Data Processing Agreement (DPA)
This Data Processing Agreement (“DPA”) is entered into by Clay Labs Inc. (“Clay”) and the Clay customer identified in the agreement for Clay services (“Customer”) (each a “Party”; collectively the “Parties”) and is incorporated by reference into the applicable agreement governing Customer’s use of Clay’s services described at https://university.clay.com/docs (the “Agreement”) between the Parties. All capitalized terms used in this DPA but not defined will have the meaning set forth in the Agreement or under Applicable Data Protection Law (defined below). This DPA prevails over any conflicting term of the Agreement but does not otherwise modify the Agreement.
1. DEFINITIONS.
1.1 “Controller”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing”, “Processor”, and “Supervisory Authority” have the meaning given to them in Applicable Data Protection Law, and their cognate terms shall be construed accordingly;
1.2 “Consumer” has the meaning defined in the U.S. Privacy Laws (defined below);
1.3 “Customer Personal Data” means Personal Data Processed by Clay as a Processor on behalf of Customer;
1.4 “Applicable Data Protection Law” means the following data protection law(s), as applicable, including any subsequent amendments, modifications and revisions thereto: (i) European Data Protection Law, including the GDPR; and (ii) the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (“CCPA”) and any other applicable U.S. federal and state privacy laws that apply generally to the processing of individuals’ Personal Data and that do not apply solely to specific industry sectors (e.g., financial institutions), specific demographics (e.g., children), or specific classes of information (e.g., health or biometric information) (“U.S. Privacy Laws”);
1.5 “Data Enrichment Tools” means the tools and APIs that Clay makes available to its Customers to enable them to query third-party data providers or the internet to obtain Marketplace Data or information that is useful to them;
1.6 “Data Subject Rights” means Data Subjects’ rights to information, access, rectification, erasure, restriction, portability, objection, the right to withdraw consent, and the right not to be subject to automated individual decision-making in accordance with Applicable Data Protection Law;
1.7 “European Data Protection Law” means the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the e-Privacy Directive 2002/58/EC (as amended by Directive 2009/136/EC), their national implementations in the European Economic Area (“EEA”), including the European Union, and all other data protection laws of the EEA, the United Kingdom (“UK”), and Switzerland, each as applicable, and as may be amended or replaced from time to time;
1.8 “International Data Transfer” means any disclosure of Customer Personal Data by an organization subject to European Data Protection Law to another organization located outside the EEA, the UK, or Switzerland (jointly “Europe”) where such disclosure would otherwise be prohibited by European Data Protection Law;
1.9 “Marketplace Data” means the business contact, firmographic, and other data records made available by Clay or third-party data providers through the Clay data marketplace for access, import, and use by Customer as part of the Services.
1.10 “Personal Data” means any information which is related to an identified or identifiable natural person, and includes “personal data,” “personal information,” “personally identifiable information,” and analogous terms, as defined by Applicable Data Protection Law, that Clay processes to provide the services under the Agreement
1.11 “Proprietary Data” means the subset of Marketplace Data that Clay obtains from third-party data providers, stores on its systems, and provides to its Customers directly;
1.12 “Share,” “Shared,” and “Sharing” have the meaning defined in the CCPA;
1.13 “Sale” and “Selling” have the meaning defined in the U.S. Privacy Laws;
1.14 “Subprocessor” means a Processor engaged by Clay to Process Customer Personal Data;
1.15 “SCCs” means the clauses annexed to the EU Commission Implementing Decision 2021/914 of June 4, 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council as amended or replaced from time to time; and
1.16 “UK Addendum” means the addendum to the SCCs issued by the UK Information Commissioner under Section 119A(1) of the UK Data Protection Act 2018 (version B1.0, in force March 21, 2022).
- SCOPE. With the exception of Sections 3.2, 11.2(a) and 11.4(a), this DPA applies to the Processing of Customer Personal Data by Clay subject to Applicable Data Protection Law to provide the Services. The subject matter, nature and purpose of the Processing, the types of Customer Personal Data and categories of Data Subjects are set out in Annexes I.A, I.B and I.C, which are an integral part of this DPA.
