Grand Avenue Software, Inc.
Data Processing Addendum
This Data Processing Addendum (“DPA”) sets forth terms and conditions applicable to the Processing of Personal Data by Grand Avenue Software for Customer in the performance of the Services. This DPA is incorporated into and made part of the Grand Avenue Software Terms of Service (“Terms of Service”). Any capitalized term used but not defined in this DPA will have the defined meaning given to such term in the Terms of Service.
- DEFINITIONS
a. Adequate Country: A country or territory recognized as providing an adequate level of protection for Personal Data under an adequacy decision made, from time to time, by (as applicable) (i) the Information Commissioner’s Office and/or under applicable UK law (including the UK GDPR), (ii) the European Commission under the GDPR, or (iii) the Swiss Federal Data Protection Authority under Swiss Data Protection Law.
b. CCPA: The California Consumer Privacy Act, Cal. Civ. Code §§ 1798.100 et seq., as amended.
c. Cessation Date: The date of cessation of Services involving the Processing of Personal Data as part of the expiration or termination of the Agreement.
d. Components: As defined in Section 12(a).
e. Data Protection Laws: Any applicable security and privacy laws and regulations, including, without limitation, the CCPA and the EU General Data Protection Regulation 2016/679 (“GDPR”).
f. Data Subject Rights: Any request by an individual concerning their Personal Data pursuant to the Data Protection Laws.
g. DPF: As defined in Section 8(f).
h. EEA: The European Economic Area.
i. EU Clauses: The standard contractual clauses for international transfers of personal data to third countries set out in the European Commission’s Decision 2021/914 of 4 June 2021 (at http://data.europa.eu/eli/dec_impl/2021/914/oj) incorporating Module Two for Controller to Processor transfers and Module Three for Processor to Processor transfers (as applicable), or its valid successor, and which form part of this DPA in accordance with Schedule 4.
j. Personal Data: Any information relating to an identified or identifiable natural person (“Data Subject”), or the meaning assigned to the terms “personal data”, “personal information” and/or similar applicable terms under Data Protection Laws, and in each case Processed by Grand Avenue or a sub-processor in connection with the Services.
k. Personal Data Breach: A breach of security by or on behalf of Grand Avenue Software leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed.
l. Personnel: Grand Avenue Software employees and other Grand Avenue Software personnel.
m. Processing (including “Process” or “Processed”): Any operation or set of operations in connection with the Services which is performed on data or sets of data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
n. Services: Any and all services provided by Grand Avenue Software under the Agreement. For the purposes of this DPA, Services shall exclude software on Customer systems or premises which is sold or licensed by Grand Avenue Software, provided that Services shall include any Processing of Grand Avenue as part of related services such as maintenance or support.
o. Standard Contractual Clauses: The EU Clauses, the Swiss Addendum and/or the UK Approved Addendum.
p. Supervisory Authority: In the UK, the Information Commissioner’s Office (“ICO”) (and, where applicable, the Secretary of State or the government), and in the EEA, an independent public authority established pursuant to the GDPR.
q. Swiss Addendum: The addendum set out in Schedule 3.
r. Swiss Data Protection Law: The Swiss Federal Data Protection Act of 19 June 1992 and, when in force, the Swiss Federal Data Protection Act of 25 September 2020 and its corresponding ordinances as amended, superseded or replaced from time to time.
s. UK Approved Addendum: The template Addendum B.1.0 issued by the UK’s Information Commissioner’s Office and laid before Parliament in accordance with s119A of the Data Protection Act 2018 of the UK on 2 February 2022, and in force on 21 March 2022, or its valid successor.
t. UK Mandatory Clauses: The Mandatory Clauses of the UK Approved Addendum, as updated from time to time and/or replaced by any final version published by the Information Commissioner’s Office. - INSTRUCTIONS. Grand Avenue Software shall Process Personal Data only in accordance with this DPA, the Agreement, as necessary or reasonable to provide the Services, and other documented written instructions provided by Customer to Grand Avenue Software consistent with this DPA after the entry into force of this DPA. Grand Avenue Software shall notify Customer promptly if, in Grand Avenue Software’s opinion, an instruction for Processing of Personal Data may violate Data Protection Laws, and shall thereafter not carry out such instruction for Processing of Personal Data if it may reasonably be construed as violating Data Protection Laws after consultation with Customer.
- DATA SUBJECT ACCESS RIGHTS. Grand Avenue shall assist Customer through technical and organizational measures for the fulfillment of requests to exercise Data Subject Rights under the Data Protection Laws. Grand Avenue Software shall without undue delay notify Customer if it receives a request concerning Data Subject Rights. Grand Avenue Software shall not respond to the request unless (a) instructed by Customer or (b) required by Data Protection Laws, in which case Grand Avenue Software shall notify Customer in advance of any response. Upon request by Customer, Grand Avenue Software will provide access to or delete Personal Data in accordance with Data Protection Laws. Except where prohibited by applicable law, Grand Avenue Software shall without undue delay notify Customer if it receives any complaint from an individual or inquiry from a government body or investigation concerning the Processing of Personal Data under the Agreement.
- CCPA. Where Customer is a “business” as defined and covered by the CCPA, or a service provider to such a business, the following section applies: Grand Avenue Software shall be a service provider to Customer under the CCPA. Grand Avenue will not: (i) sell or share Personal Data (as “sell” and “share” are defined in the CCPA); (ii) retain, use, or disclose Personal Data for any purpose other than for the specific purpose of performing the services specified in the Agreement, including retaining, using, or disclosing the personal information for a commercial purpose other than providing the services specified in the Agreement, or as permitted by the CCPA; (iii) retain, use, or disclose the Personal Data outside of the direct business relationship between Grand Avenue Software and Customer or (iv) combine Personal Data with personal information which it receives from or on behalf of another person or persons, or collects from its own interaction with a consumer. Grand Avenue Software acknowledges and agrees that it understands the requirements of the CCPA for a service provider and will comply with them as applicable. Grand Avenue Software shall notify Customer if it determines it can no longer comply with its obligations under the CCPA. Customer may no more than once annually request Grand Avenue Software to certify compliance with its data protection obligations under this section, and if Grand Avenue Software will not certify compliance, Customer may take reasonable and appropriate steps to remediate any unauthorized use of Personal Data and suspend Grand Avenue Software’s access to Personal Data.
- SECURITY.
a. Security. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Grand Avenue Software shall maintain a written information security program and implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: the pseudonymization and encryption of Personal Data; the ability to ensure the ongoing confidentiality, integrity, availability and resilience of Processing systems and the Services; the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the Processing.
b. Encryption. To the extent practicable, Grand Avenue Software shall design its processing to use industry standard secure encryption at rest and in transit in connection with Personal Data.
c. Physical Security. Grand Avenue Software shall maintain hosting at a secure data center facility with access restrictions, monitoring, security staff, and other physical security measures.
d. Grand Avenue Software Access. Personal Data is subject to physical or logical segregation from the Personal Data of other customers. Grand Avenue Software maintains user management and authentication practices, including access grants on the principle of least privilege, periodic reviews of its personnel access, and prompt removal of the access of departing personnel.
e. Disaster Recovery. Grand Avenue Software data centers shall have redundant power, provisions against fire and natural disasters, and other reasonable measures designed for the reliability of the data center.
f. Changes. Grand Avenue Software and its sub-processors may change the technical and organizational measures in effect from time to time so long as it does not materially reduce the overall level of privacy and security protection offered by the technical and organizational measures. - PERSONNEL. Grand Avenue Software shall obtain reasonable assurances from Personnel to maintain the confidentiality of the Personal Data, such as a confidentiality or non-disclosure agreement.
- PERSONAL DATA BREACH. Grand Avenue Software shall promptly investigate and respond to any Personal Data Breach. Grand Avenue Software shall notify Customer within 48 hours in the event it is aware of a Personal Data Breach. Grand Avenue Software shall provide to Customer any information necessary for Customer to comply with Data Protection Laws as well as reasonable information requested by Customer concerning the Personal Data Breach. Grand Avenue Software shall mitigate, to the extent practicable and resulting from Grand Avenue Software’s breach of this DPA, the harmful effects of the Personal Data Breach on a Data Subject of which Grand Avenue Software is aware.
- INTERNATIONAL TRANSFERS
a. Customer agrees that its use of the Services will involve the transfer of Personal Data to, and processing of Personal Data in, locations outside of the UK, Switzerland and/or EEA from time to time, such as for purposes of hosting and providing support to Customer, including but not limited to processing in the United States.
b. UK transfers:
i. To the extent Personal Data is transferred to Grand Avenue and processed by or on behalf of Grand Avenue Software outside the UK (except if in an Adequate Country) in circumstances where such transfer would be prohibited by UK GDPR in the absence of a transfer mechanism, the parties agree that the EU Clauses subject to the UK Approved Addendum will apply. The UK Approved Addendum is incorporated into this DPA.
ii. Schedule 2 references the information required by Tables 1 to 4 inclusive of the UK Approved Addendum.
c. EU transfers:
i. To the extent Personal Data is transferred to Grand Avenue and processed by or on behalf of Grand Avenue Software outside the EEA (except if in an Adequate Country) in circumstances where such transfer would be prohibited by EU GDPR in the absence of a transfer mechanism, the parties agree that the EU Clauses will apply in respect of that processing and are incorporated into this DPA in accordance with Schedule 4.
ii. Schedule 4 contains the information required by the EU Clauses.
d. Swiss transfers:
i. To the extent Personal Data is transferred to Grand Avenue Software and processed by or on behalf of Grand Avenue Software outside Switzerland (except if in an Adequate Country) in circumstances where such transfer would be prohibited by Swiss Data Protection Laws in the absence of a transfer mechanism, the parties agree that the EU Clauses subject to the Swiss Addendum will apply in respect of that processing. The Swiss Addendum is incorporated into this DPA.
ii. Schedule 3 and Schedule 4 contains the information required for the Swiss Addendum, including for the purposes of transfers to which this Section 8(d) applies.
e. Grand Avenue may (i) replace the EU Clauses, the Swiss Addendum and/or the UK Approved Addendum generally or in respect of the EEA, Switzerland and/or the UK (as appropriate) with any alternative or replacement transfer mechanism in compliance with GDPR or applicable Swiss Data Protection Law, including any further or alternative standard contractual clauses approved from time to time and (ii) make reasonably necessary changes to this DPA by notifying Customer of the new transfer mechanism or content
f. In the event that after the CJEU Schrems II decision, the EU-US Data Privacy Framework (including but not limited to its successor and any similar programs for other countries) (collectively, “DPF”) constitutes a valid transfer mechanism under GDPR, and Grand Avenue Software self-certifies to, or otherwise participates in, the DPF, to the extent permitted by GDPR, Grand Avenue Software shall transfer Personal Data in accordance with the DPF in lieu of the applicable EU Clauses, UK Approved Addendum, and Swiss Addendum.
g. In connection with a restricted transfer in relation to a Data Protection Law of another jurisdiction (other than the EU, UK and Switzerland) that requires similar safeguards as the EU Clauses for international transfers of Personal Data, the parties agree that the EU Clauses as detailed in Schedule 4 shall apply to such transfers, mutatis mutandis. - RETURN OR DESTRUCTION. Customer shall download any Personal Data in the Services prior to the Cessation Date. Following the Cessation Date, Grand Avenue Software shall, except insofar as applicable laws require Grand Avenue Software to retain Personal Data, delete (in accordance with industry standards) the Personal Data. Upon request, Grand Avenue will provide a certification that Grand Avenue Software has deleted Personal Data in accordance with this DPA.
- SUB-PROCESSORS. Grand Avenue may engage sub-processors as necessary to perform the Services, and Grand Avenue Software’s sub-processors may engage sub-processors. Customer authorizes Grand Avenue Software and Grand Avenue Software’s sub-processors to use their current sub-processors for the Services. Grand Avenue shall inform Customer at least thirty (30) days in advance of any changes to the sub-processors and provide an opportunity to object to such changes. With respect to each sub-processor, Grand Avenue Software shall (a) take steps to ensure the sub-processor is capable of providing the level of protection required by this DPA and Data Protection Laws; and (b) have a written contract with substantially the same terms as this DPA. Upon request, Grand Avenue shall provide a current list of sub-processors to Customer. Grand Avenue Software shall be liable to Customer for the acts and omissions of its sub-processors as if those acts were its own.
- AUDITS. Grand Avenue Software shall make available to Customer reasonable information concerning its compliance with this DPA and Data Protection Laws, or concerning the Services which are necessary for Customer to comply with Data Protection Laws, in response to reasonable written requests by Customer. To the extent that Grand Avenue Software maintains a current, third-party audit report or certification (e.g., SOC 2 Type II, ISO 27001), Customer agrees that the review of such report or certification shall satisfy Customer’s audit rights, unless a regulatory authority requires a more extensive audit. Where required by Data Protection Laws, and where the foregoing is insufficient for such purpose, Grand Avenue Software shall permit upon reasonable advance written notice, Customer, or its authorized third-party representative subject to an appropriate confidentiality agreement, to conduct an audit or inspection at Customer’s cost during regular business hours no more than once per calendar year to ensure compliance with this DPA and such Data Protection Laws. Customer shall conduct such audit on an agreed date with a reasonable agreed scope, and in a manner that is not detrimental to or unreasonably interfere with the business of Grand Avenue Software. To the extent that such audit identifies a material security vulnerability or noncompliance with the DPA and/or Data Protection Laws, Grand Avenue Software shall cooperate with Customer to make necessary changes without undue delay.
- MISCELLANEOUS
a. Customer Obligations. Customer has full control over the Personal Data processed and is responsible for complying with its Data Protection Laws, for assessing whether the use of the Services meets its compliance and contractual obligations, and for obtaining all rights, authorizations, and consents for the processing of Personal Data. Customer is solely responsible for the security of Personal Data on Customer systems. Customer is responsible for the security of its passwords and the actions of its user accounts. If the Services involve third-party components that are not purchased by Grand Avenue Software (“Components”), Customer is solely responsible for such Components.
b. Interpretation. The terms and conditions of this DPA shall be subject to the terms and conditions of the Agreement, provided that, in the event of a direct conflict concerning data protection between the terms and conditions of this DPA and the Agreement, this DPA shall control. Notwithstanding any language to the contrary herein or elsewhere, except to the extent otherwise required by applicable law, the limitations of liability, exclusions of damages, and specifically the aggregate liability cap, in the Agreement shall apply to this DPA.
c. Modifications. Except amendments pursuant to Section 12(d) (Required Updates), no alteration, amendment, or modification of this DPA will be valid unless in writing and signed by an authorized representative of both parties.
d. Required Updates. Grand Avenue may update this DPA as required to comply with a change in Data Protection Law by providing written notice to Customer of the amendment to the DPA. if Customer does not agree to such amendment, Customer must provide written notice of its objection to the amendment within thirty (30) days following the date of the amendment. In the event that such notice of objection is provided, the parties shall thereafter negotiate in good faith an amendment to be signed by both parties pursuant to Section 12(c) (Modifications) to address the change in Data Protection Law.
e. Invalidity. Should any provision of this DPA be found invalid or unenforceable pursuant to any applicable law, then the invalid or unenforceable provision will be deemed superseded by a valid, enforceable provision that most closely matches the intent of the original provision and the remainder of the DPA will continue in effect.
f. Duration. This DPA will become legally binding upon the effective date of the Agreement or upon the date that the last party signs this DPA if it is completed after the effective date of the Agreement. The DPA shall remain in effect until the termination of the Agreement.
g. No Third Party Beneficiaries. Except as expressly required by Data Protection Laws for a data subject in the Standard Contractual Clauses, no provision of this DPA is intended to benefit any person or party not a party to this DPA, nor shall any person or entity not a party to this DPA have any right to seek to enforce or recover any right or remedy with respect hereto.
h. Survival. The respective rights and obligations of the parties under this DPA shall survive termination of the DPA to the extent necessary to fulfill their purposes.
Last Updated: March 1, 2026
SCHEDULE 1
Data Processing Details
For the purposes of the DPA and Schedules 2, 3 and 4, the parties set out below a description of the Personal Data being processed under the Agreement and further details required pursuant to the GDPR.
| Subject Matter of the Processing | Grand Avenue’s provision of the Services to Customer. |
| Nature and purpose of Processing | The collection and storage of Personal Data pursuant to providing the Services to Customer. |
| Types of Personal Data | Personal Data that Customer in its discretion provides for the Services or Grand Avenue is directed to collect. |
| Sensitive Personal Data and applied restrictions | None |
| Categories of Data Subject | Data Subjects may include any persons (including without limitation employees, customers, or suppliers) about whom Personal Data is provided to Grand Avenue for the Services by, or at the direction of, Customer. |
| Duration of Processing | For the duration of the Agreement, or until the processing is no longer necessary for the purposes. |
SCHEDULE 2
UK Transfers
For the purposes of the UK Approved Addendum,
1. the information required for Table 1 is contained in Schedule 1 of this DPA and the start date shall be deemed dated the same date as the EU Clauses;
2. in relation to Table 2, the version of the EU Clauses to which the UK Approved Addendum applies is Module Two for Controller to Processor and Module Three for Processor to Processor transfers (as applicable);
3. in relation to Table 3, the list of parties and description of the transfer are as set out in Annex I of Schedule 4 of this DPA, Grand Avenue’s technical and organizational measures are set in section 5 of the DPA and Schedule 5 (Security Measures), and the list of Grand Avenue’s sub-processors shall be provided pursuant to section 10 of the DPA; and
4. in relation to Table 4, neither party will be entitled to terminate the UK Approved Addendum in accordance with clause 19 of the UK Mandatory Clauses.
SCHEDULE 3
Swiss Addendum
In respect of transfers otherwise prohibited by Swiss Personal Data:
5. The FDPIC will be the competent supervisory authority;
6. Data subjects in Switzerland may enforce their rights in Switzerland under Clause 18c of the EU Clauses, and
7. References in the EU Clauses to the GDPR should be understood as references to Swiss Data Protection Law insofar as the data transfers are subject to Swiss Data Protection Law.
SCHEDULE 4
EU Clauses
1. For the purposes of this Schedule 4, the EU Clauses (Module II and Module III as applicable), available at https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32021D0914&from=EN shall be incorporated by reference to this Schedule and this DPA and shall be considered an integral part thereof, and the Parties’ signatures in the DPA, shall be construed as the Parties’ signature to the EU Clauses. In the event of an inconsistency between the DPA and the EU Clauses, the latter will prevail.
2. For the purposes of the EU Clauses, the following shall apply:
- Customer shall be the data exporter and Grand Avenue shall be the data importer. Each Party agrees to be bound by and comply with its obligations in its role as exporter and importer respectively as set out in the EU Clauses.
- Clause 7 (Docking clause) shall be deemed as included.
