NATURE OF PROCESSING UNDER THE ATDATA SERVICES
AtData processes Client Personal Data in connection with the Services. AtData’s role varies depending on the Service and the type of Client Personal Data: AtData acts as an independent Controller in respect of the SafeToSend Service and the ordinary personal data element of the Fraud Product (Annex A), and as a Processor on Client’s behalf in respect of Fraud Signals processed in connection with the Fraud Product (Annex B). Each Annex is described in further detail below. Capitalised terms used but not defined in this Cover Sheet have the meaning given in Section 1 (Definitions and Interpretation).
- Ordinary personal data – AtData as independent Controller (Annex A). AtData receives ordinary categories of Personal Data from or on behalf of Client (namely IP address, email address, postal address, name, telephone number and any other ordinary personal data processed by Client under this Addendum) and processes them as an independent Controller for the purpose of providing, maintaining, and improving the Services. The processing of these types of personal data is governed by Annex A (Controller-to-Controller Terms).
- Personal data subject to Article 10 GDPR – AtData as Processor (Annex B). This occurs where Client transmits Fraud Signals to AtData (whether directly or on behalf of Client’s own customers) and/or AtData receives, processes and stores Fraud Signals including for the purpose of building, training, refining and applying a fraud detection model dedicated to Client. Fraud Signals concern the commission or alleged commission of criminal offences and/or related security measures, and therefore constitute personal data under Article 10 of the UK GDPR and EU GDPR. As Client is best placed to establish the required Article 10 lawful basis, including any substantial public interest or prevention of fraud condition, AtData processes Fraud Signals strictly as a Processor on Client’s documented instructions and in reliance on Client’s lawful basis. Such processing is governed by Annex B (Controller-to-Processor Terms).
DATA PROCESSING ADDENDUM
This Data Processing Addendum, including any applicable appendices, annexes or exhibits (collectively, this “Addendum“) is entered into between the entity identified as “Client” below (“Client“) and AtData LLC (“AtData“) (each a “Party” and collectively, the “Parties“). This Addendum shall apply to the extent that AtData collects or otherwise processes Client Personal Data in connection with the performance of its obligations or the provision of Services under the Agreement. The Parties agree that this Addendum shall be incorporated by reference into and form an integral part of the Agreement.
1. DEFINITIONS AND INTERPRETATION
For the purposes of this Addendum, the following terms shall have the respective meanings ascribed to them:
- “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party;
- “Agreement” means the agreement between Client and AtData for the provision of the Services by AtData to or on behalf of Client into which this Addendum is incorporated by reference;
- “Applicable Laws” means all data protection and data privacy laws, statutes, directives or regulations that are applicable to the Client Personal Data, or to its processing under the Agreement, including, to the extent applicable, EU Data Protection Laws, U.S. Privacy Laws, and Canadian Privacy Laws, as they may be amended or replaced from time to time;
- “Canadian Privacy Laws” means: (i) the Personal Information Protection and Electronic Documents Act (Canada); (ii) the Personal Information Protection Act (Alberta); (iii) the Personal Information Protection Act (British Columbia); (iv) the Act Respecting the Protection of Personal Information in the Private Sector (Quebec); and (v) any other applicable Canadian federal or provincial private sector privacy law, together with any amendments, rules, and regulations promulgated pursuant to any of the foregoing;
- “Client Personal Data” means any Personal Data made available by or on behalf of Client that is processed by AtData in connection with the Agreement;
- “Data Transfer” means any transfer of Client Personal Data subject to European Data Protection Laws from the European Economic Area, Switzerland or the United Kingdom to countries which do not provide an adequate level of protection for Personal Data, as required by the Applicable Laws of the country of export;
- “Digital Property” means any online or digital property or service (which includes without limitation websites, videos, advertisements, and applications);
- “European Data Protection Laws” means the following laws and regulations, to the extent applicable from time to time: (i) national laws implementing the Directive on Privacy and Electronic Communications (2002/58/EC); (ii) the General Data Protection Regulation 2016/679 (“EU GDPR“) and any national law issued in relation to that Regulation; (iii) the UK Data Protection Act 2018 and the EU GDPR as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of section 3 of the United Kingdom’s European Union (Withdrawal) Act 2018 (“UK GDPR“); (iv) the Swiss Federal Data Protection Act; and (v) any other similar national privacy laws within the European Economic Area, Switzerland and/or the United Kingdom;
- “Fraud Product” means AtData’s fraud prevention product identified as such in the Agreement, together with any related services provided by AtData thereunder;
- “Fraud Signals” means the fraud signals, flags, indicators, categorisations, and other data transmitted by or on behalf of Client to AtData for the purpose of building, training or refining a fraud detection model dedicated to Client, and which identify, characterise, or infer a data subject’s involvement or suspected involvement in fraud;
- “Personal Data” or “Personal Information” means information relating to an identified or identifiable natural person (“data subject” or “consumer“) or that describes, is reasonably capable of being associated with a particular individual, device, or household;
- “Personnel” means employees, contractors, Affiliates, Subcontractors, and other agents;
- “SafeToSend Service” means AtData’s SafeToSend email validation service, together with any related services provided by AtData thereunder;
- “SCCs” means: (i) the standard contractual clauses issued by the European Commission for the transfer of personal data under Commission Implementing Decision (EU) 2021/914/EC of 4 June 2021 (“EU SCCs“); and (ii) the International Data Transfer Addendum to the Standard Contractual Clauses, version B1.0, issued under Section 119A of the Data Protection Act 2018 (“UK Addendum“), in each case, as amended or replaced from time to time;
- “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Client Personal Data transmitted, stored or otherwise processed, and includes terms such as “personal data breach,” “breach of the security of the system,” and similar under Applicable Laws;
- “Sensitive Information“, “Sensitive Data” or “Special Category Data” shall have the meaning as set forth in the Applicable Laws and may include social security numbers; government issued identifiers; financial account information; information about an individual’s mental or physical medical conditions, history, treatment, or diagnoses; precise geolocation; genetic or biometric information; information from a child; ethnicity or race; religious or philosophical beliefs; citizenship or immigration status; national origin; union or trade membership; contents of an individual’s physical mail, email, or text messages; status as a victim of crime; sexual orientation or sexual preferences, including status as transgender or nonbinary; and personal data relating to criminal convictions and offences (including Fraud Signals);
- “Services” means the Fraud Product, the SafeToSend Service and/or products provided by AtData under the Agreement;
- “Subcontractor” means any third party (including AtData’s Affiliate(s)) engaged by AtData to process any Client Personal Data relating to the Agreement (including this Addendum);
- “Tags” means the implementation of Services, or any alternative method(s) implemented by or on behalf of Client on a Digital Property which facilitate the provision of Personal Data of data subjects who are active on that Digital Property to AtData;
- “Third Party” has the meaning provided in the California Consumer Privacy Act and its regulations, each as may be amended or replaced from time to time (“CCPA“); and
- “S. Privacy Laws” means all applicable United States federal and state data protection and privacy laws, rules, and regulations that relate to the collection and processing of Personal Information, including: (i) the California Consumer Privacy Act of 2018, together with any amending or replacing legislation, including the California Privacy Rights Act of 2020; (ii) the Colorado Privacy Act; (iii) the Connecticut Data Privacy Act; (iv) the Delaware Personal Data Privacy Act; (v) the Indiana Consumer Data Protection Act; (vi) the Iowa Consumer Data Protection Act; (vii) the Kentucky Consumer Data Protection Act; (viii) the Maryland Online Data Privacy Act; (ix) the Minnesota Consumer Data Privacy Act; (x) the Montana Consumer Data Privacy Act; (xi) the Nebraska Data Privacy Act; (xii) the New Hampshire Data Privacy Act; (xiii) the New Jersey Data Protection Act; (xiv) the Oregon Consumer Privacy Act; (xv) the Rhode Island Data Transparency and Privacy Protection Act; (xvi) the Tennessee Information Protection Act; (xvii) the Texas Data Privacy and Security Act; (xviii) the Utah Consumer Privacy Act; (xix) the Virginia Consumer Data Protection Act; and (xx) any subsequently enacted privacy law within the United States, together with any amendments, rules, and regulations promulgated pursuant to any of the foregoing.
The terms “Business“, “Business Purpose“, “Consumer“, “Controller“, “Data Subject“, “Processor“, “Process“, “Sale“, “Share“, and “Service Provider” and their conjugations and equivalent terms thereto have the meaning ascribed to such terms in Applicable Laws, provided that, to the extent any such term is not defined under the Canadian Privacy Laws applicable to the Personal Data in question, such term shall have the meaning ascribed to it under the EU Data Protection Laws. Capitalized terms used but not defined herein shall have the meaning ascribed to such terms in the Agreement.
2. ROLES OF THE PARTIES
- Data Processing Roles. The Parties acknowledge and agree that AtData processes Client Personal Data in one or both of two distinct capacities depending on the Service: (i) as an independent Controller or Business in respect of ordinary personal data (including IP address, email address, postal address, name, and telephone number) processed in connection with the Fraud Product and the SafeToSend Service as described in the Cover Sheet and more fully set out in Annex A; and (ii) as a Processor or Service Provider acting on behalf of Client (whether as Controller or Business itself, or as a Processor or Service Provider on behalf of third party Controllers or third party Businesses) in respect of Fraud Signals processed in connection with the Fraud Product only, as more fully set out in Annex B. Each Annex shall apply only to the processing activities within its scope.
- Third Party Relationships Under the CCPA. For those Services in respect of which AtData processes Client Personal Data as an independent Controller under Annex A, including without limitation AtData’s provision of Personal Data to Client in connection with data appending or the implementation of AtData Tags by Client on one or more Digital Properties, the disclosing Party may be considered to be a Third Party under the CCPA with respect to Personal Data provided to the other Party. Terms that apply to Third Party relationships are set forth in Annex A.
- Personnel Personal Data. The Parties shall each be an independent Controller with respect to any Personal Data of a Party’s and its Affiliates’ Personnel (“Personnel Personal Data“) processed by or made available to the other Party hereunder in connection with the business relationship between the Parties, which includes, without limitation, contact details (names, telephone numbers, email addresses, job titles, etc.) of the other Party and its Affiliates and Personnel, both during the term and a reasonable time after the end of the term of the Agreement.
3. GENERAL TERMS (APPLICABLE TO BOTH ANNEXES)
The following terms apply to AtData’s processing of Client Personal Data under both Annex A and Annex B.
