This Data Processing Addendum ("DPA") is incorporated into, and is subject to the terms and conditions of the executed Master Services Agreement or the online Terms and Conditions (each, the "Agreement") between the customer party to the Agreement ("Customer") and ShopRocket, LLC, a Tennessee limited liability company doing business as OktoRocket ("OktoRocket"). This DPA reflects Controller's instructions and the parties' agreement concerning the Processing of Personal Information (as those terms are defined below). This DPA, as it may be amended from time to time, is incorporated by reference into the Agreement between the parties.
Definitions.
The following definitions and rules of interpretation apply in this DPA.
"Business Purpose" means the services described in the Agreement.
"Controller" means any person or entity that alone or jointly with others determines the purposes and means of Processing Personal Information.
"Data Subject" means an individual who is the subject of the Personal Information and to whom or about whom the Personal Information relates or identifies, directly or indirectly.
"Personal Information" means any information OktoRocket processes for Customer that (a) identifies or relates to an individual, device or household which can be identified directly or indirectly from that data alone or in combination with other information in OktoRocket's possession or control or that OktoRocket is likely to have access to, or (b) the relevant Privacy and Data Protection Laws otherwise define as protected personal information.
"Privacy and Data Protection Laws" means all applicable international, federal or state laws and regulations relating to the processing, protection, or privacy of the Personal Information.
"Processing, Processes, or Process" means any activity that involves the use of Personal Information or that the relevant Privacy and Data Protection Laws may otherwise include in the definition of processing, processes, or process. It includes obtaining, using, disclosing, holding the data, or carrying out any operation or set of operations on the data including, but not limited to, organizing, amending, retrieving, using, disclosing, erasing, or destroying it. Processing also includes transferring Personal Information to third parties.
"Processor" means any person or entity that Processes Personal Information on behalf of the Customer.
"Sale" or "Sell" means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer's Personal Information for monetary or other valuable consideration.
"Security Breach" means any act or omission that compromises the security, confidentiality, or integrity of Personal Information or the physical, technical, administrative, or organizational safeguards put in place to protect it. The loss of or unauthorized access, disclosure, or acquisition of Personal Information is a Security Breach whether or not the incident rises to the level of a security breach under the Privacy and Data Protection Laws.
"Share" or "Sharing" means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer's Personal Information for cross-context behavioral advertising, whether or not for monetary or other valuable consideration.
General Terms.
- This DPA is subject to and incorporated into the Agreement; provided, however, that in the event of any conflict or ambiguity between this DPA and the Agreement relating to the Processing of Personal Information, this DPA will control.
- The parties acknowledge that with regard to the Processing of Personal Information, Customer is the Controller and OktoRocket is the Processor.
- Each party shall comply with their respective obligations under applicable Privacy and Data Protection Laws.
OktoRocket's Obligations.
- OktoRocket will only Process Personal Information in accordance with Customer's instructions as set out in this DPA, the Agreement or other written instructions and for no other commercial purpose.
- OktoRocket will not Sell, Share, or Process the Personal Information for any other purpose or in a way that does not comply with this DPA or the Privacy and Data Protection Laws. OktoRocket will not combine Personal Information received from Customer with any Personal Information received from another person or entity or OktoRocket's own interactions with a consumer, except for a Business Purpose.
- OktoRocket shall promptly notify Customer if, in its opinion, Customer's instruction would not comply with the Privacy and Data Protection Laws.
- OktoRocket shall promptly comply with any Customer request or instruction requiring OktoRocket to amend, transfer, or delete the Personal Information, or to stop, mitigate, or remediate any unauthorized processing.
- OktoRocket will maintain the confidentiality of all Personal Information. If OktoRocket receives a request for disclosure of Personal Information, OktoRocket must first inform Customer of the legal requirement to disclose such Personal Information and give Customer an opportunity to object or challenge the requirement, unless the law prohibits such notice.
