1. Definitions
As used in this DPA, the following terms have the meanings set forth below. Capitalized terms not defined herein have the meanings given in the Agreement.
(a) “Agreement” means the master services agreement, order form, services agreement, or other governing agreement between Customer and Nectar Social under which Nectar Social provides the Services.
(b) “Applicable Data Protection Laws” means all laws and regulations applicable to the Processing of Customer Personal Data, including, as applicable: (a) the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and implementing regulations; (b) other comprehensive U.S. state privacy laws; (c) Regulation (EU) 2016/679 (EU GDPR); (d) the UK GDPR and the Data Protection Act 2018, each as amended, including applicable changes under the Data (Use and Access) Act; (e) the Swiss Federal Act on Data Protection (FADP); and (f) Canadian federal and provincial privacy laws.
(c) “Controller” means the entity that determines the purposes and means of Processing Personal Data, as defined under Applicable Data Protection Laws.
(d) “Customer” means the entity identified as the customer in the Agreement.
(e) “Customer Personal Data” means Personal Data that Nectar Social Processes on behalf of Customer in connection with the Services.
(f) “Data Subject” means an identified or identifiable individual to whom Customer Personal Data relates.
(g) “De-Identified Insights Data” means data derived from Customer Personal Data that has been aggregated or de-identified so that it cannot identify, and cannot reasonably be used to identify or be linked to, Customer or any individual.
(h) “Model Clauses” means, collectively: (a) the EU Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914; (b) the UK Addendum; and (c) the Swiss FADP and FDPIC adaptations described in Section 12.
(i) “Nectar Social” means Mihafa Inc., a Delaware corporation doing business as Nectar Social.
(j) “Personal Data” means any information relating to an identified or identifiable individual, as defined under Applicable Data Protection Laws.
(k) “Personal Data Breach” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
(l) “Processing” (and “Process”) means any operation or set of operations performed on Personal Data, whether or not by automated means.
(m) “Processor” means the entity that Processes Personal Data on behalf of a Controller, as defined under Applicable Data Protection Laws.
(n) “Sensitive Personal Data” means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification, health data, sex life or sexual orientation, or any equivalent category under Applicable Data Protection Laws.
(o) “Services” means the services Nectar Social provides to Customer under the Agreement.
(p) “Subprocessor” means any third party engaged by Nectar Social to Process Customer Personal Data on behalf of Customer.
(q) “UK Addendum” means the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner under Section 119A of the Data Protection Act 2018.
2. Scope, Incorporation, and Precedence
2.1 This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the Agreement between Customer and Nectar Social. The DPA is effective upon the effective date of the Agreement or such other date as the parties agree in writing.
2.2 “Customer” means the entity identified in the governing master services agreement, order form, or services agreement that constitutes the Agreement.
2.3 This DPA requires no separate signature to take effect. If either party requests separate execution, the parties may execute this DPA in counterparts, each of which constitutes an original.
2.4 This DPA applies to all Processing of Customer Personal Data by Nectar Social in connection with the Services. To the extent of any conflict or inconsistency relating to Customer Personal Data, the following order of precedence applies: (a) the Model Clauses (including the EU SCCs, UK Addendum, and Swiss adaptations); (b) this DPA (including its Annexes); and (c) the Agreement.
2.5 This DPA supersedes all prior data-processing terms, addenda, or agreements between the parties relating to the Processing of Customer Personal Data under the Agreement.
2.6 The liability limitations and exclusions set forth in the Agreement apply to claims arising under or in connection with this DPA to the fullest extent permitted by Applicable Data Protection Laws, provided that nothing in this Section limits (a) any rights or remedies that cannot be waived or limited under Applicable Data Protection Laws, or (b) any rights of Data Subjects or supervisory authorities under the Model Clauses.
3. Roles, Instructions, and Processing Purposes
3.1 Roles. Customer is the Controller of Customer Personal Data. Nectar Social is the Processor acting on behalf of Customer. Where Customer is itself a Processor acting on behalf of a third-party Controller, Nectar Social is a Subprocessor, and Customer represents and warrants that it has obtained all authorizations necessary to appoint Nectar Social as a Subprocessor and to issue the instructions described in this DPA.
3.2 Documented Instructions. Nectar Social will Process Customer Personal Data only in accordance with Customer’s documented instructions. Documented instructions comprise:
(a) the Agreement, this DPA, and the Annexes;
(b) Customer’s configuration and use of the Services, including enabled workflows, integrations, and AI features; and
(c) any other instructions mutually agreed upon in writing by the parties.
3.3 Processing Purposes. Nectar Social will Process Customer Personal Data solely for the following specific purposes:
(a) providing, maintaining, supporting, securing, and improving the Services;
(b) social listening;
(c) community management;
(d) analytics;
(e) content publishing;
(f) creator and influencer workflows;
(g) attribution;
(h) integrations;
(i) AI-assisted engagement and configurable AI agents;
(j) authentication and account and permission management;
(k) fraud and abuse prevention;
(l) security monitoring;
(m) customer support;
(n) compliance with Applicable Data Protection Laws and other legal obligations; and
(o) creation of De-Identified Insights Data in accordance with Section 4.
3.4 Unlawful Instructions. If Nectar Social forms a reasonable belief that a documented instruction infringes Applicable Data Protection Laws, Nectar Social will promptly notify Customer unless prohibited by law from doing so. Nectar Social may suspend performance of the relevant instruction pending Customer’s clarification or amendment, and such suspension will not constitute a breach of this DPA or the Agreement.
3.5 Nectar Social Personnel. Nectar Social will ensure that persons authorized to Process Customer Personal Data are subject to appropriate obligations of confidentiality, whether contractual or statutory.
4. De-Identified Insights Data and AI Processing
4.1 Customer Instruction to Aggregate and De-Identify. Customer instructs Nectar Social to aggregate and de-identify Customer Personal Data in accordance with this Section 4. “De-Identified Insights Data” means data derived from Customer Personal Data that cannot identify, and cannot reasonably be used to identify or be linked to, Customer or any individual.
4.2 Use Rights. Nectar Social may use De-Identified Insights Data during and after the Term for any lawful business purpose, including: (a) improving and developing Nectar Social products, services, and models; and (b) producing and distributing benchmarks, analytics, and industry insights.
4.3 Safeguards Against Re-Identification. Nectar Social will: (a) take reasonable measures designed to prevent identification of any individual or Customer from De-Identified Insights Data; (b) maintain and use such data only in de-identified form; (c) not attempt to re-identify it; and (d) contractually require any recipient to maintain and use it in de-identified form and not attempt re-identification.
4.4 Status of De-Identified Insights Data. Once Customer Personal Data has been properly de-identified in accordance with this Section 4, it is no longer Customer Personal Data and is not subject to the restrictions applicable to identifiable Customer Personal Data under this DPA.
4.5 Third-Party Licensed Data. Data licensed from third parties remains subject to the applicable provider’s terms, and nothing in this Section 4 overrides those terms.
4.6 Third-Party Model Providers. Third-party model providers may process identifiable Customer Personal Data at inference time solely to provide the Services. Each such provider must be contractually restricted from using identifiable Customer Personal Data to train or improve its own models or for any independent purpose. Nectar Social will treat third-party model providers as Subprocessors subject to Section 9.
4.7 No Weakening of Identifiable Data Restrictions. Nothing in this Section 4 reduces, limits, or otherwise weakens the obligations and restrictions that apply to identifiable Customer Personal Data under this DPA, the Agreement, or Applicable Data Protection Laws.
5. Sensitive Personal Data and Direct Messages
5.1 Customer shall not intentionally configure the Services to solicit or collect Sensitive Personal Data from Data Subjects without prior written agreement between the parties establishing appropriate additional safeguards for such Processing.
5.2 Customer acknowledges that Nectar Social cannot control the content that individuals transmit through public interactions, direct messages, and connected channels. Where Sensitive Personal Data is incidentally included in such content, Nectar Social will Process it solely as necessary to provide the Services in accordance with Customer’s documented instructions and the safeguards set out in this DPA.
