1. Background
1.1 This Data Processing Addendum (DPA) is an addendum to and forms part of the StorifyMe Terms of Service or another agreement under which StorifyMe provides services (StorifyMe Services) to Customer or otherwise collaborates with Customer (such as a StorifyMe partner).
1.2 Each such agreement referred to in 1.1 above is a Main Agreement. Customer refers to the party in the Main Agreement other than StorifyMe. For purposes of processing Customer Data, StorifyMe refers to the StorifyMe entity that is a party to the Main Agreement and such entity’s affiliates that are under common control with, controlled by or controlling that entity.
1.3 Capitalized terms used in this DPA have the meaning set forth herein. Capitalized terms not otherwise defined in this DPA have the meaning given to them in the Main Agreement. Terms that are not capitalized are interpreted in accordance with applicable data protection and privacy laws.
1.4 This DPA does not change the terms of the Main Agreement but only supplements the Main Agreement for purposes of personal data processing.
1.5 This DPA applies to processing European personal data (that is, any personal data subject to the GDPR). GDPR (General Data Protection Regulation) means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
1.6 This DPA is subject to the governing law and jurisdiction provisions in the Main Agreement unless and to the extent required otherwise by applicable data protection and privacy laws.
1.7 This DPA becomes effective and remains in effect for as long as personal data is processed as per the Main Agreement.
2. Scope of Application
2.1 While providing StorifyMe Services, it may be necessary for StorifyMe to process personal data for Customer (Customer Data, see Annex 1). StorifyMe is the data processor of such personal data and Customer is the data controller.
2.2 In case of contradictions between this DPA and the provisions of other agreements, in particular the Main Agreement, the provisions of this DPA prevail. The provisions of the Standard Contractual Clauses attached in Annex 3 prevail, where applicable, over this DPA to the extent of any discrepancy between the two.
2.3 This DPA does not apply to Service Data which means any data relating to the Customer’s use, support and/or operation of StorifyMe Services and StorifyMe websites, including information relating to activity logs, use patterns, cookie data or other information regarding use of StorifyMe Services and StorifyMe websites. To the extent any Service Data is considered personal data under applicable data protection and privacy laws, StorifyMe is responsible as a data controller, and processes such data in accordance with its privacy notice available at www.storifyme.com/legal and applicable data protection and privacy laws.
3. Subject, Scope and Duration of Processing
3.1 StorifyMe processes Customer Data exclusively on behalf of Customer and on Customer's documented instructions in accordance with article 28 (3) (a) GDPR.
3.2 Annex 1 to this DPA contains a comprehensive list of the types of Customer Data that StorifyMe may process, in which manner, for what purposes, and to which categories of data subjects such data relate.
4. Scope of Customer’s Authority to Issue Instructions
4.1 Instructions related to processing Customer Data must be documented. Customer’s instructions are exclusively included in the Main Agreement and this DPA or given via the authorized use of StorifyMe Services.
4.2 StorifyMe must inform Customer immediately if in StorifyMe’s reasonable opinion Customer’s instructions conflict with this DPA, an earlier instruction or applicable data protection laws.
4.3 Customer hereby instructs StorifyMe to process Customer Data and, in particular, to transfer Customer Data to any country or territory as reasonably necessary for the provision of StorifyMe Services in accordance with the Main Agreement and this DPA.
5. Obligations and Legal Status of Customer as Data Controller
5.1 Customer is responsible for its compliance with applicable laws and the lawful processing of Customer Data in relation to the data subjects as well as for safeguarding the rights of data subjects to the extent that applicable data protection laws do not impose direct responsibility on StorifyMe.
5.2 As between the parties, Customer is and remains the owner of Customer Data and the holder of all rights relating to Customer Data.
6. Security of Processing
6.1 StorifyMe takes appropriate technical and organizational measures to ensure a suitable level of protection for Customer Data corresponding to the risk of the respective data processing. This must be in consideration of the state of the art, implementation costs and the type, scope, circumstances, and aims of the processing as well as the varying likelihood and severity of risk to the rights and freedoms of data subjects.
6.2 Customer has assessed the security measures offered by StorifyMe to meet the standards required by applicable data protection and privacy laws as at the effective date hereof. Such technical and organizational measures are specified in Annex 2 to this DPA and/or in the Main Agreement and StorifyMe will maintain those (or effectively similar) measures during the term. All changes to technical and organizational measures must be reasonably documented by StorifyMe.
