This Data Processing Agreement, alongside all its Annexes, Schedules (“DPA”) is entered into between North American Resellers LLC, a company with its mailing address at 848 Prospect St, Suite C, La Jolla, CA 92037, USA (“Flexmonster”) and Customer pursuant to Website Terms and Conditions, Software License Agreement, SaaS Entry License Agreement, or any other written or electronic agreement executed between Customer and Flexmonster (as applicable) (“Agreement”). This DPA forms part of Agreement and sets out the terms that apply where and only to the extent that Flexmonster processes Personal Data on behalf of Customer under Agreement and such Personal Data is subject to Data Protection Laws of the appropriate jurisdiction.
Following Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (“EU GDPR”), other laws and regulations, including laws and regulations of the European Union, the European Economic Area, their member states and the United Kingdom any amendments, replacements or renewals thereof, applicable to the processing of Personal Data, including where applicable the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2020, UK Data Protection Act 2018 (“UK GDPR”), the FDPA, the CCPA and any applicable national implementing laws, regulations and secondary legislation relating to the processing of Personal Data and the privacy of electronic communications, as amended, replaced or updated from time to time, including the Privacy and Electronic Communications Directive (2002/58/EC) and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426) (collectively “Data Protection Law”),
Parties have agreed as follows:
1.1. For the purposes of the implementation of Data Protection Law and, namely, Article 28(3) of EU GDPR, the rights and obligations of Customer and Flexmonster in processing Personal Data on behalf of Customer are set out herein. This DPA is designed to protect the rights of Customer, minimize the specific risks associated with the protection of Personal Data, and ensure the clarity of the relationship between Customer and Flexmonster, as well as the respective rights and obligations of both Parties.
1.2. To enable Customer to use Flexmonster Website, its relevant services, products, Materials, Flexmonster Software, and related services, or other Flexmonster’s products and services (“Services”), Flexmonster may process Customer data on behalf of Customer (“Customer Data”). Customer Data may include Personal Data and Account Data. Flexmonster, its affiliates, Flexmonster Personnel, and any subcontracted third-party processors (“Sub-Processors”) shall process such Personal Data solely to the extent necessary to provide Services and strictly in accordance with documented instructions from Customer, the terms of Agreement, this DPA, and Privacy Policy, as may be updated from time to time.
1.3. Customer and Flexmonster shall take steps to ensure that any natural person acting under the authority of Customer or Flexmonster who has access to Personal Data does not process it except on the instructions of Customer, unless they are required to do so by applicable Data Protection Law.
1.4. Parties acknowledge and agree that regarding the processing of Personal Data under the terms of this DPA, Customer may act either as Controller or Processor, and Flexmonster acts as Processor, and the provisions of this DPA related to Controller and Processor shall apply respectively.
1.5. Parties acknowledge and agree that when Customer provides Customer Data, or Flexmonster receives or processes Customer Data while providing Services, such Customer Data may constitute Personal Data relating to Customer’s business relationship with Flexmonster, including but not limited to identifiers, authentication data, financial information, contact details, digital footprints, and account or settings information and other data as prescribed in subclause 2.2.1 of Annex 1 hereto (“Account Data”). For the purposes of the processing of Account Data or when Flexmonster solely determines the purposes and means of Personal Data processing, Flexmonster processes such Account Data or Personal Data as an independent Controller and not a joint Controller with Customer, and Customer is Controller. Flexmonster processes Account Data or Personal Data as an independent Controller for the purposes as further prescribed in subclause 2.5.1 of Annex 1 hereto.
Unless otherwise stated in the relevant provision, for operations in which Flexmonster acts as an independent Controller, only Articles 7, 12-14 of this DPA will apply, to the extent applicable to the specific case.
2.1. Flexmonster will have the obligations set forth in this Article 2 if it processes Personal Data in its capacity as Customer’s Processor or service provider; for clarity, these obligations do not apply to Flexmonster in its capacity as Controller, business, or third party.
2.2. Flexmonster confirms that it shall process Personal Data on behalf of Customer only in accordance with the documented instructions of Customer as set forth in Agreement, this DPA, or subsequent written agreements between Parties, or as otherwise necessary to provide Services to Customer, unless processing is required by Data Protection Law to which Flexmonster is subject. In such cases, Flexmonster shall inform Customer of the legal requirement before processing, unless that law prohibits such information for reasons of substantial public interest.
2.2.1. Customer will ensure that its instructions comply with applicable Data Protection Law. Notwithstanding the terms of Clause 2.2.2 below, Customer acknowledges and agrees that Flexmonster is neither responsible for determining which laws and/or regulations are applicable to Customer’s business or industry, nor whether Flexmonster’s provision of Services meets or will meet the requirements of laws and/or regulations that are not applicable to Flexmonster. Customer will ensure that Flexmonster’s processing of Personal Data, when done in accordance with Customer’s instructions, will not cause Flexmonster to violate any applicable law and/or regulation, including applicable Data Protection Law.