5.3 Nectar Social will provide reasonable assistance, subject to its technical capabilities, with requests from Customer to delete, restrict, or otherwise respond to Data Subject rights requests relating to incidental Sensitive Personal Data Processed under Section 5.2.
5.4 Customer is responsible for providing all required notices to, and obtaining all required consents from, Data Subjects in connection with the Processing of Sensitive Personal Data and direct-message content through the Services, in each case as required by Applicable Data Protection Laws.
6. U.S. State Privacy Law Terms
6.1 Applicability. This Section 6 applies solely to the extent that Customer Personal Data is subject to the CCPA, as amended by the CPRA and its implementing regulations, or any other comprehensive U.S. state privacy law (collectively, “U.S. State Privacy Laws”). Terms such as “sale,” “share,” “service provider,” “contractor,” and “business purpose” carry the meanings assigned by the applicable U.S. State Privacy Law.
6.2 Role and Purpose Limitations. Nectar Social Processes Customer Personal Data as a service provider, contractor, or processor (as applicable) solely for the specific purposes set forth in Section 3 and Annex I, and only in accordance with Customer’s documented instructions. Nectar Social shall not:
(a) sell or share Customer Personal Data;
(b) retain, use, or disclose Customer Personal Data for any purpose other than the specific purposes permitted under this DPA, including any commercial purpose other than providing the Services;
(c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Nectar Social and Customer; or
(d) combine identifiable Customer Personal Data received from or on behalf of Customer with Personal Data received from other customers or collected from Nectar Social’s own direct consumer interactions, except as permitted by U.S. State Privacy Laws to perform the Services.
6.3 Compliance and Certification. Nectar Social shall comply with applicable obligations under U.S. State Privacy Laws and grant Customer the same level of privacy protection required by those laws. Nectar Social hereby certifies that it understands and will comply with the restrictions and obligations set forth in this Section 6.
6.4 Notice of Inability to Comply. Nectar Social shall notify Customer if it determines that it can no longer meet its obligations under U.S. State Privacy Laws. Upon such notice, Customer may take reasonable and appropriate steps to stop and remediate unauthorized Processing, and Nectar Social shall cooperate with such remediation efforts.
6.5 Verification. Customer may take reasonable steps, including ongoing monitoring, to verify that Nectar Social Processes Customer Personal Data in a manner consistent with this Section 6.
6.6 Rights Requests and Assessments. Nectar Social shall provide reasonable assistance to Customer in responding to verifiable Data Subject requests exercising rights under U.S. State Privacy Laws and in conducting privacy, cybersecurity, or risk assessments required by such laws, subject to Section 10.
6.7 Subprocessor Flow-Down. Nectar Social shall impose contractual obligations on each Subprocessor that provide the same level of privacy protection as required by this Section 6 and U.S. State Privacy Laws.
7. Security Measures
7.1 Nectar Social shall implement and maintain appropriate administrative, technical, and physical safeguards designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, taking into account the nature, scope, context, and purposes of Processing, the state of the art, implementation costs, and the risks to Data Subjects.
7.2 The specific technical and organizational measures in effect as of the Last Updated date of this DPA are described in Annex II. Nectar Social may update those measures from time to time, provided that any update does not materially reduce the overall level of protection afforded to Customer Personal Data during the Term.
7.3 Nectar Social shall ensure that personnel authorized to Process Customer Personal Data are subject to appropriate obligations of confidentiality, whether contractual or statutory.
7.4 Customer is responsible for (a) its own configurations, settings, and use of the Services, (b) the security of its account credentials, authentication tokens, and access permissions, (c) the security of systems and applications that Customer connects to the Services, and (d) determining whether the security measures described in Annex II are appropriate for Customer’s use of the Services in light of Customer’s own risk assessment and compliance obligations under Applicable Data Protection Laws.
7.5 If Customer becomes aware of any security vulnerability or incident affecting Customer’s account, credentials, or connected systems, Customer shall notify Nectar Social promptly at privacy@nectars.buzz.
8. Personal Data Breach Notification
8.1 Definition. For purposes of this DPA, “Personal Data Breach” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise Processed by Nectar Social or its Subprocessors.
8.2 Notification Obligation. Nectar Social will notify Customer of a Personal Data Breach without undue delay and in any event within twenty-four (24) hours after Nectar Social confirms that a Personal Data Breach has occurred. For the avoidance of doubt, the notification deadline begins only upon Nectar Social’s confirmation that a Personal Data Breach has taken place, not upon initial awareness of an unconfirmed security incident.
8.3 Content of Notification. Nectar Social will include in its notification, to the extent reasonably available at the time:
(a) the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Customer Personal Data records affected;
(b) the likely consequences of the Personal Data Breach;
(c) the measures taken or proposed to remediate and mitigate the Personal Data Breach; and
(d) the name and contact details of Nectar Social’s point of contact for further information.
8.4 Phased Updates. Where complete information is not available at the time of initial notification, Nectar Social may provide information in phases as it becomes reasonably available, without undue delay.
8.5 No Admission. Notification of a Personal Data Breach under this Section 8 will not be construed as an acknowledgment by Nectar Social of fault or liability with respect to the Personal Data Breach.
8.6 Customer Responsibility for External Notices. Customer is solely responsible for determining and fulfilling any obligation to notify Data Subjects, supervisory authorities, regulators, or other third parties of a Personal Data Breach, except to the extent Nectar Social has a direct legal obligation to provide such notification under Applicable Data Protection Laws, in which case Nectar Social will coordinate with Customer before doing so to the extent legally permitted.
9. Subprocessors
9.1 General Authorization. Customer grants Nectar Social general written authorization to engage Subprocessors to Process Customer Personal Data in connection with the Services, subject to the requirements of this Section 9.
9.2 Subprocessor List. Nectar Social maintains a current list of Subprocessors at https://privacy.nectars.buzz/subprocessors. The list identifies each Subprocessor’s name, Processing activities, and location.
9.3 Notice of Changes. Nectar Social will provide Customer at least thirty (30) days’ advance written notice before engaging a new Subprocessor or replacing an existing Subprocessor. Notice may be provided by email or through an update to the Subprocessor list with a subscription notification mechanism.
9.4 Objection Right. Customer may object to a new or replacement Subprocessor by notifying Nectar Social in writing within ten (10) business days after receipt of the notice described in Section 9.3. Any objection must state specific, reasonable data-protection grounds for the objection.
9.5 Resolution. Upon receipt of a timely objection, the parties will cooperate in good faith for up to thirty (30) days to resolve the objection. Nectar Social may, at its discretion, offer a commercially reasonable alternative to the objected-to Subprocessor. If the parties are unable to resolve the objection within the resolution period, Customer may, as its sole and exclusive remedy, terminate only the affected Services to the extent required by Applicable Data Protection Laws, and Nectar Social will refund any prepaid fees attributable to the terminated Services on a prorated basis for the remaining portion of the then-current term.
9.6 Subprocessor Agreements. Nectar Social will enter into a written agreement with each Subprocessor that imposes data-protection obligations no less protective than those set out in this DPA with respect to Customer Personal Data. The written agreement must restrict the Subprocessor to Processing Customer Personal Data solely for the purposes described in this DPA and require the Subprocessor to implement appropriate technical and organizational security measures.
9.7 Liability. Nectar Social remains responsible for the acts and omissions of its Subprocessors to the extent required by Applicable Data Protection Laws. Nothing in this Section 9 limits or modifies the liability provisions in Section 14 or the Model Clauses.
10. Data Subject Rights and Cooperation
10.1 Data Subject Requests. Taking into account the nature of the Processing, Nectar Social shall provide reasonable assistance to Customer, through appropriate technical and organizational measures and to the extent commercially practicable, in fulfilling Customer’s obligations to respond to Data Subject requests to exercise rights under Applicable Data Protection Laws. Customer shall be responsible for responding to such requests. If Nectar Social receives a request directly from a Data Subject, Nectar Social shall promptly redirect the individual to Customer unless otherwise required by law.
