Data Processing Addendum
The terms on which Novos Publishing LLC processes personal data on your behalf, for customers who need a written processor agreement.
1. When this addendum applies
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you and Novos Publishing LLC ("we", "us"). It applies automatically, without further signature, whenever we process personal data on your behalf in the course of providing Uplynx and the GDPR, the UK GDPR, or a comparable data protection law applies to that processing.
If your procurement process requires a countersigned copy, write to zero2ceo.email@gmail.com with your legal entity name and address and we will provide one. The terms will be these terms.
Where this DPA conflicts with the Terms of Service, this DPA governs for matters of personal data processing. Where it conflicts with the Standard Contractual Clauses incorporated by section 13, those Clauses govern.
2. Definitions
"Personal data", "processing", "controller", "processor", "data subject", "supervisory authority" and "personal data breach" have the meanings given to them in the GDPR. "Customer Personal Data" means personal data contained in the content you or your connected clients put into the service, and in the account records of your workspace members.
"Applicable Data Protection Law" means the GDPR, the UK GDPR, the Swiss FADP, the California Consumer Privacy Act as amended, and any other data protection law applicable to the processing under this DPA.
3. Roles of the parties
For Customer Personal Data, you are the controller and we are the processor. Where you are yourself a processor acting for another controller, we are a subprocessor and this DPA applies as though references to you were references to that controller, with you responsible for having the authority to enter into it.
We act as a controller for a limited set of data of our own: the account records we need to identify and bill you, our security and operational logs, and our support correspondence. That processing is governed by our Privacy Policy, not by this DPA.
4. Details of the processing
Subject matter: provision of the service described in the Terms of Service.
Duration: for as long as your account is open, plus the retention periods described in our Privacy Policy.
Nature and purpose: storing project state — context, decisions, findings, tasks and an append-only event record — and making it available to the accounts and clients you authorize; authenticating users; separating workspaces; supporting and securing the service.
Categories of data subject:
- you, where you are an individual
- the members of your workspaces
- any individual whose personal data you or a client you have connected chooses to write into project content
Types of personal data:
- identification and contact data — name, email address, account identifier
- workspace membership and role
- content data — anything present in the project content you store, the scope of which is under your control and not ours
- usage and technical data — activity counts, request metadata, IP address, user agent
Special category data: the service is not designed for special category data as defined in Article 9, or for data about criminal convictions and offences. Do not put such data into project content.
5. Our obligations
We will process Customer Personal Data only on your documented instructions, which comprise this DPA, the Terms of Service, your configuration of the service, and any further written instruction you give that is consistent with them — unless we are required to process it by a law we are subject to, in which case we will tell you before doing so unless that law prohibits it.
If we consider an instruction to breach Applicable Data Protection Law, we will tell you.
We will not sell Customer Personal Data, share it for cross-context behavioural advertising, retain or use it outside the direct business relationship, or combine it with data from another source, except as permitted by Applicable Data Protection Law.
We will not use Customer Personal Data to train machine-learning models.
6. Confidentiality
We limit access to Customer Personal Data to personnel who need it to provide or support the service, and everyone with access is bound by an obligation of confidentiality that survives the end of their engagement.
7. Security
We implement appropriate technical and organizational measures under Article 32, taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing. These include:
- encryption of personal data in transit and at rest
- tenant separation applied at the point of every query, so that data from one workspace is not returned to another
- authentication and access control through a dedicated identity provider, with administrative access to production limited to those who require it
- logging and monitoring sufficient to detect and investigate unauthorized access
- regular backups, held encrypted and aged out on a rolling schedule, with a tested restore path
- review of these measures as the service changes
We may update these measures, provided the level of protection is not reduced.
8. Subprocessors
You give us general written authorization to engage subprocessors. Our current subprocessors are listed on our Subprocessors page, which is incorporated into this DPA.
We will give at least 30 days' notice before adding or replacing a subprocessor, other than where an urgent change is required to keep the service secure or available. You may object on reasonable data protection grounds within the notice period; if we cannot offer an alternative, you may terminate the affected subscription and receive a refund of any prepaid amount covering the period after termination.
We impose data protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
9. Assisting you
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Applicable Data Protection Law. The service gives you direct access to the content in your workspaces, which will usually be the fastest route.
If a data subject contacts us directly about Customer Personal Data, we will not respond substantively; we will refer them to you and tell you promptly.
We will provide you with reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36, taking into account the information available to us.
10. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event within 72 hours of becoming aware of it.
The notification will describe, so far as we know it at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will provide it in phases as it becomes available.
We will cooperate with you and take reasonable steps to contain and investigate the breach. Our notification is not an admission of fault or liability.
11. Deletion and return
You may export Customer Personal Data at any time while your account is open, and for 30 days after it closes.
At the end of that period we delete Customer Personal Data from live systems. Copies persist in encrypted backups for a limited further period and are deleted as those backups age out; while they persist they remain subject to this DPA and are not used for any other purpose. We may retain data where a law we are subject to requires it, for as long as it requires.
12. Audit and information
We will make available to you the information reasonably necessary to demonstrate compliance with Article 28, and will contribute to audits and inspections conducted by you or an auditor you mandate.
Ordinarily we will satisfy this by answering a reasonable written questionnaire, no more than once a year unless a supervisory authority requires otherwise or there has been a breach affecting your data. Where that is genuinely insufficient, an on-site audit may be conducted on 30 days' written notice, during business hours, without unreasonably disrupting the service, subject to confidentiality, and at your expense. Write to zero2ceo.email@gmail.com to begin.
13. International transfers
The service is operated from the United States and every subprocessor we use processes data there.
Where personal data is transferred from the EEA, the United Kingdom or Switzerland to a country without an adequacy decision, the European Commission's Standard Contractual Clauses (Module Two, controller to processor, or Module Three where you act as a processor) are incorporated into this DPA by reference and are deemed executed between us. The UK Addendum issued by the Information Commissioner applies where the UK GDPR governs, and the Clauses apply with the necessary modifications where the Swiss FADP governs.
For the purposes of the Clauses: the data exporter is you; the data importer is us; the description of the transfer is set out in section 4; the technical and organizational measures are those in section 7; and subprocessor authorization is the general authorization in section 8.
Where the Clauses require a choice of supervisory authority or governing law that this DPA does not otherwise supply, the parties adopt the options that most closely give effect to the Clauses' protections.
14. Your obligations
You are responsible for the lawfulness of the personal data you put into the service and of your instructions to us — including having a valid legal basis, giving any notices and obtaining any consents required, and responding to data subjects about content in your workspaces.
You are responsible for who you invite into a workspace and for what access that grants them, and for which clients and integrations you authorize.
15. United States privacy laws
For the purposes of the California Consumer Privacy Act as amended and comparable US state laws, you are the business and we are a service provider or processor. We process personal information only to perform the service, and we do not sell it, share it for cross-context behavioural advertising, or retain, use or disclose it for any purpose other than the business purposes set out in the Terms of Service.
We will notify you if we determine that we can no longer meet those obligations, and you may take reasonable steps to stop and remediate unauthorized use.
16. Liability, term and governing law
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. Nothing in this section limits a data subject's rights under Applicable Data Protection Law, and nothing limits liability that cannot be limited by law.
This DPA takes effect when the Terms of Service do and continues for as long as we process Customer Personal Data on your behalf.
Except where Applicable Data Protection Law or the Standard Contractual Clauses require otherwise, this DPA is governed by the laws of the State of Texas, United States, and the venue provisions of the Terms of Service apply.
17. Contact
Data protection enquiries, audit requests and countersignature requests go to zero2ceo.email@gmail.com.
Questions go to zero2ceo.email@gmail.com.