This Data Processing Addendum (“DPA”) supplements the Terms of Service (the “Agreement”) entered into by and between the customer signing this DPA (“Customer”) and SupportMagic, Inc. (“Company”) By executing the DPA in accordance with Section 11 herein, Customer enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws (defined below), in the name and on behalf of its Affiliates (defined below), if any. This DPA incorporates the terms of the Agreement, and any terms not defined in this DPA shall have the meaning set forth in the Agreement.
Details of Processing
Nature and Purpose of Processing: Company will process Customer’s Personal Data as necessary to provide the Services under the Agreement, for the purposes specified in the Agreement and this DPA, and in accordance with Customer’s instructions as set forth in this DPA. The nature of processing includes, without limitation:
Duration of Processing: Company will process Customer’s Personal Data as long as required (i) to provide the Services to Customer under the Agreement; (ii) for Company’s legitimate business needs; or (iii) by applicable law or regulation. Company Account Data and Company Usage Data will be processed and stored as set forth in Company’s privacy policy.
Categories of Data Subjects: Customer’s employees, consultants, contractors, and/or agents.
Categories of Personal Data: Company processes Personal Data contained in Company Account Data, Company Usage Data, and any Personal Data provided by Customer (including any Personal Data Customer collects from its end users and processes through its use of the Services) or collected by Company in order to provide the Services or as otherwise set forth in the Agreement or this DPA. Categories of Personal Data include name, email, job title, username, Company device identifiers (e.g. serial number), IP address for company device, installed applications for company device, background check verification records (at discretion of Controller), security training records.
Sensitive Data or Special Categories of Data: Customers are prohibited from providing sensitive personal data or special categories of data to Company, including without limitation, any data which discloses the criminal history.
The following includes the information required by Annex I and Annex III of the EU SCCs, and Table 1, Annex 1A, and Annex 1B of the UK Addendum.
Data exporter(s):
Name: Customer, as stated and defined in the applicable Order (as such term is defined under the Agreement)
Trading Name (if different):
Address: Customer’s registered business address and any address provided to Linear at the time that Customer uses the Services.
Official Registration Number (if any) (company number or similar identifier):
Contact person’s name, position and contact details: Customer’s contact for the purposes of the SCC’s will be the contact of the person that properly accepts and binds Customer to the Agreement unless another contact person’s information is specifically provided to Linear in writing.
Activities relevant to the data transferred under these Clauses: As described in Section 2 of the DPA.
Signature and date: The UK SCC’s and EU SCC’s will be considered executed upon Customer’s proper acceptance of the Agreement.
Role (controller/processor): Controller
Data importer(s):
Name: SupportMagic, Inc.
Address and contact information: 6538 Collins Ave, Miami Beach, FL 33141; privacy@supportmagic.ai
Activities relevant to the data transferred under these Clauses: ... As described in Section 2 of the DPA.
Signature and date:
Role (controller/processor): As described in Section 2 of the DPA.
Data subjects
As described in Exhibit A of the DPA
Categories of Personal Data
As described in Exhibit A of the DPA
Special Category Personal Data (if applicable)
As described in Exhibit A of the DPA
Nature of the Processing
As described in Exhibit A of the DPA
Purposes of Processing
As described in Exhibit A of the DPA
Duration of Processing and Retention (or the criteria to determine such period)
As described in Exhibit A of the DPA
Frequency of the transfer
As necessary to provide perform all obligations and rights with respect to Personal Data as provided in the Agreement or DPA
Recipients of Personal Data Transferred to the Data Importer
Company will maintain a list of Authorized Sub-Processors at: https://trust.supportmagic.ai/subprocessors
Description of the Technical and Organisational Security Measures implemented by the Data Importer
The following includes the information required by Annex II of the EU SCCs and Annex II of the UK Addendum.
UK Addendum
International Data Transfer Addendum to the EU Commission Standard Contractual Clauses
Table 1: Parties
Start Date
This UK Addendum shall have the same effective date as the DPA
The Parties
Exporter
Importer
Parties’ Details
Customer
Company
Key Contact
See Exhibit B of this DPA
See Exhibit B of this DPA
EU SCCs
The Version of the Approved EU SCCs which this UK Addendum is appended to as defined in the DPA and completed by Section 6.2 and 6.3 of the DPA.
“Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this UK Addendum is set out in:
Annex 1A: List of Parties
As per Table 1 above
Annex 2B: Description of Transfer
See Exhibit B of this DPA
Annex II: Technical and organisational measures including technical and organisational measures to ensure the security of the data:
See Exhibit C of this DPA
Annex III: List of Sub processors (Modules 2 and 3 only):
See Exhibit B of this DPA
Ending this UK Addendum when the Approved UK Addendum changes
x Importer
x Exporter
☐Neither Party
UK Addendum
means this International Data Transfer Addendum incorporating the EU SCCs, attached to the DPA as Exhibit D.
EU SCCs
means the version(s) of the Approved EU SCCs which this UK Addendum is appended to, as set out in Table 2, including the Appendix Information
Appendix Information
shall be as set out in Table 3
Appropriate Safeguards
means the standard of protection over the personal data and of data subjects’ rights, which is required by UK Data Protection Laws when you are making an ex-UK Transfer relying on standard data protection clauses under Article 46(2)(d) UK GDPR.
Approved UK Addendum
means the template Addendum issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as may be revised under Section 18 of the UK Addendum.
Approved EU SCCs
means the standard contractual clauses approved by the European Commission in Commission Decision 2021/914 dated 4 June 2021, for transfers of personal data to countries not otherwise recognized as offering an adequate level of protection for personal data by the European Commission (as amended and updated from time to time).
ICO
means the Information Commissioner of the United Kingdom.
ex-UK Transfer
shall have the same definition as set forth in the DPA .
UK
means the United Kingdom of Great Britain and Northern Ireland
UK Data Protection Laws
means all laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the UK GDPR and the Data Protection Act 2018.
UK GDPR
shall have the definition set forth in the DPA.
This UK Addendum incorporates the EU SCCs which are amended to the extent necessary so that:
This UK Addendum incorporates the EU SCCs which are amended to the extent necessary so that:
The revised Approved UK Addendum will specify the start date from which the changes to the Approved UK Addendum are effective and whether the parties need to review this UK Addendum including the Appendix Information. This UK Addendum is automatically amended as set out in the revised Approved UK Addendum from the start date specified.