Data Processing Addendum
Data Processing Addendum
This data processing addendum (“ DPA”) is incorporated into the Agreement, and is entered into as of the date of entering into the Agreement. For the purposes of this DPA, the Customer is the Controller and Meltwater the Processor (or Service Provider, as applicable).
1. Interpretation
The terms and expressions set out in this DPA shall have the following meanings:
- “Agreement” means the agreement between Meltwater and the Customer for subscriptions to purchase the Platform;
- “Data Controller”, “Data Processor” and “processing” shall have the meanings given to them in the Applicable Privacy Law;
- “Personal Data” means all data relating to individuals which is processed by the Data Processor on behalf of the Data Controller in accordance with this DPA;
- “Applicable Privacy Law” means all privacy, data security, and data protection laws, directives, regulations, and rules in any jurisdiction applicable to the Personal Data processed under this DPA, including the General Data Protection Regulation (GDPR);
- “DPF” means the EU-U.S. Data Privacy Framework;
- “SCCs” means the Standard Contractual Clauses;
- “Sub-processor” means any third party that Processor engages to Process Personal Data on behalf of Processor.
All other defined terms shall have the meaning given to them in the Agreement.
2. Categories of Personal Data covered by the DPA
2.1. Should the Controller use the Media Intelligence (Meltwater) platform: Contact details of the Controller’s employees who are added as Authorized Users to the Platform.
2.2. Should the Controller use any of the following Meltwater services: the categories of Personal Data processed also include the following: name, email address, possibly telephone number, title, employer and social handle, of the data subjects whose information the Controller uploads to the Platform.
2.3 Should the Controller use Meltwater Engage, the categories of Personal Data processed may also include the name, email address, possibly telephone number, and social handle, of the data subjects in the Controller’s Salesforce instance which the Controller syncs with to the Platform.
2.4. Should the Controller use the Influencers Marketing platform: Controller’s employees’ contact details and any other Personal data related to influencers or the Controller’s customers.
2.5. Should the Controller use Consumer Insights or Content Curation platform: Contact details of the Controller’s employees who are added as Authorized Users to the Platform.
2.6. Should the Controller use the Sales Intelligence platform: Email address, role and the name of the employer.
3. Processing and use of Personal Data
3.1. Processor is to process Personal Data received from the Controller in compliance with instructions provided by the Controller as set out in this DPA.
3.2. The Processor shall at all times comply with Applicable Privacy Law and shall not perform its obligations in such a way as to cause the Controller to breach any of its applicable obligations.
3.3. The Processor agrees to comply with any reasonable measures required by the Controller to ensure that its obligations under this DPA are satisfactorily performed in accordance with Applicable Privacy Law.
4. Security of Personal Data
4.1. Processors agrees to implement and maintain an appropriate information security program with technical and organisational measures to protect the security of Personal Data.
4.2. Processor shall supply details of the technical and organisational systems in place to safeguard the security of the Personal Data held.
4.3. All Personal Data provided to the Processor is confidential and may not be copied, disclosed or processed in any way without the express authority of the Controller.
5. Sub-processors and employees
5.1. Where the Processor processes Personal Data on behalf of the Controller, it shall take reasonable steps to ensure the reliability of all employees and Sub-processors.
5.2. Processor will take reasonable measures to inform and train its employees about relevant privacy legislation and data security.
5.3. Controller approves the use of the Sub-processors listed at Subprocessors List.
6. Audit
Processor agrees to permit persons authorized by the Controller to access Processor’s premises where Personal Data is processed and to inspect the Processor’s systems.
7. Access to Personal Data and Security Incident
7.1. Processor shall notify the Controller if it receives a request from a data subject to have access to that person’s Personal Data or a complaint relating to the Controller’s obligations.
7.2. Processor shall provide full cooperation and assistance in relation to any complaint or request made.
7.3. If the Processor becomes aware of any unauthorized processing of any Personal Data or that any Personal Data is lost or destroyed, the Processor shall notify the Controller accordingly.
8. International data transfer
8.1. Personal Data is accessed or transferred to Processor outside of the country of the Controller, the transfers shall occur according to the requirements of the Applicable Privacy Law.
8.2. Meltwater News US Inc. participates in and certifies compliance with the DPF.
8.3. The Parties are deemed to have signed the SCCs as required for personal data from the EU and EEA.
8.4. To the extent Personal Data includes personal data from the UK, the parties agree to the amendments to the SCCs necessary for compliance with UK law.
9. Return or disposal
The Processor shall destroy or transfer all Personal Data to the Controller on request. The Personal Data shall be destroyed at the latest six months after the expiry of the Agreement.
10. General
10.1. Separate controllers and anonymised data. Meltwater may process personal data related to the customer for customer management purposes.
10.2 Conflict. If there is a conflict between the provisions of the Agreement and this DPA, the provisions of this DPA shall prevail.
10.3. Governing law and dispute resolution. This DPA shall be governed by the laws governing the Agreement.
10.4. Validity. This DPA shall be valid as long as the Agreement is in force.
ANNEX I
A. LIST OF PARTIES
Data exporter(s):
- Name: The Customer as defined in the Agreement.
- Address: The address for the Customer as defined in the Agreement.
B. DESCRIPTION OF TRANSFER
Categories of data subjects whose personal data is transferred: Controller's employees authorized to use the Platform.
Categories of personal data transferred: As defined in section 2 of the DPA.
The frequency of the transfer: Continuous basis.
Nature of the processing: Transfer, copying, use, deletion, correction, adjustment.
Purpose(s) of the data transfer and further processing: Personal data will be transferred from Controller to Data Processor for Data Processor to provide media monitoring SaaS-service.
C. COMPETENT SUPERVISORY AUTHORITY
The Data Processor’s main establishment is in the Netherlands. Dutch Supervisory Authority is the competent authority.