Company gives Creators the ability to offer paid membership subscriptions to their Community Members in exchange for certain Benefits. In order to enable Creators to connect directly with their Community Members and fulfill these Benefits, Company provides access to the personal data of Community Members (" Community Member Data") to the applicable Creator. The Creator may then process such Community Member Data in order to provide his or her Community Members with the designated Benefits.
This DPA is between Company and Creators only and is effective immediately upon a Creator first creating an Account via the Site. All Creators must agree to this DPA in order to protect the privacy rights of their Community Members when processing Community Member Data. This DPA applies exclusively to the Community Member Data collected by Company and provided to a Creator solely for the purpose of enabling the Creator to provide the Benefits offered to his or her Community Members.
1.1. "Data Protection Legislation" means all applicable laws, regulations, guidance and codes of practice relating to privacy and the processing of Community Member Data that may exist in any relevant jurisdiction, issued by the supervisory authorities. Data Protection Legislation includes, but is not limited to, European Directives 95/46/EC and 2002/58/EC (as amended by Directive 2009/136/EC) and any legislation or regulation implementing or made pursuant thereto, or which amends, replaces, or consolidates any of them, including the General Data Protection Regulation (Regulation (EU) 2016/279).
1.2. The terms "data controller", "data processor", "subprocessor", "data subject", "personal data", "processing", and "appropriate technical and organizational measures" shall be interpreted in accordance with Directive 95/46/EC, or other applicable Data Protection Legislation, in the relevant jurisdiction.
2.1. Role of the Parties. As between Creator and Company, in relation to Community Member Data that a Creator processes in the course of providing Benefits to its Community Members, Creator will process Community Member Data under this DPA only as a data processor acting on behalf of the Company and Company will act as a data controller.
2.2. Company Processing of Community Member Data. Company will comply with its obligations under Data Protection Legislation in respect of its processing of Community Member Data and any processing instructions it issues to Creator. Company represents that it has all rights and authorizations necessary for Creator to process Community Member Data pursuant to this DPA.
2.3. Creator Processing of Community Member Data. Creator will comply with its processor obligations under Data Protection Legislation and will process Community Member Data only in accordance with the Locals Policies (including this DPA), which Creator acknowledges are the complete and final instructions to Creator in relation to the processing of Community Member Data. Additionally, the nature and purpose of the processing shall be limited solely to that necessary to carry out such instructions, and not for Creator's individual purposes, or for any other purpose except as required by law. If Creator is required by law to process Community Member Data for any other purpose, Creator will inform each Community Member of such requirement prior to the processing unless prohibited by law from doing so. Creator will not retain any Community Member Data for longer than is necessary to provide the applicable Benefits.
2.4. Processing of Community Member Data.
2.4.1. Subject matter. The subject matter of the data processing is the Community Member Data.
2.4.2. Duration. The duration of the processing is for as long as a Creator retains Community Member Data.
2.4.3. Nature and Purpose. The nature and purpose of the processing under this DPA is limited to a Creator's fulfillment of Benefits for its Community Members.
2.4.4. Categories of data subjects. The category of the data subjects are users who sign up for Paid Memberships on the Site in order to receive Benefits as Community Members of certain Creators.
2.4.5. Categories of data. The type of personal data covered by this DPA includes contact information, including without limitation first and last name or account username, email address, shipping address, and amounts paid for Subscription Fees.
3.1. Security Measures by Company. Company is responsible for using and configuring the Site in a manner that enables Company to comply with Data Protection Legislation, including implementing appropriate technical and organizational measures.
3.2. Security Measures by Creator. Creator will implement and maintain appropriate technical and organizational security measures to protect against Community Member Data breaches and to preserve the security and confidentiality of Community Member Data processed by Creator on behalf of Company (" Security Measures"). The Security Measures shall be appropriate to the harm which might result from any unauthorized or unlawful processing, accidental loss, destruction, damage or theft of the personal data and having regard to the nature of the personal data which is to be protected and as a minimum shall be in accordance with applicable industry standards.
