1. Definitions and Roles
“Data Protection Law”means all laws applicable to Floe’s processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended (“CCPA”).
“Personal Data”means personal data, personal information, or equivalent contained in Customer Data or Demo Interaction Data that Floe processes on Customer’s behalf. “Controller,” “Processor,” “Data Subject,” and “Personal Data Breach” have the meanings given in the GDPR.
Roles.Customer is the Controller and Floe is the Processor in respect of Personal Data processed to provide the Service. Where Customer is itself a processor for a third-party controller, Floe is a sub-processor and Customer warrants it has the authority to enter into this DPA on that controller’s behalf.
CCPA.With respect to personal information subject to the CCPA, Floe acts as a “service provider” as defined in Cal. Civ. Code § 1798.140(ag). Floe does not sell or share such personal information, does not retain, use, or disclose it for any purpose other than performing the Service, and does not combine it with personal information received from other sources except as permitted by the CCPA.