Writer data processing agreement | Legal hub
Data Processing Agreement
This Data Processing Agreement (“DPA”) is entered into by Writer, Inc. (“Writer”) and the Writer customer identified in the Agreement (“Customer”) (each a “Party”; collectively the “Parties”) and is incorporated by reference into the applicable subscription agreement governing Customer’s use of Writer’s Platform (the “Agreement”) between the Parties and takes precedence over the Agreement to the extent of any conflict. All capitalized terms used in this DPA but not defined will have the meaning set forth in the Agreement or under Data Protection Laws. Any prior data protection agreement that may already exist between the Parties is superseded and replaced by this DPA on the date this DPA has been fully executed by the Parties.
1. Definitions.
- (a) “Data Protection Laws” means all applicable laws, regulations, and other legal or regulatory requirements in any jurisdiction relating to privacy, data protection, data security, breach notification, or the Processing of personal data, including without limitation, to the extent applicable, the General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”); the United Kingdom Data Protection Act of 2018; the Swiss Federal Act on Data Protection (“FADP”); and the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq., as amended and including its regulations (“CCPA”), and other applicable U.S. state and federal laws. For the avoidance of doubt, if Writer’s Processing activities involving Personal Data are not within the scope of a Data Protection Law, such law is not applicable for purposes of this DPA.
- (b) “Data Privacy Frameworks” means the EU-U.S Data Privacy Framework (“EU-U.S. DPF”), the Swiss-U.S. Data Privacy Framework (“Swiss-U.S. DPF”), and the UK Extension to the EU-U.S. DPF (“UK Extension”) as administered by the U.S. Department of Commerce.
- (c) “Data Subject” means an identified or identifiable natural person to whom Personal Data relates, and is deemed to also include a “consumer” as defined under Data Protection Laws.
- (d) “EU SCCs” means the Standard Contractual Clauses issued pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.
- (e) “Personal Data” includes “personal data,” “personal information,” “personally identifiable information,” and analogous terms, as defined by applicable Data Protection Laws, that Writer Processes to provide the Platform under the Agreement.
- (f) “Process”, “Processing,” “Processed,” etc., mean any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, creating, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- (g) “Security Incident” means any confirmed breach of security that results in the accidental or unlawful acquisition, destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by Writer and/or its Subprocessors in connection with Writer’s provision of the Platform.
- (h) “Subprocessor” means any third party that Writer engages to Process Personal Data to provide the Platform.
- (i) “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office.
- (j) The terms “Business,” “Controller,” “Processor,” and “Service Provider” are defined as in Data Protection Laws. “Controller” is deemed to also refer to “Business,” and “Processor” is deemed to also refer to “Service Provider.”
2. Roles of the Parties; Scope and Purposes of Processing.
- (a) Roles of the Parties. To the extent that Customer is the Controller of Personal Data, Writer is its Processor. To the extent that Customer is a Processor of Personal Data, Writer is its Subprocessor.
- (b) Scope and Purposes of Processing. This DPA applies to all Personal Data that Writer Processes to provide the Platform to Customer. Writer will Process Personal Data (i) in compliance with Data Protection Laws; (ii) on Customer’s behalf and in accordance with Customer’s instructions as set forth in this DPA and the Agreement; and (iii) to provide the Platform to Customer under the Agreement for the business purposes set forth in the Agreement and as set forth in this DPA.
- (c) Customer Rights. Customer retains the right to take reasonable and appropriate steps to (i) ensure that Writer Processes Personal Data in a manner consistent with Data Protection Laws, and (ii) upon notice, stop and remediate unauthorized Processing of Personal Data.
- (d) Customer Obligations. Where Customer is a Controller, Customer is responsible for providing any notices, obtaining any consents or authorizations, and otherwise satisfying its compliance obligations with respect to the Processing of Personal Data under this DPA.
3. Personal Data Processing Requirements.
- (a) Restrictions on Processing. Writer will:
- (i) not retain, use, or disclose Personal Data outside of the direct business relationship between Customer and Writer, or for any purpose not set forth in this DPA or the Agreement;
- (ii) not “sell” or “share” any Personal Data, or use Personal Data for purposes of “targeted advertising,” as such terms are defined in Data Protection Laws;
- (iii) comply with any applicable restrictions under the CCPA on combining Personal Data with personal data that Writer receives from, or on behalf of, another person or persons.
- (b) Confidentiality. Writer will ensure that the persons Processing the Personal Data are bound by obligations of confidentiality no less protective than those set forth in the Agreement or are under an appropriate statutory obligation of confidentiality.
4. Data Security.
Writer will use appropriate administrative, technical, physical, and organizational measures to protect Personal Data as set forth in Exhibit B. Writer will provide the level of protection for Personal Data that is required under Data Protection Laws.
5. Security Incident.
- (a) Notice. Writer will notify Customer of any Security Incident without undue delay or within the time period required under Data Protection Laws. This notification will include Writer’s current assessment of the Security Incident.
- (b) Responsibilities of the Parties. Writer will comply with the Security Incident-related obligations applicable to it under Data Protection Laws.
6. Subprocessors.
- (a) Authorization to Engage Subprocessors. Customer agrees that Writer may engage Subprocessors to Process the Personal Data on Writer’s behalf to provide the Platform. Writer will impose contractual obligations on any Subprocessor it appoints requiring it to protect Personal Data.
- (b) Subprocessor Notice and Objections. If Customer subscribes to receive updates available on Writer’s Subprocessor page, Customer will be automatically notified of new Subprocessors before Writer authorizes such Subprocessor to process Customer Personal Data.
7. Data Transfers.
- (a) Authorization to Transfer Personal Data. Customer authorizes Writer and its Subprocessors to make international transfers of Personal Data in accordance with this DPA and Data Protection Laws.
- (b) Order of Precedence. The Parties acknowledge that Data Protection Laws may require them to implement certain safeguards for Customer to transfer Personal Data to Writer.
8. Audits.
- (a) Standard Audit Process. Writer will make available to Customer documentation, data, certifications, reports, and records relating to Writer’s Processing of Personal Data to demonstrate compliance with this DPA provided the Agreement remains in effect and such audit is at Customer’s sole expense.
9. Return or Destruction of Personal Data.
Except to the extent required otherwise by Data Protection Laws, Writer will, at the choice of Customer and upon Customer’s written request return to Customer and/or delete all Personal Data, unless Data Protection Laws require Writer to retain Personal Data.
10. Survival; Amendments.
The provisions of this DPA survive the termination or expiration of the Agreement for so long as Writer or its Subprocessors Process Personal Data. Writer may amend this DPA to comply with Data Protection Laws and will notify Customer of such changes.
Exhibit A
ANNEX I to the EU SCCS
A. List of parties
Data exporter(s):
- Name: Customer, as identified in the Agreement.
Data importer(s):
- Name: Writer, as identified in the Agreement.
B. Description of transfer
Categories of data subjects whose personal data is transferred: The categories of data subjects whose Personal Data is transferred are determined solely by the data exporter.
Categories of personal data transferred: The categories of Personal Data transferred are determined solely by the data exporter.
C. Competent supervisory authority
To the extent legally permitted, the competent supervisory authority is the Irish Data Protection Commission.
Exhibit B
Data security measures
Writer has implemented and will continue to maintain administrative, technical, physical, and organizational security measures to protect the security, confidentiality, and integrity of Customer Materials, including any Personal Data therein.