GDPR - Data Processing Agreement Addendum

Last revised: September 30, 2018.
Effective date: September 30, 2018.


This GDPR Data Processing Agreement Addendum is the part of Khangames Studio Privacy policy. The purpose of this DPA is to reflect the parties’ agreement with regard to the processing of personal data in accordance with the requirements of Data Protection Legislation as defined below. 
 

Without limiting Khangames Studio obligations under the Privacy Policy, to the extent that User stores, transmits, collects, or otherwise uses EU Personal Data (as defined below) We will comply with the following additional provisions. As used herein, “Agreement” means, collectively the Privacy policy, this Addenda, and any other agreements entered into by the parties with respect to User’s use of the Khangames Studio.


1. Definitions. Capitalized terms used in this section will have the meaning set forth below.

2. “Data Breach” means any security breach, or any similar or equivalent comprise which leads to the unintended, accidental, unauthorized or unlawful loss, disclosure of, or access to, EU Personal Data by any Processor.

3. “Data Controller” has the meaning given to it under the GDPR.

4. “Data Processor” has the meaning given to it under the GDPR.

5. “Data Protection Laws” means any data protection, privacy or similar laws or regulations anywhere in the world relating to the processing or other use of personal data, including the GDPR, that apply in relation to any Personal Data processed in connection with this Agreement.

6. “EU Data Subject” will have the meaning given to “Data Subject” under the GDPR.

7. “EU Personal Data” will have the meaning given to “Personal Data” under the GDPR.

8. “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and to the extent the GDPR is no longer applicable in the United Kingdom, any implementing legislation or legislation having equivalent effect in the United Kingdom.

9. “User Personal Data” means EU Personal Data that is processed by Khangames Studio or any Khangames Studio employees, agents or personnel in performing its obligations under this Agreement or which is otherwise made available directly or indirectly to Khangames Studio or its employees, agents or personnel by User.

10. “Processing” will have the meaning given to it under the GDPR.

11. “Processor Security Obligations” will mean Article 32 of the GDPR.

12. “Supervisory Authority” has the meaning given to it under the GDPR.

13. Compliance. Khangames Studio will comply with its obligations under applicable Data Protection Laws. We will ensure that all Khangames Studio employees, subcontractors and other personnel will comply with obligations that are equivalent to the obligations imposed on us under this section to the extent that such Khangames Studio`s employees, subcontractors and personnel carry out any processing of User Personal Data under or in connection with this Agreement. We will not intentionally perform any act that puts User in breach of its obligations under applicable Data Protection Laws, and we will notify User if in our opinion performance of a User instruction would result in breach of applicable Data Protection Laws. Nothing in this Agreement will be deemed to prevent either party from taking the steps it reasonably deems necessary to comply with applicable Data Protection Laws.

14. General. The Parties acknowledge that: (i) User alone will determine the purposes for which and the manner in which User Personal Data are, or are to be, processed in the performance of this Agreement; (ii) User will be the Data Controller in respect of all User Personal Data; (iii) Khangames Studio will be the Data Processor in respect of User Personal Data; and (iv) we will only process User Personal Data for the limited purpose of performing its obligations under, and during the term of, this Agreement.

15. Requests. In a manner that conforms to any timescales set out in applicable Data Protection Laws, (and, in any event, as soon as reasonably practicable, if sooner, or as specified below in this section), Khangames Studio will comply with any written request by User to: (i) correct or delete inaccurate User Personal Data; (ii) provide a copy of User Personal Data relating to an EU Data Subject in the possession or control of Khangames Studio; (iii) provide information about the Processing of User Personal Data including information (or a report in sufficient detail if requested by User, within thirty (30) days of such request) about the technical and organizational security measures that it uses to comply with the Processor Security Obligations or information about how its processing of User Personal Data complies with applicable Data Protection Laws; (iv) within twenty (20) days of such request or notice (as applicable) from User, assist and provide the required information in respect of any request or notice, or any anticipated request or notice, by or on behalf of any EU Data Subject or by a Supervisory Authority in respect of User Personal Data; and (v) otherwise provide reasonable assistance to User as necessary to allow User to comply with applicable Data Protection Laws.

16. Use. Khangames Studio will not, without User’s prior written consent: (i) use User Personal Data for Khangames Studio’s own purposes; (ii) transfer any User Personal Data to, or allow access to any User Personal Data by, third parties (whether a subcontractor or otherwise); or (iiii) carry out the processing by automatic means of any User Personal Data for the purpose of evaluating matters about an EU Data Subject that constitutes the sole basis for any decision that significantly affects such Data Subject.

17. Transfer. Khangames Studio may disclose User Personal Data throughout the world to fulfill the purposes described above. This may include transferring User Personal Data to other countries (including countries located outside the European Economic Area) that have different data protection regimes and which are not deemed to provide an adequate level of protection for EU Personal Information.

18. Complaints. Khangames Studio will promptly notify User if any complaints are received by us from third parties about the processing of User Personal Data, and we will not make any admissions, settle or take any action which may be prejudicial to the defense or settlement of any such complaint and will provide to User such reasonable assistance, at User’s cost, as it may require in connection with such complaint. If Khangames Studio acquires, on behalf of and independently from User, any EU Personal Data from EU Data Subjects as part of the Services, we will give such individuals a data protection notice describing the intended use of such EU Personal Data, in a form provided or approved by User. Without prejudice to its other obligations under this Agreement, if Khangames Studio becomes aware of any unauthorized, unlawful or dishonest conduct or activities or any breach of this section (including the occurrence of any Data Breach), we will promptly notify User and provide all relevant information reasonably required by User about such conduct, activities and/or breaches.

19. Khangames Studio Security Obligations. Khangames Studio acknowledges that it is obliged to comply with the Processor Security Obligations (including management of on-going compliance and effective security management) in respect of User Personal Data and, in particular, that it will comply with the following obligations: (i) take appropriate technical and organizational security measures to safeguard against any unauthorized and unlawful processing of User Personal Data and against any accidental loss or destruction of, or damage to, EU Personal Data; (ii) only process User Personal Data in accordance with written instructions given by User; (iii) take reasonable steps to ensure the reliability of those Khangames Studio employees, agents or other personnel that have access to ?User Personal Data; and (iv) ensure that all Khangames Studio employees, agents or other personnel involved in processing User Personal Data have undergone reasonably adequate training in the care and handling of EU Personal Data.

20. Audit. If a relevant data protection Supervisory Authority is required by law or regulation to audit the data processing facilities from which Khangames Studio processes Personal Data in order to ascertain and/or monitor compliance with Data Protection Requirements, then we will cooperate with the audit at User’s expense.