Navigation
AtData logo

NATURE OF PROCESSING UNDER THE ATDATA SERVICES

AtData processes Client Personal Data in connection with the Services. AtData’s role varies depending on the Service and the type of Client Personal Data: AtData acts as an independent Controller in respect of the SafeToSend Service and the ordinary personal data element of the Fraud Product (Annex A), and as a Processor on Client’s behalf in respect of Fraud Signals processed in connection with the Fraud Product (Annex B). Each Annex is described in further detail below. Capitalised terms used but not defined in this Cover Sheet have the meaning given in Section 1 (Definitions and Interpretation).

  1. Ordinary personal data – AtData as independent Controller (Annex A). AtData receives ordinary categories of Personal Data from or on behalf of Client (namely IP address, email address, postal address, name, telephone number and any other ordinary personal data processed by Client under this Addendum) and processes them as an independent Controller for the purpose of providing, maintaining, and improving the Services. The processing of these types of personal data is governed by Annex A (Controller-to-Controller Terms).
  2. Personal data subject to Article 10 GDPR – AtData as Processor (Annex B). This occurs where Client transmits Fraud Signals to AtData (whether directly or on behalf of Client’s own customers) and/or AtData receives, processes and stores Fraud Signals including for the purpose of building, training, refining and applying a fraud detection model dedicated to Client. Fraud Signals concern the commission or alleged commission of criminal offences and/or related security measures, and therefore constitute personal data under Article 10 of the UK GDPR and EU GDPR. As Client is best placed to establish the required Article 10 lawful basis, including any substantial public interest or prevention of fraud condition, AtData processes Fraud Signals strictly as a Processor on Client’s documented instructions and in reliance on Client’s lawful basis. Such processing is governed by Annex B (Controller-to-Processor Terms).

DATA PROCESSING ADDENDUM

This Data Processing Addendum, including any applicable appendices, annexes or exhibits (collectively, this “Addendum“) is entered into between the entity identified as “Client” below (“Client“) and AtData LLC (“AtData“) (each a “Party” and collectively, the “Parties“). This Addendum shall apply to the extent that AtData collects or otherwise processes Client Personal Data in connection with the performance of its obligations or the provision of Services under the Agreement. The Parties agree that this Addendum shall be incorporated by reference into and form an integral part of the Agreement.


1. DEFINITIONS AND INTERPRETATION

For the purposes of this Addendum, the following terms shall have the respective meanings ascribed to them:

The terms “Business“, “Business Purpose“, “Consumer“, “Controller“, “Data Subject“, “Processor“, “Process“, “Sale“, “Share“, and “Service Provider” and their conjugations and equivalent terms thereto have the meaning ascribed to such terms in Applicable Laws, provided that, to the extent any such term is not defined under the Canadian Privacy Laws applicable to the Personal Data in question, such term shall have the meaning ascribed to it under the EU Data Protection Laws. Capitalized terms used but not defined herein shall have the meaning ascribed to such terms in the Agreement.


2. ROLES OF THE PARTIES


3. GENERAL TERMS (APPLICABLE TO BOTH ANNEXES)

The following terms apply to AtData’s processing of Client Personal Data under both Annex A and Annex B.


ANNEX A

CONTROLLER-TO-CONTROLLER TERMS – ORDINARY PERSONAL DATA

This Annex A applies to AtData’s processing of the categories of ordinary personal data described in the Cover Sheet (including IP address, email address, postal address, name and telephone number) in connection with the Services. In respect of such data, each Party processes the other Party’s Personal Data as an independent Controller or Business.


ANNEX B

CONTROLLER-TO-PROCESSOR TERMS – FRAUD SIGNALS SUBJECT TO ARTICLE 10 GDPR

This Annex B applies to AtData’s processing of Fraud Signals in connection with the Fraud Product, and to any other Client Personal Data processed by AtData as a Processor under the Fraud Product. AtData processes such data as a Processor or Service Provider acting on behalf of Client (whether as Controller or Business itself, or as a Processor or Service Provider on behalf of third party Controllers or third party Businesses). References to “Fraud Signals” in this Annex B shall be read to include such other Client Personal Data where the context requires.


