Data Processing Addendum

TABLE OF CONTENTS

This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written or electronic agreement between AskField Inc. ("AskField", "we", "us") and the customer ("Customer", "you") for the purchase of online services (the "Agreement"). This DPA reflects the parties' agreement with respect to the processing of Personal Data in connection with AskField's services.

1. Definitions

For the purposes of this DPA:

  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Data Controller" means the entity which determines the purposes and means of the processing of Personal Data.
  • "Data Processor" means the entity which processes Personal Data on behalf of the Data Controller.
  • "Data Subject" means the natural person to whom Personal Data relates.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.

2. Scope

This DPA applies to the processing of Personal Data by AskField on behalf of Customer in connection with the services provided under the Agreement. Customer is the Data Controller and AskField is the Data Processor with respect to such Personal Data.

3. Processing of Personal Data

  1. AskField shall process Personal Data only in accordance with Customer's documented instructions and this DPA.
  2. AskField shall not process Personal Data for any purpose other than those set forth in the Agreement or as required by applicable law.
  3. AskField shall ensure that persons authorized to process Personal Data are bound by confidentiality obligations.

4. Security Measures

AskField shall implement appropriate technical and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure, or destruction, including:

  • Encryption of data in transit and at rest
  • Access controls and authentication mechanisms
  • Regular security assessments and audits
  • Incident response procedures
  • Business continuity and disaster recovery plans

5. Sub-processors

Customer acknowledges that AskField may engage sub-processors to process Personal Data. AskField shall:

  1. Ensure that sub-processors are bound by data protection obligations substantially similar to those in this DPA
  2. Notify Customer of any intended changes to sub-processors
  3. Remain liable for the performance of sub-processors

6. Data Subject Rights

AskField shall assist Customer in responding to requests from Data Subjects to exercise their rights under applicable data protection laws, including:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restrict processing
  • Right to data portability
  • Right to object

7. Data Breach Notification

AskField shall notify Customer without undue delay after becoming aware of a Personal Data breach. The notification shall include:

  • Description of the nature of the breach
  • Categories and approximate number of Data Subjects affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

8. Audit Rights

AskField shall make available to Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits conducted by Customer or its authorized representatives, subject to reasonable notice and confidentiality obligations.