01.Roles of the Parties
For personal data contained in customer content and connected accounts, the customer is the controller (or a processor acting for another controller) and Red Palm is the processor. For account and billing data Red Palm processes for its own purposes, Red Palm acts as an independent controller as described in the Privacy Policy.
02.Scope & Applicable Law
This DPA applies to processing subject to the GDPR, the UK GDPR, and the CCPA/CPRA, in each case as amended. Terms such as “personal data”, “processing”, “controller”, and “processor” have the meanings given in the applicable law.
03.Processing Instructions
Red Palm processes personal data only on the customer’s documented instructions — including as set out in the Terms, this DPA, and the customer’s configuration of the service — unless processing is required by law, in which case Red Palm will inform the customer unless prohibited.
04.Details of Processing
- Subject matter: providing DECISION ENGINE.
- Duration: the subscription term plus the deletion period below.
- Nature and purpose: analyzing connected business data, producing and publishing approved marketing content, tracking and scoring inbound leads, and reporting.
- Categories of data subjects: the customer’s personnel and end customers (for example, callers and form submitters).
- Categories of personal data: contact details, call metadata and recordings where enabled, form submissions, and usage data.
05.CCPA Service Provider Terms
Where the CCPA applies, Red Palm acts as a “service provider.” Red Palm does not sell or share personal information received from the customer, does not retain, use, or disclose it outside the direct business relationship, and uses it only to perform the services.
06.Confidentiality
Red Palm ensures persons authorized to process personal data are bound by confidentiality obligations.
07.Security Measures
Red Palm implements appropriate technical and organizational measures as described in the Security Overview, taking into account the nature of the processing and the risks involved.
08.Subprocessors
The customer authorizes the subprocessors listed in the Subprocessor List. Red Palm will provide notice of changes (via that page or email where subscribed) and give the customer an opportunity to object on reasonable data-protection grounds. Red Palm remains responsible for its subprocessors’ performance.
09.International Transfers
Where personal data protected by the GDPR or UK GDPR is transferred to a country without an adequacy decision, the parties rely on appropriate safeguards, including the EU Standard Contractual Clauses (Module 2 or 3, as applicable) and the UK Addendum, which are incorporated by reference.
10.Assistance & Data Subject Requests
Taking into account the nature of the processing, Red Palm will assist the customer with data subject requests and with the customer’s obligations regarding security, breach notification, and impact assessments.
11.Personal Data Breaches
Red Palm will notify the customer without undue delay after becoming aware of a personal data breach affecting the customer’s personal data, and will provide information reasonably required for the customer to meet its own notification obligations.
12.Audit Rights
Red Palm will make available information reasonably necessary to demonstrate compliance with this DPA and, where required by law, allow audits by the customer or its mandated auditor, subject to reasonable notice, confidentiality, and frequency limits.
13.Deletion & Return
Upon termination of the service, Red Palm will delete or return personal data processed on the customer’s behalf within a reasonable period, except where retention is required by law. Note that content published to the customer’s own properties remains the customer’s.
14.Requesting a Signed DPA
Enterprise customers may request a countersigned DPA, including the SCCs, by emailing legal@redpalm.ai.