Data Processing Addendum
This Data Processing Addendum (“DPA”) is entered into between FalconEye-Faceoff Intelligence System LLC (“FalconEye,” “Processor”) and the customer identified on the applicable order form or account (“Customer,” “Controller”), and supplements the FalconEye Terms of Service (the “Agreement”). Capitalized terms not defined here have the meaning given in the Agreement.
1. Scope
This DPA applies to FalconEye's processing of personal data contained in Customer Content, including data relating to student-athletes and staff, in connection with providing the Service to Customer.
2. Roles of the Parties
Customer is the data controller (or equivalent role under applicable law) for personal data it submits to the Service. FalconEye is a service provider/processor acting solely on Customer's documented instructions, as set out in the Agreement, this DPA, and the FalconEye Privacy Policy.
3. Customer Instructions
FalconEye will process personal data only: (a) to provide, maintain, and support the Service; (b) as necessary to comply with applicable law; or (c) as otherwise instructed in writing by Customer. FalconEye will not use personal data for any independent purpose of its own, including model training for unrelated third parties, and will not sell personal data.
4. FERPA
Where personal data constitutes an “education record” under FERPA, FalconEye acts as a “school official” with a legitimate educational interest, performing an institutional service that Customer would otherwise perform with its own employees, and remains under Customer's direct control with respect to the use and maintenance of such records, consistent with 34 C.F.R. § 99.31(a)(1). FalconEye will not disclose education records to any third party except as directed by Customer or required by law.
5. COPPA and Minor Data
Customer is responsible for ensuring any consent required under COPPA is obtained prior to provisioning a player account, or submitting personal information, for an individual under 13. FalconEye will reasonably cooperate with Customer's requests to review, correct, or delete such data.
6. Confidentiality
FalconEye will ensure personnel authorized to process personal data are subject to confidentiality obligations.
7. Security Measures
FalconEye will implement and maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, or destruction, consistent with the safeguards described in the FalconEye Security & Privacy Overview, including encryption in transit, access controls, and routine security review.
8. Subprocessors
FalconEye may engage subprocessors to provide the Service (e.g., cloud hosting, payment processing). FalconEye will impose confidentiality and security obligations on subprocessors no less protective than those in this DPA and will maintain a current subprocessor list available on request. FalconEye will provide notice of new subprocessors and a reasonable opportunity for Customer to object on reasonable data-protection grounds.
9. Data Subject / Parent Requests
Where FalconEye receives a request from an individual (or parent/guardian) to access, correct, or delete personal data, FalconEye will promptly direct the request to Customer, unless legally prohibited from doing so, and will reasonably assist Customer in responding.
10. Incident Notification
FalconEye will notify Customer without undue delay, and in any event within a commercially reasonable time — no later than 72 hours after confirming a security incident affecting Customer's personal data — and will provide reasonably requested information to help Customer meet its own legal notification obligations.
11. Data Return and Deletion
Upon termination of the Agreement, and consistent with Section 15 (Term and Termination) of the Terms of Service, FalconEye will make Customer Content available for export for the period specified in the Agreement, after which it will be deleted from active systems except as retained in backups or required by law.
12. Audits
Upon reasonable written request, and no more than once per year absent a security incident, FalconEye will provide Customer with information reasonably necessary to demonstrate compliance with this DPA, which may include completing a security questionnaire in lieu of an on-site audit.
13. State Law Addenda
Where Customer is subject to a state-specific student data privacy law (e.g., New York Education Law § 2-d, California SOPIPA/AB 1584, or similar), the parties agree to cooperate in good faith to execute any additional exhibit reasonably required to comply with that law.
14. Precedence
In the event of a conflict between this DPA and the Agreement with respect to the processing of personal data, this DPA controls.