Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the Adapty Terms of Service (as defined below) between Customer and Adapty, which governs Customer’s use and provision of Adapty’s services.
The Customer and Adapty are hereinafter collectively referred to as the “Parties”, and individually as a “Party”. Details of the Parties are set out in Appendix 1.
In the event of a conflict or inconsistency with the terms of the Adapty Terms of Service, this DPA will control over the other terms in the Adapty Terms of Service to the extent of such conflict or inconsistency.
Capitalized terms not otherwise defined herein have the meaning set forth in the Adapty Terms of Service.
This DPA, including all Appendices, sets out the Parties’ data protection obligations with respect to Personal Data processed by Adapty on behalf of the Customer, as described in Appendix 1 to this DPA in accordance with Applicable Privacy Law.
1. Definitions
1.1. Adapty Terms of Service means the terms of service available at https://adapty.io/terms/ or other written or electronic agreement between Customer and Adapty.
1.2. Applicable privacy law means all laws, statutes, regulations, ordinances, codes, rules, guidelines, orders or any other legal obligation issued by any government authority that governs the collection, use, transfer and disclosure of Personal Data.
1.3. Data Controller means the natural person or organization who determines the purposes and means of the processing of Personal Data or is otherwise responsible for making decisions regarding the processing of Personal Data.
1.4. Data Processor means a natural or legal person or other body which processes Personal Data on behalf of the Controller.
1.5. Data Subject Request shall have the meaning set out in paragraph 3.2 of this DPA.
1.6. Data Subject means a directly or indirectly identified or identifiable individual to whom Personal Data relates.
1.7. GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
1.8. UK GDPR means the retained version of the EU General Data Protection Regulation ((EU) 2016/679) (EU GDPR) as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 and as amended by schedule 1 of the Data Protection, Privacy and Electronic Communications (Amendment etc.) (EU Exit) Regulations 2019 (SI 2019/419).
1.9. Personal data means any information that relates to an identified or identifiable natural person and is governed by Applicable Privacy Laws provided by the Customer for processing, including information relating to an identified or identifiable individual.
1.10. Personal Data Breach shall have the meaning a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
1.11. Processing, processes, and a process mean any activity that involves the use of Personal Data or as may be established by Applicable Privacy Law regarding processing, processes, or a process. This includes any operation or set of operations that is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction. Processing also includes the transfer of Personal Data to third parties.
1.12. Standard Contractual Clauses (SCC) means the standard contractual clauses approved by the European Commission (as updated, amended, replaced, or repealed by the European Commission over time). If the European Commission replaces the Standard Contractual Clauses with amended or new standard contractual clauses, then, to the extent that the relevant supervisory authority approves the use of such amended or new standard contractual clauses, references herein to “Standard Contractual Clauses” will be read as referring to such amended or new standard contractual clauses.
1.13. Sub-processor means a third party data processor engaged by Adapty who has been given or may potentially have access to, or processes, Personal Data.
1.14. Sub-processor Change Notice shall have the meaning set out in clause 4.1 of this DPA.
2. Processing of personal data
2.1. Roles of the Parties. The Parties acknowledge and agree that, with respect to the processing of personal data, the Customer is the controller and Adapty is the processor.
2.2. Details of data processing. The subject matter, duration, nature and purpose(s) of personal data processing, as well as the type of personal data and categories of data subjects are specified in Schedule 1.
2.3. Scope of Processing. Adapty will refrain from processing personal data beyond the reasonable and customary indications established by the Customer, as specified in Adapty’s Terms of Service or this DPA, unless such processing is required by applicable law to which Adapty is subject.
2.4. Customer Instructions. The Customer’s instructions for processing personal data must comply with applicable privacy laws. The Customer is solely responsible for the accuracy, quality, and lawfulness of personal data, as well as for the methods by which the Customer obtains personal data. Without limitation, the Customer will be solely responsible for ensuring that there is an appropriate legal basis and the right to process personal data in accordance with the terms of the Adapty Terms of Service and this DPA. The Customer specifically acknowledges and agrees that its use of the Services will not infringe the rights of any data subject.
2.5. Lawful Basis for Processing. The Customer acknowledges and agrees that Adapty’s Services are dependent on and based on a demonstrated lawful basis, which the Customer must obtain and which Adapty relies on. The Customer represents that such a lawful basis exists.
2.6. Children’s Privacy. When processing children’s personal data (as described in applicable privacy laws), the Customer is obligated to comply with additional requirements established by platform policies, regulations, and applicable privacy laws aimed at protecting children. Some of these laws are specifically targeted at children (such as COPPA), while others are broader but include special protections for children (such as the GDPR and similar regional laws).
