This Dot.vu ("Vendor") Data Processing Addendum ("DPA") forms part of the agreement governing Company's use of the Services (the "Agreement"). The Agreement is either the Dot.vu Terms of Service available at https://dot.vu/terms-of-service or a separately signed master services agreement, order, or other agreement that incorporates this DPA and governs Company's use of the Services. This DPA governs Vendor's Processing of Company Personal Data on behalf of Company in connection with the Services.
We periodically update these terms. If you have an active Dot.vu subscription, we will let you know when we do via an email or in-app notification.
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
Vendor warrants and represents that, before any Vendor Affiliate Processes any Company Personal Data on behalf of any Company Group Member, Vendor's entry into this Addendum as agent for and on behalf of that Vendor Affiliate will have been duly and effectively authorised (or subsequently ratified) by that Vendor Affiliate.
Vendor and each Vendor Affiliate shall take reasonable steps to ensure the reliability of any employee, agent or contractor of any Contracted Processor who may have access to the Company Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know or access the relevant Company Personal Data, as strictly necessary for the purposes of the Agreement, and to comply with Applicable Laws in the context of that individual's duties to the Contracted Processor, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.
Vendor and each Vendor Affiliate shall provide reasonable assistance to each Company Group Member with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, which Company reasonably considers to be required of any Company Group Member by article 35 or 36 of the EU GDPR or equivalent provisions of any other Data Protection Law, in each case solely in relation to Processing of Company Personal Data by, and taking into account the nature of the Processing and information available to, the Contracted Processors.
Subject matter and duration of the Processing
Vendor Processes Company Personal Data to provide the Services described in the Agreement. Processing continues for the term of the Agreement and any period during which Vendor retains Company Personal Data in accordance with the Agreement, this DPA, or applicable law.
Nature and purpose of the Processing
The Processing may include collection, recording, organization, structuring, hosting, storage, retrieval, consultation, use, display, transmission, integration, analysis, restriction, deletion, and other operations necessary to: provide and administer the Services; host and publish Company-configured interactive content; collect and make available end-user submissions and interaction data as configured by Company; provide analytics, integrations, support, security, maintenance, and troubleshooting; and provide AI-Assisted Editing Features where enabled by Company. Vendor Processes Company Personal Data only on Company's documented instructions, including instructions given through Company's and its authorized users' use and configuration of the Services, except where otherwise required by applicable law.
Types of Company Personal Data
Depending on Company's use and configuration of the Services, Company Personal Data may include: identifiers and business contact details; account, role, and access information processed on Company's behalf; online and technical identifiers; responses, submissions, interaction and engagement information collected through Company-configured interactive content; project content, media, documents, and other materials submitted to the Services; and any other Personal Data that Company or its authorized users submit to or collect through the Services. Company determines the specific Personal Data submitted or collected.
AI-Assisted Editing Features are not intended for the Processing of Personal Data. If and to the extent AI-Assisted Editing Data contains Personal Data, only the Personal Data contained in that material constitutes Company Personal Data. The applicable categories of Personal Data and Data Subjects depend on the content submitted by Company or its authorized users.
Special categories of Personal Data
The Services do not require Company to submit special categories of Personal Data. Company shall not submit such data unless its use is permitted by the Agreement, Company has established a lawful basis and any required safeguards, and any additional written terms or configurations required by Vendor are in place.
Categories of Data Subjects
Depending on Company's use of the Services, Data Subjects may include: Company's authorized users, editors, employees, contractors, and representatives; individuals who visit or interact with content created or published through the Services; Company's customers, prospective customers, contacts, employees, applicants, suppliers, or other individuals whose Personal Data Company or its authorized users submit to or collect through the Services; and individuals depicted or identified in uploaded content.
Frequency of Processing
Continuous or intermittent, depending on Company's and its authorized users' use and configuration of the Services.
Obligations and rights of Company
Company's obligations and rights are set out in the Agreement and this DPA. Company is responsible for the lawfulness of its instructions, the Personal Data it submits or collects, required notices and consents, and its configuration and use of the Services. Vendor remains responsible for complying with its own obligations as Processor under this DPA and applicable Data Protection Laws.
Vendor's then-current Technical and Organisational Measures Schedule ("TOM Schedule") is incorporated into and forms part of this DPA. The TOM Schedule is maintained as a versioned document and will be provided to Company upon written request.
The TOM Schedule constitutes Vendor's confidential information and may be used by Company solely to assess Vendor's compliance with this DPA and applicable Data Protection Laws. This confidentiality restriction does not prevent disclosure where required by applicable law, a Supervisory Authority, the EU SCCs, the UK Addendum, or to Company's professional advisers who are subject to appropriate confidentiality obligations.
Vendor may update the TOM Schedule from time to time to reflect changes to the Services, security practices, technologies, or legal requirements, provided that an update does not materially reduce the overall security of the Services or the protection of Company Personal Data.