Data processing agreement

The GDPR Article 28 terms for business customers, with the EU Standard Contractual Clauses and the UK Addendum built in.

Last updated Effective [Effective date] Questions: [email protected]
Template, not live data. Draft for review. Confirm bracketed items and have counsel review before publishing.

In short

  • For data in your Flows, you are the controller and Dium is your processor.
  • We process data only on your instructions, keep it confidential and apply the measures in Annex II.
  • 30 days' notice before any new subprocessor, with a right to object.
  • EU and UK transfers are covered by the 2021 Standard Contractual Clauses and the UK Addendum.
  • Accept it in the app or order form. Need a signed copy? Email [email protected].

Scope and how to accept

This Data Processing Agreement (DPA) is part of the agreement between [Legal entity name] (Dium) and a business customer (the Customer) for the Dium service. It applies when Dium processes personal data on the Customer's behalf and the GDPR, UK GDPR, Swiss data protection law, or US state privacy laws apply.

The Customer accepts this DPA by clicking to accept it in the app or order form, by signing an order that refers to it, or by continuing to use Dium for business after we have made it available [COUNSEL: confirm acceptance mechanism; in-app click-through is not built yet]. If you need a countersigned copy for your records, email [email protected] with your company name and Flow address and we will return a signed PDF. No separate e-signature tool is needed.

If this DPA conflicts with the Terms, this DPA wins for data protection. If the Standard Contractual Clauses conflict with this DPA, the Clauses win.

Roles of the parties

For personal data in the Customer's Flows (members, posts, messages, Pages, sessions), the Customer is the controller, or a processor acting for its own client, and Dium is its processor or subprocessor.

Dium is an independent controller for data it needs to run the platform across all Flows: sign-in and identity, platform-wide safety (such as global suspension), billing and legal records. Our Privacy Policy covers that data. [COUNSEL: confirm this role split].

Processing only on instructions

Dium processes Customer personal data only on the Customer's documented instructions, including for transfers. The agreement, this DPA and the Customer's use of Dium's settings (for example choosing who can join, or deleting a Flow) are those instructions. If the law requires other processing, Dium will tell the Customer first unless the law forbids it. Dium will tell the Customer if it believes an instruction breaks data protection law.

For US state laws, Dium acts as a service provider or contractor. It will not sell or share Customer personal data, retain, use or disclose it outside the direct business relationship or for any purpose other than providing Dium, or combine it with other data except as those laws allow.

Confidentiality

Dium makes sure that anyone it authorises to process Customer personal data is bound by confidentiality, and only accesses data when needed to provide or support the service, investigate abuse or security issues, or comply with law.

Security measures

Dium applies the technical and organisational measures in Annex II below, which match our security page. Dium may improve these measures over time but will not reduce the overall level of protection.

Subprocessors

The Customer gives general authorisation for Dium to use the subprocessors on our subprocessors page. Dium will give at least 30 days' notice of a new or replacement subprocessor by updating that page and emailing subscribers. The Customer can object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Customer may end the affected service and get a refund of prepaid fees for the unused period.

Dium puts data protection terms in each subprocessor contract that are at least as protective as this DPA, and stays responsible for its subprocessors.

Personal data breaches

Dium will notify the Customer without undue delay, and in any case within [breach notice hours, for example 48 or 72] hours, after becoming aware of a personal data breach affecting Customer personal data. The notice will describe what happened, the data and people affected, likely consequences, and what Dium is doing, and will be updated as we learn more. Notifying is not an admission of fault.

Help with rights requests and compliance

Taking into account the nature of the processing, Dium will help the Customer respond to requests from people using their data protection rights, and with security, breach notification, data protection impact assessments and prior consultation (GDPR Articles 32 to 36). If Dium receives a request directly from a Customer's member about Customer data, it will pass it to the Customer or tell the person to contact the Customer, unless the request is about data Dium controls.

Deletion or return at the end

When the service ends, the Customer can export its Flow content by asking [email protected] [confirm export format and turnaround]. Within [deletion window, for example 30 days] after the end, Dium will delete Customer personal data, except where the law requires us to keep it. Backups roll off within [backup retention period] and are not restored except to recover from an incident.

Information and audits

Dium will make available the information needed to show it meets Article 28. Dium does not hold a SOC 2 report or ISO 27001 certificate. We answer a written security questionnaire once a year, or after a breach, at no cost. If the questionnaire is not enough to meet a legal obligation or a regulator's request, the Customer may audit Dium once a year, with at least 30 days' notice, during business hours, under confidentiality, at its own cost, and in a way that does not expose other customers' data.

