Data Processing Addendum
This Data Processing Addendum (DPA) forms part of the Master Services Agreement and applies where Relynt processes personal data on behalf of a customer who acts as a controller. Capitalized terms not defined here have the meaning given in the MSA.
1. Definitions
“Data Protection Laws” means all laws and regulations applicable to the processing of personal data under the Agreement, including the GDPR, the UK GDPR, and applicable U.S. state privacy laws. “Controller,” “Processor,” “Data Subject,” “Personal Data,” and “Processing” have the meanings given in the applicable Data Protection Laws. “Customer Personal Data” means personal data that Relynt processes on behalf of the Customer under the Agreement.
2. Roles of the Parties
The parties agree that, with respect to Customer Personal Data, the Customer is the Controller and Relynt is the Processor, and that Relynt may engage subprocessors in accordance with this DPA. Each party will comply with its obligations under applicable Data Protection Laws.
3. Processing of Personal Data
Relynt will process Customer Personal Data only on the documented instructions of the Customer, including with regard to international transfers, unless required by law to act otherwise. The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex A. Relynt will inform the Customer if, in its opinion, an instruction infringes applicable Data Protection Laws.
4. Confidentiality
Relynt will ensure that personnel authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality and have received appropriate training on their responsibilities.
5. Security Measures
Relynt will implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art and the nature of the processing, as further described in Annex B. These measures include encryption in transit and at rest, access controls, logging and monitoring, and regular testing of security controls.
6. Subprocessors
The Customer provides a general authorization for Relynt to engage subprocessors to process Customer Personal Data, provided that Relynt: (a) maintains a current list of subprocessors and provides a mechanism to obtain notice of changes; (b) imposes data protection obligations on each subprocessor that are no less protective than those in this DPA; and (c) remains liable for the performance of each subprocessor. The Customer may object to a new subprocessor on reasonable data-protection grounds.
7. Data Subject Requests
Taking into account the nature of the processing, Relynt will provide reasonable assistance, including by appropriate technical and organizational measures, to enable the Customer to respond to requests from data subjects exercising their rights under applicable Data Protection Laws. If Relynt receives such a request directly, it will, unless legally prohibited, promptly forward it to the Customer and not respond except on the Customer’s instructions.
8. Personal Data Breach
Relynt will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and will provide information reasonably available to it to assist the Customer in meeting its breach-notification obligations.
9. Data Protection Impact Assessments
Relynt will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, in each case solely in relation to the processing of Customer Personal Data and taking into account the information available to Relynt.
10. International Transfers
To the extent Relynt processes Customer Personal Data subject to the GDPR or UK GDPR in a country that has not received an adequacy decision, the parties agree that the Standard Contractual Clauses, and the UK Addendum where applicable, are incorporated into this DPA and apply to such transfers.
11. Return and Deletion
Upon termination or expiration of the Agreement, Relynt will, at the Customer’s choice, delete or return Customer Personal Data and delete existing copies, unless applicable law requires continued storage. Routine backups will be deleted in the ordinary course consistent with Relynt’s retention schedule.
12. Audits
Relynt will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable confidentiality, scheduling, and security requirements. Relynt may satisfy audit requests by providing third-party certifications or reports where available.
13. Annexes
Annex A — Details of Processing. Describes the subject matter, duration, nature and purpose of processing, the types of personal data, and the categories of data subjects.
Annex B — Technical and Organizational Measures. Describes the security measures implemented by Relynt.
Annex C — Subprocessors. Lists the subprocessors authorized as of the effective date.