DATA PROCESSING AGREEMENT
This Data Processing Agreement ("DPA") forms part of General Terms And Conditions, governing the provision of the Services between CalorieScience ("Company") and the Subscriber ("Subscriber") (collectively, the "Agreement").
This DPA governs the Processing of Personal Data by the Company on behalf of the Subscriber in connection with the Services.
- Definitions
For the purposes of this DPA, the following capitalised terms shall have the meanings ascribed to them herein.
- "Applicable Data Protection Laws" means all applicable laws, regulations directives, regulatory guidance and legally binding governmental requirements relating to privacy, data protection, data security, data breach notification, cross-border data transfers and the Processing of Personal Data including any amendment, consolidation, re-enactment or replacement thereof.
- "Anonymous Data" means information that does not identify and cannot reasonably be used to identify an individual and is no longer Personal Data under Applicable Data Protection Laws.
- “Derived Data" means any aggregated, anonymised, de-identified, statistical, analytical, benchmarking, usage, performance, diagnostic, telemetry, system-generated or other information, insights, reports, models or trends generated from or based upon the use of the Services, provided that such information does not identify, and cannot reasonably be used to identify, directly or indirectly, any Subscriber, Client, Authorised User or Data Subject.
- “Special Category Data" means any Personal Data any personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation, as defined under Applicable Data Protection Laws.
- "Controller" means the entity that determines the purposes and means of Processing Personal Data, or any equivalent concept under Applicable Data Protection Laws.
- "Processor" means the entity that Processes Personal Data on behalf of a Controller, or any equivalent concept under Applicable Data Protection Laws.
- "Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
- "Personal Data" means any information relating to an identified or identifiable natural person and includes any equivalent concept recognised under Applicable Data Protection Laws.
- "Personal Data Breach" means any accidental, unauthorised or unlawful access, acquisition, disclosure, alteration, loss, destruction or other compromise of Personal Data.
- "Process", "Processing" or "Processed" means any operation or set of operations performed on Personal Data, whether by automated means or otherwise.
- "Subprocessor" means any third party engaged by the Company to Process Personal Data on behalf of the Subscriber in connection with the Services.
- “Restricted Transfer" means any transfer of Personal Data which requires an approved transfer mechanism under Applicable Data Protection Laws.
- "Transfer Mechanism" means any lawful mechanism recognised under Applicable Data Protection Laws for transferring Personal Data across jurisdictions, including adequacy decisions, Standard Contractual Clauses, binding corporate rules, approved codes of conduct, certifications, and any successor or equivalent mechanism.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission pursuant to Article 46 of the GDPR, together with any successor or replacement clauses.
- "Security Incident" means any actual or reasonably suspected event that compromises, or has the potential to compromise, the confidentiality, integrity, availability or security of the Services or Personal Data, whether or not it constitutes a Personal Data Breach.
- "Supervisory Authority" means any governmental, regulatory or supervisory authority having jurisdiction over the Processing of Personal Data under Applicable Data Protection Laws.
- Roles of the Parties
- As between the Parties, the Subscriber determines the purposes and means of Processing Personal Data submitted to or processed through the Services and acts as the Controller.
- The Company shall Process Personal Data, in accordance with the Agreement, this DPA and the Subscriber's documented instructions, on behalf of the Subscriber and acts as the Processor.
- Notwithstanding Clause 2.2, the Company may Process Personal Data as an independent Controller only where such Processing is required by Applicable Data Protection Laws or is necessary to comply with legal or regulatory obligations, protect and improve the security, integrity, availability, performance or resilience of the Services, prevent or investigate fraud or Security Incidents, maintain legally required business records, or establish, exercise or defend legal claims.
- Scope of Processing
- The Company shall Process Personal Data to:
- provide, operate host, maintain, support and administer the Services
- provide the functionality, features and access to the Platform in accordance with the Agreement;
- maintain, improve and development of platform features using anonymised or aggregated data;
- provide customer support, technical assistance, troubleshooting and maintenance;
- monitor, secure, maintain, improve and optimise the performance, reliability, integrity and security of the Services;
- perform backup, disaster recovery, business continuity and system restoration activities;
- create and use Anonymous Data and Derived Data in accordance with the Agreement and this DPA;
- comply with applicable law or legally binding governmental or regulatory requirements; and
- otherwise Process Personal Data as authorised in writing by the Subscriber.
- For the purposes of this DPA, the Subscriber's documented instructions include this DPA, the Agreement, the Subscriber's use and configuration of the Services, administrative settings, authorised integrations, support requests and other written instructions or communications issued by or on behalf of the Subscriber, and any other documented instructions agreed by the Parties.
- In the event the Company reasonably believes that any instruction received from the Subscriber infringes Applicable Data Protection Laws or would require the Company to violate applicable law or falls materially outside the scope of the Services or this DPA, the Company shall promptly notify the Subscriber and may suspend the relevant Processing until the Subscriber confirms, modifies or withdraws the instruction, unless prohibited by applicable law.
- Except as expressly permitted under this DPA, the Agreement or Applicable Data Protection Laws, the Company shall not Process Personal Data for its own marketing purposes; sell, rent or otherwise monetise Personal Data; disclose Personal Data to third parties except as authorised under this DPA; or Process Personal Data for any purpose incompatible with the Subscriber's documented instructions.
- The Company shall Process only such Personal Data as is reasonably necessary to perform the Services and fulfil its obligations under the Agreement and this DPA.
- The subject matter, nature, purpose, categories of Data Subjects, categories of Personal Data and duration of Processing undertaken by the Company on behalf of the Subscriber are detailed in Schedule A of this DPA .
- Subscriber Responsibilities
- The Subscriber shall be responsible for:
- establishing, documenting and maintaining an appropriate lawful basis for the collection, Processing and disclosure of Personal Data to the Company
- providing all privacy notices, disclosures and transparency information as required;
- obtaining, recording and maintaining all consents, permissions, authorisations and approvals required;
- ensuring the accuracy, relevancy, quality and legality of Personal Data submitted to the Services;
- responding to requests, complaints or inquiries from Data Subjects;
- ensuring that its instructions to the Company comply with Applicable Data Protection Laws and do not require the Company to Process Personal Data unlawfully; and
- complying with Applicable Data Protection Laws applicable to the Subscriber's activities and use of the Services.
- The Subscriber shall be responsible for maintaining the confidentiality of account credentials, user access permissions and administrative settings under its control and shall promptly notify the Company of any suspected unauthorised access to the Services.
- Company Responsibilities
- The Company shall Process Personal Data only in accordance with the Agreement, this DPA, the Subscriber's documented instructions and Applicable Data Protection Laws, and only to the extent reasonably necessary to provide the Services.
- The Company shall ensure that all personnel, employees, contractors, consultants and other persons authorised to Process Personal Data are subject to appropriate contractual or statutory confidentiality obligations, receive appropriate privacy and security training, access Personal Data only on a need-to-know basis, and Process Personal Data solely as necessary to perform their authorised duties.
- The Company shall Process Personal Data solely for the purposes authorised under the Agreement, this DPA or the Subscriber's documented instructions and shall not Process Personal Data for its own independent commercial purposes except as expressly permitted under this DPA or Applicable Data Protection Laws.
- The Company shall make available to the Subscriber such information as is reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Laws.
- The Company shall maintain appropriate records relating to the Processing activities performed on behalf of the Subscriber as required under Applicable Data Protection Laws.
- The Company shall periodically review its privacy, security and data governance practices and implement reasonable measures to ensure continuing compliance with Applicable Data Protection Laws.
- Security Measures
- The Company shall implement, maintain and periodically review appropriate technical, organisational, administrative and physical safeguards designed to protect Personal Data against accidental, unlawful or unauthorised destruction, loss, alteration, disclosure of, or access to Personal Data and to ensure a level of security appropriate to the risks presented by the Processing and the nature of the Personal Data.
- In determining the appropriate level of security, the Company shall take into account the nature of the Personal Data Processed, the risks presented by the Processing, the state of the art, implementation costs and the nature, scope, context and purposes of the Processing.
- The Company's security measures may include, as appropriate: access controls and authentication mechanisms; encryption and secure transmission technologies; logging and monitoring of system activity; backup and recovery procedures; vulnerability management and security testing processes; incident detection and response procedures; and personnel security and confidentiality measures. The Security Measures are described in detail in Schedule B of this DPA.
- The Company shall periodically review and update its security measures to address changes in technology, security risks, legal requirements and industry practices, provided that such modifications do not materially diminish the overall level of protection for Personal Data.
- The Subscriber acknowledges that no security measure, transmission method or storage system can guarantee absolute security and that the Company does not warrant that unauthorised access, cyberattacks or Security Incidents will never occur.
- Personal Data Breaches
- The Company shall maintain and implement reasonable policies, procedures and controls for the identification, assessment, investigation, containment, mitigation, remediation and documentation of Security Incidents and Personal Data Breaches.
- Upon becoming aware of a confirmed Personal Data Breach affecting Personal Data Processed on behalf of the Subscriber, the Company shall notify the Subscriber without undue delay and, where reasonably practicable, within seventy-two (72) hours after becoming aware of the Personal Data Breach.
- The notification shall include information, to the extent reasonably available, regarding:
- the nature of the Personal Data Breach;
- the categories and, where reasonably available, approximate number of affected Data Subjects
- the categories of Personal Data affected;
- the measures taken or proposed to address the Personal Data Breach; and
- any information reasonably necessary to assist the Subscriber in complying with Applicable Data Protection Laws.
- The Company shall take reasonable steps to investigate, contain, mitigate and remediate the effects of a Personal Data Breach and shall cooperate with the Subscriber in responding to regulatory enquiries, Data Subject notifications and other legal obligations arising from the Personal Data Breach.
- The Company may provide information relating to a Personal Data Breach in phases as such information becomes reasonably available.
- Except where required by applicable law, the Company shall not notify any Data Subject, regulator or governmental authority, customer, media organisation or other third party regarding a Personal Data Breach relating to Personal Data Processed on behalf of the Subscriber without the prior written authorisation by the Subscriber.
- The Subscriber acknowledges that the Company may be unable to provide information that is not reasonably available to it or that relates solely to the Subscriber's systems, processes or activities outside the Services.
- The Company shall maintain appropriate records relating to Personal Data Breaches affecting Personal Data Processed under this DPA to the extent required under Applicable Data Protection Laws.
- Notification of a Personal Data Breach by the Company shall not constitute an admission of fault, negligence, liability or wrongdoing.
- The Company shall use reasonable efforts to preserve relevant evidence relating to a Personal Data Breach for so long as reasonably necessary to investigate the incident, comply with Applicable Data Protection Laws or defend legal claims.
- Subprocessors
- The Subscriber provides general authorisation for the Company to engage Subprocessors in connection with the provision, operation, maintenance, hosting, support, security, improvement and administration of the Services.
- The Company shall conduct reasonable diligence prior to engaging a Subprocessor and shall ensure that each Subprocessor is subject to contractual obligations that provide a level of protection for Personal Data that is substantially equivalent to the obligations imposed on the Company under this DPA.
- The Company may add, replace or remove Subprocessors from time to time. A current list of material Subprocessors shall be made available by the Company upon request or through such other means as the Company may reasonably designate.
- Where required by Applicable Data Protection Laws, the Company shall provide reasonable notice of the appointment of a new Subprocessor and shall consider any reasonable objections raised by the Subscriber. If the Parties are unable to resolve such objection, the Subscriber's sole remedy shall be to discontinue the affected Services and terminate the applicable subscription without penalty for the affected Services.
- The Company shall remain responsible for the acts and omissions of its Subprocessors to the extent required by Applicable Data Protection Laws.
- The Subscriber acknowledges that certain Subprocessors may be located in jurisdictions different from those in which the Subscriber or Data Subjects are located and that Personal Data may be transferred to such jurisdictions in accordance with this DPA and Applicable Data Protection Laws.