2.2.2. To the extent that Flexmonster cannot comply with an instruction from Customer, or in case, at Flexmonster’s discretion, a processing instruction is deemed to infringe applicable Data Protection Law, Flexmonster shall cease all processing that is infringing applicable Data Protection Law and shall promptly inform Customer, providing relevant details on the aforementioned. Parties shall meet in good faith to find a viable solution to address the issue encountered.
2.3. Flexmonster will inform Customer immediately (and in any event within seventy-two (72) hours of discovering) if it becomes aware of any data security breaches and discovers that Personal Data processed on behalf of Customer is affected. In such cases, Flexmonster will take the necessary immediate measures to secure Personal Data and mitigate potential negative consequences for data subjects, coordinate its further actions with Customer, and support Customer in fulfilling any reporting obligations to data subjects and authorities. Flexmonster shall cooperate with Customer and take reasonable commercial steps as are directed by Customer to assist in the investigation, mitigation, and remediation of each such Personal Data breach. Notifications will be delivered to the email address of Customer that is mentioned in Agreement or obtained by Flexmonster during any email correspondence. Customer agrees that email notification of Personal Data breach is sufficient. Customer agrees that Flexmonster may not notify Customer of security-related events that do not result in Personal Data breach.
2.4. Flexmonster shall not: (i) sell Personal Data; (ii) retain, use, or disclose Personal Data for commercial purposes other than providing Services under the terms of Agreement; or (iii) retain, use, or disclose Personal Data outside of the terms of this DPA or Agreement.
3.1. Customer represents and warrants that: (i) it is responsible for ensuring that Personal Data is processed in accordance with this DPA and Data Protection Law and that there is a lawful basis for the processing of all Personal Data disclosed to Flexmonster; (ii) it has obtained any, and all, necessary permissions and authorizations required to permit Flexmonster, its affiliates, Flexmonster Personnel and Sub-Processors to process Personal Data as contemplated by this DPA and Agreement; and (iii) it shall ensure that all Customer’s affiliates who use Services shall comply with the Customer’s obligations under this DPA as if they were a party to it.
3.2. Customer shall implement appropriate technical and organizational procedures to protect Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons.
3.3. Customer warrants that it has used reasonable efforts to determine that Flexmonster is able, through the implementation of appropriate technical and organizational measures, to satisfy its obligations under this DPA.
3.4. Customer acknowledges and agrees that some instructions from Customer, including destruction or return of data, Flexmonster assisting with audits, inspections, data protection impact assessments, or providing any assistance under this DPA, may result in additional fees. Flexmonster shall be entitled to charge Customer for its reasonable costs and expenses in providing any such assistance.
4.1. Flexmonster hereby informs Customer that, for the purpose of fulfilling its obligations under Agreement, it may engage employees, sole proprietors, individuals, agents, officers, legal entities, other contractors (“Flexmonster Personnel”) or affiliates in countries outside the European Economic Area (EEA) and/or the United Kingdom (i.e. USA, Ukraine, Canada) to provide legal, accountant, commercial, technical, operational, and customer-related support on its behalf. Customer hereby authorizes Flexmonster to engage Flexmonster Personnel for the purposes specified herein.
4.2. Flexmonster shall:
4.2.1. ensure that Flexmonster Personnel process Personal Data solely in accordance with this DPA and Agreement;
4.2.2. implement access controls to ensure that Personal Data is not accessible by default and is limited to Flexmonster Personnel whose access is essential for the provision of Services; and
4.2.3. take commercially reasonable steps to ensure the reliability and integrity of any Flexmonster Personnel who have access to Personal Data.
5.1. Customer hereby acknowledges and agrees that in connection with the provision of Services and processing Personal Data on behalf of Customer under this DPA and the relevant Agreement: (i) Flexmonster’s affiliates and Flexmonster Personnel may be used as Sub-Processors; and (ii) Flexmonster, its affiliates, or Flexmonster Personnel, respectively, may engage third-party Sub-Processors.
5.2. Customer authorizes Flexmonster to engage Sub-Processors named in Annex 3 hereto to process Personal Data on behalf of Customer if Flexmonster and the relevant Sub-Processor enter into an agreement that requires the relevant Sub-Processor to meet obligations that are no less protective than this DPA. Customer acknowledges and agrees that the composition of this list may change from time to time, and Flexmonster is not required to provide prior notice of each change, unless otherwise required by applicable Data Protection Law. To receive advance notification of any new Sub-Processor added to the list of Sub-Processors, Customer may subscribe by completing the form available at the link provided in Annex 3.
5.3. New Sub-Processors will be deemed approved by Customer if Customer does not object within fourteen (14) days of notification by Flexmonster. Customer must substantiate its objection. Failure to object to such new Sub-Processor in writing within the specified period shall be deemed acceptance of the new Sub-Processor by Customer.
