DATA PROCESSING ADDENDUM
THIS DATA PROCESSING ADDENDUM (“DPA”) is entered into and forms part of the Customer Agreement (the “Agreement”) between the customer identified under the applicable ordering document (“Customer”), and EasyHub, Inc., a Delaware corporation (“Provider”), together the “Parties” and each a “Party”.
- DEFINITIONS
In this DPA the terms below shall have the meanings set out in this Section 1, unless expressly stated otherwise. Capitalized terms used, but not defined, in this DPA shall have the meaning given to them in the Agreement. References to “including” mean “including, without limitation”.
“Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where «control» refers to the power to direct or cause the direction of the subject entity, whether through ownership of voting securities, by contract or otherwise.
“Applicable Data Protection Laws” means the privacy, data protection and data security laws and regulations of any jurisdiction applicable to the Processing of Customer Personal Data under the Agreement, including GDPR and CCPA (as applicable).
“CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (the “CPRA”), and any regulations promulgated thereunder.
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
“Customer Personal Data” means any Personal Data pertaining to users of Customer’s websites or other online services that Customer makes available to Provider for Processing to perform the Services.
“Data Protection Laws” means all laws and regulations applicable to the Processing of Customer Personal Data under the Agreement, including, as applicable: (i) the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and any binding regulations promulgated thereunder (“CCPA”), (ii) the CCPA, (iii) the GDPR as defined herein, and (iv) the UK Data Protection Act 2018; in each case, as updated, amended or replaced from time to time.
“Data Subject” means the identified or identifiable natural person to whom Customer Personal Data relates.
“Data Subject Request” means the request of a Data Subject to exercise rights under Applicable Data Protection Laws in respect of Customer Personal Data in Provider’s possession, custody or control.
“EEA” means the European Economic Area.
“GDPR” means, as and where applicable to Processing concerned (i) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”) and/or (ii) the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (as amended, including by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019) (“UK GDPR”), including, in each case (i) and (ii), any applicable national implementing or supplementary legislation (e.g., the UK Data Protection Act 2018), and any successor, amendment or re-enactment, to or of the foregoing. References to “Articles” and “Chapters” of, and other relevant defined terms in, the GDPR shall be construed accordingly.
“Personal Data” means “personal data,” “personal information,” “personally identifiable information” or similar terms defined in Applicable Data Protection Laws.
“Personal Data Breach” means a breach of Provider’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data in Provider’s possession, custody or control.
“Process” and inflections thereof refer to any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure and destruction.
“Processor” means a natural or legal person, public authority, agency, or other body which Processes Personal Data on behalf of the Controller.
“Restricted Transfer” means any transfer of Customer Personal Data to any person located in (i) in the context of the EEA, any country or territory outside the EEA which does not benefit from an adequacy decision from the European Commission described in Chapter 45 of the GDPR (an “EU Restricted Transfer”) and (ii) in the context of the UK, any country or territory outside the UK, which does not benefit from an adequacy decision from the UK Government (a “UK Restricted Transfer”), in each case, which would be prohibited without a legal basis under Chapter V of the GDPR.
“SCCs” means (i) the standard contractual clauses for the transfer of personal data to processors established in third countries which do not ensure an adequate level of protection as set out in Regulation (EU) 2016/679 of the European Parliament and of the Council from June 4, 2021, as available here, as updated, amended, replaced or superseded from time to time by the European Commission; or (ii) where required from time to time by a supervisory authority for use with respect to any specific restricted transfer, any other set of contractual clauses or other similar mechanism approved by such Supervisory Authority or by Applicable Laws for use in respect of such Restricted Transfer, as updated, amended, replaced or superseded from time to time by such Regulatory Authority or Data Protection Laws and Regulations.
“Services” means those services performed for Customer by Provider pursuant to the Agreement.
“Subprocessor” means any third party engaged directly or indirectly by or on behalf of Provider to Process Customer Personal Data under Provider’s care, custody or control.
“Supervisory Authority” means (i) in the context of the EEA and the EU GDPR, “supervisory authority” as defined in the EU GDPR; and (ii) in the context of the UK and the UK GDPR, means the UK Information Commissioner’s Office.
“UK Transfer Addendum” means the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of the Mandatory Clauses included in Part 2 thereof (the “UK Mandatory Clauses”).
- SCOPE OF THIS DATA PROCESSING ADDENDUM
-
-
- The Parties acknowledge and agree that the details of Provider’s Processing of Customer Personal Data (including the respective roles of the Parties relating to such Processing) are as described in Annex 1 (Data Processing Details) to the DPA.
- Annex 2 (European Annex) to this DPA applies to Provider’s Processing of Customer Personal Data that is subject to the GDPR.
- Annex 3 (California Annex) to this DPA applies to Provider’s Processing of Customer Personal Data that is subject to the CCPA.
- This DPA applies to Provider’s Processing of Customer Personal Data only to the extent required under any requirements of Applicable Data Protection Laws for contracts with Processors, and in such cases, only in respect of Processing subject to such laws.
-
- PROCESSING OF CUSTOMER PERSONAL DATA
-
- . Provider will Process Customer Personal Data as a Processor only: (i) in accordance with Customer Instructions or (ii) to comply with Provider’s obligations under applicable laws, subject to any notice requirements under Data Protection Laws.
- “Customer Instructions” means: (i) Processing to provide the Service and perform Provider’s obligations in the Agreement (including this DPA) and (ii) other reasonable documented instructions of Customer consistent with the terms of the Agreement. This DPA is a complete expression of such instructions, and Customer’s additional instructions will be binding on Provider only pursuant to an amendment to this DPA signed by both parties. Customer instructs Provider to Process Customer Personal Data to provide the Services and as authorized by the Agreement. Where Provider receives an instruction from Customer that, in its reasonable opinion, infringes Applicable Data Protection Laws, Provider shall notify Customer. For the avoidance of doubt, Customer instructions shall comply with Data Protection Laws. Customer shall have sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which Customer acquired Personal Data. Customer specifically acknowledges and agrees that its use of the Services will not violate the rights of any Data Subject, including those that have opted-out from sales or other disclosures of Personal Data, to the extent applicable under Data Protection Laws.
- The Parties acknowledge that Provider’s Processing of Customer Personal Data authorized by Customer’s instructions stated in this DPA are integral to the Services and the business relationship between the Parties. Access to Personal Data does not form part of the consideration exchanged between the Parties in respect of the Agreement or any other business dealings.
3.4 Changes to Laws. The parties will work together in good faith to negotiate an amendment to this DPA as either party reasonably considers necessary to address the requirements of Data Protection Laws from time to time.
- VENDOR PERSONNEL
Provider shall ensure that all Provider employees or other personnel who Process Customer Personal Data are subject to contractual or appropriate statutory obligations of confidentiality with respect to such Customer Personal Data.
- SECURITY
5.1 Provider shall implement and maintain technical, organizational and physical measures designed to protect the confidentiality, integrity and availability of Customer Personal Data and prevent Personal Data Breaches (the “Security Measures”). Provider may update the Security Measures from time to time, so long as the updated measures do not decrease the overall protection of Personal Data.
5.2 Customer Responsibilities. (a) Customer is responsible for reviewing the information made available by Provider relating to data security and making an independent determination as to whether the Service meets Customer’s requirements and legal obligations under Data Protection Laws. (b) Customer is solely responsible for complying with security incident notification laws applicable to Customer and fulfilling any obligations to give notices to government authorities, affected individuals or others relating to any security incidents.
- DATA SUBJECT REQUESTS
-
-
- Provider, taking into account the nature of the Processing of Customer Personal Data, shall provide Customer with such assistance by appropriate technical and organizational measures as Customer may reasonably request to assist Customer in fulfilling its obligations to respond to Data Subject Requests.
- Provider shall promptly notify Customer if it receives a Data Subject Request and not respond to any Data Subject Request, other than to advise the Data Subject to submit the request to Customer, except as required by Applicable Data Protection Laws.
-
- PERSONAL DATA BREACHES
-
-
- Provider shall notify Customer of a Personal Data Breach without undue delay after becoming aware of the occurrence thereof. Provider’s notification of or response to a Personal Data Breach will not be construed as Provider’s acknowledgement of any fault or liability with respect to the Personal Data Breach.
- If Customer determines that a Personal Data Breach must be notified to any Supervisory Authority or other governmental authority, any Data Subject(s), the public or others under Applicable Data Protection Laws in a manner that directly or indirectly refers to or identifies Provider, where permitted by applicable laws, Customer agrees to notify Provider in advance and in good faith consult with Provider and consider any clarifications or corrections Provider may reasonably recommend or request to any such notification.
-
- SUB-PROCESSING
-
-
- Customer generally authorizes Provider to appoint Subprocessors to Process Customer Personal Data. Customer further agrees that Provider may engage its Affiliates as Subprocessors.
- When engaging any Subprocessor, Provider will enter into a written contract with such Subprocessor containing data protection obligations not less protective than those in this DPA with respect to Customer Personal Data to the extent applicable to the nature of the services provided by such Subprocessor. Provider shall be liable for all obligations under the Agreement subcontracted to the Subprocessor or its actions and omissions related thereto.
- Subprocessor List. Provider’s current list of Sub-processors is available on Provider’s website at: [easyhub.ai/subprocessors]. Customer hereby consents to these Sub-processors, their locations and processing activities as it pertains to their Personal Data.
- When Provider engages any Subprocessor after the effective date of the Agreement, Provider will notify Customer of the engagement (including the name and location of the relevant Subprocessor and the activities it will perform) by written means (email sufficient) at least 30 days before such Subprocessor Processes Customer Personal Data. If Customer objects to such engagement in a written notice to Provider within 15 days after being notified of the engagement on reasonable grounds relating to the protection of Personal Data, Customer and Provider will work together in good faith to consider a mutually acceptable resolution to such objection. If Provier is unable to make available such change within a reasonable period of time, which shall not exceed sixty (60) days, Customer may terminate the applicable Order Form(s) with respect only to those Services which cannot be provided by Provider without the use of the objected-to new Subprocessor by providing written notice to Provider.
-
- COMPLIANCE ASSISTANCE; AUDITS
-
-
- Provider, taking into account the nature of the Processing and the information available to Provider, shall provide such information and assistance as Customer may reasonably request (insofar as such information is available to Provider and the sharing thereof does not compromise the security, confidentiality, integrity or availability of Personal Data Processed by Provider) to help Customer meet its obligations under Applicable Data Protection Laws, including in relation to the security of Customer Personal Data, the reporting and investigation of Personal Data Breaches, the demonstration of Customer’s compliance with such obligations, and the performance of any data protection assessments and consultations with Supervisory Authorities or other government authorities regarding such assessments in relation to Provider’s Processing of Customer Personal Data, including those required under Articles 35 and 36 of the GDPR.
- Provider shall make available to Customer such information as Customer may reasonably request for Provider to demonstrate compliance with Applicable Data Protection Laws and this DPA. Without limitation of the foregoing, Customer may conduct (in accordance with Section 9.3), at its sole cost and expense, and Provider will reasonably cooperate with, audits (including inspections, manual reviews, and automated scans and other technical and operational testing that Customer is entitled to perform under Applicable Data Protection Laws), in each case, whereby Customer or an auditor appointed by Customer may assess such compliance.
- Customer shall give Provider reasonable advance notice of any such audits. Provider need not cooperate with any audit (a) performed by any third-party auditor whom Provider has not approved in advance (which approval shall not be unreasonably withheld); (b) to any individual or entity who has not entered into a non-disclosure agreement with Provider on terms acceptable to Provider in respect of information obtained in relation to the audit; (c) outside normal business hours; or (d) on more than one occasion in any calendar year during the term of the Agreement, except for any additional audits that Customer is required to perform under Applicable Data Protection Laws. The audit must be conducted in accordance with Provider’s safety, security or other relevant policies, must not impact the security, confidentiality, integrity or availability of any data Processed by Provider and must not unreasonably interfere with Provider’s business activities. Customer shall not conduct any scans or technical or operational testing of Provider’s applications, websites, Services, networks or systems without Provider’s prior approval (which shall not be unreasonably withheld).
- If the controls or measures to be assessed in the requested audit are assessed in a SOC 2 Type 2, ISO, NIST or similar audit report performed by a qualified and independent third-party auditor pursuant to a recognized industry standard audit framework within twelve (12) months of Customer’s audit request (“Audit Report”) and Provider has confirmed in writing that there have been no known material changes to the controls audited and covered by such Audit Report(s), Customer agrees to accept provision of such Audit Report(s) in lieu of requesting an audit of such controls or measures. Provider shall provide copies of any such Audit Reports to Customer upon request.
- Such Audit Reports and any other information obtained by Customer in connection with an audit under this Section 9 shall constitute confidential information of Provider, which Customer shall use only for the purposes of confirming compliance with the requirements of this DPA or meeting Customer’s obligations under Applicable Data Protection Laws. Nothing in this Section 9 shall be construed to obligate Provider to breach any duty of confidentiality.
-
- RETURN AND DELETION
-
-
- Upon expiration or earlier termination of the Agreement, Provider shall, upon Customer’s written request, return a complete copy of all Customer Personal Data in Provider’s care, custody or control, promptly following which Provider shall delete all other copies of such Customer Personal Data.
- Notwithstanding the foregoing, Provider may retain Customer Personal Data where required by law (or in the case of Customer Personal Data subject to the GDPR, the laws of the UK or European Union, as applicable), provided that Provider shall (a) maintain the confidentiality of all such Customer Personal Data and (b) Process the Customer Personal Data only as necessary for the purpose(s) and duration specified in the applicable law requiring such retention.
-
- CUSTOMER RESPONSIBILITIES
-
-
- Customer agrees that, without limiting Provider’s obligations under Section 5, Customer is solely responsible for its use of the Services, including (a) making appropriate use of the Services to maintain a level of security appropriate to the risk in respect of the Customer Personal Data; (b) securing the account authentication credentials, systems and devices Customer uses to access the Services; (c) securing Customer’s systems and devices that Provider uses to provide the Services; and (d) backing up Customer Personal Data.
- Customer shall ensure that there is a valid legal basis for Provider’s Processing of Customer Personal Data in accordance with the Agreement for the purposes of Applicable Data Protection Laws (including Article 6, Article 9(2) and/or Article 10 of the GDPR where applicable). Customer shall ensure (and is solely responsible for ensuring) that all required notices have been given to, and all consents and permissions have been obtained from, Data Subjects and others as are required, including under Applicable Data Protection laws, for Provider to Process Customer Personal Data as contemplated by the Agreement.
- Customer agrees that the Service, the Security Measures, and Provider’s commitments under this DPA are adequate to meet Customer’s needs, including with respect to any security obligations of Customer under Applicable Data Protection Laws, and provide a level of security appropriate to the risk in respect of the Customer Personal Data.
- Customer shall ensure that Customer Personal Data made available to Provider for Processing does not contain any (a) Social Security numbers or other government-issued identification numbers; (b) biometric information; (c) passwords to any online accounts; (d) credentials to any financial accounts; (e) tax return data; (f) any payment card information subject to the Payment Card Industry Data Security Standard; (g) Personal Data of children under 16 years of age; (h) data relating to criminal convictions and offences or related security measures; or (i) information that constitutes special categories of personal data (as defined in the GDPR), sensitive personal information (as defined in the CCPA) or information of a similarly sensitive character regulated by Applicable Data Protection Laws.
