"Controller"
The Customer entity that determines the purposes and means of processing personal data through the Service, as defined in GDPR Article 4(7).
"Processor"
AlecRae, Inc., which processes personal data on behalf of the Controller, as defined in GDPR Article 4(8).
"Sub-processor"
Any third party engaged by the Processor to process personal data on behalf of the Controller.
"Data Subject"
An identified or identifiable natural person whose personal data is processed through the Service.
"Personal Data"
Any information relating to a Data Subject, as defined in GDPR Article 4(1), that is processed through the Service.
"Processing"
Any operation performed on Personal Data, as defined in GDPR Article 4(2), including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.
"Data Protection Laws"
All applicable data protection and privacy legislation, including the EU General Data Protection Regulation (Regulation 2016/679), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), Brazil's LGPD, South Africa's POPIA, and any other applicable data protection law.
"Standard Contractual Clauses (SCCs)"
The standard contractual clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission (Decision 2021/914).
"Supervisory Authority"
An independent public authority responsible for monitoring the application of Data Protection Laws, as defined in GDPR Article 4(21).
"Technical and Organizational Measures (TOMs)"
The security measures implemented by the Processor to protect Personal Data, as described in Annex II of this DPA.