7. Sub-processors
7.1 Customer hereby authorizes StorifyMe to appoint sub-processors in accordance with this section and subject to any restrictions herein or in the Main Agreement.
7.2 StorifyMe can continue using those sub-processors already engaged by StorifyMe as at the date of this DPA, subject to StorifyMe meeting the obligations set out in this section.
7.3 Prior to engaging new or replacement sub-processors StorifyMe will notify Customer. Customer is entitled to object to any change notified by StorifyMe within a reasonable time (which reasonable time may be set by StorifyMe in such notification) and for materially important reasons. If Customer fails to object to such change within such reasonable time, Customer is deemed to have consented to such change. Where a materially important reason for such objection exists and an amicable resolution fails, StorifyMe may terminate the Main Agreement.
7.4 If StorifyMe engages sub-processors, StorifyMe (i) remains liable under this DPA for the acts and omissions of sub-processors and (ii) ensures that StorifyMe’s obligations on data protection resulting from the Main Agreement and this DPA are binding on sub-processors. Without prejudice to the foregoing, with respect to each sub-processor, StorifyMe will:
i. before the sub-processor processes Customer Data, carry out adequate due diligence to ensure that the sub-processor is capable of providing the level of protection for Customer Data as required herein and in the Main Agreement;
ii. ensure that the arrangement is governed by a written contract including terms which offer similar level of protection for Customer Data as those set out in this DPA and meet the requirements of article 28 (3) of GDPR;
iii. if that arrangement involves a transfer of Customer Data to a location or recipient outside of the European Economic Area or a location or recipient not offering an adequate level of protection, in accordance with GDPR, ensure that the Standard Contractual Clauses attached in Annex 3 (or other instrument providing appropriate safeguards in accordance with GDPR) are incorporated into the agreement, where required, in the name and on behalf of Customer, which authorization Customer hereby grants to StorifyMe; and
iv. on reasonable request, provide copies of StorifyMe’s agreements with sub-processors to Customer for review which agreements may be redacted to remove information not relevant to the requirements of this DPA or GDPR.
8. Data Subject Rights
8.1 If a data subject contacts StorifyMe to exercise the data subject’s legal rights, StorifyMe will not respond to such request but forward such request to Customer without undue delay. StorifyMe may only respond to data subject requests after a prior written approval by Customer or as required by laws to which StorifyMe is subject. In such a case StorifyMe will, to the extent permitted by applicable laws, inform Customer of that legal requirement before responding to the request.
8.2 Taking into account the nature of processing, StorifyMe will assist Customer by implementing appropriate technical and organizational measures, as is reasonable, for the fulfilment of Customer’s obligations to respond to data subject requests.
8.3 StorifyMe will rectify, delete or block Customer Data on Customer’s instructions.
8.4 If a data subject has a right to data portability with respect to Customer Data, StorifyMe will ensure that Customer can obtain such data in a structured, common and machine-readable format.
9. Data Breach
9.1 StorifyMe will inform Customer of any data breach affecting Customer Data without undue delay and, in any event, so as to facilitate the parties’ compliance with applicable law (such as notification timelines set by GDPR, article 33 (1)). StorifyMe must inform Customer, where possible, about the type of breach, the categories and the number of data subjects, the data affected, and the number of data sets affected.
9.2 StorifyMe will without undue delay take all necessary and reasonable measures to remedy the data breach and, where applicable, mitigate any negative effects. StorifyMe will inform Customer as soon as reasonably possible about such measures and keep Customer informed as reasonably practicable.
9.3 StorifyMe will document data breaches to support Customer to evidence compliance with any relevant legal obligations to notify (e.g. articles 33 and 34 GDPR).
10. Return and deletion of Customer Data
10.1 StorifyMe is prohibited from actively processing Customer Data after termination of the Main Agreement.
10.2 At the choice and request of Customer, all Customer Data must be either completely and irretrievably deleted (or otherwise obliterated such that it cannot be recovered or reconstructed) or returned to Customer within a reasonable time after Customer request.