- ROLES OF THE PARTIES.
3.1 Clay’s Processor Role. Customer is a Controller and appoints Clay as a Processor on behalf of Customer for the limited and specific purposes set forth in Annexes I.B and I.C, which include Clay’s processing of Customer Personal Data and Customer’s use of the Data Enrichment Tools. Customer is responsible for compliance with the requirements of Applicable Data Protection Law applicable to Controllers.
3.2 Clay’s Controller Role. Where Customer receives Proprietary Data, both parties act as separate and independent Controllers for the sharing of such Proprietary Data, as further described in Annex I.A. In this case, both parties are separately responsible for compliance with their own obligations under Applicable Data Protection Law including, as applicable, to provide notice and ensure a lawful ground for their Processing of Personal Data (such as obtaining consent where applicable), fulfill any requests to exercise their Data Subject Rights, and handle and notify any Personal Data Breaches.
- Where Customer receives Proprietary Data, Customer acts as a Third Party as defined under the CCPA and agrees to the following terms:
- Clay is making Personal Data available to Customer for the limited and specific purposes set forth in Annex I.A. Customer shall only use Personal Data it receives from Clay for those specific and limited purposes.
- Customer agrees to comply with all applicable sections of the applicable U.S. Privacy Laws.
- Upon reasonable request, Customer must make available to Clay all information necessary to demonstrate compliance with the obligations of this Section 3.2(a) of the DPA.
- Customer shall promptly notify Clay if it determines that it can no longer meet its obligations under applicable U.S. Privacy Laws. Upon receiving notice from Customer in accordance with this subsection, Clay may direct Customer to take reasonable and appropriate steps to stop and remediate unauthorized use of Proprietary Data.
- INSTRUCTIONS.
4.1 Clay will Process Customer Personal Data to provide the Services and in accordance with Customer’s documented instructions. Customer acknowledges that Clay may Process Personal Data relating to the operation, support, or use of the Services for its own business purposes, such as billing, account management, data analysis, benchmarking, technical support, product development, and compliance with law. Clay is the Controller for such Processing and will Process such data in accordance with Applicable Data Protection Law.
4.2 Clay shall comply with Applicable Data Protection Law in the Processing of Customer Personal Data, provide the level of privacy protection required by Applicable Data Protection Law and provide Customer with all reasonably-requested assistance to enable Customer to fulfill its own obligations under Applicable Data Protection Law.
4.3 Customer’s instructions are documented in this DPA, the Agreement, and any applicable statement of work.
4.4 Customer may reasonably issue additional instructions as necessary to comply with Applicable Data Protection Law.
4.5 Unless prohibited by applicable law, Clay will inform Customer if Clay is subject to a legal obligation that requires Clay to Process Customer Personal Data in contravention of Customer’s documented instructions.
4.6 Clay shall promptly notify Customer if it determines that it can no longer meet its obligations under Applicable Data Protection Law. Upon receiving notice from Clay in accordance with this subsection, Customer may direct Clay to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
4.7 With respect to Clay’s Processing of Personal Data subject to Applicable Data Protection Law as a Processor, except as explicitly required by the applicable U.S. Privacy Laws, Clay is prohibited from (i) Selling or Sharing Customer Personal Data, (ii) retaining, using, or disclosing Customer Personal Data for any purpose other than for the specific purpose of performing the services specified in Annex I.B, (iii) retaining, using, or disclosing Customer Personal Data outside of the direct business relationship between the Parties, and (iv) combining Customer Personal Data with Personal Data obtained from, or on behalf of, sources other than Customer.
- PERSONNEL.
5.1 Clay will ensure that all personnel authorized to Process Customer Personal Data are subject to an obligation of confidentiality.
- SECURITY AND PERSONAL DATA BREACHES.
6.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Clay will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including the measures listed in Annex II.
6.2 Clay will notify Customer without undue delay after becoming aware of a Personal Data Breach involving Customer Personal Data. If Clay’s notification is delayed, it will be accompanied by reasons for the delay.
- SUBPROCESSING.
