This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between VisibilityAI, LLC, a Delaware limited liability company ("VisibilityAI", "we", "us"), and the customer that has accepted the Agreement ("Customer", "you"). It applies where, in your use of the Service, we Process Personal Data on your behalf. If there is a conflict between this DPA and the Agreement regarding the Processing of Personal Data, this DPA controls.
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given in applicable data-protection law, including the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended ("CCPA"). "Customer Personal Data" means Personal Data contained in Your Content that we Process on your behalf. Capitalized terms not defined here have the meanings in the Agreement.
For Customer Personal Data, you are the Controller (or a Processor acting on behalf of a Controller) and VisibilityAI is the Processor (or sub-processor). We Process Customer Personal Data only to provide, secure, and support the Service and to carry out actions you request, as described in the Agreement and this DPA. The subject matter, duration, nature, and purpose of Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex A.
We will Process Customer Personal Data only on your documented instructions, including as set out in the Agreement, this DPA, and your configuration and use of the Service, unless required to do otherwise by law (in which case we will inform you where legally permitted). You are responsible for ensuring you have a lawful basis to provide Customer Personal Data and for the accuracy and legality of your instructions.
We ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and Process the data only as necessary to provide the Service.
We implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, or damage, taking into account the state of the art and the risks of the Processing. These measures include encryption in transit, encryption of sensitive stored credentials, access controls, and least-privilege access.
You authorize us to engage sub-processors to Process Customer Personal Data to provide the Service. We impose data-protection obligations on each sub-processor that are consistent with this DPA, and we remain responsible for their performance. We will make available a description of the categories of sub-processors we use (see our Privacy Policy) and, on request, further information reasonably necessary for a data-protection assessment. We will give you a reasonable means to be informed of changes to sub-processors so you may object on reasonable data-protection grounds.
Taking into account the nature of the Processing, we will provide reasonable assistance (including through the functionality of the Service) to help you respond to requests from Data Subjects to exercise their rights under applicable law. If we receive such a request directly, we will, where legally permitted, direct the Data Subject to you.
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to us to help you meet your notification obligations.
Following expiry or termination of the Agreement, we will make Customer Personal Data available for export for a limited period and will then delete it in accordance with our data-retention practices, unless applicable law requires further retention.
We will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality, scope, frequency, and notice terms.
We are based in the United States, and Customer Personal Data may be Processed in the United States and other countries. Where Customer Personal Data is transferred from the EEA, UK, or Switzerland to a country not deemed to provide an adequate level of protection, the parties agree that the European Commission's Standard Contractual Clauses (and the UK Addendum, where applicable) are incorporated into this DPA by reference and apply to such transfers.
To the extent the CCPA applies, we act as your "service provider". We will not sell or share Customer Personal Data, will not retain, use, or disclose it except as necessary to provide the Service or as otherwise permitted by the CCPA, and will not combine it with other data except as permitted by the CCPA. We certify that we understand and will comply with these restrictions.
Except as expressly modified by this DPA, the Agreement remains in full force and effect. This DPA is governed by the same law and subject to the same limitations of liability as the Agreement.
VisibilityAI, LLC (a Delaware limited liability company)
16192 Coastal Highway, Lewes, DE 19958
privacy@visibility.ai