Data Processing Agreement
Data Protection
DATA PROCESSING AGREEMENT
I. Introduction
This Data Processing Agreement (“Agreement”) is concluded by and between: (i) “COMPANY NAME” (“Customer” or “Controller”) and (ii) Interactio UAB, or one of its subsidiaries or affiliates (“Interactio" or “Processor”). Customer and Interactio acknowledge and agree that Customer is a Controller and Interactio is a Processor of Personal Data provided to Interactio by the Customer as defined in the EU General Data Protection Regulation 2016/679.
II. Definitions
In this Agreement the following terms shall have the meanings set out below:
- Applicable Laws means EU laws with respect to Personal Data that is subject to EU Data Protection Laws.
- Personal Data means any information relating to an identified or identifiable natural person (a “data subject”).
- Data Protection Laws means EU Data Protection Laws and, where applicable, the data protection or privacy laws of any other country.
- GDPR means EU General Data Protection Regulation 2016/679.
- Services means the services provided by Interactio for Customer.
III. Authority
Customer warrants and represents that, before Interactio processes any Personal Data on behalf of Customer, both parties have entered into this Agreement.
IV. Processing of Personal Data
Interactio shall:
- Comply with all applicable Data Protection Laws in the Processing of Personal Data.
- Not Process Personal Data other than on the Customer's instructions unless required by Applicable Laws.
Customer shall:
- Instruct Interactio to process Personal Data.
- Warrant that Customer is authorized to give the instructions.
V. International transfers of personal data
Interactio shall restrict access to Personal Data as necessary for compliance with Applicable Laws.
VI. Security
Interactio shall implement appropriate technical and physical measures to ensure a level of security appropriate to security risks related to Personal Data.
VII. Data Subject Rights
During the term of the Agreement, if Interactio receives any request from a data subject regarding Personal Data, Customer acknowledges it is responsible for responding to such requests.
VIII. Personal Data Breach
Interactio shall notify Customer without delay upon awareness of a Personal Data Breach affecting Personal Data received from Customer.
IX. Data Protection Impact Assessment and Prior Consultation
Interactio shall provide assistance to Customer with any data protection impact assessments and prior consultations as required under GDPR.
X. Deletion or return of Personal Data
Customer instructs Interactio to delete all Personal Data received after the end of the provision of services relating to Processing.
XI. Audit rights
If GDPR applies, Interactio shall provide necessary information to demonstrate compliance and allow for audits.
XII. Changes to this Data Processing Agreement
Interactio will update this Agreement and inform Customer at least 30 days before any changes will take effect.
ANNEX TO DATA PROCESSING AGREEMENT
I. Details of processing personal data
The subject matter of Processing is the proper execution of all contractual obligations including events, user identification, and troubleshooting.
Duration of Processing is the applicable term for the SERVICE AGREEMENT.
Types of Personal Data Processed include names, audio recordings, and technical information.
II. Processing records and contacts
Interactio UAB, Lithuania, EU, Phone: +37061806726, Email: dpo@interactio.io
III. Access to personal data
List of Interactio units with access to Controllers' users data is provided.
IV. Sub-processing
Customer authorizes Interactio to engage sub-processors, with notifications for any changes.
V. Technical and organizational measures
Access control measures include establishing authorizations, securing data processing equipment, and controlled destruction of Personal Data.
TABLES
Table I. Information Processing Table
| PURPOSES OF PROCESSING | CATEGORIES OF DATA SUBJECTS | CATEGORIES OF PERSONAL DATA | DATA STORAGE |
|---|---|---|---|
| To provide event media functionality | Event participant | Media data (audio, video) | 24 hours after the event |
| To download event recordings | Event participant | Audio recordings | 90 days after the event |
| To inspect problems in real-time | Event participant | Technical data | 24 hours after the event |
| To identify users during event tasks | Event participant | Contact data | Until end of contract |
| For troubleshooting audio problems | Event participant | Technical data | 24 hours after the event |
| To provide event-related statistics | Event participant | Date, speaking time, event name | 90 days after the event |
Table II. Access to personal data
| Interactio Unit | Types of data accessed | Purpose for data access | Data location |
|---|---|---|---|
| Customer Success Unit | Event data, contact data | To help set up an event | European Union |
| Dev/Sec/Ops Unit | Logging data | Security management | European Union |
Table III. List of data sub-processors
| Processor | Types of data accessed | Purpose for data access | Data location |
|---|---|---|---|
| Digital Ocean, LLC | Personal data from communications | To provide media streaming functionality | European Union |
| Amazon Web Services | Personal data from communications | To provide service functionality | European Union |