This Data Processing Addendum ("DPA") is entered into between Socero Inc. ("attention labs", "Processor") and the customer entity identified in the applicable order form or enterprise agreement ("Customer", "Controller"). It forms part of and is incorporated into the attention labs Terms of Service or other written agreement between the parties governing the SAA Cloud API and related services (the "Agreement"). This DPA governs Socero Inc.'s processing of personal data on behalf of the Controller in connection with the services. Where the Controller is subject to the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the GDPR as it forms part of the law of the United Kingdom by virtue of the European Union (Withdrawal) Act 2018 ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), or equivalent national implementing legislation, the terms of this DPA apply and supplement the Agreement. In the event of any conflict between this DPA and the Agreement on matters of data protection, this DPA prevails.
Definitions
Capitalized terms not otherwise defined in this DPA have the meanings given to them in the GDPR. For the purposes of this DPA: "personal data", "processing", "data subject", "controller", "processor", "personal data breach", and "special categories of personal data" have the meanings given in the GDPR. "Sub-processor" means any processor engaged by attention labs to process personal data on behalf of the Controller. "Supervisory authority" means an independent public authority established under applicable data protection law. "Restricted transfer" means a transfer of personal data to a country or recipient not recognized as providing an adequate level of protection under applicable data protection law. "Standard Contractual Clauses" or "SCCs" means, as applicable, the clauses adopted by the European Commission for the transfer of personal data to third countries and the corresponding mechanisms adopted under the UK GDPR and the FADP.
Scope and roles of the parties
The Controller determines the purposes and means of processing personal data submitted to the SAA Cloud API, including account data, request metadata, and any audio or video content associated with end users of the Controller's products. attention labs acts as a processor and processes such personal data solely on documented instructions from the Controller, as set out in this DPA, the Agreement, and Annex I. attention labs does not process personal data for its own commercial purposes beyond what is necessary to operate, secure, and support the services. The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex I.
Controller obligations
The Controller is responsible for ensuring it has a lawful basis for processing, including obtaining any necessary consents from data subjects whose personal data is submitted to the API. The Controller must ensure that its instructions to attention labs comply with applicable data protection law, provide end users with appropriate transparency notices, and respond to data subject rights requests that it receives directly. The Controller warrants that it is entitled to transfer the relevant personal data to attention labs so that attention labs may lawfully process it in accordance with this DPA. The Controller will maintain records of its processing activities as required under GDPR Article 30.
Processor obligations
attention labs will process personal data only on documented instructions from the Controller, including with regard to restricted transfers, unless required to process by law to which attention labs is subject, in which case attention labs will inform the Controller of that legal requirement before processing, unless the law prohibits such notice on important grounds of public interest. attention labs will:
- ensure that personnel authorized to process personal data are bound by appropriate confidentiality obligations;
- implement and maintain the technical and organizational measures described in Annex II;
- assist the Controller, by appropriate technical and organizational measures and insofar as possible, in fulfilling the Controller's obligation to respond to data subject rights requests;
- assist the Controller in ensuring compliance with its obligations regarding security of processing, personal data breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of the processing and the information available to attention labs;
- make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable advance notice, confidentiality obligations, and limits that protect the security and continuity of the services and the data of other customers.
Confidentiality
attention labs treats all personal data processed on behalf of the Controller as confidential. attention labs ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access to personal data is limited to personnel who require access to perform the Agreement.
Security of processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to the rights and freedoms of natural persons, attention labs implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with GDPR Article 32. These measures are described in Annex II and on our Security and Trust Center. attention labs may update these measures from time to time, provided that the updates do not materially reduce the overall level of security of the services.
Sub-processors
The Controller grants attention labs general written authorization to engage sub-processors to process personal data in connection with the services. A current list of sub-processors is maintained in Annex III and at Sub-processors. attention labs will notify the Controller of any intended addition or replacement of a sub-processor with reasonable advance notice, providing the Controller an opportunity to object on reasonable data protection grounds. Where attention labs engages a sub-processor, it does so under a written contract that imposes data protection obligations no less protective than those set out in this DPA. attention labs remains fully liable to the Controller for the performance of each sub-processor's obligations.
Data subject rights
attention labs will, to the extent legally permitted, promptly notify the Controller if it receives a request from a data subject seeking to exercise rights under applicable data protection law in respect of personal data processed on behalf of the Controller. attention labs will not respond to such a request itself, except on the documented instructions of the Controller or as required by law, and will assist the Controller, by appropriate technical and organizational measures and insofar as possible, in responding to such requests.
Personal data breach
attention labs will notify the Controller without undue delay, and in any event within 72 hours where feasible, after becoming aware of a personal data breach affecting the Controller's personal data. The notification will describe, to the extent then known and as required under GDPR Article 33(3), the nature of the breach, the likely consequences, and the measures taken or proposed to address it. attention labs will cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.
Data protection impact assessment and prior consultation
attention labs will provide reasonable assistance to the Controller with any data protection impact assessments and prior consultations with supervisory authorities that the Controller reasonably considers to be required under GDPR Articles 35 or 36, in each case solely in relation to the processing of personal data by attention labs on behalf of the Controller and taking into account the nature of the processing and the information available to attention labs.
