{"component": "clause", "props": {"groups": [{"snippet": "(a) The Customer shall notify to BT what personal data, if any, is included in the Customer Data (\u2018Customer Personal Data\u2019) and the Customer will provide BT with reasonable written instructions in accordance with clause 16 as to the manner and purpose of the processing by BT to the extent strictly required for the provision of the Services. Any such instructions shall require an amendment in accordance with clause 19.15.\n(b) The Customer will be the data controller and BT will be the data processor in relation to any processing of Customer Personal Data.\n(c) Each Party shall comply with any data protection laws applicable to it in its processing of Customer Personal Data under or by virtue of this Agreement.\n(d) BT will only process Customer Personal Data to the extent necessary to provide the Services and/or Products in accordance with this Agreement and will: (i) implement and maintain measures, in accordance with its security policies as amended from time to time, to protect Customer Personal Data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access; and (ii) transfer Customer Personal Data outside of the EEA, including to Affiliates, subcontractors or suppliers where required to provide the Services.\n(e) The Customer shall provide sufficient notice and obtain sufficient consent and authorisation, under any applicable laws, from any relevant data subject to permit the processing of any Customer Personal Data by BT, its respective Affiliates, subcontractors or suppliers as provided for in this Agreement.\n(f) The Customer agrees that BT, to the extent permitted by law, will not be liable for any complaint, claim or action brought by a data subject arising from any action or omission by BT to the extent that such action or omission: (i) resulted from any failure by the Customer to comply with this Clause 19.3; or resulted from BT complying with any instructions of Customer or acting on behalf of the Customer in accordance with those instructions, and the Customer shall indemnify, hold harmless and defend BT from and against any such claims or actions brought against BT.", "snippet_links": [{"key": "the-customer-shall", "type": "clause", "offset": [4, 22]}, {"key": "what-personal-data", "type": "clause", "offset": [36, 54]}, {"key": "the-customer-data", "type": "clause", "offset": [79, 96]}, {"key": "will-provide", "type": "clause", "offset": [141, 153]}, {"key": "written-instructions", "type": "definition", "offset": [173, 193]}, {"key": "in-accordance-with", "type": "definition", "offset": [194, 212]}, {"key": "clause-16", "type": "clause", "offset": [213, 222]}, {"key": "purpose-of-the-processing", "type": "clause", "offset": [244, 269]}, {"key": "the-provision-of-the-services", "type": "clause", "offset": [312, 341]}, {"key": "instructions-shall", "type": "definition", "offset": [352, 370]}, {"key": "the-data-controller", "type": "definition", "offset": [450, 469]}, {"key": "bt-will", "type": "clause", "offset": [474, 481]}, {"key": "data-processor", "type": "clause", "offset": [489, 503]}, {"key": "in-relation-to", "type": "clause", "offset": [504, 518]}, {"key": "processing-of-customer-personal-data", "type": "clause", "offset": [523, 559]}, {"key": "each-party", "type": "definition", "offset": [565, 575]}, {"key": "comply-with", "type": "definition", "offset": [582, 593]}, {"key": "applicable-to", "type": "definition", "offset": [619, 632]}, {"key": "provide-the", "type": "clause", "offset": [793, 804]}, {"key": "security-policies", "type": "definition", "offset": [934, 951]}, {"key": "as-amended", "type": "definition", "offset": [952, 962]}, {"key": "from-time-to-time", "type": "clause", "offset": [963, 980]}, {"key": "accidental-loss", "type": "definition", "offset": [1062, 1077]}, {"key": "unauthorised-disclosure", "type": "clause", "offset": [1091, 1114]}, {"key": "to-affiliates", "type": "clause", "offset": [1197, 1210]}, {"key": "where-required", "type": "clause", "offset": [1240, 1254]}, {"key": "sufficient-notice", "type": "definition", "offset": [1311, 1328]}, {"key": "applicable-laws", "type": "clause", "offset": [1388, 1403]}, {"key": "subject-to", "type": "definition", "offset": [1428, 1438]}, {"key": "respective-affiliates", "type": "definition", "offset": [1502, 1523]}, {"key": "in-this-agreement", "type": "definition", "offset": [1569, 1586]}, {"key": "customer-agrees-that", "type": "clause", "offset": [1596, 1616]}, {"key": "to-the-extent-permitted-by-law", "type": "clause", "offset": [1621, 1651]}, {"key": "any-action", "type": "definition", "offset": [1746, 1756]}, {"key": "by-the-customer", "type": "clause", "offset": [1849, 1864]}, {"key": "this-clause", "type": "clause", "offset": [1880, 1891]}, {"key": "complying-with", "type": "clause", "offset": [1918, 1932]}, {"key": "of-the-customer", "type": "clause", "offset": [1982, 1997]}, {"key": "hold-harmless-and-defend", "type": "clause", "offset": [2071, 2095]}, {"key": "claims-or-actions", "type": "definition", "offset": [2125, 2142]}], "samples": [{"hash": "iNFOQm1weA9", "uri": "/contracts/iNFOQm1weA9#customer-personal-data", "label": "Products and Services Agreement", "score": 31.7058448792, "published": true}, {"hash": "ksiEeKfLIO", "uri": "/contracts/ksiEeKfLIO#customer-personal-data", "label": "Products and Services Agreement", "score": 23.6105880737, "published": true}, {"hash": "fZiedkAWFGK", "uri": "/contracts/fZiedkAWFGK#customer-personal-data", "label": "Products and Services Agreement", "score": 23.6105880737, "published": true}], "size": 11, "hash": "bf70001ef090dc5f986bc0c1580b18d3", "id": 1}, {"snippet": "any Personal Data Processed by BAE Systems on behalf of the Customer. Data Protection Laws: the laws providing for the protection of natural persons with regard to any operations performed on information relating to them, and the movement of such information, including, without limitation, the GDPR and the UK GDPR. EEA: the