10.2 Regulatory and Compliance Cooperation. Nectar Social shall provide reasonable assistance to Customer with: (a) data protection impact assessments and prior consultations with supervisory authorities; (b) risk assessments, cybersecurity audits, and similar evaluations required under Applicable Data Protection Laws; (c) responses to inquiries or investigations by regulators or supervisory authorities relating to the Processing of Customer Personal Data; (d) Customer’s obligations regarding security of Processing under Applicable Data Protection Laws; and (e) legally required disclosures or documentation concerning automated decision-making, profiling, or AI-related Processing, in each case to the extent such obligations apply to Customer and relate to the Services.
10.3 Scope of Assistance. Nectar Social’s obligations under this Section 10 are limited to assistance that is reasonable in scope and proportionate to the nature, context, and volume of Processing. Nectar Social may make available self-service tools, platform features, and documentation to facilitate Customer’s compliance.
10.4 Extraordinary Costs. Customer shall reimburse Nectar Social for reasonable costs incurred in providing assistance under this Section 10 that exceeds routine support, at Nectar Social’s then-current professional services rates or as otherwise agreed. Reimbursement shall not apply where the need for assistance arises directly from a breach of this DPA by Nectar Social.
11. Audits
11.1 Documentation-First Process. Nectar Social will make available to Customer, upon reasonable written request and no more than once per twelve-month period, the following compliance materials (collectively, “Audit Materials”): (a) the most recent SOC 2 Type II examination report; (b) applicable certifications; (c) completed security questionnaires; (d) penetration-test summaries; and (e) other reasonably requested compliance documentation. Audit Materials are provided under the confidentiality obligations of the Agreement.
11.2 On-Site or Remote Audit. If the Audit Materials are legally insufficient to satisfy Customer’s obligations under Applicable Data Protection Laws, Customer may conduct or commission one audit per twelve-month period, subject to the following conditions: (a) Customer must provide at least thirty (30) days’ prior written notice specifying the scope and basis for the audit; (b) the audit must be conducted during normal business hours and in a manner that does not disrupt Nectar Social’s operations; (c) the audit must be performed by an independent, qualified third-party auditor bound by written confidentiality obligations acceptable to Nectar Social; and (d) the scope of the audit may not extend to other customers’ data, Nectar Social’s source code, or proprietary system architecture.
11.3 Costs. Customer will bear all costs and expenses associated with any audit under Section 11.2, unless the audit reveals a material breach of this DPA by Nectar Social, in which case Nectar Social will bear its own reasonable costs of cooperation with that audit.
11.4 Additional Audits. Audits beyond the annual entitlement in Section 11.2 are permitted only: (a) following a confirmed Personal Data Breach affecting Customer Personal Data; or (b) where a competent supervisory authority or Applicable Data Protection Laws expressly require an additional audit.
11.5 Model Clause Audit Rights. Nothing in this Section 11 limits or restricts any audit rights granted to Customer, a Data Subject, or a supervisory authority under the Model Clauses. Where the Model Clauses provide broader audit rights than this Section 11, the Model Clauses prevail in accordance with the order of precedence set out in Section 2.
12. International Data Transfers
12.1 Nectar Social is not certified under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, or the Swiss-U.S. Data Privacy Framework.
12.2 To the extent that Processing of Customer Personal Data involves a transfer from the European Economic Area to a country not subject to an adequacy decision, the parties incorporate by reference the standard contractual clauses adopted by European Commission Implementing Decision (EU) 2021/914, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj (the “EU SCCs”), unmodified, with the following elections:
(a) Module 2 (Controller-to-Processor) applies where Customer is a Controller and Nectar Social is a Processor.
(b) Module 3 (Processor-to-Processor) applies where Customer is a Processor and Nectar Social is a Subprocessor.
(c) Clause 7 (docking clause) applies, permitting additional parties to accede.
(d) Clause 9, Option 2 (general written authorization) applies, with a minimum prior notice period of 30 days.
(e) The optional language in Clause 11(a) is excluded.
(f) Clause 17, Option 1 applies; the EU SCCs are governed by the laws of Germany.
