This Data Processing Addendum ("DPA") is incorporated into and forms part of the Service Agreement (the "Agreement") between HeartLegacy II, LLC, d/b/a SalesMail ("SalesMail," "we," "us," or "our") and the customer identified in the applicable Order Form ("Customer," "you," or "your"), and governs SalesMail's Processing of Personal Data on Customer's behalf in connection with the SalesMail platform, including its Sidekick product line (the "Platform" or "Services"). Terms not defined in this DPA have the meaning given to them in the Agreement.
By signing an Order Form or otherwise using the Services, Customer agrees to this DPA and confirms that the person accepting it has authority to bind Customer. If Customer does not have that authority, or does not agree to be bound, Customer should not submit Personal Data to the Services.
1.1 "Affiliate" means an entity that controls, is controlled by, or is under common control with a party, where "control" means direct or indirect ownership of more than 50% of the voting interests of that entity.
1.2 "Authorized Affiliate" means a Customer Affiliate that is permitted to use the Services under the Agreement but has not signed its own Order Form and is not itself a "Customer."
1.3 "Authorized User" means an individual Customer permits to use the Services through Customer's account, such as a sales representative.
1.4 "CCPA" means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, and its implementing regulations.
1.5 "Controller" means the entity that determines the purposes and means of Processing Personal Data; for purposes of the CCPA, this is the "Business."
1.6 "Customer Data" has the meaning given to it in the Agreement.
1.7 "Data Protection Laws" means the U.S. federal and state laws that apply to SalesMail's Processing of Personal Data under this DPA, including the CCPA and comparable state consumer privacy statutes.
1.8 "Individual" means an identified or identifiable natural person to whom Personal Data relates (referred to as a "Consumer" under the CCPA).
1.9 "Order Form" means the ordering document, subscription order, or similar document under which Customer purchases access to the Services.
1.10 "Personal Data" means information that identifies, relates to, or could reasonably be linked with a particular Individual, to the extent included in Customer Data Processed by SalesMail on Customer's behalf under the Agreement.
1.11 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data Processed by SalesMail on Customer's behalf.
1.12 "Personnel" means individuals authorized by SalesMail to Process Personal Data.
1.13 "Process or Processing" means any operation performed on Personal Data, whether automated or not, including collection, storage, use, disclosure, or destruction.
1.14 "Processor" means the entity that Processes Personal Data on behalf of a Controller; for purposes of the CCPA, this is the "Service Provider."
1.15 "Sensitive Data" means Personal Data subject to heightened protection under Data Protection Laws, including government identification numbers, financial account information, and other categories treated as sensitive under the CCPA or comparable laws.
1.16 "Sub-Processor" means a third party engaged by SalesMail to Process Personal Data on SalesMail's behalf.
2.1 This DPA applies whenever SalesMail Processes Personal Data on Customer's behalf as part of providing the Services. Customer is the Controller (or Business, under the CCPA) of that Personal Data, and SalesMail is the Processor (or Service Provider).
2.2 SalesMail currently Processes Personal Data within the United States. If Customer's use of the Services ever requires Processing or transferring Personal Data outside the United States, the parties will work in good faith to add appropriate safeguards to this DPA before that Processing begins.
3.1 SalesMail Processes Personal Data solely to provide the Services under the Agreement, for the duration of the Agreement, and as further described in Section 4 (Categories of Data) and Section 5 (Customer's Instructions).
4.1 Customer and its Authorized Users control who takes part in the conversations captured through the Services and what information those conversations contain. SalesMail does not select or control the identity of the Individuals whose Personal Data is Processed, or the categories of Personal Data involved — that is a function of how Customer chooses to use the Services.
4.2 Health-Related Information Captured Through Recorded Conversations. The Services are used to record and transcribe conversations between Customer's Authorized Users and the individuals they speak with, and for some Customers — including those in senior living or other care-related industries — those conversations may incidentally include health-related information about an Individual who is not one of Customer's own Authorized Users. SalesMail does not solicit, request, or select for this information; its presence in Customer Data, if any, follows from Customer's own choice to record a given conversation. Customer remains solely responsible for determining what notices or consents Data Protection Laws require for this category of information and for obtaining them, consistent with Section 5.2. SalesMail will not use this information to train general-purpose AI or machine-learning models made available to other customers or the public (consistent with Section 7.2), and will not use, retain, or disclose it for any purpose other than providing the Services to the Customer whose data it is (consistent with Section 6.1).
4.3 Other Sensitive Data. Outside of the health-related information addressed in Section 4.2, the Services are not intended for Customer to submit any Sensitive Data, such as government identification numbers or payment card data, and Customer agrees not to do so.
5.1 SalesMail will Process Personal Data only on Customer's documented instructions, which Customer gives by using the Services consistent with the Agreement and this DPA, including Section 7 below covering how SalesMail may use data to operate and improve the Services. If SalesMail is asked to do something it reasonably believes would violate Data Protection Laws, SalesMail will say so and is not obligated to comply unless and until the issue is resolved between the parties.
