Data Protection Addendum Services for Businesses | Fibr
This Data Processing Addendum ("DPA") sets out the GDPR obligations governing the processing of personal data by VibeMarketing Inc. dba Fibr.ai ("Data Processor") on behalf of the Customer/Partner ("Data Controller") who has signed a Subscription Services Agreement with VibeMarketing Inc. The regulatory basis for this Addendum is GDPR Regulation (EU) 2016/679 — Articles 28, 32, and 82.
Definitions
This Addendum defines the following terms, which carry the meanings set out below throughout the document. Personal Data is any information relating to an identified or identifiable natural person ("Data Subject"); data often used for the express purpose of distinguishing individual identity that can be classified as Personal Data includes Name, Identification Number, Location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of a natural person, IP Address, Cookie Identifiers, and Radio Frequency ID (RFID) tags. An identifiable Natural Person/Data Subject is one who can be identified, directly or indirectly, by reference to their Personal Data. Processing is any operation or set of operations performed on Personal Data or on sets of Personal Data by automated means, including collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval or downloading, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, and erasure or destruction.
The Data Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law. The Data Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Data Controller. A Data Sub-Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Data Processor. GDPR is the General Data Protection Regulation (EU) 2016/679 — a legal framework that sets guidelines for the collection and processing of Personal Data of individuals within the European Union (EU).
Profiling is any form of automated processing of Personal Data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements. A Personal Data Breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed. Consent is any freely given, specific, informed and unambiguous indication of the Data Subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them. A Data Protection Impact Assessment (DPIA) is an activity carried out to enhance compliance with GDPR where processing operations are likely to result in a high risk to the rights and freedoms of Data Subjects.
A Security Breach means any actual or reasonably suspected unauthorized use of, loss of, access to, or disclosure of Subscriber Data — provided that an incidental disclosure to an Authorized Party or VibeMarketing Inc. where no reasonable suspicion of theft, fraud, criminal or malicious conduct exists shall not constitute a Security Breach unless such incidental disclosure triggers a notification obligation under applicable Law — and any security breach (or substantially similar term) as defined by applicable Law. A Supervisory Authority is an independent public authority established by an EU Member State, which is "Concerned" by the processing of personal data because the Data Controller or Processor is established on the territory of the Member State of that Supervisory Authority, Data Subjects residing in that Member State are substantially affected or likely to be substantially affected by the processing, or a complaint has been lodged with that Supervisory Authority.
Obligations of VibeMarketing Inc. as Data Processor
As a Data Processor, VibeMarketing Inc. agrees to process Customer Data only on Customer's behalf for the purpose of providing and supporting VibeMarketing Inc.'s services (including insights, reporting, analytics, and platform abuse, trust and safety monitoring), in compliance with written instructions received from Customer, and in a manner that provides no less than the level of privacy protection required under applicable Data Protection Laws. VibeMarketing Inc. will promptly inform Customer in writing if it cannot comply with the requirements of this DPA, and will inform Customer promptly if, in its opinion, any instruction from Customer violates applicable Data Protection Laws. VibeMarketing Inc. will not provide Customer with any remuneration in exchange for Customer Data — the parties acknowledge and agree that Customer has not "sold" (as defined under applicable data protection laws, including CCPA where applicable) Customer Data to VibeMarketing Inc. — and VibeMarketing Inc. will not "sell" or "share" Personal Data as defined under applicable data protection laws.
VibeMarketing Inc. will ensure that persons employed by it and other persons engaged to perform services on its behalf are subject to appropriate confidentiality obligations with respect to Customer Data and comply with the data protection obligations applicable under this DPA. VibeMarketing Inc. will engage sub-processors only as necessary to fulfill its obligations under this DPA, and will ensure that such sub-processors are bound by data protection obligations that are no less protective than those set out in this DPA. A list of sub-processors is maintained and made available in Annex 2.
Applicability
This DPA is applicable under specific conditions tied to the underlying agreement. If the Data Controller entity signing this Addendum is a party to the MSA, this DPA is an addendum to and forms part of the MSA. If the Data Controller entity signing this DPA has executed an Order Form with VibeMarketing Inc. or its Affiliate pursuant to the Agreement, but is not itself a party to the Agreement, this DPA is an addendum to that Order Form and applicable renewal Order Forms. If the Data Controller entity signing this DPA is neither a party to an Order Form nor the Agreement, this DPA is not valid and is not legally binding, and such entity should request that the Data Controller entity who is a party to the Agreement executes this DPA. If the Data Controller entity signing the DPA is instead a Data Controller indirectly via an authorized reseller of VibeMarketing Inc.'s services, this DPA is likewise not valid and is not legally binding; such entity should contact the authorized reseller to discuss whether any amendment to its agreement with that reseller may be required. This DPA shall not replace any comparable or additional rights relating to Processing of Data Controller Data contained in the Data Controller's Agreement, including any existing data processing addendum to the Agreement.
The Data Controller and VibeMarketing Inc. each warrant that they are and will continue to adhere to GDPR and shall perform their obligations under this GDPR Addendum in accordance with the provisions of the GDPR from time to time in force. The parties acknowledge that for the purposes of GDPR, the Data Controller/Partner is the Data Controller for the Personal Data and that the performance of the services will require the processing of Personal Data by VibeMarketing Inc. for the Data Controller.
Scope
For the purposes of GDPR, VibeMarketing Inc. processes Personal Data provided by the Data Controller, limited to Name, Phone, E-Mail and Job Title, for the escalation and communication used to send notifications and alerts during business operations to the Data Subjects whose personal data is shared by the Data Controller. VibeMarketing Inc. implements controls to obtain Consent from users of the platform without disrupting the Data Controller's operations, while the Data Controller is responsible for ensuring the respective Data Controllers and users accept the user consent. VibeMarketing Inc. may use various software tools and Cloud Services for storing such Personal Data in their repositories, and may use or store the Personal Data for retracting any reference to the Data Subject, as mentioned in its Privacy Policy, if required in future even after expiry of the agreement, for identifying or tracing any alerts or notifications sent to the Data Subject.
The Data Controller/Partner is responsible for notifying and obtaining Consent from its Employees, Data Controllers, and Contractors on how the Personal Data is processed by VibeMarketing Inc. and its Data Sub-Processor. VibeMarketing Inc. will bring to the Data Controller's/Partner's attention if it finds a Personal Data Breach in its own or its Data Sub-Processor's environment that has impacted any form of Personal Data stored by either or both parties. VibeMarketing Inc. shall not process Personal Data other than for the purposes documented in the Agreement.
Warranty by VibeMarketing Inc.
VibeMarketing Inc. warrants to the Data Controller that it shall fully comply with the provisions of GDPR in carrying out its obligations under this Agreement, and that it has all provisions for data protection necessary for carrying out its obligations under this Agreement and shall maintain such provisions throughout the term. VibeMarketing Inc. shall immediately advise the Data Controller in writing if it receives or learns of any complaint or allegation indicating a violation of Data Privacy Laws regarding Personal Data, any request from one or more individuals seeking to access, correct, or delete Personal Data, any inquiry or complaint from one or more individuals relating to the collection, processing, use, or transfer of Personal Data, or any regulatory request, search warrant, or other legal, regulatory, administrative, or governmental process seeking Personal Data.
Representations by VibeMarketing Inc.
VibeMarketing Inc. shall adopt and maintain appropriate technical and organizational measures to ensure Personal Data is kept secure throughout the data life cycle, considering the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, and shall take such precautions as are necessary to ensure the integrity of Personal Data and to prevent any Personal Data Breach. It shall ensure that Data Sub-Processors process Personal Data as per its instructions in accordance with GDPR requirements, and shall not collect Personal Data more than is required for processing. VibeMarketing Inc. maintains a current list of Sub-processors on its website at https://www.fibr.ai, including for each Sub-processor its name, geographic location, and a description of the processing activities performed; the Data Controller specifically authorises the engagement as Sub-processors of those entities listed at that URL. If VibeMarketing Inc. intends to add a new Sub-processor, it shall update the website or send a communication email ten (10) days prior to authorising that new Sub-processor to process Data Controller Content; if the Data Controller objects on reasonable grounds related to data protection, the parties shall work together in good faith to resolve the concern, and if no resolution is reached, the Data Controller shall have the right to terminate the agreement.