European Economic Area, being the Member States of the European Union plus Iceland, Liechtenstein and Norway. GDPR: Regulation (EU) 2016/679 \u2013 the General Data Protection Regulation. Processor to Processor Standard Contractual Clauses: the Standard Contractual Clauses comprising Module 3 thereof. Standard Contractual Clauses: the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal Data to Third Countries pursuant to the GDPR. Third Country: a country other than a country in the EEA. UK GDPR: the retained EU law version of the GDPR, as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, and as amended by secondary legislation.", "snippet_links": [{"key": "personal-data-processed", "type": "clause", "offset": [4, 27]}, {"key": "of-the-customer", "type": "clause", "offset": [53, 68]}, {"key": "data-protection-laws", "type": "definition", "offset": [70, 90]}, {"key": "the-laws", "type": "definition", "offset": [92, 100]}, {"key": "protection-of", "type": "definition", "offset": [119, 132]}, {"key": "natural-persons", "type": "clause", "offset": [133, 148]}, {"key": "with-regard-to", "type": "clause", "offset": [149, 163]}, {"key": "relating-to", "type": "definition", "offset": [204, 215]}, {"key": "such-information", "type": "definition", "offset": [242, 258]}, {"key": "without-limitation", "type": "clause", "offset": [271, 289]}, {"key": "the-gdpr", "type": "definition", "offset": [291, 299]}, {"key": "the-uk-gdpr", "type": "definition", "offset": [304, 315]}, {"key": "european-economic-area", "type": "clause", "offset": [326, 348]}, {"key": "member-states-of-the-european-union", "type": "clause", "offset": [360, 395]}, {"key": "the-general-data-protection-regulation", "type": "clause", "offset": [469, 507]}, {"key": "processor-to-processor-standard-contractual-clauses", "type": "definition", "offset": [509, 560]}, {"key": "the-standard", "type": "clause", "offset": [562, 574]}, {"key": "module-3", "type": "definition", "offset": [606, 614]}, {"key": "the-european-commission", "type": "clause", "offset": [698, 721]}, {"key": "transfer-of-personal-data-to-third-countries", "type": "clause", "offset": [816, 860]}, {"key": "pursuant-to-the", "type": "definition", "offset": [861, 876]}, {"key": "third-country", "type": "clause", "offset": [883, 896]}, {"key": "eu-law", "type": "definition", "offset": [963, 969]}, {"key": "england-and-wales", "type": "clause", "offset": [1022, 1039]}, {"key": "scotland-and-northern-ireland", "type": "clause", "offset": [1041, 1070]}, {"key": "section-3", "type": "definition", "offset": [1084, 1093]}, {"key": "act-2018", "type": "clause", "offset": [1129, 1137]}, {"key": "as-amended", "type": "definition", "offset": [1143, 1153]}, {"key": "secondary-legislation", "type": "clause", "offset": [1157, 1178]}], "samples": [{"hash": "8TbXutH3yUb", "uri": "/contracts/8TbXutH3yUb#customer-personal-data", "label": "Master Framework Agreement", "score": 35.1252212524, "published": true}, {"hash": "8PG4spyikcX", "uri": "/contracts/8PG4spyikcX#customer-personal-data", "label": "Master Framework Agreement", "score": 35.072101593, "published": true}, {"hash": "adJHjhtjoU3", "uri": "/contracts/adJHjhtjoU3#customer-personal-data", "label": "Master Framework Agreement", "score": 35.0412826538, "published": true}], "size": 8, "hash": "8e924bd4db6e538c5d9fa0f2cb3f8c5c", "id": 2}, {"snippet": "Purpose and nature of the processing operations", "snippet_links": [{"key": "processing-operations", "type": "clause", "offset": [26, 47]}], "samples": [{"hash": "foHeYEL5hzb", "uri": "/contracts/foHeYEL5hzb#customer-personal-data", "label": "Data Processing Agreement", "score": 23.1656398773, "published": true}, {"hash": "feEDUJCSdlU", "uri": "/contracts/feEDUJCSdlU#customer-personal-data", "label": "Data Processing Agreement", "score": 23.1656398773, "published": true}, {"hash": "eXOdYiL3yes", "uri": "/contracts/eXOdYiL3yes#customer-personal-data", "label": "Data Processing Agreement", "score": 23.1656398773, "published": true}], "size": 5, "hash": "111ffc33631164237dd387c8ed6b990e", "id": 3}, {"snippet": "is being processed by Hubilo as part of providing access and use of the Platform to the Customer and their End User/s, as further specified in the MSA.", "snippet_links": [{"key": "access-and-use-of-the-platform", "type": "clause", "offset": [50, 80]}, {"key": "the-customer", "type": "clause", "offset": [84, 96]}, {"key": "end-user", "type": "definition", "offset": [107, 115]}, {"key": "the-msa", "type": "definition", "offset": [143, 150]}], "samples": [{"hash": "dxKAwx2P1rX", "uri": "/contracts/dxKAwx2P1rX#customer-personal-data", "label": "Data Processing Agreement", "score": 35.3975982666, "published": true}, {"hash": "jnwWFDvUsVh", "uri": "/contracts/jnwWFDvUsVh#customer-personal-data", "label": "Data Processing Agreement", "score": 35.1083908081, "published": true}, {"hash": "6EO1oRz5nuN", "uri": "/contracts/6EO1oRz5nuN#customer-personal-data", "label": "Data Processing Agreement", "score": 35.0262718201, "published": true}], "size": 4, "hash": "477c4d583355c865dcba583b0f471cc6", "id": 4}, {"snippet": "The Data Exporter Customer", "snippet_links": [{"key": "data-exporter", "type": "clause", "offset": [4, 17]}], "samples": [{"hash": "25VJ93aTE4Y", "uri": "/contracts/25VJ93aTE4Y#customer-personal-data", "label": "Data Processing Addendum", "score": 33.8772735596, "published": true}, {"hash": "zdsYUgc6cx", "uri": "/contracts/zdsYUgc6cx#customer-personal-data", "label": "Data Processing Addendum", "score": 33.2334098816, "published": true}, {"hash": "9nUoT1qzhDB", "uri": "/contracts/9nUoT1qzhDB#customer-personal-data", "label": "Data Processing Addendum", "score": 33.2059211731, "published": true}], "size": 4, "hash": "67aeb9f122aa39a4e1c34db908401ec3", "id": 5}, {"snippet": "Customer acknowledges that the Services, Introductory SaaS Service and Beta Releases do not require Customer to input or otherwise transmit Customer Personal Data and Customer agrees not to input or otherwise transmit any Customer Personal Data to the Services, Introductory SaaS Service or Beta Releases without Sysdig\u2019s explicit consent or as otherwise set forth in the applicable Order Form or other written agreement between the Parties.", "snippet_links": [{"key": "customer-acknowledges", "type": "clause", "offset": [0, 21]}, {"key": "introductory-saas-service", "type": "clause", "offset": [41, 66]}, {"key": "beta-releases", "type": "clause", "offset": [71, 84]}, {"key": "customer-agrees", "type": "clause", "offset": [167, 182]}, {"key": "to-the-services", "type": "clause", "offset": [245, 260]}, {"key": "explicit-consent", "type": "clause", "offset": [322, 338]}, {"key": "order-form", "type": "clause", "offset": [383, 393]}, {"key": "agreement-between-the-parties", "type": "clause", "offset": [411, 440]}], "samples": [{"hash": "lE5UnVEUZyg", "uri": "/contracts/lE5UnVEUZyg#customer-personal-data", "label": "Saas Subscription Agreement", "score": 32.6967735291, "published": true}, {"hash": "hLGtDepNOrP", "uri": "/contracts/hLGtDepNOrP#customer-personal-data", "label": "Saas Subscription Agreement", "score": 32.1328735352, "published": true}, {"hash": "l1m1ZVtjlie", "uri": "/contracts/l1m1ZVtjlie#customer-personal-data", "label": "Saas Subscription Agreement", "score": 26.5619430542, "published": true}], "size": 4, "hash": "e5b0ceb7cfc21781924587628bd36cf6", "id": 6}, {"snippet": "(a) Expedia acknowledges that, as between Expedia and Decolar, Decolar is the sole and exclusive owner of all Customer Personal Data relating to any End User originated via any Decolar Travel Solution (such Customer Personal Data, the \u201cDecolar Customer Personal Data\u201d). *** Expedia, its Affiliates and sublicensees shall not use *** Represents material which has been redacted and filed separately with the Securities and Exchange Commission pursuant to a request for confidential treatment pursuant to Rule 406 under the Securities Act of 1933, as amended. the Decolar Customer Personal Data for purposes of soliciting customers or performing marketing campaigns and shall abide by the confidentiality provisions set forth herein. Notwithstanding anything in this Agreement (including this Section 5.1.2(a)) to the contrary, to the extent required to comply with tax reporting requirements, Expedia shall have access to and shall be entitled to use any Decolar Customer Personal Data collected or received by Decolar or any of its Affiliates in connection with any and all Travel Products made available through the Expedia API.\n(b) Decolar acknowledges that, as between Decolar and Expedia, Expedia is the sole and exclusive owner of all Customer Personal Data relating to any End User originated via an Expedia Travel Solution (the \u201cExpedia Customer Personal Data\u201d). During the Term of this Agreement, Expedia hereby grants Decolar a worldwide, nonexclusive, royalty-free, sub-licensable right and license to use any Expedia Customer Personal Data imported to, integrated with or collected by Decolar via the Decolar Application, Decolar Platform or any Decolar Travel Solution, and to use the know-how and analytical results resulting therefrom in connection with the operation of the Decolar Travel Solution and the enhancement, improvement, and provision of the Decolar technology and derivatives thereof, without restriction. Decolar, its Affiliates and sublicensees shall not use the Expedia Customer Personal Data for purposes of soliciting customers or performing marketing campaigns, and shall abide by the confidentiality obligations set forth herein.", "snippet_links": [{"key": "sole-and-exclusive", "type": "clause", "offset": [78, 96]}, {"key": "relating-to", "type": "definition", "offset": [133, 144]}, {"key": "end-user", "type": "definition", "offset": [149, 157]}, {"key": "decolar-travel-solution", "type": "definition", "offset": [177, 200]}, {"key": "affiliates-and-sublicensees", "type": "clause", "offset": [287, 314]}, {"key": "been-redacted", "type": "clause", "offset": [363, 376]}, {"key": "filed-separately-with-the-securities-and-exchange-commission", "type": "clause", "offset": [381, 441]}, {"key": "pursuant-to-a", "type": "definition", "offset": [442, 455]}, {"key": "request-for-confidential-treatment", "type": "definition", "offset": [456, 490]}, {"key": "pursuant-to-rule", "type": "clause", "offset": [491, 507]}, {"key": "securities-act-of-1933", "type": "definition", "offset": [522, 544]}, {"key": "as-amended", "type": "definition", "offset": [546, 556]}, {"key": "for-purposes-of", "type": "clause", "offset": [593, 608]}, {"key": "soliciting-customers", "type": "clause", "offset": [609, 629]}, {"key": "marketing-campaigns", "type": "clause", "offset": [644, 663]}, {"key": "the-confidentiality-provisions", "type": "definition", "offset": [683, 713]}, {"key": "in-this-agreement", "type": "definition", "offset": [757, 774]}, {"key": "to-the-extent", "type": "clause", "offset": [826, 839]}, {"key": "comply-with", "type": "definition", "offset": [852, 863]}, {"key": "tax-reporting-requirements", "type": "clause", "offset": [864, 890]}, {"key": "access-to", "type": "definition", "offset": [911, 920]}, {"key": "data-collected", "type": "clause", "offset": [980, 994]}, {"key": "received-by", "type": "definition", "offset": [998, 1009]}, {"key": "in-connection-with", "type": "clause", "offset": [1043, 1061]}, {"key": "travel-products", "type": "definition", "offset": [1074, 1089]}, {"key": "made-available", "type": "clause", "offset": [1090, 1104]}, {"key": "expedia-travel-solution", "type": "definition", "offset": [1306, 1329]}, {"key": "during-the-term-of-this-agreement", "type": "clause", "offset": [1370, 1403]}, {"key": "right-and-license-to-use", "type": "clause", "offset": [1491, 1515]}, {"key": "analytical-results", "type": "definition", "offset": [1710, 1728]}, {"key": "operation-of-the", "type": "clause", "offset": [1772, 1788]}, {"key": "provision-of-the", "type": "clause", "offset": [1851, 1867]}, {"key": "confidentiality-obligations", "type": "clause", "offset": [2118, 2145]}], "samples": [{"hash": "aGS8Edd7m4v", "uri": "/contracts/aGS8Edd7m4v#customer-personal-data", "label": "Lodging Outsourcing Agreement (Despegar.com, Corp.)", "score": 28.6632442474, "published": true}, {"hash": "ayqIupX0hU5", "uri": "/contracts/ayqIupX0hU5#customer-personal-data", "label": "Lodging Outsourcing Agreement (Despegar.com, Corp.)", "score": 28.529088974, "published": true}], "size": 4, "hash": "32ba57b32f4196a3485f37740c674c8f", "id": 7}, {"snippet": "8.1. In this clause 8 and where used elsewhere in the Agreement:", "snippet_links": [{"key": "clause-8", "type": "definition", "offset": [13, 21]}, {"key": "in-the-agreement", "type": "clause", "offset": [47, 63]}], "samples": [{"hash": "k7y1nbmgATu", "uri": "/contracts/k7y1nbmgATu#customer-personal-data", "label": "General Terms and Conditions", "score": 35.3301200867, "published": true}, {"hash": "jMuuz6dky2n", "uri": "/contracts/jMuuz6dky2n#customer-personal-data", "label": "General Terms and Conditions", "score": 35.0043716431, "published": true}, {"hash": "io7JqHiBOEg", "uri": "/contracts/io7JqHiBOEg#customer-personal-data", "label": "General Terms and Conditions", "score": 34.9824752808, "published": true}], "size": 3, "hash": "05fdc8aee04b0556ea8a0ceda092bf0c", "id": 8}, {"snippet": "5.1 The parties acknowledge and agree that:\n5.1.1 this clause 5 sets out the parties\u2019 respective obligations in respect of the processing of personal data under this Agreement;\n5.1.2 to the extent that the Customer (including any Authorised Users) uploads, transmits, stores or otherwise communicates personal data to or via the Software, the Customer shall be the data controller in respect of such Customer Personal Data and the Supplier shall be acting as a data processor on behalf of the Customer.\n5.2 The Supplier shall also process personal data in connection with the Agreement in its own capacity as a data controller (where the Supplier is to determine the purposes and means of the processing, including, for example, contact details for the representative of the Customer). Except where this clause 5 refers generally to personal data, the provisions of this clause 5 will not apply to such processing but the Supplier will undertake such processing in accordance with its legal obligations to data subjects under Data Protection Legislation.\n5.3 Both parties shall comply with their respective obligations under Data Protection Legislation, the provisions of this clause 5 and any applicable Data Protocol in respect of all Customer Personal Data processed in connection with this Agreement.\n5.4 As a data controller, it is the Customer's responsibility to ensure that the Customer is entitled to process and to authorise the Supplier to process the Customer Personal Data in the manner and for the duration envisaged by this Agreement. If at any time the Customer has reason to believe that the processing of any Customer Personal Data under this Agreement is in breach of the Data Protection Legislation, the Customer shall immediately notify the Supplier, together with an explanation of the concern.\n5.5 Prior to sharing any Customer Personal Data with the Supplier, the Customer shall identify the lawful basis on which the parties can rely under Data Protection Legislation to process such Customer Personal Data. Unless the lawful basis the Customer wishes to rely on is performance of a contract or the data subject's consent, the Customer shall inform the Supplier of the lawful basis for processing such Customer Personal Data (prior to sharing such personal data with the Supplier) and if the lawful basis for processing changes, the Customer shall notify the Supplier as soon as practicable, but in any event no later than 14 days after such change occurs.\n5.6 The Customer shall always ensure that the Customer\u2019s instructions to the Supplier for the processing of Customer Personal Data under this Agreement comply with Data Protection Legislation and that compliance with such instructions would not cause the Supplier to breach the Data Protection Legislation.\n5.7 The Customer shall be responsible for the provision of the corresponding fair processing information to relevant data subjects and for obtaining any consents that may be required (in each case to the extent necessary in order to comply with Data Protection Legislation) from that data subject. The Customer shall ensure that such fair processing notices are accurate and complete, and that any consents are sufficient in order for the Supplier to lawfully process the Customer Personal Data in the manner set out in this clause 5.\n5.8 If the Customer requires the Supplier to transfer any Customer Personal Data to a third-party provider engaged by the Customer, the Customer shall be solely responsible for identifying the lawful basis under the Data Protection Legislation on which the parties can rely under the Data Protection Legislation to transfer such Customer Personal Data to the relevant third-party provider (and the Customer shall notify the Supplier of the same). A written data processing agreement must be in place between the Customer and such provider. The Customer acknowledges and agrees that the Supplier has no control over and shall have no liability in respect of how any personal data is processed by such third-party provider engaged by the Customer.\n5.9 If the Customer has requested integration of the Software with any third-party applications, it shall be Customer\u2019s sole responsibility to ensure such third-party integration complies with Data Protection Legislation. Such third parties shall either be data controllers or data processors on behalf of the Customer and shall have no direct relationship with the Supplier. The Supplier shall not be responsible or liable for the way in which other data controllers and/or the Customer\u2019s other data processors process the Customer Personal Data.