Between Casentra Limited (processor) and the Customer (data user). Forms part of the Terms of Service.
1.1 This DPA applies where Casentra processes Client Data on behalf of Customer in providing the Service.\
\
1.2 Customer acts as the data user/controller or authorised representative of the relevant data user, depending on the applicable relationship. Casentra acts as a data processor/service provider when processing Client Data on Customer's documented instructions.\
\
1.3 Customer is responsible for ensuring that Client Data is collected, disclosed and processed lawfully, including providing required notices and obtaining necessary consents, permissions or authorisations under applicable laws and regulatory requirements.\
\
1.4 Casentra processes Client Data only:\
(a) on Customer's documented instructions;\
(b) as necessary to provide, maintain, secure and support the Service; or\
(c) where required by applicable law.
2.1 Casentra does not use identifiable Client Data, prompts, uploaded files or Customer-specific content submitted through the Service to train or fine-tune general-purpose AI models for unrelated customers.\
\
2.2 Casentra may process Client Data as technically necessary to provide AI Features requested by Customer, including generating Outputs and operating the Service.\
\
2.3 Casentra may use aggregated, anonymised or de-identified information that does not reasonably identify Customer, any client or any individual for purposes including analytics, security, reliability, performance optimisation and improvement of the Service, where permitted by Applicable Laws.
Casentra treats Client Data as confidential and restricts access to personnel and service providers who need access to provide, maintain or secure the Service. Such parties are subject to appropriate confidentiality obligations.
Casentra maintains reasonable technical and organisational measures designed to protect Client Data against unauthorised access, disclosure, alteration, loss or misuse.\
\
Such measures may include:\
(a) access controls;\
(b) authentication mechanisms;\
(c) encryption safeguards;\
(d) monitoring and logging;\
(e) backup and recovery procedures;\
(f) vulnerability management; and\
(g) confidentiality and security practices for personnel.\
\
Security measures may be updated from time to time as technology, risks and the Service evolve.\
\
Casentra's primary application infrastructure may be hosted in Hong Kong. Certain Service features, including AI-powered functionality, may require Client Data to be processed by third-party technology providers located outside Hong Kong. Such processing will be conducted subject to applicable contractual, technical and organisational safeguards.
5.1 Customer authorises Casentra to engage subprocessors to process Client Data.\
\
Categories of subprocessors may include:\
\
5.2 Casentra maintains a current list of material subprocessors and may update such list from time to time.\
\
5.3 Casentra requires subprocessors to undertake obligations relating to confidentiality, security and data protection that are appropriate to the services provided.\
\
5.4 Casentra remains responsible for its subprocessors' processing activities to the extent required by Applicable Laws.
Where Client Data is transferred internationally, Casentra will implement reasonable contractual, technical and organisational safeguards appropriate to the nature of the processing and applicable legal requirements.
Taking into account the nature of processing, Casentra will provide reasonable assistance to Customer in responding to requests from individuals relating to Client Data.\
\
Where an individual contacts Casentra directly regarding Client Data, Casentra may direct the individual to Customer and provide reasonable assistance where appropriate.
Casentra will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Client Data.\
\
Where reasonably available, Casentra will provide information regarding the nature of the breach, affected data categories, likely impact, mitigation measures and relevant updates as information becomes available.
Upon termination or Customer's written instruction, Casentra will delete or return Client Data in accordance with applicable legal requirements, contractual obligations and Casentra's retention policies.\
\
Backup copies may remain temporarily until overwritten through normal backup cycles.
Casentra will make available information reasonably necessary to demonstrate compliance with this DPA.\
\
Customer shall first request reasonably available compliance information before conducting an audit.\
\
Any audit shall be conducted on reasonable prior notice, subject to confidentiality obligations and without unreasonable disruption to Casentra's operations.
If Casentra receives a legally binding request from an authority for Client Data, Casentra will, unless legally prohibited, notify Customer and disclose only the information legally required.
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Casentra Terms of Service.
This DPA forms part of the Casentra Terms of Service. Capitalised terms not defined in this DPA have the meanings given in the Terms of Service.