Third Party Index

Snapshot 18250

Document
Data processing addendum
URL
https://www.alteryx.com/wp-content/uploads/media/legal/alteryx-customer-data-processing-agreement.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
252693 bytes
SHA-256 (raw)
2ce39a56bdc0248dd39d760916f395fa2e8070feee8156692171f3d867fd1313
SHA-256 (normalized text)
0949ec1a35e2c8d33d33186d1c5419732385a1a87b16655ef02c4552ed368b84

Normalized text

Scripts and page chrome removed; this is what change detection compares.

ALTERYX DATA PROCESSING AGREEMENT
This Alteryx Data Processing Agreement (“DPA”) is incorporated into and supplements the Agreement (as defined
below) and solely applies to the processing of Customer Content by Alteryx and Alteryx’s Affiliates. In the event of a
conflict between this DPA and any other documents that comprise the Agreement, this DPA controls with respect to
Alteryx’s processing of Personal Data for or on behalf of Alteryx’s customers.
1. Definitions
Capitalized terms have the meaning given to them in the Agreement, unless otherwise defined below.

 Term                 Definition
 Agreement            The Alteryx End User License Agreement or the master agreement (e.g., Master License Agreement)
                      between Alteryx and its customers (each, “Customer” or “Licensee”) governing the Services.
 Applicable Law       The relevant data protection and data privacy laws, rules, and regulations directly applicable to this
                      DPA, including, but not limited to, the General Data Protection Regulation (EU 2016/679) (“GDPR”)
                      and the California Consumer Privacy Act (“CCPA”), and all other enacted state data protection and
                      privacy laws, including without limitation the Virginia Consumer Data Protection Act, the Colorado
                      Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and any successor laws,
                      rules, and regulations. For the avoidance of doubt, “Applicable Law” will include other state, federal,
                      and international data protection and data privacy laws not expressly named above to the extent
                      applicable to this DPA.
 Cloud Content        Any data or information that Customer uploads, connects to, or imports into Alteryx cloud
                      environments for use with the Services, from its internal data sets or other sources not supplied by
                      Alteryx (e.g., Licensee-Sourced Data), together with any workflows, recipes, insights, output content,
                      or other materials created by Customer using the Services, and any log-in credentials for accessing or
                      linking to third-party data sources while using the Services.
 Customer Content     Collectively, Cloud Content and Services Content. For the avoidance of doubt, Customer Content is
                      considered “Licensee-Sourced Data” or “Licensee Content” under the Agreement. Usage Data is
                      expressly excluded from Customer Content.
 Personal Data        Encompasses “personal data”, “personally identifiable information”, or “personal information” as
                      defined under Applicable Law, collectively referred to as "Personal Data" for the purposes of this DPA.
 “process”,           Any operation or set of operations performed on data or sets of data, whether or not by automated
 “processes”,         means, such as collection, recording, organization, structuring, storage, adaptation or alteration,
 “processing” and     retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available,
 “processed”          alignment or combination, restriction, erasure, or destruction.
 SCCs                 The Standard Contractual Clauses referenced in Schedule 3 (Jurisdiction-Specific Terms), as applicable.
 Security Incident    A breach of Alteryx security leading to the accidental or unauthorized destruction, loss, alteration,
                      disclosure of, or access to Customer Content, including Personal Data therein.
 Services             All Alteryx cloud-based products, professional services, and support services provided to a customer
                      pursuant to an Order Form.
 Services Content     Services Content includes logs uploaded by the Customer related to a support request and any raw
                      data provided or made accessible to Alteryx or its Subprocessors in providing professional services
                      pursuant to an Order Form.
 Subprocessor         Contractors, vendors, and third-party service providers engaged by Alteryx to process Customer
                      Content on terms consistent with this DPA.
 Usage Data           Data that Alteryx collects directly from users of its Services to monitor the performance of the
                      Services, provide support and troubleshooting, verify authorized use of the Services for security and
                      licensing purposes, and in aggregated and de-identified form, to improve the Services.

