Data Processing Addendum
1. Definitions
1.1 In this Data Processing Addendum ("DPA"):
1.1.1 "Controller", "Commissioner", "Data Subject", "Personal Data Breach", "Processing" "Processor", "Supervisory Authority", "Sale", "Selling", "Share", "Shared", and "Sharing" have the meaning given to them in Data Protection Laws. "Data Subject" includes "Consumer" as defined under U.S. Privacy Laws;
1.1.2 "Customer Personal Data" means Personal Data Processed by Lantern as a Processor on behalf of Customer to provide the Services to Customer pursuant to the Agreement;
1.1.3 "Data Protection Laws" means all applicable data protection and privacy legislation including but not limited to: U.S. Privacy Laws, the General Data Protection Regulation (EU) 2016/679 ("EU GDPR"); the UK GDPR as defined by section 205(4) of the UK Data Protection Act 2018 ("UK GDPR"); the UK Data Protection Act 2018; and any implementing regulation thereof of any jurisdiction, and all other applicable data protection laws of the EEA, the United Kingdom, and Switzerland, each as applicable, in each case as amended, updated or replaced from time to time;
1.1.4 "Data Subject" shall be interpreted consistent with Data Protection Laws, and includes at a minimum and where applicable "data subject" as that term is defined under European Data Protection Laws and "consumer" as the term is defined under the CCPA and U.S. State Privacy Laws;
1.1.5 "Data Subject Rights" means all rights granted to Data Subjects by Data Protection Laws, including the right to information, access, rectification, erasure, restriction, portability, objection, the right to withdraw consent, and the right not to be subject to automated individual decision-making;
1.1.6 "International Data Transfer" means any disclosure of Personal Data by an organization subject to Data Protection Laws to another organization located outside the EEA or the UK;
1.1.7 "SCCs" means the clauses annexed to the EU Commission Implementing Decision 2021/914 of June 4, 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended or replaced from time to time;
1.1.8 "Subprocessor" means a Processor engaged by Lantern to carry out Processing;
1.1.9 "UK Addendum" means the addendum to the SCCs issued by the UK Information Commissioner under Section 119A(1) of the UK Data Protection Act 2018 (version B1.0, in force March 21, 2022); and
1.1.10 "U.S. Privacy Laws" means, collectively, all U.S. federal and state privacy laws and their implementing regulations, as amended or superseded from time to time, that apply generally to the processing of individuals' Personal Data and that do not apply solely to specific industry sectors (e.g., financial institutions), specific demographics (e.g., children), or specific classes of information (e.g., health or biometric information). U.S. Privacy Laws include, but are not limited to, the following:
1.1.10.1 California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ("CCPA");
1.1.10.2 Colorado Privacy Act;
1.1.10.3 Connecticut Personal Data Privacy and Online Monitoring Act;
1.1.10.4 Delaware Personal Data Privacy Act;
1.1.10.5 Indiana Consumer Data Protection Act;
1.1.10.6 Iowa Consumer Data Protection Act;
1.1.10.7 Kentucky Consumer Data Protection Act;
1.1.10.8 Maryland Online Data Privacy Act;
1.1.10.9 Minnesota Consumer Data Privacy Act;
1.1.10.10 Montana Consumer Data Privacy Act;
1.1.10.11 Nebraska Data Privacy Act;
1.1.10.12 New Hampshire Act Relative to the Expectation of Privacy;
1.1.10.13 New Jersey Act Concerning Online Services, Consumers, and Personal Data;
1.1.10.14 Oregon Consumer Privacy Act;
1.1.10.15 Rhode Island Data Transparency and Privacy Protection Act;
1.1.10.16 Tennessee Information Privacy Act;
1.1.10.17 Texas Data Privacy and Security Act;
1.1.10.18 Utah Consumer Privacy Act; and
1.1.10.19 Virginia Consumer Data Protection Act.
Capitalized terms used but not defined herein have the meaning given to them in the Agreement. In the event of a conflict in the meanings of defined terms in the U.S. Privacy Laws, the meaning from the law applicable to the state of residence of the relevant Consumer applies.
2. Scope
2.1 Excluding Section 2.3, this DPA applies to the Processing of Customer Personal Data by Lantern as a Processor to provide the Service. Customer is a Controller responsible for determining the purposes and means of Processing Customer Personal Data, and appoints Lantern as a Processor on behalf of Customer for the limited and specific purposes set forth in the Agreement and this DPA. Customer is responsible for compliance with the requirements of Data Protection Laws applicable to Controllers.
2.2 The subject matter, nature and purpose of the Processing, the types of Customer Personal Data and categories of Data Subjects are set out in Annex I, which is an integral part of this DPA.
2.3 Notwithstanding this DPA, Customer acknowledges that Lantern is a Controller under the Data Protection Laws where Lantern Processes or aggregates Customer Personal Data relating to the operation, support, or use of the Service for its own business purposes, such as billing, account management, data analysis, benchmarking, technical support, feedback, product development, and compliance with law.
3. Instructions
3.1 Lantern will Process Customer Personal Data to provide the Service and in accordance with the Customer's documented instructions.
3.2 Customer's instructions are documented in this DPA, the Agreement, and any applicable Order Form.
3.3 Lantern is prohibited from (i) Selling or Sharing Customer Personal Data, (ii) retaining, using, or disclosing Customer Personal Data for any purpose other than for the specific purpose documented in the Customer instructions and in Annex I, (iii) retaining, using, or disclosing Customer Personal Data outside of the direct business relationship between Customer and Lantern, and (iv) combining Customer Personal Data with Personal Data obtained from, or on behalf of, sources other than Customer, except as expressly permitted under applicable Data Protection Laws. For the avoidance of doubt, Lantern is permitted to retain, use, and disclose Customer Personal Data for product improvement purposes.
4. Customer's obligations
4.1 The Customer shall ensure that it has all necessary appropriate consents and notices in place to enable Lantern to Process Customer Personal Data pursuant to this Agreement.
4.2 The Customer confirms that the Customer Personal Data transferred to Lantern, and the Processing undertaken by Lantern in the course of providing the Services as a Processor, have a valid lawful basis under the Data Protection Laws.
5. Security and personal data breaches
5.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Parties shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
5.2 Lantern will notify Customer without undue delay after becoming aware of a Personal Data Breach involving Customer Personal Data.
5.2 Lantern shall ensure that its employees, agents, subcontractors, and Subprocessors are subject to a duty of confidentiality with respect to Customer Personal Data.
6. Subprocessing
6.1 Customer hereby authorizes Lantern to engage Subprocessors. A list of Lantern's current Subprocessors are in Annex II.
6.2 Lantern will enter into a written agreement with Subprocessors which imposes the same obligations as required by Data Protection Law.
6.2 Lantern will notify Customer prior to any intended change to Subprocessors. Customer may object to the addition of a Subprocessor based on reasonable grounds relating to a potential or actual violation of Data Protection Laws by providing written notice detailing the grounds of such objection within thirty (30) days following Lantern's notification of the intended change. Lantern and Customer will work together in good faith to address Customer's objection.
7. Subprocessing
7.1 Taking into account the nature of the Processing, and the information available to Lantern, Lantern will assist Customer, including, as appropriate, by implementing technical and organizational measures, with the fulfillment of Customer's own obligations under Data Protection Laws to: comply with requests to exercise Data Subject Rights; conduct data protection impact assessments, and prior consultations with the Commissioner or Supervisory Authorities; and notify a Personal Data Breach.
7.2 Where applicable, Customer shall inform Lantern of any Data Subject request made pursuant to the Data Protection Laws that they must comply with. Customer shall provide Lantern with the information necessary for Lantern to comply with the request.
7.3 Lantern shall not be required to delete any Customer Personal Data to comply with a Data Subject's request directed by Customer if retaining such information is specifically permitted by applicable Data Protection Laws; provided, however, that in such case, Lantern shall not use Customer Personal Data retained for any purpose other than provided for by that exception.
7.4 Lantern may charge a reasonable fee for assistance under this Section 7. If Lantern is at fault, Lantern and Customer shall each bear their own costs related to assistance.
8. Audit
8.1 Upon reasonable request, Lantern must make available to Customer all information necessary to demonstrate compliance with the obligations of this DPA and allow for and contribute to audits, including inspections, as mandated by the Commissioner or a Supervisory Authority or reasonably requested no more than once per every 12 months by Customer, and performed by an independent auditor as agreed upon by Customer and Lantern. The foregoing shall only extend to those documents and facilities relevant and material to the Processing of Customer Personal Data and shall be conducted during normal business hours and in a manner that causes minimal disruption.
8.2 Lantern shall promptly notify Customer if it determines that it can no longer meet its obligations under Data Protection Laws. Upon receiving notice from Lantern in accordance with this subsection, Customer may direct Lantern to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
9. International data transfers
9.1 Customer hereby authorizes Lantern to perform International Data Transfers to any country deemed to have an adequate level of data protection by the European Commission or the competent authorities, as appropriate; on the basis of adequate safeguards in accordance with Data Protection Laws; or pursuant to the SCCs and the UK Addendum.
10. Notifications
10.1 Customer will send all notifications, requests and instructions under this DPA to Lantern via email to dpo@lantern.ai.
10.2 Lantern will send all notifications under this DPA to Customer's contact as specified in an Order.
11. Term and duration of processing
11.1 The Processing will last no longer than the term of the Agreement.
11.2 Customer may request return of Customer Personal Data up to ninety (90) days after termination of the Agreement. Unless required or permitted by applicable law or this DPA, Lantern will delete all remaining copies of Customer Personal Data in its or its Subprocessors' possession without undue delay days after returning Customer Personal Data to Customer. Lantern may retain Customer Personal Data to the extent required by law but only to the extent and for such period as required by such law and always provided that Lantern shall ensure the confidentiality of all such Personal Data.
11.2 The Parties agree to cooperate in good faith to enter into additional terms to address any modifications, amendments, or updates to applicable statutes, regulations or other laws pertaining to privacy and information security.
Annex I
Description of the processing
Categories of Data Subjects whose Personal Data is Processed:
Categories of Personal Data Processed:
Nature of the processing: The Personal Data will be Processed and transferred as described in the Agreement.
Purpose(s) of the data transfer and further Processing: The Personal Data will be Processed for the provision of the Services as described in the Agreement.
Duration of the Processing: The Personal Data will be Processed for the duration of the Agreement.
Annex II
List of subprocessors
Customer has authorised the use of the following Subprocessors by Lantern:
