Data Processing Agreement
Data Processing Agreement
This Data Processing Addendum (“DPA”) supplements the CitrusBits Customer Terms of Use or other agreement between Customer and CitrusBits governing Customer’s use of the Services (together, the “Agreement”), entered into by and between the customer named in the Agreement (together with its affiliates, “Customer”) and CitrusBits, Inc. (together with its affiliates, “CitrusBits”). In the event of a conflict between this DPA and the Agreement, this DPA supersedes and controls with respect to the Processing of Personal Data.
Capitalized terms used and not defined in this DPA have the respective meanings set forth in the Agreement and/or applicable Data Protection Law.
Applicability and Acceptance of this DPA
This DPA is incorporated by reference into and forms part of the Agreement. By entering into or accepting the Agreement, the Customer agrees to be bound by this DPA. Where applicable, such acceptance shall also constitute acceptance of the Standard Contractual Clauses incorporated herein, including their Annexes.
1. Scope
- This DPA serves as a written data processing agreement between CitrusBits and Customer (on its behalf and on behalf of each Controller referenced in this DPA) and shall apply to any Processing of Personal Data by CitrusBits or any of its Sub-processors in connection with services provided under the terms of the Agreement. This DPA shall be effective for the period CitrusBits provides services to Customers under the Agreement and for any period after which CitrusBits retains Personal Data.
- The Parties agree that this DPA shall replace any existing data processing agreement or similar document that the Parties may have previously entered into in connection with the Services. In the event of any conflict between the terms of the Agreement, including any previously or concurrently executed addendums, and the terms of this DPA, the relevant terms of this DPA shall take precedence. If any provision of this DPA is found by any court of competent jurisdiction to be invalid or unenforceable, the invalidity of such provision shall not affect the other provisions hereof, and all provisions not affected by such invalidity shall remain in full force and effect.
2. Definitions
- “Customer Data” means all data provided or otherwise made available by Customer to CitrusBits in the course of CitrusBits providing services pursuant to the Agreement.
- “Data Protection Law” means laws and regulations applicable to the Processing of Personal Data under the Agreement, including (i) the General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”) and the UK GDPR, (ii) the Swiss Federal Act on Data Protection, (iii) the UK Data Protection Act 2018, in each case, as updated, amended or replaced from time to time. The terms “Controller,” “Data Subject,” “Processing,” “Processor,” and “supervisory authority” shall have the definitions set forth in the GDPR.
- “EEA” means, for purposes of this DPA, the European Economic Area, Switzerland, and the United Kingdom.
- “Personal Data” shall have the meaning set forth in the GDPR, to the extent such data is Customer Data.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed by CitrusBits.
- “Standard Contractual Clauses” means:
- for UK Personal Data, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (the “UK Addendum”), as issued by the UK Information Commissioner and amended, replaced or superseded from time to time. The UK Addendum shall apply together with the applicable EU SCCs, with the information required for the UK Addendum being provided in this DPA and Schedule 2, as applicable (“UK SCCs”); and
- for EU Personal Data, the standard contractual clauses adopted by the European Commission under Commission Implementing Decision (EU) 2021/914, including text from Module 2 or Module 3 of such clauses as applicable, as modified in Section 10 (“EU SCCs”); and
- for Swiss Personal Data, the EU SCCs.
- “Sub-processor” means any Processor engaged by CitrusBits, including affiliates of CitrusBits acting as Processors.
3. Roles of Parties
- It is acknowledged and agreed that, regarding the Processing of Personal Data under this DPA, Customer acts as the Controller and CitrusBits acts as the Processor, or, where Customer is itself a Processor acting on behalf of a third-party Controller, CitrusBits acts as a Sub-processor. Module 2 or Module 3 of the EU SCCs shall apply, as applicable to the relevant Transfer under Section 10.
- Both Parties shall, in their respective roles, comply with all Data Protection Laws regarding Personal Data Processed under this DPA.
- The nature and purpose of the Processing, the types of Personal Data and categories of Data Subject Processed under this DPA are specified in Schedule 1 – Part 1 hereto, as may be updated by the Parties as applicable from time to time.
- Customer shall, in its use and receipt of the services provided or made available by CitrusBits pursuant to the Agreement (“CitrusBits Services”), Process Personal Data in accordance with the requirements of Data Protection Laws.
4. Customer Obligations
- Customer acts as the Controller or, where Customer Processes Personal Data on behalf of a third-party Controller, as a Processor, as applicable to the relevant Processing:
- concerning any Personal Data Processed by CitrusBits or its Sub-processors under this DPA; and
- as applicable, on behalf of and in the name of its affiliates, end users, contractors and/or partners in their capacity as Controllers and whose Personal Data at any time is Processed by CitrusBits or its Sub-processors under this DPA.
- Customer shall, in its use of the Services, Process Personal Data in accordance with Data Protection Law, including any applicable requirements to provide notice to Data Subjects of the use of CitrusBits as a Processor.
- Except as may be otherwise required under applicable Data Protection Law, Customer shall serve as a single point of contact for CitrusBits in all matters under this DPA and shall be responsible for the internal coordination, review and submission of instructions or requests to CitrusBits as well as the onward distribution of any information, notifications and reports provided by CitrusBits hereunder.
- In its capacity as Controller or Processor, as applicable, Customer represents and warrants that it is entitled to provide or make available Personal Data to CitrusBits for the purposes of this DPA and that the Processing instructions provided to CitrusBits comply with applicable Data Protection Law.
- Customer shall have sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which Customer acquired Personal Data.
5. CitrusBits Obligations and Limitations
- Purposes for Processing. CitrusBits shall Process Personal Data solely in accordance with Customer’s documented instructions, which comprise the Agreement, this DPA, Schedule 1, and Customer’s use and configuration of the Services, and for the following limited purposes:
- performance of the Services under the terms of the Agreement;
- Processing initiated by authorized users of Customer in their use of the Services;
- executing documented instructions of Customer provided such instructions relate to and are consistent with the services provided by CitrusBits;
- addressing service issues or technical problems; and/or
- meeting any express requirement under applicable law, in which case CitrusBits shall, unless prohibited by applicable law from doing so, inform Customer of the legal requirement before Processing.
- Unauthorized Processing. CitrusBits will promptly inform Customer if, in its determination, any instruction or request by Customer violates applicable Data Protection Law.
- Legal Requests. CitrusBits will report to Customer without undue delay any request, demand, or order received by CitrusBits from a competent supervisory authority or Data Subject relating to the Processing of Personal Data
- Assistance and Cooperation. Taking into account the nature of the Processing, CitrusBits will assist Customer in complying with its obligations to respond to requests of Data Subjects under Data Protection Law by appropriate technical and organizational measures, insofar as this is possible such as assistance to the extent:
- the information is available to CitrusBits, and such information is not otherwise available to Customer, or the requested assistance cannot practicably be performed by Customer; and
- Customer acknowledges that CitrusBits has no responsibility to interact directly with any Data Subject or supervisory authority in respect of any request, demand, or order (except as expressly provided under applicable Data Protection Law or as otherwise agreed by the Parties in writing).
- Retention and Destruction of Personal Data. Subject to applicable legal retention obligations, upon termination or expiration of the Agreement, CitrusBits shall, at Customer’s choice, return or delete Personal Data in its possession or control in accordance with CitrusBits’ applicable data retention and deletion procedures. Personal Data contained in backup systems may be retained in accordance with CitrusBits’ standard backup retention cycle, provided that such Personal Data remains protected in accordance with this DPA and is not further Processed except as required for backup, recovery, security, or legal purposes.
- Confidentiality. CitrusBits will only rely on personnel in the Processing of Personal Data who are contractually or by statutory obligation bound to maintain confidentiality, ensure that access to Personal Data Processed is limited to those personnel who require such access to perform the applicable CitrusBits Services, and take commercially reasonable steps to ensure the reliability of personnel engaged in the Processing of Personal Data hereunder.
