Last Updated: March 1st 2024
This Data Processing Agreement (“DPA”) forms part of the Terms of Service (“Terms”) between LeadIQ Inc. and the Customer for the purchase, access to, and/or licensing of products, services and/or platforms (collectively the “Services”) to reflect the parties’ agreement with regard to the Processing of Personal Data. In the event of a conflict between the Terms as it relates to the Processing of Personal Data and this DPA, this DPA shall prevail. This DPA supersedes any previous DPAs that may have been executed between the LeadIQ and Customer.
This DPA consists of the following:
This DPA shall be effective for the duration of the Services (or longer to the extent required by applicable law).
References in this DPA to the terms "Controller", “Processor”, "Data Subject", "Member State", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" shall have the meanings ascribed to them under Data Protection Laws.
“CCPA” means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act, Cal. Civ. Code §§ 1798.100 et. seq, and its implementing regulations, as may be amended from time to time.
“Customer” means the natural person or legal entity purchasing the Services.
“Customer Personal Data” means Personal Data provided by Customer to LeadIQ.
“Data Protection Laws” means all applicable laws and regulations, including laws and regulations of the European Union, the EEA and their member states, Switzerland, the United Kingdom, and any other applicable data protection law of any country to which the Parties are subject, including but not limited to, the GDPR, UK GDPR and the CCPA.
“Data Subject” means the identified or identifiable person or household to whom Personal Data relates.
"European Economic Area" or "EEA" means the Member States of the European Union together with Iceland, Norway, and Liechtenstein.
“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
“Leads Data” means electronic data and information that can be searched and returned through the Services and acquired by Customer for its internal business purpose.
“SCCs” means Standard Contractual Clauses adopted by the Commission Implementing Decision (EU) 2021/915 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (as updated from time to time if required by law).
"Subprocessor" means any third party, including without limitation a subcontractor, engaged by LeadIQ in connection with the Processing of Personal Data.
“Third Country” means a country without an applicable adequacy decision under the Data Protection Laws of the EEA, the United Kingdom and Switzerland.
“UK GDPR” means the Data Protection Act 2018, as well as the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419).
This Part 1 of this DPA applies to the processing of Customer Personal Data by LeadIQ in the course of providing the Services.
1.1 Customer’s Processing of Personal Data. For the purposes of Part 1 of this DPA, Customer is Controller, LeadIQ is Processor. Customer shall, in its use of the Services, be responsible for complying with all requirements that apply to it under applicable Data Protection Laws with respect to its Processing of Customer Personal Data and the instructions it issues to LeadIQ.
1.2 LeadIQ’s Processing of Personal Data. LeadIQ shall process Customer Personal Data only in accordance with Customer’s reasonable and lawful instructions unless otherwise required to do so by applicable law. Customer hereby authorizes and instructs LeadIQ and its Subprocessors to:
as reasonably necessary for the provision of the Services and to comply with LeadIQ’s rights and obligations under the Terms and DPA. Customer warrants and represents that it is and will at all relevant times remain duly and effectively authorized to give such instruction.
1.3 Description of Processing. Schedule 2 to this DPA sets out a description of the processing activities to be undertaken as part of the Terms and this DPA.
1.4 Confidentiality. LeadIQ shall maintain the confidentiality of the Customer Personal Data in accordance with the Terms and shall require persons authorized to process the Customer Personal Data (including its Subprocessors) to have committed to materially similar obligations of confidentiality.
LeadIQ shall in relation to the Customer Personal Data implement reasonably appropriate technical and organizational measures, based on industry standards, to ensure a level of security appropriate to any reasonably foreseeable security risks, including, as appropriate, the measures referred to in Article 32(1) of the GDPR. In assessing the appropriate level of security, LeadIQ shall take account in particular of the risks that are presented by Processing, in particular from a Personal Data Breach.
Customer agrees to the continued use of those Subprocessors already engaged by LeadIQ as of the date of this DPA and listed at Schedule 2, Annex III and further generally authorizes LeadIQ to appoint additional Subprocessors in connection with the provision of the Services, provided that:
Taking into account the nature of the Processing, LeadIQ shall assist Customer by implementing appropriate technical and organizational measures, insofar as this is reasonably possible, for the fulfillment of Customer’s obligations, as reasonably understood by Customer, to respond to requests to exercise Data Subject rights under the Data Protection Laws (“Data Subject Request”). To the extent that Customer is unable to independently address a Data Subject Request, then upon Customer’s written request LeadIQ shall provide reasonable assistance to Customer to respond to any Data Subject Requests or requests from data protection authorities relating to the Processing of Customer Personal Data under the DPA. Customer shall reimburse LeadIQ for the commercially reasonable costs arising from this assistance.
5.1 LeadIQ shall notify Customer without undue delay and within 48 hours of LeadIQ or any Subprocessor becoming aware of a Personal Data Breach affecting Customer Personal Data, providing Customer with sufficient information to allow Customer to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Laws.
5.2 LeadIQ shall make reasonable efforts to identify the cause of the Personal Data Breach and take those steps necessary and reasonable to remediate the cause of such Personal Data Breach to the extent the remediation is within LeadIQ’s reasonable control. The obligations herein shall not apply to incidents caused by Customer.
To the extent Customer does not otherwise have access to the relevant information, and to the extent the information is available to LeadIQ, LeadIQ shall provide reasonable assistance to Customer with any data protection impact assessments to fulfill Customer’s obligations under Data Protection Laws. LeadIQ shall provide reasonable assistance to Customer in the co-operation or prior consultation with Supervising Authorities or other competent data privacy authorities, as required under GDPR. In each case this is solely in relation to Customer’s use of Services and the Processing of Customer Personal Data by, and taking into account the nature of the Processing and information available to, LeadIQ.
