Data Processing Agreement
This Data Processing Agreement (“DPA”) is entered between Ours Wellness, Inc. (“Ours Privacy”) and the applicable Ours Privacy client (“Client, and with Ours Privacy, each a “Party” and collectively the “Parties”) pursuant to a master agreement between the Parties that incorporates this DPA by reference (the “Agreement”). This DPA applies to Ours Privacy’s Processing of Client Personal Data in connection with the provision of the Ours Privacy Platform, Support and Maintenance and the Services pursuant to the Agreement. Capitalized terms used but not defined herein shall have the meanings ascribed to them in the Agreement.
1. Recitals.
1.1. Client wishes to make available to Ours Privacy Client Personal Data for the purposes described herein.
1.2. For the avoidance of doubt, this DPA does not pertain to protected health information subject to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and its attendant regulations and, where applicable, any Business Associate Agreement executed by Client in which Ours Privacy serves as a business associate or subcontractor business associate.
2. Definitions.
The following terms as used herein shall have the following meanings.
2.1. “Client Personal Data” means any information that is Processed in connection with Ours Privacy’s provision of the Ours Privacy Platform and the Services to Client and (a) that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, data subject, or household; or (b) is defined as “personal information,” “personal data,” “personally identifiable information,” “protected health information,” “nonpublic personal information,” or similar term under Applicable Data Protection Laws. For the avoidance of doubt, Client Personal Data is a subset of Client Data as defined in the Agreement.
2.2. “Security Incident” means any actual unauthorized, accidental or unlawful access, acquisition, loss, destruction, use, alteration, modification or disclosure of Client Personal Data.
2.3. “Business Purpose(s)”, “Controller”, "Data Subject(s)", “Personal Information”, “Person(s)”, “Process” (and other variations thereof), “Processor”, “Sale” (including “Sell” and other variations thereof), “Service Provider”, and “Share” (and other variations thereof) shall have the meanings given to those terms in Applicable Data Protection Laws.
3. Data Processing.
3.1. Relationship of the Parties. With respect to the Processing of Client Personal Data, Client acts as a Controller, and Ours Privacy acts as Processor or Service Provider, as such terms are defined in Applicable Data Protection Laws.
3.2. Compliance With Data Protection Laws. Ours Privacy shall comply at all times with Applicable Data Protection Laws in connection with Client Personal Data, and shall provide Client with all reasonably requested assistance and cooperation to enable Client to comply with and fulfill its obligations under Applicable Data Protection Laws in connection with Client Personal Data. Upon Client’s reasonable request, Ours Privacy shall provide Client with all reasonably requested information in its possession necessary to demonstrate Ours Privacy’s compliance with its obligations under Applicable Data Protection Laws in connection with Client Personal Data.
3.3. Client Instructions and Obligations. Ours Privacy shall Process Client Personal Data in accordance with the instructions of Client. Ours Privacy shall inform Client in writing if Ours Privacy believes any of the instructions of Client violate Data Protection Laws. Client is responsible for the accuracy, quality, and legality of the Client Personal Data. Client warrants and represents to Ours Privacy that it has provided notice and obtained all consents, permissions, and rights necessary for Ours Privacy to lawfully Process Client Personal Data for the purposes contemplated by the Agreement. Client Personal Data shall only include sensitive data if the Agreement authorizes, with specificity, the exchange of such data, and Client has obtained the consents necessary to Process the sensitive data. If consent is not necessary, Client must have provided the Data Subject the opportunity to opt-out of such Processing.
3.4. Prohibited Data. Client shall not use the Ours Privacy Platform to Process any Prohibited Personal Information. Client acknowledges that Ours Privacy is not a payment card processor and that the Ours Privacy Platform is not PCI DSS compliant. Ours Privacy shall have no liability under this DPA for use of Prohibited Personal Information, notwithstanding anything to the contrary herein.
3.5. Confidentiality. Ours Privacy shall ensure the confidential nature and use restrictions of Client Personal Data, and that access to Client Personal Data is limited to personnel needed to perform the Services and who are subject to the same restrictions and obligations set forth in this DPA, including a duty of confidentiality with respect to the Client Personal Data.
3.6. Subprocessors. Subject to the applicable provisions of the Agreement, Ours Privacy may subcontract its Processing obligations under this DPA, in whole or in part, to another person or entity (“Subprocessor(s)”). Any such activity between Ours Privacy and its Subprocessor shall be governed by a written contract that imposes contractual obligations on the Subprocessor that are as protective as those imposed on Ours Privacy in this DPA.
3.7. Requests and Assistance. The Parties agree to provide assistance as is reasonably required and requested by the other Party to enable it to comply with a request from a Data Subject regarding Client Personal Data to exercise their rights under Applicable Data Protection Laws, or any complaint, investigation, or inquiry from a supervisory authority, regulator, or other third party that relates to the Processing activities and Client Personal Data in this Agreement (“Request”). Each Party is responsible for maintaining proper records of all Data Subject Requests it receives and decisions made with respect thereto, as required under Applicable Data Protection Laws.
3.8. Data Transfer. Ours Privacy may Process Client Personal Data in the United States.
3.9. Return or Deletion. Upon Client's request or after termination of the Agreement, Ours Privacy shall securely and permanently delete or provide to Client all Client Personal Data in Ours Privacy’s possession or control, unless Ours Privacy is required to retain the data under applicable law.
3.10. CCPA Provisions. To the extent that the CCPA applies to the Processing of Client Personal Data, the Parties further agree as follows:
Ours Privacy shall Process Client Personal Data as a Service Provider.
All Client Personal Data disclosed or made available to Ours Privacy pursuant to the Agreement is done so for the limited and specified Business Purpose(s) identified in Schedule 1.
Ours Privacy shall comply with applicable obligations under the CCPA and shall notify Client in the event it makes a determination that it can no longer meets its obligations under the CCPA.
Ours Privacy shall not Sell or Share the Client Personal Data. Except as permitted by the CCPA, Ours Privacy shall not collect, retain, use, or disclose the Client Personal Data for any purpose other than the Business Purpose(s) specified above or outside of the direct business relationship between Client and Ours Privacy or the above purposes.
Except as permitted by the CCPA, Ours Privacy shall not combine Client Personal Data with Personal Data it receives from another person or persons, or otherwise.
Client may take reasonable and appropriate steps to ensure Ours Privacy uses Client Personal data in a manner consistent with the Client’s obligations under the Data Protection Laws.
Client may, upon notice, to take reasonable and appropriate steps to stop and remediate Ours Privacy’s unauthorized use of Client Personal Data
4. Security and Audits.
4.1. Security Measures. Ours Privacy shall implement and maintain reasonable security measures, procedures and practices appropriate to the nature of the Client Personal Data and as required by Applicable Data Protection Laws in connection with the Client Personal Data to protect such information from a Security Incident.
4.2. Security Incidents. In the event Ours Privacy has notice of a Security Incident, Ours Privacy will take any necessary action to stop the active breach or similar recurring breaches and shall notify Client in writing of the Security Incident and any third-party legal process relating to the Security Incident.
4.3. Audit Rights. Ours Privacy shall allow for, and contribute to, reasonable assessments and inspections by Client or Client’s designated assessor. Ours Privacy shall provide Client with access to such records, personnel, and facilities as Client may reasonably require for such purpose.
Schedule 1: Details of Processing Activities
Subject Matter of Processing: The Processing is in relation to Our Privacy’s provision of the Ours Privacy Platform and Services to Client.
Duration: The duration of the Processing is until the earlier of (i) request by Client to stop further Processing; or (ii) expiration/termination of the DPA.
Categories of Data Subjects. Client Personal Data may include the following categories of Data Subjects:
Client's end users
Client’s subscribers
Client's employees and contractors
Categories of Personal Data. Client Personal Data may include the following categories of Personal Data:
Contact information (name, address, telephone number, email address, etc.)
Commercial and behavioral information (purchasing histories, transaction details, expressed interests and tendencies, audience information)
Demographic or biographical information (date of birth, age, gender, nationality, income level, employment information, household information, etc.)
Device identifiers and internet or electronic network activity (IP addresses, GAID/IDFA, browsing history, timestamps)
Geolocation information
Sensitive Data. Client Personal Data may include the following categories of sensitive Personal Data:
Health data (including data that can be used to identify physical or mental health conditions or treatment) or genetic data
Frequency of Transfers: The frequency of the transfer of Personal Data will be on a continuous basis.
Nature and Purpose of Processing:
Performing services on behalf of Client
Maintaining or servicing accounts
Providing analytic services
Providing advertising and marketing services
Retention: Personal Data will be retained for the duration of the Processing (as described above), and only after the duration where applicable law requires retention of the Personal Data and subject to the obligations in the DPA.