5.4. If the right of objection pursuant to Clause 5.3 hereinabove is exercised, and Flexmonster is unable to offer Customer Services that cannot be provided by Flexmonster without the use of the new or replacement Sub-Processor, Customer will have an extraordinary right to terminate this DPA or Agreement without notice. Refunds of fees for Services in the event of termination under this Clause shall be governed by the terms of the relevant Agreement.
6.1. Flexmonster shall implement appropriate technical and organizational procedures to protect Personal Data, considering the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons.
6.2. Flexmonster shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: (i) the pseudonymization and encryption of Personal Data; (ii) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (iii) the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; (iv) a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing. In assessing the appropriate level of security, account shall be taken, in particular, of the risks presented by processing, including accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise processed.
6.3. Customer accepts and agrees that the technical and organizational measures are subject to development and review and that Flexmonster may use alternative suitable measures to those detailed in the attachments to this DPA, provided such measures are at least equivalent to the technical and organizational measures set out in Annex 2 and appropriate pursuant to Flexmonster’s obligations in Clauses 6.1 and 6.2 above. If Flexmonster plans to change the technical and organizational measures, it will notify Customer of this at least thirty (30) calendar days in advance via email and provide it with an updated version of the technical and organizational measures. Subject to this notification period, Flexmonster may unilaterally amend the technical and organizational measures, provided these serve to maintain or improve data security.
6.4. Taking into account the nature of the processing and the information available to Flexmonster, Flexmonster shall assist Customer by having in place appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Customer’s obligation to respond to requests for exercising data subject’s rights and the Customer’s compliance with the Customer’s data protection obligations in respect of the processing of Personal Data.
6.5. Customer acknowledges and agrees that, while providing Services to Customer, Flexmonster may be required to access Personal Data to address any technical issues or queries from Customer and to ensure the proper functioning of Services. All such access by Flexmonster will be limited to those purposes.
6.6. Flexmonster shall always implement and adhere to the technical and organizational measures detailed in Annex 2 as the minimum security standard.
7.1. Flexmonster undertakes not to disclose or otherwise make available to any third party any Personal Data, information about the processing of Personal Data covered by this DPA, or any other information received by Flexmonster as a result of this DPA or in its role as Processor or independent Controller. This obligation does not apply where Flexmonster is instructed or required by law to disclose such information to a public authority. In such cases, Flexmonster shall promptly notify Customer in writing and request that the disclosed Personal Data be subject to appropriate confidentiality obligations. The obligation to preserve confidentiality shall continue to apply after this DPA ceases to be in effect.
7.2. Flexmonster shall ensure that Flexmonster Personnel, its authorized affiliates, or Sub-Processors: (i) are informed of the confidential nature of Personal Data and committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality; (ii) have received appropriate training regarding their data protection and security responsibilities; and (iii) are subject to binding obligations that provide at least the same level of protection for Personal Data as those set out in this DPA.
8.1. Customer acknowledges and agrees that Flexmonster, Flexmonster Personnel, Flexmonster authorized affiliates, or Sub-Processors, may process Personal Data on a global basis as necessary for the performance of Agreement, including in countries outside the European Economic Area (EEA) and/or the United Kingdom (“Third Countries”) and as provided in Annex 3. Customer hereby approves the transfer of Personal Data to the locations stated in Annex 3 and acknowledges that the basis of such transfer between jurisdictions is acceptable.
8.2. Personal Data may be transferred to Third Countries that offer an adequate level of data protection recognized by the European Commission, or the competent authority for the United Kingdom and Switzerland (“Adequacy Decisions”), without any further safeguards being necessary.
8.3. Where the processing of Personal Data involves a transfer (either directly or via onward transfer) of Personal Data from the EEA and/or the United Kingdom to Third Countries which have not been subject to an Adequacy Decision, and such transfer or disclosure is not otherwise permitted by a valid transfer mechanism under Data Protection Law, Parties agree that such transfer shall be governed by (i) for the transfers form EU: the Standard Contractual Clauses for the transfer of personal data to third countries, pursuant to the European Commission’s decision (EU) 2021/914 of 4 June 2021 (“SCCs”), or (ii) for transfers from the United Kingdom: the SCCs as amended by the UK International Data Transfer Addendum issued by the Information Commissioner’s Office (“UK Addendum”). SCCs and UK Addendum are incorporated into this DPA by reference and shall be deemed completed as set forth in Schedule I. Flexmonster undertakes to comply with the transfer obligations required by applicable Data Protection Law.
9.1. Flexmonster shall provide reasonable cooperation and assistance to Customer in responding to requests from data subjects seeking to exercise their rights under applicable Data Protection Law.
9.2. Upon receipt of such a request, Flexmonster shall promptly notify Customer and, where technically feasible and appropriate, assist Customer in implementing necessary measures to facilitate a timely and compliant response.
