Data Processing Agreement

Legal

Dock Data Processing Agreement

THIS DATA PROCESSING AGREEMENT, including the selected modules of the Model Clauses and Annexes (“DPA”) forms part of and is subject to the Dock Terms of Service or other written or electronic agreement (“Main Agreement”) between Customer and Dock Labs, Inc. (“Dock,” “we,” “us,” “our”). Customer and Dock may be referred to herein as a “party” and together as the “parties.”

In the course of providing the Services to Customer under the Main Agreement, Dock may process Customer Personal Data (defined below) on behalf of Customer and the parties agree to comply with the following provisions with respect to any processing of Customer Personal Data by Dock. This DPA shall not replace any comparable or additional rights relating to processing of Customer Personal Data contained in the Main Agreement.

Annex 1 - Details of Processing

Annex 2 - Security Measures

Annex 3 - List of Sub-Processors

Annex 4 - UK Addendum


  1. Definitions

  1. Roles and Scope of Processing

  2. Processing Description. The type of personal data processed pursuant to this DPA and the subject matter, duration, nature and purpose of the processing, and the categories of data subjects, are as described in Annex 1 to the Model Clauses, in Exhibit 1 of this DPA.

    1. Data Processing Roles. In respect of the parties’ rights and obligations under this DPA regarding the Customer Personal Data, the parties acknowledge and agree that Customer is the controller and Dock is the processor.
    2. Compliance with Laws. Dock shall process Customer Personal Data in accordance with this DPA and Data Protection Laws applicable to its role under this DPA.
    3. Processing Instructions. Dock shall process Customer Personal Data in accordance with Customer’s written lawful instructions and only for the following purposes: (i) processing to provide the Services; (ii) processing to perform any steps necessary for the performance of the Main Agreement; (iii) processing initiated by Authorized Users in their use of the Service; (iv) processing to comply with other reasonable instructions provided by Customer.
    4. Customer Responsibilities. Customer is responsible for the accuracy, quality, and legality of the Customer Personal Data, the means by which Customer acquired such Customer Personal Data, and the instructions it provides to Dock regarding the processing of such Customer Personal Data.

  1. Subprocessing

  2. Notification of New Subprocessors. Dock’s authorized Subprocessors are listed in this Data Processing Agreement.

    1. Subprocessor Obligations. Dock will enter into a written agreement with each Subprocessor imposing data protection obligations no less protective of Customer Personal Data as this DPA or the Data Protection Laws.
    2. Subprocessor Objection Right. If Customer objects on reasonable grounds relating to data protection to Dock’s use of a new Subprocessor, then Customer shall promptly provide written notice of such objection to Dock.

  1. Security Measures and Security Incident Response

  2. Security Measures. Dock has implemented and will maintain appropriate technical, and organizational security measures intended to protect Customer Personal Data from Security Incidents.

    1. Personnel. Dock restricts its personnel from processing Customer Personal Data without authorization by Dock as set forth in the Security Measures.
    2. Customer Responsibilities. Customer is responsible for its secure use of the Service, including securing its account authentication credentials.
    3. Security Incident Response. Upon becoming aware of a Security Incident, Dock will notify Customer without undue delay and provide information relating to the Security Incident to Customer promptly as it becomes known.

  1. Audit and Records.

  2. Audit Rights. Dock shall make available to Customer all information in Dock’s possession or control and provide all assistance in connection with audits of Dock’s systems as Customer may reasonably request.

    1. Audit Procedures. Customer may, on giving at least thirty (30) days prior written notice, request that Customer’s personnel or a third party conduct an audit of Dock’s facilities, equipment, documents and electronic data relating to the processing of Customer Personal Data.

  1. Data Transfers.

Customer acknowledges and agrees that Dock may transfer and process Customer Personal Data to and in the United States and other locations in which Dock maintains data processing operations as more particularly described in the Subprocessor Site.


  1. Return or Deletion of Data.

Promptly upon Customer’s request, or within one hundred eighty (180) days after the termination or expiration of the Main Agreement, Dock shall delete or return Customer Personal Data in its possession or control.


  1. Cooperation

  2. Data Subject Rights Requests. Dock shall, taking into account the nature of the processing, reasonably assist Customer in responding to any requests from individuals relating to the processing of Customer Personal Data.

    1. Requests by Law Enforcement. Dock will inform a government agency that Dock is a processor or service provider of the Customer Personal Data if compelled to disclose Customer Personal Data to a law enforcement agency and will give Customer reasonable notice of the demand to allow Customer to seek a protective order or other appropriate remedy unless legally prohibited from doing so.
    2. Data Protection Impact Assessments (DPIAs). To the extent required under Data Protection Laws applicable to the EEA, Dock will provide requested information regarding the Service necessary to enable Customer to carry out data protection impact assessments.

  1. Europe

  2. Scope. The terms in this Section apply only if and to the extent Customer is established in the EEA or Customer Personal Data is subject to Data Protection Laws applicable to the EEA.

    1. Processing Instructions. Dock shall notify Customer in writing, unless prohibited from doing so under Data Protection Laws, if it becomes aware or believes that any processing instructions from Customer violates applicable Data Protection Laws.
    2. Transfer Mechanism. The parties agree that Dock shall abide by and process such Customer Personal Data in compliance with the Model Clauses.
    3. Model Clauses. The parties agree that: (i) Dock is a "data importer" and Customer is the "data exporter"; (ii) it is not the intention of either party to contradict or restrict any provisions of the Model Clauses.
    4. UK and Swiss Data Transfers. Dock shall process Customer Data originating in the UK in accordance with terms set forth in Annex 4.

  1. Controller Affiliates

  2. Affiliate Communications. Customer is responsible for coordinating all communications with Dock on behalf of its Affiliates regarding this DPA.

    1. Affiliate Enforcement. Customer Affiliates may enforce the terms of this DPA directly against Dock, subject to certain provisions.

  1. Limitation of Liability

  2. In no event shall any party limit its liability with respect to individual’s data protection rights under this DPA.

    1. Any claim or remedies Customer or its Affiliates may have against Dock arising under or in connection with this DPA will be subject to any limitation and exclusion of liability provisions that apply under the Main Agreement.

  1. RESTRICTIONS

  2. Dock is prohibited from:

    • selling Customer Personal Data;
    • retaining, using, or disclosing Customer Personal Data for any purposes other than specified.

  1. General

  2. This DPA is incorporated into and subject to the terms of the Main Agreement and shall be effective for the term of the Main Agreement or the duration of the Service.

    1. Each party acknowledges that the other party may disclose the Model Clauses, this DPA, and any privacy related provisions in the Main Agreement to any regulator upon request.
    2. Dock may periodically make modifications to this DPA as may be required to comply with Data Protection Laws.
    3. This DPA does not confer any third-party beneficiary rights and is intended for the benefit of the parties only.
    4. Other than as required by the Model Clauses, the dispute mechanisms in the Main Agreement govern any dispute pertaining to this DPA.

ANNEX 1

DETAILS OF PROCESSING

A. LIST OF PARTIES

Data exporter:

Data importer(s):

B. DESCRIPTION OF TRANSFER

C. COMPETENT SUPERVISORY AUTHORITY

The supervisory authority of one of the Member States in which the data subjects whose personal data is transferred are located shall act as competent supervisory authority.


ANNEX 2

SECURITY MEASURES

The technical and organizational measures implemented by Dock to ensure an appropriate level of security are as follows:


ANNEX 3

SUBPROCESSORS


ANNEX 4

View addendum