Business & Legal Terms Summary:
This summary is a plain English version of the terms of using Thought Industries’ Lens AI. You can find the legally binding terms and conditions below this summary.
- Terms: You can cancel the Lens AI and this Agreement at any time.
- Customer Data: You own your data in the Lens AI; on your request, Thought Industries will export the data to you or delete it for you at any time.
- Services/Reports: You own all the Reports generated by the Lens AI provided to you.
- Personal Information: Any personal information of users provided by you directly, and any personal information processed by the Lens AI (e.g., name, email, location) will only be used for provision of the Service to you, and not for any other purpose, and will never be sold, rented or shared with any third parties.
- Information Security: Your data in the Lens AI shall be encrypted and Thought Industries adheres to industry security standards.
- Confidentiality: Customer data processed in the Lens AI will be kept confidential.
- Liability: You are not liable for any potential damages to Thought Industries above what you have paid in the previous three (3) months.
- IP Infringement: Thought Industries will defend intellectual property infringement claims arising from your use of the Lens AI.
- Third-Party AI Provider: Your use of the Lens AI requires additional processing by Thought Industries’ third-party AI provider, and your use of the Service is subject to the AI provider’s policies.
These Terms of Service and Software as a Service (SaaS) Agreement (the “Agreement”) is made and is effective upon the date of your acceptance of these terms (the “Effective Date”) by and between Thought Industries, Inc., a company incorporated under the laws of Massachusetts (USA) with its principal place of business at 6 Liberty Square, #6099, Boston, MA 02109 (“TI” or “we” or “us”), and you, the customer as identified in the applicable purchase terms via TI’s website (“Customer” or “you”). The terms of this Agreement shall govern your use of and access to Thought Industries’ Lens AI.
WHEREAS TI is the owner and licensor of Lens AI, (“Lens AI” or the “Service” herein) a proprietary Software as a Service-based digital platform, with processing provided by generative AI technology, providing Customers with reports regarding Lens AI. Lens AI is designed to assist the Customer in better understanding, analyzing, processing and displaying data, to measure and demonstrate value, and other characteristics of its customers. Lens AI is designed to work with existing Customer data, to extract valuable information to measure and qualify the value of customer education and assistance programs.
WHEREAS the Customer desires to be granted a non-exclusive right to access and use the Service for the purposes described in this Agreement, and TI is willing to grant Customer such rights under the terms and conditions set forth herein.
NOW, THEREFORE, the parties hereby agree as follows:
- Software as a Service. Subject to the terms and conditions of this Agreement, including Customer's payment of the Fees set forth herein, TI hereby grants Customer a non-exclusive, non-sublicensable, non-transferable, and limited licensed right throughout the applicable subscription period to access and use the Service, for the Customer’s internal business purposes. Use of and access to the Service shall be licensed only as permitted herein, and strictly limited to the Lens AI features, functionalities and subscription time period.
- SPECIAL LICENSE TERMS. Your use of and access to Lens AI is expressly subject to the terms and conditions set forth in the Lens AI Acceptable Use Policy, found here: [Lens AI AUP]; and further governed by the Lens AI Data Processing Agreement (DPA) found here: [Lens AI DPA]. Lens AI'S INTEGRATED, THIRD-PARTY GENERATIVE ARTIFICIAL INTELLIGENCE PROVIDER’S LICENSED TECHNOLOGY SHALL BE PROVIDED TO CUSTOMER SUBJECT TO THE PROVIDER’S TERMS AND CONDITIONS FOUND AT https://openai.com/enterprise-privacy/.
- Intellectual Property Rights. “Intellectual Property Rights” for the Service (excluding the Intellectual Property Rights of third-party providers licensed to TI, which are and shall remain the property of such third-party providers, properly licensed to TI) means all intangible legal rights, titles and interests evidenced by or embodied in all: (i) inventions (regardless of patentability and whether or not reduced to practice), improvements thereto, and patents, patent applications, and patent disclosures, together with all reissuances, continuations, continuations in part, revisions, extensions, and reexaminations thereof; (ii) trademarks, service marks, trade dress, logos, trade names, and corporate names, together with translations, adaptations, derivations, and combinations thereof, including goodwill associated therewith, and applications, registrations, and renewals in connection therewith; (iii) any work of authorship, regardless of copyright ability, copyrightable works, copyrights (including moral rights) and applications, registrations, and renewals in connection therewith; (iv) trade secrets and Confidential Information; and (vi) all rights associated with the foregoing and all other proprietary rights and any other similar rights, in each case on a worldwide basis, and copies and tangible embodiments thereof, in whatever form or medium. All Intellectual Property Rights in the Service including any and all compilations of data, derivatives, changes and improvements (including updates thereof) and any suggestions, ideas, enhancement requests, or recommendations provided by Customer or any third party relating to the Service, lie exclusively with TI. TI shall be the sole owner of any Intellectual Property Rights in the compilation(s) of data derived from the Service, including Service-algorithm-generated compilations and derivatives of data (but excluding any data provided by Customer and Reports (defined below) generated by the Service for Customer). Nothing in this Agreement shall constitute a waiver of TI’s Intellectual Property Rights under any law, or be in any way construed or interpreted as such. Notwithstanding the foregoing and for purposes of clarity, TI has not agreed and does not agree to treat as confidential any feedback or input from Customer that Customer employees or contractors give TI; and nothing in this Agreement or in the parties’ dealings arising out of or related to this Agreement will restrict TI’s right to use, profit from, disclose, publish, keep secret, or otherwise exploit compilations of data, derivatives, or Customer feedback provided to TI. All Intellectual Property Rights in Customer’s data shall remain with Customer, and all Customer data shall remain the sole and exclusive property of Customer. Customer shall own all Intellectual Property Rights in the Reports (defined below) generated by the Service exclusively for Customer.
- Restrictions of Use. Customer shall (i) not attempt to infiltrate or hack the Service, or any part thereof or reverse engineer, de-compile, disassemble, or otherwise reduce to human-perceivable form the Service's source code; (ii) not represent that it possesses any proprietary interest in the Service; (iii) not directly or indirectly, take any action to contest TI's Intellectual Property Rights or infringe them in any way; (iv) except as specifically permitted by TI in writing, not use the name, trademarks, trade-names, and logos of TI; (vi) except as expressly provided in this Agreement, not use the Service to provide third parties with managed services or any other services (including without limitation not to use the Service to provide any services or features competing with TI and/or the Service whether or not in return for remuneration of any kind); (vii) not make copies of any TI documentation for any third party.
- Customer Data and Lens AI Reports. By providing your data to TI for processing under the terms of this Agreement, you grant, and you represent and warrant that you have the right to grant, to TI an irrevocable, perpetual license to host, process, use, copy, reproduce, archive, store, cache, reformat, translate, excerpt (in whole or in part), and distribute such data, solely for the purpose of providing you with the Service, and improving the Service, as set forth in this Agreement, and for no other purpose. Your data shall not be used by TI or any integrated third-party provider (including TI’s generative artificial intelligence provider) to train any artificial intelligence algorithms or any other machine learning models; and will only be used for providing you with, and improving your use of, your instance of the Service. TI does not assert any rights, Intellectual Property Rights or ownership over your data; and TI does not assert any rights, Intellectual Property Rights or ownership over the Reports provided to you through the Service. “Reports” shall mean the responses and results provided and displayed in your Lens AI application. For purposes of clarity, Reports shall not include any Customer data or the proprietary technology used to generate Reports. You retain full ownership of all Customer data and the Reports generated by Lens AI exclusively for you.
- Data Protection; User Information and Customer Data. Customer’s use of the Service will require that Customer provide TI with certain information regarding its authorized users of the Service, such as name, email, location, employer, IP address (collectively “User Information” herein) for the sole purpose of providing the Service; all of which may be subject to data protection and privacy rules, laws and regulations in multiple jurisdictions. TI’s processing of all such User Information shall be governed by the Lens AI DPA, referenced above. Customer’s use of the Service will require that Customer provide TI with access to Customer data and certain databases within the custody or control of Customer, which may include personal data, as defined under applicable data privacy laws (collectively “Customer Data PII”) all of which may be subject to data protection and privacy rules, laws and regulations in multiple jurisdictions. TI’s processing of all such Customer Data PII shall also be governed by the Lens AI DPA. To the extent TI will process User Information and Customer Data PII, as personal data defined under applicable privacy laws, TI shall only do so strictly in accordance with the documented instructions received by Customer, as governed by the applicable terms in the Lens AI DPA.
