Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") forms part of the agreement between Hubroot Solutions LLC ("Hubroot") and the customer using Skkrum ("Customer") where Hubroot processes personal data on Customer's behalf in connection with the Services.
1. Roles and Instructions
For Customer Personal Data processed on Customer's behalf, Customer acts as controller, business, responsible party, data fiduciary, or equivalent role as applicable, and Hubroot acts as processor, service provider, operator, or equivalent role. Hubroot will process Customer Personal Data only to provide and secure the Services, comply with documented lawful instructions, and meet applicable legal obligations.
2. Processing Details
Subject matter: provision of Skkrum communication, collaboration, project, task, file, account, security, support, and related services. Duration: for the term of the Customer's use of the Services plus the applicable deletion and backup period. Categories of data may include identifiers, contact information, profile information, workspace membership, communications, files, project/task information, technical data, and support data. Data subjects may include Customer personnel, contractors, clients, guests, and other authorized users.
3. Confidentiality and Security
Hubroot will ensure persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and will maintain reasonable technical and organizational security measures appropriate to the nature and risk of the processing, including access controls, secure transmission, encryption at rest in supported production environments, logging, authentication safeguards, and incident-response processes.
4. Subprocessors
Customer authorizes Hubroot to use subprocessors to provide the Services. Hubroot will require subprocessors that process Customer Personal Data to be bound by data-protection obligations appropriate to their role. Hubroot will maintain a current subprocessor disclosure and will remain responsible for its obligations under this DPA to the extent required by applicable law.
5. International Transfers
Where applicable law requires safeguards for transfers of Customer Personal Data across borders, the parties will use an available lawful transfer mechanism, contractual safeguard, consent mechanism, adequacy arrangement, or other legally permitted basis.
6. Data Subject Requests
Taking into account the nature of the processing, Hubroot will provide reasonable assistance to Customer in responding to legally valid requests by individuals to exercise privacy rights where Customer cannot reasonably fulfill the request through available Skkrum functionality.
7. Security Incidents
Hubroot will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data where notification is required by applicable law or the parties' agreement. Hubroot will provide reasonably available information necessary for Customer to assess the incident and meet applicable notification obligations.
8. Deletion and Return
At termination or upon a valid instruction, Hubroot will delete or return Customer Personal Data as required by applicable law and the agreement, subject to legitimate retention requirements and normal backup cycles.
9. Compliance Information
Hubroot will make available information reasonably necessary to demonstrate compliance with this DPA and, where required by applicable law and subject to reasonable confidentiality, security, scope, and frequency limitations, cooperate with appropriate assessments or audits.
10. Priority
If this DPA conflicts with the general Terms regarding processing of Customer Personal Data, this DPA controls to the extent of that conflict. Mandatory applicable data-protection law controls over inconsistent contractual provisions.