Writer data processing agreement | Legal hub

Data processing agreement

This Data Processing Agreement (“ DPA”) is entered into by Writer, Inc. (“ Writer”) and the Writer customer identified in the Agreement (“ Customer”) (each a “ Party”; collectively the “ Parties”) and is incorporated by reference into the applicable subscription agreement governing Customer’s use of Writer’s Platform (the “Agreement”) between the Parties and takes precedence over the Agreement to the extent of any conflict. All capitalized terms used in this DPA but not defined will have the meaning set forth in the Agreement or under Data Protection Laws. Any prior data protection agreement that may already exist between the Parties is superseded and replaced by this DPA on the date this DPA has been fully executed by the Parties.

1. Definitions.

2. Roles of the Parties; Scope and Purposes of Processing.

3. Personal Data Processing Requirements.

4. Data Security.

Writer will use appropriate administrative, technical, physical, and organizational measures to protect Personal Data as set forth in Exhibit B. Writer will provide the level of protection for Personal Data that is required under Data Protection Laws. Such measures will take into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, so as to ensure a level of security appropriate to the risk.

5. Security Incident.

6. Subprocessors.

7. Data Transfers.

8. Audits.

9. Return or Destruction of Personal Data.

Except to the extent required otherwise by Data Protection Laws, Writer will, at the choice of Customer and upon Customer’s written request return to Customer and/or securely destroy all Personal Data, unless Data Protection Laws require Writer to retain Personal Data.

10. Survival; Amendments.

The provisions of this DPA survive the termination or expiration of the Agreement for so long as Writer or its Subprocessors Process Personal Data. Writer may amend this DPA in order to comply with Data Protection Laws and will notify Customer of such changes. By continuing to use the Platform after the DPA has been updated, Customer is deemed to have agreed to the updated DPA.

Exhibit A

ANNEX I to the EU SCCS

A. List of parties

Data exporter(s):

Data importer(s):

B. Description of transfer

Categories of data subjects whose personal data is transferred: The categories of data subjects whose personal data is transferred are determined solely by the data exporter. In the normal course of the data importer’s provision of the Platform, the categories of data subjects might include (but are not limited to): the data exporter’s personnel, customers, service providers, business partners, affiliates and other end users.

Categories of personal data transferred: The categories of personal data transferred are determined solely by the data exporter. In the normal course of the data importer’s provision of the Platform, the categories of personal data transferred might include (but are not limited to) any Personal Data submitted by Customer’s data subjects in connection with their use of the Platform.

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures:  At its sole discretion, the data exporter determines all categories and types of personal data it may submit and transfer to the data importer as part of its provision of the Platform. If the data exporter chooses to transmit sensitive data through the Platform or permits its end users to, the data exporter is responsible for ensuring that suitable safeguards are in place prior to transmitting or processing, or prior to permitting the data exporter’s end users to transmit or process, any sensitive data through the Platform.

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis): Continuous for the duration of the Agreement.

Nature of the processing: The data importer’s Processing activities shall be limited to those discussed in the Agreement and the DPA.

Purpose(s) of the data transfer and further processing: The purpose of the transfer to and further Processing of Personal Data by the data importer is for the data importer to provide the Platform to the data exporter as set forth in the Agreement.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Personal Data will be retained for the period of time necessary for the data importer to provide the Platform to the data exporter under the Agreement and/or in accordance with applicable legal requirements.

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: Same as above to the extent that Personal Data is provided to Subprocessors for purposes of providing the Platform.

C. Competent supervisory authority

To the extent legally permitted, the competent supervisory authority is the Irish Data Protection Commission.

Exhibit B

Data security measures

Writer will implement and maintain the following administrative, technical, physical, and organizational security measures for the Processing of Personal Data:

  1. Information Security Policies and Standards. Writer will maintain written information security policies, standards and procedures addressing administrative, technical, and physical security controls and procedures. These policies, standards, and procedures shall be kept up to date, and revised whenever relevant changes are made to the information systems that use or store Personal Data.
  2. Physical Security. Writer will maintain commercially reasonable security systems at all Writer sites at which an information system that uses or stores Personal Data is located (“ Processing Locations”) that include reasonably restricting access to such Processing Locations, and implementing measures to detect, prevent, and respond to intrusions.
  3. Organizational Security. Writer will maintain information security policies and procedures addressing acceptable data use standards, data classification, and incident response protocols.
  4. Network Security. Writer maintains commercially reasonable information security policies and procedures addressing network security.
  5. Access Control.  Access to Customer Data is restricted to authorized Writer personnel who are required to access Customer Data to perform functions as part of the delivery of the Platform. Access is granted based on the principle of least privilege and access granted is commensurate with job function. Writer agrees that: (a) only authorized Writer staff can grant, modify, or revoke access to an information system that Processes Personal Data; and (b) it will implement commercially reasonable physical and technical safeguards to create and protect passwords.
  6. Virus and Malware Controls. Writer protects Personal Data from malicious code and will install and maintain anti-virus and malware protection software on any system that handles Personal Data.
  7. Personnel.  Writer has implemented and maintains a security awareness program to train employees about their security obligations and requires that employees follow established security policies and procedures. Writer also imposes contractual obligations on any Subprocessor Writer appoints requiring it to protect Personal Data to standards which are no less protective than those set forth under this DPA.
  8. Business Continuity. Writer implements disaster recovery and business resumption plans that are kept up to date and revised on a regular basis. Writer also adjusts its information security program in light of new laws and circumstances, including as Writer’s business and Processing change.