Data Processing Addendum
Updated: April 1, 2021
Data Processing Addendum
This Data Processing Addendum (“DPA”) and the schedules to this DPA apply to the Processing of Client Personal Data on behalf of Client as identified on the Master Services Agreement (the “Client”) in order to provide Services Client may have ordered from Vendr. This DPA forms part of the Master Services Agreement available at https://www.vendr.com/legal or such other location as the Master Services Agreement may be posted from time-to-time or such alternative agreement Client may have entered into with Vendr pursuant to which Client has accessed Vendr’s Services, as defined in the applicable agreement (the “Agreement”). In the event of a conflict between the terms of this DPA and the terms of the Agreement, the terms of this DPA will prevail, unless the Agreement explicitly provides otherwise, identifying the relevant portion of the DPA that it is superseding. For purposes of this DPA, Client and Vendr agree that Client may be a Data Controller of Client Personal Data and Vendr may be a Data Processor of such data, except when Client acts as a Data Processor of Client Personal Data, in which case Vendr is a subprocessor. In the course of providing Services to Client pursuant to the Agreement, Vendr may Process Client Personal Data on behalf of Client. Vendr agrees to comply with the following provisions with respect to any Client Personal Data submitted by or on behalf of Client for the Services or collected and Processed through the Services.
1. DEFINITIONS
Any capitalized term used but not defined in this DPA has the meaning provided to it in the Agreement or in the Applicable Data Protection Law.“Applicable Data Protection Law” refers to all laws and regulations applicable to Vendr’s Processing of Personal Data under the Agreement including, without limitation, the General Data Protection Regulation (EU 2016/679) ("GDPR").“Client Personal Data” means any Personal Data Processed by Vendr on behalf of Client pursuant to or in connection with the Agreement, with the explicit exclusions of Client Feedback, the Personal Data of representatives of third party organizations such as those the Client wishes to procure from, and records of communications between Vendr and Client.“CCPA” means the California Consumer Privacy Act 2018 Cal. Civ. Code 1798.100 et seq., including any amendments and any implementing regulations thereto that become effective on or after the effective date of this Data Processing Addendum. “Delete” means to remove or obliterate Personal Data such that it cannot be recovered or reconstructed, and “Deletion” will be construed accordingly. “GDPR” means the EU General Data Protection Regulation 2016/679 and to the extent the GDPR is no longer applicable in the United Kingdom, any implementing legislation or legislation having equivalent effect in the United Kingdom. References to “Articles” or “Chapters” of the GDPR will be construed accordingly. “Personal Data” shall have the meaning ascribed to it, or to substantially similar phrases, in Applicable Data Protection Law.“Services” means those services and activities to be supplied to or carried out by or on behalf of Vendr for Client pursuant to the Agreement. “Transfer” means the transfer of Client Personal Data outside the United Kingdom or EU/European Economic Area (“EEA”). “Subprocessor” means any third party appointed by or on behalf of Vendr to Process Client Personal Data.
2. PROCESSING OF CLIENT PERSONAL DATA
Vendr will in the course of providing Services, including with regard to Transfers of Personal Data to a third country, Process Client Personal Data only on behalf of and under the documented Instructions of Client unless required to do so otherwise under Applicable Data Protection Law; in such a case, Vendr will inform Client of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest. Schedule 1 specifies the duration of the Processing, the nature and purpose of the Processing, and the types of Personal Data and categories of data subjects. Client is responsible for ensuring that (a) it has complied, and will continue to comply, with Applicable Data Protection Law in its use of the Services and its own Processing of Client Personal Data and (b) it has, and will continue to have, the right to Transfer, or provide access to, Client Personal Data to Vendr for Processing in accordance with the terms of the Agreement and this DPA. Client appoints Vendr as a Data Processor to Process Client Personal Data on behalf of, and in accordance with, Client’s instructions (a) as set forth in the Agreement, this DPA, and as otherwise necessary to provide the Services to Client (which may include investigating security incidents and preventing spam or fraudulent activity, and detecting and preventing network exploits and abuse); (b) as necessary to comply with applicable law; and (c) as otherwise agreed in writing by the parties (“Permitted Purposes”). Client will ensure that its instructions comply with Applicable Data Protection Law. Client acknowledges that Vendr is not responsible for determining which laws are applicable to Client’s business nor whether Vendr’s provision of the Services meets or will meet the requirements of such laws. Client will ensure that Vendr’s Processing of Client Personal Data, when done in accordance with Client’s instructions, will not cause Vendr to violate any applicable law, regulation, or rule, including Applicable Data Protection Law. Vendr will inform Client if it becomes aware or reasonably believes that Client’s data Processing instructions violate any applicable law, regulation, or rule, including Applicable Data Protection Law.Client is responsible for ensuring that suitable safeguards are in place prior to transmitting or Processing, or prior to permitting Client’s end users to transmit or Process, any Special Categories of Data via the Services.Client specifically acknowledges that its use of the Services will not violate the rights of any Data Subject that has opted-out from sales or other disclosures of Client Personal Data, to the extent applicable under the CCPA.
