SiteVibes Data Processing Agreement
Last modified: December 1, 2024
This Data Processing Addendum (“DPA”) is incorporated by reference into the SiteVibes Terms of Service available at available at https://sitevibes.com/legal/enterprise-terms/ or other agreement governing the use of SiteVibes services (the “Agreement”) entered into by and between you, the customer (“Customer”, “you”, “your” or “Controller”), and SiteVibes (“SiteVibes”, “we”, “us”, “our” or “Processor”). Together, you and SiteVibes are referred to as the “Parties” and individually as a “Party”.
Capitalized terms not defined herein shall have the meanings given to them in the Agreement.
By using the Services, Customer accepts this DPA and warrants that it has full authority to bind the Customer to this DPA. If Customer cannot or does not agree to this DPA, or does not have authority to bind the Customer, please do not provide Personal Data to SiteVibes.
In the event of any conflict between this DPA and the Agreement regarding the Processing of Personal Data, the provisions of this DPA shall prevail solely with respect to such Processing.
1. DEFINITIONS
1.1 “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party. “Control” means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
1.2 “Authorized Affiliate” means any of Customer’s Affiliates which is expressly permitted to use the Services under the Agreement, but which is not party to the Agreement.
1.3 “CCPA” means the California Consumer Privacy Act of 2018 (Cal. Civ. Code §§ 1798.100 et seq.), and its implementing regulations, as amended.
1.4 “Controller”, “Processor”, “Data Subject”, “Processing” and “Supervisory Authority” shall have the meanings given in the General Data Protection Regulation (“GDPR”). For clarity, under this DPA “Controller” shall also refer to “Business” and “Processor” to “Service Provider” where the Virginia Consumer Data Privacy Act (“VCDPA”), Colorado Privacy Act (“CPA”) or other U.S. comprehensive privacy laws apply.
1.5 “Data Protection Laws” means all applicable and binding laws and regulations relating to privacy and the protection of personal data, including (without limitation) GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the CCPA, VCDPA, CPA, and analogous laws in other U.S. states or jurisdictions, as each is in force and applicable.
1.6 “Personal Data” means any information relating to an identified or identifiable natural person that is Processed by SiteVibes on behalf of the Customer, under the Agreement and this DPA. Personal Data does not include information processed by SiteVibes outside the scope of its role as Processor (for example, data about Data Subjects with which SiteVibes interacts directly as a customer or end-user of its own).
1.7 “Sensitive Data” means Personal Data that is protected under special legislation or regulation requiring heightened protections (e.g., “special categories of data” under GDPR).
1.8 “Security Measures” means the technical and organizational measures that SiteVibes implements to protect Personal Data, as described in its security documentation made available to Customer (or otherwise agreed).
1.9 “Sub-processor” means any third party engaged by SiteVibes or its Affiliates to Process Personal Data on behalf of Customer.
2. PROCESSING OF PERSONAL DATA
2.1 Roles of the Parties.With respect to the Processing of Personal Data under the Agreement, Customer is the Controller and SiteVibes is the Processor.
2.2 Controller’s obligations.Customer shall ensure that it has all required legal bases under Data Protection Laws to collect, Process and transfer to SiteVibes the Personal Data, and to authorize SiteVibes to Process Personal Data as necessary under the Agreement. Customer’s instructions to SiteVibes must be consistent with the Agreement and this DPA.
2.3 Processor’s obligations. SiteVibes shall (i) Process Personal Data only for the purposes of providing the Services pursuant to the Agreement and this DPA; (ii) Process Personal Data strictly in accordance with Customer’s documented instructions (including those given via the Services) unless otherwise required by obligation of law, in which case SiteVibes will inform Customer of such legal requirement unless prohibited; (iii) notify Customer without undue delay if it believes that any instruction from Customer infringes Data Protection Laws; (iv) assist Customer, to the extent reasonable and appropriate, in anonymizing or pseudonymizing Personal Data if requested.
