Meta tags:
description= The BRCK Data Processing Addendum (DPA) governing BRCK s processing of customer end-user personal data as a service provider / processor under U.S. state privacy laws.;
Headings (most frequently used words):
and, data, of, processing, brck, privacy, law, annex, as, controller, the, subject, obligations, personal, customer, state, service, provider, terms, processor, international, business, de, identified, aggregated, addendum, definitions, roles, parties, matter, duration, nature, purpose, assistance, with, requests, sub, processors, breach, notification, return, deletion, ccpa, 10, other, 11, audits, demonstrating, compliance, 12, transfers, 13, order, precedence, 14, term, governing, notices, details, technical, organizational, security, measures, transfer, mechanism, governed, by, policy, not, this, dpa, responsibilities, limited, independent, activity, ai, ml, development, general, authorization, flow, down, change, notice, objection, right,
Text of the page (most frequently used words):
the (197), and (177), brck (112), #customer (105), data (102), personal (66), with (39), for (36), processing (35), privacy (34), #service (32), will (32), sub (30), processor (28), this (28), that (27), not (25), section (25), business (24), services (24), applicable (21), dpa (21), subject (19), security (18), agreement (18), provider (18), terms (17), policy (17), information (17), its (16), breach (16), law (16), any (16), obligations (15), under (15), controller (14), processors (13), laws (13), state (13), only (12), including (12), process (12), may (12), access (11), required (11), other (11), notice (11), ccpa (11), means (11), all (10), communications (10), request (10), are (10), use (9), legal (9), from (9), does (9), out (9), notification (9), extent (9), provide (9), end (9), processes (8), set (8), written (8), protection (8), cpni (8), call (8), users (8), purpose (8), except (8), where (8), instructions (8), voice (7), standard (7), consistent (7), documented (7), identified (7), parties (7), which (7), such (7), behalf (7), permitted (7), messaging (6), would (6), subjects (6), annex (6), available (6), fcc (6), retention (6), reasonably (6), necessary (6), period (6), reasonable (6), assist (6), those (6), see (6), act (6), direct (6), aggregated (6), addendum (5), com (5), products (5), international (5), begins (5), own (5), third (5), party (5), temporary (5), confidentiality (5), vendor (5), technical (5), list (5), processed (5), records (5), routing (5), fraud (5), support (5), compliance (5), acts (5), sip (5), order (5), limited (5), delete (5), purposes (5), described (5), before (5), individual (5), secure (5), partners (4), transfer (4), responsible (4), equipment (4), systems (4), configuration (4), physical (4), audio (4), copies (4), least (4), termination (4), change (4), organizational (4), measures (4), duration (4), through (4), categories (4), metadata (4), address (4), billing (4), nature (4), voip (4), matter (4), governed (4), without (4), north (4), carolina (4), between (4), provided (4), obligation (4), contract (4), return (4), comply (4), notify (4), relationship (4), objection (4), requests (4), view (4), 2026 (3), acceptable (3), solutions (3), integrations (3), infrastructure (3), states (3), currently (3), contractual (3), added (3), serving (3), offered (3), sensitive (3), cdrs (3), telecom (3), need (3), handling (3), risk (3), require (3), recovery (3), contained (3), content (3), calls (3), signaling (3), e911 (3), location (3), related (3), regulatory (3), term (3), provision (3), turkana (3), llc (3), charlotte (3), effective (3), date (3), notices (3), assistance (3), must (3), into (3), precedence (3), apply (3), than (3), appropriate (3), engage (3), consumer (3), same (3), outside (3), receives (3), sell (3), share (3), defined (3), independent (3), interconnected (3), affected (3), 222 (3), new (3), given (3), has (3), directly (3), connection (3), functionality (3), identify (3), form (3), entity (3), rights (3), integration (3), fees (2), porting (2), 10dlc (2), contact (2), resources (2), pricing (2), enterprise (2), provides (2), united (2), clauses (2), idta (2), framework (2), certification (2), monitoring (2), mechanism (2), choices (2), using (2), features (2), makes (2), oversight (2), facilities (2), visitors (2), personnel (2), procedures (2), detecting (2), investigating (2), responding (2), incident (2), response (2), after (2), hours (2), minimization (2), hour (2), window (2), backup (2), encryption (2), promptly (2), authentication (2), maintains (2), protect (2), minimum (2), listed (2), individuals (2), whose (2), messages (2), detail (2), message (2), registered (2), user (2), identifiers (2), types (2), quality (2), plus (2), post (2), sms (2), mms (2), details (2), until (2), regard (2), conflict (2), provisions (2), submit (2), notifications (2), below (2), mecklenburg (2), county (2), district (2), incorporated (2), forms (2), part (2), comprising (2), governs (2), unauthorized (2), toll (2), limitation (2), liability (2), continue (2), addresses (2), transfers (2), make (2), demonstrate (2), affecting (2), satisfy (2), each (2), case (2), right (2), audit (2), customers (2), current (2), audits (2), demonstrating (2), meeting (2), ensure (2), person (2), unless (2), assessments (2), down (2), determines (2), restrictions (2), requiring (2), otherwise (2), manner (2), disclose (2), advertising (2), solely (2), lawful (2), requirements (2), accordance (2), addition (2), providers (2), impose (2), aware (2), replacement (2), update (2), writing (2), good (2), faith (2), amounts (2), owed (2), days (2), performed (2), general (2), authorization (2), account (2), respond (2), self (2), create (2), operate (2), analyze (2), develop (2), train (2), improve (2), models (2), attempt (2), instruction (2), inform (2), maintain (2), route (2), transmit (2), include (2), derived (2), operation (2), network (2), have (2), amended (2), california (2), collectively (2), gdpr (2), your (2), partner (2), program (2), msps (2), connectivity (2), compliant (2), sbc (2), avaya (2), asterisk (2), trunking (2), zoom (2), webex (2), calling (2), teams (2), number (2), inc, surcharges, product, 855, 244, info, loa, registration, trust, compare, modern, offer, here, credentials, ongoing, controlled, areas, cards, biometrics, surveillance, escorted, while, premises, breaches, aligned, posture, deleted, retained, legitimate, awareness, training, vendors, aws, oracle, netsuite, bandwidth, undergo, annual, assessment, contracts, adherence, standards, supply, chain, management, logged, monitored, logging, restoration, tests, conducted, quarterly, collected, proportionate, requested, transit, rest, industry, privilege, reviewed, regularly, revoked, role, multi, factor, mfa, enforced, contractor, control, assets, classified, sensitivity, criticality, restricted, know, basis, classification, administrative, safeguards, designed, continuous, frequency, incl, hrs, telephone, numbers, transmission, delivery, storage, prevention, assurance, legally, telephony, a2p, 16928, lancaster, hwy, suite, 109, 28277, takes, effect, both, accept, later, continues, ceases, arbitration, seat, objections, sent, copy, designated, exclusive, venue, courts, court, western, division, governing, positioned, tier, clause, event, document, controls, nothing, limits, contradicts, titled, responsibility, intended, satisfying, statutory, article, style, more, following, regulator, soc, iso, 27001, held, avoidance, doubt, grant, representatives, conduct, site, excludes, confidential, commercial, anything, questionnaire, making, then, reports, attestations, certifications, once, per, twelve, months, specific, adhere, duty, direction, flows, these, virginia, colorado, connecticut, level, can, longer, meet, certifies, understands, them, pursuant, observe, combine, specified, retain, monetary, valuable, consideration, cross, context, behavioral, constitutes, agree, perform, prohibited, upon, expiration, election, technically, feasible, existing, record, keeping, tax, anonymize, practices, retains, above, limit, further, deletion, displace, separate, handles, rule, carriers, trs, federal, enforcement, mandatory, waiting, also, fbi, secret, cfr, 2011, 111, becoming, status, commit, fixed, numeric, deadline, timing, acknowledgment, fault, take, steps, mitigate, effects, undue, delay, non, shorter, discontinuation, email, subscribe, via, based, grounds, within, work, resolve, cannot, resolved, proceeds, sole, remedy, terminate, portion, prejudice, rendered, ten, thirty, engaging, remains, performance, less, protective, flow, engages, cloud, hosting, analytics, payment, carrier, maintained, made, taking, insofar, possible, fulfill, because, charge, fee, materially, exceeds, relating, substance, advise, commitment, development, sections, becomes, infringes, suspend, confirmed, modified, withdrawn, lawfulness, flag, implement, persons, authorized, bound, who, requirement, prohibits, summary, deliver, store, definition, test, identification, artificial, intelligence, machine, learning, certain, usage, preventing, irsf, threats, abuse, maintaining, integrity, rating, collecting, complying, usf, 499, creating, treat, carve, license, activity, represents, warrants, respect, obtained, consents, bases, contemplated, accuracy, legality, acquired, their, responsibilities, collects, about, websites, marketing, administration, similar, constitute, complete, final, additional, different, agreed, roles, meaning, 1934, rules, exercise, leading, accidental, unlawful, destruction, loss, alteration, disclosure, engaged, whether, automated, receive, generate, includes, proprietary, generated, itself, identifies, relates, describes, capable, being, associated, could, linked, indirectly, particular, household, alone, jointly, others, definitions, reflects, comprehensive, together, reference, uses, master, capitalized, meanings, you, our, doing, june, talk, become, white, label, msp, failover, disaster, continuity, modernize, legacy, lines, replace, pri, pots, managed, agent, office, real, estate, client, claims, policyholder, insurance, hipaa, healthcare, scale, operations, centers, session, border, ribbon, audiocodes, native, open, source, pbx, freepbx, certified, trunk, 3cx, byoc, phone, cisco, microsoft, emergency, seamless, migration, intelligent, min, agents, campaigns, grade,
Text of the page (random words):
processor service provider and customer acts as the controller business brck will process customer personal data only on customer s documented instructions and only to provide maintain secure and support the services as set out in this dpa and the agreement the agreement and this dpa including any order form and the configuration choices customer makes constitute customer s complete and final documented instructions to brck for the processing of customer personal data additional or different instructions must be agreed in writing and may be subject to fees 2 2 brck as controller business governed by the privacy policy not this dpa for personal data that brck collects and processes for its own purposes including data about visitors to and users of brck s websites brck s marketing and communications customer s account administration and billing data and similar data brck acts as a controller business and that processing is governed by the brck privacy policy see privacy policy 1 1 not by this dpa 2 3 customer s responsibilities as controller business customer represents and warrants that with respect to customer personal data a it has provided all required notices and obtained all consents and legal bases necessary for brck and its sub processors to process the customer personal data as contemplated by the agreement b its instructions to brck comply with applicable law and c it is responsible for the accuracy quality and legality of the customer personal data and the means by which it acquired it where customer s own end users have a relationship with customer not brck customer not brck is the entity to which those end users direct their privacy rights requests consistent with privacy policy 1 2 2 4 brck s limited independent controller activity to the extent permitted by applicable law brck may process certain communications and usage metadata as an independent controller business for the limited purposes of a preventing detecting and investigating fraud toll fraud irsf security threats and abuse b maintaining the security integrity and operation of brck s network c billing rating and collecting amounts owed d complying with brck s own legal regulatory and telecom obligations including cpni usf 499 lawful process and fcc requirements and e creating de identified or aggregated data as described in section 2 5 brck will not treat this carve out as a license to use customer personal data for advertising or for any purpose outside the direct business relationship with customer see section 9 2 5 de identified and aggregated data as permitted for a service provider processor under applicable u s state privacy laws brck may create de identified and aggregated data derived from its processing of customer personal data and may use such data to operate secure analyze develop train and improve its products services and artificial intelligence and machine learning models brck maintains such data in de identified or aggregated form does not attempt to re identify it except as permitted by law to test that de identification is effective and does not disclose it in a manner that would identify any individual 3 subject matter duration nature and purpose of processing the details of processing required by applicable law are set out in annex a in summary the subject matter is brck s provision of the services the duration is the term of the agreement plus any post termination period in section 8 the nature and purpose is the processing necessary to route transmit deliver store as applicable secure and support voice messaging and related communications the types of personal data include those listed in the definition of customer personal data and the categories of data subjects are customer s end users and other individuals whose personal data is contained in communications processed through the services 4 brck s processing obligations brck will process only on documented instructions including with regard to international transfers if any except where required by applicable law to which brck is subject in such a case brck will inform customer of that legal requirement before processing unless the law prohibits such notice confidentiality ensure that persons authorized to process customer personal data are bound by appropriate obligations of confidentiality and are limited to those who need access to provide the services security implement and maintain the technical and organizational security measures described in annex b lawfulness flag if brck becomes aware that an instruction from customer infringes applicable law brck will inform customer and may suspend the affected processing until the instruction is confirmed modified or withdrawn assist with data subject requests as set out in section 5 assist with security breach notification and data protection assessments as set out in sections 7 and 8 sub processing only as set out in section 6 return or delete customer personal data as set out in section 8 records and demonstrating compliance as set out in section 11 audits 4 1 de identified and aggregated data ai ml development consistent with section 2 5 and privacy policy 4 1 brck may create and use de identified and aggregated data to operate secure analyze develop train and improve its products services and ai ml models with a commitment not to attempt to re identify it 5 assistance with data subject requests taking into account the nature of the processing brck will assist customer by appropriate technical and organizational measures insofar as this is possible to fulfill customer s obligation to respond to data subject requests because brck processes customer personal data on customer s behalf if brck receives a data subject request directly from an individual relating to customer personal data brck will not respond to the substance of the request except on customer s documented instructions or as required by law and will where permitted advise the individual to submit the request to customer and promptly notify customer of the request where the services provide self service functionality brck may direct customer to use that functionality to satisfy a data subject request brck may charge a reasonable fee for assistance that materially exceeds standard self service functionality 6 sub processors 6 1 general authorization customer provides general written authorization for brck to engage sub processors to process customer personal data in connection with the services subject to this section the categories of sub processors brck engages are cloud infrastructure and hosting analytics customer support payment processing and messaging voice carrier and routing partners a current list of brck s sub processors including the service provided the categories of data processed and the processing location is maintained and made available at brck com sub processors the sub processor list brck will update the sub processor list and provide the change notification described in section 6 3 before a new or replacement sub processor begins processing customer personal data 6 2 flow down obligations before engaging a sub processor that will process customer personal data brck will impose on the sub processor by written contract data protection obligations no less protective than those in this dpa to the extent applicable to the sub processor s services brck remains responsible for its sub processors performance of those obligations to the same extent brck would be responsible if it performed the services directly 6 3 change notice and objection right brck will provide customer with notice of the addition or replacement of a sub processor that processes customer personal data at least thirty 30 days before the new sub processor begins processing customer personal data except that for non infrastructure sub processors and where a shorter period is reasonably necessary e g to address a security risk or a vendor s discontinuation of service brck may provide at least ten 10 days notice notice will be given through the sub processor list update mechanism and or by email customer may subscribe to change notifications via privacy brck com if customer has a reasonable good faith objection based on data protection grounds to a new sub processor customer must notify brck in writing within the notice period the parties will work in good faith to resolve the objection if the objection cannot be resolved and brck proceeds with the sub processor customer may as its sole remedy terminate the affected portion of the services on written notice without prejudice to amounts owed for services rendered 7 personal data breach notification brck will notify customer of a personal data breach affecting customer personal data without undue delay as required by applicable law after becoming aware of it and will provide customer with information reasonably available to brck to assist customer in meeting its own breach notification obligations consistent with brck s status as an interconnected voip provider brck does not commit to a fixed numeric deadline such as 48 or 72 hours the timing of notice is governed by the applicable legal standard described below brck s notification is not an acknowledgment of fault or liability brck will take reasonable steps to mitigate the effects of the personal data breach this obligation is in addition to and does not displace brck s separate regulatory breach obligations as a communications provider as described in privacy policy 12 brck handles cpni under 47 u s c 222 and as an interconnected voip provider is subject to the fcc s breach notification rule for carriers interconnected voip and trs providers 47 cfr 64 2011 fcc 23 111 which may require notice to the fcc and to federal law enforcement the fbi and u s secret service and to affected customers and which does not impose a mandatory waiting period before customer notice brck will also