Data Processing Agreement
This Data Protection Agreement (“DPA”) supplements and forms part of the agreements between the Parties. Capitalized terms not defined in this DPA are defined in the main body of the Agreement. In the event of any conflict or inconsistency between the DPA and the Agreement, the DPA will govern.
1. Definitions
Affiliate means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where “control” refers to the power to direct or cause the direction of the subject entity, whether through ownership of voting securities, by contract or otherwise.
APPs mean the Australian Privacy Principles under the Australian Privacy Act.
APPI means the Act on the Protection of Personal Information of Japan.
Applicable Data Protection Laws means, as and to the extent applicable, the State Privacy Laws, GLBA, GDPR, NYDFS Cybersecurity Regulation, APPI, Australian Privacy Act and FADP.
Australian Privacy Act means the Australian Privacy Act 1988 (Cth).
Controller means the entity that, alone or jointly with others, determines the purposes or means of the Processing of Personal Data, including, as applicable, any “business” as that term is defined by the California Consumer Privacy Act.
Data Subject means the identified or identifiable natural person to whom Personal Data relates.
EEA means the European Economic Area.
FADP means the Swiss Federal Act on Data Protection in its revised version of 25 September 2020.
FDPIC means Swiss Federal Data Protection and Information Commissioner.
GDPR means, as and where applicable to Processing concerned: (i) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”); and/or (ii) the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (as amended, including by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019) (“UK GDPR”), including, in each case (i) and (ii) any applicable national implementing or supplementary legislation (e.g., the UK Data Protection Act 2018), and any successor, replacement, amendment or re-enactment, to or of the foregoing. References to “Articles” and “Chapters” of, and other relevant defined terms in, the GDPR shall be construed accordingly.
GLBA means the Gramm-Leach-Bliley Act of 1999, as amended, and any binding regulations promulgated thereunder.
Information Security Incident means an actual breach of Provider’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Provider’s possession, custody or control. Information Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.
NYDFS Cybersecurity Regulation means Title 23, Chapter I, Part 500 of the New York Code, Rules and Regulations, entitled Cybersecurity Requirements for Financial Services Companies, as amended.
OAIC means the Office of the Australian Information Commissioner.
Personal Data means Customer Content that constitutes “personal data,” “personal information,” “nonpublic personal information” or “personally identifiable information” as defined in Applicable Data Protection Laws, except that Personal Data does not include such information received by Provider directly or from other sources (such as its other customers) independent of Provider’s relationship with Customer.
Process or Processing means any operation or set of operations which is performed by Provider on behalf of Customer under this Agreement, on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Processor means the entity that Processes Personal Data on behalf and at the direction of the Controller, including, as applicable, any “service provider” as that term is defined by the California Consumer Privacy Act.
Provider means Rogo Technologies, Inc.
Restricted Data has the meaning given in 6(b). of this Annex A.
Restricted Transfer means the disclosure, grant of access or other transfer of Personal Data to any person located in: (i) when transferred from the EEA, any country or territory outside the EEA which does not benefit from an adequacy decision from the European Commission (an “EU Restricted Transfer”); (ii) when transferred from the UK, any country or territory outside the UK, which does not benefit from an adequacy decision from the UK Government (a “UK Restricted Transfer”); and (iii) when transferred from Switzerland, a country or territory outside of Switzerland which does not benefit from an adequacy decision from the Swiss authorities (a “Swiss Restricted Transfer”), in each case, which would be prohibited without a legal basis under the GDPR or FADP.
SCCs means the applicable (C-to-C, C-to-P, P-to-P or P-to-C) standard contractual clauses approved by the European Commission pursuant to implementing Decision (EU) 2021/914).
Security Measures has the meaning given in Section 4(a) (Provider Security Measures).
Services means the services that Provider performs for Customer under the Agreement.
State Privacy Laws means, collectively, the comprehensive state-specific data privacy laws and their regulations currently in effect and applicable to Provider’s Processing of Personal Data under the Agreement.
Subprocessors means third parties that Provider engages to Process Personal Data in relation to the Services.
Supervisory Authority means any entity with the authority to enforce Applicable Data Protection Laws, including, (i) in the context of the EEA and the EU GDPR, shall have the meaning given to that term in the EU GDPR; (ii) in the context of the UK and the UK GDPR, means the UK Information Commissioner’s Office (ICO); (iii) in the context of Switzerland and the FADP, means the FDPIC; and (iv) in the context of Australia and the Australian Privacy Act, means the OAIC.
UK Transfer Addendum means the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of the Mandatory Clauses included in Part 2 thereof.
2. Duration and Scope of DPA
This DPA will remain in effect so long as Provider Processes Personal Data, notwithstanding the expiration or termination of the Agreement.
Processing of Personal Data subject to the GDPR shall be subject to Annex 2 (European Annex).
Processing of Personal Data subject to the APPI is subject to Annex 5 (Japan Annex).
Processing of Personal Data subject to the Australian Privacy Act is subject to Annex 6 (Australia Annex).
Actual Uptime Percentage
Service Credit (as a percentage of monthly Fee)
≥ 99.5% but < 99.7%
2.5%
≥ 99.0% but < 99.5%
5%
≥ 98.0% but < 99.0%
10%
< 98.0%
15%
3. Customer Instructions
Provider will Process Personal Data in accordance with Customer’s instructions to Provider. By entering into this DPA, Customer instructs Provider to Process Personal Data to provide the Services and to perform its other obligations and exercise its rights under the Agreement. The Parties acknowledge and agree that the details of Provider’s Processing of Personal Data under this DPA (including the respective roles of the Parties relating to such Processing) are as described in Annex 1 (Data Processing Details) to the DPA.
4. Security
Provider Security Measures. Provider will implement and maintain technical, administrative, physical and organizational measures designed to protect Personal Data against Information Security Incidents as described in Annex 4 (the “Security Measures”). Provider may update the Security Measures from time to time, so long as the updated measures do not materially decrease the overall protection of Personal Data.
5. Data Subject Rights
Data Subject Request Assistance. Provider will (taking into account the nature of the Processing of Personal Data) provide Customer with assistance reasonably necessary and technically feasible for Customer to perform its obligations under Applicable Data Protection Laws to fulfill requests by Data Subjects to exercise their rights under Applicable Data Protection Laws (“Data Subject Requests”) with respect to Personal Data in Provider’s possession or control, including but not limited to, access, correction, deletion, and cessation of Processing of Personal Data. Customer shall compensate Provider for any such assistance at Provider’s then-current professional services rates, which shall be made available to Customer upon request. For the avoidance of doubt, Customer acknowledges and agrees that Customer shall remain solely responsible for Customer’s compliance with all Applicable Data Protection Laws, and nothing in the Agreement or this DPA shall constitute any acceptance by Provider of any responsibility for Customer’s compliance with all Applicable Data Protection Laws.
Customer’s Responsibility for Requests. If Provider receives a Data Subject Request, Provider will (i) notify Customer; and (ii) advise the Data Subject to submit the request to Customer. Customer will be solely responsible for responding to any such request.
6. Customer Responsibilities
Customer shall ensure (and is solely responsible for ensuring) that it has given such notices to and obtained such consents and permissions from third parties (including, without limitation, Data Subjects), and has all rights, in each case, as may be required under applicable law or otherwise for Provider to Process Personal Data as contemplated by the Agreement.
Customer represents and warrants to Provider that Customer Data does not and will not contain any Personal Data that contains racial, ethnic or national origin; religious or philosophical beliefs; political opinions; protected health information subject to the Health Insurance Portability and Accountability Act (“HIPAA”); other mental or physical health condition, diagnosis, history, treatment or other health data; health insurance information; pregnancy; sex life, sexuality or sexual orientation; status as transgender or non-binary; citizenship; citizenship or immigration status; union membership; status as a victim of crime; genetic, biometric, neural or biological data; personal information of children or teens; precise location information; Social Security number; driver’s license number; state identification card number; passport number; other government-issued identification numbers; financial information or account number; account login information; tax return data; contents of a communication to which you were not a party; or any bulk U.S. sensitive personal data or U.S. government-related data, in each case as defined in the U.S. Department of Justice’s Final Rule on Prohibition on Bulk Data Transfers to Foreign Adversaries (28 C.F.R. Part 202), as amended, or any successor or similar rule, law, or regulation (collectively, “Restricted Data”).
Customer represents and warrants that there is, and will be throughout the term of the Agreement, a valid legal basis for the Processing by Provider of Personal Data in accordance with this DPA and the Agreement (including, any and all instructions issued by Customer from time to time in respect of such Processing) for the purposes of all Applicable Data Protection Laws (including Article 6, Article 9(2) and/or Article 10 of the GDPR (where applicable)).
Customer shall ensure that all Data Subjects have (i) been presented with all required notices and statements (including as required by Article 12-14 of the GDPR (where applicable)); and (ii) provided all required consents, in each case (i) and (ii) relating to the Processing by Provider of Personal Data.
7. Subprocessors
Consent to Subprocessor Engagement. Customer generally authorizes Provider to engage third parties as Subprocessors in accordance with this Section 7.
Information about Subprocessors. Information about Subprocessors, including their functions and locations, is available at https://trust.rogo.ai/ (the “Subprocessor Site”), to which Customer may subscribe to receive updates. Provider may continue to use those Subprocessors already engaged by Provider as at the date of this DPA.
Requirements for Subprocessor Engagement. When engaging any Subprocessor, Provider will enter into a written contract with such Subprocessor containing data protection obligations not less protective than those in this DPA with respect to Personal Data to the extent applicable to the nature of the services provided by such Subprocessor. Provider shall be liable for all obligations subcontracted to, and all acts and omissions of, the Subprocessor in connection with the services they provide to Provider to the same extent as Provider would have been had it performed the Processing itself.
Opportunity to Object to Subprocessor Changes. When Provider engages any new Subprocessor after the effective date of the DPA, Provider will provide Customer with 30 calendar days advance notice of the engagement (including the name and location of the relevant Subprocessor and the activities it will perform) by updating the Subprocessor Site or by other written means. If Customer objects to such engagement (made in good faith based upon evidenced concerns that the use of that proposed Subprocessor would cause Customer to be in material and unavoidable breach of Applicable Data Protection Laws) in a written notice to Provider within ten (10) days after being informed of the engagement: (i) Provider shall use reasonable efforts to make available a commercially reasonable change in the provision of the Services which avoids the use of that proposed Sub-Processor; and (ii) if (A) such a change cannot be made within thirty (30) days from Provider’s receipt of Customer’s notice; (B) no commercially reasonable change is available; and/or (C) Customer declines to bear the cost of the proposed change, Customer may, as its sole and exclusive remedy, terminate the Processing of Personal Data and/or the Agreement with respect only to those services which cannot be provided by Provider without the use of the objected-to new Subprocessor, by providing no less than thirty (30) days’ prior written notice to Provider and pay Provider for all amounts due and owing under the Agreement as of the date of such termination. If Customer does not object to Provider’s appointment of a Subprocessor during the objection period referred to in this Section 7(d), Customer shall be deemed to have approved the engagement and ongoing use of that Subprocessor.
8. Audits
Reviews and Audits of Compliance. Customer may audit Provider’s compliance with its obligations under this DPA up to once per year and on such other occasions as may be required by Applicable Data Protection Laws. Provider will contribute to such audits by providing Customer with the information and assistance reasonably necessary to conduct the audit. Due to the nature of the Services, on-site audits are not necessary for Customer to audit Provider’s compliance with this DPA. If a third party is to conduct the audit, Provider may object to the auditor if the auditor is, in Provider’s reasonable opinion, not independent, a competitor of Provider, or otherwise manifestly unsuitable. Such objection by Provider will require Customer to appoint another auditor or conduct the audit itself. To request an audit, Customer must submit a proposed audit plan to Provider at least two weeks in advance of the proposed audit date and any third-party auditor must sign a customary non-disclosure agreement mutually acceptable to the parties (such acceptance not to be unreasonably withheld) providing for the confidential treatment of all information exchanged in connection with the audit and any reports regarding the results or findings thereof. The proposed audit plan must describe the proposed scope, duration, and start date of the audit. Provider will review the proposed audit plan and provide Customer with any concerns or questions (for example, any request for information that could compromise Provider security, privacy, employment or other relevant policies). Provider will work cooperatively with Customer to agree on a final audit plan. Nothing in this Section 8 shall require Provider to breach any duties of confidentiality. If the controls or measures to be assessed in the requested audit are addressed in a SOC 2 Type 2, ISO, NIST or similar audit report performed by a qualified third-party auditor within twelve (12) months of Customer’s audit request and Provider has confirmed there have been no known material changes in the controls audited since the date of such report, Customer agrees to accept such report in lieu of requesting an audit of such controls or measures. The audit must be conducted during regular business hours, subject to the agreed final audit plan and Provider’s safety, security or other relevant policies, and may not unreasonably interfere with Provider business activities. Customer will promptly notify Provider of any non-compliance discovered during the course of an audit and provide Provider the audit reports generated in connection with the audit(s) under this Section 8, unless prohibited by Applicable Data Protection Laws. Customer may use the audit reports only for the purposes of meeting Customer’s regulatory audit requirements and/or confirming compliance with the requirements of this DPA. Any audits are at Customer’s sole expense. Customer shall reimburse Provider for any time expended by Provider and any third parties in connection with any audits or inspections under this Section 8 at Provider’s then-current professional services rates, which shall be made available to Customer upon request. Customer will be responsible for any fees charged by any auditor appointed by Customer to execute any such audit.
9. Return and Deletion
Subject to Sections 9(b) and 9(c), upon the date of cessation of any Services involving the Processing of Personal Data (the “Cessation Date”), Provider shall promptly cease all Processing of Personal Data for any purpose other than for storage or as otherwise permitted or required under this DPA. For the avoidance of doubt, this Section 9 does not apply to Telemetry Data.
Subject to Section 9(d), to the extent technically possible in the circumstances (as determined in Provider’s sole discretion), on Customer’s written request to Provider (to be made no later than fourteen (14) days after the Cessation Date (“Post-cessation Storage Period”)), Provider shall within fourteen (14) days of such request, at Customer’s election either: (i) return a complete copy of all structured Personal Data within Provider’s possession to Customer by secure file transfer, promptly following which Provider shall delete or anonymize all other copies of such Personal Data, or (ii) either (at Provider’s option) delete or anonymize all structured Personal Data within Provider’s possession.
In the event that during the Post-cessation Storage Period, Customer does not instruct Provider in writing to either delete or return Personal Data pursuant to Section 9(b), Provider shall, subject to Section 9(d), promptly after the expiry of the Post-cessation Storage Period either (at its option) delete; or render anonymous, all structured Personal Data then within Provider possession to the fullest extent technically possible in the circumstances.
Notwithstanding the above, Provider may retain Personal Data, where permitted or required by applicable law, for such period as may be permitted or required by such applicable law, provided that Provider shall (i) maintain measures designed to protect all such Personal Data, and (ii) Process the Personal Data only as necessary for the purpose(s) specified in the applicable law permitting or requiring such retention.
10. Miscellaneous
Except as expressly modified by the DPA, the terms of the Agreement remain in full force and effect. Notwithstanding anything in the Agreement or any order form entered in connection therewith to the contrary, the parties acknowledge and agree that Provider’s access to Personal Data does not constitute part of the consideration exchanged by the parties in respect of the Agreement. Notwithstanding anything to the contrary in the Agreement, any notices required or permitted to be given by Provider to Customer under this DPA may be given (i) in accordance with any notice clause of the Agreement; (ii) to Provider’s primary points of contact with Customer; or (iii) to any email provided by Customer for the purpose of providing it with Services-related communications or alerts. Customer is solely responsible for ensuring that such email addresses are valid.
Provider agrees to cooperate in good faith with Customer concerning any amendments as may be reasonably necessary to address compliance with the Applicable Data Protection Laws.
Provider may on notice vary this DPA to the extent that (acting reasonably) it considers necessary to address the requirements of Applicable Data Protection Laws from time to time, including by varying or replacing the SCCs in the manner described in Paragraph 3.3 of Annex 2 (European Annex).
In the event of any conflict or inconsistency between (i) this DPA and the Agreement, this DPA shall prevail, or (ii) any SCCs entered into pursuant to Paragraph 2 of Annex 2 (European Annex) and this DPA and/or the Agreement, the SCCs shall prevail in respect of the Restricted Transfer to which they apply.
11. Limitation of Liability
The total aggregate liability of either Party towards the other Party, howsoever arising, under or in connection with the Agreement, this DPA and the SCCs (if and as they apply) will under no circumstances exceed any limitations or caps on, and shall be subject to any exclusions of, liability and loss agreed by the Parties in the Agreement; provided that, nothing in this Section 11 will affect any person’s liability to Data Subjects under the third-party beneficiary provisions of the SCCs (if and as they apply).
Annex 1 - Data Processing Details
PROVIDER / ‘DATA IMPORTER’ DETAILS
Name: Rogo Technologies, Inc. is a U.S. corporation
Address: 360 Park Avenue South, Floor 7, New York, NY 10010
Contact Details for Data Protection: Rogo Privacy Team, privacy@rogo.ai
Provider Activities: Providing a proprietary financial services research platform that is integrated with market data, news, filings, earnings, web data, and additional data sources, with features and functionality for automated analysis, AI smart search, and deep research.
Role: Processor
CUSTOMER / ‘DATA EXPORTER’ DETAILS
Name: The entity or other person who is a counterparty to the Agreement
Address: Customer’s address
Customer’s Contact Details for Data Protection: The name, position and contact details provided by Customer
Customer Activities: Customer’s activities relevant to this DPA are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement as part of its ongoing business operations.
Role: Controller
Categories of Data Subjects: Relevant Data Subjects include any Data Subjects of Personal Data that Customer causes Provider to process as part of the provisions of the Service, including Authorized Users, employees, job candidates, customers, and prospective customers of Customer’s products and services.
Categories of Personal Data: Relevant Personal Data includes any Categories of Personal Data Customer causes Provider to process as part of the provisions of the Service, including:
Personal details – for example any information that identifies the Data Subject, including name, and contact information.
Authentication details – for example username, password or PIN code, security questions and other access protocols.
