Data Processing Addendum

This Data Processing Addendum (“Addendum”) applies to agreements between NodeBB Inc (“NodeBB”), and entities who subscribe for NodeBB’s services and who are subject to Applicable Law (“Subscriber”) (collectively referred to as the “Parties”), sets forth the terms and conditions relating to the privacy, confidentiality and security of Personal Data associated with services to be rendered by NodeBB to Subscriber pursuant to the subscription agreement entered into between the Parties (the “Master Agreement”).

I. Definitions

(A) “Applicable Law” means all applicable European Union (“EU”) or national laws and regulations relating to the privacy, confidentiality, security and protection of Personal Data, including, without limitation: the European Union (“EU”) General Data Protection Regulation 2016/679 (“GDPR”), with effect from 25 May 2018, and EU Member State laws supplementing the GDPR; the EU Directive 2002/58/EC (“e-Privacy Directive”), and EU Member State laws implementing the e-Privacy Directive.

(B) “Data Controller” means a person who alone or jointly with others determines the purposes and means of the Processing of Personal Data.

(C) “Data Processor” means a person who Processes Personal Data on behalf of the Data Controller.

(D) “Data Security Measures” means technical and organisational measures that are aimed at ensuring a level of security of Personal Data that is appropriate to the risk of the Processing.

(E) “Data Subject” means an identified or identifiable natural person to which the Personal Data pertain.

(F) “Personal Data” means any information relating to an identified or identifiable natural person Processed by NodeBB in accordance with Subscriber’s Instructions.

(G) “Personal Data Breach” a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

(H) “Process”, “Processed”, or “Processing” means any operation performed upon Personal Data, such as collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, or destruction.

(I) “Services” means the services offered by NodeBB and subscribed for by Subscriber under the Master Agreement.

(J) “Sub-Processor” means the entity engaged by the Data Processor to Process Personal Data on behalf of the Data Controller.

II. Roles and Responsibilities of the Parties

(A) The Parties acknowledge and agree that Subscriber is acting as a Data Controller, and NodeBB is acting as a Data Processor on behalf of Subscriber.

(B) Any Personal Data will remain the sole property of Subscriber, and NodeBB will not have or obtain any rights therein.

III. Obligation of NodeBB

NodeBB agrees and warrants to:

(A) Process Personal Data disclosed to it by Subscriber only on behalf of and in accordance with the Instructions of the Data Controller.

(B) Ensure that any person authorised by NodeBB to Process Personal Data is subject to a duly enforceable confidentiality obligation.

(C) Not transfer Personal Data outside the original country without explicit written consent of Subscriber.

(D) Inform Subscriber promptly of any formal requests from Data Subjects regarding their Personal Data.

(E) Notify Subscriber immediately of any formal requests from government authorities seeking access to Personal Data.

(F) Provide reasonable assistance to Subscriber in complying with its obligations under Applicable Law.

(G) Maintain internal record(s) of Processing activities, copies of which shall be provided to Subscriber upon request.

IV. Sub-Processing

NodeBB shall only retain third parties that are capable of appropriately protecting the privacy, confidentiality and security of the Personal Data.

V. Compliance with Applicable Laws

(A) Each party covenants and undertakes to comply with all Applicable Laws in the use of the Services.

(B) NodeBB shall negotiate any further data Processing agreement reasonably requested by Subscriber for compliance with Applicable Law.

VI. Data Security

(A) NodeBB shall develop, maintain and implement a comprehensive information security program that complies with Applicable Law.

(B) NodeBB shall supervise its personnel to maintain appropriate privacy, confidentiality and security of Personal Data.

(C) Upon expiration or termination of the Master Agreement, NodeBB shall return or securely destroy all Personal Data upon Subscriber's request.

VII. Data Breach Notification

(A) NodeBB shall promptly inform Subscriber of any Personal Data Breach it becomes aware of, including all available information regarding such breach.

VIII. Audit

NodeBB shall make available to Subscriber all information necessary to demonstrate compliance with the obligations set forth in this Addendum.

ANNEX 1: SCOPE OF THE DATA PROCESSING

The Processing of Personal Data concerns the following categories of Data Subjects: Registered users on the individual NodeBB instances.
The Processing concerns the following categories of Personal Data: Authentication, general identification (username, profile attributes, etc.), IP address, location.
The Processing concerns the following categories of Sensitive Data: None.
The Processing concerns the following categories of data Processing activities: Authentication and verification of user accounts, moderation of posted content, general display of public profile information.
NodeBB uses the following Sub-Processors: Please see NodeBB Sub-Processors for a list of sub-processors.
NodeBB processes information in the following jurisdictions: Depending on the data center the hosted NodeBB is installed into.