Definitions
Parties
The Customer set out in the HeadBox Order Form; and
HeadBox Solutions Limited
Parties' roles
The Customer is the Data Controller; and
HeadBox Solutions Limited is the Data Processor.
Contacts
Processor – DPO@headbox.com.
Controller – as set out in the HeadBox Order Form.
Main Agreement
This Data Processing Agreement forms part of and is incorporated into the Main Agreement.
Term
This DPA will commence on the date of signature of the Main Agreement and will continue for the term of the Main Agreement.
Breach Notification Period
48 hours after becoming aware of a personal data breach.
Data Subject Rights Request Notification Period
2 working days after becoming aware of a data subject rights request.
Sub-processor Notification Period
14 days before the new sub-processor is granted access to Personal Data.
Liability Cap
Each party's aggregate liability under this DPA will not exceed the liability caps as per the Main Agreement.
Governing Law and Jurisdiction
English governing law and subject to the exclusive jurisdiction of the Courts of England and Wales.
Data Protection Laws
All laws, regulations and court orders which apply to the processing of Personal Data in connection with the Processor's services, including in the European Economic Area (EEA), the United Kingdom (UK) and the United States of America (USA).
This includes the:
European Union Regulation (EU) 2016/679 the General Data Protection Regulations (GDPR),
The UK Data Protection Act 2018 and the UK GDPR, and
California Consumer Privacy Act of 2018 (CCPA) as amended by the California Privacy Rights Act of 2020 (CPRA),
each as amended from time to time.
Services related to processing
Provision of the Services as set out in the Main Agreement, including the creation of Bespoke Avatars, account management and HeadBox user administration.
Duration of processing
Term of the Main Agreement.
Nature and purpose of processing
Management of the account, administration of users of the HeadBox platforms and Development of Bespoke Avatars and provision of virtual 3D Models and Tours (as such terms are defined in the Main Agreement)
Personal Data
The types of personal data processed are:
name;
image and likeness
voice
title and rolel; and
contact details
Data subjects
The individuals whose Personal Data will be processed are:
any person on which a Bespoke Avatar is based; and
the personnel and officers of Controller and its contractors and agents.
International Transfer Mechanism
Where HeadBox utilize the services of Sub-processors that are not in the UK, they do so in accordance with Article 49 and 46 of the UK GDPR, where required, this may include the use of the International Data Transfer Agreement issued by the Information Commissioner's Office under Section 119A of the Data Protection Act 2018.
Purpose
The Parties are entering into this Data Processing Agreement (DPA) for the purpose of processing Personal Data (as defined above).
In this DPA:
save as expressly set out herein, capitalized terms shall have the same meaning as in the Main Agreement;
adequate country means a country or territory that is recognized under Data Protection Laws from time to time as providing adequate protection for processing Personal Data;
Controller, data subject, personal data breach, process/processing, Processor and supervisory authority have the same meanings as in the Data Protection Laws; and
Sub-processor means another processor engaged by the Processor to carry out specific processing activities with Personal Data.
Obligations
Controller instructs Processor to process Personal Data in accordance with this DPA. Controller is responsible for providing all notices and obtaining all consents, licenses and legal bases required to allow Processor to process Personal Data and Controller warrants that it has done so in accordance with the Data Protection Laws.
Processor will:
only process Personal Data in accordance with this DPA and Controller's instructions (unless legally required to do otherwise)
not sell, retain or use any Personal Data for any purpose other than as permitted by this DPA and the Main Agreement
inform Controller promptly if (in its opinion) any instructions infringe Data Protection Laws;
use the technical and organizational measures described in Annex 1 when processing Personal Data to ensure a level of security appropriate to the risk involved;
notify Controller of a personal data breach within the Breach Notification Period and provide, at Controller's cost, reasonable assistance to Controller as required under Data Protection Laws in responding to it;
ensure that anyone authorized to process Personal Data is committed to confidentiality obligations
without undue delay and at Controller's cost, provide Controller with reasonable assistance with:
data protection impact assessments;
responses to data subjects' requests to exercise their rights under Data Protection Laws; and
engagement with supervisory authorities;
if requested, provide Controller with information necessary to demonstrate its compliance with obligations under Data Protection Laws and this DPA;
allow for audits of Personal Data processed in connection with the Main Agreement at Controller's reasonable request and on reasonable advance notice, provided that audits are limited to once a year and during business hours, and
return Personal Data upon Controller's written request or delete Personal Data at the end of the Term, unless retention is legally required.
The parties warrant that they and any staff and/or subcontractors will comply with their respective obligations under Data Protection Laws for the Term.
Sub-processing
Controller authorizes Processor to engage other processors (referred to in this section as Sub-processors) when processing Personal Data. Processor's existing Sub-processors are listed in Annex 2.
Processor will:
require its Sub-processors to comply with equivalent terms as Processor's obligations in this DPA;
ensure appropriate safeguards are in place before internationally transferring Personal Data to its Sub-processor; and
be liable for any acts, errors or omissions of its Sub-processors as if they were a party to this DPA.
Processor may appoint new Sub-processors provided that they notify Controller in accordance with the Sub-processor Notification Period. Such notification may be provided through any platform made available by Processor in the provision of the Services.
Controller may reasonably object in writing to any future Sub-processor. If the parties cannot agree on a solution within a reasonable time, either party may terminate the Main Agreement on written notice to the other party.
International Personal Data transfers
Processor will transfer Personal Data outside the UK, the EEA or an adequate country only on documented instructions from Controller (including services requested pursuant to the Main Agreement), unless otherwise required by law.
Where a party is located outside the UK, the EEA or an adequate country and receives Personal Data:
that party will act as the data importer;
the other party is the data exporter; and
the relevant Transfer Mechanism will apply.
Subject to terms of the relevant International Transfer Mechanism, if the data importer receives a request from a public authority to access Personal Data, it will (if legally allowed):
challenge the request and promptly notify the data exporter about it; and
only disclose to the public authority the minimum amount of Personal Data required and keep a record of the disclosure.
Other important information
Any provision of this DPA which is intended to survive the Term will remain in full force
In case of a conflict between this DPA and other relevant agreements, they will take priority in this order:
International Transfer Mechanism,
DPA,
Main Agreement.
Notices under this DPA must be in writing and sent to the Contact on the DPA's front page as may be updated by a party to the other in writing.
The Governing Law applies to this DPA and all disputes will only be litigated in the courts of the Jurisdiction.
Security measures
Technical and organizational measures to ensure the security of Personal Data:
Sub-processors
Current Sub-processors: