Introduction
This Data Processing Addendum (the "DPA") supplements and is subject to the Terms and Conditions of Service or other executed agreement (the "Terms") between TwinKnowledge Incorporated ("Company") and a business customer ("Customer") governing Company's provision of the Services. This DPA is incorporated into and forms part of the Agreement by reference and does not require separate execution; Customer's execution of an Order Form that incorporates the Terms shall constitute Customer's acceptance of this DPA.
This DPA sets out the terms that apply when Customer Personal Data is Processed by Company under the Terms and ensures that such Processing is conducted in accordance with Data Protection Legislation. To the extent of any conflict among the Terms, this DPA, and the Privacy Policy, the order of precedence shall be: (i) the Terms, (ii) this DPA, and (iii) the Privacy Policy.
1. Definitions
Customer Personal Data means Personal Data included in documents or workspaces created by Customer or its Authorized Users using the Services. It does not include Personal Data that Company collects to administer the Services.
Controller and Processor have the meanings given by applicable Data Protection Legislation. GDPR means Regulation (EU) 2016/679. Standard Contractual Clauses (SCCs) means the clauses annexed to EU Commission Implementing Decision 2021/914. UK Addendum means the addendum to the SCCs issued by the UK Information Commissioner (version B1.0, in force March 21, 2022).
Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data. All capitalized terms not defined in this DPA have the meaning given in the Terms or under Data Protection Legislation.
2. Processing of data
2.1 Scope and purpose
This DPA applies only where and to the extent Data Protection Legislation governs Company's Processing of Customer Personal Data on behalf of Customer in the course of providing the Services. Company will not disclose or otherwise make available to a third party Customer Personal Data except to provide the Services or as expressly permitted by the Terms or this DPA.
2.2 Processor and Controller responsibilities
As between the parties: (a) Company is the Processor of Customer Personal Data; (b) Customer is the Controller; and (c) each party will comply with the obligations applicable to it under the Data Protection Legislation.
2.4 Customer instructions
Customer instructs Company to Process Customer Personal Data for all activities described in the Terms, this DPA, or any applicable Order, and to comply with other reasonable instructions consistent with the Terms. Customer has sole responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which it was obtained.
2.5 Compliance with instructions
Company will only Process Customer Personal Data in accordance with Customer's instructions and will treat it as Proprietary Information. Company will immediately inform Customer if, in Company's opinion, an instruction infringes Data Protection Legislation, and may suspend Processing until the instruction is modified.
2.6 – 2.7 Data subject requests
Company provides Customer the ability to access, correct, amend or delete Customer Personal Data contained in the Services, and will promptly comply with reasonable requests to assist. Company will, to the extent legally permitted, promptly notify Customer if it receives a request from a Data Subject and forward such requests to Customer, who will be responsible for responding using the functionality of the Services.
2.8 – 2.10 Subprocessors
Customer generally authorizes the use of subprocessors and approves the list available upon written request to trust@twinknowledge.com or online at the sub-processors list. When Company engages a new subprocessor, it will notify Customer at least 30 days before that subprocessor Processes any Customer Personal Data and give Customer the opportunity to object on reasonable data protection grounds. Company remains liable for the acts and omissions of its subprocessors and imposes data protection obligations on them at least equivalent to those in this DPA.
2.11 Audit rights
Upon Customer's written request no more than once per year, Company will provide a copy of its most recent third-party audits or certifications (or summaries) so that Customer may reasonably verify compliance. Where required by Data Protection Legislation, Company will allow Customer, or a mutually agreed independent auditor, to conduct an audit no more than once per year upon 30 days' notice. Any audits are at Customer's sole cost and expense.
3. GDPR
This section only applies to Company's Processing of Customer Personal Data subject to GDPR. Company will take reasonable measures to assist Customer in conducting a data protection impact assessment and related consultations with any Supervisory Authority.
International transfers. The parties will transfer Customer Personal Data internationally only pursuant to a transfer mechanism valid under Data Protection Legislation. Where the SCCs apply, Company acts as "data importer" and Customer as "data exporter." Where more than one transfer mechanism is available for transfers from the EEA, UK, and/or Switzerland to countries without an adequate level of protection, a single valid mechanism will apply, such as the Data Privacy Framework, the SCCs, and/or the UK Addendum. If a legal instrument for international transfers is invalidated or replaced, the parties will work together in good faith to resolve any non-compliance.
