1. Scope, Order of Precedence and Parties

1.1. This Data Processing Addendum (“DPA”) applies to the Processing of Personal Data by Cloud Software Group, Inc. and its Affiliates on Your behalf when providing Green Parrot entities products (“Products”) and technical support services or consulting services (“Services”). The Products and Services are described in the relevant license and/or services agreement and the applicable order for Products and Services (collectively, the “Agreement”). In the event of a conflict between the terms of the Agreement and this DPA, the terms of this DPA shall control. In the event of a conflict between the terms of this DPA and the EU Standard Contractual Clauses, the UK SCC Addendum and/or Swiss Addendum (if applicable), the terms of the EU Standard Contractual Clauses, the UK SCC Addendum and/or Swiss Addendum (if applicable) shall control.

1.2. This DPA is between the end-user customer (“You”) and the Cloud Software Group contracting entity (“Green Parrot entities”, “We”, “Us” or “Our”) and is incorporated by reference into the Agreement.

2. Definitions

2.1. “Affiliate” means any subsidiary of Green Parrot Collective Pty Ltd that may assist other Green Parrot entities in other countries in the processing of Your Personal Data under this DPA.

2.2. “Aggregate” means information that relates to a group or category of individuals, from which identities have been removed such that the information is not linked or reasonably linkable to any individual subject to Applicable Data Protection Laws.

2.3. “Applicable Data Protection Laws” means (i) the EU General Data Protection Regulation 2016/679 (“GDPR”) and laws or regulations implementing or supplementing the GDPR; and (ii) any other international, federal, state, provincial and local privacy or data protection laws, rules, regulations, directives and governmental requirements currently in effect and as they become effective that apply to the Processing of Personal Data under this Agreement.

2.4. “Controller” is a legally defined term that generally refers to the party that determines the purposes and means (the why and how) of the processing of Personal Data.

2.5. “Customer Content” means any data uploaded to a Green Parrot entities Product for storage or processing. Customer Content may include Personal Data.

2.6. “2021 EU Standard Contractual Clauses” or “2021 EU SCCs” means the contractual clauses annexed to the EU Commission Decision 2021/914/EU or any successor clauses approved by the EU Commission.

2.7. “Personal Data” means any Customer Content Processed in connection with the performance of Products and/or Services that can identify a unique individual, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of individuals, or as otherwise defined under Applicable Data Protection Laws.

2.8. “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed in order to perform the Products and/or Services that compromises the security of the Personal Data.

2.9. “Processor” is a legally defined term that generally refers to the party that processes Personal Data on behalf of the Controller.

2.10. “Sub-Processor” means any third party engaged by a Processor or another Sub-Processor to assist with the Processing of Personal Data for the performance of Products and/or Services under the Agreement.

2.11. “Swiss SCC Addendum” means the adaptation of the 2021 EU SCCs designed to ensure an adequate level of protection for data transfers from Switzerland to a third country subject to the Swiss Federal Act on Data Protection (“FADP”).

2.12. “Usage Data” means technical data collected from Your use of Green Parrot entities Products for the purposes specified herein and as identified in the relevant Product Documentation.

2.13. “UK Data Protection Laws” means the UK GDPR and the Data Protection Act 2018, or any successor UK data protection laws as updated, amended or replaced from time to time.

2.14. “UK SCC Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (vB1.0 or any subsequent version) issued by the UK Information Commissioner’s Office.

2.15. “2021 EU Standard Contractual Clauses” or “2021 EU SCCs” means the contractual clauses annexed to the EU Commission Decision 2021/914/EU or any successor clauses approved by the EU Commission.

Terms used but not defined in this DPA (e.g., “Business Purpose, Consumer, Controller, Data Subject, Process/Processing, Processor”) shall have the same meaning as set forth in the Agreement or Applicable Data Protection Laws.

3. Roles as Controller and Processor

3.1. For purposes of this DPA, You are the Controller of the Product Personal Data Processed by Green Parrot entities under the terms of the Agreement. You are responsible for complying with your obligations as a Controller under Applicable Data Protection Laws governing your provision of Personal Data to Us for the performance of the Products and/or Services, including without limitation obtaining any consents, providing any notices, otherwise establishing the required legal basis, and responding promptly to any inquiries from a data protection authority. Unless specified in the Agreement, You will not provide Us with access to any Personal Data that imposes specific data protection requirements greater than those agreed to in the Agreement and this DPA, and you will limit Our access to Personal Data as necessary for Your use of the Products and Services under the Agreement.

3.2. Green Parrot entities is the Processor and service provider with respect to such Product Personal Data, except when You act as a Processor of Personal Data, in which case We are a Sub-Processor.

