Data Processing Agreement

Data Protection

DATA PROCESSING AGREEMENT

I. Introduction

This Data Processing Agreement (“Agreement”) is concluded by and between: (i) “COMPANY NAME” (“Customer” or “Controller”) and (ii) Interactio UAB, or one of its subsidiaries or affiliates (“Interactio" or “Processor”). Customer and Interactio acknowledge and agree that Customer is a Controller and Interactio is a Processor of Personal Data provided to Interactio by the Customer as defined in the EU General Data Protection Regulation 2016/679.

II. Definitions

In this Agreement the following terms shall have the meanings set out below:

III. Authority

Customer warrants and represents that, before Interactio processes any Personal Data on behalf of Customer, both parties have entered into this Agreement.

IV. Processing of Personal Data

Interactio shall:

Customer shall:

V. International transfers of personal data

Interactio shall restrict access to Personal Data as necessary for compliance with Applicable Laws.

VI. Security

Interactio shall implement appropriate technical and physical measures to ensure a level of security appropriate to security risks related to Personal Data.

VII. Data Subject Rights

During the term of the Agreement, if Interactio receives any request from a data subject regarding Personal Data, Customer acknowledges it is responsible for responding to such requests.

VIII. Personal Data Breach

Interactio shall notify Customer without delay upon awareness of a Personal Data Breach affecting Personal Data received from Customer.

IX. Data Protection Impact Assessment and Prior Consultation

Interactio shall provide assistance to Customer with any data protection impact assessments and prior consultations as required under GDPR.

X. Deletion or return of Personal Data

Customer instructs Interactio to delete all Personal Data received after the end of the provision of services relating to Processing.

XI. Audit rights

If GDPR applies, Interactio shall provide necessary information to demonstrate compliance and allow for audits.

XII. Changes to this Data Processing Agreement

Interactio will update this Agreement and inform Customer at least 30 days before any changes will take effect.

ANNEX TO DATA PROCESSING AGREEMENT

I. Details of processing personal data

The subject matter of Processing is the proper execution of all contractual obligations including events, user identification, and troubleshooting.

Duration of Processing is the applicable term for the SERVICE AGREEMENT.

Types of Personal Data Processed include names, audio recordings, and technical information.

II. Processing records and contacts

Interactio UAB, Lithuania, EU, Phone: +37061806726, Email: dpo@interactio.io

III. Access to personal data

List of Interactio units with access to Controllers' users data is provided.

IV. Sub-processing

Customer authorizes Interactio to engage sub-processors, with notifications for any changes.

V. Technical and organizational measures

Access control measures include establishing authorizations, securing data processing equipment, and controlled destruction of Personal Data.

TABLES

Table I. Information Processing Table

PURPOSES OF PROCESSING CATEGORIES OF DATA SUBJECTS CATEGORIES OF PERSONAL DATA DATA STORAGE
To provide event media functionality Event participant Media data (audio, video) 24 hours after the event
To download event recordings Event participant Audio recordings 90 days after the event
To inspect problems in real-time Event participant Technical data 24 hours after the event
To identify users during event tasks Event participant Contact data Until end of contract
For troubleshooting audio problems Event participant Technical data 24 hours after the event
To provide event-related statistics Event participant Date, speaking time, event name 90 days after the event

Table II. Access to personal data

Interactio Unit Types of data accessed Purpose for data access Data location
Customer Success Unit Event data, contact data To help set up an event European Union
Dev/Sec/Ops Unit Logging data Security management European Union

Table III. List of data sub-processors

Processor Types of data accessed Purpose for data access Data location
Digital Ocean, LLC Personal data from communications To provide media streaming functionality European Union
Amazon Web Services Personal data from communications To provide service functionality European Union