comply with applicable state breach notification laws 8 return and deletion of customer personal data upon termination or expiration of the agreement brck will at customer s election and to the extent technically feasible return or delete customer personal data processed on customer s behalf and delete existing copies except to the extent retention is required by applicable law including telecom record keeping cpni billing tax and lawful process requirements or for the limited independent controller purposes in section 2 4 brck will delete or anonymize customer personal data in accordance with its standard retention practices and privacy policy 11 including the 48 hour temporary call audio qa window where brck retains customer personal data as permitted above brck will continue to protect it in accordance with this dpa and limit further processing to the purpose s requiring retention 9 ccpa u s state privacy law service provider terms to the extent brck processes customer personal data that constitutes personal information subject to the ccpa the parties agree that customer is a business and brck is a service provider and that brck processes such personal information solely to perform the services under the agreement a business purpose brck is prohibited from and will not sell or share the personal information as sell and share are defined under the ccpa i e brck will not sell it for monetary or other valuable consideration and will not share it for cross context behavioral advertising retain use or disclose the personal information for any purpose other than the business purpose s specified in the agreement or outside the direct business relationship between brck and customer except as otherwise permitted by the ccpa combine the personal information brck receives from or on behalf of customer with personal information brck receives from any other person except as permitted by the ccpa for a service provider and otherwise process the personal information in any manner outside the direct business relationship with customer brck will comply with the applicable obligations of a service provider under the ccpa will provide the same level of privacy protection as required of a business and will notify customer if brck determines it can no longer meet its obligations under the ccpa brck certifies that it understands the restrictions in this section and will comply with them and will engage sub processors only pursuant to a written contract requiring the sub processor to observe the same ccpa service provider restrictions 10 other u s state privacy law processor terms to the extent the virginia consumer data protection act colorado privacy act connecticut data privacy act and other u s state privacy laws that require specific controller processor contract terms apply brck as processor will a adhere to customer s instructions and assist customer in meeting its obligations under those laws b ensure each person processing customer personal data is subject to a duty of confidentiality c at customer s direction delete or return customer personal data at the end of the services unless retention is required by law d make available to customer on reasonable request information necessary to demonstrate brck s compliance see section 11 e assist customer by appropriate technical and organizational measures with the security of processing breach notification and data protection assessments and f engage sub processors only under a written contract that flows down these obligations see section 6 11 audits and demonstrating compliance brck will make available to customer the information reasonably necessary to demonstrate compliance with this dpa and brck s obligations under applicable u s state privacy laws satisfying the statutory minimum the ccpa service provider standard and the article 28 style information provision obligation on customer s reasonable written request no more than once per twelve 12 months except following a personal data breach affecting customer personal data or where required by a regulator brck will satisfy this obligation by making available then current third party audit reports attestations or certifications e g soc 2 iso 27001 if held and by responding to a reasonable written security and data protection questionnaire in each case subject to confidentiality for the avoidance of doubt this dpa does not grant customer or its representatives a right to conduct an on site or physical audit of brck s facilities or systems any information provided under this section is limited to brck s processing of customer personal data and excludes data of other customers brck s confidential commercial information and anything that would breach brck s legal or contractual obligations 12 international transfers this dpa addresses processing under u s state privacy laws only the services are provided from the united states and are intended for u s users consistent with privacy policy 15 international transfer terms such as the eu standard contractual clauses the uk idta or an eu us data privacy framework certification...
|