alteryx.com                                                                                                  v.2026.08 |Page 1 of 13
2. Obligations of the Parties
     2.1.     Role of the Parties. For purposes of this DPA, the parties may act in the following capacities:
               Party         Role           Description of Role
                             Controller     Customer is deemed a controller if it determines the purposes and means of
                                            processing of Personal Data in Customer Content.
                             Processor      To the extent a third party determines the purposes and means of Customer’s
               Customer                     processing of Personal Data in Customer Content, Customer’s role will be a
                                            processor, provided that Customer will act in the capacity of a controller with
                                            respect to this DPA and any controller instructions provided to Alteryx
                                            hereunder.
               Alteryx       Processor      Alteryx is acting in the capacity of a processor or subprocessor, as applicable, on
                                            behalf of Customer with respect to Customer Content.
              The terms “controller”, “processor”, and “subprocessor” have the meanings set forth in the GDPR as
              well as any equivalently defined terms under other Applicable Law (e.g., “business” and “service
              provider” under CCPA).
     2.2.     General Compliance.
                  a. Alteryx will process Customer Content in compliance with this DPA and Applicable Law.
                  b. Customer will comply with its obligations as a controller or processor with respect to this DPA
                     and Applicable Law. If Customer processes Customer Content on behalf of a third party,
                     Customer is solely responsible for ensuring that use of the Services and any instructions
                     provided to Alteryx pursuant to this DPA comply with all instructions of such third-party
                     controller.
     2.3.     Jurisdiction-Specific Terms. Additional terms required by the Applicable Law of specific jurisdictions,
              including the GDPR and CCPA obligations of the parties, are set out in Schedule 3 (Jurisdiction-Specific
              Terms).
     2.4.     Controller Instructions. Alteryx will process Customer Content in accordance with Applicable Law and
              Customer’s written instructions and as outlined in Schedule 1 and any Customer configuration of the
              Services. Customer acknowledges and agrees that it is solely responsible for understanding and applying
              any laws, regulations, or standards specific to Customer’s industry or Customer Content. This DPA and
              the Agreement, together with any Customer configuration of the Services, set out Customer’s complete
              instructions regarding Alteryx’s processing of Customer Content. Additional instructions (if any), other
              than a written instruction from Customer to Alteryx to suspend or stop processing Customer Content,
              will require a prior, written amendment to this DPA.
     2.5.     Customer Contacts. For Customer and those entities that Customer permits to use the Services,
              Customer acts as a single point of contact and is solely responsible for obtaining any relevant
              authorizations, consents and permissions for the processing of Customer Content in accordance with
              this DPA, including, if applicable, Customer’s use of Alteryx as a processor or subprocessor hereunder.
              When Alteryx informs or gives notice to Customer under this DPA, such information or notice is deemed
              received by those entities permitted by Customer to use the Services and it is Customer’s responsibility
              to forward such information or notices to such entities.
     2.6.     Data Subject Requests. If a data subject makes a request to Alteryx with respect to Personal Data
              contained within Customer Content and identifies Customer as the controller of such Personal Data,
              Alteryx will promptly inform and reasonably cooperate with Customer regarding such request, as
              required by Applicable Law, and Customer will be solely responsible for responding to the data subject
              and taking such additional steps as are required to satisfy the request. Customer acknowledges that the
              Services do not include the right of Alteryx to access Cloud Content in a manner necessary to determine

alteryx.com                                                                                                   v.2026.08 |Page 2 of 13
              whether specific Personal Data exists in such Cloud Content, or to verify a data subject request and take
              action with respect to a specific individual whose Personal Data may be included in Cloud Content.
     2.7.     Agreement Limitations Apply. To the maximum extent permitted by Applicable Law, including Clause 12
              (Liability) of the EU SCCs (as defined in Part B of Schedule 3), any claims brought under or in connection
              with this DPA, including any claims brought by those entities that Customer authorizes to use the
              Services pursuant to the Agreement, will be subject to the exclusions and limitations set forth in the
              Agreement.
     2.8.     No Third-Party Beneficiaries. Except as expressly required by Applicable Law, including Clause 3 of the
              EU SCCs (Third Party Beneficiaries), no one other than a party to this DPA, its successors and permitted
              assigns has any rights under this DPA or may enforce its terms.
     2.9.     Usage Data. Consistent with common software industry practices, Alteryx collects Usage Data directly
              from users of its Services in the ordinary course of its business and for Alteryx’s internal business
              operations. To the limited extent that Usage Data may contain Personal Data, Alteryx collects such data
              directly from its users as an independent controller in accordance with Alteryx’s Privacy Policy found at
              https://www.alteryx.com/privacy, and consistent with its obligations under relevant privacy laws
              globally. Where feasible, Usage Data is de-identified prior to use by Alteryx except when use in
              unredacted form pertains to Alteryx’s provision of products and Services to the user or Customer, such
              as for license compliance, product use, and security-related purposes. Usage Data does not include
              Customer Content, nor any Personal Data included in Customer Content.
3. Subprocessors
     3.1.     Subprocessor Changes. Alteryx’s list of Subprocessors for Customer Content can be found at
              https://www.alteryx.com/subprocessors. This list will be updated at least thirty (30) days in advance of
              any intended Subprocessor changes. To receive notice of such changes via email, Customer must
              subscribe to Subprocessor updates. If Customer does not subscribe to email updates, Alteryx’s posting of
              the updated Subprocessor list on its website will be deemed to constitute notice to Customer in
              accordance with this provision. Customer will have fifteen (15) calendar days following provision of
              notice in accordance with this Section 3.1 to object in writing to a new Subprocessor of Customer
              Content. In the event Customer objects within such 15-day period, Alteryx will make commercially
              reasonable efforts to address Customer’s good faith objection based on data privacy concerns, or, where
              feasible, to suggest a commercially reasonable change to Customer’s configuration of the Services to
              avoid processing of Customer Content by the objected-to Subprocessor. If Alteryx cannot resolve the
              objection or offer a configuration workaround within thirty (30) calendar days from the date of
              objection, Customer may, as its sole and exclusive remedy, terminate the affected portion of the
              Services and receive a pro-rata refund of prepaid, unused fees. With respect to the GDPR, the EU SCCs’
              Clause 9(a), Option 2 (General Written Authorization), governs Alteryx’s use of Subprocessors of
              Customer Content to deliver the Services.
     3.2.     Subprocessor Security.
                  a. Alteryx will perform appropriate due diligence, including security reviews, of all Subprocessors
                     prior to engagement to process Customer Content. Subprocessors will be assessed annually to
                     validate each Subprocessor’s material compliance with Alteryx’s stated privacy and security
                     obligations.
                  b. Alteryx will contractually bind all Subprocessors to terms no less stringent than those applicable
                     to Alteryx under this DPA to the extent of the services performed by the Subprocessor.
                  c. Alteryx is responsible for the performance of obligations by a Subprocessor to the same extent
                     as if such obligations were directly performed by Alteryx under this DPA, and Alteryx will remain

alteryx.com                                                                                           v.2026.08 |Page 3 of 13
                      liable for the acts and omissions of its Subprocessors with respect to the processing of Customer
                      Content.
4. SCCs and International Transfers
     4.1.     Processing Locations. Alteryx may transfer and process Customer Content, including any Personal Data,
              in the United States and in other locations throughout the world where Alteryx, its Affiliates or its
              Subprocessors maintain data processing operations, provided that such processing complies with the
              requirements of this DPA and Applicable Law.
     4.2.     Transfer Mechanisms. To the extent that Personal Data under this DPA is transferred by or on behalf of
              Customer from a jurisdiction whose Applicable Law restricts cross-border transfers of Personal Data to
              Alteryx in a different jurisdiction, the transfer mechanism set out in the applicable part of Schedule 3
              (Jurisdiction-Specific Terms) will provide the appropriate safeguards required of such transfer.
5. Information Security Program
     5.1.     Technical and Organizational Measures. Alteryx maintains appropriate technical and organizational
              measures designed to protect Personal Data as required by Applicable Law (the “Information Security
              Program”) and as identified in Schedule 2. Alteryx will regularly monitor the effectiveness of its
              Information Security Program and implement additional security measures as reasonably appropriate to
              maintain the security of the Services with respect to Alteryx customers and Customer Content generally.
     5.2.     Program Updates. Customer acknowledges that the Information Security Program may be updated or
              modified from time to time, provided that such updates and modifications do not result in the
              degradation of the overall security of the Services.
     5.3.     Customer Use of Services. Except as provided by this DPA, Customer is responsible for its secure use of
              the Services, including securing its account authentication credentials, protecting the security of
              Customer Content when in Customer’s possession or control, and ensuring the secure transmission of
              Customer Content to and from the Services to the extent such transmission is not in Alteryx’s control. It
              remains Customer’s responsibility to (a) retain or backup any Customer Content it uploads to the
              Services, and (b) secure any Customer environments from which Customer Content is processed as part
              of the Services.
6. Audits
     6.1.     Security Questionnaires. Customer may reasonably request that Alteryx provide assurance of Alteryx’s
              compliance with its obligations to Customer hereunder upon at least thirty (30) days’ prior written
              notice through the submission of security questionnaires or a request for the most recent, relevant
              third-party certifications or summary executive findings pertaining to Alteryx’s Information Security
              Program. Notwithstanding any requests made by data protection authorities or as otherwise required by
              Applicable Law, Customer may make a request under this Section 6.1 no more than once per rolling
              calendar year. In lieu of providing responses to customer-specific security questionnaires, Alteryx may
              provide a System and Organization Controls 2 (SOC 2) Type 2 report, or industry accepted security
              questionnaire responses, such as CSA Consensus Assessment Initiative Questionnaires responses (CAIQs)
              or Security Information Gathering Questionnaire responses (SIGs). If these industry accepted security
              reports and questionnaire responses do not adequately address substantive questions included in a
              customer-specific security questionnaire, Alteryx will provide commercially reasonable assistance to
              Customer in providing appropriate responses to those questions.
     6.2.     Audits. To the extent expressly permitted by the SCCs or Applicable Law, Customer may, at Customer’s
              expense, request reasonable supplementary information through an audit of the Information Security
              Program and Alteryx’s policies and procedures related to this DPA. Any such audit may be conducted by
              Customer or a mutually acceptable third-party auditor subject to an Alteryx non-disclosure agreement.

alteryx.com                                                                                           v.2026.08 |Page 4 of 13
              The parties will reasonably cooperate and agree in advance as to the time, manner, and scope of this
              audit. The audit will be conducted remotely unless the parties mutually agree in writing, signed by an
              authorized representative of each party, that the purposes of this Section 6.2 cannot be reasonably
              accomplished without an on-site audit. Any necessary on-site audit activities will be conducted after the
              remote audit is completed, at which time the parties will agree to the remaining audit activities, which
              will be limited to only those remaining activities necessary to reasonably accomplish the audit purposes.
              Notwithstanding any requests made by data protection authorities or as otherwise required by
              Applicable Law, Customer may make an audit request under this Section 6.2 no more than once per
              rolling calendar year.
7. Cooperation
     7.1.     Taking into account the nature of processing and information available to Alteryx, Alteryx will reasonably
              cooperate with Customer as necessary:
                  a. for Customer to comply with its obligations under Applicable Law, or
                  b. to address Customer’s concerns if Customer has a reasonable and good faith belief that Alteryx’s
                     processing of Customer Content does not comply with Applicable Law.
              In each case, Customer must provide reasonably sufficient details to Alteryx as needed to understand
              the basis for Customer’s requests or concerns.
8. Deletion of Customer Content and Termination
     8.1.     Data Deletion. Alteryx will promptly and securely delete Customer Content after expiration or
              termination of the Agreement and otherwise in accordance with Applicable Law. Alteryx may provide
              Customer with self-service functionality that enables Customer to (a) download or export and retain
              Cloud Content for itself if Customer chooses, and (b) delete Cloud Content prior to expiration or
              termination of the Agreement. Customer must take the steps available through this self-service
              functionality to delete Cloud Content prior to expiration or termination of the Agreement. Customer
              may request reasonable assistance with respect to retention or deletion of Cloud Content prior to the
              date of expiration or termination by opening a support request with Alteryx. Any remaining Cloud
              Content that Customer does not delete prior to expiration or termination of the Agreement will be
              deleted by Alteryx in accordance with the time periods set out in Alteryx’s internal retention schedules
              and, where applicable, the requirements of Applicable Law.
     8.2.     Data Transfer Option. Where expressly designated in an Order Form, Alteryx may provide Customer a
              limited, specified period following termination or expiration (not to exceed thirty (30) calendar days)
              during which Customer may use self-service tools to back-up or export Cloud Content from Alteryx
              cloud-based products. Notwithstanding the foregoing, following any such specified period of retention
              for Customer’s benefit, Alteryx will have no obligation to retain Cloud Content.
     8.3.     Termination. This DPA terminates simultaneously and automatically with deletion of all Customer
              Content following termination or expiration of the Agreement.
9. Security Incidents
     9.1.     Security Incident Procedures. Alteryx will implement and maintain policies and standards to (a) identify,
              detect and respond to suspected or known Security Incidents, mitigate harmful effects of Security
              Incidents, and document Security Incidents and their outcomes, and (b) restore the availability or access
              to Customer Content in a timely manner.
     9.2.     Notice. Alteryx will provide prompt written notice (email will suffice) to Customer, without undue delay
              and, where feasible, not later than seventy-two (72) hours after Alteryx becomes aware that a Security
              Incident has taken place, except to the extent such notice is restricted by law enforcement or may
              permit exploitation of the Security Incident. To the extent known by Alteryx, such notice will include all
alteryx.com                                                                                            v.2026.08 |Page 5 of 13
              available details required under Applicable Law to enable Customer to comply with its notification
              obligations to regulatory authorities or individuals affected by the Security Incident, including a
              description of the Security Incident, the types of data or number of users whose Personal Data may be
              impacted, and the remediation efforts taken or planned. If and to the extent Alteryx confirms that a
              Security Incident impacts Personal Data included in Customer Content, Alteryx will provide notices
              required by this Section 9.2 in the time and manner required by Applicable Law and the SCCs. Alteryx
              will take commercially reasonable steps to investigate, contain and remedy the Security Incident and to
              prevent any further such incidents.
10. Compelled Disclosures
     10.1.    If Alteryx is ordered or otherwise compelled to provide any Customer Content to any law enforcement
              or other government agency (an “Authority”), Alteryx shall:
                  a. Request that the Authority direct its order to Customer and not Alteryx;
                  b. Notify Customer of the order, unless Alteryx reasonably understands that it is prohibited by law
                     or by the Authority to notify Customer, in which case Alteryx will use commercially reasonable
                     and lawful efforts to have the Authority permit Alteryx’s notification to Customer; and
                  c. Assist Customer, at Customer’s expense, to lawfully challenge the order to the extent such
                     challenge can be validly raised pursuant to the applicable jurisdiction and laws under which the
                     order was made.

alteryx.com                                                                                          v.2026.08 |Page 6 of 13
SCHEDULE 1 (Annex I to the EU SCCs)
 A. LIST OF PARTIES
 Data exporter(s):
 Name:                                  Customer, as named in the Agreement, and those Customer Affiliate(s) authorized to
                                        purchase products and services from Alteryx as expressly identified in the Agreement.
 Address:                               See Agreement
 Contact person’s name, position        See Agreement
 and contact details:
 Activities relevant to the data        Upload to, storage of, and use of any Personal Data included in Customer Content with
 transferred under these Clauses:       the Services for Customer’s benefit or the benefit of Customer’s employees, customers,
                                        and partners.
 Role (controller/processor):           controller, or a processor on behalf of a third party.
 Data importer(s):
 Name:                                  Alteryx, Inc.
 Address:                               3347 Michelson Drive, Suite 400 Irvine, California 92612 USA
 Contact person’s name, position        Brian Quinn, Senior Director, Privacy and Product Counsel
 and contact details:                   [email protected] and [email protected]
 Activities relevant to the data        Hosting of Customer Content, which may, in Customer’s sole discretion, include
 transferred under these Clauses:       Personal Data
 Role (controller/processor):           processor on behalf of Customer