3.3. Personnel. Creator restricts its personnel from processing Community Member Data without authorization (unless required to do so by applicable law) and will ensure that any person authorized by Creator to process Community Member Data is subject to an obligation of confidentiality and shall comply with the obligations set forth in the Locals Policies (including this DPA) and applicable Data Protection Legislation.
Upon becoming aware of a Community Member Data breach, Creator will notify Company without undue delay and will provide information relating to the Community Member Data breach as reasonably requested by Company. Creator will use reasonable endeavors to assist Company in mitigating, where possible, the adverse effects of any Community Member Data breach.
Creator may not transfer Community Member Data to any third party (including any affiliates, group companies or subcontractors) without the prior consent of Company. Creator shall at all times ensure that any such transfers are made in compliance with the requirements of Data Protection Legislation and ensure the reliability and competence of such third parties, and must include in any contract with such third parties provisions protecting Community Member Data which are equivalent to those in the Locals Policies (including this DPA) and as required by applicable Data Protection Legislation.
Following expiration or termination of the Locals Policies (including this DPA) as they apply to Creator, Creator will delete or return to Company all Community Member Data in Creator's possession except to the extent Creator is required by applicable law to retain some or all of the Community Member Data (in which case Creator will archive the data and implement reasonable measures to prevent the Community Member Data from any further processing). The terms of this DPA will continue to apply to any retained Community Member Data.
7.1. Data Protection Requests. If Creator receives any requests from individuals or applicable data protection authorities relating to the processing of Community Member Data under the Locals Policies, including requests from individuals seeking to exercise their rights under Data Protection Legislation, Creator will promptly redirect the request to the Company. Creator will not respond to such communication directly without Company's prior authorization, unless legally compelled to do so. If Creator is required to respond to such a request, Creator will promptly notify Company and provide Company with a copy of the request, unless legally prohibited from doing so.
7.2. Company Requests. Creator will reasonably cooperate with Company, at Company's expense, to permit Company to respond to any requests from individuals or applicable data protection authorities relating to the processing of Community Member Data under the Locals Policies to the extent that Company is unable to access the relevant Community Member Data.
7.3. Legal Disclosure Requests. If Creator receives a legally binding request for the disclosure of Community Member Data which is subject to this DPA, such request will be dealt with in accordance with the Locals Policies.
7.4. Additional Cooperation. Creator shall assist Company in complying with its applicable obligations under Data Protection Legislation and provide reasonable information requested by Company to demonstrate compliance with the obligations set forth in this DPA. Creator will also notify Company immediately if, in Creator's opinion, an instruction for processing of any personal data given by Company may violate a country's Data Protection Legislation.
8.1. Relationship with Locals Policies. Any claims brought under this DPA will be subject to the terms and conditions of the Locals Policies, including the exclusions and limitations set forth in the Locals Policies.
8.2. Conflicts. In the event of any conflict between this DPA and any privacy-related provisions in the Locals Policies, the terms of this DPA will prevail.
8.3. Modification and Supplementation. Company may modify the provisions of this DPA consistent with the terms of the Locals Policies, in circumstances such as: (i) if required to do so by a supervisory authority or other government or regulatory entity, (ii) if necessary to comply with Data Protection Legislation, or (iii) to implement or adhere to standard contractual clauses, approved codes of conduct or certifications, binding corporate rules, or other compliance mechanisms, which may be permitted under Data Protection Legislation. Supplemental terms may be added as an Annex or Appendix to this DPA where such terms only apply to the processing of Community Member Data under the Data Protection Legislation of specific countries or jurisdictions. Company will provide notice of such changes to Creator, and the modified DPA will become effective, in accordance with the terms of the Locals Policies or as otherwise provided on Company's website if not specified in the Locals Policies.