DATA Privacy Addendum
This Data Processing Agreement (“DPA”), is between you (“Client”) and Dragon Fruit Gaming, Inc., a Delaware corporation, with its principal place of business at 7727 Herschel Avenue, La Jolla, CA 92037 (“DFG”). You agree to these terms by using the Dragon Fruit Gaming Software and entering into the End User Licensing Agreement (“EULA”), Order Forms, Schedule 1, any amendments, orders, or statements of work executed thereunder (collectively the “Agreement”) pursuant to which DFG has agreed to provide certain goods or services to Client (the “Services”);
WHEREAS, DFG may be Processing Personal Information on behalf of Client as reasonably necessary to provide the Services; and
WHEREAS, the parties desire to amend and restate certain terms of the Agreement as set forth herein to address their obligations to comply with Data Protection Laws.
NOW, THEREFORE, for good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Parties hereto, intending to be legally bound hereby, agree as follows:
1. Definitions.
1.1 The terms “Consumer,” “Cross-Context Behavioral Advertising,” “Sell,” (and its derivatives) and “Share” (and its derivatives) shall have the meanings ascribed to them in the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”).
1.2 “Business Purpose” means performing services on behalf of Client, including the provision, operation, maintenance, hosting, and support of the Casino Management System, related software modules, remote technical assistance, and White Label Application under the Agreement.
1.3 “Data Protection Laws” means all applicable statutes, regulations, regulatory guidelines, and judicial or administrative holdings or interpretations related to privacy, information security and/or data breach, including any law applicable to any Personal Information or DFG’s access to or Processing of the same.
1.4 “Personal Information” means, in addition to any definition under Data Protection Laws, any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to any individual or a household.
1.5 “Process” or “Processing” means any operation or set of operations which is performed on Personal Information or on sets of Personal Information, whether or not by automated means, such as the collection, use, storage, disclosure, analysis, deletion, or modification of Personal Information.
2. Restrictions on Processing Personal Information. Client may provide Personal Information to DFG solely for the limited and specified Business Purposes. DFG shall Process Personal Information in accordance with the requirements of all Data Protection Laws applicable to it as a Processor and shall provide commercially reasonable protections as required by such laws. DFG shall Process the Personal Information only as reasonably necessary and proportionate to achieve the Business Purpose for which the Personal Information is provided. DFG will hold any Personal Information in confidence using a commercially reasonable degree of care and shall ensure that each person processing Personal Information is subject to a duty of confidentiality with respect to such information. DFG shall not:
2.1 Sell or Share any Personal Information;
2.2 Retain, use, or disclose Personal Information for any purpose other than for the Business Purposes, including retaining, using, or disclosing the Personal Information for a commercial purpose other than the Business Purposes, or as otherwise permitted by Data Protection Laws.
2.3 Retain, use, or disclose Personal Information outside of the direct business relationship between DFG and Client.
2.4 Combine Personal Information that DFG receives from, or on behalf of, Client with Personal Information that DFG receives from, or on behalf of, another person or persons, or collects from its own interaction with the Consumer, except as otherwise permitted under Data Protection Laws, or in connection with creating de-identified, aggregated benchmark data in accordance with Section 7.3 of the EULA.
2.5 Retain Personal Information for longer than is reasonably necessary for the specific purpose of performing the Services specified in the Agreement.
3. Restrictions on Disclosing Personal Information. DFG shall not disclose Personal Information to any third parties except as reasonable necessary to provide the Services as described in the Agreement. If disclosure to a Subprocessor is necessary, DFG shall enter into a written agreement with such third parties that requires such third party to comply with Data Protection Laws, contains obligations that are substantially equivalent to the terms in this DPA, and provide prior written notice (which may be via email or online publication) to Client with a reasonable opportunity for Client to object to such sub-processing.
4. Assistance with Consumer Requests. DFG shall provide commercially reasonable assistance as may be requested by Client to meet its obligations under any Data Protection Laws, including but not limited to its obligations to respond to individuals’ requests to exercise their rights (at Client’s expense for non-standard requests). Such assistance shall be promptly provided within a reasonable timeframe. If DFG, directly or indirectly, receives a request submitted by a Consumer to exercise a right it has under Data Protection Laws, it shall promptly redirect or provide a copy of the request to the Client who will handle the verification and response to such requests.
5. Certification. DFG hereby certifies that it understands the restrictions set forth in Data Protection Laws and will comply with them in its capacity as a Processor. DFG shall notify Client if it makes a determination that it can no longer meet its obligations under this DPA or Data Protection Laws.
6. Data Security.
6.1 Protection and Security by DFG. DFG maintains a written information security program to protect Personal Information, which includes information security policies, standards and controls (hereinafter, an “Information Security Program”) and has a designated a qualified individual responsible for overseeing, implementing and enforcing the Information Security Program. All personnel whose duties are to manage the Information Security Program shall be sufficiently qualified to manage DFG’s information security risks and to perform or oversee the information security program. Such personnel shall receive ongoing training and updates to address relevant security risks and DFG will verify that key information security personnel take steps to maintain current knowledge of changing information security threats and countermeasures. DFG’s Information Security Program includes administrative, technical, and physical safeguards designed to: (a) ensure the security, confidentiality, and integrity of Personal Information; (b) protect against any anticipated threats or hazards to the security, confidentiality, and integrity of Personal Information; (c) protect against unauthorized access to, destruction, modification, disclosure or use of Personal Information; and (d) detect and respond to Security Incidents (defined below). These safeguards and controls shall align with industry-standard frameworks (such as SOC 2 or ISO27001 guidelines). All Personal Information processed by DFG must be protected using industry standard encryption, both in transit and at rest, and multifactor authentication tools where applicable. DFG shall implement and periodically review access controls, including technical and, as appropriate, physical controls to: (i) authenticate and permit access only to authorized users to protect against the unauthorized acquisition of Personal Information; and (ii) limit authorized users’ access only to Personal Information that they need to perform their duties and functions, or, in the case of customers, to access their own information. DFG shall also implement policies, procedures, and controls designed to monitor and log the activity of authorized users and detect unauthorized access or use of, or tampering with, Personal Information by such users. DFG shall adopt procedures for change management and identify and manage the Personal Information, personnel, devices, systems, and facilities that enable it to achieve the business purposes in accordance their relative importance to DFG’s objectives and its risk strategy. DFG shall regularly, but in no event less than annually, evaluate, test and monitor the effectiveness of its Information Security Program and shall promptly adjust and/or update such programs as reasonably warranted by the results of such evaluation, testing, and monitoring. DFG shall implement continuous monitoring of its systems and shall maintain an audit trail of all access to, and use of, Personal Information. Upon Client’s written request at any time during the term of the Agreement, DFG shall promptly provide Client with information related to DFG’s Information Security Program and practices, which may include one or more of the following as DFG may determine: (i) responses to a standard information security-related questionnaire, or (ii) copies of executive summaries of relevant audits, reviews, tests, or certifications of DFG’s systems or processes.
6.2 Risk Assessments. DFG shall conduct periodic risk assessments to identify and assess reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of Personal Information. Based on such assessments, DFG shall evaluate and improve, where necessary, the effectiveness of its Information Security Program and information security controls.
6.3 Incident Response Plan. DFG represents and warrants that it has a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in its control.
6.4 Contingency. DFG shall implement and maintain appropriate business continuity, contingency and disaster recovery plans in order to maintain the availability of Personal Information and restore normal operating procedures as promptly as possible in the event of a major disruption, business interruption, or failure.
6.5 Access to Client Systems. All DFG connectivity to Client’s computing systems and all attempts at the same shall only be through Client’s security gateways/firewalls and only through Client-approved security procedures. DFG shall not access, and shall not permit unauthorized persons or entities to access, Client computing systems and/or networks without Client’s express written authorization, and any such actual or attempted access shall be consistent with any such authorization. DFG shall take appropriate measures to ensure that DFG’s systems connecting to Client’s systems do not contain any Disabling Device. For purposes of this Agreement, “Disabling Device” means any programs, mechanisms, programming devices, malware or other computer code (i) designed to disrupt, disable, harm, or otherwise impede in any manner the operation of any software program or code, or any computer system or network (commonly referred to as “malware”, “spyware”, “viruses” or “worms”); (ii) that would disable or impair the operation thereof or of any software, computer system or network in any way based on the elapsing of a period of time or the advancement to a particular date or other numeral (referred to as “time bombs”, “time locks”, or “drop dead” devices); (iii) is designed to or could reasonably be used to permit a party or any third party to access any computer system or network (referred to as “trojans”, “traps”, “access codes” or “trap door” devices); or (iv) is designed to or could reasonably be used to permit a party or any third party to track, monitor or otherwise report the operation and use of any software program or any computer system or network by the other party.
