Joiin data processing addendum
Last updated on 7 November 2022
All capitalised terms not defined in this Addendum have the meaning set out in the Agreement.
This Addendum only applies if and to the extent Joiin processes personal data on behalf of a Customer that qualifies as a controller with respect to that personal data under the Applicable Data Protection Law (as defined below). If the Customer had entered into earlier data processing terms with Joiin, those terms are replaced by this Addendum.
1. Data protection
In this Addendum, the following terms have the following meanings:
a) controller, processor, data subject, personal data, processing (and process) and special categories of personal data have the meanings given in Applicable Data Protection Law
b) Applicable Data Protection Law means the EU General Data Protection Regulation (Regulation 2016/679) (the GDPR) and/or the UK General Data Protection Regulation (the UK GDPR) and any EU Member State and/or UK laws made under or pursuant to the GDPR and/or UK GDPR
c) Customer has the same meaning as ‘you’ in the Joiin Terms & Conditions
1.2 Relationship of the parties
The Customer (the controller) appoints Joiin as a processor to process the personal data described in Annex A (the Data) only on the controller’s documented instructions (and as per the terms set out in this Addendum) for the purposes described in the Agreement or as otherwise agreed in writing by the parties (the Permitted Purpose). Each party must comply with the obligations that apply to it under the Applicable Data Protection Law.
1.3 Prohibited data
Unless explicitly requested by Joiin to do so, the Customer will not disclose (and will not permit any data subject to disclose) any special categories of personal data to Joiin for processing.
1.4 International transfers
Joiin will not transfer the Data outside of the European Economic Area (EEA) nor the United Kingdom (UK) unless it has taken such measures as are necessary to ensure the transfer is in compliance with the Applicable Data Protection Law. Such measures may include (without limitation) transferring the Data to a recipient in a country that the European Commission and/or the UK Secretary of State (as applicable) has decided provides adequate protection for personal data (for example, Australia) or to a recipient that has executed standard contractual clauses adopted or approved by the European Commission and/or UK Secretary of State or UK Information Commissioner (as applicable). To this end, you authorise Joiin to enter into standard contractual clauses as your agent and on your behalf with any recipient of Data who is not located in an Adequate Country where this is necessary for compliance with Applicable Data Protection Law.
1.5 Confidentiality of processing
Joiin will ensure that any person it authorises to process the Data (an Authorised Person) will protect the Data in accordance with Joiin’s confidentiality obligations under the Agreement.
Joiin will implement technical and organisational measures, as set out in Annex A, which may be amended and updated from time to time, to protect the Data (i) from accidental or unlawful destruction, and (ii) loss, alteration, unauthorised disclosure of, or access to the Data (a Security Incident).
The Customer consents to Joiin engaging third-party sub-processors to process the Data for the Permitted Purpose provided that:
(i) Joiin maintains an up-to-date list of its sub-processors, which is available on request from the DPO, which it will update with details of any change in sub-processors at least 30 days prior to the change;
(ii) Joiin imposes data protection terms on any subprocessor it appoints that require it to protect the Data to the standard required by Applicable Data Protection Law.
(iii) Joiin remains liable for any breach of this Addendum that is caused by an act, error or omission of its subprocessor. The Customer may object to Joiin’s appointment or replacement of a subprocessor prior to its appointment or replacement, provided such objection is based on reasonable grounds relating to data protection. In such an event, Joiin will either not appoint or replace the subprocessor or, if Joiin determines at its sole discretion that this is not reasonably possible, the Customer may suspend or terminate the Agreement without penalty (without prejudice to any fees incurred by the Customer up to and including the date of suspension or termination).
1.8 Cooperation and data subjects’ rights
Joiin will provide reasonable and timely assistance to the Customer (at the Customer’s expense) to enable the Customer to respond to:
(i) any request from a data subject to exercise any of its rights under Applicable Data Protection Law; and
(ii) any other correspondence, enquiry or complaint received from a data subject, regulator or another third party in connection with the data processing. If any such request, correspondence, enquiry or complaint is made directly to Joiin, Joiin will promptly inform the Customer, providing full details.
1.9 Data Protection Impact Assessment
If Joiin believes or becomes aware that its processing of the Data is likely to result in a high risk to the data protection rights and freedoms of data subjects, it will inform the Customer and provide reasonable cooperation to the Customer in connection with any data protection impact assessment that may be required under Applicable Data Protection Law.
1.10 Security incidents
If it becomes aware of a confirmed Security Incident, Joiin will inform the Customer without undue delay and will provide reasonable information and cooperation to the Customer so that they can fulfil any data breach reporting obligations they may have under (and in accordance with the timescales required by) Applicable Data Protection Law. Joiin will further take reasonably necessary measures and actions to remedy or mitigate the effects of the Security Incident and keep the Customer informed of all material developments in connection with the Security Incident.
1.11 Deletion or return of data
In the event that a trial is cancelled or expires but not cancelled, Joiin will delete all related data after a period of 12 months, and if a paid subscription is cancelled, Joiin will also delete all related data after 12 months. On expiry of this period or on the Customer’s earlier request, Joiin will delete or return the Data in a manner and form decided by Joiin, acting reasonably. This requirement will not apply to the extent that Joiin is required by applicable law to retain some or all of the Data or to Data it has archived on backup systems, which Data Joiin shall securely isolate and protect from any further processing.
Annex A – Data processing schedule
1. Subject matter and duration of processing of personal data
The subject matter of personal data to be processed is that of the contacts of the Customer entered by or at the Customer's election into the Joiin platform.
The duration of processing personal data shall be for as long as we have a business relationship with the Customer, and at the end of that relationship, we will act in accordance with clause 1.11 regarding the deletion or return of such personal data.
2. Nature and purpose of processing personal data
The nature and purpose of processing personal data is to enable the functionality of the Joiin Platform as set out in the Agreement and related documentation.
3. Types of personal data processed
The types of personal data processed include:
b) email addresses
c) contact details
4. Categories of data subjects
The categories of data subjects include:
a) suppliers/service providers of Customer
b) customers/clients of Customer