This Data Processing Addendum (“DPA”) is entered into as of the last date executed below by and between Leap Technologies, Inc. d/b/a Leapfin, a Delaware corporation having its principal place of business at 205 De Anza Blvd #146, San Mateo, CA 94402 (“Leapfin”) and Customer (defined below).
THIS DPA APPLIES BETWEEN THE PARTIES WHERE CUSTOMER CLICKS A BOX INDICATING ACCEPTANCE, TRANSFERS PERSONAL DATA TO LEAPFIN FOR PROCESSING BY MEANS OF THE SERVICE, OR OTHERWISE AFFIRMATIVELY INDICATES ACCEPTANCE OF THIS DPA. BY DOING SO, YOU: (A) AGREE TO THIS DPA EITHER ON BEHALF OF YOURSELF, OR THE ORGANIZATION, COMPANY, OR OTHER LEGAL ENTITY FOR WHICH YOU ACT (EACH, A “CUSTOMER”); AND (B) REPRESENT THAT YOU HAVE THE AUTHORITY TO BIND CUSTOMER AND ITS AFFILIATES TO THIS DPA. IF YOU DO NOT HAVE SUCH AUTHORITY, OR IF YOU DO NOT AGREE WITH THIS DPA, YOU MAY NOT DIRECTLY OR INDIRECTLY TRANSFER PERSONAL DATA TO LEAPFIN. LEAPFIN RESERVES THE RIGHT TO MODIFY OR UPDATE THE TERMS OF THIS DPA IN ITS DISCRETION, THE EFFECTIVE DATE OF WHICH WILL BE THE EARLIER OF (I) 30 DAYS FROM THE DATE OF SUCH UPDATE OR MODIFICATION AND (II) CUSTOMER’S CONTINUED TRANSFER OF PERSONAL DATA.
This DPA forms part of Leapfin’s “Terms of Service” (located at: https://www.leapfin.com/terms/) (referred to as the “Agreement” hereunder), unless Leapfin and Customer have entered into a separate written agreement for the use of the Service in which case such agreement is deemed the Agreement. Leapfin will provide the Service to Customer pursuant to the DPA and this Agreement which involves the Processing of Personal Data subject to Applicable Data Protection Laws (each as defined below). The purpose of this DPA is to set forth the terms under which Leapfin Processes Personal Data on behalf of Customer.
This DPA consists of the main body and Schedules 1 through 4. Execution of this DPA shall include signature and acceptance of the Standard Contractual Clauses (defined below) and its Annexes (see Schedule 2 below).
TRANSFER MECHANISMS FOR STANDARD CONTRACTUAL CLAUSES DATA TRANSFERS
Where Leapfin enters into the EU P-to-P Transfer Clauses with a Subprocessor in connection with the provision of the Services, Customer hereby grants Leapfin and Leapfin’s Affiliates authority to provide a general authorization on Controller’s behalf for the engagement of subprocessors by Subprocessors engaged in the provision of the Services, as well as decision making and approval authority for the addition or replacement of any such subprocessors.
ANNEX I THROUGH III TO THE STANDARD CONTRACTUAL CLAUSES
This Schedule 2 contains Annex I through III to the Standard Contractual Clauses and and must be completed and signed by each party below where indicated.
Data exporter(s):[Identity and contact details of the data exporter(s) and, where applicable, of its/their data protection officer and/or representative]
Data importer(s):
The Processing activities carried out by Leapfin under the Agreement may be described as follows:
Categories of data subjects whose personal data is transferred
Customer and its end users
Categories of personal data transferred
Categories of Personal Data chosen by a controller and issued to processor or subprocessor as the case may be via the Service
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
Sensitive data transferred to processor by a controller, or on its behalf as permitted under the DPA, via the Services (e.g., racial or ethnic origin, social security number, religion, etc.)
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
On a continuous basis as determined by a controller or on its behalf as permitted under the Agreement.
Nature of the processing
Description of the processing for the Services
Purpose(s) of the data transfer and further processing
For processor/subprocessor to provide the Services to a controller (or on their behalf) as required under the Agreement
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
For the term of the Agreement
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
For the term of the Agreement
The competent supervisory authority in accordance with Clause 13 of the Standard Contractual Clauses as identified in Schedule 1 Section 4(k) of this DPA.
TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
Leapfin processes all personal data received from Controller, or on its behalf under this DPA in conformity with the following technical and organizational measures:
LIST OF SUB-PROCESSORS
The Controller has authorized the use of the following Subprocessors:
Subprocessor |
Function |
Location(s) |
Amazon AWS |
Cloud service provider |
USA (West 2 – Oregon) |
TRANSFER MECHANISMS FOR UK GDPR
UNITED STATES SCHEDULE