- Compliance and Cooperation. Each Party shall comply with Applicable Laws when processing Client Personal Data in connection with the Agreement. A Party shall notify the other Party in writing if it determines that it can no longer meet its obligations under Applicable Laws.
- Client Due Diligence. In order that AtData may meet its obligations under Applicable Law, AtData may, prior to the execution of the Agreement, conduct due diligence on Client to assess Client’s data protection practices and compliance with Applicable Law (the “Initial Due Diligence“). AtData shall have the right to conduct a review and update of the Initial Due Diligence on an annual basis, and Client shall cooperate with any such review and provide AtData with such information and documentation as AtData may reasonably request for that purpose.
- Compliance Audits. In order that AtData may meet its obligations under Applicable Law, AtData shall have the right, exercisable no more than once per calendar year and on reasonable prior notice to Client, to audit (or instruct an authorised third-party representative to audit) Client’s compliance with its obligations under this Addendum (including under Annex A and Annex B), including with respect to its provision of appropriate notice to data subjects, provided that where AtData has reasonable cause to suspect a material breach by Client of its obligations under this Addendum, it may conduct such additional audits as reasonably required. Client shall provide AtData or its duly authorised representatives (as applicable) with access to all relevant records, personnel and systems, as reasonably required to complete such audit and to verify Client’s compliance with its obligations under this Addendum.
- Sensitive Personal Data. Unless otherwise specified in the Agreement or this Addendum, Client shall not share or make available to AtData any Sensitive Data, Sensitive Information or Special Category Data other than the Fraud Signals processed as Processor under Annex B. To the extent AtData shall receive or process any “protected health information” under the U.S. Health Information Portability and Accountability Act and its regulations, as amended (“HIPAA“), Client shall notify AtData in advance of making such Personal Data available to AtData and the Parties shall enter into a business associate agreement that complies with HIPAA in respect of the protected health information.
- Order of Precedence. This Addendum controls and supersedes the Agreement in all respects with respect to any inconsistent or conflicting (directly or indirectly) provision or term, except to the extent the applicable provision or term of the Agreement expressly states that such provision or term supersedes this Addendum. The Annexes to this Addendum shall take precedence over the main body of the Addendum. Notwithstanding any of the foregoing, in the event of a conflict or inconsistency between this Addendum and the SCCs incorporated herein, the SCCs shall control solely to the extent of such conflict or inconsistency and solely with respect to a Data Transfer governed thereby.
- Term. The obligations placed upon the Parties under this Addendum shall survive so long as AtData or its Subcontractors process Client Personal Data.
- Client Customers. If Client uses, obtains, or provides AtData Services for or on behalf of a customer of Client and/or other third party that does not have a direct contractual relationship with AtData with respect to such Services, as between Client and AtData, Client shall be solely responsible for ensuring that all such customers or other third parties comply with Client’s obligations under this Addendum.
- Variation. This Addendum may not be modified except by subsequent written instrument signed by both Parties.
- Invalidity. If any provision in this Addendum shall be held to be illegal, invalid or unenforceable, in whole or in part, the provision shall apply with whatever deletion or modification is necessary so that the provision is legal, valid and enforceable and gives effect to the commercial intention of the Parties.
- Entire Agreement. The Agreement and this Addendum, including any annexes, schedules or exhibits hereto and thereto, which are incorporated herein and therein by reference, constitute the entire agreement between the Parties relating to the subject matter hereof and supersedes and replaces all prior or contemporaneous oral or written agreements and understandings between the Parties in relation to the matters dealt with in the Agreement and this Addendum.
- Counterparts. This Addendum may be executed in any number of counterparts, each of which shall be deemed an original but all of which together shall constitute a single instrument, and may be executed by PDF, facsimile, or otherwise. Any Party may enter into this Addendum by executing any such counterpart.
ANNEX A
CONTROLLER-TO-CONTROLLER TERMS – ORDINARY PERSONAL DATA
This Annex A applies to AtData’s processing of the categories of ordinary personal data described in the Cover Sheet (including IP address, email address, postal address, name and telephone number) in connection with the Services. In respect of such data, each Party processes the other Party’s Personal Data as an independent Controller or Business.
- Details of the Processing. The scope of the processing of Client Personal Data carried out by AtData as an independent Controller in connection with the Agreement is set out in Exhibit A-1 to this Addendum.
- Lawfulness of Client Personal Data. Client shall ensure that all Client Personal Data made available to AtData for processing hereunder is collected lawfully, and that Client has all rights, has provided all notices, has obtained all consents, and has otherwise complied with all requirements under Applicable Law necessary for AtData’s processing of the Client Personal Data as described in the Agreement and this Addendum. Without limiting the foregoing, Client shall provide data subjects with all information required under Applicable Law in respect of AtData’s processing of Client Personal Data (including in accordance with Articles 13 and 14 of the EU GDPR and UK GDPR, as applicable). Such notice shall, at a minimum:
- disclose AtData by name and that it will receive and process Personal Data of the data subject and describe how AtData will process that Personal Data in connection with its provision of the Services (including that AtData may retain the email address and other ordinary categories of Personal Data of the data subject for the purpose of monitoring and analysing trends in domain activity, maintaining and improving the Fraud Product (if applicable), and providing services like the Services to third parties);
- include a link to AtData’s privacy notice; and
- where the Services provided under the Agreement include the SafeToSend Service, disclose that:
- where Client elects not to use the “no logging” service, AtData will retain details of the email address submitted for validation in its validation cache for a period of up to 90 days from the date of submission to avoid repeated validation of the same email address by other organisations that the data subject interacts with; and
- where a data subject has registered a complaint in respect of its receipt of marketing communications, Client may notify AtData of that fact and AtData may incorporate that information into a suppression list which it makes available to other AtData clients for the purpose of assisting those clients to honour opt-out requests and manage complaints in connection with their email marketing activities.
- Information Security Practices. AtData shall implement and maintain appropriate physical, technical and organizational measures designed to protect Client Personal Data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access and ensure a level of confidentiality and security appropriate to the risks presented by the processing and the nature of the Client Personal Data (including the sensitivity of the Client Personal Data), taking into account the state of the art and the costs of implementation. Without limiting the generality of the foregoing, such measures shall include those security measures described in Exhibit C. Client agrees that AtData may, upon Client’s reasonable request, provide Client with the results or a summary thereof of any audit performed by a third party assessor on behalf of AtData pursuant to an established and accepted audit standard or framework, such as and without limitation ISO 27001, that assesses the effectiveness of AtData’s information security program as relevant to the security and confidentiality of Client Personal Data disclosed during the course of the Agreement (“AtData Assessment“). Any such AtData Assessments shall be conducted at Client’s sole expense and not more frequently than annually.
- Security Incident Notice.
- AtData agrees to notify Client without undue delay where AtData becomes aware of a Security Incident that has occurred and shall take reasonable steps to remediate and mitigate the impact of any such Security Incident.
- If reasonably requested by Client, AtData shall reasonably cooperate with Client, at Client’s sole expense, to: (i) determine the scope and severity of any such Security Incident; (ii) respond to and remediate the Security Incident; and (iii) provide timely information and cooperation as Client may require to fulfill Client’s Security Incident reporting obligations under Applicable Laws.
- Third Parties under the CCPA. To the extent the CCPA applies to this Addendum and Personal Information subject to the CCPA is Sold or Shared by or on behalf of one Party (the “Disclosing Party“) to the other, the Party to which the Personal Information is Sold or Shared is a Third Party (the “Receiving Party“). The Business Purposes for which Personal Information is Sold or Shared to the Third Party under the CCPA are specified in Exhibit A-1, and the Third Party may process such Personal Information only for those limited and specified purposes or as otherwise permitted by Applicable Law. The Disclosing Party may take reasonable and appropriate steps to (i) ensure that the Third Party uses the Personal Information consistent with the Agreement, this Addendum, and Applicable Laws and (ii) stop and remediate unauthorized processing of Personal Information. The Parties agree to negotiate in good faith to determine what steps are reasonable and appropriate with respect to the foregoing sentence. The Receiving Party shall comply with all Applicable Laws, including the CCPA, and shall provide the same level of privacy protection as required of the Disclosing Party.
Where a Third Party is authorized to collect Personal Information from a Digital Property, such as through Tags, the Third Party shall check for a data subject’s opt-out preference signal and shall comply with such signal to the extent that the signal is successfully received, provided that the Third Party is not required to check for and comply with such signals if the Third Party is informed by the Disclosing Party that the consumer has consented to the Sale or Sharing of Personal Information about them. The Third Party shall not be responsible for compliance with any opt-out preference signal unless the Disclosing Party has specified, in advance and in writing, the specific signal(s) to be transmitted and the Third Party has confirmed, in writing, its ability to receive and comply with such signal(s).
- Data Transfers Under European Data Protection Laws.
- To the extent that a Party conducts a Data Transfer in respect of Client Personal Data processed under this Annex A, the Parties shall be deemed to have entered into, and shall comply with, the SCCs set out in this section.
- EU SCCs. The Parties agree that for Data Transfers from the European Economic Area, Module One (Controller to Controller) of the EU SCCs is hereby incorporated into this Addendum and shall be deemed to be completed as follows:
- Part A of Annex I (List of Parties) shall be completed by inserting the names and addresses of the Parties set out in the Agreement;
- Part B of Annex I (Description of Transfer) shall be completed by inserting the relevant details from the Agreement to which the transfer relates;
- Part C of Annex I (Competent Supervisory Authority) shall be completed by inserting the relevant details of the relevant regulatory authority for the place of establishment of the data exporter;
- Annex II (Technical and Organizational Measures Including Technical and Organizational Measures to Ensure the Security of Data) shall be completed by inserting the relevant details of the technical and organizational measures as identified in Exhibit C of this Addendum;
- In Clause 7 (Docking Clause) – the optional provision shall apply;
- In Clause 11 (Redress) – the optional provision shall not apply;
- In Clause 13 (Supervision) – the applicable wording (as determined by the instructions in square brackets in that clause) listed first is retained and the two remaining alternatives deleted;
- In Clause 17 (Governing Law) – Option 1 shall apply, and the laws of Ireland shall govern; and
- In Clause 18 (Choice of forum and jurisdiction) – the courts of Ireland shall have jurisdiction.
- UK Addendum. The Parties agree that for Data Transfers from the United Kingdom, the UK Addendum is hereby incorporated into this Addendum and shall be deemed to be completed as follows:
- The signatures of each Party are deemed to be inserted;
- Table 1 of the UK Addendum shall be completed by inserting the start date as the date of the Agreement, and the details of the relevant data exporter and data importer shall be completed by inserting the names and addresses of the Parties set out in the Agreement;
- Table 2 of the UK Addendum is deemed completed by selecting the second option and shall be completed by inserting the information about the EU SCCs set out in this Annex A;
- Table 3 of the UK Addendum shall be completed by inserting the information about the EU SCCs set out in this Annex A; and
- Table 4 of the UK Addendum shall be completed by selecting: (i) “Importer” where AtData is the data importer; and (ii) “Exporter” where AtData is the data exporter.
- Swiss Data Transfers. The Parties agree that for Data Transfers from Switzerland, the terms of the EU SCCs shall apply, are hereby incorporated by reference and shall be amended and supplemented as specified by the relevant guidance of the Swiss Federal Data Protection and Information Commissioner, and the competent supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner.
ANNEX B
CONTROLLER-TO-PROCESSOR TERMS – FRAUD SIGNALS SUBJECT TO ARTICLE 10 GDPR
This Annex B applies to AtData’s processing of Fraud Signals in connection with the Fraud Product, and to any other Client Personal Data processed by AtData as a Processor under the Fraud Product. AtData processes such data as a Processor or Service Provider acting on behalf of Client (whether as Controller or Business itself, or as a Processor or Service Provider on behalf of third party Controllers or third party Businesses). References to “Fraud Signals” in this Annex B shall be read to include such other Client Personal Data where the context requires.
- Details of the Processing. The scope of the processing of Fraud Signals carried out by AtData as a Processor in connection with the Agreement is set out in Exhibit B-1 to this Addendum.
- Lawfulness of Client Personal Data. Client shall ensure that all Client Personal Data made available to AtData for processing hereunder is collected lawfully, and that Client has all rights, has provided all notices, has obtained all consents, and has otherwise complied with all requirements under Applicable Law necessary for AtData’s processing of the Client Personal Data as described in the Agreement and this Addendum. Without limiting the foregoing, Client shall provide data subjects with all information required under Applicable Law in respect of AtData’s processing of Client Personal Data (including in accordance with Articles 13 and 14 of the EU GDPR and UK GDPR, as applicable). Such notice shall, at a minimum:
- disclose AtData by name, and that it will receive and process the Fraud Signals transmitted by or on behalf of Client (together with any associated identifiers, including email addresses), and describe how AtData will process those Fraud Signals in connection with AtData’s provision of the Fraud Product; and
- include a link to AtData’s privacy notice.
- Obligations of Client. As between Client and AtData, Client shall determine the purposes for, and the manner in which, Fraud Signals are processed with respect to the Services, as set forth in the Agreement and this Addendum. Client shall ensure that all Instructions (as defined below) for the processing of Fraud Signals comply with Applicable Laws, and in particular that Client has established and maintains a valid lawful basis under Article 6 and Article 10 of the UK GDPR and EU GDPR (and equivalent provisions under other Applicable Laws), including any substantial public interest or prevention of fraud condition, on which AtData is entitled to rely for its processing as Processor.
- Limitations on Processing.
- AtData shall only process Fraud Signals in accordance with Client’s written instructions, which shall be consistent with the Agreement, this Addendum, and Applicable Law and shall include AtData’s performance of its obligations and provision of the Services under the Agreement (“Instructions“), unless AtData is required to process such Fraud Signals for other purposes in accordance with Applicable Laws, including U.S. Privacy Laws and European Data Protection Laws (to the extent the Fraud Signals originate in the EEA, UK or Switzerland) or in accordance with Applicable Laws in another jurisdiction, to the extent the Fraud Signals originated in that other jurisdiction. Where AtData is required to process such Fraud Signals to comply with S. Privacy Laws or European Data Protection Laws (or, where relevant, other Applicable Laws), AtData shall notify Client prior to such processing, unless prohibited by Applicable Laws on important grounds of public interest.
- AtData shall notify Client in the event it becomes aware that any Instructions violate Applicable Laws, provided that the foregoing shall not create an affirmative duty on AtData to monitor such Instructions for compliance with Applicable Laws.
- AtData shall not: (1) collect, retain, use, disclose, or otherwise Process Fraud Signals outside of the direct business relationship with Client; (2) Sell or Share Fraud Signals; (3) combine Fraud Signals received from Client with Personal Data received from another person or persons except as permitted of a Processor under Applicable Laws; or (4) use Fraud Signals to train, develop or improve any AtData machine learning or artificial intelligence model, algorithm, product or service, except in accordance with Client’s Instructions.
- Information Security Practices. AtData shall implement and maintain appropriate physical, technical and organizational measures designed to protect Client Personal Data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access and ensure a level of confidentiality and security appropriate to the risks presented by the processing and the nature of the Client Personal Data (including the sensitivity of the Client Personal Data), taking into account the state of the art and the costs of implementation. Without limiting the generality of the foregoing, such measures shall include those security measures described in Exhibit C.
- Assistance With Data Subject Requests. If requested by Client, and at Client’s expense, AtData shall reasonably assist Client, taking into account the nature of the processing and the information available to AtData, in:
- responding to requests from or on behalf of a data subject to exercise their rights under Applicable Laws in respect of Fraud Signals (“Data Subject Requests“). AtData shall also notify Client of any Data Subject Requests received from or on behalf of a data subject in respect of Fraud Signals; and
- conducting privacy impact assessments (and any related consultations) where required under Applicable Law.
- Audit and Assessment.
- Client shall have the right, and AtData shall permit Client, to take reasonable steps to ensure that any Fraud Signals are used in accordance with AtData’s obligations under Applicable Laws.
- Client agrees that AtData may, upon Client’s reasonable request, provide Client with the results or a summary thereof of any audit performed by a third party assessor on behalf of AtData pursuant to an established and accepted audit standard or framework, such as and without limitation ISO 27001, that assesses the effectiveness of AtData’s information security program as relevant to the security and confidentiality of Fraud Signals disclosed during the course of the Agreement (“AtData Assessment“). Any such AtData Assessments shall be conducted at AtData’s sole expense and not more frequently than annually. If AtData conducts an AtData Assessment and provides results thereof to Client, AtData shall not be required to submit to a Client Assessment (as defined below) except where and to the extent expressly required by Applicable Law.
- Subject to the foregoing, upon ten (10) business day advance written notice by Client, AtData shall grant Client (or its appointed representatives) permission to perform an assessment, audit, examination or review (collectively, “Client Assessment“) of AtData’s compliance with this Annex B. AtData shall reasonably cooperate with such Client Assessment by providing reasonable access to knowledgeable personnel, physical premises, documentation, infrastructure and application software that processes, stores or transfers Fraud Signals pursuant to the Agreement. Any such Client Assessment shall be conducted not more than once per calendar year, during AtData’s regular business hours at AtData’s offices and in such a manner as not to interfere unreasonably with AtData’s normal business activities. The costs of any and all Client Assessment(s) shall be borne by Client.
- Subcontractors.
- Upon written request by Client, AtData shall provide an up-to-date list of all Subcontractors, including where those Subcontractors are located.
- AtData provides a general authorization to Client to add or replace a Subcontractor. AtData shall notify Client prior to such addition or replacement, and Client shall have ten (10) business days from the date of provision of such notice to object to the engagement of the Subcontractor, and any such objection shall be in good faith and only on reasonable grounds relating to data protection. In the event Client so objects, Client and AtData shall use reasonable efforts to resolve the objection and/or identify alternative processing mechanisms as well as any costs to be borne by one or both Parties with respect thereto.
- AtData agrees that Subcontractors shall be engaged pursuant to written agreements that include substantially the same data protection obligations as set out in this Annex B. Subject to the limitations and waivers of liability in the Agreement, AtData shall remain liable for the acts and omissions of its Subcontractors in connection with the processing of Fraud Signals as if they were AtData’s own acts and omissions.
- Security Incident Notice.
- AtData agrees to notify Client without undue delay where AtData becomes aware of a Security Incident that has occurred and shall take reasonable steps to remediate and mitigate the impact of any such Security Incident.
- If reasonably requested by Client, AtData shall reasonably cooperate with Client, at Client’s sole expense, to: (1) determine the scope and severity of any such Security Incident; (2) respond to and remediate the Security Incident; and (3) provide timely information and cooperation as Client may require to fulfill Client’s Security Incident reporting obligations under Applicable Laws.
- Unless AtData is required to give such notice under Applicable Laws, AtData shall not give notice of a Security Incident involving Client Personal Data to data subjects or government authorities unless requested to do so by Client.
- Processor Data Transfers Under European Data Protection Laws.
- To the extent that a Party conducts a Data Transfer, the Parties shall be deemed to have entered into, and shall comply with, the SCCs set out in this section.
- EU SCCs. The Parties agree that for Data Transfers from the European Economic Area, Module Two (Controller to Processor) and/or Module Three (Processor to Processor) of the EU SCCs (as applicable) are hereby incorporated into this Addendum and shall be deemed to be completed as follows:
- Part A of Annex I (List of Parties) shall be completed by inserting the names and addresses of the Parties set out in the Agreement;
- Part B of Annex I (Description of Transfer) shall be completed by inserting the relevant details from the Agreement to which the transfer relates;
- Part C of Annex I (Competent Supervisory Authority) shall be completed by inserting the relevant details of the relevant regulatory authority for the place of establishment of the data exporter;
- Annex II (Technical and Organizational Measures Including Technical and Organizational Measures to Ensure the Security of Data) shall be completed by inserting the relevant details of the technical and organizational measures as identified in Exhibit C of this Addendum;
- In Clause 7 (Docking Clause) – the optional provision shall apply;
- In Clause 9(a) (Use of sub-processors) – Option 2 shall apply, and the data exporter shall have a period of ten (10) business days to object to such Subcontractor;
- In Clause 11 (Redress) – the optional provision shall not apply;
- In Clause 13 (Supervision) – the applicable wording (as determined by the instructions in square brackets in that clause) listed first is retained and the two remaining alternatives deleted;
- In Clause 17 (Governing Law) – Option 1 shall apply, and the laws of Ireland shall govern; and
- In Clause 18 (Choice of forum and jurisdiction) – the courts of Ireland shall have jurisdiction.
- UK Addendum. The Parties agree that for Data Transfers from the United Kingdom, the UK Addendum is hereby incorporated into this Addendum and shall be deemed to be completed as follows:
- The signatures of each Party are deemed to be inserted;
- Table 1 of the UK Addendum shall be completed by inserting the start date as the date of this Agreement, and the details of the relevant data exporter and data importer shall be completed by inserting the names and addresses of the Parties set out in the Agreement;
- Table 2 of the UK Addendum is deemed completed by selecting the second option and shall be completed by inserting the information about the EU SCCs set out in this Annex B;
- Table 3 of the UK Addendum shall be completed by inserting the information about the EU SCCs set out in this Annex B; and
- Table 4 of the UK Addendum shall be completed by selecting “Importer”.
- Swiss Data Transfers. The Parties agree that for Data Transfers from Switzerland, the terms of the EU SCCs shall apply, are hereby incorporated by reference and shall be amended and supplemented as specified by the relevant guidance of the Swiss Federal Data Protection and Information Commissioner, and the competent supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner.
- Return and Deletion.
- Upon termination or expiration of the Agreement, AtData shall, at Client’s election: (1) render all or part of the Fraud Signals anonymous in such a manner that the data no longer constitutes Personal Data; (2) return the Fraud Signals to Client; and/or (3) permanently delete the Fraud Signals.
- Notwithstanding the foregoing, AtData may retain Fraud Signals as required to comply with legal obligations, provided that AtData only processes the Fraud Signals for the purposes for which they are required to be retained and deletes or deidentifies the Fraud Signals once it is no longer required to be retained.
EXHIBIT A-1 TO ANNEX A
DESCRIPTION OF DATA PROCESSING – ORDINARY PERSONAL DATA (CONTROLLER)
The data processing activities carried out by AtData as an independent Controller under Annex A are as follows:
- Categories of data subjects whose personal data is transferred/processed:
Those individuals whose contact details are provided by AtData’s customers from time to time.
- Personal Data transferred/processed:
IP address, email address, postal address, name, telephone number, reference ID, and user agent.
- Sensitive data transferred/processed (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
Not applicable.
- Nature of the processing:
Collection, use, analysis, appending, comparison, correction, disclosure and other processing required to deliver the Services or otherwise permitted under the Agreement.
- Purpose of the data transfer and further processing:
As set forth in the Agreement:
- Fraud Product analysis of ordinary Personal Data to generate insights and outputs that are not themselves subject to Article 10 of the UK GDPR or EU GDPR;
- Email validation whereby email addresses are determined to be deliverable or not;
- Data appending, in which Client provides Client Personal Data to AtData and AtData provides additional Personal Data and metadata associated with the provided Client Personal Data to Client;
- The provision of other Services as provided in the Agreement; and
- Developing, administering, and maintaining the relationship between the Parties, including without limitation performing under the Agreement, exercising rights and obligations under the Agreement, and providing, marketing, and receiving products, services, and support.
- The period for which the personal data will be retained, or if that is not possible, the criteria used to determine that period:
For the duration of the Agreement.
- For transfers to (sub-)processors, also specify subject matter, nature, and duration of the processing:
The same as set forth in this Exhibit A-1 for AtData’s processing.
EXHIBIT B-1 TO ANNEX B
DESCRIPTION OF DATA PROCESSING – FRAUD SIGNALS (PROCESSOR)
The data processing activities carried out by AtData as a Processor under Annex B are as follows:
- Categories of data subjects whose personal data is transferred/processed:
Individuals about whom Client transmits Fraud Signals or submits query data to AtData in connection with a Client-dedicated fraud detection model (each a “Custom Fraud Model”), typically including Client’s customers, applicants and other individuals whose activity Client is assessing for fraud.
- Personal Data transferred/processed:
Name, Postal Address, Email Address, Telephone Number, and IP Address. Fraud Signals or status, including Confirmed Fraud, Rejected Suspected Fraud, Not Fraud/Good.
- Sensitive data transferred/processed (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
As set out above, Fraud Signals.
- Nature of the processing:
Receipt, storage, use, analysis, appending, comparison, correction, disclosure and other processing required to deliver the Services or otherwise permitted under the Agreement.
- Purpose of the data transfer and further processing:
As set forth in the Agreement:
- Building, training and refining Custom Fraud Models dedicated to Client;
- Applying Custom Fraud Models to query data (including email addresses and other identifiers) submitted by or on behalf of Client through the Fraud Product, and returning the resulting fraud indicators or assessments to Client;
- Storing Fraud Signals within Client’s dedicated dataset within AtData’s systems; and
- Any other processing of Fraud Signals necessary to provide the Fraud Product to Client in accordance with the Agreement.
- The period for which the personal data will be retained, or if that is not possible, the criteria used to determine that period:
For the duration of the Agreement.
- For transfers to (sub-)processors, also specify subject matter, nature, and duration of the processing:
The same as set forth in this Exhibit B-1 for AtData’s processing.
EXHIBIT C
Technical and Organizational Measures Designed to Ensure the Security of Personal Data
The purpose of this Information Security Exhibit is to set forth the terms and conditions governing the handling, use, access, processing, and storage of Client Materials between Client and AtData. This Exhibit delineates the specific responsibilities and obligations of AtData under the Agreement.
