Standard contractual clauses

Last updated: December 3, 2024

Categories of data subjects whose personal data is transferred:Categories of data subjects whose personal data is transferred:
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures:One a one-off basis in most cases, or as needed to provide the Services to Controller.
Nature of the processing:The Controller may configure their BrandChamp account to request personal data from ambassadors for the purpose of evaluating entry into, and ongoing participation in, an ambassador program for the Controller. The Controller may also import personal data of ambassadors into the BrandChamp system. BrandChamp may collect and process personal data for the purposes detailed here and as detailed in the Agreement and the Privacy Policy.
Purpose(s) of the data transfer and further processing:To provide the Services to Controller.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period:As long as necessary to provide the Services.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing:First name, last name, email are passed to subprocessors for the purpose of sending emails. Processing is performed for only as long as necessary.
Identify the competent supervisory authority/ies in accordance (e.g. in accordance with Clause 13 SCCs)The Data Protection Commission, Ireland
Measure Description
Measures of pseudonymisation and encryption of personal data
Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and servicesProcessor uses Amazon Web Service’s PostgreSQL Relational Database Service running in high availability mode (distributed over multiple AWS Availability Zones), running in Processor’s own Virtual Private Cloud, and use AWS security groups to tightly control access
Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incidentProcessor uses Amazon Web Service’s PostgreSQL Relational Database Service which performs automated ongoing backups. Processor also perform full daily database backups and stores in a secured folder in AWS S3 for maximum availability.
Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures in order to ensure the security of the processingProcessor performs regular peer reviews of all changes to their platform.
Measures for user identification and authorisationProcessor uses digitally signed JSON Web Tokens for authentication along with a role-based authorization system in Processor’s API
Measures for the protection of data during transmissionProcessor public services are accessed via encrypted HTTPS protocol. Processor runs API and backend services inside an AWS Virtual Private Cloud with strict access controls.
Measures for the protection of data during storageProcessor uses Amazon Web Service’s PostgreSQL Relational Database Service which encrypts data stored at rest as well as it’s automated backups, read replicas and snapshots. Database backups are also stored in a non-public AWS S3 bucket accessible only by limited members of Processor’s engineering team.
Measures for ensuring physical security of locations at which personal data are processedPersonal data is processed in AWS services which implements industry leading access controls. For more details please see: https://aws.amazon.com/compliance/data-center/controls/
Measures for ensuring events loggingProcessor logs relevant application events to a centralized log management system and reviews regularly
Measures for ensuring system configuration, including default configurationProcessor stores system configuration in a text-based configuration management system and tracks changes via the Git source control system
Measures for internal IT and IT security governance and managementProcessor’s engineering team regularly reviews security related issues and performs regular code reviews
Measures for certification/assurance of processes and productsProcessor maintains a large suite of automated tests to ensure quality of product
Measures for ensuring data minimisationProcessor only collects information necessary to perform the Services.
Measures for ensuring data qualityProcessor has implemented reasonable verification standards.
Measures for ensuring limited data retentionProcessor retains data only for as long as reasonably necessary to perform the Services and comply with its legal obligations.
Measures for ensuring accountability
Measures for allowing data portability and ensuring erasureProcessor has published a privacy policy with instructions on how to request this information.