- Clause 9 (Use of sub-processors): OPTION 2 – GENERAL WRITTEN AUTHORISATION shall apply. The data importer shall specifically inform the data exporter in writing of any intended changes to that list through the addition or replacement of sub-processors as set out in clause 10 of the DPA.
- Clause 11 (Redress): optional clause (optional redress mechanism before an independent dispute resolution body) shall be deemed as not included.
- Clause 13 (a) (Supervision):
- [Where Customer is established in an EU Member State:] The supervisory authority with responsibility for ensuring compliance by the data exporter with Regulation (EU) 2016/679 as regards the data transfer, as indicated in Annex I.C, shall act as competent supervisory authority.
- [Where Customer is not established in an EU Member State but falls within the territorial scope of application of Regulation (EU) 2016/679 in accordance with its Article 3(2) and has appointed a representative pursuant to Article 27(1) of Regulation (EU) 2016/679:] The supervisory authority of the Member State in which the representative within the meaning of Article 27(1) of Regulation (EU) 2016/679 is established, as indicated in Annex I.C, shall act as competent supervisory authority. [OR]
- [Where Customer is not established in an EU Member State, but falls within the territorial scope of application of Regulation (EU) 2016/679 in accordance with its Article 3(2) without however having to appoint a representative pursuant to Article 27(2) of Regulation (EU) 2016/679:] The supervisory authority of one of the Member States in which the data subjects whose personal data is transferred under these Clauses in relation to the offering of goods or services to them, or whose behavior is monitored, are located, as indicated in Annex I.C, shall act as competent supervisory authority.
- [Where Customer is established in an EU Member State:] The supervisory authority with responsibility for ensuring compliance by the data exporter with Regulation (EU) 2016/679 as regards the data transfer, as indicated in Annex I.C, shall act as competent supervisory authority.
- Clause 17 (Governing law):
These Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third-party beneficiary rights. The Parties agree that this shall be the law of Ireland. - Clause 18 (b) (Choice of forum and jurisdiction): The Parties agree that any dispute between them arising from the EU Clauses shall be resolved by the courts of Ireland.
3. To the extent not prohibited by applicable law, any provision in the EU Clauses relating to liability of the parties with respect to each other shall be subject to the limitations and exclusions of the Agreement.
4. Any provision in the EU Clauses relating to the right to audit shall be interpreted in accordance with Clause 11 of the DPA and the Agreement.
ANNEX I
A. LIST OF PARTIES
Data exporter(s):
Name: Customer as specified on the DPA
Address: As specified on the Agreement
Contact person’s name, position and contact details: As specified on the Agreement or available on Customer’s Privacy Policy
Activities relevant to the data transferred under these Clauses: data exporter will transfer Personal Data to the
data importer as required for the provision of Services by the data importer under the Agreement and as set out in the DPA.
Signature and date: please refer to signature and date in the DPA.
Role (controller/processor): Controller or Processor, as appropriate
Data importer(s):
Name: Grand Avenue as specified on the DPA
Address: As specified on the Agreement
Contact person’s name, position and contact details: Available on Privacy Policy.
Activities relevant to the data transferred under these Clauses: data importer will process personal data as required for the provision of Services under the Master Agreement and as set out in the Agreement.
Signature and date: please refer to signature and date in the DPA.
Role (controller/processor): Processor
B. DESCRIPTION OF TRANSFER
Categories of data subjects whose personal data is transferred
See Schedule 1 to the DPA
Categories of personal data transferred
See Schedule 1 to the DPA
Sensitive data transferred (if applicable) and applied restrictions or safeguards
See Schedule 1 to the DPA
Frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
Transfers will occur from time to time as required during the course of the performance of the Services under the Agreement.