International transfers and the Standard Contractual Clauses

Dium processes data in the United States [confirm hosting region]. For transfers of personal data from the EEA to Dium, the parties incorporate the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 by reference: Module 2 (controller to processor) where the Customer is a controller, and Module 3 (processor to processor) where the Customer is a processor. We rely on the Clauses whether or not Dium ever joins the EU-US Data Privacy Framework, because that framework is under appeal at the Court of Justice of the EU.

The parties make these choices in the Clauses:

  • Clause 7 (docking clause): included.
  • Clause 9 (subprocessors): Option 2, general written authorisation, with at least 30 days' notice.
  • Clause 11 (redress): the optional independent dispute resolution wording is not used.
  • Clause 13 (supervision): the supervisory authority of the Customer's EU establishment or, if none, of its EU representative [or name a lead authority].
  • Clause 17 (governing law): Option 1, the law of [EU member state, for example Ireland].
  • Clause 18 (forum): the courts of [EU member state, for example Ireland].
  • Annexes I, II and III: the tables in this DPA and the subprocessors page.

Dium has assessed the laws of the US that apply to it as required by Clause 14 [COUNSEL: complete and date the transfer impact assessment]. Dium will challenge any government request for Customer data that it believes is unlawful, and will tell the Customer about such requests where it is allowed to.

Switzerland: the Clauses apply with the Swiss Federal Data Protection and Information Commissioner as the competent authority, and references to the GDPR read as references to the Swiss FADP.

UK International Data Transfer Addendum

For transfers from the UK, the parties incorporate the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0, in force from 21 March 2022). Table 1 (parties) is Annex I.A below. Table 2 (selected clauses) follows the Module and clause choices above. Table 3 (appendix information) is Annexes I to III. Table 4: either party may end the Addendum as allowed by its Section 19.

Annex I: parties and description of processing

A. List of parties

RoleName and addressActivitiesRole in the Clauses
Data exporterThe customer named in the order, account or partner agreement that accepts this DPAUses Dium to run one or more Flows or embed DiumController (Module 2) or processor for its own client (Module 3)
Data importer[Legal entity name], [Registered address]. Contact: [email protected]Provides the Dium community platformProcessor (Module 2) or subprocessor (Module 3)

B. Description of the transfer

ItemDetail
Data subjectsThe customer's members, invitees, speakers, sponsors and exhibitor staff, event attendees, and the customer's own staff
Categories of personal dataName, email, Moat profile data (avatar, headline, company, title, city, country, time zone), Flow membership and role, posts, direct messages, RSVPs and applications, Page analytics, IP address and device data
Sensitive dataNone intended. Members may choose to post it. Restrictions: access limited to the people the customer allows, encryption in transit, staff access only as described in Annex II
Frequency of transferContinuous, for as long as the customer uses Dium
Nature of processingHosting, storage, display, search, real-time delivery, email digests, moderation, backup and deletion
PurposeTo provide Dium to the customer and its members under the Terms
RetentionFor the term of the agreement, then deleted as set out in section 9 of this DPA
Transfers to subprocessorsAs listed on the subprocessors page, for the same purposes and duration

C. Competent supervisory authority

As set out under Clause 13 above.

Annex II: technical and organisational measures

These measures come from the way Dium is built today. The security page is the living version and must stay identical to this table.

AreaMeasure
Access control for usersPasswordless sign-in through Werify; canonical identity through Moat; HttpOnly, Secure, SameSite=Lax cookies; email-only stub sessions refused
PermissionsThree layers: platform role, Flow role (owner to viewer) and profile type; the server checks permissions before every write
Partner accessScoped API keys sent in the X-Api-Key header, compared in constant time; one-time sign-in tokens that expire in 5 minutes
Web protectionsCSRF tokens, per-request CORS allowlist, strict Content Security Policy, X-Frame-Options DENY, open-redirect allowlist, no-store caching on sign-in pages
Abuse limitsPer-IP rate limits, for example 30 replies and 30 messages per minute, 10 reports per minute, 20 uploads per minute; 3 MB upload limit
Account takeover defenceEmail changes pushed from Moat are logged but not applied
EncryptionTLS for all traffic [confirm minimum TLS version]; encryption at rest [confirm database and backup encryption at rest]
InfrastructureDatabase reached only through the OpsDB proxy with a secret key; no direct database connections from the app; internal folders blocked from the web [confirm hosting provider certifications]
Staff[confirm staff MFA, least-privilege access, access reviews and confidentiality agreements]
Backups and recovery[confirm backup frequency, location and restore testing]
Incident responseBreach notice to the customer as set out in section 7 [confirm written incident response plan]

Annex III: subprocessors

The current list, with purpose, data, location and transfer safeguard for each, is on our subprocessors page, where you can also subscribe to 30-day advance notice of changes.

Contact

Data protection questions about this DPA: [email protected]. Contract questions and signed copies: [email protected].