Technological details – for example internet protocol (IP) addresses, unique identifiers and numbers (including unique identifier in tracking cookies or similar technology), pseudonymous identifiers, precise and imprecise location data, internet / application / program activity data, and device IDs and addresses.
Sensitive Categories of Data, and associated additional restrictions/safeguards:
Categories of sensitive data: None – as noted in Section 6(b) of the DPA, Customer agrees that Restricted Data, which includes ‘sensitive data’ (as defined in Clause 8.7 of the SCCs), must not be submitted to the Services.
Additional safeguards for sensitive data: N/A
Frequency of transfer: Ongoing – as initiated by Customer in and through its use, or use on its behalf, of the Services.
Nature of the Processing: Processing operations required in order to provide the Services in accordance with the Agreement.
Purpose of the Processing: as necessary to provide the Services as initiated by Customer in its use thereof, and to comply with any other reasonable instructions provided by Customer in accordance with the terms of this DPA, specifically for the purposes of providing a proprietary financial services research platform that is integrated with market data, news, filings, earnings, web data, and additional data sources, with features and functionality for automated analysis, AI smart search, and deep research.
Duration of Processing / Retention Period: For the period determined in accordance with the Agreement and DPA, including Section 9 of the DPA.
Transfers to (sub)processors: Transfers to Subprocessors are as, and for the purposes, described from time to time in the Subprocessor Site.
Annex 2 - European Annex
PROCESSING OF PERSONAL DATA
1.2
Where Provider receives an instruction from Customer that, in its reasonable opinion, infringes the GDPR, Provider shall inform Customer.
1.2
Customer acknowledges and agrees that any instructions issued by Customer with regards to the Processing of Personal Data by or on behalf of Provider pursuant to or in connection with the Agreement shall be in strict compliance with the GDPR and all other applicable laws.
DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION
2.1
Provider, taking into account the nature of the Processing and the information available to Provider, shall provide reasonable assistance to Customer, at Customer’s cost, with any data protection impact assessments and prior consultations with Supervisory Authorities which Customer reasonably considers to be required of it by Article 35 or Article 36 of the GDPR, in each case solely in relation to Processing of Personal Data by Provider.
2.2
Except to the extent prohibited by applicable law, Customer shall be fully responsible for all time spent by Provider (at Provider’s then-current professional services rates) in Provider’s provision of any cooperation and assistance provided to Customer under Paragraph 2.1, and shall on demand reimburse Provider any such costs incurred by Provider.
RESTRICTED TRANSFERS
EU Restricted Transfers
3.1
To the extent that any Processing of Personal Data under this DPA involves an EU Restricted Transfer from Customer to Provider, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:
populated in accordance with Part 1 of Attachment 1 to Annex 2 (European Annex); and
entered into by the Parties and incorporated by reference into this DPA.
UK Restricted Transfers
3.2
To the extent that any Processing of Personal Data under this DPA involves a UK Restricted Transfer from Customer to Provider, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:
varied to address the requirements of the UK GDPR in accordance with UK Transfer Addendum and populated in accordance with Part 2 of Attachment 1 to Annex 2 (European Annex); and
entered into by the Parties and incorporated by reference into this DPA.
Swiss Restricted Transfers
3.3
To the extent that any Processing of Personal Data under the DPA involves a Swiss Restricted Transfer from Customer to Provider, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:
varied to address the requirements of the FADP and populated in accordance with Part 3 of Attachment 1; and
entered into by the Parties and incorporated by reference in the DPA.
Nothing in any applicable SCCs (as deemed amended pursuant to this Section 3.3) should be interpreted or construed in such a way as would limit or exclude the rights of Data Subjects under Clause 18(c) of those SCCs (as deemed amended pursuant to this Section 3.3) to bring legal proceedings before the courts in Switzerland where Switzerland is that Data Subject’s place of habitual residence.
Adoption of new transfer mechanism
3.4
Provider may upon notice vary this DPA and replace the relevant SCCs with:
any new form of the relevant SCCs or any replacement therefor prepared and populated accordingly (e.g., standard data protection clauses adopted by the European Commission for use specifically in respect of transfers to data importers subject to Article 3(2) of the EU GDPR); or
another transfer mechanism, other than the SCCs, that enables the lawful transfer of Personal Data to Provider under this DPA in compliance with Chapter V of the GDPR.
Nothing in any applicable SCCs (as deemed amended pursuant to this Section 3.3) should be interpreted or construed in such a way as would limit or exclude the rights of Data Subjects under Clause 18(c) of those SCCs (as deemed amended pursuant to this Section 3.3) to bring legal proceedings before the courts in Switzerland where Switzerland is that Data Subject’s place of habitual residence.
Provision of full-form SCCs
3.5
In respect of any given Restricted Transfer, if requested of Customer by a Supervisory Authority, Data Subject or further Controller (where applicable) – on specific written request (made to the contact details set out in Annex 1 (Data Processing Details); accompanied by suitable supporting evidence of the relevant request), Provider shall provide Customer with an executed version of the relevant set(s) of SCCs responsive to the request made of Customer (amended and populated in accordance with Attachment 1 to Annex 2 (European Annex) in respect of the relevant Restricted Transfer) for countersignature by Customer, onward provision to the relevant requestor and/or storage to evidence Customer’s compliance with Applicable Data Protection Laws.
Operational clarifications
3.6
When complying with its transparency obligations under Clause 8.3 of the SCCs, Customer agrees that it shall not provide or otherwise make available, and shall take all appropriate steps to protect, Provider’s and its licensors’ trade secrets, business secrets, confidential information and/or other commercially sensitive information.
3.7
Where applicable, for the purposes of Clause 10(a) of Module Three of the SCCs, Customer acknowledges and agrees that there are no circumstances in which it would be appropriate for Provider to notify any third-party controller of any Data Subject Request and that any such notification shall be the sole responsibility of Customer.
3.8
For the purposes of Clause 15.1(a) of the SCCs, except to the extent prohibited by applicable law and/ or the relevant public authority, as between the Parties, Customer agrees that it shall be solely responsible for making any notifications to relevant Data Subject(s) if and as required.
3.9
The terms and conditions of Section 7 of the DPA apply in relation to Provider’s appointment and use of Subprocessors under the SCCs. Any approval by Customer of Provider’s appointment of a Subprocessor that is given expressly or deemed given pursuant to that Section 7 constitutes Customer’s documented instructions to effect disclosures and onward transfers to any relevant Subprocessors if and as required under Clause 8.8 of the SCCs.
3.10
The audits described in Clauses 8.9(c) and 8.9(d) of the SCCs shall be subject to any relevant terms and conditions detailed in Section 8 of the DPA.
3.11
Certification of deletion of Personal Data as described in Clauses 8.5 and 16(d) of the SCCs shall be provided only upon Customer’s written request.
Attachment 1 - Popoulation of SCCs
In the context of any EU Restricted Transfer, the SCCs populated in accordance with Part 1 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Paragraph 3.1 of Annex 2 (European Annex) to the DPA).
In the context of any UK Restricted Transfer, the SCCs as varied by the UK Transfer Addendum and populated in accordance with Part 2 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Paragraph 3.2 of Annex 2 (European Annex) to the DPA).
In the context of any Swiss Restricted Transfer, the SCCs as varied and populated by Part 3 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Section 3.3 of Annex 2 (European Annex) to the DPA.
PART 1: POPULATION OF THE SCCs
SIGNATURE OF THE SCCs:
Where the SCCs apply in accordance with Paragraph 3.1 of Annex 2 (European Annex) to the DPA each of the Parties is hereby deemed to have signed the SCCs at the relevant signature block in Annex I to the Appendix to the SCCs.
MODULES
The following modules of the SCCs apply in the manner set out below (having regard to the role(s) of Customer set out in Attachment 1 to Annex 2 (European Annex) to the DPA):
a.
Module Two of the SCCs applies to any EU Restricted Transfer and/or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Customer is a Controller in its own right; and/or
b.
Module Three of the SCCs applies to any EU Restricted Transfer and/or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Customer is itself acting as a Processor on behalf of any other person.
POPULATION OF THE BODY OF THE SCCs
3.1
For each Module of the SCCs, the following applies as and where applicable to that Module and the Clauses thereof:
The optional ‘Docking Clause’ in Clause 7 is not used and the body of that Clause 7 is left intentionally blank.
In Clause 9:
OPTION 1 (SPECIFIC PRIOR AUTHORISATION) is not used and that optional language is deleted; as is, therefore, Annex III to the Appendix to the SCCs; and
OPTION 2 (GENERAL WRITTEN AUTHORISATION) applies, and the minimum time period for advance notice of the addition or replacement of Subprocessors shall be the advance notice period set out in Section 7(d) of the DPA.
In Clause 11, the optional language is not used and is deleted.
In Clause 13, all square brackets are removed and all text therein is retained.
In Clause 17:
OPTION 1 applies, and the Parties agree that the SCCs shall be governed by the law of Ireland in relation to any EU Restricted Transfer; and
OPTION 2 is not used and that optional language is deleted.
For the purposes of Clause 18, the Parties agree that any dispute arising from the SCCs in relation to any EU Restricted Transfer shall be resolved by the courts of Ireland, and Clause 18(b) is populated accordingly.
3.2
In this Paragraph 3, references to “Clauses” are references to the Clauses of the SCCs.
POPULATION OF ANNEXES TO THE APPENDIX TO THE SCCs
4.1
Annex I to the Appendix to the SCCs is populated with the corresponding information detailed in Annex 1 (Data Processing Details) to the DPA, with:
Customer being ‘data exporter’; and
Provider being ‘data importer’.
4.2
Part C of Annex I to the Appendix to the SCCs is populated as below:
The competent supervisory authority shall be determined as follows:
Where Customer is established in an EU Member State: the competent supervisory authority shall be the supervisory authority of that EU Member State in which Customer is established.
Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies and Customer has appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State in which Customer’s EU representative relevant to the processing hereunder is based (from time-to-time).
Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies, but Customer has not appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State notified in writing to Provider’s contact point for data protection identified in Attachment 1 to Annex 2 (European Annex) to the DPA, which must be an EU Member State in which the data subjects whose personal data is transferred under these Clauses in relation to the offering of goods or services to them, or whose behavior is monitored, are located.
4.3
Annex II to the Appendix to the SCCs is populated as below:
General:
Please refer to Section 4 of the DPA and Annex 4 (Security Measures) to the DPA.
In the event that Customer receives a Data Subject Request under the EU GDPR and requires assistance from Provider, Customer should email Provider’s contact point for data protection identified in Annex 1 (Data Processing Details) to the DPA.
Subprocessors: When Provider engages a Subprocessor under these Clauses, Provider shall enter into a binding contractual arrangement with such Subprocessor that imposes upon them data protection obligations which, in substance, meet or exceed the relevant standards required under these Clauses and the DPA – including in respect of:
applicable information security measures;
notification of Information Security Incidents to Provider;
return or deletion of Personal Data as and where required; and engagement of further Subprocessors.
PART 2: UK RESTRICTED TRANSFERS
UK TRANSFER ADDENDUM
1.1
Where relevant in accordance with Paragraph 3.2 of Annex 2 (European Annex) to the DPA, the SCCs also apply in the context of UK Restricted Transfers as varied by the UK Transfer Addendum in the manner described below –
Part 1 to the UK Transfer Addendum. As permitted by Section 17 of the UK Transfer Addendum, the Parties agree:
Tables 1, 2 and 3 to the UK Transfer Addendum are deemed populated with the corresponding details set out in Annex 1 (Data Processing Details) and the foregoing provisions of this Attachment 1 (subject to the variations effected by the Mandatory Clauses described in (b) below); and
Table 4 to the UK Transfer Addendum is completed by the box labelled ‘Data Importer’ being deemed to have been ticked.
Part 2 to the UK Transfer Addendum. The Parties agreed to be bound by the Mandatory Clauses of the UK Transfer Addendum.
1.2
In relation to any UK Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs, shall be read as a reference to those SCCs as varied in the manner set out in Paragraph 1.1 of this Part 2.
PART 3: SWISS RESTRICTED TRANSFERS
VARIATIONS FOR SWISS RESTRICTED TRANSFERS
1.1
Where applicable in accordance with Section 6.4 of the DPA, the SCCs also apply in the context of Swiss Restricted Transfers with the following terms deemed to have the following substituted meanings:
“GDPR” means the FADP;
“European Union”, “Union” and “Member State(s)” each mean Switzerland; and
“supervisory authority” means the FDPIC.
1.2
In relation to any Swiss Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs, shall be read as a reference to those SCCs as varied in the manner set out in Section 1.1 of this Part 3.
Annex 3 - State Privacy Laws Annex
For purposes of this Annex 3, the terms “business,” “commercial purpose,” “sell,” “share,” “targeted advertising” and “service provider” shall have the respective meanings given thereto in the State Privacy Laws, and “personal information” shall mean Personal Data that constitutes personal information governed by the State Privacy Laws.
It is the parties’ intent that with respect to any personal information, Provider is a service provider. Provider (a) acknowledges that personal information is disclosed by Customer only for limited and specified purposes described in the Agreement; (b) shall comply with applicable obligations under the State Privacy Laws and shall provide the same level of privacy protection to personal information as is required by the State Privacy Laws; (c) agrees that Customer has the right to take reasonable and appropriate steps to help to ensure that Provider’s use of personal information is consistent with Customer’s obligations under the State Privacy Laws; (d) shall notify Customer in writing of any determination made by Provider that it can no longer meet its obligations under the State Privacy Laws; and (e) agrees that Customer has the right, upon notice, including pursuant to the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
Provider shall not (a) sell or share any personal information or use it for targeted advertising; (b) retain, use or disclose any personal information for any purpose other than for the specific purpose of providing the Services, including retaining, using, or disclosing the personal information for a commercial purpose other than the provision of the Services; (c) retain, use or disclose the personal information outside of the direct business relationship between Provider and Customer; or (d) combine personal information received pursuant to the Agreement with personal information (i) received from or on behalf of another person, or (ii) or collected from Provider’s own interaction with any Consumer to whom such personal information pertains, except in each case (a) through (d) as and to the extent necessary as a part of Provider’s provision of the Services or as otherwise permitted by a service provider or processor under the State Privacy Laws. Provider hereby certifies that it understands its obligations under this Section 2 and will comply with them.
