Effective date: May 7th, 2021.

This CCPA Data Processing Addendum (the “Addendum”) reflects the requirements of the California Consumer Privacy Act of 2018 and its implementing regulations, as amended or superseded from time to time (California Civil Code §§ 1798.100 to 1798.199) (the “CCPA”). This Addendum makes clear that FingerprintJS is acting as a Service Provider for CCPA purposes.

This Addendum is an addendum to the Customer Terms of Service (“Agreement”) and its incorporated Customer Data Processing Agreement (the “DPA”) between FingerprintJS Inc. (“FingerprintJS”) and the Customer (each a “Party”; collectively the “Parties”) and is in effect for so long as FingerprintJS processes Personal Information (as defined in and to the extent protected by the CCPA) provided by Customer or which is collected on behalf of Customer by FingerprintJS (hereinafter, the “Personal Information”). This Addendum shall only apply and bind the Parties if and to the extent Customer is a Business under the CCPA. This Addendum prevails over any conflicting terms of the Agreement or DPA, but does not otherwise modify the Agreement or DPA. All capitalized terms not defined in this Addendum shall have the meanings set forth in the CCPA. Customer enters into this Addendum on behalf of itself and, to the extent required under the CCPA, in the name and on behalf of its Authorized Affiliates (defined below).

The parties agree as follows:

1. Definitions

1.1. “Affiliate” means an entity that directly or indirectly Controls, is Controlled by or is under common Control with an entity.

1.2. “Authorized Affiliate” means any of Customers’ Affiliate(s) permitted to or otherwise receiving the benefit of the Services pursuant to the Agreement.

2. Scope and Applicability of this Addendum

2.1. This Addendum applies to the collection, retention, use, and disclosure of the Personal Information to provide Services to Customer pursuant to the Agreement or to perform a Business Purpose.

2.2. Customer is a Business and appoints FingerprintJS as a Service Provider to process the Personal Information on behalf of Customer. Customer is responsible for compliance with the requirements of the CCPA applicable to Businesses.

3. Restrictions on Processing

3.1. FingerprintJS is prohibited from retaining, using, or disclosing the Personal Information for any purpose other than for the specific purpose of performing the Services specified in the Agreement for Customer, as set out in this Addendum, or as otherwise permitted by the CCPA. Notwithstanding the foregoing, nothing in this DPA shall restrict FingerprintJS’s ability to disclose Personal Information (i) to a Subcontractor for a Business Purpose pursuant to a written agreement to protect Personal Information in the same manner as provided herein; (ii) to a third party as necessary to comply with applicable laws; or (iii) as otherwise permitted by the CCPA.

4. Notice

4.1. Customer represents and warrants that it has provided notice to Consumers, as required under the CCPA for a Business, that the Personal Information is being used or shared as set forth in the Agreement.

5. Consumer Rights

5.1. FingerprintJS shall provide reasonable assistance to Customer in facilitating compliance with Consumer rights requests.

5.2. Upon written request by Customer, FingerprintJS shall delete the Personal Information within a commercially reasonable amount of time.

5.2.1 FingerprintJS shall not be required to delete any of the Personal Information to comply with a Consumer’s request directed by Customer if it is necessary to maintain such information in accordance with Cal. Civ. Code 1798.105(d), in which case FingerprintJS shall promptly inform Customer of the exceptions relied upon under 1798.105(d) and FingerprintJS shall not use the Personal Information retained for any other purpose than provided for by that exception.

6. Deidentified Information

6.1. In the event that either Party shares Deidentified Information with the other Party, the receiving Party warrants that it: (i) has implemented technical safeguards that prohibit reidentification of the Consumer to whom the information may pertain; (ii) has implemented business processes that specifically prohibit reidentification of the information; (iii) has implemented business processes to prevent inadvertent release of Deidentified Information; (iv) will make no attempt to reidentify the information.

7. Mergers, Sale, or other asset transfer

7.1. In the event that either Party transfers to a Third Party the Personal Information of a Consumer as an asset that is part of a merger, acquisition, bankruptcy, or other transaction in which the Third Party assumes control of all or part of such Party to the Agreement, that information shall be used or shared consistently with applicable law. If a Third Party materially alters how it uses or shares the Personal Information of a Consumer in a manner that is materially inconsistent with the promises made at the time of collection, it shall provide prior notice of the new or changed practice to the Consumer in accordance with applicable law.

8. As required by law

8.1. Notwithstanding any provision to the contrary of the Agreement, the DPA or this Addendum, FingerprintJS may cooperate with law enforcement agencies concerning conduct or activity that it reasonably and in good faith believes may violate international, federal, state, or local law.

9. No Sale of Personal Information

9.1. FingerprintJS shall not Sell any Personal Information to a Third Party without the prior written consent of the Customer.

Did this page help you?