EXHIBIT A-1 TO ANNEX A

DESCRIPTION OF DATA PROCESSING – ORDINARY PERSONAL DATA (CONTROLLER)

The data processing activities carried out by AtData as an independent Controller under Annex A are as follows:

  1. Categories of data subjects whose personal data is transferred/processed:
    Those individuals whose contact details are provided by AtData’s customers from time to time.
  2. Personal Data transferred/processed:
    IP address, email address, postal address, name, telephone number, reference ID, and user agent.
  3. Sensitive data transferred/processed (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
    Not applicable.
  4. Nature of the processing:
    Collection, use, analysis, appending, comparison, correction, disclosure and other processing required to deliver the Services or otherwise permitted under the Agreement.
  5. Purpose of the data transfer and further processing:
    As set forth in the Agreement:
    • Fraud Product analysis of ordinary Personal Data to generate insights and outputs that are not themselves subject to Article 10 of the UK GDPR or EU GDPR;
    • Email validation whereby email addresses are determined to be deliverable or not;
    • Data appending, in which Client provides Client Personal Data to AtData and AtData provides additional Personal Data and metadata associated with the provided Client Personal Data to Client;
    • The provision of other Services as provided in the Agreement; and
    • Developing, administering, and maintaining the relationship between the Parties, including without limitation performing under the Agreement, exercising rights and obligations under the Agreement, and providing, marketing, and receiving products, services, and support.
  6. The period for which the personal data will be retained, or if that is not possible, the criteria used to determine that period:
    For the duration of the Agreement.
  7. For transfers to (sub-)processors, also specify subject matter, nature, and duration of the processing:
    The same as set forth in this Exhibit A-1 for AtData’s processing.

EXHIBIT B-1 TO ANNEX B

DESCRIPTION OF DATA PROCESSING – FRAUD SIGNALS (PROCESSOR)

The data processing activities carried out by AtData as a Processor under Annex B are as follows:

  1. Categories of data subjects whose personal data is transferred/processed:
    Individuals about whom Client transmits Fraud Signals or submits query data to AtData in connection with a Client-dedicated fraud detection model (each a “Custom Fraud Model”), typically including Client’s customers, applicants and other individuals whose activity Client is assessing for fraud.
  2. Personal Data transferred/processed:
    Name, Postal Address, Email Address, Telephone Number, and IP Address. Fraud Signals or status, including Confirmed Fraud, Rejected Suspected Fraud, Not Fraud/Good.
  3. Sensitive data transferred/processed (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
    As set out above, Fraud Signals.
  4. Nature of the processing:
    Receipt, storage, use, analysis, appending, comparison, correction, disclosure and other processing required to deliver the Services or otherwise permitted under the Agreement.
  5. Purpose of the data transfer and further processing:
    As set forth in the Agreement:
    • Building, training and refining Custom Fraud Models dedicated to Client;
    • Applying Custom Fraud Models to query data (including email addresses and other identifiers) submitted by or on behalf of Client through the Fraud Product, and returning the resulting fraud indicators or assessments to Client;
    • Storing Fraud Signals within Client’s dedicated dataset within AtData’s systems; and
    • Any other processing of Fraud Signals necessary to provide the Fraud Product to Client in accordance with the Agreement.
  6. The period for which the personal data will be retained, or if that is not possible, the criteria used to determine that period:
    For the duration of the Agreement.
  7. For transfers to (sub-)processors, also specify subject matter, nature, and duration of the processing:
    The same as set forth in this Exhibit B-1 for AtData’s processing.

EXHIBIT C

Technical and Organizational Measures Designed to Ensure the Security of Personal Data 

The purpose of this Information Security Exhibit is to set forth the terms and conditions governing the handling, use, access, processing, and storage of Client Materials between Client and AtData. This Exhibit delineates the specific responsibilities and obligations of AtData under the Agreement.

