この文書は現在、英語でのみ提供されています。
法的情報
データ処理追加条項
This Data Processing Addendum ("DPA") forms part of the Agreement between Ziddny World ("Processor") and the Customer ("Controller").
This DPA is effective as of the Effective Date of the Agreement and reflects the parties' agreement with regard to the Processing of Personal Data. In the event of a conflict between this DPA and any other provision of the Agreement, this DPA shall prevail to the extent of such conflict.
1. DEFINITIONS
Capitalised terms used but not defined in this DPA shall have the meanings given to them in the Agreement. In this DPA, the following terms shall have the meanings set out below:
"Agreement" shall have the meaning set forth in the Customer Terms and Conditions.
"Controller" means the entity which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. For the purposes of this DPA, the Customer is the Controller.
"Data Protection Laws" means all applicable worldwide legislation relating to data protection and privacy, including without limitation the GDPR, the UK GDPR, Japan's Act on the Protection of Personal Information (APPI), and any national implementing or supplementary legislation, as amended, repealed, consolidated or replaced from time to time.
"Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
"EEA" means the European Economic Area.
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
"Personal Data" means any information relating to a Data Subject that is Processed by the Processor as a result of, or in connection with, the provision of the Services under the Agreement. For the avoidance of doubt, Personal Data includes all "Customer Data" that constitutes personal data.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed.
"Processing", "Process", and "Processed" mean any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
"Processor" means the entity which Processes Personal Data on behalf of the Controller. For the purposes of this DPA, Ziddny World is the Processor.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
"Sub-processor" means any third party appointed by or on behalf of the Processor to Process Personal Data on behalf of the Controller in connection with the Agreement.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner under the Data Protection Act 2018.
2. PROCESSING OF PERSONAL DATA
2.1 Roles and Responsibilities. The parties acknowledge and agree that for the purpose of the Data Protection Laws, the Customer is the Controller and Ziddny World is the Processor of the Personal Data. The details of the Processing are set out in Annex 1 to this DPA.
2.2 Processor's Obligations. The Processor shall:
- only Process Personal Data on the Controller's documented instructions, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by applicable law to which the Processor is subject. The Controller's instructions are documented in this DPA and the Agreement. The Controller's use and configuration of the features of the Services shall constitute documented instructions to the Processor to Process Personal Data on the Controller's behalf; and
- immediately inform the Controller if, in its opinion, an instruction infringes Data Protection Laws.
2.3 Controller's Obligations. The Controller warrants that it has all necessary rights to provide the Personal Data to the Processor for the Processing to be carried out in relation to the Services and that one or more lawful bases set out in Data Protection Laws supports the lawfulness of the Processing.
3. CONFIDENTIALITY AND SECURITY
3.1 Confidentiality. The Processor shall ensure that any persons it authorises to Process the Personal Data (including its staff, agents, and subcontractors) are subject to a binding duty of confidentiality (whether a contractual or statutory duty).
3.2 Security Measures. The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons. Such measures shall include, as appropriate, the measures referred to in Article 32 of the GDPR. The Processor's current security measures are described in Annex 2.
4. SUB-PROCESSORS
4.1 Authorisation. The Controller provides a general written authorisation for the Processor to engage Sub-processors to Process Personal Data on the Controller's behalf. The Processor shall make available to the Controller a list of its current Sub-processors, which is located at [URL] (the "Sub-processor List").
4.2 New Sub-processors. The Processor shall give the Controller a prior written notice of the appointment of any new Sub-processor by updating the Sub-processor List and providing notice to the Controller's designated contact.
4.3 Right to Object. The Controller may object to the appointment of a new Sub-processor within fourteen (14) days of receiving notice, provided such objection is based on reasonable grounds relating to Data Protection Laws. If no objection is received within 14 days, the sub-processor shall be deemed accepted. If the Controller objects, the Processor will use reasonable efforts to make available to the Controller a change in the Services or recommend a commercially reasonable change to the Controller's configuration or use of the Services to avoid Processing of Personal Data by the objected-to new Sub-processor. If the Processor is unable to make available such change within a reasonable period of time, which shall not exceed thirty (30) days, the Controller may terminate the applicable Order Form with respect to only those Services which cannot be provided by the Processor without the use of the objected-to new Sub-processor by providing written notice to the Processor.
4.4 Flow-down Obligations. The Processor shall ensure that any Sub-processor it engages is subject to data protection obligations that are no less protective than those imposed on the Processor in this DPA. The Processor shall remain fully liable to the Controller for the performance of the Sub-processor's data protection obligations.
5. INTERNATIONAL TRANSFERS
5.1 Processing Location. The Controller acknowledges and agrees that the Processor and its Sub-processors may Process Personal Data in countries outside the country in which the Controller is located. The primary processing location for the Services is Japan.
5.2 Transfers from the EEA/UK to Japan. The parties acknowledge that the European Commission has issued an adequacy decision for Japan under Article 45 of the GDPR. To the extent Personal Data is transferred from the EEA or the United Kingdom to the Processor in Japan, such transfer shall be governed by that adequacy decision, subject to its scope and any supplementary measures required.
5.3 Other Transfers. To the extent that the Processing of Personal Data involves a transfer from the EEA or the United Kingdom to a country not covered by an adequacy decision, the parties agree that the Standard Contractual Clauses shall be incorporated by reference into this DPA and shall apply to such transfer, as follows:
- 5.3.1 In relation to data transferred out of the EEA, the SCCs will apply, completed as follows: Module Two (Controller to Processor) will apply. Clause 7 (Docking Clause) will not apply. In Clause 9, Option 2 will apply, and the time period for notice of sub-processor changes will be as set out in Clause 4.2 of this DPA. In Clause 11, the optional language will not apply. In Clauses 17, Option 1 shall apply, and the governing law shall be that of Ireland. In Clause 18, the jurisdiction shall be Ireland. Annexes I and II of the SCCs shall be deemed completed with the information set out in the Annexes to this DPA.
- 5.3.2 In relation to data transferred out of the United Kingdom, the SCCs as implemented under sub-clause 5.3.1 shall apply, but as amended and supplemented by the UK Addendum, which is incorporated herein by reference.
6. ASSISTANCE TO THE CONTROLLER
6.1 Data Subject Rights. Taking into account the nature of the Processing, the Processor shall assist the Controller by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising Data Subject rights laid down in Chapter III of the GDPR. If the Processor receives a request directly from a Data Subject, it will promptly notify the Controller and will not respond to the Data Subject, unless legally compelled to do so.
6.2 DPIAs and Prior Consultation. The Processor shall, upon reasonable request and at the Controller's expense, provide reasonable assistance to the Controller with any data protection impact assessments and prior consultations with supervising authorities which the Controller reasonably considers to be required by Articles 35 or 36 of the GDPR, in each case solely in relation to Processing of Personal Data by, and taking into account the nature of the Processing and information available to the Processor.
7. PERSONAL DATA BREACH
7.1 The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, upon the Processor becoming aware of a Personal Data Breach affecting the Controller's Personal Data.
7.2 Such notification shall, as a minimum:
- describe the nature of the Personal Data Breach, the categories and approximate number of Data Subjects and Personal Data records concerned;
- communicate the name and contact details of the Processor's data protection officer or other contact point where more information can be obtained;
- describe the likely consequences of the Personal Data Breach; and
- describe the measures taken or proposed to be taken by the Processor to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
8. DELETION AND RETURN OF DATA
Subject to the terms of the Agreement, the Processor shall, at the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of Services relating to Processing, and shall delete existing copies unless applicable law requires storage of the Personal Data.
9. AUDIT RIGHTS
9.1 The Processor shall make available to the Controller, on request, all information necessary to demonstrate compliance with this DPA and the obligations laid down in Article 28 of the GDPR.
9.2 The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Any such audit shall be subject to the Controller giving the Processor reasonable prior notice, shall be conducted during normal business hours, and shall not unreasonably interfere with the Processor's day-to-day business. The Controller shall be responsible for all costs and expenses of such an audit. The Controller may not conduct more than one audit in any twelve (12) month period, unless required by law or following a confirmed data breach. The Controller accepts that, to the extent permitted under Data Protection Laws, the Processor may satisfy this requirement by providing a copy of its then most recent third-party audit report.
10. GENERAL TERMS
10.1 Liability. The Processor's liability under this DPA is subject to the limitations of liability set out in the Agreement.
10.2 Governing Law and Jurisdiction. This DPA is governed by the laws of Singapore. Any dispute arising out of or in connection with this contract, including any question regarding its existence, validity or termination, shall be referred to and finally resolved by arbitration administered by the Singapore International Arbitration Centre ("SIAC") in accordance with the Arbitration Rules of the Singapore International Arbitration Centre ("SIAC Rules") for the time being in force, which rules are deemed to be incorporated by reference in this clause. The seat of the arbitration shall be Singapore. The Tribunal shall consist of one arbitrator(s). The language of the arbitration shall be English.
ANNEX 1 TO THE DPA: DETAILS OF PROCESSING
A. LIST OF PARTIES
B. DESCRIPTION OF PROCESSING
The provision of the Services by the Processor to the Controller, as detailed in the Agreement.
For the term of the Agreement, and until all Personal Data is deleted or returned in accordance with Clause 8 of this DPA.
To enable the Controller's Users to create and generate Outputs (as defined in the Agreement) by submitting voice and/or text inputs to the Platform.
Account Information: Name, email address, user IDs.
User-Generated Content: Text and voice prompts submitted by Users.
Special Categories of Personal Data: Biometric Data, specifically voice recordings.
Users who are natural persons authorised by the Controller to access and use the Services.
Collection, recording, storage, analysis, generation of Outputs, hosting, retrieval, use, and erasure/deletion upon termination of services.
ANNEX 2 TO THE DPA: TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
The Processor will maintain administrative, physical, and technical safeguards for the protection of the security, confidentiality, and integrity of Personal Data. These include:
- Physical access to data centres is strictly controlled by Sub-processors (e.g. AWS).
- Logical access to production environments is restricted to authorised personnel on a need-to-know basis, using multi-factor authentication.
- Personal Data is encrypted in transit using industry-standard protocols (e.g. TLS 1.2 or higher).
- Personal Data is encrypted at rest using strong encryption algorithms (e.g. AES-256).
- The Processor collects and processes only the Personal Data necessary to provide the Services.
- The infrastructure is designed for high availability and fault tolerance.
- Regular backups of Personal Data are taken to allow for restoration in case of disaster.
- Confidentiality agreements are in place with all personnel and contractors who have access to Personal Data.
- The Processor maintains an incident response plan to detect, respond to, and report on Personal Data Breaches in accordance with this DPA.
The Processor may update or modify these security measures from time to time, provided that such updates and modifications do not result in a degradation of the overall security of the Services.
