Legal
Data processing addendum.
Our commitment to protecting your data in compliance with global privacy regulations.
Table of contents
- Definitions and Interpretation
- Personal Information Types and Processing Purposes
- Company's Obligations
- Company's Employees
- Security
- Security Breaches
- Cross-Border Transfers of Personal Information
- Sub-processors
- Data Subject Requests, Complaints, and Third-Party Rights
- Term and Termination
- Data Return and Destruction
- Audit
- Miscellaneous
- Appendix A — Personal Information Processing Purposes and Details
- Appendix B — Standard Contractual Clauses: Annexes
- Appendix C — Security Measures
Parties
This Data Processing Addendum (the “DPA”) forms part of the Agreement between the Parties and is effective as of the date of the Master Software as a Service Agreement or other Agreement (“Agreement”) (the “DPA Effective Date”) between Synergistic Designs LLC (“Company”) and Customer (together the “Parties;” each a “Party”).
Recitals
WHEREAS, the Customer and Company entered into the Agreement that may require the Company to process Personal Information provided by or collected for the Customer; and
WHEREAS, this DPA sets out the additional terms, requirements, and conditions on which the Company will obtain, handle, process, disclose, transfer, or store Personal Information when providing services under the Agreement;
NOW, THEREFORE, in consideration of the mutual covenants and agreements hereinafter set forth and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the parties hereto agree as follows:
1. Definitions and Interpretation
- The following definitions and rules of interpretation apply in this DPA.
“Business Purpose” means the services described in the Agreement or any other purpose specifically identified in Appendix A.
“Data Subject” means an individual who is the subject of the Personal Information and to whom or about whom the Personal Information relates or identifies, directly or indirectly.
“Personal Information (“personal data”)” means any information the Company processes for the Customer that (a) identifies or relates to an individual who can be identified directly or indirectly from that data alone or in combination with other information in the Company’s possession or control or that the Company is likely to have access to, or (b) the relevant Privacy and Data Protection Requirements otherwise define as protected personal information.
“Processing, processes, or process” means any activity that involves the use of Personal Information or that the relevant Privacy and Data Protection Requirements may otherwise include in the definition of processing, processes, or process. It includes obtaining, recording, or holding the data, or carrying out any operation or set of operations on the data including, but not limited to, organizing, amending, retrieving, using, disclosing, erasing, or destroying it. Processing also includes transferring Personal Information to third parties.
“Privacy and Data Protection Requirements” means all applicable U.S. federal and state, and foreign laws and regulations relating to the processing, protection, or privacy of the Personal Information.
“Security Breach” means the loss of or unauthorized access, disclosure, or acquisition of Personal Information.
“Standard Contractual Clauses (SCC)” means the European Commission’s standard contractual clauses for the transfer of personal data from the European Union to third countries, as set out in the Annex to Commission Decision (EU) 2021/914.
- This DPA is subject to the terms of the Agreement and is incorporated into the Agreement. Interpretations and defined terms set forth in the Agreement apply to the interpretation of this DPA. This DPA will apply only to the extent that the Company is engaged in the processing of Personal Information subject to Privacy and Data Protection Requirements on behalf of Customer to provide the services under the Agreement.
- The Appendices form part of this DPA and will have effect as if set out in full in the body of this DPA. Any reference to this DPA includes the Appendices.
- A reference to writing or written includes email.
- In the case of conflict or ambiguity between:
- any provision contained in the body of this DPA and any provision contained in the Appendices, the provision in the body of this DPA will prevail;
- the terms of any accompanying invoice or other documents annexed to this DPA and any provision contained in the Appendices, the provision contained in the Appendices will prevail;
- any of the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA will prevail; and
- any of the provisions of this agreement and any executed Standard Contractual Clauses, the provisions of the executed Standard Contractual Clauses will prevail.