\n5.10 In respect of the Customer Personal Data processed by the Supplier as a data processor on behalf of the Customer, the Supplier shall:\n5.10.1 only process Customer Personal Data on behalf of the Customer where and to the extent necessary to deliver the Services, and otherwise to perform the Supplier's obligations under this Agreement and applicable laws, and only in accordance with the terms of this clause 5, any applicable Data Protocol, and any additional reasonable instructions the Customer may issue from time to time (provided that such instructions are within the scope of the Supplier's obligations under this clause 5), unless otherwise required by law, regulation, court of competent jurisdiction or any other governmental or regulatory body;\n5.10.2 ensure that personnel who have access to and/or process the Customer Personal Data are obliged to keep the Customer Personal Data confidential;\n5.10.3 not transfer the Customer Personal Data outside of the United Kingdom or European Economic Area (EEA) without complying with the provisions of the Data Protection Legislation in respect of such transfer, save that if the Customer requires the Supplier to transfer any Customer Personal Data outside the United Kingdom or EEA pursuant to the Customer\u2019s instructions, it shall be the Customer\u2019s responsibility to ensure that any such transfer complies with the provisions of the Data Protection Legislation and to notify the Supplier of any specific instructions or restrictions in respect of the same;\n5.10.4 notify the Customer without undue delay if the Supplier becomes aware of any personal data breach or of any request or objection from a data subject pursuant to the Data Protection Legislation, in each case relating to the Customer Personal Data;\n5.10.5 to the extent that the Customer does not have the ability to address a Data Subject Request in respect of the Supplier's processing of Customer Personal Data, the Supplier shall, upon the Customer\u2019s request and insofar as is reasonably possible, provide commercially reasonable assistance, at the Customer\u2019s cost, to facilitate such Data Subject Request;\n5.10.6 reasonably assist the Customer, at the Customer\u2019s cost, in ensuring compliance with the Customer\u2019s obligations under the Data Protection Legislation with respect to consultations with supervisory authorities or regulators;\n5.10.7 provide the Customer with reasonable cooperation and assistance, at the Customer\u2019s cost, as may be required to fulfil the Customer\u2019s obligation under the GDPR to carry out a data protection impact assessment related to the Services, to the extent that the Customer does not otherwise have access to the relevant information and to the extent that such information is available to the Supplier;\n5.10.8 inform the Customer without undue delay after becoming aware of the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data transmitted, stored or otherwise processed by the Supplier in connection with this Agreement;\n5.10.9 maintain records and information regarding the Supplier's processing activities in respect of the Customer Personal Data to demonstrate the Supplier's compliance with this clause 5;\n5.10.10 allow for audits by the Customer or the Customer\u2019s designated auditor of the Supplier's systems and procedures relevant to the processing of Customer Personal Data, provided that in the case of any audit, the Customer shall:\n(i) comply with any reasonable requirements or security restrictions that the Supplier may impose to safeguard the Supplier's systems, personal data the Supplier holds on behalf of other customers and clients and the Supplier's own confidential or commercially sensitive information and to avoid unreasonable disruption to the Supplier's business and operations;\n(ii) reimburse the Supplier for any time expended by the Supplier for any such audit, at the Supplier's then current professional services rates, which shall be made available to the Customer upon request, which costs shall be reasonable, taking into account the resources expended by the Supplier; and\n(iii) before the commencement of any audit, the parties shall mutually agree on the scope, timing, and duration of the audit.\n5.11 The Supplier shall implement appropriate technical and organisational measures, taking into account the nature and purposes of the processing (to the best of its knowledge), for the protection and security of the Customer Personal Data and to protect against the unauthorised or unlawful processing of the Customer Personal Data and against accidental loss or destruction of, or damage to, the Customer Personal Data (the Security Measures). The Security Measures shall be appropriate to the nature of the personal data to be protected to the best of the Supplier's knowledge, it being acknowledged that the Supplier may not have full oversight over the categories and types of Customer Personal Data subject to the processing (including where processing is automatic).\n5.12 The Customer shall also implement its own appropriate technical and organisational measures, taking into account the nature and purposes of the processing, for the protection and security of the Customer Personal Data and to protect against the unauthorised or unlawful processing of the Customer Personal Data and against accidental loss or destruction of, or damage to, the Customer Personal Data, appropriate to the nature of the personal data to be protected.\n5.13 A summary of the Security Measures currently adopted by the Supplier are set out in Schedule 4 to this Agreement, further details of which are available from the Supplier upon request and which the Customer has the opportunity to review and assess in accordance with the Customer's own obligations under Data Protection Legislation. The Customer shall be responsible for ensuring that it is satisfied with the level of security offered by the Supplier in respect of its processing of Customer Personal Data and that the same meet the Customer's requirements as a data controller of the Customer Personal Data.\n5.14 The Supplier reserves the right to revise the Security Measures at any time:\n5.14.1 without notice, provided that such revisions will not materially reduce the overall security provided for the Customer Personal Data that the Supplier processes; or, in all other cases,\u200c\n5.14.2 by notifying the Customer of the same, provided that the Supplier considers such revised Security Measures are still sufficient to enable the Supplier to comply with its obligations under this clause 5 and the Data Protection Legislation, including in particular clause 5.11. Within a period of 30 days of the date of notification of such changes, the Customer may object to any such changes on reasonable grounds, in which event either party shall have the right to terminate this Agreement on giving the other party 30 days\u2019 written notice, without liability to the other party. If the Customer has not objected to any such changes within a period of 30 days of the date of the notification of the changes, the Customer shall be deemed to have accepted such changes.\n5.15 If the Customer, acting reasonably, at any time considers that the Security Measures do not offer a sufficient level of security and protection for the processing of Customer Personal Data, having regard to the nature and purpose of the processing, the Customer shall immediately notify the Supplier, together with such additional security measures which the Customer requires to be implemented to offer sufficient protection. Any such measures shall be implemented at the Customer's sole cost and expense. If it is not possible or reasonably practicable for the Supplier to implement such additional security measures (having regard to the Supplier's wider business) and/or if the Customer does not agree to the additional costs associated with such security measures, either party may terminate this Agreement on 30 days' prior written notice.\n5.16 From time to time, the Supplier may offer new or enhanced Security Measures to the Customer at additional cost (Enhanced Security). The Customer acknowledges that it is the Customer\u2019s decision whether or not to implement such Enhanced Security. If the Customer chooses not to implement such Enhanced Security, the Supplier shall not be liable for any loss, harm or damage which the Supplier can demonstrate was directly caused by or attributable to the Customer\u2019s failure to adopt such recommended measures (and which the Supplier can demonstrate would not have arisen if the Customer had implemented the recommended Enhanced Security). For the avoidance of doubt, from time to time, the Supplier may also implement new or enhanced security measures free of charge, pursuant to clause 5.14.1.", "snippet_links": [{"key": "the-parties-acknowledge-and-agree-that", "type": "clause", "offset": [4, 42]}, {"key": "clause-5", "type": "definition", "offset": [55, 63]}, {"key": "respective-obligations", "type": "clause", "offset": [86, 108]}, {"key": "in-respect-of", "type": "clause", "offset": [109, 122]}, {"key": "the-processing-of-personal-data", "type": "clause", "offset": [123, 154]}, {"key": "to-the-extent", "type": "clause", "offset": [183, 196]}, {"key": "authorised-users", "type": "clause", "offset": [230, 246]}, {"key": "the-software", "type": "definition", "offset": [325, 337]}, {"key": "the-customer-shall", "type": "clause", "offset": [339, 357]}, {"key": "the-data-controller", "type": "definition", "offset": [361, 380]}, {"key": "the-supplier-shall", "type": "clause", "offset": [427, 445]}, {"key": "of-the-customer", "type": "clause", "offset": [486, 501]}, {"key": "process-personal-data", "type": "definition", "offset": [531, 552]}, {"key": "in-connection-with", "type": "clause", "offset": [553, 571]}, {"key": "the-agreement", "type": "clause", "offset": [572, 585]}, {"key": "where-the-supplier", "type": "clause", "offset": [628, 646]}, {"key": "determine-the", "type": "clause", "offset": [653, 666]}, {"key": "purposes-and-means", "type": "clause", "offset": [667, 685]}, {"key": "for-example", "type": "clause", "offset": [716, 727]}, {"key": "contact-details", "type": "clause", "offset": [729, 744]}, {"key": "the-representative", "type": "clause", "offset": [749, 767]}, {"key": "the-provisions-of-this", "type": "clause", "offset": [848, 870]}, {"key": "the-supplier-will", "type": "clause", "offset": [918, 935]}, {"key": "in-accordance-with", "type": "definition", "offset": [962, 980]}, {"key": "legal-obligations", "type": "definition", "offset": [985, 1002]}, {"key": "data-subjects", "type": "definition", "offset": [1006, 1019]}, {"key": "both-parties", "type": "definition", "offset": [1059, 1071]}, {"key": "comply-with", "type": "definition", "offset": [1078, 1089]}, {"key": "applicable-data", "type": "clause", "offset": [1194, 1209]}, {"key": "personal-data-processed", "type": "clause", "offset": [1246, 1269]}, {"key": "to-ensure", "type": "clause", "offset": [1367, 1376]}, {"key": "the-customer-is-entitled", "type": "clause", "offset": [1382, 1406]}, {"key": "by-this-agreement", "type": "clause", "offset": [1531, 1548]}, {"key": "at-any-time", "type": "clause", "offset": [1553, 1564]}, {"key": "reason-to-believe", "type": "definition", "offset": [1582, 1599]}, {"key": "the-data-protection-legislation", "type": "definition", "offset": [1687, 1718]}, {"key": "notify-the", "type": "clause", "offset": [1751, 1761]}, {"key": "prior-to", "type": "clause", "offset": [1821, 1829]}, {"key": "performance-of-a-contract", "type": "definition", "offset": [2091, 2116]}, {"key": "lawful-basis-for-processing", "type": "clause", "offset": [2194, 2221]}, {"key": "processing-changes", "type": "clause", "offset": [2334, 2352]}, {"key": "as-soon-as-practicable", "type": "definition", "offset": [2393, 2415]}, {"key": "days-after", "type": "definition", "offset": [2451, 2461]}, {"key": "to-the-supplier", "type": "clause", "offset": [2552, 2567]}, {"key": "processing-of-customer-personal-data", "type": "clause", "offset": [2576, 2612]}, {"key": "responsible-for", "type": "clause", "offset": [2815, 2830]}, {"key": "provision-of-the", "type": "clause", "offset": [2835, 2851]}, {"key": "processing-information", "type": "clause", "offset": [2871, 2893]}, {"key": "relevant-data", "type": "definition", "offset": [2897, 2910]}, {"key": "each-case", "type": "definition", "offset": [2976, 2985]}, {"key": "order-to-comply", "type": "definition", "offset": [3013, 3028]}, {"key": "processing-notices", "type": "definition", "offset": [3128, 3146]}, {"key": "accurate-and-complete", "type": "clause", "offset": [3151, 3172]}, {"key": "for-the-supplier", "type": "clause", "offset": [3220, 3236]}, {"key": "set-out", "type": "definition", "offset": [3298, 3305]}, {"key": "in-this-clause", "type": "clause", "offset": [3306, 3320]}, {"key": "if-the-customer", "type": "clause", "offset": [3328, 3343]}, {"key": "to-transfer", "type": "clause", "offset": [3366, 3377]}, {"key": "party-provider", "type": "definition", "offset": [3416, 3430]}, {"key": "by-the-customer", "type": "clause", "offset": [3439, 3454]}, {"key": "the-relevant", "type": "clause", "offset": [3679, 3691]}, {"key": "data-processing-agreement", "type": "clause", "offset": [3781, 3806]}, {"key": "in-place", "type": "clause", "offset": [3815, 3823]}, {"key": "customer-acknowledges-and-agrees", "type": "clause", "offset": [3868, 3900]}, {"key": "no-control", "type": "clause", "offset": [3923, 3933]}, {"key": "no-liability", "type": "clause", "offset": [3954, 3966]}, {"key": "sole-responsibility", "type": "clause", "offset": [4190, 4209]}, {"key": "third-parties", "type": "clause", "offset": [4297, 4310]}, {"key": "data-controllers", "type": "definition", "offset": [4327, 4343]}, {"key": "direct-relationship", "type": "clause", "offset": [4407, 4426]}, {"key": "other-data-processors", "type": "clause", "offset": [4560, 4581]}, {"key": "obligations-under-this-agreement", "type": "clause", "offset": [4925, 4957]}, {"key": "applicable-laws", "type": "clause", "offset": [4962, 4977]}, {"key": "terms-of", "type": "clause", "offset": [5011, 5019]}, {"key": "the-customer-may", "type": "clause", "offset": [5108, 5124]}, {"key": "from-time-to-time", "type": "clause", "offset": [5131, 5148]}, {"key": "provided-that", "type": "clause", "offset": [5150, 5163]}, {"key": "scope-of-the", "type": "clause", "offset": [5197, 5209]}, {"key": "required-by-law", "type": "definition", "offset": [5272, 5287]}, {"key": "court-of-competent-jurisdiction", "type": "definition", "offset": [5301, 5332]}, {"key": "governmental-or-regulatory-body", "type": "definition", "offset": [5346, 5377]}, {"key": "the-united-kingdom", "type": "clause", "offset": [5588, 5606]}, {"key": "european-economic-area", "type": "clause", "offset": [5610, 5632]}, {"key": "complying-with", "type": "clause", "offset": [5647, 5661]}, {"key": "the-provisions-of-the", "type": "clause", "offset": [5662, 5683]}, {"key": "pursuant-to-the", "type": "definition", "offset": [5862, 5877]}, {"key": "specific-instructions", "type": "clause", "offset": [6076, 6097]}, {"key": "without-undue-delay", "type": "definition", "offset": [6165, 6184]}, {"key": "if-the-supplier", "type": "clause", "offset": [6185, 6200]}, {"key": "personal-data-breach", "type": "definition", "offset": [6222, 6242]}, {"key": "relating-to", "type": "definition", "offset": [6352, 6363]}, {"key": "ability-to", "type": "definition", "offset": [6449, 6459]}, {"key": "data-subject-request", "type": "definition", "offset": [6470, 6490]}, {"key": "reasonable-assistance", "type": "definition", "offset": [6666, 6687]}, {"key": "assist-the", "type": "clause", "offset": [6772, 6782]}, {"key": "compliance-with-the", "type": "clause", "offset": [6829, 6848]}, {"key": "obligations-under-the", "type": "clause", "offset": [6860, 6881]}, {"key": "with-respect-to", "type": "clause", "offset": [6910, 6925]}, {"key": "supervisory-authorities", "type": "clause", "offset": [6945, 6968]}, {"key": "provide-the", "type": "clause", "offset": [6991, 7002]}, {"key": "cooperation-and-assistance", "type": "clause", "offset": [7028, 7054]}, {"key": "the-gdpr", "type": "definition", "offset": [7141, 7149]}, {"key": "data-protection-impact-assessment", "type": "definition", "offset": [7165, 7198]}, {"key": "to-the-services", "type": "clause", "offset": [7207, 7222]}, {"key": "access-to-the", "type": "clause", "offset": [7280, 7293]}, {"key": "relevant-information", "type": "clause", "offset": [7294, 7314]}, {"key": "such-information", "type": "definition", "offset": [7338, 7354]}, {"key": "available-to", "type": "definition", "offset": [7358, 7370]}, {"key": "disclosure-of", "type": "clause", "offset": [7527, 7540]}, {"key": "to-customer", "type": "clause", "offset": [7552, 7563]}, {"key": "information-regarding", "type": "clause", "offset": [7700, 7721]}, {"key": "processing-activities", "type": "clause", "offset": [7737, 7758]}, {"key": "systems-and-procedures", "type": "clause", "offset": [7957, 7979]}, {"key": "in-the-case", "type": "clause", "offset": [8048, 8059]}, {"key": "security-restrictions", "type": "clause", "offset": [8141, 8162]}, {"key": "customers-and-clients", "type": "clause", "offset": [8281, 8302]}, {"key": "commercially-sensitive-information", "type": "clause", "offset": [8342, 8376]}, {"key": "business-and-operations", "type": "clause", "offset": [8432, 8455]}, {"key": "time-expended", "type": "clause", "offset": [8493, 8506]}, {"key": "professional-services-rates", "type": "clause", "offset": [8574, 8601]}, {"key": "made-available", "type": "clause", "offset": [8618, 8632]}, {"key": "upon-request", "type": "definition", "offset": [8649, 8661]}, {"key": "commencement-of", "type": "clause", "offset": [8777, 8792]}, {"key": "the-parties-shall", "type": "clause", "offset": [8804, 8821]}, {"key": "mutually-agree", "type": "definition", "offset": [8822, 8836]}, {"key": "duration-of-the-audit", "type": "definition", "offset": [8863, 