MK_Vendor_DPA
MediaKind
DATA PROCESSING AGREEMENT
Agreement between: MK.IO and MEDIAFIRST (hereinafter referred to as "Supplier" and "Customer" respectively).
This Data Processing Agreement ("DPA") is incorporated into and forms a part of the Order for MK.IO products and/or services and/or MediaFirst. In the event of any conflict between the DPA and the Order, the provisions of the DPA shall prevail. Capitalized terms not defined herein shall have the meanings given to them in the Order.
BACKGROUND
(A) The Customer will have access to MK.IO products and services defined collectively as "Products" which enable the management and delivery of Content, necessitating the Supplier to process certain Personal Data on behalf of the Customer.
(C) The Supplier may process Personal Data for various purposes, including personal data relating to Customer's subscribers and embedded within Content that the Customer chooses to encode.
(D) The proposed Processing activities are described in the Annexes to this DPA.
(E) The terms specified herein apply when Supplier and/or its Affiliates process Personal Data on Customer’s behalf.
AGREED TERMS
1. Definitions
Applicable Privacy Laws: Laws and regulations applicable to processing of Personal Data under this DPA, including CCPA, Swiss Data Protection laws, UK Data Protection Act, and EU GDPR.
Data Subject: An identifiable natural person.
Personal Data: Any information relating to an identified or identifiable natural person processed under this DPA.
Processing: Any operation performed upon Personal Data such as collection, storage, use, etc.
Processor: The legal entity that processes Personal Data on behalf of the Controller.
SCCs: Standard contractual clauses for the transfer of Personal Data to processors outside EEA.
UK Addendum: Approved international data transfer addendum for the transfer of Personal Data to processors outside the UK.
2. General Provisions
- Customer is the Controller of the Personal Data and authorizes Supplier to process the Personal Data on Customer’s behalf in connection with the Services.
- Both Parties will maintain necessary permissions and consents required under Applicable Privacy Laws.
3. Supplier’s Obligations
- The Supplier acts solely as a “Service Provider” under the CCPA.
- Supplier will keep the Personal Data confidential and limit access to authorized personnel only.
- Supplier shall implement appropriate technical and organizational measures to support Customer’s obligations.
- Upon awareness of a Personal Data Breach, Supplier will notify Customer without undue delay.
4. Customer’s Obligations
Customer shall:
- Ensure lawful basis for Processing Personal Data.
- Inform Supplier of any erroneous, rectified or updated Personal Data being processed.
- Provide Supplier with timely lawful and documented instructions regarding Processing.
5. Security of Processing
Both Parties shall implement security measures to ensure a level of security appropriate to the risk, including:
- Pseudonymisation and encryption of Personal Data.
- Regular testing and assessment of security measures.
6. Sub-processors
Supplier may sub-contract Processing of Personal Data to a third party, imposing data protection obligations no less onerous than those set out in this DPA.
7. Audit
Supplier will provide documentation demonstrating compliance with this DPA upon request by the Customer. Audits can be conducted at Customer’s cost if necessary.
8. International / Restricted Transfers
Processing of Personal Data relating to EU/EEA or Swiss Data Subjects will be carried out according to current SCCs. Transfers outside these jurisdictions are regulated by Applicable Privacy Laws.
9. Personal Data Breaches
Supplier shall notify Customer upon becoming aware of an actual or suspected Personal Data Breach. Information relevant to the breach will be provided to the Customer.
10. Business contact details
Business contact information shall be processed as required to manage the business relationship.
11. Term and Termination
The DPA remains in effect as long as Supplier processes Personal Data. Either Party can terminate the DPA upon breach, with notice periods as outlined.
12. Liability
Supplier disclaims liability for claims arising from Customer’s violations of the DPA or Applicable Privacy Laws.
13. Law and Jurisdiction
Any disputes shall be governed by the law and jurisdiction stipulated in the Order.
14. Miscellaneous
- Provisions intended to survive termination of this DPA shall remain in force.
- Notices must be served as per the terms of the Order and can be sent to privacy@mediakind.com.
APPENDIX: EU STANDARD CONTRACTUAL CLAUSES & UK ADDENDUM
1. Transfers of Personal Data under EU GDPR:
- Customers are the Controller or Processor as specified in the SCCs.
2. Transfers of Personal Data under Swiss Data Protection Act:
- Similar provisions as the above will apply with adjustment for Switzerland.
3. Transfers under UK Data Protection Act:
- The SCCs supplemented with the UK Addendum.
ANNEX I: LIST OF PARTIES
| Data exporter: | The Customer (as stated in the Order) |
|---|---|
| Data importer: | The Supplier (as stated in the Order) |
ANNEX II: TECHNICAL AND ORGANISATIONAL MEASURES
The measures that will apply can be found in the accompanying documents.
ANNEX III: LIST OF SUB-PROCESSORS
| Full Name | Services Provided | Scope of Processing |
|---|---|---|
| Microsoft Corporation | Cloud infrastructure; AI services | Storage, encoding, AI services |
| Amazon Web Services, Inc. | Cloud infrastructure; AI services | Storage, encoding, AI services |
| Google LLC | Cloud infrastructure; AI services | Storage, encoding, AI services |
| Zoho Corporation | Support request/ticket logging | Collection and storage of support request/ticket information |
| Slack Technologies, LLC | Support requests | Collection and storage of support requests. |
| L&T Technology Services Limited | Installation and support services | Access to Customer's systems |
All Personal Data subject to processing will be handled as specified by the terms laid out in the respective Orders and this DPA.
Rev. 25_05