DPA
Data Processing Agreement
This Data Processing Agreement (“DPA“) forms an integral part of, and is subject to the Terms of Use (“Terms”) available at https://site.pulseem.co.il/terms-of-use/ which have been electronically accepted by the person or entity using the Services (“Controller“). This DPA is between the Controller and Pulseem Ltd. (“Processor“) and shall be effective as of the date of the Controller’s electronic acceptance of the Terms. Capitalized terms not otherwise defined herein shall have the meaning given to them in the Terms.
WHEREAS, in connection with the performance of its obligations under the Agreement, Processor may process Controller Personal Data (both as defined below) on behalf of the Controller; and
WHEREAS, the parties wish to set forth the mutual obligations with respect to the processing of Controller Personal Data by the Processor;
NOW THEREFORE, intending to be legally bound, the parties hereby agree as follows:
- Definitions. In addition to capitalized terms defined elsewhere in this DPA, the following terms shall have the meanings set forth below:
- “Applicable Law” means as applicable: (i) Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation) (“GDPR“); (ii) the Act of 10 May 2018 on the Protection of Personal Data (Journal of Laws of the Republic of Poland of 2019, item 1781, consolidated text of 19 September 2019; (iii) laws implementing or supplementing the GDPR and/or the CCPA; and all other applicable laws, rules, regulations, regulatory guidance and regulatory requirements from time to time, in each case in each jurisdiction where the Parties Process Personal Data.
- “Controller Personal Data” means any Personal Data Processed by Processor on behalf of Controller pursuant to or in connection with the Agreement.
- “Data Protection Laws” means Applicable Law and, to the extent applicable, the data protection or privacy laws of any other applicable country where the Services is provided or as agreed in writing between the Parties.
- “Standard Clauses” means the standard clauses for the transfer of Personal Data to processors established in third countries under Directive 95/46/EC of the European Parliament and of the Council incorporated herein by reference.
- The terms “Controller“, “Data Subject“, “Personal Data“, “Processor” and “Processing” shall have the meanings ascribed to them in the Applicable Law.
- Processing of Personal Data.
- To the extant the Processor shall Process Controller Personal Data on Controller’s behalf, it shall act in accordance with the Controller’s instructions as specified in this DPA, including without limitation with regard to transfers of Controller Personal Data to a third country or international organization. Any other Processing shall be permitted only in the event that such Processing is required by any Data Protection Laws to which the Processor is subject or any other applicable law. In such event, Processor shall, unless prohibited by the Applicable Laws on grounds of public interest, inform Controller of that requirement before engaging in such Processing. For the avoidance of doubt, the Controller’s instructions for the Processing of Personal Data shall comply with all Applicable Laws.
- Controller instructs Processor (i) to Process Controller Personal Data for the provision of the services, as detailed in the Agreement (“Services“) and as otherwise set forth in the Agreement and in this DPA, and/or as otherwise directed by Controller; and (ii) to transfer Controller Personal Data to any country or territory, including the USA, as reasonably necessary for the provision of the Services and in accordance with Applicable Law.
- Controller sets forth the details of the Processing of Controller Personal Data, as required by the Applicable Law and as set forth in Schedule I (Details of Processing of Controller Personal Data), attached hereto.
- To the extent that the Processor Processes Personal data in countries outside of the European Economic Area that do not provide an adequate level of data protection, the Standard Contractual Clauses shall apply and shall be incorporated herein by reference upon execution of this DPA by the parties.
- Controller represents and warrants that it has and shall maintain throughout the term of the Agreement and this DPA, all necessary rights to provide the Controller Personal Data to Processor for the Processing to be performed in relation to the Services and in accordance with the Agreement and this DPA. To the extent required by Applicable Laws, Controller is responsible for obtaining any necessary Data Subject consents to the Processing, by the Processor and including for the transfer of such Personal Data outside of the territory of their residence, or any other sufficient statutory legal bases to justify the Processing (including the said transfer), and for ensuring that a record of such consents (or other legal bases) is maintained throughout the term of the Agreement and this DPA and/or as otherwise required under Data Protection Laws. The Controller shall have sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which the Controller acquired Personal Data.
- Processor Processor shall take reasonable steps to ensure that access to the Controller Personal Data is limited on a need to know and/or access basis and that all Processor employees receiving such access are subject to confidentiality undertakings or professional or statutory obligations of confidentiality in connection with their access to and use of Controller Personal Data.
