Talent Privacy Promise

Last update: September 2021

Data Processing Agreement: Talent Privacy Promise

Oshinstar enables talents on our platform ("Talents") to start membership businesses by connecting directly with their biggest fans and converting them into paying members ("Sponsors").

To facilitate this direct connection with Users and enable membership rewards and obligations to be fulfilled, Oshinstar provides Users' personal data ("User Data") to Talents. Talents then process the User Data to provide Users with any and all products or services as part of that Talent's Oshinstar membership business (collectively known as "Membership Services"). Oshinstar requires all Talents to agree to this Data Processing Agreement ("Privacy Promise") to ensure that Talents respect Users' privacy rights when processing User Data.

This Privacy Promise is between Oshinstar and Talents, is effective from the time an Oshinstar account is created, and applies exclusively to User Data collected by Oshinstar and provided to Talents for the purpose of administering a membership business with Oshinstar.

This Privacy Promise is an extension of Oshinstar's Terms of Service and Privacy Policy and will describe certain requirements for Talents to process User Data during and beyond their relationship with Oshinstar.

Definitions

Data protection legislation

Means all applicable laws relating to privacy and the processing of personal data that may exist in any relevant jurisdiction, including, where applicable, guidelines and codes of practice issued by supervisory authorities.

Good industry practices

It shall exercise the same skill, experience and judgment and use facilities and resources of similar quality as would be expected of a person who: (a) has the skill and experience in the provision of the services in question, seeking in good faith to perform its contractual obligations and seeking to avoid liability arising from any duty of care that might reasonably apply; (b) takes all reasonable and proper care and is diligent in the performance of its obligations; and (c) complies with the Data Protection Legislation.

Scope

The parties agree that Oshinstar is a data controller and that Talent is a data processor in relation to the User Data that Talent processes in the course of providing Membership Services. The subject matter of the data processing, the types of Personal Data processed and the categories of data subjects shall be defined and/or limited to those necessary to carry out the Membership Services. The processing to which this Privacy Promise applies will be carried out by Talent upon leaving the Oshinstar platform. The subject matter, duration, nature and purpose of the processing of personal data, as well as the type of personal data and categories of data subjects covered by this Privacy Promise, are as follows:

  1. The object of the data processing is the User Data.

  2. The duration of the processing is for as long as Talent holds the User Data.

  3. The nature and purpose of the processing under this Privacy Promise is limited to the performance of the Membership Services by Talent to the Client.

  4. The type of Personal Data covered by this agreement is contact information, including but not limited to user name, email address, shipping address, and pledge amounts.

Data Protection

The originator shall comply with the following requirements:

Processing as instructed.

Talent shall process User Data only in accordance with Oshinstar's Terms of Service, Privacy Policy and this Privacy Promise and only in accordance with Data Protection Legislation. The nature and purpose of the processing will be limited to that necessary to carry out such instructions, and not for Talent's own purposes, or for any other purpose, except as required by law. If Talent is required by law to process personal data for any other purpose, Talent will inform Oshinstar of such requirement prior to processing, unless prohibited by law.

Scope of processing

Talent processes personal data only to the extent and in the manner necessary for the provision of the Membership Services.

Appropriate Technical and Organizational Measures.

Talent shall implement and maintain appropriate technical and organizational measures designed to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, damage, theft, alteration or disclosure. The measures shall be appropriate to the harm that may result from any unauthorized or unlawful processing, accidental loss, destruction, damage or theft of personal data and having regard to the nature of the personal data to be protected and as a minimum shall be in accordance with Data Protection Legislation and Good Industry Practice.

Transfer to Third Parties

Talent will not give access to or transfer any personal data to any third party (including affiliates, group companies or subcontractors) without the prior consent of Oshinstar. Talent must also ensure the reliability and competence of such third parties, their employees or agents who may have access to personal data processed in the provision of Membership Services, and must include in any contract with such third parties provisions protecting the Client that are equivalent to those in this Privacy Promise and the Terms of Service and as required by applicable Data Protection Legislation.

Reliability and Competence of Talent Personnel

Talent will take reasonable steps to ensure the reliability and competence of any Talent Personnel who have access to User Data. Talent shall ensure that all Talent Personnel required to access Personal Data are informed of the confidential nature of Personal Data and comply with the obligations set forth in this Privacy Promise.

Data Protection Legislation Acknowledgment and Assistance

Talent will take all reasonable steps to assist Oshinstar in complying with applicable data protection legislation. For example, Talent will promptly inform Oshinstar in writing if it receives:

  1. A request from a data subject with respect to any personal data.

  2. A request for a complaint, communication or request relating to the User's obligations under the Data Protection Legislation.

Destruction or return of property upon completion of Membership Services.

Talent will not retain any of the Personal Data for longer than is necessary to provide Membership Services. At the end of the Membership Services, or when requested by Client, Talent will destroy or securely return (at Client's option) the Personal Data to Client.

Loss or Breach of Security

If Talent becomes aware of any accidental, unauthorized or unlawful destruction, loss, alteration or accidental disclosure of, or access to, User Data processed by Talent in the course of providing Membership Services, it will do the following:

  1. Notify Oshinstar. Talent will notify Oshinstar promptly and without undue delay and will provide Oshinstar with: a detailed description of the Loss or Security Breach; the type of data that was the subject of the Loss or Security Breach; the identity of each affected person, if known; and the steps Talent has taken or will take to mitigate and remediate such Security Breach, in each case as soon as such information can be collected or is otherwise available (as well as periodic updates of this information and any other information Oshinstar may reasonably request in connection with the Loss or Security Breach); and

  2. Promptly investigate the matter. Talent will promptly take steps, at its own expense, to investigate the Loss or Security Breach and to identify, prevent and mitigate the effects of the Loss or Security Breach and to take appropriate recovery actions to remedy the Loss or Security Breach.

Compliance with Data Protection Legislation

Talent shall at all times comply with and assist Oshinstar in complying with its applicable obligations under data protection legislation. Talent shall provide reasonable information requested by Oshinstar to demonstrate compliance with the obligations set forth in this Privacy Promise. Talent will notify Oshinstar immediately if, in Talent's opinion, an instruction to process personal data given by Oshinstar violates the data privacy legislation of any country.

Last updated