Updated 1 September 2023
This Dataweavers Data Processing Addendum ("DPA"), forms part of the Dataweavers Managed Services Agreement (“Agreement”) between Dataweavers Pty Ltd (“Dataweavers”) and Customer ("Customer"), together referred to as the Parties (“Parties”), and applies where Dataweavers will process Customer Data when providing Services under the Agreement. All capitalized terms not defined in this DPA shall have the meanings set forth in the Agreement.
Upon Dataweavers’ receipt of a validly completed DPA by Customer, this DPA will become effective and is legally binding.
1. Definitions
Affiliate means an entity that directly or indirectly Controls, is Controlled by or is under common Control with an entity.
Agreement means the written or electronic agreement between Customer and Dataweavers for the provision of the Services to Customer.
CCPA means the California Consumer Privacy Act, Cal. Civ. Code §1798.100 et seq., and its implementing regulations.
Control means an ownership, voting or similar interest representing fifty percent (50%) or more of the total interests then outstanding of the entity in question. The term "Controlled" will be construed accordingly.
Customer Data means data owned or supplied by the Customer and stored on the systems of Dataweavers or a Hosting Service as a result of the Customer’s usage of the Product, including Personal Data, that Dataweavers processes on behalf of Customer through Customer’s use of the Managed Services.
Data Processing Addendum means the data processing addendum made available on Dataweavers website at https://www.dataweavers.com/legal/dpa, as amended from time to time.
Data Processing Consent Form means the Data Processing Consent Form containing the relevant information required for completion of Annexes I to III of the SCCs in ANNEX D: Data Processing Consent Form as updated or notified to you by us in writing from time to time.
Data Subject or Data Subjects means an identified or identifiable natural person who can be identified directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data or an online identifier or to one or more factors specific to his or her physical, physiological, mental, economic, cultural or social identity. A legal person may qualify as a Data Subject under the Data Protection Laws of specific jurisdictions. This includes, to the extent applicable, any analogous variations of such terminology, such as “Consumer” as may relevant under US state laws.
Data Protection Laws means all data protection and privacy laws and regulations applicable to the Processing of Personal Data under the Agreement, including, where applicable, the laws of the European Union, the EEA and their member states, Switzerland, Australia and the United Kingdom that apply to the Processing of Personal Data, including but not limited to any applicable privacy and information security laws and regulations such as:
EEA means the European Economic Area.
Personal Data means any Customer Data relating to an identified or an identifiable natural person or as otherwise defined under Data Protection Laws. For the sake of clarity, this includes “Personal Information” or analogous variations of such terminology within the meaning of applicable US state laws, to the extent that these may be applicable and “Personal Information” as defined in the Australian Privacy Act 1988 (Cth).
Security Incident means any unauthorized or unlawful breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Customer Data transmitted, stored or otherwise Processed.
Service Provider has the meaning set forth in Section 1798.140(v) of the CCPA.
Services as used in this DPA means the “Managed Services” as defined in the Agreement.
Standard Contractual Clauses or SCCs means:
Table 1 to the IDTA shall be deemed to include the information at the beginning of this Agreement. Table 2 to the IDTA shall refer to the contractual clauses set forth in clause 14.1(n)(i)(A) above. Table 3 to the IDTA shall refer to the information contained in the applicable Data Processing Consent Form for such transfer that forms part of this Agreement. For purposes of Table 4 to the IDTA, the parties agree that Exporter may end this DPA as set out in Section 19 of the IDTA;
and any amendment or replacement of these terms (as applicable) published from time to time;
Subprocessor means any Data Processor or Service Provider engaged by Dataweavers or its Affiliates to assist in fulfilling its obligations with respect to providing the Services pursuant to the Agreement or this DPA. Subprocessors may include third parties or Affiliates of Dataweavers.
Controller, Processor, Processing, process, processes and Processed have the meanings given by applicable Data Protection Laws.
2. Scope of this DPA
2.1 Scope
This DPA applies where Dataweavers processes Customer Data, including Personal Data, on behalf of Customer in the course of providing Services to the Customer pursuant to the Agreement
2.2 Application to Australia
For clarity, references to provisions or concepts of the GDPR in this DPA will be deemed to be references to equivalent or corresponding provisions of, and concepts under, the applicable Data Protection Laws. For example, in respect of Australia:
3. Roles and Scope of Processing
3.1 Role of the PartiesAs between Dataweavers and Customer, Customer is the Data Controller of Customer Data and Dataweavers shall process Customer Data only as a Data Processor acting on behalf of Customer.
