Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of and is incorporated into the Terms and Conditions of Service and any Service Order between Account-Able, Inc., a California corporation (“Account-Able,” “Company,” “we,” “us,” or “our”), and the customer that accepts the Terms (“Customer,” “you,” or “your”) (together, the “Agreement”). This DPA applies to the extent Company processes Personal Information on Customer’s behalf in providing the Services. Capitalized terms not defined here have the meaning given in the Agreement.
1. Definitions
1.1 “CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations.
1.2 “Business,” “Consumer,” “Personal Information,” “Sell,” “Share,” “Service Provider,” “Deidentified,” and “Process” or “Processing” have the meanings given to them in the CCPA.
1.3 “Customer Personal Information” means Personal Information contained in Customer Data that Company Processes on Customer’s behalf in providing the Services.
1.4 “Permitted Purpose” means providing, maintaining, supporting, securing, and improving the Services for Customer under the Agreement, and the other business purposes described in Exhibit A, in each case as permitted by the CCPA.
1.5 “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Information Processed by Company.
1.6 “Subprocessor” means a third party engaged by Company to Process Customer Personal Information in providing the Services.
2. Roles and Scope
2.1 Roles. For Customer Personal Information, Customer is the Business and Company is the Service Provider. Company Processes Customer Personal Information only to provide the Services under the Agreement.
2.2 Details of Processing. The subject matter, nature, purpose, and duration of Processing, the types of Personal Information, and the categories of Consumers are described in Exhibit A.
2.3 Customer instructions. Company will Process Customer Personal Information only on Customer’s documented instructions, which include the Agreement, Customer’s configuration and use of the Services, and any later written instructions the Parties agree to. Company will inform Customer if, in Company’s reasonable opinion, an instruction conflicts with the CCPA, in which case Company may pause the affected Processing without liability until the instruction is resolved.
3. Service Provider Obligations and Restrictions
3.1 Company will Process Customer Personal Information only for the Permitted Purpose and only as needed to provide the Services under the Agreement.
3.2 Company will not:
- (a) Sell or Share Customer Personal Information;
- (b) retain, use, or disclose Customer Personal Information for any purpose other than the Permitted Purpose, including any commercial purpose other than providing the Services, unless permitted by the CCPA;
- (c) retain, use, or disclose Customer Personal Information outside the direct business relationship between the Parties; or
- (d) combine Customer Personal Information with Personal Information it receives from, or on behalf of, another person, or collects from its own interactions with a Consumer, except as the CCPA permits a Service Provider to do to perform a business purpose.
3.3 Company certifies that it understands the restrictions in this Section 3 and will comply with them.
3.4 Company will notify Customer if it determines that it can no longer meet its obligations under the CCPA. On such notice, or where Customer reasonably believes Company is Processing Customer Personal Information in an unauthorized manner, Customer may take reasonable and appropriate steps to stop and remediate the unauthorized Processing.
4. Customer Obligations
4.1 Customer is responsible for the accuracy, quality, and legality of Customer Personal Information and for the means by which it acquired that information.
4.2 Customer represents and warrants that it has provided all notices and obtained all consents and rights necessary for Company to Process Customer Personal Information as described in the Agreement and this DPA, including any consent required to record meetings or to Process the contents of communications.
4.3 Customer will not instruct Company to Process Customer Personal Information in violation of applicable law.
5. Assistance with Consumer Rights
5.1 The Services provide features that allow Customer to access, correct, delete, and export Customer Personal Information. Customer will use those features to respond to Consumer requests where possible.
5.2 Taking into account the nature of the Processing, Company will provide reasonable assistance to Customer, at Customer’s expense, to help Customer respond to verified Consumer requests under the CCPA to the extent Customer cannot address the request through the Services. If a Consumer sends a request directly to Company regarding Customer Personal Information, Company will, where permitted, direct the Consumer to Customer or promptly inform Customer.
6. Security
6.1 Company will maintain administrative, technical, and physical safeguards designed to protect Customer Personal Information that are appropriate to the nature of the information and no less protective than the measures described in Exhibit B.
6.2 Company will take reasonable steps so that personnel authorized to Process Customer Personal Information are subject to confidentiality obligations.
7. Security Incidents
7.1 Company will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Information.
7.2 Company will provide information reasonably available to it about the Security Incident to help Customer meet its own notification obligations, and will take reasonable steps to contain and remediate the incident. Company’s notification is not an acknowledgment of fault or liability.