9.3. Customer acknowledges that Flexmonster will process such requests only to the extent permitted by applicable Data Protection Law and in accordance with its internal procedures, ensuring lawful and reasonable fulfillment where possible.
9.4. Customer retains primary responsibility for responding to data subject requests under applicable Data Protection Law. However, Flexmonster may assist in fulfilling specific requests upon receiving the Customer’s written instructions, provided such assistance does not impose disproportionate effort and Customer supplies clear and detailed guidance.
9.5. If Flexmonster receives a request directly from a data subject regarding their Personal Data, it shall, unless legally prohibited, refer the individual to Customer. In cases where Flexmonster is legally obligated to respond, Customer shall cooperate fully and reimburse Flexmonster for any reasonable costs incurred in providing such assistance.
9.6. In no event does this DPA restrict or limit the rights of any data subject or of any competent supervisory authority.
10.1. Flexmonster shall make available to Customer all information reasonably necessary to demonstrate compliance with its processing obligations under this DPA and the relevant Agreement and allow for and contribute to audits and inspections.
10.2. Customer has the right to have compliance with the agreed obligations audited by an employed or externally commissioned auditor. If Customer plans to commission an external auditor who is in a competitive relationship with Flexmonster, Flexmonster may object to the commissioning of this auditor.
10.3. Audits by Customer are generally limited to one date per calendar year and must be substantiated for their proper planning and performance. For organizational and security reasons, Flexmonster may limit audits in the context of which the auditor wishes to inspect the data at the premises or physical facilities of Flexmonster to certain dates in the calendar year. Any audit conducted under this DPA shall consist of examination of the most recent reports, certificates, and/or extracts prepared by an independent auditor bound by confidentiality provisions similar to those set out in Agreement.
10.4. Flexmonster may subject audits to the fulfillment of the following conditions by Customer:
10.4.1. advance notification of the audit of at least one month by Customer;
10.4.2. performance of the audit during Flexmonster’s normal business hours, avoiding disruptions to business operations as far as possible;
10.4.3. signing of a non-disclosure agreement by the auditor regarding business secrets and the specific implementations of technical and organizational measures;
10.4.4. audit should be limited in scope to matters specific to Customer and agreed in advance;
10.4.5. proof of appropriate professional qualifications of the auditor.
This Clause shall not modify or limit the rights of audit of Customer, instead, it is intended to clarify the procedures in respect of any audit undertaken pursuant thereto.
10.5. The expenses for audits, particularly for those employees of Flexmonster who support and accompany the auditor, are to be reimbursed by Customer to Flexmonster.
10.6. Customer will provide Flexmonster with copies of any audit reports generated in connection with any audit under this Article, unless prohibited by applicable law. Customer may use the audit reports only to meet its regulatory audit requirements and/or to confirm compliance with the requirements of this DPA. Customer will promptly notify Flexmonster of any noncompliance discovered during an audit, and Flexmonster will have the opportunity to object to the finding, remediate, and/or rectify any issues identified within thirty (30) days after Customer’s notification.
11.1 Flexmonster shall, at the choice of Customer, upon receipt of a written request received within thirty (30) days of the end of the provision of Services, delete or return Personal Data to Customer unless other terms are stipulated in the relevant Agreement or the retention of the data is required for legal and regulatory purposes. Parties agree that a written instruction via email from Customer or its authorized representative shall constitute a valid notice under this Clause. In the absence of a specific request within this timeframe, Flexmonster reserves the right to delete Personal Data in accordance with its standard data retention policies. Deletion shall be performed in accordance with Flexmonster’s standard backup and retention cycles, unless otherwise required by applicable law.
12.1. Flexmonster may (i) compile statistical and other information related to the performance, operation, and use of Services, and (ii) use data from Services environment in a de-identified and/or aggregated form for security and operations management, to create statistical analyses, and for research and development purposes (collectively “Service Analyses”). Flexmonster may make Service Analyses publicly available. However, Service Analyses will not incorporate Customer Data or Personal Data in a form that could identify or serve to identify Customer or any data subject. Flexmonster retains all intellectual property rights in product and/or Service Analyses.
13.1. The limitations of liability of Agreement shall apply to each Party respectively in relation to this DPA.
13.2. Parties agree that Flexmonster shall be liable for any breaches of this DPA caused by the acts and omissions or negligence of its Sub-Processors to the same extent as Flexmonster would be liable if performing Services and processing Personal Data on behalf of Customer directly under this DPA and the relevant Agreement, subject to any limitations on liability set forth in this DPA or Agreement.
13.3. Parties agree that Customer shall be liable for any breaches of this DPA caused by the acts and omissions or negligence of its affiliates as if such acts, omissions, or negligence had been committed by Customer itself.