 B. DESCRIPTION OF TRANSFER
 Categories of data subjects whose personal data is transferred.           Solely determined by Customer as part of Customer
                                                                           Content.
 Categories of personal data transferred.                                  Solely determined by Customer as part of Customer
                                                                           Content.
 Sensitive data transferred (if applicable) and applied restrictions or    Any use of the Services with Customer Content that
 safeguards that fully take into consideration the nature of the data      contains sensitive data is at Customer’s sole
 and the risks involved, such as for instance strict purpose               discretion, in accordance with Schedule 2.
 limitation, access restrictions (including access only for staff having
 followed specialised training), keeping a record of access to the
 data, restrictions for onward transfers or additional security
 measures.
 The frequency of the transfer (e.g., whether the data is transferred      Frequency of transfers of Customer Content that
 on a one-off or continuous basis).                                        include Personal Data are at Customer’s sole
                                                                           discretion in its use of the Services.
 Nature of the processing.                                                 Hosting of Customer Content, which may contain
                                                                           Personal Data, for Customer’s use of the Services.
 Purpose(s) of the data transfer and further processing.                   Personal Data may be transferred as part of
                                                                           Customer Content solely for Customer’s use of the
                                                                           Services and for no further processing by Alteryx.
 The period for which the personal data will be retained, or, if that is   Customer is solely responsible for determining the
 not possible, the criteria used to determine that period.                 retention period of any Customer Content, including
                                                                           Personal Data, during the term of the Agreement.
 For transfers to (sub-) processors, also specify subject matter,          Subprocessors engaged to process Customer Content
 nature and duration of the processing.                                    are as outlined at
                                                                           https://www.alteryx.com/subprocessors.

 C. COMPETENT SUPERVISORY AUTHORITY
 Identify the competent supervisory authority/ies in accordance with           Bavarian State Office for Data Protection
 Clause 13.                                                                    Supervision

alteryx.com                                                                                                   v.2026.08 |Page 7 of 13
SCHEDULE 2 (Annex II to the EU SCCs)
TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO
ENSURE THE SECURITY OF THE DATA

Alteryx’s Security Standards, which describes Alteryx’s technical and organizational measures, is incorporated by
reference into this Schedule 2 and is located at: https://www.alteryx.com/security-standards.

alteryx.com                                                                                        v.2026.08 |Page 8 of 13
SCHEDULE 3 – Jurisdiction-Specific Terms
Each Part of this Schedule 3 sets out jurisdiction-specific terms that apply only to the extent that the processing of
Personal Data under the Agreement is subject to the data protection laws of, or involves a transfer of Personal Data
from, the jurisdiction identified in that Part. The presence of a Part in this DPA is not a representation or
acknowledgment by Customer that Customer is subject to the laws of, or transfers Personal Data from, that
jurisdiction.
In the event of any conflict between a Part of this Schedule 3 and the body of this DPA with respect to the subject
matter of that Part, the Part will control to the extent of the conflict. Additional jurisdiction-specific Parts may be
added to this Schedule 3 by mutual written agreement of the parties.
PART A – CALIFORNIA AND OTHER U.S. STATES
1. Applicability. This Part A applies to the extent that the CCPA, or a comparable privacy law of another U.S. state,
   applies to the processing of Personal Data contained within Customer Content under this DPA.
2. CCPA. The parties acknowledge that Alteryx is a “Service Provider” (as defined by CCPA) with respect to the
   processing of Customer Content under this DPA. Alteryx does not provide Customer with monetary or other
   valuable consideration in exchange for any Personal Data contained within Customer Content. Except as
   required by applicable law or regulation, Alteryx will not collect, access, use, disclose, process, or retain Personal
   Data contained in Customer Content for any purpose other than providing the Services or another business
   purpose expressly permitted by Applicable Law, this DPA, or the Agreement. Alteryx further acknowledges that,
   with respect to Personal Data in Customer Content that Alteryx processes as a Service Provider on behalf of
   Customer subject to this Part A:
     2.1.     Alteryx is obligated to comply with and provide the same level of privacy protection as required by
              Applicable Law.
     2.2.     Customer may take reasonable and appropriate steps to ensure that Alteryx uses such Customer
              Content in a manner consistent with Customer’s obligations under Applicable Law.
     2.3.     Alteryx must notify Customer if Alteryx determines that it can no longer meet its obligations under
              Applicable Law, and upon such notice, grant Customer the right to take reasonable and appropriate
              steps to stop and remediate unauthorized use of such Customer Content, as otherwise required by this
              DPA or Applicable Law.
     2.4.     Alteryx is prohibited from combining such Customer Content that it receives from, or on behalf of,
              Customer with Personal Data that it receives from, or on behalf of, another person or persons (or a CCPA
              household), or collects from its own interaction with a person or persons (or a CCPA household),
              provided that Alteryx may combine personal information to perform the Services.
     2.5.     Alteryx will not sell or share (as “sell” and “share” are defined and governed by Applicable Law, including
              CCPA) any Personal Data subject to this DPA.

