Data Processing Addendum

This Data Processing Addendum (this "DPA") is entered into by and between Sonarly, Inc. ("Sonarly", "we", or "us") and the party that electronically accepts or otherwise agrees to this DPA ("Customer", or "you"). This DPA is effective as of the date electronically agreed and accepted by you.

You have entered into one or more agreements with us (each, as amended from time to time, an "Agreement") governing the provision of our AI-powered error and incident analysis platform, more fully described at sonarly.com (the "Service"). This DPA amends the terms of the Agreement to reflect the parties' rights and responsibilities with respect to the processing and security of Customer Data as defined below under the Agreement. If you are accepting this DPA in your capacity as an employee, consultant, or agent of Customer, you represent that you have the authority to bind Customer to this DPA.

Any capitalized terms not defined in this DPA shall have the meanings set forth in the Agreement.

1. Definitions

The following definitions apply to this DPA:

  • CCPA means the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and any binding regulations promulgated thereunder.
  • Controller means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of processing of Personal Data.
  • Customer Data means data you submit to, store on, or send to us via the Service, including error data, stack traces, source code accessed via connected repositories, observability data (logs, metrics, traces), and incident data.
  • Data Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data on systems managed and controlled by Sonarly.
  • Data Privacy Framework means (as applicable) the EU-U.S. Data Privacy Framework...

2. Data Processing

2.1 Roles and Regulatory Compliance

Scope. This DPA applies where and only to the extent Sonarly processes Personal Data as a Processor for the purposes of Privacy Laws.

2.2 Customer Responsibilities

Customer Authorization. Sonarly shall process Personal Data in accordance with Customer's documented lawful instructions.

2.3 AI Processing

You acknowledge that the Service uses artificial intelligence models provided by third-party Subprocessors to analyze Customer Data.

3. Deletion

3.1 Deletion During Term

We will enable you to delete Personal Data during the Term in a manner consistent with the functionality of the Service.

3.2 Deletion When Term Expires

When the Term expires, we will destroy any Personal Data in our possession or control.

4. Data Security

4.1 Security Measures

We will implement and maintain appropriate technical and organizational measures to protect Personal Data.

4.2 Data Incidents

Upon becoming aware of a Data Incident, we will notify you promptly and without undue delay.

4.3 Your Security Responsibilities

You are solely responsible for your use of the Service, including securing account credentials.

5. Data Subject Rights; Data Export

5.1 Access; Rectification; Restricted Processing; Portability

You acknowledge that the Service may, depending on functionality, enable you to access Customer Data; rectify inaccurate Customer Data; restrict processing of Customer Data; delete Customer Data; and export Customer Data.

5.2 Cooperation; Data Subjects' Rights

To the extent that you cannot access the relevant Personal Data within the Service...

6. Data Transfers

6.1 Data Storage and Processing Facilities

You agree that we may, subject to compliance with applicable Privacy Laws, store and process Customer Data in the United States and any other country in which we or our Subprocessors maintain data processing operations.

7. Subprocessors

7.1 Consent to Engagement

You authorize us to engage third parties as Subprocessors.

7.2 List of Subprocessors

Subprocessor Purpose Location
Amazon Web Services (AWS) Cloud infrastructure hosting United States
Anthropic AI model provider United States
Google Cloud (Vertex AI) AI model provider United States
Stripe Payment processing United States

8. Data Protection Impact Assessment

We will provide you with reasonable and timely assistance as you may require in order to conduct a data protection impact assessment.

9. Jurisdiction-Specific Terms

The terms specified in Schedule 4 with respect to the listed jurisdictions will apply in addition to the terms of this DPA.

10. Miscellaneous

There are no third-party beneficiaries to this DPA.

Schedule 1 — Data Processing Description

Subject Matter and Purpose

Sonarly's provision of the Service to Customer.

Categories of Data Subjects

  • Customer's employees and contractors.
  • Customer's end users whose data may be present...

Schedule 2 — Security Measures

Measure Description
Encryption of data in transit All data transmitted is encrypted...

Schedule 3 — Cross-Border Transfer Mechanisms

1. Data Privacy Framework

Sonarly complies with the Data Privacy Framework in relation to transfers.

2. Standard Contractual Clauses

In the event that the Data Privacy Framework is invalidated...

Schedule 4 — Jurisdiction-Specific Terms

Europe

Additional Information. You acknowledge that Sonarly is required under European Data Protection Legislation...