13.4. Customer shall not be entitled to recover more than once in respect of the same loss.
14.1. The term of this DPA corresponds to the term of Agreement.
14.2. In the event of inconsistencies between Agreement and DPA, the provisions of this DPA will prevail. The order of precedence will be: (a) this DPA; (b) Agreement; and (c) Privacy Policy. To the extent there is any conflict between SCCs and any other terms in this DPA, Agreement, or Privacy Policy, the provisions of SCCs will prevail.
14.3. This DPA will continue to apply beyond its term as long as Flexmonster is in possession of Personal Data that it has processed on behalf of Customer. Personal Data that has not already been deleted in accordance with the storage periods specified in Annex 1 will be returned to Customer or deleted at the Customer’s discretion. The statutory retention obligations of Flexmonster remain reserved, in particular with regard to the retention of accounting records.
14.4. Provisions of this DPA or of the applicable Data Protection Law that result in obligations for Parties beyond the duration of DPA will continue to apply beyond the end of the same.
14.5. This DPA will be governed by and construed in accordance with the respective Applicable/Governing Law section of the relevant Agreement, unless otherwise required by applicable Data Protection Law.
14.6. The terms used in this DPA shall have the same meaning as in the EU GDPR, other applicable Data Protection Law, or Agreement unless otherwise explicitly defined herein.
14.7. Unless otherwise specifically indicated, all notices under this DPA, must be in English, in writing, and addressed as follows: (i) in the case of Flexmonster privacy request shall be submitted by using the relevant form here or by writing at: North American Resellers LLC, 848 Prospect St, Suite C, La Jolla, CA 92037, USA, and (ii) in the case of Customer to the contact information provided in while ordering Services or as stipulated in the relevant Agreement.
14.8. Flexmonster may update this DPA from time to time. Where such updates materially affect Customer’s rights or Flexmonster’s obligations as Processor, Flexmonster will provide reasonable advance notice. This Clause does not replace or modify any specific notification obligations expressly set out in this DPA.
14.9. Unless otherwise specified, writing notices under this DPA may be provided by email to the contact details set out in Annex 1 to this DPA, or in Agreement, or as otherwise designated by Parties.
Data exporter(s):
| Name of Data exporter: | Party identified as "Customer" in Agreement and this DPA |
| Address: | As set forth in Agreement unless separately provided by Customer |
| Contact person’s name, position, and contact details: | As set forth in Agreement unless separately provided by Customer |
| Activities relevant to the data transferred under this DPA: | See Clause 2 of this Annex 1 below |
| Signature and date: | This Annex 1 shall automatically be deemed executed when Agreement is executed by Customer |
| Role (controller/processor): | Controller or Processor |
Data importer(s):
| Name: | As set forth in Agreement |
| Address: | As set forth in Agreement |
| Contact person’s name, position, and contact details: | Flexmonster Privacy Team – privacy@flexmonster.com |
| Activities relevant to the data transferred under this DPA: | See Clause 2 of this Annex 1 below |
| Signature and date: | This Annex 1 shall automatically be deemed executed when Agreement is executed by Flexmonster |
| Role (controller/processor): | Controller or Processor |
| 2.1. Categories of data subjects whose Personal Data is transferred | 2.1.1. | MODULE ONE: Transfer Controller to Controller Customers, its employees, agents, advisors, contractors, or any user authorized by Customer (who are natural persons) to use Services from Flexmonster. |
|---|---|---|
| 2.1.2. | MODULE TWO: Transfer Controller to Processor and MODULE THREE: Transfer Processor to Processor Customers, its employees, agents, advisors, contractors, or any user authorized by Customer (who are natural persons) to use Services from Flexmonster (i.e. for the purposes of managing Client’s Area on Flexmonster Website). Customer’s end users: prospects, customers, business partners and vendors of Customer and/or their respective employees or contact persons (who are natural persons). | |
| 2.2. Categories of Personal Data transferred | 2.2.1. | MODULE ONE: Transfer Controller to Controller Account Data which constitutes Personal Data, including but not limited to Name (including First name and Last name), account or settings information, contact and payment information as well as billing/postal addresses, email address, telephone number, job title of the Customer’s employee, industry, IP address, purchase history, User Content, communications, digital footprints, cookies and other tracking technologies, usage of Services. |
| 2.2.2. | MODULE TWO: Transfer Controller to Processor and MODULE THREE: Transfer Processor to Processor Any Personal Data processed by Flexmonster in connection with Services, managing Client’s Area on Flexmonster Website, and which relate to Customer’s data subjects’ activity and interactions with Flexmonster as determined by Customer. | |
| 2.3. Sensitive data transferred (if applicable) and applied restrictions or safeguards | 2.3.1. | Flexmonster does not knowingly collect (and Customer shall not submit) any sensitive data or any special categories of data (as defined under applicable Data Protection Law). |
| 2.4. Frequency of the transfer | 2.4.1. | Continuous. |
| 2.5. Nature and purpose(s) of the data transfer and processing | 2.5.1. | MODULE ONE: Transfer Controller to Controller Customer discloses Personal Data to Flexmonster, so Flexmonster could:
|
| 2.5.2. | MODULE TWO: Transfer Controller to Processor and MODULE THREE: Transfer Processor to Processor Flexmonster will process Personal Data as necessary to provide Services and according to Customer’s direct instruction only based on Agreement and/or statement of work, and this DPA. Additional information regarding the nature of processing (including transfer) shall be described in the respective Agreement, statement of work or order for the relevant Service and the documentation referring to the technical capabilities and features including but not limited to collection, structuring, storage, transmission or otherwise making available. Flexmonster shall not sell Customer’s Personal Data or Customer end users’ Personal Data and does not share such end users’ Personal Data with third parties for compensation or for those third parties’ own business interests. | |
| 2.6. Retention period (or, if not possible to determine, the criterial used to determine the period) | 2.6.1. | MODULE ONE: Transfer Controller to Controller Unless agreed otherwise in writing Flexmonster will process Account Data for the duration of Agreement, subject to Clause 14.1 of this DPA or as long as Flexmonster has a business purpose for it, or for the longest time allowable by applicable law. Retention of some Account Data is also subject to Privacy Policy. |
| 2.6.2. | MODULE TWO: Transfer Controller to Processor and MODULE THREE: Transfer Processor to Processor Upon termination or expiry of this DPA, Flexmonster will (at Customer's election) delete or return to Customer all Personal Data (including copies) in its possession or control. Customer may request to Flexmonster to delete all Personal Data, and Flexmonster will proceed to delete the data as soon as reasonably practicable and consistent with its obligations in this DPA. | |
| 2.7. For transfers to Sub-Processors, also specify subject matter, nature, and duration of the processing | 2.7.1. | MODULE TWO: Transfer Controller to Processor and MODULE THREE: Transfer Processor to Processor Flexmonster shall use Sub-Processors when it acts as Processor. Customer authorizes Flexmonster to use these Sub-Processors consistent with Article 5 of this DPA and Annex 3 of this DPA. The list of Sub‑Processors is set out in Annex 3 of this DPA. |
Where the EU GDPR applies, the competent supervisory authority shall be (i) the supervisory authority applicable to the data exporter in its EEA country of establishment or, (ii) where the data exporter is not established in the EEA, the supervisory authority applicable in the EEA country where the data exporter's EU representative has been appointed pursuant to Article 27(1) EU GDPR, or (iii) where the data exporter is not obliged to appoint a representative, the supervisory authority applicable to the EEA country where the data subjects relevant to the transfer are located. Where the UK GDPR applies, the UK Information Commissioner's Office.
Where applicable, this Annex 2 will serve as Annex II to SCCs.
1.1. Policies & governance: Flexmonster maintains and implements its information security policies, standards, and procedures to protect the confidentiality, integrity, and availability of all information and data. Adoption of information security policies, standards, and procedures is reviewed at least annually.
1.2. Training & awareness: All Flexmonster Personnel undergo onboarding and annual security awareness training, as outlined in the Employee Training and Awareness Program. Responsibilities for security processes are clearly assigned.
1.3. Access control: Flexmonster implements role-based access management, ensuring only authorized Flexmonster Personnel have access to Personal Data.
1.4. Vendor management: Before engaging new third-party service providers or vendors as Sub-Processors with access to Personal Data, Flexmonster conducts thorough due diligence and implements appropriate contractual safeguards to ensure that all Sub-Processors adhere to data protection obligations equivalent to those set out in this DPA. Flexmonster uses trusted third-party providers for hosting and backups, including Amazon Web Services (AWS), a reputable infrastructure-as-a-service provider. Flexmonster leverages AWS’s globally redundant services to ensure the reliable operation of its Services.
1.5. Incident response: Flexmonster maintains an incident response plan to promptly review, address, and mitigate any security breaches of which Flexmonster becomes aware from an independent third party, Customer, or through Flexmonster’s own discovery. The incident response plan includes clearly defined roles and responsibilities, as well as a reporting mechanism for suspected vulnerabilities and security events affecting Customer Data.
1.6. Testing and audits: Regular security reviews of third‑party libraries and software components are performed internally.
2.1. Encryption: Personal Data is encrypted in transit (TLS/SSL).
2.2. Systems hardening: Regular patching, vulnerability scanning, and configuration management are implemented to minimize risks.
2.3. Data minimization: Flexmonster limits collection and retention of Personal Data to what is strictly necessary.
2.4. Logging & monitoring: Flexmonster fulfils continuous monitoring of systems, with audit logs maintained and reviewed for suspicious activity.
2.5. Backup & recovery: Flexmonster provides regular backups of critical systems and data, with tested disaster recovery and business continuity plans.
3.1. Secure facilities: Access to Flexmonster's facilities is restricted to Flexmonster Personnel using ID and/or access cards.
