Sable Data Processing Agreement
Last Updated: August 18, 2026
This Data Processing Agreement (the “DPA”) is entered into between Company and the customer identified in the Order Form (“Customer”). This DPA forms part of the Master Services Agreement or other written agreement between the parties for the provision of services (the “Agreement”), and is effective as of the effective date of the Agreement. Capitalized terms used but not defined in this DPA have the meanings given in the Agreement.
1. Definitions
- “Account Data” has the meaning given in the Agreement or, if not defined in the Agreement, means Personal Data that relates to Company’s relationship with Customer, including the names and contact information of individuals authorized by Customer to access Customer’s account, support communications, and billing and administrative information relating to Customer. Account Data does not include Customer Data or Customer Personal Data submitted to or processed through the Services.
- “Aggregated and De-identified Data” has the meaning given in the Agreement or, if not defined in the Agreement, means data derived from Customer Personal Data, Customer Data, or use of the Services that has been aggregated or de-identified such that it does not identify, and could not reasonably be used to identify, Customer or any natural person.
- “Applicable Privacy Law” means any applicable law, regulation, or binding regulatory guidance governing the privacy, protection, or Processing of Personal Data, including the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (“CCPA”), the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”), the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, the Swiss Federal Act on Data Protection (“Swiss FADP”), and any US state privacy law listed in Annex C (US State Privacy Law Addendum), each as amended, superseded, or replaced from time to time.
- “Controller” means the entity that determines the purposes and means of Processing Personal Data, including any “business” as defined in the CCPA.
- “Customer Personal Data” means the Personal Data within Customer Data (as defined in the Agreement) that Customer or its Users provide, transmit, or make available to Company, or that End Users provide during a Session, in connection with Customer’s use of the Services, as further described in Annex A, Part 1 (Description of Processing Activities). Customer Personal Data does not include Usage Data, Account Data, or Aggregated and De-identified Data.
- “Data Subject” means the identified or identifiable natural person to whom Personal Data relates.
- “End User” means an individual, other than a User, who interacts with the Services during a Session.
- “Outputs” has the meaning given in the Agreement or, if not defined in the Agreement, means the content and results generated or returned by the Services.
- “Personal Data” means any information that identifies, relates to, describes, or could reasonably be used to identify a natural person, as defined under Applicable Privacy Law.
- “Processing” (and “Process” and “Processes”) means any operation performed on Personal Data, whether or not by automated means, including collection, storage, use, disclosure, combination, erasure, or destruction.
- “Processor” means the entity that Processes Personal Data on behalf of the Controller, including any “service provider” or “contractor” as those terms are defined under the CCPA or other US state privacy laws.
- “SCCs” means the standard contractual clauses approved by the European Commission pursuant to Implementing Decision (EU) 2021/914.
- “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Company or its Sub-processors. Security Incident does not include unsuccessful attempts that do not compromise the security of Customer Personal Data, including unsuccessful log-in attempts, pings, port scans, or denial-of-service attacks.
- “Session” means a single interactive session between an End User and the Services.
- “Sub-processor” means any third party engaged by Company to Process Customer Personal Data on Company’s behalf.
- “Trust Center” means Company’s security and compliance portal or webpage identified in the applicable ordering document or on Company’s website, currently at https://app.vanta.com/withsable.com/trust/74d8bew88fb2xgv4rajtw.
- “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner’s Office (version B1.0, in force 21 March 2022), as updated.
- “Usage Data” has the meaning given in the Agreement or, if not defined in the Agreement, means technical logs, events, and usage and performance information generated by or collected in connection with the Services, excluding the content of Customer Personal Data.
2. Scope; Roles
2.1. Processor Role and Instructions
With respect to Customer Personal Data, Customer is the Controller and Company is the Processor. Where Customer acts as a Processor on behalf of another Controller, Customer appoints Company as a Sub-processor, and Customer represents and warrants that its instructions to Company are authorized by the relevant Controller. In that case, references in this DPA to Customer’s instructions, obligations, or rights as Controller will be deemed to include Customer acting on behalf of the relevant Controller, as applicable. Company will Process Customer Personal Data only: (a) in accordance with Customer’s documented instructions as set forth in this DPA and the Agreement; (b) as necessary to provide, maintain, secure, and support the Services; (c) as required by Applicable Privacy Law (in which case Company will inform Customer of the requirement before Processing unless prohibited by law); and (d) as set forth in Annex A, Part 1. The Agreement, this DPA, the applicable Order Forms, and Customer’s documented configuration and use of the Services constitute Customer’s complete documented instructions as of the effective date of this DPA; any additional instructions require the parties’ written agreement. If Company reasonably believes that an instruction infringes Applicable Privacy Law or is technically infeasible or outside the scope of the Services, Company will promptly notify Customer and will not be required to follow it. Company’s restrictions on using Customer Personal Data to train, develop, or improve artificial intelligence or machine learning models are set forth in Section 10 (AI and Machine Learning Restrictions) of this DPA and the applicable model-training or data-use provisions of the Agreement.
2.2. Independent Controller Activities
Except as set forth below, with respect to Usage Data and Account Data, and any Aggregated and De-identified Data that constitutes Personal Data, Company is an independent Controller (and not a joint Controller with Customer). To the extent such data constitutes Personal Data, Company Processes it as an independent Controller solely for purposes related to managing its relationship with Customer (including account administration, billing, and communications, subject to applicable law and opt-out rights), operating, securing, supporting, and improving the Services, preventing fraud and abuse, and complying with law. Company will not Process such data for advertising, sale, sharing, model training, or unrelated product development except with Customer’s express written authorization. Aggregated and De-identified Data that no longer constitutes Personal Data is not subject to this DPA except as provided in Section 11 (Aggregated and De-identified Data). Company’s Processing as an independent Controller is governed by Company’s applicable privacy notices and Applicable Privacy Law and is not subject to the Processor obligations in Sections 3 through 9 of this DPA. To the extent Usage Data constitutes Customer Personal Data and is Processed solely to provide the Services on Customer’s behalf, Company Processes it as a Processor under this DPA. Subject to the restrictions expressly set forth in this DPA and Applicable Privacy Law, nothing in this DPA limits Company’s rights with respect to Aggregated and De-identified Data, Usage Data, or Account Data.
2.3. Inability to Comply
Company will notify Customer promptly if Company determines that it can no longer meet its obligations under Applicable Privacy Law with respect to Customer Personal Data. In that case, Customer may, as Customer’s sole contractual remedy for such prospective inability to continue the affected Processing, suspend the affected Processing or terminate the affected Order Form. Nothing in this Section limits any rights or remedies that cannot be limited under Applicable Privacy Law or the SCCs.
2.4. Customer Affiliates
Customer enters into this DPA for itself and, where required by Applicable Privacy Law, on behalf of its Affiliates that use the Services, thereby establishing a separate DPA between Company and each such Customer Affiliate. Customer remains responsible for coordinating all instructions and communications with Company under this DPA and for its Affiliates’ compliance, and any right or claim under this DPA on behalf of a Customer Affiliate must be exercised or brought by Customer and not by the Affiliate directly, except to the extent such a restriction is not permitted under Applicable Privacy Law or the SCCs.
2.5. Customer-Directed Services
The Services may permit Customer to configure the Services to transmit Customer Data, including Customer Personal Data, to a third-party product or service selected by Customer, including an AI or large language model provider accessed using Customer’s own account, API key, or other credentials (each, a “Customer-Directed Service”). Customer’s configuration of the Services to route Customer Personal Data to a Customer-Directed Service constitutes Customer’s documented instruction to transmit that data. A Customer-Directed Service is not a Sub-processor, and Sections 5 (Sub-processors) and 10 (AI and Machine Learning Restrictions) do not apply to its Processing of Customer Personal Data. As between the parties, Customer is solely responsible for its selection of, and terms with, each Customer-Directed Service; for the lawfulness of the disclosure, including any required legal basis, notices, consents, and transfer mechanisms; for evaluating the Customer-Directed Service’s security, retention, and data-use practices, including any use of data to train or improve models; and for ensuring that no Restricted Data is transmitted except as permitted under Customer’s agreement with that provider and Applicable Privacy Law. Company’s obligations under this DPA do not apply to Customer Personal Data once it has been delivered to a Customer-Directed Service, and Company is not responsible for the acts, omissions, or security of any Customer-Directed Service. Company will protect credentials Customer submits to configure a Customer-Directed Service as Customer’s Confidential Information and will use them solely to provide the Services as configured by Customer.
3. Confidentiality of Processing
Company will ensure that persons authorized to Process Customer Personal Data are subject to binding confidentiality obligations or professional duties of confidentiality, and access to Customer Personal Data will be limited to Company personnel and Sub-processors who require access to perform the Services.
4. Security
Company will implement and maintain technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, or unauthorized disclosure, as further described in Annex A, Part 2 (Technical and Organizational Measures). Company may update such measures from time to time, provided that the updated measures do not materially reduce the overall level of security provided to Customer Personal Data. Company’s audit reports and certifications are available as set forth in Section 12 (Audit Rights). Where Company maintains a Trust Center, Company’s then-current security controls are described there.
5. Sub-processors
Customer authorizes Company to engage Sub-processors to Process Customer Personal Data in accordance with this Section 5. Company will maintain a current list of Sub-processors at the Trust Center or as otherwise identified by Company, and Customer may subscribe to notifications of changes on Company’s website or as otherwise directed by Company. Company will provide Customer with at least thirty (30) days’ advance notice of any material addition, replacement, or removal of a Sub-processor that will Process Customer Personal Data, except where a shorter notice period is reasonably necessary for urgent security or legal reasons. Company will impose on Sub-processors the same data protection obligations required under Applicable Privacy Law and obligations no less protective than Company’s obligations under this DPA with respect to Customer Personal Data, in each case to the extent applicable to the services provided by the Sub-processor. Company remains liable for its compliance with this DPA, including for the acts and omissions of Sub-processors that breach this DPA in connection with their Processing of Customer Personal Data. If Customer objects to a new or replacement Sub-processor on reasonable data protection grounds, Customer must notify Company in writing within fifteen (15) days of the applicable notice. The parties will cooperate in good faith to resolve the objection. If the parties cannot resolve the objection within a reasonable time, Customer may, as Customer’s sole contractual remedy for such objection, terminate the affected Order Form upon written notice and pay Company all amounts due and owing under the Agreement as of the date of such termination. Nothing in this Section limits any rights or remedies that cannot be limited under Applicable Privacy Law or the SCCs.
6. Data Subject Rights
Taking into account the nature of the Processing and the information available to Company, Company will provide Customer with reasonable assistance to fulfill Customer’s obligation to respond to Data Subject rights requests under Applicable Privacy Law. Company will promptly notify Customer if Company receives a Data Subject request and will not respond on Customer’s behalf without Customer’s prior written authorization, except as required by Applicable Privacy Law. To the extent assistance under this Section 6 requires work beyond the Services, Customer will compensate Company at Company’s then-current professional services rates. Company’s obligations under this Section are limited to information reasonably available to Company and do not require Company to disclose confidential information of other customers, compromise the security of Company systems, or take actions not required by Applicable Privacy Law.
7. Data Protection Impact Assessments
To the extent required by Applicable Privacy Law and upon Customer’s reasonable written request, Company will provide reasonable cooperation and assistance with the conduct of data protection impact assessments and any required prior consultations with supervisory authorities, in each case solely to the extent relating to Company’s Processing of Customer Personal Data. Customer is responsible for conducting the assessment and reaching any legal determinations required under Applicable Privacy Law. The cost and limitation provisions in Section 6 (Data Subject Rights) apply equally to assistance under this Section 7.
8. Security Incidents
Company will notify Customer in writing without undue delay, and in any event within seventy-two (72) hours, after Company becomes aware of a Security Incident. Company may provide initial notice based on information then available and supplement it as additional information is confirmed. To the extent then known, the notification will include a description of the Security Incident, the likely consequences, and the measures taken or proposed to address it. Company will cooperate with Customer and take reasonable steps within Company’s control to investigate, mitigate, and remediate the Security Incident. As between the parties, Customer is solely responsible for fulfilling any third-party notification obligations relating to a Security Incident, except to the extent Applicable Privacy Law requires Company to provide such notices. Company’s notification of, or response to, a Security Incident does not constitute an acknowledgment of any fault or liability.
9. Data Return; Deletion
Upon termination or expiration of the Agreement, or upon Customer’s earlier written request to the extent Customer Personal Data is no longer required for the Services and deletion or return is technically feasible, Company will securely delete Customer Personal Data or, at Customer’s election, return it in the formats and through the functionality the Services make generally available. In either case, Company will complete the action in its active systems within thirty (30) days, or within any shorter period the parties agree in writing, in each case with respect to Customer Personal Data in Company’s possession or control. Upon Customer’s written request, Company will provide a written certification confirming such return or deletion. Notwithstanding the foregoing, Company may retain Customer Personal Data (a) in routine system backups until they are overwritten or expire in the ordinary course of Company’s backup cycle; (b) to comply with a legal hold or any order or request from a court, regulator, or other governmental authority; and (c) to the extent and for the period required by Applicable Privacy Law. Customer Personal Data so retained remains subject to this DPA. Customer Personal Data retained in backups is not restored to, or otherwise accessed in, Company’s active systems except as part of a disaster recovery process or as required by applicable law. Customer acknowledges that fulfilling a return or deletion request before the end of the Term may limit or prevent Company’s ability to continue providing the affected Services.
10. AI and Machine Learning Restrictions
Company will not use Customer Personal Data to train, fine-tune, develop, or improve any artificial intelligence or machine learning model (including any such model operated by a Sub-processor or third-party provider engaged by Company), except: (a) as Aggregated and De-identified Data under Section 11 (Aggregated and De-identified Data); or (b) with Customer’s express written authorization. With respect to AI/ML Sub-processors, Company will require, or will rely on the applicable provider’s then-current standard terms that provide, that each such Sub-processor does not use Customer Personal Data to train, fine-tune, develop, or improve its models except as expressly authorized under the Agreement and, where the Sub-processor offers configurable training or retention settings, Company will use commercially reasonable efforts to configure those settings consistently with this restriction, including zero-retention configurations where the provider makes them available. Company will use commercially reasonable efforts to ensure that each such Sub-processor: (i) Processes Customer Personal Data only as necessary to provide inference or other Services to Company; (ii) does not retain Customer Personal Data except as necessary to provide, secure, debug, or comply with legal obligations for the applicable service; and (iii) does not permit human review of Customer Personal Data except for abuse, security, support, or legal-compliance purposes and only under confidentiality obligations. Company’s use of Outputs for model training or improvement is subject to the Agreement. Nothing in this Section 10 restricts Company’s Processing of Customer Personal Data as otherwise authorized under this DPA or the Agreement, or as necessary to provide, maintain, secure, or support the Services.
11. Aggregated and De-identified Data
Customer authorizes Company to aggregate and de-identify Customer Personal Data. To the extent any resulting data no longer constitutes Personal Data under Applicable Privacy Law, such data will be considered outside the scope of this DPA. With respect to any such data that constitutes Aggregated and De-identified Data: (a) Company will implement and maintain reasonable technical and organizational measures designed to ensure that the data cannot reasonably be associated with, or used to re-identify, any Data Subject; (b) Company will not attempt to re-identify the data except to test the effectiveness of its de-identification processes; (c) Company will Process the data solely in aggregated or de-identified form (as applicable); and (d) Company will contractually require any recipients of Aggregated and De-identified Data to maintain the data in aggregated or de-identified form and not to attempt re-identification, in each case to the extent required by Applicable Privacy Law. Company applies de-identification and aggregation measures intended to align with the standards for deidentified information and aggregate consumer information under California Civil Code Section 1798.140 and comparable de-identification, aggregation, or anonymization requirements under Applicable Privacy Law. Subject to the foregoing, Company may use Aggregated and De-identified Data for the purposes permitted under the Agreement or, where the Agreement does not address such use, to operate, secure, analyze, improve, benchmark, and develop the Services, and for Company’s other lawful business purposes consistent with this Section 11.
12. Audit Rights
Company’s most recent independent security audit report or assessment (such as a SOC 2 audit report or ISO 27001 certification), where Company maintains one, together with Company’s security documentation at the Trust Center, serves as the primary means of demonstrating compliance with this DPA. Where Company maintains such a report or assessment, Company will, upon reasonable request, make its then-current report or equivalent documentation available to Customer, subject to reasonable confidentiality obligations. If additional information is reasonably required, Company will respond to reasonable written security questionnaires. If compliance still cannot reasonably be demonstrated, Customer may, no more than once annually and upon at least sixty (60) days’ prior notice, engage an independent third-party auditor subject to confidentiality obligations to conduct an audit at Customer’s expense during normal business hours and in a manner that minimizes disruption to Company. Company may reasonably object to any auditor that is a competitor, lacks independence, or is otherwise unsuitable. No audit or inspection will provide Customer or its auditor with access to other customers’ data, Company’s source code, information that would compromise the security of Company’s systems or other customers, or facilities where access would pose a security risk, and Company may require Customer and its auditor to agree to reasonable confidentiality protections in connection with any audit or inspection.
13. Government Access Requests
To the extent legally permitted and reasonably practicable, Company will use commercially reasonable efforts to notify Customer of any legally binding governmental request for Customer Personal Data prior to disclosure. Company may challenge or seek to narrow any request that Company reasonably believes is overbroad, unlawful, or otherwise inappropriate and will disclose only the Customer Personal Data required by law.
14. International Data Transfers
To the extent Company Processes or transfers Customer Personal Data to a jurisdiction for which Applicable Privacy Law requires a lawful transfer mechanism, Company will comply using a recognized mechanism, including the SCCs, the UK Addendum, the Swiss modifications to the SCCs, or any other lawful transfer mechanism recognized under Applicable Privacy Law. The terms set forth in Annex B (International Data Transfer Addendum) are incorporated by reference into this DPA and apply to the extent Customer Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that the applicable supervisory authority has not recognized as providing an adequate level of protection.
15. Customer Obligations
15.1. Restricted Data
Customer represents and warrants that Customer will not submit, and will not permit any User to submit, the following categories of data to the Services without the parties’ express prior written agreement (including an executed business associate agreement, which constitutes such agreement with respect to Protected Health Information) (collectively, “Restricted Data”): (a) social security numbers or other government-issued identification numbers; (b) protected health information subject to HIPAA, or other information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis; (c) health insurance information; (d) biometric or genetic information; (e) passwords or credentials for third-party online accounts (other than credentials created for and used solely to access the Services or submitted to configure a Customer-Directed Service or credentials Customer provisions for Company’s use in operating Sessions in Customer’s systems); (f) credentials for any financial accounts; (g) tax return data; (h) payment card information subject to PCI DSS; (i) Personal Data of children under sixteen (16) years of age; (j) precise geolocation data; or (k) any other information that falls within any special categories of Personal Data as defined under Applicable Privacy Law. Restricted Data also includes API keys, private keys, access tokens, passwords, secrets, and production credentials, in each case unless the parties specifically agree otherwise in writing, and in each case excluding credentials Customer submits to configure the Services to connect to a Customer-Directed Service (as defined in Section 2.5) or credentials Customer provisions for Company’s use in operating Sessions in Customer’s systems. If Customer Personal Data submitted to the Services incidentally contains Restricted Data, Customer remains solely responsible for ensuring such submission complies with Applicable Privacy Law, and Company’s obligations under this DPA apply to such data as Customer Personal Data. Customer is responsible for scoping the accounts and permissions it provisions for Sessions, for the state and contents of the environments in which Sessions run, including any data present between Sessions, and for revoking access on expiration or termination. Accounts Customer provisions for Sessions must be non-production accounts scoped to the least privilege necessary for the Services to operate.
15.2. Lawful Basis, Security, and Assessment
Customer represents and warrants that: (a) Customer has established and will maintain a valid legal basis under Applicable Privacy Law (including, where applicable, Articles 6, 9, and 10 of the EU GDPR or the equivalent provisions of the UK GDPR) for Company’s Processing of Customer Personal Data as contemplated by the Agreement and this DPA; and (b) Customer has provided all required notices and obtained all required consents (including, where applicable, under Articles 12 through 14 of the EU GDPR or the equivalent provisions of the UK GDPR). Customer is solely responsible for making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of Customer Personal Data, for securing the account credentials, systems, and devices Customer uses to access the Services, and for backing up Customer Personal Data as applicable. Customer acknowledges that it has had the opportunity to evaluate the Services, the technical and organizational measures described in Annex A, Part 2, and Company’s commitments under this DPA in determining whether the Services are appropriate for Customer’s intended use.
16. Liability
Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability set forth in the Agreement, which are incorporated herein by reference. Nothing in this Section 16 limits the rights of Data Subjects or supervisory authorities under Applicable Privacy Law, or limits either party’s liability to such persons or authorities (or to Data Subjects under the third-party beneficiary provisions of the SCCs) to the extent such liability cannot be limited by contract under Applicable Privacy Law.
17. Term; Survival
This DPA is effective as of the effective date of the Agreement and will remain in force for the duration of the Agreement and for as long as Company Processes Customer Personal Data. Upon termination or expiration of the Agreement, this DPA will continue in effect until all Customer Personal Data has been returned or deleted in accordance with Section 9 (Data Return; Deletion). Any provision that, by its nature, is intended to survive will survive termination or expiration of this DPA and the Agreement.
18. Miscellaneous
This DPA supplements the Agreement; in any conflict between the Agreement and this DPA with respect to the Processing of Customer Personal Data, this DPA controls, unless amended by Special Terms, except that any business associate agreement between the parties controls with respect to Protected Health Information and compliance with HIPAA, and in all other respects the Agreement governs. This DPA, together with the Agreement, the Annexes hereto, and any applicable Order Forms, constitutes the entire agreement between the parties with respect to the Processing of Customer Personal Data. Except as expressly set forth in this DPA, this DPA may be amended or modified only by a written instrument signed by authorized representatives of both parties. Company may, however, modify this DPA (including replacing the SCCs, UK Addendum, or Swiss modifications to the SCCs with any successor or replacement transfer mechanism) on written notice to Customer solely to the extent necessary to maintain compliance with Applicable Privacy Law, so long as any such modification does not materially reduce the protections afforded to Customer Personal Data or materially increase Customer’s obligations under this DPA. If any provision is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable and the remaining provisions will remain in full force and effect. This DPA will be governed by, and the parties submit to, the governing law and jurisdiction specified in the Agreement. Notices under this DPA will be given in accordance with the notice provisions of the Agreement; Security Incident notices may also be sent by email to Customer’s designated notice or security contact.
Annex A: Processing Details
Part 1: Description of Processing Activities
A.1 Parties. Data Exporter: Customer, acting as Controller or Processor, as applicable. Data Importer: Company, acting as Processor or Sub-processor, as applicable. The parties’ details are as set forth in the Agreement or applicable Order Form.
A.2 Data Subjects and Personal Data. Customer Personal Data may relate to (a) Customer’s employees and contractors (Users) who access or use the Services; (b) individuals whose Personal Data Customer or its Users submit to the Services; (c) End Users who interact with the Services during a Session; and (d) any other individuals identified in the applicable Order Form, and may include professional and organizational data (job title, employer, business contact information), content data submitted by Customer or its Users in connection with the Services, Session recordings and transcripts, including audio and any information End Users provide during a Session, and any other categories specified in the applicable Order Form. For clarity, Account Data and Usage Data, including, where applicable, User names, email addresses, employee identifiers, authentication identifiers and account-access metadata (excluding passwords, access tokens, private keys, and other authentication secrets), log records, session data, feature usage statistics, device identifiers, and IP addresses generated by use of the Services, are Processed by Company as an independent Controller in accordance with Section 2.2 (Independent Controller Activities) of this DPA, except to the extent Section 2.2 provides that Company Processes such data as a Processor.
