By using our site, you agree to our use of cookies. Cookie Policy

Data Processing Addendum (DPA)

Updated on Jul 26, 2023

This Data Protection Addendum ("DPA") forms part of the agreement between Utobo Inc. ("Utobo," "we," "us," or "our") and the customer ("Customer," "you," or "your") for the provision of Utobo's services. This DPA sets out the terms that apply when Personal Data is processed by Utobo on behalf of the Customer in connection with the use of Utobo's products and services. The purpose of this DPA is to ensure that the processing of Personal Data is conducted in accordance with applicable Data Protection Laws.

Terms and Definitions

  • Customer: The individual or entity that has agreed to the Utobo Terms and Conditions and uses the Utobo Platform.
  • Customer Account Data: Personal data relating to the Customer's relationship with Utobo, including account registration information, billing details, and communications with Utobo support.
  • Customer Data: Any personal data that the Customer or its end users submit, store, send, or receive through the Platform, including course content, student information, and communications.
  • Data Protection Law: All applicable laws and regulations relating to the processing of personal data, including the GDPR, CCPA, and any other applicable privacy laws.
  • GDPR: The General Data Protection Regulation (EU) 2016/679, as amended or replaced from time to time, together with any national implementing laws in any Member State of the European Union or the United Kingdom.
  • Industry Standards: The security standards and best practices generally accepted in the technology industry for the protection of personal data, including ISO 27001, SOC 2, and similar frameworks.
  • Information Security Incident: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data or Customer Account Data.
  • Personal Data: Any information relating to an identified or identifiable natural person, as defined by applicable Data Protection Law.
  • Product: The Utobo platform and all related services provided by Utobo to the Customer under the Terms and Conditions.
  • Product Generated Data: Data generated by the Product during the provision of services, including usage data, analytics data, logs, and metadata that is derived from the Customer's use of the Platform.
  • Standard Contractual Clauses: The standard contractual clauses for the transfer of personal data to third countries, as approved by the European Commission or other relevant authority, as applicable.

General Terms

Relation Between Parties

For the purposes of this DPA, the Customer is the data controller and Utobo is the data processor with respect to Customer Data. With respect to Customer Account Data and Product Generated Data, Utobo may act as an independent data controller. The parties acknowledge that this DPA does not affect the rights and obligations of the parties under applicable Data Protection Law.

Permitted Processing

Utobo shall process Customer Data only in accordance with the Customer's documented instructions, which include the processing described in this DPA, the Terms and Conditions, and any additional instructions agreed upon in writing. Utobo shall not process Customer Data for any other purpose unless required to do so by applicable law, in which case Utobo shall inform the Customer of that legal requirement before processing unless prohibited by law.

Customer Obligations

The Customer is responsible for ensuring that its use of the Platform and its instructions to Utobo comply with all applicable Data Protection Laws. The Customer shall ensure that it has obtained all necessary consents, provided all necessary notices, and has a lawful basis for the transfer of Personal Data to Utobo for processing in accordance with this DPA.

Roles and Responsibilities

The Customer shall be responsible for the accuracy, quality, and legality of Customer Data and the means by which it acquired the data. Utobo shall be responsible for implementing appropriate technical and organizational measures to protect Customer Data in accordance with this DPA and applicable Data Protection Laws. Both parties shall cooperate in good faith to address any data protection issues that arise.

Compliance with Data Protection Law

Each party shall comply with all applicable Data Protection Laws in connection with the performance of this DPA. Utobo shall ensure that persons authorized to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Utobo shall make available to the Customer all information necessary to demonstrate compliance with the obligations set out in this DPA.

Impact Assessments and Consultations

Utobo shall provide reasonable assistance to the Customer with any data protection impact assessments and consultations with data protection authorities that the Customer is required to undertake under applicable Data Protection Law. Such assistance shall be provided taking into account the nature of the processing and the information available to Utobo.

Data Usage

Utobo may use Customer Account Data and Product Generated Data for its legitimate business purposes, including to provide and improve the Platform, generate analytics and benchmarking reports, and comply with legal obligations. Utobo shall not sell Customer Data to third parties or use Customer Data for advertising purposes without the Customer's explicit consent.

Limits on Data Sharing

Utobo shall not share Customer Data with any third party except as necessary to provide the Platform services, as instructed by the Customer, or as required by applicable law. Where Utobo shares Customer Data with third parties, it shall ensure that appropriate data processing agreements are in place and that the third party provides sufficient guarantees regarding data protection.

Third Party Processing

The Customer provides general authorization for Utobo to engage sub-processors for the processing of Customer Data. Utobo shall maintain a list of sub-processors and shall make this list available to the Customer upon request. Utobo shall ensure that each sub-processor is bound by data protection obligations no less protective than those set out in this DPA.

New Third Parties

Utobo shall notify the Customer of any intended changes to its sub-processors by updating its sub-processor list at least 30 days before engaging a new sub-processor. If the Customer objects to a new sub-processor, the parties shall work together in good faith to resolve the objection. If the objection cannot be resolved, the Customer may terminate the affected services.

Data Security

Utobo shall implement and maintain appropriate technical and organizational security measures to protect Customer Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, theft, alteration, or disclosure. These measures shall be appropriate to the risk and shall include, as appropriate, measures described in Schedule 2 of this DPA.

Security Review

Utobo shall make available to the Customer information regarding its security practices and undergo regular security assessments, including penetration testing and vulnerability assessments. Upon the Customer's request, Utobo shall provide copies of relevant certifications, audit reports, or summaries thereof, subject to confidentiality obligations.

