[Privacy Policy]

Data Processing Agreement

Effective Date: 05/16/2025

‍

This Data Processing Agreement (“DPA”) forms part of the written agreement that Customer has entered into with Contact Discovery Services, LLC, and/or its Affiliates governing Customer’s (the “Controller) use of the Service (the “Master Agreement”). Any terms used in this DPA and not defined will have the meanings given to them in the Agreement, collectively referred to as “Parties”.

This DPA and its Annexes reflect the Parties’ agreement with respect to the Processing of Personal Data as described in Annex II: Details of Processing/Transfer.

‍

Recitals

‍

WHEREAS, the Company and the Provider entered into Contract for Services (Master Agreement) that may require the Provider to process Personal Data provided by or collected for the Company.

‍

WHEREAS the Company acts as a Data Controller and Contact Discovery acts as a Processor.

‍

WHEREAS, This Data Processing Agreement (DPA) sets out the additional terms, requirements, and conditions on which Contact Discovery will obtain, handle, process, disclose, transfer, or store Personal Data when providing services under the Master Agreement.

‍

WHEREAS, The Parties seek to implement a data processing agreement that complies with the requirements of the current legal framework in relation to data processing and with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

‍

NOW, THEREFORE, in consideration of the mutual covenants and agreements hereinafter set forth and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the parties hereto agree as follows:

‍

1. Relationship of the Parties

1.1 Contact will process the Customer Data as a processor or sub-processor (as applicable) on behalf of Customer (whether the controller or itself a processor acting on behalf of a third party controller). For the purposes of the CCPA (where applicable), Contact will process Customer Data as a service provider for the Customer as a business.

‍

1.2 Customer. Customer agrees that it has entered into this DPA on its own behalf and on behalf of the Authorized Controllers, provided that such Authorized Controllers have not entered into their own separate agreement with Contact.

‍

2. Definitions

Unless otherwise defined herein, capitalized terms and expressions used in this DPA shall have the following meanings. Any capitalized terms and expressions not specifically defined in this DPA will retain the ascribed meanings set forth in the Master Agreement.

  1. “Authorized Persons” means the persons or categories of persons that the Company authorizes to given Provider written data processing instructions as identified in Annex I and from who the Provider agrees to accept such instructions.
  2. “Business Purposes” means the services to be provided by the Provider to the Company as described in the Master Agreement and any other purpose specifically identified in Annex I.
  3. “Company Personal Data” means any Personal Data Processed by a Contracted Processor on behalf of Controller pursuant to or in connection with the Master Agreement;
  4. “Confidential Information” means any and all information of any form obtained by the other Party’s employees, agents and representatives in the course of performance of the Master Agreement. Notwithstanding any other provision of this DPA or Master Agreement, Confidential Information does not include information that:
    • 4.1 is published or in the public domain through no fault of the receiving Party at the time such information as received by the receiving Party;
    • 4.2 prior to disclosure to the receiving Party, is properly within the legitimate possession of the receiving Party;
    • 4.3 subsequent to disclosure to the receiving Party, is lawfully received from a third party having rights in the information without restriction as to the third party’s right to disseminate the information and without notice of any restriction against its further disclosure;
    • 4.4 independently is developed by the receiving Party without the use of Confidential Information, by itself or through parties who have not had, either directly or indirectly, access to or knowledge of Confidential Information;
    • 4.5 is transmitted to the receiving Party after the disclosing Party has received written notice from the receiving Party that it does not desire to receive further Confidential Information; or
    • 4.6 is obligated to be produced under order of a court of competent jurisdiction or other similar requirement of a governmental or regulatory authority, provided that the receiving Party required to disclose the information provides the disclosing Party with prior written notice of such order or requirement.
  5. “Contracted Processor” means a Subprocessor;
  6. “Data Exporter” means Controller in the context of Annex 1.
  7. “Data Importer” means Processor in the context of Annex 1.
  8. “Data Privacy Framework” or “DPF” means the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and Swiss-U.S. The DPF was respectively developed by the U.S. Department of Commerce and the European Commission, UK Government, and Swiss Federal Administration to provide U.S. organizations with reliable mechanisms for personal data transfers to the United States from the European Union, United Kingdom, and Switzerland while ensuring data protection that is consistent with EU, UK, and Swiss law.
  9. “Data Protection Laws” means all applicable federal, national, state, provincial, local or foreign laws or rules, regulations, ordinances, orders, guidelines, directives, or requirements issued by any government authority or instrumentality, and self-regulatory requirements, in each case, currently in effect, as they become effective, and as amended, that relate to the privacy, confidentiality or security of Personal Information and apply with respect to the Processing of Personal Information, which may include, without limitation: the Health Insurance Portability and Accountability Act (“HIPAA”), 42 U.S.C. § 1320 et seq., the Gramm-Leach-Bliley Act (“GLBA”), 15 U.S.C. §§ 6801-6827, and all regulations implementing GLBA; the Fair Credit Reporting Act (“FCRA”), 15 U.S.C. § 1681 et seq., as amended by the Fair and Accurate Credit Transactions Act (“FACTA”), and all regulations implementing the FCRA and FACTA; any guidance from the Federal Trade Commission (“FTC”); the Controlling the Assault of Non-Solicited Pornography and Marketing Act (“CAN-SPAM”), the Telephone Consumer Protection Act, 47 U.S.C. § 227 (“TCPA”); security breach notification laws (such as Col. Rev. Stat. § 6-1-716); laws imposing minimum security requirements (such as Cal. Civ. Code § 1798.81.5, 201 Mass. Code Reg. 17.00, and Tex. TC Bus. & C. 521.052); laws requiring the secure disposal of records containing certain Personal Information (i.e., N.Y. Gen. Bus. Law § 399-H); European Union Directives governing general data protection (Directive 1995/46/EC) and the General Data Protection Regulation (EU) (Regulation 2016/679) as well as any applicable laws implementing or amending the same, electronic commerce (Directive 2002/58/EC), and data retention (Directive 2006/24/EC); UK GDPR; the Data Protection Act 2018 (and regulations made thereunder) (DPA 2018); the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) as amended; and all other legislation and regulatory requirements in force from time to time which apply to a party relating to the use of Personal Data (including, without limitation, the privacy of electronic communications); and the guidance and codes of practice issued by the Commissioner or other relevant regulatory authority and which are applicable to a party; the California Consumer Privacy Act of 2018 (Cal. Civ. Code §§ 1798.100 to 1798.199.100) and the CCPA Regulations (Cal. Code Regs. tit. 11, §§ 7000 to 7304), as amended, along with any related regulations or guidance provided by either the California Privacy Protection Agency (CCPA or Agency) or the California Attorney General (“CCPA”); and the Canadian Personal Information Protection and Electronic Documents Act (“PIPEDA”) and relevant provincial laws.
  10. “Data Transfer” means:
    • 10.1 A transfer of Company Personal Data from the Company to a Contracted Processor; or
    • 10.2 An onward transfer of Company Personal Data from a Contracted Processor to a Subcontracted Processor, or between two establishments of a Contracted Processor,
    • 10.3 In each case, where such transfer would be prohibited by Data Protection Laws (or by the terms of data transfer agreements put in place to address the data transfer restrictions of Data Protection Laws);
  11. “EEA” means the European Economic Area;
  12. “EU Data Protection Laws” means data protection laws applicable in Europe, including: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (“GDPR”); (ii) Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector; and (iii) applicable national implementations of (i) and (ii); or (iii) GDPR as it forms parts of the United Kingdom domestic law by virtue of Section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”); and (iv) Swiss Federal Data Protection Act on 19 June 1992 and its Ordinance (“Swiss DPA”); in each case, as may be amended, superseded or replaced.
  13. “GDPR” means EU General Data Protection Regulation 2016/679;
  14. “Instructions” means the written, documented instructions issued by the Company to the Provider or Contracted Processor, and directing the same to perform a specific or general action with regard to Personal Data (including, but not limited to, depersonalizing, blocking, deletion, making available).
  15. “Personal Data” means any information relating to an identified or identifiable living individual that is processed by the Provider on behalf of the Company as a result of, or in connection with, the provision of the services under the Master Agreement; an identifiable living individual is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of the individual.
  16. “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
  17. “Processing,” “processes,” “processed,” and “process” refers to any activity that involves the use of the Personal Data. It includes, but is not limited to, any operation or set of operations which is performed on the Personal Data or on sets of the Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. Processing also includes transferring the Personal Data to third parties.
  18. “Records” shall have the same meaning as Section 13, and its cognate terms should be construed accordingly.
  19. “Services” means the services referenced in the Master Agreement and applicable executed Task Orders.
  20. “Standard Contractual Clauses” means: (i) where the GDPR or Swiss Data Laws apply, the contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (“EU SCCs”); and (ii) where the UK GDPR applies, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under s.119A(1) of the DPA 2018 (“UK Addendum”).
  21. “Subprocessor” means any person appointed by or on behalf of Processor to process Personal Data on behalf of the Company in connection with the Master Agreement.
  22. “Term” refers to this Agreement’s term as defined in Section 15.
  23. “UK GDPR” has the meaning given in Section 3(10) (as supplemented by section 205(4)) of the DPA 2018.
  24. The terms, “Commissioner”, “Controller”, “Data Subject”, “Member State”, and “Supervisory Authority” shall have the same meaning as in the GDPR, and their cognate terms shall be construed accordingly.

