# Data Protection

## DATA PROCESSING AGREEMENT

### I. Introduction
This Data Processing Agreement (“Agreement”) is concluded by and between: (i) “COMPANY NAME” (“Customer” or “Controller”) and (ii) Interactio UAB, or one of its subsidiaries or affiliates (“Interactio" or “Processor”). Customer and Interactio acknowledge and agree that Customer is a Controller and Interactio is a Processor of Personal Data provided to Interactio by the Customer as defined in the EU General Data Protection Regulation 2016/679.

### II. Definitions
In this Agreement the following terms shall have the meanings set out below:

- **Applicable Laws** means EU laws with respect to Personal Data that is subject to EU Data Protection Laws.
- **Personal Data** means any information relating to an identified or identifiable natural person (a “data subject”).
- **Data Protection Laws** means EU Data Protection Laws and, where applicable, the data protection or privacy laws of any other country.
- **GDPR** means EU General Data Protection Regulation 2016/679.
- **Services** means the services provided by Interactio for Customer.

### III. Authority
Customer warrants and represents that, before Interactio processes any Personal Data on behalf of Customer, both parties have entered into this Agreement.

### IV. Processing of Personal Data
**Interactio shall:**
- Comply with all applicable Data Protection Laws in the Processing of Personal Data.
- Not Process Personal Data other than on the Customer's instructions unless required by Applicable Laws.

**Customer shall:**
- Instruct Interactio to process Personal Data.
- Warrant that Customer is authorized to give the instructions.

### V. International transfers of personal data
Interactio shall restrict access to Personal Data as necessary for compliance with Applicable Laws.

### VI. Security
Interactio shall implement appropriate technical and physical measures to ensure a level of security appropriate to security risks related to Personal Data.

### VII. Data Subject Rights
During the term of the Agreement, if Interactio receives any request from a data subject regarding Personal Data, Customer acknowledges it is responsible for responding to such requests.

### VIII. Personal Data Breach
Interactio shall notify Customer without delay upon awareness of a Personal Data Breach affecting Personal Data received from Customer.

### IX. Data Protection Impact Assessment and Prior Consultation
Interactio shall provide assistance to Customer with any data protection impact assessments and prior consultations as required under GDPR.

### X. Deletion or return of Personal Data
Customer instructs Interactio to delete all Personal Data received after the end of the provision of services relating to Processing.

### XI. Audit rights
If GDPR applies, Interactio shall provide necessary information to demonstrate compliance and allow for audits.

### XII. Changes to this Data Processing Agreement
Interactio will update this Agreement and inform Customer at least 30 days before any changes will take effect.

## ANNEX TO DATA PROCESSING AGREEMENT

### I. Details of processing personal data
The subject matter of Processing is the proper execution of all contractual obligations including events, user identification, and troubleshooting.

**Duration of Processing**  is the applicable term for the SERVICE AGREEMENT.

**Types of Personal Data Processed** include names, audio recordings, and technical information.

### II. Processing records and contacts
Interactio UAB, Lithuania, EU, Phone: +37061806726, Email: dpo@interactio.io

### III. Access to personal data
List of Interactio units with access to Controllers' users data is provided.

### IV. Sub-processing
Customer authorizes Interactio to engage sub-processors, with notifications for any changes.

### V. Technical and organizational measures
Access control measures include establishing authorizations, securing data processing equipment, and controlled destruction of Personal Data.

## TABLES

### Table I. Information Processing Table
| PURPOSES OF PROCESSING                            | CATEGORIES OF DATA SUBJECTS | CATEGORIES OF PERSONAL DATA                              | DATA STORAGE            |
|--------------------------------------------------|------------------------------|--------------------------------------------------------|-------------------------|
| To provide event media functionality              | Event participant           | Media data (audio, video)                             | 24 hours after the event|
| To download event recordings                       | Event participant           | Audio recordings                                       | 90 days after the event |
| To inspect problems in real-time                  | Event participant           | Technical data                                        | 24 hours after the event|
| To identify users during event tasks              | Event participant           | Contact data                                          | Until end of contract   |
| For troubleshooting audio problems                 | Event participant           | Technical data                                        | 24 hours after the event|
| To provide event-related statistics                | Event participant           | Date, speaking time, event name                       | 90 days after the event |

### Table II. Access to personal data
| Interactio Unit                | Types of data accessed          | Purpose for data access                               | Data location           |
|---------------------------------|----------------------------------|------------------------------------------------------|-------------------------|
| Customer Success Unit           | Event data, contact data        | To help set up an event                                | European Union          |
| Dev/Sec/Ops Unit               | Logging data                    | Security management                                    | European Union          |

### Table III. List of data sub-processors
| Processor                      | Types of data accessed           | Purpose for data access                               | Data location           |
|-------------------------------|----------------------------------|------------------------------------------------------|-------------------------|
| Digital Ocean, LLC           | Personal data from communications| To provide media streaming functionality                | European Union          |
| Amazon Web Services           | Personal data from communications| To provide service functionality                        | European Union          |
