Company
GET IN TOUCH
(+1) 732-385-3546 (US)
080-47359453 (India Sales)
080-46801265 (India Support)
62-87750-350-446 (ID)
© 2024 LeadSquared
This Data Processing Addendum (“DPA”) forms part of the LeadSquared’s Terms of Service available at https://www.leadsquared.com/leadsquared-terms-of-service/ or other written or electronic agreement (“Agreement”) including any written or electronic service orders, purchase orders or other order forms (each an “Order Form”) entered into between LeadSquared and Customer, pursuant to which LeadSquared provides Services (as defined in the Agreement) to the Customer.
The purpose of this DPA is to reflect the parties’ agreement with regard to the transfer and processing of any Personal Data that is entitled to protection under the EU Data Protection Laws, in the course of providing the Services
This DPA will take effect on the DPA Effective Date and, notwithstanding expiry of the Term, will remain in effect until, and automatically expire upon, deletion of all Customer Data by LeadSquared as described in this DPA.
This DPA includes the Standard Contractual Clauses attached hereto as Exhibit 1 along with (i) Appendix 1 to the Standard Contractual Clauses, which includes specifics on the Personal Data transferred by the data exporter to the data importer; Appendix 2 to the Standard Contractual Clauses, which includes a description of the technical and organizational security measures implemented by the data importer as referenced; and (iii) Appendix 3 to the Standard Contractual Clauses, which sets forth the List of Sub-Processors.
Processor will also facilitate Controller’s compliance with the Controller’s obligation to implement security measures with respect to Personal Data under the EU Data Protection laws.
For the purposes of Article 26(2) of Directive 95/46/EC for the transfer of personal data to processors established in third countries which do not ensure an adequate level of data protection,
The Customer, as defined in the LeadSquared Customer Terms of Service (the “data exporter”) with details as follows:
Name of the data exporting organization:
Customer’s Name and Address, as set out in the Order Form
And
Name of the data importing organisation:
MarketXpander Services Private Limited, 2nd Floor, Omega, Embassy TechSquare, Marathahalli-Sarjapur Outer Ring Road, Bellandur, Bangalore, Karnataka, India, 560103
each a ‘party’; together ‘the parties’,
HAVE AGREED on the following Contractual Clauses (the Clauses) in order to adduce adequate safeguards with respect to the protection of privacy and fundamental rights and freedoms of individuals for the transfer by the data exporter to the data importer of the personal data specified in Appendix 1.
For the purposes of the Clauses:
The data exporter agrees and warrants:
The data importer agrees and warrants:
This Appendix forms part of the Clauses. The Member States may complete or specify, according to their national procedures, any additional necessary information to be contained in this Appendix
This Appendix forms part of the Clauses.
Description of the technical and organizational security measures implemented by the data importer in accordance with Clauses 4(d) and 5(c) (or document/legislation attached):
LeadSquared currently observes the security practices described in this Appendix 2. Notwithstanding any provision to the contrary otherwise agreed to by data exporter, LeadSquared may modify or update these practices at its discretion provided that such modification and update does not result in a material degradation in the protection offered by these practices. All capitalized terms not otherwise defined herein shall have the meanings as set forth in the Agreement.
a) Access Control
b) Transmission Control
In-transit: LeadSquared makes HTTPS encryption (also referred to as SSL or TLS) available on every one of its login interfaces. LeadSquared’s HTTPS implementation uses industry standard algorithms and certificates.
All sensitive interactions with the LeadSquared products (e.g., API calls, login, authenticated sessions to the customer’s portal, etc.) are encrypted in-transit with TLS 1.2.
Certain information is encrypted or hashed at rest, based on the sensitivity of the information. For instance, user passwords are hashed. Contact Data like Lead information is encrypted at rest. Other information, like public web content, images, documents are not encrypted at rest.
c)Input Control
Detection: LeadSquared designed its infrastructure to log extensive information about the system behavior, traffic received, system authentication, and other application requests. Internal systems aggregated log data and alert appropriate employees of malicious, unintended, or anomalous activities. LeadSquared personnel, including security, operations, and support personnel, are responsive to known incidents.
Response and tracking: LeadSquared maintains a security incident response and tracking mechanism. Suspected and confirmed security incidents are investigated by security, operations, or support personnel; and appropriate resolution steps are identified and documented. For any confirmed incidents, LeadSquared will take appropriate steps to minimize product and Customer damage or unauthorized disclosure.
Communication: If LeadSquared becomes aware of unlawful access to customer data stored within its products, LeadSquared will: 1) notify the affected customers of the incident; 2) provide a description of the steps LeadSquared is taking to resolve the incident; and 3) provide status updates to the Customer contact, as LeadSquared deems necessary. Notification(s) of incidents, if any, will be delivered to one or more of the Customer’s contacts in a form LeadSquared selects, which may include via email or telephone.
d)Availability Control
LeadSquared maintains business continuity and disaster recovery plans focusing both on preventing outage through redundancy of telecommunications, systems and business operations, and on rapid recovery strategies in the event of an availability or performance issue. Whenever customer-impacting situations occur, LeadSquared’s goal is to quickly and transparently isolate and address the issue. Identified issues are published on LeadSquared’s status site and are subsequently updated until the issue is resolved.
Business continuity testing is part of LeadSquared normal processing. LeadSquared recovery processes are validated continuously through normal maintenance and support processes. We follow continuous deployment principles and create or destroy many server instances as part of our regular daily maintenance and growth. We also use those procedures to recover from impaired instances and other failures, allowing us to practice our recovery process every day.
LeadSquared primarily relies on infrastructure redundancy, real time replication and backups. All LeadSquared product services are built with full redundancy. Server infrastructure is strategically distributed across 2 distinct availability zones within our data center provider.
LeadSquared ensures data is replicated and backed up in multiple durable data-stores. The retention period of backups depends on the nature of the data. Data is also replicated across data-center availability zones in order to provide fault-tolerance within an availability zone as well as scalability and responsive recovery, when necessary. In addition, the following policies have been implemented and enforced for data resilience:
(+1) 732-385-3546 (US)
080-47359453 (India Sales)
080-46801265 (India Support)
62-87750-350-446 (ID)