This Data Processing Addendum (“DPA”) is made and entered by and between Customer, whose name and address are set forth in the Agreement, and the Impel Affiliate whose name is set forth in the Agreement (“Impel”) (collectively, the “Parties”). The DPA governs the processing of Personal Data when Customer uses Impel’s products and services and when Data Protection Laws apply.

1. Definitions. 
Defined terms used but not defined herein shall have the same meaning as the Agreement. Where the DPA uses other terms not defined in the DPA, those terms shall have the same meaning as in GDPR. The use of terms set forth in GDPR does not mean that a Party has agreed to comply with GDPR unless the GDPR is applicable to it.
The DPA shall be read and interpreted in the light of the provisions of the Data Protection Laws and shall not be interpreted in a way that runs counter to the rights and obligations provided for in the Data Protection Laws or in a way that prejudices the fundamental rights or freedoms of the data subjects, consumers, and analogous entities under Data Protection Laws (“Data Subjects”).
Affiliate” of a party means any entity that is controlled by a party to this Agreement, so long as the control exists.
Control” means direct or indirect control of more than 50% of the shares or other equity interests of the subject entity entitled to vote in the election of directors (or, in the case of an entity that is not a corporation, for the election or appointment of the corresponding managing authority). As to Customer, any reference to “Affiliate” herein is strictly limited to those Affiliates of Customer that qualify as a data controller with respect to the Personal Data and are permitted to use the Services pursuant to the Agreement but have not signed their own order form and are not a “Customer” as defined under the Agreement.
Agreement” means the agreement for the provision of the Services.
Controller” means the entity that determines the purposes and means of the processing of Personal Data, which for the purposes of this DPA is the Customer.
Data Protection Laws” means the data protection laws applicable to the Personal Data in scope of this DPA including, but not limited to: Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5) (“PIPEDA”), and any applicable provincial privacy legislation in Canada (“PIPEDA”), Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”), the Federal Data Protection Act of 19 June 1992 (Switzerland) and the revised Swiss Federal Data Protection Act effective September 1, 2023 (“Swiss FADP”), the United Kingdom (UK) Data Protection Act 2018 and the UK GDPR from December 31 st 2020 ( “UK Privacy Laws”), the Australian Privacy Act 1988, New Zealand Privacy Act 2020, the California Consumer Privacy Act as amended by the California Privacy Rights Act, the Colorado Privacy Act, the Virginia Consumer Data Protection Act, the Connecticut Act Concerning Personal Data Privacy and Online Monitoring, the Utah Consumer Privacy Act, the Iowa Data Privacy Act, the Indiana Consumer Data Protection Act, the Montana Consumer Data Privacy Act, the Tennessee Information Protection Act, and the Texas Data Privacy and Security Act and any subsequent privacy laws enacted in the United States requiring data processing agreements (“US Privacy Laws”).
Personal Data” means all data relating to individuals which is processed by Impel on behalf of the Customer under this DPA. “Processor” means an entity that Processes Personal Data on behalf of the Controller, which for the purposes of this DPA is the Impel Affiliate identified in the Agreement.

2. Scope and hierarchy. Each Party has agreed to the DPA in order to ensure that it is in compliance with the Data Protection Laws applicable to it. The DPA applies to the processing of Personal Data as specified in Annex II only.  Annexes I to IV are an integral part of the DPA. The DPA is without prejudice to obligations to which Customer is subject by virtue of the Data Protection Laws. In the event of a contradiction between the DPA and the provisions of related agreements between the Parties existing at the time when the DPA is agreed or entered into thereafter, the DPA shall prevail.

3. Description of processing. The details of the processing operations, in particular the categories of Personal Data and the purposes of processing for which the Personal Data is processed on behalf of Customer, are specified in Annex II.

4. Impel’s Obligations

  1. Instructions. Impel shall process Personal Data only on documented instructions from Customer and for the specific purpose(s) and duration of processing, as set out in Annex II, unless it is required to do so by Data Protection Laws. In this case, Impel shall inform Customer of such legal requirement before processing, unless prohibited by law. Subsequent instructions may also be given by Customer in writing throughout the duration of the processing of Personal Data. Impel shall inform Customer if, in Impel’s opinion, instructions given by Customer infringe the Data Protection Laws.
  2. Security of processing. Impel shall implement technical and organizational measures to ensure the security and protection of the Personal Data, including protecting the Personal Data against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to Personal Data (“Data Breach”). In assessing the appropriate level of security, the Parties shall take due account of the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks involved for the Data Subjects. The measures implemented by Impel at the time of entering into this DPA are specified in Annex III.
  3. Confidentiality and access to Personal Data. Impel shall only grant access to the Personal Data to members of its personnel to the extent strictly necessary for the purpose specified in Annex II. Impel shall ensure that persons authorized to process the Personal Data received have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  4. Documentation and compliance. The Parties shall be able to demonstrate compliance with the DPA. Impel shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations of this DPA
  5. Audit. At Customer’s request and subject to 30 days written notice, Impel shall also permit and contribute to audits of the processing activities covered by the DPA maximum once every calendar year, or more frequently if there has been a Data Breach involving the Personal Data.  Customer may choose to conduct the audit by itself or mandate an independent auditor, who is subject to confidentiality obligations. Audits may include inspections at the premises or physical facilities of Impel. Customer acknowledges that Impel’s obligations may be satisfied in whole or part by the provision to Customer of appropriate information; records; and certifications and audit reports issued by reputable independent third parties provided that there have been no material changes to the controls used by Impel since the certification or audit report was issued. Impel reserves the right to conduct independent audits of its processing activities and systems. The Parties shall make the information referred to in this DPA, including the results of any audits, available to the competent regulators and supervisory authority/ies on request.

5. Use of sub-processors/service providers

  1. Impel is authorized to engage (and to permit each sub-processor/service provider engaged in accordance with this DPA and set out in the list in the link in Appendix IV to engage) sub-processors/service providers (“Sub-processor”) in accordance with this DPA. If a new Sub-processor is engaged or an existing Sub-processor removed, the list in the link in Appendix IV shall be updated. In order to receive alerts regarding such list updates, an email should be sent to support@impel.ai with “Subscribe to sub-processor updates” as the subject.
  2. If the Customer objects to the engagement or removal of a Sub-processor with reasonable grounds based on Data Protection Laws, the objection must be expressed within thirty (30) days of receipt of such an alert email in writing. Should Impel not be able to adjust its services and continue the provision of the services without the appointed Sub-processor, Customer may close its account. Termination is Customer’s sole and exclusive remedy if Customer objects to the appointment of any new or the removal of any existing Sub-processor, and any previously accrued rights and obligations will survive such termination. If objection is not made within such time-period, then the addition of the new or the removal of the existing Sub-processor shall be deemed accepted.
  3. Where Impel engages a Sub-processor it shall impose on the Sub-processor, in substance, the same data protection obligations as the ones imposed on Impel in this DPA.
  4. Impel shall remain fully responsible to Customer for the performance of the Sub-processor’s obligations in accordance with the Agreement.

6. International transfers. 

  1. During the provision of the Services under the Agreement, Impel may transfer Personal Data to a third country or an international organization. Impel shall comply with Data Protection Laws and the transfer mechanisms allowed by the Data Protection Laws in all such transfers.To the extent Personal Data includes Personal Data from the EU and EEA by entering into the Agreement and this DPA, the Parties are deemed to have signed the EU Standard Contractual Clauses from June 4, 2021 (“SCCs”), including their annexes, attached hereto.
  2. To the extent the SCCs are entered into, the following options for Module 2 of the SCCs shall be used:
    • Clause 7. The optional docking does not apply.
    • Clause 9. Use of sub-processors Option 2: General written authorization is selected and the minimum time period for prior notice of sub-processor changes and the notification method have been agreed in section 6.5 of the DPA
    • Clause 11. The optional language does not apply.
    • Clause 17. Option 2 is selected and the Parties agree that this shall be Irish law.
    • Clause 18 (b). The Parties agree that any dispute arising from these Clauses shall be resolved by the courts of Ireland.
    • Clause 13. All square brackets in are hereby removed;
    • Annex I to this DPA contains the information required in Annex I of the SCCs;
    • Annex II to this DPA contains the information required in Annex II of the SCCs; and
    • Annex III to this DPA contains the information required in Annex III of the SCCs.
  3. To the extent Personal Data includes personal data from the UK for the purposes of localizing the SCCs to United Kingdom law, the parties agree that the SCCs are deemed amended to the extent necessary that they operate for transfers from the United Kingdom to a third country and provide appropriate safeguards for transfers according to Article 46 of the UK GDPR. Such amendments include changing references to the GDPR to the UK GDPR and changing references to EU Member States to the United Kingdom. The parties agree that the UK Addendum will apply to transfers of UK Personal Data protected by the UK GDPR and will be completed as follows:
    • Table 1 will be completed with the relevant information in Annex I of this DPA;
    • Table 2 will be completed with the selected modules and clauses of the EU SCCs as identified in Section 6.2 of this DPA;
    • Table 3 will be completed with the relevant information from Annexes I, II and III of this DPA;
    • In Table 4, both the data exporter and data importer may end the UK Addendum in accordance with the terms of the UK Addendum.
  4. To the extent Personal Data includes personal data from Switzerland for the purposes of localizing the SCCs to Swiss law the following applies:
    • The parties adopt the GDPR standard for all data transfers, or the standard under Swiss law where higher.
    • The parties agree that the references to provisions of the GDPR in the SCCs are to be understood as references to the corresponding provisions of the Swiss Federal Data Protection Act in the version applicable at the moment of initiation of any dispute.
    • The term Member State where used in the SCCs also applies to Switzerland. In particular, this shall ensure that data subjects are not excluded from the possibility to sue for their rights in their place of habitual residence.
    • Clause 13 and Annex I(C): The competent authorities under Clause 13, and in Annex I(C), are the Federal Data Protection and Information Commissioner and, concurrently, the EEA member state authority identified above.
    • Clause 17: The Parties agree that the governing jurisdiction is the Member State in which the data exporter is established for claims under the GDPR and the substantive laws of Switzerland for claims under the Swiss Federal Data Protection Act.
    • Clause 18: Any dispute arising from these Clauses shall be resolved by the courts of Zurich, Switzerland. A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of the Member State in which he/she has his/her habitual residence. The Parties agree to submit themselves to the jurisdiction of such courts.

7. US Privacy Laws. To the extent Impel’s processing of Personal Data under the Agreement is subject to US Privacy Laws:

  1. The Parties acknowledge that Impel’s retention, use and disclosure of Personal Data authorized by the Customer’s instructions stated in this Agreement are integral to the Services and the business relationship between the Parties.
  2. Impel shall:
    • Use, retain, and disclose Personal Data only as necessary to perform the business purposes specified in this Agreement or as otherwise permitted by US Privacy Laws;
    • Comply with applicable obligations under US Privacy Laws and shall provide the same level of privacy protection as is required of a “service provider” or “contractor” under each applicable US Privacy Law;
    • Implement reasonable and appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing, access, use, or disclosure;
    • Cooperate with the Customer to stop and remediate any unauthorized use of Personal Data.
  3. Impel shall not:
    • Sell or share any Personal Data
    • Retain, use or disclose any Personal Data for any purpose other than for the business purposes specified in the Agreement, including retaining, using, or disclosing the Personal Data for a commercial purpose other than the business purposes specified in the Agreement or as otherwise permitted by US Privacy Laws
    • Combine the Personal Data received from the Customer with Personal Data received from or on behalf another person, or Personal Data Impel collects from its own interaction with the consumer, except as otherwise permitted by US Privacy Laws
    • De-identify or aggregate Personal Data unless the de-identification meets US Privacy Laws, and the output cannot be re-identified.