A.3 Special Categories of Personal Data. Company does not intentionally collect or Process special categories of Personal Data or other Restricted Data, and Customer must not submit them to the Services unless the parties have specifically agreed in writing in the applicable Order Form or other written agreement (including, with respect to Protected Health Information, an executed business associate agreement).
A.4 Nature, Purpose, Frequency, and Duration of Processing. Company will Process Customer Personal Data as necessary to provide, maintain, secure, and support the Services, including authorized access by Company personnel to monitor, support, and intervene in Sessions where necessary to deliver the Services, to fulfill its obligations under this DPA, and to comply with Applicable Privacy Law. Processing is continuous for the duration of the Agreement (as initiated by Customer through its use of the Services) and for such additional period as is necessary to return or delete Customer Personal Data in accordance with Section 9 (Data Return; Deletion).
Part 2: Technical and Organizational Measures
Company implements and maintains an industry-standard information security program designed to protect the confidentiality, integrity, and availability of Customer Personal Data, evidenced, where Company maintains one, by Company’s then-current independent audit report or assessment (such as a SOC 2 audit report or ISO 27001 certification), available to Customer in accordance with Section 12 (Audit Rights). Company’s measures include role-based access controls and least-privilege principles, multi-factor authentication for privileged access, industry-standard encryption in transit and at rest, logical access controls designed to limit access to Customer Personal Data to authorized users and systems, logging and monitoring, a documented security incident response plan, and appropriate due diligence of Sub-processors. Company’s then-current technical and organizational measures are described in the security documentation available at the Trust Center, which is incorporated into this Annex A, Part 2 by reference. Company also maintains written information security policies and procedures governing access control, change management, vulnerability management, secure development practices, and incident response.
Part 3: Sub-processors
Customer authorizes Company to engage the Sub-processors identified at Company’s Trust Center or otherwise on Company’s website, in accordance with Section 5 (Sub-processors). The current Sub-processor list at the Trust Center constitutes the then-current list of authorized Sub-processors. Company’s Sub-processors may include providers of cloud infrastructure and hosting, artificial intelligence and machine learning model inference and API services, security, monitoring, and logging services, customer relationship management and support tooling, analytics and performance monitoring services, and authentication and identity management. Company will notify Customer of changes to the Sub-processor list in accordance with Section 5 (Sub-processors).
Annex B: International Data Transfer Addendum
This Annex B applies only to the extent Customer Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country not recognized as providing an adequate level of data protection by the applicable supervisory authority. If no such transfers occur under the Agreement, this Annex B does not apply.
B.1 EU SCCs. Where Customer Personal Data is transferred from the EEA to a country not the subject of an EU adequacy decision, the parties agree to be bound by the SCCs, incorporated by reference into this DPA. Module Two (Controller to Processor) applies where Customer is a Controller, and Module Three (Processor to Sub-processor) applies where Customer is itself a Processor on behalf of another person. In any conflict between the SCCs and any other provision of this DPA or the Agreement, the SCCs prevail with respect to transfers governed by them. The following elections apply: Clause 7 (Docking) is not used; Clause 9(a) (Sub-processors) Option 2 applies, with notice period as in Section 5 (Sub-processors); Clause 11 (Redress) optional language is not used; Clause 13 (Supervision) the competent supervisory authority will be determined in accordance with Clause 13 of the SCCs and identified in Annex I.C to the extent required; Clause 17 (Governing Law) Option 1, governed by the law of Ireland; Clause 18 (Forum) the courts of Ireland. Annexes I, II, and III to the SCCs are populated by Annex A, Part 1, Annex A, Part 2, and Annex A, Part 3 of this DPA, respectively.
B.2 UK Addendum. Where Customer Personal Data is transferred from the United Kingdom to a country not subject to UK adequacy regulations, the parties agree to be bound by the UK Addendum, incorporated by reference. Table 1 (parties) is as identified in Annex A, Part 1 and the start date is the effective date of the Agreement; Table 2 incorporates the SCCs in Section B.1; Table 3 (Appendix Information) is as set forth in Annex A, Part 1, Annex A, Part 2, and Annex A, Part 3 of this DPA; and either party may end the UK Addendum under Section 19 of the UK Addendum.
