1. Scope and Incorporation
This Data Processing Addendum ("DPA") forms part of the agreement between Playto, Inc., a Delaware corporation at 8 The Green, Ste R, Dover, DE 19901, United States ("Playto") and the business customer that has entered into an agreement with Playto ("Customer").
This DPA applies only to the extent Playto processes Covered Data on behalf of Customer as a Processor, Service Provider, Contractor, Subprocessor or equivalent role under Applicable Data Protection Law in connection with a feature or service covered by the parties' agreement ("Covered Services").
This DPA does not convert Playto's independent-controller activities into processor activities. In particular, Playto generally acts as an independent Controller for its Merchant of Record functions, Buyer transactions, billing, tax, fraud prevention, sanctions and compliance screening, disputes, Trust Score, account security and other purposes for which Playto determines the purposes and essential means of processing. Those activities are governed by the Privacy Policy and the applicable commercial terms.
If this DPA conflicts with the parties' agreement solely regarding Playto's processing of Covered Data as Customer's Processor, this DPA controls to that extent. Mandatory Applicable Data Protection Law and applicable Standard Contractual Clauses control where they cannot lawfully be varied.
2. Definitions
For this DPA:
- Applicable Data Protection Law means privacy and data-protection law applicable to the processing of Covered Data under this DPA, including, where applicable, the EU GDPR, UK GDPR, Swiss Federal Act on Data Protection, California Consumer Privacy Act as amended, and other applicable comprehensive privacy laws.
- Controller includes a controller, "business" or equivalent entity that determines the purposes and means of processing under the applicable law.
- Covered Data means Personal Data processed by Playto on behalf of Customer under the Covered Services.
- Data Subject means the identified or identifiable individual to whom Personal Data relates.
- Personal Data includes personal data, personal information and equivalent terms under Applicable Data Protection Law.
- Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Covered Data.
- Process and Processing have the meanings given under Applicable Data Protection Law.
- Processor includes a processor, service provider, contractor, subprocessor or equivalent role processing Personal Data on behalf of another entity.
- Subprocessor means a third party engaged by or on behalf of Playto to process Covered Data on behalf of Customer.
- EU SCCs means the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, as lawfully replaced or updated.
- UK Addendum means the then-current International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office, where applicable.
3. Roles of the Parties
For Covered Data processed under this DPA, Customer is the Controller and Playto is the Processor unless the parties' written arrangement identifies Customer as a Processor for another Controller, in which case Playto acts as Customer's Subprocessor to the extent required by law.
Each party remains independently responsible for processing for which it acts as Controller. Nothing in this DPA creates a joint-controller relationship merely because the parties exchange information in connection with a professional-service transaction.
Where the same item of Personal Data is processed by Playto both on Customer's instructions for a Covered Service and separately for Playto's own Merchant of Record, security, tax, fraud, compliance or legal purposes, this DPA applies only to the instructed processing. Playto's separate controller processing remains governed by Applicable Data Protection Law and the Privacy Policy.
4. Customer Responsibilities
Customer will comply with Applicable Data Protection Law for the Covered Data it provides or makes available to Playto and for the instructions it gives Playto.
Customer is responsible for ensuring that it has an appropriate lawful basis, authority and required notices or consents for Playto to process Covered Data in accordance with Customer's documented instructions.
Customer will not instruct Playto to process Covered Data in a manner that violates Applicable Data Protection Law. Customer will provide only data reasonably necessary for the Covered Services and will not use the Covered Services as a general repository for unrelated Personal Data.
Unless the Covered Service and parties' written agreement expressly permit it, Customer will not submit special-category, highly sensitive, biometric, health, government-identifier or similarly regulated data where heightened contractual or legal safeguards are required.
5. Documented Instructions
Playto will process Covered Data only on Customer's documented instructions, including instructions contained in the parties' agreement, an applicable order or Service Order, Customer's configured use of the Covered Services, and other written instructions accepted by Playto.
Customer instructs Playto to process Covered Data as necessary to provide, secure, maintain and support the Covered Services and to make transfers authorized by this DPA and the applicable order.
If Playto is required by law to process Covered Data other than on Customer's instructions, Playto will inform Customer of that legal requirement before processing unless the law prohibits such notice.
Playto will inform Customer without undue delay if, in Playto's reasonable opinion, an instruction infringes Applicable Data Protection Law and may suspend the affected instruction while the parties address the issue.
6. Confidentiality
Playto will ensure that persons authorized to process Covered Data are subject to appropriate confidentiality obligations or a statutory duty of confidentiality and receive access only as reasonably necessary for their functions.
Playto will limit internal access to Covered Data based on legitimate business need and will take reasonable steps to ensure personnel with access understand the applicable privacy and security obligations.
7. Security Measures
Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks to individuals, Playto will implement and maintain appropriate technical and organizational measures designed to protect Covered Data.
The minimum control categories applicable to the Covered Services are described in Annex 2. The parties acknowledge that specific controls may differ by system and risk, but Playto will not materially reduce the overall level of protection for Covered Data during the applicable term without a lawful basis and appropriate notice where required.
Annex 2 describes contractual security commitments and does not represent that Playto holds a particular certification, audit report or attestation unless Playto separately confirms that status in writing.
8. Personal Data Breaches
After becoming aware of a Personal Data Breach affecting Covered Data, Playto will notify Customer without undue delay where notification is required by Applicable Data Protection Law.
To the extent reasonably available, the notice will describe the nature of the breach, relevant categories of data or individuals, likely consequences, measures taken or proposed, and a contact for follow-up. Playto may provide information in phases as an investigation develops.
Playto will take reasonable steps to contain, investigate and remediate the breach and will reasonably assist Customer with Customer's legally required breach assessment and notifications, taking into account the nature of the processing and information available to Playto.
Notification under this section is not an admission of fault or liability.
9. Data Subject Requests
Taking into account the nature of the processing, Playto will provide reasonable assistance through appropriate technical and organizational measures to help Customer respond to requests from Data Subjects exercising rights under Applicable Data Protection Law.
If Playto receives a request relating to Covered Data processed solely on Customer's behalf, Playto may direct the requester to Customer and will notify Customer where legally required or reasonably necessary. Playto will not independently fulfill the request concerning Customer-controlled processing unless Customer instructs Playto to do so or applicable law requires Playto to respond.
Where the request also concerns information for which Playto acts as independent Controller, Playto may respond directly with respect to that controller processing.
10. DPIAs, Risk Assessments and Regulatory Consultation
Taking into account the nature of the processing and information available to Playto, Playto will provide reasonable assistance with a data-protection impact assessment, transfer assessment, privacy risk assessment, cybersecurity audit support or prior consultation that Customer is legally required to conduct specifically because of Playto's processing of Covered Data.
Assistance may include relevant information about processing activities, Subprocessors, transfers and security measures that Playto can lawfully disclose. Customer remains responsible for determining whether its own processing requires a DPIA, risk assessment, cybersecurity audit, consultation or other assessment.
Where applicable U.S. state privacy law requires a service provider or contractor to cooperate with a business's legally required cybersecurity audit or risk assessment, Playto will provide the information in its possession, custody or control that the law requires for the applicable Covered Services.
11. Subprocessors
Customer provides Playto with general written authorization to engage Subprocessors for the Covered Services.
Playto will maintain an up-to-date list of Subprocessors used to process Covered Data and will make that list available to Customer upon written request. Playto may satisfy this obligation through a maintained electronic list or another durable method.
Playto will notify Customer of an intended addition or replacement of a Subprocessor at least 14 calendar days before the change takes effect, giving Customer an opportunity to object on reasonable grounds relating to data protection.
If Customer makes a timely reasonable objection, the parties will work in good faith to address the concern. Where Playto cannot provide a commercially reasonable alternative without the Subprocessor, Customer may terminate the affected Covered Service before the new Subprocessor begins processing the affected Covered Data. An objection does not require Playto to discontinue an infrastructure provider used only for unrelated controller activities.
Playto will impose written data-protection obligations on each Subprocessor that provide at least the protection required by Applicable Data Protection Law for the relevant processing. Playto remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law.
Where the EU SCCs or another applicable law requires Playto to provide a copy of relevant Subprocessor terms, Playto will provide the applicable provisions on request and may redact unrelated confidential information, security-sensitive information and Personal Data where permitted.
12. International Transfers
Customer authorizes Playto and authorized Subprocessors to process Covered Data in countries necessary to provide the Covered Services, subject to the transfer safeguards required by Applicable Data Protection Law.
Where the EU GDPR applies to a restricted transfer of Covered Data to Playto and no other valid transfer mechanism applies, the EU SCCs are incorporated into this DPA as described in Annex 3.
Where UK Data Protection Law applies to a restricted transfer and no other valid transfer mechanism applies, the current UK Addendum is incorporated as described in Annex 3 together with the applicable EU SCCs, or the parties may use another lawful UK transfer mechanism.
Where Swiss data-protection law applies and a transfer requires contractual safeguards, the EU SCCs apply with the adaptations required by Swiss law and the Swiss Federal Data Protection and Information Commissioner, as described in Annex 3.
Nothing in this DPA represents that Playto participates in a certification or transfer framework unless Playto separately confirms that participation.
13. Government and Law-Enforcement Requests
If Playto receives a legally binding request from a government or law-enforcement authority seeking Covered Data, Playto will review the request and, where legally permitted and reasonably appropriate, notify Customer before disclosure.
Playto may challenge or seek to narrow a request where Playto reasonably determines there are grounds to do so. Playto will disclose no more Covered Data than it reasonably believes the applicable legal process requires.
Where the EU SCCs, UK transfer rules or Swiss transfer requirements impose additional obligations relating to public-authority access, those obligations apply to the relevant restricted transfer.
14. Return and Deletion
Upon termination of the Covered Services, and at Customer's choice where Applicable Data Protection Law requires it, Playto will delete or return Covered Data processed solely on Customer's behalf and delete existing copies, subject to technical feasibility and any applicable legal retention obligation.
Playto may retain Covered Data where law requires retention or where the same information is independently retained by Playto in its capacity as Controller for legitimate Merchant of Record, payment, tax, compliance, fraud, dispute, security or legal purposes. In that case, the retained copy is no longer processed on Customer's instructions under this DPA and remains subject to Playto's independent legal obligations and Privacy Policy.
Data retained in routine backups may remain until overwritten according to the applicable backup cycle, provided it is protected from ordinary use and is deleted or isolated when restored where required.
15. Records, Regulatory Cooperation and Compliance Information
Playto will maintain records and documentation relating to its processing of Covered Data to the extent required of a Processor under Applicable Data Protection Law.
Playto will make available information reasonably necessary to demonstrate compliance with the processor obligations applicable to the Covered Services and will cooperate with competent supervisory authorities to the extent required by Applicable Data Protection Law.
Nothing in this section requires Playto to disclose another customer's confidential information, information protected by legal privilege, internal security information that would materially increase risk if disclosed, or information beyond what applicable law requires.
16. Audit and Inspection Rights
Customer should ordinarily use available questionnaires, summaries, security documentation, independent assessments or other reasonable evidence before requesting an on-site or bespoke audit.
Where Applicable Data Protection Law gives Customer a right to audit and the available information is insufficient, Customer may conduct an audit itself or through an independent auditor that is not a competitor of Playto and is bound by confidentiality.
Except where a regulator or Applicable Data Protection Law requires otherwise, there will be no more than one such audit in a 12-month period unless a Personal Data Breach or reasonable evidence of material non-compliance justifies an additional audit.
Audits must be conducted on reasonable advance notice, during normal business hours, within a scope reasonably related to Covered Data, and in a manner that avoids unreasonable disruption or access to information belonging to other customers. Customer bears its own audit costs unless Applicable Data Protection Law requires a different allocation.
17. US State Privacy Terms
To the extent Playto receives Covered Data as a "service provider", "contractor" or equivalent role under an applicable U.S. state privacy law, the parties agree that the specific business purposes for the processing are the Covered Services identified in the applicable order, including the storage, hosting, organization, transmission, retrieval, display, customer-directed support, customer-configured reporting or analytics, security, debugging, and customer-authorized integrations necessary to provide that Covered Service.
Customer discloses Covered Data to Playto only for those limited and specified business purposes. For that Covered Data, Playto will not sell or share the Personal Data as those terms are defined by the applicable law, retain, use or disclose it outside the specified business purposes except as permitted by law, or combine it with Personal Data obtained from another person or from Playto's own interactions except as permitted by applicable law.
Playto will provide the level of privacy protection required of a service provider or contractor, will notify Customer if Playto determines it can no longer meet an applicable requirement, and will allow Customer to take reasonable and appropriate steps required by law to help stop and remediate unauthorized use of Covered Data.
Playto certifies that it understands the restrictions in this section and will comply with them to the extent the applicable U.S. state privacy law treats Playto as Customer's service provider or contractor for the Covered Data.
Any Subprocessor handling Covered Data under this section will be subject to the contractual restrictions required by the applicable law.
18. Controller-to-Controller Data
Some information exchanges between Customer and Playto occur between independent Controllers rather than under this DPA. Examples can include information that Playto needs for its own Merchant of Record sale, payment administration, tax, sanctions screening, fraud prevention, Trust Score, legal compliance or dispute handling.
Each party is independently responsible for its own Controller obligations for such information. The parties will not use this DPA to characterize an independent Controller activity as instructed processing merely to avoid an applicable privacy obligation.
19. Liability and Relationship to Agreement
Liability arising from this DPA is subject to the liability allocations and limitations in the parties' principal agreement to the extent permitted by Applicable Data Protection Law, except where the EU SCCs, UK Addendum, Swiss transfer terms or another mandatory law requires a different result.
Nothing in this DPA limits the rights of Data Subjects or supervisory authorities under mandatory Applicable Data Protection Law.
20. Term, Survival and Changes
This DPA begins when it is incorporated into the parties' agreement and remains in effect for as long as Playto processes Covered Data on Customer's behalf.
Provisions that by their nature must continue after termination, including confidentiality, deletion or return, transfer obligations, audit rights relating to retained Covered Data, and mandatory legal duties, survive for as long as necessary to give them effect.
Playto may update this DPA prospectively to reflect changes in Applicable Data Protection Law, approved transfer mechanisms or the Covered Services. Playto will provide notice of a material change where required by law or the parties' agreement.
An update to this DPA does not retroactively change completed processing or replace a mandatory requirement for additional agreement or authorization.
21. Contact
Questions concerning this DPA, Subprocessor information, transfer safeguards or data-protection matters may be sent to:
support@playto.so
Playto, Inc.
8 The Green, Ste R
Dover, DE 19901
United States
22. Annex 1 - Details of Processing
This Annex describes processing for which Playto acts as Processor. It does not describe Playto's independent-controller Merchant of Record activities.
Subject matter: processing of Covered Data required to provide the Covered Services identified in the applicable agreement, order or enabled feature.
Duration: for the term of the Covered Service and any limited post-termination period necessary for deletion, return, backup cycling or legally required retention.
Nature and purposes: storage, hosting, organization, retrieval, transmission, display, customer-directed support, customer-configured reporting or analytics, authorized integration handling, security, debugging and other processing reasonably necessary to provide the specific Covered Service on Customer's documented instructions.
Categories of Data Subjects: may include Customer personnel, representatives, customers, prospective customers, contractors, Service Partner personnel, project participants and other individuals whose Personal Data Customer lawfully submits to the Covered Service.
Categories of Personal Data: may include business contact details, account identifiers, project or service information, communications, files, support data and other Personal Data submitted to the Covered Service. Payment, tax, fraud, sanctions and MoR transaction data that Playto processes for its own purposes is excluded from Covered Data to that extent.
Sensitive data: not intended unless the applicable Covered Service and written terms expressly permit such data and the required safeguards have been agreed.
Frequency: continuous or on-demand during Customer's use of the Covered Service.
Retention: as described in Section 14 and the applicable order.
Customer's rights and obligations: Customer retains the rights and obligations of Controller under Applicable Data Protection Law, including determining the lawful purposes of instructed processing, providing lawful instructions, exercising audit and information rights, and directing Playto regarding Covered Data subject to this DPA and the applicable agreement.
23. Annex 2 - Technical and Organizational Measures
Playto will maintain a written security program appropriate to the Covered Services and risks. As applicable to systems processing Covered Data, the program will include measures designed to address the following:
- Access control: access limited to authorized personnel according to role or business need; prompt removal or adjustment of access when responsibilities change; and periodic review of privileged access.
- Authentication: controls designed to authenticate users and administrators, with stronger authentication for privileged or higher-risk access where appropriate.
- Encryption and transmission security: encryption of Covered Data in transit using currently supported secure protocols and encryption at rest for production systems where appropriate to the data and risk.
- System and endpoint security: secure configuration, vulnerability and patch management, malware or endpoint protection where relevant, and controls designed to reduce unauthorized system access.
- Logging and monitoring: security logging, monitoring and alerting proportionate to the Covered Services and risk, with access to security logs appropriately restricted.
- Secure development and change management: development, review, testing and deployment practices designed to reduce vulnerabilities and unauthorized changes in Playto-controlled software.
- Availability, backup and recovery: backup, redundancy, recovery or continuity controls appropriate to the Covered Services, together with periodic validation of recovery procedures where appropriate.
- Incident response: documented processes to identify, investigate, contain, remediate and document material security incidents.
- Data minimization and lifecycle controls: measures designed to limit Covered Data to what is reasonably necessary and to support retention, return and deletion obligations.
- Subprocessor and vendor security: reasonable diligence and contractual safeguards for Subprocessors with access to Covered Data, proportionate to the nature of the processing.
- Personnel safeguards: confidentiality obligations and security or privacy awareness appropriate to personnel roles.
- Testing and review: periodic assessment of relevant security controls, vulnerabilities and risk appropriate to the Covered Services.
- Physical security: reasonable controls for Playto-controlled physical locations and reliance on appropriate physical protections maintained by infrastructure providers for hosted environments.
The particular implementation of these measures may evolve as systems and risks change. This Annex does not state that Playto holds SOC 2, ISO 27001, PCI DSS or another certification or attestation unless Playto separately confirms it.
24. Annex 3 - International Transfer Terms
EU transfers. Where Customer transfers Covered Data protected by the EU GDPR to Playto in a country that is not covered by an applicable adequacy decision and no other lawful transfer mechanism applies, the EU SCCs are incorporated by reference.
Where Customer is a Controller and Playto is a Processor, Module Two applies. Where Customer is a Processor and Playto is its Subprocessor, Module Three applies. Clause 7 (docking) applies. For Clause 9, Option 2 (general written authorization) applies with the 14-calendar-day notice period in Section 11. The optional language in Clause 11 does not apply. For Clause 17, Option 1 applies and the SCCs are governed by Irish law. For Clause 18, disputes under the SCCs will be resolved by the courts of Ireland.
Annex I of the EU SCCs is completed using the parties' identity and contact information in the applicable agreement and this DPA, together with the processing details in Annex 1. Annex II is completed by Annex 2. The competent supervisory authority under Clause 13 is determined in accordance with the EU SCCs based on the applicable Data Exporter and Data Subjects.
UK transfers. For a restricted transfer governed by UK Data Protection Law where the EU SCCs plus the UK Addendum are used, the parties agree to be bound by the current ICO-approved UK Addendum together with the EU SCCs selected above, and the information in this DPA and Annexes 1 and 2 completes the corresponding tables and appendices to the extent applicable. The parties may instead execute another lawful UK transfer mechanism. The exporting party remains responsible for completing the transfer risk assessment or other data-protection test required by UK law.
Swiss transfers. Where the Swiss Federal Act on Data Protection applies to a transfer requiring contractual safeguards, the EU SCCs selected above apply with the adaptations necessary for Swiss law. References to the EU GDPR will be interpreted to include the corresponding provisions of Swiss data-protection law where required; references to EU Member States will not exclude Data Subjects in Switzerland; and the competent Swiss supervisory authority is the Swiss Federal Data Protection and Information Commissioner where Swiss law gives it jurisdiction.
Transfer assessments. The parties will reasonably cooperate with any transfer-impact assessment, transfer-risk assessment or equivalent data-protection test required for the relevant restricted transfer. Playto may provide information about public-authority access and supplementary protections to the extent lawfully available and reasonably necessary.
If the EU SCCs, UK Addendum or mandatory Swiss transfer requirements conflict with another provision of this DPA regarding a restricted transfer, the mandatory transfer terms control for that transfer.