This Data Processing Agreement ("Agreement") forms part of the Terms of Service between you ("Controller") and Server Management LLC, a limited liability company organised under the laws of [STATE], United States, with its registered office at [ADDRESS], operating the Wiremo service ("Processor", "Wiremo").
The Processor shall comply with the following in respect of personal data ("PD") as defined under Regulation (EU) 2016/679 (General Data Protection Regulation (“GDPR”)):
Data Processing Agreement
This Data Processing Agreement ("Agreement") forms part of the Terms of Service between you ("Controller") and Server Management LLC, a limited liability company organised under the laws of [STATE], United States, with its registered office at Address: 1201 N, Orange St STE 700, 19801 Wilmington, DE, USA, operating the Wiremo service ("Processor", "Wiremo"). All defined terms contained herein shall have the same meaning as the definitions set forth in the Terms of Service.
The Processor shall comply with the following in respect of personal data ("PD") as defined under Regulation (EU) 2016/679 (General Data Protection Regulation ("GDPR")):
Controller's Compliance
Controller's instructions for processing of PD shall comply with all applicable privacy and data protection laws, including the GDPR. The Controller shall have sole responsibility for the accuracy, quality and legality of PD and the means by which Controller acquired PD.
Details of Processing
The details of the processing activities to be carried out by the Processor in respect of the Services are:
- Nature, purpose and subject matter of the Processing. The nature, purpose and subject matter of the Processing is the provision of the Services set forth in the Terms of Service.
- Categories of Data Subjects. Users that purchased products and/or services from Controller or submitted a review via the onsite widget that is installed on the Controller website.
- Categories of Personal Data. Email address, first name, last name, IP address, and the content of reviews submitted by data subjects.
- Duration. For the term of the Terms of Service, subject to the Return and Deletion of PD section below.
Data Subjects Rights
The Processor shall assist Controller, by using appropriate technical and organizational measures, in the fulfillment of Controller's obligations to respond to requests by data subjects in exercising their rights under applicable laws.
Confidentiality
The Processor shall ensure that its personnel engaged in the processing of PD are bound by a confidentiality undertaking.
Data Breach
The Processor will promptly notify Controller after becoming aware of any suspected or actual breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, PD ("Data Breach").
Records
The Processor will maintain up-to-date written records of its processing activities, including, inter alia, Processor's and Controller's contact details, the categories of processing, transfers of PD across borders and the technical and organizational security measures implemented by the Processor. Upon request, Processor will provide an up-to-date copy of these records to Controller.
Sub-Processors
Controller provides general written authorisation for Processor to engage the third-party sub-processors listed in Appendix 1. Processor will give Controller at least 30 days' prior notice of the addition or replacement of any sub-processor, and Controller may object on reasonable data protection grounds within that period. Where Controller objects and the parties cannot agree a resolution, Controller may terminate the affected Services. Sub-processors shall be bound by data protection obligations no less protective than those in this Agreement to the extent applicable to the nature of the Services provided by such sub-processor.
Assistance
The Processor will assist Controller in ensuring compliance with Controller's obligations related to the security of the processing, notification and communication of Data Breaches, conduct of data protection impact assessments and any inquiry, investigation or other requests by a supervisory authority.
Possible Violation
Where Processor believes that an instruction would result in a violation of any applicable data protection laws, Processor shall notify the Controller thereof.
Information
The Processor will make available to Controller, upon request, information necessary to demonstrate compliance with the obligations set forth in this Agreement.
Audit
Upon Controller's request, Processor shall cooperate with audits and inspections of its compliance with the requirements and obligations herein and/or under applicable law. Such audits and inspections may be conducted by Controller or by any third party designated by Controller. The costs of the audit shall be borne by the Controller.
Technical and Organizational Measures
- Processor shall implement and maintain all technical and organizational measures that are required for protection of the PD and ensure a level of security that is appropriate for dealing with and protecting against any risks to the rights and freedoms of the data subjects, and as required in order to avoid accidental or unlawful destruction, loss, alteration or unauthorized disclosure of, or access to PD and/or as otherwise required pursuant to the GDPR, including, inter alia, the measures set forth in Appendix 2. When complying with this Section, Processor shall take into consideration the state of technological development existing at the time and the nature, scope, context and purposes of processing as well as the aforementioned risks.
- Processor shall regularly monitor its compliance with this Agreement and will provide Controller, upon request, with evidence that will enable verification of such monitoring activities. Processor shall ensure that all persons acting under its authority or on its behalf and having access to the PD do not process the PD except as instructed by Controller and permitted herein.
Transfer of PD to Third Countries
Processor is established in the United States. Personal Data is therefore transferred outside the European Economic Area. Such transfers are governed by the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor), which are incorporated into this Agreement by reference and completed by Appendix 3 below. In the event of any conflict between this Agreement and those Clauses, the Clauses prevail. Processor will make available to Controller, on request, its Transfer Impact Assessment and details of the supplementary measures applied.
Return and Deletion of PD
On the Controller's request, Processor shall return or destroy PD to the extent allowed by applicable law.
Appendix 1 — Sub-Processors
Sub-processor Purpose Location DigitalOcean, LLC Hosting and infrastructure United States Intercom, Inc. Customer support messaging United States Hotjar Ltd Product analytics Malta / EU Google LLC (Analytics, Tag Manager) Website analytics United States Appsero Plugin licensing and updates United States
Server Management LLC is the contracting party and data importer under this Agreement, not a sub-processor.
Appendix 2 — Technical and Security Measures
- The pseudonymization and encryption of PD.
- The ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
- The ability to restore the availability and access to PD in a timely manner in the event of a physical or technical incident.
- A process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.
Appendix 3 — Standard Contractual Clauses (2021/914, Module Two)
Annex I.A — Parties
Data exporter: the Controller, being the account holder identified in Processor's account records, acting as controller in respect of the PD described above.
Data importer: Server Management LLC, Address: 1201 N, Orange St STE 700, 19801 Wilmington, DE, USA, United States. Contact: support@wiremo.co. Activities relevant to the transfer: provision of the review collection, moderation and display Services. Role: processor.
Annex I.B — Description of transfer
Categories of data subjects, categories of personal data, nature and purpose of processing, and duration are as set out in the "Details of Processing" section above. Frequency: continuous. Onward transfers to sub-processors are limited to those listed in Appendix 1.
Annex I.C — Competent supervisory authority
The supervisory authority of the EEA Member State in which the data exporter is established.
Annex II — Technical and organisational measures
As set out in Appendix 2.
Annex III — Sub-processors
As set out in Appendix 1.
Optional Clause 7 (docking) applies. Under Clause 9, option 2 (general written authorisation) applies with a 30-day notice period. Under Clause 11, the optional independent dispute resolution provision does not apply. Under Clause 17, the governing law is that of Ireland. Under Clause 18(b), the forum is the courts of Ireland.