Appendix – Data Processing Addendum
1. Definitions and Interpretations
1.1. For the purposes of this DPA, capitalized terms shall have the following meanings, unless defined elsewhere in the Agreement:
“Agreement” shall mean the agreement to which this DPA is attached and forms integral part of;
“Approved Jurisdiction” shall mean a member state of the European Economic Area (“EEA”), or other jurisdiction as may be approved as having adequate legal protections for personal data by the European Commission, currently available here: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en;
“Business Day” shall mean any day except any Saturday, Sunday or a public holiday in the respective countries of incorporation of the Parties to the Agreement;
“CCPA” shall mean the U.S. California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CPRA”) and from time to time;
“Competent Data Protection Authority” shall mean the competent data protection authority or regulator, which, by way of example, is the Austrian Data Protection Authority [die österreichische Datenschutzbehörde];
“Data Protection Legislation” shall mean all applicable data protection legislation, including the GDPR, CCPA, any national, federal, or state data protection legislation, and any regulations, guidelines or any other documents issued by a Competent Data Protection Authority, each as amended from time to time;
“DPA” shall mean this Appendix – Data Processing Addendum;
“GDPR” shall mean Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, as amended from time to time;
“Personal Data” shall mean any information relating to an identified or identifiable natural person processed under this DPA and the categories of Personal Data processed under this DPA are further defined in Annex 1 – Personal Data Processing Description;
1.2. For the purposes of this DPA, the terms “data controller”, “data processor”, “data subject”, “personal data”, “business”, “service provider”, “process”, “processing” and “data breach” shall have the meanings attributed to them in the GDPR (and as respective terms as defined under CCPA and other applicable data protection legislation).
2. Purpose of this DPA
2.1. The purpose of this DPA is to determine the roles and responsibilities of each Party during the provision of the Products and/or Services under the Agreement and associated processing of the Personal Data in order to ensure Parties’ compliance with the applicable Data Protection Legislation. The categories of the Personal Data processed, the categories of data subjects to whom the Personal Data relates and the processing operations performed on the Personal Data are further detailed in Annex 1 – Personal Data Processing Description.
2.2. The Parties agree that with regard to the processing of the Personal Data, Sportradar shall act as the data processor/service provider processing the Personal Data on behalf of the Client acting as the data controller/business.
3. Term and Termination
3.1. This DPA shall be bound to the term of the Agreement.
3.2. Upon termination of the Agreement, Sportradar shall proceed in accordance with the clause 4.13 of this DPA.
4. Obligations of Sportradar regarding the Personal Data
4.1. Sportradar shall process the Personal Data in accordance with the instructions of the Client and in compliance with the Data Protection Legislation. Sportradar shall immediately inform in writing the Client if Sportradar believes that any of the instructions of the Client violate the Data Protection Legislation. For the avoidance of doubt, this notification obligation shall not mean that Sportradar is obliged to perform a comprehensive legal examination with respect to a Client’s instructions. In addition, this DPA represents the final and complete instructions from the Client and any further instructions are subject to mutual agreement between the Parties and may be subject to additional costs.
4.2. Sportradar shall keep a written record of all categories of processing operations carried out on behalf of the Client as required under the applicable Data Protection Legislation.
4.3. Sportradar shall not disclose the Personal Data to third parties, unless with the express prior written consent of the Client or when required under applicable law. For the avoidance of doubt, the Client acknowledges and agrees that Sportradar’s sub-processors, affiliates and subsidiaries shall not be considered as third parties for the purposes of this DPA.
Sportradar may disclose the Personal Data to other data processors working for the Client, pursuant to the Client’s instructions. In this case, the Client shall identify, in writing and in advance, the entity the Personal Data shall be disclosed to, the Personal Data to be disclosed, and the security measures to be applied for the disclosure.