3. Interpretations

The terms, “Commissioner”, “Controller”, “Data Subject”, “Member State”, and “Supervisory Authority” shall have the same meaning as in the GDPR, and their cognate terms shall be construed accordingly.

‍

  1. This DPA is subject to the terms of the Master Agreement and is incorporated into the Master Agreement. Interpretations and defined terms set forth in the Master Agreement apply to the interpretation of this DPA.
  2. The Annexes form part of this DPA and will have effect as if set out in full in the body of this DPA. Any reference to this DPA includes the Annexes.
  3. A reference to writing or written includes faxes and email.
  4. In the case of conflict or ambiguity between:
    • 4.1 any provision contained in the body of this DPA and any provision contained in the Annexes, the provision in the body of this DPA will prevail;
    • 4.2 the terms of any accompanying invoice or other documents annexed to this DPA and any provision contained in the Annexes, the provision contained in the Annexes will prevail;
    • 4.3 any of the provisions of this DPA and the provisions of the Master Agreement, the provisions of this DPA will prevail; and
    • 4.4 any of the provisions of this agreement and any executed Standard Contractual Clauses, the provisions of the executed Standard Contractual Clauses will prevail.

4. Personal Data Types and Processing Purposes

  1. Company and Provider acknowledge that for the purpose of any applicable Privacy and Data Protection Requirements, the Company is the data controller and the Provider is the data processor.
  2. Company retains control of the Personal Data and remains responsible for its compliance obligations under the applicable Privacy and Data Protection Requirements, including providing any required notices and obtaining any required consents, and for the processing instructions it gives to the Provider.
  3. Annex I describes the general Personal Data categories and Data Subject types the Provider may process to fulfil the Business Purposes of the Master Agreement.
  4. Provider shall comply with all applicable Data Protection Laws in the Processing of Company Personal Data and not Process Company Personal Data other than on the relevant Company’s documented Instructions.
  5. The Company will supply Provider with written Instructions to Process Company Personal Data.