3.3. Green Parrot entities is responsible for the Processing of Usage Data solely for Our legitimate business interests, including measuring Customer’s use of Green Parrot entities Products in accordance with the Agreement and pursuant to the terms of this DPA.

3.4. Each party shall comply with their respective obligations as Controllers and Processors under Applicable Data Protection Laws.

4. Green Parrot Collective Pty Ltd’s Purpose of Processing

4.1. Green Parrot entities and any persons acting under its authority under this DPA, including Sub-Processors and Affiliates as described in Section 6, will Process Personal Data only for the purposes of performing the Products and/or Services in accordance with your written instructions as specified in the Agreement, this DPA, Your Product configurations, and in accordance with Applicable Data Protection Laws. We may also Aggregate Personal Data as part of the Products and/or Services in order to provide, secure, and enhance Green Parrot entities Products and Services.

4.2. We will not disclose Personal Data in response to a subpoena, judicial or administrative order, or other binding instrument (a “Demand”) unless required by law. We will promptly notify You of any Demand unless prohibited by law and provide You reasonable assistance to facilitate Your timely response to the Demand. We may provide Personal Data to Affiliates in connection with any anticipated or actual merger, acquisition, sale, bankruptcy, or other reorganization of some or all of its business, subject to the obligation to protect Personal Data consistent with the terms of this DPA.

5. Data Subjects and Categories of Personal Data

5.1. You determine the Personal Data to which You provide Us access to in order to perform the Products and/or Services. This may involve the
Processing of Personal Data of the following categories of Your Data Subjects:

5.1.1. Employees and applicants

5.1.2. Customers and end users

5.1.3. Suppliers, agents, and contractors

5.2. The Processing of Your Personal Data may also include the following categories of Personal Data:

5.2.1. Direct identifiers such as first name, last name, date of birth, and home address

5.2.2. Communications data such as home telephone number, cell telephone number, email address, postal mail address, and fax number

5.2.3. Family and other personal circumstance information, such as age, date of birth, marital status, spouse or partner, and number and names of children

5.2.4. Employment information such as employer, work address, work email and phone, job title and function, salary, manager, employment ID, system usernames and passwords, performance information, and CV data

5.2.5. Other data such as financial, good or services purchased, device identifiers, online profiles and behaviour, and IP address

5.2.6. Other Personal Data to which You provide Us access in connection with the provision of Products or Services

6. Sub-Processing

6.1. Subject to the terms of this DPA, You authorize Us to engage Sub-Processors and Affiliates for the Processing of Personal Data. These Sub-Processors and Affiliates are bound by written agreements that require them to provide at least the level of data protection required of Green Parrot entities by the Agreement and this DPA, and We have implemented commercially reasonable measures designed to confirm compliance with such measures. You may request Us to perform an audit on a Sub-Processor or to obtain an existing third-party audit report related to the Sub-Processor’s operations to verify compliance with these requirements. You may also request copies of the data protection terms We have in place with any Sub-Processor or Affiliate involved in providing the Products and/or Services. We remain responsible at all times for such Sub-Processors’ and Affiliates’ compliance with the requirements of the Agreement, this DPA and Applicable Data Protection Laws.

6.2. A list of sub-Processors and Affiliates, as well as a mechanism to obtain notice of any updates to the list, are available at https://www.greenparrot.io/trust-center/sub-processor-list. At least fourteen (14) calendar days before authorizing any new Sub-Processor to access Personal Data, We will update the list of Sub-Processors and Affiliates. Where Green Parrot entities is a Processor (and not a Sub-Processor), the following terms apply:

6.2.1. If, based on reasonable grounds related to the inability of such Sub-Processor or Affiliate to protect Personal Data, You do not approve of a new Sub-Processor or Affiliate, then You may terminate any subscription for the affected Service without penalty by providing, before the end of the notice period, written notice of termination that includes an explanation of the grounds for non-approval.

6.2.2. If the affected Product and/or Service is part of a suite (or similar single purchase of Products and/or Services), then any such termination will apply to the entire suite.

6.2.3. After such termination, You shall remain obligated to make all payments required under any purchase order or other contractual obligation with the ELA Reseller and/or Green Parrot entities and shall not be entitled to any refund or return of payment from the ELA Reseller and/or Green Parrot entities.

7. International Transfer of Personal Data

8. Requests from Data Subjects

8.1. We will make available to You the Personal Data of Your Data Subjects and the ability to fulfill requests by Data Subjects to exercise one or more of their rights under Applicable Data Protection Laws in a manner consistent with Our role as a Processor. We will provide reasonable assistance to assist with Your response.

