Data Processing Addendum
This data processing addendum ("DPA") is hereby incorporated into the Olive Terms of Service, including all order forms and any amendments or addenda thereto (“Agreement”) between Olive and the Customer and all the terms of the Agreement shall apply to this DPA.
1.DEFINITIONS
1.1"Data Protection Laws" means all data protection or privacy laws applicable to the Processing of Personal Data under the Agreement including but not limited to the European Data Protection Laws, UK Data Protection Laws, and, to the extent applicable, the data protection or privacy laws of any other country;
1.2"EU Restricted Transfer" means a transfer of Personal Data by Customer to Olive where such transfer would be prohibited by EU Data Protection Laws in the absence of the protection for the transferred Personal Data provided by the EU Standard Contractual Clauses or any other mechanism permitted under European Data Protection Laws;
1.3"European Data Protection Laws" means the GDPR and any implementing, derivative or related national legislation, rule, or regulation enacted thereunder by any European Union Member State subject to its jurisdiction;
1.4"EU Standard Contractual Clauses" means the standard contractual clauses set out in the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended or replaced from time to time by a competent authority under the relevant Data Protection Laws;
1.5"GDPR" means the General Data Protection Regulation (EU) 2016/679 on the protection of natural persons about the processing of personal data and on the free movement of such data;
1.6"Customer Personal Data" means the Personal Data Processed by Olive and/or Sub-processor pursuant to the Agreement on behalf of the Customer as further set-out in Appendix 1 (Description of Data Processing);
1.7"Restricted Transfer" means a transfer of Customer Personal Data, where such transfer would be prohibited by Data Protection Laws in the absence of additional safeguards;
1.8"Services" means Olive’s AI-powered sales-intelligence and copy-generation platform and associated services, including products and support, provided by Olive under the Agreement;
1.9"Sub-processor" any Processor (including any third party and any Olive affiliate) appointed by or on behalf of Olive to Process Customer Personal Data;
1.10"Supervisory Authority" means a regulatory authority responsible for the enforcement of Data Protection Laws;
1.11“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK's Information Commissioner as amended or replaced from time to time;
1.12"UK Data Protection Laws" means the Data Protection Act 2018 (and the UK GDPR as defined therein), the Privacy and Electronic Communications (EC Directive) Regulations 2003 (in each case as amended) and other data protection or privacy legislation in force from time to time in the United Kingdom;
1.13"UK Restricted Transfer" means a transfer of Personal Data by Customer to Olive where such transfer would be prohibited by UK Data Protection Laws in the absence of the protection for the transferred Personal Data provided by the UK Addendum or any other mechanism permitted under UK Data Protection Laws;
1.14The terms "Controller", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Processor" and "Special Categories of Personal Data" shall have the same meaning as in Data Protection Laws (or their closest equivalent term) and, in each case, their cognate terms shall be construed accordingly;
1.15Capitalized terms not defined herein shall have the meaning given to them in the Agreement.
1.16If there is a conflict between the Agreement and this DPA, the terms of this DPA will control in relation to Processing of Personal Data.
2.CUSTOMER OBLIGATIONS
2.1Customer shall comply with Data Protection Laws regarding any Processing of Customer Personal Data. Without prejudice to the generality of the foregoing, Customer shall:
-
ensure that it has all necessary rights to provide the Customer Personal Data to Olive and that it has obtained all necessary consents or otherwise has an appropriate lawful basis to provide Customer Personal Data to Olive for its processing as set out in this DPA);
-
comply with its obligations to notify Data Subjects of the Processing of Customer Personal Data as required under Data Protection Laws; and
-
comply with any obligations under Data Protection Laws in relation to Restricted Transfers.
-
3.OLIVE PROCESSING OF PERSONAL DATA AS A CONTROLLER
3.1The parties agree that, Olive shall only act as a Controller of Customer Personal Data to the extent it is Processing Customer Personal Data for the purposes of (a) maintaining and developing Olive's business relationship with Customer; (b) compliance with quality control and risk management procedures; (c) security-related processing (for example, automated scanning of incoming and outgoing emails for viruses); (d) complying with legal and regulatory obligations; and (e) establishing, exercising and defending legal claims.
3.2To the extent Olive is acting as a Controller, Olive shall comply with all applicable Data Protection Laws when Processing Customer Personal Data.
4.OLIVE PROCESSING OF PERSONAL DATA AS A PROCESSOR
4.1Subject to clause 3.1, the parties agree that Olive shall Process the Customer Personal Data as a Processor. Olive shall Process Customer Personal Data in accordance with Data Protection Laws (as applicable to Processors) and shall:
-
only Process Customer Personal Data on Customer's documented instructions unless Processing is required by applicable laws, in which case Olive shall inform Customer of that legal requirement before such Processing (unless prohibited from informing on important grounds of public interest). For this purpose, Customer hereby instructs Olive (and authorises Olive to instruct each Sub-processor) to Process Customer Personal Data, including to transfer Customer Personal Data to the United Arab Emirates and the United States of America, subject to the terms of this DPA in connection with the provision of the Services. Customer instructs Olive to anonymise Customer Personal Data and use the resulting anonymised and aggregated data for the purposes of improving and developing the Service, provided that such data cannot be re-identified or attributed to any individual or to Customer;
-
inform Customer if, in Olive's opinion, Customer's instructions infringe Data Protection Laws, in which case Olive shall not be obliged to comply with such infringing instruction;
-
ensure access to the Customer Personal Data is permitted only to authorized personnel who are subject to contractual or statutory obligations of confidentiality in respect of the Customer Personal Data;
-
implement appropriate technical and organizational measures to protect against unauthorized or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to the Customer Personal Data as set out at Appendix 2 of this DPA;
-
to the extent legally permitted and taking into account the nature of Processing, inform the Customer of any complaint, notice or communication that relates directly to Olive Processing of Customer Personal Data or request from Data Subjects to exercise their rights under Data Protection Laws;
-
to the extent legally permitted and taking into account the nature of Processing and the information available to Olive, provide reasonable assistance to Customer, at Customer's cost, to:
-
respond to any complaints, notices, communications or requests set out in clause 4.1.5;
-
comply with any notice served by a Supervisory Authority that directly relates to Olive's Processing of Customer Personal Data;
-
comply with its obligations to: i) carry out an assessment of the impact of the Processing of Customer Personal Data where such Processing is likely to result in a high risk to the rights and freedoms of natural persons; and ii) consult with a competent Supervisory Authority in relation to such assessment(s); and
-
-
inform the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and provide reasonable information and assistance to Customer, at Customer's cost, to enable the Customer to comply with any requirements under Data Protection Laws to notify a Supervisory Authority or affected Data Subjects; and
-
Customer may delete Customer Personal Data via the functionality of the Services at any time. Following termination or closure of Customer’s account, except where otherwise instructed by Customer, Olive will delete all Customer Personal Data within 60 days unless Olive is required to continue to Process Customer Personal Data to comply with applicable laws or to establish, exercise or defend legal rights.
-
4.2Use of AI
-
The Services use artificial intelligence and machine learning technologies, including large language model capabilities provided by approved Sub-processors, to generate outputs on behalf of Customer.
-
Olive has implemented the following safeguards in relation to AI processing:
-
Sub-processors providing generative AI technology are contractually prohibited from using Customer Personal Data to train, improve or develop their own AI models;
-
Customer Personal Data is processed on a per-tenant basis and is not combined with data of other customers; and
-
Olive does not use Customer Personal Data to train its own large language or other AI models.
-
-
5.SUB-PROCESSORS
5.1Customer provides prior general authorisation to Olive to engage the Sub-processors set out at https://runolive.ai/subprocessors in Appendix 4 (Sub-processors).
5.2From time to time, Olive may appoint a new Sub-processor to Process Customer Personal Data. Olive will provide written notice to Customer of its intention to appoint a new Sub-processor at least 30 days in advance of such appointment becoming effective and Customer shall have the right to object to such appointment within 30 days of receiving such notice. If the Customer reasonably objects to the appointment of a Sub-processor, Olive shall, at its sole discretion: a) provide a replacement Sub-processor; or b) continue to provide the Services without appointing the Sub-processor; or c) otherwise work to address the objection at Customer's cost, i.e. by changing the location of processing or requiring the configuration of additional security measures. If neither a), b) nor c) can be feasibly achieved, as determined by Olive in its sole discretion, each party shall have the right to terminate the Agreement.
5.3Olive shall:
-
remain responsible for the acts and omissions of each Sub-processor;
-
impose similar terms on each Sub-processor as are set out in this DPA. In particular, to the extent a transfer of Personal Data from Olive to a Sub-processor is a Restricted Transfer, implement (or procure that the Sub-processor implements) adequate safeguarding measures in accordance with Data Protection Laws which may include requiring the Sub-processor to enter into the relevant module of the EU Standard Contractual Clauses and/or the UK Addendum.
-
6.AUDIT RIGHTS
6.1Subject to clause 6.2, upon Customer’s request not more than once a year, Olive will make available information reasonably necessary to demonstrate its compliance with the obligations laid down in this DPA. Olive will use reasonable efforts to provide the requested information within 30 days of receiving such request (taking into account the information available to Olive and recognizing its role as a Processor).
6.2To the extent Customer’s audit requirements under the Data Protection Laws cannot reasonably be satisfied through the information provided by Olive or a Supervisory Authority requires further verification, Customer may audit Olive subject always to the following conditions:
-
the audit will be carried out by an independent accredited third-party auditor under appropriate confidentiality obligations;
-
the audit will be conducted in accordance with Olive internal policies and reasonable security requirements;
-
the audit will be strictly limited to Customer Personal Data and Olive shall grant no access to data of other Olive customers or to systems or processes not involved in the provision of the Services;
-
Customer provides Olive with reasonable advance notice of its intention to carry out such audit together with a detailed explanation of why the audit is necessary;
-
such audit shall be carried out solely at the Customer's cost; and
-
Customer shall share the results of the audit with Olive, which shall be treated as Olive's Confidential Information.
-
7.INTERNATIONAL TRANSFERS OF CUSTOMER PERSONAL DATA
7.1With respect to an EU Restricted Transfer, Customer (“data exporter”) and Olive (“data importer”) agree that:
-
the provisions of Module 1 of the EU Standard Contractual Clauses shall apply in respect of exports of Customer Personal Data to Olive acting as a Controller by Customer acting as a Controller, in each case as incorporated by reference under clause 7.2;
-
the provisions of Module 2 of the EU Standard Contractual Clauses shall apply in respect of exports of Customer Personal Data to Olive acting as a Processor by Customer acting as a Controller, in each case as incorporated by reference under clause 7.2;
-
7.2The EU Standard Contractual Clauses are hereby incorporated by reference into this DPA and shall come into effect upon the commencement of the EU Restricted Transfer. The Parties make the following selections for the purposes of the EU Standard Contractual Clauses:
|
|
|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
7.3In respect of any UK Restricted Transfer, Customer (“data exporter”) and Olive (“data importer”), with effect from the date of the relevant transfer, enter into the UK Addendum in respect of such transfer and the following options shall apply in respect of the UK Addendum:
-
Table 1, Part 1 of the UK Addendum shall be populated with the details of the parties as set out in the Agreement;
-
Table 2, Part 1 of the UK Addendum shall be populated, as set out in clause 7.1 (as applicable depending on Olive's role as controller or processor) and clause 7.2;
-
Table 3, Part 1 of the UK Addendum shall be populated as follows: the description of transfer is set out in Appendix 3, the technical and organizational security measures are set out in Appendix 2 and the list of sub-processors is set out at https://runolive.ai/subprocessors;
-
Table 4, Part 1 of the UK Addendum shall be completed with the option "Importer".
-
7.4In respect of any Restricted Transfer which is neither an EU Restricted Transfer nor a UK Restricted Transfer, Customer shall be responsible for taking such steps and adopting such measures as necessary to ensure such Restricted Transfer is compliant with Data Protection Laws and Olive shall reasonably cooperate with Customer to implement such measures as reasonably required under Data Protection Laws.
APPENDIX 1 – DESCRIPTION OF DATA PROCESSING
Subject matter and duration of the Processing of the Personal Data:
The subject matter and duration of the Processing of the Customer Personal Data are set out in the Agreement.
Categories of Personal Data
-
Account and individual selection details provided by Customer (names of target companies and individuals selected by Customer for research). Olive may identify relevant senior executives from publicly available sources in the course of generating account-level intelligence.
-
Professional information about target individuals collected by Olive from publicly available sources (such as name, role, tenure, career history, operational priorities and communication style)
-
AI-generated inferences and assessments about target individuals (such as seniority classification, engagement angles and language patterns)
-
Outreach copy generated by the Services (such as draft emails, call scripts and LinkedIn messages)
-
Customer user account information (name, business email address, organisation)
-
Usage information (access times, activity data, browser type, IP address)
Special Categories of Personal Data:
No
Categories of Data Subjects
-
Customer’s employees and authorised users of the Services
-
Business contacts and professionals identified by Customer as targets for research and outreach
Nature and Purpose of the Processing
Olive shall Process the Customer Personal Data for:
-
Processing as Processor: Provision of the Services to Customer, including account and company research from publicly available sources, enrichment of named individuals from publicly available sources, generation of AI-powered inferences and assessments, production of tailored outreach copy, quality review of generated outputs, anonymising personal data for service improvement, and facilitating access to the Services.
-
Processing as Controller:
-
(a) Maintaining and developing Olive’s business relationship with Customer
-
(b) Compliance with quality control and risk management procedures;
-
(c) Security-related processing;
-
(d) Complying with legal and regulatory obligations;
-
(e) Establishing, exercising and defending legal claims.
-
Obligations and rights of Customer
The obligations and rights of Customer are set out in the Agreement.
Frequency of the Processing and, where applicable, transfer
Ongoing
APPENDIX 2 – SECURITY MEASURES
-
Services are hosted on Supabase (database) and Google Cloud Run (pipeline processing) infrastructure in Frankfurt, Germany within the EEA. Underlying infrastructure is provided by Amazon Web Services (AWS) and Google Cloud Platform respectively.
-
Data is encrypted in transit using TLS 1.2 or above and encrypted at rest using AES-256 encryption.
-
User roles in the Services are assigned with specific profiles and role access that determines what data is available to the user and how they can interact with it.
-
Users can only access the Services through authenticated credentials.
-
Customer data is logically separated on a per-tenant basis using row-level security controls. Data is not pooled, shared or made accessible across customer tenants.
-
Olive maintains documented incident response procedures for the identification, containment and notification of security incidents.
-
Data minimisation: Olive does not collect prospect contact details (such as email addresses or phone numbers). Processing is limited to data necessary for the provision of the Services.
APPENDIX 3 - DESCRIPTION OF THE TRANSFER
A. LIST OF PARTIES
Data exporter(s):
Name: The legal entity entering into the Agreement
Address: The registered address of the entity entering into the Agreement
Contact person’s name, position and contact details: As set out in the Agreement
Activities relevant to the data transferred under these Clauses: See Appendix 1
Signature and date: As set out in the Agreement
Role (controller/processor): Controller
Data importer(s):
Name: Olive Consulting L.L.C-FZ
Address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, UAE
Contact person’s name, position and contact details: scott@oliveconsulting.ae
Activities relevant to the data transferred under these Clauses: See Appendix 1
-
Signature and date: As set out in the Agreement
-
Role (controller/processor): Processor or Controller
B. DESCRIPTION OF TRANSFER
See Appendix 1