Third Party Index

Snapshot 12274

Document
Data processing addendum
URL
https://www.mis-sciences.com/_files/ugd/9142b7_003677d67e004387b3b73253d5f55b8c.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
123731 bytes
SHA-256 (raw)
fa9fbce4953276c3b5b383b6afd4d5705c60a84148e797c83afcc68d7f7b0e25
SHA-256 (normalized text)
e171426f872e86435e6e145c5cbf4e9991c3024f074d5e8b894c110c6a028246

Normalized text

Scripts and page chrome removed; this is what change detection compares.

                             MIS SCIENCES CORPORATION
                                             Cloud Services
          Data Processing Addendum (Appendix A to the Master Services Agreement)

This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Master
Services Agreement (“MSA”) between MIS Sciences Corporation (“MIS”) and the Client (as
defined in the MSA), and is the document referenced as Appendix A to the MSA. This DPA
governs the Processing of Personal Information and the handling of Security Incidents in
connection with the Services. Capitalized terms used but not defined in this DPA have the
meanings given to them in the MSA. In the event of a conflict between this DPA and the remainder
of the MSA with respect to the Processing of Personal Information or data protection, this DPA
controls, consistent with the MSA’s order of precedence.

1. Definitions
“Applicable Data Protection Laws” means all laws and regulations applicable to the Processing
of Personal Information under the MSA, including the California Consumer Privacy Act, Cal. Civ.
Code §1798.100 et seq., as amended by the California Privacy Rights Act (“CCPA/CPRA”), and,
to the extent applicable, other U.S. state privacy laws and the federal requirements applicable to
the Services.
“Authorization Boundary” means the FedRAMP authorization boundary of the GovPoint Cloud
Services (GCS), comprising the information-system components, services, and interconnections
covered by the GCS JAB P-ATO (Package ID: F1311222650), as documented in the GCS System
Security Plan (SSP).
“Controller” means the Party that determines the purposes and means of the Processing of
Personal Information; and “Processor” means the Party that Processes Personal Information on
behalf of the Controller. For purposes of the CCPA/CPRA, “Business,” “Service Provider,”
“Consumer,” “Personal Information,” “Sell,” and “Share” have the meanings given in that statute.
“Federal Data” means Client Content that constitutes United States federal government
information or that is Processed on behalf of a United States federal agency within the
Authorization Boundary.
“Personal Information” means, for purposes of this DPA, PII (as defined in the MSA) and any
“personal information” within the meaning of the CCPA/CPRA that is contained in Client Content
and Processed by MIS on behalf of Client.
“Processing” means any operation performed on Personal Information, whether or not by
automated means, including collection, recording, organization, structuring, storage, adaptation,
retrieval, use, disclosure, transmission, erasure, or destruction. “Process” and “Processed” have
corresponding meanings.
“Security Incident” means a confirmed or reasonably suspected breach of security leading to
the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized
access to, Client Content or Personal Information Processed by MIS, or any event affecting the
confidentiality, integrity, or availability of Client Content within the Authorization Boundary. A
Security Incident does not include unsuccessful attempts or activities that do not compromise the
security of Client Content, such as pings, port scans, denial-of-service attempts that do not result
in a compromise, or similar events.
“Sub-processor” means any Third Party engaged by MIS to Process Personal Information in
connection with the Services.

    MIS Cloud Services — Data Processing Addendum (Appendix A) | Revision 1.5 | Janurary 27, 2026 | Page 1 of 7
The terms “Client Content," “End User," “PII," “Services,” and “SOW” have the meanings given in
the MSA.

