1 Parties, incorporation, and scope
1.1 Parties
This Data Processing Agreement ("DPA") forms part of the agreement
governing the Customer's use of the MonsterOps Services (the
"Agreement") between:
-
MonsterOps: HCG Partners GmbH, trading as
MonsterOps, Blegistrasse 11B, 6340 Baar, Switzerland ("MonsterOps");
and
-
Customer: the person or legal entity identified as
the Customer in the Agreement.
MonsterOps' privacy contact is [email protected].
1.2 Effective date
This DPA takes effect when the Customer first accepts or enters into
an Agreement that incorporates it, unless the parties agree another
effective date in writing.
1.3 Scope
This DPA applies only to Personal Data that MonsterOps processes on
the Customer's behalf in providing the Services ("Customer Personal
Data"). It does not apply when MonsterOps processes Personal Data as
an independent controller, including for billing and accounting,
direct marketing, fraud and abuse prevention, product research under
Section 6.1(e) of the Terms, or Aggregated Statistics under Section
4.3 of the Terms. Those activities are described in the MonsterOps
Privacy Policy.
1.4 Roles
The Customer is a controller of Customer Personal Data or a processor
authorized by the relevant controller. MonsterOps is respectively a
processor or subprocessor. Each party will comply with the obligations
applicable to its role under Applicable Data Protection Law.
2 Definitions
Capitalized terms not defined in this DPA have the meanings given in
the Agreement.
Applicable Data Protection Law means privacy and
data-protection laws applicable to the processing of Customer Personal
Data under the Agreement, including, where applicable, the EU General
Data Protection Regulation 2016/679 ("EU GDPR"), the EU GDPR as
incorporated into United Kingdom law ("UK GDPR"), the UK Data
Protection Act 2018, and the Swiss Federal Act on Data Protection
("Swiss FADP").
Customer Personal Data means Personal Data contained
in Customer Data that MonsterOps processes on the Customer's behalf in
providing the Services.
Data Subject, Personal Data,
process, processing,
controller, processor, and
supervisory authority have the meanings given by
Applicable Data Protection Law.
Personal Data Breach means a breach of security
leading to the accidental or unlawful destruction, loss, alteration,
unauthorized disclosure of, or access to Customer Personal Data
transmitted, stored, or otherwise processed.
Restricted Transfer means a transfer of Customer
Personal Data that requires an adequacy decision, appropriate
safeguard, or other transfer mechanism under Applicable Data
Protection Law.
Subprocessor means a third party engaged by
MonsterOps to process Customer Personal Data on the Customer's behalf.
3 Instructions and permitted processing
3.1 Documented instructions
The Agreement, this DPA, the Customer's and Authorized Users' use and
configuration of the Services, and the Customer's documented requests
constitute the Customer's instructions to MonsterOps. MonsterOps will
process Customer Personal Data only on those instructions and as
necessary to provide the Services, including hosting, collaboration,
integrations, notifications, support, and enabled or automated AI
Features described in Appendix A, except for independent-controller
processing permitted by the Agreement and described in Section 1.3.
3.2 Processing required by law
If applicable law requires MonsterOps to process Customer Personal
Data other than on the Customer's instructions, MonsterOps will inform
the Customer before that processing unless the law prohibits notice.
3.3 Unlawful instructions
MonsterOps will promptly inform the Customer if, in MonsterOps'
reasonable opinion, an instruction infringes Applicable Data
Protection Law. MonsterOps may suspend the affected processing until
the parties resolve the issue.
3.4 Customer responsibilities
The Customer is responsible for:
-
having authority to provide Customer Personal Data to MonsterOps and
instruct its processing;
-
providing legally required notices and obtaining any legally
required permissions or consents;
-
ensuring its instructions and use of the Services comply with
Applicable Data Protection Law;
-
configuring access, integrations, retention, and AI Features
appropriately for its use; and
-
not submitting data subject to specialized regulatory requirements
unless MonsterOps has expressly agreed in writing to support that
processing.
MonsterOps remains responsible for its own obligations under this DPA.
3.5 US state privacy laws
To the extent MonsterOps processes Customer Personal Data as a
processor, service provider, or contractor under an applicable US
state privacy law, MonsterOps will:
-
process it only for the limited and specified purposes described in
the Agreement, this DPA, and the Customer's documented instructions;
-
not sell or share it as those terms are defined under applicable US
state privacy law;
-
not retain, use, or disclose it outside the direct business
relationship with the Customer or for a purpose other than the
permitted purposes, except as allowed or required by law;
-
not combine it with Personal Data received from another person or
collected from MonsterOps' own interaction with an individual,
except as permitted by applicable law; and
-
notify the Customer if MonsterOps determines that it can no longer
meet these obligations.
The Customer may take reasonable and appropriate steps to verify
compliance through Section 6.4 and to stop and remediate unauthorized
processing. MonsterOps certifies that it understands and will comply
with the restrictions in this Section.
4 Confidentiality and security
4.1 Confidentiality
MonsterOps will ensure that persons authorized to process Customer
Personal Data are subject to confidentiality obligations and access it
only when necessary for authorized duties.
4.2 Security measures
MonsterOps will maintain appropriate technical and organizational
measures designed to protect Customer Personal Data against accidental
or unlawful destruction, loss, alteration, unauthorized disclosure, or
access. The current measures are described in Appendix C. MonsterOps
may update those measures as the Services evolve, provided the overall
level of security is not materially reduced.
4.3 Administrative access
Administrative access to Customer Personal Data is limited to the
purposes and safeguards described in Section 6 of the Terms, including
requested support, technical troubleshooting, security and abuse
investigations, legal compliance, and the Customer's written
instructions.
4.4 AI model training
MonsterOps will not use Customer Personal Data to train a shared or
general-purpose artificial intelligence model, or permit an AI
Subprocessor to do so, unless the Customer has expressly instructed
that use in a separate written arrangement that complies with
Applicable Data Protection Law.
5 Subprocessors
5.1 General authorization
The Customer gives MonsterOps general written authorization to engage
the Subprocessors listed in Appendix B. A Subprocessor supporting an
optional feature will receive Customer Personal Data only when that
feature is used or enabled.
5.2 Subprocessor obligations
Before a Subprocessor processes Customer Personal Data, MonsterOps
will:
-
assess the Subprocessor's data-protection and security practices as
appropriate to the risk;
-
ensure the Subprocessor is bound by written terms, including
electronic or incorporated terms, that impose data-protection
obligations that are no less protective, in substance, than the
obligations applicable to the delegated processing under this DPA;
and
-
ensure an appropriate transfer mechanism is in place for any
Restricted Transfer.
MonsterOps remains responsible to the Customer for a Subprocessor's
performance of its data-protection obligations to the extent required
by Applicable Data Protection Law.
5.3 Changes and objections
MonsterOps will give the Customer at least 14 days' advance notice by
email or through the Services before an intended addition or
replacement of a Subprocessor begins processing Customer Personal
Data. The notice will identify the Subprocessor's function and
relevant processing locations.
The Customer may object during the notice period on reasonable grounds
relating to the protection of Customer Personal Data. The parties will
work in good faith to find a practical resolution. If MonsterOps
cannot reasonably resolve the objection, the Customer may terminate
the affected Services before the new Subprocessor begins processing
Customer Personal Data. Any refund is governed by the Agreement.
5.4 Subprocessor chains
A Subprocessor may use its own downstream processors under its
agreement with MonsterOps. MonsterOps will maintain information
sufficient to assess the relevant processing chain, security, and
international transfers. A downstream processor is not required to be
listed separately in Appendix B when it is already disclosed and
governed through the listed Subprocessor's terms.
6 Assistance, incidents, and audits
6.1 Data Subject requests
Taking account of the nature of the processing and information
available to it, MonsterOps will reasonably assist the Customer in
responding to requests to exercise Data Subject rights, including
access, correction, erasure, restriction, objection, and portability.
MonsterOps will promptly forward a request relating to Customer
Personal Data to the Customer and will not respond on the Customer's
behalf unless instructed or legally required.
6.2 Personal Data Breaches
MonsterOps will notify the Customer without undue delay after becoming
aware of a Personal Data Breach affecting Customer Personal Data. To
the extent available, MonsterOps will provide:
- a description of the nature of the Personal Data Breach;
-
the categories and approximate number of affected Data Subjects and
records;
- the likely consequences;
-
measures taken or proposed to contain, investigate, mitigate, and
remediate the breach; and
- a contact for follow-up.
MonsterOps may provide information in phases as it becomes available.
Notification is not an admission of fault or liability. MonsterOps
will reasonably assist the Customer with legally required
notifications and communications.
6.3 Compliance assistance
Taking account of the nature of the processing and information
available to MonsterOps, MonsterOps will provide the assistance
required by Applicable Data Protection Law with the Customer's
security assessments, data-protection impact assessments, and prior
consultations, but only to the extent they relate to Customer Personal
Data processed under this DPA. MonsterOps may charge reasonable fees
for assistance beyond its standard documentation and support, provided
it informs the Customer of the fees in advance. MonsterOps will not
charge for assistance required because of its breach of this DPA.
6.4 Compliance information and audits
MonsterOps will make available information reasonably necessary to
demonstrate compliance with this DPA. The Customer must first use
MonsterOps' then-current DPA, security documentation, Subprocessor
information, written questionnaire responses, and any available
independent audit reports or certifications.
Only where that information is insufficient to demonstrate compliance
with Applicable Data Protection Law may the Customer request an audit.
The parties will first use a remote document review. An onsite
inspection is permitted only where the remote review is insufficient
and the inspection is required by Applicable Data Protection Law.
An audit may occur no more than once in any 12-month period, must be
conducted by an independent auditor that is not a MonsterOps
competitor, and requires at least 30 days' written notice. It must
occur during normal business hours, avoid unreasonable disruption, be
limited to processing relevant to Customer Personal Data, and protect
MonsterOps' and other customers' confidentiality and security.
MonsterOps may coordinate or consolidate substantially similar audit
requests.
The Customer bears all audit costs and will reimburse MonsterOps for
reasonable assistance beyond standard documentation and support, with
any fees disclosed in advance. These limitations do not apply where a
competent supervisory authority requires otherwise, or where an
additional audit is reasonably necessary following a Personal Data
Breach affecting Customer Personal Data or credible evidence of
MonsterOps' material non-compliance with this DPA.
7 International transfers
7.1 Transfer mechanisms
Before making a Restricted Transfer, MonsterOps will use a lawful
transfer mechanism, which may include an adequacy decision, the
Swiss-U.S. or EU-U.S. Data Privacy Framework where the recipient is
certified, the EU Standard Contractual Clauses, the UK Addendum or
International Data Transfer Agreement, or another mechanism recognized
under Applicable Data Protection Law.
7.2 EU Standard Contractual Clauses
Where a Restricted Transfer from the European Economic Area to
MonsterOps is not covered by another valid transfer mechanism, the
standard contractual clauses in the Annex to European Commission
Implementing Decision (EU) 2021/914 of 4 June 2021 ("EU SCCs") are
incorporated into this DPA as follows:
-
Module Two applies where the Customer is a controller and MonsterOps
is a processor;
-
Module Three applies where the Customer is a processor and
MonsterOps is a subprocessor;
- Clause 7 (Docking Clause) applies;
-
in Clause 9(a), Option 2 applies and the notice period is 14 days;
- the optional language in Clause 11 does not apply;
- in Clause 17, the EU SCCs are governed by the law of Ireland;
-
in Clause 18(b), disputes will be resolved by the courts of Ireland;
-
the competent supervisory authority under Clause 13 is determined in
accordance with that clause;
- Section 1 and the Agreement complete Annex I.A;
- Appendix A completes Annex I.B;
- Appendix C completes Annex II; and
- Appendix B completes Annex III.
If this Section conflicts with the EU SCCs, the EU SCCs prevail.
