III. Genius Referrals as a Processor – Processing Customer Content5. Customer Instructions. Customer appoints Genius Referrals as a processor to process Customer Content on behalf of, and in accordance with, Customer's instructions (a) as set forth in the Agreement, this Addendum, and as otherwise necessary to provide the Services to Customer, and which includes investigating security incidents and preventing spam, fraudulent activity, and violations of the Genius Referrals Acceptable Use Policy, the current version of which is available at
https://geniusreferrals.com/legal/aup, and detecting and preventing network exploits or abuse; (b) as necessary to comply with applicable law or regulation, including Applicable Data Protection Law; and (c) as otherwise agreed in writing between Customer and Genius Referrals ("
Permitted Purposes").
5.1 Lawfulness of Instructions. Customer will ensure that its instructions comply with Applicable Data Protection Law. Customer acknowledges that Genius Referrals is neither responsible for determining which laws or regulations are applicable to Customer's business nor whether Genius Referrals' provision of the Services meets or will meet the requirements of such laws or regulations. Customer will ensure that Genius Referrals' processing of Customer Content, when done in accordance with Customer's instructions, will not cause Genius Referrals to violate any applicable law or regulation, including Applicable Data Protection Law. Genius Referrals will inform Customer if it becomes aware, or reasonably believes, that Customer's instructions violate any applicable law or regulation, including Applicable Data Protection Law.
5.2 Additional Instructions. Additional instructions outside the scope of the Agreement or this Addendum will be agreed to in writing between Customer and Genius Referrals, including any additional fees that may be payable by Customer to Genius Referrals for carrying out such additional instructions.
6. Confidentiality6.1 Responding to Third Party Requests. In the event any Third Party Request is made directly to Genius Referrals in connection with Genius Referrals' processing of Customer Content, Genius Referrals will promptly inform Customer and provide details of the same, to the extent legally permitted. Genius Referrals will not respond to any Third Party Request without Customer's prior consent, except as legally required to do so or to confirm that such Third Party Request relates to Customer.
6.2 Confidentiality Obligations of Genius Referrals Personnel. Genius Referrals will ensure that any person it authorizes to process Customer Content has agreed to protect personal data in accordance with Genius Referrals' confidentiality obligations in the Agreement.
7. Sub-processors7.1 Authorization for Onward Sub-processing. Customer provides a general authorization for Genius Referrals to engage onward sub-processors that is conditioned on the following requirements:
(a) Genius Referrals will restrict the onward sub-processor's access to Customer Content only to what is strictly necessary to provide the Services, and Genius Referrals will prohibit the sub-processor from processing the personal data for any other purpose;
(b) Genius Referrals agrees to impose contractual data protection obligations, including appropriate technical and organizational measures to protect personal data, on any sub-processor it appoints that require such sub-processor to protect Customer Content to the standard required by Applicable Data Protection Law, including the requirements set forth in Schedule 4 (Jurisdiction Specific Terms) of this Addendum; and
(c) Genius Referrals will remain liable for any breach of this Addendum that is caused by an act, error, or omission of its sub-processors.
7.2 Current Sub-processors. Customer consents to Genius Referrals engaging third party sub-processors to process Customer Content within the Services for the Permitted Purposes provided that Genius Referrals maintains an up-to-date list of its sub-processors at
https://geniusreferrals.com/legal/sub-processors. With respect to changes in infrastructure providers, Genius Referrals will endeavor to give written notice sixty (60) days prior to any change, but in any event will give written notice no less than thirty (30) days prior to any such change. With respect to Genius Referrals' other sub-processors, Genius Referrals will endeavor to give written notice thirty (30) days prior to any change, but will give written notice no less than ten (10) days prior to any such change.
7.3 Objection Right for new Sub-processors. Customer may object to Genius Referrals appointment or replacement of a sub-processor prior to its appointment or replacement, provided such objection is in writing and based on reasonable grounds relating to data protection. In such an event, Customer and Genius Referrals agree to discuss commercially reasonable alternative solutions in good faith. If Customer and Genius Referrals cannot reach a resolution within ninety (90) days from the date of Genius Referrals' receipt of Customer’s written objection, Customer may discontinue the use of the affected Services by providing written notice to Genius Referrals. Such discontinuation will be without prejudice to any fees incurred by Customer prior to the discontinuation of the affected Services. If no objection has been raised prior to Genius Referrals replacing or appointing a new sub-processor, Genius Referrals will deem Customer to have authorized the new sub-processor.
8. Data Subject Rights. Genius Referrals provides Customer with a number of self-service features via the Services, including the ability to delete, obtain a copy of, or restrict use of Customer Content. Customer may use such self-service features to assist in complying with its obligations under Applicable Data Protection Law with respect to responding to Third Party Requests from data subjects via the Services at no additional cost. Upon Customer's request, Genius Referrals will provide reasonable additional and timely assistance to Customer in complying with Customer's data protection obligations with respect to data subject rights under Applicable Data Protection Law to the extent Customer does not have the ability to resolve a Third Party Request from a data subject through self-service features made available via the Services.
9. Impact Assessments and Consultations. Genius Referrals will provide reasonable cooperation to Customer in connection with any data protection impact assessment (at Customer's expense only if such reasonable cooperation will require Genius Referrals to assign significant resources to that effort) or consultations with regulatory authorities that may be required in accordance with Applicable Data Protection Law.
10. Return or Deletion of Customer Content. Genius Referrals will, in accordance with Section 3 (Duration of the Processing) of Schedule 1 (Details of Processing) of this Addendum, delete or return to Customer any Customer Content stored within the Services.
10.1 Extension of Addendum. Upon termination of the Agreement, Genius Referrals may retain Customer Content in storage for the time periods set forth in Schedule 1 (Details of Processing) of this Addendum, provided that Genius Referrals will ensure that Customer Content (a) is processed only as necessary for the Permitted Purposes and (b) remains protected in accordance with the terms of the Agreement, this Addendum, and Applicable Data Protection Law.
10.2 Retention Required by Law. Notwithstanding anything to the contrary in this Section 10, Genius Referrals may retain Customer Content, or any portion of it, if required by applicable law or regulation, including Applicable Data Protection Law, provided such Customer Content remains protected in accordance with the terms of the Agreement, this Addendum, and Applicable Data Protection Law.