Your privacy is important to us. It is Caudena Corp.’s (“Caudena”) policy to respect your privacy regarding any information we may collect from you across our website, www.caudena.com, and other sites we own and operate.
When you use and interact with our websites or services, communicate with us, visit our offices, among other activities further described within the full Privacy Statement, we may collect, use, share and process information relating to you. These Privacy Statement Highlights summarize our personally identifiable information processing practices and your related rights.
This policy explains Caudena’s rules for data minimization, deletion, and letting users opt in or out.
PII and Data Minimization
Personally identifiable information (“PII”) is data that can be used to identify someone. PII includes basic details like name, location, or phone number, and can also cover browsing or buying habits. PII rules vary by country, but they usually have strict guidelines for collecting, storing, and deleting PII. There are also rules about who can access PII and how long it is kept.
A common theme is collecting the least amount of data you need to do the job. This theme is often called data minimization.
Keep reading to learn how Caudena works to follow these PII guidelines.
Data Collection
Log data
When you visit our website, our servers may automatically log the standard data provided by your web browser. It may include your computer’s Internet Protocol (IP) address, your browser type and version, the pages you visit, the time and date of your visit, the time spent on each page, and other details.
Device data
We may also collect data about the device you’re using to access our website. This data may include the device type, operating system, unique device identifiers, device settings, and geo-location data. What we collect can depend on the individual settings of your device and software. We recommend checking the policies of your device manufacturer or software provider to learn what information they make available to us.
Legal bases for processing
We will process your PII lawfully, fairly and in a transparent manner. We collect and process information about you only where we have legal bases for doing so.
These legal bases depend on the services you use and how you use them, meaning we collect and use your information only where:
•it’s necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract (for example, when we provide a service you request from us);
•it satisfies a legitimate interest (which is not overridden by your data protection interests), such as for research and development, to market and promote our services, and to protect our legal rights and interests;
•you give us consent to do so for a specific purpose (for example, you might consent to us sending you our newsletter); or
•we need to process your data to comply with a legal obligation.
Where you consent to our use of information about you for a specific purpose, you have the right to change your mind at any time (but this will not affect any processing that has already taken place).
Data Retention
Caudena applies guidelines to ensure aging analytics data is deleted on a timely basis, and the way the data is deleted keeps it from being recreated, accessed or read.
We don’t keep PII for longer than is necessary. While we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorized access, disclosure, copying, use or modification. That said, we advise that no method of electronic transmission or storage is 100% secure and cannot guarantee absolute data security. If necessary, we may retain your PII for our compliance with a legal obligation or in order to protect your vital interests or the vital interests of another natural person.
•Time-based Deletion - User analytics data is deleted six months after it is collected.
•Related Record Deletion - If a user’s customer record is deleted, that user’s analytics data is deleted six months after the record deletion.
•Deletion by Caudena User - Users can delete their user record in CaudexCatena or CaudexCatena MCP.
Customers cannot delete the End User Identifiable Information (EUII) data saved in temporary data stores. Temporary EUII data is automatically removed from CaudexCatena and CaudexCatena MCP after 30 days plus an offline index retention period.
•Deletion by Caudena - Authorized Caudena personnel can delete user data upon receiving a request from the user or customer.
Note
Users cannot delete the EUII data saved in temporary data stores. However, this data is automatically removed after 30 days.
Data Security
Only authorized Caudena staff can access user data, and safeguards limit how much and what kind of data they can see. Access to data associated with a CaudexCatena or CaudexCatena MCP account is determined by the account owner or organization administrator and by Caudena.
Data Portability
CaudexCatena and CaudexCatena MCP give users different ways to obtain structured, machine-readable data they have permitted to be uploaded and stored by Caudena.
•Analytics data is saved as Caudena records, and the platform supports several ways to export this data.
•Customers can use Caudena’s Saved Search and Workbook Analytics features to export analytics data in CSV format.
Data Availability
To ensure availability of user analytics data stored by CaudexCatena or CaudexCatena MCP, information saved to customer or contact records is stored in the Caudena database with other Caudena customer data.
Disclosure of PII to third parties
We may disclose PII to:
•third party service providers for the purpose of enabling them to provide their services, including (without limitation) IT service providers, data storage, hosting and server providers, ad networks, analytics, error loggers, debt collectors, maintenance or problem-solving providers, marketing or advertising providers, professional advisors and payment systems operators;
•courts, tribunals, regulatory authorities and law enforcement officers, as required by law, in connection with any actual or prospective legal proceedings, or in order to establish, exercise or defend our legal rights; and
•third parties to collect and process data.
International transfers of PII
The PII we collect is stored and processed in Cyprus, or where we or our partners, affiliates and third-party providers maintain facilities. By providing us with your PII, you consent to the disclosure to these overseas third parties.
We will ensure that any transfer of PII from countries in the European Economic Area (EEA) to countries outside the EEA will be protected by appropriate safeguards, for example by using standard data protection clauses approved by the European Commission, or the use of binding corporate rules or other legally accepted means.
Where we transfer PII from a non-EEA country to another country, you acknowledge that third parties in other jurisdictions may not be subject to similar data protection laws to the ones in our jurisdiction. There are risks if any such third party engages in any act or practice that would contravene the data privacy laws in our jurisdiction and this might mean that you will not be able to seek redress under our jurisdiction’s privacy laws.
Your rights and controlling your PII
Choice and consent: By providing PII to us, you consent to us collecting, holding, using and disclosing your PII in accordance with this privacy policy. If you are under 16 years of age, you must have, and warrant to the extent permitted by law to us, that you have your parent or legal guardian’s permission to access and use the website and they (your parents or guardian) have consented to you providing us with your PII. You do not have to provide PII to us, however, if you do not, it may affect your use of this website or the products and/or services offered on or through it.
Information from third parties: If we receive PII about you from a third party, we will protect it as set out in this privacy policy. If you are a third party providing PII about somebody else, you represent and warrant that you have such person’s consent to provide the PII to us.
Restrict: You may choose to restrict the collection or use of your PII. If you have previously agreed to us using your PII for direct marketing purposes, you may change your mind at any time by contacting us using the details below. If you ask us to restrict or limit how we process your PII, we will let you know how the restriction affects your use of our website or products and services.
Correction: If you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, please contact us using the details below. We will take reasonable steps to correct any information found to be inaccurate, incomplete, misleading or out of date.
Notification of data breaches: We will comply with laws applicable to us in respect of any data breach.
Complaints: If you believe that we have breached a relevant data protection law and wish to make a complaint, please contact us using the details below and provide us with full details of the alleged breach. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. You also have the right to contact a regulatory body or data protection authority in relation to your complaint.
Unsubscribe: To unsubscribe from our e-mail database or opt-out of communications (including marketing communications), please contact us at info@caudexcatena.com.
Cookies
We use “cookies” to collect information about you and your activity across our site. A cookie is a small piece of data that our website stores on your computer, and accesses each time you visit, so we can understand how you use our site. This helps us serve you content based on preferences you have specified. Please refer to our Cookie Policy for more information.
Business transfers
If we or our assets are acquired, or in the unlikely event that we go out of business or enter bankruptcy, we would include data among the assets transferred to any parties who acquire us. You acknowledge that such transfers may occur, and that any parties who acquire us may continue to use your PII according to this policy.