(g) Clause 18(b): disputes are submitted to the courts of Germany.
(h) Annexes I, II, and III of this DPA complete the corresponding annexes of the EU SCCs.
12.3 For transfers subject to the UK GDPR, the parties incorporate the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner, available at https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf (the “UK Addendum”). The tables of the UK Addendum are completed by the Agreement and the Annexes to this DPA. Either party may terminate the UK Addendum only as the UK Addendum itself permits upon adoption of a revised Approved Addendum.
12.4 For transfers subject to the Swiss FADP, the EU SCCs apply with the following adaptations: references to the GDPR are read as references to the Swiss FADP; references to “EU,” “Union,” and “Member State” are read to include Switzerland; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC); and the term “member state” must not be interpreted to exclude Data Subjects in Switzerland from exercising their rights in their place of habitual residence.
12.5 Each party will cooperate in good faith to complete transfer impact assessments and implement supplementary measures where reasonably necessary to address identified risks. Neither party guarantees that the legal framework of any destination country provides protection essentially equivalent to that of the originating jurisdiction.
13. Data Return and Deletion
13.1 Access and Export During the Term. Throughout the Term, Customer may access and export Customer Personal Data through the functionality available within the Services.
13.2 Election Period. Within thirty (30) days following the effective date of termination or expiration of the Agreement, or upon receipt of a valid written instruction from Customer during the Term, Customer may elect in writing either (a) return of Customer Personal Data in a standard, machine-readable format, or (b) deletion of Customer Personal Data from Nectar Social’s active systems. If Customer does not make an election within the thirty-day period, Nectar Social will delete Customer Personal Data from its active systems.
13.3 Written Confirmation. Nectar Social will provide written confirmation of deletion upon Customer’s reasonable request.
13.4 Backup Retention. Following deletion from active systems, copies of Customer Personal Data residing in backup or disaster-recovery systems will be protected from active Processing and will be deleted no later than ninety (90) days after deletion from active systems, unless Applicable Data Protection Laws require longer retention. During any such retention period, Nectar Social will continue to apply the security measures described in Section 7 and Annex II and will not actively Process such data except as required by law.
13.5 Legal Retention. To the extent Applicable Data Protection Laws require Nectar Social to retain any Customer Personal Data beyond the periods stated above, Nectar Social may do so solely for the duration and purposes required by law, subject to the confidentiality and security obligations of this DPA.
13.6 De-Identified Insights Data Exclusion. The obligations of this Section 13 do not apply to De-Identified Insights Data, which Nectar Social may retain and use in accordance with Section 4.
13.7 Subprocessor Compliance. Nectar Social will ensure that its Subprocessors comply with the return and deletion obligations set forth in this Section 13 within the timeframes specified, subject to the Subprocessor’s technical capabilities and any applicable legal retention requirements.
14. Liability
14.1 Aggregate Liability Cap. The limitations and exclusions of liability set forth in the Agreement apply to all claims arising under or in connection with this DPA, the Model Clauses, and any related data-processing terms. For purposes of calculating aggregate liability, the Agreement, this DPA, and all related data-processing terms are treated as a single agreement, and liability caps apply once across all such instruments to the fullest extent permitted by Applicable Data Protection Laws.
14.2 Preservation of Nonwaivable Rights. Nothing in this Section 14 or the Agreement limits or excludes either party’s liability to the extent that such limitation or exclusion is prohibited by Applicable Data Protection Laws or would conflict with the rights and obligations established under the Model Clauses. Where the Model Clauses impose liability obligations that exceed the caps in the Agreement, the Model Clauses prevail with respect to the Processing of Customer Personal Data subject to those Model Clauses.
14.3 Regulatory Penalties. Each party bears responsibility for regulatory fines, penalties, and administrative sanctions attributable to its own violation of Applicable Data Protection Laws, except to the extent that such fines, penalties, or sanctions are directly caused by the other party’s breach of this DPA, the Agreement, or the Model Clauses. Nothing in this provision limits a Data Subject’s rights under Applicable Data Protection Laws or the Model Clauses.
15. General Provisions
15.1 Notices. All notices under this DPA must be in writing and sent to: (a) for Nectar Social, 119 University Avenue, Palo Alto, CA 94301, United States, email: privacy@nectars.buzz; and (b) for Customer, the address or email specified in the Agreement. Notices are effective upon confirmed receipt.
15.2 Updates to DPA. Nectar Social may update this DPA to reflect changes in Applicable Data Protection Laws, regulatory guidance, or the Services, provided that no update materially reduces the protections afforded to Customer Personal Data. Nectar Social will notify Customer of material updates at least thirty (30) days before they take effect. If Customer objects in writing within that period on reasonable data-protection grounds, the parties will negotiate in good faith. If the parties cannot resolve the objection within thirty (30) days, Customer may terminate the affected Services in accordance with Section 9.
15.3 Severability. If any provision of this DPA is held invalid, illegal, or unenforceable, the remaining provisions will continue in full force and effect. The parties will negotiate in good faith to replace the invalid provision with a valid provision that achieves, to the extent possible, the original commercial and legal intent.
15.4 Waiver. No failure or delay by either party in exercising any right under this DPA constitutes a waiver of that right. A waiver of any provision is effective only if in writing and signed by the waiving party, and applies only to the specific instance for which it is given.
15.5 Entire Agreement for Data Processing. This DPA, together with the Agreement and the Annexes hereto, constitutes the entire agreement between the parties with respect to the Processing of Customer Personal Data and supersedes all prior or contemporaneous data-processing terms, agreements, or understandings between the parties on that subject matter.
15.6 Third-Party Beneficiaries. This DPA does not confer any rights on third parties except to the extent that Data Subjects are entitled to enforce rights as third-party beneficiaries under the Model Clauses, as expressly provided therein.
15.7 Counterparts. If the parties elect to execute this DPA separately from the Agreement, it may be executed in counterparts, each of which constitutes an original and all of which together constitute one instrument. Electronic signatures are deemed original signatures for all purposes.
15.8 Governing Law. Except as otherwise required by the Model Clauses, this DPA is governed by the law governing the Agreement.
Annex I: Processing Details
This Annex I forms part of the Data Processing Agreement and completes the annexes required by the Model Clauses.
A. Parties and Contacts
| Field | Data Exporter (Customer) | Data Importer (Nectar Social) |
|---|---|---|
| Name | As identified in the Agreement | Mihafa Inc. d/b/a Nectar Social |
| Address | As specified in the Agreement | 119 University Avenue, Palo Alto, CA 94301, United States |
| Contact | As specified in the Agreement | privacy@nectars.buzz |
| Role | Controller (or Processor, where applicable) | Processor (or Subprocessor, where Customer is a Processor) |
B. Description of Processing
| Element | Details |
|---|---|
| Categories of Data Subjects | Customer employees, agents, and authorized users; end users and followers of Customer social media accounts; individuals who interact with Customer content, direct messages, or connected channels; creators and influencers engaged by Customer; individuals whose data is collected through social listening. |
| Categories of Customer Personal Data | Identifiers (name, username, handle, email address, phone number, IP address, device and browser identifiers); profile information and photographs; social media content, posts, comments, reactions, and direct messages; engagement and interaction data; analytics and attribution data; geolocation data (city or region level); employment or role information of authorized users; authentication credentials and access logs; any other Personal Data submitted by or collected at the direction of Customer through the Services. |
| Sensitive Personal Data | Customer will not intentionally configure the Services to solicit Sensitive Personal Data without prior written agreement. Nectar Social cannot control data individuals transmit through public interactions, direct messages, or connected channels. Any incidental Sensitive Personal Data is processed solely to provide the Services under Customer instructions and DPA safeguards. |
| Processing Operations | Collection, receipt, access, organization, storage, retrieval, analysis, classification, transcription, generation, transmission, disclosure, restriction, deletion, aggregation, and de-identification. |
| Frequency | Continuous for the duration of the Term. |
| Purposes | Providing, maintaining, supporting, securing, and improving the Services; social listening; community management; analytics; publishing; creator and influencer workflows; attribution; integrations; AI-assisted engagement and agents; authentication; account and permission management; fraud and abuse prevention; security monitoring; support; legal compliance; and creation of De-Identified Insights Data. |
| Processing Locations (U.S. Regions) | AWS us-east-1; AWS us-east-2; GCP us-central1; GCP us-east4. |
| Retention Period | As set out in Section 13 (Data Return and Deletion) of the DPA. Customer Personal Data is retained during the Term and deleted in accordance with the timelines specified therein, unless Applicable Data Protection Laws require longer retention. |
| Competent Supervisory Authority | Determined in accordance with Clause 13 of the EU SCCs: the supervisory authority of the EU Member State in which the data exporter is established or, where the data exporter is not established in the EU, the supervisory authority of the Member State in which the data exporter’s EU representative is established, or where neither applies, the supervisory authority of the Member State in which the Data Subjects most affected are located. |
Where Module 3 (Processor-to-Processor) of the EU SCCs applies, references to the data exporter in this Annex refer to Customer acting as a Processor on behalf of its own controller(s).
