AppointmentCore Data Protection Addendum

This Data Processing Addendum (“Addendum”) supplements the End User License Agreement (“License Agreement”) entered into by and between AppointmentCore and Customer for the purchase and use of AppointmentCore’s online products and services (“Services”). Together, the License Agreement and this Addendum are referred to as the “Agreement.”

It is the intention of the Parties that this Addendum forms part of the License Agreement, subject to Section 2 (“Applicability”), and is incorporated into the License Agreement by reference.

The terms used in this Addendum shall have the meanings set forth below. Capitalized terms not otherwise defined in this Addendum shall have the meanings given to them in the License Agreement. Except as modified by this Addendum, the License Agreement remains in full force and effect.

In consideration of the mutual obligations set out herein, the parties agree as follows.

1. Definitions

1.1

In this Addendum, the following terms shall have the meanings set out below and related terms shall be construed accordingly:

1.1.1 “Applicable Laws” means applicable laws and regulations relating to privacy, data protection, and the Processing of Client Personal Data.

1.1.2 “Client” means the Customer, as defined in the License Agreement, including its affiliates to the extent those affiliates are authorized to use the Services under the License Agreement.

1.1.3 “Client Personal Data” means any Personal Data Processed by AppointmentCore or a Subprocessor on behalf of the Client pursuant to or in connection with the Services.

1.1.4 “Data Protection Laws” means the GDPR and, to the extent applicable to the Processing of Client Personal Data under the Agreement, other applicable privacy and data protection laws.

1.1.5 “EEA” means the European Economic Area.

1.1.6 “EU Data Protection Laws” means Regulation (EU) 2016/679 (“GDPR”) and applicable laws of the European Union or EEA Member States implementing, supplementing, or relating to the GDPR.

1.1.7 “GDPR” means Regulation (EU) 2016/679, the General Data Protection Regulation.

1.1.8 “Restricted Transfer” means a transfer of Client Personal Data from the EEA to a country or recipient for which an applicable Data Protection Law requires additional safeguards or a recognized transfer mechanism.

1.1.9 “Services” means the services and other activities supplied or carried out by or on behalf of AppointmentCore pursuant to the License Agreement.

1.1.10 “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission under Commission Implementing Decision (EU) 2021/914 of June 4, 2021, as amended, replaced, or superseded from time to time.

1.1.11 “Subprocessor” means a third party appointed by or on behalf of AppointmentCore that Processes Client Personal Data on behalf of the Client in connection with the Services.

1.2

The terms “Controller,” “Data Subject,” “Member State,” “Personal Data,” “Personal Data Breach,” “Processing,” “Processor,” and “Supervisory Authority” shall have the meanings given to them under the GDPR where the GDPR applies.

1.3

The word “include” means “include without limitation,” and related terms shall be construed accordingly.

2. Applicability

2.1

This Addendum applies to AppointmentCore’s Processing of Client Personal Data on behalf of the Client where that Processing is subject to Data Protection Laws requiring a controller-processor agreement or equivalent contractual protections.

Where EU Data Protection Laws do not apply to particular Client Personal Data, the provisions of this Addendum relating specifically to the GDPR or EU international data transfers will not apply to that Processing unless otherwise required by Applicable Laws.

2.2

This Addendum becomes effective when it is incorporated into or otherwise forms part of the License Agreement and replaces any earlier AppointmentCore data processing addendum between the parties covering the same Processing.

3. Processing of Client Personal Data

3.1

To the extent AppointmentCore Processes Client Personal Data on behalf of the Client, the Client acts as Controller and AppointmentCore acts as Processor, except where the Client itself acts as a Processor, in which case AppointmentCore will act as its Subprocessor.

Nothing in this Addendum prevents AppointmentCore from acting as an independent Controller for Personal Data that AppointmentCore Processes for its own legitimate business purposes, such as account administration, billing, security, fraud prevention, or direct communications with its customers, where permitted by Applicable Laws.

3.2

AppointmentCore shall:

3.2.1 Process Client Personal Data only on documented instructions from the Client, including with regard to transfers of Personal Data to a third country or international organization, unless AppointmentCore is required to Process the Personal Data by Applicable Laws. Where permitted by law, AppointmentCore will inform the Client of that legal requirement before carrying out the Processing;

3.2.2 Process Client Personal Data as necessary to provide, maintain, support, and secure the Services and otherwise as instructed through the Client’s use and configuration of the Services;

3.2.3 comply with obligations directly applicable to AppointmentCore as a Processor under applicable Data Protection Laws; and

3.2.4 inform the Client if AppointmentCore becomes aware that an instruction, in AppointmentCore’s reasonable opinion, infringes applicable Data Protection Laws.

3.3

The Client instructs AppointmentCore, and authorizes AppointmentCore to instruct its Subprocessors, to Process Client Personal Data as reasonably necessary to provide the Services.

The Client also authorizes AppointmentCore and its Subprocessors to Process Client Personal Data in the countries in which AppointmentCore and its authorized Subprocessors operate, subject to Section 12 of this Addendum.

3.4

The Client is responsible for:

3.4.1 providing lawful instructions to AppointmentCore;

3.4.2 determining the lawfulness of the Client’s collection and use of Personal Data through the Services;

3.4.3 providing any notices and obtaining any consents required by Applicable Laws; and

3.4.4 avoiding the collection of Personal Data through configurable fields where the Client does not have an appropriate lawful basis for doing so.

The Client may provide AppointmentCore with additional information reasonably required to support the parties’ obligations under this Addendum by contacting [email protected].

4. AppointmentCore Personnel

AppointmentCore shall take reasonable steps to ensure that personnel authorized to access Client Personal Data are subject to appropriate confidentiality obligations.

Access to Client Personal Data shall be limited to personnel who require access for legitimate business purposes in connection with the Services, support, security, or AppointmentCore’s obligations under the Agreement.

5. Security

5.1

Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of the Processing, as well as the risks to the rights and freedoms of individuals, AppointmentCore shall maintain appropriate technical and organizational measures designed to provide a level of security appropriate to the risk.

Those measures shall take into account the requirements of Article 32 GDPR where applicable.

5.2

AppointmentCore’s security measures may include, as appropriate to the relevant systems and risks, measures relating to access control, authentication, confidentiality, protection of data in transmission and storage, logging and monitoring, backups and recovery, vulnerability and patch management, personnel security, vendor management, and incident response.

AppointmentCore does not represent that any particular security framework, certification, technology, or control applies unless expressly identified in the Agreement or separate written documentation provided by AppointmentCore.

5.3

AppointmentCore may update its technical and organizational measures from time to time to reflect changes in technology, risks, and the Services, provided that AppointmentCore does not materially reduce the overall level of protection for Client Personal Data during the applicable term of the Services.

A current summary of applicable technical and organizational measures may be provided to the Client upon reasonable written request, subject to appropriate confidentiality and security restrictions.

6. Subprocessing

6.1

The Client provides AppointmentCore with general written authorization to appoint Subprocessors in connection with the Services.

AppointmentCore shall maintain information identifying its current Subprocessors that Process Client Personal Data and shall make that information available to the Client upon request or through an AppointmentCore-maintained subprocessor list.

6.2

AppointmentCore shall enter into a written agreement with each Subprocessor that imposes data protection obligations appropriate to the Processing and no less protective in substance than the obligations applicable to AppointmentCore under this Addendum, to the extent required by applicable Data Protection Laws.

AppointmentCore remains responsible for the performance of its Subprocessors’ data protection obligations to the extent required by applicable Data Protection Laws.

6.3

AppointmentCore shall provide prior written notice of a new Subprocessor that will Process Client Personal Data.

Unless otherwise agreed, the Client may object to the appointment of a new Subprocessor on reasonable data protection grounds by providing written notice to AppointmentCore within ten (10) days after AppointmentCore’s notice.

If the Client makes a timely objection, the parties will work in good faith to address the Client’s reasonable concerns.