- Non-Delegation. CitrusBits will not delegate the Processing of Personal Data to a Sub-processor other than pursuant to Section 8 below.
6. Security
- Security Obligations. In connection with its Processing of Personal Data hereunder, CitrusBits will provide for and maintain appropriate administrative, physical, technical and organizational security measures for such Processing, which measures are intended to protect Personal Data against accidental, illegal, or unauthorized loss, use, destruction, alteration, modification, disclosure or access, and to ensure a level of security appropriate to the particular risks involved in the Processing. In this connection:
- Further details regarding the administrative, physical, technical and organizational security measures implemented and maintained by CitrusBits in connection with the Processing of Personal Data are described in Schedule 1 – Part 2.
- The technical and organizational measures implemented by CitrusBits may be updated from time to time to reflect technical progress, developments, and improvements in the protection of Personal Data, provided that CitrusBits will not materially decrease the overall level of security of the CitrusBits Services with respect to the Processing of Personal Data.
- Data Breach. CitrusBits will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA and will provide reasonable assistance to Customer in meeting its applicable Personal Data Breach notification and reporting obligations. CitrusBits will:
- investigate the Personal Data Breach and take reasonable measures to identify its nature and root cause(s) and, where such breach is caused by CitrusBits or a Sub-processor, take appropriate steps to contain, mitigate, remediate, and prevent recurrence of the Personal Data Breach; and
- as information becomes available, provide Customer with available information reasonably necessary for Customer to comply with its obligations under applicable Data Protection Law, including, where available, a description of the nature of the Personal Data Breach, the categories and approximate number of affected Data Subjects and Personal Data records, the likely consequences of the Personal Data Breach, and the measures taken or proposed to address and mitigate its effects. Such information may be provided in phases as it becomes available.
- To the extent that a Personal Data Breach is caused by Customer, a Customer affiliate or anyone acting for Customer, CitrusBits will inform Customer of the Personal Data Breach and provide information it discovers up to the stage at which it identifies that the breach is so caused. Further assistance to investigate such a Personal Data Breach is subject to additional agreement of the Parties.
7. Audits
- If required under applicable Data Protection Law or where reasonable grounds exist to suspect non-compliance with this DPA or applicable Data Protection Law on CitrusBits’ part, CitrusBits shall, upon Customer’s written request, make all necessary information available to demonstrate compliance hereof. This may include a summary audit report or certification produced by a reputable third party which demonstrates CitrusBits’ compliance in line with a generally accepted privacy and security framework. If required by applicable Data Protection Law or if, in Customer’s reasonable opinion, the scope of such reports is insufficient to demonstrate compliance with this DPA, then CitrusBits shall allow for audits, including inspections, to be performed by Customer (or an independent third party auditor mandated by Customer that is reasonably acceptable to CitrusBits and subject to signature of a confidentiality agreement with CitrusBits). It is agreed that:
- Customer will primarily rely on any applicable summary audit reports, certifications or other verifications already available, if any, to confirm CitrusBits’ compliance and avoid unnecessary repetitive audits;
- any audit will be on prior arrangement, having agreed the scope and duration of the audit with CitrusBits in advance, and will be conducted without unreasonably interfering with CitrusBits’ business activities, during regular business hours and subject to CitrusBits’ security policies;
- unless required by applicable Data Protection Law, an audit will be conducted not more than once in any twelve-month period;
- to the extent legally permitted, Customer will provide CitrusBits with a copy of the audit report. Customer agrees to use the report only for the purposes of meeting its regulatory audit requirements and/or confirming compliance with the requirements of this DPA. The audit reports shall be kept strictly confidential by the Parties;
8. Sub-processors
- CitrusBits may delegate the Processing of Personal Data to a Sub-processor which is bound to comply with provisions relating to confidentiality and data protection no less stringent than the terms of this DPA. CitrusBits shall remain fully liable for the conduct of any of its Sub-processors as for its own conduct.