Limits of our policy
Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices.
GDPR
This portion of the Caudena Privacy Policy applies only to consumers who reside in one of the Member States of the European Union.
Please see the attached Caudena GDPR Data Processing Addendum.
UK GDPR
This portion of the Caudena Privacy Policy applies only to consumers who reside in the United Kingdom.
Please see the attached UK GDPR Addendum To Caudena GDPR Data Processing Addendum.
California Privacy
Your California Privacy Rights
Last update: August 1, 2026
This portion of the Caudena Privacy Policy applies only to consumers who reside in the State of California.
If you are a California resident, you may ask us to refrain from sharing your PII with certain Caudena affiliates and other third parties for their marketing purposes. Please contact us at info@caudexcatena.com.
To opt-out of the disclosure of PII about you for monetary or other valuable consideration or for cross-context behavioral advertising, please contact us at info@caudexcatena.com.
PII We Collect about Users
We describe the PII we have collected about consumers in the twelve (12) months preceding the effective date of the Caudena Privacy Policy. The information we may have obtained includes the following:
•Identifiers such as name, physical address, email address, username, password and other credentials used to access Caudena products and services, social media handles, and, when you visit our websites, use our apps or interact with Caudena-related tools, widgets or plug-ins, Internet Protocol address and unique device identifier.
•The following PII described in California Civil Code § 1798.80(e): (1) the PII listed in the preceding bullet point as “identifiers,” (2) signature, (3) telephone number, (4) payment information (including payment card details or online payment services number and invoicing address) and financial information (such as bank account numbers), and (5) the other information that identifies, relates to, describes, or is capable of being associated with, a particular individual that we describe in “Data Collection.” In the twelve months prior to this Policy we have only collected email addresses from Users.
•Commercial information, including (1) records of services purchased or received from Caudena, (2) information provided to us by you, but only to the extent an identifiable person can be linked to such content, (3) information on actions taken on Caudena websites or mobile apps, which may include information about Caudena services considered, and (4) information about consumer preferences and behavior that we collect on our websites and mobile apps or purchase from third parties in order to target consumers for digital advertisements or to personalize content we deliver on our websites and mobile apps.
•Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding a consumer’s interaction with Caudena websites and, if any, mobile apps, and Caudena advertisements that might display on Caudena websites or mobile apps or on third party sites and apps.
•Audio information from calls placed with customer service and accounting centers which may be recorded and/or monitored, and electronic information in the form of Internet or other electronic network activity information as described above.
•Professional or employment-related information in the form of business contact information such as name, company name, physical address and email address and telephone or fax number.
•Inferences drawn from (1) the information we collect when you visit our websites, use our apps (if any), or interact with Caudena-related tools, widgets or plug-ins, (2) information we collect, including through third-party suppliers, regarding content and other data posted on the Internet (such as public locations on the Internet), and (3) information about consumer preferences and behavior that we collect on our websites and mobile apps or purchase from third parties in order to create a profile about a consumer reflecting the consumer’s preferences, characteristics, predispositions, behavior, and attitudes.
•Sensitive PII such as account login information allowing access to an account, and precise geolocation data, in each case as further described above in the relevant categories.
We may, but do not currently, collect this PII from sources including yourself directly and others (e.g., ecommerce retailers) whom you instruct to interact with us on your behalf and other users, public databases, social networks, and third party partners such as analytics or marketing providers. For more information, please see “Data Collection” in the Caudena Privacy Policy.
Disclosures of PII for Monetary or Other Valuable Consideration or for Business Purposes
We have not disclosed email addresses of certain customers of Caudena for monetary or other valuable consideration within the twelve (12) months preceding the effective date of the Caudena Privacy Notice. As is common practice among businesses that operate Internet Web sites, we may have disclosed certain identifiers, information about the use of our websites and apps (if any), and inferences drawn about you to third parties, but we do not sell your PII to third-parties for monetary consideration. These disclosures may qualify as “sales” of PII for consideration, sharing of PII for cross-context behavioral advertising, or processing of PII for targeted advertising under U.S. state comprehensive data privacy laws.
We may have disclosed PII in all or substantially all of the categories identified herein for various business purposes.
We do not disclose PII of individuals we know to be under the age of 16 to businesses or third parties for monetary or other valuable consideration as a “sale” of PII, or as the “sharing” of PII as defined in the California Consumer Privacy Act.
Use of PII about Consumers
We use the PII we collect about consumers for the business purposes disclosed within the Caudena Privacy Policy.
The business purposes for which we may use PII about consumers include:
•Helping to ensure security and integrity to the extent the use of a consumer’s PII is reasonably necessary and proportionate for these purposes;
•Debugging to identify and repair errors in our systems and on our websites and apps;
•Short-term, transient use including non-personalized communications shown as part of a consumer’s current interaction with us;
•Providing services on our behalf or on behalf of another, including maintaining or servicing accounts, providing customer service, fulfilling transactions, verifying identity information, processing payments, and other services. This includes:
◦Conducting internal research to develop and demonstrate technology; and
◦Conducting activity to verify, enhance, and maintain the quality or safety of services or devices which we may own, control, or provide.
We may also use the information we collect for our own or our service providers’ other operational purposes, purposes for which we provide you additional notice, purposes disclosed elsewhere in the Caudena Privacy Policy, or for purposes compatible with the context in which the PII was collected.
Caudena does not use sensitive PII for purposes that would give rise to a right to limit the use or disclosure of sensitive PII for residents of California. We only use sensitive PII as described above to perform services reasonably expected by an average consumer who requests those services; to prevent, detect, and investigate security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted PII; to resist malicious, deceptive, fraudulent, or illegal actions directed at us and to prosecute those responsible for those actions; for short-term, transient use; to perform services on our behalf; or to conduct activity to verify, enhance, and maintain the quality or safety of services or devices which we may own, control, or provide.
Your Privacy Rights
If you reside in California, you may have one or more of the following rights. We will honor requests received to the extent required by applicable law and within the time provided by law.
•Right to Know. You have the right to request that we disclose to you the categories and specific pieces of PII we have collected about you. Specifically, you have the right to request that we disclose what PII we have collected, used, disclosed, including:
◦Whether we are processing PII about you;
◦Specific pieces of information that we have collected about you;
◦Categories of PII we have collected about you;
◦Categories of sources from which the PII is collected;
◦Categories of third parties to whom we disclose PII;
◦The business or commercial purpose for collecting, selling, or sharing PII;
◦Categories of PII about you, if any, that we have sold or shared and the categories of third parties to whom we have sold or shared the information, by category or categories of PII for each category of third party to whom we sold or shared the PII; and
◦Categories of PII about you that we disclosed for a business purpose and the categories of recipients to whom we disclosed the information for a business purpose.
As used above, “sale,” “sold,” “selling,” “shared,” and “sharing” have the meanings provided in the California Consumer Privacy Act.
•Right to Correct. You have the right to request that we correct inaccurate PII that we have collected about you.
•Right to Delete. You have the right to request that we delete PII that we have collected about you. Please note if you have requested a service that requires the use of your PII, we may not be able to provide that service if you choose to delete your PII.
•Right to Opt Out. You have the right to opt out of the disclosure of PII about you for monetary or other valuable consideration, the sharing of PII about you for cross-context behavioral advertising, and targeted advertising. To opt-out, contact us at info@caudexcatena.com. If we receive and are able to process a signal from your device indicating your preference to opt out from sales or sharing of PII, as defined by law, then we will apply that preference to PII we collect from that device, provided that we may not be able to associate the signal to the same device if:
◦you use a different web browser or other tool to interact with us,
◦you make changes to your browser (e.g., uninstall and reinstall or certain types of upgrades) that impact our ability to associate the device with the signal your device originally sent, or
◦you clear cookies or browsing data from your browser or device in a way that impacts our ability to associate the device with the signal your device originally sent.
You can learn how to set up and use an opt-out preference signal by visiting the California Attorney General’s “California Consumer Privacy Act (CCPA)” page or the California Privacy Protection Agency’s “Frequently Asked Questions (FAQs)” page.
Please note that a signal sent from one device may not apply to other devices you use or to data that we collect from you through other sources.
We do not process your PII for profiling in furtherance of “decisions that produce legal or similarly significant effects” as such term is defined under applicable law.
•Right to Appeal. If we decline to take action on a request that you make in accordance with the foregoing to exercise the foregoing privacy rights, then you may appeal our decision by submitting an appeals request to info@caudexcatena.com.
Verification Process
For requests made in connection with the Right to Know, Right to Correct, and/or Right to Delete, please note:
•As required or permitted under applicable law, we may take steps to verify your request before we can provide PII to you, correct or delete PII, or otherwise process your request. To verify your request, we may require you to provide your name, physical address, email address, contact information, and information about your account or previous transactions with us. If we believe we need further information to verify your request as required by law, we may ask you to provide additional information to us.
•We will process your request in the manner required by law within 45 days after receipt of a request, unless we notify you that we require additional time to respond, in which case we will respond within such additional period of time required by law. We may deliver the PII to you through your account, if you maintain an account with Caudena, or electronically or by mail at your option. If electronically, then we will deliver the information to you or, at your request, to another entity, in a portable and, to the extent technically feasible, in a structured, commonly used, machine-readable format that allows you to transmit the information from one entity to another without hindrance.
Nondiscrimination
We may not discriminate against you because of your exercise of any of the foregoing privacy rights, or any other rights under the California Consumer Privacy Act, including by:
•Denying you goods or services;
•Charging different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties;
•Providing you a different level or quality of goods or services; or
•Suggesting that you will receive a different price or rate for goods or services or a different level or quality of goods or services.
We may, however, charge different prices or rates, or provide a different level or quality of goods or services, if that difference is reasonably related to the value provided to Caudena by your PII. We may limit our response to your exercise of rights as permitted by law.
Requests to Exercise Your Rights
You may request to exercise the foregoing rights by:
•Submitting a request to us at info@caudexcatena.com.
Agent Authorization
You may designate an authorized agent to request any of the above rights on your behalf. You may make such a designation by providing the agent with written permission, signed by you, to act on your behalf. Your agent may contact us at info@caudexcatena.com to make a request on your behalf. Even if you choose to use an agent, we may, as permitted by law, require:
•The authorized agent to provide proof that you provided signed permission to the authorized agent to submit the request
•You to verify your identity directly with us; or
•You to directly confirm with us that you provided the authorized agent permission to submit the request.
Changes to this policy
At our discretion, we may change our privacy policy to reflect current acceptable practices. We will take reasonable steps to let users know about changes via our website. Your continued use of this site after any changes to this policy will be regarded as acceptance of our practices around privacy and PII.
If we make a significant change to this privacy policy, for example changing a lawful basis on which we process your PII, we will ask you to re-consent to the amended privacy policy.
This policy is effective as of August 1, 2026.
CAUDENA DATA PROCESSING ADDENDUM
This Data Processing Addendum (“DPA”) supplements the Caudena Privacy Policy and any other agreement between Customer and Caudena governing Customer’s use of the Services (the “Agreement”). This DPA is an agreement between you and the entity you represent (“Customer”, “you” or “your”) and Caudena Corp. under the Agreement (“Caudena”). Unless otherwise defined in this DPA or in the Agreement, all capitalized terms used in this DPA will have the meanings given to them in Section 17 of this DPA.
1.1Scope and Roles. This DPA applies when Customer Data is processed by Caudena. In this context, Caudena will act as processor to Customer, who can act either as controller or processor of Customer Data.
1.2Customer Controls. Customer can use the Service Controls to assist it with its obligations under Applicable Data Protection Law, including its obligations to respond to requests from data subjects. Taking into account the nature of the processing, Customer agrees that it is unlikely that Caudena would become aware that Customer Data transferred under the Standard Contractual Clauses is inaccurate or outdated. Nonetheless, if Caudena becomes aware that Customer Data transferred under the Standard Contractual Clauses is inaccurate or outdated, it will inform Customer without undue delay. Caudena will cooperate with Customer to erase or rectify inaccurate or outdated Customer Data transferred under the Standard Contractual Clauses by providing the Service Controls that Customer can use to erase or rectify Customer Data.
1.3Details of Data Processing.
1.3.1Subject matter. The subject matter of the data processing under this DPA is Customer Data.
1.3.2Duration. As between Caudena and Customer, the duration of the data processing under this DPA is determined by Customer.
1.3.3Purpose. The purpose of the data processing under this DPA is the provision of the Services initiated by Customer from time to time.
1.3.4Nature of the processing. Compute, storage and such other Services as described in the Documentation and initiated by Customer from time to time.
1.3.5Type of Customer Data. Customer Data uploaded to the Services under Customer’s Caudena accounts.
1.3.6Categories of data subjects. The data subjects could include Customer’s customers, employees, suppliers and End Users.
1.4Compliance with Laws. Each party will comply with all laws, rules and regulations applicable to it and binding on it in the performance of this DPA, including Applicable Data Protection Law.
2.Customer Instructions. The parties agree that this DPA and the Agreement (including Customer providing instructions via configuration tools such as the Caudena management console and APIs made available by Caudena for the Services) constitute Customer’s documented instructions regarding Caudena’s processing of Customer Data (“Documented Instructions”). Caudena will process
Customer Data only in accordance with Documented Instructions (which if Customer is acting as a processor, could be based on the instructions of its controllers). Additional instructions outside the scope of the Documented Instructions (if any) require prior written agreement between Caudena and Customer, including agreement on any additional fees payable by Customer to Caudena for carrying out such instructions. Customer is entitled to terminate this DPA and the Agreement if Caudena declines to follow instructions requested by Customer that are outside the scope of, or changed from, those given or agreed to be given in this DPA. Taking into account the nature of the processing, Customer agrees that it is unlikely Caudena can form an opinion on whether Documented Instructions infringe Applicable Data Protection Law. If Caudena forms such an opinion, it will immediately inform Customer, in which case, Customer is entitled to withdraw or modify its Documented Instructions.
3.Confidentiality of Customer Data. Caudena will not access or use, or disclose to any third party, any Customer Data, except, in each case, as necessary to maintain or provide the Services, or as necessary to comply with the law or a valid and binding order of a governmental body (such as a subpoena or court order). If a governmental body sends Caudena a demand for Customer Data, Caudena will attempt to redirect the governmental body to request that data directly from Customer. As part of this effort, Caudena may provide Customer’s basic contact information to the governmental body. If compelled to disclose Customer Data to a governmental body, then Caudena will give Customer reasonable notice of the demand to allow Customer to seek a protective order or other appropriate remedy unless Caudena is legally prohibited from doing so.