8. Customer Representations and Warranties. Customer hereby represents and warrants that it: (a) will comply with all Data Protection Laws; (b) will ensure that its instructions to Impel for processing Personal Data comply with Data Protection Laws; (c) will maintain appropriate disclosures and privacy policies, notice and consent mechanisms, and methods for handling Data Subject requests pursuant to Data Protection Laws, ; (d) has all consents, authorizations, and rights required to transfer or disclose, and permit Impel to process, any and all Personal Data in connection with the Agreement; and (e) has and will have sole responsibility for the accuracy, quality, and legality of any and all Personal Data processed by Impel. For the avoidance of doubt, to the extent Customer requests that Impel transfer Personal Data to any third parties on Customer’s behalf, Customer is solely responsible for ensuring that Customer has all necessary consents and rights to transfers such Personal Data. Customer will promptly notify Impel if it is unable to comply with any of its obligations under this DPA or any Data Protection Laws.

9. Assistance to the Customer

  1. Impel shall promptly, and at latest within ten (10) business days, notify Customer of any request it has received from a Data Subject. It shall not respond to the request itself, unless authorized to do so by Customer.
  2. Impel shall reasonably assist Customer in fulfilling its obligations to respond to Data Subjects’ requests to exercise their rights, taking into account the nature of the processing.
    • Impel shall furthermore, taking into account the nature of the data processing and the information available to Impel, assist Customer in ensuring compliance with the Customer’s legal obligations, including without limitation, to carry out data protection impact assessments where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons and  consulting the competent supervisory authority/ies.

10. Notification of Data Breach.

  1. In the event of a Data Breach, Impel shall notify Customer without undue delay after Impel has become aware of the Data Breach. Such notification shall contain, at least a) a description of the nature of the breach (including, where possible, the categories and approximate number of Data Subjects and data records concerned); b) the details of a contact point where more information concerning the Data Breach can be obtained and; c) the likely consequences and the measures taken or proposed to be taken to address the breach, including to mitigate its possible adverse effects.
  2.  Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.

11. Non-compliance, termination and expiration.

  1. Customer has the right to stop and remediate the unauthorized use of the Personal Data by Impel.
  2. Without prejudice to any provisions of the Data Protection Laws applicable to the Impel, in the event that Impel is in breach of its obligations under the DPA, Customer may instruct Impel to suspend the processing of Personal Data until the latter complies with the DPA or the DPA is terminated. Impel shall promptly inform Customer in case it is unable to comply with the DPA, for whatever reason.
  3. Customer shall be entitled to terminate the DPA insofar as it concerns processing of Personal Data in accordance with the Agreement if:
    • the processing of Personal Data by Impel has been suspended by Customer pursuant to point 11.2 and if compliance with the Agreement is not restored within a reasonable time and in any event within one month following suspension; or
    • Impel fails to comply with a binding decision of a competent court or the competent supervisory authority/ies regarding its obligations pursuant to the Agreement or to the Data Protection Laws applicable to it.
  4. Impel shall be entitled to terminate the Agreement insofar as it concerns processing of Personal Data under the Agreement where, after having informed Customer that its instructions infringe applicable legal requirements, Customer insists on compliance with the instructions
  5. Following termination or expiration of the DPA, Impel shall, at the choice of Customer, delete all Personal Data processed on behalf of Customer or, return all the Personal Data to Customer and delete existing copies unless Data Protection Laws applicable to it require storage of the Personal Data. Until the data is deleted or returned, Impel shall continue to ensure compliance with the DPA. In absence of the Customer’s instructions the Personal Data will be deleted according to Annex II.

12. Government and Regulatory Requests. In the event that Impel receives a legally binding request from any government, regulatory, or law enforcement authority for the disclosure of Personal Data processed under this DPA (“Government Request“), Impel shall: (a) to the extent permitted by applicable law, promptly notify Customer in writing of the Government Request prior to disclosing any Personal Data, and in any event as soon as reasonably practicable; (b) disclose only the minimum amount of Personal Data strictly required to comply with the Government Request; and (d) maintain a record of all Government Requests received. Where Impel is prohibited by applicable law from notifying Customer of a Government Request, Impel shall: (i) use commercially reasonable efforts to have such prohibition lifted or to obtain the right to notify Customer; and (ii) notify Customer as soon as it is legally permitted to do so. Nothing in this section 12 shall require Impel to act in contravention of applicable law or to incur any costs or liability in challenging a Government Requestunless Customer has agreed in writing to reimburse such costs in advance.

