This Data Processing Addendum (“DPA”) supplements the End User License Agreement (the “Agreement”) entered into between Kanawai AI (“Company”) and customer signing the Agreement (“Customer”), in relation to the transfer and processing of Covered Data in connection with the performance of the Services.
1. DEFINITIONS
1.1. Capitalized terms used but not defined within this DPA will have the meaning set forth in the Agreement. The following capitalized terms used in this DPA will be defined as follows:
“Account Data” means authentication, account, billing, and administrative contact information relating to Customer’s Kanawai AI account, including names, business contact details, user IDs, and authentication tokens or credentials used to administer the Customer’s Kanawai AI account, but excluding credentials provisioned by Customer to grant Kanawai AI read-only access to Customer Systems.
“Affiliate” means any entity which, directly or indirectly, Controls, is Controlled by, or is under common Control with the Customer entity executing this Agreement.
“Applicable Data Protection Laws” means all applicable laws, rules, regulations, and governmental requirements relating to the privacy, confidentiality, or security of Personal Data, as they may be amended or otherwise updated from time to time, including (without limitation): the GDPR, Swiss Data Protection Laws and the US Data Protection Laws.
“CCPA” means the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended, including its implementing regulations and the California Privacy Rights Act of 2020.
“Controller Purposes” means: (a) monitoring the performance of the Services to identify and repair errors and ensure the security and integrity of the Services; (b) undertaking internal research for technological development, including testing, improving, developing and altering the functionality of the Services and developing new products and services; and (c) administering Company’s relationship with Customer under the Agreement, including maintaining and servicing accounts on the Services.
“Covered Data” means Personal Data that is: (a) provided by or on behalf of Customer to Company in connection with the Services; or (b) obtained, developed, produced or otherwise Processed by Company, its Affiliates, its agents or subcontractors, for the purposes of providing the Services, in each case as further described in Schedule 1.
“Data Subject” means a natural person whose Personal Data is Processed.
“Deidentified Data” means data created using Covered Data that cannot reasonably be linked to such Covered Data, directly or indirectly.
“GDPR” means Regulation (EU) 2016/679 (the “EU GDPR”) or, where applicable, the “UK GDPR”, as defined in section 3 of the Data Protection Act 2018.
“Personal Data” means any data or information that: (a) is linked or reasonably linkable to an identified or identifiable natural person; or (b) is otherwise “personal data”, “personal information”, “personally identifiable information”, or similarly defined data or information under Applicable Data Protection Laws.
“Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means. “Process”, “Processes” and “Processed” will be interpreted accordingly.
“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to (including unauthorized internal access to), Covered Data.
“Services” means the services to be provided by Company to Customer under the Agreement.
“Standard Contractual Clauses” or “SCCs” means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914.
“Sub-processor” means, with respect to any Processing performed by Company as a processor or service provider, an entity appointed by Company to Process Covered Data on its behalf.
“Swiss Data Protection Laws” means the Swiss Federal Act on Data Protection of 25 September 2020 (“FADP”) and the Swiss Data Protection Ordinance of 31 August 2022 (the “Ordinance”), and any new or revised version of these laws that may enter into force for time to time.
“US Data Protection Laws” means all applicable federal and state laws rules, regulations, and governmental requirements relating to data protection, the Processing of Personal Data, privacy and/or data protection in force from time to time in the United States, including (without limitation): the CCPA as amended, including its implementing regulations and the California Privacy Rights Act of 2020), Consumer Data Protection Act (Virginia) (Code of Virginia Title 59.1 Chapter 52 § 59.1-571 et seq.), Colorado Privacy Act (Colorado Revised Statute Title 6 Article 1 Part 13 § 6-1-1301 et seq.), Connecticut Act Concerning Personal Data Privacy and Online Monitoring 2023, Consumer Privacy Act (Utah) (Utah Code § 13-6-101 et seq.), Oregon Consumer Privacy Act (ORS 646A. 570-646A. 589), Texas Data Privacy and Security Act (88(R) HB 4).
“Usage Data” means diagnostic, usage and performance information collected by Company in relation to Customer’s and its authorized users’ use of the Services.
1.2. The terms “controller”, “processor”, “business” and “service provider” have the meanings given to them in the Applicable Data Protection Laws.
2. INTERACTION WITH THE AGREEMENT
This DPA is incorporated into and forms an integral part of the Agreement. This DPA supplements and (in case of contradictions) supersedes the Agreement with respect to any Processing of Covered Data.
3. ROLE OF THE PARTIES
The Parties acknowledge and agree that:
- save as set out in paragraph 3(b), Company acts as a processor or service provider in relation to the Processing of Covered Data under the Agreement and this DPA and Customer acts as a controller or business; and
- for the purposes of the GDPR and with respect to the Processing of Administration Data and Usage Data for the Controller Purposes, Company acts as a controller.
4. DETAILS OF DATA PROCESSING
4.1. The details of the Processing of Personal Data under the Agreement and this DPA (including subject matter, nature and purpose of the Processing, categories of Personal Data and Data Subjects) are described in the Agreement and in Schedule 1 to this DPA.
4.2. Company shall comply with its obligations under Applicable Data Protection Laws. Save with respect to any Processing of Covered Data for the Controller Purposes, Company will only Process Covered Data on behalf of and under the instructions of Customer and in accordance with Applicable Data Protection Laws.
4.3. The Agreement and this DPA shall constitute Customer’s instructions for the Processing of Covered Data. Customer may issue further written instructions in accordance with this DPA. Without limiting the foregoing, Company is prohibited from:
- selling Covered Data or otherwise making Covered Data available to any third party for monetary or other valuable consideration;
- sharing Covered Data with any third party for cross-context behavioural advertising;
- retaining, using, or disclosing Covered Data for any purpose other than for the business purposes specified in the Agreement or as otherwise permitted by Applicable Data Protection Laws;
- sharing or training or otherwise exploiting Covered Data on or with any third party artificial intelligence system (including any large language model), except as necessary for the provision of Services;
- retaining, using, or disclosing Covered Data outside of the direct business relationship between the Parties; and
- except as otherwise permitted by Applicable Data Protection Laws, combining Covered Data with Personal Data that Company receives from or on behalf of another person or persons, or collects from its own interaction with the Data Subject.
4.4. Company will:
- provide Customer with information to enable Customer to conduct and document any data protection assessments required under Applicable Data Protection Laws;
- promptly inform Customer if, in its opinion, an instruction from Customer infringes the Applicable Data Protection Laws; and
- limit access to Covered Data to personnel who have a business need to have access to such Covered Data, and will ensure that such personnel are subject to obligations at least as protective of the Covered Data as the terms of this DPA and the Agreement.
5. COMPLIANCE
5.1. Customer shall comply with its obligations as a controller, business or equivalent term under the Applicable Data Protection Laws, and shall:
- provide such information to Data Subjects regarding the Processing of their Covered Data in connection with the Customer’s use of the Services as required under Applicable Data Protection Laws;
- to the extent required for the lawful Processing of Covered Data under Applicable Data Protection Laws, obtain valid consents from Data Subjects for such Processing in the form required under Applicable Data Protection Laws; and
- at Customer’s sole discretion, implement appropriate technical and organisational measures to give effect to Data Subject rights under Applicable Data Protection Laws, and shall comply with requests from Data Subjects to exercise their rights under Applicable Data Protection Laws within the timeframe and subject to any exemptions prescribed in the Applicable Data Protection Laws.
6. SUB-PROCESSORS
6.1. Company may Process Covered Data anywhere that Company, its Affiliates or its Sub-processors maintain facilities, subject to the remainder of this clause 6.
6.2. Customer grants Company general authorisation to engage any of its Affiliates and/or Sub-processors listed in Schedule 4, as amended in accordance with clause 6.4 (the “Authorized Sub-processors”), to Process Covered Data.
6.3. Company shall:
- enter into a written agreement with each Authorized Sub-processor imposing data protection obligations that, in substance, are no less protective of Covered Data than Company’s obligations under this DPA; and
- remain liable for each Authorized Sub-processor’s compliance with the obligations under this DPA.
6.4. Company will provide Customer with at least thirty (30) days’ notice of any proposed changes to the Authorized Sub-processors. Customer shall notify Company if it objects to the proposed change to the Authorized Sub-processors (including, where applicable, when exercising its right to object under clause 9(a) of the SCCs) by providing Company with written notice of the objection within thirty (30) days after Company has provided notice to Customer of such proposed change (an “Objection”).
6.5. In the event Customer submits an Objection to Company, Company and Customer shall work together in good faith to find a mutually acceptable resolution to address such Objection. If Company and Customer are unable to reach a mutually acceptable resolution within a reasonable timeframe, which shall not exceed thirty (30) days, Customer may terminate the portion of the Agreement relating to the Services affected by such change by providing written notice to Company, and Company shall provide refund of any unused, pre-paid Fees to Customer relating to the part of the Services terminated in accordance with this clause 6.5 (in addition to any other remedies available to Customer).
7. DATA SUBJECT RIGHTS REQUESTS
7.1. Company will notify Customer without undue delay of any request received by Company from a Data Subject to assert their rights in relation to Covered Data under Applicable Data Protection Laws (a “Data Subject Request”).
7.2. Other than in respect of any Processing of Administration Data and Usage Data for the Controller Purposes, Customer will have sole discretion in responding to the Data Subject Request, and Company shall not respond to the Data Subject Request, save that Company may advise the Data Subject that their request has been forwarded to Customer.
7.3. Company will provide Customer with timely and reasonable assistance as necessary for Customer to fulfil its obligation under Applicable Data Protection Laws to respond to Data Subject Requests.
8. SECURITY
8.1. Company will implement and maintain appropriate technical and organisational data protection and security measures designed to ensure security of Covered Data, including, without limitation, protection against unauthorized or unlawful Processing and against accidental loss, destruction, or damage of or to Covered Data.
8.2. When assessing the appropriate level of security, Company shall take into account the nature, scope, context and purpose of the Processing as well as the risks that are presented by the Processing, in particular from accidental or unlawful destruction, loss, alteration, un-authorized disclosure of, or access to Covered Data.
8.3. Company will implement and maintain as a minimum standard the measures set out in Schedule 2.
8.4. Company will take appropriate measures to protect and secure Administrative Data and Usage Data to the extent such data can be linked to Customer.
9. INFORMATION AND AUDITS
9.1. Company shall notify Customer promptly if Company determines that it can no longer meet its obligations under Applicable Data Protection Laws.
9.2. Customer may take reasonable and appropriate steps to:
- ensure that Company uses Covered Data in a manner consistent with Customer’s obligations under Applicable Data Protection Laws; and
- upon reasonable notice, stop and remediate unauthorized use of Covered Data.
9.3. Customer may audit Company’s compliance with this DPA. The Parties agree that all such audits will be conducted:
- not more than once a year, unless additional audits are required:
- by a supervisory authority with jurisdiction over Customer’s processing of Covered Data; or
- to investigate the causes of and remediation following a Security Incident;
- upon reasonable written notice to Company;
- only during Company’s normal business hours; and
- in a manner that does not materially disrupt Company’s business or operations.
9.4. With respect to any audits conducted in accordance with clause 9.3 or 9.4:
- Customer may engage an independent third-party auditor to conduct the audit on its behalf; and
- Company shall not be required to facilitate any such audit unless and until the Parties have agreed, in good faith, in writing the scope and timing of such audit, unless required otherwise by applicable law;
- Customer shall pay any Customer-engaged third-party costs incurred with regards to audits specifically requested by the Customer under this Agreement, and shall procure all reasonable efforts to complete the audit in a timely manner and with minimal impact on day-to-day business of the Company.
9.5. Customer shall promptly notify Company of any non-compliance discovered during an audit.
9.6. The results of the audit shall be Company’s confidential information.
9.7. Company shall provide to Customer upon request, or may provide to Customer in response to any audit request submitted by Customer’s to Company, either of the following:
- data protection compliance certifications issued by a commonly accepted certification issuer which has been audited by a data security expert, or by a publicly certified auditing company; or
- such other documentation reasonably evidencing the implementation of the technical and organisational data security measures in accordance with industry standards.
9.8. If an audit requested by Customer is addressed in the documents or certification provided by Company in accordance with paragraph 9.7, and:
- the certification or documentation is dated within twelve (12) months of Customer’s audit request; and
- Company confirms that there are no known material changes in the controls audited,
9.9. Customer agrees to accept that certification or documentation in lieu of conducting a physical audit of the controls covered by the relevant certification or documentation, provided, however, that if Customer reasonably believes that certification or documentation is not sufficient to demonstrate Company’s compliance with this DPA, the Customer may still proceed with a physical audit.
10. SECURITY INCIDENTS
10.1. Company shall notify Customer in writing without undue delay, and in any event within seventy-two (72) hours, after becoming aware of any Security Incident.
10.2. Company shall take reasonable steps to contain, investigate, and mitigate any Security Incident, and shall send Customer timely information about the Security Incident, to the extent known to Company or as the information becomes available to Company, including, but not limited to, the nature of the Security Incident, the measures taken to mitigate or contain the Security Incident, and the status of the investigation.
10.3. Company shall provide reasonable assistance with Customer’s investigation of any Security Incidents and any of Customer’s obligations in relation to the Security Incident under Applicable Data Protection Laws, including any notification to Data Subjects or supervisory authorities.
10.4. Company’s notification of or response to a Security Incident under this paragraph 10 shall not be construed as an acknowledgement by Company of any fault or liability with respect to the Security Incident.
11. TERM, DELETION AND RETURN
11.1. This DPA shall commence on the Effective Date and, notwithstanding any termination of the Agreement, will remain in effect until, and automatically expire upon, Company’s deletion of all Covered Data as described in this DPA.
11.2. Company shall:
- within thirty (30) days of expiry of the Agreement (the “Retention Period”), provide a copy of all Covered Data in such commonly used format as requested by Customer, or provide a self-service functionality allowing Customer to download such Covered Data; and
- on expiry of the Retention Period, delete all copies of Covered Data Processed by Company or any Authorized Sub-processors, other than any Administration Data and Usage Data Processed for the Controller Purposes, and will provide confirmation in writing of such deletion to Customer.
11.3. Furthermore, at the Customer’s request, the Company shall promptly delete any relevant Covered Data specified by and/or related to the request made by the Customer, and shall provide confirmation in writing of such deletion to the Customer. For the avoidance of doubt, the Company may discharge its entire obligations under this clause 11.3 by providing a self-service functionality that enables Company to delete its own data.
12. STANDARD CONTRACTUAL CLAUSES
12.1. The Standard Contractual Clauses shall, as further set out in Schedule 3, apply to the transfer of any Covered Data from Customer to Company, and form part of this DPA, to the extent that:
- the GDPR or Swiss Data Protection Law applies to Customer when making that transfer; or
- the Applicable Data Protection Laws that apply to Customer when making that transfer (the “Exporter Data Protection Laws”) prohibit the transfer of Covered Data to Company under this DPA in the absence of a transfer mechanism implementing adequate safeguards in respect of the Processing of that Covered Data, and any one or more of the following applies:
- the relevant authority with jurisdiction over Customer’s transfer of Covered Data under this DPA has not formally adopted standard data protection clauses or another transfer mechanism under the Exporter Data Protection Laws; or
- such authority has issued guidance that entering into standard contractual clauses approved by the European Commission would satisfy any requirement under the Exporter Data Protection Laws to implement adequate safeguards in respect of that transfer; or
- entering into standard contractual clauses approved by the European Commission would reasonably satisfy any requirement under the Exporter Data Protection Laws to implement adequate safeguards in respect of that transfer; or
- the transfer is an “onward transfer” (as defined in the applicable module of the SCCs).
12.2. The Parties agree that execution of the Agreement shall have the same effect as signing the SCCs.
13. DEIDENTIFIED DATA
If Company receives Deidentified Data from or on behalf of Customer, Company shall:
- take reasonable measures to ensure the information cannot be associated with a Data Subject;
- publicly commit to Process the Deidentified Data solely in deidentified form and not to attempt to reidentify the information; and
- contractually obligate any recipients of the Deidentified Data to comply with the foregoing requirements and Applicable Data Protection Laws.
14. GENERAL
14.1. The Parties hereby certify that they understand the requirements in this DPA and will comply with them.
14.2. The following provisions shall apply with respect to liability:
Notwithstanding the Terms and Conditions, Company’s maximum liability for any breach of this Data Processing Agreement or Applicable Data Protection Laws relating to the Covered Data shall be the greater of (i) three (3) times the annual fees paid by Customer to Company for the Services under the Agreement in the 12 months prior to the act that gave rise to the liability; or (ii) USD 120,000; in each case, whether or not it has been advised of the possibility of such damages and whether or not such losses or damages were otherwise foreseeable. For the avoidance of doubt, this clause 14.2 shall take precedence over any conflicting provisions in the Terms and Conditions or elsewhere in the Agreement.
14.3. The Parties agree to negotiate in good faith any amendments to this DPA as may be required in connection with changes in Applicable Data Protection Laws.
SCHEDULE 1: Details of Processing
1. List of Parties
| Item | Customer | Company |
|---|---|---|
| Role | Data exporter | Data importer |
| Contact person | Customer Point of Contact | Kanawai AI Security Officer |
| Activities relevant to the transfer | The receipt of the Services under the Agreement. | The performance of the Services under the Agreement. |
2. Description of Processing
| Categories of Data Subjects | Kanawai AI provides an AI-enabled service that retrieves, queries, reads, and analyzes system and document metadata through Customer Systems and APIs; it does not, as a general matter, replicate, migrate, or persistently store underlying Customer content. Customer’s employees, contractors, and authorized users whose identifiers appear in Customer Systems, and individuals referenced in document or system metadata. |
| Categories of Personal Data | System and document metadata - File and folder names, document owners and authors, creation and modification timestamps, access logs, permissions, sharing metadata, and financial records metadata. User-directory information - Names, business email addresses, job titles, and group and role membership. Authentication and account data - User IDs, tokens, and OAuth or API credentials provisioned by Customer, excluding passwords in cleartext. Technical and usage data - IP addresses, device and browser identifiers, event and audit logs, and telemetry. Incidental Customer content - Personal Data incidentally contained in Customer content transiently accessed through APIs in responding to a Customer-initiated query. |
| Duration of the processing | Company will process Covered Data as long as is required to provide the Services to Customer under the Agreement, as notified by Customer to Company using the appropriate functionalities of the Services. |
| Nature of the Processing | Receiving data, including collection, accessing, retrieval, recording, and data entry. Analyzing data, including product usage assessment. Sharing data, including disclosure to Sub-processors as permitted in this DPA. |
| Purposes of the data transfer and further Processing | To facilitate the Service as requested by Customer, including retrieving, querying, and analyzing system and document metadata through Customer Systems and APIs, and to adhere to documented instructions under the Agreement. |
| Retention period | For the duration of the Agreement, unless earlier deletion is requested by the Company. |
| Sub-processors | As set out in Schedule 4. |
SCHEDULE 2: TECHNICAL AND ORGANIZATIONAL MEASURES
Introduction
Company employs a combination of policies, procedures, guidelines and technical and physical controls to protect the personal data it processes from accidental loss and un-authorized access, disclosure or destruction.
Governance and Policies
Company assigns personnel with responsibility for the determination, review and implementation of data handling polices and measures.
Company:
- has a documented data handling policy and/or other relevant guidelines and documents; and
- reviews its security measures and policies to ensure they continue to be appropriate for the data being protected.
Company establishes and follows secure configurations for systems and software, and ensures that security measures are considered during project initiation and the development of new IT systems.
Breach response
Company has an incident response plan that has been developed to address data breach events.
Intrusion, anti-virus and anti-malware defences
Company IT systems used to process personal data have appropriate data security software installed on them, including:
- firewall, anti-virus system and anti-spyware system;
- an intrusion detection or prevention system managed outside of the control of system and network administrators;
- third-party penetration testing;
- vulnerability scanning;
- collection, maintenance, review and audit of event logs; and
- monitoring of Company’s cloud service operation.
Access controls
Company limits access to personal data by implementing appropriate access controls, including:
- limiting administrative access privileges and use of administrative accounts;
- access to data received from the Customer is granted only for justifiable business cases, such as debugging failures, machine learning training problems or other operational issues;
- employee access to production is guarded by an approval process. When access is approved, access is granted on a temporary basis;
- monitoring and logging access to IT systems; and
- monitoring and logging amendments to data or files on IT systems.
Availability and Back-up personal data
Company has a documented disaster recovery plan that ensures that key systems and data can be restored in the event of a physical or technical incident.
Company regularly backs-up information on IT systems and keeps back-ups in separate locations.
Segmentation of personal data
Company logically separates Covered Data at the database/datastore level using a unique identifier for Customer. The separation is enforced at the API layer where Customer must authenticate with a chosen account and then the customer unique identifier is included in the access token and used by the API to restrict access to data to the account. All database/datastore queries then include the account identifier.
Encryption
All databases, data stores and file systems are encrypted according to Company’s Encryption Policy.
Data at rest is encrypted using industry-standard 256-bit Advanced Encryption Standard.
Company supports the latest recommended secure cipher suites to encrypt all traffic in transit, including TLS 1.2 protocols, AES256 encryption, and SHA2 signatures.
Transmission or transport of personal data
Appropriate controls are implemented by Company to secure personal data during transmission or transit, including:
- use of VPNs;
- encryption in transit; and
- logging of access when transmitted electronically.
Device hardening
Company ensures that all virtual machines are hardened in accordance with the Center for Internet Security (CIS) Benchmarks.
Asset and Software management
Company maintains an inventory of IT assets and the data stored on them, together with a list of owners of the relevant IT assets.
Company:
- documents and implements rules for acceptable use of IT assets;
- requires network-level authentication and uses client certificates to validate and authenticate systems;
- deploys automated patch management tools and software update tools for operating systems and software;
- proactively monitors software vulnerabilities and promptly implements any out of cycle patches; and
- permits the use of only the latest versions of fully supported web browsers and email clients.
Company stores all API keys securely, including as follows:
- Company stores API keys directly in its environment variables;
- Company does not store API keys on client side;
- Company does not publish API key credentials in online code repositories (whether private or not); and
- Company uses API key management tools to retrieve and manage credentials for large development projects.
Staff training and awareness
Company’s agreements with staff and contractors and employee handbooks set out its personnel’s responsibilities in relation to information security.
Company carries out:
- regular staff training on data security and privacy issues relevant to their job role and ensures that new starters receive appropriate training before they start their role (as part of the onboarding procedures);
- appropriate screening and background checks on individuals that have access to sensitive personal data.
Company ensures that information security responsibilities that are applicable immediately before termination or change of employment and those which apply after termination / change of employment are communicated and implemented.
Staff are subject to disciplinary measures for breaches of Company’s policies and procedures relating to data privacy and security.
Selection of service providers and commission of services
Company assesses service providers’ ability to meet their security requirements before engaging them.
Company has written contracts in place with service providers which require them to implement appropriate security measures to protect the personal data they have access to and limit the use of personal data in accordance with Company’s instructions.
The Data Importer conducts audits of vendors (including Authorized Sub-processors) that have access to the Company’s data by reviewing vendors’ security accreditation (such as ISO 27001 or SOC II) reports.
SCHEDULE 3: STANDARD CONTRACTUAL CLAUSES
1. EU SCCS
With respect to any transfers referred to in clause 12, the Standard Contractual Clauses shall be completed as follows:
- Module Two (controller to processor) of the SCCs will apply.
- Clause 7 of the Standard Contractual Clauses (Docking Clause) does not apply.
- Option 2 of Clause 9(a) (General written authorization) shall apply, and the time period to be specified is determined in clause 6.4 of the DPA.
- The option in Clause 11(a) of the Standard Contractual Clauses (Independent dispute resolution body) does not apply.
- With regard to Clause 17 of the Standard Contractual Clauses (Governing law), the Parties agree that option 1 will apply and the governing law will be Irish law.
- In Clause 18 of the Standard Contractual Clauses (Choice of forum and jurisdiction), the Parties submit themselves to the jurisdiction of the courts of Ireland.
- For the Purpose of Annex I of the Standard Contractual Clauses, Schedule 1 of the DPA contains the specifications regarding the parties, the description of transfer, and the competent supervisory authority.
- For the Purpose of Annex II of the Standard Contractual Clauses, Schedule 2 of the DPA contains the technical and organizational measures.
2. UK ADDENDUM
2.1. This paragraph 2 (UK Addendum) shall apply to any transfer of Covered Data from Customer (as data exporter) to Company (as data importer), to the extent that:
- the UK Data Protection Laws apply to Company when making that transfer; or
- the transfer is an “onward transfer” as defined in the Approved Addendum.
2.2. As used in this paragraph 2:
“Approved Addendum” means the template addendum, version B.1.0 issued by the UK Information Commissioner under S119A(1) Data Protection Act 2018 and laid before the UK Parliament on 2 February 2022, as it may be revised according to Section 18 of the Approved Addendum.
“UK Data Protection Laws” means all laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the UK GDPR and the Data Protection Act 2018.
2.3. The Approved Addendum will form part of this DPA with respect to any transfers referred to in paragraph 2.1, and execution of this DPA shall have the same effect as signing the Approved Addendum.
2.4. The Approved Addendum shall be deemed completed as follows:
- the “Addendum EU SCCs” shall refer to the SCCs as they are incorporated into this Agreement in accordance with clause 12 and this Schedule 3;
- Table 1 of the Approved Addendum shall be completed with the details in paragraph A of Schedule 1;
- the “Appendix Information” shall refer to the information set out in Schedule 1 and Schedule 2;
- for the purposes of Table 4 of the Approved Addendum, Company (as data importer) may end this DPA, to the extent the Approved Addendum applies, in accordance with Section 19 of the Approved Addendum; and
- Section 16 of the Approved Addendum does not apply.
3. SWISS ADDENDUM
3.1. This Swiss Addendum will apply to any Processing of Covered Data that is subject to Swiss Data Protection Laws or to both Swiss Data Protection Laws and the EU GDPR.
3.2. Interpretation of this Addendum
Where this Addendum uses terms that are defined in the Standard Contractual Clauses, those terms will have the same meaning as in the Standard Contractual Clauses. In addition, the following terms have the following meanings:
“Addendum” means this addendum to the Clauses;
“Clauses” means the Standard Contractual Clauses as incorporated into this DPA in accordance with clause 12 and as further specified in this Schedule 3; and
“FDPIC” means the Federal Data Protection and Information Commissioner.
This Addendum shall be read and interpreted in a manner that is consistent with Swiss Data Protection Laws, and so that it fulfils the Parties’ obligations under Article 16(2)(d) of the FADP.
This Addendum will not be interpreted in a way that conflicts with rights and obligations provided for in Swiss Data Protection Laws.
Any references to legislation (or specific provisions of legislation) means that legislation (or specific provision) as it may change over time. This includes where that legislation (or specific provision) has been consolidated, re-enacted and/or replaced after this Swiss Addendum has been entered into.
In relation to any Processing of Personal Data subject to Swiss Data Protection Laws or to both Swiss Data Protection Laws and the GDPR, this Addendum amends and supplements the Clauses to the extent necessary so they operate:
- for transfers made by the data exporter to the data importer, to the extent that Swiss Data Protection Laws apply to the data exporter’s Processing when making that transfer; and
- as standard data protection clauses approved, issued or recognized by the FDPIC for the purposes of Article 16(2)(d) of the FADP.
3.3. Hierarchy
In the event of a conflict or inconsistency between this Addendum and the provisions of the Clauses or other related agreements between the Parties, existing at the time this Addendum is agreed or entered into thereafter, the provisions which provide the most protection to Data Subjects will prevail.
3.4. Changes to the Clauses for transfers exclusively subject to Swiss Data Protection Laws
To the extent that the data exporter’s Processing of Personal Data is exclusively subject to Swiss Data Protection Laws, or the transfer of Personal Data from a data exporter to a data importer under the Clauses is an “onward transfer” (as defined in the Clauses, as amended by the remainder of this paragraph 3.3(a)) the following amendments are made to the Clauses:
- References to the “Clauses” or the “SCCs” mean this Swiss Addendum as it amends the SCCs.
- Clause 6 Description of the transfer(s) is replaced with: “The details of the transfer(s), and in particular the categories of Personal Data that are transferred and the purpose(s) for which they are transferred, are those specified in Schedule 1 of this DPA where Swiss Data Protection Laws apply to the data exporter’s Processing when making that transfer.”
- References to “Regulation (EU) 2016/679” or “that Regulation” or “GDPR” are replaced by “Swiss Data Protection Laws” and references to specific Article(s) of “Regulation (EU) 2016/679” or “GDPR” are replaced with the equivalent Article or Section of Swiss Data Protection Laws extent applicable.
- References to Regulation (EU) 2018/1725 are removed.
- References to the “European Union”, “Union”, “EU” and “EU Member State” are all replaced with “Switzerland”.