5. European Data Processing

  1. Processor shall not make or permit any onward transfers of such European Personal Data received from Company to a third party unless such onward transfer is made in compliance with a transfer mechanism permitted under applicable Data Protection Laws. If there is any conflict between this DTA and the Standard Contractual Clauses applicable to Company’s transfer of Personal Data to Processor, those Standard Contractual Clauses will prevail. In the case of conflict or ambiguity between (a) any provision contained in the body of this Agreement and any provision contained in the Annexes (excluding any executed SCC), the provision in the body of this Agreement will prevail; (b) the terms of any accompanying invoice or other documents annexed to this Agreement and any provision contained in the Annexes, the provision contained in the Annexes will prevail; (c) any of the provisions of this Agreement and the provisions of the Master Agreement, the provisions of this Agreement will prevail; and (d) any of the provisions of this Agreement (or any other provision contained in the Annexes or any of the documents referred to in (b) and (c) above) and any executed SCC, the provisions of the executed SCC will prevail.
  2. The Processor may not transfer or authorize the transfer of Data to countries outside the EU and/or the European Economic Area (EEA) without the prior written consent of the Company. If personal data processed under this Agreement is transferred from a country within the European Economic Area to a country outside the European Economic Area, the Parties shall ensure that the personal data are adequately protected. To achieve this, the Parties shall, unless agreed otherwise, rely on EU approved standard contractual clauses for the transfer of personal data.
  3. In relation to data transfers protected by the GDPR, the EU SCCs will apply in relation to that transferred Personal Data and completed as follows: (a) Module One will apply; (b) in Clause 7, the optional docking Clause will not apply; (c) in Clause 11, the optional language will not apply.
  4. In relation to data transfers protected by Swiss Data Laws, the EU SCCs, as set out above, shall be amended and supplemented as specified by the relevant guidance of the Swiss Federal Data Protection and Information Commissioner, and the competent supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner.
  5. In relation to Restricted Transfers protected by the UK GDPR, the UK Addendum will apply in relation to that transferred Personal Data and completed as follows: (h) the EU SCCs, completed as set out above, shall apply and be deemed executed between the Parties, and shall be modified by the UK Addendum (completed as set out in sub-clause (i)); and (i) tables 1 to 3 of the UK Addendum shall be deemed completed with relevant information from the EU SCCs, completed as set out above, and the options “Exporter” and “Importer” shall be deemed checked in Table 4. The start date of the UK Addendum (as set out in Table 1) shall be the Effective Date of this DTA. This Agreement’s term is as defined in Section 15.

6. Provider's Obligations

  1. Provider will only process the Personal Data to the extent, and in such a manner, as is necessary for the Business Purposes in accordance with Company’s written instructions from Authorized Persons. Provider will not process the Personal Data for any other purpose or in a way that does not comply with this Agreement or the Data Protection Legislation. Provider must promptly notify the Company if, in its opinion, the Company’s instructions do not comply with the Data Protection Legislation.
  2. Provider must comply promptly with any Company written instructions from Authorized Persons requiring the Provider to amend, transfer, delete or otherwise process the Personal Data, or to stop, mitigate or remedy any unauthorized processing.
  3. Provider will maintain the confidentiality of the Personal Data and will not disclose the Personal Data to third parties unless the Company or this Agreement specifically authorizes the disclosure, or as required by domestic law, court or regulator (including the Commissioner). If a domestic law, court or regulator (including the Commissioner) requires the Provider to process or disclose the Personal Data to a third party, the Provider must first inform the Company of such legal or regulatory requirement and give the Company an opportunity to object or challenge the requirement, unless the domestic law prohibits the giving of such notice.
  4. The Provider will reasonably assist the Company with meeting the Company’s compliance obligations under the Data Protection Legislation, taking into account the nature of the Provider’s processing and the information available to the Provider, including in relation to Data Subject rights, data protection impact assessments and reporting to and consulting with the Commissioner or other relevant regulator under the Data Protection Legislation.
  5. The Provider must promptly notify the Company of any changes to the Data Protection Legislation that may reasonably be interpreted as adversely affecting the Provider’s performance of the Master Agreement or this Agreement.
  6. The Company acknowledges that the Provider is under no duty to investigate the completeness, accuracy, or sufficiency of any specific Company instructions from Authorized Persons or the Personal Data other than as required under the Privacy and Data Protection Requirements.

7. Provider Personnel

  1. Parties shall take reasonable steps to ensure the reliability of any employee, agent or representative of the respective Party who may have access to Confidential Information, ensuring in each case that access is strictly limited to those individuals who need to know or access the relevant Confidential Information, as strictly necessary for the purposes of the Master Agreement, and to comply with Applicable Laws in the context of that individual’s duties to the Party, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.

8. Subprocessing

  1. Company hereby agrees that Provider may engage its Affiliates and third parties as Subprocessor in connection with the provision of services under the Master Agreement. Provider shall carry out reasonable due diligence as appropriate to the nature of each Subprocessor’s services to ensure that the Subprocessor can provide the level of protection for Personal Data required by this DTA. Upon request, Provider shall make available a current list of any material Subprocessors that have access to Personal Data; the parties hereto agree that such list is the Confidential Information of Provider and subject to the confidentiality provisions of the Master Agreement.

9. Data Subject Rights

  1. Considering the nature of the Processing, Provider shall assist the Company by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Company obligations, as reasonably understood by Company, to respond to requests to exercise Data Subject rights under the Data Protection Laws.
  2. Provider shall:
    • 2.1 Promptly notify Company if it receives a request from a Data Subject under any Data Protection Law in respect of Company Personal Data; and
    • 2.2 Ensure that it does not respond to that request except on the documented instructions of Company or as required by Applicable Laws to which the Provider is subject, in which case Provider shall to the extent permitted by Applicable Laws inform Company of that legal requirement before the Contracted Provider responds to the request.

10. Security

  1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Provider shall in relation to the Company Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR. In assessing the appropriate level of security, Processor shall take account in particular the risks that are presented by Processing, in particular from a Personal Data Breach. Technical and Organizational Security Measures are herein further identified in Annex II.

11. Personal Data Breach and Data Loss

  1. Provider will promptly notify the Company if any Personal Data is lost or destroyed or becomes damages, corrupted, or unusable. The Provider will restore such Personal Data at its own expense.
  2. Provider shall notify Company immediately and without undue delay if Provider becomes aware of any unauthorized or unlawful processing of the Personal Data or a Personal Data Breach affecting Company Personal Data. Provider shall supply sufficient information to allow Company to meet any obligations to report or inform impacted Data Subjects and/or applicable regulatory authorities of the Personal Data Breach under applicable Data Protection Laws, including:
    • 2.1 A description of the nature of the Personal Data Breach including the categories of in-scope Personal Data and approximate number of both Data Subjects and the Personal Data records concerned;
    • 2.2 A description of the measures taken or proposed to be taken to address the Personal Data Breach including measures to mitigate its possible adverse effects;
  3. Immediately following any unauthorized or unlawful Personal Data processing, the parties will coordinate with each other to investigate the matter. Provider shall co-operate with the Company and take reasonable commercial steps as are directed by Company to assist in the investigation, mitigation, and remediation of each such Personal Data Breach.
  4. Provider will not inform any third-party of any accidental, unauthorized, or unlawful processing of all or part of the Company Personal Data or a Personal Data Breach without first obtaining Company’s written consent, except where required to do so by applicable law or if such disclosure does not include specific reference to Company.
  5. Provider agrees that the Company has the sole right to determine:
    • 5.1 whether to provide notice of the Personal Data Breach to any Data Subjects, regulators, law enforcement agencies, or others, as required by law or regulation or contractual agreement; and
    • 5.2. whether to offer any type of remedy to affected Data Subjects, including the nature and extent of such remedy, as required by applicable Data Protection Laws.
  6. The Provider will cover all reasonable expenses associated with the performance of the obligations under Section 10.2 and 10.3, unless the Personal Data Breach arose from the Company’s specific instructions, negligence, willful default, or breach of this DPA, in which case the Company will cover all reasonable expenses.
  7. The Provider will also reimburse the Company for actual reasonable expenses the Company incurs when responding to and mitigating damages, to the extent that the Provider caused a Personal Data Breach, including all costs of notice and remedy as set out in Section 10.5.

12. Data Protection Impact Assessment and Prior Consultation

  1. Provider shall supply reasonable assistance to the Company with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, which Company reasonably considers to be required by article 35 or 36 of the GDPR or equivalent provisions of any other Data Protection Law as applicable, in each case solely in relation to Processing of Company Personal Data by, and taking into account the nature of the Processing and information available to, the Contracted Providers.

