REV.
November 1, 2024

Data Processing Details

Note: this Annex 1 (Data Processing Details) to the DPA includes certain details of the Processing of Customer Personal Data, including as required by Article 28(3) GDPR and to populate the Appendix to the SCCs in the manner described in Paragraph 2.2(d) of Annex 3 (European Annex).

Categories of Data Subjects:

Any individuals whose Personal Data is comprised within data submitted to the Service by or on behalf of Customer under the Agreement, which will depend upon the nature of the use/deployment of those Service and any systems, platforms or technologies with which Customer integrates the Service and the configuration(s) of such integration(s) – but may include:

  • Customer’s own employees, service providers, business partners, vendors, and any natural person(s) authorized by Customer to use the Service.
  • End-Users authorized by Customer to access and use the Service whose data is processed in any databases connected to the Service or otherwise Processed or made available to the Service. Where any of the above is a business or organization, it includes their Personnel or other relevant natural persons. Each category includes current, past and prospective Data Subjects.

Categories of Personal Data:

Any Personal Data comprised within data submitted to Service by or on behalf of Customer under the Agreement, which will depend upon the nature of the use/deployment of those Service and any systems, platforms or technologies with which Customer integrates the Service and the configuration(s) of such integration(s) – but may include:

  • Personal details – for example any information that identifies the Data Subject and their personal characteristics, name and username.
  • Contact details – for example email address, telephone details and other contact information.
  • Communication details – for example, communications during support services, such as messaging support, email support, and phone support.
  • Technological details – for example internet protocol (IP) addresses, unique identifiers and numbers (including unique identifier in tracking cookies or similar technology), pseudonymous identifiers, imprecise location data, internet / application / program activity data, and device IDs and addresses.
  • Any other details – for example any Personal Data relating to relevant Data Subjects included in text fields or contained in any databases submitted to the Service or otherwise Processed by Crescendo to perform the Services, or mad

Sensitive Categories of Data, and associated additional restrictions/safeguards:

Categories of sensitive data:

None – as noted in Section 3.4 of the Agreement, Customer agrees that Restricted Data, must not be submitted to the Services.

Additional safeguards for sensitive data:

N/A

Frequency of transfer:

Processing operations required in order to provide the Service in accordance with the Agreement.

Purpose of the Processing:

Customer Personal Data will be processed as set forth in Section 3 of this DPA.

Duration of Processing / Retention Period:

For the period determined in accordance with the Agreement and DPA, including Section 10 of the DPA.

Transfers to (sub)-processors

Transfers to Sub-Processors are as, and for the purposes, described from time to time in the Sub-Processor Site (as may be updated from time to time in accordance with Section 8 of the DPA).