This DPA describes how ClearSignalQ Inc. ("ClearSignalQ," "Processor") processes Customer Personal Data on behalf of the Customer ("Controller") in connection with the Services.
"Personal Data," "Controller," "Processor," "Sub-processor," "Processing," and "Data Subject" have the meanings given under applicable data protection laws (including the GDPR and CCPA/CPRA, as applicable). "Customer Personal Data" means Personal Data that Customer submits to the Services.
For Customer Personal Data, Customer is the Controller and ClearSignalQ is the Processor. ClearSignalQ processes Customer Personal Data only to provide and support the Services and in accordance with Customer's documented instructions (including the Terms of Service and this DPA).
The Services are not intended for, and Customer shall not submit, Protected Health Information (PHI) as defined under HIPAA. ClearSignalQ is not a Business Associate and does not enter into Business Associate Agreements. Nothing in this DPA constitutes a BAA.
ClearSignalQ ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.
ClearSignalQ implements appropriate technical and organizational measures designed to protect Customer Personal Data, as described in our Security & Trust Center, including encryption in transit and at rest and access controls.
Customer authorizes ClearSignalQ to engage the sub-processors listed in our Security & Trust Center. ClearSignalQ imposes data-protection obligations on its sub-processors and remains responsible for their performance. We will provide notice of new sub-processors and a reasonable opportunity to object.
Taking into account the nature of the processing, ClearSignalQ will provide reasonable assistance to enable Customer to respond to requests from Data Subjects to exercise their rights (such as access, correction, deletion, restriction, and portability).
ClearSignalQ will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and will provide information reasonably available to assist Customer in meeting its notification obligations.
Upon termination of the Services, ClearSignalQ will delete or return Customer Personal Data in accordance with the Terms of Service and applicable law, except where retention is required by law.
Customer Personal Data may be processed in the United States and other jurisdictions where ClearSignalQ or its sub-processors operate. Where required, the parties will implement an appropriate transfer mechanism.
ClearSignalQ will make available information reasonably necessary to demonstrate compliance with this DPA and will cooperate with reasonable audit requests, subject to confidentiality and reasonable scheduling.
This DPA is governed by the laws of the State of Delaware, consistent with the Terms of Service, except where applicable data protection law requires otherwise.
To execute a signed DPA or for enterprise security review: info@clearsignalq.io.