2. Personal Information Types and Processing Purposes
- The Customer retains control of the Personal Information and remains responsible for its compliance obligations under the applicable Privacy and Data Protection Requirements, including providing any required notices and obtaining any required consents, for the processing instructions it gives to the Company, legal bases for processing (as required by law) and for the accuracy, quality, and legality of the Personal Information processed by Company under the Agreement. This DPA and the Agreement, including any Insertion Order (“IO”), constitute Customer’s instructions. Any additional or changes to Customer’s instructions require a separate signed agreement between Company and Customer and may be subject to additional fees as relevant. The Customer warrants and represents that the Company’s expected use of the Personal Information for the Business Purpose and as specifically instructed by the Customer will comply with all Privacy and Data Protection Requirements.
- Appendix A describes the general Personal Information categories and related types of Data Subjects the Company may process to fulfill the Business Purposes of the Agreement.
- Special or Sensitive Data: Unless set forth in a statement of work, order, or other document that forms part of the Agreement, Personal Information may not include any sensitive personal information or special categories of data that impose specific data security or data protection obligations on Company in addition to or different from those specified in any documentation or which are not provided as part of the Services. Company does not require and does not request from Customer any sensitive personal information or special categories of data to provide the Services. Customer understands and agrees that Company does not differentiate between different types of data sensitivity when processing Personal Information under the Agreement or treat certain types of Personal Data differently from other types and applies the same security measures to all Personal Information as set forth in this DPA.
3. Company’s Obligations
- The Company will only process, retain, use, or disclose the Personal Information to the extent, and in such a manner, as is necessary for the Business Purposes in accordance with and as permitted by the Customer’s instructions. The Company will not process, retain, use, or disclose the Personal Information for any other purpose, outside of the parties’ business relationship, or in a way that does not comply with this DPA or the Privacy and Data Protection Requirements. The Company will notify the Customer if, in Company’s opinion, the Customer’s instruction would not comply with the Privacy and Data Protection Requirements.
- The Company will comply with any Customer request or instruction (at Customer’s expense) requiring the Company to amend, transfer, or delete the Personal Information. Company will also comply with any Customer request or instruction to stop, mitigate, or remedy any unauthorized processing.
- The Company will maintain the confidentiality of all Personal Information and will not sell it to anyone, share it for cross-context behavioral advertising (targeted advertising) with anyone, or disclose it to third parties without specific authorization from the Customer, this DPA, or as necessary to provide the services under the Agreement, unless required by law. If a law requires the Company to process or disclose Personal Information, the Company will first inform the Customer of the legal requirement and give the Customer an opportunity to object to or challenge the requirement, unless the law prohibits such notice.
- The Company will reasonably assist the Customer (at Customer’s expense) with meeting the Customer’s compliance obligations under the Privacy and Data Protection Requirements, taking into account the nature of the Company’s processing, the information available to the Company, and Customer’s ability to use its access to the services for such purposes. This includes cooperation in connection with any data protection impact assessment that Customer may be required to perform under applicable Privacy and Data Protection Requirements.
- The Company will notify the Customer of any changes to Privacy and Data Protection Requirements, or its ability to meet those obligations, that may adversely affect the Company’s performance of the Agreement or this DPA.
- Customer acknowledges that the Company has no duty to investigate the completeness, accuracy, or sufficiency of any specific Customer instructions or Personal Information other than as required under the Privacy and Data Protection Requirements.
4. Company’s Employees
- The Company will limit Personal Information access to:
- those employees who require Personal Information access to meet the Company’s obligations under this DPA and the Agreement; and
- the part or parts of the Personal Information that those employees strictly require for the performance of their duties.
- Prior to engaging any employee who may receive access to Customer Personal Information, Company will conduct a background check subject to local laws.
- The Company will ensure that all employees are informed of the Personal Information’s confidential nature and use restrictions and are obliged to keep the Personal Information confidential.
5. Security
- The Company will implement appropriate technical and organizational measures designed to (a) safeguard Personal Information cached in the services or (b) in transit between Customer’s databases and the services against unauthorized or unlawful processing, access, copying, modification, storage, reproduction, display, or distribution, and against accidental loss, destruction, unavailability, or damage. Company may modify its technical and organization measures from time to time and will not materially decrease the overall security of the services during the term of the Agreement or this DPA.
- Customer is responsible for security relating to its environment and databases and security relating to its configuration of the services (including the software). This includes implementing and managing procedural, technical, and administrative safeguards on its software and networks sufficient to: (a) ensure the confidentiality, security, integrity, and privacy of Customer data in transit, at rest, and in storage; (b) protect against any anticipated threats or hazards to the security and integrity of Customer data; and (c) protect against any unauthorized processing, loss, use, disclosure or acquisition of or access to Customer data. Notwithstanding any other provision of this DPA, the Agreement, or any other agreement related to the service, Company will have no obligations or liability as to any breach or loss resulting from: (x) Customer’s environment, databases, systems, or software, or (y) Customer’s security configuration or administration of the services and software.
- Customer is solely responsible for designating and permitting access to Authorized Users on the services, including: (a) methods of authenticating Authorized Users (such as industry-standard secure username/password policies, two-factor authentication or SAML-supported SSO iDP); (b) restricting access by Authorized User or group, and from the database level down to the row or column level; (c) managing administrator privileges; (d) deauthorizing personnel who no longer need access to the Services; (e) securely configuring any APIs; and (f) regularly auditing any public access links Authorized Users create and restricting the permission to create public links, as necessary.
- To use the Services, Customer must authorize the services to access Customer’s databases. When granting authorization, Customer must follow the principle of least privilege to Customer database information, including by granting Company no more than read-only access to database data. Company will not be responsible for any Security Breach, security incident, or other loss to the extent Customer provides the services with write or administrator access to Customer’s databases or other Personal Information.
6. Security Breaches
- The Company will notify Customer via email if it becomes aware of any Security Breach impacting Customer Personal Information. Company will take any reasonably necessary measures and actions to address or mitigate the effects of the Security Breach and will keep Customer informed of all material developments in connection with the Security Breach. Company’s contact point for additional information is privacy@synergistic.io.
- Customer is solely responsible for complying with data incident notification requirements applicable to Customer and fulfilling any third-party notification obligations related to any Security Breach affecting Customer Personal Information.
- Company will provide reasonable information and cooperation to Customer so that Customer can fulfill any legally required reporting obligations it may have under (and in accordance with the timescales required by) applicable Privacy and Data Protection Requirements.
- Company’s prior written approval shall be required for any statements containing specific information regarding Company’s systems, security practices, or the nature of the Security Breach or references to Company by name.
7. Cross-Border Transfers of Personal Information
- If the Privacy and Data Protection Requirements restrict cross-border Personal Information transfers, the Customer will only transfer that Personal Information to the Company under the following conditions:
- the Customer obtained valid Data Subject consent to the transfer under the Privacy and Data Protection Requirements; or
- the transfer otherwise complies with the Privacy and Data Protection Requirements for the reasons set forth in Appendix A.
- If any Personal Information transfer between the Company and the Customer requires execution of Standard Contractual Clauses to comply with the Privacy and Data Protection Requirements, the Parties will complete all relevant details in, and execute, the Standard Contractual Clauses contained in Appendix B, and take all other actions required to legitimize the transfer, including implementing any needed supplementary measures or supervisory authority consultations.
- Customer shall be deemed to have signed the Standard Contractual Clauses in its capacity of “data exporter” and Company in its capacity as “data importer.” Module Two or Module Three of the Standard Contractual Clauses shall apply to the transfer depending on whether Customer is Controller of the Personal Information (for Module Two) or a Processor of the Personal Information on behalf of its customer (for Module Three). If Module Three applies, Customer hereby notifies Company that Customer is a Processor and the instructions for Processing shall be as set forth in this DPA. For purposes of Clauses 17 and 18 of the Standard Contractual Clauses, the Parties select Ireland. Additional provisions applicable to Personal Information transferred pursuant to Standard Contractual Clauses are set forth in Appendix B.
8. Sub-processors
- Customer authorizes Company to use Company affiliates and/or the third parties (“sub-processors”) listed in Appendix A, as may be updated from time to time, to process the Personal Information under the Agreement.
- Company will enter into a written agreement with the sub-processor that contains terms substantially the same as those set out in this DPA to the extent applicable to the nature of the services provided by such sub-processor.
- Customer may object to Company’s appointment of a new or replacement sub-processor prior to its appointment or replacement, provided such objection is based on reasonable and objective data protection grounds. Customer has fifteen (15) days after Company notifies Customer of such new sub-processor to notify Company in writing of its objection supported by documentary evidence. Upon receipt of Customer’s written objection, Customer and Company will work together without unreasonable delay to find a mutually acceptable resolution to address the objection, including but not limited to reviewing additional documentation supporting the sub-processor’s ability to comply with Data Protection Law. If Customer and Company do not reach a mutually acceptable resolution within a reasonable timeframe, Company will use reasonable efforts to make available to Customer a change in the services or will recommend a commercially reasonable change to the services to prevent the applicable sub-processor from processing Customer’s Personal Information. If Company is unable to make available such a change within a reasonable time, Customer may, as its sole remedy, suspend or terminate the portion of the Agreement that requires use of such sub-processor to provide the services under the Agreement in accordance with the termination provisions in the Agreement without liability to Company. Customer will not receive a refund of any unused prepaid fees on such termination and, if fees remain unpaid for a subscription term, Customer will immediately pay the remaining balance due for the remainder of the subscription term.
- If a sub-processor fails to fulfill its data protection obligations with respect to Customer Personal Information such that Company would have been found to have violated its obligations to Customer under this DPA, the Company will be responsible to Customer for the sub-processor’s performance of its agreement obligations.
9. Data Subject Requests, Complaints, and Third-Party Rights
- The Company will notify Customer if it receives a request from a Data Subject to exercise any rights the individual may have regarding their Personal Information. Company will comply with Customer’s instructions regarding the handling of a Data Subject inquiry.
- The Company will notify the Customer if it receives any other complaint, notice, or communication that directly or indirectly relates to the Personal Information processing or to either party’s compliance with the Privacy and Data Protection Requirements.
- The Company will provide the Customer with reasonable and timely assistance (at Customer’s expense) to enable the Customer to respond to any complaint, notice, communication, or Data Subject request.
- The Company will not disclose the Personal Information to any Data Subject or to a third party unless the disclosure is either at the Customer’s request or instruction, permitted by this DPA, or is otherwise required by law.
10. Term and Termination
- This DPA will remain in full force and effect so long as:
- the Agreement remains in effect; or
- the Company retains any Personal Information related to the Agreement in its possession or control (the “Term”).
- Any provision of this DPA that expressly or by implication should come into or continue in force on or after termination of the Agreement to protect Personal Information will remain in full force and effect.
- If a change in any Privacy and Data Protection Requirement or either Party’s circumstances prevents a Party from fulfilling all or part of its Agreement obligations, the Parties will suspend the processing of Personal Information until the Party’s processing complies with the requirements. If the Parties are unable to bring the Personal Information processing into compliance with the Privacy and Data Protection Requirements within a commercially reasonable time, they may terminate the Agreement, as provided in the Agreement, upon written notice to the other Party.
11. Data Return and Destruction
- At the Customer’s request, within 30 days of receipt of such request, the Company will give the Customer a copy of or access to all or part of the Customer’s Personal Information in its possession or control in the format and on the media reasonably specified by the Customer, to the extent Customer does not have access to such information.
- On termination of the Agreement for any reason or expiration of its Term, the Company will make reasonable efforts to securely destroy or, if directed in writing by the Customer, return and not retain, all or any Personal Information related to the Agreement in its possession or control to the extent retention by Company is otherwise required by law or needed to support Company’s business operations. Data retained for these purposes will only be used by Company for such purposes. Any Personal Information in Company backup or archive systems will be retained until such records are overwritten or expunged in accordance with Company’s data retention practices.
12. Audit
- If a Privacy and Data Protection Requirement permits Customer to audit Company’s compliance with such law, Company will, on Customer’s written request and subject to the confidentiality obligations set forth in the Agreement or an appropriate Non-Disclosure Agreement (“NDA”), make available to Customer a summary of its most recent SOC 2 audit report, as available, not more than once per year.
- If Customer requires additional information, Company will respond to a reasonable and written Customer security questionnaire no more than once per year and meet by teleconference to address any additional questions.
- If Customer requires additional information and reasonably believes Company is not in compliance with this DPA, or if required by a supervisory authority, Customer may contact Company in accordance with the “Notices” Section of the Agreement to request an on-site audit, not more than once per year (unless otherwise legally required, including by a supervisory authority), of its procedures relevant to the protection of Personal Information.
- At least two weeks before the commencement of any such on-site audit, Customer must provide to Company a draft written audit plan, after which Customer and Company will discuss in good faith and finalize the audit plan and the parties shall mutually agree upon the scope, timing, and duration of the audit and the reimbursement rate for any travel or other expenses Company incurs in the course of such audit.
- Audits may be conducted only during regular business hours, in accordance with the finalized audit plan and Company’s security and other policies, and may not unreasonably interfere with Company’s regular business activities.
- Customer shall promptly notify Company regarding any alleged non-compliance discovered during the course of an audit and share relevant information regarding the same.
- Any third party engaged by Customer to conduct an audit must be pre-approved by Company (such approval not to be unreasonably withheld) and sign Company’s confidentiality agreement.
- Information obtained or results produced in connection with an audit are Company Confidential Information under the Agreement and may only be used by Customer to confirm compliance with this DPA and Privacy and Data Protection Requirements.
13. Miscellaneous
- Amendment; Enforcement of Rights: No modification of or amendment to this DPA, nor any waiver of any rights under this DPA, will be effective unless in writing and signed by the Parties to this DPA. The failure by either Party to enforce any rights under this DPA will not be construed as a waiver of any rights of such party.
- Changes in Law: If Privacy and Data Protection Requirements change subsequent to the signing of this DPA or the Agreement, the Parties shall negotiate in good faith to reach agreement on reasonable next steps, including, where applicable, changes that may be necessary and operationally, technically, and commercially feasible to the Agreement, the DPA and/or the services (including, without limitation, the fees payable by Customer to Company for the services) to enable Company to continue providing the services in compliance with such revised Privacy and Data Protection Requirements.
- Business Transactions: Company may share and disclose Personal Information and other Customer Data (referred to as Client Data under the Agreement) in connection with, or during the negotiation of, any merger, sale of company assets, consolidation or restructuring, financing, or acquisition of all or a portion of Company’s business by or to another company, including the transfer of contact information and data of customers, partners, and end users, including for diligence purposes related to the same.
- Bundling of Customer Entities: The Parties agree that the bundling of Customer’s data exporters, for example, if Customer is comprised of multiple global affiliates, as Controllers within this DPA is undertaken for efficiency purposes (i.e., to avoid a multitude of different contract documents) and (i) shall result in legally separate DPAs between the respective Customer entity and Company solely for purposes of addressing any such obligations under Privacy and Data Protection Requirements; (ii) shall not create any new or different legal or other relationship whatsoever between the “bundled” Customer entities; (iii) does not create any additional rights or remedies for such bundled Customer entities; (iv) all processing instructions must be provided by the Customer entity that is signatory to the Agreement and Company is not responsible for consolidating or evaluating the validity of instructions received from other Customer entities; (v) any commercial terms not provided by the DPA are provided by the Agreement regardless of whether the bundled Customer entities signed or were consulted regarding the terms of the Agreement; and (vi) any audits conducted in accordance with the DPA shall be conducted only by and through the Customer entity that is signatory to the Agreement.
