Data Processing Agreement (Summary)
Empathy First Media takes data protection seriously. For clients and partners in jurisdictions that require Data Processing Agreements (DPAs) (such as under the GDPR for EU personal data), we have a comprehensive DPA available. This section provides a summary of our Data Processing Agreement terms and our commitments as a data processor. (For the full legally binding DPA, please contact us; we will provide it and incorporate it into our service contract when applicable.)
Role Definition: In our relationship with clients, Empathy First Media often acts as a Data Processor (or “Service Provider” under CCPA) on behalf of our clients, who are usually the Data Controllers (or “Businesses” under CCPA). This means we handle personal data provided or collected by our clients strictly according to their instructions and for the purposes of delivering our digital marketing services. We do not determine the purposes or means of processing that personal data; that remains the client’s domain.
Types of Personal Data: The personal data we might process on behalf of a client can include (depending on services):
-
Contact information (names, emails, phone numbers) of our client’s leads or customers (for example, if we manage an email marketing campaign).
-
Online identifiers or analytics data (IP addresses, cookie IDs) from users interacting with client websites or ads we manage.
-
Any other data our client provides us to work with (e.g., a customer list for creating a custom audience, or form submissions from a landing page). We do not intentionally process sensitive personal data (like health, financial, or special categories under GDPR) unless explicitly agreed and with extra safeguards.
Our Processing Obligations: Under our DPA and relevant laws, we agree to:
-
Process data only on documented instructions from the controller (the client. We use personal data solely for the purposes needed to deliver the service the client has hired us for, and not for any other purposes. We do not “sell” or use that data for our own marketing.
-
Duty of Confidentiality: All Empathy First Media personnel who handle client data are bound by confidentiality obligations. They are trained in data protection and will not disclose personal data to unauthorized parties. Only staff who need access (e.g., an account manager, analyst, or developer working on the client’s project) will get access.
-
Security Measures: We implement appropriate technical and organizational security measures to protect personal data against unauthorized access, loss, or breach. This includes measures such as encryption (we encrypt personal data in transit, e.g., via SSL on our tools, and at rest where applicable), access controls (role-based access to data), pseudonymization where feasible, regular security training for staff, and due diligence on any sub-processors. We follow industry best practices (like maintaining updated antivirus, firewalls, etc.) and adhere to frameworks like ISO 27001 where possible, though we may not be certified.
-
Use of Sub-Processors: Sometimes we may engage third-party sub-processors to help deliver services (for example, cloud hosting providers, SaaS tools for email or project management). Our DPA specifies that we will only use sub-processors with the client’s general or specific authorization. We have a list of common sub-processors (e.g., AWS, Google, MailChimp, etc.) that we can provide. Any sub-processor will be bound by the same or equivalent data protection obligations via a contract. We remain liable for any sub-processor’s performance.
-
Data Subjects’ Rights Assistance: If an individual (data subject) whose data we process on behalf of a client exercises their GDPR rights (access, rectification, erasure, etc.), we will assist the client in fulfilling those requests. For instance, if a user asks to be forgotten and it involves data we hold, we will delete or return that data as directed. We have procedures to handle such requests promptly as required (typically within the GDPR’s one-month timeframe for access requests, etc., under the client’s guidance).
-
Assistance with Controller Obligations: We also help clients meet other GDPR obligations where relevant. This can include: assisting with Data Protection Impact Assessments (DPIAs) by providing necessary information about our processing; helping demonstrate compliance during audits; promptly informing clients if we think an instruction violates GDPR; etc.
-
End-of-Contract Data Handling: Upon termination of services, or at the client’s instruction, we will delete or return all personal data we have been processing for the client unless retention is required by law. Our default is to securely erase data (e.g., remove from our systems, overwrite or physically destroy if applicable) after a grace period following contract end. If the client prefers data returned, we can export it in a common format.
-
Audits and Inspections: We understand clients or their appointed auditors may need to verify our compliance. Our DPA states that we agree to reasonable audits or inspections, provided they’re not overly frequent or disruptive. Often, we can provide existing security and compliance documentation to satisfy this. If an on-site audit is needed, it may require notice and certain conditions for confidentiality. We also might share third-party certifications or audit reports if available to reduce the need for direct audits.
-
Breach Notification: In the unfortunate event of a personal data breach on our side, we will notify the client without undue delay after becoming aware of it. We’ll provide known details of the breach, what data was involved, the likely consequences, and steps we’re taking to mitigate it. This allows the client (controller) to fulfill any regulatory reporting duties (like notifying supervisory authorities or data subjects). We have an internal incident response plan to handle such situations.
-
International Transfers: If we transfer personal data from the EU/EEA/UK to outside those regions, we will ensure appropriate transfer mechanisms are in place (e.g., Standard Contractual Clauses, adequacy decision, etc.). For instance, as a US-based company, if we handle EU personal data, we will sign the EU Standard Contractual Clauses with the client as needed, and ensure sub-processors also have SCCs or equivalent. We also commit to follow any special measures under local law (like UK Addendum, Swiss rules, etc.). We’ll also implement any supplementary measures if required due to government access concerns, etc.
-
Regulatory Compliance: Our DPA reflects Article 28 of the GDPR’s required clauses. We also adapt to CCPA as a Service Provider: meaning we don’t retain, use, or disclose personal info for purposes other than performing our services for the client, as per CCPA §1798.140(ag). We certify we understand those restrictions.
-
Data Categories and Duration: The DPA typically lists categories of data and processing activities, but generally, we only process data as long as needed to provide the services and as instructed. We don’t keep client data longer than that unless law requires (e.g., backup retention, or legal hold).
-
Liability and Indemnity: While our full DPA and Master Services Agreement cover specifics of liability, as a summary: both parties agree to be responsible for their own compliance. We maintain appropriate insurance for cyber/data incidents. The DPA usually specifies that each party’s liability for data protection breaches is subject to any agreed cap in the main contract (unless law forbids limiting liability for certain things).
-
Location of Processing: Our operations are in the U.S. and possibly mention any other main locations. If we use sub-processors or team members in other countries, that will be disclosed. We strive to process EU data in the EU or U.S. under proper safeguards, and similarly manage data location for other regions per contract.
Obtaining the DPA: Clients who require a DPA can request it from us at [email protected]. Typically, our DPA is incorporated into the service agreement or available as an addendum. We’re happy to sign client-provided DPAs too, provided they align with our obligations and do not conflict with our standard terms (we can review and negotiate if needed).
Privacy Contact: We have a designated privacy contact (see Privacy Policy) and a Data Protection Officer if required (though as a small agency, we might not legally need a DPO, we still assign responsibility internally to ensure oversight). For any concerns about how we handle data as a processor, clients can reach out to [email protected].
In essence, Empathy First Media is committed to processing personal data securely, lawfully, and in accordance with our clients’ instructions, and to provide all necessary assistance and transparency to uphold data subjects’ rights and meet regulatory requirements. Our DPA is there to formalize these commitments, giving our clients peace of mind and legal assurance when they entrust us with personal data as part of our services.
Last Updated: April 2025