Updated on June 11, 2022
This Data Processing Addendum (“DPA”) forms part of the Subscription Agreement available at https://alphaa.ai/terms (collectively, the “Agreement”) between the parties under which Alphaa AI will provide certain services (collectively, the “Services”) to Customer. This DPA consists of the main body and Schedules 1, 2, 3, and 4. To complete this DPA, the Parties must sign and date in the provided signature region of the main body of this DPA and Schedules 1 and 2. Execution of this DPA by Customer shall be deemed to constitute signature and acceptance by Customer of the Standard Contractual Clauses (defined hereinafter) and their Appendices, which are incorporated herein by reference herein in their entirety. If the Customer entity signing this DPA is a party to the Agreement, this DPA is an addendum to and forms part of the Agreement. If the Customer entity signing the DPA is not a party to an Order Form nor an Agreement directly with Alphaa AI, but is instead a customer indirectly via an authorized reseller of Alphaa AI services, this DPA is not valid and is not legally binding. Such entity should contact the authorized reseller to discuss whether any amendment to its agreement with that reseller may be required.
HOW TO EXECUTE THIS DPA
1. This DPA consists of two parts: the main body of the DPA, and Schedules 1 – 4.
2. This DPA has been pre-signed on behalf of Alphaa AI. Schedule 2 has been pre-signed by Alphaa AI, Inc. as the data importer.
3. To complete this DPA, the Customer must:
a. Complete the information in the signature box of this DPA and sign this DPA.
b. Send the signed DPA to Alphaa AI by email to legal@alphaa.ai.
Except as otherwise expressly provided in the Agreement, this DPA will become legally binding upon receipt by Alphaa AI of the validly completed DPA at the above email address. For the avoidance of doubt, signature of this DPA shall be deemed to constitute signature and acceptance of the Standard Contractual Clauses, including Schedule 2. Where the Customer wishes to separately execute the Standard Contractual Clauses and its Appendix, the Customer should also complete the information as the data exporter and sign Schedule 2.
For purposes of this DPA, the terms below have the meanings set forth below. Capitalized terms that are used but not defined in this DPA have the meanings given in the Agreement.
1.1. Authorized Affiliate means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where “control” refers to the power to direct or cause the direction of the subject entity, whether through ownership of voting securities, by contract or otherwise.
1.2. Applicable Data Protection Laws means the privacy, data protection and data security laws and regulations of any jurisdiction applicable to the Processing of Personal Data under the Agreement, including, without limitation, European Data Protection Laws and the CCPA.
1.3.CCPA means the California Consumer Privacy Act of 2018 and any regulations promulgated thereunder, in each case, as amended from time to time, including the California Privacy Rights Act of 2020, and any regulations promulgated thereunder.
1.4. EEA means the European Economic Area.
1.5. European Data Protection Laws means the GDPR and other data protection laws and regulations of the European Union, its Member States, Switzerland, Iceland, Liechtenstein, Norway and the United Kingdom, in each case, to the extent applicable to the Processing of Personal Data under the Agreement.
1.6. GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, as amended from time to time.
1.7. Information Security Incident means a breach of Alphaa AI’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Alphaa AI’s possession, custody or control. Information Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.
1.8.Personal Data means Customer Content that constitutes “personal data,” “personal information,” or “personally identifiable information” defined in Applicable Data Protection Laws, or information of a similar character regulated thereby, except that Personal Data does not include such information pertaining to Customer’s personnel or representatives who are business contacts of Alphaa AI, where Alphaa AI acts as a controller of such information.
1.9. Processing means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
1.10. Security Measures has the meaning given in Section 4(a) (Alphaa AI’s Security Measures).
1.11. Standard Contractual Clauses means Standard Contractual Clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and the Council approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as currently set out at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj.
1.12. Subprocessors means third parties that Alphaa AI engages to Process Personal Data in relation to the Services.
1.13. The terms controller, data subject, processor and supervisory authority as used in this DPA have the meanings given in the GDPR.
2. Duration and Scope of DPA
2.1 This DPA will remain in effect so long as Alphaa AI Processes Personal Data, notwithstanding the expiration or termination of the Agreement.
2.2. Schedules 1 and 2 to this DPA apply solely to Processing subject to European Data Protection Laws. Schedule 3 to this DPA applies solely to Processing subject to the CCPA to the extent that the Customer is a “business” (as defined in CCPA) with respect to such Processing.
