Corporate Builder

Data Processing Agreement

Template for customers who need one – especially EU customers

between

[CUSTOMER NAME] (“Controller”)

and

eightM Corporation (“Processor”)

This DPA forms part of the Terms of Service / Master Agreement between the parties.

1. Subject Matter & Duration

Processor processes personal data on behalf of Controller solely for the purpose of providing the Corporate Builder Service, for the duration of the agreement and any post-termination period required by law or the main agreement.

2. Nature and Purpose of Processing

Processing consists of storage, retrieval, organisation and transmission of data that Controller inputs into the Service (account data, buy-box criteria, notes, and any personal data that may appear in public sources Controller chooses to screen). Purpose is limited to delivering the contracted Service.

3. Types of Personal Data & Categories of Data Subjects

  • Account holders / authorised users of Controller
  • Names, email addresses, professional contact details
  • Any personal data that appears on publicly available company websites that Controller elects to screen (incidental)

4. Obligations of Processor

Processor shall:

  • process personal data only on documented instructions from Controller;
  • ensure persons authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures;
  • not engage sub-processors without prior general or specific authorisation;
  • assist Controller with data-subject requests and data-protection impact assessments where reasonably possible;
  • delete or return personal data at the end of the provision of services, at Controller’s choice, unless retention is required by law;
  • make available information necessary to demonstrate compliance and allow for audits (reasonable notice, no more than once per year, at Controller’s cost).

5. Sub-processors

Controller grants general authorisation for the use of the sub-processors listed in [Appendix / Trust Center]. Processor will inform Controller of intended changes and give Controller the opportunity to object.

6. International Transfers

Where personal data is transferred outside the EEA/UK, Processor ensures appropriate safeguards (SCCs, adequacy decisions, etc.).

7. Liability

Liability is governed by the main agreement, subject to mandatory data-protection law.

8. Governing Law

Same as main agreement

This document is published in English. The English version is the version that applies.

Zurück zu den Tools

ImpressumDatenschutzAGBAuftragsverarbeitungCookiesSupport

with love from Austin, Texas | by eightM Corporation

Wir möchten Seitenaufrufe mit Google Analytics zählen, wofür Cookies gesetzt werden. Was Sie in ein Werkzeug eingeben, wird nie übertragen — keine Firmennamen, keine Kriterien, keine Ergebnisse. Bei Ablehnung wird kein Analyse-Cookie gesetzt und nichts an Google gesendet. Cookie-Richtlinie