Duku Data Processing Addendum
This Data Processing Addendum (this “Addendum”) is incorporated into and forms part of the Duku Terms and Conditions (“Agreement”) between Customer and Duku, and applies to the extent Duku Processes Personal Data on behalf of the Customer as a Processor in connection with the Services. Except as expressly modified by this Addendum, the terms of the Agreement remain in full force and effect. In the event of any conflict or inconsistency between the Agreement and this Addendum, the terms of this Addendum will prevail to the extent of the conflict or inconsistency. For clarity, this Addendum takes effect from the effective date of the Agreement and continues until the later of the termination of the Agreement or the completion of Duku’s Processing of Customer Personal Data under the Agreement.
Definitions
In this Addendum, the following words and expressions have the following meanings:
“Customer Personal Data” means Personal Data Processed by Duku as Processor on behalf of Customer pursuant to the provision of the Services and as further described in Section 2.2;
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” (including related terms such as “Process”, “Processes” and “Processed”) and “Supervisory Authority” all have the meanings given to those terms and equivalent concepts under Data Protection Laws;
“Data Protection Laws” means all applicable laws and regulations relating to data protection and privacy as applicable to the parties and/or to the Processing of Personal Data under the Agreement, including without limitation, United States data protection and privacy laws, the EU General Data Protection Regulation 2016/679 (“EU GDPR”); the EU GDPR in such form as incorporated into the laws of the United Kingdom (“UK GDPR”, and together with the EU GDPR “GDPR”); the UK Data Protection Act 2018; and any associated implementing legislation and regulations, in each case, as in force and applicable, and as amended, supplemented or replaced from time to time;
“Party” means each of Duku and Customer, and “Parties” shall mean Duku and the Customer collectively;
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to Customer Personal Data;
“Services” means the services provided by Duku pursuant to the Agreement; and
“Sub-Processor” means any vendor, supplier or subcontractor of Duku authorised to Process Customer Personal Data on behalf of Duku.
Data Processing Details and Compliance
-
The Parties acknowledge that in respect of Customer Personal Data, Duku is a Processor Processing Personal Data on behalf of Customer. Each Party shall comply with its obligations under Data Protection Laws as relates to Customer Personal Data.
-
Details of Customer Personal Data Processed by Duku under the Agreement are as follows:
-
Subject Matter, Nature and Purpose of Processing. Duku’s Processing of Customer Personal Data in providing the Services under the Agreement.
-
Duration of Processing. Processing of Customer Personal Data by Duku shall be for the term of the Agreement and in accordance with Duku’s retention obligations under the Agreement and this Addendum.
-
Personal Data in Scope. Personal Data made available to Duku by or on behalf of Customer in connection with the Services, the nature and extent of which is determined and controlled by Customer. This comprises:
-
test account data supplied by Customer for use in the application environments under test, such as usernames, email addresses and associated login credentials;
-
Personal Data displayed by, or transmitted through, the application environments Customer connects to the Services during automated exploration and testing, as captured in the test artefacts generated by the Services (including screenshots, session video recordings, DOM snapshots, network and console logs, and error and diagnostic records); and
-
any Personal Data contained in configuration inputs, application descriptions and other content Customer submits through its use of the Services.
-
The Services are designed to operate against test environments. Whether the environments and test data Customer connects to the Services contain Personal Data, and the categories of any such Personal Data, are determined solely by Customer.
-
-
Category of Data Subjects. Individuals whose Personal Data is made available to Duku by or on behalf of Customer in connection with the Services, which may include:
-
Customer's personnel and other users authorised by Customer to access the Services;
-
holders of test accounts supplied by Customer; and
-
individuals whose Personal Data appears in the application environments Customer connects to the Services which, depending on the environments and data Customer elects to use, may include Customer's end users, customers, employees, contractors, suppliers and other individuals with whom Customer interacts in the course of its operations.
-
-
-
Duku shall be an independent Controller with respect to its Processing of Personal Data in connection with the execution and administration of the Agreement (including contact details of Customer personnel/representatives); Duku’s creation and maintenance of User accounts on Duku platforms; and the processing of Personal Data and platform usage data for analytics and improvement of Duku products and services. The Parties agree that the Personal Data described under this Section 2.3 does not form part of Customer Personal Data.
Processing of Customer Personal Data
-
Customer represents and warrants that, in connection with its use of the Services, transfer of Customer Personal Data to Duku and provision of instructions to Duku as Processor of Customer Personal Data: (a) Customer has provided or will provide all necessary notices to all Data Subjects of Customer Personal Data as required under Data Protection Laws; (b) Customer has received all necessary permissions, consents, or approvals and otherwise secured a valid legal basis of Processing to facilitate Duku’s Processing of Customer Personal Data in accordance with the terms of the Agreement and Data Protection Laws; (c) Duku’s Processing of Customer Personal Data in accordance with Customer’s instructions will not cause Duku to violate any applicable law; and (d) Customer shall have responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired such data.
-
Duku shall Process Customer Personal Data in accordance with Customer’s prior written instructions agreed between the Parties (including as set out in the Agreement) unless Duku is required to otherwise Process Customer Personal Data by applicable laws. Duku is hereby instructed to Process Customer Personal Data for the purposes of providing the Services. Where Duku is required by applicable laws to Process Customer Personal Data other than in accordance with Customer’s instructions, prior to any such Processing and to the extent permitted by applicable laws, Duku shall notify Customer in writing of that legal requirement prior to Processing Customer Personal Data.
-
Duku shall promptly inform Customer if, in its reasonable opinion, an instruction from Customer under this Addendum infringes Data Protection Laws. Duku shall be entitled to suspend the relevant Processing of Customer Personal Data (other than storing and securing the affected data) until Customer has confirmed or modified the instruction to ensure compliance with Data Protection Laws.