  1. For the purposes of this Exhibit C, the following terms shall have the following meaning:
    • AtData Security Breach means any actual unauthorized access to or use of the Client Personal Data in the possession or control of AtData or its agent.
    • Client Materials means Client Data, software, and any materials, documentation, processes, models, reports, technologies, methodologies, or other items developed, provided and/or licensed by Client to AtData in connection with the Agreement, excluding AtData’s data.
    • Information Security Program means a comprehensive set of policies, procedures, and documentation regarding systems designed to protect the confidentiality, integrity, and availability of Client Materials from unauthorized access, disclosure, alteration, or destruction.
  2. Information Security Program Requirement:
    AtData must maintain an Information Security Program that adheres to an industry-recognized framework, such as ISO/IEC 27001, or the NIST Cybersecurity Framework, and any Applicable Laws, and that adequately protects Client Materials. This Information Security Program must: (i) protect the security and confidentiality of the Client Materials; (ii) protect against anticipated threats or hazards to the security or integrity of the Client Materials; (iii) protect against unauthorized access or use of the Client Materials that could cause significant harm or inconvenience to Client; and (iv) ensure the ongoing effectiveness of controls.
    AtData’s Information Security Program will include as a minimum:
    • Training and Awareness. AtData shall require all personnel to participate in information security training and awareness sessions at least annually, and track completion of training for all personnel.
    • Identification, Authentication and Authorization. Each user of any device will have a uniquely assigned user ID and password to enable individual authentication, and such ID will remain confidential and be removed promptly upon termination or transfer of the individual.  Authentication mechanisms will be designed to protect user accounts from known attack methods. Appropriate level of authentication implemented shall be proportionate to the sensitivity of the data.  Authorized personnel, including but not limited to privileged users, shall only have the level of access required to perform their job functions.  All remote and wireless access to Client Data or Devices will use a multi-factor authentication process prior to being allowed connection to AtData’s network. AtData will maintain controls designed to provide adequate segregation of duties among personnel, including access to systems and networks.
    • Network Security and Encryption. AtData will safeguard the confidentiality and integrity of all Client Data being transmitted over any form of data network and maintain strong, industry-standard encryption techniques for all cases in which Client Data is transmitted over any public data network.  AtData’s Internet connections will be protected with dedicated, industry-recognized firewalls that are configured and managed consistent with industry standards. AtData shall not make any internal or private Internet Protocol (IP) address publicly available or natively routed to the Internet.
    • Vulnerability Management. AtData shall implement controls designed to protect against malicious code and/or malware, and to prevent transferring malicious code to Client’s systems. AtData will use security measures to protect Devices that house Client Data to reduce the risk of infiltration, hacking, and access penetration by or exposure to an unauthorized third party.  All Devices will be kept current with appropriate security-specific system patches.  AtData will perform or require the performance of penetration tests in accordance with AtData policies and common industry practice to detect any vulnerabilities. Identified vulnerabilities will be remediated based on risk.
    • Intrusion, Detection and Prevention. AtData will use security measures to protect telecommunications system(s) and any Device used to reduce the risk of infiltration, hacking, access penetration by or exposure to a third party.
    • Physical Security. Client Materials will be stored only in physically secure locations.
    • Logging and Monitoring. AtData will keep audit logs that capture access to Client Data, new user adds, attempts to change security configurations, system start up, back up and shut down, and invalid login attempts.  Audit logs will be retained by AtData in a protected state for a period consistent with common industry practice, with processes in place to review periodically to detect intrusions, unauthorized access, unintended activities, malicious software or attempts of these or other actions that could compromise the security of systems processing Client Data.
    • Security Incidents Monitoring and Management. AtData will establish processes and procedures for identifying and responding to security violations and unusual or suspicious events and incidents to limit and mitigate damage to information assets and to permit identification and prosecution of violators. These processes and procedures will include the ability to collect, analyze, and preserve evidence in a forensically sound manner to support criminal proceedings if required.
  3. Information Stewardship and Segregation:
    AtData must logically or physically segregate Client Data from other information, so it can be easily identified.
  4. AtData Security Breaches:
    If there is an AtData Security Breach, AtData must notify Client within 24 hours after becoming aware of the AtData Security Breach to Client’s designated contact as specified in the Agreement, unless law enforcement or legal authorities restrict such notification. AtData must also:
    • Investigate the AtData Security Breach and provide Client with relevant information about it; and
    • Take commercially reasonable steps to mitigate and minimize the damage from the AtData Security Breach.
  5. Law Enforcement Requests:
    If AtData receives a request from law enforcement or a government authority for personal data provided by Client, AtData must attempt to redirect the authority to Client. AtData may provide Client’s contact details to the authority for this purpose. If AtData is legally required to disclose such personal information, it must notify Client before doing so, or as soon as reasonably possible afterward if prior notification is prohibited.
  6. Right to Audit:
    In addition to other audit rights in the Agreement, Client may audit AtData’s Information Security Program. Client or its designated third party may perform the audit with reasonable advance notice, no more than once annually, unless there is a reasonable belief that AtData has materially failed to comply with the Agreement. The audit will be subject to AtData’s confidentiality agreement.
  7. Remediation:
    If an audit reveals that AtData is not materially complying with the Agreement, AtData must promptly address the non-compliance and provide evidence of remediation to Client. AtData must also use commercially reasonable efforts to fix any errors or material control deficiencies identified in the audit.
Let's Talk