1. DEFINITIONS

“客户”或“公司”是指MotionPoint为其提供服务的MotionPoint客户(如果客户是一家机构,则为该机构的客户);

“客户个人数据”或“个人信息”是指MotionPoint在向客户提供服务的过程中获得的个人数据(如有);

“数据控制方”(或控制方)、“数据处理方”(或处理方)、“数据主体”、“个人数据”、“处理”和“敏感个人数据”(或特殊类别的个人数据)都具有“数据保护法”中这些术语的含义(“处理”和“已处理”等相关术语应具有相应含义);

“数据保护法”是指与个人隐私、数据安全或信息保护有关的任何适用法律和法规,适用于客户、MotionPoint和/或根据本协议提供的服务,包括但不限于2018年加州消费者隐私法(CCPA),并且,如果客户个人数据与欧盟或瑞士的数据主体的个人数据有关,则1998年数据保护法、2003年隐私和电子通信(EC指令)条例(SI 2426/2003)以及执行理事会指令95/46/EC或2002/58/EC的任何法律或法规;GDPR和/或任何相应或等效的国家法律或法规;以及上述任何内容的司法或行政解释,以及任何相关监管机构发布的任何指南、准则、业务守则、批准的行为准则或批准的认证机制;

“数据主体”应当具备数据保护法中“数据主体”的含义;

“数据主体请求”是指数据主体为行使数据保护法中数据主体的任何权利而提出的请求;

“DP损失”是指所有负债和金额,包括所有:

a. 费用(包括诉讼费)、索赔、需求、诉讼、和解、恩恤金、收费、程序、开支、损失和损害(包括物质或非物质相关损害,包括情绪压力);
b. 声誉、品牌或商誉的损失或损害;
c. 适用法律和法规允许的范围内;

i. 行政处罚、罚款、制裁、债务或监管机构施加的其他补救措施;
ii. 向数据主体支付的酬劳;以及
iii. 监管机构的调查合规成本。

“DPIA”是指数据保护影响评估或隐私影响评估(如数据保护法中所定义或使用的,包括监管机构的相关指导);

“GDPR”是指欧洲议会和委员会就有关个人数据处理和此类数据自由流通对自然人保护作出的规管,并废除95/46/EC法令(一般数据保护法规);

“标准条款”是指针对将数据传输到EEA以外地区、不具备充分数据保护法规的国家的2010年2月5日欧盟委员会2010/87/EU号决定的标准合同条款附件;

“标准合同条款”系指由2010年2月5日的欧盟委员会决议2010/87/EU所规定,并经2016年12月16日的委员会执行决议(EU) 2016/2297所修订的标准数据保护条款,适用于将个人数据转移至设立在第三国的处理方的情况;

“安全漏洞”是指违反安全的行为,或造成他人意外或非法破坏、丢失、篡改、未经授权地披露或获取客户个人信息的作为或不作为;

“服务提供商”是指代表客户处理个人数据并且客户出于业务目的向其披露个人信息的法人实体。“业务目的”是指将个人数据用于客户的经营目的,包括MotionPoint根据本协议代表客户提供服务。双方承认并同意,MotionPoint对个人数据的处理对于为客户执行此类服务是合理必要且相称的,并且此类服务与收集个人数据的背景相符;

“出售”是指出于金钱或其他有效对价或适用的州或联邦法律规定而交换个人数据;“次级处理方”是指MotionPoint委托代表MotionPoint执行客户个人数据处理活动的其他数据处理方;“监管机构”是指任何地方、国家或跨国机构、部门、官员、议会、公众或法定人士或任何政府或职业机构、监管或监督机构、委员会或负责管理数据保护法的其他机构。

2. 合规

各方均应遵守数据保护法,因为其涉及根据本协议所处理的客户个人信息。 MotionPoint shall notify Customer if MotionPoint makes a determination that it can no longer meet its obligations under applicable Data Protection Laws.

3. 数据处理详细信息。

3.1 In respect of Customer Personal Data processed under this Agreement, MotionPoint is a Data Processor and the Customer is a Data Controller. MotionPoint certifies that it understands the restrictions of this Section

3 and will comply with them.

3.2 The Customer Personal Data shall be Processed for the Term of this Agreement (subject to any legal obligations on MotionPoint to keep Customer Personal Data longer).

3.3 The Customer Personal Data may consist of:

3.3.1 the following data types: personal details, contact details, family details, lifestyle and social circumstances, financial or payment details, employment information, marketing information, data analytics, images or video, device identifiers, personal profiles, order details, log in details, user testimonials, contact form details, preference details and all other information submitted by end users (including physical or mental health data, genetic data, biometric data, racial or ethnic group information and religious or philosophical beliefs information, where relevant) through Deployed Digital Properties.

3.3.2 Personal Data Processed in respect of individuals who are end users of Customer’s Deployed Digital Properties whose Personal Data is processed to provide Services under this Agreement.

