When this addendum applies
This Data Processing Addendum (DPA) is offered by GENMARK TECHNOLOGIES INC, the Canton, Michigan, United States business providing Instaconnect, with registered mailing address 45697 SOUTHWICK DR, CANTON, MI 48188, United States. It applies when incorporated into a written service agreement with an identified customer. The parties must complete the deployment schedule described below and agree any required transfer mechanism before the relevant processing starts.
Publishing this document does not state that a DPA has already been executed with every visitor or customer, or that every deployment is suitable for regulated information. A signed DPA or mandatory transfer instrument prevails over conflicting general service terms for the processing it governs. Contact instasocial@instaconnect.io to arrange the agreement and schedules.
Roles, definitions and scope
"Customer Personal Data" means personal information processed by GENMARK TECHNOLOGIES INC on the customer’s behalf through the agreed service. The customer is controller, or a processor authorized by its controller; GENMARK TECHNOLOGIES INC is processor or subprocessor respectively. Each party retains its separate responsibilities for information it processes as an independent controller.
"Applicable Data Protection Law" means the data-protection law that applies to the relevant processing, including the EU GDPR, UK GDPR and applicable US state privacy laws where relevant. Terms such as personal data, controller, processor and personal data breach have the meanings assigned by the applicable law.
Documented instructions and customer duties
GENMARK TECHNOLOGIES INC shall process Customer Personal Data only on documented, lawful customer instructions, including the agreed service configuration and order, unless law requires otherwise. If legally permitted, GENMARK TECHNOLOGIES INC shall inform the customer of a legal requirement before such processing. GENMARK TECHNOLOGIES INC shall promptly inform the customer if it believes an instruction infringes Applicable Data Protection Law.
The customer shall establish the lawful basis, provide required notices, obtain required permissions and submit only information within the agreed scope. It shall maintain authority for any instruction issued on behalf of another controller and manage its users, integrations and retention choices lawfully.
Confidentiality and use restrictions
GENMARK TECHNOLOGIES INC shall ensure that people authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and receive relevant data-handling instructions. Access shall be limited to the duties needed to deliver, support and protect the agreed service.
GENMARK TECHNOLOGIES INC shall not sell Customer Personal Data or use it for its own unrelated advertising or general-purpose model training under this DPA. Where applicable US law requires service-provider or contractor restrictions, GENMARK TECHNOLOGIES INC shall not retain, use, disclose or combine the data outside the permitted business purposes and direct business relationship, except as that law permits. GENMARK TECHNOLOGIES INC shall notify the customer if it can no longer meet the applicable contractual restrictions and cooperate with reasonable steps to stop and remediate unauthorized use.
Security measures
For a deployment governed by this DPA, GENMARK TECHNOLOGIES INC shall implement and maintain measures appropriate to the nature of the data and the risks, considering available technology, implementation costs and the nature, scope and purposes of processing. The agreed security schedule must identify the actual measures and shared responsibilities for that deployment.
The schedule shall address access authorization and offboarding; protection in transit and storage; credential and secret handling; separation of customer data; logging and incident handling; backup and restoration; vulnerability management; and procedures for reviewing effectiveness. Customer-configured integrations, device security and participant permissions remain within the customer’s responsibility unless expressly agreed otherwise. No certification, customer-managed key feature or data-residency guarantee is created merely by this paragraph.
Subprocessors
The customer must give prior specific or general written authorization for subprocessors. The initial authorized list shall identify each entity, function and relevant processing location. A marketing integration directory is not that list. GENMARK TECHNOLOGIES INC shall bind each subprocessor to data-protection obligations appropriate to its processing and offering at least the protection required by this DPA, and remains responsible for its subprocessor obligations.
Where general authorization is agreed, GENMARK TECHNOLOGIES INC shall give at least 30 days’ advance notice of an intended addition or replacement, unless an urgent security or continuity event requires shorter notice. The customer may object on reasonable data-protection grounds. The parties shall try to resolve the concern through an alternative or affected-feature restriction; if they cannot, the customer may terminate the affected processing before the change takes effect, subject to arrangements that preserve legally required protection.
Individual requests and compliance assistance
Taking into account the nature of the processing, GENMARK TECHNOLOGIES INC shall provide reasonable assistance through appropriate technical and organizational measures so the customer can respond to requests to exercise privacy rights. GENMARK TECHNOLOGIES INC shall forward a request concerning customer-controlled data to the customer and shall not decide the response independently except where law requires.
Taking into account the information available, GENMARK TECHNOLOGIES INC shall assist the customer with security obligations, breach notifications, data-protection impact assessments and consultation with supervisory authorities where required. The parties may agree reasonable charges for exceptional assistance, but charges shall not prevent compliance with mandatory obligations or excuse a breach of this DPA.
Personal data incidents
GENMARK TECHNOLOGIES INC shall notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notification shall include information then available about the nature of the incident, affected data and individuals, likely consequences, measures taken or proposed, and a contact for follow-up. Information may be provided in phases as an investigation develops.
GENMARK TECHNOLOGIES INC shall take reasonable steps to contain, investigate and remediate the incident and cooperate with the customer’s legally required notifications. An incident notice is not an admission of liability. The customer remains responsible for notices for which it is legally accountable unless otherwise required or agreed.
International transfers
GENMARK TECHNOLOGIES INC shall not make a restricted international transfer of Customer Personal Data without a lawful mechanism and the required customer instruction or authorization. The deployment schedule must identify relevant locations and any applicable safeguards.
Where required, the parties shall execute the appropriate EU Standard Contractual Clauses, UK International Data Transfer Agreement or UK Addendum, and complete their annexes and required transfer assessment before the transfer. No such instrument is represented as executed or incorporated solely by this public DPA. If lawful safeguards cannot be established, the affected processing must not proceed.
Return, deletion and retained copies
At the end of the relevant service, GENMARK TECHNOLOGIES INC shall, at the customer’s choice, return or delete Customer Personal Data and delete existing copies unless applicable law requires retention. The parties shall document the return format, active-system deletion period and backup removal period in the deployment schedule.
Any information retained because of a legal requirement shall remain protected, be used only for that requirement and be deleted when the requirement ends. Backup data awaiting routine removal shall remain restricted and shall not be restored for an unrelated use. GENMARK TECHNOLOGIES INC shall provide reasonable confirmation of completion on request.
Information, audits and records
GENMARK TECHNOLOGIES INC shall make available information reasonably necessary to demonstrate compliance with this DPA and permit and contribute to audits and inspections by the customer or its authorized independent auditor. The parties may use relevant documentation first and agree proportionate arrangements that protect other customers, security and confidential information.
Reasonable notice, confidentiality and scheduling requirements must not prevent an audit required by law, a regulator or a material incident. Each party shall maintain records and cooperation required of it by Applicable Data Protection Law.
Processing schedule: baseline scope
Subject matter and purpose: providing the specifically ordered Instaconnect communication, scheduling, event, AI or recording features on documented customer instructions. Nature of operations: collection, transmission, organization, storage, retrieval, authorized disclosure, analysis where enabled, return and deletion.
People involved may include the customer’s staff and authorized users, website visitors, business contacts, meeting participants and event registrants or attendees. Data may include business identifiers and contact details, messages and knowledge content, booking and event records, service metadata, and media, recordings, transcripts or summaries when expressly enabled.
Duration: the agreed service term plus the documented return/deletion period. Frequency: as customer activity requires within the enabled features. Clinical information, protected health information, payment-card credentials and other sensitive categories are excluded unless a separate supported arrangement expressly permits them. This standard DPA does not offer a BAA.
Completing the deployment schedule
Before this DPA is used, the parties shall record: their exact legal names and notice contacts; the customer’s controller or processor role; ordered products and enabled features; permitted data and individuals; locations and transfer instruments; authorized subprocessors; actual security measures; assistance contacts; and the return, deletion and backup periods.
These details form part of the executed agreement and cannot be inferred from a product logo, a website hosting provider or a generic policy. Send a DPA request to instasocial@instaconnect.io identifying the organization, intended workflow and relevant requirements.