Application
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between ANTHONY OLIVA, INC. (“Anthony Oliva”, “Processor”) and the customer (“Customer”, “Controller”). It applies where Anthony Oliva processes personal data on the Customer’s behalf and where that processing is subject to the EU General Data Protection Regulation, the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended, or a comparable law.
If the Customer is itself a processor for another controller, Anthony Oliva acts as a sub-processor and the Customer confirms it has the controller’s authority to appoint us.
Where this DPA conflicts with the Terms of Service, this DPA prevails for matters of data protection.
Roles of the parties
The Customer is the controller of the personal data it submits to the platform, including recipient telephone numbers, message content, and consent records. The Customer determines the purposes and means of processing and is solely responsible for the lawfulness of the data it submits, including obtaining valid consent from recipients.
Anthony Oliva is the processor and will process personal data only on the Customer’s documented instructions, which comprise the Terms of Service, this DPA, and the Customer’s use of the platform, unless required otherwise by law. Where the law requires other processing, we will inform the Customer beforehand unless the law prohibits it.
Telecommunications providers used to carry messages are not processors of Anthony Oliva nor sub-processors of the Customer. They act as independent controllers of the traffic data they handle in order to route and terminate the message on their networks.
For the purposes of the CCPA, Anthony Oliva is a service provider. We will not sell or share personal information, will not retain, use, or disclose it for any purpose other than performing the services, and will not combine it with personal information from other sources except as permitted by the CCPA.
Details of processing
Subject matter. Provision of the A2P messaging platform and related registration, delivery, and support services.
Duration. For the term of the Terms of Service, plus the retention periods stated in our Privacy Policy.
Nature and purpose. Transmission, routing, storage, delivery reporting, campaign registration, abuse prevention, and technical support.
Categories of data subject. The Customer’s message recipients, and the Customer’s own personnel who administer the account.
Categories of personal data. Mobile telephone numbers, message content submitted by the Customer, delivery metadata, consent records, and account administrator contact details. The Customer must not submit special categories of data unless expressly agreed in writing.
Confidentiality and personnel
We limit access to personal data to personnel who need it to deliver the services. All personnel are bound by written confidentiality obligations that survive the end of their engagement and receive data protection training appropriate to their role.
Security measures
We implement and maintain the technical and organizational measures described on our Security page, including at minimum:
- TLS 1.2 or higher for data in transit, including API requests and webhook deliveries
- Encryption at rest for production databases and backups
- Role-based access control with least privilege, reviewed quarterly
- Mandatory multi-factor authentication for administrative and production access
- Scoped, revocable API credentials
- Network segmentation and restricted administrative ingress
- Centralized logging with twelve months of audit retention
- Documented backup, restoration, and incident response procedures, tested annually
- Vulnerability management with regular dependency and infrastructure patching
We may update these measures provided the overall level of security is not reduced.
Sub-processors
The Customer gives a general authorization for Anthony Oliva to engage sub-processors. Our current sub-processors are listed at anthonyoliva.com/legal/sub-processors.
Before engaging a new sub-processor we carry out security and privacy due diligence and put in place a written contract imposing data protection obligations no less protective than those in this DPA. We remain liable for the acts and omissions of our sub-processors.
We will give at least 30 days’ notice before adding or replacing an infrastructure sub-processor and at least 10 days’ notice for any other sub-processor. Notice is given by email to account administrators who have subscribed on the sub-processors page. If the Customer objects on reasonable data protection grounds within the notice period, the parties will discuss in good faith; if no resolution is reached, the Customer may terminate the affected services without penalty.
Assistance to the Customer
Taking into account the nature of the processing, we will:
- Assist the Customer in responding to data subject requests for access, correction, deletion, restriction, portability, and objection. Where a request comes directly to us, we will route it to the Customer rather than respond, unless legally required to respond.
- Provide the information reasonably necessary for the Customer to carry out a data protection impact assessment or prior consultation.
- Make available the information necessary to demonstrate compliance with this DPA, and allow audits by the Customer or an independent auditor no more than once a year, on 30 days’ notice, during business hours, subject to confidentiality and at the Customer’s cost. Where available, we may satisfy an audit request by providing a current third-party report.
Personal data breach
We will notify the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Customer’s personal data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Where full information is not immediately available, we will provide it in phases.
We will cooperate with the Customer and take reasonable steps to mitigate the effects of the breach.
International transfers
Personal data is primarily processed in the United States. Where personal data is transferred from the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, the transfer is governed by the European Commission’s Standard Contractual Clauses (Module Two, controller to processor, or Module Three, processor to processor, as applicable), which are incorporated into this DPA by reference and completed as follows:
- Clause 7, the docking clause, applies
- Clause 9, option 2, general written authorization, with the notice periods in the Sub-processors section above
- Clause 11, the optional independent dispute resolution body, does not apply
- Clause 17, governing law, is the law of Ireland
- Clause 18(b), forum, is the courts of Ireland
- Annex I, II, and III are populated by the Details of processing, Security measures, and Sub-processors sections of this DPA
For UK transfers, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies, with the same annexes. For Swiss transfers, references to the GDPR are read as references to the Swiss FADP and the supervisory authority is the Federal Data Protection and Information Commissioner.
Deletion and return
On termination, and at the Customer’s choice, we will delete or return the personal data we process on the Customer’s behalf, and delete existing copies, unless retention is required by law. Deletion follows the retention schedule in our Privacy Policy. Backup copies are deleted on the standard backup expiry cycle.
Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
Signature
This DPA is incorporated by reference into the Terms of Service and is effective without separate signature. Customers who require a countersigned copy can request one from legal@anthonyoliva.com.
How to reach us
Questions about this document can be sent tolegal@anthonyoliva.com. Privacy requests go toprivacy@anthonyoliva.com. Abuse reports go toabuse@anthonyoliva.com or through ourabuse reporting form.
ANTHONY OLIVA, INC.
6724 Thompson Road, Syracuse, NY 13211, United States
+1 (332) 231-6423
support@anthonyoliva.com