6.4

AppointmentCore shall take reasonable steps before engaging a Subprocessor to determine that the Subprocessor is capable of providing protections appropriate to the nature of the Client Personal Data and Processing involved.

The extent of AppointmentCore’s review may take into account the nature of the services provided by the Subprocessor, the type of Personal Data involved, and the risks associated with the Processing.

7. Data Subject Rights

7.1

Taking into account the nature of the Processing, AppointmentCore shall provide reasonable assistance to the Client, through appropriate technical and organizational measures where reasonably possible, to support the Client’s obligations to respond to requests from Data Subjects under applicable Data Protection Laws.

7.2

If AppointmentCore receives a request directly from a Data Subject relating to Client Personal Data, AppointmentCore shall:

7.2.1 notify the Client without undue delay where AppointmentCore can reasonably identify the relevant Client; and

7.2.2 not respond to the substance of the request except on documented instructions from the Client or where required by Applicable Laws.

7.3

AppointmentCore is not responsible for completing requests involving Personal Data held solely in systems controlled by the Client or by third-party services selected, configured, or controlled by the Client.

AppointmentCore will provide reasonable assistance relating to Client Personal Data held in AppointmentCore-controlled systems.

8. Personal Data Breach

8.1

AppointmentCore shall notify the Client without undue delay after becoming aware of a Personal Data Breach affecting Client Personal Data.

8.2

Taking into account the nature of the Processing and the information available to AppointmentCore, AppointmentCore shall provide information reasonably available to it that the Client may need to meet applicable breach notification obligations.

Where complete information is not available at the time of the initial notification, AppointmentCore may provide additional information in phases as it becomes reasonably available.

8.3

AppointmentCore shall reasonably cooperate with the Client in investigating, mitigating, and remediating a Personal Data Breach affecting Client Personal Data, taking into account the nature of the Processing and the information available to AppointmentCore.

8.4

AppointmentCore’s notification of or response to a Personal Data Breach shall not be construed as an admission of fault or liability.

9. Data Protection Impact Assessments and Prior Consultation

Taking into account the nature of the Processing and information available to AppointmentCore, AppointmentCore shall provide reasonable assistance, upon written request and subject to appropriate confidentiality obligations, with data protection impact assessments and prior consultations with Supervisory Authorities that the Client reasonably determines are required under Articles 35 or 36 GDPR in relation to AppointmentCore’s Processing of Client Personal Data.

AppointmentCore is not required to provide legal advice to the Client or disclose information that would compromise the security of the Services, the confidentiality of other customers, or AppointmentCore’s legal privileges.

10. Deletion or Return of Client Personal Data

10.1

Upon termination or expiration of the Services, AppointmentCore shall, at the Client’s choice and to the extent required by applicable Data Protection Laws, delete or return Client Personal Data in AppointmentCore-controlled systems, unless Applicable Laws require AppointmentCore to retain the Personal Data.

10.2

The Client may also request deletion of Client Personal Data during the term of the Agreement to the extent supported by the Services and required by Applicable Laws.

10.3

Client Personal Data contained in backups may remain until deleted or overwritten through AppointmentCore’s normal backup retention cycle, provided that such data remains protected and is not used for ordinary business purposes.

Where retained data is restored from backup, AppointmentCore shall apply applicable deletion instructions where reasonably practicable.

10.4

AppointmentCore is not responsible for deleting Personal Data from a calendar, CRM, email account, or other third-party system controlled by the Client or another third party where AppointmentCore does not control that system or its retention functionality.

11. Audit and Compliance Information

11.1

AppointmentCore shall make available to the Client information reasonably necessary to demonstrate AppointmentCore’s compliance with its applicable Processor obligations under Article 28 GDPR and this Addendum.