3. Data Subject Requests
3.1. Responses to Data Subject Requests. The Customer is solely responsible for complying with any legal obligations regarding requests to exercise data subject rights under applicable privacy laws. The parties agree and acknowledge that Adapty is unable to respond to data subject requests.
3.2. Data Subject Requests.
Customer responsibility and handling of Data Subject Requests. Customer shall remain solely responsible for compliance with any statutory obligations concerning Data Subject Requests under Applicable Privacy Law. Customer authorizes Adapty, acting solely on Customer’s documented instructions and as Customer’s Processor, to automatically process and give effect to unsubscribe requests and objections to direct marketing received directly from Recipients through the unsubscribe mechanisms made available in Messages, including by adding the relevant Recipient to Customer’s suppression list.
Except as expressly set out in this clause, Adapty shall not substantively respond to Data Subject Requests on Customer’s behalf and shall, to the extent legally permitted, direct the Data Subject to Customer and/or notify Customer in accordance with this clause.
3.3. Subject Request. If the Customer requests Adapty’s assistance in responding to a request, Adapty will, to the extent feasible, use commercially reasonable efforts to assist the Customer in responding to such request, to the extent Adapty has a legal right to do so and responding to such request is required by applicable privacy laws.
3.4. Costs. To the extent permitted by law, the Customer is responsible for any costs incurred as a result of Adapty providing such assistance, including any fees associated with the provision of additional functionality. In such cases, Adapty will notify the Customer of these costs in advance.
4. Sub-processing
4.1. Sub-processor Appointment. Customer authorizes Adapty to appoint sub-processors in accordance with this section and any limitations in the DPA. Customer acknowledges and agrees that Adapty may engage sub-processors without Customer’s prior consent. A condition for allowing a third-party sub-processor to process personal data is that Adapty enters into a written agreement with each sub-processor containing data protection commitments that ensure at least the same level of protection for personal data as in this DPA. Adapty will notify Customer in writing of any proposed changes regarding the addition or replacement of sub-processors prior to such sub-processor changes (hereinafter referred to as the “Sub-processor Change Notice”). Customer may object to such sub-processor changes in accordance with Section 4.2 of this DPA.
4.2. Current List of Sub-processors. The current list of sub-processors engaged by Adapty for processing is set out in Schedule 3 of this DPA. Adapty will update the list of sub-processors in this DPA within thirty (30) days of any changes involving the addition or replacement of a sub-processor.
4.3. Liability. With respect to each sub-processor, Adapty shall: (i) take reasonable steps to ensure that the sub-processor is obliged to ensure the level of protection of personal data required by the DPA, and (ii) remain fully responsible to the Customer for the sub-processor’s compliance with its data protection obligations in the event that the sub-processor fails to comply with such obligations.
4.4. Right to Object to Sub-processors. Customer may reasonably object to any proposed change involving the addition or replacement of a sub-processor (for example, if providing personal data to a sub-processor may violate applicable data protection laws or weaken the protection of such personal data) by notifying Adapty promptly in writing within thirty (30) days of receiving notice of the change of sub-processor. Such notice from Customer must explain the reasonable grounds for the objection.
If Customer notifies Adapty of such an objection, the parties will negotiate the matter in good faith with the aim of reaching a commercially reasonable solution. If such objections cannot be resolved within fifteen (15) days because the processing cannot properly continue without the involvement of such sub-processor, Adapty has the right to refuse further processing in accordance with this DPA and terminate Adapty’s Terms of Service without liability for such termination.
5. Cross-border transfer of personal data
5.1. Transfers from the EU. To the extent the processing of Personal Data is protected by the GDPR, the Parties hereby agree that such transfers are subject to the SCC, which is incorporated into this DPA by reference and constitutes an integral part of this DPA. The SCC options and appendices are deemed to be completed based on Schedule 4 to this DPA.
5.2. Transfers from Switzerland. To the extent that the processing of Personal Data is protected by the Swiss Federal Act of 19 June 1992 on Data Protection (“FADP”), the Parties hereby agree that such transfers shall be subject to SCCs with the necessary adaptations so that the SCCs comply with Swiss law and are thus suitable to ensure an adequate level of protection for the transfer of data from Switzerland to a third country in accordance with Article 6, paragraph 2, letter a of the FADP. A list of adaptations is provided in point 4.3. for transfers of personal data to a country with an inadequate level of data protection based on the standard contractual clauses and model contracts of 27 August 2021 of the Federal Data Protection and Information Commissioner (available at https://www.edoeb.admin.ch/edoeb/en/home/data-protection/handel-und-wirtschaft/transborder-data-flows.html). Example 2 of Case 2 shall apply.