- Except to the extent prohibited by applicable law, Customer shall compensate Provider at Provider’s then-current professional services rates for, and reimburse any costs reasonably incurred by Provider in the course of providing, cooperation, information or assistance requested by Customer pursuant to Sections 6, 9 and (solely in relation to the return of Customer Personal Data requested by Customer) 10 of this DPA beyond Provider’s provision of any self-service tools as part of the Services that Customer can use to obtain the requested cooperation, information or assistance.
-
- PRECEDENCE
In the event of any conflict or inconsistency between (a) this DPA and the Agreement, this DPA shall prevail or (b) any SCCs entered into pursuant to Annex 2 (European Annex) and this DPA and/or the Agreement, the SCCs shall prevail in respect of the Restricted Transfer to which they apply.
Annex 1 – Data Processing Details
Subject matter. Provider will Process Personal Data as necessary to perform the Services pursuant to the Agreement, as further instructed by Customer in its use of the Services.
Nature and Purpose of Processing
- Performing the Agreement, this DPA and/or other contracts executed by the Parties, including, providing the Service(s) to Customer and providing support and technical maintenance, if agreed in the Agreement
- For Provider to comply with documented reasonable instructions provided by Customer where such instructions are consistent with the terms of the Agreement.
Duration of Processing. Subject to any provision of this DPA and/or the Agreement dealing with the duration of the Processing and the consequences of the expiration or termination thereof, Provider will Process Personal Data for the duration of the Agreement, unless otherwise agreed upon in writing.
Type of Personal Data. Customer may submit Personal Data to the Services, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not limited to the following categories of Personal Data:
- Full name
- Username
- Email address
- Title / job position
- Customer details (to the extent that includes Personal Data)
- Any other Personal Data or information that the Customer provides or instructs Provider to Process in the context of the Services.
For the avoidance of doubt, the log-in details to Provider’s platform are subject to Provider’s privacy policy available here: https://www.easyhub.ai/privacy-policy and not to this DPA.
Notwithstanding anything to the contrary, Customer acknowledges that the same personal information or Personal Data provided by Customer or processed on behalf of Customer may have already been (or will be) provided by other customers or clients to Provider, or may have already been (or will be) collected by Provider independently or from other customers or clients, or may be available on public sources. For avoidance of doubt, this data and information may be collected, used and processed by Provider and/or disclosed by Provider to third parties and other customers or clients without this being deemed a breach of this DPA and/or the Agreement.
Categories of Data Subjects. Customer and its End Users may submit Personal Data to the Services, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not limited to Personal Data relating to the following categories of Data Subjects:
- Customer’s customers and End Users.
- Customer’s employees and contractors by Customer to use the Services
- Employees, agents, advisors, freelancers of Customer (who are natural persons)
- Employees or contact persons of Customer’s prospects, customers, business partners and vendors
The frequency of the transfer. Continuous basis
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period – As described in this DPA and/or the Agreement
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing. As detailed in the Subprocessor list
Annex 2 – European Annex
- RESTRICTED TRANSFERS
-
-
- General. The Parties acknowledge that Customer’s transmission of Customer Personal Data to Provider hereunder may involve a Restricted Transfer. The SCCs described in Paragraph 1.2 and/or 1.3 shall apply and have effect only if and to the extent permitted and required under the EU GDPR and/or UK GDPR (if and as applicable) to establish a valid basis under Chapter V of the EU GDPR and/or UK GDPR in respect of the transfer from Customer to Provider of Customer Personal Data.
- EU Restricted Transfers. To the extent that any Processing of Customer Personal Data under this DPA involves an EU Restricted Transfer from Customer to Provider, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be (a) populated in accordance with Part 1 of Attachment 1 to Annex 2 (European Annex); and (b) entered into by the Parties and incorporated by reference into this DPA.
- UK Restricted Transfers. To the extent that any Processing of Customer Personal Data under this DPA involves a UK Restricted Transfer from Customer to Provider, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be (a) varied to address the requirements of the UK GDPR in accordance with UK Transfer Addendum and populated in accordance with Part 2 of Attachment 1 to Annex 2 (European Annex); and (b) entered into by the Parties and incorporated by reference into this DPA.
- Provision of full-form SCCs. In respect of any given Restricted Transfer, on Customer’s written request, Provider shall provide Customer with an executed version of the relevant set(s) of SCCs (amended and populated in accordance with Attachment 1 to Annex 2 (European Annex)) in respect of the relevant Restricted Transfer.
-
- OPERATIONAL CLARIFICATIONS
-
-
- When complying with its transparency obligations under Clause 8.3 of the SCCs, Customer agrees that it shall not provide or otherwise make available, and shall take all appropriate steps to protect, Provider’s and its licensors’ trade secrets, business secrets, confidential information and/or other commercially sensitive information.
- Where applicable, for the purposes of Clause 10(a) of Module Three of the SCCs, Customer acknowledges and agrees that there are no circumstances in which it would be appropriate for Provider to notify any third-party controller of any Data Subject Request and that any such notification shall be the sole responsibility of Customer.
- For the purposes of Clause 15.1(a) of the SCCs, except to the extent prohibited by applicable law and/or the relevant public authority, as between the Parties, Customer agrees that it shall be solely responsible for making any notifications to relevant Data Subject(s) if and as required.
- The terms and conditions of Section 8 apply in relation to Provider’s appointment and use of Subprocessors under the SCCs.
- Any approval by Customer of Provider’s appointment of a Subprocessor that is given expressly or deemed given pursuant to Section 8 constitutes Customer’s documented instructions to effect disclosures and onward transfers to any relevant Subprocessors if and as required under Clause 8.8 of the SCCs.
- The audits described in Clauses 8.9(c) and 8.9(d) of the SCCs shall be subject to any relevant terms and conditions detailed in Section 9.
- Certification of deletion of Customer Personal Data as described in Clauses 8.5 and 16(d) of the SCCs, shall be provided only upon Customer’s written request
-
- LIABILITY TO DATA SUBJECTS
Notwithstanding any provision of the Agreement to the contrary, nothing in the Agreement shall limit either party’s liability to Data Subjects under the third party beneficiary provisions of the SCCs.
- TO EUROPEAN ANNEX
POPULATION OF SCCs
In the context of any EU Restricted Transfer, the SCCs populated in accordance with Part 1 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Paragraphs 1.1 and 1.2 of Annex 2 (European Annex) to the DPA).
In the context of any UK Restricted Transfer, the SCCs as varied by the UK Transfer Addendum and populated in accordance with Part 2 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Paragraphs 1.1 and 1.3 of Annex 2 (European Annex) to the DPA).
PART 1: POPULATION OF EU SCCs
- SIGNATURE OF THE SCCs; MODULES
-
- Where applicable in accordance with Paragraphs 1.1 and 1.2 of Annex 2 (European Annex) to the DPA, (a) each of the Parties is hereby deemed to have signed the SCCs at the relevant signature block in Annex I to the Appendix to the SCCs; and (b) those SCCs are entered into by and between the Parties with effect from (i) the effective date of the Agreement; or (ii) the date of the first EU Restricted Transfer to which they apply in accordance with Paragraphs 1.1 and 1.2 of 2 (European Annex) to the DPA, whichever is the later.
- The following modules of the SCCs apply in the manner set out below (having regard to the role(s) of Customer set out in Annex 1 (Data Processing Details) to the DPA):
Module Two of the SCCs applies to any EU Restricted Transfer involving Processing of Customer Personal Data in respect of which Customer is a Controller in its own right.
