Global Data Processing Addendum

Last updated: 8/31/2026

Superagent Technologies, Inc.
Last updated: 8/31/2026

This Global Data Processing Addendum (including its annexes, this "DPA") forms part of the Services Agreement or other written agreement governing the Services (the "Agreement") between the customer accepting or entering into the Agreement ("Customer") and Superagent Technologies, Inc. ("Provider") (each a "Party" and together the "Parties"). This DPA becomes effective when Customer accepts the Agreement or when the Parties otherwise agree to it.

Definitions

The following terms have the meanings set out below for purposes of this DPA. Any capitalized terms not defined in this DPA have the meanings given in the Agreement.

Affiliate means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where "control" refers to the power to direct or cause the direction of the subject entity, whether through ownership of voting securities, by contract or otherwise.

Applicable Data Protection Laws means the privacy, data protection and data security laws and regulations applicable to Provider's Processing of Personal Data under the Agreement, including, as and to the extent applicable, the State Privacy Laws and GDPR.

Controller means the entity that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data, including, as applicable, any "business" or "controller" as such term is defined by the California Consumer Privacy Act (the "CCPA") or other State Privacy Laws.

Customer Data means information provided or otherwise made available by or on behalf of Customer to Provider for Processing on Customer's behalf to perform the Services.

Data Subject means the identified or identifiable natural person to whom Personal Data relates.

EEA means the European Economic Area.

FADP means the Swiss Federal Act on Data Protection of 25 September 2020 (as amended and in force from 1 September 2023) and any applicable implementing legislation and ordinances, and, to the extent applicable, its predecessor of 19 June 1992.

FDPIC means Swiss Federal Data Protection and Information Commissioner.

GDPR means, as and where applicable to Processing concerned: (i) the General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"); and/or (ii) the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (as amended, including by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019) ("UK GDPR"), including, in each case (i) and (ii) any applicable national implementing or supplementary legislation (e.g., the UK Data Protection Act 2018), and any successor, amendment or re-enactment, to or of the foregoing. References to "Articles" and "Chapters" of, and other relevant defined terms in, the GDPR shall be construed accordingly.

Information Security Incident means a breach of Provider's security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Provider's possession, custody or control. Information Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.

Personal Data means Customer Data that constitutes "personal data," "personal information," or "personally identifiable information" defined in Applicable Data Protection Laws or information of a similar character regulated thereby, provided that Personal Data does not include such information pertaining to Customer's business contacts who are Customer personnel or such information that Provider receives, collects, or generates independently of the Services and not from or on behalf of Customer.

Process or Processing means any operation or set of operations which is performed by Provider (or on Provider's behalf) for Customer under the Agreement on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Processor means the entity that Processes Personal Data on behalf of the Controller, including, as applicable, any "service provider" or "contractor" as those terms are defined by the CCPA.

Restricted Transfer means the disclosure, grant of access or other transfer of Personal Data to any person located in: (i) in the context of the EEA, any country or territory outside the EEA which does not benefit from an adequacy decision from the European Commission (an "EU Restricted Transfer"); (ii) in the context of the UK, any country or territory outside the UK which does not benefit from an adequacy decision from the UK Government (a "UK Restricted Transfer"); and (iii) in the context of Switzerland, a country or territory outside of Switzerland which does not benefit from an adequacy decision from the Swiss Government (a "Swiss Restricted Transfer"), in each case, which would be prohibited without a legal basis under applicable data protection law (including Chapter V of the GDPR, where applicable).

SCCs means the standard contractual clauses approved by the European Commission pursuant to implementing Decision (EU) 2021/914.

Security Measures has the meaning given in Section 4(a) (Provider Security Measures).

Services has the meaning given in the Agreement.

State Privacy Laws means, collectively, the comprehensive state-specific data privacy laws (and any implementing regulations) currently in effect and applicable to Provider's Processing of Personal Data under the Agreement.

Subprocessors means Provider's Affiliates and third parties that Provider engages to Process Personal Data in relation to the Services.

Supervisory Authority means any entity with the authority to enforce Applicable Data Protection Laws, including, (i) in the context of the EEA and the EU GDPR, shall have the meaning given to that term in the EU GDPR; (ii) in the context of the UK and the UK GDPR, means the UK Information Commissioner's Office; and (iii) in the context of Switzerland and the FADP, means the FDPIC.

UK Transfer Addendum means the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of the Mandatory Clauses included in Part 2 thereof.

Duration and Scope of DPA

This DPA will remain in effect so long as Provider Processes Personal Data, notwithstanding the expiration or termination of the Agreement.

Processing of Personal Data subject to the GDPR shall be subject to Annex 2 (European Annex).

Processing of Personal Data subject to the State Privacy Laws with respect to which Customer is a Business, Controller, Processor, or Service Provider (as such terms are defined in State Privacy Laws) shall be subject to Annex 3 (State Privacy Laws Annex) to this DPA.

Customer Instructions

Provider will Process Personal Data only in accordance with Customer's documented instructions to Provider, including as set out in this DPA, the Agreement, any applicable order form(s), and any other written instructions provided by Customer from time to time that are consistent with the Agreement and this DPA. To the extent Customer requests instructions that are outside the scope of the Services or that would require Provider to materially change the Services or undertake additional work not contemplated by the Agreement, the Parties will agree to such instructions in a mutually executed amendment to this DPA or other written agreement. By entering into this DPA, Customer instructs Provider to Process Personal Data to provide the Services and to perform its other obligations and exercise its rights under the Agreement. The parties agree that the details of Provider's Processing of Personal Data (including the respective roles of the Parties relating to such Processing) are as described in Annex 1 (Data Processing Details) to the DPA.

Security

Provider Security Measures. Provider will implement and maintain technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data as described in Annex 4 (the "Security Measures"), taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing and the risks to Data Subjects. Provider may update the Security Measures from time to time, including to maintain or improve security or address changes in Applicable Data Protection Laws, so long as the updated measures do not materially decrease the overall protection of Personal Data.

Security Compliance by Provider Staff. Provider will require that its personnel who are authorized to access Personal Data are subject to appropriate confidentiality obligations.

Information Security Incidents. Provider will notify Customer without undue delay of any Information Security Incident of which Provider becomes aware. Such notifications will describe, to the extent then known, available details of the Information Security Incident, including steps taken to mitigate the potential risks and steps Provider recommends Customer take to address the Information Security Incident. Provider's notification of or response to an Information Security Incident will not be construed as Provider's acknowledgement of any fault or liability with respect to the Information Security Incident. Provider will reasonably cooperate with Customer and take such commercially reasonable steps, to the extent within Provider's control, as may be reasonably requested by Customer and mutually agreed in good faith by the Parties to assist in the investigation of any such Information Security Incident. Customer is solely responsible for complying with notification laws applicable to Customer and fulfilling any third-party notification obligations related to any Information Security Incident. If Customer determines that an Information Security Incident must be notified to any Supervisory Authority, any Data Subject(s), the public or others under Applicable Data Protection Laws, to the extent such notice directly or indirectly refers to or identifies Provider, where permitted by applicable law, Customer agrees to (i) notify Provider in advance, and (ii) in good faith, consult with Provider and consider any clarifications or corrections Provider may reasonably recommend or request to any such notification, which: (a) relate to Provider's involvement in or relevance to such Information Security Incident; and (b) are consistent with applicable laws.

Customer's Security Responsibilities and Assessment

Customer's Security Responsibilities. Customer agrees that, without limitation of Provider's obligations under Section 4 (Security), Customer is solely responsible for its use of the Services, including (a) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Personal Data; (b) securing the account authentication credentials, systems and devices Customer uses to access the Services; (c) securing Customer's systems and devices that Customer provides or makes available for Provider to access in order to provide the Services; and (d) backing up Personal Data, as applicable.

Customer's Security Assessment. Customer acknowledges that it has evaluated the Services, the Security Measures and Provider's commitments under this DPA and, based on information made available by Provider, determines that they are adequate to meet Customer's needs, including with respect to any security obligations of Customer under Applicable Data Protection Laws, and provide a level of security appropriate to the risk in respect of the Personal Data.

Data Subject Rights

Data Subject Request Assistance. Provider will (taking into account the nature of the Processing of Personal Data) provide Customer with assistance reasonably necessary and technically feasible for Customer to perform its obligations under Applicable Data Protection Laws to fulfill requests by Data Subjects to exercise their rights under Applicable Data Protection Laws ("Data Subject Requests") with respect to Personal Data in Provider's possession or control. Customer will compensate Provider for any such assistance, to the extent such assistance requires work beyond the Services, at Provider's then-current professional services rates, which shall be made available to Customer upon request, and Provider will, upon request, provide Customer with a good-faith estimate of applicable fees.

Customer's Responsibility for Requests. If Provider receives a Data Subject Request, Provider will (i) promptly notify Customer (unless prohibited by applicable law); and (ii) advise the Data Subject to submit the request to Customer. Customer will be solely responsible for responding to any such request, unless otherwise required by applicable law.

Customer Responsibilities

(a) Customer will ensure (and is solely responsible for ensuring) that it has provided all notices to, and obtained all consents and permissions from, third parties (including, without limitation, Data Subjects), and has reserved all necessary rights, in each case, as may be required under Applicable Data Protection Laws for Provider to Process Personal Data as contemplated by the Agreement.

Customer represents and warrants that it will not intentionally submit social security numbers or other government-issued identification numbers; protected health information subject to HIPAA or other medical or health-insurance information; biometric information; production passwords or credentials for third-party online or financial accounts; tax-return data; payment-card information subject to the Payment Card Industry Data Security Standard; personal data of children under 16; or other special-category or regulated sensitive data (collectively, "Restricted Data"), unless the Parties expressly agree in writing and implement legally required safeguards. This restriction does not prohibit credentials or test data that Customer is authorized to provide solely for a documented, scoped security assessment, provided they do not permit access outside that scope.

Customer shall ensure that there is, and will be throughout the term of the Agreement, a valid legal basis for the Processing by Provider of Personal Data in accordance with this DPA and the Agreement (including any and all instructions issued by Customer from time to time in respect of such Processing) as required under all Applicable Data Protection Laws (including, where applicable, Articles 6, 9(2) and/or 10 of the GDPR).

Customer will ensure that all Data Subjects have (i) been presented with all required notices and statements (including as required by Articles 12-14 of the GDPR (where applicable)); and (ii) provided all required consents, in each case (i) and (ii) relating to the Processing by Provider of Personal Data.

Subprocessors

Consent to Subprocessor Engagement. Customer specifically authorizes the engagement of Provider's Affiliates as Subprocessors and generally authorizes Provider to engage third parties as Subprocessors in accordance with this Section 7.

Information about Subprocessors. Information about Subprocessors, including their functions and locations, is available on Provider's Subprocessor List (the "Subprocessor Site"). Provider may continue to use those Subprocessors already engaged by Provider as of the effective date of this DPA.

Requirements for Subprocessor Engagement. When engaging any Subprocessor, Provider will enter into a written contract with such Subprocessor containing data protection obligations not less protective than those in this DPA with respect to Personal Data to the extent applicable to the nature of the services provided by such Subprocessor. Provider shall remain responsible for the performance of all obligations subcontracted to the Subprocessor and shall be liable for all acts and omissions of the Subprocessor to the same extent as Provider would have been had it performed the Processing itself.

Opportunity to Object to Subprocessor Changes. When Provider engages any new Subprocessor after the effective date of the DPA, Provider will notify Customer of the engagement (including the name and location of the relevant Subprocessor and the activities it will perform) by updating the Subprocessor Site and providing written notice (including by email) to Customer's designated contact for Services-related communications, or by other written means. If Customer objects to such engagement in a written notice to Provider within 15 days after receipt of such notice on reasonable grounds relating to the protection of Personal Data, Customer and Provider will work together in good faith to find a mutually acceptable resolution to address such objection. If the Parties are unable to reach a mutually acceptable resolution within a reasonable timeframe, Customer may, as its sole and exclusive remedy, terminate the Agreement and cancel the Services by providing written notice to Provider and pay Provider for all amounts due and owing under the Agreement as of the date of such termination.

Audits

Reviews and Audits of Compliance. Customer may audit Provider's compliance with its obligations under this DPA up to once per year and on such other occasions as may be required by Applicable Data Protection Laws solely to the extent Customer is legally required to conduct such additional audit or a competent Supervisory Authority with jurisdiction over Customer requires it, in each case upon Customer's written request providing reasonable detail and, where available, supporting documentation of the applicable requirement. Provider will contribute to such audits by providing Customer with the information and assistance reasonably necessary to conduct the audit. If a third party is to conduct the audit, Provider may object to the auditor if the auditor is, in Provider's reasonable opinion, not independent, a competitor of Provider, or otherwise manifestly unsuitable. Such objection by Provider will require Customer to appoint another auditor or conduct the audit itself. To request an audit, Customer must submit a proposed audit plan to Provider at least two weeks in advance of the proposed audit date and any third-party auditor must sign a customary non-disclosure agreement mutually acceptable to the Parties (such acceptance not to be unreasonably withheld) providing for the confidential treatment of all information exchanged in connection with the audit and any reports regarding the results or findings thereof. The proposed audit plan must describe the proposed scope, duration, and start date of the audit. Provider will review the proposed audit plan and provide Customer with any concerns or questions (for example, any request for information that could compromise Provider security, privacy, employment or other relevant policies). Provider will work cooperatively with Customer to agree on a final audit plan. Nothing in this Section 8 shall require Provider to breach any duties of confidentiality. If the controls or measures to be assessed in the requested audit are addressed in an SOC 2 Type 2, ISO, NIST or similar audit report performed by a qualified third-party auditor within 12 months of Customer's audit request and Provider has confirmed there have been no known material changes in the controls audited since the date of such report, Customer agrees to accept such report in lieu of requesting an audit of such controls or measures. The audit must be conducted during regular business hours, subject to the agreed final audit plan and Provider's safety, security or other relevant policies, and may not unreasonably interfere with Provider business activities. Customer will promptly notify Provider of any non-compliance discovered during the course of an audit and provide Provider any audit reports generated in connection with any audit under this Section 8, unless prohibited by Applicable Data Protection Laws. Customer may use the audit reports only for the purposes of meeting Customer's regulatory audit requirements and/or confirming compliance with the requirements of this DPA. Any audits are at Customer's sole expense. Customer shall reimburse Provider for any reasonable, documented costs (including reasonable internal time expended by Provider and any third parties in connection with any audits or inspections under this Section 8 at Provider's then-current professional services rates, which shall be made available to Customer upon request). Customer will be responsible for any fees charged by any auditor appointed by Customer to execute any such audit.

Return and Deletion

Subject to Sections 9(b) and 9(c), upon the date of cessation of any Services involving the Processing of Personal Data (the "Cessation Date"), Provider will promptly cease all Processing of Personal Data for any purpose other than for storage and Processing necessary to effect the return, deletion, or anonymization of such Personal Data, or as otherwise permitted or required under this DPA or applicable law.

Subject to Section 9(d), to the extent technically feasible in the circumstances (as determined in Provider's sole discretion), on written request to Provider (to be made within 30 days after the Cessation Date ("Post-cessation Storage Period")), Provider will, within a commercially reasonable period following receipt of such request, as elected by Customer in such request, either (i) return a complete copy of all Personal Data within Provider's possession to Customer by secure file transfer or other commercially reasonable secure method, promptly following which Provider shall delete or anonymize all other copies of such Personal Data, or (ii) delete or anonymize all Personal Data within Provider's possession.

If, during the Post-cessation Storage Period, Customer does not instruct Provider in writing to either delete or return Personal Data under Section 9(b), Provider will, within a commercially reasonable time after the expiry of the Post-cessation Storage Period, either (at its option) delete or anonymize all Personal Data then within Provider's possession, custody or control to the fullest extent technically feasible in the circumstances.

Provider may retain Personal Data to the extent permitted or required by applicable law, for no longer than such applicable law requires, provided that Provider will (i) maintain the confidentiality of all such Personal Data and protect it in accordance with the Security Measures, (ii) Process such Personal Data only as necessary for the purpose(s) specified in the applicable law permitting or requiring such retention, and (iii) delete or anonymize such Personal Data once it is no longer permitted or required to be retained under applicable law.

Artificial Intelligence and Automated Processing

Provider will not use Personal Data to train, fine-tune, develop, or improve any artificial intelligence or machine learning model, whether the Provider's own or a third party's, unless (a) such use is reasonably necessary to provide the Services in accordance with the Customer's documented instructions, or (b) expressly authorized by the Customer in writing.

Provider will prohibit its Subprocessors, including any AI model providers, from using Personal Data for their own model training, fine-tuning, development, or improvement purposes, except as expressly authorized by the Customer in writing.

If the Services involve automated decision-making that produces legal or similarly significant effects on Data Subjects, Provider will: (a) disclose the existence of such processing to the Customer; (b) to the extent reasonably available to the Provider, provide meaningful information about the logic involved without requiring disclosure of the Provider's trade secrets or confidential information; and (c) reasonably cooperate with the Customer, as required by Applicable Data Protection Laws, to enable Data Subjects to exercise applicable rights under such laws relating to automated decision-making.

Miscellaneous

Except as expressly modified by the DPA, the terms of the Agreement remain in full force and effect. Notwithstanding anything in the Agreement or any order form entered in connection therewith to the contrary, the Parties acknowledge and agree that Provider's access to Personal Data does not constitute part of the consideration exchanged by the Parties in respect of the Agreement. Notwithstanding anything to the contrary in the Agreement, any notices required or permitted to be given by Provider to Customer under this DPA may be given (a) in accordance with any notice clause of the Agreement; (b) to Customer's contact details for data protection set out in Annex 1; (c) to Provider's primary points of contact with Customer; or (d) to any email address designated by Customer in writing for the purpose of receiving Services-related communications or alerts. Customer is solely responsible for ensuring that such email addresses are valid.

Provider agrees to cooperate in good faith with Customer to consider any amendments that may be reasonably necessary to address compliance with the Applicable Data Protection Laws.

Provider may, on written notice, vary this DPA solely to the extent necessary to maintain compliance with Applicable Data Protection Laws from time to time, provided that any such variation will not materially reduce the protections afforded to Personal Data or materially increase Customer's obligations under this DPA without Customer's written agreement, and may include varying or replacing the SCCs in accordance with Paragraph 3.4 (Adoption of new transfer mechanism) of Annex 2 (European Annex).

To the extent permitted by Applicable Data Protection Laws and the SCCs (if and as they apply), the total aggregate liability of either Party to the other Party, however arising, under or in connection with this DPA and the SCCs (if and as they apply) will under no circumstances exceed any limitations or caps on, and will be subject to any exclusions of, liability and loss agreed by the Parties in the Agreement; provided that nothing in this Section 11(d) will affect any person's liability to Data Subjects under the third-party beneficiary provisions of the SCCs (if and as they apply).

In the event of any conflict or inconsistency between (i) this DPA and the Agreement, this DPA will prevail, or (ii) any SCCs entered into pursuant to Paragraph 3 of Annex 2 (European Annex) and this DPA and/or the Agreement, the SCCs shall prevail in respect of the Restricted Transfer to which they apply.

By accepting the Agreement electronically or signing an Order or other document that incorporates this DPA, each Party agrees to be legally bound by this DPA.

Annex 1 Data Processing Details

PROVIDER / 'DATA IMPORTER' DETAILS

Name: Superagent Technologies, Inc.

Address: 1111B S Governors Ave, Suite 3232, Dover, Delaware 19904, United States

Contact Details for Data Protection: Privacy Team, privacy@superagent.sh

Provider Activities: Providing AI security, software-supply-chain security, contributor trust, agreement, runtime and context guardrail, and authorized red-team services.

