Mobaro A/S (“Mobaro”) uses certain subprocessors (including members of the Mobaro Group and third parties, as listed below), subcontractors and content delivery networks to assist it in providing the Mobaro Services as described in the Master Agreement. Defined terms used herein shall have the same meaning as defined in the MSA.
What is a Subprocessor:
A subprocessor is a third party data processor engaged by Mobaro, including entities from within the Mobaro Group, who has or potentially will have access to or process Service Data (which may contain Personal Data). Mobaro engages different types of subprocessors to perform various functions as explained in the tables below. Mobaro refers to third parties that do not have access to or process Service Data but who are otherwise used to provide the Services as “subcontractors” and not subprocessors.
Due Diligence:
Mobaro undertakes to use a commercially reasonable selection process by which it evaluates the security, privacy and confidentiality practices of proposed subprocessors that will or may have access to or process Service Data.
Contractual Safeguards:
Mobaro requires its subprocessors to satisfy equivalent obligations as those required from Mobaro (as a Data Processor) as set forth in Mobaro’s Data Processing Agreement (“DPA”), including but not limited to the requirements to:
- process Personal Data in accordance with data controller’s (i.e. Subscriber’s) documented instructions (as communicated in writing to the relevant subprocessor by Mobaro);
- in connection with their subprocessing activities, use only personnel who are reliable and subject to a contractually binding obligation to observe data privacy and security, to the extent applicable, pursuant to applicable data protection laws;
- Provide regular training in security and data protection to personnel to whom they grant access to Personal Data;
- implement and maintain appropriate technical and organizational measures (including measures consistent with those to which Mobaro is contractually committed to adhere insofar as they are equally relevant to the subprocessor’s processing of Personal Data on Mobaro’s behalf) and provide an annual certification that evidences compliance with this obligation. In the absence of such certification Mobaro reserves the right to audit the subprocessor;
- promptly inform Mobaro about any actual or potential security breach; and
- cooperate with Mobaro in order to deal with requests from data controllers, data subjects or data protection authorities, as applicable.
This policy does not give Subscribers any additional rights or remedies and should not be construed as a binding agreement. The information herein is only provided to illustrate Mobaro’s engagement process for subprocessors as well as to provide the actual list of third party subprocessors, subcontractors and content delivery networks used by Mobaro as of the date of this policy (which Mobaro may use in the delivery and support of its Services).
If you are a Mobaro Subscriber and wish to enter into our DPA, please email us at privacy@mobaro.com.
Process to Engage New Subprocessors:
For all Subscribers who have executed Mobaro’s standard DPA, Mobaro will provide notice via this policy of updates to the list of subprocessors that are utilized or which Mobaro proposes to utilize to deliver its Services. Mobaro undertakes to keep this list updated regularly to enable its Subscribers to stay informed of the scope of subprocessing associated with the Mobaro Services.
Pursuant to the DPA, a Subscriber can object in writing to the processing of its Personal Data by a new subprocessor within thirty (30) days after updating of this policy and shall describe its legitimate reasons to object. If Subscriber does not object during such time period the new subprocessor(s) shall be deemed accepted.
If a Subscriber objects to the use of a subprocessor pursuant to the process provided under the DPA, Mobaro shall have the right to cure the objection through one of the following options (to be selected at Mobaro’s sole discretion):
(a) Mobaro will cease to use the subprocessor with regard to Personal Data;
(b) Mobaro will take the corrective steps requested by Subscriber in its objection (which remove Subscriber’s objection) and proceed to use the subprocessor to process Personal Data; or
(c) Mobaro may cease to provide or Subscriber may agree not to use (temporarily or permanently) the particular aspect of a Mobaro Service that would involve use of the subprocessor to process Personal Data.
Termination rights, are set forth in the Master Agreement.
The following is an up-to-date list (as of the date of this policy) of the names and locations of Mobaro subprocessors, subcontractors and content delivery networks (including members of the Mobaro Group and third parties):
Infrastructure Subprocessors – Service Data Storage
Mobaro controls access to the infrastructure that Mobaro uses to host Service Data submitted to the Services, other than as set forth below. Currently, the Mobaro production systems for the Services are located in Europe. The following table describes the countries and legal entities engaged in the storage of Service Data by Mobaro.
Entity Name |
Entity Type |
Entity Country |
Microsoft Azure |
Cloud Service Provider |
United States |
Service Specific Subprocessors
Mobaro works with certain third parties to provide specific functionality within the Services. These providers are the Subprocessors set forth below. In order to provide the relevant functionality these Subprocessors access Service Data. Their use is limited to the indicated Services.
Entity Name |
Purpose |
Entity Country |
Stored In |
Amazon Europe |
Distribution of push notifications to registered devices. |
United States |
Europe |
SendGrid |
Distribution of emails from Mobaro - e.g. assignment notifications, periodic reports and checklist report copies. |
United States |
Europe |
Auth0 |
Authentication-as-a-Service handling all login requests from end-users to Mobaro. |
United States |
Europe |
RayGun |
Tracks and registers usage information as well as diagnostic data from the Mobaro mobile app as well as the administrative web application. |
United States |
Europe |
ZenDesk |
Holds end-user documentation as well as support tickets submitted by users. |
United States |
Europe |
Intercom |
Holds end-user data, usage, and patterns to provide personalized communication and support. |
United States |
Europe |
Mobaro Group Subprocessors
The following entities are members of the Mobaro Group. Accordingly, they function as subprocessors to provide the Services.
Entity Name |
Country |
Mobaro, Inc. |
United States |
Mobaro Retail Ltd. |
United Kingdom |
Comments
0 comments