Data Processing Addendum
Contents
- 1. Scope
- 2. Roles of the Parties
- 3. Client Instructions and Responsibilities
- 4. RetterTEK Processing Restrictions
- 5. Confidentiality
- 6. Security
- 7. Security Incident Notification
- 8. Subprocessors
- 9. Data Subject and Consumer Rights Requests
- 10. Data Return, Export, and Deletion
- 11. Client Retention Responsibilities
- 12. Audits and Compliance Information
- 13. U.S. State Privacy Laws
- 14. GDPR and UK GDPR; International Transfers
- 15. Sensitive and Prohibited Data
- 16. De-Identified and Aggregated Data
- 17. Order of Precedence; Term
- 18. Contact
Purpose. This document is incorporated into the applicable JAMr FIT Order Form and Master SaaS Terms when identified there or otherwise made applicable to Client.
1. Scope
This Data Processing Addendum (“DPA”) forms part of the Agreement between Client and Premier TEK LLC d/b/a RetterTEK and governs RetterTEK’s processing of Personal Data on Client’s behalf in connection with JAMr FIT. This DPA applies only to the extent Privacy Laws require contractual processor, service-provider, contractor, or equivalent obligations between the parties. Capitalized terms not defined in this DPA have the meanings assigned in the Master SaaS Terms or applicable Privacy Laws. “Personal Data” includes personal information, personal data, personally identifiable information, or equivalent information protected by applicable Privacy Laws. “Privacy Laws” means applicable U.S. state privacy laws and, where applicable to the Services and Client Data, GDPR, UK GDPR, and other data-protection laws.
2. Roles of the Parties
For Personal Data processed by RetterTEK solely to provide the Services on Client’s behalf, Client is the business, controller, or equivalent responsible party and RetterTEK is Client’s service provider, contractor, processor, or equivalent downstream provider, as those terms are defined by applicable Privacy Laws. Client determines the purposes and essential means of processing Client Data. Nothing in this DPA prevents RetterTEK from processing data for its own legitimate purposes to the extent permitted by the Agreement and applicable law, including account administration, security, fraud prevention, legal compliance, service analytics using de-identified or aggregated data, and management of RetterTEK’s business relationship with Client.
3. Client Instructions and Responsibilities
Client instructs RetterTEK to process Personal Data as reasonably necessary to provide, host, secure, support, maintain, and improve the Services; to perform documented instructions reflected in Client’s configuration and use of JAMr FIT; and as otherwise described in the Agreement. Client represents that it has provided required notices and has all rights, permissions, consents, and other lawful authority necessary for RetterTEK and its subprocessors to process Client Data under the Agreement. Client is responsible for the lawfulness, accuracy, quality, and scope of Client Data and for determining whether particular data may lawfully be collected, imported, retained, disclosed, or used.
4. RetterTEK Processing Restrictions
To the extent required by applicable Privacy Laws, RetterTEK shall process Personal Data only for the limited and specified business purposes described in the Agreement and Client’s documented instructions, except where processing is required by applicable law. Except as permitted by applicable Privacy Laws and the Agreement, RetterTEK shall not sell Client Personal Data or share Client Personal Data for cross-context behavioral advertising; retain, use, or disclose Client Personal Data outside the direct business relationship with Client; or combine Client Personal Data with personal data received from another person or collected from RetterTEK’s own interaction with an individual where applicable Privacy Laws prohibit such combination.
5. Confidentiality
RetterTEK shall ensure that personnel authorized to process Client Personal Data are subject to appropriate confidentiality obligations and access Personal Data only to the extent reasonably necessary for their job responsibilities and the Services.
6. Security
RetterTEK shall maintain commercially reasonable administrative, technical, and organizational safeguards designed to protect Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. Security measures may evolve over time to reflect changes in technology, risk, and the Services, provided RetterTEK does not materially reduce the overall protection of Client Personal Data during the applicable subscription term. Client remains responsible for user access, permissions, endpoint security, credential security, the security of Client-controlled systems and integrations, and secure configuration of the Services within Client’s control.
7. Security Incident Notification
If RetterTEK becomes aware of a confirmed breach of security resulting in unauthorized acquisition of, access to, or disclosure of Client Personal Data processed by RetterTEK (“Security Incident”), RetterTEK shall notify Client without undue delay as required by applicable law and provide information reasonably available to RetterTEK that Client may need to evaluate applicable notification obligations. RetterTEK’s notice of a Security Incident is not an admission of fault or liability. Client is responsible for determining whether notices to individuals, regulators, or other parties are legally required, except to the extent applicable law independently imposes a direct notification obligation on RetterTEK.
8. Subprocessors
Client authorizes RetterTEK to engage subprocessors to process Client Personal Data in connection with the Services. RetterTEK shall maintain a current public subprocessor list and shall impose written data-protection obligations on subprocessors that are appropriate to the processing they perform and no less protective in material respects than the obligations applicable to RetterTEK under this DPA, to the extent required by applicable Privacy Laws. RetterTEK may add, replace, or remove subprocessors as the Services evolve. Where applicable Privacy Laws or the Agreement require notice of a new subprocessor, RetterTEK may provide such notice by posting an updated subprocessor list, in-product notice, email, or other reasonable method.