8.2. If We receive a request directly from Your Data Subject to exercise one or more of their rights under Applicable Data Protection Laws, We will direct the Data Subject to You unless prohibited by law.

9. Security

10. Personal Data Breach

10.1. We shall notify You without undue delay after becoming aware of a Personal Data Breach involving Personal Data in Our possession, custody or control. Such notification shall at least: (i) describe the nature of the Personal Data Breach including, where possible, the categories and approximate number of Your Data Subjects concerned and the categories and approximate number of Personal Data records concerned; (ii) provide the name and contact details of the data protection officer or other contact where more information can be obtained; and (iii) describe the measures taken or proposed to be taken to address the Personal Data Breach including, where appropriate, measures to mitigate its possible adverse effects. You will coordinate with Us on the content of any public statements or required notices to individuals and/or Supervisory Authorities.

11. Your Instructions and Providing Information & Assistance

11.1. You may provide additional instructions to Us related to the Processing of Personal Data that are necessary for You and Green Parrot entities to comply with our respective obligations under Applicable Data Protection Laws as Controller and Processor. We will comply with Your instructions, provided that in the event that Your instructions impose costs on Us beyond those included in the scope of Products and/or Services under the Agreement, the parties agree to negotiate in good faith to determine the additional costs. We will promptly inform You if We believe that Your instructions are not consistent with Applicable Data Protection Laws, provided that We will not be obligated to independently inspect or verify Your Processing of Personal Data.

11.2. We will provide You with information reasonably necessary to assist You in enabling Your compliance with Your obligations under Applicable Data Protection Laws, including without limitation Our obligations under the EU General Data Protection Regulation to implement appropriate data security measures, carry out a data protection impact assessment and consult the competent Supervisory Authority (taking into account the nature of Processing and the information available to Us), and as further specified in this DPA.

12. Return and Deletion of Personal Data

12.1. We will return or provide an opportunity for You to retrieve all Personal Data after the end of the provision of Products and/or Services and delete existing copies. With respect to cloud services, You shall have thirty (30) calendar days to download Your Personal Data after termination of the Agreement and You must contact technical support for download access and instructions. In the event You do not contact technical support for this purpose within 30 calendar days after the end of the provision of Products and/or Services, We shall delete Your Personal Data promptly once that Personal Data is no longer accessible by You, except for (i) back-ups deleted in the ordinary course, and (ii) retention as required by applicable law. In the event of either (i) or (ii), We will continue to comply with the relevant provisions of this DPA until such data has been deleted. We will provide written confirmation of deletion upon request.

13. Audit

13.1. In the event the information you request of Green Parrot entities under Section 11 above does not satisfy your obligations under Applicable Data Protection Laws, You may carry out an audit of Our Processing of Your Personal Data up to one time per year or as otherwise required by Applicable Data Protection Laws. To request an audit, you must provide Us with a proposed detailed audit plan three weeks in advance, and We will work with you in good faith to agree on a final written plan. Any such audit shall be conducted at Your own expense, during normal business hours, without disruption to Our business, and in accordance with Our security rules and requirements. Prior to any audit, We undertake to provide You reasonably requested information and associated evidence to satisfy Your audit obligations, and You undertake to review this information prior to undertaking any independent audit. If any of the requested scope of the audit is covered by an audit report issued to Us by a qualified third-party auditor within the prior twelve months, then the parties agree that the scope of Your audit will be reduced accordingly.

13.2. You may use a third-party auditor with Our agreement, which will not be unreasonably withheld. Prior to any third-party audit, such auditor shall be required to execute an appropriate confidentiality agreement with Us. If the third party is Your Supervisory Authority that applicable law enables it to audit Us directly, We will cooperate with and provide reasonable assistance to the Supervisory Authority in accordance with Applicable Data Protection Laws.

13.3. You will provide Us with a copy of any final report unless prohibited by Applicable Data Protection Laws, will treat the findings as confidential information in accordance with the terms of the Agreement (or confidentiality agreement entered into between You and Green Parrot entities), and use it solely for the purpose of assessing Our compliance with the terms of the Agreement, this DPA, and Applicable Data Protection Laws.

14. Data Protection Officer

14.1. You may contact the Our global Chief Privacy Officer and privacy team c/o Green Parrot Collective Pty Ltd, 15 Devere Avenue, Belrose, NSW 2085 Australia. If you have appointed a Data Protection Officer, you may include their contact information in your order for Products and Services.

15. Term

15.1. This DPA becomes effective upon Your purchase of the Products and Services. Termination of the Agreement does not relieve either party of its obligations under this DPA.

Login / Sign UpGPC Platform