Before a Sub-processor first processes Data Controller Information, VibeMarketing Inc. will ensure that the Sub-processor is capable of providing the level of protection required, and VibeMarketing Inc. remains fully liable to the Data Controller in respect of any failure by the Sub-processor to fulfil its data protection obligations. VibeMarketing Inc. will allow Data Subjects to keep the contents of their Personal Data accurate, and on reasonable written notice by the Data Controller, will make available all such information as is necessary to demonstrate compliance with GDPR, including where such information is requested as part of an assessment or compliance check. VibeMarketing Inc. shall provide reasonable assistance to the Data Controller in relation to data subject requests, DPIAs, and regulatory inquiries, at no additional cost where such requests are standard and proportionate; for requests that are excessive, repetitive, or require significant additional effort, VibeMarketing Inc. reserves the right to charge reasonable fees based on the effort involved, subject to prior notice to the Data Controller.
On termination of the Agreement, at the Data Controller's sole requisition, VibeMarketing Inc. will provide all Personal Data to the Data Controller and shall provide confirmation of erasure. VibeMarketing Inc. will keep records of the processing activities carried out on behalf of the Data Controller, and will assist the Data Controller in meeting its GDPR obligations to notify Personal Data Breaches to the Supervisory Authority, along with the process and information required. VibeMarketing Inc. will provide commercially reasonable cooperation to the Data Controller in responding to regulatory or supervisory authority requests, data subject complaints or inquiries, and investigations relating to any Personal Data Breach or suspected breach; such cooperation shall include providing relevant information and support necessary for the Data Controller to meet its obligations under applicable Data Protection Laws, provided that such cooperation does not require VibeMarketing Inc. to disclose confidential information of other customers or violate applicable law. VibeMarketing Inc. shall ensure appropriate prioritization and escalation of requests relating to security incidents or Personal Data Breaches.
VibeMarketing Inc. will not use Personal Data for activities like analytics and profiling unless required for business operations to provide subscribed services, and will inform the Data Controller if, in its opinion, a processing instruction infringes applicable legislation or regulation. Where shared Personal Data is transferred outside the Data Processor's territorial boundaries, VibeMarketing Inc. will ensure that the recipient of such data is under contractual obligations to protect it to the same or higher standards as those imposed under this Addendum and applicable Data Protection Laws, and will regularly train individuals having access to Personal Data in data security and data privacy in accordance with accepted industry practice, ensuring that all Personal Data is kept strictly confidential.
Audit Rights
VibeMarketing Inc. shall engage independent third-party auditors to assess the adequacy of its security and data protection measures at least annually, including in accordance with ISO 27001 and SOC 2 requirements. Upon written request and subject to a mutually agreed Non-Disclosure Agreement (NDA), VibeMarketing Inc. shall provide the Data Controller with relevant audit reports, including SOC 2 Type II reports, ISO 27001 certifications, and related security documentation, sufficient to demonstrate compliance with applicable Data Protection Laws. Audit rights of the Data Controller shall primarily be satisfied through such third-party audit reports and documentation.
Any additional audit requests, including on-site or detailed assessments, shall be permitted only where required by applicable law or regulatory authority, or following a material security incident affecting Customer Personal Data. Any such audits shall be conducted with reasonable prior notice, occur during normal business hours, not unreasonably interfere with VibeMarketing Inc.'s operations, and be at the Data Controller's expense. VibeMarketing Inc. may reasonably limit the scope of any audit to protect confidentiality, security, and obligations owed to other customers.
Right to Terminate
If VibeMarketing Inc. contravenes the provisions mentioned in the Audit Rights clause, the Data Controller shall have the right to terminate this Data Processing Addendum (DPA) and the Master Services Agreement (MSA).
Mechanism of Data Transfers
Where Personal Data is transferred outside the European Economic Area ("EEA") or to a country that has not been recognized by the European Commission as providing an adequate level of protection, the Parties agree that such transfers shall be governed by the Standard Contractual Clauses (EU) 2021/914 ("SCCs"). The SCCs are hereby incorporated by reference into this DPA and form an integral part of the Agreement. For the purposes of the SCCs, the Customer shall act as the data exporter and VibeMarketing Inc. shall act as the data importer, with the applicable module being Module Two (Controller to Processor) or Module Three (Processor to Processor), as applicable. In the event of any conflict between this DPA and the SCCs, the SCCs shall prevail with respect to international data transfers.
When the transfer of Customer Personal Data from Customer and/or any of its Affiliates (as exporter) to VibeMarketing Inc. (as importer) is a Restricted Transfer and EU Area Law applies, the transfer shall be subject to the appropriate Controller to Processor SCCs, deemed incorporated into this Addendum as follows: Module Two will apply (controller to processor transfers); in Clause 7, the optional docking clause will apply; in Clause 9, Option 2 will apply, with the time period for prior notice of sub-processor changes as set out in the Representations section of this Addendum; in Clause 11, the optional language will not apply; in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Irish law; in Clause 18(b), disputes shall be resolved before the courts of the Republic of Ireland; Annex I of the EU SCCs shall be deemed completed with the information set out in Annex 1 to this Addendum, and Annex II of the EU SCCs shall be deemed completed with the information set out in Section 4 of Annex 1 to this Addendum.
In relation to Customer Personal Data protected by the Swiss DPA, the EU SCCs shall apply as set out above, but with modifications: any references to "Regulation (EU) 2016/679" shall be interpreted as references to the Swiss DPA and the equivalent articles or sections therein; any references to "EU", "Union", "Member State", and "Member State law" shall be interpreted as references to Switzerland and Swiss law; any references to the "competent supervisory authority" and "competent courts" shall be interpreted as references to the relevant data protection authority and courts in Switzerland; and the Controller to Processor SCCs shall be governed by the laws of Switzerland, with disputes resolved before the competent Swiss Courts.
In relation to Customer Personal Data protected by the UK GDPR, the EU SCCs shall apply as set out above, but as modified and interpreted by the Part 2: Mandatory Clauses of the UK Addendum, which shall be incorporated into and form an integral part of this Addendum; any conflict between the terms of the EU SCCs and the UK Addendum shall be resolved in accordance with Sections 10 and 11 of the UK Addendum. Tables 1 to 3 in Part 1 of the UK Addendum shall be completed respectively with the information set out in Annex I of this Addendum, and table 4 in Part 1 of the UK Addendum shall be deemed completed by selecting both "Importer" and "Exporter".
VibeMarketing Inc. shall process Personal Data using AI and machine learning technologies within the Frankfurt Region, Germany, in accordance with the terms of this Addendum and applicable Data Protection Laws, including GDPR. The purpose of such AI processing is limited to the services provided by VibeMarketing Inc., which shall ensure that any AI processing of Personal Data is conducted only to the extent necessary to achieve the specified purposes. VibeMarketing Inc. shall not participate in any other Restricted Transfers of Customer Personal Data unless the Restricted Transfer is made in compliance with applicable Data Protection Law and pursuant to the relevant Standard Contractual Clauses.
"Transfer Mechanism" refers to any lawful means of transferring personal data from the EEA or any adequate country to a third country in compliance with applicable data protection laws. This may include, but is not limited to, Standard Contractual Clauses (SCCs) approved by the European Commission Decision of 4 June 2021 (as amended from time to time) for the transfer of personal data from the EEA or adequate countries to a third country; the International Data Transfer Agreement issued by the Information Commissioner's Office (ICO) under Section 119A of the Data Protection Act 2018, effective from 21 March 2022; and the International Data Transfer Addendum issued by the ICO under the same Section, effective from the same date. If the Transfer Mechanism is insufficient to safeguard the transferred Personal Data, the data importer will promptly implement supplementary measures to ensure Personal Data is protected to the same standard required under Data Protection Laws.
Subject to terms of the relevant Transfer Mechanism, if the data importer receives a request from a public authority to access Personal Data, it will, if legally allowed, challenge the request and promptly notify the data exporter about it, and only disclose to the public authority the minimum amount of Personal Data required, keeping a record of the disclosure. The Customer should routinely review all international transfers of Personal Data on a case-by-case basis in order to monitor new risks and implement additional safeguards, such as encryption or pseudonymization, to mitigate identified risks.
Data Incident Management
VibeMarketing Inc. maintains security incident management policies and procedures and shall notify the Data Controller without undue delay and, where feasible, within forty-eight (48) hours after becoming aware of a Personal Data Breach — including the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Data Controller Data transmitted, stored or otherwise processed by VibeMarketing Inc. or its Sub-processors (a "Data Controller Data Incident"). VibeMarketing Inc. shall make reasonable efforts to identify the cause of such a Data Controller Data Incident and take those steps it deems necessary and reasonable to remediate the cause, to the extent the remediation is within its reasonable control. Such notification shall, to the extent available at the time of notification, include the nature of the Personal Data Breach, categories and approximate number of affected Data Subjects, likely consequences of the breach, and measures taken or proposed to address and mitigate the breach. These obligations do not apply to incidents caused by the Data Controller or the Data Controller's Users.
The Data Processor shall immediately notify the Data Controller with full details of any Personal Data Breach in relation to this Addendum, any processing of Personal Data which is contrary to GDPR or would require the Processor to act in a way contrary to GDPR, and any request received, including from an individual or the Supervisory Authority, to disclose any Personal Data.
Return and Erasure of Data Controller Data
Upon termination or expiration of the Agreement, VibeMarketing Inc. shall, at the choice of the Data Controller, return or delete all Personal Data processed on behalf of the Data Controller, unless retention is required by applicable law. Such deletion or return shall be completed within a reasonable period not exceeding sixty (60) days from the date of termination, and VibeMarketing Inc. shall, upon written request, provide written confirmation of deletion of such Personal Data. Notwithstanding the foregoing, Personal Data may be retained in secure backup systems for a limited period in accordance with standard backup retention practices, after which such data shall be securely deleted or overwritten.
General
Nothing in this Agreement shall relieve VibeMarketing Inc. of its own direct responsibilities and liabilities under GDPR. The Clauses in this document shall be governed by the law of the Member State of the EEA (European Economic Area) in which the data processing is established. In assessing the appropriate level of security, VibeMarketing Inc. shall conduct a Data Protection Impact Assessment (DPIA) on a periodic basis to evaluate the risks presented by processing, in particular from a Personal Data Breach perspective.
Data Processing
This DPA applies when Customer Data is processed by VibeMarketing Inc.; in this context, VibeMarketing Inc. will act as processor to Customer, who can act either as controller or processor of Customer Data. Customer can use the Service Controls to assist it with its obligations under Applicable Data Protection Law, including its obligations to respond to requests from data subjects. Taking into account the nature of the processing, Customer agrees that it is unlikely that VibeMarketing Inc. would become aware that Customer Data transferred under the Standard Contractual Clauses is inaccurate or outdated; nonetheless, if VibeMarketing Inc. becomes aware that Customer Data transferred under the SCCs is inaccurate or outdated, it will inform Customer without undue delay and will cooperate with Customer to erase or rectify inaccurate or outdated Customer Data by providing the Service Controls that Customer can use to erase or rectify Customer Data.
Details of Data Processing
The subject matter of the data processing under this DPA is Customer Data. As between VibeMarketing Inc. and Customer, the duration of the data processing under this DPA is determined by Customer. The purpose of the data processing under this DPA is the provision of the Services initiated by Customer from time to time, and the nature of the processing is compute, storage, and such other Services as described in the Documentation and initiated by Customer from time to time. The type of Customer Data covered is Customer Data uploaded to the Services under Customer's accounts with VibeMarketing Inc., and the categories of data subjects could include Customer's customers, employees, suppliers, and end users.
Compliance with Laws
Each party will comply with all laws, rules and regulations applicable to it and binding on it in the performance of this DPA, including Applicable Data Protection Law.
Indemnity
Each Party (the "Indemnifying Party") shall defend, indemnify, and hold harmless the other Party and its Affiliates (the "Indemnified Party") from and against any third-party claims, damages, liabilities, fines, penalties, and expenses, including reasonable legal fees, arising out of or related to any breach of this Data Processing Addendum by the Indemnifying Party, or any violation of applicable Data Protection Laws by the Indemnifying Party. Customer shall indemnify VibeMarketing Inc. for claims arising from unlawful or improper collection of Personal Data, failure to obtain required consents or provide required notices, or instructions that violate applicable Data Protection Laws. VibeMarketing Inc. shall indemnify Customer for claims arising from breach of its obligations under this DPA, failure to implement appropriate technical and organizational security measures, or acts or omissions of its Sub-processors, to the extent VibeMarketing Inc. is responsible.
Each Party may participate in the defense of any claim with counsel of its choosing at its own expense. This indemnity section shall be subject to the limitation of liability set forth in the Master Services Agreement (MSA), except in cases of gross negligence, willful misconduct, or regulatory fines directly attributable to a Party's breach.
Insurance
During the term of this DPA and for a period of two (2) years following its expiration or termination, Fibr.ai shall maintain minimum insurance coverages with carriers having an AM Best rating of at least A- VII, as detailed below. Upon Customer's written request, Fibr.ai shall provide Certificates of Insurance evidencing these coverages within 10 business days, and shall notify Customer in writing within 30 days if any of the coverages are cancelled, materially reduced, or lapse during the term. The existence of insurance does not limit or reduce Fibr.ai's liability under this DPA.
| Insurance Type | Coverage Limit |
|---|---|
| Commercial General Liability | USD 1,000,000 per occurrence / USD 2,000,000 aggregate |
| Cyber Liability / Data Breach and Errors & Omissions (Tech E&O) | USD 1,000,000 per claim / USD 3,000,000 aggregate |
| Umbrella / Excess Liability | USD 3,000,000 aggregate |
Severability
The Parties agree that, if any section or sub-section of this Addendum is held by any court or competent authority to be unlawful or unenforceable, it shall not invalidate or render unenforceable any other section of this Addendum.
Data Protection Officer
VibeMarketing Inc. has appointed a Data Protection Officer (DPO) in compliance with GDPR Article 37. The DPO can be contacted at roy@fibr.ai.
Annex 1 — Parties & Description of Transfer
The Data Exporter is the Customer, as set forth in the relevant Order Form, with its address, contact person, and signature and date as set forth in the relevant Order Form and Agreement; the Customer's role is Controller, and its activities relevant to the transfer are as recipient of the Services provided by VibeMarketing Inc. in accordance with the Agreement. The Data Importer is VibeMarketing Inc., located at 42700 Everglades Park Dr, Fremont, CA 94538, with contact person Pritam Roy, DPO, reachable at roy@fibr.ai; VibeMarketing Inc.'s role is Processor, and its activities relevant to the transfer are provision of the Services to the Customer in accordance with the Agreement.
The categories of data subjects for the transfer are the Customer's authorized users of the Services. The categories of personal data transferred include Name, Address, Date of Birth, Age, Education, Email, Gender, Image, Job, Language, Phone, Related person, Related URL, User ID, Username, and other such items as defined in Article 9 of GDPR. No sensitive data is collected. The frequency of transfer is on a continuous basis.
Regarding the nature of the processing: on the client-facing side, email addresses and names are collected for login and stored in Firebase and MongoDB, with automated triggers used to send newsletters and alerts; no invisible tracking pixels are used for behavior analysis beyond click-through rates, and all data resides in the primary country where the client has logged in. On the user (client's client)-facing side, the SDK collects non-PII information for events like page visits, conversions, and other engagements, with no personal customer information collected, and all data is stored in the primary country where the client operates. The purpose of the data transfer is to facilitate the performance of the Services more fully described in the Agreement and accompanying order forms, and the retention period for Customer Personal Data is more fully described in the Agreement, Addendum, and accompanying order forms. For transfers to sub-processors, the subject matter, nature, and duration of the processing are more fully described in the Agreement, Addendum, and accompanying order forms.
Technical and Organisational Security Measures
VibeMarketing Inc. implements technical and organisational security measures as the data processor and data importer to ensure an appropriate level of security, taking into account the nature, scope, context, and purpose of the processing and the risks for the rights and freedoms of natural persons. Under its Security Management System, VibeMarketing Inc. designates qualified security personnel responsible for development, implementation, and ongoing maintenance of the Information Security Program; management reviews and supports all security-related policies, updated at least once annually, to ensure the security, availability, integrity and confidentiality of Customer Personal Data. VibeMarketing Inc. engages a reputable independent third party to perform risk assessments of all systems containing Customer Personal Data at least once annually, and maintains a formal and effective risk treatment program that includes penetration testing, vulnerability management, and patch management to identify and protect against potential threats to the security, integrity, or confidentiality of Customer Personal Data. VibeMarketing Inc. also maintains an effective vendor management program, reviews security incidents regularly including effective determination of root cause and corrective action, and operates an information security management system that complies with the requirements of ISO/IEC 27001:2022.
On personnel security, VibeMarketing Inc. requires personnel to conduct themselves consistently with the company's guidelines regarding confidentiality, business ethics, appropriate usage, and professional standards. VibeMarketing Inc. conducts reasonably appropriate background checks on employees who will have access to client data under the Agreement, to the extent legally permissible and in accordance with applicable local labor law, customary practice, and statutory regulations. Personnel are required to execute a confidentiality agreement in writing at the time of hire and to protect Customer Personal Data at all times, must acknowledge receipt of and compliance with VibeMarketing Inc.'s confidentiality, privacy and security policies, and are provided with privacy and security training on how to implement and comply with the Information Security Program. Personnel handling Customer Personal Data are required to complete additional requirements appropriate to their role, such as certifications, and will not process Customer Personal Data without authorization.
On access controls, VibeMarketing Inc. maintains a formal access management process for the request, review, approval, and provisioning of all personnel with access to Customer Personal Data, limiting access to properly authorized persons having a need for such access, with periodic access reviews to ensure only personnel who still require access retain it. Infrastructure security personnel, who receive required security training, are responsible for ongoing monitoring of VibeMarketing Inc.'s security infrastructure and responding to security incidents. VibeMarketing Inc.'s and Customer's administrators and end users must authenticate themselves via a Multi-Factor authentication system or via a single sign-on system in order to use the Services. Systems are designed to allow only authorized persons to access data they are authorized to access, based on principles of "least privilege" and "need to know," with the granting or modification of access rights based on the authorized personnel's job responsibilities, job duty requirements necessary to perform authorized tasks, a need-to-know basis, and accordance with VibeMarketing Inc.'s internal data access policies and training. Approvals are managed by workflow tools that maintain audit records, access to systems is logged to create an audit trail, and where passwords are employed, password policies follow industry standard practices covering complexity, expiry, lockout, restrictions on reuse, and re-prompt after inactivity.
On data center and network security, US clients are hosted in us-central1, a Google Cloud Platform region in Council Bluffs, Iowa, USA, while Indian clients are hosted in asia-south1, a Google Cloud Platform region in Mumbai, MH, India. Multiple Availability Zones are enabled on GCP for resiliency, with backup restoration testing conducted regularly. Servers are customised and hardened for security, with a code review process employed to increase the security of the code used to provide the Services. Data is replicated over multiple systems to protect against accidental destruction or loss as part of disaster recovery, with disaster recovery programs designed and regularly tested. Systems have logging enabled to support security audits and monitor for actual and attempted attacks, and regular vulnerability scans are performed on all infrastructure components, with vulnerabilities remediated on a risk basis and Critical, High, and Medium patches installed as soon as commercially possible. On the external attack surface, VPC Firewall Rules combined with Target Tags or Service Accounts and Security Groups are in place for the Production environment on GCP. Production transmissions are transmitted via Internet standard protocols.
VibeMarketing Inc. maintains incident management policies and procedures, including detailed security incident escalation procedures, and monitors a variety of communication channels for security incidents; its security personnel react promptly to suspected or known incidents, mitigate harmful effects of such incidents, and document the incidents and their outcomes. VibeMarketing Inc. makes HTTPS encryption available for data in transit and implements encryption technologies for data at rest to ensure the security and confidentiality of Customer Data.
On data storage, isolation, authentication, and destruction, VibeMarketing Inc. stores data in a multi-tenant environment on GCP servers. Data, the Services database, and file system architecture are replicated between multiple availability zones in the US and India, applicable only for user-facing high-availability resolution servers; for other data, it stays within the same country. VibeMarketing Inc. logically isolates the data of different customers, uses a central authentication system across all Services to increase uniform security of data, and ensures secure disposal of Client Data through a series of data destruction processes.
Annex 2 — List of Sub-Processors
VibeMarketing Inc. maintains the following list of sub-processors, each engaged for a specific processing activity and hosted in the stated location.
| Sub-Processor Name | Nature of Processing | Location |
|---|---|---|
| Google Cloud Platform (GCP) | Cloud infrastructure, data hosting, compute, storage, database services, backup & disaster recovery | US and IN |
| Google Workspace | Corporate email, internal collaboration, document storage | US |
| ClickUp | Project management, task tracking, internal workflow coordination | US |
| Keka | HRIS | IN |
| Gusto | HRIS | US |
| Slack | Communication | US |
| OpenAI | AI model inference for content generation, personalization, and natural language processing | US |
| Anthropic | US | |
| Google Vertex AI | AI model inference, machine learning services for content personalization and optimization | US |
| ChargeBee | Payment processing and billing | US |
| Sentry | Application monitoring, error tracking, logging | US |
| SendGrid | Transactional and marketing email delivery | US |
| GitHub | Source code hosting, CI/CD pipelines | Delaware, USA |