Data Processing Agreements | Descartes
Data Processing Agreements
Updated: September 5, 2024
These Data Processing Terms (“DPA” or “Data Processing Terms”), when incorporated by reference into a commercial agreement (“Agreement”) between The Descartes Systems Group Inc. or one of its affiliates (hereafter referred to as “Descartes”) and a Customer, as defined in the Agreement, apply to any Processing of Personal Data performed by Descartes on Customer’s behalf as part of Descartes provision of GLN Services, Data Services, or other services (collectively “Services”). All capitalized terms used in these Data Processing Terms shall have the meaning set out in the Agreement unless otherwise defined in these Data Processing Terms.
Except as expressly stated otherwise, in the event of any conflict between the terms of the Agreement and any other attachments thereto and the Data Processing Terms, the Data Processing Terms shall take precedence but only to the extent of the conflict. For greater certainty, where an obligation is not addressed in these Data Processing Terms which is addressed in the Agreement, a conflict shall not be deemed to have arisen.
Where Descartes is deemed to be a Controller and not a Processor under Data Protection Regulations, Descartes will comply with its own privacy policy ( https://www.descartes.com/legal/privacy-center) in the handling of any applicable Personal Data.
These Data Processing Terms do not apply to the Processing of any data that does not qualify as Personal Data under Data Protection Regulations.
- Relationship Between the Parties
Descartes provides one or more Services to Customer under an existing commercial relationship. Descartes and Customer are separate legal entities with independent obligations under Data Protection Regulations. Customer understands that it may have an obligation under Data Protection Regulations to independently determine whether its use of Services complies with Data Protection Regulation. Customer acknowledges that Descartes has not made, and explicitly disclaims, any representations that the use of Services will cause Customer to become compliant with Data Protection Regulations.
- Definitions
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data; for the purposes of this DPA, where Customer acts as processor for another controller, it shall in relation to Descartes be deemed as additional and independent Controller with the respective controller rights and obligations under this DPA.
“Data Subject” means an identified or identifiable living natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Data Protection Regulations” means (a) Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5) along with any supplementary or replacement bills enacted into law by the Government of Canada (collectively “PIPEDA”); (b) the General Data Protection Regulation (Regulation (EU) 2016/679) and applicable laws by EU member states which either supplement or are necessary to implement the GDPR (collectively “GDPR”); (c) the California Consumer Privacy Act of 2018 (Cal. Civ. Code § 1798.198(a)), along with its various amendments (collectively “CCPA”); (d) the GDPR as applicable under section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (as amended) (collectively “UK GDPR”); (e) the Swiss Federal Act on Data Protection of June 19, 1992 and as it may be revised from time to time (the “FADP”); and (f) any other applicable law related to the protection of Personal Data.
“Model Clauses” means the standard contractual clauses annexed to the EU Commission Decision (EU) 2021/914 of 4 June 2021 for the Transfer of Personal Data to Processors established in Third Countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, or any successor standard contractual clauses that may be adopted pursuant to an EU Commission decision.
“Personal Data” means any information that relates to a Data Subject that Customer or its Administrative User or Permitted Users provide to Descartes to Process under the Agreement.
“Process” or “Processing” means any operation or set of operations, whether or not by automated means, which is performed upon Personal Data that is stored on computers, servers, or mobile devices owned or maintained by Descartes, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination of otherwise making available, alignment or combination, blocking, erasure or destruction.
“Processor List” means the list of Descartes’ Affiliates and/or Third Party Processors who may assist Descartes with some or all of the Processing of Personal Data of the Customer, a copy of the list being accessible at https://www.descartes.com/legal/privacy-center/supplemental-privacy-information.
**