Data Protection Addendum Services for Businesses | Fibr
Data protection addendum
This Data Processing Addendum ("DPA") sets out the GDPR obligations governing the processing of personal data by VibeMarketing Inc. dba Fibr.ai ("Data Processor") on behalf of the Customer/Partner ("Data Controller") who has signed a Subscription Services Agreement with VibeMarketing Inc.
Regulatory basis: GDPR Regulation (EU) 2016/679 — Articles 28, 32, and 82
1. DEFINITIONS
The following terms have the meanings set out below throughout this Addendum.
1.1 Personal Data
Any information relating to an identified or identifiable natural person ('Data Subject'). The following data, often used for the express purpose of distinguishing individual identity, can be classified as Personal Data:
- Name
- Identification Number
- Location data
- An online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of a natural person
- IP Address
- Cookie Identifiers
- Radio Frequency ID (RFID) tags
1.2 Natural Person / Data Subject
An identifiable Natural Person/Data Subject is one who can be identified, directly or indirectly, by reference to their Personal Data.
1.3 Processing
Any operation or set of operations performed on Personal Data or on sets of Personal Data by automated means, including but not limited to:
- Collection
- Recording
- Organisation
- Structuring
- Storage
- Adaptation or alteration
- Retrieval / Downloading data
- Consultation
- Use
- Disclosure by transmission
- Dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction
1.4 Data Controller
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
1.5 Data Processor
A natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Data Controller.
1.6 Data Sub-Processor
A natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Data Processor.
1.7 GDPR
The General Data Protection Regulation (EU) 2016/679 — a legal framework that sets guidelines for the collection and processing of Personal Data of individuals within the European Union (EU).
1.8 Profiling
Any form of automated processing of Personal Data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person — in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.
1.9 Personal Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
1.10 Consent
Any freely given, specific, informed and unambiguous indication of the Data Subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
1.11 Data Protection Impact Assessment (DPIA)
An activity carried out to enhance compliance with GDPR where processing operations are likely to result in a high risk to the rights and freedoms of Data Subjects.
1.12 Security Breach
Means:
- any actual or reasonably suspected unauthorized use of, loss of, access to, or disclosure of Subscriber Data; provided that an incidental disclosure to an Authorized Party or VibeMarketing Inc. where no reasonable suspicion of theft, fraud, criminal or malicious conduct exists shall not constitute a Security Breach unless such incidental disclosure triggers a notification obligation under applicable Law; and
- any security breach (or substantially similar term) as defined by applicable Law.
1.13 Supervisory Authority
An independent public authority established by an EU Member State...
2. OBLIGATIONS OF VIBEMARKETING INC. AS DATA PROCESSOR
Shall process Customer Data only:
- on Customer's behalf for the purpose of providing and supporting VibeMarketing Inc.'s services (including insights, reporting, analytics, and platform abuse, trust and safety monitoring);
- in compliance with written instructions received from Customer; and
- in a manner that provides no less than the level of privacy protection required under applicable Data Protection Laws;
Promptly inform Customer in writing if VibeMarketing Inc. cannot comply with the requirements of this DPA;
Not provide Customer with any remuneration in exchange for Customer Data. The parties acknowledge and agree that Customer has not "sold" (as defined under applicable data protection laws, including CCPA where applicable) Customer Data to VibeMarketing Inc.;
Not "sell" or "share" Personal Data as defined under applicable data protection laws;
Inform Customer promptly if, in VibeMarketing Inc.'s opinion, any instruction from Customer violates applicable Data Protection Laws;
Ensure that persons employed by VibeMarketing Inc. and other persons engaged to perform services on its behalf are subject to appropriate confidentiality obligations with respect to Customer Data and comply with the data protection obligations applicable under this DPA;
Engage sub-processors only as necessary to fulfill its obligations under this DPA, and ensure that such sub-processors are bound by data protection obligations that are no less protective than those set out in this DPA. A list of sub-processors is maintained and made available in Annex 2.
3. APPLICABILITY
This DPA is applicable under the following conditions:
- If the Data Controller entity signing this Addendum is a party to the MSA, this DPA is an addendum to and forms part of the MSA.
- If the Data Controller entity signing this DPA has executed an Order Form with VibeMarketing Inc. or its Affiliate pursuant to the Agreement, but is not itself a party to the Agreement, this DPA is an addendum to that Order Form and applicable renewal Order Forms.
- If the Data Controller entity signing this DPA is neither a party to an Order Form nor the Agreement, this DPA is not valid and is not legally binding. ...
19. DATA PROTECTION OFFICER
VibeMarketing Inc. has appointed a Data Protection Officer (DPO) in compliance with GDPR Article 37.
DPO Contact: roy@fibr.ai
ANNEX 1 — PARTIES & DESCRIPTION OF TRANSFER
1. Data Exporter
**Name:**Customer (as set forth in the relevant Order Form)
**Address:**As set forth in the relevant Order Form
**Contact Person:**As set forth in the relevant Order Form
**Activities relevant to the transfer:**Recipient of the Services provided by VibeMarketing Inc. in accordance with the Agreement
**Signature and date:**As set out in the Agreement
**Role:**Controller
2. Data Importer
**Name:**VibeMarketing Inc.
**Address:**42700 Everglades Park Dr, Fremont, CA 94538
**Contact Person:**Pritam Roy, DPO — roy@fibr.ai
**Activities relevant to the transfer:**Provision of the Services to the Customer in accordance with the Agreement
**Signature and date:**As set out in the Agreement
**Role:**Processor
3. Description of Transfer
Categories of data subjects:
- Customer's authorized users of the Services
Categories of personal data transferred:
- Name, Address, Date of Birth, Age, Education, Email, Gender, Image, Job, Language, Phone, Related person, Related URL, User ID, Username, and other such items as defined in Article 9 of GDPR
4. Technical and Organisational Security Measures
Description of the technical and organisational security measures implemented by VibeMarketing Inc. as the data processor/data importer to ensure an appropriate level of security.