Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the Everconnected Terms of Service (the “Agreement”) between Everconnected (“EC”, “we”, “us”, or “our”) and the Customer agreeing to these terms (“Customer”, “you”, or “your”).

1. Definitions

“Controller”, “Processor”, “Data Subject”, “Personal Data”, “processing” (and “process”) and “Special Categories of Personal Data” shall have the meanings given in Applicable Data Protection Law.

“Applicable Data Protection Law” means all laws and regulations applicable to the processing of Personal Data under the Agreement, including but not limited to UK GDPR and the Data Protection Act 2018.

“Customer Data” means any Personal Data that EC processes on behalf of Customer as a Processor in the course of providing Services.

“Services” means the services provided by EC to Customer pursuant to the Agreement.

“UK GDPR” means the United Kingdom General Data Protection Regulation.

2. Relationship of the Parties

The parties acknowledge and agree that with regard to the processing of Personal Data, Customer is the Controller, EC is the Processor and that EC will engage Sub-processors pursuant to the requirements set forth in Section 5 “Sub-processors” below.

3. EC’s Processing of Customer Data

3.1. EC shall treat Customer Data as confidential and shall only process Customer Data on behalf of and in accordance with Customer’s documented instructions for the following purposes: (i) Processing in accordance with the Agreement; (ii) Processing initiated by users in their use of the Services; and (iii) Processing to comply with other documented reasonable instructions provided by Customer (e.g., via email) where such instructions are consistent with the terms of the Agreement.

3.2. EC shall inform Customer if, in its opinion, an instruction from Customer infringes Applicable Data Protection Law.

4. Details of the Processing

4.1. Subject matter: The subject matter of the processing under this DPA is the Customer Data.

4.2. Duration: The duration of the processing under this DPA is until the termination of the Agreement in accordance with its terms.

4.3. Nature and Purpose of the Processing: EC will process Customer Data as necessary to perform the Services pursuant to the Agreement, as further specified in the DPA, and as further instructed by Customer in its use of the Services.

4.4. Categories of Data Subjects: Customer may submit Personal Data to the Services, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not limited to Personal Data relating to the following categories of data subjects:

– Prospects, customers, business partners and vendors of Customer (who are natural persons)

– Employees or contact persons of Customer’s prospects, customers, business partners and vendors

– Employees, agents, advisors, freelancers of Customer (who are natural persons)

– Customer’s users authorized by Customer to use the Services

4.5. Type of Personal Data: Customer may submit Personal Data to the Services, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not limited to the following categories of Personal Data:

– Contact information (sign up: email, phone, google/apple/FB account login)

– Language (preference and proficiency)

– Age (18 and above)

– Gender identity 

– Interests 

– Lifestyle and habits

– Connection data (Time availability, local time)

– Credit card information (apple/google pay)

– Localization data – City name (manual data input/gps), time zone

– Beliefs and faith

– Relationship status

– Nature of employment and relevant skills

– Personality type / MBTI Personality Test Result

– Zodiac sign

– Personal life experiences (faced and looking forward)

– Audio data

– Video data

5. Sub-processors

5.1. Appointment of Sub-processors: Customer acknowledges and agrees that (a) EC’s Affiliates may be retained as Sub-processors; and (b) EC and EC’s Affiliates respectively may engage third-party Sub-processors in connection with the provision of the Services.

5.2. List of Current Sub-processors and Notification of New Sub-processors: EC shall make available to Customer the current list of Sub-processors for the Services. Such Sub-processor list shall include the identities of those Sub-processors and their country of location. EC shall provide notification of a new Sub-processor(s) before authorizing any new Sub-processor(s) to process Personal Data in connection with the provision of the applicable Services.

5.3. Objection Right for New Sub-processors: Customer may object to EC’s use of a new Sub-processor by notifying EC promptly in writing within ten (10) business days after receipt of EC’s notice in accordance with the mechanism set out in Section 5.2. In the event Customer objects to a new Sub-processor, EC will use reasonable efforts to make available to Customer a change in the Services or recommend a commercially reasonable change to Customer’s configuration or use of the Services to avoid Processing of Personal Data by the objected-to new Sub-processor without unreasonably burdening the Customer. If EC is unable to make available such change within a reasonable period of time, which shall not exceed thirty (30) days, Customer may terminate the applicable Order Form(s) with respect only to those Services which cannot be provided by EC without the use of the objected-to new Sub-processor by providing written notice to EC.

6. Security

EC shall implement and maintain appropriate technical and organizational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access as described in EC’s security documentation. EC regularly monitors compliance with these measures. EC will not materially decrease the overall security of the Services during Customer’s subscription term.