3.2. Environmental controls: Flexmonster's physical premises, buildings, and assets are protected by implementing the following minimum environmental control mechanism requirements: a) air conditioning; b) humidity controls; c) fire detection systems; d) fire suppression systems appropriate for the environment. Uninterruptible Power Supply (UPS) or similar systems are deployed to protect critical IT systems in the event of a power failure.
3.3. Asset protection: All Flexmonster's equipment (e.g., laptops, monitors) is labeled, inventoried, and secured when not in use.
4.1. Secure software engineering and coding practices are applied throughout a defined software development lifecycle, including mandatory peer code review, dependency vetting, and regression testing prior to release.
4.2. All new Flexmonster Software code undergoes peer review, comprehensive quality assurance, and regression testing before being deployed to production. Each release of Flexmonster Software code is reviewed, and manual security testing is performed against the OWASP Top 10 vulnerabilities.
4.3. Flexmonster separates environments for development, testing, and production, whether logically or physically.
4.4. Flexmonster Software does not collect, store, or transfer data externally, including Personal Data, and does not enable external data transmission through Flexmonster Software.
5.1. Encryption: All data transmitted between the user’s browser and Flexmonster servers is encrypted using TLS 1.2+ protocols (HTTPS). User passwords are securely hashed and salted before storage; Flexmonster does not store passwords in plain text.
5.2. Network security: Flexmonster uses industry-standard firewalls and DDoS protection services to safeguard our infrastructure against malicious attacks.
5.3. Access control: Access to the Website's administrative panel and Customer Data is restricted to authorized personnel only, based on the principle of least privilege. Multi-factor authentication (MFA) is enforced for administrative access where applicable.
5.4. Backup & recovery: as detailed in Clause 2.5 of this Annex 2.
5.5. Software updates: Flexmonster regularly updates its server software, frameworks, and plugins to the latest stable versions to patch known security vulnerabilities.
6.1. Password policy enforces complexity, rotation, and secure storage for all Flexmonster Personnel.
6.2. Background checks are conducted for all Flexmonster Personnel.
6.3. NDA and security policy acknowledgment are required.
6.4. Flexmonster Personnel (i.e., developers) participate in periodic secure development training.
6.5. Logical and physical access is terminated within 24 hours of a Flexmonster Personnel's termination.
7.1. Flexmonster has a process that allows data subjects to exercise their privacy rights (including a right to amend and update their Personal Data), as described in Flexmonster’s Privacy Policy.
8.1. Flexmonster reviews and updates technical and organizational measures in response to technological developments, regulatory changes, or identified vulnerabilities.
Prior to engaging any third-party Sub-Processor, Flexmonster performs due diligence to evaluate their privacy, security, and confidentiality practices. Where SCCs are not applicable, Flexmonster shall ensure that a binding contract is in place with Sub-Processor that imposes data protection obligations substantially equivalent to those set forth in this DPA.
Upon the Customer's request, a copy of the contract with Sub-Processor and any subsequent amendments thereto shall be provided to Customer, thereby enabling Customer to ensure that Sub-Processor is subject to the same data protection obligations as outlined in this DPA. Flexmonster shall notify Customer of any failure by Sub-Processor to fulfil its obligations under that contract or other legal act binding on Sub-Processor.
Flexmonster uses Sub-Processors when it acts as Processor. The following list of third-party Sub-Processors is agreed by Customer:
| Sub-Processor | Purpose | Location of Sub-Processor |
|---|---|---|
| Amazon Web Services, Inc. | Hosting and infrastructure service provider | USA |
| Hetzner Online GmbH | Data storage and hosting services | EU |
| MongoDB, Inc. | Cloud database hosting and data storage for Client’s Area | USA |
| Campaign Monitor | Marketing email service | USA |
| Microsoft Corporation | Provision of Microsoft 365 cloud-based productivity suite and internal collaboration tools | USA |
| Google LLC (or Google Ireland Limited) | Email service provider, cloud storage & collaboration tools (Google Workspace); Website analytics and performance; Measurement and advertising‑related services (e.g., Enhanced Conversions, Google Ads, Google Analytics, Google Tag Manager); Security and fraud prevention service (reCAPTCHA). For other Google services that Flexmonster may use, Google may act as an independent controller of data | USA, EU |
| Stripe, Inc. | Credit card payment processing | USA |
| Slack Technologies, LLC (or other relevant entity from SFDC Group) | Communication software | USA |
| Docusign, Inc. | Contract signing and management | USA |
| Adobe Inc. | Cloud-based electronic signature services and contract management | USA |
| Chatbase Inc. | AI‑powered chatbot services | USA |
| Anthropic, PBC (or Anthropic Ireland, Limited) | AI functionality | USA, EU |
To engage Sub-Processors for processing Personal Data for purposes other than those specified in Clause 1 of Annex 3 hereto, a written authorization from Customer is required.