2.4 Details of Processing. The subject-matter, duration, nature and purpose of the Processing of Personal Data, the types of Personal Data and categories of Data Subjects are set out in Schedule 1 (Details of Processing) below.
2.5 Sensitive Data. If Customer provides or instructs SiteVibes to Process Sensitive Data, Customer must obtain SiteVibes’ prior written consent and may be required to enter into additional agreements.
2.6 CCPA and other U.S. law obligations. When Processing Personal Data that is subject to CCPA, VCDPA, CPA or other U.S. comprehensive privacy laws, SiteVibes shall not (without Customer’s prior written consent) (i) combine Customer’s Personal Data with information it processes on behalf of other Customers; (ii) sell or share the Personal Data as defined under applicable law; or (iii) process the Personal Data outside the direct business relationship between SiteVibes and Customer. SiteVibes will notify Customer without undue delay if it determines it can no longer meet its obligations under the applicable law.
3. DATA SUBJECT REQUESTS
SiteVibes shall, to the extent it is legally permitted, notify Customer if it receives a request from a Data Subject to exercise rights under applicable Data Protection Laws (such as access, correction, erasure, portability, objection to processing, restriction of processing, not to be subject to automated decision-making). SiteVibes shall provide reasonable assistance to Customer (taking into account the nature of the Processing) so that Customer can respond to such Data Subject requests within applicable timeframes.
4. CONFIDENTIALITY
SiteVibes shall ensure that its personnel and any third-party agents or Sub-processors engaged in the Processing of Personal Data have committed to confidentiality appropriate to the Processing of Personal Data.
5. SUB-PROCESSORS
5.1 Appointment of Sub-processors. Customer acknowledges that SiteVibes’ Affiliates and third-party Sub-processors may be engaged in connection with providing the Services.
5.2 List of Sub-processors; notification. SiteVibes will make available to Customer a current list of Sub-processors and will update that list when new Sub-processors are appointed. SiteVibes’s current Sub-processors listed at https://sitevibes.com/legal/subprocessors as of the Effective Date.
5.3 Right to object. SiteVibes shall provide Customer with at least fifteen (15) days’ prior notice of any proposed changes to the Sub-processors it uses to Process Customer Personal Data. Customer may object in writing within 3 days of notification to a new Sub-processor for legitimate data protection reasons. If Customer objects, SiteVibes will use commercially reasonable efforts to provide alternative solutions. If no alternative can be offered within 30 days, Customer may terminate the Agreement with respect only to those Services relying on the Sub-processor, by written notice.
5.4 Agreements with Sub-processors. SiteVibes or its Affiliates shall enter into written agreements with each Sub-processor imposing data protection obligations equivalent to those in this DPA. SiteVibes remains fully liable for the Sub-processor’s performance of such obligations.
6. SECURITY & AUDITS
6.1 Security Measures. SiteVibes shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, or disclosure, as described in its security documentation.
6.2 Audits and inspections. Upon Customer’s reasonable prior written request (no more than once per 12 months) SiteVibes will provide information necessary to demonstrate compliance with this DPA, and will allow for an audit by Customer or Customer’s independent auditor (subject to confidentiality safeguards and not being a competitor of SiteVibes). The audit right will be exercised in a manner that minimizes disruption to SiteVibes’ business.
7. DATA INCIDENTS
SiteVibes maintains incident management policies and procedures. In the event of a Data Incident (i.e., accidental or unlawful destruction, loss, alteration or unauthorized disclosure or access to Personal Data processed by SiteVibes on behalf of Customer), SiteVibes will notify Customer without undue delay after becoming aware of the incident. SiteVibes shall take reasonable steps to investigate and remediate/mitigate the incident to the extent within its control. Customer shall not make any public disclosure or press release regarding the incident that names SiteVibes without SiteVibes’ prior written consent, unless legally required, in which case Customer shall provide SiteVibes with prior written notice to the extent possible.