3. Customer Instructions
Alphaa AI will Process Personal Data only in accordance with Customer’s instructions to Alphaa AI. This DPA is a complete expression of such instructions, and Customers' additional instructions will be binding on Alphaa AI only pursuant to an amendment to this DPA signed by both parties. Customer instructs Alphaa AI to Process Personal Data to provide the Services and as authorized by the Agreement.
4. Security
4.1. Alphaa AI Security Measures. Alphaa AI will implement and maintain administrative, technical and physical safeguards designed to protect the security and integrity of Personal Data, and prevent Information Security Incidents (the “Security Measures”). The Security Measures shall at a minimum include the measures described in Schedule 4 and any other measures required by Applicable Data Protection Laws. Alphaa AI may update the Security Measures from time to time, so long as the updated measures do not materially decrease the overall protection of Personal Data.
4.2. Information Security Incidents. Alphaa AI will notify Customer without undue delay of any Information Security Incident of which Alphaa AI becomes aware. Such notifications will describe available details of the Information Security Incident, including steps taken to mitigate the potential risks and steps Alphaa AI recommends the Customer take to address the Information Security Incident. Alphaa AI’s notification of or response to an Information Security Incident will not be construed as Alphaa AI’s acknowledgement of any fault or liability with respect to the Information Security Incident.
4.3. Reviews and Audits of Compliance
4.4. The Customer may audit Alphaa AI’s compliance with its obligations under this DPA up to once per year and on such other occasions as may be required by European Data Protection Laws, including if mandated by Customer’s supervisory authority. Alphaa AI will contribute to such audits by providing Customer or Customer’s supervisory authority with the information and assistance reasonably necessary to conduct the audit. If a third party is to conduct the audit, Alphaa AI may object to the auditor if the auditor is, in Alphaa AI’s reasonable opinion, not independent, a competitor of Alphaa AI, or otherwise manifestly unsuitable. Such objections by Alphaa AI will require the Customer to appoint another auditor or conduct the audit itself. To request an audit, Customer must submit a proposed audit plan to Alphaa AI at least two weeks in advance of the proposed audit date and any third-party auditor must sign a customary non-disclosure agreement mutually acceptable to the parties (such acceptance not to be unreasonably withheld) providing for the confidential treatment of all information exchanged in connection with the audit and any reports regarding the results or findings thereof. The proposed audit plan must describe the proposed scope, duration, and start date of the audit. Alphaa AI will review the proposed audit plan and provide the Customer with any concerns or questions (for example, any request for information that could compromise Alphaa AI security, privacy, employment or other relevant policies). Alphaa AI will work cooperatively with the Customer to agree on a final audit plan. Nothing in this Section 2(b) shall require Alphaa AI to breach any duties of confidentiality. If the controls or measures to be assessed in the requested audit are addressed in an SOC 2 Type 2, ISO, NIST or similar audit report performed by a qualified third party auditor within twelve (12) months of Customer’s audit request and Alphaa AI has confirmed there have been no known material changes in the controls audited since the date of such report, Customer agrees to accept such report in lieu of requesting an audit of such controls or measures. The audit must be conducted during regular business hours, subject to the agreed final audit plan and Alphaa AI’s safety, security or other relevant policies, and may not unreasonably interfere with Alphaa AI business activities. Customer will promptly notify Alphaa AI of any non-compliance discovered during the course of an audit and provide Alphaa AI any audit reports generated in connection with any audit under this Section 2(b), unless prohibited by European Data Protection Laws or otherwise instructed by a supervisory authority. Customer may use the audit reports only for the purposes of meeting Customer’s regulatory audit requirements and/or confirming compliance with the requirements of this DPA. Any audits are at Customer’s sole expense. Customer shall reimburse Alphaa AI for any time expended by Alphaa AI and any third parties in connection with any audits or inspections under this Section 2(b) at Alphaa AI’s then-current professional services rates, which shall be made available to Customer upon request. The Customer will be responsible for any fees charged by any auditor appointed by the Customer to execute any such audit.
4.5. Impact Assessments and Consultations
4.6. Alphaa AI will (taking into account the nature of the Processing and the information available to Alphaa AI) reasonably assist Customer in complying with its obligations under Articles 35 and 36 of the GDPR, by (a) making available documentation describing relevant aspects of Alphaa AI’s information security program and the security measures applied in connection therewith and (b) providing the other information contained in the Agreement, including this DPA.
4.7. Customer’s Responsibilities
4.7.1. Customer Obligations. Without limitation of Customer’s obligations under the Agreement, Customer (a) agrees that Customer is solely responsible for its use of the Services, including (1) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Personal Data, (2) securing the account authentication credentials, systems and devices Customer uses to access the Services, (3) securing Customer’s systems and devices that Alphaa AI uses to provide the Services, and (4) backing up Personal Data; (b) shall comply with its obligations under Applicable Data Protection Laws; and (c) shall ensure (and is solely responsible for ensuring) that its instructions in Section 3 comply with Applicable Data Protection Laws, and that Customer has given all notices to, and has obtained all such notices from, individuals to whom Personal Data pertains and all other parties as required by applicable laws or regulations for Alphaa AI to Process Personal Data as contemplated by the Agreement. (d) Customer shall comply with its obligations under Applicable Data Protection Laws.
4.7.2. Prohibited Data. Customer represents and warrants to Alphaa AI that Customer Data does not and will not, without Alphaa AI’s prior written consent, contain any social security numbers or other government-issued identification numbers, protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA) or other information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a healthcare professional; health insurance information; biometric information; passwords for online accounts; credentials to any financial accounts; tax return data; credit reports or consumer reports; any payment card information subject to the Payment Card Industry Data Security Standard; information subject to the Gramm-Leach-Bliley Act, Fair Credit Reporting Act or the regulations promulgated under either such law; information subject to restrictions under Applicable Data Protection Laws governing Personal Data of children, including, without limitation, all information about children under 16 years of age; or any information that falls within any special categories of data (as defined in GDPR).
5. Data Subject Rights
5.1. Data Subject Request Assistance. Alphaa AI will (taking into account the nature of the Processing of Personal Data) provide Customer with assistance reasonably necessary for Customer to perform its obligations under Applicable Data Protection Laws to fulfill requests by data subjects to exercise their rights under Applicable Data Protection Laws (“Data Subject Requests”) with respect to Personal Data in Alphaa AI’s possession or control. The Customer shall compensate Alphaa AI for any such assistance at Alphaa AI’s then-current professional services rates, which shall be made available to Customer upon request.
5.2. Customer’s Responsibility for Requests. If Alphaa AI receives a Data Subject Request, Alphaa AI will advise the data subject to submit the request to Customer and Customer will be responsible for responding to the request.
6. Europe Specific Provisions.
6.1. Definitions. For the purposes of this section 12 and Schedule 1 these terms shall be defined as follows:
6.1.1. “EU C-to-P Transfer Clauses” means Standard Contractual Clauses sections I, II, III and IV (as applicable) to the extent they reference Module Two (Controller-to-Processor).
6.1.2. “EU P-to-P Transfer Clauses” means Standard Contractual Clauses sections I, II III and IV (as applicable) to the extent they reference Module Three (Processor-to-Processor).
6.2. GDPR. Alphaa AI will Process Personal Data in accordance with the GDPR requirements directly applicable to Alphaa AI’s provision of its Services.
6.3. Customer Instructions. Alphaa AI shall inform Customer immediately (i) if, in its opinion, an instruction from Customer constitutes a breach of the GDPR and/or (ii) if Alphaa AI is unable to follow Customer’s instructions for the Processing of Personal Data.
6.4. Transfer mechanisms for data transfers. If, in the performance of the Services, Personal Data that is subject to the GDPR or any other law relating to the protection or privacy of individuals that applies in Europe is transferred out of Europe to countries which do not ensure an adequate level of data protection within the meaning of the European Data Protection Laws, the transfer mechanisms listed below shall apply to such transfers and can be directly enforced by the Parties to the extent such transfers are subject to the European Data Protection Laws:
6.4.1. The EU C-to-P Transfer Clauses. Where Customer and/or its Authorized Affiliate is a Controller and a data exporter of Personal Data and Alphaa AI is a Processor and data importer in respect of that Personal Data, then the parties shall comply with the EU C-to-P Transfer Clauses, subject to the additional terms in Schedule 1; and/or
6.4.2. The EU P-to-P Transfer Clauses. Where Customer and/or its Authorized Affiliate is a Processor acting on behalf of a Controller and a data exporter of Personal Data and Alphaa AI is a Processor and data importer in respect of that Personal Data, the parties shall comply with the terms of the EU P-to-P Transfer Clauses, subject to the additional terms in Schedule 1.
6.5. Impact of local laws. As of the Effective Date, Alphaa AI has no reason to believe that the laws and practices in any third country of destination applicable to its Processing of the Personal Data as set forth in the Infrastructure and Subprocessors Documentation, including any requirements to disclose Personal Data or measures authorizing access by a Public Authority, prevent Alphaa AI from fulfilling its obligations under this DPA. If Alphaa AI reasonably believes that any existing or future enacted or enforceable laws and practices in the third country of destination applicable to its Processing of the Personal Data (“Local Laws”) prevent it from fulfilling its obligations under this DPA, it shall promptly notify Customer. In such a case, Alphaa AI shall use reasonable efforts to make available to the affected Customer a change in the Services or recommend a commercially reasonable change to Customer’s configuration or use of the Services to facilitate compliance with the Local Laws without unreasonably burdening Customer. If Alphaa AI is unable to make available such change promptly, Customer may terminate the applicable Order Form(s) and suspend the transfer of Personal Data in respect only to those Services which cannot be provided by Alphaa AI in accordance with the Local Laws by providing written notice in accordance with the “Notices” section of the Agreement. Customer shall receive a refund of any prepaid fees for the period following the effective date of termination for such terminated Services.
7. Subprocessors
7.1. Consent to Subprocessor Engagement. The Customer specifically authorizes the engagement of Alphaa AI’s Affiliates as Subprocessors and generally authorizes the engagement of other third parties as Subprocessors (“Subprocessors”).
7.2. Information about Subprocessors. Information about Subprocessors, including their functions and locations, is available at: https://alphaa.ai/sub-processors (as may be updated by Alphaa AI from time to time) or such other website address as Alphaa AI may provide to Customer from time to time (the “Subprocessor Site”).
7.3. Requirements for Subprocessor Engagement. When engaging any Subprocessor, Alphaa AI will enter into a written contract with such Subprocessor containing data protection obligations not less protective than those in this DPA with respect to Personal Data to the extent applicable to the nature of the services provided by such Subprocessor. Alphaa AI shall be liable for all obligations under the Agreement subcontracted to the Subprocessor or its actions and omissions related thereto.
7.4. Opportunity to Object to Subprocessor Changes. When Alphaa AI engages any new Third Party Subprocessor after the effective date of the Agreement, Alphaa AI will notify Customer of the engagement (including the name and location of the relevant Subprocessor and the activities it will perform) by updating the Subprocessor Site or by other written means. If Customer objects to such engagement in a written notice to Alphaa AI within 15 days after being informed of the engagement on reasonable grounds relating to the protection of Personal Data, Customer and Alphaa AI will work together in good faith to find a mutually acceptable resolution to address such objection. If the parties are unable to reach a mutually acceptable resolution within a reasonable timeframe, Customer may, as its sole and exclusive remedy, terminate the Agreement and cancel the Services by providing written notice to Alphaa AI and pay Alphaa AI for all amounts due and owing under the Agreement as of the date of such termination.
8. Miscellaneous
Except as expressly modified by the DPA, the terms of the Agreement remain in full force and effect. In the event of any conflict or inconsistency between this DPA and the other terms of the Agreement, this DPA will govern. Notwithstanding anything in the Agreement or any order form entered in connection therewith to the contrary, the parties acknowledge and agree that Alphaa AI’s access to Personal Data does not constitute part of the consideration exchanged by the parties in respect of the Agreement. Notwithstanding anything to the contrary in the Agreement, any notices required or permitted to be given by Alphaa AI to Customer under this DPA may be given (a) in accordance with any notice clause of the Agreement; (b) to Alphaa AI’s primary points of contact with Customer; or (c) to any email provided by Customer for the purpose of providing it with Services-related communications or alerts. Customer is solely responsible for ensuring that such email addresses are valid.
SCHEDULE 1
TRANSFER MECHANISMS FOR EUROPEAN DATA TRANSFERS
For the purposes of the EU C-to-P Transfer Clauses and the EU P-to-P Transfer Clauses, Customer is the data exporter and Alphaa AI is the data importer and the parties agree to the following. If and to the extent an Authorized Affiliate relies on the EU C-to-P Transfer Clauses or the EU P-to-P Transfer Clauses for the transfer of Personal Data, any references to ‘Customer’ in this Schedule include such Authorized Affiliate. Where this Schedule 1 does not explicitly mention EU C-to-P Transfer Clauses or EU P-to-P Transfer Clauses, it applies to both of them.
1.7. Notification of New Subprocessors and Objection Right for new Subprocessors. Pursuant to clause 9(a), Customer acknowledges and expressly agrees that Alphaa AI may engage new Subprocessors as described in section 7 of this DPA. Alphaa AI shall inform Customer of any changes to Subprocessors following the procedure provided for in section 7 of this DPA.
1.8. Complaints – Redress. Alphaa AI shall inform Customer if it receives a Data Subject Request with respect to Personal Data and shall without undue delay communicate the complaint or dispute to Customer. Alphaa AI shall not otherwise have any obligation to handle the request (unless otherwise agreed with Customer). The option under clause 11 shall not apply.
1.9. Liability. Alphaa AI‘s liability under clause 12(b) shall be limited to any damage caused by its Processing where Alphaa AI has not complied with its obligations under the GDPR specifically directed to Processors, or where it has acted outside of or contrary to lawful instructions of Customer, as specified in Article 82 GDPR.
1.10. Supervision. Clause 13 shall apply as follows:
1.10.1. Where Customer is established in an EU Member State, the supervisory authority with responsibility for ensuring compliance by Customer with Regulation (EU) 2016/679 as regards the data transfer shall act as competent supervisory authority.
1.10.2. Where Customer is not established in an EU Member State, but falls within the territorial scope of application of Regulation (EU) 2016/679 in accordance with its Article 3(2) and has appointed a representative pursuant to Article 27(1) of Regulation (EU) 2016/679, the supervisory authority of the Member State in which the representative within the meaning of Article 27(1) of Regulation (EU) 2016/679 is established shall act as competent supervisory authority.
1.10.3. Where Customer is established in the United Kingdom or falls within the territorial scope of application of UK Data Protection Laws, the Information Commissioner’s Office shall act as competent supervisory authority.
1.10.4. Where Customer is established in Switzerland or falls within the territorial scope of application of Swiss Data Protection Laws, the Swiss Federal Data Protection and Information Commissioner shall act as competent supervisory authority insofar as the relevant data transfer is governed by Swiss Data Protection Laws.
1.11. Notification of Government Access Requests. For the purposes of clause 15(1)(a), Alphaa AI shall notify Customer (only) and not the Data Subject(s) in case of government access requests. Customer shall be solely responsible for promptly notifying the Data Subject as necessary.
1.12. Governing Law. The governing law for the purposes of clause 17 shall be the law that is designated in the section of the Agreement. If the Agreement is not governed by an EU Member State law, the Standard Contractual Clauses will be governed by either (i) the laws of Ireland; or (ii) where the Agreement is governed by the laws of the United Kingdom, the laws of the United Kingdom.
1.13. Choice of forum and jurisdiction. The courts under clause 18 shall be those designated in the Agreement. If the Agreement does not designate an EU Member State court as having exclusive jurisdiction to resolve any dispute or lawsuit arising out of or in connection with this Agreement, the parties agree that the courts of either (i) Ireland; or (ii) where the Agreement designates the United Kingdom as having exclusive jurisdiction, the United Kingdom, shall have exclusive jurisdiction to resolve any dispute arising from the Standard Contractual Clauses. For Data Subjects habitually resident in Switzerland, the courts of Switzerland are an alternative place of jurisdiction in respect of disputes.
1.14. Data Exports from the United Kingdom and Switzerland under the Standard Contractual Clauses. In case of any transfers of Personal Data from the United Kingdom and/or transfers of Personal Data from Switzerland subject exclusively to the Data Protection Laws and Regulations of Switzerland (“Swiss Data Protection Laws”), (i) general and specific references in the Standard Contractual Clauses to GDPR or EU or Member State Law shall have the same meaning as the equivalent reference in the Applicable Data Protection Laws of the United Kingdom (“UK Data Protection Laws”) or Swiss Data Protection Laws, as applicable; and (ii) any other obligation in the Standard Contractual Clauses determined by the Member State in which the data exporter or Data Subject is established shall refer to an obligation under UK Data Protection Laws or Swiss Data Protection Laws, as applicable. In respect of data transfers governed by Swiss Data Protection Laws, the Standard Contractual Clauses also apply to the transfer of information relating to an identified identifiable legal entity where such information is protected similarly as Personal Data under Swiss Data Protection Laws until such laws are amended to no longer apply to a legal entity.
1.15. Conflict. The Standard Contractual Clauses are subject to this DPA and the additional safeguards set out hereunder. The rights and obligations afforded by the Standard Contractual Clauses will be exercised in accordance with this DPA, unless stated otherwise. In the event of any conflict or inconsistency between the body of this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.
SCHEDULE 2
DESCRIPTION OF PERSONAL DATA PROCESSING
This Schedule forms part of the Standard Contractual Clauses and must be completed and signed by the parties. As evidenced by the signature of each party’s authorized representative below, the data Processing activities carried out by Alphaa AI under the Agreement may be described as follows:
SCHEDULE 3
CALIFORNIA SCHEDULE
SCHEDULE 4
Security Measures