organisational safeguards, which govern the handling of Customer Personal Data in compliance with applicable law. The security program is designed to protect the confidentiality and integrity of Customer Personal Data, appropriate to the nature, scope, context, and purposes of processing and the risks involved in the processing for the data subjects.

  • Certification or assurance of processes and products:

    • Provider holds the following security-related certifications from independent third-party auditors: SOC 2 Type II.

  • Ensuring data minimization:

    • Provider will adhere to the principle of data minimization by collecting and processing only the Personal Data that is strictly necessary for the specified purposes outlined in this DPA. This involves a thorough assessment of the data requirements for each processing activity and a commitment to avoiding the collection of excessive or irrelevant data.

  • Ensuring data quality:

    • Provider will take proactive steps to ensure the quality of Personal Data throughout the processing lifecycle. This involves implementing measures such as data validation checks at the point of collection to prevent errors and inconsistencies, regular data cleansing activities to identify and rectify inaccuracies or outdated information, and establishing clear procedures for data subjects to access and rectify their personal data. Provider will also maintain a transparent process for addressing data quality complaints from data subjects and promptly investigate and resolve any identified issues.

  • Ensuring limited data retention:

    • A data retention policy will define how long different types of data will be stored, and data that is no longer needed will be securely deleted or anonymized. The effectiveness of these data protection measures will be regularly audited and reviewed to ensure they remain adequate and up to date.

  • Ensuring accountability:

    • Provider will appoint a Data Protection Officer (DPO) knowledgeable in data protection law and practices, if required by law. The DPO will have the necessary resources and authority to advise on data protection obligations, monitor compliance, cooperate with the supervisory authority, and serve as a contact point for the Controller and Data Subjects. Additionally, a comprehensive data protection training and awareness program will be implemented for all relevant personnel, ensuring they understand their responsibilities under the DPA and applicable laws.

  • Allowing data portability and erasure:

    • Processor shall, at the documented instruction of the Controller, provide reasonable assistance to the Controller to enable Data Subjects to exercise their right to data portability under Article 20 of the GDPR. This assistance shall include:

      • Providing the Data Subject's personal data to the Controller in a structured, commonly used, and machine-readable format.

      • Where technically feasible, transmitting the personal data directly from the Processor to another controller designated by the Data Subject.

      • Ensuring that the data provided is accurate, complete, and up to date as of the time of the request.

      • Complying with the Controller's reasonable requests for information and support in facilitating the data portability process.

    • The Processor shall, at the documented instruction of the Controller, promptly comply with Data Subjects' valid requests for erasure of their personal data under Article 17 of the GDPR, unless an exception under applicable law applies. This shall include:

      • Deleting or anonymizing the personal data from all storage systems and backups under the Processor's control.

      • Taking reasonable steps to ensure that any links to, or copies of, the personal data are also deleted or anonymized, to the extent technically feasible.

      • Providing the Controller with written confirmation of the erasure or anonymization within a reasonable timeframe.

      • Maintaining records of erasure requests and actions taken for a period consistent with applicable law and the Controller's record-keeping policies.

    • Notwithstanding the above, the Processor may be entitled to refuse a request for erasure or restrict processing of personal data in accordance with applicable law, including but not limited to situations where the personal data is necessary for:

      • Exercising the right of freedom of expression and information

      • Compliance with a legal obligation

      • Reasons of public interest in the area of public health

      • Archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes

      • Establishment, exercise, or defense of legal claims


Data Processing Agreement Standard Terms

1. Processor and Subprocessor Relationships

1.1 Provider as Processor. In situations where Customer is a Controller of the Customer Personal Data, Provider will be deemed a Processor that is Processing Personal Data on behalf of Customer.

1.2 Provider as Subprocessor. In situations where Customer is a Processor of the Customer Personal Data, Provider will be deemed a Subprocessor of the Customer Personal Data.

2. Processing

2.1 Processing Details. Annex I(B) on the Cover Page describes the subject matter, nature, purpose, and duration of this Processing, as well as the Categories of Personal Data collected and Categories of Data Subjects.

2.2 Processing Instructions. Customer instructs Provider to Process Customer Personal Data:

  • (a) to provide and maintain the Service;

  • (b) as may be further specified through Customer's use of the Service;

  • (c) as documented in the Agreement; and

  • (d) as documented in any other written instructions given by Customer and acknowledged by Provider about Processing Customer Personal Data under this DPA.

Provider will abide by these instructions unless prohibited from doing so by Applicable Laws. Provider will immediately inform Customer if it is unable to follow the Processing instructions. Customer has given and will only give instructions that comply with Applicable Laws.

