Data Processing Agreement (DPA) | Panther
DATA PROCESSING ADDENDUM
This Data Processing Addendum, including all schedules attached hereto, (the “DPA”) is incorporated into and forms a part of the Enterprise Subscription Agreement (“Agreement”) entered into by and between the customer identified below (“Customer”) and the supplier identified below (“Supplier”) (each a “Party”, together the “Parties”) and is entered into as of the date of last signature below (the “Effective Date”). All capitalized terms used, but not defined in this DPA shall have the meanings set forth in the Agreement. In the event of a conflict between the Agreement and the DPA, the terms of the DPA shall prevail.
The parties hereby agree that the terms and conditions set out below shall be added as an addendum to the Agreement. The following obligations shall only apply to the extent required by Data Protection Laws (as defined below) with regard to the relevant Customer Personal Data, if applicable.
1. Definitions and interpretation
1.1 Definitions
In this DPA, the following terms shall have the following meanings:
- “Applicable Data Protection Laws" shall mean all applicable international, national, federal, state, provincial, and local laws, rules, regulations, directives, and governmental data privacy and security laws and regulations currently in effect, or as they become effective, applicable to Panther’s processing of Personal Data, as necessary to provide the Services as further described in the Agreement, including, without limitation and to the extent applicable, European Data Protection Laws (as defined below) and the United States Data Protection Laws (as defined below).
- “Controller” means an entity that determines the purposes and means of Processing Personal Data.
- “Customer Personal Data” means Personal Data contained in Customer Data that is Processed by Supplier on behalf of Customer to perform the Services under the Agreement.
- “Data Subject” means the identified or identifiable natural person.
- “European Data Protection laws” includes the EU General Data Protection Regulations 2016/679 (“GDPR”), the UK GDPR, and other applicable laws related to data protection in the UK and EU.
1.2 Further Definitions
- “International Data Transfer” means any transfer of Customer’s Data from the EEA, Switzerland or the United Kingdom to an international organization or to a country outside of the EEA, Switzerland and the United Kingdom;
- “Personal Data” means information that constitutes “personal information”, “personal data”, or similar terms under Applicable Data Protection Laws.
- “Processor” means an entity that Processes Personal Data on behalf of the Controller.
- “Security Incident” means a breach of Supplier’s security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to the Customer Personal Data in Supplier’s possession, custody, or control.
2. Data Protection
2.1 Relationship of the parties
The parties acknowledge and agree that with regard to the Processing of Customer Personal Data, Customer may either act as a Controller or Processor (to a third party Controller in respect to some of the Customer Personal Data) of Data, and Supplier is the Processor acting on behalf of Customer.
2.2 Customer Instructions
Supplier will Process Customer Personal Data in accordance with Customer’s documented instructions unless otherwise required by Applicable Data Protection Laws.
2.3 Purpose limitation
Customer shall have sole responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired such Customer Personal Data.
2.4 Confidentiality of processing
Supplier shall ensure that any person authorized to process the Data shall be subject to a strict duty of confidentiality.
2.5 Security
Supplier shall implement appropriate technical and organizational measures designed to protect the Data from accidental or unlawful destruction, and loss, alteration, unauthorized disclosure of, or access to the Data.
2.6 Subprocessing
Customer generally authorizes Supplier to engage Subprocessors as Supplier considers reasonably appropriate for the Processing of Customer Personal Data.
2.7 Cooperation and data subjects' rights
Supplier shall provide reasonable assistance to Customer necessary to enable Customer to fulfill its obligations under Applicable Data Protection Laws to respond to requests from a Data Subject to exercise their rights under Applicable Data Protection Laws.
2.8 Security Incidents
Upon becoming aware of a Security Incident, Supplier shall notify Customer without undue delay.
2.9 Deletion or return of Data
Upon termination or expiry of this DPA, Supplier shall destroy or return to Customer all Data in its possession or control.
3. International Transfers
Supplier may, subject to the remaining terms of this Section, Process Customer Personal Data in the United States or anywhere Supplier or its Subprocessors maintain facilities.
4. Limitation of Liability
Each Party’s liability arising out of or related to this Agreement shall be subject to the “Limitations of Liability” section of the Agreement.
5. Miscellaneous
This DPA shall be governed by the law of the State of California, USA.
SCHEDULE 1
STANDARD CONTRACTUAL CLAUSES
SECTION I
Purpose and scope
a. The purpose of these standard contractual clauses is to ensure compliance with Regulation (EU) 2016/679.
b. The Parties:
- the data exporter and the data importer as identified in Annex I.A.
SECTION II - OBLIGATIONS OF THE PARTIES
Data protection safeguards
The data importer warrants that it will process the personal data only on documented instructions from the data exporter and will take appropriate technical and organisational measures to ensure compliance.
SECTION III - FINAL PROVISIONS
Governing law
These Clauses shall be governed by the law of the EU Member State in which the data exporter is established.
Appendix 1
Data Processing Description
A. LIST OF PARTIES
- Processor/Data importer: Panther Labs Inc., a Delaware corporation (“Supplier”). B. DESCRIPTION OF TRANSFER
- Categories of data subjects: employees or contractors of Customer.
- Categories of personal data: Employee or contractor name, work email, work phone number. "}