6.6 Use of Public Cloud Computing Services. During the term of the Agreement, DFG will use Amazon Web Services (“AWS”) or other reputable public cloud computing services (“Cloud Provider”) to deploy its software and to provide its Services. The parties acknowledge and agree that the use of such cloud services is a shared responsibility between the Cloud Provider and DFG, where the Cloud Provider is responsible for security of the cloud and DFG is responsible for security in the cloud. This means that DFG retains control of the security it chooses to implement to protect any content, platform, applications, systems, and networks no differently than it would in an on-site data center. Thus, DFG shall be responsible for configuring the cloud offering to ensure compliance with the terms of this Addendum.
7. Security Incidents. DFG shall notify Client promptly, but no later than seventy-two (72) hours, upon discovering any actual unauthorized access, disclosure, use, or transmission of any Personal Information (“Security Incident”), and shall use commercially reasonable efforts to investigate and remediate any such Security Incident. DFG will reasonably cooperate with Client’s requests for information pursuant to Client’s security incident reporting requirements and any requests for information from any of Client’s affected customers and by law enforcement or regulatory officials investigating each Security Incident. The parties will reasonably cooperate with each other and with any affected Client customers to determine: (i) whether notice is to be provided to any individuals, regulators, consumer reporting agencies, or others as required by law or regulation. DFG’s liability for any Security Incident or breach of this DPA shall be subject to Section 13 (Limitation of Liability) of the EULA.
8. Training. All DFG personnel with access to Personal Information shall be provided appropriate information security and privacy training to ensure their compliance with DFG’s obligations and restrictions under this DPA, Data Protection Laws, and with DFG’s Information Security Program. This training shall be updated as necessary to reflect risks identified by the risk assessment.
9. Audit. DFG hereby grants Client the right to take reasonable and appropriate steps to ensure that DFG uses Personal Information received from, or on behalf of, Client in a manner consistent with the Client’s obligations under this DPA and Data Protection Laws. Reasonable and appropriate steps may include, reviewing DFG’s annual SOC 2 or third-party security audit reports. If such reports are insufficient, Client may conduct a third-party audit upon at least thirty (30) days’ prior written notice, during normal business hours, no more than once per calendar year. Upon the reasonable request of Client, DFG shall make available to Client or its designated representative all information in its possession necessary to demonstrate its compliance with the obligations under this DPA and Data Protection Laws. DFG shall cooperate with Client to reasonably stop and remediate any unauthorized use of Personal Information discovered from any such audit/assessment, or as otherwise discovered by either party.
10. Secure Destruction of Personal Information. Upon the expiration or termination of the Agreement or anytime at Client’s written request, DFG shall return to Client or securely destroy, as directed by Client, all Personal Information in its possession or control and provide a written certificate, confirming completion upon request, provided that the DFG may retain copies of Personal Information that are stored on backup and disaster recovery systems until the ordinary course deletion thereof.
11. Remedies. Any remedies or claims arising out of or related to a breach of this DPA shall be governed exclusively by the dispute resolution, notice, and cure mechanisms set forth in the EULA.
12. Amendments to Data Protection Laws. DFG acknowledges that Data Protection Laws are subject to change and have comprehensive privacy laws under consideration. DFG shall reasonably cooperate with Client to amend the terms of this DPA to the extent necessary for Client’s compliance with all amended and additional Data Protection Laws.
13. No Conflicts. In the event of a conflict between the terms and conditions of the Agreement and the terms and conditions of this DPA, the terms and conditions of this DPA shall prevail.
14. No Further Amendment. Except as expressly amended hereby, the Agreement is in all respects ratified and confirmed and all the terms, conditions, and provisions thereof shall remain in full force and effect. This DPA is limited precisely as written and shall not be deemed to be an amendment to any other term or condition of the Agreement or any of the documents referred to therein.
15. Effect of Amendment. This DPA shall be a part of the Agreement for all purposes, and each party hereto and thereto shall be bound hereby. From and after the execution of the DPA on the Effective Date by the Parties hereto, any reference to the Agreement is deemed a reference to the Agreement as amended hereby.
16. Severability. If any term or other provision of this DPA is held to be invalid, illegal, or incapable of being enforced by any rule of law or public policy by a court of competent jurisdiction, the validity, legality, and enforceability of the remaining provisions of this DPA shall, to the extent permitted by law, remain in full force and effect.
17. Indemnification. Indemnification for data privacy and security claims under this DPA shall be governed by Section 12 (Indemnification) and Section 13 (Limitation of Liability) of the EULA, and shall be subject to the Super-Cap set forth therein.
18. Miscellaneous. This DPA may be executed in one or more counterparts, each of which shall be an original, but, which together shall constitute a single document. A copy or facsimile of a signature shall have the same force and effect as an original signature. The terms of this DPA shall survive any expiration or termination of the Agreement.