Data Processing Addendum | Argon
DATA PROCESSING ADDENDUM
This Data Processing Addendum (the “Addendum”), including its Exhibits, forms a part of the Order Form and Terms of Service, Enterprise SaaS Agreement or other written agreement entered into by the Parties (the “Agreement”) between Argon AI, Inc. (“Company”) and Customer (Customer and together with Company, the “Parties”).
Subject Matter and Duration
Subject Matter.
This Addendum reflects the Parties’ commitment to abide by Data Protection Laws concerning the Processing of Customer Personal Data in connection with Company’s performance of its obligations under the Agreement. All capitalized terms that are not expressly defined in this Addendum will have the meanings given to them in the Agreement. In the event of any conflict or inconsistency among the following documents, the order of precedence will be: (1) the applicable terms in the Standard Contractual Clauses; (2) the terms of this Addendum; and (3) the Agreement. For purposes of Data Protection Laws, Company is the “data processor” and Customer is the “data controller” with respect to Customer Personal Data.
Duration and Survival.
This Addendum will become legally binding upon the effective date of the Agreement. Company will Process Customer Personal Data until the relationship terminates as specified in the Agreement. Company’s obligations and Customer’s rights under this Addendum will continue in effect so long as Company Processes Customer Personal Data.
Definitions
For the purposes of this Addendum, the following terms and those defined within the body of this Addendum apply.
- “Authorized Persons” means (i) personnel of Company and (ii) third parties engaged by Company in accordance with Sections 3(b)-(d) of this Addendum.
- “Company Account Data” means personal data that relates to Company’s relationship with Customer.
- “Company Usage Data” means Service usage data collected and processed by Company in connection with the provision of the Services.
- “Customer Personal Data” means Personal Data Processed by Company on behalf of Customer.
- “Data Protection Laws” means any applicable laws and regulations in any relevant jurisdiction relating to the use or Processing of Personal Data.
- “EU-US DPF” means The EU-U.S. Data Privacy Framework.
- “EU SCCs” means the standard contractual clauses approved by the European Commission.
- “Personal Data” means any information relating to an identified or identifiable natural person.
- “Process” means any operation performed on data or sets of data.
- “Security Incident(s)” means the breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of Customer Personal Data.
- “Services” means any and all products and services that Company provides under the Agreement.
- “Subprocessor(s)” means Company’s authorized contractors, agents, vendors and third-party service providers.
Data Use and Processing
Company and its Subprocessors shall Process Customer Personal Data solely for the purpose of providing the Services and in accordance with Data Protection Laws. Company will inform Customer in writing if it believes there is a conflict between Customer’s instructions and applicable law.
Authorization to Use Subprocessors.
Customer hereby authorizes Company to engage Subprocessors.
Company and Subprocessor Compliance.
Company shall enter into a written agreement with Subprocessors regarding their Processing of Customer Personal Data.
Right to Object to Subprocessor.
Company will notify Customer via email about new Subprocessors allowing 10 days to object if Customer has reasonable objections.
Data Processing Laws
CPRA.
With respect to Customer Personal Data, Customer is a Business and Company is a Service Provider for the purposes of the CPRA. Company shall not Sell or Share Customer Personal Data and will only disclose it for specific purposes.
Security Incidents
Company will notify Customer’s Designated POC without undue delay if a Security Incident occurs, detailing necessary information for compliance with regulatory obligations.
Data Storage and Deletion.
Company will securely destroy all copies of Customer Personal Data after the Agreement terminates or upon Customer request.
Company’s Role as a Controller.
With respect to Company Account Data and Company Usage Data, Company is an independent controller.
Contact Information.
The Customer Designated POC shall be the contact specified for the Data Exporter in Exhibit B.
Exhibits
Exhibit A
- Subject Matter of Processing: Company Account Data and Company Usage Data.
- Duration of Processing: Company Account Data and Company Usage Data will be processed as described in Company’s privacy policy.
Exhibit B
- Parties: Data exporter(s) and Data importer(s) defined according to their contact details.
Exhibit C
- Technical and Organizational Security Measures implemented to protect Customer Personal Data.
Exhibit D
- UK Addendum and international data transfer agreements.