PART B – EUROPEAN ECONOMIC AREA
Transfers from the EEA. If and solely to the extent that Personal Data under this DPA is transferred by or on behalf
of Customer from within the European Economic Area (EEA) to Alteryx in a jurisdiction outside of the EEA, and to the
extent such transfer is restricted under the GDPR, the parties agree that the Standard Contractual Clauses approved
by the European Commission under Decision 2021/914 of 4 June 2021, as currently provided at https://eur-

alteryx.com                                                                                             v.2026.08 |Page 9 of 13
lex.europa.eu/eli/dec_impl/2021/914/oj, as may be modified or supplemented from time to time (the “EU SCCs”), will
provide the appropriate transfer safeguards, subject to the following modifications:
      SCC Reference          Title                                  Application
      Module Two and         Module Two: Controller to              Module Two or Module Three will apply, depending on
      Module Three           Processor                              whether Customer is a controller or processor of the
                             Module Three: Processor to             Customer Content. In each case, Alteryx is a processor to
                             Processor                              Customer.
      Clause 7               Docking Clause                         The optional docking clause will apply.
      Clause 9(a),           Use of Subprocessors                   General Written Authorization will be used for
      Option 2                                                      Subprocessors, as described in Section 3.1 (Subprocessor
                                                                    Changes) of this DPA.
      Clause 11              Redress                                The optional language regarding independent dispute
                                                                    resolution will not apply.
      Clause 17,             Governing Law                          The SCCs will be governed by the laws of Germany.
      Option 1
      Clause 18(b)           Forum and Jurisdiction                 All disputes will be resolved before the courts of Germany.
      Annex I                List of Parties, Description of        Annex I is deemed completed with the information set out in
                             Transfer and Competent                 Schedule 1 to this DPA.
                             Supervisory Authority
      Annex II               Technical and Organisational           Annex II is deemed completed with the information set out in
                             Measures Including Technical and       Schedule 2 to this DPA.
                             Organisational Measures to Ensure
                             the Security of the Data
      Annex III              List of Subprocessors                  Annex III is deemed completed using the Subprocessor List
                                                                    found at https://www.alteryx.com/subprocessors.

PART C – UNITED KINGDOM
3. Transfers from the United Kingdom. If and solely to the extent that Personal Data under this DPA is transferred
   by or on behalf of Customer from within the United Kingdom to Alteryx in a different jurisdiction, and to the
   extent such transfer is restricted under Applicable Law, then the EU SCCs, as modified by Part B of this Schedule
   3, provide the appropriate safeguards required of such a transfer, subject to the following additional
   modifications:
4. References Modified:
      SCC References                            Modification to the SCC References
      “Regulation (EU) 2016/679”, “the          Will be interpreted as references to the Applicable Law of the United Kingdom.
      Regulation”, or the GDPR
      Articles of the GDPR                      Where required or appropriate, references to specific Articles will be replaced
                                                with the equivalent article or section of the Applicable Law of the United
                                                Kingdom.
      “EU”, “Union” and “Member State”          Will be replaced with references to the United Kingdom.
      “Competent supervisory authority”         Will be the UK Information Commissioner.
      “Competent courts”                        Will mean the courts of England and Wales.

alteryx.com                                                                                                     v.2026.08 |Page 10 of 13
5. Governing Law; Forum and Jurisdiction. In Clause 17 and Clause 18(b), the EU SCCs will be governed by the laws
   of the United Kingdom (England and Wales), and disputes will be resolved before the courts of the United
   Kingdom (England and Wales).
6. UK Addendum. The United Kingdom’s International Data Transfer Addendum to the EU Commission Standard
   Contractual Clauses (version B1.0), in force 21 March 2022 (the “UK Addendum”) is attached as Annex 1 to this
   Part C.

