This Data Processing Addendum ("DPA") supplements the Terms of Service between Atol, Inc. ("Atol" or "Processor") and the customer entity ("Controller") and governs Atol's processing of personal data on behalf of the Controller in connection with the Atol platform. In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to data protection matters.
This DPA is entered into as of the date the Controller first accepts the Terms of Service (the "Effective Date").
Atol agrees to:
The Controller provides general written authorization for Atol to engage sub-processors. Atol will maintain a current list at /subprocessors and will give the Controller at least 14 days advance notice of any new or replacement sub-processor by updating that page and, where the Controller has registered an email address, by email.
The Controller may object to a new or replacement sub-processor on reasonable data protection grounds within 14 days of notice. If a reasonable objection cannot be resolved, the Controller may terminate the applicable service on 30 days written notice without penalty.
Atol requires all sub-processors to comply with data protection obligations substantially equivalent to this DPA. Atol remains fully liable to the Controller for the acts and omissions of its sub-processors.
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, Atol implements and maintains the following measures:
Atol will promptly notify the Controller if it receives a request from a data subject exercising rights under applicable Data Protection Law. Atol will not respond to such requests on the Controller's behalf without the Controller's written authorization but will cooperate and provide reasonable assistance to enable the Controller to respond within the applicable time limits.
The Atol API provides endpoints for Controller-initiated deletion and export of end-user data. Device data erasure is described in the technical documentation at /docs/privacy.
The Controller instructs Atol to transfer personal data to the United States (where Atol is headquartered and its primary infrastructure operates) and, where sub-processors are engaged, to any country in which those sub-processors operate.
For transfers from the EEA or UK to Atol (as Processor), the parties incorporate the Standard Contractual Clauses adopted by the European Commission under Decision 2021/914/EU, Module 2 (Controller to Processor), including the UK Addendum issued by the ICO where applicable. These SCCs are incorporated by reference as if set out in full in this DPA, with the following selections: (a) Clause 7 (docking clause) -- applicable; (b) Clause 11 (redress) -- the optional language is not included; (c) Clause 17 -- governing law: Republic of Ireland (for EU transfers) / England and Wales (for UK transfers); (d) Clause 18 -- courts: the competent courts of the relevant governing law jurisdiction.
Upon the Controller's written request no more than once per year (and at any time following a Security Incident), Atol will provide the Controller with relevant security documentation (including any current third-party audit reports, certifications, or SOC 2 reports) to verify compliance with this DPA, subject to reasonable confidentiality obligations.
If documentation is insufficient, the Controller may request an audit conducted by the Controller or a mutually agreed third-party auditor, at the Controller's expense, with at least 30 days written notice and subject to reasonable conditions to protect Atol's confidential information and other customers' data.
Upon termination or expiry of the Terms of Service (or on the Controller's earlier written request), Atol will, at the Controller's election, either delete or return all personal data processed on the Controller's behalf and delete existing copies, unless retention is required by applicable law.
Deletion will be completed within [PLACEHOLDER: e.g. '90 days'] of the termination date. Atol will confirm completion in writing. Append-only audit logs that cannot be selectively deleted will be pseudonymized or suppressed from any further processing within the same period.
Atol will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Security Incident affecting the Controller's personal data. Notification will be sent to the email address registered for the Controller's account or via the security contact designated in the console.
The notification will include, to the extent then known: the nature of the incident, the categories and approximate number of data subjects and personal data records concerned, the likely consequences, and the measures taken or proposed. Atol will provide further information as it becomes available.
The Controller is responsible for notifying supervisory authorities and data subjects as required under applicable Data Protection Law. Atol will cooperate and provide reasonable assistance.
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service, except where applicable Data Protection Law provides otherwise.
Where both parties are liable to a data subject for damage caused by a breach of GDPR, they will be jointly and severally liable as provided by GDPR Art. 82, subject to the right to claim back the part of compensation corresponding to the other party's part of responsibility.
To the extent the CCPA/CPRA applies, Atol agrees: