Preamble
This Data Processing Addendum (the "Addendum") forms part of the Terms of Service agreed between Black Swan Ventures Group LLC (the "Processor") and the client (the "Controller"), and applies whenever the Processor processes personal data upon the Controller's behalf.
The Addendum is published as a standing instrument, incorporated by reference into every Order Form, so that an engagement may be concluded without protracted negotiation of terms which are in any event prescribed by Article 28 GDPR.
1. Roles of the Parties
1.1 The Controller determines the purposes and means of processing. The Processor acts solely upon the Controller's documented instructions.
1.2 Where the Processor determines purposes independently, in respect of its own marketing, its own business records, and its own compiled business contact data, it acts as a controller in its own right under the Privacy Policy, and this Addendum has no application to such processing.
2. Particulars of Processing
| Matter | Particulars |
|---|---|
| Subject-matter | The supply of sales automation, artificial intelligence system design, outbound infrastructure, and related services |
| Duration | The term of the engagement, together with the period of deletion at clause 10 |
| Nature and purpose | Configuration; enrichment; segmentation; sequencing; transcription; analysis; storage; erasure |
| Categories of personal data | Business contact data (name, office held, employer, business electronic mail address, business telephone number, professional profile); records of engagement and interaction; call audio and transcripts; and such further data as the Controller places within the systems |
| Categories of data subject | The Controller's prospects, leads, customers, and personnel |
| Special categories | None. The Controller shall not instruct the Processor to process special categories of personal data absent prior written agreement |
3. Obligations of the Processor
The Processor shall:
3.1 process personal data solely upon the Controller's documented instructions, including as regards transfers to third countries, save where required otherwise by law to which the Processor is subject, in which case the Processor shall inform the Controller of that requirement before processing, unless that law prohibits such information on important grounds of public interest;
3.2 inform the Controller without delay where, in the Processor's opinion, an instruction infringes the GDPR or any other provision of data protection law;
3.3 ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
3.4 implement the technical and organisational measures required by Article 32 GDPR, as described in the Cybersecurity Disclosure and in Annex A hereto;
3.5 observe the conditions at clause 4 in respect of the engagement of sub-processors;
3.6 assist the Controller, by appropriate technical and organisational measures and insofar as is possible, in fulfilling its obligation to respond to requests for the exercise of rights under Chapter III GDPR;
3.7 assist the Controller in ensuring compliance with the obligations at Articles 32 to 36 GDPR, having regard to the nature of processing and to the information available to the Processor;
3.8 at the Controller's election, delete or return all personal data upon the conclusion of the engagement, as set out at clause 10; and
3.9 make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, as set out at clause 8.
4. Sub-processors
4.1 The Controller grants general written authorisation for the engagement of sub-processors. The current list is published in the Sub-processor Register.
4.2 The Processor shall impose upon every sub-processor data protection obligations no less protective than those contained in this Addendum, and shall remain fully liable to the Controller for the performance of each sub-processor's obligations.
4.3 The Processor shall give not less than thirty days' notice of the addition or substitution of any sub-processor processing the Controller's data.
4.4 The Controller may object upon reasonable data protection grounds within that period, whereupon the Processor shall use commercially reasonable endeavours to offer an alternative. No alternative being available, either party may terminate the affected service without penalty in respect of the unused portion.
5. Security
The Processor maintains the measures described at Annex A. It may update those measures provided that the level of protection is not thereby diminished.
6. Personal Data Breach
6.1 The Processor shall notify the Controller without undue delay, and in any event within forty-eight hours, upon becoming aware of a personal data breach affecting the Controller's data.
6.2 Such notification shall describe, insofar as known: the nature of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a point of contact.
6.3 The Processor shall furnish further information as it becomes available and shall cooperate with the Controller's obligations of notification to supervisory authorities and to data subjects.
6.4 The Processor shall not notify the Controller's supervisory authority nor the Controller's data subjects save upon the Controller's written instruction.
7. Requests by Data Subjects
Where the Processor receives a request from a data subject of the Controller, it shall not respond substantively but shall forward the request to the Controller within five business days and shall assist the Controller in responding, having regard to the nature of the processing.