- POPULATION OF THE BODY OF THE SCCs
-
-
- For each Module of the SCCs, the following applies as and where applicable to that Module and the Clauses thereof:
- The optional ‘Docking Clause’ in Clause 7 is not used and the body of that Clause 7 is left intentionally blank.
- In Clause 9:
- OPTION 2: GENERAL WRITTEN AUTHORIZATION applies, and the minimum time period for advance notice of the addition or replacement of Subprocessors shall be the advance notice period set out in Section 8 of DPA, and the list of Subprocessors already authorized by the data exporter shall be the list on the Subprocessor Site as of the effective date of the Agreement; and
- OPTION 1: SPECIFIC PRIOR AUTHORIZATION is not used and that optional language is deleted; as is, therefore, Annex III to the Appendix to the SCCs.
- In Clause 11, the optional language is not used and is deleted.
- In Clause 13, all square brackets are removed and all text therein is retained.
- In Clause 17:
- OPTION 1 applies, and the Parties agree that the SCCs shall governed by the law of Ireland in relation to any EU Restricted Transfer; and
- OPTION 2 is not used and that optional language is deleted.
- For the purposes of Clause 18, the Parties agree that any dispute arising from the SCCs in relation to any EU Restricted Transfer shall be resolved by the courts of Ireland, and Clause 18(b) is populated accordingly.
- In this Paragraph, references to “Clauses” are references to the Clauses of the SCCs.
- For each Module of the SCCs, the following applies as and where applicable to that Module and the Clauses thereof:
-
- POPULATION OF ANNEXES TO THE APPENDIX TO THE SCCs
-
- Annex I to the Appendix to the SCCs is populated with the corresponding information detailed in Annex 1 (Data Processing Details) to the DPA, with Customer being ‘data exporter’ and Provider being ‘data importer’.
- Part C of Annex I to the Appendix to the EU SCCs is populated as follows:
- Where Customer is established in an EU Member State, the competent supervisory authority shall be the supervisory authority of that EU Member State in which Customer is established.
- Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies and Customer has appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State in which Customer’s EU representative relevant to the processing hereunder is based (from time-to-time).
- Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies, but Customer has not appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State notified in writing to Provider’s contact point for data protection identified in Annex 1 (Data Processing Details) to the DPA, which must be an EU Member State in which the data subjects whose personal data is transferred under these Clauses in relation to the offering of goods or services to them, or whose behaviour is monitored, are located.
- Annex II to the Appendix to the SCCs is populated as below
- General: Please refer to Section 5 of the DPA and the Security Measures described therein. In the event that Customer receives a Data Subject Request under the EU GDPR and requires assistance from Provider, Customer should email Provider’s contact point for data protection identified in Annex 1 (Data Processing Details) to the DPA.
- Subprocessors: When Provider engages a Subprocessor under these Clauses, Provider shall enter into a binding contractual arrangement with such Subprocessor that imposes upon them data protection obligations which, in substance, meet or exceed the relevant standards required under these Clauses and the DPA – including in respect of (a) applicable information security measures; (b) notification of Personal Data Breaches to Provider; (c) return or deletion of Customer Personal Data as and where required; and (d) engagement of further Subprocessors.
PART 2: UK RESTRICTED TRANSFERS
- UK TRANSFER ADDENDUM
-
- Where relevant in accordance with Paragraphs 1.1 and 1.3 of Annex 2 (European Annex) to the DPA, the SCCs also apply in the context of UK Restricted Transfers as varied by the UK Transfer Addendum in the manner described below –
- Part 1 to the UK Transfer Addendum. As permitted by Section 17 of the UK Transfer Addendum, the Parties agree:
- Tables 1, 2 and 3 to the UK Transfer Addendum are deemed populated with the corresponding details set out in Annex 1 (Data Processing Details) to the DPA and the foregoing provisions of this Attachment 1 to Annex 2 (European Annex) (subject to the variations effected by the Mandatory Clauses described in (b) below); and
- Table 4 to the UK Transfer Addendum is completed by the box labelled ‘Data Importer’ being deemed to have been ticked.