If Sportradar shall transfer Personal Data to a third country or international organisation, pursuant to applicable European Union or Member State law, Sportradar shall inform the Client of that legal requirement beforehand, unless the law prohibits this on important grounds of public interest.
4.4. The Client authorises Sportradar to appoint – and permit each sub-processor appointed in accordance with this clause to appoint – sub-processors. The current list of sub-processors engaged by Sportradar can be provided to the Client upon request. When appointing new sub-processors, Sportradar shall perform appropriate due diligence on any sub-processor to be engaged in the processing of the Personal Data and conclude a data processing agreement with such sub-processor that provides similar level of protection to the Personal Data as this DPA. Sportradar shall be responsible for all acts and omissions of the sub-processors it engages.
4.5. Sportradar shall maintain the duty of secrecy regarding the Personal Data, even after the termination of the Agreement.
4.6. Sportradar shall ensure that the individuals authorized to process the Personal Data expressly undertake in writing to respect the confidentiality of the Personal Data and to comply with any relevant security measures, of which they shall be duly informed. In addition, Sportradar shall ensure that the individuals authorized to process the Personal Data have appropriate data protection training.
4.7. Taking into account the nature of the processing, Sportradar shall assist the Client by taking appropriate technical and organizational measures, insofar as this is possible, in meeting the Client’s obligation to respond to data subjects’ requests. The Client shall reimburse Sportradar for all reasonable costs and expenses incurred with regard to such assistance.
4.8. Sportradar shall promptly notify the Client of any data subjects’ requests received by Sportradar relating to the processing of the Personal Data under this DPA. The notification shall be accompanied, where appropriate, by other information that may be relevant for the Client to resolve the data subject’s request.
4.9. Sportradar shall notify the Client without undue delay of any confirmed data breach involving Personal Data processed under this DPA (the “Data Breach”) and will reasonably respond to the Client’s request for further information pertaining to the Data Breach so that the Client may fulfil its obligations under the Data Protection Legislation.
4.10. Sportradar shall provide reasonable support to the Client in sending prior consultations to Competent Data Protection Authorities and in conducting data protection impact assessments.
4.11. Sportradar shall provide the Client with all reasonable information necessary to demonstrate compliance with its obligations under the Data Protection Legislation and shall allow audits and inspections to be carried out by an independent third party auditor mutually agreed by the Client and Sportradar, at the cost of the Client. Such audit or inspection may only be undertaken once in any 12 (twelve) calendar month period upon a prior written notice during normal business hours. For the avoidance of doubt, providing to the Client information via reports, certifications or Client’s questionnaires or forms, shall be deemed as sufficient provision of information by Sportradar under this clause and on-premise audits and inspections shall be carried out by the Client only in case of a confirmed breach of Sportradar’s material obligations under this DPA.
4.12. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of individuals, Sportradar shall implement appropriate technical and organisational measures to:
a. ensure a level of security appropriate to the risk involved in order to protect the Personal Data from unauthorized use, alteration, access or disclosure, loss, theft, and damage;
b. ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
c. restore the availability and access to the Personal Data in a timely manner in the event of a physical or technical incident;
d. test, assess and evaluate the effectiveness of technical and organisational measures implemented for ensuring the security of the processing of the Personal Data;
e. pseudonymise and encrypt the Personal Data, as appropriate;
4.13. The Client instructs Sportradar, upon termination of the Agreement, to delete all Personal Data processed under this DPA from its systems in accordance with Sportradar’s internal data retention schedule, unless instructed otherwise by the Client in writing. The Client acknowledges and agrees that Sportradar shall have the right to use de-identified and/or aggregated data related to or obtained in connection with the Agreement and/or this DPA for its legitimate internal business purposes, such as analytics, reporting, and to improve, benchmark and develop its internal products and services, including for the purpose of developing and training of artificial intelligence algorithms and models.
5. Obligations of the Client regarding the Personal Data
5.1. The Client shall provide the Personal Data or otherwise make the Personal Data available to Sportradar and shall not instruct Sportradar to process the Personal Data in violation of the Data Protection Legislation.
5.2. The Client shall comply with all applicable Data Protection Legislation and shall notify Sportradar without undue delay of any relevant changes to the Data Protection Legislation that may have impact on the processing of the Personal Data under this DPA.
5.3. The Client shall ensure that as required by and in accordance with the requirements of the Data Protection Legislation: (i) at the time of collection, the data subjects are provided with clear and sufficient information about the collection and processing of the personal data processed under this DPA, (ii) at the time of collection, legal basis for processing of the personal data under this DPA is secured and any consents of data subjects are obtained, (iii) the data subjects are provided with the opportunity to exercise their data subject rights under the Data Protection Legislation and their requests to exercise their rights are complied with, (iv) appropriate technical and organizational measures are implemented by the Client to sufficiently protect the Personal Data and (v) the Client does not provide or otherwise make available to Sportradar Personal Data related to minors (as this term is defined in the applicable laws).
5.4. The Client shall conduct any relevant data protection impact assessments and prior consultations with respect to the processing operations to be carried out under this DPA and in relation to the Agreement.
5.5. The Client shall ensure that Sportradar complies with the Data Protection Legislation prior to and during processing of the Personal Data.
5.6. Upon Client’s written request, Sportradar shall provide the Client with all available Processor Personal Data relating to the Client’s end-users, including any prompts or inputs provided by end-users to AI chatbot services.
6. International Data Transfers
6.1. Sportradar may process (including transfer) the Personal Data outside of the EEA, United Kingdom (“UK”) and/or Switzerland if such transfer is made in accordance with the applicable Data Protection Legislation, i.e. (1) to an Approved Jurisdiction, (2) subject to applicable model clauses for data transfers (standard contractual clauses) or frameworks approved by a Competent Data Protection Authority, or (3) subject to other legal mechanisms for international data transfers.
6.2. To the extent that Sportradar processes the Personal Data originating from or otherwise subject to the Data Protection Legislation of any of the jurisdictions listed below, the terms specified therein with respect to the applicable jurisdiction(s) apply in addition to the foregoing terms.
6.3. To the extent that the Client transfers the Personal Data from the EEA, the UK or Switzerland to a subsidiary or affiliate of Sportradar located outside the EEA, UK or Switzerland, unless the Parties may rely on an alternative transfer mechanism or basis under the Data Protection Legislation, the Parties will be deemed to have entered into the standard contractual clauses approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 available at http://data.europa.eu/eli/dec_impl/2021/914/oj (“Clauses”) in respect of such transfer, whereby:
a. the Client is the “data exporter” and Sportradar is the “data importer”;
b. the footnotes, Clause 9(a) Option 1, Clause 11(a) Option and Clause 17 Option 1 are omitted, the time period in Clause 9(a) Option 2 is 14 days, and the applicable annexes are completed respectively with the information set out in the DPA and the Agreement;
c. to the extent that the Client acts as a data controller and Sportradar acts as a data processor, Module Two applies and Modules One, Three and Four are omitted, and to the extent that the Client acts as a data processor and Sportradar acts as a sub-processor, Module Three applies and Modules One, Two and Four are omitted;
d. the “competent supervisory authority” is the supervisory authority in Austria;
e. the Clauses are governed by the law of Austria;
f. any dispute arising from the Clauses will be resolved by the courts of Austria; and
g. if there is any conflict between the terms of the Agreement and/or the DPA, on the one hand, and the Clauses, on the other hand, the Clauses will prevail.
6.4. In relation to transfers of the Personal Data from the UK, the Clauses as implemented under clause 7.3. above will apply subject to the following modifications:
a. the Clauses are amended as specified by Part 2 of the international data transfer addendum to the European Commission’s standard contractual clauses issued under Section 119A of the UK Data Protection Act 2018, as may be amended or superseded from time to time (“UK Addendum”);
b. tables 1 to 3 in Part 1 of the UK Addendum are completed respectively with the information set out in the DPA and the Agreement (as applicable); and
c. table 4 in Part 1 of the UK Addendum is completed by selecting “neither party”.
6.5. In relation to transfers of the Personal Data from Switzerland, the Clauses as implemented under clause 7.3. above will apply subject to the following modifications:
a. references to “Regulation (EU) 2016/679” shall be interpreted as references to the Swiss Federal Act on Data Protection (“FADP”);
b. references to specific Articles of “Regulation (EU) 2016/679” shall be replaced with the equivalent article or section of the FADP;
c. references to “EU”, “Union”, “a Member State” and “Member State law” shall be replaced with references to “Switzerland” or “Swiss law”, as applicable;
d. the term “member state” shall not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of accessing their rights;
e. Clause 13(a) and Part C of Annex I are not used and the “competent supervisory authority” is the Swiss Federal Data Protection Information Commissioner;
f. the Clauses are governed by the law of Switzerland; and
g. any dispute arising from the Clauses will be resolved by the courts of Switzerland.
7. Liability and Limitation of Liability
7.1. The Client shall be liable and shall hold Sportradar harmless from and against any and all losses, fines, liabilities, damages, costs, claims, amounts paid in settlement and expenses (including legal fees, disbursements, costs of investigation, litigation, settlement, judgment, interest and penalties) that are sustained or suffered or incurred by, awarded against or agreed to be paid by, Sportradar as a result of, or arising from, a breach by the Client of its obligations under this DPA and/or the Data Protection Legislation.
7.2. To the fullest extent permitted by law, neither Sportradar nor any of its affiliates, shall be liable to the Client under or in connection with this DPA for any indirect, special or consequential losses or damages, loss of business or good will, profit or revenue. Notwithstanding anything to the contrary in the Agreement, the total aggregate liability of Sportradar to the Client under or in connection with this DPA (whether the liability arises because of a breach of contract, negligence, breach of statutory duty or otherwise) for any loss or damage of whatsoever nature and howsoever caused shall not exceed the lower of either (i) the total amount of fees actually paid by the Client under the Agreement during the 12 (twelve) months prior to the event giving rise to the claim, or (ii) 150,000,- (one hundred and fifty thousand) EUR.
8. Contact Point
Each Party shall nominate the following contact person within their organisation who can be contacted in respect of queries, complaints or notifications of any kind whatsoever regarding this DPA or the Data Protection Legislation:
For Sportradar:
Name and Position: Stefano Celardo (Global Data Protection Officer)
E-mail: [email protected]
For the Client:
As per the Agreement
9. Miscellaneous
9.1. Unless specifically agreed otherwise between the Parties in writing, in the event of any conflict between the terms of this DPA, the Agreement and any other agreement between the Parties, this DPA shall take precedence. In the event of any conflict between the Clauses and the DPA, the Clauses shall prevail.
9.2. This DPA shall be governed by and construed in accordance with the laws chosen by the Parties in the Agreement. All disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the court(s) chosen by the Parties in the Agreement.
9.3. The provisions of this DPA are severable. If any phrase, clause or provision is invalid or unenforceable in whole or in part, such invalidity or unenforceability shall affect only such phrase, clause or provision and the rest of this Agreement shall remain in full force and effect.