8. Audit
8.1 Upon reasonable written notice, and not more than once in any period of twelve months (save following a personal data breach or where a supervisory authority so requires), the Controller may audit the Processor's compliance with this Addendum.
8.2 Audits shall be conducted during business hours, subject to obligations of confidence, and with minimal disruption to the Processor's operations.
8.3 The Processor may in the first instance discharge an audit request by furnishing written responses to a security questionnaire, its then-current Cybersecurity Disclosure, and evidence of the relevant controls.
8.4 The Controller bears its own costs of audit.
9. Transfers to Third Countries
9.1 The Processor may transfer personal data outside the European Economic Area, the United Kingdom, and Switzerland, including to the United States and to Taiwan, solely where an appropriate safeguard subsists.
9.2 Where required, the parties incorporate by reference the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), together with the International Data Transfer Addendum issued by the United Kingdom Information Commissioner, upon the following elections:
| Clause | Election |
|---|---|
| Clause 7 (docking) | Included |
| Clause 9 | Option 2, general written authorisation, thirty days' notice |
| Clause 11 | Optional redress body not included |
| Clause 17 | Governed by the law of Ireland, save where the Controller is established in Germany, in which case by German law |
| Clause 18(b) | Courts of Ireland, or of Germany as applicable |
| Annexes I, II, III | Populated respectively by clause 2, Annex A, and the published Sub-processor Register |
10. Return and Deletion
10.1 Within thirty days of the conclusion of the engagement, at the Controller's election, the Processor shall return the personal data and delete existing copies, or shall delete the same entirely, save where retention is required by law to which the Processor is subject.
10.2 Copies within backup media are deleted upon the Processor's ordinary rotation, and in any event within ninety days.
10.3 The Processor shall certify deletion in writing upon request.
10.4 Exception. The Processor may retain: business contact records independently sourced by it and held by it as a controller; and such data as are required for its own accounting, taxation, or defence of legal claims.
11. Liability
Liability under this Addendum is subject to the limitations at clause 14 of the Terms of Service, save where such limitation is prohibited by applicable data protection law.
12. Order of Precedence
In the event of conflict, the Standard Contractual Clauses prevail over this Addendum, and this Addendum prevails over the Terms of Service, in each case solely in respect of data protection matters.
Annex A, Technical and Organisational Measures
| Measure | Implementation |
|---|---|
| Access control | Role-based; least privilege; mandatory multi-factor authentication; credentials held within a password manager; rights reviewed [[CONFIRM: quarterly]] and revoked upon conclusion of engagement |
| Encryption | Transport Layer Security 1.2 or higher in transit; encryption at rest as afforded by hosting and storage providers; full-disk encryption upon every endpoint |
| Pseudonymisation | Applied wherever it does not defeat the purpose of processing |
| Confidentiality | Written obligations of confidence binding upon all personnel and contractors |
| Integrity | Change logging; version control; principle of least functionality |
| Availability | Managed hosting with provider-level redundancy; backup [[CONFIRM: frequency and retention]] |
| Resilience | Documented incident response procedure, per clause 7 of the Cybersecurity Disclosure |
| Testing and evaluation | Periodic review of access rights; patching of dependencies; review of configuration |
| Vendor management | Data processing agreements with every sub-processor; security posture assessed prior to onboarding |
| Artificial intelligence | Configuration against training upon customer inputs; prohibition upon submission of special categories to third-party models; review by a natural person prior to production deployment |
Execution
This Addendum is incorporated by reference into the Order Form and requires no separate execution. A countersigned copy shall be furnished upon request.
Black Swan Ventures Group LLC
30 N Gould Street, Ste N
Sheridan, Wyoming 82801, United States of America
mgmt@blackswanventuresgroup.com
+1 872-375-3144
Correspondence
Black Swan Ventures Group LLC30 N Gould Street, Ste N
Sheridan, Wyoming 82801
United States of America
mgmt@blackswanventuresgroup.com
+1 872-375-3144
Related notices