Appendix A — Personal Information Processing Purposes and Details
Business Purposes/Nature of Processing: Company shall process Personal Information as necessary to perform the services described in the Agreement, including as applicable:
Web Development Services. Website and application development, hosting support, maintenance, analytics implementation, and related technical services.
Creative Services. Content creation, asset management, design, production, and related creative activities.
Media Planning and Buying Services. Audience targeting, campaign execution, optimization, reporting, and use of advertising platforms and analytics tools.
Personal Information Categories:
- Name
- Email address
- Cookie Information
- Device Identifiers
- IP address and other online identifiers
- Account log-in details and passwords
- Telephone/mobile number
- Location Data
Data Subject Types: Customer Authorized Users
Processing Duration: For the duration of performance of the services under the Agreement and as provided in this DPA.
Approved Sub-processors:
| Sub-processor | Service |
|---|---|
| Vercel | Website hosting and content delivery |
| Analytics and tag management (Google Analytics, Tag Manager) | |
| Sanity | Content management system |
| Adobe | Web font delivery (Adobe Fonts) |
Appendix B — Standard Contractual Clauses: Annexes
Annex 1 — A. List of Parties
| Data exporter | |
|---|---|
| Name: | The data exporter is the entity identified as “Customer” in the Agreement |
| Address: | As set forth in the Agreement |
| Contact person’s name, position, and contact details: | As set forth in the Agreement |
| Activities relevant to the data transferred under these Clauses: | The services provided as set forth in the Agreement and this DPA |
| Signature and date: | As provided in Section 7.3 |
| Role: | Controller, except when processing data on behalf of another entity, in which case data exporter is a processor |
| Data importer | |
|---|---|
| Name: | The data importer is Synergistic Designs LLC, identified as “Company” in the DPA |
| Address: | As set forth in the Agreement |
| Contact person’s name, position, and contact details: | Synergistic Legal General Counsel/Legal 10325 S. Medallion Dr., Cincinnati, OH 45241 |
| Signature and date: | As provided in Section 7.3 |
| Role: | Processor (or sub-processor if data exporter is a processor) |
| B. Description of Transfer | |
|---|---|
| Categories of data subjects whose personal information is transferred: | Authorized Users of Customer’s instance of the services |
| Categories of personal information transferred: |
|
| Sensitive data transferred (if applicable): | N/A |
| Frequency of the transfer: | Continuous basis throughout the Term of the Agreement |
| Nature of processing: | As set out in Appendix A |
| Purpose(s) of the data transfer and further processing: | As set out in Appendix A |
| Retention: | As set out in this DPA |
C. Competent Supervisory Authority
If Customer is established in an EU Member state, the competent supervisory authority shall be the supervisory authority applicable to the establishment location of Customer. If Customer is not established in an EU Member state, the competent supervisory authority shall be the supervisory authority located where Customer has appointed its EU Representative. If Customer is not established in an EU Member state and is not required to appoint an EU Representative, the competent supervisory authority shall be the supervisory authority applicable to the location of the Data Subject whose data is at issue.
Annex II — Technical and Organizational Measures
Technical and organizational measures, including technical and organizational measures to ensure security of Personal Information: as provided in Appendix C.
Annex III — Sub-processors
As provided in Appendix A.
Appendix C — Security Measures
- System Access Controls: The Parties will take reasonable measures to prevent Personal Information from being used without authorization. These controls will vary based on the nature of the processing undertaken and may include, among other controls, authentication via passwords and/or two-factor authentication, documented authorization processes, documented change management processes and/or logging of access on several levels.
- Data Access Controls: The Parties will take reasonable measures to ensure that Personal Information is accessible and manageable only by properly authorized staff, direct database query access is restricted and application access rights are established and enforced to ensure that persons entitled to use a data processing system only have access to the Personal Information to which they have privilege of access; and, that Personal Information cannot be read, copied, modified or removed without authorization in the course of processing.
Contact information
For questions about this Data Processing Addendum, please contact us at:
Email: privacy@synergistic.io
Address: 10325 S Medallion Dr, Cincinnati, OH 45241