Skip to content

Creative Force Data Processing Addendum

 

soc-2

Creative Force is SOC 2 Certified

Learn more about SOC 2 ->

This Data Processing Addendum (“Addendum”) is entered into as of the date of the last signature below, (the “Effective Date”), by and between CREATIVEFORCE.IO, INC, a Delaware corporation with its primary place of business at 237 A. St. PMB 48388, San Diego, CA 92101 (“Creative Force”), and the customer using Creative Force’s services (“Customer”) pursuant to the Creative Force Software as a Service Agreement available at https://www.creativeforce.io/legal/saasagreement/, as updated from time to time, or other agreement between Customer and Creative Force governing Customer’s use of the Service, as applicable (“the Agreement”). Creative Force and Customer are hereinafter referred to from time to time individually as “party” and collectively as “parties.”

This Addendum is incorporated into and forms part of the Agreement. The terms used in this Addendum have the meaning set forth in this Addendum. Capitalized terms not otherwise defined herein have the meaning given to them in the Agreement. Except as modified below, the Agreement remains in full force and effect.

How this addendum applies

Creative Force provides services to Customer under the Agreement. Pursuant to the Agreement, Creative Force may from time to time process Personal Data (as defined below) for which Customer may be a “Data Controller” as defined by applicable privacy laws, including the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”). The parties acknowledge that the terms of this Addendum, including the Appendices, are incorporated into and form part of the Agreement. Capitalized terms have the meaning given to them in the Agreement unless defined elsewhere in this Addendum. Where this Addendum uses terms that are defined in Applicable Data Protection Law (defined below), those terms shall have the same meaning as given to those terms (or an equivalent term) in the applicable law.

In the event and to the extent of a conflict between the provisions of the Agreement and this Addendum, this Addendum will prevail. Except as expressly set forth in this Addendum, all other provisions of the Agreement will remain in full force and effect. To the extent that the EU SCCs (defined below) or UK International Data Transfer Agreement (defined below) are incorporated herein, such terms therein shall take precedence over both this Addendum and the Agreement to the extent necessary to resolve the conflict or inconsistency. For the avoidance of doubt, execution of the Agreement shall be deemed to constitute signature and acceptance of this Addendum and any SCCs or UK International Data Transfer Agreement incorporated herein.

1. Definitions

1.1. “Affiliate(s)” means any business entity that, directly or indirectly, through one or more intermediaries, controls, is controlled by, or is under common control with a party to the Agreement. For purposes of this definition, “control” means an ownership, voting, or similar interest representing fifty percent (50%) or more of the total interests then outstanding of the entity in question.

1.2. “Aggregated Statistics” means any data relating to Customer’s use, support, and/or operation of the Services which is used by Creative Force in an aggregated and anonymous manner.

1.3. "Applicable Data Protection Law" means all laws and regulations applicable to the processing of personal data under the Agreement. For the sake of clarity, Applicable Data Protection Law includes, without limitation (1) data protection laws and regulations of the European Union, the European Economic Area and their member states and Switzerland; (2) data protection laws and regulations of the United Kingdom; and (3) data protection laws and regulations of the United States and its individual states.

1.4. “Authorized Users” means individuals who have created an account to access the Services pursuant to the Agreement. Authorized Users include employees and contractors designated by Customer to receive access to the Services as well as employees and contractors of any Affiliates authorized to access the Services under the Agreement.

1.5. “Controller-to-Processor Clauses” means the standard contractual clauses between controllers and processors for Data Transfers (module 2), as approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

1.6. “Customer” means the Customer entities or Affiliates that are party to the Agreement.

1.7. “Customer Account Data” means personal data that relates to Customer’s relationship with Creative Force and for which Creative Force determines the means and purposes of processing.

1.8. “Customer Data” means any personal data that is (i) provided or made available or accessible to Creative Force or its Sub-processors by or on behalf of Customer or a controller for whom Customer acts as a processor; and/or (ii) generated by Creative Force or its Sub-processors in the performance of the Agreement.

1.9. “Data Protection Supervisory Authority” means a supervisory authority or other government body responsible for the administration, implementation, and/or enforcement of Applicable Data Protection Law and includes, without limitation, competent supervisory authorities of the European Union (“EU”) and its member states, the Swiss Federal Data Protection Authority, and the United Kingdom (“UK”) Information Commissioner’s Office.

1.10. “Data Transfer” means any situation in which Customer Data is transferred, either directly or via onward transfer, to a Third Country.

1.11. “Elections” means with respect to the EU SCCs, (i) for purposes clause 9(a), option 2 applies and the specified time period is the time period required under Section 5 (Subprocessing) of this Addendum for notice of change of a Sub-processor; (ii) for purposes of clause 11, the independent dispute resolution option does not apply; (iii) for purposes of clause 17, option 2 is selected, provided if the EU member state in which the data exporter is established does not allow for third-party beneficiary rights, then the law of Ireland shall govern; and (iv) as pertains to clause 18(b), the courts of the EU member state in which the data exporter is established shall be the choice of forum and jurisdiction.

1.12. “EU SCCs” means (i) the Controller-to-Processor Clauses, or (ii) the Processor-to- Processor Clauses, as applicable in accordance with Section 2.1 (Scope and Role of the Parties), including the Elections and on the basis that Appendix 1 of this Addendum operates as Annex I to the EU SCCs and Appendix 2 of this Addendum operates as Annex II to the EU SCCs.

1.13. “European and UK Data Protection Law” means all data protection laws and regulations applicable to Europe, including (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation (“GDPR”); (ii) Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector; (iii) applicable national implementations of (i) and (ii); and (iii) in respect of the United Kingdom (“UK”) any applicable national legislation that replaces or converts in domestic law the GDPR or any other law relating to data and privacy as a consequence of the UK leaving the European Union.

1.14. “Europe” means, for the purposes of this Addendum, the European Union (“EU”), the European Economic Area (“EEA”), and/or their member states, Switzerland, and the United Kingdom (“UK”).

1.15. “Processor-to-Processor Clauses” means the standard contractual clauses between processors for Data Transfers (module 3), as approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

1.16. “Security Incident” means any confirmed or reasonably suspected unauthorized or unlawful breach of security that leads to the accidental or unlawful destruction, loss, or alteration of, or unauthorized disclosure of or access to, Customer Data on systems managed or otherwise controlled by Creative Force.

1.17. “Sensitive Data” means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person’s sex life or sexual orientation, data relating to criminal convictions or offenses, or other information that falls within the definition of “special categories of data” (or an equivalent term) under Applicable Data Protection Law.

1.18. “Services” means the services Creative Force is providing pursuant to the Agreement.

1.19. “Sub-processor” means any person or entity engaged by Creative Force or its Affiliates to perform Creative Force’s obligations under the Agreement.

1.20. “Third Country” means a country outside of Europe or the UK not recognized by the European Commission or the competent UK regulatory authority as providing an adequate level of protection for personal data under European and UK Data Protection Law.

1.21. “UK International Data Transfer Agreement” means the UK International Data Transfer Addendum to the EU SCCs, issued by the UK Information Commissioner, Version B1.0, effective as of 21 March 2022, and on the following basis: (i) with respect to Table 1 of the UK International Data Transfer Agreement, the parties’ details and key contact information is located in Appendix 1 of this Addendum; (ii) with respect to Table 2, information about the version of the EU SCCs, modules, and selected clauses are located in the Elections, and (iii) with respect to Table 3, information about the parties and a description of the transfer is set forth in Appendix I to this Addendum, a description of Creative Force’s technical and organizational security measures is located in Appendix II, and Creative Force’s list of sub-processors is set forth in Section 5.1 (Authorized Sub-processors).

1.22. “UK Personal Data” means Customer Data, the processing of which is within the territorial scope of the data protection, privacy, or security laws of the UK.

 

2. Processing of Personal Data

2.1. Scope and Roles of the Parties. The parties acknowledge and agree that with regard to the processing of Customer Data, Creative Force will act as processor to Customer, who may act as either a controller or a processor. Each party shall comply with its obligations under Applicable Data Protection Law, and this Addendum, when processing Customer Data. When Customer is acting as a controller, the Controller-to Processor Clauses will apply to any Data Transfer that occurs pursuant the Agreement. When Customer is acting as a processor, the Processor-to-Processor Clauses will apply to any Data Transfer that occurs pursuant to the Agreement. Customer agrees that it is unlikely that Creative Force will know the identity of Customer’s controllers, if any, because Creative Force has no direct relationship with Customer’s controllers. Therefore, Customer agrees that it will fulfil Creative Force’s obligations to Customer’s controllers under the Processor-to-Processor Clauses. For the avoidance of doubt, this Addendum does not apply to Aggregated Statistics or Customer Account Data.

2.2. Customer Instructions. Creative Force shall process Customer Data only in accordance with Customer’s documented lawful instructions as set forth in (i) the Agreement, including this Addendum and any applicable order forms; (ii) as necessary to comply with applicable law; (iii) or as otherwise agreed in writing or as initiated by Authorized Users in their use of the Services (including via configuration tools and APIs made available through the Services (“Permitted Purposes”). Customer may give additional instructions throughout the term of the Agreement. Creative Force shall immediately inform Customer if it is unable to follow those instructions.

2.3. Customer Obligations. Customer represents and warrants that (i) it has complied, and will continue to comply, with all applicable laws, including Applicable Data Protection Law, in respect of its processing of Customer Data and any processing instructions it issues to Creative Force; and (ii) it has, and will continue to have, the right to transfer, or provide access to, the personal data to Creative Force for processing in accordance with the terms of the agreement and this Addendum. Customer shall have sole responsibility for the accuracy, quality, and legality of Customer Data and the means by which Customer acquired Customer Data. Without prejudice to the generality of the foregoing, Customer agrees that it shall be responsible for complying with all laws (including Applicable Data Protection Law) applicable to any content created, sent, or managed through the Creative Force s. Customer specifically acknowledges and agrees that its use of the Services will not violate the rights of any data subject that has opted-out from the sale or other disclosure of his or her personal data.

2.4. Lawfulness of Instructions. Customer acknowledges that Creative Force is neither responsible for determining which laws or regulations are applicable to Customer’s business nor whether Creative Force’s provision of the Services meets or will meet the requirements of such laws or regulations. Customer will ensure that its instructions comply with Applicable Data Protection Law and Creative Force’s processing of the Customer Data in accordance with Customer’s instructions will not cause Creative Force to violate any applicable law, regulation, or rule, including without limitation Applicable Data Protection Law. Creative Force will inform Customer if it becomes aware or reasonably believes that Customer’s data processing instructions violate Applicable Data Protection Law.

2.5. Creative Force Personnel. Creative Force shall grant access to Customer Data to members of its personnel only to the extent strictly necessary for the implementation, management, and monitoring of the Agreement. It will further ensure that any person it authorizes to process the Customer Data shall be under an appropriate obligation of confidentiality (whether a contractual or statutory duty).

2.6. Accuracy. Customer agrees that it is unlikely that Creative Force would become aware that Customer Data it has received is inaccurate or outdated. Nonetheless, if Creative Force does become aware that Customer Data it has received is inaccurate, or has become outdated, it shall inform Customer without undue delay and shall cooperate with Customer to erase or rectify the data.

2.7. Return or Deletion of Customer Data. Creative Force shall only process Customer Data for the duration specified in Appendix 1.B. Upon Customer's request or upon termination or expiration of the Agreement, Creative Force agrees, at Customer’s option, to either (i) permit Customer to export all Customer Data at its expense; or (ii) delete all such Customer Data using the controls provided within the Services. This requirement shall not apply to the extent Creative Force is required by applicable law to retain some or all of the Customer Data or to Customer Data it has archived on back-up systems, which Customer Data Creative Force shall securely isolate, protect from any further processing, and eventually delete in accordance with Creative Force’s deletion policies. Creative Force agrees that these controls shall be available to Customer and/or its Affiliates at any time up to and for thirty (30) days following the termination or expiry of the Agreement.

2.8. No Sale of Information. Creative Force will not sell Customer Data, nor retain, use, or disclose Customer Data for any commercial purpose other than providing the Services. Creative Force will not disclose Customer Data outside the scope of the Agreement. Creative Force understands its obligations under Applicable Data Protection Law and will comply with them.

3. Responding to Data Subjects and Other Requests

3.1. Assistance Provided to Customer. Creative Force provides Customer with several selfhelp features and tools within the Services, including the ability to delete, obtain a copy of, or restrict use of Customer Data. Customer may use these self-help features and tools to honor requests from data subjects to exercise their rights under Applicable Data Protection Law. To the extent Customer, in its ordinary use of the Services, does not have the ability to address a data subject request, Creative Force shall, upon Customer’s written request, provide commercially reasonable assistance to Customer in responding to such data subject request. If complying with Customer’s request for assistance will require Creative Force to expend significant resources, such assistance shall be at Customer’s expense (scoped in advance).

3.2. Handling Requests Made Directly to Creative Force. In the event that any request, correspondence, enquiry or complaint from a data subject, regulator, or third party, including, but not limited to law enforcement, is made directly to Creative Force in connection with Creative Force’s processing of Customer Data, Creative Force shall promptly inform Customer providing details of the same, to the extent legally permitted. Unless legally obligated to do so, Creative Force shall not respond to any such request, inquiry, or complaint without Customer’s prior written consent. In the case of a legal demand for disclosure of Customer Data in the form of a subpoena, search warrant, court order, or other compulsory disclosure request, Creative Force shall attempt to redirect the requesting party or agency to request disclosure from Customer. Customer agrees that Creative Force may provide Customer’s basic contact information for this purpose. If Creative Force is unable to redirect the requesting party or agency, Creative Force shall act in accordance with its obligations under the EU SCCs or UK International Data Transfer Agreement, as applicable, incorporated herein. For the avoidance of doubt, nothing in the Agreement, including this Addendum shall restrict or prevent Creative Force from responding to any data subject requests or other requests in relation to personal data for which Creative Force is a controller.

3.3. Data Protection Impact Assessments. If Creative Force believes or becomes aware that its processing of Customer personal data is likely to result in a high risk to the data protection rights and freedoms of data subjects, Creative Force shall inform Customer and (taking into account the nature of the processing and the information available to Creative Force) provide commercially reasonable cooperation to Customer in connection with any data protection impact assessment or consultations with Data Protection Supervisory Authorities that may be required under Applicable Data Protection Law. Creative Force shall comply with the foregoing by (i) complying with Section 4.7 (Audits); (ii) providing the information contained in the Agreement, including this Addendum; and (iii) if the foregoing sub-sections (i) and (ii) are insufficient for Customer to comply with such obligations, upon request, providing additional reasonable assistance at Customer’s expense (scoped in advance).

4. Security

4.1. Technical and Organizational Measures. Creative Force has implemented and will maintain appropriate technical and organizational security measures designed to preserve the security and confidentiality of Customer Data in accordance with Creative Force’s security standards described in Appendix 2 (“Security Measures”).

4.2. Updates to Security Measures. Customer is responsible for reviewing the information Creative Force makes available regarding its data security and making an independent determination as to whether the Services meets Customer’s requirements and legal obligations, including its legal obligations under Applicable Data Protection Law. Customer acknowledges that the Security Measures are subject to technical progress and development and that Creative Force may update or modify the Security Measures from time to time, provided that such updates and modifications do not materially decrease the overall security of the Services.

4.3. Security Incident Response. Creative Force shall, to the extent permitted by law, notify Customer without undue delay of any Security Incident which affects Customer Data. Such notification will be delivered to one or more of Customer’s business or administrative contacts by any means Creative Force selects, including via email. It is Customer’s sole responsibility to ensure it maintains accurate contact information in the Services and under the Agreement at all times. The notice shall summarize in reasonable detail the nature and scope of the Security Incident, to the extent known, and the corrective action already taken or to be taken by Creative Force. Furthermore, Creative Force shall provide timely information relating to the Security Incident as it becomes known or as reasonably requested by Customer and shall promptly take reasonable steps to remedy or mitigate the effect of any Security Incident. Creative Force’s notification of or response to a Security Incident shall not be construed as an acknowledgement by Creative Force of any fault or liability with respect to the Security Incident. The parties will collaborate on whether any notice of breach is required to be given to any person, and if so, the content of that notice. Unless prohibited by an applicable statute or court order, Creative Force shall also notify Customer of any third-party legal process relating to any Security Incident, including, but not limited to, any legal process initiated by any governmental entity.

4.4. Unsuccessful Security Incidents. Customer agrees that an unsuccessful Security Incident will not be subject to Section 4.3 (Security Incident Response). An unsuccessful Security Incident is one that results in no unauthorized access to Customer Data or to any of Creative Force’s equipment or facilities storing Customer Data and could include, without limitation, pings and other broadcast attacks on firewalls, port scans, unsuccessful log-in attempts or invalid URLs, denial of service attacks, packet sniffing (or other unauthorized access to traffic data that does not result in access beyond IP addresses or headers) or similar incidents.

4.5. Customer Responsibilities. Notwithstanding the above, Customer agrees that except as provided in this Addendum, Customer is responsible for its secure use of the Creative Force Service, including securing its account authentication credentials, using the Services strictly as permitted under the Agreement, and using features and functionalities made available by Creative Force to maintain appropriate security in light of the nature of the data processed.

4.6. Documentation and Compliance. The parties acknowledge that Customer must be able to assess Creative Force’s compliance with its obligations under Applicable Data Protection Law and this Addendum. To facilitate such assessment, Creative Force will keep appropriate documentation on the processing activities carried out on behalf of Customer under the Agreement, and upon written request, make available to Customer all information reasonably necessary to demonstrate compliance with the obligations set out in this Addendum.

4.7. Audits. To the extent Creative Force is unable to demonstrate its compliance with Applicable Data Protection Laws and this Addendum through appropriate documentation as described in Section 4.6 (Documentation and Compliance) above, then, upon Customer’s written request and subject to the confidentiality obligations set forth in the Agreement, Creative Force shall allow for and contribute to audits and inspections conducted by Customer (or Customer’s independent, third-party auditor that is not a competitor of Creative Force). Audits shall occur at most annually or more frequently (i) in response to a demand from a Data Protection Supervisory Authority, (ii) following notice of a Security Incident, or (iii) as a follow-up to a duly conducted annual audit. Audits must be preceded by thirty (30) days advance written notice, must be conducted during Creative Force’s normal business hours, and must be limited to systems and procedures within Creative Force’s control and relevant to Creative Force’s processing of Customer Data. Creative Force will make its personnel, records, and similar items available upon fewer than thirty (30) days advance notice, but no less than reasonable notice if (i) requested by a Data Protection Supervisory Authority pursuant to an audit of Customer or (ii) following notice of a Security Incident. In lieu of such an audit, in the event that Creative Force independently obtains third-party annual audits of its privacy and security program, Customer agrees that Creative Force may satisfy its obligations under this Section 4.7 (Audits), by making available to Customer a copy of Creative Force’s then most recent third-party audit report. Such audit reports will be made available to Customer upon Customer’s written request, at reasonable intervals, and subject to the confidentiality obligations set forth in the Agreement. If any audit reveals any material vulnerability, Creative Force shall take commercially reasonable steps to correct such vulnerability.

5. Sub-processing

5.1. Authorized Sub-processors. Creative Force has Customer’s general authorization to engage third-party Sub-processors to fulfill its contractual obligations under this Addendum or to provide certain services on its behalf. The Sub-processors Creative Force currently engages to carry out processing activities can be found at https://www.creativeforce.io/legal/creative-force-subprocessors/. At least ten (10) business days prior to engaging or removing any Sub-processor, Creative Force will update this list and provide Customer with a mechanism to obtain notice of that update. Customer may object in writing to Creative Force's appointment or replacement of a Subprocessor prior to its appointment or replacement, provided such objection is based on reasonable grounds relating to data protection. In such event, the parties shall discuss commercially reasonable alternative solutions in good faith. If the parties cannot reach resolution, Creative Force will, in its sole discretion, either not appoint such Sub-processor, direct such Sub-processor to not process Customer Data, or permit Customer to suspend or terminate the Agreement without liability to either party in which case, however, and notwithstanding anything to the contrary in this Addendum, the SCCs or UK International Data Protection Agreement (as applicable), or the Agreement, Creative Force shall refund Customer any prepaid fees covering the remainder of the Term of the Agreement from the date of suspension/termination of the Agreement as per the foregoing.

5.2. Sub-processor obligations. Creative Force shall (i) conduct appropriate due diligence on each Sub-processor it engages to perform services on its behalf; (ii) enter into a written agreement with each Sub-processor containing data protection obligations that provide at least the same level of protection for Customer Data as those in this Addendum, to the extent applicable to the nature of the service provided by such Sub-processor; and (iii) remain responsible for such Sub-processor’s compliance with the obligations of this Addendum and for any acts or omissions of such Sub-processor that cause Creative Force to breach any of its obligations under this Agreement.

6. International Data Transfers

6.1. Data Center Locations. Customer understands and acknowledges that Customer Data may be transferred to and processed in the United States or in any country in which Creative Force or its Sub-processor have operations. Creative Force shall notify Customer at least ten (10) business days prior to adding or replacing a Sub-processor in the same manner provided for notification under Section 5.1 (Authorized Sub-processors) above. Customer may object in writing to Creative Force’s changes as per the above, provided such objection is based on reasonable grounds relating to data protection (including, but not limited to, changes of location for processing (including access) from within Europe to the United or another non-Europe country). In such event, the parties shall discuss commercially reasonable alternative solutions in good faith. If the parties cannot reach resolution, Creative Force will, in its sole discretion, either not proceed with the change, or permit Customer to suspend or terminate the Agreement without liability to either party in which case, however, and notwithstanding anything to the contrary in this Addendum, the EU SCCs or UK International Data Transfer Agreement (as applicable), or the Agreement, Creative Force shall refund Customer any prepaid fees covering the remainder of the term of the Agreement from the date of suspension/termination of the Agreement as per the foregoing. Creative Force shall ensure that such transfers comply with the requirements of Applicable Data Protection Law.

6.2. European and UK Data Transfers. To the extent that Creative Force receives Customer Data protected by European and UK Data Protection Laws, Creative Force agrees to abide by and process such data in compliance with the EU SCCs and UK International Data Transfer Agreement (as applicable), which are incorporated herein in full and form an integral part of this Addendum. For the purposes of the EU SCCs and UK International Data Transfer Agreement (as applicable): (i) Creative Force is the “data importer” and Customer is the “data exporter” (notwithstanding that Customer may be an entity located outside Europe or the UK); (ii) Appendixes 1 and 2 of this Addendum shall replace Annexes I and II of the EU SCCs and Tables 1 and 2 of the UK International Data Transfer Agreement (as applicable), and (iii) the EU SCCs shall be applied giving effect to the Elections. For the avoidance of doubt, the UK International Data Transfer Agreement shall apply to any Data Transfer pursuant to the Agreement that involves UK Personal Data.

7. Limitation of Liability

7.1. Liability Cap. Each party and all of its Affiliates’ liability to the other party and its Affiliates, taken together arising out of or related this this Addendum, including the EU SCCs and UK International Data Transfer Agreement (as applicable) shall be subject to the exclusions and limitations of liability set forth in the Agreement. For the avoidance of doubt, Creative Force and its Affiliates’ total liability for all claims from the Customer arising out of or relating to the Agreement or this Addendum shall apply in aggregate.

7.2. Liability to Data Subjects. Nothing in Section 7.1 (Liability Cap) shall alter the parties liability to data subjects as provided for in either the EU SCCs or UK International Data Transfer Agreement (as applicable). Each party agrees that it will be liable to data subjects for the entire damage resulting from a violation by it of Applicable Data Protection Law. If one party paid full compensation for the damage suffered, it is entitled to claim back from the other party that part of the compensation corresponding to the other party’s part of the responsibility for the damage. Notwithstanding the foregoing, with respect to processing of personal data subject to either the EU SCCs or UK International Data Transfer Agreement as provided herein, the allocation of liability to data subjects as between the parties shall be governed by the applicable SCCs taking into consideration that both parties agree that Customer will be liable to data subjects for the entire damage resulting from a violation of European and UK Data Protection Law with regard to processing of personal data for which it is a controller, and that Creative Force will only be liable to data subjects for the entire damage resulting from a violation of the obligations of European and UK Data Protection Law directed to processors where it has acted outside of or contrary to Customer’s lawful instructions or violated this Addendum. Creative Force will be exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage.

8. Modification and Termination of this Addendum

This Addendum shall remain in effect until the later of (i) termination of the Agreement or (ii) such time as Creative Force no longer processes any Customer Data on behalf of Customer. Failure to comply with any of the material provisions of this Addendum is considered a material breach of the Agreement. In the event of termination, Creative Force will return or destroy data pursuant to Section 2.7 (Return or Deletion of Customer Data). Creative Force may update the terms of this Addendum from time to time; provided, however, Creative Force will provide at least thirty (30) days prior written notice to Customer of any proposed update. The then-current terms of this Addendum are available at https://creativeforce.io/legal.

9. Entire Agreement; Conflict

This Addendum supersedes and replaces all prior and contemporaneous agreements, oral and written, with regard to the subject matter of this Addendum, including any prior data processing addenda entered into between Customer and Creative Force. If there is any conflict between this Addendum and any agreement, including the Agreement, the provisions of the following documents (in order of precedence) shall prevail: (a) the EU SCCs and their Annexes and/or the UK International Data Transfer Agreement and its Tables (as applicable); then (b) this Addendum and its Appendices; then (c) the Agreement.

10. Invalidity and Severability

10.1. General. If any provision of this Addendum is found by any court or administrative body of competent jurisdiction to be invalid and unenforceable, the invalidity or unenforceability of such provision shall not affect any other provision of this Addendum and all provisions not affected by such invalidity or unenforceability will remain in full force and effect.

10.2. Invalidity of EU SCCs and/or UK International Data Transfer Agreement. If the EU SCCs and/or UK International Data Transfer Agreement (as applicable) cease to or do not (including due to insufficient supplementary measures) meet the requirements under European and UK Data Protection Law or otherwise cease to or do not provide a valid legal basis to transfer personal data outside the EEA, EU, UK, or Switzerland, Creative Force shall (i) promptly notify Customer using the email address on file; (ii) upon request (whether nor not Creative Force has provided notice to Customer) immediately stop and, as applicable procure the cessation of the processing by its Sub-processors of the affected personal data promptly after the occurrence of any such notifiable event outside the relevant countries (except to the extent directed otherwise by Customer), and as soon as possible put in place commercially reasonable measures to mitigate the impact of such; and (iii) discuss with Customer commercially reasonably alternative measures in order to ensure an adequate level of protection with respect to the privacy rights of individuals and the lawful transfer of, or access to, personal data outside the relevant countries whilst continuing the provision of the Services with minimum disruption to Customer. If the parties cannot reach resolution, Customer may suspend or terminate the Agreement without liability to either party, in which case, notwithstanding anything to the contrary in this Addendum or the Agreement, Creative Force shall refund Customer any prepaid fees covering the remainder of the term of the Agreement from the date of suspension/termination of the Agreement as per the forgoing.

 

APPENDIX 1 – DETAILS OF PROCESSING

 

A. List of Parties

Data exporter(s):
The data exporter is the legal entity identified as “Customer” in the Agreement. Customer may be a brand, commercial studio, online retailer, or other creative. Customer may be a controller or a processor with respect to Customer Data.

Data importer(s):
The data importer is Creative Force.io, Inc. located at 237 A. St. PMB 48388, San Diego, CA 92101- 4003, USA Thomas Green Knudson, Chief Financial Officer, is Creative Force’s contact person with responsibility for data protection. He can be reached at green@creativeforce.io or at +45 21 48 07 77. Creative Force.io, Inc. is a provider of e-commerce photo studio management software. Creative Force is either a processor or a sub-processor with respect to Customer Data processed pursuant to the Agreement.

B. Description of Transfer

Categories of data subjects whose personal data is transferred
Customer may upload, submit, or otherwise provide personal data concerning the following categories of data subjects:

  • Customer and Customer’s Authorized Users; and

  • Persons in photographs belonging to, purchased by, or otherwise legally obtained by the Customer.

Categories of personal data transferred
Customer may upload, submit, or otherwise provide certain personal data to the Services, the extent of which is typically determined and controlled by Customer in its sole discretion, and may include the following types of personal data:

  • Name, phone number, and email address of data subjects;

  • Photographs of data subjects; and

  • Any other personal data uploaded, submitted, or otherwise provided to Creative Force by Customer in its sole discretion.

  • Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance, strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.

Creative Force does not want to, nor does it intentionally, collect or process any Sensitive Data in connection with the provision of the Services. However, certain Sensitive Data may be inferred from the Customer Data collected through the Services including the following:

  • Racial or ethnic origin.

To the extent collected, Creative Force shall apply strict purpose limitation to the processing of such data.

To the extent that other Sensitive Data is introduced into Customer Data, Customer agrees that it is solely responsible for ensuring that sufficient safeguards are in place to protect such Sensitive Data and Creative Force shall have no liability whatsoever in relation to such data.

The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis)
Customer Data will be transferred on a continuous basis for the duration of the Agreement. As between Customer and Creative Force, the duration of the processing under this Addendum is determined by Customer; provided that, generally the duration of the processing of Customer Data shall be for the duration of the Agreement and for the minimum period thereafter required to winddown the parties relationship under the Agreement and properly return or dispose of Customer Data pursuant to Section 2.7 (Return or Deletion of Customer Data).

Nature of the processing
Customer Data will be processed in accordance with the Agreement (including this Addendum) and may be subject to the following processing activities:

  • Storage and other processing necessary to provide, maintain, and improve the service provided to Customer pursuant to the Agreement; and/or

  • Disclosures in accordance with the Agreement, Customer’s instructions, and/or as compelled by applicable law.

Purpose(s) of the data transfer and further processing
Creative Force shall only process Customer Data for the Permitted Purposes outlined in Section which shall include: (i) processing as necessary to provide the Service in accordance with the Agreement; (ii) processing initiated by Customer in its use of the Service; and (iii) processing to comply with any other reasonable instructions provided by Customer (e.g., via email or support tickets) that are consistent with the terms of the Agreement.

Creative Force shall process Customer Data for the Permitted Purposes described in Section 2.2 (Customer Instructions).

The period for which the personal data will be retained, or if that is not possible, the criteria used to determine that period
Customer Data will be retained for the duration of the Agreement plus thirty (30) days after expiration or termination unless expressly instructed by Customer to delete or destroy Customer Data sooner or as otherwise required or permitted by law.

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
For all transfers to Sub-processors the subject matter, nature, and duration of the processing are as follows:

  • Subject matter: The subject matter of the transfer and processing is the Customer Data.

  • Nature of processing: The nature of the processing varies by Sub-processor. Detailed information for each Sub-processor can be found at https://www.creativeforce.io/legal/creative-force-subprocessors/.

  • Duration of the processing: The duration of the processing is for so long as is necessary for the purpose for which the information was transferred to the Sub-processor and in any event, for no longer than the duration of the agreement between Creative Force and the relevant Sub-processor.

C. Data Protection Supervisory Authority

The applicable Data Protection Supervisory Authority for purposes of this Addendum shall be established in accordance with any applicable SCCs incorporated herein, or if no SCCs are incorporated, the applicable Data Protection Supervisory Authority shall be any such entity with authority over the parties involved.