7.1 Customer hereby authorizes Clay to engage Subprocessors. A list of Clay’s current Subprocessors is available here.
7.2 Clay will enter into a written agreement with Subprocessors which imposes the same obligations as required by Applicable Data Protection Law.
7.3 Clay will notify Customer prior to any intended change to Subprocessors. Customer may object to the addition of a Subprocessor based on reasonable grounds relating to a potential or actual violation of Applicable Data Protection Law by providing written notice detailing the grounds of such objection within thirty (30) days following Clay’s notification of the intended change. Customer and Clay will work together in good faith to address Customer’s objection. If Clay chooses to retain the Subprocessor, Clay will inform Customer at least thirty (30) days before authorizing the Subprocessor to Process Customer Personal Data, and either party may immediately discontinue providing or using the relevant parts of the Services, as applicable, and may terminate the relevant parts of the Services within thirty (30) days.
- ASSISTANCE.
8.1 Taking into account the nature of the Processing, and the information available to Clay, Clay will assist Customer, including, as appropriate, by implementing technical and organizational measures, with the fulfillment of Customer’s own obligations under Applicable Data Protection Law to: comply with requests to exercise Data Subject Rights; conduct data protection impact assessments, and prior consultations with Supervisory Authorities; and notify a Personal Data Breach.
8.2 Clay shall:
- promptly notify Customer if it receives a request to exercise Data Subject Rights under Applicable Data Protection Law in respect of Customer Personal Data; and
- ensure that it does not respond to that request except on the documented instructions of Customer or as required by applicable law to which Clay is subject, in which case Clay shall to the extent permitted by applicable law inform Customer of that legal requirement before Clay responds to the request.
8.3 Customer shall promptly inform Clay if it receives any request to exercise Data Subject Rights or any Consumer request made pursuant to the Applicable Data Protection Law affecting Customer Personal Data Processed by Clay that Customer must comply with. Customer shall provide Clay with the information necessary for Clay to comply with any such request.
8.4 Clay shall not be required to delete any Customer Personal Data to comply with a Consumer’s request directed by Customer if retaining such information is specifically required by Applicable Data Protection Law; provided, however, that in such case, Clay will promptly inform Customer of the exceptions relied upon under Applicable Data Protection Law and Clay shall not use Customer Personal Data retained for any purpose other than provided for by that exception.
8.5 Clay may charge a reasonable fee for assistance under this Section 8. If Clay is at fault, Clay and Customer shall each bear their own costs related to assistance.
- AUDIT.
9.1 Upon reasonable request, and occurring no more frequently than once per calendar year unless otherwise required under Applicable Data Protection Law, Clay must make available to Customer all information necessary to demonstrate compliance with the obligations of this DPA and allow for and contribute to audits, including inspections, as mandated by a Supervisory Authority or reasonably requested no more than once per year by Customer, and performed by an independent auditor as agreed upon by Customer and Clay. The foregoing shall only extend to those documents and facilities relevant and material to the Processing of Customer Personal Data and shall be conducted during normal business hours and in a manner that causes minimal disruption.
9.2 Clay will inform Customer if Clay believes that Customer’s instruction under Section 9.1 infringes Applicable Data Protection Law. Clay may suspend the audit or inspection or withhold requested information until Customer has modified or confirmed the lawfulness of the instructions in writing.
9.3 Clay and Customer each bear their own costs related to an audit.
9.4 With respect to the Processing of Personal Data subject to Applicable Data Protection Law, Customer has the right to monitor Clay’s compliance with this DPA through measures, including, but not limited to, ongoing manual reviews, automated scans, regular assessments, audits, or other annual technical and operational testing at least once every 12 months.
9.5 Where permitted by law, Clay may instead make available to Customer a summary of the results of a third-party audit or certification reports relevant to Clay’s compliance with this DPA.
- RETURN OF PERSONAL DATA.
10.1 Customer may request the return of Customer Personal Data after the termination of the Agreement. Unless required or permitted by applicable law, Clay will delete all remaining copies of Customer Personal Data after returning Customer Personal Data to Customer.
- INTERNATIONAL DATA TRANSFERS.
11.1 Customer hereby authorizes Clay to perform International Data Transfers to any country deemed to have an adequate level of data protection by the European Commission or the competent authorities, as appropriate; on the basis of adequate safeguards in accordance with European Data Protection Law; or pursuant to the SCCs and the UK Addendum referred to in Sections 11.2 and 11.4.
11.2 By entering into this DPA, Clay and Customer conclude the following modules of the SCCs:
- Module 1 (Controller-to-Controller), which applies to any International Data Transfers conducted by Clay acting as a Controller pursuant to Section 3.2 of the DPA, and is hereby incorporated and completed as follows: the “data exporter” is Clay; the “data importer” is Customer; the optional docking clause in Clause 7 is implemented; the optional paragraph in Clause 11(a) is struck; Option 1 in Clause 17 is implemented and the governing law is the law of Ireland; the courts in Clause 18(b) are the Courts of Ireland; Annex I and II to Module 1 of the SCCs are Annex I.A and Annex II to this DPA respectively.
- Module 2 (Controller-to-Processor) of the SCCs, which applies to any International Data Transfer conducted by Customer acting as a Controller when sharing Personal Data with Clay acting as a Processor pursuant to Section 3.1 of the DPA, and is hereby incorporated and completed as follows: the “data exporter” is Customer; the “data importer” is Clay; the optional docking clause in Clause 7 is implemented; Option 2 of Clause 9(a) is implemented and the time period therein is specified in Section 7.3 above; the optional redress clause in Clause 11(a) is struck; Option 1 in Clause 17 is implemented and the governing law is the law of Ireland; the courts in Clause 18(b) are the Courts of Ireland; Annex I and II to Module 2 of the SCCs are Annex I.B and Annex II to this DPA respectively.
- Module 4 (Processor-to-Controller) of the SCCs, which applies to any International Data Transfers conducted by Clay acting as a Processor pursuant to Section 3.1 of the DPA when Customer uses the Data Enrichment Tools, and is hereby incorporated and completed as follows: the “data exporter” is Clay; the “data importer” is Customer; the optional docking clause in Clause 7 is implemented; the optional redress clause in Clause 11(a) is struck; the governing law in Clause 17 is the law of Ireland; the courts in Clause 18 are the courts of Ireland; Annex I to Module 4 of the SCCs is Annex I.C to this DPA.
11.3 For International Data Transfers subject to Applicable Data Protection Law in Switzerland, Data Subjects who have their habitual residence in Switzerland may bring claims under the SCCs before the courts of Switzerland.
11.4 By acknowledging this DPA, Clay and Customer conclude the UK Addendum, which is hereby incorporated and applies to International Data Transfers subject to Applicable Data Protection Law in the UK. Part 1 of the UK Addendum is completed as follows:
- For Module 1 of the SCCs: (i) in Table 1, the “Exporter” is Clay and the “Importer” is Customer, their details are set forth in this DPA, and the Agreement; (ii) in Table 2, the first option is selected and the “Approved EU SCCs” are the SCCs referred to in Section 11.2(a) of this DPA; (iii) in Table 3, Annex 1 (A and B) and 2 to the “Approved EU SCCs” are Annex I.A and Annex II of this DPA; and (iv) in Table 4, both the “Importer” and the “Exporter” can terminate the UK Addendum.
- For Module 2 of the SCCs: (i) in Table 1, the “Exporter” is Customer and the “Importer” is Clay, their details are set forth in this DPA, and the Agreement; (ii) in Table 2, the first option is selected and the “Approved EU SCCs” are the SCCs referred to in Section 11.2(b) of this DPA; (iii) in Table 3, Annexes 1 (A and B) and II to the “Approved EU SCCs” are Annex I.B and Annex II respectively; and (iv) in Table 4, both the “Importer” and the “Exporter” can terminate the UK Addendum.
- For Module 4 of the SCCs: (i) in Table 1, the “Exporter” is Clay and the “Importer” is Customer, their details are set forth in this DPA, and the Agreement; (ii) in Table 2, the first option is selected and the “Approved EU SCCs” are the SCCs referred to in Section 11.2(c) of this DPA; (iii) in Table 3, Annex 1 (A and B) to the “Approved EU SCCs” is Annex I.C of this DPA; and (iv) in Table 4, both the “Importer” and the “Exporter” can terminate the UK Addendum.
11.5 If Clay’s compliance with European Data Protection Law applicable to International Data Transfers is affected by circumstances outside of Clay’s control, including if a legal instrument for International Data Transfers is invalidated, amended, or replaced, then Customer and Clay will work together in good faith to reasonably resolve such non-compliance. In the event that additional, replacement or alternative standard contractual clauses or UK standard contractual clauses are approved by Supervisory Authorities, Clay reserves the right to amend the Agreement and this DPA by adding to or replacing, the SCC’s or UK Addendum that form part of it at the date of signature in order to ensure continued compliance with European Data Protection Law.
- NOTIFICATIONS.
12.1 Customer will send all notifications, requests and instructions under this DPA to Clay via email to privacy@clay.com.
- TERMINATION.
13.1 This DPA is terminated upon the termination of the Agreement, except that Clay’s obligations under this DPA survive for so long as Clay Processes Customer Personal Data.
- APPLICABLE LAW AND JURISDICTION.
14.1 This DPA is governed by the laws of New York. Any disputes relating to this DPA will be subject to the exclusive jurisdiction of the courts of New York.
- MODIFICATION OF THIS DPA.
15.1 Subject to Section 11.5, this DPA may only be modified by a written amendment signed by both Clay and Customer.
- INVALIDITY AND SEVERABILITY.
16.1 If any provision of this DPA is found by any court or administrative body of a competent jurisdiction to be invalid or unenforceable, then the invalidity or unenforceability of such provision does not affect any other provision of this DPA and all provisions not affected by such invalidity or unenforceability will remain in full force and effect.
ANNEX I.A: CONTROLLER TO CONTROLLER.
DESCRIPTION OF THE TRANSFER
- LIST OF PARTIES.
Data exporter:
- Name: Clay
- Address: See the signature block of the Agreement.
- Contact person’s name, position and contact details: See the signature block of the Agreement.
- Activities relevant to the data transferred under these Clauses: Clay grants Customer access to its Proprietary Data as part of the Services.
- Signature and date: See the signature block of the Agreement.
- Role (controller/processor): Controller
Data importer:
- Name: Customer
- Address: See the signature block of the Agreement.
- Contact person’s name, position and contact details: See the signature block of the Agreement.
- Activities relevant to the data transferred under these Clauses: Customer receives access to Proprietary Data as part of the Services.
- Signature and date: See the signature block of the Agreement.
- Role (controller/processor): Controller
- DESCRIPTION OF INTERNATIONAL DATA TRANSFER.
- Categories of Data Subjects whose Personal Data is transferred: Individuals whose Personal Data is included in the Proprietary Data.
- Categories of Personal Data transferred:
- Professional contact details, such as work email address, work telephone number, postal address
- Careers information, such as job title, employer name
- Any other information that Customer chooses to query on Clay’s database
- Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: N/A
- The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis): On a continuous basis.
- Nature of the processing: The Personal Data will be processed and transferred as described in the Agreement.
- Purpose(s) of the data transfer and further processing: The Personal Data will be transferred and further processed for the provision of the Services as described in the Agreement.
- The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Personal Data will be retained for as long as necessary taking into account the purpose of the Processing, and in compliance with applicable laws, including laws on the statute of limitations and European Data Protection Law.
- For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: N/A
- COMPETENT SUPERVISORY AUTHORITY.
- The competent authority for the Processing of Personal Data relating to Data Subjects located in the EEA is the Irish Data Protection Commission.
- The competent authority for the Processing of Personal Data relating to Data Subjects located in the UK is the UK Information Commissioner.
- The competent authority for the Processing of Personal Data relating to Data Subjects located in Switzerland is the Swiss Federal Data Protection and Information Commissioner.
ANNEX I.B: CONTROLLER TO PROCESSOR.
DESCRIPTION OF THE TRANSFER
- LIST OF PARTIES.
Data exporter:
- Name: Customer
- Address: See the signature block of the Agreement.
- Contact person’s name, position and contact details: See the signature block of the Agreement.
- Activities relevant to the data transferred under these Clauses: Customer receives Clay’s Services as described in the Agreement and Customer provides Personal Data to Clay in that context.
- Signature and date: See the signature block of the Agreement.
- Role (controller/processor): Controller
Data importer:
- Name: Clay
- Address: See the signature block of the Agreement.
- Contact person’s name, position and contact details: See the signature block of the Agreement.
- Activities relevant to the data transferred under these Clauses: Clay provides its Services to Customer as described in the Agreement and Processes Personal Data on behalf of Customer in that context.
- Signature and date: See the signature block of the Agreement.
- Role (controller/processor): Processor
- DESCRIPTION OF INTERNATIONAL DATA TRANSFER.
- Categories of Data Subjects whose Personal Data is transferred:
- Customer’s personnel, staff and contractors
- Customer’s end-users
- Other individuals included in Customer’s own CRM datasets uploaded to Clay’s platform
- Categories of Personal Data transferred:
- Clay account details, such as account name, email address, job title, company, password
- Professional contact details, such as work email address, work telephone number, postal address
- Contact details and other lead data from Customer’s own sources that Customer uploads onto Clay’s platform
- Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: N/A
- The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis): On a continuous basis.
- Nature of the processing: The Personal Data will be processed and transferred as described in the Agreement.
- Purpose(s) of the data transfer and further processing: The Personal Data will be transferred and further processed for the provision of the Services as described in the Agreement.
- The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Personal Data will be retained for as long as necessary taking into account the purpose of the Processing, and in compliance with applicable laws, including laws on the statute of limitations and European Data Protection Law.
- For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: For the subject matter and nature of the Processing, reference is made to the Agreement and this DPA. The Processing will take place for the duration of the Agreement.
- COMPETENT SUPERVISORY AUTHORITY.
- The competent authority for the Processing of Personal Data relating to Data Subjects located in the EEA is the Supervisory Authority a) of Customer’s country of establishment, or, where not applicable, b) of the country where Customer’s EU data protection representative is located, or, where not applicable, c) of one of the EEA countries where the Data Subjects are located.
- The competent authority for the Processing of Personal Data relating to Data Subjects located in the UK is the UK Information Commissioner.
- The competent authority for the Processing of Personal Data relating to Data Subjects located in Switzerland is the Swiss Federal Data Protection and Information Commissioner.
ANNEX I.C: PROCESSOR TO CONTROLLER.
DESCRIPTION OF THE TRANSFER
- LIST OF PARTIES.
Data exporter:
- Name: Clay
- Address: See the signature block of the Agreement.
- Contact person’s name, position and contact details: See the signature block of the Agreement.
- Activities relevant to the data transferred under these Clauses: Clay provides its Customers with Data Enrichment Tools to enable them to retrieve information.
- Signature and date: See the signature block of the Agreement.
- Role (controller/processor): Processor
Data importer:
- Name: Customer
- Address: See the signature block of the Agreement.
- Contact person’s name, position and contact details: See the signature block of the Agreement.
- Activities relevant to the data transferred under these Clauses: Customer uses the Data Enrichment Tools made available by Clay.
- Signature and date: See the signature block of the Agreement.
- Role (controller/processor): Controller
- DESCRIPTION OF INTERNATIONAL DATA TRANSFER.
- Categories of Data Subjects whose Personal Data is transferred: Individuals about whom Customer runs queries using Clay’s Data Enrichment Tools.
- Categories of Personal Data transferred:
- Professional contact details, such as name, work email address, work telephone number, postal address
- Careers information, such as job title, employer name, career history, education and job qualifications, information about promotions and lateral moves, publicly-available information about companies’ remuneration and compensation
- Any other information that Customer retrieves using the Data Enrichment Tools.
- Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: N/A
- The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis): On a continuous basis.
- Nature of the processing: The Personal Data will be processed and transferred as described in the Agreement.
- Purpose(s) of the data transfer and further processing: The Personal Data will be transferred and further processed for the provision of the Services as described in the Agreement.
- The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Personal Data will be retained for as long as necessary taking into account the purpose of the Processing, and in compliance with applicable laws, including laws on the statute of limitations and European Data Protection Law.
- For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: N/A
ANNEX II.
TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
Both Clay and Customer will implement industry-standard security measures including the following types of measures:
- Physical access control.
Technical and organizational measures to prevent unauthorized persons from gaining access to the data processing systems available in premises and facilities (including databases, application servers and related hardware), where Customer Personal Data are Processed, include:
- Establishing security areas, restriction of access paths;
- Establishing access authorizations for employees and third parties;
- Access control system (ID reader, magnetic card, chip card);
- Key management, card-keys procedures;
- Door locking (electric door openers etc.);
- Security staff;
- Surveillance facilities, video/CCTV monitor, alarm system; and
- Securing decentralized data processing equipment and personal computers.
- Virtual access control.
Technical and organizational measures to prevent data processing systems from being used by unauthorized persons include:
- User identification and authentication procedures;
- Strong ID/password security procedures (special characters, minimum length and complexity requirements, change of password);
- Automatic blocking (e.g. password or timeout);
- Monitoring of break-in-attempts and automatic turn-off of the user ID upon several erroneous passwords attempts;
- Creation of one master record per user, user-master data procedures per data processing environment; and
- Encryption of archived data media.
- Data access control.
Technical and organizational measures to ensure that persons entitled to use a data processing system gain access only to such Customer Personal Data in accordance with their access rights, and that Customer Personal Data cannot be read, copied, modified or deleted without authorization, include:
- Internal policies and procedures;
- Control authorization schemes;
- Differentiated access rights (profiles, roles, transactions and objects);
- Monitoring and logging of accesses;
- Disciplinary action against employees who access Customer Personal Data without authorization;
- Reports of access;
- Access procedure;
- Change procedure;
- Deletion procedure; and
- Encryption.
- Disclosure control.
Technical and organizational measures to ensure that Customer Personal Data cannot be read, copied, modified or deleted without authorization during electronic transmission, transport or storage on storage media (manual or electronic), and that it can be verified to which companies or other legal entities Customer Personal Data are disclosed, include:
- Encryption/tunneling;
- Logging; and
- Transport security.
- Entry control.
Technical and organizational measures to monitor whether Customer Personal Data have been entered, changed or removed (deleted), and by whom, from data processing systems, include:
- Logging and reporting systems; and
- Audit trails and documentation.
- Control of instructions.
Technical and organizational measures to ensure that Customer Personal Data are Processed solely in accordance with the instructions of the Controller include:
- Unambiguous wording of the contract;
- Formal commissioning (request form); and
- Criteria for selecting the Processor.
- Availability control.
Technical and organizational measures to ensure that Customer Personal Data are protected against accidental destruction or loss (physical/logical) include:
- Backup procedures;
- Mirroring of hard disks (e.g. RAID technology);
- Uninterruptible power supply (UPS);
- Remote storage;
- Anti-virus/firewall systems; and
- Disaster recovery plan.
- Separation control.
Technical and organizational measures to ensure that Customer Personal Data collected for different purposes can be Processed separately include:
- Separation of databases;
- “Internal client” concept / limitation of use;
- Segregation of functions (production/testing); and
- Procedures for storage, amendment, deletion, transmission of data for different purposes.
- Testing controls.
Technical and organizational measures to test, assess and evaluate the effectiveness of the technical and organizational measures implemented in order to ensure the security of the processing include:
- Periodical review and test of disaster recovery plan;
- Testing and evaluation of software updates before they are installed;
- Authenticated (with elevated rights) vulnerability scanning; and
- Test bed for specific penetration tests and Red Team attacks.
- IT governance.
Technical and organizational measures to improve the overall management of IT and ensure that the activities associated with information and technology are aligned with the compliance efforts include:
- Certification/assurance of processes and products;
- Processes for data minimization;
- Processes for data quality;
- Processes for limited data retention;
- Processes for ensuring accountability; and
- Data subject rights policies.
















.avif)














.avif)