4.Confidentiality Obligations of Caudena Personnel. Caudena restricts its personnel from processing Customer Data without authorization by Caudena as described in the Security Standards. Caudena imposes appropriate contractual obligations upon its personnel, including relevant obligations regarding confidentiality, data protection and data security.
5.Security of Data Processing
5.1Caudena has implemented and will maintain the technical and organizational measures for the Caudena Network as described in the Security Standards and this Section. In particular, Caudena has implemented and will maintain the following technical and organizational measures:
(a)security of the Caudena Network as set out in Section 1.1 of the Security Standards;
(b)physical security of the facilities as set out in Section 1.2 of the Security Standards;
(c)measures to control access rights for authorized personnel to the Caudena Network as set out in Section 1.3 of the Security Standards; and
(d)processes for regularly testing, assessing and evaluating the effectiveness of the technical and organizational measures implemented by Caudena as described in Section 2 of the Security Standards.
5.2Customer can elect to implement technical and organizational measures to protect Customer Data. Such technical and organizational measures include the following which can be obtained by Customer from Caudena as described in the Documentation, or directly from a third-party supplier:
(a)pseudonymization and encryption to ensure an appropriate level of security;
(b)measures to ensure the ongoing confidentiality, integrity, availability and resilience of the processing systems and services that are operated by Customer; measures to allow Customer to backup and archive appropriately in order to restore availability and access to Customer Data in a timely manner in the event of a physical or technical incident; and
(c)processes for regularly testing, assessing and evaluating the effectiveness of the technical and organizational measures implemented by Customer.
6.1Authorized Sub-processors. Customer provides general authorization to Caudena’s use of sub-processors to provide processing activities on Customer Data on behalf of Customer (“Sub-processors”) in accordance with this Section. The Caudena website lists Sub-processors that are currently engaged by Caudena. At least 30 days before Caudena engages a Sub-processor, Caudena will update the applicable website and provide Customer with a mechanism to obtain notice of that update. To object to a Sub-processor, Customer can: (i) terminate the Agreement pursuant to its terms; (ii) cease using the Service for which Caudena has engaged the Sub-processor; or (iii) move the relevant Customer Data to another Region where Caudena has not engaged the Sub-processor.
6.2Sub-processor Obligations. Where Caudena authorizes a Sub-processor as described in Section 6.1:
(i)Caudena will restrict the Sub-processor’s access to Customer Data only to what is necessary to provide or maintain the Services in accordance with the Documentation, and Caudena will prohibit the Sub-processor from accessing Customer Data for any other purpose;
(ii)Caudena will enter into a written agreement with the Sub-processor and, to the extent that the Sub-processor performs the same data processing services provided by Caudena under this DPA, Caudena will impose on the Sub-processor the same contractual obligations that Caudena has under this DPA; and
(iii)Caudena will remain responsible for its compliance with the obligations of this DPA and for any acts or omissions of the Sub-processor that cause Caudena to breach any of Caudena’s obligations under this DPA.
7.Caudena Assistance with Data Subject Requests. Taking into account the nature of the processing, the Service Controls are the technical and organizational measures by which Caudena will assist Customer in fulfilling Customer’s obligations to respond to data subjects’ requests under Applicable Data Protection Law. If a data subject makes a request to Caudena, Caudena will promptly forward such request to Customer once Caudena has identified that the request is from a data subject for whom Customer is responsible. Customer authorizes on its behalf, and on behalf of its controllers when Customer is acting as a processor, Caudena to respond to any data subject who makes a request to Caudena, to confirm that Caudena has forwarded the request to Customer. The parties agree that Customer’s use of the Service Controls and Caudena forwarding data subjects’ requests to Customer in accordance with this Section, represent the scope and extent of Customer’s required assistance.
8.Optional Security Features. Caudena makes available many Service Controls that Customer can elect to use. Customer is responsible for (a) implementing the measures described in Section 5.2, as appropriate, (b) properly configuring the Services, (c) using the Service Controls to allow Customer to restore the availability and access to Customer Data in a timely manner in the event of a physical or technical incident (for example backups and routine archiving of Customer Data), and
(d) taking such steps as Customer considers adequate to maintain appropriate security, protection, and deletion of Customer Data, which includes use of encryption technology to protect Customer Data from unauthorized access and measures to control access rights to Customer Data.
9.Security Incident Notification.
9.1Security Incident. Caudena will (a) notify Customer of a Security Incident without undue delay after becoming aware of the Security Incident, and (b) take appropriate measures to address the Security Incident, including measures to mitigate any adverse effects resulting from the Security Incident.
9.2Caudena Assistance. To enable Customer to notify a Security Incident to supervisory authorities or data subjects (as applicable), Caudena will cooperate with and assist Customer by including in the notification under Section 9.1(a) such information about the Security Incident as Caudena is able to disclose to Customer, taking into account the nature of the processing, the information available to Caudena, and any restrictions on disclosing the information, such as confidentiality. Taking into account the nature of the processing, Customer agrees that it is best able to determine the likely consequences of a Security Incident.
9.3Unsuccessful Security Incidents. Customer agrees that:
(i)an unsuccessful Security Incident will not be subject to this Section 9. An unsuccessful Security Incident is one that results in no unauthorized access to Customer Data or to any of Caudena’s equipment or facilities storing Customer Data, and could include, without limitation, pings and other broadcast attacks on firewalls or edge servers, port scans, unsuccessful log-on attempts, denial of service attacks, packet sniffing (or other unauthorized access to traffic data that does not result in access beyond headers) or similar incidents; and
(ii)Caudena’s obligation to report or respond to a Security Incident under this Section 9 is not and will not be construed as an acknowledgement by Caudena of any fault or liability of Caudena with respect to the Security Incident.
9.4Communication. Notification(s) of Security Incidents, if any, will be delivered to one or more of Customer’s administrators by any means Caudena selects, including via email. It is Customer’s sole responsibility to ensure Customer’s administrators maintain accurate contact information on the Caudena management console and secure transmission at all times.
9.5Notification Obligations. If Caudena notifies Customer of a Security Incident, or Customer otherwise becomes aware of any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data, Customer will be responsible for (a) determining if there is any resulting notification or other obligation under Applicable Data Protection Law and (b) taking necessary action to comply with those obligations. This does not limit Caudena’s obligations under this Section 9.
10.Caudena Certifications and Audits.
10.1Caudena ISO-Certification and SOC Reports. In addition to the information contained in this DPA, upon Customer’s request, and provided that the parties have an applicable NDA in place, Caudena will make available the following documents and information:
(i)the certificates issued for the ISO 27001 certification, the ISO 27017 certification, the ISO 27018 certification, and the ISO 27701 certification (or the certifications or other documentation evidencing compliance with such alternative standards as are substantially equivalent to ISO 27001, ISO 27017, ISO 27018, and ISO 27701); and
(ii)the System and Organization Controls (SOC) 1 Report, the System and Organization Controls (SOC) 2 Report and the System and Organization Controls (SOC) 3 Report (or the reports or other documentation describing the controls implemented by Caudena that replace or are substantially equivalent to the SOC 1, SOC 2 and SOC 3).