2.3 Processing by Provider. Provider will only Process Customer Personal Data in accordance with this DPA, including the details in the Cover Page. If Provider updates the Service to update existing or include new products, features, or functionality, Provider may change the Categories of Data Subjects, Categories of Personal Data, Special Category Data, Special Category Data Restrictions or Safeguards, Frequency of Transfer, Nature and Purpose of Processing, and Duration of Processing as needed to reflect the updates by notifying Customer of the updates and changes.

2.4 Customer Processing. Where Customer is a Processor and Provider is a Subprocessor, Customer will comply with all Applicable Laws that apply to Customer's Processing of Customer Personal Data. Customer's agreement with its Controller will similarly require Customer to comply with all Applicable Laws that apply to Customer as a Processor. In addition, Customer will comply with the Subprocessor requirements in Customer's agreement with its Controller.

2.5 Consent to Processing. Customer has complied with and will continue to comply with all Applicable Data Protection Laws concerning its provision of Customer Personal Data to Provider and/or the Service, including making all disclosures, obtaining all consents, providing adequate choice, and implementing relevant safeguards required under Applicable Data Protection Laws.

2.6 Subprocessors.

(a) Provider will not provide, transfer, or hand over any Customer Personal Data to a Subprocessor unless Customer has approved the Subprocessor. The current list of Approved Subprocessors includes the identities of the Subprocessors, their country of location, and their anticipated Processing tasks. Provider will inform Customer at least 10 business days in advance and in writing of any intended changes to the Approved Subprocessors, whether by addition or replacement of a Subprocessor, which allows Customer enough time to object to the changes before Provider begins using the new Subprocessor(s). Provider will give Customer the information necessary to allow Customer to exercise its right to object to the change. Customer has 30 days after notice of a change to object, otherwise Customer will be deemed to accept the changes. If Customer objects within 30 days of notice, Customer and Provider will cooperate in good faith to resolve Customer's objection or concern.

(b) When engaging a Subprocessor, Provider will have a written agreement with the Subprocessor that ensures the Subprocessor only accesses and uses Customer Personal Data (i) to the extent required to perform the obligations subcontracted to it, and (ii) consistent with the terms of the Agreement.

(c) If the GDPR applies to the Processing of Customer Personal Data, (i) the data protection obligations described in this DPA (as referred to in Article 28(3) of the GDPR, if applicable) are also imposed on the Subprocessor, and (ii) Provider's agreement with the Subprocessor will incorporate these obligations, including details about how Provider and its Subprocessor will coordinate to respond to inquiries or requests about the Processing of Customer Personal Data. In addition, Provider will share, at Customer's request, a copy of its agreements (including any amendments) with its Subprocessors. To the extent necessary to protect business secrets or other confidential information, including personal data, Provider may redact the text of its agreement with its Subprocessor prior to sharing a copy.

(d) Provider remains fully liable for all obligations subcontracted to its Subprocessors, including the acts and omissions of its Subprocessors in Processing Customer Personal Data. Provider will notify Customer of any failure by its Subprocessors to fulfill a material obligation about Customer Personal Data under the agreement between Provider and the Subprocessor.

3. Restricted Transfers

3.1 Authorization. Customer agrees that Provider may transfer Customer Personal Data outside the EEA, the United Kingdom, or other relevant geographic territory as necessary to provide the Service. If Provider transfers Customer Personal Data to a territory for which the European Commission or other relevant supervisory authority has not issued an adequacy decision, Provider will implement appropriate safeguards for the transfer consistent with Applicable Data Protection Laws.

3.2 Ex-EEA Transfers. Customer and Provider agree that if the GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the EEA to Provider outside of the EEA, and the transfer is not governed by an adequacy decision made by the European Commission, then by entering into this DPA, Customer and Provider are deemed to have signed the EEA SCCs and their Annexes, which are incorporated by reference. Any such transfer is made pursuant to the EEA SCCs, which are completed as follows:

  • Module Two (Controller to Processor) of the EEA SCCs applies when Customer is a Controller and Provider is Processing Customer Personal Data for Customer as a Processor.

  • Module Three (Processor to Sub-Processor) of the EEA SCCs applies when Customer is a Processor and Provider is Processing Customer Personal Data on behalf of Customer as a Subprocessor.

For each module, the following applies (when applicable):

  • (i) The optional docking clause in Clause 7 does not apply.

  • (ii) In Clause 9, Option 2 (general written authorization) applies, and the minimum time period for prior notice of Subprocessor changes is 10 business days.

  • (iii) In Clause 11, the optional language does not apply.

  • (iv) All square brackets in Clause 13 are removed.

  • (v) In Clause 17 (Option 1), the EEA SCCs will be governed by the laws of the Governing Member State.

  • (vi) In Clause 18(b), disputes will be resolved in the courts of the Governing Member State.

  • (vii) The Cover Page to this DPA contains the information required in Annex I, Annex II, and Annex III of the EEA SCCs.

