NewsWhip Data Processing Addendum
This EU Data Processing Addendum (the “Addendum”) is entered into between NewsWhip Media Ltd., and its subsidiaries and affiliates (including but not limited to NewsWhip US, Inc.) with address at 47 Merrion Square, Dublin 2, Ireland (“NewsWhip”) and the company identified as the “Client” in this Addendum (the “Client”) on (the “Effective Date”). From the date of the last signature below, the Addendum shall form part of the agreement executed between NewsWhip and the Client governing the services provided by Client (the “Agreement”). This Addendum applies to the personal data received by NewsWhip from or on behalf of the Client in connection with the performance of the services under the Agreement including the personal data set out in Schedule 1 (“Client Personal Data”).
The following definitions apply in this Addendum (unless the context requires otherwise):
- “Data Protection Legislation” means the Data Protection Acts 1988 and 2018 (as may be amended from time to time), and as of 25 May 2018, the General Data Protection Regulation (EU) 2016/679 (the “GDPR”);
- “Security Breach” the accidental or unlawful destruction, loss, alteration, unauthorised disclosure or, or access to the Client Personal Data;
- “Services” has the meaning ascribed to it in the Agreement or, in the absence of any defined term in the Agreement, shall mean the services provided by NewsWhip to the Client in the manner contemplated by and in accordance with the terms of the Agreement; and
- “controller”, “data subject”, “personal data”, “processing”, “processor” and “supervisory authority” shall have the meanings given to those terms in the GDPR.
The following rules of interpretation apply in this Addendum (unless the context requires otherwise):
- a reference to this Addendum includes its schedules;
- words in the singular include the plural and vice versa;
- any words that follow ‘include’, ‘includes’, ‘including’, ‘in particular’ or any similar words and expressions shall be construed without limitation;
- clause, schedule or other headings in this Addendum are included for convenience only and shall have no effect on the interpretation of this Addendum;
- a reference to any statute, statutory provision, rule, regulation or any requirement shall be construed as including references to it as modified, consolidated, re-enacted or superseded from time to time and shall include all subordinate legislation made from time to time under that statute or statutory provision;
- a reference to any regulator or regulatory board shall include a reference to any replacement or successor bodies from time to time; and
- in the case of conflict or ambiguity between the terms of this Addendum and the terms of the Agreement as to the subject matter of this Addendum, the terms of this Addendum shall prevail.
3. Data Processing
In respect of any Client Personal Data processed by NewsWhip under this Addendum, the Parties acknowledge that the Client shall be the controller and NewsWhip shall be a processor.
4. Client Obligations
Client, as the controller or primary processor (as applicable), is solely responsible for establishing the lawful basis for the processing of Client Personal Data by NewsWhip under this Addendum and will ensure that it has all necessary appropriate consents and notices in place to enable lawful transfer of the Client Personal Data to NewsWhip for the duration and purposes of this Addendum. Client, as the controller, is further solely responsible for the accuracy and quality of the Client Personal Data.
5. NewsWhip Obligations
To the extent that NewsWhip processes Client Personal Data pursuant to this Addendum, NewsWhip shall:
- process the Client Personal Data in accordance with the terms of the Agreement and the instructions of the Client (unless NewsWhip is required to process the Client Personal Data by applicable European Union (“EU”) or EU Member State law in which case NewsWhip shall notify the Client of that legal requirement before such transfer or access occurs or is permitted, unless that law prohibits such notification on important grounds of public interest);
- ensure that all personnel authorised to process the Client Personal Data are party to confidentiality obligations in respect of the Client Personal Data;
- cooperate as reasonably requested by the Client (at the Client’s sole expense):
- to enable the Client to comply with any exercise of rights by a data subject under the Data Protection Legislation in respect of Client Personal Data; and
- where the Client conducts a data protection impact assessment;
- notify the Client if NewsWhip receives a request from a data subject to have access to that data subject’s personal data. NewsWhip shall not respond directly to such data subject unless it is instructed to do so by the Client;
- implement and maintain appropriate technical and organisational measures in place to ensure the security of the Client Personal Data taking into account:
- the state of the art;
- the costs of implementation;
- the nature, scope, context and purposes of the processing; and
- the inherent risk of the processing activities to data subjects;
- notify the Client without undue delay after becoming aware of any Security Breach; and
- cooperate with the Data Protection Commission (or, to the extent reasonably required by the Client, any other supervisory authority) in the performance of its tasks where required.
6. International Transfers
The Client hereby agrees to the transfer of Client Personal Data processed under this Addendum outside of the EU PROVIDED that in effecting any international transfer of Client Personal Data, NewsWhip shall ensure that:
- it has provided appropriate safeguards in relation to the transfer which may include Privacy Shield certification (in the case of US transferees) or EU standard contractual clauses. The Client hereby appoints NewsWhip as its agent for the purpose of entering into any EU standard contractual clauses in the context of providing the Services; and
- data subjects continue to have enforceable rights and effective legal remedies following the transfer.
The Client hereby authorises NewsWhip to use third parties (“sub-processors”) to provide the Services provided:
- NewsWhip shall notify the Client in advance of any proposed use of a sub-processor, and any replacement or addition to them and the Client shall have the right to object on reasonable grounds to the use of or change to any sub-processor within 14 days of Client notifying the Client of the change. In the event of the Client raising such an objection, NewsWhip may terminate part or all of the Agreement on 14 days’ notice;
- in engaging any sub-processor NewsWhip agrees adequate data protection arrangements that are in all material respects similar to those set out in this Addendum; and
- NewsWhip shall at all times remain liable for the acts and omissions of any sub-processor as if such acts and omissions were those of NewsWhip.For the purpose of this Addendum, the Client consents to the use of the sub-processors listed at Schedule 2.
NewsWhip shall make available all information reasonably requested by the Client to satisfy itself that NewsWhip is complying with its data protection obligations under this Addendum. Client (and its third-party representatives) shall be permitted to audit NewsWhip’s premises, systems, and facilities during normal business hours PROVIDED THAT:
- Client shall provide at least 14 days’ prior written notice of its intention to carry out an audit;
- Client shall ensure (and shall procure that each of its representatives) minimise the disruption to NewsWhip’s business in the course of such an audit or inspection;
- all expenses incurred by NewsWhip shall be promptly discharged by Client;
- NewsWhip may request that any third party representative performing an audit on behalf of Client shall provide written confidentiality undertakings to the reasonable satisfaction of NewsWhip and NewsWhip shall be entitled to refuse access to any of its premises or records until such time as it has received such undertakings;
- NewsWhip need not contribute or allow for an inspection or audit more than once in any calendar year, except for any additional audits or inspections which are required or requested be carried out in connection with the Data Protection Laws or a supervisory authority;
- NewsWhip may object in writing to an auditor or representative mandated by the Client if the auditor or representative is, in NewsWhip’s reasonable opinion, not suitably qualified or independent, a competitor of NewsWhip, or otherwise manifestly unsuitable (in the event of such an objection, the Client shall appoint another auditor or conduct the audit itself); and
- nothing in this Addendum shall entitle Client to access or inspect any records which contain information relating to any other client or customer of NewsWhip and NewsWhip shall be entitled to restrict or prevent access to any part of its premises which it considers in its sole discretion could compromise the security of any information or data relating to such other clients or customers.
NewsWhip will inform Client if it comes to its attention that any instructions received in respect of this clause 8 infringe the provisions of any applicable EU or EU Member State data protection law. Notwithstanding the foregoing, NewsWhip shall have no obligation to review the lawfulness of any instruction received from Client.
9. Term and Termination
This Addendum shall be effective as and from the Effective Date and shall remain in force until such time as the Agreement is terminated. Following termination of this Addendum, NewsWhip shall, at the written request and at the cost of the Client, delete or return Client Personal Data and copies thereof to the Client save to the extent that NewsWhip is required by applicable law to retain the Client Personal Data.
The general provisions listed in this clause 10 apply to this Addendum (unless the context requires otherwise).
- Any notice or other communication required to be given to a party under or in connection with this Addendum shall be in writing and shall be delivered by email only to the address set out at the end of this Addendum. Any notice or communication shall be deemed to have been received the first working day after the time of transmission
- The parties’ respective aggregate liability whether in contract, tort (including negligence), breach of statutory duty, or otherwise for any and all claims arising out of or in connection with this Addendum shall be as set out in the Agreement.
- Client shall not assign or deal in any other manner with any of its rights and obligations under this Addendum without the prior written consent of the NewsWhip (which is not to be unreasonably withheld or delayed).
- No failure or delay by a party to exercise any right or remedy provided under this Addendum or by law shall constitute a waiver of that or any other right or remedy, nor shall it preclude or restrict the further exercise of that or any other right or remedy. No single or partial exercise of such right or remedy shall preclude or restrict the further exercise of that or any other right or remedy.
- This Addendum, together with the Agreement, represents the entire agreement between the parties with respect to its subject matter. Each party confirms that it has not relied upon any representations not recorded in this document inducing it to enter into this Addendum. No variation of these terms and conditions will be valid unless confirmed in writing by authorised signatories of each of the parties on or after the date of this Addendum.
- No variation of this Addendum shall be effective unless it is in writing and signed by the parties (or their authorised representatives).
- If any provision or part-provision of this Addendum is or becomes invalid, illegal or unenforceable, the parties shall negotiate in good faith to amend such provision so that, as amended, it is legal, valid and enforceable, and, to the greatest extent possible, achieves the intended commercial result of the original provision. If such amendment is not possible, the relevant provision or part-provision shall be deemed deleted. Any amendment to or deletion of a provision or part-provision under this clause shall not affect the validity and enforceability of the rest of this Addendum.
- Nothing in this Addendum is intended to, or shall be deemed to, establish any partnership or joint venture between any of the parties, nor authorise any party to make or enter into any commitments for or on behalf of any other party except as expressly provided herein.
- This Addendum may be executed in any number of counterparts, each of which when executed shall constitute a duplicate original, but all the counterparts shall together constitute the one agreement. Transmission of an executed counterpart of this agreement by email (in PDF, JPEG or other agreed format) shall take effect as delivery of an executed counterpart of this Addendum.
- This Addendum and all disputes arising from this Addendum whether contractual or non-contractual in nature shall be governed by and construed in accordance with the laws of Ireland. The parties irrevocably submit to the exclusive jurisdiction of the Irish courts in relation to all matters arising out of or in connection with this Addendum.The parties hereby agree that this Addendum supersedes any conflicting or inconsistent provisions in the Agreement related to data protection and, in any event of ambiguity, this Addendum will prevail. The Agreement, as amended and modified by this Addendum, otherwise remains in full force and effect.
Schedule 1- Personal Data¹
The personal data transferred concern the following categories of data (please specify):
- Personal master data (including but not limited to name, address, title, company)
- Contact details (including but not limited to telephone number, mobile phone number, email address, fax number, business addresses, shipping address)
Schedule 2- List of Sub-Processors²
|Name||Processing||Description of Analysis|
|Gmail||Internal and external communications|
|Dropbox||Files including personal information||Storage of NewsWhip files|
|Slack||Files including personal information||Internal communications|
|Google Analytics||Usage Data including personal information||Site usage analytics|
|Intercom||Usage Data and personal information||Internal and external communications, client account lookups and servicing|
|G Suite / Google||Spreadsheets and Word processing documents that may contain personal information||Internal and external file sharing|
|Marketo||Usage Data||Marketing communications and analytics|
|SumoMe||Usage Data||Marketing communications and analytics|
|Mailchimp||Names, email addresses, company names||Marketing communications|
|Yesware||Names, email addresses and similar personal information||Email analytics|
|Salesforce||Names, email addresses, addresses and similar personal information||Lead, opportunity, account, contract lookups and client servicing|
|Xero||Names, email addresses and similar personal information||Invoicing payments|
|Stripe||Names, email addresses and similar personal information||Credit card payments|
|Logentries||Usage data||Log management|
|Internal NW software
(User Admin panel)
|Names, email addresses, company names||Account lookups and servicing|
² To be reviewed and amended as necessary