13. Deletion or Return of Company Personal Data

  1. At Company’s request, the Provider will give Company a copy of, or access to, the Customer’s Personal Data in its possession or control, in the format and on the media reasonably specified, of which are not unduly burdensome, by the Company.
  2. Subject to this Section 12 and Section 15, Provider shall promptly and in any event within 10 business days of the date of cessation of any services involving the Processing of Company Personal Data (the “Cessation Date”), delete and procure the deletion of all copies of those Company Personal Data.
  3. If any law, regulation, or government, or regulatory body requires the Provider to retain any documents or materials that the Provider would otherwise be required to return or destroy, it will notify the Customer in writing of that retention requirement, giving details of the documents or materials that it must retain, the legal basis for retention, and establishing a specific timeline for destruction once the retention requirement ends.
  4. Provider shall provide written certification to Company that it has fully complied with this Section 12 within 10 business days of the Cessation Date.
  5. Notwithstanding the foregoing, Provider will not be required to destroy, delete, or modify any backup tapes or other media pursuant to automated archival processes in the ordinary course of business, provided that any such Confidential Information retained will remain subject to the terms of this DPA.

14. Records

  1. The Provider will keep detailed, accurate and up-to-date written records regarding any processing of the Personal Data, including but not limited to, the access, control and security of the Personal Data, approved subcontractors, the processing purposes, categories of processing, any transfers of personal data to a third country and related safeguards, and a general description of the technical and organizational security measures referred to in Section 9.1 and Annex II.
  2. The Provider will ensure that the Records are sufficient to enable the Company to verify the Provider’s compliance with its obligations under this Agreement and the Provider will provide the Company with copies of the Records upon request.
  3. The Company and the Provider must review the information listed in the Annexes to this Agreement at regular intervals not greater than a period of one (1) year to confirm its current accuracy and update it when required to reflect current practices.

15. Audit

  1. Provider shall make available to the Company on request information necessary to demonstrate compliance with this Agreement, and shall allow for and contribute to audits upon reasonable notice, including inspections subject to the terms of this Section, by the Company or prior agreed upon independent third-party by the Company in relation to the Processing of the Company Personal Data by the Contracted Providers. Provider shall provide to Company, its authorized representatives, and such independent inspection body: (i) reasonable access to Provider’s information processing premises, systems, practices, procedures, and records containing Company Personal Data; (ii) reasonable assistance and cooperation of Provider’s relevant staff; and (iii) reasonable facilities at Provider’s premises. Upon request by Company, Provider shall make available to Company documentation attesting to Provider’s compliance with the requisite information security practices set out in Section 5.1 and Annexes in the form of the Provider’s latest Payment Card Industry (PCI) Compliance Report, Service Organization Controls (SOC) Type 1, 2, or 3 audit reports, Statement on Standards for Attestation Engagements (SSAE) No. 18 audit reports for Reporting on Controls at a Service Organization, reports relating to its ISO/IEC 27001 certification or other substantially similar industry standard security certifications.
  2. The Provider will promptly address any exceptions noted in the audit reports conducted pursuant to Section 14.1 with the development and implementation of a corrective action plan by the Provider’s management.
  3. If Company reasonably believes that Provider has failed to abide by the security controls identified in Section 5 and Annexes following auditing processes identified in Section 14.1, Company will furnish Provider with notice within 10 business days detailing perceived deficiencies, supplemented with means to cure perceived deficiencies. Following provisioning of the aforementioned notice, Company will provide Provider with a period of no less than 30 days for Provider to either rebut the assertions identified or to cure perceived deficiencies.
  4. Information and audit rights of the Company only arise under Section 14.1 to the extent that the Master Agreement does not otherwise give them information and audit rights meeting the relevant requirements of Data Protection Law.