5.3. Transfers from the UK. To the extent that the processing of Personal Data is protected by the UK GDPR, the Parties hereby agree that such transfer is subject to the International Addendum to the European Commission’s standard contractual clauses for international data transfers, available at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf, as adopted, amended or updated by the UK Information Commissioner’s Office, Parliament or the Secretary of State.
6. Technical and organizational measures
6.1. Technical and Organizational Measures Adapty shall implement and maintain appropriate technical and organizational measures to ensure an appropriate level of security, confidentiality, and integrity of Personal Data, including, where relevant and applicable, the measures provided for in Article 32 of the GDPR, as set out in Schedule 2 to this DPA, to protect Personal Data from:
- accidental or unlawful destruction, and
- loss, alteration, unauthorized disclosure of, or access to, Personal Data (each, a “Personal Data Breach”).
6.2. Compliance Monitoring. Adapty regularly monitors compliance with the measures set out in Schedule 2 of this DPA.
6.3. Assistance in Ensuring Compliance. Given the nature of the Processing and the Personal Data available to Adapty, Adapty assists the Customer in ensuring compliance with obligations under Articles 32-36 of the GDPR.
7. Personal Data Breach
7.1. Personal Data Breach Notification. If Adapty becomes aware of a personal data breach, Adapty shall, to the extent permitted by law, notify the Customer without undue delay by email after Adapty or any Sub-processor becomes aware of the personal data breach involving the Customer’s personal data and provide reasonable information (to the extent reasonably within Adapty’s knowledge and/or control).
7.2. Cooperation. Adapty shall provide cooperation, taking into account the nature of the processing and the information available to Adapty, to assist the Customer in complying with any obligations to inform data subjects or data protection authorities of a personal data breach in accordance with Applicable Privacy Law. Adapty shall also take any steps and actions reasonably necessary to eliminate or mitigate the consequences of a personal data breach and shall keep the Customer informed of all significant developments related to the personal data breach.
8. Audit
8.1. Customer’s Right to Conduct Audits. Adapty will provide the Customer with all information reasonably necessary to demonstrate compliance with the obligations set forth in this DPA and will facilitate audits, including inspections, conducted by the Customer or another auditor authorized by the Customer regarding compliance with the obligations under this DPA.
8.2. Adapty’s Cooperation in Conducting an Audit. Adapty shall provide the Customer with all information, systems, and personnel reasonably necessary for the Customer or its third-party auditors to conduct such an audit, provided that the Customer:
8.2.1. notifies forty-five (45) days prior to the audit; and
8.2.2. conducts the audit during normal business hours; and
8.2.3. takes all reasonable measures to prevent unnecessary disruptions to Adapty’s operations. Such audits must be strictly limited to information related to the processing of personal data.
8.3. Audit Parameters. The parties mutually agree on the scope, timing, and duration of the audit or inspection.
8.4. Confidentiality. All audits under this DPA are subject to confidentiality obligations. The Customer must share the full audit report with Adapty and must not share it with third parties other than its accountants and legal advisors, who are required to maintain confidentiality. The Customer must not use such audit report for any purpose other than assessing Adapty’s compliance with this DPA.
8.5. Costs. The Customer shall bear the costs of such audit unless the Parties agree otherwise.
8.6. Frequency of Audits. The Customer may not exercise its audit rights more than once in any twelve (12) calendar months, except in the following cases:
8.6.1. if and when required by a competent data protection authority; or
8.6.2. if it is necessary in connection with a personal data security breach suffered by Adapty and/or Sub-processors.
9. Confidentiality
9.1. Adapty will take all reasonable steps to ensure the reliability of any personnel authorised to process personal data and ensure that such personnel are subject to appropriate confidentiality obligations and will at all times act in accordance with applicable data protection legislation.
10. Deletion or Return of Personal Information
10.1 Upon (i) termination of this DPA, or (ii) Customer’s written request, or (iii) Adapty no longer needs to process Personal Data to perform its obligations under the Adapty Terms of Service and this DPA, or (iv) Adapty opts out of processing in accordance with Section 4.4 of this DPA, Adapty will, at Customer’s option, delete, destroy, or return all Personal Data to Customer and destroy or return any existing copies, unless Adapty is required by Applicable Privacy Law to retain a copy of the Personal Data for a specified retention period. Upon expiration of such retention period, Adapty will promptly delete or destroy all remaining Personal Data.
For Adapty Mail Recipient profiles, deletion is performed by irreversibly de-identifying the Personal Data in the profile and marking the profile as deleted. The resulting record cannot reasonably be used by Adapty, alone or in combination with other information available to Adapty, to identify or re-identify the relevant Recipient.