9. Data Subject and Consumer Rights Requests
Client is responsible for receiving, evaluating, authenticating, and responding to requests from members, prospects, employees, or other individuals to exercise privacy rights, including rights of access, correction, deletion, portability, restriction, objection, or opt-out, as applicable. Taking into account the nature of processing, RetterTEK shall provide commercially reasonable assistance through available product functionality or support processes to enable Client to respond to verified requests where required by applicable Privacy Laws. RetterTEK may direct a person who submits a request directly to RetterTEK concerning Client-controlled data back to Client unless applicable law requires RetterTEK to respond directly.
10. Data Return, Export, and Deletion
During the subscription term, Client may export Client Data using generally available functionality. Following termination or expiration, RetterTEK may make Client Data available for a limited export period stated in the Master SaaS Terms or applicable policy, after which RetterTEK may delete or de-identify Client Data in accordance with its retention schedule. RetterTEK may retain backup copies until overwritten in ordinary backup cycles and may retain records where reasonably necessary to comply with law, establish or defend legal claims, prevent fraud, maintain security, preserve billing or audit records, or fulfill other legitimate obligations permitted by applicable law. Any retained Personal Data remains subject to applicable confidentiality and security obligations.
11. Client Retention Responsibilities
Client is responsible for establishing and implementing retention periods applicable to Client’s business and for exporting records Client must retain beyond JAMr FIT’s standard retention period. RetterTEK is not Client’s official record keeper unless expressly agreed in a separate written agreement.
12. Audits and Compliance Information
Upon reasonable written request and subject to confidentiality and security restrictions, RetterTEK shall make available information reasonably necessary to demonstrate compliance with this DPA, which may include relevant policies, summaries, questionnaires, certifications, or third-party reports then available to RetterTEK. If applicable Privacy Laws require an audit beyond available documentation, the parties shall cooperate in good faith to establish a reasonable audit process that protects the confidentiality and security of RetterTEK, its other customers, and its systems. Audits shall be no more frequent than reasonably required by applicable law, shall occur during normal business hours, shall not unreasonably interfere with operations, and may be subject to reasonable costs unless the audit identifies a material breach of this DPA by RetterTEK.
13. U.S. State Privacy Laws
To the extent a U.S. state privacy law applies and requires processor, service-provider, or contractor terms, RetterTEK shall process Client Personal Data for the limited and specified business purposes described in the Agreement; provide the level of privacy protection required of a processor, service provider, or contractor under applicable law; cooperate with Client in responding to consumer requests as required; and notify Client if RetterTEK determines it can no longer meet material obligations imposed on RetterTEK by applicable Privacy Laws. Client may take reasonable and appropriate steps, as permitted by applicable law and the Agreement, to help ensure that RetterTEK uses Client Personal Data consistently with Client’s obligations under applicable Privacy Laws and to stop and remediate unauthorized processing.
14. GDPR and UK GDPR; International Transfers
If Client Personal Data subject to GDPR or UK GDPR is processed by RetterTEK, the parties acknowledge that Client acts as controller and RetterTEK acts as processor unless the parties agree otherwise for a specific processing activity. RetterTEK shall process such Personal Data on documented instructions, ensure confidentiality, implement appropriate security measures, assist with data-subject rights and legally required assessments as reasonably applicable to the Services, delete or return Personal Data at the end of processing subject to lawful retention, and make compliance information available as required by Article 28 or equivalent requirements. Where a restricted international transfer requires an approved transfer mechanism, the parties agree to execute or incorporate the then-applicable Standard Contractual Clauses, UK International Data Transfer Addendum, or other lawful transfer mechanism. Any required transfer annexes may be completed by reference to the Agreement, this DPA, RetterTEK’s security documentation, and subprocessor list.
15. Sensitive and Prohibited Data
The Services are not offered as a HIPAA Business Associate service unless separately agreed in writing. Client shall not submit PHI requiring a HIPAA Business Associate Agreement, full payment-card data, CVV data, bank-account credentials, Social Security numbers, driver’s-license numbers, passport numbers, government identification documents, or other data expressly prohibited by the Master SaaS Terms or Acceptable Use Policy. If Client nevertheless submits prohibited data, Client remains responsible for the resulting legal and regulatory obligations except to the extent applicable law independently imposes non-waivable obligations on RetterTEK.
16. De-Identified and Aggregated Data
RetterTEK may create and use de-identified or aggregated information derived from use of the Services for security, analytics, service improvement, capacity planning, benchmarking, and business operations, provided such information is processed in a manner designed to prevent identification of Client or any individual where required by applicable law. RetterTEK will not attempt to re-identify data that has been legally de-identified except as permitted by law for testing the effectiveness of de-identification controls.
17. Order of Precedence; Term
This DPA remains in effect for as long as RetterTEK processes Client Personal Data under the Agreement. If this DPA conflicts with the Master SaaS Terms on a matter concerning data-processing obligations required by applicable Privacy Laws, this DPA controls for that matter. The Order Form controls for expressly negotiated commercial terms.
18. Contact
Privacy and data-protection inquiries may be directed to [email protected].