3.3 Ex-UK Transfers. Customer and Provider agree that if the UK GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the United Kingdom to Provider outside of the United Kingdom, and the transfer is not governed by an adequacy decision made by the United Kingdom Secretary of State, then by entering into this DPA, Customer and Provider are deemed to have signed the UK Addendum and its Annexes, which are incorporated by reference. Any such transfer is made pursuant to the UK Addendum, which is completed as follows:

  • Section 3.2 of this DPA contains the information required in Table 2 of the UK Addendum.

  • Table 4 of the UK Addendum is modified as follows: neither party may end the UK Addendum as set out in Section 19 of the UK Addendum; to the extent the ICO issues a revised Approved Addendum under Section 18 of the UK Addendum, the parties will work in good faith to revise this DPA accordingly.

  • The Cover Page contains the information required by Annex 1A, Annex 1B, Annex II, and Annex III of the UK Addendum.

3.4 Other International Transfers. For Personal Data transfers where Swiss law (and not the law in any EEA member state or the United Kingdom) applies to the international nature of the transfer, references to the GDPR in Clause 4 of the EEA SCCs are, to the extent legally required, amended to refer to the Swiss Federal Data Protection Act or its successor instead, and the concept of supervisory authority will include the Swiss Federal Data Protection and Information Commissioner.

4. Security Incident Response

Upon becoming aware of any Security Incident, Provider will:

  • (a) notify Customer without undue delay when feasible, but no later than 72 hours after becoming aware of the Security Incident;

  • (b) provide timely information about the Security Incident as it becomes known or as is reasonably requested by Customer; and

  • (c) promptly take reasonable steps to contain and investigate the Security Incident.

Provider's notification of or response to a Security Incident as required by this DPA will not be construed as an acknowledgment by Provider of any fault or liability for the Security Incident.

5. Audit and Reports

5.1 Audit Rights. Provider will give Customer all information reasonably necessary to demonstrate its compliance with this DPA and will allow for and contribute to audits, including inspections by Customer, to assess Provider's compliance with this DPA. However, Provider may restrict access to data or information if Customer's access would negatively impact Provider's intellectual property rights, confidentiality obligations, or other obligations under Applicable Laws. Customer acknowledges and agrees that it will only exercise its audit rights under this DPA and any audit rights granted by Applicable Data Protection Laws by instructing Provider to comply with the reporting and due diligence requirements below. Provider will maintain records of its compliance with this DPA for 3 years after the DPA ends.

5.2 Security Reports. Customer acknowledges that Provider is regularly audited against the standards defined in the Security Policy by independent third-party auditors. Upon written request, Provider will give Customer, on a confidential basis, a summary copy of its then-current Report so that Customer can verify Provider's compliance with the standards defined in the Security Policy.

5.3 Security Due Diligence. In addition to the Report, Provider will respond to reasonable requests for information made by Customer to confirm Provider's compliance with this DPA, including responses to information security, due diligence, and audit questionnaires, or by giving additional information about its information security program. All such requests must be in writing, made to the Provider Security Contact, and may only be made once a year.

6. Coordination and Cooperation

6.1 Response to Inquiries. If Provider receives any inquiry or request from anyone else about the Processing of Customer Personal Data, Provider will notify Customer about the request and will not respond to the request without Customer's prior consent. Examples include a judicial, administrative, or regulatory agency order about Customer Personal Data where notifying Customer is not prohibited by Applicable Law, or a request from a data subject. If allowed by Applicable Law, Provider will follow Customer's reasonable instructions about these requests, including providing status updates and other information reasonably requested by Customer. If a data subject makes a valid request under Applicable Data Protection Laws to delete or opt out of Customer's giving of Customer Personal Data to Provider, Provider will assist Customer in fulfilling the request according to the Applicable Data Protection Law. Provider will cooperate with and provide reasonable assistance to Customer, at Customer's expense, in any legal response or other procedural action taken by Customer in response to a third-party request about Provider's Processing of Customer Personal Data under this DPA.

6.2 DPIAs and DTIAs. If required by Applicable Data Protection Laws, Provider will reasonably assist Customer in conducting any mandated data protection impact assessments or data transfer impact assessments and consultations with relevant data protection authorities, taking into consideration the nature of the Processing and Customer Personal Data.

7. Deletion of Customer Personal Data

7.1 Deletion by Customer. Provider will enable Customer to delete Customer Personal Data in a manner consistent with the functionality of the Services. Provider will comply with this instruction as soon as reasonably practicable, except where further storage of Customer Personal Data is required by Applicable Law.

