Data Processing Agreement
This Data Processing Agreement (this “DPA”) forms part of the Master Services Agreement (the “Agreement”) between Interfere, Inc., a Delaware corporation with offices at 121 W 27th St. #501, New York, NY 10001 (“Interfere”), and the entity that has entered into the Agreement (“Customer”). Interfere and Customer are each a “Party” and together the “Parties.” This DPA is effective as of the effective date of the Agreement (the “Effective Date”). Capitalized terms not defined in this DPA have the meanings given in the Agreement.
1. Scope and Roles
This DPA applies to Interfere’s processing of Personal Data contained in Customer Data on behalf of Customer in connection with the Services (“Customer Personal Data”). “Data Protection Laws” means privacy and data-protection laws applicable to that processing. “Personal Data,” “Controller,” “Processor,” “process,” “sale,” and “sharing” have the meanings given by applicable Data Protection Laws. “Subprocessor” means a third party engaged by Interfere to process Customer Personal Data on Interfere’s behalf.
As between the Parties, Customer is the Controller of Customer Personal Data, or a Processor acting on a Controller’s behalf, and Interfere is the Processor or Subprocessor.
Interfere will process Customer Personal Data only on documented instructions from Customer, including the Agreement, this DPA, applicable Order Forms, and instructions, permissions, and automation settings given through use of the Services, unless applicable law requires other processing.
If legally permitted, Interfere will notify Customer before processing required by law. Interfere will also notify Customer if it reasonably believes an instruction violates Data Protection Laws.
Customer is responsible for the lawfulness of Customer Personal Data and its instructions, including providing required notices and obtaining required rights, consents, and permissions.
Customer will not provide categories of data prohibited by Section 3.2 of the Agreement unless expressly agreed in an Order Form, which will specify any additional safeguards required for that processing.
This DPA does not apply to Personal Data that Interfere processes as an independent Controller for its own legitimate business purposes, such as business contact, account administration, billing, security of Interfere’s own systems, accounts, and personnel, and legal-compliance data. Interfere will process such Personal Data in accordance with applicable Data Protection Laws.
2. Processing, Security, and Assistance
Interfere will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only as necessary to provide, secure, maintain, and support the Services.
Interfere will not sell or share Customer Personal Data or use it for advertising. Interfere will not use Customer Personal Data to train or improve a general-purpose or foundation model without Customer’s written consent.
Nothing in this DPA limits Interfere’s use of aggregated and de-identified service data permitted under Section 3.2 of the Agreement, provided that the data does not identify Customer, an individual, or a Customer application and does not constitute Personal Data under applicable Data Protection Laws.
Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, Interfere will maintain reasonable technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The measures are described in Schedule 2 and may evolve, provided that Interfere does not materially reduce the overall level of protection during the term.
Interfere will notify Customer without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data (a “Security Incident”).
Interfere will provide information reasonably available to it concerning the nature and likely consequences of the Security Incident, the data and individuals affected, and measures taken or proposed. Information may be provided in phases as it becomes available. Interfere will take reasonable steps to contain and remediate the Security Incident. Notice is not an admission of fault or liability.
Taking into account the nature of the processing and information available to Interfere, Interfere will provide reasonable assistance to Customer, to the extent Customer cannot reasonably satisfy the relevant obligation through the Services or information already provided by Interfere, with requests from individuals to exercise privacy rights, security and breach-notification obligations, data-protection or data-transfer impact assessments, cybersecurity audits or risk assessments required by applicable law, and consultations with regulators.
If Interfere receives a request directly from an individual concerning Customer Personal Data, Interfere will refer the request to Customer and will not respond except on Customer’s documented instructions or as required by law.
Upon expiration or termination of the affected Services, Interfere will, at Customer’s choice, return or delete Customer Personal Data after any reasonable export period requested under Section 3.3 of the Agreement. Where Customer chooses return, Interfere will delete its remaining active copies.
Except where retention is required by law, Customer Personal Data contained in production database backups will be deleted or aged out within fourteen (14) days after the end of that export period. Other residual copies, including logs and security records, will be retained only for periods determined by the type of data, the operational and security purpose for which it is maintained, applicable legal requirements, and Interfere’s established system-retention practices, and will remain protected under this DPA and unavailable for ordinary use until deleted or aged out.
Customer Personal Data processed by a Subprocessor will be returned or deleted in accordance with that Subprocessor’s applicable retention obligations and Data Protection Laws.
Upon Customer’s written request, Interfere will provide written confirmation of deletion of active copies completed under this Section and, where applicable, identify the categories of residual copies retained under this Section.
Unless prohibited by law, Interfere will notify Customer of a legally binding government request for Customer Personal Data. Where lawful and reasonable, Interfere will challenge requests it reasonably believes are unlawful or overbroad and will disclose only the minimum data legally required.
Interfere will not voluntarily disclose Customer Personal Data to a government authority except at Customer’s direction or as required by law and, where appropriate, will direct the authority to Customer.
3. Subprocessors
Customer generally authorizes Interfere to engage Subprocessors to process Customer Personal Data as necessary to provide the Services.
Interfere will impose written data-protection obligations on each Subprocessor that are no less protective in substance than the obligations applicable to Interfere under this DPA. Interfere remains responsible for each Subprocessor’s performance to the same extent as for its own obligations under this DPA.
Interfere will maintain and make available to Customer a current Subprocessor list identifying each Subprocessor’s name, function, and processing location and will provide at least thirty (30) days’ prior written notice of any new or replacement Subprocessor.
Customer may object during that notice period on reasonable and documented data-protection grounds. The Parties will work in good faith to resolve the objection. If no reasonable resolution is available, Customer may terminate the affected Services before the new or replacement Subprocessor begins processing and receive a pro rata refund of prepaid Fees for the unused portion of the terminated Services.
If an urgent security, service-continuity, or legal circumstance reasonably requires Interfere to appoint or replace a Subprocessor without the full notice period, Interfere may do so and will provide notice without undue delay and in any event within ten (10) business days after the change.
4. Compliance Information and Audits
Interfere will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant independent audit reports or security documentation then available. Interfere may also satisfy reasonable requests for additional compliance information by completing a reasonable security or privacy questionnaire or providing equivalent written information.
If those materials are not reasonably sufficient to satisfy Customer’s requirements under Data Protection Laws, Customer may, no more than once in any twelve-month period, conduct an audit itself or through an independent auditor subject to confidentiality obligations, unless an additional audit is reasonably required following a Security Incident or by applicable law or a regulator.
Audits must be conducted during normal business hours, on at least thirty (30) days’ prior written notice unless a shorter period is required by applicable law or a regulator, at Customer’s expense, and without unreasonable disruption to Interfere’s operations. The Parties will reasonably agree in advance on the scope, timing, and duration of the audit. Before an onsite audit, Customer will first review available reports, written information, and questionnaire responses. Any independent auditor must not be a competitor of Interfere and must be subject to appropriate confidentiality obligations. Customer will provide Interfere with a copy of any final audit findings relating to Interfere’s compliance with this DPA. Audits may not require disclosure of Interfere source code, trade secrets, or other proprietary information, or compromise the security, confidentiality, or rights of other customers or Interfere.
5. Regional Terms
To the extent applicable U.S. state privacy laws apply, Customer discloses Customer Personal Data to Interfere only for the limited and specified business purposes described in Schedule 1, Section S1.2, and Interfere acts as a service provider, contractor, or processor with respect to that Personal Data. Interfere will process that Personal Data only for those purposes or as otherwise permitted by applicable law.
Interfere will not sell or share Customer Personal Data; retain, use, or disclose it outside those purposes or the direct business relationship between the Parties; or combine it with personal data received from another person or collected from Interfere’s own interaction with an individual, except as permitted by applicable law.
Interfere will provide the same level of privacy protection required by applicable law, notify Customer if it determines it can no longer meet those obligations, and, upon notice, permit Customer to take reasonable and appropriate steps to verify compliance and stop and remediate unauthorized use. Sections 2.4 and 4 apply to these obligations.
Where Customer Personal Data protected by the laws of the European Economic Area, United Kingdom, or Switzerland is transferred to a country without an applicable adequacy decision, the applicable transfer mechanism below is incorporated into this DPA. Mandatory data-transfer terms control to the extent of any conflict with this DPA or the Agreement.
For transfers protected by European Economic Area law, the European Commission’s 2021 Standard Contractual Clauses (“EU SCCs”), Module 2 or Module 3 as applicable, are incorporated by reference. Clause 7 applies; Option 2 in Clause 9 applies with the notice period in Section 3.2; the optional language in Clause 11 does not apply; Option 1 in Clause 17 applies with Irish law; and the courts of Ireland apply under Clause 18. Annex I.A is completed with the Party information in this DPA and the Agreement and the roles in Section 1.2; Annex I.B with Schedule 1; Annex I.C by the supervisory authority determined under Clause 13; and Annex II with Schedule 2. Annex III is completed with the current Subprocessor list maintained under Section 3.2.
For transfers protected by United Kingdom law, the International Data Transfer Addendum to the EU SCCs, version B1.0 in force March 21, 2022 (the “UK Addendum”), including its mandatory clauses, is incorporated by reference. Table 1 is completed using the Party and contact information in this DPA and the Agreement, and the Start Date is the Effective Date of this DPA; Table 2 incorporates the EU SCC selections above; Table 3 is completed using Schedule 1, Schedule 2, and the current Subprocessor list maintained under Section 3.2; and in Table 4, both the Importer and Exporter are selected as parties that may end the UK Addendum as set out in Section 19.
For transfers protected by Swiss law, the EU SCCs apply as adapted so that references to the GDPR, the European Union, and Member States are read to include the Swiss Federal Act on Data Protection and Switzerland; the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority; the EU SCCs are governed by Swiss law under Clause 17; disputes under Clause 18 are resolved before the courts of Switzerland; and data subjects in Switzerland may enforce their rights in Switzerland.
Interfere will not permit a Subprocessor to make a further restricted transfer of Customer Personal Data except in compliance with applicable Data Protection Laws and an applicable lawful transfer mechanism.
If an applicable transfer mechanism is replaced, invalidated, or otherwise becomes unavailable, the Parties will cooperate in good faith to implement another lawful transfer mechanism that preserves substantially equivalent protection for the affected Personal Data.
6. General
This DPA continues while Interfere processes Customer Personal Data.
If there is a conflict concerning the processing or protection of Customer Personal Data, mandatory data-transfer terms control first, then this DPA, then the Agreement. Liability arising from this DPA is subject to Section 7 of the Agreement, including the enhanced cap applicable to a breach of a data processing agreement.
This DPA, including its Schedules, together with the applicable transfer terms, constitutes the Parties’ complete agreement concerning the processing of Customer Personal Data.
Except as provided below, this DPA may be amended only in a writing signed by both Parties. Interfere may update Schedule 1 by written notice to Customer to reflect changes to the Services or processing activities, provided that the update does not materially reduce the protections in this DPA, materially expand Interfere’s rights to use Customer Personal Data, or otherwise materially diminish Customer’s rights. Any update to Schedule 1 that forms part of applicable transfer terms will take effect only to the extent permitted by those transfer terms.
Electronic signatures and counterparts are permitted.
Interfere Privacy Contact: Head of Operations, legal@interfere.com.
Customer Privacy Contact: the privacy or data-protection contact Customer designates in the Agreement or an applicable Order Form.
Operational notices under this DPA, including Security Incident and Subprocessor notices, may be sent to the privacy contacts above. Formal legal notices remain governed by Section 9.1 of the Agreement.
Schedule 1 - Processing Details
Interfere processes Customer Personal Data to provide the Services during the term of the Agreement. Following expiration or termination, Interfere may process such Personal Data during any reasonable export period requested under Section 3.3 of the Agreement. Active copies are then returned or deleted in accordance with Section 2.5. Personal Data contained in production database backups may remain for up to fourteen (14) days thereafter. Retention of other residual Personal Data is determined by the type of data, the operational and security purpose for which it is maintained, applicable legal requirements, and Interfere’s established system-retention practices. Personal Data processed by Subprocessors is retained in accordance with Section 2.5 and the applicable Subprocessor’s retention obligations.
Processing may include collecting, accessing, hosting, copying, transmitting, organizing, analyzing, securing, troubleshooting, and deleting Customer Personal Data on a continuous or as-needed basis to provide, secure, maintain, and support the Services. Within the permissions and instructions authorized under the Agreement, processing may include Personal Data contained in or associated with repositories, source code, repository metadata, logs, traces, errors, exceptions, session and usage data, and connected systems in order to detect, investigate, prioritize, and help remediate software defects and to generate customer-specific Output.
Approved Subprocessors, including model providers, may process Customer Personal Data solely as necessary to provide these functions. The purposes in this Schedule do not expand Interfere’s rights to use Customer Data under the Agreement.
Data subjects may include Customer personnel, contractors, customers, application users, and other individuals whose Personal Data appears in Customer Data.
Customer Personal Data may include identifiers and contact details; account and authentication information; IP addresses, browser, device, session, and usage information; Personal Data contained in or associated with source code, repository metadata, logs, traces, errors, and exceptions; support communications; and other Personal Data submitted to or made available through the Services.
Special categories of Personal Data under applicable Data Protection Laws and other regulated data prohibited by Section 3.2 of the Agreement are not intended for processing unless expressly agreed in an Order Form. Customer remains subject to the restrictions in Section 3.2 of the Agreement concerning protected health information, payment-card data, classified information, and data requiring certifications or authorizations Interfere has not agreed to maintain.
Interfere hosts and stores Customer Personal Data in the United States. Approved Subprocessors may process Customer Personal Data in other locations identified on the current Subprocessor list, subject to Section 5.2.
Schedule 2 - Security Measures
Interfere’s security measures are designed to provide a level of protection appropriate to the nature of the Services and Customer Personal Data. As applicable to the systems and Personal Data involved, those measures include the following:
- Access controls. Least-privilege access, unique credentials, and multi-factor authentication for privileged administrative and cloud access.
- Encryption. Encryption of Customer Personal Data in transit and at rest using industry-standard methods.
- Separation and environment controls. Logical separation of customer data and controls designed to prevent unauthorized cross-customer access.
- Logging and monitoring. Logging and monitoring designed to identify unauthorized access, anomalous activity, and security events affecting systems used to provide the Services.
- Secure development and vulnerability management. Secure development practices, vulnerability management, and risk-based remediation of identified security issues.
- Availability and recovery. Backup and recovery controls appropriate to the Services and data involved.
- Incident response. Procedures for investigating, containing, remediating, and communicating Security Incidents.
- Personnel and Subprocessors. Confidentiality obligations and reasonable security awareness practices for personnel with access to Customer Personal Data, together with risk-based review of Subprocessors.
Interfere will periodically review the effectiveness of these measures and address identified risks according to severity. These measures may evolve in accordance with Section 2.2.