3.3.3 为根据本协议向客户提供服务而处理客户个人数据。MotionPoint同意就个人数据而言,其仅作为服务提供商,并且客户具有确定处理个人数据的目的和方式的专有权。

3.4. MotionPoint不得出售个人数据。

3.5. MotionPoint在以下情况不得收集、保留、使用、披露或以其他方式处理个人数据:1) 怀有除根据本协议的规定出于客户的利益履行服务、义务或行为以外的任何目的(包括商业目的)或2) 在MotionPoint与客户之间的直接业务关系之外。

4. 数据处理说明

MotionPoint应当仅出于根据本协议提供服务的目的处理个人信息。双方同意,个人数据不构成本协议对价的一部分。

5. 供应商员工和次级处理方

5.1 MotionPoint shall ensure all MotionPoint personnel who Process Customer Personal Data have signed agreements requiring them to keep Personal Data confidential.

5.2 The Customer consents to the use of all Sub-Processors engaged by MotionPoint for provision of Services to customers at the time of this Agreement.

5.3 Where MotionPoint appoints a new Sub-Processor to carry out Processing of Customer Personal Data, during the term of this Agreement, the Customer shall be provided with reasonable notice of such Sub-Processor and the right to object to such appointment on reasonable data protection grounds within 30 days of receiving notice of the appointment.

5.4 MotionPoint shall ensure all Sub-processors Processing Customer Personal Data enter into written agreements that impose the same obligations on the Sub-processor as are imposed on MotionPoint as a Processor under this Processing Schedule, as applicable to the Sub-Processor’s role.

5.5 MotionPoint shall remain fully liable to the Customer for the performance of the Sub-Processor’s data protection obligations under the written agreement in section 5.4 of this Processing Schedule, in the event the Sub-Processor fails to fulfil those obligations.

5.6 Where the Customer exercises the right to object as set out in section 5.3 of this Processing Schedule, MotionPoint reserves the right to terminate this Agreement on giving the Customer reasonable notice of such termination.

5.7     MotionPoint shall not combine the personal information that its provider receives from, or on behalf of, Customer with personal information that it receives from, or on behalf of, another person or persons, or collects from its own interaction with the consumer, unless expressly permitted by applicable Data Protection Laws.

6. 数据传输

6.1 In provision of the Services to the Customer, MotionPoint may transfer Customer Personal Data to countries outside the EEA.

6.2 Transfer of Customer Personal Data outside the EEA are subject to MotionPoint putting in place adequate safeguards under Data Protection Law for such transfers and notifying the Customer of the safeguards in place prior to any such transfer. 这些保障措施包括标准合同条款。

7. 安全和数据泄露通知。

7.1 MotionPoint shall implement and maintain appropriate technical and organizational measures in relation to the processing of Customer Personal Data to ensure a level of security appropriate to the risk of accidental, unauthorized or unlawful access, disclosure, alteration, loss, or destruction of Customer Personal Data.

7.2 MotionPoint shall notify the Customer without undue delay after becoming aware of any Security Breach and provide the Customer with reasonable assistance in complying with its Security Breach notification obligations under Data Protection Laws.

7.3     Customer may, upon notice, take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.

8. 协助

在处理客户个人数据方面,MotionPoint应当(如适用):

8.1 将客户个人数据的数据主体根据数据保护法行使数据主体权时提出的请求转发给客户;

8.2 根据执行《数据保护法》“数据主体权利”的客户个人数据的主体提出的任何请求,向客户提供合理的帮助(由客户承担费用);

8.3 Provide the Customer with reasonable assistance (at Customer’s expense) to enable the Customer to conduct any DPIA and consultations with (or notifications to) relevant regulatory authorities that it is required to undertake under Data Protection Laws;

8.4 Provide the Customer with reasonable assistance (at Customer’s expense) in complying with its obligation to implement and maintain appropriate technical and organizational security measures in relation to the processing of Customer Personal Data.

9. 数据删除或退还

本协议终止或失效时,MotionPoint应当(应客户要求)销毁或向客户返还持有或控制的所有客户个人数据,并删除现有副本(MotionPoint可能具有延长客户个人数据留存时间的法律义务)。

10. 信息请求和审计

10.1 MotionPoint shall allow for audits conducted by the Customer or a representative mandated by the Customer for the purpose of demonstrating MotionPoint's compliance with its obligations under this Processing Schedule. 这要求客户向MotionPoint提供有关此类计划内审计的合理提前书面通知,并确保所有审计人员遵守具有约束力的保密义务,以及在开展此类审计或稽查的过程中,将MotionPoint的业务中断降至最低。此章节10.1下的审计权限每年一次,费用由客户承担。

10.2 MotionPoint shall (at Customer’s request) provide the Customer with necessary information to demonstrate MotionPoint’s compliance with the obligations under this Processing Schedule.

10.3   Customer may, at its own expense, take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.



欢迎垂询

欢迎垂询,了解我们将如何助您轻松在全球扩展业务。

预约咨询