3. SECURITY
Vendr will ensure that its employees (including subprocessors) who Process Client Personal Data for Vendr or who have access to Client Personal Data are authorized to Process this Personal Data, and have undertaken to, or are contractually bound to observe confidentiality. Vendr will ensure that this obligation to maintain confidentiality continues beyond the termination of employment contracts or service contracts, and beyond the termination of this DPA.Taking into account the state of the art, the costs of implementation and the nature, scope, context, and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of Natural Persons, Vendr will in relation to Client Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by Art. 32 GDPR. As appropriate, this may include:the pseudonymization and encryption of Personal Data;the ability to ensure the ongoing confidentiality, integrity, availability and resilience of Processing systems and services; andthe ability to restore the availability and access to Client Personal Data in a timely manner in the event of a physical or technical incident.In assessing the appropriate level of security, Vendr will take into account the risks presented by Processing, in particular from a Personal Data Breach. Vendr’s technical and organizational measures specified in Schedule 2 Appendix 2 are subject to technical advancements and development. Vendr will regularly test, assess and evaluate the effectiveness of technical and organizational measures to reasonably ensure the security of the Processing.
4. SUBPROCESSING
Client agrees that Vendr may use subprocessors to fulfill its contractual obligations under the Agreement. Where Vendr authorizes any subprocessor as described in this Section 4, Vendr agrees to impose data protection terms on any subprocessor it appoints that require it to protect Client Personal Data to the standard required by Applicable Data Protection Law, such as including the same data protection obligations referred to in Article 28(3) of the GDPR, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the Processing will meet the requirements of the GDPR.Client provides a general consent for Vendr to engage onward subprocessors, conditional on the following requirements: Any onward subprocessor must agree in writing to only Process data in a country that the European Commission has declared to have an “adequate” level of protection; or to only Process data on terms equivalent to the Standard Contractual Clauses, or pursuant to a Binding Corporate Rules approval granted by competent European data protection authorities; andVendr will restrict the onward subprocessor’s access to Client Personal Data only to what is strictly necessary to provide the Services, and Vendr will prohibit the subprocessor from Processing the Client Personal Data for any other purpose.Client consents to Vendr engaging additional third party subprocessors to Process Client Personal Data within the Services for the Permitted Purposes provided that Vendr maintains an up-to-date list of its subprocessors at https://www.vendr.com/legal. Vendr will provide details of any change in subprocessors as soon as reasonably practicable, but in any event will give notice no less than fourteen (14) days prior to any such change.The Client may object to the new or changed Subprocessor within five calendar days after receipt of Vendr’s notice. If within ten (10) calendar days of receipt of that notice, Client notifies Vendr of an objection to an appointment (based on reasonable grounds relating to data protection), then (i) Vendr will work with Client in good faith to make available a commercially reasonable change in the provision of the Services which avoids the use of that proposed Subprocessor; and (ii) where such a change cannot be made within fourteen (14) days from Vendr’s receipt of Client’s objection notice, notwithstanding anything in the Agreement, Client may, by such notice to Vendr, terminate the Agreement to the extent that it relates to the Services which require the use of the proposed Subprocessor. Such termination will be without prejudice to any fees incurred by Client prior to suspension or termination. If no objection has been raised prior to Vendr replacing or appointing a new subprocessor, Vendr will deem Client to have authorized the new subprocessor.Vendr will remain liable for any breach of this DPA that is caused by its subprocessors.