9.4. Clause 4.13, 5.3 and 7 of this DPA shall survive the termination or the expiry of this DPA and the Agreement.
9.5. Any amendment to this DPA must be made in writing upon mutual agreement by the Parties.
Annex 1 – Personal Data Processing Description
| Product/Service provided under the Agreement | Marketing Services |
| Categories of the personal data processed | AI Marketing Services Sports/Casino Personalization and Insights: a) location IDs (IP Address, ZIP/location of retail or terminal unit); b) account IDs; c) device IDs; d) geolocation; e) age and gender; f) signup date and other real-time and historical information, such as favorite bet types, favorite sports types; g) bonus information (signup channel, source of acquisition, campaign ID, bonus ID, bonus type, reward type, award type, accepted date, restriction type (bonus, cashout, non withdrawable, etc.), wager requirements, bonus amount; h) transaction information (day and time of transaction, transaction ID, transaction type (deposit, withdrawal, etc.), amount, transaction status, payment method); i) account balance, the balance of the gaming wallet; j) web analytics data (impressions, conversions, clicks, visits, pages visited user journey and click stream, bounces); k) other browsing metadata, such as device information, web analytics data, ISP, landing page loads, referring URL, URL visited, user agent string and browser metadata and language; l) any other personal data as shared by the Client with Sportradar or as otherwise agreed between the Parties; (the “Punter Personal Data”); Bingo: a) Bingo participants/users: b) User IDs and usernames; c) statistics about usage and sentiment; d) age and gender; e) registration date, total messages and chat messages; f) session time and how much end users spent on bingo; g) Bingo chat hosts: h) User IDs and usernames; i) Session information and duration, idle time and activity logs; j) Chat messages; (the “Bingo Personal Data”); |
| Categories of data subjects | The data subjects to whom the Punter Personal Data and the Bingo Personal Data relates are Client’s end users and/or punters. |
| Processing operations performed
| AI Marketing Services Sports/Casino Personalization and Insights: a) collecting and/or receiving from Client the Punter Personal Data; b) analyzing via AI real-time and historical Punter Personal Data about each of Client’s end users (Favorite Bet types, Favorite Sport types, average stakes, etc.); c) serving Client’s end users with: i. (if applicable) personalized content based on analyzed player life-time value of each end user in order to define the best acquisition/retention strategy and to recommend the best promotion/bonus to provide to each end user (e.g. suitable promotions); ii. (if applicable), personalized content based on analyzed Punter Personal Data in order to provide personalized betting recommendations to each end user (e.g. betting recommendations/up-sell); d) based on the analyzed information according to the point a), providing to the Client predictions on the end user´s value and inactivity; e) performing analytics in order to control and develop the widgets through which the Marketing Services are delivered, including (i) verifying that an end user is from an allowed country or, if applicable, from an allowed subdivision or region of a country, and (ii) ensuring security and fraud detection and prevention and debugging. Bingo a) receiving from the Client the Bingo Personal Data; b) analysing via AI the Bingo Personal Data in order to provide to the Client insights about: i. how Client’s chat hosts are moderating the bingo game and players’ betting activities; ii. the general sentiment and engagement based on captured interactions, including labelling and tagging comments with specific parameters.
|
| Product/Service provided under the Agreement | Betting Entertainment Tools Services |
| Categories of the personal data processed | a) IP addresses; b) geolocations and timezones; c) other browsing metadata such as: device information, web analytics data, ISP, landing page loads, referring URL, URL visited, user agent string and browser metadata, number of clicks, user behavior, and language; d) (applicable only for BET Concierge) userID; e) (where applicable) comments and chat conversations; (the “BET Personal Data”). |
| Categories of data subjects | The data subjects to whom the BET Personal Data processed for Betting Entertainment Tool Services relates are Client’s end users. |
| Processing operations performed | a) collecting the BET Personal Data via CDN logs; b) processing the BET Personal Data: i. to deliver the Betting Entertainment Tools Services; ii. to perform analytics in order to control and develop the Betting Entertainment Tools Services; iii. to verify that Client’s end users are from an allowed country or, if applicable, from an allowed subdivision or region of a country; iv. for fraud detection and prevention and to ensure security and for debugging; v. (where applicable) to monitor the chat function and detect toxic language via AI systems and models. vi. (applicable only for BET Concierge) to monitor the usage of BET Concierge widget for pricing purposes based on such usage; vii. upon Client’s written request, to provide Client with their end-users’ data. |