DATA PROCESSING AGREEMENT
This DPA is entered into between the Processor and the Controller and is incorporated into and governed by the terms of the Agreement.
Any capitalised term not defined in this DPA shall have the meaning given to it in the Agreement.
“Affiliates” |
means any entity that directly or indirectly controls, is controlled by, or is under common control of a party. “Control,” for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of a party; |
“Agreement” |
means the agreement between the Processor and the Controller for the provision of the Solution and Services; |
“Controller” |
means the Customer; |
“Data Protection Law” |
means the GDPR and/or any subsequent amendment or replacement or supplementary legislation; |
“Data Subject” |
shall have the same meaning as in Data Protection Law; |
“DPA” |
means this data processing agreement together with Exhibit A and the Security Policy; |
“GDPR” |
means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016; |
“Personal Data” |
shall have the same meaning as in Data Protection Law; |
“Processor” |
means the Company; |
“Security Policy” |
means the Processor’s security document as updated from time to time, and accessible via www.incresingly.com/security or otherwise made reasonably available by the Processor; |
“Standard Contractual Clauses” |
means the EU model clauses for personal data transfer from controllers to processors c2010-593 - Decision 2010/87EU; |
“Sub-Processor” |
means any person or entity engaged by the Processor or its Affiliate to process Personal Data in the provision of the Solution and Services to the Controller. |
The parties agree that this DPA is incorporated into and governed by the terms of the Agreement.
Exhibit A
Overview of data processing activities to be performed by the Processor
The Controller transfers Personal Data identified in sections 3, 4 and 5 below, as it relates to the processing operations identified in section 6 below.
The Controller is the Customer.
The Processor received data identified in sections 3, 4 and 5 below, as it relates to the processing operations identified in section 6 below.
The Processor is the Company.
The Personal Data transferred includes but is not limited to the following categories of Data Subjects:
The Personal Data transferred includes but is not limited to the following categories of data:
No sensitive data or special categories of data are permitted to be transferred and shall not be contained in the content of or attachments to, emails.
The Personal Data transferred will be subject to the following basic processing activities: