valastic
Legal

Data Processing Agreement

Effective date: January 15, 2025

This Data Processing Agreement ("DPA") is entered into between Valastic, Inc. ("Valastic" or "Data Processor") and the customer ("Data Controller") and supplements the Valastic Terms of Service. This DPA reflects the parties' obligations under applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA).

Definitions

"Data Controller" means the customer who determines the purposes and means of processing personal data. "Data Processor" means Valastic, which processes personal data on behalf of the Data Controller. "Data Subject" means the identified or identifiable natural person to whom personal data relates.

"Personal Data" means any information relating to an identified or identifiable natural person processed by Valastic on behalf of the Data Controller in connection with the Services. "Processing" means any operation performed on personal data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, or erasure.

This Data Processing Agreement ("DPA") forms part of and is incorporated into the Valastic Terms of Service and any applicable Order Forms between Valastic and the customer.

Scope and Purpose

This DPA applies to the processing of Personal Data by Valastic on behalf of the Data Controller in connection with the provision of the Valastic platform and services. The subject matter, duration, nature, and purpose of the processing are as described in the Terms of Service and any applicable Order Forms.

The types of Personal Data processed include names, email addresses, phone numbers, company information, form submissions, workflow data, and any other data submitted by the Data Controller or its users through the Services. The categories of Data Subjects include the Data Controller's employees, contractors, customers, and other individuals whose data is submitted through the platform.

Data Processing Obligations

Valastic shall process Personal Data only on documented instructions from the Data Controller, including with regard to transfers of Personal Data to a third country or international organization, unless required to do so by applicable law. In such cases, Valastic shall inform the Data Controller of the legal requirement before processing, unless prohibited by law.

Valastic shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Valastic shall implement and maintain appropriate technical and organizational security measures as described in this DPA.

Valastic shall not engage another processor without prior specific or general written authorization of the Data Controller. Where Valastic engages a sub-processor under general written authorization, Valastic shall inform the Data Controller of any intended changes, giving the Data Controller the opportunity to object within 30 days.

Sub-processors

Valastic maintains a list of approved sub-processors who process Personal Data on behalf of Valastic. The current list is available upon request and at trust.valastic.com. Valastic will notify the Data Controller at least 30 days before engaging any new sub-processor.

All sub-processors are contractually bound to provide at least the same level of data protection as set out in this DPA. Valastic remains fully liable for the acts and omissions of its sub-processors.

The Data Controller may object to the engagement of a new sub-processor within 30 days of receiving notification. If the Data Controller objects on reasonable data protection grounds, the parties shall discuss the matter in good faith. If no resolution is reached, the Data Controller may terminate the affected services without penalty.

International Data Transfers

Valastic processes data in data centers located within the United States and the European Economic Area. Where Personal Data is transferred from the EEA, United Kingdom, or Switzerland to a country outside those jurisdictions, Valastic ensures that appropriate safeguards are in place.

Valastic relies on Standard Contractual Clauses (SCCs) approved by the European Commission as the primary mechanism for international data transfers. A copy of the applicable SCCs is incorporated into this DPA by reference. Valastic will update the SCCs as new versions are adopted by the European Commission.

Where required, Valastic also conducts Transfer Impact Assessments to evaluate whether the legal framework of the destination country provides adequate protection for Personal Data, and implements supplementary measures as necessary.

Security Measures

Valastic implements and maintains appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures are reviewed regularly and updated as necessary.

Specific measures include: encryption of Personal Data in transit and at rest; regular testing and evaluation of the effectiveness of security measures; measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems; and the ability to restore availability and access to Personal Data in a timely manner in the event of a physical or technical incident.

Valastic will promptly notify the Data Controller without undue delay and no later than 48 hours after becoming aware of a personal data breach affecting the Data Controller's Personal Data, and shall provide sufficient information to enable the Data Controller to meet its obligations to report or inform Data Subjects of the breach.

Data Subject Rights

Valastic shall assist the Data Controller in responding to requests from Data Subjects exercising their rights under applicable data protection laws, including rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing.

If Valastic receives a request directly from a Data Subject, Valastic shall promptly notify the Data Controller (within 5 business days) and shall not respond to the request without the Data Controller's authorization, except where required by applicable law.

Where technically feasible and upon the Data Controller's request, Valastic will provide the Data Controller with the ability to export Personal Data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance.

Term and Termination

This DPA shall remain in effect for the duration of the Data Controller's use of the Valastic Services and until all Personal Data is returned or deleted in accordance with the Terms of Service.

Upon termination of the Services, Valastic shall, at the Data Controller's choice, return or delete all Personal Data within 30 days, except where retention is required by applicable law. Valastic will certify in writing that all Personal Data has been returned or securely deleted.

The obligations of Valastic under this DPA with respect to the processing of Personal Data shall survive the termination of the Terms of Service to the extent that Valastic retains any Personal Data.