Backups are retained and overwritten in accordance with Adapty’s standard backup-rotation cycle.
10.2. In the event that Personal Data has been processed by any Contractors, Adapty will ensure that in such cases such Contractors also return, delete or destroy all Personal Data they hold in accordance with the terms set out in this section.
11. California Consumer Privacy Rights
11.1. “Personal Information,” “Consumer,” and other capitalized terms in this Section 11 shall have the meanings set forth in the California Consumer Privacy Act of 2018, Cal. Civ. Code §§ 1798.100 et. Seq., as amended from time to time (“CCPA”).
11.2. It is hereby agreed that any exchange of personal data between the Parties is carried out solely for the purpose of fulfilling a business purpose, and Adapty does not receive or process any personal data as a reward for the Services.
11.3. Therefore, the Customer is solely responsible for compliance with the CCPA with respect to its use of the Services. The Customer is solely responsible and liable for ensuring that the exchange or transfer of personal data of Data Subjects during the provision of the Services does not constitute a Sale of Personal Data.
11.4. Adapty will not store, use or transfer personal data for commercial purposes other than to provide the Services specified in the Adapty Terms of Service.
12. Term
12.1. This DPA is effective as of the date specified in the Adapty Terms of Service. This DPA will remain in effect for as long as the Adapty Terms of Service remain in effect.
13. Severability
13.1. If any provision of this DPA is or is found to be invalid, ineffective or unenforceable in whole or in part, the validity, effectiveness and enforceability of the other provisions of this DPA will remain unaffected.
13.2. Any such invalid, ineffective or unenforceable provision shall, to the extent permitted by law, be deemed to be replaced by such valid, effective and enforceable provision that most closely reflects the economic intent and purpose of the invalid, ineffective or unenforceable provision as to its subject matter, time, place and scope of application.
13.3. The said rule will apply mutatis mutandis to fill any gaps that may be found in this DPA.
14. Complete Agreement
14.1. The Parties expressly declare that this DPA (including the schedules referred to herein) and the documents referred to herein constitute the entire agreement between the Parties and supersede any previous drafts, agreements, commitments, understandings, conditions and arrangements, regardless of any conflicting order of priority, of any kind between the Parties, whether in writing or not, in relation to the subject matter of this DPA.
15. Applicable law and jurisdiction
15.1. The DPA is governed by law in accordance with the terms set out in the Adapty Terms of Service.
15.2. The Parties hereby submit to the choice of jurisdiction provided in the DPA with respect to any disputes or claims howsoever arising under this DPA, including disputes regarding its existence, validity or termination, and the consequences of its invalidity.
16. Miscellaneous
16.1. In the event of a conflict or uncertainty between:
16.1.1 any provision of the DPA and any provision of the Adapty Terms of Service, the provisions of the DPA shall prevail;
16.1.2. any provision of this DPA and any signed SCC, the provisions of the signed SCC shall prevail.
Schedule 1. Data Processing Parameters
Schedule 2. Technical and Organisational Measures, Including Technical and Organisational Measures to Ensure Data Security
• Regularly updating operating systems, hardware and third-party software to address security vulnerabilities.
• Using firewalls and intrusion prevention systems (IPS) to restrict access to and protect the servers.
• Ensuring secure remote access communications using multi-factor authentication.
• Backing up Customer data on a daily rotating schedule.
Schedule 3. List of Sub-processors
Schedule 4. SCC Conditions
3. Appendix IA to the SCC shall be deemed to be completed as follows:
- The data exporter is the Customer, and the data of the data exporter are the same as those specified in Appendix 1 (Part A) of the DPA.
The activities related to the transferred data under the SCC: the transfer of Personal Data by the data exporter to the data importer in order to enable the data importer to process such Personal Data on behalf of the data exporter and provide the Services in accordance with the Adapty Terms of Service. - The data importer is Adapty, and the Adapty data are the same as those specified in Appendix 1 (Part A) of the DPA.
The activities related to the data transferred under the SCC are: receiving Personal Data from the Data Exporter for the purpose of providing the Services in accordance with the Adapty Terms of Service.
4. Appendix IB of the SCC will be the same as Schedule 1 of the DPA, and in addition the following information is included to complete Appendix IB: the transmission frequency is continuous.
5. Appendix IC is completed as follows: Republic of Ireland Supervisory Authority.
6. Appendix II of the SCC will be the same as Appendix 2 of the DPA.
7. Appendix III of the SCC will be the same as Appendix 3 of the DPA.