- Nothing in this Clause restricts the Company's ability to engage affiliates, contractors, infrastructure providers, hosting providers, communication providers, payment processors, analytics providers, artificial intelligence providers or other service providers as Subprocessors in connection with the Services.
- Where immediate replacement of a Subprocessor is reasonably necessary to address a Security Incident, legal or regulatory requirement, service interruption or other urgent operational issue, the Company may appoint a replacement Subprocessor without prior notice, provided that notice is given to the Subscriber as soon as reasonably practicable thereafter.
- International Transfers
- The Subscriber acknowledges and agrees that Personal Data may be Processed, accessed, transferred or stored in jurisdictions other than the jurisdiction in which the Subscriber or the relevant Data Subjects are located, including jurisdictions in which the Company, its affiliates or Subprocessors operate, subject to this DPA and Applicable Data Protection Law.
- The Company shall implement and maintain appropriate safeguards for Restricted Transfers where required under Applicable Data Protection Laws and shall Process Personal Data in accordance with the applicable transfer mechanism .
- Where Applicable Data Protection Laws require a specific transfer mechanism for the lawful transfer of Personal Data, the Parties agree to cooperate in good faith to implement such mechanism, including, where appropriate: the adequacy decisions; execution of standard contractual clauses, approved certifications or codes of conducts, data transfer agreements or other recognised transfer mechanisms.
- The Subscriber authorises the Company and its Subprocessors to undertake Restricted Transfers to the extent reasonably necessary to provide, operate, maintain, support and improve the Services and to perform obligations under the Agreement and this DPA.
- Unless expressly agreed otherwise in writing or required under Applicable Data Protection Laws, nothing in this DPA shall require the Company to store or Process Personal Data exclusively within any particular jurisdiction.
- The Company shall not be responsible for restrictions on international transfers arising from the Subscriber's failure to implement measures required under Applicable Data Protection Laws or to cooperate in establishing an appropriate transfer mechanism where required.
- Each Party shall reasonably cooperate with the other in implementing any additional documentation or measures reasonably required to enable lawful international transfers under Applicable Data Protection Laws.
- The jurisdiction-specific transfer obligations applicable to particular jurisdictions are set out in Schedule C and shall prevail to the extent required by the Applicable Data Protection Laws governing the relevant Processing.
- Assistance and Cooperation
- Taking into account the nature of the Processing, the Services and the information reasonably available to the Company, the Company shall provide reasonable assistance to the Subscriber to enable the Subscriber to comply with Applicable Data Protection Laws in relation to the Processing of Personal Data undertaken by the Company on the Subscriber's behalf.
- The Company shall, to the extent reasonably practicable and lawful, promptly notify the Subscriber if it receives a request, complaint, inquiry or communication from a Data Subject, regulator or governmental authority relating to Personal Data Processed on behalf of the Subscriber.
- Unless required by applicable law, the Company shall not directly respond to any such request or notice without the Subscriber's prior authorisation d may direct the requesting party to the Subscriber where appropriate.
- The Subscriber remains responsible for determining the appropriate response to requests from Data Subjects, regulators and governmental authorities and for complying with its obligations under Applicable Data Protection Laws.
- The Company may charge reasonable fees for assistance that requires material additional resources, custom development, extensive investigation, legal review or other services beyond the ordinary provision of the Services.
- Each Party shall reasonably cooperate with the other in connection with matters arising under this DPA, provided that neither Party shall be required to disclose information protected by legal privilege, confidentiality obligations owed to third parties or applicable law.
- Any jurisdiction-specific assistance obligations imposed under Applicable Data Protection Laws shall be set out in Schedule C and shall apply to the extent required by the Applicable Data Protection Laws governing the relevant Processing.
- The Company shall not be required to provide assistance to the extent the requested information is not reasonably available, the assistance would compromise the security, confidentiality or integrity of the Services or the Personal Data of other customers, violate applicable law or legally binding obligations to third parties, or fall outside the scope of the Services unless the Parties have agreed the applicable commercial terms.
- Audit Rights
- The Company shall make available to the Subscriber such information as is reasonably necessary to demonstrate the Company's compliance with this DPA and Applicable Data Protection Laws.
- The Company may satisfy its obligations under Clause 11.1 by providing security certifications, audit reports, compliance attestations, policies, questionnaires, summaries of technical and organisational measures, penetration testing summaries, or other documentation reasonably relevant to the Processing of Personal Data.
- To the extent required by Applicable Data Protection Laws and where the information provided under Clause 11.2 is insufficient, the Subscriber may request an audit upon reasonable prior written notice of the Company's Processing activities relating to Personal Data Processed on behalf of the Subscriber.
- Any audit shall be conducted during normal business hours; (b) be limited to matters relevant to this DPA; (c) minimise disruption to the Company's business; (d) comply with the Company's reasonable security and confidentiality requirements; and (e) be conducted at the Subscriber's expense unless otherwise required by Applicable Data Protection Laws or the audit identifies a material breach by the Company.
- The Company shall not be required to disclose information relating to other customers, trade secrets, source code, confidential security information, legally privileged information, or any information whose disclosure would violate applicable law or compromise the security or integrity of the Services.
- The Company may satisfy an audit request through remote review, virtual inspection or by providing existing independent audit reports or certifications where these reasonably demonstrate compliance.
- Return, Retention and Deletion of Personal Data
- Upon expiration or termination of the Agreement, the Subscriber may retrieve or export Personal Data using the functionality made available through the Services.
- The Company may retain Personal Data for a reasonable period following termination to facilitate data retrieval, account closure, security, backup and recovery, dispute resolution, and compliance with applicable law.
- Following the applicable retention period, the Company shall delete or anonymise Personal Data unless retention is required by applicable law or is necessary for legal, regulatory, audit, security, fraud prevention or legal claims.
- Any Personal Data retained under this Clause shall continue to be protected in accordance with this DPA for so long as it remains in the Company's possession or control.
- Where the Company reasonably determines that deletion of Personal Data would conflict with legal obligations, regulatory requirements, litigation holds or preservation obligations, the Company may suspend deletion for the period reasonably necessary to comply with such obligations.
- Nothing in this Clause requires the Company to delete anonymised information, system logs, security, audit or operational records, or information retained in routine backup systems until such backups are overwritten or deleted in accordance with the Company's standard retention practices.
- Derived Data, Anonymous Data and Product Improvement
- The Subscriber acknowledges and agrees that, in connection with providing and improving the Services, the Company may create, generate, compile, analyse or otherwise derive Derived Data from information Processed through or generated by the Services.
- The Parties acknowledge and agree that, to the extent permitted under Applicable Data Protection Laws, Derived Data:
- shall not constitute Personal Data to the extent it does not identify and cannot reasonably identify a Data Subject;
- shall not constitute Subscriber Data, Client Records or Confidential Information of the Subscriber;
- may be retained by the Company following termination of the Agreement; and
- may be used by the Company for analytics, benchmarking, research, testing, product development, service improvement, security, operational purposes and the development, maintenance and improvement of automated, machine-learning and artificial intelligence functionality.
- As between the Parties, the Company owns all right, title and interest, including all intellectual property rights, in and to Derived Data, Anonymous Data and any improvements, analyses, models or insights generated therefrom.
- Except as expressly authorised by the Subscriber or permitted under Applicable Data Protection Laws, the Company shall not use identifiable Personal Data, Client Records or Subscriber Confidential Information to train publicly available or general-purpose artificial intelligence models.
- Subject to this DPA and Applicable Data Protection Laws, the Company may use Derived Data for analytics, benchmarking, research, testing, security, fraud detection, monitoring, product development, service improvement, quality assurance, statistical reporting, artificial intelligence and machine learning functionalities, and other legitimate business purposes.
- The Company shall not knowingly attempt to re-identify Anonymous Data except where necessary to verify the effectiveness of the anonymisation process, to comply with applicable law, or where otherwise expressly authorised under Applicable Data Protection Laws.