7.3 United Kingdom transfers
For a Restricted Transfer governed by the UK GDPR, the International
Data Transfer Addendum to the EU Commission Standard Contractual
Clauses, version B1.0 in force from 21 March 2022 ("UK Addendum"), is
incorporated into this DPA. The parties' information and the selected
EU SCC modules are set out in this DPA and the Agreement; Appendix B
identifies authorized Subprocessors; and Appendix A and Appendix C
provide the processing description and security measures. The
mandatory clauses of the UK Addendum apply, and either party may end
the UK Addendum as permitted by it.
7.4 Swiss transfers
For a Restricted Transfer governed by the Swiss FADP, the EU SCCs
apply with the adaptations required by the Swiss Federal Data
Protection and Information Commissioner. References to the EU GDPR
include the Swiss FADP to the extent applicable; references to EU
Member State law are understood to include Swiss law; the competent
authority is the Swiss Federal Data Protection and Information
Commissioner; and Swiss Data Subjects may enforce their rights in
Switzerland. Where both the EU GDPR and Swiss FADP apply, these
adaptations do not displace the EU requirements that also apply.
7.5 Further measures
The parties will reasonably cooperate with transfer-risk assessments
and supplementary measures required by Applicable Data Protection Law.
MonsterOps will ensure that onward transfers by its Subprocessors are
subject to corresponding safeguards.
8 Return, deletion, and retention
8.1 Export and deletion
At the end of the Services, the Customer may export available Customer
Personal Data or request its deletion, subject to identity
verification and applicable legal exceptions. Unless the Customer
requests earlier deletion, Customer Personal Data will remain
available for export for at least 30 days following expiration or
termination, except where access is restricted because of unlawful
activity, a security threat, or a legal prohibition. MonsterOps will
delete Customer Personal Data from active systems within 90 days after
the export period ends.
8.2 Backups
Encrypted backups may remain for up to 30 days after deletion from
active systems. Until expiry, backups will remain protected, will not
be restored except for disaster recovery, security, or legal
requirements, and will not be used for another purpose. If a backup is
restored, applicable deletion instructions will be reapplied.
8.3 Subprocessors and legal retention
MonsterOps will require Subprocessors to delete or return Customer
Personal Data in accordance with their applicable contractual
obligations. MonsterOps may retain Customer Personal Data where
required by law, but only for the required data and period and subject
to continued protection. MonsterOps will provide reasonable
confirmation of deletion on request.
8.4 Independent-controller records
This Section does not govern Personal Data that MonsterOps retains as
an independent controller under the Privacy Policy, including legally
required accounting records and limited security or abuse-prevention
records.
9 Order of precedence and effect
9.1 Precedence
This DPA takes precedence over conflicting provisions of the Agreement
concerning the processing of Customer Personal Data on the Customer's
behalf. Applicable mandatory transfer clauses take precedence over
this DPA. The Agreement otherwise remains unchanged.
9.2 Duration
This DPA remains effective for as long as MonsterOps processes
Customer Personal Data on the Customer's behalf.
9.3 Updates
MonsterOps may update this DPA where reasonably necessary to comply
with law, regulatory guidance, or changes to the Services. MonsterOps
will give reasonable advance notice of a material change unless an
immediate change is required by law or security. An update will not
materially reduce the protection of Customer Personal Data.
Appendix A - Description of processing
The Customer may further specify the subject matter, duration, nature,
purposes, Personal Data, and Data Subjects through its use and
configuration of the Services and documented instructions consistent
with the Agreement.
Appendix B - Authorized Subprocessors
The following providers may process Customer Personal Data to provide
the functions described below. Access is limited to data reasonably
necessary for the relevant function. Optional providers receive
Customer Personal Data only when the relevant feature is used.
Stripe and other providers used solely for MonsterOps' billing,
accounting, direct marketing, or other independent-controller
activities are outside this DPA and are described in the Privacy
Policy.
Customer-directed integrations that the Customer independently
contracts for, enables, or connects through the Services, API, MCP
tools, or automation platforms are not MonsterOps Subprocessors merely
because the Services transmit data to them on the Customer's
instructions.
Appendix C - Technical and organizational measures
MonsterOps maintains the following measures, taking account of the
nature, scope, context, and purposes of processing and the risks to
individuals. Measures may evolve as described in Section 4.2.