2. Roles and Scope of Processing
Between the Parties, Client is the Controller (and, under the CCPA/CPRA, the Business), and
MIS is the Processor (and, under the CCPA/CPRA, the Service Provider) with respect to the
Processing of Personal Information under the MSA. Where Client itself acts as a processor or
service provider to a United States federal agency or other third party, MIS Processes the
applicable Federal Data on Client’s behalf as Client’s downstream processor, and the relevant
agency or third party remains the owner or controller of that Federal Data. The subject matter,
duration, nature, and purpose of the Processing, the types of Personal Information, and the
categories of data subjects are described in Annex 1.
MIS provides only infrastructure-as-a-service (IaaS). The Client retains sole control of, and is
solely responsible for, Client Content — including its content, accuracy, classification, encryption,
configuration, lawful basis, and use, and the management of access to it by the Client’s personnel
and End Users. MIS does not determine the purposes or means of Processing the contents of
Client Content; the Client alone determines what data it places on the Services and how that data
is used. This allocation is consistent with the Client’s responsibilities under Section 7.2 of the
MSA.
MIS does not access, view, or use the contents of Client Content except as strictly necessary to
provide, operate, maintain, secure, and (where contracted) back up the infrastructure, to comply
with applicable law, or as instructed by the Client. MIS personnel are not authorized to access the
contents of Client Content for any other purpose. Such access as is technically necessary to
operate the infrastructure is restricted to authorized personnel on a need-to-know basis and is
logged, consistent with the access-control and audit controls (NIST SP 800-53 Rev. 5 AC and AU
families) documented in the GCS SSP.

3. Processing Instructions
MIS shall Process Personal Information only on documented instructions from Client, including
with regard to transfers, unless required to Process by applicable law to which MIS is subject (in
which case MIS shall inform Client of that legal requirement before Processing, unless that law
prohibits such notice on important grounds of public interest). The MSA, the applicable SOW(s),
and this DPA, together with Client’s configuration and use of the Services, constitute Client’s
documented instructions. Consistent with Section 2, MIS’s access to Client Content is limited to
that necessary to operate and secure the infrastructure and to act on Client’s instructions. MIS
shall promptly notify Client if, in MIS’s reasonable opinion, an instruction infringes Applicable Data
Protection Laws.

4. Service Provider / Processor Obligations (CCPA/CPRA)
MIS, acting as a Service Provider, certifies that it understands and will comply with the following
restrictions, and shall provide at least the same level of privacy protection as is required of
Businesses by the CCPA/CPRA:
   • MIS shall not sell or share Personal Information received from Client.
   • MIS shall not retain, use, or disclose Personal Information for any purpose other than the
      business purpose of performing the Services specified in the MSA, including retaining,

    MIS Cloud Services — Data Processing Addendum (Appendix A) | Revision 1.5 | Janurary 27, 2026 | Page 2 of 7
      using, or disclosing Personal Information for a commercial purpose other than providing
      the Services.
   • MIS shall not retain, use, or disclose Personal Information outside the direct business
      relationship between MIS and Client.
   • MIS shall not combine Personal Information received from or on behalf of Client with
      Personal Information received from or collected through MIS’s interactions with individuals
      other than Client, except as permitted under Cal. Civ. Code §1798.140(ag).
   • MIS shall notify Client promptly if it determines that it can no longer meet its obligations
      under the CCPA/CPRA, and Client may, upon reasonable notice, take reasonable and
      appropriate steps to stop and remediate unauthorized use of Personal Information.
MIS shall ensure that any person authorized to Process Personal Information is bound by
appropriate obligations of confidentiality, whether by contract or statutory duty.

5. Confidentiality and Personnel
MIS shall limit access to Personal Information to personnel who require access to perform the
Services on a need-to-know basis. MIS personnel with access to Federal Data shall be United
States persons and shall have undergone background checks consistent with Section 8.2 of the
MSA and applicable FedRAMP and agency requirements. MIS shall ensure that such personnel
are subject to confidentiality obligations and appropriate security and privacy training.

6. Security Measures
MIS shall implement and maintain appropriate technical and organizational measures to protect
Personal Information and Client Content against a Security Incident, consistent with FedRAMP
Moderate requirements and the security controls of NIST SP 800-53 Rev. 5 as documented in
the GCS SSP, and at a level no less protective than that required to maintain the GCS JAB P-
ATO. A summary of these measures is set out in Annex 2. MIS shall maintain its Authority to
Operate and continuous-monitoring program throughout the Term and shall not materially
diminish the security of the Services during the Term.

7. Sub-processors
MIS does not engage Sub-processors to Process Personal Information in connection with the
Services. MIS’s data center providers furnish physical colocation only — namely, space, power,
cooling, and physical security for MIS-owned and MIS-operated equipment — and do not access,
Process, or otherwise handle Client Content or Personal Information. Accordingly, such providers
are physical-infrastructure providers and are not Sub-processors. The physical and environmental
protections afforded by these facilities are addressed as part of MIS’s security controls under
Section 6 and Annex 2 (NIST SP 800-53 Rev. 5 PE family).
If MIS elects in the future to engage a Sub-processor to Process Personal Information, MIS shall
first update Annex 3 and shall: (a) provide Client at least 30 days’ advance written notice of the
addition involving infrastructure, hosting, or security services, consistent with Section 12.10 of the
MSA; (b) ensure that any Sub-processor supplying services within the Authorization Boundary
itself holds a current FedRAMP authorization at or above the Moderate impact level; (c) impose
on each Sub-processor, by written contract, data-protection and security obligations no less
protective than those in this DPA; and (d) remain responsible for the acts and omissions of its
Sub-processors to the same extent MIS would be responsible if performing the services directly.
Client may object in writing to a proposed Sub-processor on reasonable data-protection grounds

    MIS Cloud Services — Data Processing Addendum (Appendix A) | Revision 1.5 | Janurary 27, 2026 | Page 3 of 7
within the notice period, and the Parties shall work in good faith to resolve the objection; if they
cannot, Client may terminate the affected Services as provided in the MSA.

8. Security Incidents
MIS shall notify Client of any Security Incident affecting Client Content or the Authorization
Boundary in accordance with the timelines and procedures set forth in Section 8.4 of the MSA,
namely: (a) initial notification within one (1) hour of MIS becoming aware of the Security Incident;
(b) a written incident report within 24 hours of the initial notification; (c) simultaneous notification
to the applicable Authorizing Official and submission of required reports to the FedRAMP Program
Management Office (PMO) and US-CERT in accordance with FedRAMP Incident Communication
Procedures and NIST SP 800-61; and (d) status updates at intervals no greater than 24 hours
until the Security Incident is fully remediated and a final post-incident report is delivered. MIS shall
take reasonable steps to contain, investigate, and mitigate the Security Incident, and shall
reasonably cooperate with Client in meeting Client’s and any federal agency’s own notification
obligations. Costs associated with incident response shall be allocated as provided in Section 8.4
of the MSA. Client shall likewise notify MIS, within the same timelines, of any Security Incident
originating from Client’s systems, personnel, or End Users that affects or may affect the
Authorization Boundary.

9. Assistance to Client
Taking into account the nature of the Processing and the information available to MIS, MIS shall
provide Client reasonable assistance with: (a) responding to verified requests from data subjects
or Consumers to exercise their rights under Applicable Data Protection Laws; (b) data protection
impact assessments and consultations with regulators or Authorizing Officials, where applicable;
and (c) demonstrating compliance with this DPA. MIS shall promptly forward to Client any request
it receives directly from a Consumer or data subject relating to Client’s Personal Information and
shall not respond except on Client’s documented instructions or as required by law.

10. Data Residency and International Transfers
MIS shall process and store Federal Data and Client Content solely within the continental United
States, at the authorized GCS data centers, and shall not Process, access, or store such data
outside the United States, or permit access from outside the United States, without Client’s prior
written consent and any required Authorizing Official approval.

11. Federal Data and FedRAMP Obligations
With respect to Federal Data and the Authorization Boundary, MIS shall: (a) maintain the GCS
JAB P-ATO (Package ID: F1311222650) for Moderate Rev. 5 throughout the Term; (b) perform
continuous monitoring and significant-change management in accordance with FedRAMP
requirements; (c) identify and manage critical vulnerabilities and POA&M items in accordance
with applicable Federal law, guidelines, and policies; and (d) report incidents to the FedRAMP
PMO, US-CERT, and the applicable Authorizing Official as required. These obligations are in
addition to, and do not limit, MIS’s obligations under Section 8 of the MSA.

12. Audits and Records
MIS shall make available to Client information reasonably necessary to demonstrate compliance
with this DPA and shall allow for and contribute to audits, including inspections, conducted by

    MIS Cloud Services — Data Processing Addendum (Appendix A) | Revision 1.5 | Janurary 27, 2026 | Page 4 of 7
Client or an auditor mandated by Client, in accordance with and subject to the conditions and
frequency limitations set forth in Section 8.5 of the MSA. As part of its continuous-monitoring
obligations, MIS shall provide Client monthly automated vulnerability-scan reports, quarterly
POA&M status updates, and the annual third-party (3PAO) assessment results as provided in the
MSA.

13. Return and Deletion of Data
Upon termination or expiration of the MSA or the applicable Service, MIS shall, in accordance
with Section 3.5 of the MSA, return to Client or destroy all Client Content and Personal Information
within 30 days, except to the extent retention is required by applicable law or by the record-
keeping requirements of a federal agency. Upon the Client’s written request, MIS shall provide a
certificate of destruction. MIS shall continue to protect any Personal Information that it retains in
accordance with this DPA for so long as it is retained.

14. Liability
Each Party’s liability arising out of or relating to this DPA is subject to, and shall be counted
toward, the limitations and exclusions of liability set forth in Section 10 of the MSA, including the
Enhanced Cap applicable to confidentiality breaches and Security Incidents involving Client
Content. Nothing in this DPA expands, or shall be construed to expand, either Party’s liability
beyond the limits set forth in the MSA.

15. General
This DPA is effective as of the Effective Date of the MSA and remains in effect for so long as MIS
Processes Personal Information under the MSA; obligations relating to retained Personal
Information survive until such information is returned or destroyed. This DPA may be amended
only by a written instrument executed by both Parties. Except as expressly modified by this DPA,
the terms of the MSA remain in full force and effect, and the same law and subject govern this
DPA to the same venue as the MSA. In the event of a conflict between this DPA and the MSA
regarding data protection or the Processing of Personal Information, this DPA controls.

    MIS Cloud Services — Data Processing Addendum (Appendix A) | Revision 1.5 | Janurary 27, 2026 | Page 5 of 7
Annex 1 — Details of Processing
 Subject matter                       Provision of the GovPoint Cloud Services (FedRAMP-
                                      authorized IaaS/PaaS) and related support under the MSA.
 Duration                             The Term of the MSA, plus any period during which Personal
                                      Information is retained pending return or destruction.
 Nature and purpose                   Hosting, storage, transmission, processing, backup (where
                                      contracted), and security monitoring of Client Content within
                                      the Authorization Boundary, solely to provide the Services.
 Types of Personal                    As determined and uploaded by the Client and its End Users.
 Information                          [To be completed by Client — e.g., contact data, account
                                      identifiers, and any PII contained in Client Content.]
 Special/sensitive                    [To be completed by Client — specify any sensitive
 categories                           categories, if applicable.]
 Categories of data subjects          [To be completed by Client — e.g., Client’s personnel,
                                      Client’s End Users, and individuals whose data is contained
                                      in Client Content.]
 Frequency of Processing              Continuous, for the duration of the Services.

Annex 2 — Technical and Organizational Security Measures
MIS maintains the following measures, implemented in accordance with FedRAMP Moderate
requirements and NIST SP 800-53 Rev. 5 as documented in the GCS SSP. This summary does
not limit the controls set out in the SSP.
   • Access control: role-based access, least privilege, and phishing-resistant multifactor
      authentication for privileged and remote access (NIST 800-53 AC, IA families).
   • Encryption: FIPS-validated encryption of Client Content in transit and at rest (SC family).
   • Audit and accountability: centralized logging, monitoring, and alerting of security-relevant
      events (AU family).
   • Configuration and vulnerability management: hardened baselines, change control, and
      continuous vulnerability scanning with POA&M tracking (CM, RA families).
   • Boundary protection: network segmentation, firewalls, and intrusion detection at the
      Authorization Boundary (SC, SI families).
   • Contingency and recovery: backup, alternate processing site, and incident-response
      capabilities (CP, IR families).
   • Physical and environmental protection at the authorized U.S. data centers (PE family).
   • Personnel security: background screening and security training for personnel with access
      (PS, AT families).

Annex 3 — Sub-processors
Sub-processors: None. As of the Effective Date, MIS engages no Sub-processors to Process
Personal Information in connection with the Services.

   MIS Cloud Services — Data Processing Addendum (Appendix A) | Revision 1.5 | Janurary 27, 2026 | Page 6 of 7
For transparency, the data-center facilities used by MIS are listed below. These providers furnish
physical colocation only and do not access or Process Client Content; they are physical-
infrastructure providers, not Sub-processors.
 Facility (Physical Colocation Only)                       Location
 Cyxtera / Lumen                                           Burbank, California, USA
 Flexential                                                North Las Vegas, Nevada, USA

    MIS Cloud Services — Data Processing Addendum (Appendix A) | Revision 1.5 | Janurary 27, 2026 | Page 7 of 7