- Nothing in this DPA restricts the Company's ability to use Derived Data and Anonymous Data to develop, train, validate, improve or maintain proprietary algorithms, analytical models, decision-support tools or artificial intelligence functionality, provided that such use does not involve identifiable Personal Data except as permitted under this DPA and Applicable Data Protection Laws.
- Liability
- Except as expressly provided in this DPA or where Applicable Data Protection Laws require otherwise, the rights, remedies, exclusions, limitations of liability and allocation of risk contained in the Agreement shall apply to all claims arising out of or relating to this DPA.
- Nothing in this DPA shall be construed as increasing, expanding or modifying either Party's liability beyond that expressly provided in the Agreement, except to the extent such limitation is prohibited under Applicable Data Protection Laws.
- Each Party shall remain independently responsible for its own compliance with Applicable Data Protection Laws and for any fines, penalties, regulatory actions, damages, liabilities or claims arising from its own acts, omissions or breach of such laws.
- The Company shall not be liable for any claim, liability or loss arising from or relating to:
- the Subscriber's instructions;
- the Subscriber's failure to comply with Applicable Data Protection Laws;
- the Subscriber's failure to obtain any required notices, permissions, authorisations or consents;
- inaccurate, unlawful or improperly collected Personal Data provided by the Subscriber;
- the Subscriber's configuration or use of the Services contrary to the Agreement or the Company's documentation; or
- Processing activities undertaken by or on behalf of the Subscriber outside the Services.
- Nothing in this DPA shall excludes or limits liability to the extent such exclusion or limitation is prohibited under Applicable Data Protection Laws.
- To the extent permitted under Applicable Data Protection Laws, each Party shall be responsible for any regulatory fines, penalties or sanctions imposed upon it arising from its own acts or omissions.
- Term and Termination
- This DPA shall commence on the Effective Date of the Agreement and shall remain in effect for so long as the Company Processes Personal Data on behalf of the Subscriber.
- Unless otherwise required under this DPA or Applicable Data Protection Laws, termination or expiration of the Agreement shall automatically terminate this DPA, except to the extent the Company continues to Process or retain Personal Data following such termination or expiration.
- The rights and obligations of the Parties under this DPA relating to confidentiality, security, retention, deletion, liability and any other provisions which by their nature are intended to survive shall continue for so long as the Company retains or Processes Personal Data.
- Order of Precedence
- In the event of a conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA shall prevail solely to the extent of such conflict.
- In the event of any conflict between the main body of this DPA and the applicable jurisdiction-specific provisions contained in Schedule C, the relevant provisions of Schedule C shall prevail solely to the extent required by the Applicable Data Protection Laws governing the relevant Processing.
- Except as expressly modified by this DPA, the Agreement shall remain in full force and effect.
- Schedule C supplements this DPA and shall apply only to the extent the relevant Applicable Data Protection Laws govern the Processing of Personal Data.
Schedule A
Description of Processing
- Subject Matter of Processing
The Company provides, hosts, operates, supports and maintains the Services under the Agreement. In connection with providing the Services, the Company Processes Personal Data on behalf of the Subscriber solely for the purposes described in this Schedule and the Agreement.
- Nature and Purpose of Processing
The Company may Process Personal Data for purposes including:
- user registration and account management;
- authentication and access management;
- client onboarding and profile management;
- administration of questionnaires, assessments and workflows;
- creation and management of nutrition plans, wellness programmes, reports and recommendations;
- communications, scheduling, reminders and notifications;
- customer support and technical assistance;
- operation, hosting, maintenance and administration of the Services;
- security monitoring, fraud prevention, troubleshooting and incident response;
- backup, disaster recovery and business continuity;
- analytics, service optimisation and performance monitoring;
- compliance with legal and regulatory obligations;
- creation of Anonymous Data and Derived Data in accordance with the Agreement and this DPA.
- Categories of Data Subjects
The categories of Data Subjects may include:
- Subscribers;
- Authorised Users;
- practitioners, nutritionists, dietitians, coaches, consultants and other professionals using the Services;
- prospective clients, clients, patients and programme participants of the Subscriber;
- individuals invited to access or interact with the Services; and
- individuals whose Personal Data is submitted to or processed through the Services by or on behalf of the Subscriber.