- OktoRocket will reasonably assist Customer with meeting Customer's compliance obligations under the Privacy and Data Protection Laws, taking into account the nature of OktoRocket's processing and the information available to OktoRocket.
- OktoRocket will limit Personal Information access to those employees who require access to meet OktoRocket's obligations under this DPA and the Agreement.
- OktoRocket will hold those employees to a duty of confidentiality and ensure such employees are aware both of OktoRocket's duties and their personal duties and obligations under the Privacy and Data Protection Laws and this DPA.
Security.
- OktoRocket must at all times use appropriate technical and organizational measures designed to safeguard Personal Information against unauthorized or unlawful processing, access, copying, modification, storage, reproduction, display, or distribution, and against accidental loss, destruction, unavailability, or damage.
- OktoRocket must take reasonable precautions to preserve the integrity of any Personal Information it processes and to prevent any corruption or loss of the Personal Information, including but not limited to establishing effective back-up and data restoration procedures.
Security Breaches.
- OktoRocket shall notify Customer promptly and in any event within seventy-two (72) hours after becoming aware of a Security Breach. OktoRocket shall provide Customer with sufficient information to allow Customer to assess whether any notifications to consumers or regulators are required. Such notification will include (to the extent known by OktoRocket): (a) the nature of the Security Breach, including the categories and approximate number of Data Subjects concerned; (b) the likely impact of the Security Breach; and (c) the measures proposed or taken by OktoRocket to address the Security Breach, including any mitigation factors.
- OktoRocket shall make reasonable efforts to identify the cause of the Security Breach and undertake steps to remediate the cause of the Security Breach.
- OktoRocket will not inform any third party of a Security Breach without first obtaining Customer's prior written consent, except for its legal advisors or governmental or regulatory authorities, or as otherwise required by applicable law or regulation.
Subcontractors.
OktoRocket may only authorize a third party (subcontractor) to process the Personal Information if OktoRocket enters into a written contract with the subcontractor that contains terms substantially the same as those set out in this DPA.
Complaints, Data Subject Requests.
- OktoRocket must notify Customer immediately if it receives any complaint, notice, or communication that directly or indirectly relates to the Personal Information processing or to either party's compliance with the Privacy and Data Protection Laws.
- OktoRocket must notify Customer promptly upon receipt of a Data Subject request to exercise any rights the individual may have regarding their Personal Information, such as access or deletion. OktoRocket will reasonably assist Customer in responding to any complaint, notice, communication, or Data Subject request.
Data Return and Destruction.
- On termination of the Agreement for any reason or expiration of its term, OktoRocket will securely destroy or, if directed in writing by Customer, return and not retain, all or any Personal Information related to this DPA in its possession or control.
- If any law, regulation, or government or regulatory body requires OktoRocket to retain any documents or materials that OktoRocket would otherwise be required to return or destroy, it will notify Customer in writing of that retention requirement. OktoRocket may only use this retained Personal Information for the required retention reason or audit purposes.
Records.
- OktoRocket will keep detailed, accurate, and up-to-date records regarding any processing of Personal Information it carries out for Customer, including but not limited to, the access, control, and security of the Personal Information, approved subcontractors and affiliates, the processing purposes, and any other records required by the applicable Privacy and Data Protection Laws (the "Records").
- OktoRocket will ensure that the Records are sufficient to enable Customer to verify OktoRocket's compliance with its obligations under this DPA.
Audit.
Upon prior written request, OktoRocket agrees to reasonably cooperate and, within reasonable time, provide Customer with: (a) a summary of any audit reports or other information demonstrating its compliance with its obligations under Privacy and Data Protection Laws relating to this DPA, after redacting any confidential and commercially sensitive information; and (b) confirmation that an audit has not revealed any material vulnerability in the context of this DPA, or to the extent that any such vulnerability was detected, that such vulnerability has been remedied.
Change in Laws.
The parties will cooperate to amend this DPA to the extent reasonably necessary to address the requirements of applicable Privacy and Data Protection Laws.


