This Data Processing Agreement including its schedules (the "DPA") is incorporated into and forms part of the agreement between the Customer and Maven Clinic, Co. ("Maven") under which Maven provides the Services (the "Agreement"). Unless otherwise defined herein, capitalized terms used in this DPA have the same meaning given to them under the Agreement. Customer enters into this DPA on behalf of itself and, to the extent required under Applicable Data Protection Laws, in the name and on behalf of its Affiliates permitted to use the Services under the Agreement.
WHEREAS, in connection with providing services to Customer under the Agreement, Maven will have access to and will process for or on behalf of Customer, Personal Data owned and belonging to Customer;
WHEREAS, the Parties wish to enter into this DPA in connection with their respective obligations under Data Protection Laws;
NOW THEREFORE, in consideration of the mutual covenants and promises contained herein, and for other good and valuable consideration, the sufficiency of which is hereby acknowledged, the Parties agree that the terms and conditions set forth below shall be added to the Agreement:
-
DEFINITIONS. For purposes of this DPA, the following terms shall have the meanings set out below. Capitalized terms used in this DPA but not defined herein shall have the meanings given to them in the Agreement.
“Applicable Data Protection Laws” means any data protection or privacy laws applicable to Maven’s Processing of Persona Data pursuant to the Agreement, including (as applicable, based on the location of Customer and/or the Data Subject):
-
the (i) California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), (ii) Virginia Consumer Data Protection Act, (iii) Colorado Privacy Act, (iv) Connecticut Data Privacy Act, (v) Utah Consumer Privacy Act, (vi) Oregon Consumer Privacy Act, (vii) Texas Data Privacy and Security Act, (viii) Montana Consumer Data Privacy Act and (ix) once effective, similar comprehensive privacy laws in other U.S. states (together, “U.S. Data Protection Laws”);
-
the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and any applicable national implementing laws;
-
the UK General Data Protection Regulation (“UK GDPR”) and the UK Data Protection Act 2018 (“UK DPA”); and
-
the Canadian Canada’s Personal Information Protection and Electronic Documents Act 2000 (“PIPEDA”)
“Personal Data” means any information relating to an identified or identifiable natural person that Maven receives or obtains directly from and processes at the direction of Customer in connection with the Services performed under the Agreement.
“Personal Data Breach” shall have the meaning as defined under Applicable Data Protection Laws.
“Processing” shall have the meaning as defined under Applicable Data Protection Laws.
“SCCs” means the standard contractual clauses for Processors annexed to the European Commission’s Decision (EU) 2021/914 of 4 June 2021, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj; as may be amended, superseded or replaced.
“Subprocessor” means any third party that Maven engages to process Personal Data in order to provide the Services.
-
ROLES AND SCOPE OF PROCESSING.
-
Scope. This DPA applies to the extent that Maven processes any Personal Data as described in Schedule 1 of this DPA.
-
Role of the Parties. The Parties agree that, for purposes of this DPA, Client is a controller or business (as applicable) with respect to the processing of the Personal Data, and Maven will process the Personal Data only as a processor or service provider (as applicable) on behalf of and pursuant to the instructions of Client. Each Party will comply with all laws, rules and regulations applicable to it in the performance of this DPA, including any Applicable Data Protection Laws.
-
Description of Processing. The subject matter of the data processing is the performance of the Services as described in the Agreement. Schedule 1 of this DPA sets out the nature, duration, and purpose of the processing (the “Permitted Purposes”), the types of Personal Data that Maven processes, and the categories of data subjects whose Personal Data is processed.
-
Customer Obligations. Customer agrees to:
-
not instruct Maven to use or disclose Personal Data in any manner that would not be permissible under Data Protection Laws if done directly by Customer;
-
provide to Maven the minimum amount of Personal Data necessary for the accomplishment of the processing purpose;
-
warrant that it has obtained and will obtain any consents, authorizations, and/or other legal permissions required under Data Protection Laws and other Applicable Law for the disclosure of Personal Data to Maven. Customer will notify Maven of any changes in, or revocation of, the permission by a data subject to use or disclose his or her Personal Data, to the extent that such changes may affect Maven’s use or disclosure of Personal Data; and
-
not impose any restriction on the use or disclosure of Personal Data that will restrict Maven’s use or disclosure of Personal Data under the Agreement or this DPA unless such restriction is required by Applicable Law or Maven grants its written consent, which consent will not be unreasonably withheld.
-
DATA SECURITY.
-
Technical and Organizational Measures. Maven will implement and maintain appropriate technical and organizational measures designed to protect the Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, theft, alteration, or disclosure, as set forth in Schedule 2.
-
Personal Data Breach. As required by Applicable Data Protection Laws, Maven will provide notice to Client upon confirming any Personal Data Breach, within the time period required by law but in no event later than 72 hours after confirming such Personal Data Breach. Such notice shall include the information required under Applicable Data Protection Laws to the extent such information is reasonably available to Maven. Maven’s response to, or notice of, a Personal Data Breach is not an acknowledgment by Maven of any fault or liability. Maven agrees to investigate any Personal Data Breach, and use commercially reasonable efforts to identify, prevent, mitigate, and remedy the effects.
-
Audits. Maven shall, upon Customer’s reasonable request, provide Customer with reports of qualified, independent third-party audits and validation of Maven’s technical and organizational measures (collectively, “Audit Reports”). To the extent Customer’s audit requirements under Applicable Data Protection Laws cannot reasonably be satisfied through the Audit Reports, documentation, or other compliance information generally available to Maven’s Customers, Maven will promptly respond to Customer’s additional reasonable security or audit questionnaires, provided that Customer not exercise this right more than once annually (unless Customer is required to provide this information to a data protection authority, or Maven has experienced a Personal Data Breach).
-
DATA SUBJECT REQUESTS. Maven will promptly notify Customer if it receives a Data Subject Request. Unless otherwise required by Data Protection Laws, Maven will not respond to a Data Subject Request, other than directing the data subject to Customer. Maven shall provide Customer with reasonable cooperation to assist Customer to fulfill any Data Subjects Requests relating to the processing of Personal Data under this DPA.
-
DATA TRANSFERS. Customer acknowledges and agrees that Maven may transfer and process Personal Data to and in the United States and anywhere else in the world where Maven operates. Maven shall at all times ensure such transfers are made in compliance with the requirements of Applicable Data Protection Laws and this DPA, including the provisions of Section 8 below regarding transfers.
-
SUB-PROCESSORS. Customer provides a general authorization to Maven to engage Subprocessors to provide services on its behalf, including those Subprocessors listed in Schedule 3. Where Maven subcontracts its obligations under the Agreement, Maven must take steps to ensure that each Subprocessor provides sufficient guarantees that it will comply with Data Protection Laws and this DPA. Maven shall enter into a written agreement with the Subprocessor incorporating terms which are no less protective than those set out in this DPA, and Maven will remain responsible for the performance of this DPA by any such Subprocessor.
-
JURISDICTION-SPECIFIC TERMS.
-
Europe. In connection with the Services, the Parties anticipate that Maven (and its Subprocessors) may process outside of the European Economic Area (“EEA”) certain Personal Data protected by the GDPR. In such instances, the Parties agree that such processing shall be supported by the following adequacy mechanisms (to the extent still supported and applicable), in order of priority: (a) Maven’s participation in the EU-U.S. Data Privacy Framework; and (b) the SCCs, as detailed below. To the extent that there is any conflict between such mechanisms, the Data Privacy Framework shall prevail, to the extent it is still supported and applicable.
-
SCCs. To the extent the SCCs apply, they shall apply completed as follows:
- Module Two shall apply.
- In Clause 7, the optional docking clause shall apply.
- In Clause 9, option 2 (General Written Authorization) shall apply.
- In Clause 11, the optional independent dispute resolution clause shall apply, as specified in more detail in Maven’s privacy policy.
- In Clause 17, option 1 shall apply, using the law of Ireland.
- in Clause 18(b), disputes shall be resolved as set forth in the Agreement, or, if that jurisdiction is not an EU Member State, then the courts in Ireland.
- Annex 1 shall be deemed completed with the information in Schedule 1 of this DPA, with Customer serving as Data Exporter and Maven as Data Importer.
- Annex 2 shall be deemed completed with the information in Schedule 2 of this DPA.
-
United Kingdom.
- In relation to Personal Data that is protected by the UK GDPR, the SCCs, completed as set out above in Section 7.1.1 of this DPA, shall apply to transfers of such Personal Data, except that:
- The SCCs shall be deemed amended as specified by the UK Addendum issued by the UK Information Commissioner’s Office, which shall be deemed executed between Customer and Maven;
- Any conflict between the terms of the SCCs and the UK Addendum shall be resolved in accordance with Section 10 and Section 11 of the UK Addendum;
- For the purposes of the UK Addendum, Tables 1 to 3 in Part 1 of the UK Addendum shall be deemed completed using the information contained in Schedules 1 and 2 of this DPA; and
- Table 4 in Part 1 of the UK Addendum shall be deemed completed by selecting “neither party.”
-
California. Customer and Maven agree that: (i) Maven shall not retain, use or disclose the Personal Data for any purpose other than the Permitted Purposes; (ii) Personal Data was not “sold” to or “shared” with Maven and Maven will not “sell” or “share” the Personal Data (as defined by the CCPA); and (iii) Maven shall not retain, use or disclose the Personal Data outside of the direct business relationship between Customer and Maven.
-
LIMITATIONS OF LIABILITY. Each Party’s liability, taken together in the aggregate, arising out of or related to this DPA (including the SCCs) whether in contract, tort or under any other theory of liability, shall be subject to the limitations and exclusions of liability in the Agreement, and any reference in provisions to the liability of a party means the aggregate liability of that party and all of its Affiliates under and in connection with the Agreement and this DPA together.
SCHEDULE 1: DETAILS OF PROCESSING
Categories of Data Subjects:
Customer’s employees and their dependents.
Categories of Personal Data:
Customer’s Eligibility File, which may contain some or all of the following Personal Data, depending on which Maven services are covered:
- Employee ID number
- Employee business email address
- First and last name
- Date of birth
- Home address
- Gender
- Employee office state location
- Employee office country location
- Employee start date
- Employee eligibility date
- Medical plan name
- Insurer name
- Coverage level
- Dependent id(s)
Nature and Purpose of Processing:
Customer shall send Maven a file which will contain the information of those Customer employees and their dependents deemed eligible to register for Maven’s services (“Eligibility File”). Maven shall use the Eligibility File to determine whether individual data subjects are eligible for the Services, or otherwise as instructed by Customer.
Duration of Processing:
For the duration of the Services.
SCHEDULE 2: TECHNICAL AND ORGANISATIONAL MEASURES
Maven (the “Data Recipient”) shall at all times implement and maintain the security measures identified below:
-
Minimum Requirements: the pseudonymisation and encryption of the Personal Data where appropriate and feasible; the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
-
Backup: the ability to restore the availability and access to the Personal Data in a timely manner in the event of a physical or technical incident;
-
Testing: a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing;
-
Physical Access Control: the prevention of unauthorised persons gaining access to data processing systems;
-
Logical Access Control: the prevention of data processing systems being used without authorization;
-
Data Access Control: ensuring that persons entitled to use a data processing system gain access only to such Personal Data as they are entitled to access in accordance with their legitimate access rights, and that, in the course of processing or use and after storage, Personal Data cannot be read, copied, modified or deleted without authorization;
-
Data Transfer Control: ensuring that the Personal Data cannot be read, copied, modified or deleted without authorization during electronic transmission, transport or storage on storage media, and that the target entities for any transfer of the Personal Data by means of data transmission facilities can be established and verified;
-
Entry Control: ensuring the establishment of an audit trail to document whether and by whom the Personal Data have been entered into, modified in, or removed from data processing systems;
-
Control of Instructions: ensuring that the Personal Data is processed solely in accordance with Customer’s instructions;
-
Cyber security: ensuring measures to secure and defend Personal Data against "hackers" and others who may seek to modify the Services or the data therein without the consent of Data Recipient or Customer, and to correct the Services to its original form in the event that it is modified without Customer’s consent;
-
Audit: Data Recipient shall, upon Customer’s reasonable request, provide Customer, or its representatives, reports of qualified, independent third-party audits and validation of Data Recipient’s privacy and security measures (collectively, “Audit Reports”). Customer will provide Data Recipient with a written report of any non-compliance with this Schedule 2 and Data Recipient agrees to promptly remedy any such non- compliance. To the extent Customer’s audit requirements under Applicable Laws cannot reasonably be satisfied through Audit Reports, documentation or compliance information Data Recipient generally makes available to its customers, Data Recipient will promptly respond to Customer's additional reasonable audit requests. Before the commencement of an audit, Customer and Data Recipient will mutually agree upon the scope, timing, duration, and control and evidence requirements. To the extent needed to perform the audit, Data Recipient will make the processing systems, facilities and supporting documentation relevant to the Processing of Personal Data by Data Recipient available. Customer shall not have access to any data from Data Recipient's other customers or to Data Recipient's systems or facilities not involved in the processing of Customer's Personal Data.
-
Physical Security: Data Recipient must maintain and enforce at Data Recipient’s physical sites safety and physical security procedures that are at least equal to best industry standards and practices for such types of service locations. Specifically:
- Physical access granted via badge access at a minimum.
- Physical access must be restricted and recorded and access allowed based on a need-to- know basis.
- Ensure background check procedure for all personnel accessing data processing systems.
- (i) ensure restriction of physical access to the data processing systems (including its information systems, equipment and the respective operating environments) to authorized employees only; (ii) adequately protect the physical plant and contained supporting infrastructure environment for information systems; (iii) provide supporting utilities for information systems; (iv) protect information systems against environmental hazards; and (v) provide appropriate environmental controls in facilities containing information systems.
- Ensure restriction of physical access to (network and server) equipment and other infrastructural systems and devices used for rendering the Services to specified employees only and must adequately monitor these restrictions.
-
Information Protection Policy: Data Recipient must maintain an information protection/security policy and ensure on-going compliance controls are enabled according to SOC2 or NIST security standards.
-
Logging Information: Ensuring Security and Audit logs be retained for 360 days and access to security logs are restricted to authorized persons.
-
External Penetration Testing: Data Recipient must validate their security controls using a third-party auditor at least once a year and after changes to the infrastructure that may impact Confidentiality, Integrity and Availability principles set forth by Art. 32 of GDPR.
SCHEDULE 3: SUBPROCESSORS
LIST OF SUB-PROCESSORS
A current list of Maven Clinic’s sub-processors can be found at: https://www.mavenclinic.com/subprocessors.