This Data Processing Agreement (“DPA”) governs the data processing relationship between Clever Prototypes LLC (unless otherwise indicated below, the “Provider” or “Processor”) and the Customer (unless otherwise indicated below, the “Controller”).
2.1 Provider as Processor. In situations where Customer is a Controller of the Customer Personal Data, Provider will be deemed a Processor that is Processing Personal Data on behalf of Customer.
2.2 Provider as Subprocessor. In situations where Customer is a Processor of the Customer Personal Data, Provider will be deemed a Subprocessor of the Customer Personal Data.
3.1 Processing Details. Appendix 2 describes the subject matter, nature, purpose, and duration of this Processing, as well as the Categories of Personal Data collected and Categories of Data Subjects.
3.2 Processing Instructions. Customer instructs Provider to Process Customer Personal Data: (a) to provide and maintain the Service; (b) as may be further specified through Customer’s use of the Service; (c) as documented in the Agreement; and (d) as documented in any other written instructions given by Customer and acknowledged by Provider about Processing Customer Personal Data under this DPA. Provider will abide by these instructions unless prohibited from doing so by Applicable Laws. Provider will immediately inform Customer if it is unable to follow the Processing instructions. If, in the Provider’s opinion, an instruction infringes the GDPR or other Applicable Data Protection Laws, the Provider will immediately inform Customer. Customer has given and will only give instructions that comply with Applicable Laws.
3.3 Processing by Provider. Provider will only Process Customer Personal Data in accordance with this DPA and Customer’s documented instructions. Customer, as Controller, determines the purposes and means of Processing Customer Personal Data. If Provider updates the Service to modify existing functionality or add new products, features, or functionality, Provider may propose corresponding changes to the Categories of Data Subjects, Categories of Personal Data, Special Category Data, Special Category Data Restrictions or Safeguards, Frequency of Transfer, Nature and Purpose of Processing, or Duration of Processing, and will notify Customer of any such changes in advance. Provider will not make any change that materially expands the scope of Processing, or that changes the Nature and Purpose of Processing, the Categories of Personal Data, or the Categories of Data Subjects, without Customer’s prior written consent. Where Customer does not consent to a change that Provider reasonably requires to deliver the updated Service, either party may address the matter under the change-control or termination provisions of the Agreement.
3.4 Customer Processing. Where Customer is a Processor and Provider is a Subprocessor, Customer will comply with all Applicable Laws that apply to Customer’s Processing of Customer Personal Data. Customer’s agreement with its Controller will similarly require Customer to comply with all Applicable Laws that apply to Customer as a Processor. In addition, Customer will comply with the Subprocessor requirements in Customer’s agreement with its Controller.
3.5 Consent to Processing. Customer has complied with and will continue to comply with all Applicable Data Protection Laws concerning its provision of Customer Personal Data to Provider and/or the Service, including making all disclosures, obtaining all consents, providing adequate choice, and implementing relevant safeguards required under Applicable Data Protection Laws.
3.6 Confidentiality. Provider will ensure that any person it authorizes to Process Customer Personal Data, including its employees, agents, and contractors, has committed to a binding obligation of confidentiality with respect to the Customer Personal Data or is under an appropriate statutory obligation of confidentiality. Provider will limit access to Customer Personal Data to those personnel who need access to perform the Service.
3.7 Subprocessors.
4.1 Authorization. Customer agrees that Provider may transfer Customer Personal Data outside the EEA, the United Kingdom, or other relevant geographic territory as necessary to provide the Service. If Provider transfers Customer Personal Data to a territory for which the European Commission or other relevant supervisory authority has not issued an adequacy decision, Provider will implement appropriate safeguards for the transfer of Customer Personal Data to that territory consistent with Applicable Data Protection Laws.
4.2 Ex-EEA Transfers. Customer and Provider agree that if the GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the EEA to Provider outside of the EEA, and the transfer is not governed by an adequacy decision made by the European Commission, then by entering into this DPA, Customer and Provider are deemed to have signed the EEA SCCs and their Annexes, which are incorporated by reference. Any such transfer is made pursuant to the EEA SCCs, which are completed as follows:
4.3 Ex-UK Transfers. Customer and Provider agree that if the UK GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the United Kingdom to Provider outside of the United Kingdom, and the transfer is not governed by an adequacy decision made by the United Kingdom Secretary of State, then by entering into this DPA, Customer and Provider are deemed to have signed the UK Addendum and their Annexes, which are incorporated by reference. Any such transfer is made pursuant to the UK Addendum, which is completed as follows:
4.4 Other International Transfers. For Personal Data transfers where Swiss law (and not the law in any EEA member state or the United Kingdom) applies to the international nature of the transfer, references to the GDPR in Clause 4 of the EEA SCCs are, to the extent legally required, amended to refer to the Swiss Federal Data Protection Act or its successor instead, and the concept of supervisory authority will include the Swiss Federal Data Protection and Information Commissioner.
Provider will implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR and other Applicable Data Protection Laws, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to data subjects. These measures are described in Appendix 3, and Provider will not materially decrease the overall level of protection during the term of this DPA.
Upon becoming aware of any Security Incident, Provider will: (a) notify Customer without undue delay when feasible, but no later than 72 hours after becoming aware of the Security Incident; (b) provide timely information about the Security Incident as it becomes known or as is reasonably requested by Customer; and (c) promptly take reasonable steps to contain and investigate the Security Incident. Provider’s notification of or response to a Security Incident as required by this DPA will not be construed as an acknowledgment by Provider of any fault or liability for the Security Incident.