Customer Data contained in backups may be retained until deleted in accordance with StorifyMe's ordinary backup retention cycle, provided that such Customer Data remains protected in accordance with this DPA and is not further processed except as required for backup restoration, security, or compliance with applicable law.
10.3 StorifyMe may retain Customer Data to the extent required by applicable laws and only to the extent and for such period as required by applicable laws.
10.4 StorifyMe will keep confidential such Customer Data that StorifyMe retains in accordance with subsections 10.2 and 10.3 after cessation of processing. Customer Data referred to in section 10.3 will only be processed as necessary for the purposes specified in the applicable laws requiring its storage and for no other purpose.
10.5 On Customer’s reasonable request StorifyMe must provide a written confirmation that StorifyMe has complied with this section.
11. Data Transfers
If applicable,
11.1 Customer and StorifyMe hereby enter into the Standard Contractual Clauses (attached in Annex 3) related to transfers of personal data from Customer to StorifyMe;
11.2 Customer hereby authorizes StorifyMe to sign the Standard Contractual Clauses on Customer’s behalf with any sub-processor to the extent required to effect a lawful data transfer from controller to sub-processor;
11.3 the Standard Contractual Clauses are hereby incorporated to this DPA and agreed to without a separate signature on the Standard Contractual Clauses;
11.4 the Standard Contractual Clauses come into effect between Customer and StorifyMe on the commencement of a transfer, if any, of Customer Data that would otherwise not be allowed under the GDPR and will apply to such Customer Data only; and
11.5 StorifyMe may use other lawful data transfer mechanisms instead of the Standard Contractual Clauses provided that StorifyMe will ensure that such mechanisms comply with applicable law and are properly documented.
12. Audit
12.1 To the extent that the Main Agreement does not otherwise give the information and audit rights meeting the relevant requirements of data protection and privacy laws (including, where applicable, article 28(3)(h) GDPR), StorifyMe will upon reasonable request make available to Customer all information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, by Customer or an auditor mandated by Customer in relation to the processing of Customer Data. StorifyMe will not unreasonably withhold or delay agreement to an auditor selected by Customer.
12.2 If Customer wishes to alter its above instructions concerning audits, Customer will issue a suggestion for altered audit instructions to StorifyMe in writing reasonably in advance of an expected audit. If the parties fail to reach an amicable resolution on altered audit instructions, StorifyMe may terminate the Main Agreement.
12.3 Audits will be subject to customary confidentiality undertakings or professional duty of confidentiality. Customer will give StorifyMe reasonable notice of any audit or inspection and will take (and ensure that auditors take) all reasonable endeavors to minimize disruption to StorifyMe’s business, including e.g. carrying out the audits during normal business hours.
12.4 Customer will not carry out more than one audit per year of the Main Agreement term unless (i) Customer reasonably considers it necessary because of genuine and demonstrable concerns as to StorifyMe’s compliance with this DPA or applicable data protection and privacy laws; or (ii) Customer is required or requested to carry out an audit by data protection and privacy laws, a supervisory authority or any similar regulatory authority responsible for enforcement of such laws; or (iii) if an earlier audit has identified non-conformity with this DPA or applicable data protection and privacy laws.
12.5 All costs and expenses arising from audits are borne by Customer.
12.6 Nothing herein limits any rights mandated by law, such as supervisory authority and data subject rights, including in accordance with the Standard Contractual Clauses.
13. Other StorifyMe Obligations
13.1 If Customer is required to provide information to a supervisory authority relating to processing of Customer Data, or to otherwise cooperate with a public authority, StorifyMe will support Customer by providing such information reasonably available to it or otherwise reasonably cooperating with Customer. This applies in particular to information and documents relating to technical and organizational measures taken in line with article 32 GDPR.
13.2 To the extent necessary and reasonable, StorifyMe will support Customer with data protection impact assessments as well as with any subsequent consultation (if applicable) with the supervisory authorities in the meaning of articles 35 and 36 GDPR.
13.3 Without prejudice to anything in this DPA, StorifyMe is responsible for its and its sub-processors’ compliance with applicable laws relating to this DPA.
13.4 Customer will reimburse to StorifyMe the reasonable cost and expenses arising out of StorifyMe’s support to Customer in accordance with this section.
Annex 1: Purposes and scope of the processing, type of data and categories of data subjects
For purposes of the Standard Contractual Clauses in Annex 3, this Annex 1 serves as Appendix 1.