10.2Caudena Audits. Caudena uses external auditors to verify the adequacy of its security measures, including the security of the physical data centers from which Caudena provides the Services. This audit: (a) will be performed at least annually; (b) will be performed according to ISO 27001 standards or such other alternative standards that are substantially equivalent to ISO 27001; (c) will be performed by independent third-party security professionals at Caudena’s selection and expense; and (d) will result in the generation of an audit report (“Report”), which will be Caudena’s Confidential Information.
10.3Audit Reports. At Customer’s written request, and provided that the parties have an applicable NDA in place, Caudena will provide Customer with a copy of the Report so that Customer can reasonably verify Caudena’s compliance with its obligations under this DPA.
10.4Privacy Impact Assessment and Prior Consultation. Taking into account the nature of the processing and the information available to Caudena, Caudena will assist Customer in complying with Customer’s obligations in respect of data protection impact assessments and prior consultation, by providing the information Caudena makes available under this Section 10.
11.Customer Audits. Customer chooses to conduct any audit, including any inspection, it has the right to request or mandate on its own behalf, and on behalf of its controllers when Customer is acting as a processor, under Applicable Data Protection Law or the Standard Contractual Clauses, by instructing Caudena to carry out the audit described in Section 10. If Customer wishes to change this instruction regarding the audit, then Customer has the right to request a change to this instruction by sending Caudena written notice as provided for in the Agreement. If Caudena declines to follow any instruction requested by Customer regarding audits, including inspections, Customer is entitled to terminate the Agreement in accordance with its terms.
12.Transfers of Personal Data.
12.1Regions. Customer can specify the location(s) where Customer Data will be processed within the Caudena Network (each a “Region”), including Regions in the EEA. Once Customer has made its choice, Caudena will not transfer Customer Data from Customer’s selected Region(s) except as necessary to provide the Services initiated by Customer, or as necessary to comply with the law or valid and binding order of a governmental body.
12.2Application of Standard Contractual Clauses. Subject to Section 12.3, the Standard Contractual Clauses will only apply to Customer Data subject to the GDPR that is transferred, either directly or via onward transfer, to any Third Country (each a “Data Transfer”).
12.2.1When Customer is acting as a controller, the Controller-to-Processor Clauses will apply to a Data Transfer.
12.2.2When Customer is acting as a processor, the Processor-to-Processor Clauses will apply to a Data Transfer. Taking into account the nature of the processing, Customer agrees that it is unlikely that Caudena will know the identity of Customer’s controllers because Caudena has no direct relationship with Customer’s controllers and therefore, Customer will fulfil Caudena’s obligations to Customer’s controllers under the Processor-to-Processor Clauses.
12.3Alternative Transfer Mechanism. The Standard Contractual Clauses will not apply to a Data Transfer if Caudena has adopted Binding Corporate Rules for Processors or an alternative recognized compliance standard for lawful Data Transfers.
13.Termination of the DPA. This DPA will continue in force until the termination of the Agreement (the “Termination Date”).
14.Return or Deletion of Customer Data. At any time up to the Termination Date, and for 90 days following the Termination Date, subject to the terms and conditions of the Agreement, Caudena will return or delete Customer Data when Customer uses the Service Controls to request such return or deletion. No later than the end of this 90-day period, Customer will close all Caudena accounts containing Customer Data.
15.Duties to Inform. Where Customer Data becomes subject to confiscation during bankruptcy or insolvency proceedings, or similar measures by third parties while being processed by Caudena, Caudena will inform Customer without undue delay. Caudena will, without undue delay, notify all relevant parties in such action (for example, creditors, bankruptcy trustee) that any Customer Data subjected to those proceedings is Customer’s property and area of responsibility and that Customer Data is at Customer’s sole disposition.
16.Entire Agreement; Conflict. This DPA incorporates the Standard Contractual Clauses by reference. Except as amended by this DPA, the Agreement will remain in full force and effect. If there is a conflict between the Agreement and this DPA, the terms of this DPA will control, except that the Service Terms will control over this DPA. Nothing in this document varies or modifies the Standard Contractual Clauses.
17.Definitions. Unless otherwise defined in the Agreement, all capitalized terms used in this DPA will have the meanings given to them below:
“API” means an application program interface.
“Applicable Data Protection Law” means all laws and regulations applicable to and binding on the processing of Customer Data by a party, including, as applicable, the GDPR.
“Caudena Network” means the servers, networking equipment, and host software systems (for example, virtual firewalls) that are within Caudena’s control and are used to provide the Services.
“Binding Corporate Rules” has the meaning given to it in the GDPR.
“controller” has the meaning given to it in the GDPR.
“Controller-to-Processor Clauses” means the standard contractual clauses between controllers and processors for Data Transfers, as approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
“Customer Data” means the Personal Data that is uploaded to the Services under Customer’s Caudena accounts.
“Documentation” means the then-current documentation for the Services located at https://mcp.caudexcatena.com/docs (and any successor locations designated by Caudena).
“EEA” means the European Economic Area.
“GDPR” means Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
“Personal Data” means personal data, personal information, personally identifiable information or other equivalent term (each as defined in Applicable Data Protection Law).
“processing” has the meaning given to it in the GDPR and “process”, “processes” and “processed” will be interpreted accordingly.
“processor” has the meaning given to it in the GDPR.
“Processor-to-Processor Clauses” means the standard contractual clauses between processors for Data Transfers, as approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
“Region” has the meaning given to it in Section 12.1 of this DPA.
“Security Incident” means a breach of Caudena’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data. “Security Standards” means the security standards attached to this DPA as Annex 1.
“Service Controls” means the controls, including security features and functionalities, that the Services provide, as described in the Documentation.
“Standard Contractual Clauses” means (i) the Controller-to-Processor Clauses, or (ii) the Processor- to-Processor Clauses, as applicable in accordance with Sections 12.2.1 and 12.2.2.
“Third Country” means a country outside the EEA not recognized by the European Commission as providing an adequate level of protection for personal data (as described in the GDPR).
Annex 1 Security Standards
Capitalized terms not otherwise defined in this document have the meanings assigned to them in the Policy.
1Information Security Program. Caudena will maintain an information security program designed to (a) enable Customer to secure Customer Data against accidental or unlawful loss, access, or disclosure, (b) identify reasonably foreseeable risks to the security and availability of the Caudena Network, and (c) minimize physical and logical security risks to the Caudena Network, including through regular risk assessment and testing. Caudena will designate one or more employees to coordinate and be accountable for the information security program.
Caudena’s information security program will include the following measures:
A.Access Controls. Caudena will make the Caudena Network accessible only to authorized personnel, and only as necessary to maintain and provide the Services. Caudena will maintain access controls and policies to manage authorizations for access to the Caudena Network from each network connection and user, including through the use of firewalls or functionally equivalent technology and authentication controls. Caudena will maintain access controls designed to (i) restrict unauthorized access to data, and (ii) segregate each customer’s data from other customers’ data.
B.Restricted User Access. Caudena will (i) provision and restrict user access to the Caudena Network in accordance with least privilege principles based on personnel job functions, (ii) require review and approval prior to provisioning access to the Caudena Network above least privileged principles, including administrator accounts; (iii) require at least quarterly review of Caudena Network access privileges and, where necessary, revoke Caudena Network access privileges in a timely manner, and (iv) require two- factor authentication for access to the Caudena Network from remote locations.
C.Vulnerability Assessments. Caudena will perform regular external vulnerability assessments and penetration testing of the Caudena Network, and will investigate identified issues and track them to resolution in a timely manner.
D.Application Security. Before publicly launching new Services or significant new features of Services, Caudena will perform application security reviews designed to identify, mitigate and remediate security risks.
E.Change Management. Caudena will maintain controls designed to log, authorize, test, approve and document changes to existing Caudena Network resources, and will document change details within its change management or deployment tools. Caudena will test changes according to its change management standards prior to migration to production. Caudena will maintain processes designed to detect unauthorized changes to the Caudena Network and track identified issues to a resolution.
F.Data Integrity. Caudena will maintain controls designed to provide data integrity during transmission, storage and processing within the Caudena Network. Caudena will provide Customer the ability to delete Customer Data from the Caudena Network.
G.Business Continuity and Disaster Recovery. Caudena will maintain a formal risk management program designed to support the continuity of its critical business functions (“Business Continuity Program”). The Business Continuity Program includes processes and procedures for identification of, response to, and recovery from, events that could prevent or materially impair Caudena’s provision of the Services (a “BCP Event”). The Business Continuity Program includes a three-phased approach that Caudena will follow to manage BCP Events:
(i)Activation & Notification Phase. As Caudena identifies issues likely to result in a BCP Event, Caudena will escalate, validate and investigate those issues. During this phase, Caudena will analyze the root cause of the BCP Event.
(ii)Recovery Phase. Caudena assigns responsibility to the appropriate teams to take steps to restore normal system functionality or stabilize the affected Services.
(iii)Reconstitution Phase. Caudena leadership reviews actions taken and confirms that the recovery effort is complete and the affected portions of the Services and Caudena Network have been restored. Following such confirmation, Caudena conducts a post-mortem analysis of the BCP Event.
H.Incident Management. Caudena will maintain corrective action plans and incident response plans to respond to potential security threats to the Caudena Network. Caudena incident response plans will have defined processes to detect, mitigate, investigate, and report security incidents. The Caudena incident response plans include incident verification, attack analysis, containment, data collection, and problem remediation. Caudena will maintain a Caudena Security Bulletin which publishes and communicates security-related information that may affect the Services and provides guidance to mitigate the risks identified.
I.Storage Media Decommissioning. Caudena will maintain a media decommissioning process that is conducted prior to final disposal of storage media used to store Customer Data. Prior to final disposal, storage media that was used to store Customer Data will be degaussed, erased, purged, physically destroyed, or otherwise sanitized in accordance with industry standard practices designed to ensure that the Customer Data cannot be retrieved from the applicable type of storage media.
A.Access Controls. Caudena will (i) implement and maintain physical safeguards designed to prevent unauthorized physical access, damage, or interference to the Caudena Network, (ii) use appropriate control devices to restrict physical access to the Caudena Network to only authorized personnel who have a legitimate business need for such access, (iii) monitor physical access to the Caudena Network using intrusion detection systems designed to monitor, detect, and alert appropriate personnel of security incidents, (iv) log and regularly audit physical access to the Caudena Network, and (v) perform periodic reviews to validate adherence with these standards.
B.Availability. Caudena will (i) implement redundant systems for the Caudena Network designed to minimize the effect of a malfunction on the Caudena Network, (ii) design the Caudena Network to anticipate and tolerate hardware failures, and (iii) implement automated processes designed to move customer data traffic away from the affected area in the case of hardware failure.
A.Employee Security Training. Caudena will implement and maintain employee security training programs regarding Caudena information security requirements. The security awareness training programs will be reviewed and updated at least annually.
B.Background Checks. Where permitted by law, and to the extent available from applicable governmental authorities, Caudena will require that each employee undergo a background investigation that is reasonable and appropriate for that employee’s position and level of access to the Caudena Network.
2Continued Evaluation. Caudena will conduct periodic reviews of the information security program for the Caudena Network. Caudena will update or alter its information security program as necessary to respond to new security risks and to take advantage of new technologies.
UK GDPR ADDENDUM TO CAUDENA GDPR DATA PROCESSING ADDENDUM
This UK GDPR Addendum (this “UK Addendum”) supplements the Caudena GDPR Data Processing Addendum, or other agreement between Customer and Caudena governing the processing of Customer Data (the “DPA”). This UK Addendum applies when the UK GDPR applies to Customer’s use of the Services to process UK Customer Data. Unless otherwise defined in this UK Addendum, all capitalised terms used in this UK Addendum will have the meanings given to them in the DPA.
1.Applicability. Except as otherwise set out in this UK Addendum, the terms of the DPA will apply to Customer’s use of the Services to process UK Customer Data, and all references to (i) “GDPR” will be replaced with “UK GDPR”, (ii) “Customer Data” will be replaced with “UK Customer Data”, (iii) “Standard Contractual Clauses” will be replaced with “UK Standard Contractual Clauses”, (iv) “Controller-to-Processor Clauses” will be replaced with “UK Controller-to-Processor Clauses”, and (v) “Processor-to-Processor Clauses” will be replaced with “UK Processor-to-Processor Clauses”.
2.Transfers of UK Customer Data. When this UK Addendum applies, Sections 12.2 (“Application of Standard Contractual Clauses”) and 12.3 (“Alternative Transfer Mechanism”) of the DPA will not apply, and the following Sections will apply:
“12.2 Application of UK Standard Contractual Clauses. Subject to Section 12.3, the UK Standard Contractual Clauses will only apply to UK Customer Data that is transferred, either directly or via onward transfer, to any UK Third Country, (each a “UK Data Transfer”).
12.2.1 When Customer is acting as a controller, the UK Controller-to-Processor Clauses will apply to a UK Data Transfer.
12.2.2 When Customer is acting as a processor, the UK Processor-to-Processor Clauses will apply to a UK Data Transfer. Taking into account the nature of the processing, Customer agrees that it is unlikely that Caudena will know the identity of Customer’s controllers because Caudena has no direct relationship with Customer’s controllers and therefore, Customer will fulfil Caudena’s obligations to Customer’s controllers under the UK Processor-to-Processor Clauses.
12.3 Alternative Transfer Mechanism. The UK Standard Contractual Clauses will not apply to a UK Data Transfer if Caudena has adopted Binding Corporate Rules (as defined in the UK GDPR) for Processors or an alternative recognised compliance standard for lawful UK Data Transfers.”
3.Definitions. The following capitalised terms used in this UK Addendum have the meaning given to them below:
“International Data Transfer Addendum” means the international data transfer addendum to the Standard Contractual Clauses issued by the Information Commissioner’s Office under section 119A of the Data Protection Act 2018 on 2 February 2022, and located in Annex A of this UK Addendum.
“UK Controller-to-Processor Clauses” means the Controller-to-Processor Clauses, as amended by the International Data Transfer Addendum.
“UK Processor-to-Processor Clauses” means the Processor-to-Processor Clauses, as amended by the International Data Transfer Addendum.
“UK Standard Contractual Clauses” means (i) the UK Controller-to-Processor Clauses, or (ii) the UK Processor-to-Processor Clauses, as applicable in accordance with Sections 12.2.1 and 12.2.2.
“UK Customer Data” means the “personal data” (as defined in the UK GDPR) that is uploaded to the Services under Customer’s Caudena accounts.
“UK GDPR” means the “applied GDPR” as defined in section 3 of the Data Protection Act 2018.
“UK Third Country” means a country outside the UK not recognised by the Secretary of State or the Data Protection Act 2018 as providing an adequate level of protection for personal data (as described in the UK GDPR).”
4.International Data Transfer Addendum. Annex A (“International Data Transfer Addendum to the Standard Contractual Clauses”) of this UK Addendum will apply in accordance with Section 2 of this UK Addendum.
5.Entire Agreement; Conflict. Except as supplemented by this UK Addendum, the DPA (if applicable) and the Agreement will remain in full force and effect. Where both this UK Addendum and the DPA apply to a processing activity, both will apply concurrently. This UK Addendum, together with the DPA and the Agreement: (a) is intended by the parties as a final, complete and exclusive expression of the terms of their agreement, and (b) supersedes all prior agreements and understandings between the parties with respect to the subject matter hereof.
Annex A
International Data Transfer Addendum to the Standard Contractual Clauses (the “Addendum”)
This Addendum is attached to and forms part of the UK Addendum. The parties hereby enter into this Addendum as a legally binding contract for the purpose of making UK Data Transfers. Unless otherwise defined in this Addendum, all capitalised terms used in this Addendum will have the meanings given to them in the UK Addendum.
Part 1: Tables
Table 1: Parties
Start date | The date that Customer starts to use the Services to transfer UK Customer Data to UK Third Countries. |
The Parties | Exporter (who sends the Restricted
Transfer) | Importer (who receives the
Restricted Transfer) |
Parties’ details | Full legal name: The entity identified as “Customer” in the DPA.
Trading name (if different): If different, the trading name for Customer associated with its Caudena account or as otherwise specified in the DPA or the Agreement.
Main address (if a company registered address): The address for Customer associated with its Caudena account or as otherwise specified in the DPA or the Agreement.
Official registration number (if any) (company number or similar identifier): If any, the official registration number for Customer associated with its Caudena account or as otherwise specified in the DPA or the Agreement. | Full legal name: "Caudena” as identified in the DPA.
Trading name (if different): N/A
Main address (if a company registered address): The address for Caudena specified in the Agreement.
Official registration number (if any) (company number or similar identifier): If any, the official registration number for Caudena specified in the Agreement. |
Key Contact | Job Title: The job title for the contact associated with Customer’s Caudena account, or as otherwise specified in the DPA or the Agreement.
Contact details including email: The contact details associated with Customer’s Caudena account, or as otherwise specified in the DPA or the Agreement. | Job Title: The job title for the contact for Caudena specified in the DPA or the Agreement.
Contact details including email: The contact details for Caudena specified in the DPA or the Agreement. |
Signature (if required for the purposes of
Section 2) | By using the Services to transfer UK Customer Data to UK Third Countries, the Exporter will be deemed to have signed this Addendum. | By transferring UK Customer Data to UK Third Countries on Customer’s instructions, the Importer will be deemed to have signed this Addendum. |
Table 2: Selected SCCs, Modules and Selected Clauses
Addendum EU SCCs | The version of the Approved EU SCCs which this Addendum is appended to, detailed below, including the Appendix Information:
Date: The date that Customer starts to use the Services to transfer Customer Data to Third Countries.
Reference (if any): N/A
Other identifier (if any): This Addendum is appended by reference to the following versions of the Approved EU SCCs (as applicable):
•the Controller-to-Processor Clauses; and
•the Processor-to-Processor Clauses.
|
Table 3: Appendix Information
“Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in:
Annex 1A: List of Parties:
Data exporter(s):
Name: The entity identified as “Customer” in the DPA.
Address: The address for Customer associated with its Caudena account or as otherwise specified in the DPA or the Agreement.
Contact person’s name, position and contact details: The contact details associated with Customer’s Caudena account, or as otherwise specified in the DPA or the Agreement.
Activities relevant to the data transferred under these Clauses: The activities specified in Section
1.3 of the DPA.
Signature and date: By using the Services to transfer Customer Data to Third Countries, the data exporter will be deemed to have signed Annex I.
Role (controller / processor): (I) where the Controller-to-Processor Clauses apply, the data exporter will be a controller; and (ii) where the Processor-to-Processor Clauses apply, the data exporter will be a processor.
Data importer(s):
Name: "Caudena” as identified in the DPA.
Address: The address for Caudena specified in the Agreement.
Contact person’s name, position and contact details: The contact details for Caudena specified in the DPA or the Agreement.
Activities relevant to the data transferred under these Clauses: The activities specified in Section
1.3 of the DPA.
Signature and date: By transferring Customer Data to Third Countries on Customer’s instructions, the data importer will be deemed to have signed Annex I.
Role (controller / processor): Processor.
Annex 1B: Description of Transfer:
Categories of data subjects whose personal data is transferred
Categories of data subjects are specified in Section 1.3 of the DPA.
Categories of personal data transferred
The personal data is described in Section 1.3 of the DPA.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures
The data exporter might include sensitive personal data in the personal data described in Section
1.3 of the DPA.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis)
Personal data is transferred in accordance with Customer’s instructions as described in Section 12 of the DPA.
Nature of the processing
The nature of the processing is described in Section 1.3 of the DPA.
Purpose(s) of the data transfer and further processing To provide the Services.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
Not applicable because the data exporter determines the duration of processing in accordance with the terms of the DPA.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
The subject matter, nature and duration of the processing are described in Section 1.3 of the DPA.
Annex II: Technical and organisational measures including technical and organisational measures to ensure the security of the data:
Description of the technical and organisational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons
The technical and organizational measures (including the certifications held by the data importer) as well as the scope and the extent of the assistance required to respond to data subjects’ requests, are described in the DPA.
For transfers to (sub-) processors, also describe the specific technical and organisational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter.
The technical and organisational measures that the data importer will impose on sub-processors are described in the DPA.
Annex III: List of Sub processors (Modules 2 and 3 only):
A link to a list of Sub-processors is set out in Section 6 of the DPA.
Table 4: Ending this Addendum when the Approved Addendum Changes
Ending this
Addendum when the Approved Addendum changes | Which Parties may end this Addendum as set out in Section 19:
Importer Exporter neither Party |
Part 2: Mandatory Clauses
Entering into this Addendum
1.Each Party agrees to be bound by the terms and conditions set out in this Addendum, in exchange for the other Party also agreeing to be bound by this Addendum.
2.Although Annex 1A and Clause 7 of the Approved EU SCCs require signature by the Parties, for the purpose of making Restricted Transfers, the Parties may enter into this Addendum in any way that makes them legally binding on the Parties and allows data subjects to enforce their rights as set out in this Addendum. Entering into this Addendum will have the same effect as signing the Approved EU SCCs and any part of the Approved EU SCCs.