8884]}, {"key": "appropriate-technical-and-organisational-measures", "type": "clause", "offset": [8920, 8969]}, {"key": "nature-and-purposes-of-the-processing", "type": "clause", "offset": [8995, 9032]}, {"key": "security-of-the", "type": "clause", "offset": [9088, 9103]}, {"key": "loss-or-destruction", "type": "clause", "offset": [9243, 9262]}, {"key": "the-security", "type": "clause", "offset": [9309, 9321]}, {"key": "the-personal-data", "type": "definition", "offset": [9393, 9410]}, {"key": "be-protected", "type": "clause", "offset": [9414, 9426]}, {"key": "subject-to-the", "type": "definition", "offset": [9592, 9606]}, {"key": "summary-of-the", "type": "clause", "offset": [10137, 10151]}, {"key": "schedule-4", "type": "definition", "offset": [10219, 10229]}, {"key": "to-this-agreement", "type": "clause", "offset": [10230, 10247]}, {"key": "details-of", "type": "clause", "offset": [10257, 10267]}, {"key": "opportunity-to-review", "type": "clause", "offset": [10350, 10371]}, {"key": "offered-by", "type": "definition", "offset": [10563, 10573]}, {"key": "supplier-reserves", "type": "clause", "offset": [10754, 10771]}, {"key": "the-right", "type": "clause", "offset": [10772, 10781]}, {"key": "without-notice", "type": "definition", "offset": [10834, 10848]}, {"key": "for-the-customer", "type": "clause", "offset": [10936, 10952]}, {"key": "supplier-to-comply", "type": "clause", "offset": [11170, 11188]}, {"key": "in-particular", "type": "clause", "offset": [11277, 11290]}, {"key": "period-of", "type": "clause", "offset": [11313, 11322]}, {"key": "notification-of", "type": "clause", "offset": [11346, 11361]}, {"key": "reasonable-grounds", "type": "definition", "offset": [11423, 11441]}, {"key": "right-to-terminate-this-agreement", "type": "clause", "offset": [11486, 11519]}, {"key": "other-party", "type": "definition", "offset": [11534, 11545]}, {"key": "without-liability", "type": "clause", "offset": [11571, 11588]}, {"key": "acting-reasonably", "type": "clause", "offset": [11819, 11836]}, {"key": "not-offer", "type": "clause", "offset": [11890, 11899]}, {"key": "security-and-protection", "type": "clause", "offset": [11922, 11945]}, {"key": "the-nature-and-purpose-of-the-processing", "type": "clause", "offset": [12009, 12049]}, {"key": "additional-security-measures", "type": "clause", "offset": [12122, 12150]}, {"key": "to-offer", "type": "definition", "offset": [12197, 12205]}, {"key": "cost-and-expense", "type": "clause", "offset": [12291, 12307]}, {"key": "agree-to", "type": "clause", "offset": [12502, 12510]}, {"key": "additional-costs", "type": "definition", "offset": [12515, 12531]}, {"key": "associated-with", "type": "definition", "offset": [12532, 12547]}, {"key": "such-security", "type": "definition", "offset": [12548, 12561]}, {"key": "either-party-may-terminate", "type": "clause", "offset": [12572, 12598]}, {"key": "prior-written-notice", "type": "definition", "offset": [12626, 12646]}, {"key": "measures-to", "type": "clause", "offset": [12720, 12731]}, {"key": "any-loss", "type": "definition", "offset": [13000, 13008]}, {"key": "harm-or-damage", "type": "clause", "offset": [13010, 13024]}, {"key": "caused-by", "type": "clause", "offset": [13073, 13082]}, {"key": "failure-to-adopt", "type": "clause", "offset": [13117, 13133]}, {"key": "for-the-avoidance-of-doubt", "type": "clause", "offset": [13290, 13316]}, {"key": "free-of-charge", "type": "clause", "offset": [13403, 13417]}, {"key": "pursuant-to-clause", "type": "clause", "offset": [13419, 13437]}], "samples": [{"hash": "5rfO5G6IznB", "uri": "/contracts/5rfO5G6IznB#customer-personal-data", "label": "Software as a Service Agreement", "score": 31.3729019165, "published": true}], "size": 3, "hash": "5379bcdb28ef961447800cfb7dc68b9d", "id": 9}, {"snippet": "RingCentral does not intentionally collect or process any special categories of data in the provision of its Services. Under the DPA, the Customer agrees not to provide special categories of data to RingCentral at any time.", "snippet_links": [{"key": "special-categories-of-data", "type": "clause", "offset": [58, 84]}, {"key": "provision-of", "type": "clause", "offset": [92, 104]}, {"key": "the-customer-agrees", "type": "clause", "offset": [134, 153]}, {"key": "to-provide", "type": "clause", "offset": [158, 168]}, {"key": "at-any-time", "type": "clause", "offset": [211, 222]}], "samples": [{"hash": "giYGvmJ3JII", "uri": "/contracts/giYGvmJ3JII#customer-personal-data", "label": "Master Services Agreement", "score": 26.270362854, "published": true}, {"hash": "45vP0H0yP2", "uri": "/contracts/45vP0H0yP2#customer-personal-data", "label": "Master Services Agreement", "score": 26.2635173798, "published": true}], "size": 2, "hash": "0b131fff2239fdca758d35e2ce1e615c", "id": 10}], "next_curs": "Cl8SWWoVc35sYXdpbnNpZGVyY29udHJhY3RzcjsLEhZDbGF1c2VTbmlwcGV0R3JvdXBfdjU2Ih9jdXN0b21lci1wZXJzb25hbC1kYXRhIzAwMDAwMDBhDKIBAmVuGAAgAA==", "clause": {"children": [["", ""], ["licence", "LICENCE"], ["personnel", "PERSONNEL"], ["acceptance", "ACCEPTANCE"], ["minimum-term", "MINIMUM TERM"]], "title": "Customer Personal Data", "parents": [["confidential-information", "CONFIDENTIAL INFORMATION"], ["service-in-the-united-states", "Service in the United States"], ["services", "Services"], ["controls-policies-and-procedures", "Controls Policies and Procedures"], ["roles-of-the-parties", "Roles of the Parties"]], "size": 106, "id": "customer-personal-data", "related": [["processing-of-customer-personal-data", "Processing of Customer Personal Data", "Processing of <strong>Customer Personal Data</strong>"], ["processing-personal-data", "Processing Personal Data", "Processing Personal Data"], ["your-personal-data", "Your Personal Data", "Your Personal Data"], ["personal-data", "Personal Data", "Personal Data"], ["personal-data-processing", "Personal Data Processing", "Personal Data Processing"]], "related_snippets": [], "updated": "2025-07-23T06:00:56+00:00"}, "json": true, "cursor": ""}}