5. DATA RIGHTS REQUESTS
Vendr’s Services provide Client with a number of self-service features, including the ability to rectify, delete, obtain a copy of, or restrict use of Client Personal Data, which may be used by Client to assist in complying with its obligations under Applicable Data Protection Law with respect to responding to requests from data subjects via the Vendr Services at no additional cost. In addition, upon Client’s request, Vendr will provide reasonable additional and timely assistance (at Client’s expense only if complying with Client’s request will require Vendr to assign significant resources to that effort) to assist Client in complying with its data protection obligations with respect to data subject rights under Applicable Data Protection Law.In the event that any request, correspondence, enquiry or complaint from a data subject, regulatory or third party, including, but not limited to law enforcement, is made directly to Vendr in connection with Vendr’s Processing of Client Personal Data, Vendr will inform Client providing details of the same, to the extent legally permitted. Unless legally obligated to do so, Vendr will not respond to any such request, inquiry or complaint without Client’s prior consent. In the case of a legal demand for disclosure of Client Personal Data in the form of a subpoena, search warrant, court order or other compulsory disclosure request, Vendr will attempt to redirect the requesting party or agency to request disclosure from Client. If Vendr is legally compelled to respond to such a request, Vendr will notify Client prior to disclosure of Client Personal Data so that Client may seek a protective order or other relief, if appropriate, unless Vendr is barred by law from giving such notification.
6. PERSONAL DATA BREACH
Upon becoming aware of a Personal Data Breach, Vendr will without undue delay and within (48) forty-eight hours inform Client and provide written details of the Personal Data Breach reasonably required to fulfill Client’s notification obligations under Applicable Data Protection Law. Where possible, such details will include, the nature of the Personal Data Breach, the categories and approximate number of data subjects concerned and the categories and approximate number of Client Personal Data records concerned, the likely consequences, and the measures taken or proposed to be taken to mitigate any possible adverse effects.Vendr will promptly work to recover Client Personal Data which is lost, damaged, destroyed or distorted as a result of the Personal Data Breach, and take such reasonable commercial steps as may be directed by Client to assist in the investigation, mitigation, and remediation of each such Personal Data Breach.
7. DPIA AND CONSULTATION
Vendr will provide reasonable assistance to Client in connection with data protection impact assessments, and prior consultations with Supervisory Authorities, which Client reasonably considers to be required of Client by Article 35 or 36 of the GDPR, with regards to Processing of Client Personal Data by Vendr.
8. RETURN AND DELETION OF CLIENT PERSONAL DATA
Within two (2) months after the expiry or termination of the Agreement, Vendr will, upon Client’s request return all Client Personal Data to Client. Following the earlier of such request or the two (2) month period, Vendr will destroy any Client Personal Data and any copies in Vendr’s control or possession and provide written confirmation once returned or destroyed.Vendr may retain Client Personal Data after the expiry or termination of the Agreement to the extent required by applicable law, and only to the extent and for such period as required by applicable laws and always provided that Vendr will ensure the confidentiality of all such Client Personal Data and will ensure that such Client Personal Data is only Processed as necessary for the purpose(s) specified in the applicable laws requiring its storage and for no other purpose.
9. DE-IDENTIFIED DATA
"De-identified Data" means Client Personal Data that has been Processed such it can no longer be linked to an identified or identifiable Natural Person, or a device linked to such person.Vendr may Process Client Personal Data to create de-identified data for Vendr’s legitimate business purposes. De-identified data will not be considered Client Personal Data and Vendr may retain such data at its discretion.
10. AUDITS
Vendr will make available information to Client at Client’s request which is necessary to demonstrate compliance with this DPA and allow for any audits, including inspections, conducted by Client or another auditor, as requested by Client on reasonable, legitimate grounds for suspecting a breach of this DPA. Vendr will provide for such audits by allowing Client to review confidential summary reports ("Audit Report") prepared by third-party security professionals at Vendr's selection and Expense. If Client can demonstrate that it requires additional information, beyond the Audit Report, then Client may request, at Client's cost, Vendr to provide for an audit subject to reasonable confidentiality procedures, which will: (i) not include access to any information that could compromise confidential information relating to other Vendr clients or suppliers, Vendr's technical and organizational measures or any trade secrets; and (ii) be performed upon no less than sixty (60) days’ notice, during regular business hours and in such a manner as not to unreasonably interfere with Vendr’s normal business activities. If Vendr is unable to follow Client's instructions (for example, where Client's request relates to a subprocessor that will not provide such information or right to Vendr) or declines, Client may terminate the Agreement.
11. INTERNATIONAL DATA TRANSFERS
Client authorizes Vendr and its subprocessors to Transfer Client Personal Data across international borders, including from the UK or European Economic Area to the United States. Any international Transfer of Client Personal Data from the UK or European Economic Area to a Third Country must be supported by an approved EU adequacy mechanism.Vendr and Client will use the Standard Contractual Clauses described Schedule 2 as the adequacy mechanism supporting the Transfer and Processing of Client Personal Data.
12. JURISDICTION SPECIFIC TERMS
Where Vendr Processes Client Personal Data protected by Applicable Data Protection Law in one of the jurisdictions listed in Schedule 3, the terms specified in Schedule 3 with respect to the applicable jurisdiction(s) (“Jurisdiction Specific Terms”) apply in addition to the terms of this DPA. In case of any conflict or ambiguity between the Jurisdiction Specific Terms and any other terms of this DPA, the applicable Jurisdiction Specific Terms will take precedence.
13. LIABILITY
Client and Vendr will each be separately liable to the other party for damages it causes by any breach of the clauses in this DPA. Liability as between the parties is limited to actual damage suffered. Punitive damages (i.e. damages intended to punish a party for its outrageous conduct) are specifically excluded. Each party will be liable to data subjects for damages it causes by any breach of third party rights under these clauses. This does not affect the liability of the data exporter under its Applicable Data Protection Law.
14. FAILURE TO PERFORM
In the event that changes in law or regulation render performance of this DPA impossible or commercially unreasonable, the Parties may renegotiate this DPA in good faith. If renegotiation would not cure the impossibility, or the Parties cannot reach an agreement, the Parties may terminate the Agreement in accordance with the Agreement’s termination provisions.
15. UPDATES
Vendr may update the terms of this DPA from time to time; provided, however, Vendr will provide at least thirty (30) days prior written notice to Client when an update is required as a result of (a) the release of new products or services or material changes to any of the existing Services; (b) changes in Applicable Data Protection Law; or (c) a merger, acquisition, or other similar transaction. The then-current terms of this DPA are available at https://www.vendr.com/legal.
16. DURATION AND SURVIVAL
This DPA will become legally binding upon the Effective Date of the Agreement or upon the date that the Parties sign this DPA if it is completed after the effective date of the Agreement. Vendr will Process Client Personal Data until the relationship terminates as specified in the Agreement. Any obligation imposed on Vendr under this DPA in relation to the Processing of Client Personal Data will terminate when Vendr no longer Processes Client Personal Data.
Schedules
Schedule 1: Client Personal Data Processing Details
Subject Matter of Processing
The Processing will involve: the performance of theServices pursuant to the Agreement.
Duration of Processing
The Processing will continue as set forth in the Agreement.
Categories of Data Subjects
Client employees, contractors, agents, and/or representatives
Special Categories of Personal Data
None
Nature and Purpose of Processing
Includes the following: The Processing activities performed by Vendr will be as described in the Agreement.
Types of Personal Data
Corporate contact information such as name, job title, email address, physical address and phone number.
Physical Location of Personal Data Processed by Vendr
United States
Vendr List of Data Subprocessors
Schedule 2: Cross Border DataTransfer Mechanisms
1. Definitions
2. Cross Border Data Transfer Mechanisms
Appendix 1 to Schedule 2
This Appendix 1 forms part of the Clauses and must be completed and signed by the Parties.
The Member States may complete or specify, according to their national procedures, any additional necessary information to be contained in this Appendix 1.
Data exporter
The data exporter is (please specify briefly your activities relevant to the transfer): The Data Exporter is the Client of Vendr’s Services as defined in the Agreement.
Data importer
The data importer is (please specify briefly your activities relevant to the transfer): The Data Importer is Vendr which offers services to Client through its online platform with respect to the Services.
Data subjects
The Personal Data transferred concern the following categories of data subjects (please specify): See Schedule 1 of the DPA.
Categories of data
The Personal Data transferred concern the following categories of data subjects (please specify, tick the applicable): See Schedule 1 of the DPA.
Special categories of data (if appropriate)
The Personal Data transferred concern the following special categories of data (please specify, tick the applicable): See Schedule 1 of the DPA.
Processing operations
The Personal Data transferred will be subject to the following basic Processing activities (please specify): See Schedule 1 of the DPA.
On behalf of the data exporter (Client):
Name (written out in full):
Position:
Address:
Other information necessary in order for the contract to be binding (if any):
Signature……………………………………….
On behalf of the data importer (Vendr):
Name (written out in full):
Position:
Address: 501 Boylston Street, 10th Floor Boston, MA 02116, United States
Other information necessary in order for the contract to be binding (if any):
Signature……………………………………….
Appendix 2 to Schedule 2
This Appendix forms part of the Clauses and must be completed and signed by the Parties.
Description of the Technical and Organizational Security Measures implemented by the Data Importer in accordance with Clauses 4(d) and 5(c) (or document/legislation attached):
Vendr will maintain administrative, physical, and technical safeguards for protection of the security, confidentiality and integrity of Client Personal Data, as described in the DPA. Vendr will not materially decrease the overall security of the Services during the term.
Subprocessors will be bound to adhere to similar but not identical organizational security measures which will not fall below the level of data security as agreed herein. Any organizational security measures are subject to change of technical standards and can be adopted. If so requested, Vendr will provide Client with a description of the then current measures.
Vendr shall:
- ensure that Client Personal Data can be accessed only by authorized personnel for the purposes set forth in Schedule 1 of this DPA;
- take all reasonable measures to prevent unauthorized access to Client Personal Data through the use of appropriate physical and logical (passwords) entry controls, securing areas for data processing, and implementing procedures for monitoring the use of data processing facilities;
- build in system and audit trails;
- use secure passwords, network intrusion detection technology, encryption and authentication technology, secure logon procedures and virus protection;
- account for all the risks that are presented by processing, for example from accidental or unlawful destruction, loss, or alteration, unauthorized or unlawful storage, processing, access or disclosure of Client Personal Data;
- ensure pseudonymisation and/or encryption of Client Personal Data, where appropriate;
- maintain the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- 10. maintain the ability to restore the availability and access to Client Personal Data in a timely manner in the event of a physical or technical incident;
- implement a process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures for ensuring the security of the Processing of Client Personal Data;
- monitor compliance on an ongoing basis;
- implement measures to identify vulnerabilities with regard to the processing of Client Personal Data in systems used to provide services to Client;
- provide employee and contractor training to ensure ongoing capabilities to carry out the security measures established in policy.
- maintain SOC 2 compliance.
On behalf of the data exporter (Client):
Name (written out in full):
Position:
Address:
Other information necessary in order for the contract to be binding (if any):
Signature……………………………………….
On behalf of the data importer (Vendr):
Name (written out in full):
Position:
Address: 501 Boylston Street, 10th Floor, Boston, MA 02116, United States
Other information necessary in order for the contract to be binding (if any):
Signature……………………………………….
Schedule 3: Jurisdiction Specific Terms
1. Australia:
1.1. The definition of “Applicable Data Protection Law” includes the Australian Privacy Principles and the Australian Privacy Act (1988).
1.2. The definition of “Personal Data” includes “Personal Information” as defined under Applicable Data Protection Law.
1.3. The definition of “Sensitive Data” includes “Sensitive Information” as defined under Applicable Data Protection Law.
2. Brazil:
2.1 The definition of “Applicable Data Protection Law” includes the Lei Geral de Proteção de Dados (LGPD).
2.2 The definition of “Data Processor” includes “operator” as defined under Applicable Data Protection Law.
3. Canada:
3.1. The definition of “Applicable Data Protection Law” includes The Federal Personal Information Protection and Electronic Documents Act (PIPEDA).
3.2. Vendr’s subprocessors, as described in Schedule 1 of this DPA, are third parties under Applicable Data Protection Law, with whom Vendr has entered into a written contract that includes terms substantially similar to this DPA. Vendr has conducted appropriate due diligence on its subprocessors.