B.3 Swiss Modifications to the SCCs. Where Customer Personal Data is transferred from Switzerland and the Swiss FADP applies, the SCCs in Section B.1 apply with the following modifications: references to the GDPR mean the Swiss FADP and applicable Swiss data protection provisions; references to a “Member State” will not be interpreted to exclude Data Subjects in Switzerland from exercising rights in their place of habitual residence; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and the governing law and courts are those of Switzerland, together with any further modifications required under the Swiss FADP or guidance of the Swiss Federal Data Protection and Information Commissioner.
B.4 New Transfer Mechanism. Company may, on notice to Customer, modify this DPA and replace the SCCs, UK Addendum, or Swiss modifications to the SCCs with any new or successor transfer instrument, or with another valid transfer mechanism, in each case to the extent necessary to maintain compliance with Applicable Privacy Law and provided that the replacement does not materially decrease the overall protection of Customer Personal Data.
B.5 Operational Clarifications. For Clause 8.3 of the SCCs, Customer will protect Company’s and its licensors’ trade secrets, business secrets, and confidential information when complying with transparency obligations. For Clause 8.8, any approval by Customer of a Sub-processor under Section 5 (Sub-processors) constitutes Customer’s documented instructions to effect onward transfers to that Sub-processor. Audits under Clauses 8.9(c) and 8.9(d) are governed by Section 12 (Audit Rights). Certification of deletion under Clauses 8.5 and 16(d) will be provided only upon Customer’s written request.
Annex C: US State Privacy Law Addendum
C.1 General and Generic Terms. This Annex C applies to the extent Company Processes Personal Data of residents of US states that have enacted applicable privacy laws, including the CCPA and the other state laws described in Section C.3 (Applicability). In any conflict between this Annex C and the main body of this DPA with respect to US state privacy law compliance, this Annex C controls. The terms “business,” “controller,” “processor,” “commercial purpose,” “sell,” “share,” “service provider,” and “contractor” have the respective meanings given in the applicable US state privacy laws, and “personal information” means Customer Personal Data to the extent it constitutes “personal information,” “personal data,” or a similar term governed by those laws. The parties intend that, with respect to any personal information, Company acts as a service provider, contractor, or processor under the US state privacy laws.
C.2 Service Provider Commitments. Company will not: (a) sell or share Customer Personal Data; (b) engage in cross-context behavioral advertising using Customer Personal Data; (c) retain, use, or disclose Customer Personal Data for any purpose other than performing the Services for Customer under the Agreement, or as otherwise permitted by the applicable US state privacy laws; (d) retain, use, or disclose Customer Personal Data outside the direct business relationship between Company and Customer; or (e) combine Customer Personal Data with personal information received from or on behalf of another person or entity, or collected from Company’s own interactions with consumers, except as permitted under the applicable US state privacy laws. Company will provide the same level of privacy protection as required of businesses or controllers under the applicable US state privacy laws. Company will cooperate with Customer to assist with consumer privacy rights requests by providing technical means to access and delete Customer Personal Data within the Services, as technically feasible; unless required by law, Company will refer such requests to Customer. To the extent Company Processes Sensitive Personal Information (as defined by Applicable Privacy Law) on behalf of Customer, Company will Process it only for the purposes set forth in this DPA and the Agreement and will not use or disclose it to infer characteristics about individuals except as permitted by law. Customer may take reasonable and appropriate steps to help ensure Company’s use of Customer Personal Data is consistent with Customer’s obligations under applicable US state privacy laws. Company will notify Customer if it determines that it can no longer meet its obligations under this Annex C and will cooperate to stop and remediate any unauthorized Processing. Company certifies that it understands the restrictions in this Section C.2 and will comply with them.
C.3 Applicability. This Annex C applies to the CCPA (as amended by the CPRA) and to any other comprehensive US state privacy law applicable to Company’s Processing of Customer Personal Data, in each case to the extent the applicable thresholds are met and as amended or superseded from time to time.