Skip to main content

Chrono, Inc
Creator Data Processing Agreement

Last Modified: April 23, 2024

This Data Processing Agreement (this “DPA”), is part of the Nexus Terms of Service (the “Terms”) between Creator (who is the data processor) and Chrono, Inc. dba Nexus (who is the data controller, and is hereinafter referred to as “Nexus”) and governs Creator’s processing of the personal data of Nexus users that it receives from Nexus in connection with its Nexus. Creator and Nexus acknowledge and agree that Nexus provides the personal data to Creator and Creator processes the personal data solely for the purposes of providing Nexus users with the services and products that they request through Creator’s Nexus (the “Services”). All capitalized terms used but not defined in this DPA have the meanings given to them in the Terms of Service.

Processing of Nexus User Personal Data

1.            Definitions.

  • The terms "data controller", "data processor", “subprocessor”, "data subject", "personal data", "processing", and "appropriate technical and organizational measures" shall be interpreted in accordance with Directive 95/46/EC, or other applicable Data Protection
  • "Data Protection Legislation" means all applicable laws relating to privacy and the processing of personal data that may exist in any relevant jurisdiction, including, where applicable, the guidance and codes of practice issued by the supervisory authorities. Data Protection Legislation includes, but is not limited to, European Directives 95/46/EC and 2002/58/EC (as amended by Directive 2009/136/EC) and any legislation and/or regulation implementing or made pursuant to them, or which amends, replaces, re-enacts or consolidates any of them, including the General Data Protection Regulation (Regulation (EU) 2016/279).
  • "Good Industry Practice" means exercising the same skill, expertise and judgement and using facilities and resources of a similar quality as would be expected from a person who:(a) is skilled and experienced in providing the services in question, seeking in good faith to comply wit contractual obligations and seeking to avoid liability arising under any duty of care that might reasonably apply; (b) takes all proper and reasonable care and is diligent in performing their obligations; and (c) complies with the Data Protection Legislation.


2. Instructions from Nexus. Creator will only process personal data in order to provide the Services to Nexus users on behalf of Nexus, in accordance with the Terms, Nexus’s Privacy Policy and Nexus’s written instructions, or as required by applicable Law. Creator will only process the personal data in the manner and to the extent necessary for the provision of the Services in each instance. Creator will only retain the personal data for the period necessary in order for Creator to provide the Services. Creator will promptly inform Nexus if following Nexus instructions would result in a violation of applicable data protection law or where Creator must disclose personal data in response to a legal obligation (unless the legal obligation prohibits Creator from making such disclosure).

 

3.  Confidentiality. Creator will restrict access to personal data to those authorized persons who need such information to provide the Services. Such authorized persons are obligated to maintain the confidentiality of any personal data.

 

4. Sensitive Information. Nexus will inform Creator if personal data falls into any special categories of personal data as defined in Article 9(1) of Regulation (EU) 2016/679.

 

5.  Security. Creator will implement appropriate, industry standard, technical and organizational measures to ensure a level of security appropriate to the personal data provided by Nexus and processed by Creator such measures will be consistent with the Data Protection Legislation and Good Industry Practice.

 

6.  Sub-processors. Nexus agrees that Creator, a processor, may engage other processors (“Sub-processors”) to assist in providing the Services consistent with the Terms, subject to Nexus’s written approval in each instance. Creator will provide Nexus with a written list of such Sub-processors to Nexus and obtain Nexus’s written permission prior to transferring any personal data to such Sub-processors.

 

7.  Sub-processor Liability. Where Creator engages another processor, such as a collaborator, for the purpose of carrying out specific processing activities on behalf of Nexus, the same data protection obligations as set out in this DPA will be imposed on that other processor by way of a contract or other legal act under EU or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of the EU data protection law. Where that other processor fails to fulfil its data protection obligations, Creator shall remain fully liable to the Nexus for the performance of that other processor’s obligations.

