Data Processing Agreement
Governs TribeROI’s processing of personal data on the Customer’s behalf in the application at beta.triberoi.com.
- Version
- 1.0
- Annexes
- I, II and III — see /dpa/annexes
Preamble
This Data Processing Agreement (“DPA”) forms part of the agreement between TribeROI Inc, a company registered in New Jersey, United States, with its principal place of business at 971 US Highway 202N, Suite N, Branchburg, NJ 08876 (“TribeROI”), and the customer identified in that agreement (“Customer”), governing Customer’s use of the TribeROI application at beta.triberoi.com (the “Service”, and together the “Agreement”).
This DPA applies to TribeROI’s processing of personal data on Customer’s behalf. It becomes effective on the effective date of the Agreement and remains in force for its duration.
Where this DPA conflicts with the Agreement, this DPA governs in respect of the processing of personal data. Where the Standard Contractual Clauses incorporated under section 9 conflict with this DPA, those Clauses govern.
1. Definitions
“Applicable Data Protection Law” means all laws relating to the protection of personal data applicable to the processing under this DPA, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the GDPR as incorporated into the law of the United Kingdom (“UK GDPR”), the Swiss Federal Act on Data Protection, and applicable United States state privacy laws.
“Community Member Data” means personal data relating to members of Customer’s community which Customer uploads to the Service or which the Service collects from a Connected Platform on Customer’s instruction.
“Connected Platform” means a third-party service which Customer authorizes TribeROI to read from using credentials Customer supplies. Connected Platforms are listed in Annex III Part B.
“Customer Personal Data” means Community Member Data together with personal data relating to Customer’s Authorized Users.
“Authorized User” means an individual Customer permits to access the Service.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
“UK Addendum” means the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
“Sub-processor” means a third party engaged by TribeROI to process Customer Personal Data.
“Personal Data Breach” has the meaning given in Article 4(12) GDPR.
The terms “controller”, “processor”, “data subject”, “personal data”, “processing”, and “supervisory authority” have the meanings given in the GDPR.
2. Roles of the parties
In respect of Customer Personal Data, Customer is the controller and TribeROI is the processor.
Where Customer itself processes Community Member Data on behalf of a third party, Customer is a processor and TribeROI is a sub-processor. In that case Customer warrants that it has the third party’s authority to appoint TribeROI and to give the instructions set out in this DPA.
TribeROI is an independent controller in respect of personal data relating to its own commercial relationship with Customer, including account administration, billing, and service communications. That processing is governed by the TribeROI privacy notice and falls outside this DPA.
Community members have no direct relationship with TribeROI. Customer alone determines which individuals’ data enters the Service, from which sources, and for what purpose.
3. Scope and instructions
TribeROI will process Customer Personal Data only on Customer’s documented instructions, including for international transfers, unless required to do otherwise by law to which TribeROI is subject. Where such a legal requirement applies, TribeROI will inform Customer before processing unless the law prohibits it.
Customer’s complete and final instructions at the effective date are: the Agreement, this DPA including its Annexes, and Customer’s configuration and use of the Service. Additional instructions must be agreed in writing and may attract a reasonable charge where they fall outside the Service as configured.
TribeROI will not:
sell or share Customer Personal Data as those terms are defined in applicable United States state privacy laws;
retain, use, or disclose Customer Personal Data for any purpose other than performing the Service;
combine Customer Personal Data with personal data received from any other source, except as required to perform the Service for Customer;
use Customer Personal Data to train machine learning models.
TribeROI will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. TribeROI may suspend the affected processing until the instruction is confirmed or withdrawn.
4. Customer obligations and warranties
Customer warrants and undertakes that:
Lawful basis. It has a valid lawful basis under Applicable Data Protection Law for each category of Customer Personal Data it submits to the Service and for the processing described in Annex I.
Notice to members. It has provided community members with the information required by Articles 13 and 14 GDPR, including that their data is processed by a third-party analytics provider. Because community members have no relationship with TribeROI, TribeROI cannot discharge this duty and does not attempt to.
Connected Platform authorization.It is authorized to disclose data from each Connected Platform it connects, that the credentials it supplies are its own and lawfully held, and that its use of that data through the Service is permitted by that platform’s terms. Customer acknowledges that connecting certain platforms causes member email addresses to be disclosed to TribeROI.
Special category data. It will not submit to the Service, and will not connect a source whose ordinary content would constitute, special categories of personal data within the meaning of Article 9 GDPR or data relating to criminal convictions and offences. Customer acknowledges that free-text fields, tags, discussion topic titles ingested from Connected Platforms, and the interaction graph are technically capable of carrying such data, and that the Service applies no technical control preventing it.
Children. It will not submit data relating to individuals below the age at which consent applies under Applicable Data Protection Law. The Service applies no age verification.
Accuracy and legality. It is responsible for the accuracy, quality, and legality of Customer Personal Data and of the means by which it acquired that data.
Customer will not submit Customer Personal Data to any free-text field where it is not necessary for the purpose.
Customer is responsible for configuring roles and permissions within the Service so that access is limited to Authorized Users with a legitimate need.
5. Confidentiality
TribeROI will ensure that each person authorized to process Customer Personal Data is bound by an appropriate obligation of confidentiality, whether contractual or statutory, and has received appropriate training.
