1. Scope#
This DPA applies whenever TopMod processes Personal Data as a processor on behalf of the Customer in connection with the Services.
2. Roles of the parties#
The Customer acts as the Data Controller (or Processor acting on behalf of another controller, where applicable). TopMod acts as the Data Processor and will process Personal Data only on the Customer's documented instructions unless otherwise required by law.
3. Processing details#
The subject matter, duration, nature and purpose of processing, categories of Personal Data and categories of Data Subjects are described in Annex 1 to this DPA.
4. Customer obligations#
The Customer is responsible for ensuring it has a lawful basis for processing Personal Data, providing any required notices, obtaining necessary consents where applicable and ensuring its instructions comply with applicable Data Protection Laws.
5. TopMod obligations#
TopMod will: (a) process Personal Data only on documented instructions; (b) ensure personnel are subject to confidentiality obligations; (c) implement appropriate technical and organisational measures; (d) assist the Customer with Data Subject requests where reasonably requested; (e) notify the Customer without undue delay after becoming aware of a Personal Data Breach; and (f) make available information reasonably necessary to demonstrate compliance with this DPA.
6. Subprocessors#
The Customer authorises TopMod to engage subprocessors to support delivery of the Services. TopMod will ensure subprocessors are bound by written agreements providing substantially equivalent data protection obligations. A current list of subprocessors is published on TopMod's website and will be updated in accordance with the change-notification process described in that list.
7. International transfers#
Where Personal Data is transferred internationally, TopMod will implement appropriate safeguards, including Standard Contractual Clauses or other recognised transfer mechanisms where required by applicable law.
8. Security#
TopMod will maintain commercially reasonable administrative, technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
9. Data subject requests#
Where TopMod receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Customer, TopMod will, unless prohibited by law, promptly notify the Customer and will not respond except on the Customer's documented instructions.
10. Personal data breaches#
TopMod will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and, where reasonably practicable, within forty-eight (48) hours after becoming aware of it.
TopMod may provide information in phases as further details become available and will provide reasonable updates concerning the nature, impact, containment and remediation of the Personal Data Breach.
11. Audits#
TopMod will provide information reasonably necessary to demonstrate compliance with this DPA. Where required by applicable law, the Customer may conduct an audit no more than once annually upon reasonable prior written notice, during normal business hours and subject to appropriate confidentiality obligations. Existing third-party audit reports or certifications may be provided in satisfaction of this obligation where appropriate.
12. Return or deletion of data#
Upon termination of the Services, TopMod will return or delete Customer Personal Data in accordance with the Subscription Terms, unless retention is required by applicable law.
13. Liability#
The liability of each party arising under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the TopMod Subscription Terms.
14. Order of precedence#
In the event of any inconsistency between this DPA and the TopMod Subscription Terms in relation to the processing of Personal Data, this DPA prevails to the extent of that inconsistency.
Annex 1 — Details of processing#
Controller
Customer
Processor
TestMod, Inc. trading as TopMod
Subject matter
Provision of the TopMod Services.
Duration
For the Subscription Term and any agreed retention period.
Purpose
Provision, support, maintenance and security of the Services.
Categories of data subjects
- Customer employees
- Customer contractors
- Authorised users
- End users where applicable
Categories of personal data
- Account information
- Contact details
- Authentication data
- Customer Data, including recordings, video, audio, screenshots, attachments, bug reports and related project content
- Usage, telemetry and diagnostic information
Special categories
Only where submitted by or on behalf of the Customer.
Processing operations
Collection, hosting, storage, organisation, retrieval, transmission, analysis (where instructed), deletion and other processing necessary to provide the Services.