Role: Processor (or Subprocessor, as applicable)

CUSTOMER / 'DATA EXPORTER' DETAILS

Name: The entity or other person who is a counterparty to the Agreement

Customer's address: The address associated with Customer's account or Order

Customer's Contact Details for Data Protection: Customer's account administrator or the contact identified in the Agreement or Order

Customer Activities: Customer's activities relevant to this DPA are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement as part of its ongoing business operations.

Role: Controller or Processor (as applicable)

Categories of Data Subjects: Relevant Data Subjects include any Data Subjects whose Personal Data Customer causes Provider to Process in connection with the Services, including End-users and other users of Customer's products and services, and Customer's personnel (including employees and contractors) and other business contacts or representatives of Customer.

Categories of Personal Data: Relevant Personal Data includes any Personal Data Customer causes Provider to Process through the Services, including:

  • Identity and contact details, such as names, usernames, email addresses, profile information, organization roles, and contributor or signer details.
  • Repository, contribution, and agreement details, such as repository and pull-request content, commit and contribution history, public account information, agreement templates, signature records, and related metadata.
  • Technical and activity details, such as IP addresses, device and browser information, pseudonymous identifiers, logs, endpoint events, commands, tool activity, URLs, package and file metadata, and security findings or decisions.
  • Customer-provided content, such as source code, files, email, web content, prompts, rules, configurations, authorized assessment targets and test data, and Outputs associated with that content.
  • Authentication and integration details, such as access tokens and credentials that Customer expressly authorizes Provider to use for the Services or for a scoped security assessment.

Sensitive Categories of Data, and associated additional restrictions/safeguards:

Categories of sensitive data: None intended. Under Section 6(b), Customer must not intentionally submit Restricted Data without the Parties' prior written agreement. Authorized credentials or test data used only for a documented, scoped security assessment are not authorization to submit other Restricted Data.

Additional safeguards for sensitive data: As agreed in writing for any authorized processing, including scope restrictions, access controls, encryption, and data minimization appropriate to the risk.

Frequency of transfer: Ongoing - as initiated by Customer in and through its use, or use on its behalf, of the Services.

Nature of the Processing: Processing operations required in order to provide the Services and perform Provider's obligations in accordance with the Agreement and this DPA.

Purpose of the Processing: As necessary to provide the Services as initiated by Customer in its use thereof, and to comply with Customer's documented instructions as permitted under and in accordance with the terms of this DPA and the Agreement.

Duration of Processing / Retention Period: For the period determined in accordance with the Agreement and DPA, including Section 9 of the DPA.

Transfers to (sub)processors: Transfers to Subprocessors are as, and for the purposes, described from time to time on the Subprocessor List. Annex 2

European Annex

1. PROCESSING OF PERSONAL DATA

1.1. Where Provider receives an instruction from Customer that, in its reasonable opinion, infringes the GDPR, Provider shall inform Customer.

1.2. Customer acknowledges and agrees that any instructions issued by Customer with regards to the Processing of Personal Data by or on behalf of Provider pursuant to or in connection with the Agreement shall be in strict compliance with the GDPR and all other applicable laws.

2. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION

2.1. Provider, taking into account the nature of the Processing and the information available to Provider, shall provide reasonable assistance to Customer, at Customer's cost, upon Customer's written request, to the extent reasonably necessary and technically feasible, with any data protection impact assessments and prior consultations with Supervisory Authorities as may be required of Customer under Article 35 or Article 36 of the GDPR, in each case solely in relation to Processing of Personal Data by Provider.‍

2.2. Except to the extent prohibited by applicable law, Customer will be fully responsible for all time spent by Provider (at Provider's then-current professional services rates) in Provider's provision of any cooperation and assistance provided to Customer under Paragraph 2.1, and shall on demand reimburse Provider for any such costs incurred by Provider.

3.RESTRICTED TRANSFERS

EU Restricted Transfers

3.1. To the extent that any Processing of Personal Data under this DPA involves an EU Restricted Transfer from Customer to Provider, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:

(a) populated in accordance with Part 1 of Attachment 1 to Annex 2 (European Annex); and

‍(b) entered into by the Parties and incorporated by reference into this DPA.

UK Restricted Transfers

3.2. To the extent that any Processing of Personal Data under this DPA involves a UK Restricted Transfer from Customer to Provider, the Parties shall comply with their respective obligations set out in the SCCs (as varied by the UK Transfer Addendum), which are hereby deemed to be:

(a) varied to address the requirements of the UK GDPR in accordance with the UK Transfer Addendum and populated in accordance with Part 2 of Attachment 1 to Annex 2 (European Annex); and

‍(b) entered into by the Parties and incorporated by reference into this DPA.

Swiss Restricted Transfers

3.3. To the extent that any Processing of Personal Data under the DPA involves a Swiss Restricted Transfer from Customer to Provider, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:

(a) varied to address the requirements of the FADP and populated in accordance with Part 3 of Attachment 1 to Annex 2 (European Annex); and

(b) entered into by the Parties and incorporated by reference into this DPA.

(c) Nothing in any applicable SCCs (as deemed amended pursuant to this Paragraph 3.3) should be interpreted or construed in such a way as would limit or exclude the rights of Data Subjects under Clause 18(c) of those SCCs (as deemed amended pursuant to this Paragraph 3.3) to bring legal proceedings before the courts in Switzerland where Switzerland is that Data Subject's place of habitual residence.

‍Adoption of new transfer mechanism

3.4. Provider may, on notice, vary this DPA and replace the relevant SCCs with:

(a) any new form of the relevant SCCs or any replacement therefor prepared and populated accordingly to the extent necessary to maintain compliance with Applicable Data Protection Laws, provided that any such replacement does not materially decrease the overall protection of Personal Data under the SCCs (e.g., standard data protection clauses adopted by the European Commission for use specifically in respect of transfers to data importers subject to Article 3(2) of the EU GDPR); or

(b) another valid transfer mechanism, other than the SCCs, that Provider reasonably determines is necessary to maintain compliance with Chapter V of the GDPR for the relevant transfer(s) and that does not materially diminish the data protection safeguards for Personal Data under this DPA.

‍Provision of full-form SCCs

3.5. In respect of any given Restricted Transfer, if requested of Customer by a Supervisory Authority, Data Subject or further Controller (where applicable) - on specific written request (made to the contact details set out in Annex 1 (Data Processing Details); accompanied by suitable supporting evidence of the relevant request), and to the extent required to evidence Customer's compliance with Applicable Data Protection Laws, Provider shall provide Customer within a reasonable time with an executed version of the relevant set(s) of SCCs responsive to the request made of Customer (amended and populated in accordance with Attachment 1 to Annex 2 (European Annex) in respect of the relevant Restricted Transfer) for countersignature by Customer, onward provision to the relevant requestor and/or storage.

Operational clarifications

3.6. When complying with its transparency obligations under Clause 8.3 of the SCCs, Customer agrees that it shall not provide or otherwise make available, and shall take all appropriate steps to protect, Provider's and its licensors' trade secrets, business secrets, confidential information and/or other commercially sensitive information.

3.7. Where applicable, for the purposes of Clause 10(a) of Module Three of the SCCs, Customer acknowledges and agrees that there are no circumstances in which it would be appropriate for Provider to notify any third-party controller of any Data Subject Request and that any such notification shall be the sole responsibility of Customer.

3.8. For the purposes of Clause 15.1(a) of the SCCs, except to the extent prohibited by applicable law and/or the relevant public authority, as between the Parties, Customer agrees that it shall be solely responsible for making any notifications to relevant Data Subject(s) if and as required.

3.9. The terms and conditions of Section 7 of the DPA apply in relation to Provider's appointment and use of Subprocessors under the SCCs. Any approval by Customer of Provider's appointment of a Subprocessor that is given expressly or deemed given pursuant to that Section 7 constitutes Customer's documented instructions to effect disclosures and onward transfers of Personal Data to such Subprocessor solely in connection with the Services, if and as required under Clause 8.8 of the SCCs.

3.10. The audits described in Clauses 8.9(c) and 8.9(d) of the SCCs shall be subject to any relevant terms and conditions detailed in Section 8 of the DPA.

3.11. Certification of deletion of Personal Data as described in Clauses 8.5 and 16(d) of the SCCs shall be provided only upon Customer's written request. Attachment 1

To Annex 2 (European Annex)

POPULATION OF SCCs

Note

In the context of any EU Restricted Transfer, the SCCs populated in accordance with Part 1 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Paragraph 3.1 of Annex 2 (European Annex) to the DPA).

In the context of any UK Restricted Transfer, the SCCs as varied by the UK Transfer Addendum and populated in accordance with Part 2 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Paragraph 3.2 of Annex 2 (European Annex) to the DPA).

In the context of any Swiss Restricted Transfer, the SCCs as varied and populated by Part 3 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Section 3.3 of Annex 2 (European Annex) to the DPA).

PART 1: POPULATION OF THE SCCs

  1. SIGNATURE OF THE SCCs:

Where the SCCs apply in accordance with Paragraph 3.1 of Annex 2 (European Annex) to the DPA, each of the Parties is hereby deemed to have signed the SCCs at the relevant signature block in Annex I to the Appendix to the SCCs.

  1. MODULES

The following modules of the SCCs apply in the manner set out below (having regard to the role(s) of Customer under the Agreement and as set out in Annex 1 (Data Processing Details) to the DPA):

(a) Module Two of the SCCs applies to any EU Restricted Transfer and/or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Customer is a Controller in its own right; and/or

(b) Module Three of the SCCs applies to any EU Restricted Transfer, UK Restricted Transfer and/or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Customer is itself acting as a Processor on behalf of any other person.

  1. POPULATION OF THE BODY OF THE SCCs

3.1. For each Module of the SCCs, the following applies as and where applicable to that Module and the Clauses thereof:

(a) The optional 'Docking Clause' in Clause 7 is not used and the body of that Clause 7 is left intentionally blank.

(b) In Clause 9:

(i) OPTION 2: GENERAL WRITTEN AUTHORISATION applies, and the minimum time period for advance notice of the addition or replacement of Subprocessors shall be the notice period set out in Section 7(d) of the DPA (currently fifteen (15) days); and

(ii) OPTION 1: SPECIFIC PRIOR AUTHORISATION is not used and that optional language is deleted; as is, therefore, Annex III to the Appendix to the SCCs.

(c) In Clause 11, the optional language is not used and is deleted.

(d) In Clause 13, all square brackets are removed, and all text therein is retained.

(e) In Clause 17:

i. OPTION 1 applies, and the Parties agree that the SCCs shall be governed by the law of Ireland in relation to any EU Restricted Transfer; and

ii. OPTION 2 is not used and that optional language is deleted.

(f) For the purposes of Clause 18, the Parties agree that any dispute arising from the SCCs in relation to any EU Restricted Transfer shall be resolved by the courts of Ireland, and Clause 18(b) is populated accordingly.

3.2. In this Paragraph 3, references to "Clauses" are references to the Clauses of the SCCs.

  1. POPULATION OF ANNEXES TO THE APPENDIX TO THE SCCs

4.1. Annex I to the Appendix to the SCCs is populated with the corresponding information detailed in Annex 1 (Data Processing Details) to the DPA, with:

(a) Customer being 'data exporter'; and

(b) Provider being 'data importer'.

4.2. Part C of Annex I to the Appendix to the SCCs is populated as below:

The competent supervisory authority shall be determined as follows:

Where Customer is established in an EU Member State: the competent supervisory authority shall be the supervisory authority of that EU Member State in which Customer is established.

Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies and Customer has appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State in which Customer's EU representative relevant to the processing hereunder is based (from time-to-time).

Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies, but Customer has not appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State notified in writing to Provider's contact point for data protection identified in Annex 1 (Data Processing Details) to the DPA, which must be an EU Member State in which the data subjects whose personal data is transferred under these Clauses in relation to the offering of goods or services to them, or whose behavior is monitored, are located.

4.3. Annex II to the Appendix to the SCCs is populated as below:

General:

Please refer to Section 4 of the DPA and Annex 4 (Security Measures) to the DPA.

If Customer receives a Data Subject Request under the EU GDPR and requires assistance from Provider, Customer should email Provider's contact point for data protection identified in Annex 1 (Data Processing Details) to the DPA.

Subprocessors: When Provider engages a Subprocessor under these Clauses, Provider shall enter into a binding contractual arrangement with such Subprocessor that, to the extent applicable to the nature of the services provided by such Subprocessor, imposes upon them data protection obligations which, in substance, meet or exceed the relevant standards required under these Clauses and the DPA - including in respect of:

appropriate technical and organizational information security measures;

notification of Information Security Incidents to Provider;

return or deletion of Personal Data, as and where required; and the engagement of further Subprocessors.

‍PART 2: UK RESTRICTED TRANSFERS

  1. UK TRANSFER ADDENDUM

1.1. Where relevant in accordance with Paragraph 3.2 of Annex 2 (European Annex) to the DPA, the SCCs also apply in the context of UK Restricted Transfers as varied by the UK Transfer Addendum in the manner described below -

(a) Part 1 to the UK Transfer Addendum. As permitted by Section 17 of the UK Transfer Addendum, the Parties agree:

(i) Tables 1, 2 and 3 to the UK Transfer Addendum are deemed populated with the corresponding details set out in Annex 1 (Data Processing Details) and the foregoing provisions of this Attachment 1 (subject to the variations effected by the Mandatory Clauses described in (b) below); and‍

(ii) Table 4 to the UK Transfer Addendum is completed by the box labelled 'Data Importer' being deemed to have been ticked.

(b) Part 2 to the UK Transfer Addendum. The Parties agree to be bound by the Mandatory Clauses of the UK Transfer Addendum.‍

1.2. In relation to any UK Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs shall be read as a reference to those SCCs as varied in the manner set out in Paragraph 1.1 of this Part 2.

PART 3: SWISS RESTRICTED TRANSFERS

  1. VARIATIONS FOR SWISS RESTRICTED TRANSFERS

1.1 Where applicable in accordance with Paragraph 3.3 of Annex 2 (European Annex) to the DPA, the SCCs also apply in the context of Swiss Restricted Transfers with the following terms deemed to have the following substituted meanings:

(a) "GDPR" means the FADP (as defined in the DPA);

(b) "European Union", "Union" and "Member State(s)" each mean Switzerland; and

(c) "supervisory authority" means the FDPIC.

1.2 In relation to any Swiss Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs shall be read as a reference to those SCCs as varied in the manner set out in Section 1.1 of this Part 3.

Annex 3

State Privacy Laws Annex

For purposes of this Annex 3, the terms "business," "controller," "processor," "commercial purpose," "sell," "share," "service provider" and "contractor" shall have the respective meanings given thereto in the applicable State Privacy Laws, and "personal information" shall mean Personal Data to the extent it constitutes "personal information" or "personal data" (or a similar term) governed by the State Privacy Laws.

It is the Parties' intent that with respect to any personal information, Provider is a service provider, contractor and/or processor, as applicable under the State Privacy Laws. Provider (a) acknowledges that personal information is disclosed by Customer only for limited and specified purposes described in the Agreement; (b) will comply with applicable obligations under the State Privacy Laws and shall provide the same level of privacy protection to personal information as is required by the State Privacy Laws; (c) agrees that Customer has the right to take reasonable and appropriate steps to help to ensure that Provider's Processing of personal information is consistent with Customer's obligations under the State Privacy Laws; (d) will notify Customer in writing of any determination made by Provider that it can no longer meet its obligations under the State Privacy Laws; and (e) agrees that Customer has the right, upon reasonable notice, including under the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.

Provider will not (a) sell or share any personal information; (b) retain, use or disclose any personal information for any purpose other than for the specific purpose of providing the Services, including retaining, using, or disclosing the personal information for a commercial purpose other than the provision of the Services, or as otherwise permitted by the State Privacy Laws; (c) retain, use or disclose the personal information outside of the direct business relationship between Provider and Customer; or (d) combine personal information received under the Agreement with personal information (i) received from or on behalf of another person, or (ii) collected from Provider's own interaction with any Data Subject to whom such personal information pertains, except as and to the extent permitted by the State Privacy Laws and necessary as part of Provider's provision of the Services. Provider hereby certifies that it understands its obligations under this Section 3 and will comply with them.

Giving Customer notice of Subprocessor engagements in accordance with Section 7 of the DPA will satisfy Provider's obligation under the State Privacy Laws to give notice of and an opportunity to object to such engagements.

Customer may conduct audits, in accordance with Section 8 of the DPA, to help ensure that Provider's use of personal information is consistent with Provider's obligations under the State Privacy Laws.

The Parties acknowledge that Provider's retention, use and disclosure of personal information authorized by Customer's instructions documented in the Agreement and this DPA are integral to Provider's provision of the Services and the business relationship between the Parties. Annex 4 Security Measures

Organizational management and personnel with assigned responsibility for the development, implementation and maintenance of the Provider's information security program.

Audit and risk assessment procedures for the purposes of periodic review and assessment of risks to Provider's organization, monitoring and maintaining compliance with the Provider's policies and procedures, and reporting the condition of its information security and compliance to internal senior management.

Data security controls which include, at a minimum, logical segregation of data, restricted (e.g., role-based) access and monitoring, and utilization of commercially available industry-standard encryption technologies (or materially equivalent safeguards) for Personal Data when transmitted over public networks (i.e., the Internet) or when transmitted wirelessly or at rest or stored on portable or removable media (i.e., laptop computers, CD/DVD, USB drives, back-up tapes).

Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions (e.g., granting access on a need-to-know and least-privilege basis, use of unique user IDs and appropriate authentication credentials for all users, and periodic review and revoking/changing access promptly when employment terminates or changes in job functions occur).

Password controls designed to manage and control password strength, expiration and usage including prohibiting users from sharing passwords and requiring that the Provider maintain password controls for its employees that are consistent with generally accepted industry standards and appropriate to the risk, including: (i) minimum password length and/or use of multi-factor authentication as appropriate; (ii) not being stored in readable format on the Provider's computer systems (e.g., stored using industry-standard hashing and salting); (iii) appropriate complexity or other compensating controls; (iv) having a history threshold to prevent reuse of recent passwords; and (v) newly issued or reset passwords being changed after first use.

System audit or event logging and related monitoring procedures to proactively record user access and system activity.

Physical and environmental security of data centers, server room facilities and other areas containing Personal Data designed to: (i) protect information assets from unauthorized physical access, (ii) as appropriate, manage, monitor and log movement of persons into and out of the Provider's facilities, and (iii) guard against environmental hazards such as heat, fire and water damage.

Operational procedures and controls to provide for the secure configuration, monitoring and maintenance of technology and information systems, including secure disposal of systems and media in accordance with commercially reasonable industry standards to render all information or data contained therein unreadable and, to the extent technically feasible, unrecoverable prior to final disposal or release from the Provider's possession.

Change management procedures and tracking mechanisms designed to test, approve and monitor all material changes to Provider's technology and information assets that may affect the security of Personal Data.

Incident management procedures designed to allow Provider to investigate, respond to, mitigate, and provide notifications in accordance with this DPA regarding events related to Provider's technology and information assets.

Network security controls designed to protect systems from intrusion and limit the scope of any successful attack, including the use of firewalls and network segmentation, and intrusion detection and/or prevention, monitoring, and traffic and event correlation procedures.

Vulnerability assessment, patch management and threat protection technologies, and scheduled monitoring procedures designed to identify, assess, mitigate and protect against identified security threats, viruses and other malicious code.

Business resiliency/continuity and disaster recovery procedures designed to maintain service and/or recovery from foreseeable emergencies or disasters. Annex 5
Subprocessor List

Customer approves Provider's engagement of the Subprocessors identified on the current Subprocessor List, which states each Subprocessor's location and processing function. The Subprocessor List is incorporated into this DPA by reference.