Date of last revision: February 28, 2024
This Data Processing Agreement, including its Annexes ("DPA"), is entered into by UNIFIED API Inc., an Ontario, Canada corporation having its principal place of business at 325 Front Street West, 4th floor, Toronto, Ontario, M5V2Y1 ("Company" or "UNIFIED"), and Counterparty (defined below).
UNIFIED provides its proprietary, infrastructure solution for integrating HR, recruiting, sales, file storage, and accounting platforms ("Service(s)") to Customers and End Customer (each as defined below). The provision of the Service involves the Processing of Personal Data subject to the Data Protection Laws, and the purpose of this DPA is to set forth the terms under which UNIFIED Processes the Personal Data.
This Data Processing Agreement (DPA) applies between the parties where a representative of Counterparty transfers personal data to Company for processing by means of the service, by signing up for the service or otherwise affirmatively indicates acceptance. By doing so, you:
If Customer and UNIFIED have executed a written data processing agreement governing the processing of personal data by means of the Service, then the terms of such signed data processing agreement between the parties will supersede this DPA.
In the provision of services by UNIFIED involving Counterparty, the following roles ("Roles") apply among the parties:
Counterparty | Description | Data Processing Function(s) |
---|---|---|
Customer | Party that uses the Service | For Customer Personal Data Processed by UNIFIED, Customer is the Controller and UNIFIED is a Processor. For End Customer Personal Data Processed by UNIFIED, Customer is a Processor and UNIFIED is a Processor and/or subprocessor |
End Customer | The Customer's customer that enables integration between the Service and Data Provider's platform in order for UNIFIED to Process the End Customer's Personal Data for the benefit of the Customer. | For End Customer Personal Data Processed by UNIFIED, End Customer is the Controller; Customer is a Processor; and UNIFIED is a Processor and/or subprocessor |
Data Provider | Provider of a SaaS solution used by End Customer (can be, but not limited to CRM solution, ATS/HRIS platform, Accounting/eCommerce software, etc.) | End Customer is the Controller; Data Provider is the Processor; UNIFIED is the Processor to End Customer |
1. Definitions.
All capitalized terms used in this DPA will have the meanings given to them herein, in applicable Data Protection Laws, or as set forth in the applicable Agreement between UNIFIED and the Counterparty.
"Agreement" means the applicable terms between UNIFIED and Counterparty regarding use of or integration with the Service.
"Controller" means the entity or Business which solely or jointly with other entities determines the purposes and means of the Processing of Personal Data, and for the purposes of this DPA is as set forth in the Roles table above.
"Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, or alteration, unauthorized disclosure of, or access to, Personal Data Processed by UNIFIED on behalf of Counterparty.
"Data Protection Laws" means all applicable data protection and privacy laws, their implementing regulations, regulatory guidance, and secondary legislation, each as updated or replaced from time to time, including, as they may apply: (i) the General Data Protection Regulation ((EU) 2016/679) (the "GDPR") and any applicable national implementing laws; (ii) the UK General Data Protection Regulation ("UK GDPR") and the UK Data Protection Act 2018; (iii) U.S. legislation (e.g., the California Consumer Privacy Act and the California Privacy Rights Act); and (iv) any other laws that may be applicable.
"Data Subject" means the identified or identifiable person to whom the Personal Data relates, as defined in the applicable Data Protection Laws.
"EU Standard Contractual Clauses" or "SCCs" or "Clauses" means the terms available at eur-lex.europa.eu and promulgated pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council 4 June.
"Personal Data" means any information relating to a Data Subject that is subject to the Data Protection Laws and that UNIFIED Processes on behalf of Counterparty as described in Section 4 of this DPA.
"Processing" has the meaning given to it in the Data Protection Laws and "process", "processes" and "processed" will be construed accordingly.
"Processor" means the entity or Service Provider which Processes Personal Data on behalf of the Controller, as defined in the applicable Data Protection Laws and for the purposes of this DPA is as set forth in the Roles table above.
2. Compliance With Laws.
Each party will comply with the Data Protection Laws as applicable to it.
3. Personal Data Obligations.
Counterparty undertakes that all instructions for the Processing of Personal Data under the Agreement or this DPA or as otherwise agreed will comply with the Data Protection Laws, and such instructions will not cause UNIFIED to be in breach of any Data Protection Laws. Counterparty, to the extent that it provides its Personal Data to UNIFIED, is responsible for the means by which the Personal Data was acquired.
4. Data Processing.
UNIFIED will Process the Personal Data solely for the purposes of providing the Service and in accordance with Counterparty's instructions as outlined in the Agreement and this DPA, or as otherwise documented by Counterparty, in either event only as permitted by applicable Data Protection Laws.
Unless prohibited by applicable law, UNIFIED will notify Counterparty if in its opinion, an instruction infringes any Data Protection Laws to which it is subject, in which case UNIFIED will be entitled to suspend performance of such instruction without liability to UNIFIED, until Counterparty confirms in writing that such instruction is valid under the Data Protection Laws. Any additional instructions regarding the manner in which UNIFIED Processes the Personal Data will require prior written agreement between UNIFIED and Counterparty.
UNIFIED will not disclose Personal Data to any government, except as necessary to comply with applicable law or a valid and binding order of a law enforcement agency (such as a subpoena or court order). If UNIFIED receives a binding order from a law enforcement agency for Personal Data, UNIFIED will notify Counterparty of the request it has received so long as UNIFIED is not legally prohibited from doing so.
UNIFIED will ensure that individuals with access to or involved in the Processing of Personal Data are subject to appropriate confidentiality obligations and/or are bound by related obligations under Data Protection Laws or other applicable laws.
Where UNIFIED acts as Counterparty's Service Provider, UNIFIED shall not: (i) sell or share Personal Data; (ii) collect, retain, use, or disclose Personal Data (a) for any purpose other than providing the Service specified in the Agreement and this Addendum or (b) outside of the direct business relationship between UNIFIED and Counterparty; or (iii) combine this Personal Data with Personal Data that UNIFIED obtains from other sources except as permitted by applicable Data Protection Laws. UNIFIED certifies that it understands the prohibitions outlined in this Section and will comply with them.
The duration of the Processing, the nature and specific purposes of the Processing, the types of Personal Data Processed, and categories of Data Subjects under this Addendum are further specified in the Annexes to this Addendum and, on a more general level, in the Agreement.
5. Transfers of Personal Data.
UNIFIED shall transfer Personal Data between jurisdictions as a Data Processor in accordance with applicable Data Protection Laws.
Transfers of Personal Data Outside the EEA.
Transfers of Personal Data Outside Switzerland.
If Personal Data is transferred from Switzerland in a manner that would trigger obligations under the Federal Act on Data Protection of Switzerland ("FADP"), the EU SCCs shall apply to such transfers and shall be deemed to be modified in a manner to that incorporates relevant references and definitions that would render such EU SCCs an adequate tool for such transfers under the FADP.
Transfers of Personal Data Outside the UK.
If Personal Data is transferred in a manner that would trigger obligations under UK GDPR, the parties agree (i) that Annex IV shall apply.
Annexes.
This Addendum and its Annexes, together with the Agreement, including as relevant applicable Clauses, serve as a binding contract that sets out the subject matter, duration, nature, and purpose of the Processing, the type of Personal Data and categories of data subjects as well as the obligations and rights of the Controller. UNIFIED may execute relevant contractual addenda, including as relevant the EU SCCs (Module 3) with any relevant Subprocessor (as hereinafter defined, including Affiliates). Unless UNIFIED notifies Customer to the contrary, if the European Commission subsequently amends the EU SCCs at a later date, such amended terms will supersede and replace any EU SCCs executed between the parties.
Alternative Data Export Solution.
The parties agree that the data export solutions identified in this Section 5 will not apply if and to the extent that Customer adopts an alternative data export solution for the lawful transfer of Personal Data (as recognized under applicable Data Protection Laws), in which event, Customer shall reasonably cooperate with UNIFIED to implement such solution and such alternative data export solution will apply instead (but solely to the extent such alternative data export solution extends to the territories to which Personal Data is transferred under this Addendum).
6. Technical and Organizational Measures.
UNIFIED will implement appropriate technical and organizational measures to ensure a level of security of the Personal Data appropriate to the risk, as further described in Annex II hereto. In assessing the appropriate level of security, UNIFIED will take into account the risks that are presented by Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored or otherwise Processed.
7. Data Subject Rights.
UNIFIED will assist Counterparty in responding to Data Subjects' requests exercising their rights under the Data Protection Laws. To that effect, UNIFIED will
8.Data Protection Impact Assessments.
