This document is also available in Spanish for your convenience; if the two versions differ, the English version governs.
Introduction
This Data Processing Addendum ("DPA") forms part of the Servato Terms of Service ("Agreement") between Servato ("Processor") and the customer subscribing to the Service ("Controller"). This DPA applies to the extent that Servato processes Personal Data on behalf of the Controller in the course of providing the Service.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, such as collection, storage, use, and deletion.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
- Other capitalized terms not defined herein have the meanings set forth in the Agreement.
2. Scope and purpose of processing
Processor will process Personal Data submitted to the Service by Controller for the sole purpose of providing the Service and fulfilling its obligations under the Agreement. The categories of data subjects and types of Personal Data processed are determined by the Controller in its use of the Service.
3. Obligations of the Processor
Processor agrees to:
- Process Personal Data only on the documented instructions of the Controller, as set forth in the Agreement and this DPA, unless required to do so by law.
- Ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement and maintain the technical and organizational security measures described in Section 5 of this DPA to protect the Personal Data.
- Taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising data subject rights.
- Assist the Controller in ensuring compliance with its obligations regarding security of processing and data breach notification.
- At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless applicable law requires storage of the Personal Data.
4. Sub-processors
Controller provides a general authorization for Processor to engage sub-processors to provide the Service. Processor shall maintain a list of its current sub-processors, available upon request. Processor will provide Controller with at least 30 days' prior written notice of any intended changes concerning the addition or replacement of sub-processors, thereby giving the Controller the opportunity to object to such changes. Processor shall ensure that any sub-processor is subject to data protection obligations that are at least as protective as those in this DPA.
5. Security measures
Processor will implement and maintain appropriate technical and organizational measures to protect Personal Data, including measures to ensure the ongoing confidentiality, integrity, availability, and resilience of our processing systems and services. These measures include data encryption in transit and at rest, access controls, and regular security assessments.
6. Data subject requests
The Service includes self-service features that allow Controller to access, modify, and delete Workspace Content, which may contain Personal Data. To the extent a data subject makes a request directly to Processor, Processor will promptly notify Controller and will not respond to the request directly, except as legally required.
7. Data transfers
Personal Data is processed and stored in the United States. To the extent any data transfer from another jurisdiction (such as the EU or UK) occurs, Processor will ensure such transfers are made in compliance with applicable data protection laws.
8. Data breach notification
If Processor becomes aware of a Personal Data Breach affecting Controller's data, Processor will notify the Controller's workspace owner(s) without undue delay, and in any event within 72 hours of discovery. Processor shall provide Controller with sufficient information to allow the Controller to meet any obligations to report the breach to data subjects or supervisory authorities.
9. Deletion of data
When Controller deletes their workspace from the Service, all associated Workspace Content is permanently deleted from production systems within 30 days.
10. Changes to this DPA
We may update this DPA from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes.