This Data Processing Addendum (“DPA”) forms part of, and is subject to, the Terms of Service and any Order Form between Horizen Ag, Inc. (“Horizen Ag”) and the customer identified in the Order Form (“Customer”) (together, the “Agreement”). This DPA sets out the terms on which Horizen Ag Processes Personal Data on Customer’s behalf in providing the Services. Capitalized terms not defined here have the meanings given in the Agreement.
In the event of a conflict between this DPA and the remainder of the Agreement with respect to the Processing of Personal Data, this DPA governs.
“Applicable Data Protection Laws” has the meaning given in the Agreement, and includes each U.S. state comprehensive consumer privacy law applicable to the Processing under this DPA.
“Controller,” “Processor,” “Data Subject,” “Personal Data Breach,” and “Process” (and its variants) have the meanings given under Applicable Data Protection Laws. Where a law uses different terminology — including “Business,” “Service Provider,” “Consumer,” or “Third Party” — the corresponding term applies.
“Customer Personal Data” means Personal Data contained within Customer Content that Horizen Ag Processes on Customer’s behalf in providing the Services.
“Derived Data” has the meaning given in Section 5.3 of the Terms of Service.
“Sub-processor” means any third party engaged by Horizen Ag to Process Customer Personal Data.
Customer is the Controller of Customer Personal Data and Horizen Ag is the Processor. Where the applicable law uses the terms “Business” and “Service Provider,” Customer is the Business and Horizen Ag is the Service Provider.
Customer is responsible for the accuracy and legality of Customer Personal Data and for having a lawful basis and all necessary notices, consents, and permissions for Horizen Ag to Process it as contemplated by the Agreement, including as provided in Section 5.5 of the Terms of Service. This includes notices and consents required from Customer’s own customers and growers.
Horizen Ag will Process Customer Personal Data only: (a) on documented instructions from Customer, which the Agreement, this DPA, and Customer’s configuration and use of the Services constitute; (b) as necessary to provide, maintain, secure, and support the Services; and (c) as otherwise required by applicable law, in which case Horizen Ag will inform Customer of that requirement before Processing unless legally prohibited.
Horizen Ag will not: (a) sell or share Customer Personal Data as those terms are defined under Applicable Data Protection Laws; (b) retain, use, or disclose Customer Personal Data for any purpose other than performing the Services or as otherwise permitted by Applicable Data Protection Laws; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties; or (d) combine Customer Personal Data with personal information received from another source, except as permitted under Applicable Data Protection Laws.
Horizen Ag will notify Customer if it determines it can no longer meet its obligations under Applicable Data Protection Laws. Customer may, upon notice, take reasonable and appropriate steps to stop and remediate unauthorized Processing.
Nothing in this DPA restricts Horizen Ag’s right to create and use Derived Data in accordance with Section 5.3 of the Terms of Service. Derived Data is not Customer Personal Data and is not Personal Data, because it does not identify and is not reasonably capable of being associated with, or linked to, any Data Subject or Customer.
With respect to any de-identified or aggregated data, Horizen Ag will: (a) take reasonable measures to ensure the information cannot be associated with a Data Subject or household; (b) publicly commit to maintain and use the information in de-identified form and not attempt to re-identify it, except that Horizen Ag may attempt re-identification solely to test the effectiveness of its de-identification measures; and (c) contractually obligate any recipient to comply with the foregoing.
Horizen Ag will not disclose to any third party Derived Data drawn from a cohort comprising fewer than five (5) distinct customers of Horizen Ag.
Horizen Ag will ensure that personnel authorized to Process Customer Personal Data are subject to binding obligations of confidentiality, have been informed of the confidential nature of the data, and receive appropriate training. Horizen Ag will limit access to those personnel who require it to perform the Services.
Horizen Ag will implement and maintain the technical and organizational measures described in Annex II, designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access. Horizen Ag may update those measures provided the level of protection is not materially degraded.
Customer provides general authorization for Horizen Ag to engage Sub-processors. A current list is set out in Annex III and maintained in Annex III of this DPA as published at horizen.ag/dpa. Horizen Ag will impose on each Sub-processor data protection obligations no less protective than those in this DPA and remains liable for its Sub-processors’ performance.
Horizen Ag will give Customer at least thirty (30) days’ notice before adding or replacing a Sub-processor, by the mechanism identified in Annex III. Customer may object on reasonable data protection grounds within that period, in which case the parties will work in good faith to find an alternative; if none is available, Customer may terminate the affected Services and receive a pro-rata refund of prepaid Fees.