International data transfers and Standard Contractual Clauses
Personal data may be transferred to and processed in Canada, the United States, and other countries in which attention labs or its sub-processors operate, in connection with the services. Where the processing of personal data by attention labs involves a restricted transfer from the European Economic Area, the parties agree that the Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914 ("EU SCCs") are incorporated into this DPA by reference and apply to that transfer. For these purposes:
- Module Two (controller to processor) applies where the Controller is a controller and attention labs is a processor;
- the Controller is the data exporter and attention labs is the data importer;
- the optional docking clause in Clause 7 applies;
- in Clause 9, Option 2 (general written authorization) applies, with the notice period set out in the Sub-processors section above;
- in Clause 11, the optional independent dispute resolution language does not apply;
- in Clause 17, the EU SCCs are governed by the law of Ireland;
- in Clause 18, disputes are resolved before the courts of Ireland;
- Annex I and Annex II of the EU SCCs are populated by Annex I and Annex II of this DPA, and Annex III of the EU SCCs is populated by Annex III of this DPA.
In the event of any conflict between this DPA and the EU SCCs in respect of a restricted transfer, the EU SCCs prevail.
United Kingdom International Data Transfer Addendum
Where the processing of personal data involves a restricted transfer subject to the UK GDPR, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the United Kingdom Information Commissioner under section 119A of the Data Protection Act 2018 (the "UK Addendum") is incorporated into this DPA by reference and applies to that transfer. The UK Addendum is completed as follows: in Table 1, the parties and their details are as set out in this DPA and Annex I; in Table 2, the version of the EU SCCs to which the UK Addendum is appended is the version incorporated above; in Table 3, the appendix information is set out in Annex I, Annex II, and Annex III of this DPA; and in Table 4, neither party may end the UK Addendum as set out in its Section 19. The Part 2 mandatory clauses of the UK Addendum apply by reference.
Switzerland
Where the processing of personal data is subject to the FADP, the EU SCCs apply with the following adjustments: references to the GDPR are to be understood as references to the FADP insofar as the processing is subject to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; the term "member state" must not be interpreted to exclude data subjects in Switzerland from suing for their rights in their place of habitual residence; and references to personal data protected under the EU SCCs also extend, where applicable, to data of legal entities until the entry into force of revisions to the FADP that remove such protection.
Return or deletion of data
Upon termination or expiry of the Agreement, or on written request from the Controller, attention labs will, at the Controller's election, return or securely delete the personal data processed on the Controller's behalf, and delete existing copies, unless applicable law requires continued storage. attention labs does not retain raw audio or video beyond the duration necessary to process each API request unless a specific data retention feature is expressly agreed in writing.
Liability, governing law, and order of precedence
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA governs to the extent of any conflict with the Agreement on matters of data protection. For any restricted transfer, the applicable Standard Contractual Clauses and, where relevant, the UK Addendum govern to the extent of any conflict with this DPA or the Agreement. Except as expressly modified by this DPA, the Agreement remains in full force and effect and governs the relationship between the parties.
Annex I: Details of processing
| Item | Description |
|---|---|
| Data exporter | The Controller identified in the Agreement, acting as controller. |
| Data importer | Socero Inc., acting as processor in connection with the SAA Cloud API. |
| Categories of data subjects | The Controller's end users and authorized users of the Controller's products and accounts. |
| Categories of personal data | Account and contact data, API request metadata, session identifiers, technical diagnostics, and audio or video content submitted by the Controller for processing. |
| Special categories of personal data | None are required by the services. The Controller is responsible for any special category data it chooses to submit and for any additional safeguards required. |
| Frequency of transfer | Continuous, for the duration of the Agreement. |
| Nature and purpose of processing | Providing, operating, securing, and supporting the SAA Cloud API and related services as instructed by the Controller. |
| Duration of processing | For the term of the Agreement and any period thereafter as required to fulfill return or deletion obligations or as required by law. |
| Competent supervisory authority | Determined in accordance with the data exporter's place of establishment or as otherwise required under applicable data protection law. |
Annex II: Technical and organizational security measures
attention labs maintains technical and organizational measures appropriate to the risk, including the following:
- Encryption of personal data in transit and at rest.
- Access control and least privilege, with role based access and authentication for systems that process personal data.
- Network security, including segmentation and protection of service boundaries.
- Logging and monitoring of access to and processing of personal data.
- Personnel confidentiality obligations and security awareness training.
- Vulnerability management, including regular review and timely remediation.
- Incident response procedures for identifying, investigating, and responding to security events.
- Business continuity and resilience measures appropriate to the services.
- Vendor and sub-processor management, including data protection obligations flowed down to sub-processors.
Annex III: List of sub-processors
attention labs engages the following categories of sub-processors to deliver the services, as described in the Sub-processors section above.
| Sub-processor category | Purpose | Location |
|---|---|---|
| Cloud infrastructure and compute | Hosting and running the SAA Cloud API. | United States |
| Database and object storage | Storing account and usage records. | United States |
| Authentication and identity | Managing account access and credentials. | United States |
| Payment processing | Processing billing and payments. | United States |
| Email and communications | Sending account and service communications. | United States |
For an executed copy of this DPA, including the Standard Contractual Clauses, contact [email protected].