7.1 Audit Rights. Provider will give Customer all information reasonably necessary to demonstrate its compliance with this DPA and Provider will allow for and contribute to audits—limited to one audit annually—including appropriately-scoped inspections by Customer, to assess Provider’s compliance with this DPA. However, Provider may restrict access to data or information if Customer’s access to the information would negatively impact Provider’s intellectual property rights, confidentiality obligations, or other obligations under Applicable Laws. Customer acknowledges and agrees that it will ordinarily exercise its audit rights under this DPA and any audit rights granted by Applicable Data Protection Laws by instructing Provider to comply with the reporting and due diligence requirements below; provided that, where the GDPR applies and the reporting and due diligence measures are insufficient to demonstrate compliance with Article 28 of the GDPR, Customer (or an independent auditor mandated by Customer) retains the right to conduct an audit, including on-site inspections, of Provider’s Processing on reasonable prior written notice. Provider will maintain records of its compliance with this DPA for 3 years after the DPA ends.
7.2 Security Reports. Customer acknowledges that Provider is regularly audited against the standards defined in the Security Policy by independent third-party auditors. Upon written request, Provider will give Customer, on a confidential basis, a summary copy of its then-current Report so that Customer can verify Provider’s compliance with the standards defined in the Security Policy.
7.3 Security Due Diligence. In addition to the Report, Provider will respond to reasonable requests for information made by Customer to confirm Provider’s compliance with this DPA, including responses to information security, due diligence, and audit questionnaires, or by giving additional information about its information security program. All such requests must be in writing and made to the Provider Security Contact and may only be made once a year.
8.1 Response to Inquiries. If Provider receives any inquiry or request from anyone else about the Processing of Customer Personal Data, Provider will notify Customer about the request and Provider will not respond to the request without Customer’s prior consent. Examples of these kinds of inquiries and requests include a judicial or administrative or regulatory agency order about Customer Personal Data where notifying Customer is not prohibited by Applicable Law, or a request from a data subject. If allowed by Applicable Law, Provider will follow Customer’s reasonable instructions about these requests, including providing status updates and other information reasonably requested by Customer. If a data subject makes a valid request under Applicable Data Protection Laws to exercise any of its rights, including the rights of access, rectification, erasure, restriction of Processing, data portability, objection, and the right not to be subject to automated decision-making, or to delete or opt out of Customer’s giving of Customer Personal Data to Provider, Provider will, taking into account the nature of the Processing, reasonably assist Customer by reasonably appropriate technical and organizational measures, insofar as possible, in fulfilling Customer’s obligation to respond to the request according to the Applicable Data Protection Law. Provider will cooperate with and provide reasonable assistance to Customer, at Customer’s expense, in any legal response or other procedural action taken by Customer in response to a third-party request about Provider’s Processing of Customer Personal Data under this DPA.
8.2 DPIAs and DTIAs. If required by Applicable Data Protection Laws, Provider will reasonably assist Customer in conducting any mandated data protection impact assessments or data transfer impact assessments and consultations with relevant data protection authorities, taking into consideration the nature of the Processing and Customer Personal Data.
To the extent California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq (“CCPA”) applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement, which constitutes a business purpose. Provider will not sell any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph.
10.1 Deletion by Customer. Provider will enable Customer to delete Customer Personal Data in a manner consistent with the functionality of the Services. Provider will comply with this instruction as soon as reasonably practicable except where further storage of Customer Personal Data is required by Applicable Law.
10.2 Deletion at DPA Expiration.
11.1 Liability Caps and Damages Waiver. To the maximum extent permitted under Applicable Data Protection Laws, each party’s total cumulative liability to the other party arising out of or related to this DPA will be subject to the waivers, exclusions, and limitations of liability stated in the Agreement.
11.2 Related-Party Claims. Any claims made against Provider or its Affiliates arising out of or related to this DPA may only be brought by the Customer entity that is a party to the Agreement.
11.3 Exceptions. This DPA does not limit any liability to an individual about the individual’s data protection rights under Applicable Data Protection Laws. In addition, this DPA does not limit any liability between the parties for violations of the EEA SCCs or UK Addendum.
This DPA forms part of and supplements the Agreement. If there is any inconsistency between this DPA, the Agreement, or any of their parts, the part listed earlier will control over the part listed later for that inconsistency: (1) the EEA SCCs or the UK Addendum, (2) this DPA, and then (3) the Agreement.
This DPA will start when Provider and Customer sign or electronically accept the Agreement and will continue until the Agreement expires or is terminated. However, Provider and Customer will each remain subject to the obligations in this DPA and Applicable Data Protection Laws until Customer stops transferring Customer Personal Data to Provider and Provider stops Processing Customer Personal Data.
Service: Storyboard That – an online digital storyboard creator, as made available to Customer under the Agreement.
Categories of Data Subjects:
Categories of Personal Data:
In the Education Edition, student email addresses are not knowingly collected and student personal data is minimized.
Special Category Data: None known collected. The Service is not designed or intended to process special category data.
Special Category Data Restrictions or Safeguards: Not applicable.
Frequency of Transfer: Continuous, for the duration of the Agreement.
Nature and Purpose of Processing: Provider hosts and stores Customer Personal Data and processes it to create and administer user accounts, authenticate users, enable users to create and store storyboards and other content, organize users into classes or teams, and provide related support. Provider processes Customer Personal Data only to deliver the Service and on Customer’s documented instructions.
Duration of Processing: For the term of the Agreement and until Customer Personal Data is returned or deleted in accordance with this DPA.
Competent Supervisory Authority: Based on the data exporter / Customer’s place of establishment in accordance with Clause 13 of the EEA SCCs.
Provider maintains technical and organizational measures appropriate to the risk, including: