Data Protection Agreement
This Data Processing Agreement, including its schedules and annexes, (collectively, this “DPA”) is incorporated into and forms part of the Software License and Services Agreement, and/or any other legally entered and binding written or electronic agreement (collectively, the “Agreement”) entered into between BlinkReceipt LLC dba Microblink (“Microblink”) and Customer, acting on its own behalf and on behalf of its Affiliates (defined below). This DPA sets forth each party’s respective obligations regarding the processing of Personal Data (defined below) in connection with the Services (defined below) provided pursuant to the Agreement.
This DPA shall become effective as of the Effective Date of the Agreement. All capitalized terms not defined in this DPA will have the meaning given to them in the Agreement.
1. Definitions
The following definitions and rules of interpretation apply in this DPA.
1.1. “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity.
1.2. “Customer Personal Data” means (a) Personal Data provided by or made available by Customer to Microblink or collected by Microblink on behalf of Customer, which Microblink Processes to perform the Services and is a subset of “Customer Data” as defined in the Agreement and (b) Personal Data provided, generated or made available by Microblink to Customer in the course of providing the Serviced under the Agreement.
1.3. “Data Protection Laws” means all applicable global laws, regulations, or treaties concerning privacy, data security, data protection, or the Processing of Personal Data including, but not limited to, United States privacy laws, such as the California Consumer Privacy Act of 2018 (“CCPA”), each as amended, replaced, or superseded from time to time and the guidance and codes of practice issued by the relevant data protection or supervisory authorities and applicable to a Party.
1.4. “Disclosure Request” means (a) any order, demand, warrant, or any other document requesting or purporting to compel the production of Customer Personal Data (for example, by oral questions, interrogatories, requests for information or documents in legal proceedings, subpoenas, civil investigative demands, regulatory inspection or other similar processes); or (b) any other request, inquiry, or complaint involving Customer Personal Data or the Processing of such Customer Personal Data from any governmental, regulatory authority or law enforcement department, including, but not limited to, a data protection authority, or similar regulatory authority.
1.5. “Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise Processed.
1.6. The “Parties” means Microblink and Customer.
1.7. Except as otherwise defined in this DPA, “Business,” “Contractor,” “Controller,” “Data Subject,” “Personal Data” or “Personal Information,” “Process” or “Processing,” “Processor,” “Sell” or “Selling,” Sensitive Personal Data,” “Sensitive Personal Information,” “Service Provider,” “Share” or “Sharing,” and “Third Party” are as defined under the relevant Data Protection Laws, and the conjugation of these terms shall be defined accordingly. For purposes of this DPA, the term “Controller” shall also refer to the terms “Business” or “Third Party,” as applicable, and the term “Processor” shall also refer to the term “Service Provider.”
2. Purpose and Scope of Processing
2.1. Roles of the Parties. Customer and Microblink acknowledge and agree that under Data Protection Laws and this DPA, they each act as separate, independent Controllers and shall comply with their respective obligations under Data Protection Laws.
2.2. Details of Processing. The subject matter, duration, nature and purpose of Processing, categories of Customer Personal Data, and Data Subject type(s) are described in ANNEX A. DETAILS OF PROCESSING of this DPA.
3. Customer Obligations
3.1. Processing. As between the Parties, Customer is solely responsible for the accuracy, quality, and legality of (a) the Customer Personal Data provided to Microblink by or on behalf of Customer and (b) the means by which Customer acquired the Customer Personal Data provided to Microblink. Customer is responsible for providing all necessary notices, consents, and opt-out mechanisms for the use of any tracking code via the Services and for ensuring that its website discloses the use of third-party tracking technology in compliance with Data Protection Laws.
3.2. Sensitive Personal Data. Customer acknowledges and agrees that Customer shall not Process Sensitive Personal Data via the Services, in accordance with any Restricted Data provisions set out under the Agreement.
3.3. Customer Affiliates. Customer enters into this DPA on behalf of itself and in the name and on behalf of its Affiliates, as applicable, thereby establishing a separate DPA between Customer and each such Customer Affiliate. Customer shall remain responsible for coordinating all communication with Microblink under this DPA and be entitled to make and receive any communication in relation to this DPA on behalf of its Affiliates.
4. Processing Obligations
4.1. Compliance with DPA and Data Protection Laws. The Parties shall comply with all Data Protection Laws with respect to the Processing of Customer Personal Data under the Agreement. Each Party shall notify the other if such Party makes a determination that it cannot comply with its obligations under Data Protection Laws. For the avoidance of doubt, each party shall establish a lawful basis for its Processing of Customer Personal Data and provide appropriate notice to the Data Subjects in a timely manner, and at a minimum in accordance with the elements required under Data Protection Laws.
4.2. CCPA Processing Limitations. To the extent that the CCPA applies to the Processing of Customer Personal Data, each Party acknowledges and agrees that: (i) such Customer Personal Data is made available to the other Party solely for the limited and specified purposes set forth in the Agreement; (ii) the Party receiving such Customer Personal Data shall comply with and provide the same level of privacy protection as is required by the CCPA; and (iii) the Party providing such Customer Personal Data shall have the right, upon reasonable notice, to take reasonable and appropriate steps to ensure that the receiving party uses the Customer Personal Data in a manner consistent with its obligations under the CCPA and stop and remediate unauthorized uses of the Customer Personal Data.
4.3. Confidentiality. Each Party shall protect the confidentiality of the Customer Personal Data in accordance with the terms of the Agreement and this DPA and ensure that any Customer Personal Data is not disclosed or otherwise made available to other persons or used in violation of this DPA. Each Party shall ensure that any person that it authorizes to Process Customer Personal Data are informed of the confidential nature of the Customer Personal Data and are subject to an appropriate duty of confidentiality.
4.4. Compliance Assistance. Each Party shall reasonably assist the other Party with meeting that Party’s compliance obligations under the Data Protection Laws, taking into account the nature of the Processing and the information available.
4.5. Data Subject Rights. If a Party receives a request from a Data Subject to exercise any of their related rights under the Data Protection Laws, the Party shall fulfill the request in accordance with Data Protection Law, or, if this is not feasible, shall promptly notify the other Party of the request and coordinate with the other Party to ensure the request is fulfilled in accordance with Data Protection Laws. Upon one Party’s reasonable request, the other Party shall reasonably assist the requesting Party to comply with the rights of Data Subjects under the Data Protection Laws and to respond to any inquiry, complaint, or other correspondence from a Data Subject.
4.6. Disclosure Requests, Complaints, and Other Communications. If either Party receives a Disclosure Request, complaint, or any other communication that relates to the other Party’s Processing of Customer Personal Data or about the other Party’s compliance with the Data Protection Laws, the receiving Party shall direct the request to the other Party and promptly notify the other Party, unless prohibited to do so by law. Subject to applicable law, the Party receiving a Disclosure Request relating to the other Party’s Processing of Customer Personal Data shall oppose such Disclosure Request, and if legally required to respond, shall provide the minimal amount of Customer Personal Data or information about Processing of Customer Personal Data in response to such request or inquiry. Each Party shall reasonably assist the other in responding to any Disclosure Requests, complaints, or other communications regarding the Processing of Customer Personal Data.
5. Security and Audits
5.1. Security Measures. Each Party shall implement appropriate technical and organizational measures against unauthorized or unlawful Processing, access, or disclosure of Customer Personal Data and against accidental or unlawful loss, destruction, alteration, disclosure or damage of Customer Personal Data.
5.2. Data Breach. Microblink shall notify Customer no later than forty-eight (48) hours upon becoming aware of a Data Breach impacting Customer Personal Data and promptly take such steps as Microblink deems necessary and reasonable to investigate, contain, and mitigate such Data Breach.
5.3. Audit Reports and Documentation. At Customer’s written request at reasonable intervals, Microblink shall provide Customer with the most recent copies of external third-party audit reports, certifications, or other documentation regarding Microblink’s compliance with the obligations in this DPA.
