Data Processing Agreement
Last updated: October 24, 2024
Interpretation and Definitions
Interpretation
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Data Processing Agreement:
Company (referred to as either "the Company", "We", "Us" or "Our" in this Data Processing Agreement) refers to StudySavyMD.
Service refers to the Website.
You means the individual accessing the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Website refers to StudySavyMD, accessible from www.studysavymd.org.
Personal Data refers to any information that relates to an identified or identifiable individual, as defined under applicable data protection laws.
Processor refers to Us, StudySavyMD, processing Your Personal Data on Your behalf as part of the services provided via the Website.
Controller refers to You, the individual or entity that determines the purposes and means of the processing of Personal Data.
Scope of this Data Processing Agreement
This Data Processing Agreement governs the processing of Personal Data that We collect from You or that You provide to Us in connection with Your use of the Service. It applies to the Personal Data that We process as a data processor on Your behalf in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR).
Roles and Responsibilities
Data Controller: You, as the Data Controller, are responsible for determining the purposes and means of processing the Personal Data collected via the Service.
Data Processor: We, as the Data Processor, are responsible for processing Personal Data on Your behalf and in accordance with Your instructions as described in this Agreement.
Processing of Personal Data
We process Personal Data solely for the purpose of providing the Service, in accordance with Your instructions, and in compliance with applicable data protection laws. We will not process Personal Data for any other purpose unless required by law.
Types of Personal Data Processed
We may process the following types of Personal Data on Your behalf, which may include but are not limited to:
Contact information (e.g., email address)
User preferences and account details
Any other data provided by You while using the Service
Sub-Processors
We may engage third-party service providers (sub-processors) to assist in processing Personal Data on Our behalf. When engaging sub-processors, We ensure that they provide sufficient guarantees to implement appropriate technical and organizational measures in such a manner that processing will meet the requirements of applicable data protection laws.
Data Security
We implement appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and accidental loss, destruction, or damage. These measures are designed to ensure a level of security appropriate to the risks presented by the processing.
International Data Transfers
Where Personal Data is transferred outside the European Economic Area (EEA), We ensure that such transfers are protected by appropriate safeguards, such as standard contractual clauses or other lawful mechanisms recognized by applicable data protection laws.
Your Rights as Data Controller
As the Data Controller, You have the right to:
Access, correct, or delete Personal Data processed on Your behalf
Restrict or object to the processing of Personal Data
Request the return or deletion of Personal Data upon termination of the Service, except where We are required to retain the data under applicable law
Data Breach Notification
In the event of a data breach that may result in a risk to the rights and freedoms of individuals, We will notify You without undue delay after becoming aware of the breach, providing sufficient information to enable You to meet any legal obligations with respect to breach notification.
Duration of Processing
We will process Personal Data for as long as necessary to fulfill the purposes outlined in this Agreement or as required by law. Upon termination or expiration of the Service, We will, at Your request, either delete or return the Personal Data, unless further retention is required by law.
Amendments to this Agreement
We may update or modify this Data Processing Agreement to reflect changes in applicable laws or operational practices. Any updates will be communicated to You in a timely manner.
Contact Us
If You have any questions about this Data Processing Agreement, You can contact Us:
By email: studysavymd@gmail.com