- Security. Processor shall implement appropriate technical and organizational measures to ensure an appropriate level of security of the Controller Personal Data. In assessing the appropriate level of security, Processor shall take into account the risks that are presented by the nature of the Processing and the information available to the Processor.
- Sub-processing
- Appointment of Sub-processors. Controller acknowledges and agrees that (i) Processor may be retained as Sub-processor („Sub-processor”); and (ii) the Processor may engage third-party Sub-processors in connection with the provision of the Services. Processor has entered or will enter into a written agreement with each Sub-processor containing data protection obligations not less protective than those in this DPA with respect to the protection of the Controller Personal Data, to the extent applicable to the specific services provided by such Sub-processor.
- Objection Right for New Sub-processors. Processor will provide reasonable prior notice if it intends to make any changes to its Sub-processors. Controller may object to Processor’s use of a new Sub-processor in respect of the Services provided to the Controller by notifying Processor promptly in writing within ten (10) business days after Processor’s notice is posted. In the event Controller objects to a new Sub-processor, as permitted in the preceding sentence, Processor will use reasonable efforts to make available to Controller a change in the Services or recommend a commercially reasonable change to Controller’s configuration or use of the Services to avoid Processing of Personal Data by the objected-to new Sub-processor without unreasonably burdening Controller. If Processor is unable to make available such change within a reasonable period of time, which shall not exceed thirty (30) days, Controller and Processor will decide on a case-by-case basis whether to terminate the part of Services which relies on such new Sub-processors and cannot be provided by Processor without the use of the objected-to new Sub-processor.
- Liability. Processor shall be liable for the acts and omissions of its Sub-processors to the same extent Processor would be liable if performing the services of each Sub-processor directly under the terms of this DPA, except as otherwise set forth in this DPA.
- Security
- Security Measures. Processor has implemented and will maintain appropriate technical and organizational security measures to protect the Controller Personal Data from Security Incidents and to preserve the security and confidentiality of the Personal Data (“Security Measures“).
- Updates to Security Measures. Controller is responsible for reviewing the information made available by Processor relating to its Security Measures and making an independent determination as to whether the Services meet Controller’s requirements and legal obligations under Applicable Controller acknowledges that the Security Measures are subject to technical progress and development and that the Processor may update or modify the Security Measures from time to time provided that such updates and modifications do not result in the degradation of the overall security of the Services purchased by Controller.
- Processor restricts its personnel from Processing the Controller Personal Data without authorization by Processor as set forth in the Security Measures and shall ensure that any person who is authorized by Processor to process the Controller Personal Data is under an appropriate obligation of confidentiality.
- The Controller’s Responsibilities. Notwithstanding the above, Controller agrees that except as provided by this DPA, Controller is responsible for the Controller’s secure use of the Services, including securing Controller’s account authentication credentials, protecting the security of the Controller Personal Data when in transit to and from the Services, and taking any appropriate steps to securely encrypt or backup any of the Controller Personal Data uploaded to the Services.
- Controller’s Data Incident Management and Response. Processor shall notify Controller as soon as commercially practicable, after becoming aware of the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Controller Personal Data, transmitted, stored, or otherwise Processed by the Processor or its Sub-processors (a “Controller’s Data Incident”). Processor shall use reasonable efforts to identify the cause of such Controller’s Data Incident and take those steps as the Processor deems reasonably necessary in order to remediate the cause of such Controller’s Data Incident to the extent the remediation is within Processor’s reasonable control. The obligations herein shall not apply to incidents that are caused by the Controller or the Controller’s
- Data Protection Impact Assessment and Prior Consultation. At Controller’s written request and expense, the Processor shall provide reasonable assistance to Controller with respect to any Controller Personal Data Processed by Processor, with any data protection impact assessments or prior consultations with the relevant authorities or other competent data privacy authorities, as required under any Applicable Laws.
- Audit Rights. Any provision of security attestation reports or audits shall take place in accordance with the Controller’s rights under the Agreement with respect to the Services. If such Agreement does not include a provision regarding security attestation reports, Processor shall provide a copy of its most current security attestation report upon Controller’s written request not more than once annually. If such Controller’s does not include audit rights, Processor and Controller will discuss and agree in advance on the reasonable start date, scope and duration of and security and confidentiality controls applicable to any audit, and Processor reserves the right to charge a fee (based on the Processor’s reasonable costs) for any such audit. Processor will provide further details of any applicable fee and the basis of its calculation to the Controller in advance of such audit.
