1. Definitions
This Data Processing Agreement ("DPA") governs HKR Media SRL's ("HKR", "we", "us") processing of personal data on behalf of Customer in connection with the Service. The DPA forms part of and is incorporated into the Terms of Service ("ToS" or "Terms") between HKR and Customer, and applies from the moment Customer's use of the Service involves the processing of personal data.
In this DPA:
- Customer Personal Data means personal data Customer submits to HKR for processing in connection with the Service.
- Sub-processor means any third party engaged by HKR to process Customer Personal Data.
- Standard Contractual Clauses (SCCs) means the standard contractual clauses for the transfer of personal data outside the European Economic Area adopted by the European Commission.
- Other terms have the meaning given in the ToS or, where applicable, in the GDPR.
Matters not expressly addressed in this DPA are governed by the corresponding provisions of the ToS. In the event of conflict between this DPA and the ToS in respect of the processing of Customer Personal Data, this DPA prevails. Where SCCs apply, the SCCs prevail over the rest of this DPA in case of conflict.
2. Roles
Customer acts as Controller in respect of Customer Personal Data, or as Processor on behalf of its own underlying Controller where applicable. HKR acts as Processor or, where Customer is itself a Processor, as Sub-processor in Customer's chain. The parties are not joint controllers.
3. Scope of processing
The subject matter of the processing is the provision of the Service. The duration is the term of the ToS plus any statutory retention period. The nature of the processing is the production of human-supervised AI Deliverables based on Customer's Inputs and instructions. The purpose is to deliver to Customer the Deliverables Customer has requested.
The types of personal data and the categories of data subjects are determined by Customer's Inputs. Customer is responsible for the personal data it submits, in accordance with its warranties in the ToS and the Acceptable Use Policy.
4. Instructions
HKR processes Customer Personal Data only on Customer's documented instructions. The ToS, this DPA, the Service description published from time to time, and Customer's submitted briefs and requests together constitute Customer's documented instructions to HKR. HKR will notify Customer if it considers an instruction to infringe applicable data protection law and may suspend processing pending resolution.
5. Processor obligations
HKR shall:
- Ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations
- Implement technical and organizational measures to protect Customer Personal Data, as described in Section 8
- Engage Sub-processors only in accordance with Section 6
- Provide reasonable assistance to Customer in accordance with Section 10
- On Customer's reasonable written request, provide information sufficient to demonstrate HKR's compliance with this DPA, as described in Section 11
- Delete or return Customer Personal Data at the end of the processing relationship, as described in Section 12
6. Sub-processors
Customer authorizes HKR to engage Sub-processors as set out in the ToS. The current Sub-processor list is published at hkr.ai/trust-center. The notice period, Customer's right to object, and the consequences of objection are governed by the ToS and apply equally under this DPA.
7. International transfers
HKR is established in Romania and processes Customer Personal Data within the European Economic Area ("EEA") where possible. Where HKR transfers Customer Personal Data outside the EEA, HKR applies appropriate safeguards under Chapter V of the GDPR, including:
- Adequacy decisions of the European Commission, where applicable
- Standard Contractual Clauses
- Transfer Impact Assessments where required
Where SCCs apply, the SCCs are incorporated into this DPA by reference. The Module corresponding to the relationship between the parties — Module 2 for Controller-to-Processor or Module 3 for Processor-to-Sub-processor — applies. The annexes of the SCCs are populated by reference to Sections 3, 6, and 8 of this DPA and to the Sub-processor list referenced in Section 6.
8. Security
HKR implements technical and organizational measures appropriate to the risks associated with the processing of Customer Personal Data, including measures relating to encryption, access controls, employee training, incident response, and business continuity.
HKR maintains certifications relevant to information security and quality management. Current details of HKR's certifications are available at hkr.ai/trust-center. These certifications evidence the technical and organizational measures HKR has implemented to protect Customer Personal Data.
9. Breach notification
HKR will notify Customer of any personal data breach affecting Customer Personal Data without undue delay and in any event within 72 hours of HKR becoming aware. The notice will include, to the extent known at the time of notification:
- The categories and approximate numbers of data subjects and records affected
- The likely consequences of the breach
- The measures HKR has taken or proposes to take to mitigate
- A point of contact for further information
HKR will cooperate with Customer in any onward notification to supervisory authorities and affected data subjects. HKR does not notify supervisory authorities or data subjects directly; Customer, as Controller, retains that responsibility.
10. Assistance
HKR will provide reasonable assistance to Customer in respect of:
- Data subject requests. Where HKR receives a request from a data subject in respect of Customer Personal Data, HKR will forward the request to Customer without responding substantively, and will provide reasonable technical and organizational assistance to enable Customer to respond within the timeframes required by applicable data protection law.
- Data protection impact assessments and prior consultations. HKR will provide reasonable assistance in respect of Customer's data protection impact assessments and any prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to HKR.
HKR reserves the right to charge for material time spent providing assistance under this Section beyond a reasonable baseline.
11. Audits
HKR will make available, on Customer's reasonable written request, summary information sufficient to demonstrate HKR's compliance with this DPA, including descriptions of HKR's technical and organizational measures and copies of third-party audit reports HKR holds.
Where such information is insufficient to demonstrate compliance, or where required by a supervisory authority, HKR will permit an on-site inspection limited to HKR's own processing, on 30 days' written notice, no more than once per 12 months, during business hours, subject to confidentiality and without access to other clients' data or environments, at Customer's cost.
12. Deletion and return
On termination of the Services, HKR will, at Customer's written election, delete or return Customer Personal Data. Absent an election within a reasonable period, HKR will proceed to deletion. When Customer Personal Data is no longer required by HKR, HKR and its service providers will perform the necessary procedures for destroying, deleting, erasing, or converting it into an anonymous form as permitted or required under applicable law.
HKR may retain Customer Personal Data where required by applicable law.