This Data Processing Agreement including its schedules (the "DPA") is incorporated into and forms part of the agreement between the entity or person identified as the customer in the applicable order form (“Customer”) and Maven Clinic, Co. ("Maven") under which Maven provides the Services (the "Agreement"). Unless otherwise defined herein, capitalized terms used in this DPA have the same meaning given to them under the Agreement. Customer enters into this DPA on behalf of itself and, to the extent required under Applicable Data Protection Laws, in the name and on behalf of its Affiliates permitted to use the Services under the Agreement.
WHEREAS, in connection with providing services to Customer under the Agreement, Maven will have access to and will process for or on behalf of Customer, Personal Data owned and provided to Maven by Customer;
WHEREAS, the Parties wish to enter into this DPA in connection with their respective obligations under Data Protection Laws;
NOW THEREFORE, in consideration of the mutual covenants and promises contained herein, and for other good and valuable consideration, the sufficiency of which is hereby acknowledged, the Parties agree that the terms and conditions set forth below shall be added to the Agreement:
- 1. DEFINITIONS. For purposes of this DPA, the following terms shall have the meanings set out below. Capitalized terms used in this DPA but not defined herein shall have the meanings given to them in the Agreement.
“Applicable Data Protection Laws” means any data protection or privacy laws applicable to Maven’s Processing of Personal Data pursuant to the Agreement, including (as applicable, based on the location of Customer and/or the Data Subject):
- (a) the (i) California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), (ii) Virginia Consumer Data Protection Act, (iii) Colorado Privacy Act, (iv) Connecticut Data Privacy Act, (v) Utah Consumer Privacy Act, (vi) Oregon Consumer Privacy Act, (vii) Texas Data Privacy and Security Act, (viii) Montana Consumer Data Privacy Act and (ix) once effective, similar comprehensive privacy laws in other U.S. states (together, “U.S. State Privacy Laws”);
- (b) the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and any applicable national implementing laws;
- (c) the UK General Data Protection Regulation (“UK GDPR”) and the UK Data Protection Act 2018 (“UK DPA”); and
“Controller” shall have the meaning as the equivalent term under Applicable Data Protection Laws including “Business” under the CCPA.
“Personal Data” means any information relating to an identified or identifiable natural person or as otherwise defined by or including the equivalent term Applicable Data Protection Laws.
“Personal Data Breach” shall have the meaning as the equivalent term defined under Applicable Data Protection Laws.
“Processing” shall have the meaning as defined under Applicable Data Protection Laws.
“Processor” shall have the meaning as defined under Applicable Data Protection Laws including “Service Provider” under the CCPA.
“SCCs” means the standard contractual clauses for Processors annexed to the European Commission’s Decision (EU) 2021/914 of 4 June 2021, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj; as may be amended, superseded or replaced.
“Subprocessor” shall have the meaning as the equivalent term defined under Applicable Data Protection Laws.
- 2. ROLES AND SCOPE OF PROCESSING.
- 2.1. Scope. This DPA applies to the extent that Maven Processes any Personal Data as described in Schedule 1 of this DPA.
- 2.2. Role of the Parties. The Parties agree that, for purposes of this DPA, Customer is a Controller with respect to the processing of the Personal Data, and Maven will process the Personal Data only as a Processor on behalf of and pursuant to the instructions of Customer. Each Party will comply with all laws, rules and regulations applicable to it in the performance of this DPA, including any Applicable Data Protection Laws.
- 2.3. Description of Processing. The subject matter of the data processing is the performance of the Services as described in the Agreement. Schedule 1 of this DPA sets out the nature, duration, and purpose of the processing , the types of Personal Data that Maven processes, and the categories of data subjects whose Personal Data is processed.
- 3. MAVEN OBLIGATIONS
- 3.1. Security Measures. Maven will implement and maintain appropriate technical and organizational measures designed to protect the Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, theft, alteration, or disclosure, as set forth in Schedule 2. Maven will ensure that any of its personnel who will engage in processing of Personal Data will be informed of the confidential nature of the Personal Data, receive training relevant to their responsibilities, and execute confidentiality agreements.
- 3.2. Personal Data Breach. As required by Applicable Data Protection Laws, Maven will provide notice to Customer upon confirming any Personal Data Breach, without undue delay. Such notice shall include the information required for Customer to meet its obligations under Applicable Data Protection Laws to the extent such information is reasonably available to Maven. If required information is not available, Maven will provide subsequent reports to supplement the initial notice. Maven’s response to, or notice of, a Personal Data Breach is not an acknowledgment by Maven of any fault or liability. Maven agrees to investigate any Personal Data Breach, and use commercially reasonable efforts to identify, prevent, mitigate, and remedy the effects.
- 3.3. Audits. Upon the Customer’s annual request, Maven shall provide its latest SOC 2 Type II report, proof of its HITRUST certification, or equivalent report (“Audit Materials”) in order to demonstrate compliance with this DPA. Customer shall treat the Audit Materials as Maven’s Confidential Information (as defined in the Underlying Agreement) and not further disclose the Audit Materials absent Maven’s prior written consent.
- 3.4. Data Subject Access Requests. Maven will promptly notify Customer if it receives a Data Subject Request impacting Personal Data under this DPA. Unless otherwise required by Data Protection Laws, Maven will not respond to a Data Subject Request, other than directing the data subject to Customer. Maven shall provide Customer with reasonable cooperation to assist Customer to fulfill any Data Subjects Requests relating to the processing of Personal Data under this DPA.
- 3.5. Subprocessors. Customer provides a general authorization to Maven to engage Subprocessors to provide services on its behalf, including those Subprocessors listed in https://www.mavenclinic.com/subprocessors Customer may subscribe to updates to the list of Subprocessors by emailing subprocessors@mavenclinic.com with the appropriate contact information. Maven must take steps to ensure that each Subprocessor provides sufficient guarantees that it will comply with Applicable Data Protection Laws and this DPA. Maven shall enter into a written agreement with the Subprocessor incorporating terms which are substantially similar to those set out in this DPA, and Maven will remain responsible for the performance of this DPA by any such Subprocessor.
- 4. CUSTOMER OBLIGATIONS.
- 4.1. Customer shall not instruct Maven to use or disclose Personal Data in any manner that would not be permissible under Data Protection Laws if done directly by Customer.
- 4.2. Customer will only provide to Maven the minimum amount of Personal Data necessary for the accomplishment of the processing purpose.
- 4.3. Customer represents and warrants that it has obtained and will obtain any consents, authorizations, and/or other legal permissions required under Data Protection Laws and other Applicable Law for the disclosure of Personal Data to Maven. Customer will notify Maven of any changes in, or revocation of, the permission by a data subject to use or disclose his or her Personal Data, to the extent that such changes may affect Maven’s use or disclosure of Personal Data.
- 4.4. Customer will not impose any restriction on the use or disclosure of Personal Data that will restrict Maven’s use or disclosure of Personal Data under the Agreement or this DPA unless such restriction is required by Applicable Law or Maven grants its written consent, which consent will not be unreasonably withheld.
- 5. US State Personal Information. To the extent the Personal Data contain personal information as defined by US State Privacy Laws, the Parties acknowledge and agree that Maven is a “service provider” or the equivalent term as defined under US State Privacy Laws. In that capacity, Maven shall: (i) use Customer’s Personal Data only as allowed in this DPA or Agreement; (ii) comply with the privacy protections required under the US State Privacy Laws; (iii) grant Customer rights to take reasonable and appropriate steps to ensure that Maven uses Customer’s Personal Data appropriately; (iv) notify Customer if it makes a determination that it can no longer meet its obligations herein; and (v) grant Customer the right, upon notice, to take reasonable steps to stop and remediate unauthorized use of Customer’s Personal Data by Maven.
- 5.1. Additionally, Maven will not (i) “sell” or “share” Customer’s Personal Data as those terms are defined under US State Privacy Laws, (ii) combine Customer’s Personal Data with any other personal information, unless expressly instructed by Customer for a specific purpose, and sole benefit of Customer, as permitted by the Agreement, or (iii) retain, use, or disclose Customer’s Personal Data for any purpose (including any commercial purpose) other than for the specific purpose of Maven’s performance under the Agreement. Maven certifies that it understands the preceding restrictions.
- 6. DATA TRANSFERS. Customer acknowledges and agrees that Maven may transfer and process Personal Data to and in the United States. Maven shall at all times ensure such transfers are made in compliance with the requirements of Applicable Data Protection Laws and this DPA, including the provisions below. To the extent that such transfer constitutes a Restricted Transfer the Parties shall rely upon the SCCs as the transfer mechanism. The parties agree that the SCCs shall be incorporated into this DPA implemented as below:
- 6.1. European Union. The Parties agree that Restricted Transfers governed by the EU GDPR are made pursuant to the SCCs, which are deemed entered into (and incorporated into this DPA by this reference) and completed as follows: (i) Module Two shall apply; (ii) the optional docking clause in Clause 7 shall apply; (iii) in Clause 9, Option 2 applies, and with the necessary information found in section 3.5; (iv) Clause 11’s optional language does not apply; (v) in Clause 17 (Option 1), the SCCs will be governed by Irish law; (vi) in Clause 18(b), disputes will be resolved before the courts of Ireland; (vii) Annex 1 shall be deemed completed with the information in Schedule 1; (viii) Schedule 1 contains the information required in Annex II of the SCCs; and (ix) Schedule 2 contains the information required in Annex III of the SCCs.
- 6.2. United Kingdom. For Restricted Transfers governed by the UK GDPR, the SCCs shall apply with the following modifications: (i) references to the “GDPR” shall mean the UK GDPR; (ii) Tables 1, 2 and 3 of the UK Addendum will be deemed completed with the information set out in the Schedules of this DPA; (iii) Table 4 in Part 1 of the UK Addendum shall be deemed completed by selecting both “exporter” and “importer”; (iv) references to the “competent supervisory authority” shall be interpreted as references to the Information Commissioner’s Office; and (v) any conflict between the SCCs and the UK Addendum shall be resolved in accordance with Section 10 and Section 11 of the UK Addendum.
- 6.3. Switzerland. For Restricted Transfers governed by Swiss Data Protection Laws, the SCCs shall apply with the following modifications: (i) references to the “GDPR” shall mean the Swiss FADP; (ii) references to “EU,” “Union,” and “Member State” shall be replaced with “Switzerland”; (iii) references to the “competent supervisory authority” and “competent courts” shall be interpreted as references to the “Swiss Federal Data Protection and Information Commissioner” and the “competent Swiss courts”; and (iv) the Standard Contractual Clauses shall be governed by the laws of Switzerland and disputes shall be resolved before the competent Swiss courts.
- 7. TERM AND TERMINATION
- 7.1. This DPA shall commence on the Effective Date of the Agreement and terminate upon the earliest of (i) the date of termination or expiration of the Agreement, or (ii) the destruction of Customer’s Personal Data.
- 7.2. Within 90 days following termination of this DPA, Maven shall destroy all of Customer’s Personal Data in Maven’s possession or control, save that this requirement shall not apply to the extent Maven is required by applicable law to retain some or all of Customer’s Personal Data, or to Customer’s Personal Data it has archived on back-up systems, which Maven shall securely isolate and protect from any further processing, except to the extent required by applicable law.
- 8. MISCELLANEOUS
- 8.1. Except as otherwise provided herein, notices under this DPA shall be sent to the contact information provided in the Agreement.
- 8.2. This DPA is incorporated into and subject to the terms and conditions of the Agreement. In the event of a conflict between the Agreement and this DPA, then this DPA shall control regarding the protection of Customer’s Personal Data. Any ambiguity of the language herein shall be construed to allow the Parties to comply with the Applicable Data Protection Laws.
- 8.3. This DPA may be amended only through mutual agreement of the Parties in writing. The Parties will work in good faith to amend this DPA if necessary to comply with an update to Applicable Data Protection Laws and will operate in compliance with such an update regardless of whether an amendment is in place.
SCHEDULE 1
DETAILS OF PROCESSING
Subject Matter of the Processing:
Performance of Services under the Agreement.
Categories of Data Subjects:
Customer’s employees and their dependents.
Categories of Personal Data:
Customer’s eligibility file, which may contain some or all of the following Personal Data, depending on which Maven services are covered:
- Employee ID number
- Employee business email address
- First and last name
- Date of birth
- Home address
- Gender
- Employee office state location
- Employee office country location
- Employee start date
- Employee eligibility date
- Medical plan name
- Insurer name
- Coverage level
- Dependent id(s)
Special Category Data: None
Nature and Purpose of Processing:
Maven shall Process Personal Data to determine whether individual data subjects are eligible for the Services, to perform initial outreach to eligibility individuals about the Services, to provide data reporting to the Customer, or as otherwise instructed by Customer.
Duration of Processing:
For the duration of the Services.
Frequency of Transfer:
Continuous as agreed by the Parties.
Competent Supervisory Authority:
EU GDPR: Ireland’s Data Protection Commission
UK GDPR: the Information Commissioner’s Office
Swiss FADP: Swiss Federal Data Protection and Information Commissioner
SCHEDULE 2
TECHNICAL AND ORGANISATIONAL MEASURES
Maven shall at all times implement and maintain the security measures identified below:
- Minimum Requirements: the pseudonymisation and encryption of the Personal Data where appropriate and feasible; the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- Backup: the ability to restore the availability and access to the Personal Data in a timely manner in the event of a physical or technical incident;
- Testing: a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing;
- Physical Access Control: the prevention of unauthorized persons gaining access to data processing systems;
- Logical Access Control: the prevention of data processing systems being used without authorization;
- Data Access Control: ensuring that persons entitled to use a data processing system gain access only to such Personal Data as they are entitled to access in accordance with their legitimate access rights, and that, in the course of processing or use and after storage, Personal Data cannot be read, copied, modified or deleted without authorization;
- Data Transfer Control: ensuring that the Personal Data cannot be read, copied, modified or deleted without authorization during electronic transmission, transport or storage on storage media, and that the target entities for any transfer of the Personal Data by means of data transmission facilities can be established and verified;
- Entry Control: ensuring the establishment of an audit trail to document whether and by whom the Personal Data have been entered into, modified in, or removed from data processing systems;
- Control of Instructions: ensuring that the Personal Data is processed solely in accordance with Customer’s instructions;
- Cyber security: ensuring measures to secure and defend Personal Data against unauthorized access , and to correct the Services to its original form in the event that it is modified without Customer’s consent;
- Audit: Maven will cooperate with audits as described in Section 3.3 of the DPA.
- Information Protection Policy: Maven must maintain an information protection/security policy and ensure on-going compliance controls are enabled according to SOC2 or NIST security standards.
- Logging Information: Ensuring Security and Audit logs be retained for 360 days and access to security logs are restricted to authorized persons.
- External Penetration Testing: Maven must validate its security controls using a third-party auditor at least once a year and after changes to the infrastructure that may impact Confidentiality, Integrity and Availability principles set forth by Art. 32 of GDPR.