8. RETURN OR DELETION OF PERSONAL DATA
Upon termination or expiration of the Agreement, whichever occurs first, SiteVibes will, at Customer’s choice, return all Personal Data processed solely on Customer’s behalf or permanently delete it (subject to applicable law). If required by law, SiteVibes may retain one archive copy solely for evidential or compliance purposes.
9. CROSS-BORDER DATA TRANSFERS
If the Processing involves transfers of Personal Data from the European Economic Area (“EEA”), UK or Switzerland to countries that do not offer an adequate level of protection under Data Protection Laws, then the applicable standard contractual clauses for data exports (e.g., the EU SCCs, UK Addendum, Swiss Addendum) shall apply and be incorporated by reference, and appropriate additional safeguards shall be used.
10. AUTHORIZED AFFILIATES
10.1 Scope. Customer may, on behalf of its Authorized Affiliates, enter into this DPA on behalf of each such Affiliate. Each Authorized Affiliate is bound by the terms of this DPA when SiteVibes Processes Personal Data on its behalf.
10.2 Communications. Customer shall coordinate all communication with SiteVibes under this DPA and the Agreement on behalf of its Authorized Affiliates.
11. OTHER PROVISIONS
11.1 Data Protection Impact Assessment & Prior Consultation. At Customer’s request and cost, SiteVibes shall provide reasonable assistance to Customer in fulfilling its obligations under the GDPR or other applicable Data Protection Laws with respect to carrying out Data Protection Impact Assessments (DPIAs) or prior consultation with Supervisory Authorities.
11.2 Amendments. Either Party may propose modifications to this DPA (with at least forty-five (45) calendar days’ prior written notice) if required by changes in applicable Data Protection Laws. The Parties will negotiate in good faith to implement such modifications. If the Parties cannot agree within thirty (30) days, either Party may terminate the Agreement (and this DPA) with respect to the affected Services by written notice.
11.3 Survival. Sections 4 (Confidentiality), 7 (Data Incidents), 8 (Return or Deletion), 9 (Cross-Border Transfers), and 11 (Other Provisions) shall survive termination of the Agreement and this DPA.
11.4 Order of precedence. In the event of any conflict between the Agreement and this DPA, this DPA shall prevail solely with respect to matters covered by it.
11.5 Governing Law & Venue. These terms will be interpreted, construed, and enforced in all respects in accordance with the local laws of the State of Illinois, U.S.A., without reference to its choice of law rules to the contrary. The parties agree to submit to the exclusive jurisdiction of, and venue in the federal or state court of competent jurisdiction located in DuPage County, Illinois, U.S.A.
11.6 Severability. If any provision of this DPA is held unenforceable, the remaining provisions shall remain in full force and effect.
SCHEDULE 1 – DETAILS OF PROCESSING
Nature and Purpose of Processing:
- Provision of the Services to Customer under the Agreement;
- Performing the Agreement, this DPA and any other contractual obligations between the Parties;
- Processing in accordance with Customer’s documented instructions;
- Facilitating integrations between the Services and third-party services as configured by or on behalf of Customer;
- Anonymizing or pseudonymizing Personal Data (if requested);
- Compliance with applicable laws and regulations.
Duration of Processing:
- For the duration of the Agreement and as necessary thereafter in accordance with Section 8 (Return or Deletion) of this DPA, unless otherwise agreed in writing.
Types of Personal Data:
- Contact information (e.g., name, email address, phone number);
- Usage data (e.g., IP address, device identifiers, location data, system logs);
- Transaction and purchase information (e.g., product purchased, time of purchase, cart value, excluding payment method details);
- Content submitted by Data Subjects (e.g., reviews, UGC, comments, images, photos);
- Other information submitted, stored, sent or received via the Services by Data Subjects or by Customer on behalf of Data Subjects.
Categories of Data Subjects:
- Customers’ end users, shoppers, customers, website visitors, or consumers whose data is collected, stored or processed by Customer and submitted to SiteVibes in connection with the Services;
- Data Subjects who provide reviews, ratings, comments or other user-generated content via Customer’s website or mobile app.