3.3. Vendr will implement technical and organizational measures as set forth in Section 3 (Security) of this DPA.
4. Israel:
4.1 The definition of “Applicable Data Protection Law” includes the Protection of Privacy Law (PPL).
4.2 The definition of “Data Controller” includes “Database Owner” as defined under Applicable Data Protection Law.
4.3 The definition of “Data Processor” includes “Holder” as defined under Applicable Data Protection Law.
4.4 Vendr will require that any personnel authorized to process Client Personal Data comply with the principle of data secrecy and have been duly instructed about Applicable Data Protection Law. Such personnel sign confidentiality agreements with Vendr in accordance with Section 3 (Security) of this DPA.
4.5 Vendr must take sufficient steps to ensure the privacy of Data Subjects by implementing and maintaining the security measures as specified in Section 3 (Security) of this DPA and complying with the terms of the Agreement.
4.6 Vendr must ensure that the personal data will not be transferred to a subprocessor unless such subprocessor has executed an agreement with Vendr pursuant to Section 4 (Subprocessing) of this DPA.
5. Japan:
5.1 The definition of “Applicable Data Protection Law” includes the Act on the Protection of Personal Information (APPI).
5.2 The definition of “Personal Data” includes “Personal Information” as defined under Applicable Data Protection Law.
5.3 The definition of “Data Controller” includes “Business Operator” as defined under Applicable Data Protection Law. As a Business Operator, Vendr is responsible for the handling of Personal Data in its possession.
5.4 The definition of “Data Processor” includes a business operator entrusted by the Business Operator with the handling of personal data in whole or in part (also a “trustee”), as described under Applicable Data Protection Law. As a trustee, Vendr will ensure that the use of the entrusted Personal Data is securely controlled.
6. Singapore:
6.1 The definition of “Applicable Data Protection Law” includes the Personal Data Protection Act 2012 (PDPA).
6.2 Vendr will process personal data to a standard of protection in accordance with the PDPA by implementing adequate technical and organizational measures as set forth in Section 3 (Security) of this DPA and complying with the terms of the Agreement.
7. United Kingdom:
7.1 References in this DPA to GDPR will to that extent be deemed to be references to the corresponding laws of the United Kingdom (including the UK GDPR and Data Protection Act 2018)
7.2 The Standard Contractual Clauses will also apply to Client in the United Kingdom as data exporter and to Vendr as data importer for Transfers of Personal Data to countries that are not deemed to have an adequate level of data protection under the United Kingdom's Applicable Data Protection Law.
8. United States - California:
8.1 The definition of “Applicable Data Protection Law” includes the California Consumer Privacy Act of 2018 (CCPA).
8.2 The definition of “Data Controller” includes “Business” as defined under Applicable Data Protection Law.
8.3 The definition of “Data Processor” includes “Service Provider” as defined under Applicable Data Protection Law.
8.4 The definition of “Personal Data” includes “Personal Information” as defined under Applicable Data Protection Law and, for clarity, includes any Personal Information contained within Client Personal Data.
8.5 The definition of “Data Subject” includes “Consumer” as defined under Applicable Data Protection Law. Any Data Subject rights, as described in Section 5 (Data Rights Requests) of this DPA, apply to Consumer rights.
8.6 Vendr will Process, retain, use, and disclose Personal Data only as necessary to provide the Services under the Agreement, which constitutes a business purpose. Vendr agrees not to (a) sell (as defined by the CCPA) Client Personal Data or Client end users’ Personal Data; (b) retain, use, or disclose Client Personal Data for any commercial purpose (as defined by the CCPA) other than providing the Services; or (c) retain, use, or disclose Client Personal Data outside of the scope of the Agreement.
8.7 Vendr certifies that its subprocessors, as listed in Schedule 1 of this DPA, are Service Providers under Applicable Data Protection Law, with whom Vendr has entered into a written contract that includes terms substantially similar to this DPA. Vendr conducts appropriate due diligence on its subprocessors.
8.8 Vendr will implement and maintain reasonable security procedures and practices appropriate to the nature of the Personal Data it Processes as set forth in Section 3 (Security) of this DPA.