Data Processing and Security Addendum This Data Processing Addendum (“DPA“) is entered into between Harri (USA) LLC (“Vendor“), and the counterparty listed in the signature block below (“Client“) (each, a “Party” and collectively, the “Parties“). This DPA supplements and forms part of the Master Services Agreement (the “Agreement“) in which Vendor Processes Client Personal Data (defined below) from or on behalf of Client. This DPA will be effective as of the last signature date set forth below (the “Effective Date“). Capitalised terms not otherwise defined in this DPA shall have the meanings ascribed to them in the Agreement.
- Definitions. “Affiliate” means a legal entity that controls, is controlled by, or is under common control with another legal entity. As used in this definition, “control” means ownership of, control of, or power to vote twenty-five (25) per cent or more of the outstanding shares of any class of voting security of the entity, directly or indirectly, or acting through one or more other persons.”Business Purpose” means the limited and specified Services described in the Agreement and any Statement of Work, or any other purpose specifically identified in Exhibit 1.”Client Personal Data” means any Personal Data obtained by or provided to Vendor and Processed by Vendor (or a Sub-processor) in the course of providing the Services under the Agreement.”Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Client Personal Data transmitted, stored or otherwise processed. “Data Protection Laws” means, to the extent applicable, all federal and state laws and regulations relating to the Processing, protection, or privacy of Client Personal Data. “Law” or “Laws” means all applicable federal, country, state, provincial, regional, territorial or local laws, and other laws, rules, and regulations (including, but not limited to, Data Protection Laws), ordinances, interpretive letters, and other official releases of or by any authority, decrees, orders, and codes (including any requirements for permits, certificates, approvals, and inspections), as the same are promulgated, supplemented, and/or amended from time to time. “Personal Data” means any data or information that: (i) identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual, household, or device; or (ii) is otherwise “personal information”, “personally identifiable information”, “personal data”, or similarly defined data or information under applicable Data Protection Laws. “Privacy Rights Request” means an individual’s valid request to exercise their privacy rights under applicable Data Protection Laws. “Sub-processor” means any person (including any entity or individual but excluding an employee of Vendor) appointed by or on behalf of Vendor to Process Client Personal Data under the Agreement. The terms “Business“, “Controller“, “Processing“, “Processor“, “Sell“, “Share“, and “Service Provider” shall have the same meaning assigned to them under applicable Data Protection Laws. The term “Controller” is deemed to include “Business” and the term “Processor” is deemed to include “Service Provider”.
- Roles. Client and Vendor acknowledge and agree that to the extent Data Protection Laws apply to the Processing of Client Personal Data under the Agreement, Client is the Controller, and Vendor is the Processor. For the avoidance of doubt, this DPA does not relieve either Party from the liability imposed on it under applicable Data Protection Laws by virtue of its role in the Agreement and this DPA.
- Client Obligations. Client has the sole responsibility for the accuracy, quality, and legality of Client Personal Data and the means by which Client acquires Client Personal Data and shares Client Personal Data with Vendor. Client will use the Services in compliance with all applicable Laws. Client represents and warrants that: (i) it provides and shall provide all notices as may be required to inform individuals about the Processing and their rights provided by and in compliance with applicable Data Protection Laws; and (ii) it has collected all consents and confirmations and/or opt-outs as may be required for Processing and/or transfer of Personal Data under applicable Data Protection Laws.
- Vendor Processing of Client Personal Data.
- Vendor will only Process Client Personal Data on behalf of Client for Business Purposes, unless required to do so by applicable Law, in which case Vendor shall, without undue delay, notify Client of such requirement. The instructions set forth in this DPA, the Agreement, any SOW, or other duly documented instructions are Client’s complete instructions to Vendor for the Processing of Client Personal Data. The instructions are more fully set forth in Exhibit 1. The Parties acknowledge and agree that Client is disclosing Client Personal Data to Vendor only for Business Purposes.
- Vendor will not: (i) retain, use, or disclose Client Personal Data for any purpose, including, without limitation, any commercial purpose other than Business Purposes, unless expressly permitted by Data Protection Laws; (ii) Sell or Share Client Personal Data; (iii) retain, use, or disclose Client Personal Data for any purpose, outside of the Parties’ direct business relationship, unless expressly permitted by Data Protection Laws; or (iv) combine or update Client Personal Data with Personal Data collected from its own interaction with an individual or received from another source, unless expressly permitted by Data Protection Laws. Vendor certifies that it understands these provisions.
- Vendor shall, without undue delay, but not later than twenty-four (24) hours from receipt, refer any requests received from regulators or other governmental entities regarding Client Personal Data or the privacy practices of Vendor to Client. Unless otherwise required by applicable Law, Vendor shall not refer to or disclose any Client Personal Data without Client’s prior written consent.
- Vendor shall notify Client, without undue delay, but within not more than five (5) days, if it determines that it is no longer able to comply with its obligations under applicable Data Protection Laws.
- Vendor shall comply with all applicable Data Protection Laws in the Processing of Client Personal Data and provide the same level of privacy protection as required of Client under applicable Data Protection Laws.
- Assistance. Vendor shall provide reasonable assistance to Client with (i) complying with Client’s obligations in relation to the security of Processing Client Personal Data and notification of a Data Breach, (ii) any data protection assessments, and (iii) any investigations by competent data privacy authorities, in each case solely in relation to Processing of Client Personal Data by and taking into account the nature of the Processing and information available to Vendor. Vendor shall provide to Client all information reasonably necessary to demonstrate compliance with applicable Data Protection Laws.
- Individual Requests. Upon receipt of an individual’s Privacy Rights Request, Vendor shall inform Client of such request and instruct the individual to submit the request directly to Client. Vendor will not respond to an individual’s Privacy Rights Request absent Client’s explicit instruction unless Vendor is required to respond under applicable Law, in which case Vendor will respond to the minimum extent necessary to comply with such law. To the extent Client is unable to comply with an individual’s Privacy Rights Request by using the self-service features available through the Services, Vendor shall provide reasonable assistance and information necessary to enable Client to comply with such request, taking into account the nature of the Processing and the information available to Vendor. Notwithstanding Client’s other obligations set forth in the Agreement and this DPA, Client acknowledges and agrees that it is solely responsible for complying with its own retention obligations under applicable Law.
- Technical and Organisational Measures. Vendor will provide at least the same level of privacy protection as required by applicable Data Protection Laws. Vendor represents and warrants that it has implemented and maintains appropriate technical and organisational measures to ensure a level of security commensurate to the risk to Client Personal Data as set forth in Exhibit 2. Such measures include taking appropriate administrative, physical, organisational, and technical safeguards to prevent and guard against the unauthorised or accidental access, disclosure, destruction, loss, processing, damage, or alteration of Client Personal Data. Client represents and warrants, as of the Effective Date, to have evaluated the security measures implemented by Vendor as providing an appropriate level of protection for the Client Personal Data, taking into account the risk associated with the Processing of such information.
- Vendor Personnel. Vendor shall ensure that its personnel engaged in the Processing of Client Personal Data are informed of the confidential nature of Client Personal Data and are subject to a duty of confidentiality with respect to such data.
- Audit.
- Client will have the right to take reasonable and appropriate steps to ensure that Vendor uses Client Personal Data in a manner consistent with Client’s obligations under applicable Data Protection Laws. Subject to the terms in this Section 9, Vendor shall: (i) make available to Client all information reasonably necessary to demonstrate compliance with this DPA and applicable Data Protection Laws; and (ii) allow Client (or an auditor appointed by Client) to conduct reasonable audits of Vendor’s systems to the extent such systems relate to the Processing of Client Personal Data by Vendor. Client cannot exercise this right more than once per any twelve (12) month period during the Term (defined below). Any audit performed pursuant to this Section 9 will be conducted under a confidentiality agreement and any information or report derived from such audit will be deemed Vendor’s Confidential Information.