3.2 Customer’s obligationsCustomer shall have the sole and exclusive authority to determine the purposes and means of Processing Customer Data transferred or otherwise disclosed to Dataweavers. As between the Parties, the Customer shall have the sole responsibility for the accuracy, quality and legality of Personal Data as required by applicable Data Protection Laws and the means by which the Customer acquired Personal Data, including the provision of proper notice and obtaining consents where appropriate for Dataweavers’ Processing.
3.3 Dataweavers Processing of Customer Data3.4 Details of Data Processing
Customer agrees that in order to provide the Services, Dataweavers may engage Subprocessors to process Customer Data. A list of Dataweavers’ current authorized Subprocessors is found in ANNEX B: Subprocessors.
4.2 Subprocessor ObligationsWhere Dataweavers authorizes any Subprocessor as described in Section 4.1:
Dataweavers has implemented and will maintain appropriate technical and organizational security measures to protect Customer Data from Security Incidents and to preserve the security and confidentiality of the Customer Data ("Security Measures"). The Security Measures applicable to the Services are set forth in ANNEX A: Technical and organizational security measures as updated or replaced from time to time in accordance with Section 5.2. Customer is responsible for reviewing the information made available by Dataweavers relating to data security and making an independent determination as to whether the Services meet Customer’s requirements and legal obligations under Data Protection Laws, taking into account the nature, scope, context and purposes of processing, the risks associated with the Personal Data and the Data Protection Laws.
5.2 Updates to Security MeasuresDataweavers has implemented a procedure for the regular testing, inspection, assessment and evaluation of the effectiveness of Dataweavers’ Security Measures. Accordingly, Customer acknowledges that the Security Measures are subject to technical progress and development and that Dataweavers may update or modify the Security Measures from time to time provided that such updates and modifications do not result in the degradation of the overall security of the Services purchased by the Customer. Such updates to the Security Measures will be made available to Customer upon its reasonable request.
5.3 PersonnelDataweavers shall take reasonable steps to ensure the reliability of any employee, agent, contractor or Subprocessor who may have access to Customer Data, ensuring that access is strictly limited on a least-privilege basis to those individuals who need to know or need to have access to Customer Data as is necessary for the provision of the Services under the Agreement. Further, Dataweavers shall ensure that personnel with access to Customer Data are under an appropriate obligation of confidentiality and that such personnel have received appropriate data protection and security training pertaining to the responsibilities of their role.
5.4 Customer ResponsibilitiesNotwithstanding the above, Customer agrees that except as provided by this DPA, Customer is responsible for its secure use of the Services, including securing its account authentication credentials, protecting the security of Customer Data when in transit to and from the Services and taking any appropriate steps to securely encrypt or backup any Customer Data uploaded to the Services.
5.5 Sufficient EvidenceUpon the reasonable request of Customer, Dataweavers shall provide Customer with sufficient information to enable Customer to demonstrate that the necessary technical and organizational security measures (as further detailed in Annex A) have been implemented.
5.6 Security Incident ResponseUpon becoming aware of a Security Incident, Dataweavers will notify Customer without undue delay (and no later than 48 hours after becoming aware of the Security Incident) and will provide information relating to the Security Incident as it becomes known or as is reasonably requested by Customer including:
Dataweavers shall provide reasonable assistance to Customer, in the event Customer is required under Data Protection Laws to notify a supervisory authority or any Data Subjects of a Security Incident. Dataweavers reserves the right to charge Customer for this assistance should it become overly burdensome.
6. Reports and Audit
6.1 Upon Customer’s request, Dataweavers will make available a statement from its Security Team containing all information necessary to demonstrate compliance with this DPA (a “Dataweavers Report”) and any documentation pursuant to Section 10.1.
6.2 No more than once per year, Customer may conduct reviews of Dataweavers’ documents and systems, by way of desk-based questionnaires and phone conferences with Dataweavers personnel.
6.3 Notwithstanding the foregoing, Customer will have the right, at its expense, to conduct an onsite audit, only in the event that:
7. International Transfers
7.1 Data Centre locations. Dataweavers shall store Customer Data only in the selected Azure data centre region/s outlined in Schedule 2 of the Dataweavers Managed Services Agreement (“Agreement”) unless notified otherwise. For sake of clarity, Dataweavers makes no warranties for the appropriateness of a selected data centre.