TribeROI personnel may access Customer Personal Data only where necessary for support, administration, or incident response. Administrative access is limited as described in Annex II section 3.
6. Security
TribeROI will implement and maintain the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the risks to data subjects.
TribeROI may update those measures provided the update does not materially reduce the overall level of security.
Annex II states the limits of each measure as well as its coverage. Customer acknowledges those stated limits.
7. Sub-processors
Customer grants TribeROI general written authorization to engage the Sub-processors listed in Annex III Part A and at https://beta.triberoi.com/sub-processors, which is the canonical list.
TribeROI will give Customer at least 30 days’ notice before engaging a new Sub-processor. Customer may object within that period on reasonable data protection grounds. The parties will work in good faith toward a resolution. If none is reached, Customer may terminate the affected part of the Service without penalty for the remainder of the term.
TribeROI will impose on each Sub-processor data protection obligations no less protective than those in this DPA, and remains liable to Customer for each Sub-processor’s performance.
Connected Platforms are not Sub-processors. They are sources from which the Service reads on Customer’s instruction using Customer’s own credentials. Customer holds the relationship with each. TribeROI does not transmit Customer Personal Data to them.
8. Data subject rights
The Service provides Customer with the functionality described in Annex II section 14 to respond to data subject requests, comprising access, portability, erasure, restriction, and rectification.
Customer acknowledges the following characteristics of that functionality:
Restriction. A member placed under restriction is removed from all Customer-facing surfaces and retained unchanged. Statistics already computed are not recalculated. Processing does not cease entirely.
Erasure limits. Erasure does not reach the categories listed in Annex II section 15.
Connected Platform deletions. Where a member is deleted at the source, that deletion is not propagated to the Service. The Service retains what it ingested until Customer removes it. Customer is responsible for removing such records.
Objection and withdrawal of consent. The Service holds no consent flag. Where a member objects or withdraws consent, Customer must act on that through the erasure or restriction functionality.
Where TribeROI receives a request directly from a community member, TribeROI will acknowledge it within five business days, will not act on it, will refer the individual to Customer as controller, and will notify Customer that the request was received.
Taking into account the nature of the processing, TribeROI will provide Customer with reasonable assistance in responding to data subject requests which Customer cannot fulfil through the Service.
9. International transfers
Where Customer transfers personal data subject to the GDPR to TribeROI, the SCCs apply and are incorporated by reference:
Module Two (controller to processor) where Customer is a controller;
Module Three (processor to sub-processor) where Customer is a processor.
For the purposes of the SCCs:
Clause 7 (docking clause) does not apply.
Clause 9: Option 2 (general written authorization) applies, with the notice period in section 7.2.
Clause 11: the optional redress wording does not apply.
Clause 17: Option 1 applies and the governing law is the law of Ireland.
Clause 18(b): the forum is the courts of Ireland.
Annex I of the SCCs is completed by Annex I of this DPA; Annex II of the SCCs by Annex II; Annex III of the SCCs by Annex III Part A.
Where the transfer is subject to the UK GDPR, the UK Addendum applies and is incorporated by reference, with the SCCs as completed above forming the addended clauses. TribeROI as importer may end the UK Addendum in accordance with its Table 4.
Where the transfer is subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, references to EU Member States include Switzerland, and the competent authority is the Federal Data Protection and Information Commissioner.
TribeROI will provide Customer with information reasonably necessary to complete a transfer impact assessment on request.
10. Personal Data Breach
TribeROI will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notification will describe, so far as known at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the full picture is not available, TribeROI will provide information in phases without undue further delay.
TribeROI will provide reasonable assistance to Customer in meeting Customer’s own notification obligations to supervisory authorities and data subjects.
Notification under this section is not an acknowledgement of fault or liability.
11. Deletion and return
Customer may export Customer Personal Data through the Service at any time during the term.
Within 30 days of termination or expiry of the Agreement, TribeROI will delete Customer Personal Data, save where retention is required by law.
Deletion under 11.2 is subject to the limits in Annex II section 15, in particular that backups are overwritten on a rolling seven-day cycle and application logs on a rolling thirty-day cycle. Data remaining in those systems is not processed further and is deleted on expiry of the relevant cycle.
TribeROI will certify deletion in writing on request.
12. Records and audit
TribeROI will maintain records of its processing under this DPA and will make available to Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR.
Customer may audit TribeROI’s compliance no more than once per twelve months on 30 days’ written notice, subject to reasonable confidentiality undertakings, at Customer’s cost, and conducted so as not to disrupt TribeROI’s operations. A supervisory authority may audit where Applicable Data Protection Law requires it, without the frequency limit.
TribeROI will provide reasonable assistance with data protection impact assessments and with prior consultation of a supervisory authority, taking into account the nature of the processing and the information available to it.
13. Liability and precedence
Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Applicable Data Protection Law does not permit such limitation.
Nothing in this DPA limits a data subject’s rights under the SCCs or under Applicable Data Protection Law.
Order of precedence: (1) the SCCs; (2) this DPA; (3) the Agreement.
14. Term
This DPA takes effect on the effective date of the Agreement and continues until TribeROI has completed deletion under section 11.
Signature
TribeROI Inc
Customer