13. Changes to the DPA. Any changes to the DPA shall be made in writing and signed by both Parties. Impel reserves the right to update the DPA if required by Data Protection Laws or in order to comply with its obligations related to transfers of Personal Data to third countries such as the EU Standard Contractual Clauses.

14. Limitation of Liability. Each party’s and all of its Affiliates’ liability, taken together in the aggregate, arising out of or related to this DPA, whether in contract, tort or under any other theory of liability, is subject to the limitations and exclusions of liability in the Agreement, and any reference in provisions to the liability of a party means the aggregate liability of that party and all of its Affiliates under the Agreement and the DPA together. For the avoidance of doubt, Impel, its Affiliates, and its Sub-processor’s total liability for all claims from Customer and all of its Controller Affiliates arising out of or related to the Agreement and the DPA shall apply in the aggregate for all claims under both the Agreement and the DPA.

15. Governing Law, Choice of Forum, and Jurisdiction. The Agreement shall be governed by and construed in accordance with the laws of the Agreement.

CUSTOMER   AUGMENTED REALITY CONCEPTS LLC, D/B/A IMPEL
By: By:
Title:Name:
Date:Title:
Date:

ANNEX I: List of parties

Controller(s): Customer

Processor(s): Augmented Reality Concepts, LLC (d/b/a Impel)

ANNEX II: Description of the processing

Categories of Data Subjects whose personal data in processed

  • Consumers who visit the websites of Impel customers
  • Consumers who submit inquiries to Impel customers
  • Business contacts at customers and prospective customers of Impel

Categories of personal data processed

  • IP address, unique identifier, browsing history
  • For users of Impel’s products: name, email address, phone number, any personal data that a consumer or an Impel customer may disclose via web form, web chat, voice mail, email, video or text message
  • For customers and prospective customers of Impel: business contact details

Sensitive data processed (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.

  • None

Nature of the processing

  • Collection, transfer, entry, storage, analysis, matching, sharing, retrieval, combination

Purpose(s) for which the personal data is processed on behalf of the controller/business

  • Provision of digital marketing services to Impel customers

Duration of the processing

  • The default retention period is 3 years, but there are exceptions for some data sources.

For processing by (sub-)processors/service providers, also specify subject matter, nature and duration of the processing

  • The same as described above in this Annex II.

ANNEX III: Technical and organizational measures including technical and organizational measures to ensure the security of the data

Description of the technical and organizational security measures implemented by the processor(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context, and purpose of the processing, as well as the risks for the rights and freedoms of natural persons.

Impel has attained SOC 2 Type I certification.

Impel’s engineering team is trained on and follows secure software development life cycle practices.

Code developed by one engineer is reviewed by another before deployment.

Code undergoes testing before deployment.

Automated monitoring detects unexpected conditions that could indicate denial of service or similar attacks.

Customer-facing applications are hosted in major cloud providers’ secure data centers.

Impel conducts periodic network scans and remediates vulnerabilities.

Impel undergoes application penetration tests and remediates vulnerabilities.

Impel defines policies to secure office networks, computers and mobile devices.

New hires undergo background checks.

Employees receive initial and ongoing information security training.

Impel encrypts personal data at rest and in transit.

For transfers to (sub-)processors/service providers, also describe the specific technical and organizational measures to be taken by the (sub-)processor to be able to provide assistance to the controller

Impel maintains a vendor management policy with criteria for identifying key vendors, including those who process personal data.

Impel maintains a list of key vendors and performs vendor risk management.

Sub-processors must adhere to SCCs, DPAs or similar agreements that require technical and organizational measures at least as effective as Impel’s own.

Description of the specific technical and organizational measures to be taken by the processor/service provider to be able to provide assistance to the controller/business.

Policies and procedures are in place which require Impel to provide assistance to Customer as required by the Agreement and the Data Protection Laws.

ANNEX IV: List of sub-processors

The name, address, contact person’s name, position and contact details, and description of the processing (including a clear delimitation of responsibilities) for each sub-processor can be found at https://trust.impel.ai/subprocessors