Definitions
"Applicable Laws" means the laws, rules, regulations, court orders, and other binding requirements of a relevant government authority that apply to or govern a party.
"Applicable Data Protection Laws" means the Applicable Laws that govern how the Service may process or use an individual's personal information, personal data, personally identifiable information, or other similar term, including, where they apply, the California Consumer Privacy Act of 2018 and its regulations (the "CCPA") and other US state consumer privacy laws.
"Controller Personal Data" means Personal Data that the Controller provides or makes available to the Processor, or that the Processor collects on the Controller's behalf, as part of the Service and that is governed by this DPA.
"DPA" means this data processing agreement, including its schedules.
"Personal Data" will have the meaning(s) given in the Applicable Data Protection Laws for personal information, personal data, or other similar term.
"Processing" or "Process" will have the meaning(s) given in the Applicable Data Protection Laws for any use of, or performance of a computer operation on, Personal Data, including by automatic methods.
"Report" means audit reports prepared by another company according to the standards defined in the Security Policy on behalf of the Processor.
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Controller Personal Data, including any event that is a breach of the security of a system under Applicable Laws.
"Service" means the products and services the Processor provides under the Agreement.
"Sensitive Data" means Personal Data that is sensitive personal information, sensitive data, special category data or a similar term under Applicable Data Protection Laws.
"Subprocessor" means any person the Processor engages to Process Controller Personal Data.
"Business purpose", "consumer", "contractor", "sell", "service provider", "share" and similar terms have the meanings given in Applicable Data Protection Laws.
"EEA SCCs" means the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council; "EEA" means the member states of the European Union, Norway, Iceland and Liechtenstein; and "GDPR" means Regulation (EU) 2016/679.
"UK GDPR" has the meaning given in the UK Data Protection Act 2018; "UK Addendum" means the International Data Transfer Addendum to the EEA SCCs issued under section 119A of the UK Data Protection Act 2018; and "UK IDTA" means the International Data Transfer Agreement issued under that section; in each case as current from time to time.
"Restricted Transfer" means (a) where the GDPR applies, a transfer of personal data from the EEA to a country outside the EEA that is not subject to an adequacy decision of the European Commission; (b) where the UK GDPR applies, a transfer of personal data from the United Kingdom to a country or organization not approved by regulations under Article 45A of the UK GDPR; and (c) where the Swiss Federal Act on Data Protection of 25 September 2020 (the "FADP") applies, a transfer of personal data from Switzerland to a country that the Swiss Federal Council has not recognized as providing an adequate level of protection.