Giving Customer notice of Subprocessor engagements in accordance with Section 7 of the DPA shall satisfy Provider’s obligation under the State Privacy Laws to give notice of and an opportunity to object to such engagements.
Provider agrees that Customer may conduct audits, in accordance with Section 8 of the DPA, to help ensure that Provider’s use of personal information is consistent with Provider’s obligations under the State Privacy Laws.
The parties acknowledge that Provider’s retention, use and disclosure of personal information authorized by Customer’s instructions documented in the DPA are integral to Provider’s provision of the Services and the business relationship between the parties.
Annex 4 - Security Measures
Organizational management and dedicated staff responsible for the Provider’s information security program.
Data security controls which include, at a minimum, logical segregation of data, restricted (e.g., role-based) access and monitoring, and utilization of commercially available industry standard technologies for Personal Data that is transmitted over public networks (i.e., the internet).
Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions.
Password controls designed to manage and control password strength, expiration and usage including prohibiting users from sharing passwords.
Monitoring and maintenance of technology and information systems, including secure disposal of systems and media prior to final disposal or release from the Provider’s possession.
Change management procedures and tracking mechanisms designed to test, approve and monitor all material changes to the Provider’s technology and information assets.
Incident management procedures designed to allow Provider to investigate, respond to, mitigate and notify of events related to the Provider’s technology and information assets.
Network security controls that provide for the use of enterprise firewalls and intrusion detection systems designed to protect systems from intrusion and limit the scope of any successful attack.
Vulnerability assessment, patch management and threat protection technologies designed to identify, assess, mitigate and protect against identified security threats, viruses and other malicious code.
Business resiliency/continuity and disaster recovery procedures designed to maintain service and/or recovery from foreseeable emergencies or disasters.
Annex 5 - Japan Annex
Scope and Applicability
This Annex applies solely where Customer transfers Personal Data originating from Japan to Provider in connection with the performance of this Agreement.
For the avoidance of doubt, the parties acknowledge that:
Customer acts as a personal information handling business operator under the APPI;
Provider Processes such Personal Data on behalf of Customer; and
such transfer constitutes an entrustment under the APPI and may also constitute a cross-border transfer subject to Article 28 of the APPI.
In the event of any conflict between this Japan Annex and the DPA, this Japan Annex shall prevail with respect to Personal Data originating from Japan.
Government Access
To the extent permitted by applicable law, Provider shall:
promptly notify Customer of any legally binding request from a Japanese governmental authority for access to Personal Data;
assess the legality of such request and, where reasonably justified, challenge such request; and
disclose only the minimum amount of Personal Data necessary to comply with such request.
Remedial Measures and Suspension
Where Provider becomes unable to maintain the measures referred to in the DPA or this Japan Annex, Provider shall promptly notify Customer and take corrective actions. If such corrective actions cannot be implemented within a reasonable period, Customer may suspend the transfer of Personal Data from Japan and/or terminate the relevant Processing.
Information Security Incident
Provider shall promptly notify Customer of any Information Security Incident in accordance with Section 4(c) and provide reasonable assistance to enable Customer to comply with its notification and reporting obligations under applicable Japanese data protection laws.
Annex 6 - Australia Annex
Scope and Applicability
This Annex applies solely where Customer transfers Personal Data originating from Australia to Provider in connection with the performance of this Agreement (“Australian Personal Data”).
For the purposes of Section 6(b) of the DPA, “Restricted Data” includes ‘sensitive information’ within the meaning of the Australian Privacy Act.
In relation to disclosures of Australian Personal Data by the Provider to Subprocessors based outside of Australia, the requirements for Subprocessor engagement under Section 7(c) of the DPA are deemed to be reasonable steps by the Provider to ensure compliance with the APPs by such Subprocessors.
In the event of any conflict between this Annex 6 and the DPA, this Annex 6 shall prevail with respect to Australian Personal Data.
Information Security Incident
Provider shall promptly notify Customer of any Information Security Incident in accordance with Section 4(c) and provide reasonable assistance to enable Customer to comply with its notification obligations pursuant to Part IIIC of the Australian Privacy Act.