- Subject to Section 8.1, Customer hereby gives its general written consent and authorization to CitrusBits to use the Sub-processors identified in Schedule 1 – Part 3 for processing of personal data for the purposes set forth in this DPA. CitrusBits shall provide Customer with notification of new Sub-processor(s) at least thirty (30) days before authorizing such new Sub-processor(s) to process personal data in connection with the provision of the applicable services.
- Customer may object to CitrusBits’ use of a new Sub-processor on reasonable grounds by notifying CitrusBits in writing within ten (10) business days after receiving the notification pursuant to Section 8.2. In the event Customer objects, CitrusBits will use commercially reasonable efforts to make available to Customer a change in the services or recommend a commercially reasonable change to Customer’s configuration or use of the services to avoid Processing of Personal Data by the objected-to Sub-processor without unreasonably burdening Customer. If CitrusBits is unable to make available such change, Customer may as its sole remedy terminate the portion of the Service(s) which cannot be provided by CitrusBits without the use of the objected-to Sub-processor, provided that the Parties shall always first use their mutual reasonable endeavors to resolve the issue at hand and Customer acknowledges that any termination shall be used as a last resort only.
9. Limitation of Liability
CitrusBits’ and all of its affiliates’ liability, taken together in the aggregate, arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the “Limitation of Liability” section in the Agreement, and any reference in such section to the liability of CitrusBits means the aggregate liability of CitrusBits and all of its affiliates under the Agreement and this DPA taken together.
10. Restricted Transfers
- Transfers. It is acknowledged that CitrusBits, either itself or using permitted Sub-processors, as part of its regular business, performs services from locations in countries and territories outside the EEA. This Section 10 sets forth the provisions on how Personal Data Processed under this DPA may be transferred from a country or territory within the EEA to, or accessed from, a country or territory outside the EEA, either directly or via onward transfer (each a “Transfer”) by CitrusBits, acting itself and/or through permitted Sub-processors, and Customer hereby gives its specific written mandate, authorization and instruction to CitrusBits for the purposes of conducting such Transfers when providing the services from locations outside the EEA, as set forth below.
- Transfer Agreement. For the purposes of Transfers of Personal Data under this DPA, Customer and CitrusBits incorporate the relevant Standard Contractual Clauses as if they were set out in full in this DPA (the “Data Transfer Agreement”) and under which Customer acts as the “data exporter” and CitrusBits, itself and/or through any permitted Sub-processor outside of the EEA, acts as the “data importer”. The Parties’ entry into or acceptance of the Agreement shall be deemed to constitute their acceptance of the Data Transfer Agreement. The terms of the relevant Data Transfer Agreements, if applicable, will prevail over conflicting or inconsistent terms in this DPA to the extent of the conflict or inconsistency.
- Transfer Limitations. Transfers of Personal Data shall only be permitted if:
- the Transfer is performed under and pursuant to the terms of the Data Transfer Agreement;
- the Transfer is to a country which has been found to ensure an adequate level of protection for the rights and freedoms of data subjects in relation to the Processing of Personal Data; or
- the Transfer is pursuant to a framework determined by the European Commission or other competent authority as ensuring an adequate level of protection for the rights and freedoms of data subjects and subject to the scope restrictions of any such determination, e.g. Binding Corporate Rules; or
- the Transfer is subject to a separate data transfer agreement incorporating the Standard Contractual Clauses applicable at the time of the relevant Transfer; or
- the Transfer is otherwise covered by a suitable framework recognized by the relevant supervisory authorities or courts as providing an adequate level of protection.
- Standard Contractual Clauses. Without prejudice to Section 10.3, the following provisions will be used to assist in the interpretation of the Standard Contractual Clauses incorporated as part of this DPA:
- Annexes to the EU SCCs and the UK SCCs are set out in Schedule 2;
- for the purposes of the EU SCCs: (i) Clause 7 (optional docking clause) shall not apply; (ii) Clause 9 Option 2 shall apply (general written authorization) and the Parties agree that the time period for submitting notice of changes shall be thirty (30) days
- for Swiss Personal Data, the Data Transfer Agreement shall be deemed modified in such a way, and limited solely to that necessary, so as not to exclude Data Subjects in Switzerland from the possibility of enforcing their rights in their place of habitual residence in accordance with Clause 18(c) of the Standard Contractual Clauses.
- for UK Personal Data, the UK Addendum shall apply to the applicable EU SCCs. The information required for Part 1 of the UK Addendum shall be deemed completed using the corresponding information contained in this DPA and Schedule 2. The applicable EU SCC module shall be Module 2 (Controller to Processor) or Module 3 (Processor to Processor), as applicable to the relevant Processing. The Parties agree that the provisions of Part 2 (Mandatory Clauses) of the UK Addendum are incorporated into and form part of this DPA. For the purposes of Table 4 of the UK Addendum, both the Data Exporter and the Data Importer may end the UK Addendum as set out in Section 19 of the UK Addendum.
11. Choice of Laws and Jurisdiction
This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, unless required otherwise by applicable Data Protection Law or the Standard Contractual Clauses.
SCHEDULE 1
PART 1: DETAILS OF PROCESSING
Item | Detail |
|---|---|
Nature and Purpose of Processing | CitrusBits will Process Personal Data as necessary to perform the Services pursuant to the Agreement, and as further instructed by Customer. This includes designing, building, testing, deploying, monitoring, supporting and maintaining the applications and systems specified in the Agreement or the applicable statement of work, and technical support and troubleshooting initiated by Customer. |
Duration of Processing | Subject to Section 5.5 of the DPA, CitrusBits will process Personal Data for the duration of the Agreement, unless otherwise agreed upon in writing. |
Categories of Data Subjects | The categories of Data Subjects whose Personal Data are Processed on behalf of the Customer consist of the following:
|
Categories of Personal Data Processed | The categories of Personal Data consist of the following:
|
Purposes for which Personal Data is Processed on Behalf of Customer |
|
PART 2: TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
CitrusBits shall maintain reasonable administrative, organizational, technical and physical controls designed to ensure the privacy, security and confidentiality of the Personal Data (“Safeguards”), that comply with this DPA and Data Protection Law.
Security Measures. CitrusBits will implement and maintain the technical and organizational measures described below, as applicable to the Services and the Processing of Personal Data:
# | Measure |
|---|---|
1 | Physical Access. CitrusBits will maintain physical access controls designed to secure relevant facilities, infrastructure, hard copy files, servers, backup systems, and equipment (including mobile devices) used to access Personal Data, including controls to prevent, detect, and respond to attacks, intrusions, or other system failures; |
2 | User Authentication. CitrusBits will maintain user authentication and access controls within operating systems, applications, equipment, and media; |
3 | Personnel Security. CitrusBits will maintain personnel security policies and practices restricting access to Personal Data, including written confidentiality agreements and background checks consistent with Data Protection Law for all personnel with access to Personal Data or who maintain, implement, or administer CitrusBits’ information security program and Safeguards; |
4 | Logging and Monitoring. CitrusBits will log and monitor appropriate details of access to Personal Data on networks, systems, and devices operated by CitrusBits. CitrusBits’ logging and monitoring systems shall meet generally accepted standards, and applicable access logs shall be retained for at least 90 days. |
5 | Malware Controls. CitrusBits will maintain reasonable and up-to-date controls to protect all networks, systems, and devices that access Personal Data from malware and unauthorized software; |
6 | Security Patches and Vulnerability Management. CitrusBits will maintain controls and processes designed to ensure that networks, systems, and devices (including operating systems and applications) that access Personal Data are up to date, including prompt implementation of security patches when issued; |
7 | User Account Management. CitrusBits will implement reasonable user account management procedures to securely create, amend, and delete user accounts on CitrusBits’s networks, systems, and devices, including monitoring redundant accounts and ensuring that information owners properly authorize all user account requests. |
8 | Infrastructure and Network Security. CitrusBits will implement and maintain appropriate infrastructure and network security controls designed to protect the confidentiality, integrity, and availability of Personal Data, including, as appropriate, endpoint security, network security controls, encryption, firewalls, intrusion detection and prevention mechanisms, communications security, backups, and other appropriate safeguards. |
