Data Processing Agreement

INTRODUCTION

This data processing agreement (Data Processing Agreement) is a legal agreement in connection with the provision of service that forms an integral part of and applies in addition to the existing Service Contract concluded by and between the User as defined in such contract and Plain Tiger Inc in connection with the provision of specific services. Any capitalized words used in this Data Processing Agreement shall have the meaning attributed to it in the Service Contract unless specifically defined in this Data Processing Agreement. Plain Tiger reserves the right to make, at its sole discretion, make any changes to this Data Processing Agreement as long as these do not materially impact the rights of the User. Plain Tiger shall notify the User of any such changes.

GENERAL DESCRIPTION OF PROCESSING ACTIVITIES

  1. Details of Processing
    Plain Tiger offers services to the User consisting of an online platform that functions as a B2B Marketplace. Users can be a Brand and/or Retailer on this platform and have control over specific data relating to identified or identifiable individuals (Personal Data) which it will process through the services offered by Plain Tiger.

  2. Purpose
    Plain Tiger can process Personal Data on behalf of the User for the purpose of providing the Services under the Service Contract to the User. It may further process personal data for any other purpose pursuant to a specific instruction it receives from the user.

  3. Categories of Data Subjects
    The personal data of the following data subjects will be processed by Plain Tiger: Employees and other persons who have an account to access and use the Platform Customers

  4. Categories of Personal Data
    ● Name (first and/or last)
    ● Contact information (email address, home address, phone number)
    ● Language
    ● Gender
    ● Date of Birth
    ● IP Address
    ● Geographical data
    ● Employer information (company,  title, company details)
    ● Bank account details
    ● Other payment account details (credit card, paypal, etc.)

  5. Duration of processing activities
    Plain Tiger shall process the Personal Data for the duration of the Services or until the User requests Plain Tiger to cease the processing of Personal Data.

SPECIFIC COVENANTS

  1. Introduction
    Both Plain Tiger and the User are familiar with the General Data Protection Regulation and shall use its best efforts to comply with all statutory requirements in the processing of personal data. User hereby instructs Plain Tiger, in its capacity as processor, to process the personal data of the User as specified in the description above. Plain Tiger hereby accepts these instructions and in that respect covenants and agree to comply with the terms as specified in this Data Processing Agreement.

  2. Processing of Personal Data
    Plain Tiger shall process Personal Data only on the documented instructions of the User. If Plain Tiger is required to process Personal Data in compliance with the law to which Plain Tiger is subject, it will inform the User of such legal requirement prior to such processing, unless such law which Plain Tiger is subject to prohibits it from doing so.

  3. Sub-processors
    Plain Tiger may engage the sub-processors as described at the bottom of this Data Processing Agreement and any other processors to process Personal Data on Customer’s behalf. Plain Tiger shall inform the User of any intended changes concerning the addition or replacement of (sub-) processors that process Personal Data of the User and give the User the opportunity to object to such changes.

  4. Security
    Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Plain Tiger shall in relation to the Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk. In assessing the appropriate level of security, Plain Tiger shall take into account the risks that are presented by the processing, in particular in relation to a personal data breach.

  5. Data Subject Requests
    Plain Tiger shall promptly notify the User if it receives a request from an individual with respect to Personal Data, including but not limited to information access requests, information rectification requests, requests for blocking, erasure, or portability of Personal Data and shall not respond to any such requests unless expressly authorized to do so by the User or unless required under a law to which Plain Tiger is subject. Plain Tiger shall ensure that it has implemented technical and organizational measures to assist Customer in fulfilling its obligation to respond to any such requests from an individual with respect to Personal Data processed.

  6. Personal Data Breach
    Plain Tiger shall notify the User without undue delay upon becoming aware of a Personal Data breach affecting Personal Data, providing the User with sufficient information to allow the User to meet any obligations to report or inform data subjects of the Personal Data Breach under the data protection laws. Plain Tiger shall cooperate with the User and take reasonable commercial steps as are directed by the User to assist in the investigation, mitigation and remediation of each such Personal Data breach.

  7. Data Protection Impact Assessment
    Plain Tiger shall provide reasonable assistance to the User with any data protection impact assessments, and prior consultations with supervising authorities or other competent data privacy authorities.

  8. Data Transfers
    Plain Tiger may only subcontract (part of the) Services to third parties if Plain Tiger ensures that such third parties are bound in writing to the same obligations. Plain Tiger shall only transfer or authorize the transfer of Personal Data if it ensures that the Personal Data is adequately protected.

  9. Confidentiality
    Plain Tiger shall hold Personal Data in strict confidentiality and require employees and any other person under its authority who will be provided access to or will otherwise process Personal Data are held to the same level of confidentiality in accordance with the requirements of the Data Processing Agreement (including during the term of their employment or engagement and thereafter).

  10. Disclosure
    Plain Tiger shall not disclose Personal Data to any third party or unauthorized persons, unless the User has given its prior written consent to such disclosure and subject to the obligations under this Data Processing Agreement.

  11. Third Party Inquiries
    Plain Tiger shall promptly inform the User if: 

    1. it receives an inquiry, a subpoena or a request for inspection or audit from a competent public authority relating to the processing of Personal Data under this Data Processing Agreement, except where Plain Tiger is otherwise prohibited by law from making such disclosure; or 

    2. it intends to disclose Personal Data to any competent public authority. In case of inspection or audits by a competent governmental authority relating to the processing of Personal Data, Plain Tiger shall make available its relevant processing systems, facilities and supporting documentation to the relevant competent public authority for an inspection or audit if this is necessary to comply with applicable laws. In the event of any inspection or audit, each party shall provide all reasonable assistance to the other party in responding to that inspection or audit. If a competent public authority deems the processing of Personal Data under this Data Processing Agreement unlawful, the parties shall take immediate action to ensure future compliance with applicable data protection law.

  12. Non-compliance by Plain Tiger
    In the event that 

    1. Plain Tiger is unable to comply with the material obligations stated in this Agreement, where any obligation required by law is considered material, or 

    2. Plain Tiger becomes aware of any circumstances or changes in applicable data protection law that is likely to have a substantial adverse effect on Plain Tiger’s ability to meet its obligations under the Agreement, Plain Tiger shall promptly notify the User to this effect, and the User shall then be entitled, at its option, to 

      1. suspend all transfers of Personal Data until such time that the non-compliance is remedied, 

      2.  require Plain Tiger to cease processing relevant Personal Data until such time that the non-compliance is remedied, and/or 

      3. immediately terminate this Agreement.

  13. Termination of processing
    Upon termination or expiration of the Services for whatever reason, or upon request by the User, Plain Tiger shall immediately cease to process Personal Data and shall promptly return to the User all such Personal Data, or delete the same, in accordance with such instructions as may be given by User at that time, unless it is required to store the Personal Data under a law to which Plain Tiger is subject or unless explicitly agreed otherwise with the User.

The User hereby gives Plain Tiger permission to engage the following sub-processors on Plain Tiger’s behalf:

  • Google  - Hosting of data - United States

  • Shopify - Software platform - United States

  • Shopify payments - Payment solutions provider - United States

  • Paypal - Payment solutions provider - United States

  • DHL - Logistics provider - International

This list may change over time as we add/change our partners. Please refer to this website for the latest information - changes to this list will not be continuously communicated.