16. General Terms

  1. The Provider warrants and represents that:
    • 1.1. its employees, subcontractors, agents and any other person or persons accessing Company Personal Data on its behalf are reliable and trustworthy and have received the required training on the applicable Data Protection Laws relating to the Company Personal Data; and
    • 1.2. it and anyone operating on its behalf will process the Personal Data in compliance with all applicable Data Protection Laws and other laws, enactments, regulations, orders, standards, and other similar instruments; and it has no reason to believe that any applicable Data Protection Laws prevent it from providing any of the Master Agreement’s contracted services; and
    • 1.3. considering the current technology environment and implementation costs, it will take appropriate technical and organizational measures to prevent the unauthorized or unlawful processing of Personal Data and the accidental loss or destruction of, or damage to, Personal Data, and ensure a level of security appropriate to: (A) the harm that might result from such unauthorized or unlawful processing or accidental loss, destruction, or damage; (B) the nature of the Personal Data protected; and (C) comply with all applicable Data Protection Laws and its information and security policies, including the security measures required in Section 5 and Annexes.
  2. Company warrants and represents that the Provider’s expected use of the Personal Data for the Business Purpose and as specifically instructed by the Company will comply with all Applicable Data Protection Laws
  3. Confidentiality. Each Party must keep this Agreement and information it receives about the other Party and its business in connection with this Agreement (“Confidential Information”) confidential and must not use or disclose that Confidential Information without the prior written consent of the other Party except to the extent that: (a) disclosure is required by law; (b) the relevant information is already in the public domain.
  4. Indemnification and liability terms should be construed in accordance with the Master Agreement. The Provider agrees to indemnify, hold harmless, and defend at its own expense, the Company against all costs, claims, damages, or expenses incurred by the Company or for which the Company may become liable due to any failure by the Provider or its employees, subcontractors, or agents to comply with any of its obligations under this DPA or applicable Data Protection Laws. Except for Provider’s obligations enumerated in applicable Data Protection Laws or specifically agreed upon in this DPA or the Master Agreement, Company agrees Provider is not liable for Company’s compliance and adherence to applicable Data Protection Laws including, but not limited to, Company’s obligations relating to or concerning regulatory authority reporting, privacy and/or security requirements, individual, consumer, user, and/or natural persons access rights, data breach notification, notice, consent, and other individual, consumer, user, and/or natural persons requirements related to data privacy not explicitly referenced herein.
  5. Notices. All notices and communications given under this Agreement must be in writing and will be delivered personally or via certified mail, unless otherwise agreed upon in Annex I, to:
  6. Section 15.4 does not apply to the service of any proceedings or other documents in any legal action or, where applicable, any arbitration or method of dispute resolution.
  7. This Agreement will remain in full force and effect so long as:
    • 7.1 the Master Agreement remains in effect; or
    • 7.2 the Provider retains any of the Personal Data related to the Master Agreement in its possession or control (Term).
  8. Any provision of this Agreement that expressly or by implication should come into or continue in force on or after termination of the Master Agreement in order to protect the Personal Data will remain in full force and effect.
  9. The Provider’s failure to comply with the terms of this Agreement is a material breach of the Master Agreement. In such event, the termination may occur pursuant to the terms enumerated and agreed upon in the Master Agreement.
  10. If a change in any Data Protection Legislation prevents either party from fulfilling all or part of its Master Agreement obligations, the parties may agree to suspend the processing of the Personal Data until that processing complies with the new requirements. If the parties are unable to bring the Personal Data processing into compliance with the Data Protection Legislation within the statutorily allotted period, or if not defined within an appropriate and reasonable period of time, either party may terminate the Master Agreement on not less than 10 (ten) business days on written notice to the other party.

17. Governing Law and Jurisdiction

  1. This Agreement will be governed by and construed in accordance with governing law and jurisdiction provisions in the Agreement, unless otherwise required by Applicable Privacy Law or the SCCs.
  2. Any dispute arising in connection with this Agreement, which the Parties will not be able to resolve amicably, will be submitted to the exclusive jurisdiction of the courts as defined in the Master Agreement subject to possible appeal.

Effective Date: 05/16/2025

Last Modified: 05/16/2025