This Data Processing Addendum forms part of the Agreement between Moment and Client and applies where Moment processes Personal Data on behalf of Client in connection with the Services.
1. Definitions
Controller means the entity that determines the purposes and means of Processing Personal Data.
Data Protection Laws means all applicable data protection, privacy, data security, security breach notification, and related laws, rules, and regulations, in any jurisdiction, including any implemented regulations, as updated or amended from time to time, and any legally binding requirements, orders, directives or decisions of any regulatory, judicial, or governmental authority in connection with the enforcement thereof.
Processor means the entity that Processes Personal Data on behalf of a Controller.
Personal Data means any information relating to an identified or identifiable individual.
Processing means any operation performed on Personal Data.
Subprocessor means any third party engaged by Moment to assist in fulfilling its obligations in providing Services to Client.
Client Personal Data means Personal Data processed by Moment on behalf of Client in connection with the Services.
End Users means the individuals who use or receive the Services, including individuals who sync or receive Events or Schedules in a personal digital calendar.
For purposes of this DPA, Client is the Controller and Moment is the Processor.
2. Role of the Parties
The parties acknowledge and agree that with regard to the processing of Client Personal Data, Client shall be the business and Moment shall be the service provider. Business and service provider have the definitions provided under the Data Protection Laws and shall include all equivalents, such as controller and processor, respectively. Moment certifies that it understands the obligations imposed on it by this DPA and will comply with such obligations.
3. Scope and Purpose of Processing
Moment shall Process Personal Data solely on documented instructions from Client and solely for the purpose of performing its obligations under the Agreement and in accordance with Client’s documented instructions (the "Permitted Purposes") and not for any other purpose, including:
- delivering and maintaining calendar entries selected by End Users;
- updating entries when details change;
- personalizing content based on non-precise context such as time zone, locale, and approximate region;
- providing engagement and performance analytics to Client; and
- supporting, securing, and improving the Services.
Moment shall not Process Personal Data for its own independent purposes when acting as a Processor.
4. Nature and Categories of Personal Data
Categories of Data Subjects:
- End Users
- Client administrators or contacts
Categories of Personal Data:
- identifiers such as email address where provided;
- calendar connection metadata and authorization tokens;
- engagement data such as adds, reminders, clicks, unsubscribes; and
- technical and contextual data such as IP address, device type, time zone, and locale.
Moment does not intentionally process sensitive categories of Personal Data.
5. Client Obligations
Client represents and warrants that it has provided required notices to End Users, has a valid legal basis for Processing Personal Data, and will comply with applicable data protection laws. Client is responsible for the lawfulness of instructions provided to Moment.
6. Moment Obligations
Restrictions on Processing. Moment is prohibited from: (i) selling or sharing Client Personal Data; (ii) retaining, using, or disclosing Client Personal Data for any purpose other than the Permitted Purposes; (iii) retaining, using, or disclosing Client Personal Data outside of the direct business relationship with Client; or (iv) combining Client Personal Data with Personal Data that it receives from or on behalf of another person or persons, or collects from its own interaction with a consumer, except as permitted by applicable Data Protection Laws.
Confidentiality. Moment shall ensure that persons processing Client Personal Data are under an obligation to maintain the confidentiality of all Client Personal Data accessed or received.
Access by Authorities. To the extent permitted by law, Moment will promptly, and in all cases before producing and/or providing access to any Client Personal Data, notify Client of (i) any request for access to any Client Personal Data from any regulatory body, government official, or other third party, and/or (ii) any warrant, subpoena, request for production, other legal process, or other request to Moment regarding any Client Personal Data.
Cooperation/Assistance. Moment shall assist Client in: (i) its obligation to respond to requests from consumers to exercise their privacy rights under the Data Protection Laws ("Rights Requests"), including by implementing the technical and organizational controls necessary to receive and respond to such Rights Requests; (ii) responding to requests from data protection authorities to the extent they relate to the Services; and (iii) the completion of any data protection impact assessments required by Data Protection Laws, upon Client’s request.
7. Subprocessors
Client authorizes Moment to engage Subprocessors listed in Exhibit A. Moment shall enter into written agreements with Subprocessors imposing obligations no less protective than those in this DPA and shall remain responsible for performance of Subprocessors. Moment may update Exhibit A as necessary.