8. Subprocessors
8.1 Customer provides general authorization for Company to engage Subprocessors to Process Customer Personal Information in providing the Services. A current list of Subprocessors is set out in Exhibit C or is otherwise made available by Company on request.
8.2 Company will impose on each Subprocessor data protection obligations that are substantially similar to and no less protective than the applicable obligations in this DPA.
8.3 Company will make available a means for Customer to be informed of changes to its Subprocessors. Company remains responsible for its Subprocessors’ performance of their obligations to the same extent Company would be responsible if performing the services directly.
9. Deidentified Information
Company may create and use Deidentified information derived from Customer Personal Information. Company will maintain and use such information in Deidentified form, will not attempt to reidentify it except as permitted by law to test that the deidentification is effective, and will require any recipient to comply with the same restrictions.
10. Return and Deletion
On termination or expiration of the Agreement, Company will return or delete Customer Personal Information as described in the Terms and Conditions of Service, which currently provide a thirty-day download window followed by deletion, except for copies retained in routine backups for a limited period before they are overwritten or as required by law.
11. Demonstrating Compliance
11.1 Company will make available to Customer information reasonably necessary to demonstrate Company’s compliance with this DPA.
11.2 Where Customer reasonably requires further verification, Company will respond to a reasonable written security questionnaire, and will make available any then-current third-party audit reports or security certifications it holds. Any onsite or third-party audit is limited to no more than once in any twelve-month period, requires at least thirty days’ prior written notice, must be conducted during business hours in a manner that does not disrupt Company’s operations, is subject to confidentiality, and is at Customer’s expense.
12. Liability
Each Party’s liability arising out of or related to this DPA is subject to the exclusions and limitations of liability in the Agreement, including the cap in the Limitation of Liability section, and any reference in the Agreement to a Party’s liability means the aggregate liability of that Party under the Agreement and this DPA together.
13. General
13.1 Scope of this DPA. This DPA addresses Processing subject to the CCPA. The Services are offered in the United States only. If the Parties later agree that Company will Process Personal Information subject to the laws of the European Union, the United Kingdom, or another jurisdiction outside the United States, the Parties will enter into additional terms, including any required standard contractual clauses, before that Processing begins.
13.2 Order of precedence. If there is a conflict between this DPA and the rest of the Agreement regarding the Processing of Customer Personal Information, this DPA controls. In all other respects the Agreement remains in full force.
13.3 Changes. Company may update this DPA as needed to reflect changes in the CCPA or Company’s practices, consistent with the change process in the Terms and Conditions of Service, provided that no update will materially reduce the protections for Customer Personal Information.
Exhibit A: Details of Processing
Subject matter: Company’s provision of the meeting management Services to Customer under the Agreement.
Duration: For the term of the Agreement, plus the retention and deletion periods described in the Terms and Conditions of Service.
Nature and purpose of Processing: Hosting, storing, organizing, transmitting, displaying, transcribing, analyzing, and otherwise Processing Customer Personal Information as needed to provide the Services and their features, including meeting agendas and templates, timers, decision and task tracking, performance and KPI reporting, previews and recaps, meeting ratings, and recording, transcription, and artificial intelligence features that Customer enables.
Types of Personal Information: Identifiers such as name, username, email address, phone number, and account identifiers; professional information such as job title and employer; content that Customer and its Users create or upload, including meeting content, notes, decisions, and tasks; recordings and transcripts of meetings that Customer chooses to record; and usage and log data associated with the account.
Categories of Consumers: Customer’s Users, administrators, meeting participants, and the individuals whose information Customer or its Users include in Customer Data.
Exhibit B: Security Measures
Company maintains a security program that includes measures such as: access controls and authentication for the Services; role-based access limits for personnel; encryption of data in transit and, where appropriate, at rest; network and application safeguards; logging and monitoring; regular patching and vulnerability management; use of reputable hosting and infrastructure providers; personnel confidentiality obligations; and periodic review of these measures. Company may update the specific measures over time provided the overall level of protection is not materially reduced.
Exhibit C: Subprocessors
Company uses Subprocessors to provide the Services, which may include providers of cloud hosting and storage, transcription and artificial intelligence processing, analytics, communications, and payment processing. A current list of Subprocessors, and the means to be informed of changes, is available from Company on request at support@account-able.io.
Contact
Account-Able, Inc.
Email: support@account-able.io
Web: account-able.io/contact