7. Data Subject Rights

EC shall, to the extent legally permitted, promptly notify Customer if EC receives a request from a Data Subject to exercise the Data Subject’s right of access, right to rectification, restriction of Processing, erasure, data portability, object to the Processing, or its right not to be subject to automated individual decision making (“Data Subject Request”). Taking into account the nature of the Processing, EC shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Customer’s obligation to respond to a Data Subject Request under Applicable Data Protection Law. In addition, to the extent Customer, in its use of the Services, does not have the ability to address a Data Subject Request, EC shall, upon Customer’s request, provide commercially reasonable efforts to assist Customer in responding to such Data Subject Request, to the extent EC is legally permitted to do so and the response to such Data Subject Request is required under Applicable Data Protection Law.

8. Personal Data Breach

EC shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data. EC shall provide Customer with sufficient information to allow Customer to meet any obligations to report or inform Data Subjects of the Personal Data Breach under Applicable Data Protection Law. Such notification shall as a minimum:

  1. a) describe the nature of the Personal Data Breach, the categories and numbers of Data Subjects concerned, and the categories and numbers of Personal Data records concerned;
  2. b) communicate the name and contact details of EC’s data protection officer or other relevant contact from whom more information may be obtained;
  3. c) describe the likely consequences of the Personal Data Breach; and
  4. d) describe the measures taken or proposed to be taken to address the Personal Data Breach.

9. Deletion or Return of Customer Data

EC shall, at the choice of Customer, delete or return all the Personal Data to Customer after the end of the provision of Services relating to processing, and delete existing copies unless Applicable Data Protection Law requires storage of the Personal Data.

10. Audit Rights

EC shall make available to Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer.

11. International Transfers

Any transfer of Customer Data made subject to this DPA from the United Kingdom to countries which do not ensure an adequate level of data protection within the meaning of Applicable Data Protection Law shall be made in compliance with the transfer restrictions set forth in the relevant Applicable Data Protection Law.

12. Miscellaneous

This DPA is subject to the terms of the Agreement and is incorporated into the Agreement. In the event of any conflict or inconsistency between this DPA and the Agreement, the terms of this DPA shall prevail to the extent of such inconsistency. This DPA replaces and supersedes any existing data processing addendum that the parties may have previously entered into in connection with the Services.



This Data Processing Addendum (“DPA”) forms part of the Everconnected Terms of Service (the “Agreement”) between Everconnected (“EC”, “we”, “us”, or “our”) and the Customer agreeing to these terms (“Customer”, “you”, or “your”).

1. Definitions

“Controller”, “Processor”, “Data Subject”, “Personal Data”, “processing” (and “process”) and “Special Categories of Personal Data” shall have the meanings given in Applicable Data Protection Law.

“Applicable Data Protection Law” means all laws and regulations applicable to the processing of Personal Data under the Agreement, including but not limited to UK GDPR and the Data Protection Act 2018.

“Customer Data” means any Personal Data that EC processes on behalf of Customer as a Processor in the course of providing Services.

“Services” means the services provided by EC to Customer pursuant to the Agreement.

“UK GDPR” means the United Kingdom General Data Protection Regulation.

2. Relationship of the Parties

The parties acknowledge and agree that with regard to the processing of Personal Data, Customer is the Controller, EC is the Processor and that EC will engage Sub-processors pursuant to the requirements set forth in Section 5 “Sub-processors” below.

3. EC’s Processing of Customer Data

3.1. EC shall treat Customer Data as confidential and shall only process Customer Data on behalf of and in accordance with Customer’s documented instructions for the following purposes: (i) Processing in accordance with the Agreement; (ii) Processing initiated by users in their use of the Services; and (iii) Processing to comply with other documented reasonable instructions provided by Customer (e.g., via email) where such instructions are consistent with the terms of the Agreement.

3.2. EC shall inform Customer if, in its opinion, an instruction from Customer infringes Applicable Data Protection Law.

4. Details of the Processing

4.1. Subject matter: The subject matter of the processing under this DPA is the Customer Data.

4.2. Duration: The duration of the processing under this DPA is until the termination of the Agreement in accordance with its terms.

4.3. Nature and Purpose of the Processing: EC will process Customer Data as necessary to perform the Services pursuant to the Agreement, as further specified in the DPA, and as further instructed by Customer in its use of the Services.

4.4. Categories of Data Subjects: Customer may submit Personal Data to the Services, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not limited to Personal Data relating to the following categories of data subjects:

– Prospects, customers, business partners and vendors of Customer (who are natural persons)

– Employees or contact persons of Customer’s prospects, customers, business partners and vendors

– Employees, agents, advisors, freelancers of Customer (who are natural persons)

– Customer’s users authorized by Customer to use the Services

4.5. Type of Personal Data: Customer may submit Personal Data to the Services, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not limited to the following categories of Personal Data:

– Contact information (sign up: email, phone, google/apple/FB account login)

– Language (preference and proficiency)

– Age (18 and above)

– Gender identity 

– Interests 

– Lifestyle and habits

– Connection data (Time availability, local time)

– Credit card information (apple/google pay)

– Localization data – City name (manual data input/gps), time zone

– Beliefs and faith

– Relationship status

– Nature of employment and relevant skills

– Personality type / MBTI Personality Test Result

– Zodiac sign

– Personal life experiences (faced and looking forward)

– Audio data

– Video data

5. Sub-processors

5.1. Appointment of Sub-processors: Customer acknowledges and agrees that (a) EC’s Affiliates may be retained as Sub-processors; and (b) EC and EC’s Affiliates respectively may engage third-party Sub-processors in connection with the provision of the Services.

5.2. List of Current Sub-processors and Notification of New Sub-processors: EC shall make available to Customer the current list of Sub-processors for the Services. Such Sub-processor list shall include the identities of those Sub-processors and their country of location. EC shall provide notification of a new Sub-processor(s) before authorizing any new Sub-processor(s) to process Personal Data in connection with the provision of the applicable Services.

5.3. Objection Right for New Sub-processors: Customer may object to EC’s use of a new Sub-processor by notifying EC promptly in writing within ten (10) business days after receipt of EC’s notice in accordance with the mechanism set out in Section 5.2. In the event Customer objects to a new Sub-processor, EC will use reasonable efforts to make available to Customer a change in the Services or recommend a commercially reasonable change to Customer’s configuration or use of the Services to avoid Processing of Personal Data by the objected-to new Sub-processor without unreasonably burdening the Customer. If EC is unable to make available such change within a reasonable period of time, which shall not exceed thirty (30) days, Customer may terminate the applicable Order Form(s) with respect only to those Services which cannot be provided by EC without the use of the objected-to new Sub-processor by providing written notice to EC.

6. Security

EC shall implement and maintain appropriate technical and organizational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access as described in EC’s security documentation. EC regularly monitors compliance with these measures. EC will not materially decrease the overall security of the Services during Customer’s subscription term.

7. Data Subject Rights

EC shall, to the extent legally permitted, promptly notify Customer if EC receives a request from a Data Subject to exercise the Data Subject’s right of access, right to rectification, restriction of Processing, erasure, data portability, object to the Processing, or its right not to be subject to automated individual decision making (“Data Subject Request”). Taking into account the nature of the Processing, EC shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Customer’s obligation to respond to a Data Subject Request under Applicable Data Protection Law. In addition, to the extent Customer, in its use of the Services, does not have the ability to address a Data Subject Request, EC shall, upon Customer’s request, provide commercially reasonable efforts to assist Customer in responding to such Data Subject Request, to the extent EC is legally permitted to do so and the response to such Data Subject Request is required under Applicable Data Protection Law.

8. Personal Data Breach

EC shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data. EC shall provide Customer with sufficient information to allow Customer to meet any obligations to report or inform Data Subjects of the Personal Data Breach under Applicable Data Protection Law. Such notification shall as a minimum:

  1. a) describe the nature of the Personal Data Breach, the categories and numbers of Data Subjects concerned, and the categories and numbers of Personal Data records concerned;
  2. b) communicate the name and contact details of EC’s data protection officer or other relevant contact from whom more information may be obtained;
  3. c) describe the likely consequences of the Personal Data Breach; and
  4. d) describe the measures taken or proposed to be taken to address the Personal Data Breach.
9. Deletion or Return of Customer Data

EC shall, at the choice of Customer, delete or return all the Personal Data to Customer after the end of the provision of Services relating to processing, and delete existing copies unless Applicable Data Protection Law requires storage of the Personal Data.

10. Audit Rights

EC shall make available to Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer.

11. International Transfers

Any transfer of Customer Data made subject to this DPA from the United Kingdom to countries which do not ensure an adequate level of data protection within the meaning of Applicable Data Protection Law shall be made in compliance with the transfer restrictions set forth in the relevant Applicable Data Protection Law.

12. Miscellaneous

This DPA is subject to the terms of the Agreement and is incorporated into the Agreement. In the event of any conflict or inconsistency between this DPA and the Agreement, the terms of this DPA shall prevail to the extent of such inconsistency. This DPA replaces and supersedes any existing data processing addendum that the parties may have previously entered into in connection with the Services.