Legal

GDPR & Data Processing Agreement

How we process personal data on your behalf, and the safeguards that apply.
Last updated: 2023

1. Applicability

This Green Click Data Processing Agreement ("DPA") shall apply to all of your ("User's") agreements ("Agreements") with Green Click Corp. and its affiliates and/or subsidiaries ("Green Click") and you and/or the entity you represent ("Customer") supplements the Green Click terms of use, as updated from time to time ("TOU"), or any agreement between Customer and Green Click, governing Customer's use of the Services ("Agreements") to the extent that Green Click processes data.

2. Definitions

2.1. Terms used in this DPA but not defined herein (whether or not capitalized) shall have the meanings assigned to such terms in the Agreements, or in the Applicable Data Protection Laws, as applicable.

2.2. "Applicable Data Protection Laws" shall mean, to the extent applicable to Green Click's processing of Personal Data hereunder (with respect to each data subject): (i) General Data Protection Regulations (EU GDPR); (ii) EU GDPR as it forms part of the law of England and Wales (UK GDPR); (iii) California Consumer Privacy Act of 2018 (CCPA) and the California Privacy Rights Act of 2020 (CPRA); (iv) Protection of Privacy Law (Israel); and (v) any rules or regulations that amend and/or replace any of the aforementioned Data Protection Laws.

2.3. "Customer Data" shall mean the Personal Data that is uploaded to the Green Click Services which may include software, data, text, audio, video, or images that Customer or any of its end customers transfers to Green Click for processing, storage, or hosting by the Services.

2.4. "Personal Data" refers to the definition of that term or any other similar term defined under the Applicable Data Protection Laws.

2.5. "Standard Contractual Clauses or SCCs" shall mean: where the EU GDPR applies, the standard contractual clauses pursuant to the EU Commission's Implementing Decision 2021/914 of 4 June 2021; where the UK GDPR applies, the EU SCCs together with the UK Information Commissioner's Office addendum.

2.6. "Services" means the services and products provided to Customer by Green Click in accordance with the Agreements.

3. Processing of Personal Data on Behalf of a Customer

The Parties acknowledge and agree that with regard to the Processing of Personal Data performed solely on behalf of Customer: (i) Customer is the Controller or Business (to the extent the CCPA is applicable) of Personal Data; (ii) Green Click acts as a Processor or Service Provider for Customer, and upon the instructions of Customer, as set forth herein, and in the Agreements, as may be amended from time to time by Green Click (collectively, the "Terms"), pursuant to which personal data may be disclosed to Green Click and Green Click may process such personal data (the "Contracted Business Purpose").

4. Customer Representations

Customer sets forth the details, including the purpose, the means and the ways in which Green Click shall process the Customer Data, as required by Applicable Data Protection Laws, and Customer represents and warrants that:

4.1. It complies with personal data security and other obligations prescribed by Applicable Data Protection Laws for controllers/businesses, and that the provision of Customer Data to Green Click complies with Applicable Data Protection Laws.

4.2. It only processes personal data/personal information that has been collected in accordance with the Applicable Data Protection Laws.

4.3. It has in place procedures in case individuals/consumers whose personal data is collected, wish to exercise their rights in accordance with the Applicable Data Protection Laws.

4.4. It provides Customer Data to Green Click for a business purpose in accordance with the representations Customer makes to consumers in Customer's privacy policy, and Customer does not sell Customer Data to Green Click.

4.5. It shall provide to Green Click as a processor/service provider only such Customer Data which is explicitly permitted under Green Click's Privacy Notice ("Permitted Personal Data").

4.6. It is and will remain duly and effectively authorized to give the instructions set out herein at all relevant times.

4.7. Customer acknowledges that Green Click is able to access Customer Data, and might do so when required for operational and maintenance purposes and if required to provide the Services.

5. Green Click Obligations

5.1. Green Click carries out the processing of Customer Data on Customer's behalf.

5.2. Pursuant to the provisions of Article 28 of the GDPR, Green Click represents and warrants that it will:
• Process Customer Data solely on Customer's behalf and in compliance with User's instructions, unless required to do so by EU or applicable Member State law
• Implement appropriate technical and organizational measures to provide an appropriate level of security, including the measures referred to in Article 32(1) of the GDPR
• Take reasonable steps to ensure that access to the processed Customer Data is limited on a need to know/access basis, and that all personnel receiving such access are subject to confidentiality undertakings
• Provide reasonable assistance to Customer with any data protection impact assessments or prior consultations with supervising authorities

5.3. Pursuant to the CCPA, to the extent applicable, Green Click agrees that:
• Green Click is acting solely as a service provider with respect to Customer Data
• Green Click shall not retain, use or disclose Customer Data for any purpose other than for the Contracted Business Purpose
• Green Click may de-identify or aggregate Customer Data as part of performing the services
• Green Click will limit personal information collection, use, retention, and disclosure to activities reasonably necessary and proportionate to achieve the Contracted Business Purposes

6. Sub-Processing

6.1. Customer authorizes Green Click to appoint sub-processors in accordance with the provision of the Terms. Any subcontractor used must qualify as a service provider under the Applicable Data Protection Laws.

