Data Processing Addendum
This GDPR Data Processing Addendum ("DPA") forms part of the Terms of Service available at https://clickmagick.com/terms/ or such other location as the Terms of
Service may be posted from time to time (as applicable, the "Agreement"), entered into by and between the Customer and ClickMagick, Inc. ("ClickMagick"), pursuant
to which Customer has accessed ClickMagick's Service as defined in the applicable Agreement. The purpose of this DPA is to reflect the parties' agreement with
regard to the processing of Personal Data in accordance with the requirements of Data Protection Legislation as defined below.
This DPA shall not replace or supersede any agreement or addendum relating to processing of Personal Data negotiated by Customer and referenced in the Agreement,
and any such individually negotiated agreement or addendum shall apply instead of this DPA.
In the course of providing the Service to Customer pursuant to the Agreement, ClickMagick may process Personal Data on behalf of Customer. ClickMagick agrees to
comply with the following provisions with respect to any Personal Data submitted by or for Customer to the Service or collected and processed by or for Customer
through the Service. Any capitalized but undefined terms herein shall have the meaning set forth in the Agreement.
Data Processing Terms
In this DPA, "Data Protection Legislation" means European Directives 95/46/EC and 2002/58/EC (as amended by Directive 2009/136/EC) and any legislation and/or
regulation implementing or made pursuant to them, or which amends, replaces, re-enacts or consolidates any of them (including the General Data Protection
Regulation (Regulation (EU) 2016/279)), and all other applicable laws relating to processing of Personal Data and privacy that may exist in any relevant
jurisdiction.
"data controller", "data processor", "data subject", "Personal Data", "processing", and "appropriate technical and organisational measures" shall be interpreted
in accordance with applicable Data Protection Legislation;
The parties agree that Customer is the data controller and that ClickMagick is its data processor in relation to Personal Data that is processed in the course of
providing the Service. Customer shall comply at all times with Data Protection Legislation in respect of all Personal Data it provided to ClickMagick pursuant to
the Agreement.
The subject-matter of the data processing covered by this DPA is the Service ordered by Customer either through ClickMagick's website or through an Ordering
Document and provided by ClickMagick to Customer via www.clickmagick.com, or as additionally described in the Agreement or the DPA. The processing will be carried
out until the term of Customer's ordering of the Service ceases. Further details of the data processing are set out in Annex 1 hereto.
In respect of Personal Data processed in the course of providing the Service, ClickMagick:
-
shall process the Personal Data only in accordance with the documented instructions from Customer (as set out in this DPA or the Agreement or as otherwise
notified by Customer to ClickMagick (from time to time) If ClickMagick is required to process the Personal Data for any other purpose provided by applicable law
to which it is subject, ClickMagick will inform Customer of such requirement prior to the processing unless that law prohibits this on important grounds of
public interest;
-
shall notify Customer without undue delay if, in ClickMagick's opinion, an instruction for the processing of Personal Data given by Customer infringes
applicable Data Protection Legislation;
-
shall implement and maintain appropriate technical and organisational measures designed to protect the Personal Data against unauthorised or unlawful processing
and against accidental loss, destruction, damage, theft, alteration or disclosure. These measures shall be appropriate to the harm which might result from any
unauthorised or unlawful processing, accidental loss, destruction, damage or theft of the Personal Data and having regard to the nature of the Personal Data
which is to be protected;
-
may hire other companies to provide limited services on its behalf, provided that ClickMagick complies with the provisions of this Clause. Any such
subcontractors will be permitted to process Personal Data only to deliver the services ClickMagick has retained them to provide, and they shall be prohibited
from using Personal Data for any other purpose. ClickMagick remains responsible for its subcontractors' compliance with the obligations of this DPA. Any
subcontractors to whom ClickMagick transfers Personal Data will have entered into written agreements with ClickMagick requiring that the subcontractor abide by
terms substantially similar to this DPA.
-
shall ensure that all ClickMagick personnel required to access the Personal Data are informed of the confidential nature of the Personal Data and comply with
the obligations sets out in this Clause;
-
at the Customer's request and cost (and insofar as is possible), shall assist the Customer by implementing appropriate and reasonable technical and
organisational measures to assist with the Customer's obligation to respond to requests from data subjects under Data Protection Legislation (including requests
for information relating to the processing, and requests relating to access, rectification, erasure or portability of the Personal Data) provided that
ClickMagick reserves the right to reimbursement from Customer for the reasonable cost of any time, expenditures or fees incurred in connection with such
assistance;
-
when the General Data Protection Regulation (Regulation (EU) 2016/279) comes into effect, shall take reasonable steps at the Customer's request and cost to
assist Customer in meeting Customer's obligations under Article 32 to 36 of that regulation taking into account the nature of the processing under this DPA,
provided that ClickMagick reserves the right to reimbursement from Customer for the reasonable cost of any time, expenditures or fees incurred in connection
with such assistance;
- at the end of the applicable term of the Service, upon Customer's request, shall securely destroy or return such Personal Data to Customer;
-
shall allow Customer and its respective auditors or authorized agents to conduct audits or inspections during the term of the Agreement, which shall include
providing reasonable access to the premises, resources and personnel used by ClickMagick in connection with the provision of the Service, and provide all
reasonable assistance in order to assist Customer in exercising its audit rights under this Clause. The purposes of an audit pursuant to this Clause include to
verify that ClickMagick is processing Personal Data in accordance with its obligations under the DPA and applicable Data Protection Legislation. Notwithstanding
the foregoing, such audit shall consist solely of: (i) the provision by ClickMagick of written information (including, without limitation, questionnaires and
information about security policies) that may include information relating to subcontractors; and (ii) interviews with ClickMagick's IT personnel. Such audit
may be carried out by Customer or an inspection body composed of independent members and in possession of the required professional qualifications bound by a
duty of confidentiality. For the avoidance of doubt no access to any part of ClickMagick's IT system, data hosting sites or centers, or infrastructure will be
permitted;
-
If ClickMagick becomes aware of any accidental, unauthorised or unlawful destruction, loss, alteration, or disclosure of, or access to the Personal Data that is
processed by ClickMagick in the course of providing the Service (an "Incident") under the Agreement it shall without undue delay notify Customer and provide
Customer (as soon as possible) with a description of the Incident as well as periodic updates to information about the Incident, including its impact on
Customer Content. ClickMagick shall additionally take action to investigate the Incident and reasonably prevent or mitigate the effects of the Incident;
- shall provide information requested by Customer to demonstrate compliance with the obligations set out in this DPA.
Annex 1
Details of the Data Processing
ClickMagick shall process information to provide the Service pursuant to the Agreement. ClickMagick shall process information sent by Customer's end users
identified through Customer's implementation of the Service. As an example, in a standard implementation, to utilize the Service, Customer may allow the following
information to be sent by default to ClickMagick:
Types of Personal Data
- City
- Region
- Country
- Time zone
- Browser
- Browser Version
- Device
- Current URL
- Initial Referrer
- Initial Referring Domain
- Operating System
- Referrer
- Referring Domain
- Screen Height
- Screen Width
- Search Engine
- Search Keyword
- UTM Parameters (ie. any UTM tags associated with the link a customer clicked to arrive at the domain)
Categories of Data Subjects
Users of the Customer's web and mobile applications.
Processing Activities
The provision of Service by ClickMagick to Customer.