AirDemo Data Processing Agreement
This Data Processing Agreement (“DPA”) supplements the AirDemo Customer Agreement (the “Agreement”) entered into between the customer signing this DPA (“Customer”) and AirDemo, Inc. (“Company”). By executing this DPA, Customer agrees to its terms on behalf of itself and, to the extent required under applicable Data Protection Laws, on behalf of its Affiliates (defined below). The DPA incorporates the terms of the Agreement, and any terms not defined herein shall have the meaning given in the Agreement.
1. Definitions
1.1 “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the party in question.
1.2 “Authorized Sub-Processor” means any third-party data processor that has access to Customer’s Personal Data to assist AirDemo in fulfilling its obligations under this DPA or the Agreement.
1.3 “Customer Account Data” means Personal Data related to the management of Customer’s account with AirDemo, such as billing information and login credentials.
1.4 “Customer Usage Data” means data related to Customer’s use of the AirDemo platform, including but not limited to activity logs and service usage metrics.
1.5 “Data Exporter” refers to the Customer.
1.6 “Data Importer” refers to AirDemo.
1.7 “Data Protection Laws” refers to all applicable laws and regulations concerning the use and processing of Personal Data, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and any other relevant data protection laws.
1.8 “Services” refers to the services provided by AirDemo under the Agreement.
1.9 “Standard Contractual Clauses (SCCs)” refers to the EU and UK standard contractual clauses for data transfers, as applicable.1.10 “Personal Data” has the meaning assigned in applicable Data Protection Laws.
2. Scope and Processing of Data
2.1 The parties agree that Customer is the controller or processor of Personal Data, and AirDemo is the processor. Customer instructs AirDemo to process Personal Data to provide the Services in accordance with this DPA and the Agreement. Customer is responsible for ensuring that the processing of Personal Data complies with all applicable Data Protection Laws.
2.2 AirDemo will process Personal Data only in accordance with documented instructions from the Customer, unless required by law. AirDemo shall notify Customer if it believes any instruction violates applicable laws. The processing details, including subject matter, duration, and nature, are outlined in Exhibit A.
2.3 Upon completion of the Services, AirDemo will either delete or return Customer’s Personal Data, as instructed by Customer, unless applicable law requires continued storage. If deletion is not feasible, AirDemo will ensure the confidentiality of the retained data.
3. Confidentiality
3.1 AirDemo will ensure that its personnel authorized to process Personal Data are under confidentiality obligations and will only process the data as necessary to fulfill AirDemo’s obligations under this DPA.
3.2 AirDemo may disclose Personal Data to its advisors or third parties when required to meet legal obligations, provided that such third parties are subject to confidentiality obligations.
4. Sub-Processors
4.1 Customer agrees that AirDemo may use Authorized Sub-Processors to assist in providing the Services. AirDemo will maintain a list of sub-processors, and updates to this list will be provided to Customer upon request.
4.2 If AirDemo intends to add new sub-processors, it will notify Customer at least ten (10) days in advance. Customer may object to the new sub-processor within this period. If the parties cannot resolve the objection, Customer may terminate the affected Services.
4.3 AirDemo will ensure that its sub-processors are bound by data protection obligations that provide at least the same level of protection as this DPA.
5. Security Measures
5.1 AirDemo will implement appropriate technical and organizational measures to protect Personal Data against unauthorized access, loss, or disclosure. These measures are detailed in Exhibit B.6. Data Transfers
6.1 Customer acknowledges that AirDemo may process Personal Data outside the European Economic Area (EEA), the UK, or Switzerland. AirDemo will ensure that appropriate safeguards, such as SCCs or other legally acceptable mechanisms, are in place to protect Personal Data during such transfers.
6.2 Exhibit A provides details on data transfers, including the categories of data subjects, types of data, and nature of processing.
6.3 AirDemo and Customer will cooperate to implement supplementary measures where necessary to ensure the protection of Personal Data transferred outside the EEA, UK, or Switzerland.
7. Data Subject Rights
7.1 AirDemo will assist Customer in responding to data subject requests regarding their Personal Data (e.g., access, correction, deletion) as required by applicable laws. Customer shall be responsible for any costs incurred in providing such assistance.
7.2 If a data subject submits a request directly to AirDemo, AirDemo will promptly notify Customer and advise the data subject to submit the request directly to Customer.
8. Data Breach
8.1 In the event of a Personal Data Breach, AirDemo will notify Customer without undue delay and provide sufficient information to assist Customer in complying with its legal obligations regarding the breach.
8.2 AirDemo will take steps to mitigate the effects of the breach and prevent further breaches.
9. Audits
9.1 AirDemo will maintain records of its processing activities. Upon reasonable request and at Customer’s expense, AirDemo will make such records available for audit to demonstrate compliance with this DPA.
9.2 Any audit must be conducted during normal business hours and with prior notice, and must not interfere unreasonably with AirDemo’s business.
10. Conflict
In the event of any conflict between this DPA and the Agreement, the terms of this DPA shall prevail.
Exhibit A
Nature of Processing: AirDemo processes Personal Data to provide its Services under the Agreement, including the provision of demos, analytics, and customer support.
Duration: Personal Data will be processed for the duration of the Agreement unless otherwise specified.
Categories of Data Subjects: Employees, consultants, contractors, or agents of Customer.
Categories of Data: Customer Account Data, Customer Usage Data, and any data necessary to provide the Services.