Following termination of the Services, LeadIQ will delete or, upon Customer’s written request, return Customer Personal Data, except to the extent LeadIQ is required by applicable law to retain some or all of the Customer Personal Data. The terms of this DPA will continue to apply to that retained Customer Personal Data.
LeadIQ shall make available to Customer on request all information necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, by Customer or an auditor mandated by Customer in relation to the Processing of the Customer Personal Data by LeadIQ. Any costs or fees incurred by LeadIQ related to any audits requested by Customer shall be the sole responsibility of Customer. Customer shall provide LeadIQ with a minimum thirty (30) days notice if such audit is required. Such audit shall be at the maximum conducted once per calendar year, except where an additional audit is required by the Data Protection Law, or a Supervisory Authority.
9.1 LeadIQ may, in connection with the provision of the Services make international transfers of Personal Data from the European Union, the EEA and/or their member states (“EU Data”), Switzerland (“Swiss Data”) and the United Kingdom (“UK Data”) to its Subprocessors. When making such transfers, LeadIQ shall ensure appropriate protection is in place to safeguard the Personal Data transferred under or in connection with the Terms and this DPA.
9.2 Where the provision of Services involves the international transfer of EU Data, the Parties agree to the Standard Contractual Clauses as approved by the European Commission under Decision 2021/914 of 4 June 2021 (“EU SCCs”), which shall be automatically incorporated by reference and form an integral part of this DPA. The EU SCCs shall apply completed as follows:
9.3 Where the provision of Services involves the international transfer of UK Data, the Parties agree to the template Addendum B.1.0, International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022 (the “UK IDT Addendum”), shall amend the SCCs in respect of such transfers and Part 1 of the UK IDT Addendum shall be completed as follows:
9.4 Where the provision of Services involves the international transfer of Swiss Data subject to the Federal Act on Data Protection ("FADP"), the Parties agree to the EU SCC, which shall be automatically incorporated to this DPA in accordance with section 9.2 and with applicable references replaced with the Swiss equivalent.
This Part 2 of this DPA applies to the processing of Leads Data by Customer in the course of receiving the Services.
10.1 Customer acknowledges and agrees to its obligations as an independent Controller of Leads Data that it receives from LeadIQ.
11.1 Customer that is located in a Third Country may, in connection with using the Services, be a recipient of EU Data, Swiss Data or UK Data. Where international transfer of EU Data occurs, the Parties agree to enter into the EU SCC which shall be automatically incorporated by reference and form an integral part of this DPA. The EU SCCs shall apply completed as follows:
11.2 Where the provision of Services involves the international transfer of UK Data, the Parties agree to the UK IDT Addendum which shall amend the SCCs in respect of such transfers and Part 1 of the UK IDT Addendum shall be completed as follows: .
11.3 Where the provision of Services involves the international transfer of Swiss Data subject to the FADP, the Parties agree to the EU SCC, which shall be automatically incorporated to this DPA in accordance with section 11.1 and with applicable references replaced with the Swiss equivalent.
12.1 Changes in Data Protection Laws. If any variation is required to this DPA as a result of a change in Data Protection Law, then either Party may provide written notice to the other Party of that change in law. The Parties will discuss and negotiate in good faith any necessary variations to this DPA to address such changes with a view to agreeing and implementing those variations as soon as is reasonably practicable.
12.2 Severance. Should any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability, while preserving the parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.
12.3 Liability. For the avoidance of doubt and to the extent permitted by Data Protection Laws, each party’s liability and remedies under this DPA are subject to the aggregate liability limitations and damages exclusions set forth in the Terms.
A) Transfer controller to processor
Data exporter(s): Customer
Data importer(s): LeadIQ, Inc.
Data Subjects
Employees, agents, advisors or any other users authorized by data exporter to use the data importer’s Services. Employees or contact persons of potential customers (prospects), current customers and business partners of data exporter.
Categories of personal data
Sensitive data
N/A
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
Personal data of each data subject is transferred once. Personal data as a whole will be transferred on a continuous basis.
Nature of the processing
The nature of the processing includes storing, transferring, review, deletion of the personal data, and as otherwise required for delivery of the Services.
Purpose of the processing
To provide Data exporter with the Services or as otherwise agreed by the parties.
Duration
As necessary for data importer to provide and for the data exporter to receive the Services pursuant to the Terms.
The supervisory authority of the Data exporter.
B) Transfer controller to controller
A. LIST OF PARTIES
Data exporter(s): LeadIQ, Inc.
Data importer(s): Customer
Data Subjects
Employees or contact persons of potential customers (prospects), current customers and business partners of data importer.
Categories of personal data
First name, Last name, Job title, Employer/Company name, Contact information (email, phone, physical business address).
Sensitive data
N/A
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
Personal data of each data subject is transferred once. Personal data as a whole will be transferred on a continuous basis.
Nature of the processing
The nature of the processing includes storing, transferring, review, deletion of the personal data, and as otherwise required for delivery of the Services.
Purpose of the processing
To provide Data importer with the Services or as otherwise agreed by the parties.
Duration
As necessary for data exporter to provide and for the data importer to receive the Services pursuant to the Terms.
The supervisory authority of one of the Member States in which the data subjects whose personal data is transferred are located.
TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
Please make a request for LeadIQ’s Security Policies and Processes by contacting support@leadiq.com
LIST OF SUB-PROCESSORS
The controller has authorized the use of the sub-processors listed on our website at https://leadiq.com/legal/sub-processors
Signature
Signature
Name
Name
Title
Title
Date
Date