9 | Secure Architecture and Design. CitrusBits will maintain appropriate security policies and controls applicable to relevant components of its IT infrastructure, including, as applicable, workstations, servers, storage systems, network devices, firewalls, routers, virtualization technologies, and cloud computing environments. |
10 | Business Continuity and Disaster Recovery. CitrusBits will maintain appropriate technical and organizational systems to preserve and continue business in the wake of a disaster. |
11 | Encryption Requirements. CitrusBits will use reasonable and appropriate encryption measures to protect Personal Data in transit over public or otherwise untrusted networks and Personal Data stored on portable devices or portable electronic media, and will apply encryption at rest where appropriate based on the nature and risk of the Processing. |
12 | Access Controls. CitrusBits will: (a) maintain reasonable controls to ensure that only individuals who have a legitimate need to access Personal Data under the Agreement will have such access; (b) promptly terminate an individual’s access to Personal Data when such access is no longer required for performance under the Agreement; (c) log the appropriate details of access and retain such records for no less than 90 days; and (d) be responsible for any unauthorized access to Personal Data under its or a Sub-processor’s custody or control. |
13 | Training and Supervision: CitrusBits will provide reasonable ongoing privacy and information protection training and supervision for all personnel who access Personal Data. |
PART 3: LIST OF SUB-PROCESSORS
Sub-processor | Type of Service | Location | More information |
|---|---|---|---|
Amazon Web Services (AWS) – Security & Monitoring Tools (includes GuardDuty, Security Hub, Inspector, and CloudWatch) | Cloud-based security monitoring, compliance, auditing, configuration, tracking, vulnerability detection (cloud/IaaS) | US | https://aws.amazon.com/trust-center/ |
Google Workspace | Productivity/email (SaaS) | US | https://cloud.google.com/trust-center |
SCHEDULE 2
ANNEX I
LIST OF PARTIES
Data Exporter(s):
The Customer identified in the applicable Agreement with CitrusBits, Inc. that incorporates this DPA, including the Customer’s name, address, and contact details as specified in the applicable Agreement or otherwise provided by Customer to CitrusBits.
Activities relevant to the data transferred under these Clauses: Provision of the CitrusBits Services as described in the Agreement
Role: Controller or Processor, as applicable to the relevant Processing.
Data Importer(s):
Item | Detail |
|---|---|
Name | CitrusBits, Inc. |
Address | 5994 West Las Positas Blvd, Suite 101, Pleasanton, CA 94588, United States of America |
Contact for data protection matters | |
Activities relevant to the transfer | Activities relevant to the data transferred under these Clauses: Provision of the CitrusBits Services as described in the Agreement |
Role | Processor or Sub-processor, as applicable to the relevant Processing. |
DESCRIPTION OF TRANSFER
Item | Detail |
|---|---|
Categories of data subjects whose personal data is transferred | The categories described in Schedule 1 – Part 1 of the DPA. |
Categories of personal data transferred | The categories described in Schedule 1 – Part 1 of the DPA. |
The frequency of the transfer | Continuous for the duration of the Processing under the DPA. |
Nature of the processing / Purpose(s) of the data transfer and further processing | The nature and purpose of processing is described in Schedule 1 – Part 1 of the DPA. |
The period for which the personal data will be retained | Personal Data will be retained for the duration of the Processing under the Agreement and, following termination or expiration, will be returned or deleted in accordance with Section 5.5 of the DPA and applicable legal retention requirements. |
For transfers to (sub-)processors, also specify subject matter, nature and duration of the processing | The subject matter and nature described in Schedule 1 – Part 1 of the DPA between the parties. |
COMPETENT SUPERVISORY AUTHORITY
The competent supervisory authority shall be determined in accordance with Clause 13 of the EU Standard Contractual Clauses.
ANNEX II
TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
See the security measures described in Schedule 1 – Part 2 of the DPA
ANNEX III
LIST OF SUB-PROCESSORS
As described in Schedule 1 – Part 3 of the DPA.