- Categories of Personal Data
The categories of Personal Data may include:
- identification information, including names, usernames and account identifiers;
- contact information, including email addresses, telephone numbers and mailing addresses;
- demographic information, including age, gender and date of birth;
- account, subscription and authentication information;
- appointment, scheduling and communication information;
- questionnaire responses, assessments and survey information;
- nutritional, dietary, lifestyle and wellness information;
- meal plans, recipes, preferences and programme information;
- uploaded documents, images, notes and records;
- biomarker information, laboratory values and related health and wellness information submitted by or on behalf of the Subscriber;
- communications exchanged through the Services;
- device, usage, log and technical information generated through use of the Services; and
- any other Personal Data submitted to or processed through the Services by or on behalf of the Subscriber.
- Special Category Data
- To the extent submitted by or on behalf of the Subscriber, the Company may Process special categories of Personal Data, including:
- health and wellness information;
- dietary and nutritional information;
- biomarker information and laboratory data;
- information relating to medical conditions, allergies, intolerances or dietary restrictions; and
- other sensitive Personal Data submitted by or on behalf of the Subscriber through the Services.
- The Subscriber acknowledges and instructs the Company to Process such Personal Data solely for the purposes described in this Schedule and the Agreement.
- Duration of Processing
The Company shall Process Personal Data for the duration of the Agreement and thereafter for such period as necessary to comply with the Agreement, this DPA, applicable law, legitimate business requirements, security obligations, dispute resolution requirements and applicable retention practices.
Schedule B
Security Measures
The Company maintains administrative, technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data. Such measures may include the following:
- Access Controls
- role-based access controls designed to limit access to Personal Data on a need-to-know basis;
- procedures for granting, reviewing and revoking access rights;
- restriction of administrative access to authorised personnel; and
- measures designed to prevent unauthorised access to systems and data.
- Authentication
- authentication mechanisms for access to systems and services;
- password management and credential protection measures;
- controls designed to prevent unauthorised use of user accounts; and
- additional authentication measures where appropriate based on risk and system functionality.
- Encryption and Data Protection
- use of secure communication protocols for data transmission where appropriate;
- encryption or equivalent protective measures for Personal Data where appropriate based on the nature of the Processing and associated risks;
- controls designed to protect Personal Data during storage, transmission and processing; and
- measures designed to prevent unauthorised disclosure or alteration of Personal Data.
- Logging and Monitoring
- maintenance of system and security logs where appropriate;
- monitoring of systems for security, operational and performance purposes;
- investigation of suspicious activities or security events; and
- retention of logs and records in accordance with operational and security requirements.
- Backup and Recovery
- backup procedures designed to support the availability and recovery of Personal Data;
- disaster recovery and business continuity measures appropriate to the nature of the Services;
- procedures for restoring access to Personal Data following a disruption; and
- periodic review and testing of recovery processes where appropriate.
- Vulnerability Management
- processes designed to identify, assess and address security vulnerabilities;
- application of security updates and patches as appropriate;
- periodic review of security risks and threats; and
- security testing, monitoring or assessment activities appropriate to the Services.
- Incident Response
- procedures for identifying, investigating and responding to security incidents;
- processes for containment, mitigation and remediation of security incidents;
- escalation and reporting procedures for material security incidents; and
- procedures for notifying affected customers of Personal Data Breaches in accordance with the DPA and applicable law.
- Personnel Security and Confidentiality
- confidentiality obligations applicable to personnel with access to Personal Data;
- training and awareness measures relating to privacy and information security;
- procedures for onboarding and offboarding personnel; and
- measures designed to ensure that personnel access Personal Data only as necessary to perform their duties.
- Review of Security Measures
The Company may review, modify and update these Security Measures from time to time to address changes in technology, security risks, legal requirements, industry practices and the nature of the Services, provided that such changes do not materially reduce the overall level of protection afforded to Personal Data.