 

APPENDIX 2 – SECURITY MEASURES

Description of the technical and organizational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons.

Creative Force currently observes the following security measures:

Physical Access Control
(Measures to prevent unauthorized persons from gaining physical access to IT systems that handle personal data)

Buildings and systems used for data processing are secured. Data processing media is stored securely, kept locked when unattended, and is not available to unauthorized third parties. Creative Force regularly updates all hardware and software used in its business.

System Access Control
(Measures to prevent unauthorized persons from using IT systems)

Creative Force requires multi-factor authentication to access personal data processing systems. Employee accounts are not shared and inactive sessions are terminated after sixty (60) minutes. Through CloudWatch and network event monitoring, Creative Force keeps network logs and an intrusion detection log.

Data Access Control
(Measures to ensure that Creative Force employees only have access to the personal data pursuant to their access rights)

Access to personal data is role-based and data can only be accessed by Creative Force or the Customer. Access to databases are IP-restricted. Creative Force has also introduced log-in and password procedures that ensure that only employees with access rights may access personal data. Creative Force keeps a list of employees that have access to the Customer’s data, and limits the employees who have access to databases.

Transmission Access Control
(Measures to ensure that personal data cannot be read, copied, altered, or deleted by unauthorized persons during electronic transmission or during transport or storage on data media)

All data submitted by the Customer is encrypted upon transfer to Creative Force and stored encrypted.

Entry Control and Traceability
(Measures to ensure that entry, alteration, and deletion of personal data is logged as well as measures to ensure the accountability and traceability of the processing of personal data)

Creative Force applies a log monitoring solution to collect and compare logged events. All Elastic Load Balancing traffic is monitored via CloudWatch. CloudWatch alerts Creative Force of any issues in the system. Creative Force keeps both a log of all service access and errors and a Windows event log. All logs are collected by logbeat and filebeat services and stored for thirty (30) days. The logs contain information on who accessed data, from which IP address, the data was accessed, which data were accessed, and when data was accessed. Creative Force performs internal audits to ensure that all security measures stated in this Appendix 2 are taken and that each new feature or amendment to services provided by Creative Force live up to these standards.

Availability Control
(Measures to ensure that personal data is protected against accidental destruction or loss)

Creative Force uses web application firewalls and anti-virus software as well as back-up procedures to provide multiple layers of security. Creative Force uses AWS API Gateway and Firewall to prevent distributed-denial-of-service (DDOS) attacks. In addition, Creative Force maintains an Auto Scale Group able to scale up in case of a sharp increase in traffic. Creative Force uses Amazon Inspector and W3AF vulnerability scanning tools. Creative Force also uses a ERCore (Entity Framework)/SQL Parameter to prevent SQL Injection and uses Sonarqube and npmaudit to scan code and detect security issues. Creative Force maintains recovery processes to allow for continuation of data processing and to provide effective and accurate recovery of personal data.

Transparency
(Measures to ensure an adequate level of transparency to the Customer regarding Creative Force and its Sub-processors)

Customer can always access data submitted to Creative Force and can download such data after submission.

Intervenability (Measures to ensure that the Customer is allowed to access, rectify, delete, block, and manage objections to the processing of personal data)

Customer can download data submitted to the Services. Customer can also correct, delete, or object to the processing of personal data using either self-help tools Creative Force makes available to Customers or by contacting Creative Force.

Portability
(Measures to ensure the portability of personal data, if the migration of data is requested by the Customer or data subjects)

Data submitted by the Customer may be downloaded through the Services.

Data Retention and Deletion
(Measures to ensure that personal data is adequately erased or destroyed when use of personal data is no longer necessary)

Personal data is stored for the duration of the Agreement. After termination or expiration of the Agreement, Section 2.7 (Return or Deletion of Customer Data) of this Addendum applies.

For transfer to (sub-) processors, also describe the specific technical and organizational measures to be taken by the (sub-)processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter.

Each Sub-processor Creative Force engages contractually commits to implementing and maintaining appropriate technical and organizational measures sufficient to allow them to provide assistance to Creative Force, its Customers, and/or the controller, as necessary, consistent with this Addendum and any SCCs incorporated herein. This includes obligations relating to enforceable data subject rights, access and use limitations, security controls, and cooperation. Sub-processors are responsible for providing notice and assistance as required and for following documented processing instructions as received.

Moreover, prior to engaging Sub-processors, Creative Force assesses each Sub-processor’s capabilities in the area in which they do business, including their procedural and operational controls, to ensure they can provide a level of security and privacy appropriate in light of the nature of the processing for which they are engaged.