Customer's Role

The Customer is responsible for reviewing the security measures provided by Utobo and determining whether they are appropriate for the Customer's use of the Platform. The Customer is responsible for properly configuring its account settings and using the security features available on the Platform. Utobo is not responsible for security incidents that result from the Customer's failure to implement appropriate security measures within its control.

Security Incidents

Utobo shall notify the Customer without undue delay after becoming aware of an Information Security Incident. The notification shall include the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the incident. Utobo shall cooperate with the Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of the incident.

Public Communications

Unless required by applicable law, Utobo shall not make any public communication regarding an Information Security Incident without the Customer's prior written consent. Utobo shall cooperate with the Customer in preparing any required notifications to data protection authorities or affected individuals.

International Provisions

Where Customer Data is transferred to a country that has not been deemed to provide an adequate level of data protection, Utobo shall ensure that appropriate safeguards are in place, including Standard Contractual Clauses or other transfer mechanisms approved under applicable Data Protection Law. The specific provisions applicable to different jurisdictions are set out in Schedule 3 of this DPA.

Changes to Agreement

Utobo may update this DPA from time to time to reflect changes in Data Protection Laws, industry practices, or Utobo's services. Material changes will be communicated to the Customer with at least 30 days' notice. The Customer's continued use of the Platform after the effective date of any changes constitutes acceptance of the updated DPA.

Updates

Utobo shall keep this DPA and all related documentation up to date and shall ensure that its data processing practices remain in compliance with applicable Data Protection Laws. The Customer may request updates to this DPA to address changes in applicable law or the Customer's data processing requirements, and Utobo shall consider such requests in good faith.

Contact Information

For any questions or concerns regarding this DPA or data protection matters, please contact us:

Email: support@utobo.com
Address: 800 W El Camino Real Suite 180, Mountain View, CA 94040

Schedule 1: Processing Details

Processing Purpose

Utobo processes Customer Data for the purpose of providing, maintaining, and improving the Platform services, including course delivery, student management, payment processing, communications, analytics, and customer support.

Processing Activities for Customer Data

Processing activities include collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, alignment, combination, restriction, erasure, and destruction of Customer Data as necessary to provide the Platform services.

Processing Activities for Account Data

Processing activities for Customer Account Data include account creation and management, billing and payment processing, customer support communications, service notifications, and account security measures.

Processing Activities for Product Generated Data

Processing activities for Product Generated Data include generation and collection of usage analytics, performance monitoring, error logging, feature usage tracking, and aggregate reporting for service improvement.

Categories of Data Subjects

Data subjects include the Customer's employees, contractors, students, end users, course participants, and any other individuals whose Personal Data is submitted to the Platform by or on behalf of the Customer.

Processing Duration

Utobo shall process Customer Data for the duration of the Customer's use of the Platform and for such additional period as may be necessary to comply with applicable legal obligations, resolve disputes, and enforce agreements. Upon termination, Utobo shall delete or return Customer Data in accordance with the Terms and Conditions unless retention is required by applicable law.

Schedule 2: Security Measures

Utobo implements the following technical and organizational security measures to protect Customer Data:

  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of data at rest using AES-256 or equivalent
  • Access controls and authentication mechanisms, including multi-factor authentication
  • Regular security assessments, penetration testing, and vulnerability scanning
  • Network security measures, including firewalls and intrusion detection systems
  • Physical security measures for data centers, including access controls and surveillance
  • Employee security training and awareness programs
  • Incident response and disaster recovery procedures
  • Regular backups and data redundancy
  • Logging and monitoring of system access and activities
  • Vendor risk management and due diligence for sub-processors
  • Data minimization and retention policies
  • Secure development practices, including code review and testing

Schedule 3: Jurisdiction Specific Terms

California

For California residents, Utobo complies with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). Utobo acts as a "service provider" as defined under the CCPA with respect to Customer Data. Utobo shall not sell Customer Data, retain, use, or disclose Customer Data for any purpose other than providing the Platform services, or retain, use, or disclose Customer Data outside of the direct business relationship with the Customer.

EEA (European Economic Area)

For data subjects in the European Economic Area, processing is governed by the GDPR. Where Customer Data is transferred outside the EEA to a country not deemed adequate by the European Commission, Standard Contractual Clauses (Module Two: Controller to Processor) shall apply. The Customer acts as the data exporter and Utobo acts as the data importer. Data subjects in the EEA have rights including access, rectification, erasure, restriction, portability, and objection.

United Kingdom

For data subjects in the United Kingdom, processing is governed by the UK GDPR and the Data Protection Act 2018. Where Customer Data is transferred outside the UK, the International Data Transfer Addendum to the EU Standard Contractual Clauses (as approved by the UK Information Commissioner) shall apply. Utobo shall comply with all applicable UK data protection requirements.

Canada

For data subjects in Canada, Utobo complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. Utobo shall ensure that Customer Data is processed in accordance with Canadian privacy principles, including consent, limiting collection, limiting use, disclosure, and retention, accuracy, safeguards, openness, individual access, and challenging compliance.

Australia

For data subjects in Australia, Utobo complies with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). Utobo shall take reasonable steps to ensure that Customer Data is processed in accordance with the APPs, including requirements regarding collection, use, disclosure, data quality, data security, and cross-border disclosure of Personal Data.

New Zealand

For data subjects in New Zealand, Utobo complies with the Privacy Act 2020 and the Information Privacy Principles (IPPs). Utobo shall process Customer Data in accordance with the IPPs, including principles regarding purpose of collection, source of information, collection of information, manner of collection, storage and security, access, correction, accuracy, retention, limits on use, and limits on disclosure.