To subscribe to receive updates concerning new Sub-Processors that will be added to this list, please use this Request Form or send an email to privacy@flexmonster.com.
For any additional information concerning Flexmonster’s data processing practices or any specific Sub-Processor, please send an email to privacy@flexmonster.com identifying Sub-Processor and the requested information.
Customer may object to Flexmonster’s use of a specific Sub-Processor in accordance with the terms of this DPA. Such objection may be sent by email to privacy@flexmonster.com (subject line “Sub-Processor Objection”) containing the following information:
Objections must be based on legitimate data protection grounds in accordance with the terms of this DPA.
| SCCs Modules | Module One (Controller to Controller) | Module Two (Controller to Processor) | Module Three (Processor to Processor) |
|---|---|---|---|
| Applicability | it will apply for Account Data processing as described in Clause 1.5 of this DPA, whereby Customer acts as Controller and Flexmonster acts as an independent Controller | it will apply for data processing as described in Article 1 of this DPA, whereby Customer acts as Controller and Flexmonster acts as Processor | it will apply for data processing as described in Article 1 of this DPA, whereby Customer acts as Processor and Flexmonster acts as Sub-Processor |
| Options: | |||
| Clause 7 of SCCs | the optional docking clause will apply | ||
| Clause 9 of SCCs | - | Option 2 will apply, and the time period for prior notice of Sub-Processor changes shall be as set out in Clause 5.2 of this DPA | |
| Clause 11 of SCCs | the optional language will not apply | ||
| Clause 17 of SCCs | Option 2 will apply, and SCCs will be governed by the law of the EU Member State in which the data exporter is established. Where such law does not allow for third-party beneficiary rights, they shall be governed by the law of another EU Member State that does allow for third-party beneficiary rights. Parties agree that this shall be the law of Ireland | ||
| Clause 18(b) of SCCs | disputes shall be resolved before the courts of Ireland | disputes shall be resolved before the courts of the EU Member State in which the data exporter is established, and otherwise in Ireland | |
| Annex I of SCCs | shall be deemed completed with the information set out in Annex 1 to this DPA respectively | ||
| Annex II of SCCs | shall be deemed completed with the information set out in Annex 2 to this DPA | ||
2.1. references to "Regulation (EU) 2016/679" shall be interpreted as references to UK Privacy Laws or the Swiss DPA (as applicable);
2.2. references to specific Articles of "Regulation (EU) 2016/679" shall be replaced with the equivalent article or section of UK Privacy Laws or the Swiss DPA (as applicable);
2.3. references to "EU", "Union", "Member State", and "Member State law" shall be replaced with references to "UK" or "Switzerland", or "UK law" or "Swiss law" (as applicable);
2.4. the term "member state" shall not be interpreted in such a way as to exclude data subjects in the UK or Switzerland from the possibility of suing for their rights in their place of habitual residence (i.e., the UK or Switzerland);
2.5. Clause 13(a) of SCCs and Part C of Annex I of SCCs are not used, and the "competent supervisory authority" is the UK Information Commissioner or Swiss Federal Data Protection Information Commissioner (as applicable);
2.6. references to the "competent supervisory authority" and "competent courts" shall be replaced with references to the "Information Commissioner" and the "courts of England and Wales" or the "Swiss Federal Data Protection Information Commissioner" and "applicable courts of Switzerland" (as applicable);
2.7. in Clause 17 of SCCs, SCCs shall be governed by the laws of England and Wales or Switzerland (as applicable); and
2.8. with respect to transfers to which UK Privacy Laws apply, Clause 18 of SCCs shall be amended to state "Any dispute arising from these Clauses shall be resolved by the courts of England and Wales. A data subject may bring legal proceedings against the data exporter and/or data importer before the courts of any country in the UK. Parties agree to submit themselves to the jurisdiction of such courts", and with respect to transfers to which the Swiss DPA applies, Clause 18(b) of SCCs shall state that disputes shall be resolved before the applicable courts of Switzerland.
3.1. Table 1 (Parties): The relevant information is set forth in Annex 1 of this DPA.
3.2. Table 2 (Selected SCCs): SCCs, including the specific Modules and options selected in Clauses 1-3 of this Schedule I, are the "Approved EU SCCs" referred to in UK Addendum.
3.3. Table 3 (Appendix Information): The information required for the List of Parties, Description of Transfer, and Technical and Organizational Measures is set forth in Annex 1 and Annex 2 of this DPA.
3.4. Table 4 (Ending the Addendum): Both the importer and exporter may end UK Addendum as set out in Section 19 of UK Addendum; therefore, "neither party" is selected for Table 4.
4. It is not the intention of either Party to contradict or restrict any of the provisions set forth in SCCs and, accordingly, if and to the extent SCCs conflict with any provision of Agreement (including this DPA), SCCs shall prevail to the extent of such conflict.