4. U.S. privacy laws
As Company does not currently meet the thresholds established by the CCPA, the CCPA does not apply to Company's Processing of Customer Personal Data under this DPA. If Company meets the applicable thresholds in the future, this section will be updated accordingly. Company agrees to Process Customer Personal Data in compliance with all applicable U.S. Privacy Laws and will not sell or otherwise disclose Customer Personal Data to any third party except as necessary to provide the Services or as required by law. The exchange of Personal Data between the parties does not form part of any monetary or other valuable consideration.
5. Security
Company personnel. Company will inform its personnel engaged in Processing of the confidential nature of the Customer Personal Data and subject them to obligations of confidentiality that survive their engagement.
Third party disclosure. Company will not disclose Customer Personal Data to any third party unless authorized by Customer or required by law. If a government entity or Supervisory Authority demands access, Company will attempt to redirect the requestor to Customer or notify Customer prior to disclosure, unless prohibited by law.
Security measures. Company will implement commercially reasonable technical and organizational measures to safeguard Customer Personal Data, taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of Processing. A description of these measures is set forth in Appendix III or made available upon written request to trust@twinknowledge.com.
6. Security breach
Upon becoming aware of any Security Incident affecting Customer Personal Data, the parties shall notify each other without undue delay and provide timely updates, including the nature of the incident, the categories and number of Data Subjects affected, the likely consequences, and the measures taken or proposed to address it. These obligations do not apply to incidents caused by Customer or Authorized Users, or to unsuccessful attempts that do not compromise security (e.g., unsuccessful log-in attempts, pings, port scans, denial of service attacks).
It is Customer's sole responsibility to maintain accurate contact information and to notify the relevant Supervisory Authority and, when applicable, Data Subjects, as required under Articles 33 and 34 of the GDPR. Company will promptly comply with reasonable requests to assist with such notification requirements.
7. Miscellaneous
Term. This DPA will remain in effect until, and automatically expire upon, deletion of all Customer Personal Data as described in this DPA.
Deletion. Company will delete Customer Personal Data in its possession in accordance with the Terms, subject to its automated deletion schedule and back-up policy, except to the extent required to retain a copy under applicable law.
Modification. Company may amend this DPA with no less than 30 days' prior written notice of any material modifications. Customer's continued use of the Services following the effective date constitutes acceptance. If Customer does not agree, it may provide written notice of non-acceptance prior to the effective date, in which case the prior DPA continues for the remainder of the then-current Term.
Claims & severability. Any claim under this DPA is subject to the limitations and exclusions of liability in the Terms. This DPA is governed by the governing law and jurisdiction provisions in the Terms. If any part is held unenforceable, the remaining parts are unaffected.
Appendices
Appendix I — Annex I to the Standard Contractual Clauses
- Data exporter
- The Customer identified in the applicable Order Form. Role: Controller (Customer Personal Data).
- Data importer
- TwinKnowledge Incorporated, 575 Lexington Ave., New York, NY 10022. Contact: Data Protection Contact, trust@twinknowledge.com. Role: Processor (Customer Personal Data).
- Categories of data subjects
- Authorized Users of the Services (employees, contractors, or other personnel of Customer), and any other individuals whose personal data is included in Customer Data.
- Categories of personal data
- Account information (name, email, password, SSO credentials); natural language prompts and inputs; interaction metadata and AI-generated outputs; usage data (IP addresses, device identifiers, log data, browser type, access times); billing and payment information; and any other personal data included in Customer Data.
- Sensitive data
- The parties do not anticipate the transfer of sensitive data or special categories of personal data. Customer shall not submit such data without Company's prior written consent.
- Frequency of transfer
- Continuous, on an ongoing basis throughout the duration of the Term.
- Nature of processing
- Collection, storage, transmission to third-party AI model providers (solely to process and interpret Customer instructions), use, and deletion of Customer Personal Data to provide the Services.
- Retention period
- For the duration of the Term. Upon termination, Customer Personal Data is available for export for 30 days; returned or destroyed within 60 days upon written request; otherwise destroyed within 90 days with written certification.
- Competent Supervisory Authority
- Determined in accordance with Clause 13 of the SCCs. For UK Data Subjects, the UK Information Commissioner.
Appendix II — List of sub-processors
A list of sub-processors can be found at the sub-processors list or by contacting trust@twinknowledge.com.
Appendix III — Technical and organizational security measures
A description of the technical and organizational security measures implemented by Company to protect Customer Personal Data shall be made available upon written request to trust@twinknowledge.com. Company may update such measures from time to time, provided that any update shall not materially diminish the overall level of security afforded to Customer Personal Data.