This Data Processing Agreement ("DPA") is incorporated into and forms part of the SupaClub Terms of Service (the "Agreement") between Good Creative Lab Inc. ("SupaClub" or "Processor") and the Customer ("Controller").
Terms such as "Personal Data," "Data Subject," "Processing," "Controller," and "Processor" shall have the meanings ascribed to them in applicable Data Protection Law (such as the GDPR). "Customer Personal Data" means the Personal Data of End Users that Processor Processes on behalf of Controller in connection with the provision of the Services within the Controller's Organization.
Processor shall implement and maintain appropriate technical and organizational security measures to protect Customer Personal Data from security incidents.
Processor shall ensure that its personnel engaged in the Processing of Customer Personal Data are subject to obligations of confidentiality.
Controller acknowledges and agrees that Processor may engage third-party sub-processors. Processor will provide a list of its sub-processors upon request and shall ensure they are bound by agreements that provide at least the level of data protection required by this DPA.
Processor shall, to the extent legally permitted, promptly notify Controller if it receives a request from a Data Subject to exercise their rights. Processor shall assist Controller by appropriate technical and organizational measures for the fulfillment of Controller's obligation to respond to a Data Subject's request.
Processor shall notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
Upon termination of the Agreement, Processor shall, at the choice of Controller, delete or return all Customer Personal Data to Controller.
Processor shall make available to Controller on request all information necessary to demonstrate compliance with this DPA.