7.2 Data Transfers. If applicable, Dataweavers will at all times ensure that any Customer Data which is transferred is done so in compliance with adequate transfer mechanisms. Further, Dataweavers will ensure that an adequate level of protection is provided for the Customer Data Processed, and that processing is done in accordance with the requirements of Data Protection Laws.
7.3 Standard Contractual Clauses. The Parties agree that the Standard Contractual Clauses shall be the adequate transfer mechanism pursuant to Section 7.3 above and apply to Customer Data that is transferred from the EEA and/or Switzerland to outside the EEA and Switzerland, either directly or via onward transfer, to any country or recipient not recognized by the European Commission as providing an adequate level of protection for personal data (as described in the Data Protection Laws).
8. Return or Deletion of Data
8.1 Upon termination or expiration of the Agreement, Customer may, within 30 days of the contract expiration date, require Dataweavers to:
9. Privacy Rights
9.1 To the extent that Customer is unable to independently access the relevant Customer Data within the Services, Dataweavers shall provide reasonable and timely cooperation to assist Customer to respond to any requests from individuals or applicable data protection authorities relating to the Processing of Personal Data under the Agreement. In the case of complex or voluminous enquiries that can be managed by Customer through access within the Services but where Customer is requesting additional assistance beyond Dataweavers’ compliance requirements, Dataweavers reserves the right to charge Customer for reasonable expenses. In the event that any such request is made directly to Dataweavers, a Dataweavers Affiliate or any Subprocessor, Dataweavers shall not respond to such communication directly without Customer's prior authorization, unless legally compelled to do so. If Dataweavers is required to respond to such a request, Dataweavers will promptly notify Customer and provide it with a copy of the request unless legally prohibited from doing so.
9.2 If a law enforcement agency sends Dataweavers a demand for Customer Data (for example, through a subpoena or court order), Dataweavers will attempt to redirect the law enforcement agency to request that data directly from Customer. As part of this effort, Dataweavers may provide Customer’s basic contact information to the law enforcement agency. If compelled to disclose Customer Data to a law enforcement agency, then Dataweavers will give Customer reasonable notice of the demand to allow Customer to seek a protective order or other appropriate remedy unless Dataweavers is legally prohibited from doing so.
9.3 Dataweavers shall, upon Customer request and at Customer’s expense, provide reasonable assistance to Customer needed to fulfil any Customer obligation under the applicable Data Protection Laws to perform any data protection impact assessments. Dataweavers shall, upon Customer request, provide reasonable assistance to Customer in any prior consultations with supervising authorities or other competent data privacy authorities, which Customer reasonably considers to be required of Customer under Data Protection Laws.
10. Privacy and Data Protection
10.1 Dataweavers maintains a privacy program that includes dedicated resourcing, audit and review processes designed to implement appropriate privacy controls and procedures, including but not limited to:
11. Compliance with this DPA
11.1 Dataweavers shall maintain appropriate documentation necessary to demonstrate Dataweavers’ compliance with the terms of the Agreement (including certifications, independent audit report summaries and policy tables of content) and make such documentation, subject to redaction of non-relevant Confidential Information, available to Customer upon request.
11.2 Upon Customer request, Dataweavers shall provide to Customer such copies of Dataweavers’ agreements with Subprocessors referred to in Section 4 (which may be redacted to remove Confidential information not relevant to the requirements of this DPA) as Customer may request annually.
11.3 Each Party shall appoint an individual within its organization authorized to respond from time to time to enquiries regarding the Personal Data and each Party shall deal with such enquiries promptly.
11.4 Dataweavers shall make reasonable efforts to notify Customer if it becomes aware of any possible violation of, or inability to comply with, this DPA or Data Protection Laws.
12. Contact
12.1 Customer may contact Dataweavers’ security team in relation to any security incident, notification or security question by emailing continuity@dataweavers.com.
12.2 All other queries relating to this DPA should be directed to continuity@dataweavers.com.
13. General
13.1 For the avoidance of doubt, any claim or remedies either party may have against the other party, any of its Affiliates and their respective employees, agents and Subprocessors arising under or in connection with this DPA, including any fines or damages payable under Data Protection Laws will be subject to the limitation of liability provisions (including any agreed aggregate financial cap) set forth in the Agreement.No FAQs found for the selected category.