Data Handling

Data Handling Agreement (the "Agreement") is entered into between:

  • Sidecar Data Solutions LLC, (the "Recipient"), and
  • Client, dictated by signee on the Statement of Work (the "Client").
  1. Purpose
  2. This Agreement establishes data protection and security measures to ensure compliance with Ohio data protection laws, including the Ohio Data Protection Act (ODPA) and Ohio Personal Privacy Act.

  3. Scope of Data Access & Processing
  4. The Service Provider will process the following client data:

    • Transaction data from Clover
    • Sales performance reports
    • Customer purchase trends
    • Email addresses

    The Service Provider will not process sensitive personal information such as Social Security numbers, credit card details (beyond aggregated reporting), or health data.

  5. Security & Confidentiality Measures
  6. The Service Provider agrees to:

    • Restrict access to authorized personnel only
    • Use secure cloud storage that complies with PCI DSS standards
  7. Data Retention & Deletion
    • The Service Provider will retain data for the duration of the contract, unless otherwise required by law.
    • Upon request, all client data will be securely deleted within 30 days, with confirmation provided to the Client.
  8. Client Rights
  9. In compliance with Ohio Personal Privacy Act, the Client has the right to:

    • Request access to the processed data
    • Request correction or deletion of data
    • Request information on how data is being used
  10. Breach Notification Policy
    • If a data breach occurs, the Service Provider will notify the Client within 48 hours of discovery.
    • Affected individuals will be notified within 45 days, as required by Ohio Revised Code 1347.12.
  11. Third-Party Sharing
    • The Service Provider will not share data with third parties unless explicitly authorized by the Client.
    • Data will be shared with external analytic software (e.g., Power BI, Excel, etc) being used.
  12. Liability & Indemnification
    • The Service Provider is liable for any security breaches caused by their negligence.
    • If a breach occurs due to client negligence (e.g., sharing login credentials), the Service Provider is not responsible.
    • The Service Provider is not responsible for data breaches on the Clover platform or from negligence on those platforms.
  13. Governing Law
  14. This Agreement shall be governed by the laws of the State of Ohio.

    By signing the SOW and using the services, you acknowledge that you have read, understood, and agreed to this Data Handling Agreement.