Taking into account the nature of the Processing, Horizen Ag will provide Customer with the functionality within the Services necessary to access, correct, delete, restrict, and export Customer Personal Data, so that Customer may fulfill requests from Data Subjects.
If Horizen Ag receives a request directly from a Data Subject relating to Customer Personal Data, it will not respond substantively except to confirm receipt and direct the Data Subject to Customer, and will promptly notify Customer. Horizen Ag will provide reasonable assistance, at Customer’s expense to the extent the assistance is not available through the Services’ standard functionality.
Horizen Ag will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate volume of data and Data Subjects affected to the extent known, the likely consequences, and the measures taken or proposed. Horizen Ag will provide further information as it becomes available and will reasonably cooperate with Customer in investigating and mitigating the breach and in meeting Customer’s notification obligations.
Horizen Ag’s notification of, or response to, a Personal Data Breach is not an acknowledgement of fault or liability.
Horizen Ag will provide Customer with reasonable assistance, taking into account the nature of the Processing and the information available to Horizen Ag, in conducting any data protection impact assessment or similar assessment required under Applicable Data Protection Laws, and in consulting with supervisory authorities where required.
Horizen Ag will make available to Customer information reasonably necessary to demonstrate compliance with this DPA. Upon Customer’s written request no more than once in any twelve (12) month period, and subject to reasonable notice of at least thirty (30) days, Horizen Ag will (a) respond to a reasonable security questionnaire, and (b) where available, provide its then-current third-party security assessment or audit report.
Where the foregoing is insufficient to satisfy a requirement under Applicable Data Protection Laws, Customer may conduct an audit of Horizen Ag’s Processing, during regular business hours, without unreasonably interfering with operations, subject to confidentiality obligations, and at Customer’s expense. Audits following a Personal Data Breach affecting Customer Personal Data are at Horizen Ag’s expense.
Upon expiration or termination of the Agreement, Horizen Ag will handle Customer Personal Data in accordance with Section 12.4 of the Terms of Service, including making it available for retrieval during the retrieval period and thereafter deleting it, subject to the exceptions stated there for routine backup and archival systems and for legally required retention, and subject to Horizen Ag’s surviving rights in Derived Data under Section 5.3(e) of the Terms of Service.
Upon Customer’s written request, Horizen Ag will certify deletion.
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions set out in Section 9 (Limitation of Liability) of the Terms of Service.
This DPA takes effect on the Order Form Effective Date and continues until Horizen Ag has ceased all Processing of Customer Personal Data. Sections 4, 5, 9, 12, and 13 survive termination.
Subject matter and duration. Provision of the Horizen Ag Solution and related Professional Services for the Term of the Agreement and any retrieval period thereafter.
Nature and purpose. Hosting, storage, organization, retrieval, analysis, transmission, and display of Customer Content in order to operate Customer’s sales, inventory, purchasing, finance, and fulfillment workflows, and to provide support.
Categories of Data Subjects. Customer’s Authorized Users; Customer’s employees and contractors; Customer’s customers, including growers and their personnel; Customer’s vendor and supplier contacts.
Categories of Personal Data. Name, business contact details, job title and role, user credentials and access logs, order and transaction history, billing and payment details, delivery addresses and locations, communications content, and other information Customer elects to submit.
Sensitive data. None is required or requested by the Services. Customer should not submit sensitive categories of Personal Data.
Frequency. Continuous for the duration of the Agreement.
Horizen Ag maintains, at minimum, the following technical and organizational measures:
Access control: unique credentials per user; role-based authorization; administrative access restricted and logged. Encryption: TLS 1.2+ in transit; encryption at rest for production data stores. Infrastructure: hosted on Microsoft Azure in the United States; network segmentation and firewalling; regular patching. Development: code review and change management for production changes; separation of production and development environments. Monitoring: centralized logging of production systems; alerting on anomalous access. Resilience: automated backups; documented recovery procedures. Personnel: confidentiality obligations; security training; access revoked promptly on departure. Incident response: documented procedure for identifying, escalating, and remediating security incidents. Customer isolation: logical separation of each customer’s data.
Horizen Ag engages the following Sub-processors:
Microsoft Corporation (Microsoft Azure) — cloud hosting and infrastructure for the Horizen Ag Solution — United States.
Stripe, Inc. — payment processing — United States.
Twilio Inc. — SMS and text-message delivery — United States.
Twilio Inc. (SendGrid) — transactional email delivery — United States.
Horizen Ag’s artificial intelligence features run on infrastructure operated by or on behalf of Horizen Ag within the hosting environment listed above. Horizen Ag does not transmit Customer Content to third-party model or inference providers.
Notice mechanism for Sub-processor changes: email to Customer’s designated privacy contact.