- Service Fees. Customer shall pay TI the service fees for the use of the Service in accordance with the specific services purchased by Customer on TI’s website, at the applicable price and terms set forth on TI’s website (or in a separate order form indicating the Service, applicable price and terms, when Customer requirements dictate) (the “Fees” herein).
- Payment Terms. Customer’s payment terms are set forth on the TI website, and Customer shall pay the Fees due to TI, and the applicable credit card charges and fees in accordance with the terms of its credit card issuer. In the event Customer fails to pay any Fees due to TI, TI shall be entitled to cease providing the Service and terminate this Agreement.
- Taxes. Customer is solely responsible for payment of any applicable sales tax or other tax that may be due in connection with the purchase of the Services.
- Disclaimer. TI PROVIDES ACCESS AND USAGE OF THE SERVICE TO CUSTOMERS ON AN “AS IS” BASIS, WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTY OF MERCHANTABILITY, NON-INFRINGEMENT, AND FITNESS FOR PARTICULAR PURPOSE OR ACCURACY. NOTWITHSTANDING ANYTHING TO THE CONTRARY HEREIN, TI DOES NOT WARRANT THAT THE SERVICE OR ANY INFORMATION OR SERVICES RELATED THERETO WILL BE DELIVERED OR PERFORMED ERROR-FREE OR WITHOUT INTERRUPTION.
- Indemnification by TI. TI shall defend, indemnify, and hold harmless Customer from and against any claims, losses, costs, damages, fees or expenses (including reasonable legal fees and expenses) (collectively, “Losses”) to the extent resulting directly from third-party claims, actions, suits or proceedings of any kind brought by a third party alleging that the Service infringes intellectual property rights of such third party. As a condition to the defense set forth above, Customer shall (i) give TI prompt notice of any such claim made against it, (ii) grant TI sole control of the defense and settlement of any such claim; and (iii) provide TI with all reasonable information and assistance, at TI’s expense. TI’s indemnification obligations shall not extend or apply to any such claims arising from Customer’s acts or omissions. TI’s intellectual property indemnification obligations shall not extend or apply to any information, data, output, responses or the like, provided by third-party artificial intelligence providers integrated within the Service.
- Indemnification By Customer. Customer shall defend, indemnify and hold harmless TI and its affiliates from and against any and all Losses to the extend resulting from any claims, actions, suits or proceedings brought by a third party (i) alleging that data provided by the Customer (including User Data and Customer Data PII) processed by the Service, was collected or obtained in violation of any applicable law or regulation; and/or (ii) Customer has violated the terms of this Agreement. TI shall give Customer prompt notice of any such claim made against it, and grant Customer sole control of the defense of any such claim, suit or proceeding, including appeals, negotiations and any settlement or compromise thereof, provided any resolution or settlement of any claim(s) shall require the reasonable consent of TI.
- Limitation of Liability. IN NO EVENT SHALL EITHER PARTY’S LIABILITY UNDER, ARISING OUT OF OR RELATING TO THIS AGREEMENT, EXCEED THE AMOUNT OF FEES ACTUALLY PAID TO TI UNDER THIS AGREEMENT IN THE THREE (3) MONTH PERIOD PRECEDING THE EVENT THAT GAVE RISE TO THE CLAIM. IN NO EVENT WILL TI BE LIABLE FOR LOST PROFITS, LOSS OF USE, LOSS OF DATA, COST OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES, OR ANY FOR ANY SPECIAL, INCIDENTAL, INDIRECT, OR CONSEQUENTIAL DAMAGES, HOWEVER CAUSED, AND ON ANY THEORY OF LIABILITY, WHETHER FOR BREACH OF CONTRACT, TORT (INCLUDING NEGLIGENCE AND STRICT LIABILITY), OR OTHERWISE, WHETHER OR NOT TI HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
- Confidential Information. Either party may from time to time during the Term of this Agreement disclose (the “Disclosing Party”) to the other party (the “Receiving Party”) certain information regarding the Disclosing Party’s business, including technical, marketing, financial, pricing information, employee, customer, and other confidential or proprietary information, including without limitation any information either party marks as confidential (“Confidential Information”). Regardless of whether so marked or identified, any information that may be reasonably understood, under the circumstances to be considered confidential or proprietary or a trade secret, including but not limited to the terms and conditions of this Agreement, will be considered Confidential Information of the Disclosing Party.
- Protection of Confidential Information. The Receiving Party will not use any Confidential Information of the Disclosing Party for any purpose not expressly permitted by this Agreement, and will disclose the Confidential Information of the Disclosing Party only to the employees and agents of the Receiving Party who need to know such Confidential Information for the purpose of this Agreement and who are under a duty of confidentiality no less restrictive than the Receiving Party’s duty hereunder. The Receiving Party will protect the Disclosing Party’s Confidential Information from unauthorized use, access, or disclosure in the same manner as the Receiving Party protects its own confidential or proprietary information of a similar nature and with no less than reasonable care. This Agreement does not transfer ownership of Confidential Information or grant a license thereto.
- Confidential Information Exceptions. The Receiving Party’s obligations under this Section shall not apply to if such information: (a) was already lawfully known to the Receiving Party at the time of disclosure by the Disclosing Party; (b) was disclosed to the Receiving Party by a third party who had the right to make such disclosure without any confidentiality restrictions; (c) is, or through no fault of the Receiving Party has become, generally available to the public; or (d) was independently developed by the Receiving Party without access to, or use of, the Disclosing Party’s Confidential Information. In addition, the Receiving Party will be allowed to disclose Confidential Information of the Disclosing Party to the extent that such disclosure is required by law or by the order or a court of similar judicial or administrative body, provided that the Receiving Party notifies the Disclosing Party of such required disclosure promptly and in writing (unless prohibited by law) and reasonably cooperates with the Disclosing Party, at the Disclosing Party’s sole cost and expense, in any lawful action to contest or limit the scope of such required disclosure.
- Publicity. OnIy upon written agreement of the parties shall either party’s name and logo be used or presented on any website or any promotional and marketing activities.
- Term and Termination. This Agreement shall be in force and effect as of the Effective Date through the applicable subscription period purchased by Customer. Customer may terminate this Agreement at any time. TI may terminate this Agreement in the event Customer breaches the terms of this Agreement, including non-payment of Fees due herein. No refunds will be made in case of termination by the Customer prior to the expiration of the then current Subscription Period.
GENERAL TERMS of the Agreement: - Governing Law. This Agreement shall be governed by the laws of the Commonwealth of Massachusetts, without reference to its conflict of laws rules. The competent state and federal courts in Massachusetts shall have the exclusive jurisdiction over any dispute arising under this Agreement.
- Assignment. This Agreement and any rights under this Agreement may not be assigned by Customer; provided, however, Customer may assign this Agreement with the written consent of TI. Customer may assign this Agreement in case of a sale of all or substantially all of its assets of shares to a third party, or in the event or merger, acquisition or divestiture, as the case may be, provided that prior written notice is delivered to TI with respect to such assignment, no less than ninety (90) days prior to any such assignment; and the assignee agrees in writing to be subject to the terms of this Agreement. Any such purported assignment in violation of this section shall be null and void.
- Severability. If any provision of this Agreement will be held to be invalid, that provision shall be replaced with a valid provision implementing the intent of the parties at the time of the signing of this Agreement.
- Force Majeure. Except for Customer’s obligation to pay amounts due under this Agreement, neither party hereto shall be liable for any loss, damage, or penalty resulting from such party's failure to perform its obligations hereunder when such failure is due to events beyond its reasonable control, including, without limitation, flood, earthquake, fire, acts of God, military insurrection, civil riot, or labor strikes. It is hereby clarified that force majeure shall not relieve a Customer from its payment obligations hereunder.
- Entire Agreement. This Agreement (and exhibits attached thereto) unless subject to an Evaluation or Trial Period Agreement, constitutes the entire agreement between TI and Customer and supersedes any previous agreements or representations, either oral or written. Customer acknowledges that it has not relied upon any representations or warranties other than those expressly contained in this Agreement. This Agreement may be amended, terminated, or altered only by an instrument in writing signed by individuals of appropriate authority of both parties.
- Notices. Any notice or report required or permitted by this Agreement shall be deemed given if (i) delivered personally to an officer of the other party, (ii) sent by either party to the other by first class mail, postage prepaid, addressed to the other party at the address given below or such other address as to which such party shall give notice hereunder, or (iii) sent by email to the email address provided by either party or such other email address as to which such party shall give notice hereunder.
Lens AI Evaluation Agreement
Summary of Lens AI Evaluation Agreement:
- Customer is provided the opportunity to access and use the Lens AI to evaluate the service for a period of up to one hundred twenty (120) days, without further obligation.
- Customer can elect to enter into a paid subscription plan, or not, after the Evaluation Period.
- Customer can terminate this Agreement at any time. If not terminated by the parties, this Agreement will terminate at the end of the Evaluation Period without any liability to the Customer.
- This Agreement is subject to TI’s Terms of Service found here: {Lens AI Terms of Service}.
- TI will protect Customer’s data as confidential information.
- Overview; Binding Agreement. This Evaluation Agreement (the “Agreement”) is made by and between and applies to Thought Industries, Inc. (“TI”, “we”, or “us” herein), and the customer/user (“Customer”, or “you” herein) accepting the terms of this Agreement and accessing or using the Lens AI. By accepting these terms and accessing or using the Lens AI, you agree to be bound by this Agreement. If you do not agree to this Agreement, you are not allowed to access or use the Lens AI. The “Effective Date” of this Agreement is the date you first access or use any aspect of the Lens AI. If you are accessing or using the Lens AI in your capacity as an employee, consultant or agent of the contracting entity, you represent that you are an employee, consultant or agent of that entity, and that you have the authority to accept these terms and bind that entity to this Agreement. TI reserves the right to change or modify this Agreement, or any of our other policies or guidelines, at any time upon notice to you. We may provide that notice in a variety of ways, including, without limitation, sending you an email or posting the revised Agreement on our web site and revising the date at the top of this Agreement. Any changes or modifications will be effective after we provide notice that this Agreement has been modified. You acknowledge that your continued access or use of the Lens AI following such notice constitutes your acceptance of the modified Agreement. For the purposes of this Agreement: (i) “Lens AI” means the TI-proprietary SaaS Lens AI(s) that you will be allowed to use and access during the Evaluation Period, as suchLens AIs are set forth or described in any applicable Ordering Document; (ii) the “Evaluation Period” means the number of days that you will have to evaluate the Lens AI(s), as set forth in the Ordering Document (if no timeframe is set forth in the Ordering Document or in the event no Ordering Document is executed) the default Evaluation Period will be one hundred twenty (120) days from the Effective Date; and (iii) the “Ordering Document” is the order form or other ordering document completed by the Customer (including any applicable on-line form or on-line credit card purchase terms completed by Customer) that identifies the Customer and the applicable details the Lens AI(s) to be evaluated.
- Evaluation License; Restrictions. Subject to the terms of this Agreement and the Lens AI AI Terms of Service (TI Lens AI Terms of Service) which are incorporated herein by reference, TI grants you a revocable, limited, non-exclusive, nontransferable, non-sublicensable right to access and use the Lens AI(s) during the Evaluation Period, solely for the purpose of internally evaluating whether to purchase a paid subscription to the Lens AI(s), and not for any other purpose or use. Unless otherwise set forth in the Ordering Document, there is no fee associated with this grant of access during the Evaluation Period. If you decide that you want to use the Lens AI(s) beyond the Evaluation Period, you will need to buy a paid subscription, and accept a new agreement for that purpose; TI shall provide you with the necessary agreements for a paid subscription, should you elect to enter into such an arrangement. As between you and TI, TI owns all right, title and interest in and to the Lens AIs, and reserves all rights not granted herein. You agree not to: (i) sublicense, sell, rent, assign, or distribute the Lens AIs to third parties; (ii) allow any third party to access or use the Lens AIs under the rights granted to you herein; (iii) host the Lens AIs for the benefit of third parties; (iv) modify the Lens AIs, or any proprietary rights notices therein; or (v) disassemble, decompile, or reverse engineer the Lens AIs, or attempt to create any derivative works or competing products. Each party will bear its own costs associated with its performance under this Agreement.
- Term and Termination. Unless terminated as provided for in this Section 3, this Agreement will continue in effect throughout the Evaluation Period. This Agreement will automatically terminate without the requirement of notice at the end of the Evaluation Period unless the parties mutually agree in writing to an extension. Customer can terminate this Agreement at any time with written notice to TI. TI can terminate this Agreement immediately upon written notice in the event you breach the terms of this Agreement or any other agreement(s) made with TI or incorporated herein. In addition to the foregoing, either party can terminate this Agreement upon written notice to the other if the other party commits a material breach of any provision of this Agreement, and fails to cure the breach within thirty (30) days of receiving written notice, clearly describing the nature of the material breach. In addition to the foregoing, TI reserves the right to terminate this Agreement immediately upon written notice to you, and without giving you a cure period, if you breach any of the terms of this Agreement relating to our intellectual property (including your compliance with the access grant and any restrictions) or TI’s confidential information. When this Agreement terminates or expires: (i) the Evaluation Period will end; and (ii) you will no longer have the right to access or use the Lens AIs. The following provisions will survive the termination or expiration of this Agreement: Restrictions; No Warranty; Disclaimer; Confidentiality; Limitation of Liability; Miscellaneous.
- No Warranty; Disclaimer; Limitation of Liability. You acknowledge and agree that the Lens AIs are being provided “AS-IS” and without warranty of any kind, express or implied. WE HEREBY SPECIFICALLY DISCLAIM ALL WARRANTIES AND CONDITIONS, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING BUT NOT LIMITED TO WARRANTIES OR CONDITIONS OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. IN NO EVENT WILL WE BE LIABLE TO YOU OR TO ANY THIRD PARTY FOR DAMAGES OF ANY KIND, INCLUDING, WITHOUT LIMITATION, DIRECT, INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THIS AGREEMENT, HOWEVER CAUSED, AND WHETHER OR NOT WE HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
- Customer Warranty. When you access or use Lens AI(s) you represent and warrant as follows: (i) that you will not use the Lens AI for any purpose other than the limited evaluation set forth herein; and (ii) that your use of the Lens AI will comply with all applicable laws and regulations.
- Confidentiality. For the purposes of this Agreement, “Confidential Information” means any business or technical information that either party discloses to the other, in writing, orally, or by any other means, pursuant to this Agreement. For the purposes of this Agreement, the Lens AIs and associated documentation will be deemed to be TI Confidential Information, regardless of whether they are marked as such. Neither party will use the other party’s Confidential Information, except as permitted under this Agreement. Each party agrees to maintain in confidence and protect the other party’s Confidential Information using at least the same degree of care as it uses for its own information of a similar nature, but in all events at least a reasonable degree of care. Each party agrees to take all reasonable precautions to prevent any unauthorized disclosure of the other’s Confidential Information, including, without limitation, disclosing Confidential Information only to its employees, independent contractors, consultants, and legal and financial advisors (collectively, “Representatives”): (i) who have a need to know such information, (ii) who are parties to appropriate agreements sufficient to comply with this Section 6, and (iii) who are informed of the nondisclosure obligations imposed by this Section 6. Each party will be responsible for all acts and omissions of its Representatives. The foregoing obligations will not restrict either party from disclosing Confidential Information of the other party pursuant to the order or requirement of a court, administrative agency, or other governmental body, provided that the party required to make such a disclosure provides reasonable notice to the other party to enable them to contest such order or requirement. The restrictions set forth in this Section 6 shall remain in effect during the term of this Agreement, and for five (5) years thereafter. Notwithstanding the foregoing, to the extent that any Confidential Information is trade secret information, such Confidential Information will be protected in perpetuity for as long as it remains a trade secret. The restrictions set forth in this Section 6 will not apply with respect to any Confidential Information that: (i) was or becomes publicly known through no fault of the receiving party; (ii) was rightfully known or becomes rightfully known to the receiving party without confidential or proprietary restriction from a source other than the disclosing party who has a right to disclose it; (iii) is approved by the disclosing party for disclosure without restriction in a written document which is signed by a duly authorized officer of such disclosing party; or (iv) the receiving party independently develops without access to or use of the other party’s Confidential Information.
- Miscellaneous. The English version of this document will prevail over any translation. Any personal data contained in this Agreement (addresses, email, etc.) will be processed by the parties, as independent data controllers, in order to comply with the purpose of this Agreement, and will be kept for as long as the relationship is maintained or for as long as necessary in order to comply with applicable legal obligations. Any personal data processed on your behalf during the Evaluation Period by the Lens AI is subject to the terms of our DPA, found here: (TI Lens AI DPA). Individuals and data subjects whose personal data is processed by the Lens AI, may exercise their data protection rights by means of written notice in accordance with TI’s DPA. You agree to indemnify, defend, and hold TI harmless from and against any third-party claims or threatened suits, actions, claims, damages, and losses arising out of or relating to your access to or use of the Lens AIs, not in accordance with the terms of this Agreement. This Agreement will be governed by the laws of the Commonwealth of Massachusetts. Any legal action or proceeding arising under this Agreement will be brought exclusively in the appropriate federal or state courts located in Suffolk County, Massachusetts, and the parties irrevocably consent to the personal jurisdiction and venue there. The United Nations Convention on Contracts for the International Sale of Goods and the Uniform Computer Information Transactions Act will not apply. Neither party may assign this Agreement without the other party’s written consent. In the event that any provision of this Agreement is deemed unenforceable, this Agreement will be modified to give as much effect as possible to that provision. Any provision that cannot be modified or reformed in this way will be deemed deleted, and the remaining provisions of this Agreement will continue in full force and effect. A party’s obligations can only be waived in a writing signed by an authorized representative of the other party. The parties are independent contractors. This Agreement can only be amended in a writing signed by both parties. This Agreement (including the agreements incorporated herein) is the entire agreement of the parties with respect to its subject matter.
Lens AI Acceptable Use Policy for Thought Industries
Context:
This Acceptable Use Policy (“AUP”) is a straightforward, concise approach to mitigating potential risks of using Lens AI in inappropriate, unintended, and unacceptable settings or in industries that are unaligned with the true purpose and contractually permitted use of Lens AI. It is not Thought Industries’ final AUP or comprehensive approach to product policy, and it will be subject to on-going revision and updating, as further refinements to Lens AI are implemented.
Thought Industries, Inc. (“TI”) currently has no staff dedicated to overseeing and enforcing this policy and potential violations will be handled reactively; further, it is the duty of each TI customer to provide this AUP to its authorized users of the Lens AI and provide reasonably necessary instructions and prohibitions to its users.
Scope:
The Policy below assumes Lens AI is provided primarily on a B2B-basis, with TI’s customers operating as organized businesses, which then permit their authorized users to access and use the Lens AI.
Policy: You (and your authorized users) agree not to use Lens AI for the following activities and use cases. This list is representative and non-exhaustive; TI retains the right to revise and update the Policy.
- Adult industries or sexually explicit content and services;
- Bullying, harassment, or threatening behavior;
- Controlled and illegal substances (e.g. drugs, pharmaceuticals, etc.);
- Deceptive, fraudulent, or misleading practices and services (e.g. comment and review generation, impersonation, multi-level marketing and pyramid schemes, plagiarism, spam, etc.);
- Discrimination, hate speech, and hateful content;
- Automated decision making regarding natural persons;
- Gambling, lending, trading, or other financial activities;
- Tracking, locating or monitoring any natural person; queries of natural persons;
- Financial decision making or creditworthiness of any natural person;
- Health, medical, or therapy applications for natural persons;
- Inappropriate or invasive use of confidential or personal information;
- Influencing campaigns, elections, or other political activities;
- Interfering with or negatively impacting Lens AIs;
- Malware, phishing, or viruses; SPAM and marketing email;
- Products and services infringing on the intellectual property or rights of others;
- Products, services, or activities that violate applicable laws and regulations;
- Violence or harm against persons, animals, or property (including encouragement, facilitation, or support);
- Violent extremism or terrorism (including encouragement, facilitation, or support);
- Weapons, explosives, and dangerous materials; and
- Using Lens AI in violation of any natural person’s rights, including privacy rights as defined in applicable, global privacy laws
Lens AI Data Processing Agreement for Thought Industries
The scope and applicability of this Data Processing Agreement (“DPA”) applies to Thought Industries, Inc., a Massachusetts corporation, with its principal place of business at 6 Liberty Square, #6099, Boston, MA 02109, (“TI”) and its processing of Personal Data on your behalf; you (TI’s customer) are the “Controller” under this DPA and TI is the “Processor” in connection with the provision of TI’s Services specified in the applicable TI Terms of Service and Software as a Service (SaaS) Agreement for TI Lens AI (the “Agreement”); and more specifically, the processing of “User Information” and “Customer Data PII” under the terms of the Agreement. Unless otherwise expressly stated in the Agreement, this DPA shall be effective and remain in force for the full term of the Agreement. TI/Controller and the customer/Processor each may be referred to herein as a “Party” or collectively as the “Parties.”
- DEFINITIONS
- Capitalized terms used but not defined within this DPA will have the meaning set forth in the Agreement. The following capitalized terms used in this DPA will be defined as follows:
“Applicable Data Protection Laws” means all applicable laws, rules, regulations, and governmental requirements relating to the privacy, confidentiality, or security of Personal Data, as they may be amended or otherwise updated from time to time.
"Controller Affiliate" means an affiliate of Controller who is a beneficiary to the Agreement.
“Covered Data” means Personal Data that is: provided by or on behalf of Controller to Processor in connection with the Services.
“Data Subject” means a natural person whose Personal Data is Processed.
“Deidentified Data” means data created using Covered Data that cannot reasonably be linked to such Covered Data, directly or indirectly.
"EEA" means the European Economic Area including the European Union ("EU").
"GDPR" means Regulation (EU) 2016/679 (the "EU GDPR") or, where applicable, the "UK GDPR" as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the UK European Union (Withdrawal) Act 2018 or, where applicable, the equivalent provision under Swiss data protection law.
“Instruction” means any documented instruction, submitted by Controller to Processor, directing Processor to perform a specific action with regard to Covered Data, including but not limited to the description of the Services under the Agreement.
"Member State" means a member state of the EEA, being a member state of the European Union, Iceland, Norway, or Liechtenstein.
“Personal Data” means any data or information that: (a) is linked or reasonably linkable to an identified or identifiable natural person; or (b) is otherwise “personal data,” “personal information,” “personally identifiable information,” or similarly defined data or information under Applicable Data Protection Laws.
"Processing" means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means. “Process”, “Processes” and “Processed” will be interpreted accordingly.
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to (including unauthorized internal access to), Covered Data.
"Services" means the services to be provided by Processor pursuant to the Agreement.
"Standard Contractual Clauses" or “SCCs” means Module Two (controller to processor) and/or Module Three (processor to processor) of the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914, dated June 4, 2021.
"Sub-processor" means an entity appointed by Processor to Process Covered Data on its behalf.
“UK” means the United Kingdom.
“US Data Protection Laws” means, to the extent applicable, federal and state laws relating to data protection, the Processing of Personal Data, privacy and/or data protection in force from time to time in the United States, including (but not limited to) (as may be amended from time to time) the California Consumer Privacy Act of 2018 (CCPA), the California Consumer Privacy Rights Act (CPRA), the Colorado Privacy Act and applicable Colorado Consumer Protection Act, the Connecticut Personal Data Privacy and Online Monitoring Act, the Utah Consumer Privacy Act, the Virginia Consumer Data Protection Act, the Texas Data Privacy and Security Act, the Oregon Consumer Privacy Act.
- Interaction with the Agreement
- This DPA is incorporated into and forms an integral part of the Agreement. This DPA supplements and (in case of contradictions) supersedes the Agreement with respect to any Processing of Covered Data. Controller acknowledges that Processor’s Services are not designed, intended, or provided for the purpose of making predictions regarding any Data Subject, determining creditworthiness, or any other manner of automated decision-making regarding Data Subject(s). The scope of Processor’s Services is set forth in the Agreement, and Controller shall not permit any authorized user (with access to Processor Services under Controller’s Agreement with Processor) to utilize the Services for any other purpose.
- Any Processing operation as described in clause 4 (Details of Data Processing) and Schedule 1 to this DPA will be subject to this DPA.
- With respect to any Controller Affiliates, Controller warrants it is duly authorised to enter into the DPA for and on behalf of any such Controller Affiliates and, subject to clause 2.4, each Controller Affiliate shall be bound by the terms of this DPA as if they were the Controller. Controller will ensure that all obligations under this DPA will be passed on to the respective Controller Affiliate.
- Controller warrants that it is duly mandated by any Controller Affiliates on whose behalf Processor Processes Covered Data in accordance with this DPA to (a) enforce the terms of this DPA on behalf of Controller Affiliates, and to act on behalf of Controller Affiliates in the administration and conduct of any claims arising in connection with this DPA; and (b) receive and respond to any notices or communications under this DPA on behalf of Controller Affiliates.
- Controller will be the only point of contact for all communication between Controller Affiliates and Processor. The Parties acknowledge and agree that any notice or communication sent by Processor to Controller shall satisfy any obligation to send such notice or communication to a Controller Affiliate.
- Role of the Parties
The Parties acknowledge and agree that:
- for the purposes of this DPA and Processing Personal Data under the applicable terms of the Agreement, and for purposes of the GDPR, Processor acts as "processor" or "sub-processor" (as defined in the GDPR). Processor's function as processor or sub-processor will be determined by the then-applicable function of Controller in connection with processing Personal Data:
- Where Controller acts as a controller, Processor acts as a processor.
- Where Controller acts as a processor on behalf of another controller, Processor acts as a sub-processor.
- for the purposes of the US Data Protection Laws, Processor will act as a "service provider" or “processor” (as defined in US Data Protection Laws), as applicable, in its performance of its obligations pursuant to the Agreement and this DPA.
- Detail of Data Processing
- The details of the Processing of Personal Data under the Agreement and this DPA (such as subject matter, nature and purpose of the Processing, categories of Personal Data and Data Subjects) are described in the Agreement and in Schedule 1 to this DPA.
- Covered Data will only be Processed on behalf of and under the Instructions of Controller and in accordance with Applicable Data Protection Laws. The Agreement and this DPA will generally constitute Instructions for the Processing of Covered Data. Controller may issue further written Instructions in accordance with this DPA. Without limiting the foregoing, Processor is prohibited from:
- selling Covered Data or otherwise making Covered Data available to any third party for monetary or other valuable consideration;
- sharing Covered Data with any third party for cross-context behavioural advertising;
- retaining, using, or disclosing Covered Data for any purpose other than for the business purposes specified in the Agreement or as otherwise permitted by Applicable Data Protection Laws;
- retaining, using, or disclosing Covered Data outside of the direct business relationship between the Parties; and
- except as otherwise permitted by Applicable Data Protection Laws, combining Covered Data with Personal Data that Processor receives from or on behalf of another person or persons, or collects from its own interaction with the Data Subject.
- Processor will ensure that such personnel are subject to obligations reasonably consistent with the terms of this DPA and the Agreement.
- To the extent that any of the Instructions require Processing of Covered Data in a manner that falls outside the scope of the Services, Processor may:
- Notify the Controller that such Instructions fall outside the scope of Services under the Agreement and not carry out such Instructions, or at Processor’s election, make the performance of any such Instructions subject to the payment by Controller of any costs and expenses incurred by Processor or such additional charges as Processor may reasonably determine; or
- Terminate the Agreement and the Services.
- If Controller’s Instructions will cause Processor to Process Covered Data in violation of applicable law or outside the scope of the Agreement or the DPA, Processor shall promptly inform Controller thereof, unless prohibited by applicable law (without prejudice to the SCCs).
- Processor may (without prejudice to clause 11) Process Covered Data anywhere that Processor or its Sub-processors maintain facilities, subject to clause 5 of this DPA.
- Processor will reasonably cooperate and provide Controller with information to enable Controller to conduct and document any data protection assessments required under Applicable Data Protection Laws. In addition, Processor will notify Controller promptly if Processor determines that it can no longer meet its obligations under Applicable Data Protection Laws.
- Controller will have the right to take reasonable and appropriate steps to ensure that Processor uses Covered Data in a manner consistent with Controller’s obligations under Applicable Data Protection Laws.
- Processor is permitted to anonymize Covered Data through a reliable state of the art anonymization procedure and use such anonymized data for its internal business purposes, including for research, development of new products and services, and security purposes.
- Sub-processors
- Controller grants Processor the general authorisation to engage Sub-processors, subject to clause 5.2, as well as Processor's current Sub-processors listed in Schedule 5 as of the Effective Date.
- Processor will (i) enter into a written agreement with each Sub-processor imposing data protection obligations that, in substance, are no less protective of Covered Data than Processor’s obligations under this DPA to the extent applicable to the nature of the services provided by such Sub-Processor; and (ii) remain liable for each Sub-processor’s compliance with the obligations under this DPA.
- Processor will provide Controller with at least fifteen (15) days’ notice of any proposed changes to the Sub-processors it uses to Process Covered Data (including any addition or replacement via email including a link to the updated list of processors as referred to in clause 5.1). Controller may object to Processor’s use of a new Sub-processor based upon reasonable data privacy and data security concerns regarding the new Sub-processor (including when exercising its right to object under clause 9(a) of the SCCs if applicable) by providing Processor with written notice of the objection within ten (10) days after Processor has provided notice to Controller of such proposed change (an "Objection"). If Controller does not object to the engagement within the Objection period, consent regarding the engagement will be assumed. In the event Controller objects to Processor’s use of a new Sub-processor, Controller and Processor will work together in good faith to find a mutually acceptable resolution to address such Objection. If the Parties are unable to reach a mutually acceptable resolution within a reasonable timeframe, either Party may, as its sole and exclusive remedy, terminate the portion of the Agreement relating to the Services affected by such change by providing written notice to the other Party. During any such Objection period, Processor may suspend the affected portion of the Services. Controller may only request a pro-rata refund if Controller can prove the Objection is based on justified reasons of incompliance with Applicable Data Protection Laws.
- Data Subject Rights Requests
- As between the Parties, Controller will have sole discretion and responsibility in responding to the rights asserted by any individual in relation to Covered Data under Applicable Data Protection Laws, including requests, complaints, inquiries, and objections (each, a "Data Subject Request"). Controller shall have sole discretion and responsibility for verifying the identity of Data Subjects (making all reasonable efforts) and confirming the proper and legitimate nature of such Data Subject Requests.
- Processor will forward to Controller promptly any Data Subject Request received by Processor or any Sub-processor from an individual in relation to their Covered Data and may advise the individual to submit their request directly to Controller, otherwise, Processor shall not respond directly to Data Subject Requests.
- Processor will (taking into account the nature of the Processing of Covered Data) provide Controller with reasonable assistance as necessary for Controller to fulfil its obligation under Applicable Data Protection Laws to respond to Data Subject Requests, including if applicable, subject to the foregoing obligations, Controller’s obligation to respond to requests for exercising the rights set out in Applicable Data Protection Laws.
- Security and Audits
- Processor will implement and maintain appropriate technical and organizational data protection and security measures designed to ensure security of Covered Data, including, without limitation, protection against unauthorized or unlawful Processing and against accidental loss, destruction, or damage of or to it. When assessing the appropriate level of security, account will be taken in particular of the nature, scope, context and purpose of the Processing as well as the risks that are presented by the Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Covered Data.
- Processor will implement and maintain as a minimum standard the measures set out in Schedule 2.
- With respect to any audits, the Parties agree that:
- all such audits will be conducted:
- upon reasonable written notice to Processor;
- only once per year;
- only during Processor’s normal business hours; and
- in a manner that does not disrupt Processor’s business.
- Controller will:
- Enter into a confidentiality agreement with Processor prior to conducting the audit; and
- Ensure that its personnel comply with Processor’s policies and procedures when attending Processor’s premises, as notified to Controller by Processor.
- To conduct such audit, Controller may engage a third-party auditor subject to such auditor complying with the requirements under clause 7.3 and provided that such auditor is suitably qualified, independent and not a competitor of Processor.
- To request an audit, Controller must submit a detailed proposed audit plan to Processor at least two weeks in advance of the proposed audit date. Processor will review the proposed audit plan and work cooperatively with Controller to agree on a final audit plan. All such audits must be conducted subject to the agreed final audit plan and Processor’s health and safety or other relevant policies. Nothing in this clause 7.5 will require Processor to breach any duties of confidentiality.
- Controller will promptly notify Processor of any non-compliance discovered during the audit and provide Processor with any audit reports generated in connection with any agreement, unless prohibited by Applicable Data Protection Laws or otherwise instructed by a regulatory or government authority. Controller may use the reports only for the purposes of meeting Controller’s regulatory audit requirements and/or confirming compliance with the requirements of the DPA.
- Controller will bear the costs for any audit initiated by Controller. Controller shall reimburse Processor for any time expended by Processor or its Sub-processors in connection with such audits.
- Upon request, Processor will provide to Controller documentation reasonably evidencing the implementation of the technical and organizational data security measures in accordance with industry standards. Processor may, in its discretion, provide data protection compliance certifications issued by a commonly accepted certification issuer which has been audited by a data security expert, or by a publicly certified auditing company. If the requested audit scope is addressed in such a certification produced by a qualified third-party auditor within twelve (12) months of Controller’s audit request and Processor confirms there are no known material changes in the controls audited, Controller agrees to accept those findings in lieu of requesting an audit of the controls covered by the report
- Processor will audit its Sub-processors, or conduct adequate due diligence on a regular basis and will, upon Controller’s request, confirm their compliance with Applicable Data Protection Laws and the Sub-processors’ contractual obligations. Controller may request Processor to conduct further audits only in the event reasonably justified, and in such case(s) Processor will conduct further audits to the extent permissible.
- Security Incidents
Processor will notify Controller in writing without undue delay after becoming aware of any Security Incident, in any event within forty-eight (48) hours and reasonably cooperate in any obligation of Controller pursuant to Applicable Data Protection Laws to make any notifications, such as to individuals or supervisory authorities. Processor will take reasonable steps to contain, investigate, and mitigate any Security Incident, and will send Controller timely information about the Security Incident. Processor’s notification of or response to a Security Incident under this clause 8 will not be construed as an acknowledgement by Processor of any fault or liability with respect to the Security Incident.
Processor will provide reasonable assistance with Controller's investigation of the possible Security Incident and any notification obligation of Controller required under Applicable Data Protection Laws, such as in relation to individuals or supervisory authorities.
- Deletion and Return
Processor will, in any event, within forty-five (45) days of the date of termination or expiry of the Agreement (a) if requested to do so by Controller within that period, return a copy of all Covered Data or provide a self-service functionality allowing Controller to do the same; and (b) delete all other copies of Covered Data Processed by Processor or any Sub-processors. Processor shall not retain Covered Data for any purpose for more than sixty (60) days; unless stated otherwise in the Agreement, Processor shall automatically delete or anonymize all Covered Data within ninety (90) days following termination of the Agreement or termination of the Services for any reason.
- DPA Contract Period
This DPA will remain in effect for the duration of the Agreement, and shall remain in effect until, and automatically expire upon, Processor’s deletion of all Covered Data as described in this DPA.
- Standard Contractual Clauses
- The Parties agree that the terms of the Standard Contractual Clauses Module Two (Controller to Processor) and Module Three (Processor to Processor), as further specified in Schedule 3 of this DPA, are hereby incorporated by reference and will be deemed to have been executed by the Parties and apply to any transfers of Covered Data falling within the scope of the GDPR from Controller (as data exporter) to Processor (as data importer).
- To the extent applicable, the jurisdiction-specific addenda to the Standard Contractual Clauses set out in Schedule 3 are also incorporated herein by reference and will be deemed to have been executed by the Parties and apply to any transfers of Covered Data falling within the scope of Applicable Data Protection Laws in the listed jurisdiction(s) from Controller (as data exporter) to Processor (as data importer).
- Processor will provide Controller reasonable support to enable Controller’s compliance with the requirements imposed on international transfers of Covered Data. Processor will, upon Controller’s request, provide information to Controller which is reasonably necessary for Controller to complete a transfer impact assessment under Applicable Data Protection Laws.
- Processor further agrees to implement certain supplementary measures in order to enable Controller’s compliance with requirements imposed on international transfers of Covered Data under Applicable Data Protection Laws. Processor may charge Controller, and Controller will reimburse Processor, for any assistance provided by Processor with respect to any transfer impact assessment(s), data protection impact assessments or consultation with any supervisory authority of Controller; Processor shall reasonably cooperate with Controller by providing responses to any data privacy or security questionnaires regarding Processor’s supplementary measures described above.
- Deidentified Data
If Processor receives Deidentified Data from or on behalf of Controller, then Processor will:
- take reasonable measures to ensure the information cannot be associated with a Data Subject.
- publicly commit to Process the Deidentified Data solely in deidentified form and not to attempt to reidentify the information.
- contractually obligate any recipients of the Deidentified Data to comply with the foregoing requirements and Applicable Data Protection Laws.
Details of Processing
- List of Parties
The Parties are set out in the preamble to this DPA. With regard to any transfers of Covered Data falling within the scope of the GDPR from Controller to Processor, additional information regarding the data exporter and data importer is set out below.
- Data Exporter
The data exporter is: each of the Controller and/or Controller Affiliates operating in the countries which comprise the European Economic Area, UK and/or Switzerland and/or – to the extent agreed by the Parties – Controller and/or Controller Affiliates in any other country to the extent the GDPR applies.
The data exporter’s contact person’s name, position and contact details as well as (if appointed) the data protection officer’s name and contact details and (if relevant) the representative’s contact details are included in the Agreement or will be disclosed to Processor upon request.
The activities relevant to the data transfer under these Clauses are defined by the Agreement and the data exporter who decides on the scope of the Processing of Personal Data in connection with the Services further described in section B of this Schedule 1.
- Data Importer
The data importer is: Thought Industries, Inc., 6 Liberty Square, #6099, Boston, MA 02019, United States.
The data importer’s contact person and contact details are included in the Agreement or will be disclosed to Controller upon request.
The data importer’s activities relevant to the data transfer under these Clauses are as follows: the data importer Processes Personal Data provided by the data exporter on behalf of the data exporter in connection with providing the Services to the data exporter as further described in section B of this Schedule 1 and in the Agreement.
Description of Processing
- Categories of Data Subjects
The categories of Data Subjects whose Personal Data are Processed: Determined by the Controller (under the applicable terms of the Agreement).
- Categories of Personal Data
The Processed categories of Personal Data are: Determined by the Controller (under the applicable terms of the Agreement); includes User Information and Customer Data PII, as defined in the Agreement.
- Special categories of Personal Data (if applicable)
The Processed Personal Data includes the following special categories of data: None.
- Frequency of the Processing
The Processing is performed on a continuous basis for the duration of the Agreement and is determined by Controller’s configuration of the Services.
- Subject matter and nature of the Processing
The subject matter of the Processing is: To provide the Services to the Controller which involves the third-party provision of a natural language-based, artificial intelligence-based machine-learning generated responses (output) based upon Controller’s prompts (input) as further described in the Agreement.
The nature of the Processing is the collection, storage, organisation and structuring of Personal Data to provide the Services to the Controller. Disclosure by transmission to third party sub-processors in order to provide the Services and erasure and destruction as per data retention requirements in accordance with Applicable Data Protection Laws.
- Purpose(s) of the data transfer and further Processing
The purpose/s of the data transfer and further Processing is: To provide the Services to Controller pursuant to the Agreement and as may be further agreed upon by Controller and Processor.
- Storage Limitation
The period during which the Personal Data will be Processed, or, if that is not possible, the criteria used to determine that period: The duration is defined in this DPA.
- Sub-processor (if applicable)
For Processing by sub-processors, specify subject matter, nature, and duration of the Processing: To provide Processing system capability to Processor (as described in Schedule 5) to provide the Services described in the Agreement.
- Competent Supervisory Authority
Identify the competent supervisory authority/ies in accordance with clause 13 of the SCCs
Where the data exporter is established in an EU Member State*: The supervisory authority of the country in which the data exporter established is the competent authority.*
Where the data exporter is not established in an EU Member State, but falls within the territorial scope of application of the GDPR in accordance with its Article 3(2) and has appointed a representative pursuant to Article 27(1) of the GDPR*: The competent supervisory authority is the one of the Member State in which the representative is established.*
Where the data exporter is not established in an EU Member State, but falls within the territorial scope of application of the GDPR in accordance with its Article 3(2) without, however, having to appoint a representative pursuant to Article 27(2) of the GDPR*: The competent supervisory authority is the supervisory authority of Ireland.*
Technical and Organizational Measures
Processor has implemented the following technical and organizational measures (including any relevant certifications when applicable) to ensure an appropriate level of security, taking into account the nature, scope, context, and purpose of the processing, as well as the risks for the rights and freedoms of natural persons:
1) Organizational management and dedicated staff responsible for the development, implementation, and maintenance of Processor’s information security program.
2) Audit and risk assessment procedures for the purposes of periodic review and assessment of risks to Processor’s organization, monitoring and maintaining compliance with Processor’s policies and procedures, and reporting the condition of its information security and compliance to internal senior management.
3) Utilization of commercially available and industry standard encryption technologies for Covered Data that is:
- a) being transmitted by Processor over public networks (i.e., the Internet) or when transmitted wirelessly; or
- b) at rest or stored on portable or removable media (i.e., laptop computers, CD/DVD, USB drives, back-up tapes).
4) Data security controls which include at a minimum, but may not be limited to, logical segregation of data, logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions, (e.g., granting access on a need-to-know and least privilege basis, use of unique IDs and passwords for all users, periodic review, and revoking/changing access promptly when employment terminates or changes in job functions occur).
5) Password controls designed to manage and control password strength, expiration and usage including prohibiting users from sharing passwords and requiring that Processor’s passwords that are assigned to its employees; controls include appropriate password security requirements, and specific time and use limitations for passwords.
6) System audit or event logging and related monitoring procedures to proactively record user access and system activity for routine review.
7) Physical and environmental security of data center, server room facilities and other areas containing Personal Data designed to: (i) protect information assets from unauthorized physical access, (ii) manage, monitor, and log movement of persons into and out of Processor facilities, and (iii) guard against environmental hazards such as heat, fire, and water damage.
8) Operational procedures and controls to provide for configuration, monitoring and maintenance of technology and information systems according to prescribed internal and adopted industry standards, including secure disposal of systems and media to render all information or data contained therein as undecipherable or unrecoverable prior to final disposal or release from Processor’s possession.
9) Change management procedures and tracking mechanisms designed to test, approve, and monitor all changes to Processor’s technology and information assets.
10) Incident / problem management procedures design to allow Processor to investigate, respond to, mitigate, and notify of events related to Processor’s technology and information assets.
11) Network security controls that provide for the use of firewall systems and other traffic and event correlation procedures designed to protect systems from intrusion and limit the scope of any successful attack.
12) Vulnerability assessment, patch management and threat protection technologies and scheduled monitoring procedures designed to identify, assess, mitigate, and protect against identified security threats, viruses, and other malicious code.
13) Business resiliency/continuity plan and procedures designed to maintain service and/or recovery from foreseeable emergency situations or disasters.
Standard Contractual Clauses
- EU SCCS
The Standard Contractual Clauses will apply to any Processing of Covered Data that is subject to the GDPR. For the purposes of the Standard Contractual Clauses:
- Module Two will apply in the case of the Processing under clause 3.1(a)(i) of the DPA and Module Three will apply in the case of Processing under clause 3.1(a)(ii) of the DPA.
- Clause 7 of the Standard Contractual Clauses (Docking Clause) does not apply.
- Clause 9(a) option 2 (General written authorization) is selected, and the time period to be specified is determined in clause 5.3 of the DPA.
- The option in Clause 11(a) of the Standard Contractual Clauses (Independent dispute resolution body) does not apply.
- With regard to Clause 17 of the Standard Contractual Clauses (Governing law), the Parties agree that, option 1 will apply and the governing law will be the law of the Republic of Ireland.
- In Clause 18 of the Standard Contractual Clauses (Choice of forum and jurisdiction), the Parties submit themselves to the jurisdiction of the courts of the Republic of Ireland.
- For the Purpose of Annex I of the Standard Contractual Clauses, Schedule 1 of the DPA contains the specifications regarding the parties, the description of transfer, and the competent supervisory authority
- For the Purpose of Annex II of the Standard Contractual Clauses, Schedule 2 of the DPA contains the technical and organizational measures.
- The specifications for Annex III of the Standard Contractual Clauses, are determined by clause 5.1 of the DPA. The Sub-processor’s contact person’s name, position and contact details will be provided by Processor upon request.
- UK Addendum
This UK Addendum will apply to any Processing of Covered Data that is subject to the UK GDPR or to both the UK GDPR and the GDPR.
- As used in this UK Addendum:
“Approved Addendum” means the template addendum, version B.1.0 issued by the UK Information Commissioner under S119A(1) Data Protection Act 2018 and laid before the UK Parliament on 2 February 2022, as it may be revised according to Section 18 of the Mandatory Clauses.
“Mandatory Clauses” means “Part 2: Mandatory Clauses” of the Approved Addendum.
- With respect to any transfers of Covered Data falling within the scope of the UK GDPR from Controller (as data exporter) to Processor (as data importer):
- the Approved Addendum as further specified in this Schedule 5 will form part of this DPA, and the Standard Contractual Clauses will be read and interpreted in light of the provisions of the Approved Addendum, to the extent necessary according to Clause 12 lit. 1 of the Mandatory Clauses;
- In deviation to Table 1 of the Approved Addendum and in accordance with Clause 17 of the Mandatory Clauses, the parties are further specified in Schedule 1,A. of this DPA.
- The selected Modules and Clauses to be determined according to Table 2 of the Approved Addendum are further specified in this Schedule as amended by the Mandatory Clauses.
- Annex 1 A and B of Table 3 to the Approved Addendum are specified by Schedule 1 of this DPA, Annex II of the Approved Addendum is further specified by Schedule 2 of this DPA, and Annex III of the Approved Addendum is further specified by Schedule 1,B.10 of this DPA.
- Processor (as data importer) may end this DPA, to the extent the Approved Addendum applies, in accordance with clause 19 of the Mandatory Clauses;
- Clause 16 of the Mandatory Clauses will not apply.
- Swiss Addendum
This Swiss Addendum will apply to any Processing of Covered Data that is subject to Swiss Data Protection Laws (as defined below) or to both Swiss Data Protection Laws and the GDPR. - Interpretation of this Addendum
- Where this Addendum uses terms that are defined in the Standard Contractual Clauses, those terms will have the same meaning as in the Standard Contractual Clauses. In addition, the following terms have the following meanings:
| This Addendum | This Addendum to the Clauses |
|---|---|
| Clauses | The Standard Contractual Clauses as further specified in this Schedule |
| Swiss Data Protection Laws | The Swiss Federal Act on Data Protection of 19 June 1992 and the Swiss Ordinance to the Swiss Federal Act on Data Protection of 14 June 1993, and any new or revised version of these laws that may enter into force from time to time. |
- This Addendum will be read and interpreted in the light of the provisions of Swiss Data Protection Laws, and so that if fulfils the intention for it to provide the appropriate safeguards as required by Article 46 GDPR and/or Article 6(2)(a) of the Swiss Data Protection Laws, as the case may be.
- This Addendum will not be interpreted in a way that conflicts with rights and obligations provided for in Swiss Data Protection Laws.
- Any references to legislation (or specific provisions of legislation) means that legislation (or specific provision) as it may change over time. This includes where that legislation (or specific provision) has been consolidated, re-enacted and/or replaced after this Addendum has been entered into.
- Hierarchy
In the event of a conflict or inconsistency between this Addendum and the provisions of the Clauses or other related agreements between the Parties, existing at the time this Addendum is agreed or entered into thereafter, the provisions which provide the most protection to Data Subjects will prevail.
- Incorporation of the Clauses
- In relation to any Processing of Personal Data subject to Swiss Data Protection Laws or to both Swiss Data Protection Laws and the GDPR, this Addendum amends the DPA the Standard Contractual Clauses to the extent necessary so they operate:
- for transfers made by the data exporter to the data importer, to the extent that Swiss Data Protection Laws or Swiss Data Protection Laws and the GDPR apply to the data exporter’s Processing when making that transfer; and
- to provide appropriate safeguards for the transfers in accordance with Article 46 of the GDPR and/or Article 6(2)(a) of the Swiss Data Protection Laws, as the case may be.
- To the extent that any Processing of Personal Data is exclusively subject to Swiss Data Protection Laws, the amendments to the DPA including the SCCs, as further specified in this Schedule and as required by clause 3.1 of this Swiss Addendum, include (without limitation):
- References to the "Clauses" or the "SCCs" mean this Swiss Addendum as it amends the SCCs.
- Clause 6 Description of the transfer(s) is replaced with:
"The details of the transfer(s), and in particular the categories of Personal Data that are transferred and the purpose(s) for which they are transferred, are those specified in Schedule 1 of this DPA where Swiss Data Protection Laws apply to the data exporter’s Processing when making that transfer."
- References to "Regulation (EU) 2016/679" or "that Regulation" or "“GDPR" are replaced by "Swiss Data Protection Laws" and references to specific Article(s) of "Regulation (EU) 2016/679" or "GDPR" are replaced with the equivalent Article or Section of Swiss Data Protection Laws extent applicable.
- References to Regulation (EU) 2018/1725 are removed.
- References to the "European Union", "Union", "EU" and "EU Member State" are all replaced with "Switzerland".
- Clause 13(a) and Part C of Annex I are not used; the "competent supervisory authority" is the Federal Data Protection and Information Commissioner (the "FDPIC") insofar as the transfers are governed by Swiss Data Protection Laws;
- Clause 17 is replaced to state
"These Clauses are governed by the laws of Switzerland insofar as the transfers are governed by Swiss Data Protection Laws".
- Clause 18 is replaced to state:
"Any dispute arising from these Clauses relating to Swiss Data Protection Laws will be resolved by the courts of Switzerland. A Data Subject may also bring legal proceedings against the data exporter and/or data importer before the courts of Switzerland in which he/she has his/her habitual residence. The Parties agree to submit themselves to the jurisdiction of such courts."
Until the entry into force of the revised Swiss Data Protection Laws, the Clauses will also protect Personal Data of legal entities and legal entities will receive the same protection under the Clauses as natural persons.
- To the extent that any Processing of Personal Data is subject to both Swiss Data Protection Laws and the GDPR, the DPA including the Clauses as further specified in this Schedule will apply (i) as is and (ii) additionally, to the extent that a transfer is subject to Swiss Data Protection Laws, as amended by clauses 3.1 and 3.3 of this Swiss Addendum, with the sole exception that Clause 17 of the SCCs will not be replaced as stipulated under clause 3.3(b)(vii) of this Swiss Addendum.
- Controller warrants that it and/or Controller Affiliates have made any notifications to the FDPIC which are required under Swiss Data Protection Laws.
4.0 California Addendum (California, USA)
4.1 The following additional provisions apply to Processor acting as a Service Provider regarding the Processing of Covered Data which may include Personal Information (as defined under the CCPA/CPRA) that is lawfully subject to the CCPA and/or CPRA, as applicable.
- Definitions: Unless otherwise indicated in this DPA, the capitalized terms used in this section shall have the meaning assigned to them in the California Privacy Rights Act (“CPRA” or the “Act”), codified at Cal. Civ. Code §1798.100 et seq., effective January 1, 2023.
- “Business Purpose(s)” means Processing Personal Information on behalf of Controller for the following purposes: (i) to provide the Services as specifically defined in the Agreement; (ii) to detect security incidents or protect the Personal Information against malicious, deceptive, fraudulent or illegal activity; or (iii) otherwise as expressly permitted by the CPRA or the CPRA Regulations.
- “CCPA” means Title 1.81.5 California Consumer Privacy Act of 2018 (California Civil Code §§ 1798.100–1798.199), as amended or superseded from time to time.
- “Consumer” means a California resident (a) who is a natural person, and (b) whose Personal Information is Processed by Service Provider on Controller’s behalf for the purposes stated in the Agreement and this DPA.
- “CPRA Regulations” means final regulations implementing the CPRA after those regulations go into effect.
- “Personal Information” shall have the meaning set forth in the CPRA but shall be limited to Personal Information of California Consumers which Service Provider Processes on Controller’s behalf pursuant to the Agreement and this DPA.
- Processing Of Personal Information: Controller is a Business and appoints Processor as its Service Provider (as defined under the CPRA) to Process Personal Information only for the Business Purposes. Service Provider shall comply with all applicable sections of the CPRA and/or the CPRA Regulations, including providing the same level of protection for Personal Information as the CPRA requires Controller, as a Business, to provide. Service Provider grants Controller the right to take reasonable and appropriate steps to help ensure that Service Provider uses Personal Information consistent with the CPRA and to stop and remediate unauthorized use of Personal Information.
- Restrictions On Processing Personal Information: Service Provider is prohibited from: (i) Processing Personal Information for any purposes but for the Business Purposes; (ii) Processing Personal Information for any additional commercial purpose (other than the Business Purposes) including in the servicing of a different business, unless otherwise expressly permitted by the CPRA or the CPRA Regulations; (iii) Processing Personal Information outside the direct business relationship between Controller and Service Provider unless otherwise expressly permitted by the CPRA or the CPRA Regulations; (iv) Selling or Sharing Personal Information; (v) combining Personal Information with personal information that it receives from, or on behalf of, another person or persons, or Collects from its own interaction with a Consumer (except as permitted by the CPRA Regulations); or (vi) Processing the Personal Information for any other purpose except as permitted by this DPA.
- Inability To Comply With CPRA: Service Provider shall, within five (5) business days, notify Controller after Service Provider determines that it no longer can meet its obligations under this Addendum, the CPRA or the CPRA Regulations. In the event of Service Provider’s inability to meet its obligations, Controller may, in its discretion, (i) take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information, or (ii) terminate the Service Agreement.
Processor’s Additional Supplementary Measures
Processor further commits to implementing additional supplementary measures based on guidance provided by EU supervisory authorities in order to enhance the protection of Covered Data in relation to the Processing in a third country. Processor’s additional supplementary measures shall include appropriate technical and organizational measures to provide the Controller with assurances regarding the privacy and security of Covered Data. Upon written request, Processor shall provide Controller with applicable details and specifications regarding the implementation and maintenance of additional technical and organizational measures as required by Applicable Data Protection Laws.
Sub-processors
| Name | Address | Business Category | Location of Processing | Data Processed | Purpose of Processing | Retention (Company Specific) |
|---|---|---|---|---|---|---|
| FiveTran | 1221 Broadway, Suite 2400, Oakland, CA 94612, United States | ETL / Data Pipelines | United States | Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer | Moving data between data sources. | Typically <24 hours for pipelined data, connection credentials may be retained up to 30 days |
| Neon | 209 Orange Street, City of Wilmington, County of New Castle, Delaware 19801 | Serverless Postgres Database | United States | Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer | Product serverless databases with autoscaling | TI controls this retention = duration of services and up to 45 days post churn. Backups age off after 90 days |
| Inngest | 600 California Street Suite 1200 San Francisco, CA 94109 | Cloud Job Processing | United States | Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer | AI code to handle the backend infra, queueing, scaling, concurrency, throttling, rate limiting, and observability | TI controls this retention = duration of services and up to 45 days post churn. Backups age off after 90 days |
| Clerk | 660 King Street Unit 345 San Francisco, California, 94107 | Cloud Authentication and Authorization | United States | Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer | Product user authentication and management | TI controls this retention = duration of services and up to 45 days post churn. Backups age off after 90 days |
| Vercel Frontend Cloud | 650 California St San Francisco, CA 94108 | Serverless Application Hosting | Global CDN for Assets United States-Generated Content | Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer | Managed Infrastructure (AWS) | Logs are stored for 1 day |
| OpenAI API Platform | 3180 18th St. San Francisco, CA 94110 | LLM Inference | United States | Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer | Customer data processing | No data retention |
| Anthropic API (Claude) | 500 Howard Street San Francisco, CA 94105 | LLM Inference | United States | Customer info, company name, personal name, email address, location, order history, order information, and any other customer-provided data sent for inference | Customer data processing | Deleted within 30 days (exceptions may apply; ZDR available by agreement) |
| Google Cloud Vertex AI | 1600 Amphitheatre Pkwy Mountain View, CA 94043 | LLM Inference | United States | Customer info, company name, personal name, email address, location, order history, order information, and any other customer-provided data sent for inference | Customer data processing | By default, in-memory caching (not at-rest) with ~24-hour TTL; configurable/disable-able; ZDR-related controls available |
| Databricks, Inc. | 160 Spear St, 15th Floor San Francisco, CA 94105 | Data analytics / ETL / warehousing (customer data processing platform) | United States | Customer info, company name, personal name, email address, location, order history, order information, and any other customer-provided data sent to TI. | Customer data processing | Retained for the term of the agreement and any period after termination during which Databricks processes the data per the agreement |
| Cloudflare | 101 Townsend St, San Francisco, CA 94107, United States | DDoS/Bot Protection, Proxying, SSL Certificate Management. | United States | Domains/Urls, IP, Location, Browser info | DDoS/Bot protection | Up to 30 Days |
| Sentry | 45 Fremont Street, 8th Floor, San Francisco, CA 94105 | Data Logging | United States | Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer | Logging for application improvement, security, and analytics purposes | Logs retained for 90 Days |
| Stripe | 354 Oyster Point Boulevard, South San Francisco, CA 94080 | Ecommerce / Payment Processing | United States | Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer, Card Data | Payment processing | Varies depending on legal and regulatory obligations. See Stripe Security And Retention |
| Google Analytics | 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA | Product Analytics | United States | Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer | Product Analytics | Retained for the term of the agreement and any period after termination per the agreement |
| Posthog | 2261 Market Street, Suite 4008, San Francisco, CA 94114, United States | Product Analytics | United States | Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer | Product Analytics | Retained for the term of the agreement and any period after termination per the agreement |
| Data Dog | 620 8th Ave 45th Floor New York, NY 10018 USA | Data Logging | United States | Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer | Logging for application improvement, security, and analytics purposes | Logs retained for 90 Days |