Nature of the processing
See Schedule 1 to the DPA
Purpose(s) of the data transfer and further processing
See Schedule 1 to the DPA
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
See Schedule 1 to the DPA
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
Available on request in accordance with section 10 of the DPA
C. COMPETENT SUPERVISORY AUTHORITY
Identify the competent supervisory authority/ies in accordance with Clause 13
ANNEX II – TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL
See section 5 of the DPA and Schedule 5 (Security Measures)
ANNEX III – LIST OF SUB-PROCESSORS
Available on request in accordance with section 10 of the DPA.
As of last notice:
1. US Signal, Processing Activity: Data Center, Location: USA;
2. DataDog, Processing Activity: Application performance monitoring and logging, Location: USA
3. Amazon Web Services, Inc., Processing Activity: Data Center, Location: United States and such other regions as necessary to provide the Services, a current list of which is available on request
4. Avahi, Inc., Processing Activity: Professional services, involving access to Personal Data as necessary to perform the Services, Location: United States and other countries where Avahi’s personnel or authorized contractors are located; a current list of processing locations is available on request.
SCHEDULE 5
Security Measures
Data Importer will implement technical and organizational measures for the protection of the security, confidentiality and integrity of Personal Data with respect to the services or other obligations with the contracting party (“Customer”) and/or the Data Exporter (as applicable, where Data Exporter is not the Customer), including the following measures:
1. Physical Security – If hosting by Data Importer is agreed as part of the Services, maintain hosting at a secure facility with data center access restrictions, monitoring, security staff, and other physical security measures.
2. System and Network Security – Maintain network access restrictions, firewalls, server hardening measures, and user authentication protocols designed to protect the security of Personal Data on Data Importer systems.
3. Information Security Policy – Data Importer shall maintain a written information security program and implement technical and organizational security measures in Data Importer systems designed to ensure a level of security for Personal Data appropriate to the risk.
4. Security Incident Management – Maintain information security incident management procedures regarding the internal reporting, investigation, and mitigation of security incidents. Report a Personal Data Breach to Customer in accordance with applicable laws.
5. Encryption – In connection with Personal Data accessed or stored by Data Importer, encrypt Personal Data where feasible and commercially reasonable in accordance with industry standards for encryption at rest and in transit.
6. Business Continuity; Backups – Establish and maintain standards, processes and controls for the timely recoverability of business critical data and information processing systems. Maintain periodic backups and archive methodologies in accordance with the practices of Data Importer and the agreement with Customer. Ensure data centers engaged by Data Importer have redundant power, provisions against fire and natural disasters, and other measures to ensure the reliability of services.
7. Staff Management – Ensure the workforce has agreed in writing to maintain the confidentiality of Personal Data.
8. Account Identification, Authorization and Access – Use and access to Personal Data is limited to the purposes of the services or otherwise as agreed with the Customer. Access of team members is granted on the principle of least privilege on a role basis and subject to authorization and deactivation practices of Data Importer. Access is subject to password restrictions and other user management and authentication practices designed to ensure the security of accounts. Personal Data is subject to physical or logical segregation from the Personal Data of other customers.
9. Event Logging – Maintain event logging in accordance with the agreement with Customer and the practices of Data Importer.
10. Data Minimization – Create and/or collect Personal Data as necessary for the services and as agreed with, or to the extent processing on behalf of Customer instructed by, Customer.
11. Data Subject Access Rights (DSAR) – Maintain appropriate processes to enable and/or facilitate the fulfilment of DSAR requests.
12. Data Retention – Maintain Personal Data in accordance with the agreement with Customer and, where a processor, the instructions of Customer consistent with the DPA. Return or destroy Personal Data in accordance with applicable law, the agreement with Customer and the practices of Data Importer.
13. Subprocessors – Enter into contractual commitments with its Subprocessors as necessary and/or required by applicable law. Subprocessors may offer different, but not less protective, technical and organizational measures.
14. Changes – Data Importer may change the technical and organizational measures in effect from time to time, in its sole but reasonable discretion, so long as it does not materially reduce the overall level of privacy and security protection offered by the technical and organizational measures.
Last Updated: August 25, 2026