Data Exporter
Name: The Customer acting as a Data Controller subscribed to a Service that allows authorized users to enter, amend, use, delete or otherwise process Personal Data, as identified in the Agreement.
Address: As stated in the Agreement.
Contact person’s name, position and contact details: As stated in the Agreement.
Role: (Controller/Processor): Controller
Data Importer
Name: Drivn and its Subprocessors, each as identified in the Agreement.
Address: As stated in the Agreement.
Contact person’s name, position and contact details: As stated in the Agreement.
Role: (Controller/Processor): Processor
Purpose(s) of the data transfer and further processing
Provision by Drivn of Fidero, including:
Description of Transfer
Categories of Data Subjects whose personal data is transferred
Unless provided otherwise by the Data Exporter, transferred Customer Personal Data relates to the following categories of data subjects: individuals to whom the Customer wishes to market its products or services
Categories of personal data transferred
The transferred Customer Personal Data submitted to Fidero may concern the following categories of data: Customer, in its sole discretion and control, determines the categories of Customer Personal Data in accordance with Fidero component(s) ordered under the Agreement. Customer can configure the data fields during implementation of Fidero or as otherwise provided by Fidero, subject to the functionality of the related Service component(s). The transferred Customer Personal Data submitted into Fidero may include, but is not limited to the following categories of data:
Sensitive data transferred
None.
Processing Operations (Activities relevant to the data transferred under the DPA)
The transferred Customer Personal Data is subject to the following basic processing activities:
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis):
Continuous
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period:
As defined in the Agreement.
Competent supervisory authority
United Kingdom
List of Subcontractors as of the Effective Date
Company | Purpose | Location of data hosting |
---|---|---|
Digital Ocean | Backend code (API) hosting, data storage | EU |
Amazon Web Services | CDN, config storage | EU |
The following sets out Drivn’s current technical and organizational security measures. Drivn may change these at any time without notice so long as it maintains a comparable or better level of security. This may mean that individual measures are replaced by new measures that serve the same purpose without diminishing the security level.
EU Standard Contractual Clauses
EU SCC term | Amendment / Selected option |
---|---|
Module | Module 2 (Controller to Processor) |
Clause 7 (Docking clause) | Not included |
Clause 9 (Use of sub-processors) / Annex III | Option 2 shall apply. |
The list of sub-processors already authorised by Customer is contained in Appendix 1. | |
Clause 11 (Redress) | Not included |
Clause 13 (Supervision) and Annex 1.C | The supervisory authority with responsibility for ensuring compliance by the data exporter is:<br /><br />where the data exporter is established within an EU member state, the supervisory authority of that EU member state OR<br /><br />where the data exporter is subject to EU GDPR pursuant to Article 3(2) EU GDPR and has appointed a representative in the EU, the supervisory authority of that EU member state OR<br /><br />where the data exporter is subject to EU GDPR pursuant to Article 3(2) EU GDPR, but has not appointed a representative in an EU member state, the supervisory authority of the EU member state where the relevant data subjects are located. |
Clause 17 (Governing law) | Ireland |
Clause 18 (Choice of forum and jurisdiction) | Ireland |
Annex I.A (List of parties) | The relevant data exporters and data importers are specified in Appendix 1. |
Annex I.B (Description of the transfer) | The categories of data subject, personal data categories, purposes of international transfer and processing, any additional safeguards, and if applicable the duration of processing and any maximum data retention periods are specified in Appendix 1. |
Annex II (Technical and organisational measures) | The relevant technical and organisational measures are specified in Appendix 2. |
UK Standard Contractual Clauses
UK Data Transfer Addendum Incorporating EU Standard Contractual Clause terms | Amendment / Selected option |
---|---|
Clause 7 (Docking clause) | Not included |
Clause 9 (Use of sub-processors) / Annex III | Option 2 shall apply. |
The list of sub-processors already authorised by Customer is contained in Appendix 1. | |
Clause 11 (Redress) | Not included |
Clause 13 (Supervision) and Annex 1.C | The competent supervisory authority is the UK Information Commissioner’s Office. |
Clause 17 (Governing law) | England |
Clause 18 (Choice of forum and jurisdiction) | England |
Annex I.A (List of parties) | The relevant data exporters and data importers are specified in Appendix 1. |
Annex I.B (Description of the transfer) | The categories of data subject, personal data categories, purposes of international transfer and processing, any additional safeguards, and if applicable the duration of processing and any maximum data retention periods are specified in Appendix 1. |
Annex II (Technical and organisational measures) | The relevant technical and organisational measures are specified in Appendix 2. |