This Data Processing Agreement and its Exhibits (“DPA“) forms part of and is subject to the terms and conditions of the Agreement (as defined below) by and between you (“Customer“) and Seesaw Learning, Inc. and its Affiliates (“Seesaw” and, together with the Customer, the “Parties“).
1. Definitions
1.1 Capitalized terms not defined in this DPA (including its Exhibits) will have the meaning set forth in the Agreement. The following capitalized terms used in this DPA are defined as follows:
“Affiliate” means any entity within a controlled group of companies that directly or indirectly, through one or more intermediaries, is controlling, controlled by, or under common control with one of the Parties.
“Agreement” means the agreement entered into between the Customer and Seesaw in respect of the Services, comprising Seesaw’s Terms of Service or as otherwise agreed between the Parties.
“Controller Purposes” means the purposes described in Exhibit A in respect of Processing that Seesaw conducts as a controller, business or third party (as identified in Exhibit A).
“Customer” has the meaning given to it in the Agreement.
“Customer Personal Data” means: (a) any Personal Data that is provided by or on behalf of Customer to Seesaw in connection with the performance of the Services; or (b) Personal Data that is obtained by Seesaw directly from Data Subjects, or is otherwise developed or produced by Seesaw, or its agents or subcontractors, in connection with the provision of the Services, in each case as further described in Exhibit A.
“Data Subject” means a natural person to whom Personal Data relates.
“Data Protection Laws” means all laws and regulations applicable to the Processing of Customer Personal Data, including but not limited to the laws and regulations identified in Exhibit C hereto, as may be amended, modified or supplemented from time to time, as applicable.
“Effective Date” means the date the Parties enter into the Agreement or, if different, the date on which such Agreement is deemed to take effect.
“Personal Data” means any data or information that: (a) is linked or reasonably linkable to an identified or identifiable natural person; or (b) is otherwise “personal data”, “personal information”, “personally identifiable information”, or similarly defined data or information under Data Protection Laws.
“Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means. “Process“, “Processes” and “Processed” will be interpreted accordingly.
“Restricted Transfer” means any transfer of Customer Personal Data protected by Data Protection Laws to a third country or an international organization in a third country (including data storage on foreign servers).
“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to (including unauthorized internal access to), Customer Personal Data.
“Standard Contractual Clauses” or “SCCs” are the model clauses for Restricted Transfers adopted from time to time by the relevant authorities of the jurisdictions indicated in Exhibit C, insofar as their use is approved by the relevant authorities as an appropriate mechanism or safeguard for Restricted Transfers.
“Subprocessor” means a processor appointed to Process Personal Data on behalf of another processor.
2. Relationship with the Agreement
2.1 If there is any conflict between this DPA and the Agreement, this DPA shall prevail to the extent of that conflict.
2.2 Any claims brought under or in connection with this DPA shall be subject to the terms and conditions, including but not limited to, the exclusions and limitations set forth in the Agreement.
2.3 This DPA shall be governed by and construed in accordance with governing law and jurisdiction provisions in the Agreement, unless required otherwise by applicable Data Protection Laws.
3. Roles
3.1 The Parties acknowledge and agree that:
(a) save as set out in section 3.1(b) and 3.1(c), Seesaw acts as a processor in Processing Customer Personal Data and Customer acts as a controller;
(b) Seesaw acts as a controller in respect of its Processing of Customer Personal Data for the Controller Purposes; and
(c) Seesaw and Customer act as joint controllers as identified in Exhibit A.
4. Compliance
4.1 This DPA will apply to the Processing of all Customer Personal Data, regardless of country of origin, place of Processing, location of Data Subjects, or any other factor. Each Party shall comply with its obligations under Data Protection Laws in respect of its Processing of Customer Personal Data.
4.2 Without prejudice to the foregoing, and subject to the obligations set out in section 8 and Exhibit B in respect of any Processing carried out by the Parties as joint controllers, each Party shall, with respect to Processing it undertakes as controller:
(a) provide such information to Data Subjects regarding the Processing of Customer Personal Data as required under Data Protection Laws; and
(b) to the extent required for the lawful Processing of Customer Personal Data under Data Protection Laws, obtain valid consents from Data Subjects for such Processing in the form required under Data Protection Laws.
4.3 Each Party shall promptly notify the other if it receives a request from a Data Subject to assert their rights to the erasure or rectification of their Customer Personal Data.
5. Confidentiality
5.1 Seesaw shall:
(a) limit access to Customer Personal Data to personnel who have a business need to have access to such Customer Personal Data; and
(b) ensure that such personnel are subject to obligations at least as protective of the Customer Personal Data as the terms of this DPA and the Agreement, including duties of confidentiality with respect to any Customer Personal Data to which they have access.
6. Data Processing
6.1 This section 6 applies to the extent that Seesaw acts as a Processor or ‘service provider’ in Processing the Customer Personal Data.
6.2 The details of the Processing of Personal Data under the Agreement and this DPA (including subject matter, nature and purpose of the Processing, categories of Personal Data and Data Subjects) are described in the Agreement and in Exhibit A.
6.3 Seesaw will only Process Customer Personal Data on behalf of and under the instructions of Customer and in accordance with Data Protection Laws, unless Processing is required under applicable law, in which case Seesaw shall notify Customer of that legal requirement before Processing unless that law prohibits providing such information on important grounds of public interest.
6.4 Seesaw shall:
(a) provide Customer with information to enable Customer to conduct and document any data protection assessments required under Data Protection Laws and provide such reasonable assistance to Customer as required in connection with any investigation by or consultation with the Client’s supervisory authority;
(b) immediately notify Customer if, in its reasonable opinion, an instruction infringes Data Protection Laws;
(c) promptly notify Customer of any request received by Seesaw or any Subprocessor from a Data Subject to assert their rights in relation to Customer Personal Data under Data Protection Laws (a “Data Subject Request“);
(d) not respond to any Data Subject Requests and, taking into account the nature of the Processing, provide Customer with reasonable assistance through technical and organizational measures, insofar as this is possible, for Customer to fulfil its obligation under Data Protection Laws to respond to Data Subject Requests.
6.5 Seesaw may engage any of the Subprocessors listed at https://trust.seesaw.me/subprocessors, as amended in accordance with section 6.6 (the “Authorized Subprocessors“), to Process Customer Personal Data. Seesaw shall:
(a) enter into a written agreement with each Subprocessor imposing data protection obligations that, in substance, are no less protective of Customer Personal Data than Seesaw’s obligations under this DPA; and
(b) remain liable for each Subprocessor’s compliance with the obligations under this DPA.
6.6 Seesaw will provide Customer with at least fifteen (15) days’ notice of any proposed changes to the Authorized Subprocessors. Customer shall comply with any reasonable instructions provided by Seesaw for receiving such notifications, including (where applicable) subscribing to any data feeds or mailing lists that Seesaw makes available for such notifications. The webpage where Customers can subscribe to notices is https://trust.seesaw.me/subprocessors, once there click on the “Subscribe to updates” button at the top right of the screen. Customer shall notify Seesaw if it objects to the proposed change to the Authorized Subprocessors by providing Seesaw with written notice of the objection within ten (10) days after Seesaw has provided notice to Customer of such proposed change. In such event, the parties shall discuss such concerns in good faith with a view to achieving resolution. If this is not possible, Customer may suspend or terminate the Agreement and request a pro-rated refund of any fees paid.
6.7 Seesaw shall, subject to section 9, provide Customer with all information reasonably necessary to demonstrate its compliance with this DPA. Seesaw shall, no more than once per year, allow for, and contribute to, reasonable audits and inspections by Customer or Customer’s designated auditor.
6.8 Upon becoming aware of a Security Incident, Seesaw shall notify Customer without undue delay and shall provide timely information relating to the Security Incident as it becomes known or as is reasonably requested by Customer. Seesaw shall provide reasonable assistance to Customer as required for Customer to comply with any notification obligations in respect of the Security Incident arising under Data Protection Laws.
7. Joint control
7.1 To the extent that Seesaw and Customer act as joint controllers in respect of the Processing of Customer Personal Data, as identified in Exhibit A, they shall perform their obligations under Data Protection Laws as set out in Exhibit B, save where their responsibilities are otherwise determined by applicable law.
8. Security
8.1 Seesaw shall implement and maintain appropriate technical and organizational security measures to protect Customer Personal Data from Security Incidents and to preserve the security and confidentiality of the Customer Personal Data, in accordance with Seesaw’s security standards described in https://help.seesaw.me/hc/en-us/articles/203258429.
8.2 Customer acknowledges that the Security Measures are subject to technical progress and development and that Seesaw may update or modify the Security Measures from time to time provided that such updates and modifications do not result in the degradation of the overall security of the Services purchased by the Customer.
9. Audits
9.1 The Parties agree that any audits conducted in accordance with section 6.7 shall be conducted as follows:
(a) Following receipt by Seesaw of an audit request, Seesaw and Customer will discuss and agree in advance on the reasonable start date, scope and duration of, and security and confidentiality controls applicable to, any audit. Any audit must be: (i) conducted during Seesaw’s regular business hours; (ii) with reasonable advance notice to Seesaw; (iii) carried out in a manner that prevents unnecessary disruption to Seesaw’s operations; and (iv) subject to reasonable confidentiality procedures.
(b) Seesaw may charge a fee (based on Seesaw’s reasonable costs) for any audit. Seesaw will provide Customer with further details of any applicable fee, and the basis of its calculation, in advance of any such audit. Customer will be responsible for any fees charged by any third-party auditor appointed by Customer to execute any such audit.
(c) Seesaw may object to any third-party auditor appointed by Customer to conduct any audit under section 6.7(a) if the auditor is, in Seesaw’s reasonable opinion, not suitably qualified or independent, a competitor of Seesaw, or otherwise manifestly unsuitable. Any such objection by Seesaw will require Customer to appoint another auditor or conduct the audit itself.
(d) Nothing in this DPA shall require Seesaw either to disclose to Customer or its third-party auditor, or to allow Customer or its third-party auditor to access:
any data of any other customer of Seesaw;
Seesaw’s internal accounting or financial information;
any trade secret of Seesaw;
any information that, in Seesaw’s reasonable opinion, could: (A) compromise the security of Seesaw’s systems or premises; or (B) cause Seesaw to breach its obligations under Data Protection Laws or
its security and/or privacy obligations to Customer or any third party; or
any information that Customer or its third-party auditor seeks to access for any reason other than the good faith fulfillment of Customer’s obligations under Data Protection Laws.
9.2 Seesaw may, in response to the Customer’s audit request:
(a) provide the Customer with any independent audit reports or data protection compliance certifications issued by a commonly accepted certification and obtained by Seesaw in support of Seesaw’s obligations under this DPA; or
(b) arrange for a qualified and independent auditor to conduct an audit of Seesaw’s policies and technical and organizational measures in support of the obligations under this DPA using an appropriate and accepted control standard or framework and audit procedure for the audits as applicable, and provide the report of such audit to Customer,
and Customer agrees to accept any such audit reports or certifications provided by Seesaw in place of conducting an audit.
10. Jurisdiction Specific Terms
10.1 To the extent Seesaw Processes Customer Personal Data originating from or protected by Applicable Data Protection Laws in a jurisdiction listed in Exhibit C, then the terms and definitions specified in Exhibit C with respect to the applicable jurisdiction(s) (“Jurisdiction Specific Terms”) shall apply in addition to the terms of this DPA.
10.2 Seesaw may update Exhibit C from time to time to reflect changes in or additions to Data Protection Laws to which relevant Processing operations are subject. If Seesaw updates Exhibit C, it will notify Customer in writing. If Customer does not object to the updated Exhibit C within fourteen (14) days of receipt, Customer will be deemed to have consented to the updated Exhibit C.
10.3 In case of any conflict or ambiguity between the Jurisdiction Specific Terms and any other terms of this DPA, the applicable Jurisdiction Specific Terms will prevail.
11. International Transfers
11.1 Restricted Transfers of Customer Personal Data within the scope of this DPA shall be conducted in accordance with Exhibit C and Applicable Data Protection Laws.
11.2 Seesaw may update the Exhibits to this DPA from time to time to reflect changes in or additions necessary to conclude the Standard Contractual Clauses. Without limiting the generality of the foregoing, if the execution of a new version of the Standard Contractual Clauses adopted by the relevant authorities in the jurisdiction governing the Processing of Customer Personal Data is later required in order for the Parties to rely on the Standard Contractual Clauses as a lawful mechanism for Restricted Transfers, the Parties are deemed to have agreed to the new version of the Standard Contractual Clauses by signing this DPA, and, if necessary, Seesaw shall be entitled to update the Exhibits accordingly.
11.3 If an alternative transfer mechanism, such as Binding Corporate Rules, is adopted by Seesaw during the term of the Agreement (an “Alternative Mechanism”), and Seesaw notifies Customer that some or all Restricted Transfers can be conducted in compliance with Data Protection Laws pursuant to the Alternative Mechanism, the Parties will rely on the Alternative Mechanism instead of the transfer mechanisms in Exhibit C for Restricted Transfers to which the Alternative Mechanism applies.
12. Term, Return or Deletion of Data
12.1 This DPA shall be deemed to commence on the Effective Date and, notwithstanding termination of the Agreement, will remain in effect until, and automatically expire on, Seesaw’s deletion or anonymization of all Customer Personal Data.
12.2 Seesaw shall:
(a) if requested to do so by Customer within ninety (90) days of termination or expiry of the Agreement (the “Termination Retention Period”), provide Customer a copy of all Customer Personal Data Processed by Seesaw as a Processor or service provider in such commonly used format as requested by Customer, or provide a self-service functionality allowing Customer to download such Customer Personal Data; and
(b) on expiry of the Termination Retention Period, delete all copies of Customer Personal Data Processed by Seesaw or any Authorized Subprocessors, other than: (i) Customer Personal Data that Seesaw is required to retain by applicable law; and (ii) Customer Personal Data that Seesaw Processes as a controller or business for the Controller Purposes.
List of Exhibits
Exhibit A: Details of the Processing
Exhibit B: Allocation of Responsibilities between Joint Controllers
Exhibit C: Jurisdiction Specific Terms
EXHIBIT A
DETAILS OF THE PROCESSING
Customer Personal Data
Seesaw receives the following Personal Data from Customer, or collects
the following Personal Data from Authorized Users, and Processes such
Personal Data for the following purposes, in each case in connection
with the provision of the Services:
| Data Subjects | Category of Personal Data | Purpose of Processing | Seesaw’s role | Retention period |
|---|---|---|---|---|
Authorized Users who:
|
Contact information, such as name, email address, phone number and Customer granting the Administrator or Teacher access to the Services. | Create and authenticate the Authorized User’s account on the Services. Send the Authorized User service-related communications in accordance with the Authorized User’s account preferences. Respond to support requests received in respect of the Services. |
Processor | Until the earlier of:
|
Communicate with Administrators in relation to the administration of the Agreement and relationship between the Parties. |
Controller | |||
Send promotional emails in accordance with the Authorized User’s preferences. |
Controller | |||
Single sign-on or third-party login authentication token |
Create and authenticate the Authorized User’s account on the Services. |
Processor | ||
| Questions, comments and other correspondence submitted by the Authorized User to Seesaw. | Respond to support requests in relation to the Services. | Processor | ||
Identify and remedy errors and inform product development. |
Controller | |||
| Communication preferences, such as preferences for service-related communications and promotional emails. | Send service-related communications only in accordance with the Authorized User’s preferences. | Processor | ||
Send promotional emails only in accordance with the Authorized User’s preferences. |
Controller | |||
Activities and tasks created or uploaded to the Services and / or assigned to Students for completion. |
Provide the interactive learning functionalities of the Services. | Processor | ||
Comments and feedback on Student activities (including approval of content uploaded by Students to the Services) and messages sent and received through the Services. |
Provide the interactive learning functionalities of the Services. Facilitate communication between Teachers, Students and Family Members. |
Processor | ||
Content and posts to online classrooms for access by all Students and Family Members enrolled to that class. |
Facilitate communication between Teachers, Students and Family Members. |
Processor | ||
Contributions to the Community Library [c]and Teacher Scrapbook[d]. |
Provide community-driven resource libraries to teachers. Promote the Services and community engagement between teachers and schools using the Services. |
Controller | For as long as we maintain the Community Library and Teacher Scrapbook on the Services. | |
Authorized Users who are granted access to the Services through a family member account (“Family Members“). |
Account information such as name, email address, phone number and Teacher or Administrator granting the Family Member access to the Services. | Create and authenticate the Authorized User’s account on the Services. Send the Authorized User service-related communications in accordance with the Authorized User’s account preferences. Respond to support requests received in respect of the Services. |
Processor | Until the earlier of:
|
Single sign-on or third-party login authentication token |
Create and authenticate the Authorized User’s account on the Services. |
Processor | ||
Linked student details, including name of the Family Member’s child that accesses the Services. |
Grant the Family Member access to the relevant Student’s activities on the Services in accordance with the access settings set by the Administrator or Teacher. Grant the Family Member access to the content / updates posted by Teachers and Administrators in respect of the Student or the Student’s class for review by Family Members. |
Processor | ||
| Messages and comments sent or uploaded by the Family Member through the Services. | Facilitate communication between family members, teachers and schools in accordance with the functionalities of the Seesaw Service. |
Processor | ||
| Questions, comments and other correspondence submitted by the Authorized User to Seesaw. | Respond to support requests in relation to the Services. | Processor | ||
Identify and remedy errors and inform product development. |
Controller | |||
| Authorized Users who are granted access to the Services through a student account (“Students“) | Account information, such as name, email address, Teacher or Administrator granting the Student access to the Services. | Create and authenticate the Authorized User’s account on the Services. Send the Authorized User service-related communications in accordance with the Authorized User’s account preferences. |
Processor | Until the earlier of:
|
Single sign-on or third-party login authentication token |
Create and authenticate the Authorized User’s account on the Services. |
Processor | ||
| Profile photo / avatar | Allow Students to personalize their accounts on the Services. | Processor | ||
Teacher and class to which the Student is enrolled. |
Grant the Authorized User access to activities and content assigned to the Student’s class. | Processor | ||
Activities assigned to the Student by their Teacher or Administrator and completed by the Student through the Services. |
Provide the interactive learning functionalities of the Services. Facilitate communication between Teachers, Students and Family Members. |
Processor | ||
Content and comments uploaded by the Student as part of their journal on the Services, including images, text and audio. |
Provide the interactive learning functionalities of the Services. Facilitate communication between Teachers, Students and Family Members. |
Processor | ||
Feedback from Teachers on Student work uploaded to the Services. |
Provide the interactive learning functionalities of the Services. Facilitate communication between Teachers, Students and Family Members. |
Processor | ||
| Messages sent between the Student and their Teacher on the Services, and between the Teacher and Family Members in relation to the Student. | Provide the interactive learning functionalities of the Services. Facilitate communication between Teachers, Students and Family Members. |
Processor | ||
Linked Family Member account details, including name of Family Member. |
Grant the Family Member access to the relevant Student’s activities on the Services in accordance with the access settings set by the Administrator or Teacher. Grant the Family Member access to the content / updates posted by Teachers and Administrators in respect of the Student or the Student’s class for review by Family Members. |
Processor | ||
| Administrators, Teachers, Family Members, Students | Information about the device used to access the Services, such as IP address, unique device identifying numbers, type of device used, operating system, screen size, browser type, browser window size and device model and approximate location derived from IP address. Information about how the Authorized User interacts with the Services such as the pages viewed and visited and features used on the Services, and any errors that occur on the Services while the Authorized User uses it. |
Grant Authorized Users access to the Services and provide the features and functionalities of the Services. |
Processor | 60 days |
| Administrators, Teachers, Family Members, Students | Detect and prevent fraudulent use of the Services. |
Joint controller | 60 days |
EXHIBIT B
ALLOCATION OF RESPONSIBILITIES BETWEEN JOINT CONTROLLERS
| Responsibility | Customer | Seesaw | Description |
|---|---|---|---|
| Lawfulness | ✓ | Seesaw shall, to the extent required under Data Protection Laws, obtain consent to the Processing of Personal Data. Where Seesaw has obtained consent to the Processing of Personal Data, neither Party shall Process any Personal Data to the extent that a Data Subject has withheld or withdrawn their consent. |
|
| Transparency / Notification | ✓ | Seesaw shall provide Data Subjects with a privacy notice setting out the information required under Data Protection Law in respect of the Processing of Personal Data. Neither the Customer nor the Seesaw shall process shared Personal Data other than as set out in such privacy notice. |
|
| Data Subject Requests | ✓ | Seesaw shall be the contact point for any Data Subject requests concerning Personal Data Processed by the Parties jointly. Customer shall notify Seesaw promptly following receipt of a Data Subject request concerning Personal Data Processed jointly. Seesaw shall determine how to respond and be responsible for giving effect to the Data Subject request (including the application of any exemptions). |
|
| Processors | ✓ | Subject to any restrictions on the onward transfer of Personal Data in the Agreement, Seesaw may appoint Processors in accordance with Data Protection Law. Seesaw shall be responsible for ensuring the Processors it appoints comply with applicable Processing agreements. | |
| Records of Processing Activities | ✓ | Seesaw shall maintain records in compliance with Data Protection Laws for the Processing activities undertaken by the Parties jointly, and make such records available to Customer on request. Customer shall provide any information reasonably requested by Seesaw for the purpose of maintaining such records of Processing. | |
| Security | ✓ | Seesaw shall implement and be responsible for implementing appropriate security measures with respect to the Processing undertaken by the Parties jointly within Seesaw’s information systems. | |
| Consultation with supervisory authority | ✓ | Seesaw shall be the primary point of contact for any requests from or consultation with supervisory authorities. Each Party shall notify the other promptly upon, and in any event within forty-eight (48) hours of receiving a request from any supervisory authority in relation to the joint Processing of Personal Data. The Parties shall cooperate and coordinate responses and requests to supervisory authorities. |
|
| Security notification | ✓ | Seesaw shall be the primary point of contact for any notifications to supervisory authorities or Data Subjects under Data Protection Law. | |
| Data Protection Impact Assessment | ✓ | Seesaw shall identify any Processing that is likely to result in high risk to the rights and freedoms of Data Subjects and notify the other Party of any data protection impact assessments to be conducted in respect of the Processing. | |
| Privacy / Data Protection Officers | ✓ | ✓ | Each Party shall appoint a DPO where required under applicable Data Protection Laws. |
| Restricted Transfers | ✓ | Seesaw shall determine and be responsible for the transfers of Personal Data under Data Protection Laws undertaken by Seesaw in respect of Personal Data Processed jointly. |
EXHIBIT C
JURISDICTION-SPECIFIC TERMS
Argentina.
Applicability. Wherever the Processing pursuant to the DPA falls within the scope of Argentina’s Personal Data Protection Law 25,326, Regulatory Decree 1558/2001, and any other corresponding decrees, regulations, or guidance governing the Processing of Personal Data in Argentina (collectively “Argentine Data Protection Laws”), the provisions of the DPA and this Exhibit shall apply to such Processing.
Restricted Transfers.
With regard to any Restricted Transfer subject to Argentine Data Protection Laws between the Parties, one of the following transfer mechanisms shall apply, in the following order of precedence:
a valid adequacy decision adopted by the Argentine National Bureau of Personal Data Protection (“NBPDP”);
the appropriate SCCs adopted by the NBPDP from time to time; or
any other lawful data transfer mechanism, as laid down in Argentine Data Protection Laws.
Standard Contractual Clauses.
The DPA hereby incorporates by reference the SCCs. The Parties are deemed to have accepted, executed, and signed the SCCs where necessary in their entirety (including the annexures thereto).
The Parties agree that any references to annexures within this Section shall be deemed to be the same as the cognate and corresponding references within any appropriate, updated SCCs as may be applicable from time to time pursuant to the DPA.
For the purposes of the annexures to Annex II of the SCCs promulgated by the NDPDP in its Provision 60-E/2016 (“Argentine SCCs”) and any substantially similar SCCs which may be adopted by the relevant authorities in the future, the content of Annex A of the Argentine SCCs is set forth in Exhibits A and B.
In cases where the SCCs apply and there is a conflict between the terms of the DPA and the terms of the SCCs, the terms of the SCCs shall prevail with regard to the Restricted Transfer in question.
Termination. Subject to section 12.2 of the DPA, upon termination of the Agreement, Seesaw shall destroy all Customer Personal Data it has Processed on behalf of Customer after the end of the provision of Services relating to the Processing and destroy all copies of the Personal Data unless applicable law requires or permits storage of such Personal Data.
Australia. When applicable, the Processing of Customer Personal Data shall be compliant with the Australian Privacy Principles, the Australian Privacy Act (1988), and any other applicable law, regulation, or decree of Australia pertaining to the protection of such information.
Brazil.
Applicability. Wherever the Processing pursuant to this DPA falls within the scope of Brazil’s Lei Geral de Proteção de Dados, Law No. 13.709 of 14 August 2018 and any other applicable law, regulation, or decree of Brazil pertaining to the protection of such information (collectively “Brazilian Data Protection Laws”), the provisions of the DPA and this Section shall apply to such Processing.