11.2

Where the information made available under Section 11.1 is not reasonably sufficient to demonstrate compliance, AppointmentCore shall allow for and reasonably contribute to an audit conducted by the Client or an independent auditor appointed by the Client, subject to the following conditions:

11.2.1 the Client shall provide reasonable advance written notice;

11.2.2 the audit shall be conducted during normal business hours and in a manner designed to avoid unreasonable disruption to AppointmentCore’s business;

11.2.3 the auditor shall be subject to appropriate confidentiality obligations;

11.2.4 the audit shall be limited to systems, records, and Processing relevant to Client Personal Data and the requirements of this Addendum;

11.2.5 the audit shall not require AppointmentCore to disclose information relating to other customers, information that would create a material security risk, or legally privileged information; and

11.2.6 unless required by a Supervisory Authority, following a Personal Data Breach affecting Client Personal Data, or otherwise reasonably necessary to establish compliance, the Client shall not conduct more than one such audit in any twelve-month period.

11.3

AppointmentCore may satisfy reasonable audit requests, in whole or in part, by providing relevant policies, security documentation, questionnaires, independent assessment reports, certifications, or other evidence that AppointmentCore has available.

Any audit will be at the Client’s expense unless otherwise required by Applicable Laws or agreed in writing by the parties.

12. International Data Transfers

12.1

AppointmentCore shall ensure that any Restricted Transfer of Client Personal Data is made using a transfer mechanism permitted by applicable Data Protection Laws.

Such mechanisms may include an applicable adequacy decision, an approved data privacy framework where AppointmentCore or the relevant recipient is eligible and currently certified, the Standard Contractual Clauses, or another lawful transfer mechanism available under applicable Data Protection Laws.

Nothing in this Addendum represents that AppointmentCore participates in any particular certification or data privacy framework unless AppointmentCore separately confirms that participation in writing.

12.2 Standard Contractual Clauses

Where a Restricted Transfer requires use of the Standard Contractual Clauses, the applicable provisions of the SCCs adopted under Commission Implementing Decision (EU) 2021/914 are incorporated into this Addendum and form part of the Agreement.

The parties agree that:

12.2.1 where the Client is a Controller and AppointmentCore is a Processor, Module Two (Controller to Processor) shall apply;

12.2.2 where the Client is a Processor and AppointmentCore acts as its Subprocessor, Module Three (Processor to Processor) shall apply;

12.2.3 Clause 7, the optional docking clause, shall apply;

12.2.4 for Clause 9, Option 2, general written authorization for the use of Subprocessors, shall apply, and AppointmentCore shall provide at least ten (10) days’ prior notice of an intended addition or replacement of a Subprocessor;

12.2.5 the optional language in Clause 11 shall not apply;

12.2.6 for Clause 17, the governing law shall be the law of Ireland, provided that law permits third-party beneficiary rights under the SCCs;

12.2.7 for Clause 18, disputes arising from the SCCs shall be resolved by the courts of the Member State identified in Section 12.2.6; and

12.2.8 the information contained in Exhibit A, Exhibit B, and Annex 2 of this Addendum shall complete the corresponding annexes of the SCCs to the extent applicable.

The SCCs shall be considered executed when the Client becomes bound by this Addendum.

12.3 Transfer Assessments

Where the SCCs apply, each party shall provide the other with information reasonably necessary for the parties to evaluate the circumstances of the Restricted Transfer and comply with the requirements of the SCCs.

AppointmentCore shall take reasonable steps to assess information available to it concerning laws and practices applicable to AppointmentCore as data importer and shall implement supplementary measures where reasonably necessary to satisfy the requirements of the SCCs.

AppointmentCore is not required to disclose privileged legal advice, confidential information relating to other customers, or information that would reasonably be expected to compromise the security of the Services.

12.4 Government Requests

Where required by the applicable SCCs, AppointmentCore shall notify the Client of legally binding requests from public authorities for access to transferred Client Personal Data unless AppointmentCore is prohibited by law from providing such notice.

AppointmentCore shall review the legality of such requests and challenge them where required by and consistent with the applicable SCCs.

12.5 Conflict

If there is a conflict between this Addendum or the License Agreement and the applicable Standard Contractual Clauses, the Standard Contractual Clauses shall control with respect to the Restricted Transfer.

13. General Terms

13.1

Except as expressly modified by this Addendum, all terms of the License Agreement remain in full force and effect, including applicable provisions relating to governing law, dispute resolution, jurisdiction, and limitation of liability, to the maximum extent permitted by Applicable Laws.

