Data Processing Addendum
This Data Processing Addendum (the "DPA") forms part of the Terms of Engagement (the "Terms of Engagement") between Chillz N.L.E Ltd. ("Chillz") and the Organizer that has accepted them (the "Organizer"). It applies when Chillz processes Organizer Personal Data on the Organizer's behalf.
This DPA is the agreement required under regulation 15 of the Protection of Privacy (Data Security) Regulations, 5777-2017 between the Organizer, as the controller of a database (בעל שליטה במאגר מידע), and Chillz, as an external party that holds and processes information on the Organizer's behalf (מחזיק). Capitalized terms not defined in this DPA have the meanings given in the Terms of Engagement.
1. Definitions
- "Data Protection Law" means the Protection of Privacy Law, 5741-1981 and the regulations under it, including the Data Security Regulations and the Transfer Regulations, and any other data protection law that applies to the processing of Organizer Personal Data.
- "Data Security Regulations" means the Protection of Privacy (Data Security) Regulations, 5777-2017.
- "Transfer Regulations" means the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 5761-2001.
- "Organizer Personal Data" means personal information processed by Chillz on the Organizer's behalf within the Processing Scope described in Section 2.1.
- "Processing" means any operation on information, including collection, storage, organization, retrieval, use, matching, transmission, disclosure, alteration and deletion.
- "Data Subject" means an individual to whom Organizer Personal Data relates.
- "Security Incident" means a security incident (אירוע אבטחה) within the meaning of the Data Security Regulations that affects Organizer Personal Data in Chillz's possession or control. For the purposes of this DPA, unsuccessful attempts and activities that do not compromise the security of Organizer Personal Data, such as pings, port scans, blocked log-in attempts and denial-of-service attacks that do not result in unauthorized access to, or the loss or alteration of, Organizer Personal Data, are not Security Incidents.
- "Sub-holder" means a third party that Chillz engages to process Organizer Personal Data.
2. Scope and Roles
2.1 Processing Scope
Chillz acts as the Organizer's holder and processor for the following processing (the "Processing Scope"):
- contacts and other personal information that the Organizer uploads, imports, pastes or enters into the Services;
- the Organizer's contact records and audiences maintained in the Services, including information the Organizer adds to records of Buyers;
- messages and campaigns that the Organizer sends or schedules through the Services, and the related delivery, engagement and refusal records;
- purchase and event reports that the Organizer instructs Chillz to send to the Organizer's advertising accounts; and
- personal information synced into the Services from the Organizer's third-party accounts and integrations.
2.2 Outside the Processing Scope
This DPA does not apply to:
- personal information that Chillz collects through its own checkout, booking, account, marketplace and other flows, including information about Buyers and about the Organizer's Authorized Users, of which Chillz is an independent controller and which Chillz may use for its own purposes as described in its Privacy Policy; or
- personal information about Buyers that the Organizer receives through the Services, of which the Organizer is an independent controller.
The same individual's information may fall within more than one category. Each party's role is determined separately for each processing activity.
2.3 Instructions
The Terms of Engagement, this DPA and the Organizer's configuration and use of the Services are the Organizer's complete instructions to Chillz for processing Organizer Personal Data. Any additional instruction requires Chillz's written agreement, and Chillz may charge for it or decline it. Chillz may process Organizer Personal Data where required by law. Chillz is not required to verify the lawfulness of the Organizer's instructions, without prejudice to any duty that Data Protection Law imposes on Chillz, or that Chillz undertakes in Section 10, to inform the Organizer of an instruction that Chillz considers unlawful.
3. The Organizer's Responsibilities
The Organizer is responsible, as the controller of its database, for complying with Data Protection Law and with section 30A of the Communications (Telecommunications and Broadcasting) Law, 5742-1982, and represents and warrants that:
- it has collected Organizer Personal Data lawfully and has given Data Subjects every notice required by law, including under section 11 of the Protection of Privacy Law;
- it has every consent, authorization and legal basis required for Chillz to process Organizer Personal Data as described in the Terms of Engagement and this DPA, including for the Permitted Platform Purposes in Section 5;
- it has complied with any obligation to register its database, to appoint any officer or to maintain any document required of it by Data Protection Law;
- it has determined the security level that applies to its database under the Data Security Regulations, and will notify Chillz in writing before providing any Organizer Personal Data whose processing requires measures beyond those Chillz applies to the Services generally;
- where it enables social, attendee or conversion features, it has given Data Subjects every notice and obtained every consent required for the enrichment and display described in Section 4.1;
- it will not provide information of special sensitivity (מידע בעל רגישות מיוחדת), identity numbers or payment card numbers, unless Chillz has agreed in writing; and
- its instructions comply with the law.
The Organizer is responsible for responding to requests from Data Subjects, including requests to review, correct or delete information and requests under section 17F of the Protection of Privacy Law. The Organizer is responsible for the oversight measures required of it under regulation 15(a) of the Data Security Regulations, which it may carry out as described in Section 4.9.
4. Matters Required by Regulation 15
4.1 Information and permitted purposes
The information that Chillz may process is the Organizer Personal Data within the Processing Scope, which may include names, contact details (including email addresses and phone numbers), social media handles, demographic details that the Organizer provides, purchase, attendance and engagement history, consent and refusal records, segment and tag membership, and other fields that the Organizer chooses to add.
Chillz may use Organizer Personal Data to provide the Services to the Organizer in accordance with the Organizer's instructions, including storing and managing contact records, building audiences, sending and tracking messages, applying suppression and refusal records, syncing with the Organizer's integrations, sending reports to the Organizer's advertising accounts, and, where the Organizer enables social, attendee or conversion features, enriching contact records with publicly available social profile information and displaying that information in those features, and for the Permitted Platform Purposes in Section 5.
4.2 Systems Chillz may access
Chillz may access the database systems of the Services in which Organizer Personal Data is processed, including the hosted application, databases, file storage, messaging, email delivery and link infrastructure, logs and backups, and the systems of its Sub-holders used for the same purposes.
4.3 Types of processing
Chillz may carry out any processing reasonably necessary for the purposes in Sections 4.1 and 5, including collection, import, storage, organization, segmentation, matching, de-duplication, enrichment, normalization, hashing, transmission, disclosure to recipients that the Organizer designates, generation of reports and statistics, correction, and deletion.
4.4 Duration, return and deletion
This DPA applies for as long as Chillz processes Organizer Personal Data under the Terms of Engagement. During that period, the Organizer may export Organizer Personal Data using the export features of the Services. After the Terms of Engagement end, Chillz will delete or de-identify Organizer Personal Data within a reasonable period, except for information that Chillz retains for the Permitted Platform Purposes, information required to be retained by law or for the establishment or defense of legal claims, and information in backups until they are overwritten in the ordinary course. The Organizer may retrieve Organizer Personal Data before the Terms of Engagement end using the export features of the Services, which is the manner of return. Chillz will report the deletion to the Organizer, which it may do through the Services or by email, including by a general notice.
4.5 Data security
Chillz will implement the data security obligations that apply to it as a holder under the Data Security Regulations, using administrative, technical, organizational and physical measures designed to protect Organizer Personal Data, appropriate to the security level of the Organizer's database as notified to Chillz under Section 3. Chillz may update its measures from time to time, provided they continue to meet those obligations. Chillz may decline processing that would require measures beyond those it applies to the Services generally.
4.6 Confidentiality of personnel
Chillz will require each person it authorizes to access Organizer Personal Data to undertake to keep it confidential, to use it only as permitted under this DPA, and to comply with the security measures that apply to it.
4.7 Sub-holders
The Organizer authorizes Chillz to engage Sub-holders, including Chillz's affiliates and providers of hosting, database, storage, messaging, email delivery, link shortening, monitoring, support, moderation, analytics and advertising services. Where Chillz engages a Sub-holder, Chillz will include in its agreement with the Sub-holder the matters required by regulation 15 of the Data Security Regulations, to the extent they apply to the services the Sub-holder provides. Chillz may make information about its Sub-holders available to the Organizer on request.
4.8 Reporting and Security Incidents
Chillz will report to the Organizer at least once a year on its performance of its obligations under this DPA and the Data Security Regulations. Chillz may do so by a written statement or summary made available through the Services or by email, and may use a common report for multiple Organizers.
Chillz will notify the Organizer of a Security Incident that Chillz becomes aware of, with the information reasonably available to Chillz. The Organizer is responsible for any notification to the Privacy Protection Authority, to Data Subjects or to others that the law requires of the controller. Chillz may also report a Security Incident to the Privacy Protection Authority where the law requires it of a holder. A notification by Chillz is not an admission of fault or liability.
4.9 Oversight
To support the Organizer's oversight under regulation 15(a) of the Data Security Regulations, the Organizer may, no more than once a year unless required by a competent authority or following a Security Incident, request that Chillz complete a reasonable written questionnaire about its compliance with this DPA, or provide existing documentation that Chillz makes available for this purpose. Any further review must be agreed in advance, is at the Organizer's cost, and is subject to Chillz's confidentiality and security requirements.
5. Permitted Platform Purposes
To the extent permitted by Data Protection Law, the Organizer authorizes and instructs Chillz to process Organizer Personal Data for the following purposes (the "Permitted Platform Purposes"):
- providing, maintaining, supporting, building and improving the Services, including developing and training models, features and analytics, other than to provide services to another customer;
- detecting, preventing and investigating security incidents, fraud, abuse, spam and violations of Chillz's terms and policies, including across Organizers and the Services;
- complying with law, responding to requests from competent authorities, and establishing, exercising or defending legal claims;
- creating de-identified or aggregated information, which is not personal information and which Chillz may use for any purpose; and
- maintaining and applying platform-wide suppression, opt-out and refusal lists across Organizers and the Services, and retaining the information needed to do so.
To the extent that Chillz determines the purposes and means of processing for a Permitted Platform Purpose, Chillz is responsible for that processing as an independent controller.
6. Assistance
Chillz may provide features in the Services that the Organizer can use to respond to Data Subject requests and to meet its own obligations. Where a Data Subject contacts Chillz about Organizer Personal Data, Chillz may refer the Data Subject to the Organizer, and may act on a refusal or opt-out request as described in Section 5. Chillz may provide other reasonable assistance on the Organizer's written request, at the Organizer's cost.
7. Transfers Abroad
The Organizer authorizes Chillz and its Sub-holders to process and store Organizer Personal Data outside Israel, including in the European Union, the United States and other countries. Where Organizer Personal Data is transferred abroad, Chillz will rely on a basis permitted under regulation 2 of the Transfer Regulations, such as transfer to a country whose law provides a level of protection not lower than that provided under Israeli law, or transfer to a recipient that undertakes in an agreement to comply with the conditions for the maintenance and use of information that apply to a database in Israel, with the necessary changes. Chillz will obtain the written undertaking required by regulation 3 of the Transfer Regulations, to the extent it applies.
Where Organizer Personal Data was transferred to Israel from the European Economic Area, the Organizer must inform Chillz in writing, and the Protection of Privacy (Provisions Regarding Information Transferred to Israel from the European Economic Area) Regulations, 5783-2023 apply to the extent required.
8. Liability and Indemnity
Chillz's liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability in the Terms of Engagement, to the extent permitted by Applicable Law. Chillz's liability under this DPA counts toward, and is not in addition to, the limit on Chillz's aggregate liability in Section 22.2 of the Terms of Engagement, to the extent permitted by Applicable Law. Nothing in this DPA limits the Organizer's liability. The Organizer must indemnify Chillz in accordance with the Terms of Engagement for any claim, fine or loss arising from the Organizer's breach of this DPA or of Data Protection Law, or from the Organizer's instructions.
9. Term, Changes and Precedence
This DPA remains in effect for as long as Chillz processes Organizer Personal Data, and Sections 1, 2.3, 4.4, 5 and 8, and any other provision that by its nature should survive, survive its end. Chillz may update this DPA in accordance with the Terms of Engagement, including to reflect changes in Data Protection Law. This DPA prevails over the Terms of Engagement on data protection matters within its scope. This DPA is governed by the law and jurisdiction provisions of the Terms of Engagement.
10. Module A: GDPR
This Module applies only where the General Data Protection Regulation (EU) 2016/679 (the "GDPR"), or the GDPR as it applies in the United Kingdom, applies to the processing of Organizer Personal Data. Where this Module applies, the Organizer is the controller and Chillz is the processor for the Processing Scope, and the following terms supplement the rest of this DPA:
- Instructions. Chillz will process Organizer Personal Data only on the Organizer's documented instructions as described in Section 2.3, including with regard to transfers, unless required to do so by applicable law, in which case Chillz will inform the Organizer before processing unless the law prohibits it. Chillz will inform the Organizer if, in its opinion, an instruction infringes the GDPR.
- Subject matter, nature and purpose. The subject matter, nature, purpose, types of personal data and categories of Data Subjects are described in Sections 2.1, 4.1 and 4.3. The duration is described in Section 4.4.
- Confidentiality and security. Section 4.6 applies, and Chillz will implement measures designed to meet the requirements of Article 32 of the GDPR.
- Sub-processors. The Organizer gives general authorization for Chillz to engage sub-processors under Section 4.7. Chillz will inform the Organizer of intended additions or replacements by updating the information it makes available about its Sub-holders or by other reasonable means. The Organizer may object on reasonable data protection grounds within a reasonable period after being informed; if the parties cannot resolve the objection, the Organizer's sole and exclusive remedy is to stop using the affected part of the Services. Chillz will impose on each sub-processor data protection obligations that meet the requirements of Article 28(4) of the GDPR.
- Assistance. Taking into account the nature of the processing and the information available to it, Chillz will provide reasonable assistance to the Organizer with Data Subject requests and with the Organizer's obligations under Articles 32 to 36 of the GDPR, at the Organizer's cost.
- Personal data breaches. Chillz will notify the Organizer without undue delay after becoming aware of a personal data breach affecting Organizer Personal Data.
- Deletion or return. At the end of the relevant processing services, Chillz will, at the Organizer's choice, delete or return all Organizer Personal Data processed on the Organizer's behalf and delete existing copies, unless storage is required by law in accordance with Article 28(3)(g) of the applicable GDPR. This requirement prevails over Section 4.4 for processing subject to this Module.
- Information and audits. Chillz will make available all information necessary to demonstrate compliance with Article 28 of the GDPR and will allow for and contribute to audits, including inspections, conducted by the Organizer or an auditor it appoints. The arrangements in Section 4.9 apply only insofar as they do not restrict these rights or make them dependent on Chillz's further agreement.
- Transfers. Where a transfer of Organizer Personal Data to a country outside the European Economic Area or the United Kingdom requires an appropriate safeguard under Chapter V of the GDPR, the parties will put that safeguard in place before the transfer. If they rely on standard contractual clauses adopted by the European Commission or an equivalent United Kingdom instrument, they will complete and enter into the applicable clauses, including all required annexes and details, before the transfer. Those clauses prevail over any conflicting provision of this DPA or the Terms of Engagement.
- Permitted Platform Purposes. Section 5 applies only to the extent permitted by the GDPR.
11. Contact
Questions about this DPA may be sent to privacy@chillz.com.