- Clause 13(a) and Part C of Annex I are not used; the “competent supervisory authority” is the FDPIC.
- Clause 17 is replaced to state: “These Clauses are governed by the laws of Switzerland”.
- Clause 18 is replaced to state: “Any dispute arising from these Clauses relating to Swiss Data Protection Laws will be resolved by the courts of Switzerland. A Data Subject may also bring legal proceedings against the data exporter and/or data importer before the courts of Switzerland in which he/she has his/her habitual residence. The Parties agree to submit themselves to the jurisdiction of such courts.”
3.5. Supplementary provisions for transfers of Personal data subject to both the GDPR and Swiss Data Protection Laws
To the extent that the data exporter’s Processing of Personal Data is subject to both Swiss Data Protection Laws and the GDPR, or the transfer of Personal Data from a data exporter to a data importer under the Clauses is an “onward transfer” under both the Clauses and the Clauses as amended by paragraph 3.4 of this Addendum:
- for the purposes of Clause 13(a) and Part C of Annex I:
- the FDPIC shall act as competent supervisory authority with respect to any transfers of Personal Data to the extent Swiss Data Protection Laws apply to the data exporter’s Processing when making that transfer, or such transfer is an “onward transfer” as defined in the Clauses (as amended by paragraph 3.4 of this Addendum); and
- subject to the provisions of paragraph 2 of this Schedule 3 (UK Addendum), the supervisory authority identified in Schedule 1 shall act as competent supervisory authority with respect to any transfers of Personal Data to the extent the GDPR applies to the data exporter’s processing, or such transfer is an “onward transfer” as defined in the Clauses.
- the terms “European Union”, “Union”, “EU”, and “EU Member State” shall not be interpreted in a way that excludes the ability of Data Subjects in Switzerland bringing a claim in their place of habitual residence in accordance with Clause 18(c) of the Clauses.
4. Transfers under the laws of other jurisdictions
4.1. With respect to any transfers of Personal Data referred to in clause 12.1(b) (each a “Global Transfer”), the SCCs shall not be interpreted in a way that conflicts with rights and obligations provided for in the Exporter Data Protection Laws.
4.2. For the purposes of any Global Transfers, the SCCs shall be deemed to be amended to the extent necessary so that they operate:
- for transfers made by the applicable data exporter to the data importer, to the extent the Exporter Data Protection Laws apply to that data exporter’s Processing when making that transfer; and
- to provide appropriate safeguards for the transfers in accordance with the Exporter Data Protection Laws.
4.3. The amendments referred to in clause paragraph 4.2 include (without limitation) the following:
- references to the “GDPR” and to specific Articles of the GDPR are replaced with the equivalent provisions under the Exporter Data Protection Laws;
- reference to the “Union”, “EU” and “EU Member State” are all replaced with reference to the jurisdiction in which the Exporter Data Protection Laws were issued (the “Exporter Jurisdiction”);
- the “competent supervisory authority” shall be the applicable supervisory in the Exporter Jurisdiction; and
- Clauses 17 and 18 of the SCCs shall refer to the laws and courts of the Exporter Jurisdiction respectively.
4.4. Where, at any time during Company’s Processing of Covered Data under this DPA, a transfer mechanism other than the SCCs is approved under the Exporter Data Protection Laws with respect to transfers of Covered Data by Customer to Company, the Parties shall promptly enter into a supplementary agreement that:
- incorporates any standard data protection clauses or another transfer mechanism formally adopted by the relevant authority in the Exporter Jurisdiction;
- incorporates the details of Processing set out in Schedule 1; and
- shall, with respect to the transfer of Personal Data subject to the Exporter Data Protection Laws, take precedence over this DPA in the event of any conflict.
4.5. Where required under the Exporter Data Protection Laws, the relevant data exporter shall file a copy of the agreement entered into in accordance with paragraph 4.4 with the relevant national authority.
SCHEDULE 4: AUTHORIZED SUB-PROCESSORS
| Sub-processor | Description of processing |
|---|---|
| Google Cloud Platform, Amazon Web Services, and/or Microsoft Azure | Data storage, data analytics and other data management tooling. |
| Google, Anthropic, and/or OpenAI | AI/LLM functionality, in each case under enterprise terms prohibiting training on Personal Data. |
