DATA PROCESSING AGREEMENT
Section 4.1 lists our current sub-processors by name. We will update it when we add one, such as a payment processor.
(Addendum to the Greendex Master Subscription Agreement)
This Data Processing Agreement (“DPA”) is entered into between United Green Connections, LLC (“Company”) and the Customer that has executed a Sales Order incorporating the Greendex Master Subscription Agreement (the “Agreement”). This DPA applies only to the extent Company processes Personal Data on Customer’s behalf as described below, and supplements, without replacing, the Agreement. This DPA is available upon Customer’s request and, once executed or accepted by the parties, is incorporated into the Agreement by reference.
1. Definitions
• “Applicable Data Protection Laws” means all state, federal, and other laws and regulations applicable to the processing of Personal Data under this DPA, including applicable U.S. state privacy laws.
• “Controller” means the party that determines the purposes and means of processing Personal Data. For purposes of this DPA, Customer is the Controller of the Personal Data described in Section 2.
• “Processor” means the party that processes Personal Data on behalf of, and under the instructions of, a Controller. For purposes of this DPA, Company is the Processor.
• “Personal Data” means information relating to an identified or identifiable individual that Company processes on Customer’s behalf in connection with the Services, such as the business contact and account information described in Section 2 of this DPA.
• “Data Subject” means the individual to whom Personal Data relates.
• “Sub-processor” means a third party engaged by Company to process Personal Data on Company’s behalf in connection with providing the Services.
• “Personal Data Breach” means a confirmed unauthorized access to, or acquisition, disclosure, alteration, or destruction of, Personal Data processed under this DPA.
2. Scope of Processing
2.1 Personal Data Covered. This DPA covers Personal Data that Company processes on Customer’s behalf as a Processor, namely: account and business contact information (names, business emails, phone numbers, titles) of Customer’s personnel and authorized users, and License on File information, each as described in the Privacy Policy.
2.2 Excluded Activity — Cannabis Market Data. This DPA does not apply to Company’s generation, aggregation, or publication of Cannabis Market Data described in Sections 6 and 8 of the Agreement. With respect to that activity, Company acts as an independent controller of the underlying business data (which does not itself constitute Personal Data once aggregated and non-attributable), and not as Customer’s Processor. For the avoidance of doubt, Company does not process identifiable Personal Data as part of Cannabis Market Data.
2.3 Nature and Purpose. Company processes Personal Data described in Section 2.1 solely to provide, maintain, and support the Services, to communicate with Customer’s personnel, and to perform Company’s obligations under the Agreement, in each case in accordance with Customer’s documented instructions as set out in the Agreement and this DPA, unless otherwise required by applicable law.
2.4 Duration. Company will process Personal Data under this DPA for the duration of the Agreement, and thereafter only as necessary to comply with Section 8 (Return or Deletion of Data) or applicable law.
3. Company’s Obligations
3.1 Processing on Instructions. Company will process Personal Data only on Customer’s documented instructions, including those reflected in the Agreement and this DPA, unless required to do otherwise by applicable law, in which case Company will inform Customer of that legal requirement before processing, unless the law prohibits such notice.
3.2 Personnel Confidentiality. Company will ensure that personnel authorized to process Personal Data are subject to confidentiality obligations consistent with Section 7 of the Agreement.
3.3 Security Measures. Company will implement appropriate administrative, technical, and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, consistent with Section 11 of the Privacy Policy.
3.4 Assistance with Data Subject Requests. Taking into account the nature of the processing, Company will provide reasonable assistance to Customer, at Customer’s expense for anything beyond ordinary support, to enable Customer to respond to verified requests from Data Subjects to exercise their rights under Applicable Data Protection Laws, to the extent Customer cannot reasonably fulfill such requests independently using the Services.
4. Sub-processors
4.1 General Authorization. Customer authorizes Company to engage Sub-processors to process Personal Data in connection with providing the Services. Company’s current Sub-processors are: Vercel (website and application hosting); Supabase (database, user authentication, and file storage hosting); Resend (email delivery); Cloudflare (bot and abuse protection at sign-up and sign-in, through its Turnstile service); and Anthropic (automated processing of documents and content Customer uploads, such as detecting information to redact from certificates of analysis). Company does not currently use a payment processor as a Sub-processor, because buyers pay sellers directly, and does not currently send SMS or text messages. Company will update this list as provided in Section 4.3 when it adds a Sub-processor, including a payment processor.
4.2 Sub-processor Obligations. Company will impose data protection obligations on each Sub-processor that are substantially consistent with those in this DPA, and Company remains responsible for each Sub-processor’s performance of those obligations.
4.3 Notice of New Sub-processors. Company will provide notice of the addition of a new Sub-processor by posting an updated list or providing notice consistent with Section 5.4 of the Agreement. If Customer reasonably objects to a new Sub-processor on legitimate data protection grounds within fifteen (15) days of notice, the parties will discuss in good faith; if the objection is not resolved, Customer’s sole remedy is to terminate the affected Service in accordance with the Agreement.
5. Personal Data Breach Notification
Company will notify Customer without undue delay, and in any event within seventy-two (72) hours of confirming a Personal Data Breach affecting Personal Data processed under this DPA, and will provide information reasonably available to Company regarding the nature of the breach, the categories and approximate number of Data Subjects and records affected, and the measures taken or proposed to address it. Company’s notification of, or response to, a Personal Data Breach is not an acknowledgment of fault or liability.
6. International Transfers
Company processes Personal Data covered by this DPA within the United States. Company will provide advance notice to Customer before transferring Personal Data covered by this DPA outside the United States, other than to a Sub-processor already disclosed under Section 4.
7. Audits
Upon Customer’s written request, no more than once per twelve-month period, Company will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, such as a summary of Company’s security practices or relevant third-party certifications then held by Company, if any. Any on-site or third-party audit is subject to reasonable advance notice, confidentiality protections, and scheduling that does not unreasonably interfere with Company’s operations, and may be conducted at Customer’s expense.
8. Return or Deletion of Data
Upon termination or expiration of the Agreement, Company will, at Customer’s written election made within thirty (30) days of termination, delete or return the Personal Data described in Section 2.1 then in Company’s possession, except to the extent Company is required to retain copies under applicable law or for legitimate business archival purposes consistent with Section 5 of the Agreement (or the Privacy Policy). For the avoidance of doubt, this Section does not require deletion of Cannabis Market Data, which is addressed separately in Section 2.2 of this DPA and Section 8.1 of the Agreement.
9. Liability; Relationship to the Agreement
Each party’s liability arising out of or relating to this DPA is subject to the limitations of liability set forth in Section 11 of the Agreement. In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls; the Agreement otherwise controls as to all other matters.
10. Term; Governing Law
This DPA takes effect upon the effective date of the Agreement (or, if later, upon Customer’s request and Company’s countersignature or acceptance) and remains in effect for as long as Company processes Personal Data on Customer’s behalf. This DPA is governed by the laws of the State of Michigan, consistent with Section 15.1 of the Agreement.
United Green Connections, LLC. Questions about this document: info@unitedgreenbrands.com.