- Part 2 to the UK Transfer Addendum. Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO.
- Part 1 to the UK Transfer Addendum. As permitted by Section 17 of the UK Transfer Addendum, the Parties agree:
- Where relevant in accordance with Paragraphs 1.1 and 1.3 of Annex 2 (European Annex) to the DPA, the SCCs also apply in the context of UK Restricted Transfers as varied by the UK Transfer Addendum in the manner described below –
(c) Annex I.A: With respect to Module Two: Data Exporter is Customer as a data controller and the Data Importer is Provider as a data processor. With respect to Module Three: Data Exporter is Customer as a data processor and the Data Importer is Provider as a data processor (sub-processor). Data Exporter and Data Importer Contact details: As detailed in the Agreement. Signature and Date: By entering into the Agreement and this DPA, each Party is deemed to have signed these UK Standard Contractual Clauses incorporated herein, including their Annexes, as of the Effective Date of the DPA.
(d) Annex I.B of the UK Standard Contractual Clauses shall be completed as described in Annex 1 (Details of the Processing) of this DPA.
(e) Annex I.C of the UK Standard Contractual Clauses shall be completed as follows: The competent supervisory authority is the ICO supervisory authority.
(f) Annex II of the UK Standard Contractual Clauses shall be completed as described and agreed between the parties in the Agreement and/or this DPA.
(g) Annex III of the UK Standard Contractual Clauses shall be completed with the authorized sub-processors detailed in Schedule 2 (Sub-processor list) of this DPA.
- In relation to any UK Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs, shall be read as a reference to those SCCs as varied in the manner set out in Paragraph 4.1 of this Part 2.
Annex 3 – California Annex
-
- Capitalized terms used in this California Annex but not defined in the Agreement shall have the meanings given in the CCPA. As used in this California Annex, “Personal Information” means Customer Personal Data that constitutes “personal information” under the CCPA.
- It is the Parties’ intent that Provider is a Service Provider with respect to its processing of Customer Personal Data. Provider (a) acknowledges that Personal Information is disclosed by Customer only for limited and specified purposes described in the Agreement; (b) shall comply with applicable obligations under the CCPA and shall provide the same level of privacy protection to Personal Information as is required by the CCPA; (c) agrees that Customer has the right to take reasonable and appropriate steps under Section 9 of the DPA to help to ensure that Provider’s use of Personal Information is consistent with Customer’s obligations under the CCPA; (d) shall notify Customer in writing of any determination made by Provider that it can no longer meet its obligations under the CCPA; and (e) agrees that Customer has the right, upon notice, including pursuant to the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information.
- Provider shall not (a) Sell or Share Personal Information; (b) retain, use, or disclose any Personal Information for any purpose other than for the Business Purposes specified in the Agreement, including retaining, using, or disclosing Personal Information for a Commercial Purpose other than the Business Purpose specified in the Agreement, or as otherwise permitted by CPPA; (c) retain, use or disclose Personal Information outside of the direct business relationship between Provider and Customer; or (d) combine Personal Information received pursuant to the Agreement with Personal Information (i) received from or on behalf of another person, or (ii) or collected from Provider’s own interaction with any Consumer to whom such Personal Information pertains. Provider hereby certifies that it understands the obligations under this Section and will comply with them.
- Giving Customer notice of Subprocessor engagements in accordance with Section 8 of the DPA shall satisfy Provider’s obligation under the CPRA to give notice of such engagements. The Subprocessors used by Provider are Amazon Web Services and Google Cloud Platform.
Obligations under this California Annex that are neither required to be imposed on Provider for Provider to qualify as a Service Provider under the CCPA nor for the Parties to comply with their obligations under the CCPA in relation to the required terms of contracts, in each case, before the CPRA takes effect on January 1, 2023, shall apply to Provider only on and after January 1, 2023.