Nothing in the License Agreement or this Addendum shall limit rights or obligations under the Standard Contractual Clauses where such limitation would be inconsistent with the SCCs.

13.2

If any provision of this Addendum is found invalid or unenforceable under Applicable Laws, that provision shall be interpreted or replaced, to the extent permitted by law, so as to most closely achieve its intended effect, and the remainder of the Addendum will continue in effect.

13.3

If AppointmentCore determines that it can no longer meet a material obligation under this Addendum relating to Client Personal Data, AppointmentCore shall notify the Client where required by Applicable Laws and shall take reasonable and appropriate steps to address the noncompliance or cease the affected Processing.

13.4

In the event of a conflict between this Addendum and the License Agreement concerning the Processing of Client Personal Data, this Addendum shall control to the extent of the conflict.


EXHIBIT A

Details of Processing

This Exhibit A describes the Processing of Client Personal Data for purposes of Article 28(3) GDPR and, where applicable, Annex I of the Standard Contractual Clauses.

Subject Matter of the Processing

The subject matter of the Processing is the provision of the Services requested by the Client, including scheduling, appointment management, calendar synchronization and integrations, account-related functionality, and related support.

Duration of Processing

AppointmentCore Processes Client Personal Data for the duration of the Client’s use of the Services and for such additional period as reasonably necessary to complete deletion, return, backup expiration, or other Processing permitted or required under the Agreement or Applicable Laws.

Nature and Purpose of Processing

Processing may include collecting, receiving, recording, organizing, storing, retrieving, consulting, transmitting, synchronizing, displaying, updating, deleting, and otherwise using Client Personal Data as necessary to provide, maintain, support, and secure the Services in accordance with the Client’s instructions.

Categories of Data Subjects

Depending on the Client’s use of the Services, Data Subjects may include:

·      Client account users and administrators;

·      Client employees and contractors;

·      prospects, leads, and customers of the Client;

·      individuals scheduling or attending meetings;

·      meeting invitees and other contacts whose information is submitted to or synchronized with the Services; and

·      other individuals whose Personal Data the Client chooses to Process through the Services.

Categories of Personal Data

Depending on the Client’s use and configuration of the Services, Client Personal Data may include:

·      names;

·      email addresses;

·      telephone numbers;

·      account and profile information;

·      profile images;

·      time zone and location information;

·      scheduling and calendar availability;

·      meeting dates, times, participants, titles, and related scheduling information;

·      information synchronized from calendars, CRM systems, email services, or other integrations selected by the Client; and

·      information entered by the Client or Data Subjects into configurable fields.

Special Categories of Personal Data

The Services are not designed to require the Processing of special categories of Personal Data under Article 9 GDPR as part of ordinary scheduling activities.

The Client shall not intentionally use configurable fields or other Service functionality to collect or Process special categories of Personal Data unless the Client has determined that such Processing is lawful, appropriate for the Services, and supported by an applicable lawful basis and safeguards.

Frequency of Transfer

Transfers may occur on a continuous or recurring basis for the duration of the Client’s use of the Services, depending on the Client’s configuration and use of integrations.

Client Rights and Obligations

The Client’s rights and obligations are set out in the License Agreement and this Addendum.


EXHIBIT B

Subprocessors

AppointmentCore uses third-party Subprocessors to support the provision of the Services.

The current list of Subprocessors that Process Client Personal Data, together with relevant information regarding their processing purpose and location, is maintained by AppointmentCore and will be made available to the Client upon request or at:

SubprocessorPurposeProcessing location
Amazon Web Services, Inc.Cloud infrastructure, hosting and storageUnited States / applicable AWS regions
Twilio Inc. / SendGridTransactional email deliveryUnited States / applicable regions
Zendesk, Inc.Customer support servicesUnited States / applicable regions
IntercomCustomer support servicesUnited States
Chargebee Inc. Customer billingUnited States
Rackspace TechnologyInfrastructure / hosting servicesUnited States
Google LLCInternal email serviceApplicable Google regions

The following third-party services are optional integrations that are enabled only when configured by the Customer. AppointmentCore transmits Customer Personal Data to these providers solely at the Customer’s direction.

