Loading legal…
Legal
This DPA is part of the Terms of Use whenever we process Customer Content as your processor.
This Data Processing Addendum (“DPA”) is between the customer (“Customer”) and Allocatin, Inc. (“Processor”). It applies to personal data in Customer Content that we process on Customer’s instructions. It does not apply to data we process as an independent controller (accounts, billing, security, member directory, and our own matching graph), which is described in the Privacy Policy.
If Customer is subject to GDPR, UK GDPR, PIPEDA, Quebec Law 25, or US state privacy laws that require processor terms, this DPA fills that requirement. Larger customers may also countersign a PDF copy on request at privacy@allocatin.com.
Customer is the controller (or a processor itself, in which case we are a subprocessor). We will process Customer Personal Data only on documented instructions: to provide the services, as described in the Terms, and as required by law. If a legal demand conflicts with an instruction, we will notify Customer unless the law forbids notice.
| Item | Description |
|---|---|
| Subject matter | Hosting and operating the AllocatIN workspace |
| Duration | The subscription or authorized access period, plus residual backups and legal holds |
| Nature | Storage, transmission, display, matching inputs you choose to use, and deletion |
| Purpose | Provide the services Customer has ordered |
| Data subjects | Customer personnel and, if Customer uploads them, counterparties or other business contacts |
| Data types | Names, titles, business emails, professional notes, documents, mandate fields, messages |
| Special category data | Not intended. Customer must not upload it unless it has a lawful basis and has told us in writing |
We will ensure persons authorized to process Customer Personal Data are bound by confidentiality and receive appropriate training. Access is limited to what is needed to operate, secure, and support the services.
We implement the technical and organizational measures described in Security, including encryption in transit and at rest, tenant isolation, access control, and audit logging. Customer is responsible for seat administration, visibility rules, and the content it uploads.
Customer authorizes us to use the vendors on the Subprocessors page. We will impose data protection terms no less protective than this DPA and remain responsible for their performance. We will post new subprocessors on that page and, for larger customers who have asked for notice, email them at least 14 days before a material addition. Customer may object on reasonable data-protection grounds; if we cannot accommodate the objection, Customer may terminate the affected service.
Customer Personal Data may be processed in the United States and other locations of authorized subprocessors. For restricted transfers under GDPR or UK GDPR, the parties incorporate:
For the SCCs: the data exporter is Customer; the data importer is Allocatin, Inc.; the governing law and forum for the clauses are Ireland (EU SCCs) and England and Wales (UK Addendum), unless Customer notifies another valid choice; Annex I and II are this DPA plus the Security and Subprocessors pages; Clause 17/18 elections are as stated here. If a later approved transfer tool replaces the SCCs, the parties will use that tool.
Taking into account the nature of processing, we will assist Customer with data subject requests, DPIAs, and consultations with authorities, at Customer’s reasonable expense if the work is not already a standard product feature. We will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and in any event in a timeframe that allows Customer to meet a 72-hour GDPR clock where applicable.
On termination, Customer may export Customer Content using available product tools while the account remains open. Within 30 days after a written deletion request, we will delete Customer Personal Data from production systems, except copies retained as required by law, for security logs, or in encrypted backups until they rotate. Certification of deletion is available on written request.
On reasonable written notice, no more than once per year (unless a regulator or confirmed breach requires more), Customer may review our then-current security summary, third-party reports we are allowed to share, and answers to a standard questionnaire. On-site audits are available if those materials are not sufficient, at Customer’s expense, during business hours, and without unreasonably disrupting operations.
We are a service provider / processor under the CPRA and similar US state laws. We will not sell or share Customer Personal Data, retain or use it outside the business purpose of providing the services, or combine it with other personal information except as those laws allow for security, debugging, or a permitted business purpose. We will notify Customer if we can no longer meet these obligations.
We will process Customer Personal Data in accordance with PIPEDA principles as they apply to a processor, and we will notify Customer of any breach we are required to report that affects Canadian personal information we process for Customer.
Liability under this DPA is subject to the limitations in the Terms, except that those limitations do not reduce either party’s liability to a data subject that cannot be limited under GDPR or UK GDPR. If this DPA conflicts with the Terms on data-protection subject matter, this DPA controls. This DPA is governed by the same law as the Terms (England and Wales, United Kingdom), except for the SCCs, which use their own governing-law elections.