6.2. Green Click may continue to use those sub-processors already engaged by Green Click as of the date of this DPA. A list of such sub-processors will be provided upon request.

6.3. Green Click may appoint new sub-processors and shall give reasonable notice of the appointment of any new sub-processor. Customer's continued use of the applicable services after such notification constitutes Customer's acceptance of the new sub-processor.

7. Data Subjects' Rights

7.1. Customer shall be solely responsible for compliance with any statutory obligations concerning requests to exercise data subject rights under Applicable Data Protection Laws. Green Click shall reasonably endeavor to assist Customer insofar as feasible, to fulfil Customer's said obligations with respect to such data subject requests, at Customer's sole reasonable expense.

7.2. Green Click shall (i) without undue delay notify customer if it receives a request from a data subject under any Applicable Data Protection Laws in respect of Processed Personal Data; and (ii) not respond to that request, except on the written instructions of Customer or as required by Applicable Data Protection Laws.

8. Personal Data Breach

8.1. Green Click shall notify Customer without undue delay upon Green Click becoming aware of any personal data breach within the meaning of Applicable Data Protection Laws relating to Customer Data which may require a notification to be made to a supervisory authority or data subject.

8.2. At the written request of the Customer and at Customer's sole expense, Green Click shall provide reasonable co-operation and assistance to Customer in respect of Customer's obligations regarding the investigation of any Personal Data Breach and the notification to the supervisory authority and data subjects; provided, however, that Green Click shall, at its own expense, use reasonable efforts to contain and remedy any Personal Data Breach caused by Green Click without undue delay.

9. Deletion or Return of Processed Personal Data

9.1. Subject to the terms hereof, Green Click shall within up to sixty (60) days, unless a sooner time period is required by Applicable Data Protection Laws, return and then destroy the Customer Data, except such copies as authorized or required to be retained in accordance with Applicable Data Protection Laws.

9.2. Green Click may retain Customer Data only to the extent authorized or required by Applicable Data Protection Laws, provided that Green Click shall ensure the confidentiality of such Customer Data.

9.3. Upon Customer's prior written request, Green Click shall provide written certification to Customer that it has complied with this Section.

10. Audit Rights

10.1. Subject to the terms hereof, and not more than once in each calendar year, Green Click shall make available to a reputable auditor mandated by Customer in coordination with Green Click, at the reasonable cost of the Customer upon prior written request, within normal business hours at Green Click premises, such information necessary and relevant to reasonably demonstrate compliance with this DPA.

10.2. Customer shall use (and ensure that each of its mandated auditors use) its best efforts to avoid causing any damage, injury or disruption to Green Click's premises, equipment, personnel and business while its personnel are on those premises in the course of such an audit or inspection.

11. International Data Transfers

11.1. Customer may select the datacenter locations as offered by Green Click where Customer Data will be processed. Once Customer has made its choice, Green Click will not transfer Customer Data from Customer's selected locations, except as necessary to provide the Services initiated by Customer, or as specifically required by the Customer, or as necessary to comply with applicable law.

11.2. Personal Data may be transferred from the European Economic Area and the United Kingdom ("UK") to countries that offer an adequate level of data protection under or pursuant to adequacy decisions, without any further safeguard being necessary.

11.3. To the extent that Green Click transfers Personal Data to countries outside of the European Economic Area and/or outside of the UK which have not been subject to a relevant Adequacy Decision, such transfer shall be subject to the Standard Contractual Clauses as incorporated into this DPA by reference.

11.4. Clause 17: The parties select the law of Ireland.
Clause 18(b): The parties specify the courts of Ireland.

11.5. Green Click reserves the right to adopt an alternative compliance standard to the SCCs for the lawful transfer of Personal Data, provided it is recognized under Data Protection Law. Green Click will provide 30 days' advance notice of its adoption of an alternative compliance standard.

12. General Terms

12.1. Governing Law and Jurisdiction. All disputes with respect to this DPA shall be determined in accordance with the laws of the State of Israel and shall be handled at a competent court in Tel Aviv-Yafo.

12.2. Conflict. In the event of any conflict or inconsistency between this DPA and any other agreements between the parties, the provisions of this DPA shall prevail.

12.3. Changes in Applicable Data Protection Laws. Green Click may by at least forty-five (45) calendar days' prior written notice to Customer, request in writing any changes to this DPA, if they are required as a result of any change in any Applicable Data Protection Law.

12.4. Severance. Should any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain valid and in force.

For questions about this DPA, contact us at: [email protected]