If Counterparty is required under the Data Protection Laws to conduct a Data Protection Impact Assessment, then upon written request from Counterparty, UNIFIED will assist where reasonably possible in the fulfillment of the Counterparty's obligation as related to its use of the Service, to the extent Counterparty does not otherwise have access to the relevant information. If required under Data Protection Laws UNIFIED will provide reasonable assistance to Counterparty in the cooperation or prior consultation with Data Protection Authorities in relation to any applicable Data Protection Impact Assessment.
9. Audit of Technical and Organizational Measures.
UNIFIED agrees to make available all information necessary to demonstrate its compliance with data protection policies and procedures implemented as part of the Service. To this end, upon written request (not more than once annually) Counterparty may, at its sole cost and expense, verify UNIFIED's compliance with its data protection obligations as specified in this DPA by:
Such interviews will be conducted with a minimum of disruption to UNIFIED's normal business operations and subject always to UNIFIED's agreement on scope and timings. The Counterparty may perform the audit described above either by itself or through a mutually agreed upon third party auditor, provided that Counterparty or its authorized auditor executes a mutually agreed upon non-disclosure agreement. Counterparty will be responsible for any actions taken by its authorized auditor. All information disclosed by UNIFIED under this Section 9 will be deemed UNIFIED Confidential Information, and Counterparty will not disclose any audit report to any third party except as obligated by law, court order or administrative order by a government agency. UNIFIED will remediate any mutually agreed, material deficiencies in its technical and organizational measures identified by the audit procedures described in this Section 9 within a mutually agreeable time frame.
10. Breach notification
If UNIFIED becomes aware of a Data Breach that results in unlawful or unauthorized access to, or loss, disclosure, or alteration of the Personal Data, then UNIFIED will notify the Counterparty without undue delay and in any event, within seventy-two hours after becoming aware of such Data Breach and will cooperate with the Counterparty and take such reasonable commercial steps as agreed with the Counterparty to assist in the investigation, mitigation and remediation of such Data Breach. UNIFIED will provide all reasonably required support and cooperation necessary to enable Counterparty to comply with its legal obligations in case of a Data Breach pursuant to applicable Data Protection Laws.
11. Sub-processing.
Counterparty agrees that UNIFIED may engage either UNIFIED affiliated companies or third parties providers as "Subprocessors" and hereby authorizes UNIFIED to engage such Subprocessors in the provision of the Service. UNIFIED will restrict the Processing activities performed by Subprocessors to only what is necessary to accomplish the purposes of the Agreement and this DPA. UNIFIED will impose appropriate contractual obligations in writing upon the Subprocessors that are no less protective than this DPA, and UNIFIED will remain responsible for the Subprocessors' compliance with the obligations under this DPA.
UNIFIED maintains a list of all Subprocessors at unified.to/gdpr/subprocessors (Annex III). UNIFIED may amend the list of Subprocessors by adding or replacing Subprocessors at any time and will use commercially reasonable efforts to provide Counterparty with fifteen (15) days' advance notice of any updates so long as Counterparty subscribes to UNIFIED's notification list. Controller will be entitled to object to a new Subprocessor by notifying UNIFIED in writing the reasons for its objection. UNIFIED will work in good faith to address the Controller's objections. If UNIFIED is unable or unwilling to adequately address Controller's objections to its reasonable satisfaction, then Controller may terminate this DPA and the Agreement, as specified in the Agreement.
12. Governing Law. This Addendum shall be governed by and construed in accordance with governing law of the province of Ontario in Canada, unless required otherwise by applicable Data Protection Laws. For the purposes of Clauses 17 and 18 of the EU SCCs, where applicable, to the extent that the governing law and jurisdiction provisions in the Agreement do not meet the requirements of the EU SCCs, the parties select Option 2 of Clause 17, and agree that the EU SCCs shall be governed by the law of the EU Member State in which the data exporter is established; where such law does not allow for third-party beneficiary rights, the EU SCCs shall be governed by the laws of the country of Ireland. Pursuant to Clause 18, any dispute between the Parties arising from the EU SCCs shall be resolved by the courts of Ireland, and the Parties submit themselves to such jurisdiction. For the purposes of Clause 13 of the EU SCCs, the Supervisory Authority shall be the data exporter's applicable Supervisory Authority. Data exporter shall notify data importer of the applicable Supervisory Authority by email at legal@unified.to and shall provide any necessary updates without undue delay.
13. Return or Deletion of Personal Data.
Unless otherwise required by applicable Data Protection Laws, UNIFIED will delete or return, in Counterparty's discretion and upon Counterparty's written request, Personal Data within a reasonable period of time following the termination or expiration of the Agreement.
14. Termination.
This Addendum shall automatically terminate upon the termination or expiration of the Agreement. This Addendum cannot, in principle, be terminated separately to the Agreement, except where the Processing ends before the termination of the Agreement, in which case, this Addendum shall automatically terminate.
15. Entire Agreement; Conflict.
Except as amended by this DPA, the Agreement will remain in full force and effect. If there is a conflict between the Agreement and this DPA, the terms of this DPA will control.
APPENDIX
ANNEX I
ANNEX II
TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
UNIFIED processes all personal data received from Controller, or on its behalf under this DPA in conformity with the following technical and organizational measures:
Information Security Organization
Personnel Security UNIFIED has established a Code of Conduct outlining ethical expectations, behavior standards, and ramifications of noncompliance, as well as Acceptable Use, Data Protection, and Information Security Policies. Internal personnel acknowledge all codes and procedures within 30 days of hire.
Internal personnel complete annual training programs for information security to help them understand their obligations and responsibilities related to security.
Access Controls and Asset Management
Internal users are provisioned access to systems based on role, which is reviewed and approved by the Chief Technology Officer ("CTO"). The CTO approves any additional access required outside the access matrix.
Internal user access to systems and applications with service data requires two-factor authentication in the form of user ID / password or SSO, and one-time passcode.Production infrastructure is restricted to users with a valid SSH key; administrative access to production servers and databases is restricted to the Back-end Engineering team.
Upon termination or when internal users no longer require access, infrastructure and application access is removed within one business day. Internal use of the internal admin tool is logged. These logs are reviewed monthly for appropriateness. The Engineering team maintains a list of the company's system components, owners, and their business function, and the Chief Technology Officer reviews this list annually.
Incident Management and Business Continuity
UNIFIED's Incident Response Plan outlines the process of identifying, prioritizing, communicating, assigning, and tracking incidents through to resolution.
The Security team tracks identified incidents according to the Incident Response Plan and creates a ‘lessons learned' document after each high or critical incident. This document is shared with the Engineering team to make any required changes.
Change Controls
UNIFIED's Change Management Process and Standard governs the system development life cycle, including documented policies for tracking, testing, approving, and validating changes.
System changes are tested via automated test scripts prior to being deployed into production.
Code merge requests are independently peer reviewed prior to integrating the code change into production.
Configuration changes are tested (if applicable) and approved prior to being deployed into production.
Data and Availability Controls
UNIFIED's Data Protection Policy details the security and handling protocols for service data.
Full backups are performed continuously and retained in accordance with the Backup Policy.
Encryption is used to protect the transmission of data over the internet; service data is encrypted at rest.
System tools monitor company load balancers and notify appropriate personnel of any events or outages based on predetermined criteria.
The Platform is configured to operate across availability zones to support continuous availability.
ANNEX III
LIST OF SUB-PROCESSORS
The controller has authorized the use of the Subprocessors listed at the following website: unified.to/gdpr/subprocessors
ANNEX IV
UK ADDENDUM TO EU STANDARD CONTRACTUAL CLAUSES
PART 1: TABLES
Parties
Start date | Effective the date of the execution of the Addendum | |
The Parties | Exporter (who sends the Restricted Transfer)As listed in Annex I | Importer (who receives the Restricted Transfer)As listed in Annex I |
Parties Details | As listed in Annex I | As listed in Annex I |
Key Contacts | As listed in Annex I | As listed in Annex I |
Selected SCCs, Modules and Selected Clauses
The version of the approved EU SCCs agreed to in the Addendum to which this UK Addendum is appended to, including the Appendix Information.
Appendix Information
"Appendix Information" means the information which must be provided for the selected modules as set out in the Appendix of the Approved SCCs (other than the Parties), and which for this UK Addendum is set out in:
Ending this Addendum when the Approved Addendum Changes
Which Parties may end this Addendum:
PART 2: MANDATORY CLAUSES
Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.