This Data Processing Addendum ("DPA") forms part of the agreement between OhTry, Inc. ("Processor") and the customer ("Controller") for the provision of the Services. It applies to the extent Processor processes Personal Data on behalf of Controller and where the GDPR, UK GDPR, or comparable data protection laws apply.
1. Definitions
Capitalized terms not defined here have the meaning in the GDPR. "Personal Data", "Processing", "Controller", "Processor", and "Data Subject" have the meanings given in Article 4 of the GDPR.
2. Scope and Roles
Controller determines the purposes and means of Processing Personal Data submitted to the Services. Processor Processes such Personal Data only on documented instructions from Controller, including as set out in the agreement, the Services' documented functionality, and this DPA.
3. Nature of Processing
- Subject matter: Provision of the OhTry Services.
- Duration: The term of the agreement, plus any period required to delete or return Personal Data.
- Categories of data subjects: Controller's employees, contractors, end users, constituents, or customers.
- Categories of data: Identifiers, contact information, communications content and metadata, professional information, and any other data Controller submits to the Services.
4. Processor Obligations
- Process Personal Data only on Controller's documented instructions.
- Ensure that personnel authorized to Process Personal Data are bound by confidentiality.
- Implement appropriate technical and organizational measures as described in Annex II of the SCCs and Processor's security documentation.
- Assist Controller with data subject rights, DPIAs, and prior consultation obligations, taking into account the nature of Processing and information available to Processor.
5. Subprocessors
Controller authorizes Processor to engage the Subprocessors listed at /legal/subprocessors. Processor will provide notice of new or replacement Subprocessors and gives Controller the opportunity to object on reasonable data protection grounds. Processor remains liable for the acts and omissions of its Subprocessors.
6. International Transfers
Where Processing involves the transfer of Personal Data outside the EEA, UK, or Switzerland to a country without an adequacy decision, the parties incorporate the applicable EU Standard Contractual Clauses (Module 2 or 3, as appropriate) and, for UK transfers, the UK International Data Transfer Addendum, both of which are incorporated by reference.
7. Security Incidents
Processor will notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Controller's Personal Data and will provide information reasonably necessary for Controller to meet its notification obligations.
8. Audits
Processor will make available information reasonably necessary to demonstrate compliance with this DPA, including through third-party audit reports and completed security questionnaires. On-site audits are limited to once per year, at Controller's expense, subject to reasonable confidentiality and safety requirements.
9. Deletion and Return
On termination or expiration of the agreement, Processor will delete or return Personal Data as instructed by Controller within the timeframe set out in the Services' documentation, unless retention is required by law.
10. Contact
To execute a countersigned copy of this DPA or for privacy-related requests, email privacy@ohtry.com.