Annex II: Technical and Organizational Security Measures
Nectar Social maintains the following technical and organizational security measures when Processing Customer Personal Data. These measures may be updated in accordance with Section 7 of this DPA.
| Category | Controls |
|---|---|
| Access Management | Centralized identity management; approved access provisioning; least-privilege access controls; quarterly reviews of sensitive-system access; FIDO2/WebAuthn multi-factor authentication for all personnel; additional MFA required for privileged production access; prompt access revocation upon role change or departure; annual security awareness training; quarterly phishing simulations. |
| Encryption and Data Separation | AES-256 encryption at rest; TLS 1.2 or higher in transit; AWS KMS (or equivalent) key management with six-month key rotation; strong password hashing (e.g., bcrypt or equivalent); logical tenant separation. |
| Network Security | Web application firewall (WAF); network anomaly detection; perimeter and internal firewalls; WPA2/802.1X wireless security; secure remote access; cloud security posture management. |
| Endpoint Security | Automatic screen lockout; full-disk encryption; endpoint detection and response (EDR) and anti-malware; remote wipe and lock capability; use of vendor-supported software only. |
| Incident Management | Annual incident-response-plan review and update; designated incident-response team and incident register; separation of administrative and log-custodian roles. |
| Business Continuity | Recovery Time Objective (RTO) of 72 hours; Recovery Point Objective (RPO) of 24 hours; daily backups; annual backup restoration, business-continuity, and disaster-recovery testing. |
| Development Security | Secure software development lifecycle (SDLC); threat modeling; static application security scanning; software composition analysis; mandatory peer code review; formal change management process. |
| Assurance | Annual independent penetration testing with tracked remediation; annual SOC 2 Type II examination and report; assurance reports made available under confidentiality obligations. |
| Subprocessor Management | Written data-protection terms in all Subprocessor agreements; risk-based due diligence prior to engagement; periodic review of Subprocessor compliance. |
Annex III: Authorized Subprocessors
This Annex III forms part of the Data Processing Agreement between Customer and Nectar Social.
(a) Nectar Social maintains a current list of authorized Subprocessors at the following URL: https://privacy.nectars.buzz/subprocessors. That list identifies each Subprocessor’s name, entity location, and the processing activities performed.
(b) Customer grants general authorization for Nectar Social’s use of Subprocessors in accordance with Section 9 of this DPA.
(c) Nectar Social will update the Subprocessor list and provide at least thirty (30) days’ advance notice before engaging any new or replacement Subprocessor, as described in Section 9. Customer may object to a proposed Subprocessor within ten (10) business days of receiving notice, on specific reasonable data-protection grounds, and the parties will follow the resolution process set out in Section 9.
(d) All Subprocessors are bound by written agreements imposing data-protection obligations no less protective than those in this DPA, including obligations regarding confidentiality, security, and restrictions on Processing of Customer Personal Data.
(e) Nectar Social reviews and updates the Subprocessor list on an ongoing basis. The version of the list in effect at any given time is the version then published at the URL above.