- For the purposes of this Exhibit C, the following terms shall have the following meaning:
- AtData Security Breach means any actual unauthorized access to or use of the Client Personal Data in the possession or control of AtData or its agent.
- Client Materials means Client Data, software, and any materials, documentation, processes, models, reports, technologies, methodologies, or other items developed, provided and/or licensed by Client to AtData in connection with the Agreement, excluding AtData’s data.
- Information Security Program means a comprehensive set of policies, procedures, and documentation regarding systems designed to protect the confidentiality, integrity, and availability of Client Materials from unauthorized access, disclosure, alteration, or destruction.
- Information Security Program Requirement:
AtData must maintain an Information Security Program that adheres to an industry-recognized framework, such as ISO/IEC 27001, or the NIST Cybersecurity Framework, and any Applicable Laws, and that adequately protects Client Materials. This Information Security Program must: (i) protect the security and confidentiality of the Client Materials; (ii) protect against anticipated threats or hazards to the security or integrity of the Client Materials; (iii) protect against unauthorized access or use of the Client Materials that could cause significant harm or inconvenience to Client; and (iv) ensure the ongoing effectiveness of controls.
AtData’s Information Security Program will include as a minimum:
- Training and Awareness. AtData shall require all personnel to participate in information security training and awareness sessions at least annually, and track completion of training for all personnel.
- Identification, Authentication and Authorization. Each user of any device will have a uniquely assigned user ID and password to enable individual authentication, and such ID will remain confidential and be removed promptly upon termination or transfer of the individual. Authentication mechanisms will be designed to protect user accounts from known attack methods. Appropriate level of authentication implemented shall be proportionate to the sensitivity of the data. Authorized personnel, including but not limited to privileged users, shall only have the level of access required to perform their job functions. All remote and wireless access to Client Data or Devices will use a multi-factor authentication process prior to being allowed connection to AtData’s network. AtData will maintain controls designed to provide adequate segregation of duties among personnel, including access to systems and networks.
- Network Security and Encryption. AtData will safeguard the confidentiality and integrity of all Client Data being transmitted over any form of data network and maintain strong, industry-standard encryption techniques for all cases in which Client Data is transmitted over any public data network. AtData’s Internet connections will be protected with dedicated, industry-recognized firewalls that are configured and managed consistent with industry standards. AtData shall not make any internal or private Internet Protocol (IP) address publicly available or natively routed to the Internet.
- Vulnerability Management. AtData shall implement controls designed to protect against malicious code and/or malware, and to prevent transferring malicious code to Client’s systems. AtData will use security measures to protect Devices that house Client Data to reduce the risk of infiltration, hacking, and access penetration by or exposure to an unauthorized third party. All Devices will be kept current with appropriate security-specific system patches. AtData will perform or require the performance of penetration tests in accordance with AtData policies and common industry practice to detect any vulnerabilities. Identified vulnerabilities will be remediated based on risk.
- Intrusion, Detection and Prevention. AtData will use security measures to protect telecommunications system(s) and any Device used to reduce the risk of infiltration, hacking, access penetration by or exposure to a third party.
- Physical Security. Client Materials will be stored only in physically secure locations.
- Logging and Monitoring. AtData will keep audit logs that capture access to Client Data, new user adds, attempts to change security configurations, system start up, back up and shut down, and invalid login attempts. Audit logs will be retained by AtData in a protected state for a period consistent with common industry practice, with processes in place to review periodically to detect intrusions, unauthorized access, unintended activities, malicious software or attempts of these or other actions that could compromise the security of systems processing Client Data.
- Security Incidents Monitoring and Management. AtData will establish processes and procedures for identifying and responding to security violations and unusual or suspicious events and incidents to limit and mitigate damage to information assets and to permit identification and prosecution of violators. These processes and procedures will include the ability to collect, analyze, and preserve evidence in a forensically sound manner to support criminal proceedings if required.
- Information Stewardship and Segregation:
AtData must logically or physically segregate Client Data from other information, so it can be easily identified.
- AtData Security Breaches:
If there is an AtData Security Breach, AtData must notify Client within 24 hours after becoming aware of the AtData Security Breach to Client’s designated contact as specified in the Agreement, unless law enforcement or legal authorities restrict such notification. AtData must also:
- Investigate the AtData Security Breach and provide Client with relevant information about it; and
- Take commercially reasonable steps to mitigate and minimize the damage from the AtData Security Breach.
- Law Enforcement Requests:
If AtData receives a request from law enforcement or a government authority for personal data provided by Client, AtData must attempt to redirect the authority to Client. AtData may provide Client’s contact details to the authority for this purpose. If AtData is legally required to disclose such personal information, it must notify Client before doing so, or as soon as reasonably possible afterward if prior notification is prohibited.
- Right to Audit:
In addition to other audit rights in the Agreement, Client may audit AtData’s Information Security Program. Client or its designated third party may perform the audit with reasonable advance notice, no more than once annually, unless there is a reasonable belief that AtData has materially failed to comply with the Agreement. The audit will be subject to AtData’s confidentiality agreement.
- Remediation:
If an audit reveals that AtData is not materially complying with the Agreement, AtData must promptly address the non-compliance and provide evidence of remediation to Client. AtData must also use commercially reasonable efforts to fix any errors or material control deficiencies identified in the audit.