Prior to engaging a new Subprocessor, Moment will provide Client at least thirty (30) days’ written advance notice and a reasonable opportunity to object. If Client does not object within thirty (30) days, the Subprocessor shall be deemed approved. If Client objects on reasonable data protection or security grounds, Moment will reasonably work in good faith with Client to address Client’s concerns. If Client and Moment are unable to resolve Client’s concerns following a good faith attempt to do so, either party may terminate the affected Services, and Moment will provide a pro rata refund of prepaid unused fees for the affected Services.
For the current list of Subprocessors engaged by Moment, see our Sub-Processors page.
8. Data Security and Security Incident
Moment shall (a) develop, maintain and implement a comprehensive written information security program that complies with Data Protection Laws and that includes administrative, technical, organizational and physical safeguards and other security measures designed to (i) ensure the security and confidentiality of Personal Information; (ii) protect against any anticipated threats or hazards to the security and integrity of Personal Information; and (iii) protect against any Data Security Incident. The security program shall ensure regular patching and deployment of anti-virus and other security software and multi-factor authentication for external access control to Personal Information, as well as the encryption of Personal Information when transmitted over public networks; and (b) provide summary documentation of its security program upon request, subject to confidentiality and security restrictions.
Moment shall promptly, but in any event within forty-eight (48) hours, inform Client in writing of any Security Incident involving Client Personal Data in the possession, custody, or control of Moment or its Subprocessors. Such notice shall summarize in reasonable detail the effect on Client, if known, of the Security Incident and the corrective action taken or to be taken by Moment. Moment shall promptly take all necessary and advisable corrective actions and shall cooperate fully with Client in all reasonable and lawful efforts to prevent, mitigate or rectify such Security Incident. Moment shall (i) investigate such Security Incident and perform a root cause analysis thereon; and (ii) remediate the effects of such Security Incident while preserving relevant forensic evidence. Moment will reasonably assist Client with notifications to regulators, affected individuals, or third parties to the extent required by applicable law. The parties will consult in good faith regarding public statements relating to a Security Incident to the extent legally permitted and practicable; provided that neither Party will be required to obtain prior approval where doing so would delay legally required notifications or communications. To the extent a Security Incident is caused by Moment’s breach of this Agreement or applicable law, Moment shall be responsible for reasonable and documented third-party costs directly resulting from such Security Incident to the extent required by applicable law, subject to the liability limitations set forth in Section 13 of the Agreement.
9. International Data Transfers
Moment’s primary infrastructure is hosted on Google Cloud Platform in the United States. Where Personal Data originating from the EEA, UK, or Switzerland is transferred internationally, Moment relies on appropriate safeguards, including Standard Contractual Clauses and applicable addenda, including those provided by Google.
10. Audits and Compliance
Moment shall notify Client immediately if it is unable to comply with its obligations under this Addendum or the Data Protection Laws and acknowledges that Client has the right to take reasonable and appropriate steps to stop and remediate any unauthorized use of Client Personal Data. Upon reasonable written request, Moment shall make available information reasonably necessary to demonstrate compliance with this DPA. Client may conduct an audit no more than once in any twelve (12) month period, unless a confirmed Security Incident has occurred, subject to reasonable confidentiality, security, scope, and business disruption limitations. Moment may satisfy this obligation by providing a current third-party audit report or comparable security assessment, provided that such third-party audit must be conducted by a qualified, independent assessor and covers Moment’s relevant policies and measures, and be conducted using an accepted control standard or framework, except to the extent such materials are insufficient to address Client’s reasonable concerns. If Moment materially fails to comply with this DPA or applicable Data Protection Laws, and does not cure such failure within a reasonable period after notice, Client may terminate the Agreement for cause.
11. Return or Deletion
Upon termination of the Services, Moment shall delete or return Personal Data in accordance with the Agreement, unless retention is required by law, and shall certify that deletion has been completed upon request.
12. Miscellaneous
All amendments, supplements or other modifications to this Addendum must be in a written instrument signed by each Party. Moment may assign this Addendum without Client’s prior written consent to an Affiliate or in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of its assets.
13. Governing Law
This DPA is governed by the law specified in the Agreement.
Questions about this DPA?
Contact our data protection team at privacy@momentco.ai.