Restricted Transfers. With regard to any Restricted Transfer subject to Brazilian Data Protection Laws, one of the following transfer mechanisms shall apply, in the following order of precedence:
A valid adequacy decision adopted by the Brazilian Data Protection Authority (“ANDP”) on the basis of Resolution 19/2024;
The Standard Contractual Clauses adopted by the ANDP in Annex II to the Resolution No. 19/2024 on August 23, 2024 (“Brazilian Standard Contractual Clauses”);
The recognition of foreign Standard Contractual Clauses that provide an equivalent level of protection as the Brazilian Standard Contractual Clauses by the ANDP; or
Any other lawful data transfer mechanism, as laid down in Brazilian Data Protection Laws, as the case may be.
Standard Contractual Clauses.
The DPA hereby incorporates by reference the Brazilian Standard Contractual Clauses. The Parties are deemed to have accepted, executed, and signed the Brazilian Standard Contractual Clauses where necessary in their entirety.
The Parties agree that any references to clauses, and choices within the Brazilian Standard Contractual Clauses shall be deemed to be the same as the cognate and corresponding references within any appropriate, updated Brazilian Standard Contractual Clauses as may be applicable from time to time pursuant to the DPA.
For the purposes of the Brazilian Standard Contractual Clauses and any substantially similar Standard Contractual Clauses which may be adopted by the relevant authorities in the future, the Parties agree to apply the following:
Clause 1: The content of Clause 1 is set forth in Exhibit A to the DPA.
Clause 2: The content of Clause 2 is set forth in Exhibit A to the DPA.
Clause 3: The Parties choose Option B. The process for onward transfer is outlined Section 6 of the DPA in conjunction with Exhibit A of the DPA.
Clause 4: The Parties choose Option A where Customer is the Controller and Seesaw is the processor; and Option A where Customer and Seesaw are Joint Controllers. The selections for Clauses 4.1 (a), (b) and (c) are as set out in Exhibits A and B to this DPA, respectively.
Section III: The measures requested under Section III are set forth in Section 8 of the DPA.
In cases where the Brazilian Standard Contractual Clauses apply and there is a conflict between the terms of the DPA and the terms of the Brazilian Standard Contractual Clauses, the terms of the Brazilian Standard Contractual Clauses shall prevail with regard to the Restricted Transfer in question.
Bulgaria.
Applicability. Wherever the Processing pursuant to the DPA falls within the scope of Bulgaria’s Personal Data Protection Act (as amended in November 2019), the Electronic Communications Act, and any other corresponding decrees, regulations, or guidance, the provisions of the DPA and this Section shall apply to such Processing.
General. Seesaw shall:
return to Customer any Personal Data Processed pursuant to the DPA within a period of one month after having become aware of any Personal Data that has been disclosed (i) without a legal basis pursuant Article 6 (1) of the EU GDPR, or (ii) contrary to the principles under Article 5 of the EU GDPR; or, if this is impossible or would involve disproportionate efforts, erase or destroy the Personal Data; and
if the Personal Data is erased or destroyed in accordance with Section 4.2(a) of these Jurisdiction Specific Terms, document such erasure and destruction.
Canada.
When applicable, the Processing of Customer Personal Data shall be compliant with the Canadian Federal Personal Information Protection and Electronic Documents Act and any other applicable law, regulation, or decree of Canada pertaining to the protection of such information.
Colombia.
Applicability. Wherever the Processing pursuant to the DPA falls within the scope of Colombia’s Data Protection Law No. 1581 of 2012 (“Data Protection Law No. 1581”), Data Protection Decree No. 1377 of 2013 (“Data Protection Decree”), and any corresponding decrees, regulations, or guidance (collectively “Colombian Data Protection Laws”), the provisions of the DPA and this Section shall apply to such Processing.
Definitions.
“Information Processing Policy” (“Política de Tratamiento de la información”) shall have the meaning set forth in Article 13 of the Data Protection Decree.
“Rights of the Data Subjects” (as used in the DPA) include such Data Subjects’ hábeas data rights, as that phrase is construed under the Constitution of Colombia and Colombian Data Protection Laws.
“Security Incident” (as used in the DPA) includes “violations of security codes” [that] “result in risks to the administration of Data Subjects’ information” (“violaciones a los códigos de seguridad y existan riesgos en la administración de la información de los Titulares”), as that phrase is construed under Articles 17(n) and 18(k) of the Data Protection Law No. 1581.
“Supervisory Authority” (as used in the DPA) includes Colombia’s Superintendency of Industry and Commerce (Superintendencia de Industria y Comercio).
General. As applicable, Seesaw shall comply with all requirements applicable to processors under the Columbian Data Protection Laws, including but not limited to obligations under Article 18 of Data Protection Law No. 1581 and Articles 11, 23, and 25 of the Data Protection Decree. Seesaw shall also comply with Customer’s Information Processing Policy, if any.
European Economic Area.
Definitions.
“EEA” means the European Economic Area, consisting of the EU Member States, and Iceland, Liechtenstein, and Norway.
“EEA Data Protection Laws” means the EU GDPR and all laws and regulations of the EU and the EEA countries applicable to the Processing of Customer Personal Data.
“EU 2021 SCCs” means the contractual clauses adopted by the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.
“EU GDPR” (as used in the DPA) means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, as may be amended from time to time.
Restricted Transfers.
With regard to any Restricted Transfer subject to EEA Data Protection Laws between the Parties, one of the following transfer mechanisms shall apply, in the following order of precedence:
a valid adequacy decision adopted by the European Commission on the basis of Article 45 of the EU GDPR;
the appropriate SCCs adopted by the European Commission from time to time; or
any other lawful data transfer mechanism, as laid down in EEA Data Protection Laws.
Standard Contractual Clauses.
The DPA hereby incorporates by reference the SCCs. The Parties are deemed to have accepted, executed, and signed the SCCs where necessary in their entirety (including the annexures thereto).
The Parties agree that any references to clauses, annexures, modules and choices within this Section shall be deemed to be the same as the cognate and corresponding references within any appropriate, updated SCCs as may be applicable from time to time pursuant to the DPA.
For the purposes of the EU 2021 SCCs and any substantially similar SCCs which may be adopted by the relevant authorities in the future:
the Parties agree to apply the following module[s]:
Module One with respect to Controller-to-Controller Restricted Transfers;
Module Two with respect to Controller-to-Processor Restricted Transfers;
Module Four with respect to Processor-to-Controller Restricted Transfers;
Clause 7: The Parties choose not to include the optional docking clause;
Clause 9(a): The Parties choose option 2, “General Written Authorization,” and the time period set forth in Section 6.6 of the DPA (The procedures for designation and notification of new Subprocessors are set forth in more detail in Section 6 of the DPA);
Clause 11: The Parties choose not to include the optional language relating to the use of an independent dispute resolution body;
Clause 13 (Annex I.C): The competent Supervisory Authority is the Irish Data Protection Commission;
Clause 17: The SCCs shall be governed by the laws of the Republic of Ireland;
Clause 18: Any dispute arising from the SCCs shall be resolved by the courts of the Republic of Ireland;
Annex I(A and B): The content of Annex I(A) and (B) is set forth in the DPA and Exhibit A;
Annex II: The content of Annex II is available at https://help.seesaw.me/hc/en-us/articles/203258429; and
Annex III: The content of Annex III is set out at https://trust.seesaw.me/subprocessors.
In cases where the SCCs apply and there is a conflict between the terms of the DPA and the terms of the SCCs, the terms of the SCCs shall prevail with regard to the Restricted Transfer in question.
Israel.
Applicability. Wherever the Processing pursuant to the DPA falls within the scope of Israel’s Protection of Privacy Law (5741-1981), the Protection of Privacy Regulations (Data Security) 5777-2017, and any corresponding decrees, regulations, or guidance, the provisions of the DPA and this Section shall apply to such Processing.
Deletion or Return of Personal Data. After returning or deleting Customer Personal Data pursuant to Section 12.2 of the DPA, Seesaw shall provide Customer with written confirmation that it no longer possesses any Customer Personal Data.
General. Seesaw shall notify Customer, at least once annually (and in a format to be agreed upon by the Parties), on the manner in which Seesaw has implemented its obligations in the DPA.
Singapore.
Applicability. Wherever the Processing pursuant to the DPA falls within the scope of Singapore’s Personal Data Protection Act 2012, Personal Data Protection (Amendment) Bill 2020, Personal Data Protection Regulations 2021, and any corresponding decrees, regulations, or guidance, the provisions of the DPA and this Section shall apply to such Processing.
Retention of Personal Data. Seesaw shall not retain Customer Personal Data (or any documents or records containing Customer Personal Data, electronic or otherwise) for any period of time longer than is necessary to serve the purposes of the Agreement.
Deletion or Return of Personal Data. After returning or deleting Customer Personal Data pursuant to Section 12 of the DPA, Seesaw shall provide Customer with written confirmation that it no longer possesses any Customer Personal Data.
Switzerland.
Definitions.
“EU 2021 SCCs” means the contractual clauses adopted by the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.
“FDPIC” means the Swiss Federal Data Protection and Information Commissioner.
“Swiss Data Protection Laws” includes the Federal Act on Data Protection of 19 June 1992 (“FADP”) and the Ordinance to the Federal Act on Data Protection.
Restricted Transfers.
With regard to any Restricted Transfer subject to Swiss Data Protection Laws between the Parties, one of the following transfer mechanisms shall apply, in the following order of precedence:
a valid adequacy decision adopted by the FDPIC on the basis of Article 6 of the FADP;
the appropriate SCCs adopted by the FDPIC from time to time; or
any other lawful transfer mechanism, as laid down in Swiss Data Protection Laws.
Standard Contractual Clauses.
The DPA hereby incorporates by reference the EU 2021 SCCs, which have been adopted for use by the FDPIC with certain modifications. The Parties are deemed to have accepted, executed, and signed the EU 2021 SCCs where necessary in their entirety (including the annexures thereto).
The Parties incorporate and adopt the EU 2021 SCCs for Restricted Transfers subject to Swiss Data Protection Laws in the same manner set forth in Section 7.3 of these Jurisdiction Specific Terms, subject to the following:
Clause 13 (Annex I.C): The competent authority shall be the FDPIC. Nothing about the Parties’ designation of the competent Supervisory Authority shall be interpreted to preclude Data Subjects in Switzerland from applying to the FDPIC for relief;
Clause 17: The SCCs shall be governed by the laws of Switzerland;
Clause 18: Any dispute arising from the SCCs shall be resolved by the courts of Switzerland. The Parties’ selection of forum may not be construed as forbidding Data Subjects habitually resident in Switzerland from suing for their rights in Switzerland;
references to “Regulation (EU) 2016/679” and specific articles therein shall be replaced with references to the FADP and the equivalent articles or sections therein, insofar as there are any Restricted Transfers subject to Swiss Data Protection Laws; and
the SCCs also protect the data of legal entities until the entry into force of the revised FADP.
In cases where the SCCs apply and there is a conflict between the terms of the DPA and the terms of the SCCs, the terms of the SCCs shall prevail with regard to the Restricted Transfer in question.
Turkey
When applicable, the Processing of Customer Personal Data shall be compliant with Turkey’s Personal Data Protection Law No. 6698 of 2016, and any corresponding decrees, regulations, or guidance.
United Arab Emirates: ADGM.
Definitions.
“ADGM Data Protection Laws” includes the Abu Dhabi Global Market (“ADGM”) Data Protection Regulations 2021 (“DPR 2021”), and any corresponding decrees, regulations, or guidance.
“ADGM SCCs” means the contractual clauses adopted by the Commissioner of Data Protection effective from 2021-08-14 relating to the transfer of Personal Data outside the ADGM pursuant to DPR 2021.
Personal Data Breach. In addition to those terms contained in Section 8 of the DPA, immediately upon providing notice of a Security Incident, Seesaw shall provide to Customer the name and contact details of the contact point where more information can be obtained.
Restricted Transfers.
With regard to any Restricted Transfer subject to ADGM Data Protection Laws between the Parties, one of the following transfer mechanisms shall apply, in the following order of precedence:
a valid adequacy decision adopted by the Commissioner of Data Protection on the basis of Article 41 of the DPR 2021;
the appropriate SCCs adopted by the Commissioner of Data Protection from time to time; or
any other lawful data transfer mechanism, as laid down in ADGM Data Protection Laws.
Standard Contractual Clauses.
The DPA hereby incorporates by reference the SCCs. The Parties are deemed to have accepted, executed, and signed the SCCs where necessary in their entirety (including the annexures thereto).
The Parties agree that any references to clauses, annexures, modules and choices within this Section shall be deemed to be the same as the cognate and corresponding references within any appropriate, updated SCCs as may be applicable from time to time pursuant to the DPA.
For the purposes of the ADGM SCCs and any substantially similar SCCs which may be adopted by the relevant authorities in the future:
the Parties agree to apply the following module[s]:
Module One with respect to Controller-to-Controller Restricted Transfers;
Module Two with respect to Controller-to-Processor Restricted Transfers;
Module Four with respect to Processor-to-Controller Restricted Transfers;
Clause 7: The Parties choose not to include the optional docking clause;
Clause 9(a): The Parties choose option 2, “General Written Authorization,” and the time period set forth in Section 6.3 of the DPA (The procedures for designation and notification of new Subprocessors are set forth in more detail in Section 6 of the DPA);
Clause 11: The Parties choose not to include the optional language relating to the use of an independent dispute resolution body;
Clause 17: The SCCs shall be governed by the laws of the ADGM;
Clause 18: Any dispute arising from the SCCs shall be resolved by the courts of the ADGM;
Annex I(A and B): The content of Annex I(A) and (B) is set forth in the DPA and Exhibit A;
Annex II: The content of Annex II is available at https://help.seesaw.me/hc/en-us/articles/203258429; and
Annex III: The content of Annex III is set out at https://trust.seesaw.me/subprocessors.
In cases where the SCCs apply and there is a conflict between the terms of the DPA and the terms of the SCCs, the terms of the SCCs shall prevail with regard to the Transfer in question.
General. Seesaw shall fully co-operate, on request, with the ADGM Office of Data Protection in the performance of Seesaw’s obligations under the ADGM Data Protection Laws.
United Arab Emirates: DIFC.
Definitions.
“Commissioner” means the DIFC Commissioner of Data Protection.
“DIFC Data Protection Laws” includes the Dubai International Financial Centre (“DIFC”) Data Protection Law No. 5 of 2020, as amended by DIFC Law No. 2 of 2022 (“DP Law 2020”), the DIFC Data Protection Regulations of 2020 (“Regulations”), and any corresponding decrees, regulations, or guidance.
“DIFC SCCs” means the contractual clauses adopted by the Commissioner in accordance with regulations relating to the transfer of Personal Data outside the DIFC pursuant to DP Law 2020.
Personal Data Breach. In addition to those terms contained in Section 6.8 of the DPA, immediately upon providing notice of a Security Incident, Seesaw shall provide to Customer the name and contact details of the contact point where more information can be obtained. Seesaw shall fully co-operate with any investigation of the Commissioner in relation to any Security Incident.
Audit Rights. In addition to those terms contained in Section 9 of the DPA, Seesaw shall make available to the Commissioner, upon request, all information necessary to demonstrate compliance with the obligations laid down in this Section 13 of these Jurisdiction Specific Terms and the DPA, and allow for and contribute to audits, including inspections, conducted by the Commissioner.
Restricted Transfers.
With regard to any Restricted Transfer subject to DIFC Data Protection Laws between the Parties, one of the following transfer mechanisms shall apply, in the following order of precedence:
a valid adequacy decision adopted by the Commissioner on the basis of Article 26 of the DP Law 2020;
the appropriate SCCs adopted by the Commissioner from time to time;
any other lawful data transfer mechanism, as laid down in DIFC Data Protection Laws.
Standard Contractual Clauses.
The DPA hereby incorporates by reference the SCCs. The Parties are deemed to have accepted, executed, and signed the SCCs where necessary in their entirety (including the appendices thereto).
The Parties agree that any references to clauses, appendices, and choices within this Section shall be deemed to be the same as the cognate and corresponding references within any appropriate, updated SCCs as may be applicable from time to time pursuant to the DPA.
For the purposes of the DIFC SCCs and any substantially similar SCCs which may be adopted by the relevant authorities in the future:
The SCCs shall be effective from the Effective Date. The term of the SCCs shall be three (3) years, at which time the DPA will be reviewed and updated as needed in order to comply with then-current DIFC Data Protection Laws.
Clause 7: The Parties choose not to include the optional docking clause;
Clause 9: The Parties choose option 2, “General Written Authorization,” and the time period set forth in Section 6.6 of the DPA (The procedures for designation and notification of new Subprocessors are set forth in more detail in Section 6 of the DPA);
Clause 16: The Parties choose to include the optional language relating to terminating the SCCs when circumstances change, including where they are no longer required by providing sixty (60) days written notice to the other Party;
Appendix 1: The content of Appendix 1 of the DIFC SCCs is set forth in the DPA and Exhibit A;
Appendix 2: The content of Appendix 2 of the DIFC SCCs is set forth at https://help.seesaw.me/hc/en-us/articles/203258429; and
Appendix 3: The content of Appendix 3 of the DIFC SCCs is set out at https://trust.seesaw.me/subprocessors.
In cases where the SCCs apply and there is a conflict between the terms of the DPA and the terms of the SCCs, the terms of the SCCs shall prevail with regard to the Restricted Transfer in question.
United Arab Emirates: Federal.
Definitions.
“Data Office” means the UAE Data Office established by virtue of Decree-Law No. 44 of 2021.
“UAE Federal Data Protection Laws” includes the United Arab Emirates (“UAE”) Personal Data Protection Law (Decree-Law No. 45 of 2021), Decree-Law No. 44 of 2021, and any corresponding decrees, regulations, or guidance.
Personal Data Breach. In addition to its obligations pursuant to Section 6.8 of the DPA, immediately upon providing notice of a Security Incident, Seesaw shall describe to Customer in as much detail as reasonably possible: (i) the form and causes of the Security Incident, (ii) the potential and expected impact and consequences of such Security Incident upon Customer and the affected Data Subjects, and (iii) the name and contact details of a contact point where more information can be obtained.
Restricted Transfers.
With regard to any Restricted Transfer subject to UAE Federal Data Protection Laws between the Parties, one of the following transfer mechanisms shall apply, in the following order of precedence:
a valid adequacy decision adopted by the Data Office on the basis of Article 22 of Decree-Law No. 45 of 2021;
the appropriate SCCs adopted by the Data Office from time to time; or
any other lawful data transfer mechanism, as laid down in UAE Federal Data Protection Laws.
Standard Contractual Clauses.
The DPA hereby incorporates by reference the SCCs. The Parties are deemed to have accepted, executed, and signed the SCCs where necessary in their entirety (including the appendices thereto).
The Parties agree that any references to clauses, appendices, and choices within this Section shall be deemed to be the same as the cognate and corresponding references within any appropriate SCCs as may be applicable from time to time pursuant to the DPA.
For the purposes of the SCCs and any substantially similar SCCs which may be adopted by the relevant authorities in the future:
The SCCs shall be effective from the Effective Date. The term of the SCCs shall be three (3) years, at which time the DPA will be reviewed and updated as needed in order to comply with then-current UAE Federal Data Protection Laws.