- To request an audit, Client must submit a detailed audit plan to Vendor at least thirty (30) days in advance of the proposed audit date. Vendor will review the proposed audit plan and work cooperatively with Client to agree on a final audit plan. All such audits must be conducted subject to the final audit plan agreed to by the Parties. Notwithstanding the foregoing, the Parties agree that any such audit will be: (i) conducted during Vendor’s normal business hours; and (ii) limited to systems that relate to the Processing of Client Personal Data by Vendor.
- Upon Client’s request to perform an audit, to the extent permitted by applicable Data Protection Laws, Vendor may elect to retain a qualified and independent assessor to perform such audit, using an appropriate and accepted control standard or framework and assessment procedure for such assessments.
- Client shall, without undue delay, notify Vendor of any non-compliance discovered during the audit.
- Client shall be responsible and fully liable for the actions and omissions of its personnel and authorised representatives while on Vendor’s premises and/or inspecting Vendor’s systems and facilities. Client shall bear the costs for any audit initiated by Client.
- Upon notification of unauthorised use of Client Personal Data, Client shall have the right to take reasonable and appropriate steps to remediate the unauthorised use, and in doing so, Client and Vendor shall make reasonable efforts to mutually agree on steps to remediate and ensure Client Personal Data is used appropriately.
- Data Breach. Vendor shall, to the extent permitted by Law, notify Client without undue delay and, where feasible, within twenty-four (24) hours after Vendor becomes aware of a Data Breach affecting Client Personal Data, provide Client with necessary information to allow Client to meet any obligations to report or inform individual(s) and/or regulators of the Data Breach under applicable Data Protection Laws. The notification, at a minimum, will include: (i) the types of Client Personal Data that were or are reasonably believed to be the subject of the Data Breach; (ii) the date or estimated date of the Data Breach; (iii) a general description of the Data Breach; and (iv) the steps Vendor has taken to remediate the Data Breach. Vendor shall continuously supplement the information provided to Client as additional information becomes available to it regarding the Data Breach. If it is determined that Vendor or a Sub-processor is responsible for the Data Breach, Vendor shall review the applicable technical and organisational measures and, if needed, make appropriate changes to prevent such Data Breach from occurring in the future.
- Sub-processing.
- Client hereby approves the Sub-processors currently engaged by Vendor and that are listed in Exhibit 3.
- Vendor shall provide written notice to Client within thirty (30) calendar days of engaging a new Sub-processor, and Client will have thirty (30) calendar days to provide written notice of its objection to such Sub-processor. Upon Client’s objection, Vendor shall use reasonable efforts to change the provision of the Services in a manner that avoids the use of the proposed Sub-processor. Where such a change cannot be made, notwithstanding anything in the Agreement, Client may, by written notice to Vendor, terminate the Agreement to the extent it relates to the Services, which require use of the proposed Sub-processor. In any event, Vendor will not provide Client Personal Data to the objected-to Sub-processor unless and until Client’s objections are resolved.
- If the Sub-processor is engaged without objection from Client, Vendor shall enter into a written agreement with each Sub-processor that complies with Data Protection Laws and imposes data protection obligations that are no less protective of Client Personal Data than Vendor’s obligations under this DPA. Vendor will remain responsible for Sub-processors’ compliance with the obligations of this DPA and for any acts or omissions of such Sub-processor as if they were Vendor’s acts or omissions.
- Deletion or Return of Client Personal Data. At the choice of Client, Vendor shall delete or return all Client Personal Data (including copies) upon expiration or termination of the Agreement. This requirement does not apply to the extent Vendor is required by applicable Law to retain some or all of the Client Personal Data, or to Client Personal Data it has archived on back-up systems; provided, however, Vendor shall continue to protect the security and confidentiality of such data until the data is no longer in Vendor’s possession.
- Deidentified Data. To the extent Vendor collects on behalf of Client, or receives from Client deidentified data or pseudonymised data (as such terms are defined under applicable Data Protection Laws) (collectively, “D&P Data“) or to the extent the Agreement permits Vendor to render Client Personal Data into D&P Data, Vendor shall implement such deidentification or pseudonymisation in accordance with applicable Data Protection Laws. In addition, for deidentified data, Vendor shall: (i) take reasonable measures to ensure that the information cannot be linked, attributed, or otherwise associated with an individual, household, or device (including without limitation: (a) implement and maintain technical and administrative safeguards that prohibit reidentification of the deidentified data; (b) implement and maintain business processes that specifically prohibit reidentification of the deidentified data and prevent inadvertent release of the deidentified data; (c) periodically reassess technical safeguards and processes to ensure that they are still adequate to prevent reidentification of and prohibit inadvertent release of the deidentified data); (ii) publicly commit to maintain and use the deidentified data in deidentified form and not to attempt to reidentify the deidentified data; and (iii) contractually obligate any recipients of the deidentified data to comply with all provisions of this Section 13.
- General.
- Indemnification. Indemnification under this DPA is subject to the indemnification section(s) of the Agreement.
- Limitation of Liability. NOTWITHSTANDING ANYTHING TO THE CONTRARY CONTAINED IN THIS DPA OR THE AGREEMENT, IN NO EVENT SHALL EITHER PARTY BE LIABLE TO THE OTHER PARTY FOR ANY INDIRECT, INCIDENTAL, SPECIAL OR CONSEQUENTIAL DAMAGES, INCLUDING DAMAGES FOR LOSS OF PROFITS, DATA OR USE, INCURRED BY THE OTHER PARTY OR ANY THIRD PARTY, WHETHER IN AN ACTION IN CONTRACT OR TORT, EVEN IF SUCH PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. Notwithstanding the foregoing, no provision of this DPA shall be deemed to waive or limit the rights of an individual or competent regulatory authority under applicable Data Protection Laws.
- Order of Precedence. In the event of a conflict between the terms of this DPA, SOW(s), and the Agreement with respect to the subject matter herein, the following order of precedence shall apply: (i) this DPA; (ii) the Agreement; (iii) SOW(s).
- Changes in Data Protection Laws. If any amendment is required for this DPA as a result of a change in applicable Law (including Data Protection Laws), then either Party may provide written notice to the other Party of that change in Law. The parties will discuss and negotiate in good faith any necessary amendment to the Agreement or this DPA to address such changes. If either Party gives notice under this Section 14, the Parties shall without undue delay discuss the proposed variations and negotiate in good faith with a view to agreeing and implementing those or alternative variations designed to address the requirements identified in the notice as soon as is reasonably practicable. If the Parties fail to amend the Agreement or this DPA in accordance with this Section 14, the notifying Party may terminate the Agreement upon written notice to the other Party.
- Term. The term (“Term“) of this DPA will commence on the Effective Date and end simultaneously and automatically at the later of: (i) the termination of the Agreement; or (ii) when Vendor is no longer in possession of any Client Personal Data.
- Jurisdiction and Governing Law. The Parties hereby submit to the choice of law and jurisdiction stipulated in the Agreement with respect to any disputes or claims howsoever arising under this DPA, including disputes regarding its existence, validity or termination, or the consequences of its nullity.
- Survival. The obligations set forth herein will survive termination of the Agreement and DPA for as long as Vendor Processes or stores Client Personal Data.
- Severability. Should any provision of this DPA be deemed invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall be either amended as necessary to ensure its validity and enforceability, while preserving the Parties’ intentions as closely as possible or, if this is not possible, construed in a manner as if the invalid or unenforceable part had never been contained therein.
- Exhibits. All Exhibits to this DPA are hereby incorporated by reference into, and made a part of, this DPA.
EXHIBIT 1 Description of Processing Categories of individuals whose Personal Data is Processed:
Categories of Client Personal Data Processed:
- Name
- Email
- Phone number
- Home address
- Gender
- Date of Birth
- Social Security Number
- Hire date
- Position of employment
- Wage rate
- Wage type (hourly, salaried)
- Bank account and routing numbers
- Biometric data (for use only in Biometric clock-in, if selected by Client)
The frequency of the Processing: Continuous for as long as Client uses the Services. Nature of the Processing: Vendor will collect, receive, store, retain, transmit, delete (as provided in this DPA, the Agreement, and/or SOW(s)), use, and otherwise Process Client Personal Data as needed to provide the Services.Specifically, the process involves the following:
- Cloud-based Storage: Hosting and storage of data on our secure AWS cloud infrastructure/instance.
- Automated Computation: Algorithmic processing to calculate scheduling availability, sales and cost estimates, candidate scoring, etc.
- Data Transfer: Transmission of data to third-party integrations (e.g., payroll providers, background check services, etc.) as requested by Client.
- Display and Reporting: Visualising data within the Harri UI for Client’s use.
Purpose(s) of the Processing: The purpose of the Processing is to facilitate Vendor’s provision of the Services to Client in accordance with the Agreement, this DPA, any SOW(s), and applicable Law. The period for which the Client Personal Data will be retained, or, if that is not possible, the criteria used to determine that period: Vendor will Process Client Personal Data for as long as required to provide the Services. In the event of contract termination, Vendor will retain Client Personal Data for up to seven (7) years from the termination date, unless a written request is provided by Client to destroy Client’s Personal Data. EXHIBIT 2 Technical and Organisational Measures Vendor implements and maintains policies and procedures that include appropriate technical and organisational measures to ensure a level of security appropriate to: (i) protect the security, confidentiality, and integrity of Client Personal Data; and (ii) protect against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of Client Personal Data. Vendor regularly monitors, evaluates, and assesses the effectiveness of the technical and organisational measures implemented. Vendor’s technical and organisational measures include: Risk Management: Vendor maintains a risk management framework and conducts a yearly risk assessment of its environment and systems to understand its risks and applies appropriate controls to manage and mitigate risks before processing Client Personal Data. Access Controls: Vendor implements the following access controls with respect to Client Personal Data:
- Access to Client Personal Data is restricted to Vendor personnel authorised to have such access in accordance with their job function and based on the principle of “least privilege.”
- Vendor maintains account creation and deletion procedures, with appropriate approvals, for each personnel role.
- Vendor maintains a record of personnel security privileges for those personnel that have access to Client Personal Data.
- Vendor reviews personnel access rights at regular intervals and makes adjustments as necessary.
- Each account from which Client Personal Data can be accessed is attributable to a single user with a unique ID which is authenticated through a password or another authentication method.
- Vendor uses industry-standard practices to identify and authenticate users who attempt to access its information systems, including multi-factor authentication.
- Passwords are renewed regularly.
- Passwords are required to conform to very strong password control parameters. Passwords are required to contain: (i) eight alphanumeric characters; (ii) upper and lowercase letters; (iii) one number; and (iv) one special character.
Physical Security: Vendor implements the following physical security measures with respect to Client Personal Data:
- All devices are secured with a password/PIN screen lock with the automatic activation feature. Vendor personnel are required to lock the screen or log off when a device is unattended.
- Access to locations where Client Personal Data is processed or stored is limited to authorised personnel only.
- Visitors to locations where Client Personal Data is processed or stored are required to sign a visitor register and are escorted at all times.
- Physical access logs detailing access are retained.
- Physical documents that contain Client Personal Data are required to be kept in a locked office or file cabinet when not in use.
- Vendor facilities are monitored 24/7.
Network Security: Vendor’s network employs the following safeguards:
- Vendor maintains security controls designed to detect and mitigate attacks by use of network layer firewalls and intrusion detection/prevention systems (IDS/IPS).
- All network traffic passes through firewalls, which are monitored at all times.
- Vendor maintains management procedures that provide a consistent approach for controlling, implementing, and documenting changes for information systems.
- Endpoint protection, including anti-virus and anti-malware, is implemented on all endpoints.
- When remote connectivity to Vendor’s network is required, Vendor uses VPN servers for the remote access with encrypted connection of 256-bit encryption.
- Vendor employs multi-factor authentication for administrative interfaces and for all access to Vendor systems and applications.
Vulnerability and Patch Management: All Vendor devices are configured for automatic patching and application security patches are installed without unreasonable delay. Vendor conducts regular testing and monitoring of the effectiveness of safeguards, controls, systems, including penetration testing. Encryption: Vendor encrypts Client Personal Data as follows:
- Vendor shall use encryption certified against U.S. Federal Information Processing Standard 140-2, Level 2, or equivalent industry standard.
- All emails between Vendor and Client shall utilise Transport Layer Security (TLS) if transmitting Client Personal Data.
- Vendor will encrypt all Client Personal Data that resides on the Vendor’s systems, servers, backups, or other information systems, including Client Personal Data that resides on the systems and servers of any third-party with which the Vendor has subcontracted to store electronic data.
- Vendor shall encrypt at rest using solutions that are certified against U.S. Federal Information Processing Standard 140-2, Level 2, or equivalent industry standard, and verify that the encryption keys and any keying material are not stored with any associated data.
- In the event Vendor uses a cloud-based environment to store Client Personal Data, Vendor must only use United-States based providers whose dedicated cloud-based environment encrypts data at rest.
- In the event that Client Personal Data could be transferred to a mobile device, tablet, or laptop, Vendor implements, monitors, and maintains encryption and information leakage prevention tools using solutions that are certified against the U.S. Federal Information Processing Standard 140-2, Level 2, or equivalent industry standard, and verifies that the encryption keys and keying material are not stored with any associated data.
Personnel: Vendor employs the following administrative safeguards for its personnel:
- All Vendor personnel undergo privacy and data security training, upon hiring, and annually thereafter.
- Vendor informs its personnel of relevant security procedures and their roles and ensure that all personnel sign a confidentiality agreement or be subject to statutory obligations of confidentiality.
- Personnel that fail to comply with Vendor’s information security policies, practices, and procedures may be subject to disciplinary action, up to and including termination.
- Vendor performs background checks on personnel where legally permissible.
- Vendor maintains procedures for revoking or changing access in response to termination or changes in job functions.
Sub-processors: Vendor employs the following safeguards with respect to any Sub-processors that access, store, or transmit Client Personal Data on its behalf:
- Due diligence is conducted on all Sub-processors who may gain access to, store, or transmit Client Personal Data in accordance with the DPA.
- Sub-processor physical and electronic access to Client Personal Data is terminated no later than the date of separation or to a role no longer requiring access to Client Personal Data.
- Vendor has agreements with all Sub-processors who may gain access to, store, or transmit Client Personal Data that requires compliance with Vendor’s information security requirements.
Business Continuity: Vendor maintains a disaster recovery and business continuity programme for systems and facilities used to provide services. Such programme is designed to ensure that Vendor is able to continue providing services after its systems are damaged, destroyed, or otherwise unavailable for use. Vendor’s disaster recovery and business continuity programme is tested on an annual basis. Incident Management: Vendor maintains an incident management plan designed to promptly identify, prevent, investigate, mitigate, and address the impact of security incidents. EXHIBIT 3 Sub-processors Vendor Sub-processors: The list of all Harri sub-processors can be found here: https://go.harri.com/subprocessors