5.2 Customer is solely responsible for the accuracy and legality of the Personal Data it submits to the Services, for providing all notices required by Data Protection Laws to the Individuals involved, and for obtaining any consent or other lawful basis those laws require. Customer will indemnify and hold SalesMail harmless from claims arising out of Customer's failure to meet these obligations.
5.3 If SalesMail cannot carry out an instruction consistent with Data Protection Laws, SalesMail will explain why, may pause the affected Processing while the issue is worked out, and, if the parties cannot reach agreement, either party may terminate the Agreement as it relates to the affected Services.
6.1 SalesMail does not sell or share Personal Data, as those terms are defined under the CCPA, and does not receive Personal Data as payment for the Services. SalesMail will not combine Personal Data Processed on Customer's behalf with data from any other customer, and will not use, retain, or disclose it for any purpose other than providing the Services.
7.1 SalesMail may use Personal Data to operate,maintain, and improve the Services for the Customer whose data it is —including, for Personal Data other than the health-related informationdescribed in Section 4.2, through machine learning or model development intendedto improve the Services generally.
7.2 Health-related information described in Section 4.2 will be treated differently, and more narrowly, than other Personal Data: SalesMail will not use it to train general-purpose AI or machine-learning models made available to other customers or the public, and any use of it willbe limited to providing the Services to the Customer whose data it is.
8.1 SalesMail limits access to Personal Data to Personnel who need it to provide the Services, requires those Personnel to sign confidentiality obligations that survive their employment or engagement, andensures they are trained on their responsibilities before they are given access.
9.1 Customer authorizes SalesMail to engage the Sub-Processors reasonably necessary to provide the Services — including cloud hosting, communications, audio-transcription, and analytics providers, among others — under written agreements that hold them to data protection obligations consistent with this DPA.
10.1 SalesMail maintains administrative, technical,and physical safeguards designed to protect Personal Data against unauthorized access, use, disclosure, alteration, or destruction, including encryption of Personal Data in transit and at rest, and access controls limiting Personnel access to what their role requires.
11.1 SalesMail maintains incident response policiesand will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer's Personal Data, describing, to the extent known: the nature of the breach; the categories and approximate number of Individuals and records affected; SalesMail's assessment of the likely consequences; and the steps SalesMail has taken or plans to take in response. Where full information is not available immediately, SalesMail will provide itin phases without further delay.
11.2 Customer will not publicly identify SalesMail in connection with a Personal Data Breach without SalesMail's prior written approval, except to the extent Data Protection Laws require it — in which case Customer will give SalesMail reasonable advance notice and limit the disclosure to what the law requires.
12.1 SalesMail will provide reasonable assistance, at Customer's request and expense beyond a negligible amount, to help Customer respond to an Individual's request to access, correct, delete, or limit the use of their Personal Data, and to help Customer meet its own security, breach-notification, and risk-assessment obligations under Data Protection Laws, to the extent the relevant information is available to SalesMail and Customer does not already have it.
13.1 On Customer's reasonable written request, SalesMailwill provide the information reasonably necessary to show compliance with this DPA, which Customer may use only to assess that compliance and must kee confidential.
13.2 SalesMail will also allow Customer, or areputable auditor Customer engages who is not a SalesMail competitor, to audit SalesMail's compliance with this DPA, subject to reasonable conditions: at least ninety (90) days' advance written notice, no more than once every twelve (12) months (except following a Personal Data Breach), a signed confidentiality undertaking from the auditor, no access to other customers' data, and Customer bearing the audit's costs. SalesMail may satisfy this obligation by providing a relevant third-party audit report or certification instead of a direct audit, where one reasonably covers the same ground.
14.1 Within thirty (30) days after the Agreement ends, SalesMail may delete Customer's Personal Data in its possession, except data SalesMail is required by law to retain or that exists on backup systems, which SalesMail will isolate from further Processing until it is deleted on the ordinary backup cycle.
15.1 Customer may enter into this DPA on behalf of itself and its Authorized Affiliates. Each Authorized Affiliate is bound by Customer's obligations under this DPA to the extent SalesMail Processes Personal Data on that Affiliate's behalf, and Customer remains responsible for coordinating all communication with SalesMail under this DPA on behalf of its Authorized Affiliates.
16.1 This DPA takes effect on the earliest of its execution date, the effective date of the Agreement, or the date SalesMail begins Processing Personal Data on Customer's behalf, and continues until the Agreement ends.
17.1 Either party may request changes to this DPA, on at least forty-five (45) days' written notice, if needed to comply with a change in Data Protection Laws. Each party will negotiate those changes in good faith; if the parties cannot agree within thirty (30) days, either may terminate the Agreement as it relates to the affected Services, without further liability beyond what has already accrued.
18.1 Before either party starts a legal proceeding over this DPA, the parties will first try to resolve it informally: direct discussion between the people managing the relationship, and if that does notwork, between executives with authority to settle it. These discussions are confidential settlement communications.
19.1 Each party's liability arising out of this DPA is subject to, and aggregated with, the limitation of liability terms in the Agreement — this DPA does not create a separate or additional liability cap.
20.1 Where this DPA and the Agreement conflict on how Personal Data is Processed, this DPA controls.