IntegrationTypical Purpose
ActiveCampaignCRM / Marketing Automation
GoTo MeetingVideo conferencing
Google CalendarCalendar synchronization
HubSpotCRM
Keap (formerly Infusionsoft)CRM
Microsoft ExchangeCalendar synchronization
Microsoft Outlook / Office 365Calendar synchronization
Microsoft TeamsMeetings
Redtail CRMCRM
RingCentralVoice / Video
SalesforceCRM
WebexVideo conferencing
ZapierWorkflow automation
ZoomVideo conferencing

The Client provides general authorization for AppointmentCore to use the Subprocessors identified on the current list, subject to Section 6 of this Addendum.


ANNEX 1

Standard Contractual Clauses

For any Restricted Transfer for which the Standard Contractual Clauses are required, the parties incorporate the applicable clauses adopted under Commission Implementing Decision (EU) 2021/914.

The applicable module and options are identified in Section 12.2 of this Addendum.

The parties agree that the Standard Contractual Clauses are binding on them as if set out in full in this Addendum.

A copy of the applicable Standard Contractual Clauses shall be made available to the Client upon request or through the European Commission’s official publication of Commission Implementing Decision (EU) 2021/914.

For purposes of Annex I.A to the SCCs:

Data exporter:
The Client identified in the License Agreement.

Role:
Controller under Module Two, or Processor under Module Three, as applicable.

Data importer:
AppointmentCore
2637 E Atlantic Blvd, #18940
Pompano Beach, FL 33062
United States of America

Role:
Processor under Module Two, or Subprocessor under Module Three, as applicable.

Contact for data protection matters:
[email protected]

For purposes of Annex I.B to the SCCs, the categories of Data Subjects, categories of Personal Data, nature and purpose of Processing, frequency, duration, and subject matter of the transfers are described in Exhibit A.

For purposes of Annex I.C to the SCCs, the competent Supervisory Authority shall be determined in accordance with Clause 13 of the applicable SCCs.

ANNEX 2

Technical and Organizational Measures

AppointmentCore maintains technical and organizational measures designed to provide a level of security appropriate to the risk associated with the Processing of Client Personal Data.

The measures applicable to the Services may include the following, based on the systems involved and the nature of the Processing:

Access and Confidentiality

Access to Client Personal Data is restricted to authorized personnel with a legitimate business need. Personnel with access are subject to appropriate confidentiality obligations.

Protection of Data in Transit

AppointmentCore uses security measures designed to protect Client Personal Data transmitted over public networks.

Protection of Stored Data

AppointmentCore uses storage and hosting security controls appropriate to the nature and risk of the Personal Data Processed.

Logging and Monitoring

AppointmentCore uses available application, infrastructure, and service-provider logging and monitoring capabilities to support the operation and security of the Services.

Backup and Recovery

AppointmentCore uses backup and recovery capabilities appropriate to the systems used to provide the Services.

Backups may be retained according to normal backup rotation schedules and remain subject to applicable confidentiality and security measures.

Incident Response

AppointmentCore maintains processes for identifying, escalating, investigating, containing, and responding to security incidents affecting the Services.

Where an incident constitutes a Personal Data Breach affecting Client Personal Data, AppointmentCore will comply with Section 8 of this Addendum.

Vulnerability and Patch Management

AppointmentCore addresses identified vulnerabilities and security updates based on factors including severity, exploitability, exposure, and operational impact.

AppointmentCore does not commit to a particular vulnerability remediation period unless expressly agreed in writing.

Subprocessor and Service Provider Controls

AppointmentCore applies the Subprocessor requirements set out in Section 6 and uses contractual protections appropriate to the nature of the Processing.

Review of Measures

AppointmentCore may modify these measures as its systems, providers, technologies, and risks change, provided that it does not materially reduce the overall level of protection for Client Personal Data during the term of the Services.