Interpretation of this Addendum
3.Where this Addendum uses terms that are defined in the Approved EU SCCs those terms shall have the same meaning as in the Approved EU SCCs. In addition, the following terms have the following meanings:
Addendum | This International Data Transfer Addendum which is made up of this Addendum incorporating the Addendum EU SCCs. |
Addendum EU SCCs | The version(s) of the Approved EU SCCs which this Addendum is appended to, as set out in Table 2, including the Appendix Information. |
Appendix Information | As set out in Table 3. |
Appropriate Safeguards | The standard of protection over the personal data and of data subjects’ rights, which is required by UK Data Protection Laws when you are making a Restricted Transfer relying on standard data protection clauses under
Article 46(2)(d) UK GDPR. |
Approved Addendum | The template Addendum issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18. |
Approved EU SCCs | The Standard Contractual Clauses set out in the Annex of Commission Implementing Decision (EU) 2021/914 of 4 June 2021. |
ICO | The Information Commissioner. |
Restricted Transfer | A transfer which is covered by Chapter V of the UK GDPR. |
UK | The United Kingdom of Great Britain and Northern Ireland. |
UK Data Protection Laws | All laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the UK GDPR and the Data Protection Act 2018. |
UK GDPR | As defined in section 3 of the Data Protection Act 2018. |
4.This Addendum must always be interpreted in a manner that is consistent with UK Data Protection Laws and so that it fulfils the Parties’ obligation to provide the Appropriate Safeguards.
5.If the provisions included in the Addendum EU SCCs amend the Approved SCCs in any way which is not permitted under the Approved EU SCCs or the Approved Addendum, such amendment(s) will not be incorporated in this Addendum and the equivalent provision of the Approved EU SCCs will take their place.
6.If there is any inconsistency or conflict between UK Data Protection Laws and this Addendum, UK Data Protection Laws applies.
7.If the meaning of this Addendum is unclear or there is more than one meaning, the meaning which most closely aligns with UK Data Protection Laws applies.
8.Any references to legislation (or specific provisions of legislation) means that legislation (or specific provision) as it may change over time. This includes where that legislation (or specific provision) has been consolidated, re-enacted and/or replaced after this Addendum has been entered into.
Hierarchy
9.Although Clause 5 of the Approved EU SCCs sets out that the Approved EU SCCs prevail over all related agreements between the parties, the parties agree that, for Restricted Transfers, the hierarchy in Section 10 will prevail.
10.Where there is any inconsistency or conflict between the Approved Addendum and the Addendum EU SCCs (as applicable), the Approved Addendum overrides the Addendum EU SCCs, except where (and in so far as) the inconsistent or conflicting terms of the Addendum EU SCCs provides greater protection for data subjects, in which case those terms will override the Approved Addendum.
11.Where this Addendum incorporates Addendum EU SCCs which have been entered into to protect transfers subject to the General Data Protection Regulation (EU) 2016/679 then the Parties acknowledge that nothing in this Addendum impacts those Addendum EU SCCs.
Incorporation of and changes to the EU SCCs
12.This Addendum incorporates the Addendum EU SCCs which are amended to the extent necessary so that:
a.together they operate for data transfers made by the data exporter to the data importer, to the extent that UK Data Protection Laws apply to the data exporter’s processing when making that data transfer, and they provide Appropriate Safeguards for those data transfers;
b.Sections 9 to 11 override Clause 5 (Hierarchy) of the Addendum EU SCCs; and
c.this Addendum (including the Addendum EU SCCs incorporated into it) is (1) governed by the laws of England and Wales and (2) any dispute arising from it is resolved by the courts of England and Wales, in each case unless the laws and/or courts of Scotland or Northern Ireland have been expressly selected by the Parties.
13.Unless the Parties have agreed alternative amendments which meet the requirements of Section 12, the provisions of Section 15 will apply.
14.No amendments to the Approved EU SCCs other than to meet the requirements of Section 12 may be made.
15.The following amendments to the Addendum EU SCCs (for the purpose of Section 12) are made:
a. References to the “Clauses” means this Addendum, incorporating the Addendum EU SCCs; b. In Clause 2, delete the words:
“and, with respect to data transfers from controllers to processors and/or processors to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU)
2016/679”;
c.Clause 6 (Description of the transfer(s)) is replaced with:
“The details of the transfers(s) and in particular the categories of personal data that are
transferred and the purpose(s) for which they are transferred) are those specified in Annex I.B where UK Data Protection Laws apply to the data exporter’s processing when making that transfer.”;
d.Clause 8.7(i) of Module 1 is replaced with:
“it is to a country benefitting from adequacy regulations pursuant to Section 17A of the UK
GDPR that covers the onward transfer”;
e.Clause 8.8(i) of Modules 2 and 3 is replaced with:
“the onward transfer is to a country benefitting from adequacy regulations pursuant to
Section 17A of the UK GDPR that covers the onward transfer;”
f.References to “Regulation (EU) 2016/679”, “Regulation (EU) 2016/679 of the European
Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation)” and “that Regulation” are all replaced by “UK Data Protection Laws”. References to specific Article(s) of “Regulation (EU) 2016/679” are replaced with the equivalent Article or Section of UK Data Protection Laws;
g.References to Regulation (EU) 2018/1725 are removed;
h.References to the “European Union”, “Union”, “EU”, “EU Member State”, “Member State” and “EU or Member State” are all replaced with the “UK”;
i.The reference to “Clause 12(c)(i)” at Clause 10(b)(i) of Module one, is replaced with “Clause 11(c)(i)”;
j.Clause 13(a) and Part C of Annex I are not used;
k.The “competent supervisory authority” and “supervisory authority” are both replaced with the “Information Commissioner”;
l.In Clause 16(e), subsection (i) is replaced with:
“the Secretary of State makes regulations pursuant to Section 17A of the Data Protection
Act 2018 that cover the transfer of personal data to which these clauses apply;”; m. Clause 17 is replaced with:
“These Clauses are governed by the laws of England and Wales.”;
n.Clause 18 is replaced with:
“Any dispute arising from these Clauses shall be resolved by the courts of England and Wales. A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of any country in the UK. The Parties agree to submit themselves to the jurisdiction of such courts.”; and
o.The footnotes to the Approved EU SCCs do not form part of the Addendum, except for footnotes 8, 9, 10 and 11.
Amendments to this Addendum
16.The Parties may agree to change Clauses 17 and/or 18 of the Addendum EU SCCs to refer to the laws and/or courts of Scotland or Northern Ireland.
17.If the Parties wish to change the format of the information included in Part 1: Tables of the Approved Addendum, they may do so by agreeing to the change in writing, provided that the change does not reduce the Appropriate Safeguards.
18.From time to time, the ICO may issue a revised Approved Addendum which:
a.makes reasonable and proportionate changes to the Approved Addendum, including correcting errors in the Approved Addendum; and/or
b.reflects changes to UK Data Protection Laws;
The revised Approved Addendum will specify the start date from which the changes to the Approved
Addendum are effective and whether the Parties need to review this Addendum including the Appendix Information. This Addendum is automatically amended as set out in the revised Approved Addendum from the start date specified.
19.If the ICO issues a revised Approved Addendum under Section 18, if any Party selected in Table 4 “Ending the Addendum when the Approved Addendum changes”, will as a direct result of the changes in the Approved Addendum have a substantial, disproportionate and demonstrable increase in:
a.its direct costs of performing its obligations under the Addendum; and/or b its risk under the Addendum,
and in either case it has first taken reasonable steps to reduce those costs or risks so that it is not substantial and disproportionate, then that Party may end this Addendum at the end of a reasonable notice period, by providing written notice for that period to the other Party before the start date of the revised Approved Addendum.
20.The Parties do not need the consent of any third party to make changes to this Addendum, but any changes must be made in accordance with its terms.