This Data Processing Addendum (“DPA”) forms an integral part of the Company’s Terms of Use, available at
https://bik.ai/bik-terms, the master service agreement or similar agreement (including any exhibits, appendices, annexes, terms, orders or policies referenced therein) (“Agreement”), entered into by and between Bikayi, Inc. (the “Company”) and Customer that governs Customer’s use and Company’s provision of Company’s Services (identified either as “Services” or otherwise in the applicable agreement, and hereinafter defined as “Services”) to reflect the parties’ agreement with regard to the Processing of Personal Data.
By signing the Agreement, Customer enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws and Regulations, in the name and on behalf of its Authorised Affiliates, if and to the extent Bikayi, Inc. processes Personal Data for which such Authorised Affiliates qualify as the Controller. For the purposes of this DPA only, and except where indicated otherwise, the term "Customer" shall include Customer and Authorised Affiliates. All capitalised terms not defined herein shall have the meaning set forth in the Agreement.
In the course of providing the Services to Customer pursuant to the Agreement, Company may Process Personal Data on behalf of Customer, and the Parties agree to comply with the following provisions with respect to any Personal Data, each acting reasonably and in good faith. For the avoidance of doubt, each reference to the DPA in this DPA means this DPA including its Schedules.
1. Definitions
Affiliate means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. Control, for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
Authorized Affiliate means any of Customer's Affiliate(s) which (i) is subject to the data protection laws and regulations of the European Union, the European Economic Area and/or their member states, and (ii) is permitted to use the Services pursuant to the Agreement between Customer and Company.
CCPA means the California Consumer Privacy Act 2018, Cal. Civ. Code § 1798.100 et seq., and its implementing regulations, as the same may be amended from time to time.
Controller means the entity which determines the purposes and means of the Processing of Personal Data.
Customer Data means all electronic data or information submitted by or on behalf of Customer to, or collected from the Customer by Company.
Data Protection Laws and Regulations means all laws and regulations, including GDPR and CCPA, as well as other similar applicable worldwide data protection laws applicable to a party in its use or provision of the Services, in connection with the Processing of Personal Data under the Agreement.
Data Subject means the identified or identifiable natural person to whom Personal Data relates.
Data Subject right means any right afforded to a Data Subject under Data Protection Laws and Regulations, including the rights to access, rectify, restrict the Processing of Personal Data, erasure (including the right to be forgotten), data portability, objecting to the Processing, or to not be subject to an automated individual decision making.
GDPR means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
Personal Data means any information relating to an identified or identifiable natural person where such data is Customer Data.
Processing means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Processor means the entity which Processes Personal Data on behalf of the Controller
Personal Data Breach means a security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data, transmitted, stored or otherwise Processed by Company or its Sub-processors of which the Company becomes aware.
Security, Privacy and Architecture Datasheet means the Security, Privacy and Architecture Datasheet for the Company Services, as updated from time to time.
Standard Contractual Clausesmeans the agreement by and between Customer and Bikayi, Inc. pursuant to the European Commission's decision on Standard Contractual Clauses for the transfer of personal data to processors established in third countries which do not ensure an adequate level of data protection, a copy of which can be found at
https://bik.ai/scc Sub-processor means any Processor engaged by the Company or its Affiliates engaged in the Processing of Personal Data.
2. Processing of personal data
3. Rights of data subjects
4. Company personnel
5. Sub-processors
6. Security
6.1 Controls for the Protection of Customer Data. Company shall maintain appropriate technical and organisational measures for protection of the security (including protection against Personal Data Breach), confidentiality and integrity of Customer Data, as set forth in the Security, Privacy and Architecture Datasheet attached hereto as Schedule 1. Company regularly monitors compliance with these measures. Customer is responsible for reviewing the information made available by Company relating to data security and making an independent determination as to whether the Services meet Customer's requirements and legal obligations under Data Protection Laws and Regulations. Customer acknowledges that the security measures described within the Security, Privacy and Architecture Datasheet are subject to technical progress and development and that Company may update or modify such documents from time to time provided that such updates and modifications do not result in a material decrease of the overall security of the Services during a subscription term.
6.2 Customer Data Incident Management and Notification. Company maintains security incident management policies and procedures specified in the Security, Privacy and Architecture Datasheet and shall notify Customer without undue delay after becoming aware of a Personal Data Breach. Company shall provide information to Customer necessary to enable Customer to comply with its obligations under Data Protection Laws and Regulations. The content of such communication to Customer will (i) include the nature of Processing and the information available to Company, and(ii) take into account that under applicable Data Protection Laws and Regulations, Customer may need to notify regulators or individuals of the following: (a) a description of the nature of the Personal Data Breach including, where possible, the categories and approximate number of individuals concerned, and the categories and approximate number of Personal Data records concerned; (b) a description of the likely consequences of the Personal Data Breach; and (c) a description of the measures taken or proposed to be taken to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects. Company shall make commercially reasonable efforts to identify the cause of such Personal Data Breach and take those steps as Company deems necessary and reasonable in order to remediate the cause of such Personal Data Breach to the extent the remediation is within Company's reasonable control. The obligation to remediate the cause of a Personal Data Breach shall not apply to Personal Data Breaches that are caused by Customer or Customer's Users.At the written request of the Customer, Company shall reasonably cooperate with Customer and take such commercially reasonable steps, as are agreed by the parties or necessary under Data Protection Laws, to assist in the investigation, mitigation and remediation of each such Personal Data Breach, at Customer's sole expense.
6.3 Third-Party Certifications and Audits. Company has obtained the third-party certifications and audits set forth in the Security, Privacy and Architecture Datasheet. Upon Customer's written request at reasonable intervals, and subject to the confidentiality obligations set forth in the Agreement, Company shall allow for and contribute to audits and inspections (Audits) conducted by Customer (or Customer's independent, third-party auditor that is not a competitor of Company and that is subject to confidentiality obligations substantially similar to those set forth in the Agreement), by providing any information regarding Company's compliance with the obligations set forth in this DPA in the form of a copy of Company's then most recent third-party audits or certifications, as applicable. Customer may perform an Audit remotely or on-site, up to one (1) time per year, with at least three (3) weeks' advance written notice, unless otherwise required by Customer's regulators or applicable law. If Customer requests an on-site Audit, the following terms shall apply: (a) such Audit shall be limited to facilities operated by Company and shall not exceed one (1) business day; (b) before the commencement of any such on-site Audit, Customer and Company shall mutually agree upon the scope and timing of the Audit; (c) Customer shall reimburse Company for actual expenses and costs incurred in connection with such Audit.Customer shall use (and ensure that each of its mandated auditors uses) its best efforts to avoid causing any damage, injury or disruption to Company's premises, equipment, personnel and business while its personnel are on those premises in the course of such an audit or inspection. All such audits shall be subject to the confidentiality obligations set forth in the Agreement. Additionally, Company need not give access to its premises for the purposes of such an audit or inspection: (a) to any individual unless he or she produces reasonable evidence of identity and authority; (b) to any competitor of Company or (c) outside Company's normal business hours.
7. Return and deletion of customer data
8. Authorised affiliates
9. Limitation of liability
10. European specific provisions
11. California Consumer Privacy Act of 2018 (CCPA)
11.1 Effective as of January 1, 2020, the following shall apply for Customers subject to the CCPA:
11.1. All references to Data Protection Laws and Regulations in this DPA shall be deemed to include a reference to the CCPA;
11.1. All references to Personal Data in this DPA shall be deemed to include Personal Information, as defined in the CCPA, provided such data is Customer Data;
11.1. All references to 'Controller' in this DPA shall be deemed to be references to Business, as defined in the CCPA;
11.1. All references to 'Processo' in this DPA shall be deemed to be references to Service Provider, as defined in the CCPA;
11.1. Any capitalised term used in this Section 11 but not defined herein, shall have the meaning set forth in the CCPA.
11.2 Cmpany does and shall not Sell any Personal Information.
11.3 Cmpany will Process Personal Information solely as set forth in Section 2.3 (the 'Business Purpose'), and shall not retain, use, or disclose the Personal Information for any purpose other than the Business Purpose.
11.4 ompany does not receive any Personal Information from Customer as consideration for Company's provision of the Services.
11.5 ompany certifies that it understands the restrictions set forth in this Section 11 and will comply with them.
12. Retention of Customer Data
13. Governing Law & Settlement of Disputes
| Customer | | Bikayi, Inc | |
|---|
| Signature | | Signature | |
| Printed | | Printed | Sonakshi Nathani |
| Title | | Title | CEO |
| Date | | Date | |
Schedule 1
We take data security, privacy and compliance very seriously. We have put in several standards and diligently follow protocols to protect our customer’s user data. Company follows a “security by design” philosophy. Which means, Company does not treat security as an afterthought. The “security by design” team consists of product managers, architects, engineers and compliance consultants, who review privacy policies and security measures regularly. Company complies with the two most critical facets of GDPR, “Right to Erasure” and “Right to Restriction of Processing”. Under "Right To Erasure" of GDPR, Company has exposed an API which will remove all the personal data associated with specific users who have requested to be erased. To comply with the data tracking opt-out requests of users under "Right To Restriction of Processing" of GDPR, the latest Company SDKs are now shipped with the methods to opt out of data tracking. Company is committed towards abiding by increased transparency regarding the collection and processing of personal information.
Confidentiality
Company gives high priority to customer information safety. To ensure the same, the Company has enabled encryption across all our Data volumes where customer data resides. All the database activities are strictly monitored and audited on time-to-time basis.
Availability
Company maintains high uptime up to 99.9% for all Company services and applications to help the customers utilize the platform to the highest and make use of redundant resources to make sure the services are available to Company customers without any interruptions. Company takes backups continuously and follows disaster recovery plans to ensure the Company platform is available even in case of unexpected scenarios.
Few of the key practices Company follows under Security Process:
- A very strict Secure SDLC process while developing any application.
- In-depth VAPT (vulnerability assessment and penetration testing) for any application going into production.
- Regular assessments on all our infrastructure on a quarterly basis.
- Continuous audits on all our database machines to ensure high security standards
- Regular info-sec assessments on all Company Corp assets to ensure the security at End Point level.
- Support for SSO via SAML 2.0 and acts as a service provider (SP) for SSO.
- Compliance with the California Consumers Protection Act (CCPA).
- RBAC for all Company internal application/software(s) to ensure only authorised personnel perform privileged actions.
Schedule 2
SUB-PROCESSORS USED IN CONNECTION WITH THE COMPANY’s SERVICES This Schedule describes the Sub-processors material to Company’s provision of the Company Services. (effective as of the Effective Date; subject to change) Last Modified: December 2022 Bikayi, Inc. (“Company”) uses certain Sub-processors in connection with its provision of the Company Services to its customers. Following is the full list of Sub-processors that Company uses in its provision of the Company Services. Depending upon a Customer’s use of the Company Services e.g., geographical location of the Customer, not all Sub-Processors will be needed to deliver the Company Services. As used herein, Sub-processors refer to Affiliates of Company and third parties who process Personal Data on behalf of Company. Third parties engaged by Company as Sub-processors are subject to written agreements that contain confidentiality and security commitments not less protective than those in the DPA with respect to the protection of Personal Data to the extent applicable to the nature of the services provided by such Sub- processor. Company remains responsible for the acts and omissions of its Sub-processors pursuant to the DPA. Terms used herein without definition are used as defined in the MSA.
| Sl. No. | List of third party processor | Service Provided | Corporate Headquarters | Service Provided |
| 1 | zohobooks. | Accounting tool | Chennai,India | Customer financial information |
| 2 | outplay. | Marketing tool | Delaware, USA | Customer contact data |
| 3 | moengage. | Marketing tool | San Francisco, CA | Customer contact data |
| 4 | sales navigator. | Marketing tool | Templeton, CA | Customer contact data |
| 5 | Atlassian-Jira. | Productivity Tool | Sydney, Australia | Track of tech tasks; No Customer Data |
| 6 | Slack | Communication Tool | San Francisco, CA | Intra company knowledge exchange; No customer data |
| 7 | Quickbooks | Accounting tool | Mountain View, USA | Customer financial information |
| 8 | Amplitude | Analytics Tool | Burlington, USA | Product usage data; Customer contact data |
| Sl. No. | List of third party processor | Service Provided | Corporate Headquarters | Service Provided |
| 1 | Google Cloud Platform | Cloud hosting | Mountain View, USA | All platform data |
| 2 | Freshworks | Customer support tool | Delaware, USA | Customer support requests, Customer Contact data |
| 3 | Amazon AWS | Cloud hosting | Seattle, USA | Information associated with delivery of website content |
| 4 | WhatsApp | Messaging | California, USA | Customer contact data |
| 5 | SendGrid | Messaging | Denver, USA | Customer contact data |
| 6 | TrustSignal | Messaging | Noida, India | Customer contact data |
| 7 | Firebase | Messaging | California, USA | Customer contact data |
| 8 | Amplitude | Analytics Tool | Burlington, USA | Product usage data; Customer contact data |
SCHEDULE 3
DETAILS OF THE PROCESSING
Nature and Purpose of Processing
Company will Process Personal Data as necessary to perform the Services pursuant to the Agreement, as further specified in the Documentation, and as further instructed by Customer in its use of the Services.
Duration of Processing
Subject to Section 7 of the DPA, Company will Process Personal Data for the duration of the Agreement, unless otherwise agreed upon in writing.
Categories of Data Subjects
Customer may submit Personal Data to the Services, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not limited to, Personal Data relating to the following categories of Data Subjects:
(i) Prospects, customers, End-Users, business partners and vendors of Customer (who are natural persons)
(ii) Employees or contact persons of Customer’s prospects, customers, business partners and vendors
(iii) Customer’s Users authorized by Customer to use the Services
Data exporter
Customer may submit Personal Data to the Services, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not limited to the following categories of Personal Data:
1. Name
2. Email address
3. Mobile Number
4. Device data
5. Address
Details relevant for Appendix 1 to Standard Contractual Clauses
Data exporter
The data exporter is the Customer or a Customer Authorised Affiliate, i.e., a company that wishes to manage its customer engagement via the Company Services.
Data importer
The data importer is Company, a company which processes Personal Data upon the instruction of the data exporter in accordance with the terms of the Agreement.
Data subjects
The personal data transferred concern the following categories of data subjects: the data subjects listed above in “Categories of Data Subjects”, in particular the data exporter’s Users of the Company Services and End- Users.
Categories of data
The personal data transferred concern the following categories of data: Application data, email address, location data, application settings and preferences, campaign data, connections with social networks or other platforms, device data.
Special categories of data (if appropriate)
The personal data transferred concern the following special categories of data: N/A
Processing operations
The personal data transferred will be subject to the following basic processing activities: The Personal Data transferred is stored by the data importer and accessible by the data exporter within a web interface to enable the data exporter to segment their user audience and create targeted multi-channel messaging.