Data Processing Addendum

Template version: v1.0

TEMPLATE. This Data Processing Addendum (“DPA”) is published to support enterprise privacy and security review. Specific terms may be negotiated in the executed version. The executed DPA supplements the Master Services Agreementbetween Customer and PlotCipher (“MSA”).

1. Definitions

  • “Personal Data” means information relating to an identified or identifiable natural person that is contained in Customer Data.
  • “Processing” means any operation performed on Personal Data, whether or not by automated means.
  • “Controller” means Customer with respect to Customer Data.
  • “Processor” means PlotCipher with respect to Customer Data Processed on Customer's behalf under the MSA.
  • “Subprocessor” means a third party engaged by PlotCipher to Process Personal Data, listed at /subprocessors.
  • “Data Protection Laws” means applicable US state privacy laws (CCPA/CPRA, TDPSA, VCDPA, CPA, CTDPA, UCPA, OCPA, DPDPA) and, where applicable, the EU/UK GDPR.

2. Roles & Scope

Customer is the Controller. PlotCipher is the Processor (or, where applicable, the Service Provider / Processor under CCPA). PlotCipher Processes Personal Data only on documented instructions from Customer, including with regard to transfers to a third country.

3. Categories of Personal Data & Data Subjects

Categories of Personal Data Processed: identifiers (name, email, account ID), commercial information, internet/network activity, content created by Users (deal notes, pipeline activity, room contents). PlotCipher does not knowingly Process sensitive Personal Data.

Categories of Data Subjects: Customer's authorized Users and (incidentally) property owners whose names appear in public real-property records displayed in the Service.

4. Confidentiality & Personnel

PlotCipher ensures that personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations and have received privacy and security training.

5. Security Measures

PlotCipher implements and maintains the technical and organizational security measures described at /security, including encryption in transit and at rest, identity and access management, vulnerability management, incident response, and disaster recovery. PlotCipher will not materially weaken these measures during the Term.

6. Subprocessors

Customer authorizes PlotCipher to engage the Subprocessors listed at /subprocessors. PlotCipher will:

  • Bind each Subprocessor to data protection obligations no less protective than those in this DPA;
  • Remain liable to Customer for each Subprocessor's performance;
  • Provide at least thirty (30) days' advance notice of any material change (new Subprocessor or significant change in data Processed) via in-product banner and email to billing contacts;
  • Honor a reasonable Customer objection during that period; if the objection cannot be resolved, Customer may terminate the affected portion of the Service for cause.

7. Data Subject Rights & Requests

PlotCipher will, taking into account the nature of the Processing, assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligation to respond to requests by data subjects exercising their rights under Data Protection Laws.

Customer's Users may also use the self-service /privacy-requests portal directly.

8. Personal Data Breach Notification

PlotCipher will notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware of a Personal Data breach affecting Customer Data, providing the information reasonably available to assist Customer in meeting its notification obligations.

9. Audit Rights

On reasonable prior written notice (not more than once per twelve months, except in response to a confirmed breach or regulatory request), PlotCipher will respond to a Customer audit questionnaire and make available such information as is necessary to demonstrate compliance with this DPA. Customer may, at its expense and subject to confidentiality, retain a mutually-agreed third-party auditor to conduct an audit, no more than once every twenty-four months.

10. Return or Deletion of Personal Data

On termination of the MSA, PlotCipher will (a) make Customer Data available for export for thirty (30) days, after which (b) PlotCipher will delete or anonymize Personal Data in its production systems within ninety (90) days, except as required for legal retention or as preserved in backups subject to standard rotation.

11. International Transfers

PlotCipher Processes Personal Data in the United States. If Customer transfers Personal Data subject to GDPR or UK GDPR, the Parties will execute Standard Contractual Clauses (Module 2 — Controller-to-Processor) or the UK International Data Transfer Addendum, as applicable.

12. Liability

Each Party's liability under this DPA is subject to the limitation of liability in the MSA.

13. CCPA Service-Provider Terms

To the extent CCPA applies, PlotCipher:

  • Will Process Personal Data only for the limited and specified purposes set forth in the MSA;
  • Will not sell or share Personal Data;
  • Will not retain, use, or disclose Personal Data outside the direct business relationship between PlotCipher and Customer or for any commercial purpose other than providing the Service;
  • Will notify Customer if it determines it can no longer meet its obligations under CCPA;
  • Authorizes Customer to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data.

14. Term

This DPA is effective on execution and remains effective for the duration of the MSA and for so long as PlotCipher retains Customer Personal Data.

Contact

Privacy & security: mark@tryplotcipher.com and mark@tryplotcipher.com.

Free forever · No credit card

Start finding deals today.