Duku Personnel and Sub-Processors
-
Duku shall ensure that all Duku personnel authorised to Process Customer Personal Data are either subject to binding written contractual obligations or statutory obligations to keep Customer Personal Data confidential.
-
Customer authorises Duku to engage the Sub-Processors included in the Sub-Processor list set out in https://duku.ai/legal/subprocessors (“Sub-Processor List”). Where Duku intends to engage any additional Sub-Processor not already approved on the Sub-Processor List, prior to engaging the Sub-Processor, Duku shall notify Customer of the proposed engagement of the Sub-Processor giving Customer the opportunity to object. Customer shall be entitled to make a written objection to the proposed engagement (with respect to confidentiality and data protection compliance concerns) within twenty (20) days of Duku providing notice to Customer under this Section. If no objection is received within the timeframe under this Section, Customer is deemed to have authorised the engagement of such Sub-Processor.
-
Where Customer raises a reasonable objection to the use of a proposed Sub-Processor in accordance with this Section, Duku may at its option: (i) use reasonable endeavours to remedy the situation giving rise to the reasonable objection; or (ii) propose an alternative Sub-Processor to conduct the relevant Processing. If Duku is unable to remedy the situation or propose an alternative Sub-Processor within twenty (20) days from receipt of Customer’s objection (or such other period as the Parties may agree in writing), either Party may terminate the Agreement or the applicable Services schedule or order form without penalty by providing written notice to the other Party, but only to the extent the affected Services cannot be provided without the objected-to Sub-Processor. Termination shall not relieve Customer of its payment obligation under the Agreement.
-
Duku shall ensure that prior to permitting any Sub-Processor to Process Customer Personal Data, the Sub-Processor has entered into a binding written agreement with Duku that imposes obligations substantially equivalent to the obligations imposed on Duku as a Processor under this Addendum. Duku shall remain fully liable to Customer for the performance of the Sub-Processor’s data protection obligations concerning Customer Personal Data in the event the Sub-Processor fails to fulfil those obligations.
International Transfers
-
Duku shall not transfer Customer Personal Data to any party in a country not deemed adequate for the international transfer of Customer Personal Data under Data Protection Laws unless the transfer is performed in accordance with the requirements of the Data Protection Laws (including having in place appropriate transfer safeguards as applicable).
Security and Personal Data Breach Notification
-
Duku shall implement and maintain appropriate technical and organisational measures in relation to the Processing of Customer Personal Data to ensure a level of security appropriate to the risks which may occur as a result of Processing Customer Personal Data, and in particular the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.
-
Duku shall notify Customer without undue delay on becoming aware of a Personal Data Breach and provide Customer with details of the Personal Data Breach as required under Data Protection Laws.
Assistance
-
At Customer’s written request (taking into account the nature of Processing and the information available to Duku), Duku shall provide Customer with reasonable assistance, at Customer’s cost:
-
using appropriate technical and organisational measures, in complying with any requests received from Data Subjects of Customer Personal Data exercising Data Subject rights under Data Protection Laws;
-
to enable Customer to conduct data protection impact assessments and consultations with a Supervisory Authority, where Customer is required to do so under Data Protection Laws, to the extent Customer does not otherwise have access to the relevant information;
-
to assist Customer in complying with its obligation to implement and maintain appropriate technical and organisational security measures to protect Customer Personal Data in line with Section 6; and
-
to assist Customer in complying with its obligation to notify a Personal Data Breach to competent authorities and/or affected Data Subjects, where Customer is required to do so under Data Protection Laws.
-
Deletion or Return of Data
-
Duku will delete (or, at the election of Customer, return before such deletion, in a format reasonably determined by Duku, provided that any expenses associated with such transfer are agreed between the Parties in advance) all Customer Personal Data in the possession or control of Duku, within thirty (30) business days after the termination of the Agreement, unless retention is permitted or required under applicable law, or as otherwise agreed in writing with Customer.
Information Requests and Audits
-
Duku shall, on reasonable request from Customer, make available to Customer all information necessary to demonstrate Duku’s compliance with its obligations under this Addendum. Duku shall allow for audits (including inspections), at Customer’s cost, conducted by a designated independent auditor agreed between the Parties, for the purpose of demonstrating Duku’s compliance with its obligations under this Addendum. For the avoidance of doubt such audits shall be limited to once per calendar year except as required by a Supervisory Authority and the scope of any audit will be limited to Duku’s policies, procedures, systems and controls relevant to the Processing of Customer Personal Data.
-
Duku’s obligations under Section 9.1 of this Addendum are subject to Customer:
-
giving Duku reasonable prior notice of such information requests, audits and/or inspections being required by Customer, provided that such notice shall be no less than twenty (20) business days, except where a shorter period is required by a Supervisory Authority;
-
ensuring that all information obtained or generated by Customer or the auditor(s) in connection with such information requests, inspections and audits is kept strictly confidential (save for disclosure to a Supervisory Authority or as otherwise required by applicable laws); and
-
ensuring that such audit or inspection is undertaken during normal business hours, with, so far as reasonably practicable, minimal disruption to Duku’s business and the business of other Customers of Duku.
-
Liability
-
Customer acknowledges that Duku is reliant on Customer for direction as to the extent to which Duku is entitled to Process Customer Personal Data on behalf of Customer in the provision of the Services. Consequently Duku will not be liable under the Agreement or this Addendum for any claim arising from any action or omission, to the extent that such action or omission resulted directly from Customer’s instructions or from Customer’s failure to comply with its obligations under applicable Data Protection Laws.
-
Notwithstanding any provisions to the contrary included in this Addendum, each Party’s liability under or in connection with this Addendum will be limited in accordance with the liability provisions of the Agreement.