Last Updated: December 2024
This Data Processing Agreement (“DPA”) supplements the Shortlister Terms of Use and applies when Wellness Research Institute LLC, D/B/A Shortlister (“Shortlister“, “we”, “us”, or “our”) processes personal data on behalf of our business users (“you” or “Customer“) in connection with the Shortlister platform services.
This DPA is incorporated by reference into our Terms of Use and applies automatically when you use our Services to process personal data of individuals in the European Economic Area (EEA), United Kingdom (UK), or where otherwise required by applicable data protection laws.
For purposes of this DPA:
“Applicable Data Protection Laws” means all applicable data protection and privacy laws and regulations, including without limitation:
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing”, and “Supervisory Authority” have the meanings given in the EU GDPR and UK GDPR.
“Customer Data” means any Personal Data that Customer uploads, submits, or otherwise provides to the Shortlister platform, or that is processed by Shortlister on Customer’s behalf.
“Services” means the Shortlister platform services as described in our Terms of Use, including vendor research, RFP management, and related features.
“Sub-processor” means any third party engaged by Shortlister to process Customer Data.
This DPA applies when:
Customer warrants and represents that:
Shortlister will:
Purpose of Processing:
Categories of Data Subjects:
Types of Personal Data:
Processing will continue for the duration of the Services and as required for legal compliance or as instructed by Customer.
Shortlister will implement and maintain appropriate technical and organizational measures to protect Customer Data, including:
We regularly review and update our security measures to address evolving threats and maintain effectiveness.
Customer agrees that Shortlister may engage Sub-processors to process Customer Data, subject to:
Our current Sub-processors are listed at: www.myshortlister.com/subprocessors
Shortlister will provide reasonable assistance to help Customer respond to Data Subject requests, including:
In the event of a Personal Data Breach, Shortlister will:
o Nature and scope of the breach
o Categories and number of affected Data Subjects
o Categories and number of affected Personal Data records
o Likely consequences and mitigation measures
Customer is responsible for determining whether to notify:
If we transfer Customer Data outside the EEA or UK, we will ensure appropriate safeguards through:
Information about countries where Customer Data may be processed is available in our Privacy Policy.
Shortlister will:
We retain Customer Data:
Upon termination or Customer request:
Nature of Platform Operations:
The Shortlister platform is designed to facilitate data sharing between different parties (e.g., brokers sending RFPs to vendors, vendors submitting proposals to brokers). When Customer Data is shared through the platform’s intended operations:
Independent Controller Status:
Deletion Limitations:
Customer Acknowledgment:
Customer acknowledges and agrees that:
Audit Trails:
Notwithstanding deletion requests, Shortlister may retain minimal audit trail data necessary for:
Each party will defend and indemnify the other against third-party claims arising from that party’s violation of Applicable Data Protection Laws.
For Customer Data from the EEA:
For Customer Data from the UK:
For California residents’ Personal Data:
If any provision is invalid or unenforceable, the remainder continues in effect.
For questions about this DPA or our data protection practices:
Data Protection Officer
Wellness Research Institute LLC
310 Busse Hwy,
#386 Park Ridge, IL 60068
Email: privacy@myshortlister.com
For Business Accounts: By using the Services to process Personal Data, you accept this DPA on behalf of your organization.
Effective Date: This DPA is effective when you first use the Services after the Last Updated date above.
Where required for international transfers, the EU Commission’s Standard Contractual Clauses (Module 2: Controller to Processor) are incorporated by reference and available at: www.myshortlister.com/scc
For UK transfers, the UK International Data Transfer Agreement is incorporated by reference and available at: www.myshortlister.com/uk-idta
For California Personal Information:
1. Definitions: Terms used have meanings in the CCPA.
2. Service Provider Obligations: Shortlister will:
o Process Personal Information only for the Services
o Not sell or share Personal Information
o Not retain, use, or disclose Personal Information outside the Services
o Provide reasonable assistance with consumer requests
3. Certifications: Shortlister certifies it understands and will comply with CCPA restrictions.
This Data Processing Agreement demonstrates Shortlister’s commitment to protecting personal data in compliance with global data protection regulations. For questions or concerns, please contact our Data Protection Officer.
Used by most of the top employee benefits consultants in the US, Shortlister is where you can find, research and select HR and benefits vendors for your clients.
Shortlister helps you reach your ideal prospects. Claim your free account to control your message and receive employer, consultant and health plan leads.