Clause 7: The Parties choose not to include the optional docking clause;
Clause 9(a): The Parties choose option 2, “General Written Authorization,” and the time period set forth in Section 6.6 of the DPA (The procedures for designation and notification of new Subprocessors are set forth in more detail in Section 6 of the DPA);
Clause 16: The Parties choose to include the optional language relating to terminating the SCCs when circumstances change, including where they are no longer required by providing sixty (60) days written notice to the other Party;
Appendix 1: The content of Appendix 1 of the DIFC SCCs is set forth in the DPA and Exhibit A;
Appendix 2: The content of Appendix 2 of the DIFC SCCs is set forth at https://help.seesaw.me/hc/en-us/articles/203258429; and
Appendix 3: The content of Appendix 3 of the DIFC SCCs is set out at https://trust.seesaw.me/subprocessors.
In cases where the SCCs apply and there is a conflict between the terms of the DPA and the terms of the SCCs, the terms of the SCCs shall prevail with regard to the Restricted Transfer in question.
General.
Seesaw shall notify Customer if the Processing exceeds the duration set forth in Exhibit A so that Customer may extend such duration or issue the appropriate directions.
Seesaw shall fully co-operate, on request, with the Data Office in the performance of its obligations under the UAE Federal Data Protection Laws.
United Kingdom.
Definitions.
“EU 2021 SCCs” means the contractual clauses adopted by the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.
“UK Data Protection Laws” includes the Data Protection Act 2018, the UK GDPR, and the Data Use and Access Act 2025.
“UK GDPR” (as used in the DPA) means the United Kingdom General Data Protection Regulation, as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018.
“UK ICO” means the UK Information Commissioner’s Office.
“UK Transfer Addendum” (as used in this Section) means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued pursuant to Section 119A(1) of the Data Protection Act 2018 and approved by the UK Parliament.
Restricted Transfers. With regard to any Restricted Transfer subject to UK Data Protection Laws between the Parties, one of the following transfer mechanisms shall apply, in the following order of precedence:
a valid adequacy decision adopted pursuant to Article 45 of the UK GDPR;
the EU 2021 SCCs and UK Transfer Addendum;
any other lawful data transfer mechanism, as laid down in the UK Data Protection Laws.
EU 2021 SCCs and UK Transfer Addendum.
The DPA hereby incorporates by reference the EU 2021 SCCs, which have been adopted for use by the UK ICO with certain modifications and the addition of the UK Transfer Addendum. The Parties are deemed to have accepted, executed, and signed the EU 2021 SCCs where necessary in their entirety (including the annexures thereto).
For the purposes of the tables to the UK Transfer Addendum:
Table 1: The content of Table 1 is set forth in the DPA and Exhibit A;
Table 2: The content of Table 2 is incorporated and adopted as to Restricted Transfers subject to UK Data Protection Laws in exactly the same manner set forth in Section 7.3 of these Jurisdiction Specific Terms. To the extent Module 4 is applicable, the Parties confirm that Personal Data received from the Data Importer is combined with personal data collected by the Data Exporter;
Table 3: The content of Table 3 (Annexes 1A, 1B, II, and III) is set forth in Exhibit A, at https://help.seesaw.me/hc/en-us/articles/203258429 and at https://trust.seesaw.me/subprocessors.
Table 4: The Parties agree that neither Party may terminate the UK Transfer Addendum.
Subject to Section 15 of the UK Transfer Addendum, the Parties incorporate and adopt the EU 2021 SCCs as to Restricted Transfers subject to UK Data Protection Laws in exactly the same manner set forth in Section 7.3 of these Jurisdiction Specific Terms.
Section 16 of the UK Transfer Addendum does not apply.
In cases where the EU 2021 SCCs, in conjunction with the UK Transfer Addendum, apply and there is a conflict between the terms of the DPA and the terms of the EU 2021 SCCs or UK Transfer Addendum, the terms of the UK Transfer Addendum shall prevail with regard to the Restricted Transfer in question.
United States of America.
Applicability. Wherever the Processing pursuant to the DPA falls within the scope of United States Data Protection Laws (defined below), the provisions of the DPA and this Section shall apply to such Processing.
Definitions.
“United States Data Protection Laws” include, individually and collectively, enacted and already in-effect state and federal laws, acts, and regulations of the United States of America that apply to the Processing of Personal Data, as may be amended from time to time. Such laws include, without limitation:
the California Consumer Privacy Act of 2018, as amended, including as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Code § 1798.100 et seq.)., and the California Consumer Privacy Act Regulations, together with all implementing regulations; and
similar state privacy laws, including, without limitation, the Colorado Privacy Act, the Connecticut Act Concerning Personal Data Privacy and Online Monitoring, the Delaware Personal Data Privacy Act, the Iowa Consumer Data Protection Act, the Maryland Online Data Privacy Act, the Minnesota Consumer Data Privacy Act, the Montana Consumer Data Privacy Act, the Nebraska Data Privacy Act, the New Hampshire Privacy Act, the New Jersey Senate Bill 332, the Oregon Consumer Privacy Act, the Tennessee Information Protection Act, the Texas Data Privacy and Security Act, the Utah Consumer Privacy Act, and the Virginia Consumer Data Protection Act.
“Security Incident” (as used in the DPA) includes “Breach of Security” and “Breach of the Security of the System” as defined under applicable United States Data Protection Laws.
The terms “Business Purpose”, “Commercial Purpose”, “Sell”, and “Share” shall have the same meanings as under applicable United States Data Protection Laws, and their cognate and corresponding terms shall be construed accordingly.
Processing of Customer Personal Data.
Customer discloses Customer Personal Data to Seesaw solely for: (i) valid Business Purposes; and (ii) to enable Seesaw to perform the Services.
Seesaw shall not: (i) Sell or Share Customer Personal Data; (ii) retain, use or disclose Customer Personal Data for a Commercial Purpose other than providing the Services specified in the Agreement or as otherwise permitted by United States Data Protection Laws; (iii) retain, use, or disclose Customer Personal Data except where permitted under the Agreement between Customer and Seesaw; nor (iv) combine Customer Personal Data with other information that Seesaw Processes on behalf of other persons or that Seesaw collects directly from the Data Subject, with the exception of Processing for Business Purposes. Seesaw certifies that it understands these prohibitions and agrees to comply with them.
Termination. Upon termination of the Agreement, subject to section 12.2 of the DPA, Seesaw shall, as soon as reasonably practicable, destroy all Customer Personal Data it has Processed on behalf of Customer after the end of the provision of Services relating to the Processing and destroy all copies of such Customer Personal Data unless applicable law requires or permits storage of such Personal Data.
Version History
| Last Update: | Description: |
|---|---|
| 4 August, 2026 |
|