6. Cross-border Transfers
6.1. Adequate Measures for Transfers. Customer and Microblink shall not transfer or otherwise Process Personal Data outside of the country or region of origin of such Personal Data, either directly or via onward transfer, unless each Party takes measures to ensure the transfer in compliance with Data Protection Laws and guidance from data protection regulatory authorities in relevant jurisdictions.
7. Processors, Contractors and Third-Parties
7.1. Authorization. Each Party may subcontract Processing of Customer Personal Data to a Processor, Contractor, or Third-Party (each an “External Recipient”) to Process Customer Personal Data on its behalf.
7.2. Disclosure Requirements. Prior to disclosing any Customer Personal Data to any External Recipient, the disclosing Party shall enter into a written agreement with each such External Recipient that imposes obligations that are no less protective than the obligations in this DPA and that comply with the requirements for any such disclosure under Data Protection Laws.
8. Term and Termination
8.1. Survival. This DPA shall remain in full force and effect for the duration of the Agreement.
8.2. Material Breach. A party’s failure to comply with the terms of this DPA is a material breach. In the event of a material breach by either party, the other party may terminate this DPA, in whole or in part, effective immediately on written notice without further liability or obligation.
8.3. Noncompliance. If a change in any Data Protection Law prevents either party from fulfilling all or part of its obligations under this DPA, the Parties shall suspend the Processing of Customer Personal Data until that Processing complies with the new requirements. If the Parties are unable to bring the Processing of Customer Personal Data into compliance with the Data Protection Laws within sixty (60) days, they may terminate this DPA on written notice to the other Party.
9. General
9.1. Annexes. The Annexes form part of this DPA and shall have effect as if set out in full in the body of this DPA. Any reference to this DPA includes the Annexes.
9.2. Conflicts with the DPA. In the event of any conflict or inconsistency between the Agreement, and the DPA, the provisions of the DPA shall prevail.
9.3. Limitation of Liability. Liability arising out of or related to this DPA shall be subject to the liability terms in the Agreement.
9.4. Choice of Law. This DPA shall be governed by and construed in accordance with the laws of the Agreement.
9.5. Changes in Data Protection Laws. In the event of any changes to Data Protection Laws that may require variation to this DPA, and upon notice from either Party, the Parties shall promptly discuss such variations and negotiate in good faith with a view to agreeing on and implementing variations to the DPA designed to address the requirements of any such changes in Data Protection Laws as soon as reasonably practical.
Details of Processing
1. Data Exporter
| Company Name | Address | Customer Authorized Privacy Contact, position, and contact information | Role |
|---|---|---|---|
| Customer, as specified in the Agreement | Customer’s as specified in the Agreement | Customer’s contact information, as specified in the Agreement | Controller/Business |
2. Data Importer
| Company Name | Address | Contact name, position, and contact information | Role |
|---|---|---|---|
| Microblink | 10 Grand Street, Suite 2400, Brooklyn, New York, 11249 | Eric Stein, President. eric.stein@microblink.com |
Controller/Third Party |
3. Activities relevant to the data transferred
Activities related to data transferred are described below in Section 4. Processing Details, under the “Nature of the processing” and “Purpose of the data transfer and further processing” fields.
4. Processing Details
| Description | Details |
|---|---|
| Categories of data subjects whose Customer Personal Data is Processed | Customer may use Services to process any data subjects as they determine is necessary, including, but not limited to:
|
| Categories of Customer Personal Data Processed | Customer may use Services to process any data categories as they determine is necessary, including, but not limited to:
|
| Sensitive Personal Information Processed by Microblink | None |
| Frequency of the transfer | Continuous |
| Nature of the processing | The Parties Process Customer Personal Data for purposes of providing the Services as described in the Agreement. |
| Purpose of the data transfer and further processing | |
| Period for which the Customer Personal Data will be retained or criteria used to determine that period | The period for which Customer Personal Data will be retained is the duration of the Agreement. |