 

8. Access Requests. Creator will notify Nexus immediately in the event it receives a request from a Nexus user related to the personal data. For example, Creator will implement and will maintain appropriate technical and organizational measures needed to enable Nexus to respond to requests from data subjects to access, correct, transmit, limit processing of, or delete any relevant personal data held by Creator.

 

9.  Recordkeeping. Upon a request issued by a supervisory authority for records regarding personal data, Creator will cooperate to provide the supervisory authority with records related to processing activities performed on Nexus’s behalf, including information on the categories of personal data processed and the purposes of the processing, the use of service providers with respect to such processing, any data disclosures or transfers to third parties and a general description of technical and organizational measures to protect the security of such data.

 

10. Cooperation. Creator will take all reasonable steps to assist Nexus in complying with applicable Data Protection Legislation. Creator will comply with Nexus ’s requests related to data protection impact assessments and consultation with supervisory authorities and for the fulfillment of Nexus’s obligation to respond to requests for exercising a data subject’s rights in Chapter III of Regulation (EU) 2016/679.

 

11. Third Party Requests. If Creator receives a request from a third party in connection with any government investigation or court proceeding that Creator believes would require it to produce any personal data, Creator will inform Nexus in writing of such request and cooperate with Nexus if Nexus wishes to limit, challenge or protect against such disclosure, to the extent permitted by applicable Law.

 

12. Transfer of personal data; Appointment. Nexus authorizes Creator to transfer, store or process personal data in the United States or any other country in which Creator or its Sub-processors maintain facilities. Nexus appoints Creator to perform any such transfer of personal data to any such country and to store and process personal data in order to provide the Services. Creator will conduct all such activity in compliance with the Terms, this DPA, applicable Law and Nexus instructions.

13. Retention, Deletion or Return. Creator will retain the personal data it receives from Nexus only for so long as is necessary in order for Creator to provide the Services or as otherwise required under applicable Law (“Retention Period”). At the end of the Retention period, or upon Nexus's request, Creator will securely destroy or return (at Nexus’s election) the personal data to Nexus. Creator will relay Nexus’s instructions to all Sub-processors.

15. Breach Notification. If Creator becomes aware of a personal data breach, Creator will immediately notify Nexus of: (a) the exact nature of the data breach; (b) the type of data involved, (c) the identity of the affected user, if known. Creator will take reasonable steps at its sole cost and expense to mitigate and remediate the breach and will inform Nexus of the same. Creator will additionally take any steps with respect to the breach as may be requested by Nexus.

16. Audits. Upon request, Creator will make available to Nexus all information necessary, and allow for and contribute to audits, including inspections, conducted by Nexus or another auditor mandated by Nexus, to demonstrate compliance with Article 28 of Regulation (EU) 2016/679. For clarity, such audits or inspections are limited to Creator’s processing of personal data only, not any other aspect of Creator’s business or information systems. If Nexus requires Creator to contribute to audits or inspections that are necessary to demonstrate compliance, Nexus will provide Creator with written notice at least 30 days in advance of such audit or inspection. Such written notice will specify the things, people, places or documents to be made available. Such written notice, and anything produced in response to it (including any derivative work product such as notes of interviews), will be considered Confidential Information and, notwithstanding anything to the contrary in the Terms, will remain Confidential Information in perpetuity or the longest time allowable by applicable Law after termination of the Terms. Such materials and derivative work product produced in response to Nexus’s request will not be disclosed to anyone without the prior written permission of Creator unless such disclosure is required by applicable Law. If disclosure is required by applicable Law, Nexus will give Creator prompt written notice of that requirement and an opportunity to obtain a protective order to prohibit or restrict such disclosure except to the extent such notice is prohibited by applicable Law or order of a court or governmental agency. Nexus will make every effort to cooperate with Creator to schedule audits or inspections at times that are convenient to Creator. If, after reviewing Creator’s response to Nexus’s audit or inspection request, Nexus requires additional audits or inspections, Nexus acknowledges and agrees that it will be solely responsible for all costs incurred in relation to such additional audits or inspections.