Data Processing Agreement 20211103 I Synthesia

Data Processing Agreement 20211103

Effective as of 3rd of November 2021

1. Preamble

1.1 This Data Processing Agreement represents an addendum and an integral part of Synthesia’s Terms of Service Agreement available at https://www.synthesia.io/terms-of-service and Synthesia's Master Service Agreement available at https://www.synthesia.io/terms/master-service-agreement. Under the Data Protection Laws, Synthesia Limited, a company located at 16 Dufour's Place, London W1F 7SP, United Kingdom (" Synthesia") has a position of a ‘Processor’ and Synthesia’s customers have a position of a ‘Controller’ regarding the personal data collected using Synthesia services (" Services").

2. Definitions

2.1 The following definitions explain some of the terminology and abbreviations used throughout this Data Processing Agreement:

3. Processing

3.1 Processor undertakes to process all Data in accordance with Data Protection Laws and other applicable laws, statutes, and regulations. Nature and the purpose of processing, the types of Data processed, and the categories of Data Subjects whose Data is processed are set out in Appendix 1 to this DPA.

3.2 Unless otherwise explicitly stated in this DPA, the Processor may process the Data for the purposes of providing the Services set out in the Agreement, and only in accordance with the Controller’s documented instructions.

3.3 During the term of this DPA Controller shall remain the owner of the Data transferred to the Processor as well as the Data collected by the Processor on behalf of the Controller.

3.4 Controller warrants that the Data is obtained in accordance with the applicable laws, statutes and regulations and that Processing which Controller requests does not violate any applicable law, statute, or regulation.

3.5 Data that the Processor shall process includes such Data which is requested by the Controller on a case-by-case basis, and which is necessary to perform the services described in the Agreement. Processor shall not process special categories of Data as defined in article 9. of the GDPR.

3.6 Data may be processed for the duration of the Agreement unless otherwise instructed by the Controller.

4. Personnel

4.1 The Processor shall ensure that all employees, contractors, and other persons operating under the authority of the Processor are bound by a strict confidentiality agreement prior to providing them with access to the Data.

4.2 The Processor shall take steps to ensure that any person acting under the authority of the Processor who has access to the Data does not process them except on instructions from the Controller.

5. Security

5.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of Data Subjects, the Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:

5.2 In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing,

5.3 The list of technical and organizational security measures is provided in the Appendix 3 of this DPA.

6. Sub-Processor

6.1 The Controller agrees that Processor may engage sub-processors listed in Appendix 2 to this DPA.

6.2 Where the Processor engages another processor for carrying out specific processing activities on behalf of the Controller, the same Data protection obligations as set out in this DPA shall be imposed on that other processor by way of a contract or other legal act.

7. Data Subject rights

7.1 Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures for the fulfilment of the Controller’s obligations to respond to requests to exercise Data Subject rights under the GDPR.

7.2 The Processor shall:

8. Data Breach

8.1 The Processor shall notify the Controller without undue delay after becoming aware of a Data Breach affecting the Data.

8.2 The Processor shall cooperate with the Controller and take such reasonable steps as are directed by the Controller to assist in the investigation, mitigation, and remediation of each such Data Breach.

9. Data Protection Impact Assessment and Prior Consultation

9.1 The Processor shall provide reasonable assistance to the Controller with any Data protection impact assessments, and prior consultations with competent data privacy authorities.

10. Deletion or return of the Data

10.1 Subject to sections 10.2 and 10.3 the Processor shall promptly delete and procure the deletion of all copies of those Data upon cessation of any Services.

10.2 The Controller may in its absolute discretion require Processor to return a complete copy of all Data to the Controller.

10.3 The Processor may retain the Data to the extent required by applicable laws.

10.4 The Processor shall provide written certification to the Controller that the Processor fully complied with this section 10 upon written request of the Controller.

11. Audit rights

11.1 The Processor shall make available to the Controller on request all information necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections.

11.2 Information and audit rights of the Controller only arise under section 11.1 to the extent that the Agreement does not otherwise give them information and audit rights.

12. Limitation of Liability

12.1 Each party’s liability arising out of, or related to this DPA, is limited to the cumulative amounts paid by the Controller to the Processor in the past 12 months to the event giving rise to the claim.

13. Final provisions

13.1 Any matter that is not regulated by this DPA shall be governed by the Agreement or other subsequent contract concluded between the parties.

13.2 If any part of this DPA is found to be invalid, illegal, or unenforceable, it will not affect the validity or enforceability of the remainder.

13.3 Any failure to exercise or enforce any right or provision shall not constitute a waiver of such right or provision.

13.4 The section titles in the DPA are for convenience only and have no legal or contractual effect.

Appendix 1 – Description of processing

The purpose of the Processor’s processing of Data on behalf of the Controller is:

The Processor’s processing of Data on behalf of the Controller shall mainly pertain to (the nature of the processing):

The processing includes the following types of personal data about data subjects:

Processing includes the following categories of data subject:

The Processor’s processing of Data on behalf of the Controller may be performed when this Data Processing Agreement commences. Processing has the following duration:

Appendix 2 – List of approved sub-processors

Appendix 3 – Technical and organizational measures of the Processor

The Processor has implemented and maintains the following technical and organizational measures to protect the security, confidentiality and integrity of the Personal Data:

Security Operations

Human Resource Security

Data Center Security

Physical Access Control

System Access Control

Device and Network Security

Secure Development

Application Level Security

Protection from Data Loss and Corruption

Third party management