Schedule C
Jurisdiction-Specific Terms
This Schedule supplements the DPA solely to the extent the Processing of Personal Data is governed by the Applicable Data Protection Laws identified in the relevant Part of this Schedule. Where a provision of this Schedule conflicts with the main body of the DPA, this Schedule shall prevail only to the extent necessary to comply with the relevant Applicable Data Protection Laws.
Capitalised terms used but not defined in this Schedule shall have the meanings assigned in the DPA.
Part A– EUROPEAN UNION (GDPR)
- This Part applies where the Processing is subject to Regulation (EU) 2016/679 ("GDPR") EU GDPR and related implementing legislation.
- The Parties acknowledge that the Subscriber acts as Controller and the Company acts as Processor in respect of Personal Data Processed on behalf of the Subscriber.
- The Parties acknowledge that the DPA is intended to satisfy Article 28 GDPR.
- Parties agree that where required, EU SCCs are incorporated by reference.
- The Company shall Process Personal Data only on documented instructions from the Subscriber unless otherwise required by law.
- The Company shall provide reasonable assistance to enable the Subscriber to comply with its obligations relating to Data Subject rights, Personal Data Breaches, data protection impact assessments, and regulatory inquiries.
- The Company shall provide reasonable assistance enabling Subscriber to comply with access, rectification, erasure, restriction, portability, objection,automated decision making to the extent applicable.
- With respect to Personal Data Breaches, the Company shall provide reasonable assistance enabling Subscriber to comply with Articles 33 and 34 GDPR.
- Where Personal Data is transferred outside the European Economic Area, the Parties shall implement such transfer mechanisms as may be required under GDPR, including the European Commission Standard Contractual Clauses or any successor mechanism.
- The Parties agree that the information contained in Schedule A constitutes the description of Processing required under Article 28 GDPR.
Part 2 – United Kingdom
- This Part applies where the Processing is subject to UK GDPR and related implementing legislation.
- References to Applicable Data Protection Law in the DPA shall be interpreted as references to UK GDPR as per the context.
- Where required, the UK International Data Transfer Addendum (or successor mechanism) shall automatically supplement the EU SCCs. Where SCCs are not appropriate, the Parties shall implement the UK International Data Transfer Agreement (IDTA).
- The Parties shall cooperate to implement changes required by binding guidance issued by the Information Commissioner's Office affecting international transfers.
- Company shall provide reasonable assistance regarding UK GDPR rights.
- Company shall reasonably assist Subscriber in complying with UK GDPR breach notification obligations.
- The Parties acknowledge that the Subscriber acts as Controller and the Company acts as Processor in respect of Personal Data Processed on behalf of the Subscriber.
- Where Personal Data is transferred outside the United Kingdom, the Parties shall implement such transfer mechanisms as may be required under UK GDPR, including the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or any successor mechanism.
- The Parties agree that the information contained in Schedule A constitutes the description of Processing required under Article 28 UK GDPR.
Part 3 – USA
- This Part applies where the Processing is subject to United States federal and state privacy laws, to the extent applicable.
- The Parties intend that the Company acts as a Service Provider, Processor, Contractor or equivalent role, as applicable under the relevant law.
- The Company shall Process Personal Data solely for the purposes described in the Agreement and shall not sell Personal Data or share Personal Data for cross-context behavioural advertising except as permitted by Applicable Data Protection Laws.
- Except where expressly permitted by applicable law, Company shall not:(a) sell Personal Data; (b) share Personal Data for cross-context behavioural advertising; (c) retain or use Personal Data outside the direct business relationship; (d) combine Personal Data with Personal Data received from other customers except as permitted by law.
- Company shall Process Sensitive Personal Information solely as instructed by Subscriber and for the business purposes contemplated under the Agreement.
- The Company shall provide reasonable assistance to the Subscriber in responding to consumer requests regarding access, deletion, correction, portability, opt-out requests etc. where required by US Laws.
- The Company shall notify the Subscriber if it determines that it can no longer meet its obligations under the applicable privacy laws governing the Processing.
- The Parties acknowledge that the rights and obligations set out in the DPA are intended to satisfy the contractual requirements applicable to service providers, contractors and processors under relevant United States privacy laws.