Annex 2: Technical and organizational measures
For purposes of the Standard Contractual Clauses in Annex 3, this Annex 2 serves as Appendix 2.
This Annex 2 may be replaced by StorifyMe security policy by appending or referencing and incorporating such policy herein:
Annex 3: Standard Contractual Clauses
International transfers of personal data
Where a transfer of Customer Data by Customer to StorifyMe is subject to
Chapter V of the GDPR and requires appropriate safeguards under Article
46 GDPR, the Standard Contractual Clauses set out in the Annex to
Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the
"SCCs") are incorporated into this DPA by reference and apply as set out
below.
1. Applicable Modules
(a) Where Customer is a controller and StorifyMe is a processor,
Module Two (Transfer controller to processor) applies.
(b) Where Customer is a processor and StorifyMe is a processor or
sub-processor, Module Three (Transfer processor to processor)
applies.
2. Completion of the SCCs
For purposes of the SCCs:
(a) Clause 7 (Docking clause) applies.
(b) In Clause 9 (Use of sub-processors), Option 2: General written
authorisation applies. The time period for prior notice of an
intended addition or replacement of sub-processors shall be the
notice period provided under Section 7.3 of this DPA.
(c) The optional language in Clause 11(a) concerning an independent
dispute resolution body does not apply.
(d) For purposes of Clause 13, the competent supervisory authority
shall be determined in accordance with Clause 13 of the SCCs.
(e) In Clause 17 (Governing law), Option 1 applies and the SCCs
shall be governed by the law of Germany.
(f) For purposes of Clause 18 (Choice of forum and jurisdiction),
the courts of Germany shall have jurisdiction.
3. Annex I to the SCCs
A. List of Parties
Data exporter: The Customer identified in the Main Agreement.
Address: The address specified in the Main Agreement.
Contact person's name, position and contact details: As specified in the
Main Agreement or otherwise communicated to StorifyMe.
Activities relevant to the data transferred under these Clauses: Use of
the StorifyMe Services as described in the Main Agreement and this DPA.
Role: Controller where Module Two applies; processor where Module Three
applies.
Data importer: StorifyMe GmbH
Address: As specified in the Main Agreement.
Contact person's name, position and contact details: As specified in the
Main Agreement or otherwise communicated to Customer.
Activities relevant to the data transferred under these Clauses:
Provision of the StorifyMe Services as described in the Main Agreement
and this DPA.
Role: Processor.
The parties agree that execution of the Main Agreement incorporating
this DPA constitutes execution of the SCCs by the data exporter and data
importer as of the effective date of the Main Agreement.
B. Description of Transfer
The categories of data subjects, categories of personal data, nature and
purpose of processing, duration of processing and other details of the
processing and transfers are as described in Annex 1 of this DPA.
The StorifyMe Services are not intended for the processing of special
categories of personal data unless otherwise expressly agreed between
StorifyMe and Customer.
Frequency of the transfer: Continuous or as otherwise determined by
Customer's use of the StorifyMe Services.
Retention period: For the duration of the Main Agreement and
thereafter as provided in Section 10 of this DPA.
For transfers to sub-processors: The subject matter, nature and
duration of processing are as necessary for the relevant sub-processor
to provide its services to StorifyMe in connection with the StorifyMe
Services.
C. Competent Supervisory Authority
The competent supervisory authority shall be determined in accordance
with Clause 13 of the SCCs.
4. Annex II to the SCCs: Technical and Organisational Measures
The technical and organisational measures applicable to the processing
are those described in Annex 2 of this DPA.
5. Annex III to the SCCs: List of Sub-processors
Because Option 2 (General written authorisation) under Clause 9 is
selected, Annex III of the SCCs is not required.
6. Conflict
In the event of any conflict between the SCCs and this DPA, the SCCs
shall prevail to the extent of the conflict.
7. Incorporation of Official SCC Text
The SCCs incorporated by reference above are the standard contractual
clauses contained in the Annex to Commission Implementing Decision
(EU) 2021/914 of 4 June 2021, as amended, replaced or superseded from
time to time in accordance with applicable law.
For the avoidance of doubt, this Annex does not modify the text of the
SCCs except by selecting the modules, options and information that the
SCCs expressly permit the parties to complete.