7.2 Deletion at DPA Expiration.

(a) After the DPA expires, Provider will return or delete Customer Personal Data at Customer's instruction unless further storage is required or authorized by Applicable Law. If return or destruction is impracticable or prohibited by Applicable Laws, Provider will make reasonable efforts to prevent additional Processing of Customer Personal Data and will continue to protect the Customer Personal Data remaining in its possession, custody, or control. For example, Applicable Laws may require Provider to continue hosting or Processing Customer Personal Data.

(b) If Customer and Provider have entered the EEA SCCs or the UK Addendum as part of this DPA, Provider will only give Customer the certification of deletion of Personal Data described in Clause 8.1(d) and Clause 8.5 of the EEA SCCs if Customer asks for one.

8. Limitation of Liability

8.1 Liability Caps and Damages Waiver. To the maximum extent permitted under Applicable Data Protection Laws, each party's total cumulative liability to the other party arising out of or related to this DPA will be subject to the waivers, exclusions, and limitations of liability stated in the Agreement.

8.2 Related-Party Claims. Any claims made against Provider or its Affiliates arising out of or related to this DPA may only be brought by the Customer entity that is a party to the Agreement.

8.3 Exceptions. This DPA does not limit any liability to an individual about the individual's data protection rights under Applicable Data Protection Laws. In addition, this DPA does not limit any liability between the parties for violations of the EEA SCCs or UK Addendum.

9. Conflicts Between Documents

This DPA forms part of and supplements the Agreement. If there is any inconsistency between this DPA, the Agreement, or any of their parts, the part listed earlier will control over the part listed later for that inconsistency:

  1. The EEA SCCs or the UK Addendum

  2. This DPA

  3. The Agreement

10. Term of Agreement

This DPA will start when Provider and Customer agree to a Cover Page for the DPA and sign or electronically accept the Agreement, and will continue until the Agreement expires or is terminated. However, Provider and Customer will each remain subject to the obligations in this DPA and Applicable Data Protection Laws until Customer stops transferring Customer Personal Data to Provider and Provider stops Processing Customer Personal Data.

11. Definitions

11.1 Applicable Laws The laws, rules, regulations, court orders, and other binding requirements of a relevant government authority that apply to or govern a party.

11.2 Applicable Data Protection Laws The Applicable Laws that govern how the Service may process or use an individual's personal information, personal data, personally identifiable information, or other similar term.

11.3 Controller Has the meaning(s) given in the Applicable Data Protection Laws for the company that determines the purpose and extent of Processing Personal Data.

11.4 Cover Page A document signed or electronically accepted by the parties that incorporates these DPA Standard Terms and identifies Provider, Customer, and the subject matter and details of the data processing.

11.5 Customer Personal Data Personal Data that Customer uploads or provides to Provider as part of the Service and that is governed by this DPA.

11.6 DPA These DPA Standard Terms, the Cover Page between Provider and Customer, and the policies and documents referenced in or attached to the Cover Page.

11.7 EEA SCCs The standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679.

11.8 European Economic Area (EEA) The member states of the European Union, Norway, Iceland, and Liechtenstein.

11.9 GDPR European Union Regulation 2016/679 as implemented by local law in the relevant EEA member nation.

11.10 Personal Data Has the meaning(s) given in the Applicable Data Protection Laws for personal information, personal data, or other similar term.

11.11 Processing / Process Has the meaning(s) given in the Applicable Data Protection Laws for any use of, or performance of a computer operation on, Personal Data, including by automatic methods.

11.12 Processor Has the meaning(s) given in the Applicable Data Protection Laws for the company that Processes Personal Data on behalf of the Controller.

11.13 Report Audit reports prepared by another company according to the standards defined in the Security Policy on behalf of Provider.

11.14 Restricted Transfer (a) where the GDPR applies, a transfer of personal data from the EEA to a country outside of the EEA which is not subject to an adequacy determination by the European Commission; and (b) where the UK GDPR applies, a transfer of personal data from the United Kingdom to any other country which is not subject to adequacy regulations adopted pursuant to Section 17A of the United Kingdom Data Protection Act 2018.

11.15 Security Incident A Personal Data Breach as defined in Article 4 of the GDPR.

11.16 Service The product and/or services described in the Agreement.

11.17 Special Category Data Has the meaning given in Article 9 of the GDPR.

11.18 Subprocessor Has the meaning(s) given in the Applicable Data Protection Laws for a company that, with the approval and acceptance of the Controller, assists the Processor in Processing Personal Data on behalf of the Controller.

11.19 UK GDPR European Union Regulation 2016/679 as implemented by section 3 of the United Kingdom's European Union (Withdrawal) Act of 2018 in the United Kingdom.

11.20 UK Addendum The international data transfer addendum to the EEA SCCs issued by the Information Commissioner for parties making Restricted Transfers under S119A(1) Data Protection Act 2018.


Questions about this DPA? Contact [email protected].

Did this answer your question?