Data Protection Addendum Services for Businesses | Fibr

Data protection addendum

This Data Processing Addendum ("DPA") sets out the GDPR obligations governing the processing of personal data by VibeMarketing Inc. dba Fibr.ai ("Data Processor") on behalf of the Customer/Partner ("Data Controller") who has signed a Subscription Services Agreement with VibeMarketing Inc.

Regulatory basis: GDPR Regulation (EU) 2016/679 — Articles 28, 32, and 82

1.  DEFINITIONS

The following terms have the meanings set out below throughout this Addendum.

1.1 Personal Data

Any information relating to an identified or identifiable natural person ('Data Subject'). The following data, often used for the express purpose of distinguishing individual identity, can be classified as Personal Data:

1.2 Natural Person / Data Subject

An identifiable Natural Person/Data Subject is one who can be identified, directly or indirectly, by reference to their Personal Data.

1.3 Processing

Any operation or set of operations performed on Personal Data or on sets of Personal Data by automated means, including but not limited to:

1.4 Data Controller

The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.

1.5 Data Processor

A natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Data Controller.

1.6 Data Sub-Processor

A natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Data Processor.

1.7 GDPR

The General Data Protection Regulation (EU) 2016/679 — a legal framework that sets guidelines for the collection and processing of Personal Data of individuals within the European Union (EU).

1.8 Profiling

Any form of automated processing of Personal Data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person — in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.

1.9 Personal Data Breach

A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.

1.10 Consent

Any freely given, specific, informed and unambiguous indication of the Data Subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.

1.11 Data Protection Impact Assessment (DPIA)

An activity carried out to enhance compliance with GDPR where processing operations are likely to result in a high risk to the rights and freedoms of Data Subjects.

1.12 Security Breach

Means:

1.13 Supervisory Authority

An independent public authority established by an EU Member State...

2.  OBLIGATIONS OF VIBEMARKETING INC. AS DATA PROCESSOR

  1. Shall process Customer Data only:

    • on Customer's behalf for the purpose of providing and supporting VibeMarketing Inc.'s services (including insights, reporting, analytics, and platform abuse, trust and safety monitoring);
    • in compliance with written instructions received from Customer; and
    • in a manner that provides no less than the level of privacy protection required under applicable Data Protection Laws;
  2. Promptly inform Customer in writing if VibeMarketing Inc. cannot comply with the requirements of this DPA;

  3. Not provide Customer with any remuneration in exchange for Customer Data. The parties acknowledge and agree that Customer has not "sold" (as defined under applicable data protection laws, including CCPA where applicable) Customer Data to VibeMarketing Inc.;

  4. Not "sell" or "share" Personal Data as defined under applicable data protection laws;

  5. Inform Customer promptly if, in VibeMarketing Inc.'s opinion, any instruction from Customer violates applicable Data Protection Laws;

  6. Ensure that persons employed by VibeMarketing Inc. and other persons engaged to perform services on its behalf are subject to appropriate confidentiality obligations with respect to Customer Data and comply with the data protection obligations applicable under this DPA;

  7. Engage sub-processors only as necessary to fulfill its obligations under this DPA, and ensure that such sub-processors are bound by data protection obligations that are no less protective than those set out in this DPA. A list of sub-processors is maintained and made available in Annex 2.

3.  APPLICABILITY

This DPA is applicable under the following conditions:

  1. If the Data Controller entity signing this Addendum is a party to the MSA, this DPA is an addendum to and forms part of the MSA.
  2. If the Data Controller entity signing this DPA has executed an Order Form with VibeMarketing Inc. or its Affiliate pursuant to the Agreement, but is not itself a party to the Agreement, this DPA is an addendum to that Order Form and applicable renewal Order Forms.
  3. If the Data Controller entity signing this DPA is neither a party to an Order Form nor the Agreement, this DPA is not valid and is not legally binding. ...

19.  DATA PROTECTION OFFICER

VibeMarketing Inc. has appointed a Data Protection Officer (DPO) in compliance with GDPR Article 37.

DPO Contact: roy@fibr.ai

ANNEX 1 — PARTIES & DESCRIPTION OF TRANSFER

1.  Data Exporter

**Name:**Customer (as set forth in the relevant Order Form)

**Address:**As set forth in the relevant Order Form

**Contact Person:**As set forth in the relevant Order Form

**Activities relevant to the transfer:**Recipient of the Services provided by VibeMarketing Inc. in accordance with the Agreement

**Signature and date:**As set out in the Agreement

**Role:**Controller

2.  Data Importer

**Name:**VibeMarketing Inc.

**Address:**42700 Everglades Park Dr, Fremont, CA 94538

**Contact Person:**Pritam Roy, DPO — roy@fibr.ai

**Activities relevant to the transfer:**Provision of the Services to the Customer in accordance with the Agreement

**Signature and date:**As set out in the Agreement

**Role:**Processor

3.  Description of Transfer

Categories of data subjects:

Categories of personal data transferred:

4.  Technical and Organisational Security Measures

Description of the technical and organisational security measures implemented by VibeMarketing Inc. as the data processor/data importer to ensure an appropriate level of security.