- Individual Data Subject Rights. Processor shall, to the extent legally permitted, promptly notify the Controller if it receives a request from a Data Subject to access, correct, or delete that person’s Personal Data or if a Data Subject objects to the Processing thereof (“Data Subject Request”). Processor shall not respond to a Data Subject Request without the Controller’s prior written consent except to confirm that such request relates to the Controller, to which the Controller hereby agrees. To the extent the Controller, in its use of the Services, do not have the ability to address a Data Subject Request, the Processor shall upon the Controller’s request provide commercially reasonable assistance to facilitate such Data Subject Request to the extent the Processor is legally permitted to do so and provided that such Data Subject Request is exercised in accordance with Data Protection Laws. To the extent legally permitted, the Controller shall be responsible for any costs arising from the Processor’s provision of such assistance.
- Indemnity. Controller shall indemnify and hold Processor harmless against all claims, actions, third party claims, losses, damages and expenses incurred by Processor and arising directly or indirectly out of or in connection with a breach of this DPA and/or the Applicable Law by Controller.
- Term and Termination
- The Term of this DPA shall begin as of the Effective Date and continue in full force and effect for so long as Processor is processing Personal Data on the Controller’s behalf.
- After sixty (60) days following termination or expiration of this DPA, Processor shall delete all of the Controller Personal Data in its possession or control such that it cannot be recovered or reconstructed; provided, however, that, unless prohibited by Applicable Law, Processor shall promptly delete the Controller’s Data upon receipt of its written request. This requirement shall not apply to the extent Processor is required by Applicable Law to retain some or all of the Controller Personal Data, or to the Data it has archived on back-up systems, which Processor shall securely isolate and protect from any further processing, except to the extent required by Law.
- General Terms.
- This DPA states the entire agreement between the parties with respect to the subject matter of this DPA and shall terminate and supersede all previous discussions, proposals, negotiations, representations, commitments, writings, agreements and other communications, both oral and written, between the parties. This DPA may not be modified or amended except by a written document signed by each of the parties.
- All of the terms and conditions of this DPA shall be binding upon, inure to the benefit of, and be enforceable by the respective successors and permitted assignees of the parties.
- Any failure or delay by either party in exercising any right or remedy will not constitute a waiver.
- In the event that any provision of this DPA is held invalid or unenforceable, the remaining provisions shall remain in full force and effect.
- This DPA may be executed in number of counterparts, each of which together shall constitute one and the same instrument. The exchange of a fully executed DPA (in counterparts or otherwise) by electronic transmission shall be sufficient to bind the parties to the terms of this DPA.
- The validity, construction and performance of this DPA shall be governed by and interpreted in accordance with the laws of the State of Israel, without giving effect to the principles of conflict of laws thereof. The competent courts of the city of Tel Aviv-Jaffa, Israel shall have exclusive jurisdiction to settle all disputes arising in connection with this DPA and no other courts shall have any jurisdiction whatsoever in respect of such disputes.
- Any notices to be given hereunder shall be served on a party by prepaid registered letter, facsimile, or email to its address given herein or such other address as may from time to time be notified for this purpose. Any notice given by letter shall be deemed to have been served four days after the time at which it was posted and any notice given by facsimile or email shall be deemed to have been served 24 hours after it is dispatched.
- By electronically accepting the Terms, the Controller represents and warrants that it is authorized to accept this DPA, and that said Controller has authorized and approved this DPA.
By electronically accepting the Terms
ELECTRONIC ACCEPTANCE, you hereby acknowledge and agree that you have read, understood and agree to be bound by all of the terms and conditions of this DPA, which forms an integral part of the Terms.
Schedule I
Details of Data Processing
- Subject Matter. The subject matter of the data processing under this DPA is the Customer’s Data to the extent it constitutes Personal Data.
- Duration. As between the Processor and the Controller, the duration of the data processing under this DPA is the period of the provision of Services by the Processor.
- Purpose and Nature of the Processing. The purpose of the data processing under this DPA is the provision of the Services to the Controller and the performance of the Controller’s obligations under this DPA (or as otherwise agreed by the Parties).
- Categories of Data Subjects. Data Subjects consist of the Controller’s clients, employees or any recipients of direct marketing communications, and the Controller’s employees or other authorized users who have access to the Processor’s system.
- Types of Personal Data. Regarding Controller’s clients, the types of Personal Data collected by the Processor or its Service includes contact information (such as name, email address, phone number, address), account information, communication preferences, and any other Personal Data that the Controller chooses to include in the data processed through the Services.