ANNEX 1 TO PART C – UK ADDENDUM
This Addendum has been issued by the Information Commissioner for parties making Restricted Transfers. The
Information Commissioner considers that it provides Appropriate Safeguards for Restricted Transfers when it is
entered into as a legally binding contract.

 Part 1: Tables

 Start date       The effective date set forth in the Agreement

 The Parties      Exporter (who sends the Restricted      Importer (who receives the Restricted Transfer)
                  Transfer)

 Parties’         Full legal name: See Agreement          Full legal name: Alteryx, Inc.
 details
                  Trading name (if different): See        Main address (if a company registered address): 3347 Michelson
                  Agreement                               Drive, Suite 400 Irvine, California 92612 USA

                  Main address (if a company              Official registration number (if any) (company number or similar
                  registered address): See Agreement      identifier): N/A

                  Official registration number (if any)
                  (company number or similar
                  identifier): See Agreement

 Key Contact      Full Name (optional): See Agreement     Full Name (optional): Brian Quinn

                  Job Title: See Agreement                Job Title: Senior Director, Privacy and Product Counsel

                  Contact details including email: See    Contact details including email: [email protected] and
                  Agreement                               [email protected]

 Signature (if                                            N/A
 required for
                  N/A
 the purposes
 of Section 2)

 Table 2: Selected SCCs, Modules and Selected Clauses

alteryx.com                                                                                                 v.2026.08 |Page 11 of 13
 Addendum EU SCCs                 The Approved EU SCCs, including the Appendix Information and with only the following
                                  modules, clauses or optional provisions of the Approved EU SCCs brought into effect for the
                                  purposes of this Addendum:

Module        Module in       Clause 7         Clause 11       Clause 9a (Prior Clause 9a (Time   Is personal data received
              operation       (Docking         (Option)        Authorisation or period)           from the Importer combined
                              Clause)                          General                            with personal data collected
                                                               Authorisation)                     by the Exporter?

      1            No              N/A             N/A

      2            Yes              Yes                No          General             30

      3            Yes              Yes                No          General             30

      4            No              N/A             N/A                                                           N/A

 Table 3: Appendix Information

 “Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix
 of the Approved EU SCCs (other than the parties), and which for this Addendum is set out in:

 Annex 1A: List of Parties: Schedule 1.A of this DPA

 Annex 1B: Description of Transfer: Schedule 1.B of this DPA

 Annex II: Technical and organisational measures to ensure the security of the data: Schedule 2 of this DPA

 Annex III: List of Sub processors (Modules 2 and 3 only): www.alteryx.com/subprocessors

 Table 4: Ending this Addendum when the Approved Addendum Changes

 Ending this Addendum          Which Parties may end this Addendum as set out in Section 19:
 when the Approved
                               Neither Party
 Addendum changes

 Part 2: Mandatory Clauses

 Mandatory Clauses             Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0
                               issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection
                               Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.

alteryx.com                                                                                                   v.2026.08 |Page 12 of 13
PART D – SWITZERLAND
1. Transfers from Switzerland. If and solely to the extent that Personal Data under this DPA is transferred by or on
   behalf of Customer from within Switzerland to Alteryx in a different jurisdiction, and to the extent such transfer
   is restricted under Applicable Law, then the EU SCCs, as modified by Part B of this Schedule 3, provide the
   appropriate safeguards required of such a transfer, subject to the following additional modifications:
2. References Modified:
      SCC References                       Modification to the SCC References
      “Regulation (EU) 2016/679”, “the     Will be interpreted as references to the Applicable Law of Switzerland.
      Regulation”, or the GDPR
      Articles of the GDPR                 Where required or appropriate, references to specific Articles will be
                                           replaced with the equivalent article or section of the Applicable Law of
                                           Switzerland.
      “EU”, “Union” and “Member State”     Will be replaced with references to Switzerland.
      “Competent supervisory authority”    Will be the Swiss Federal Data Protection and Information Commissioner.
      “Competent courts”                   Will mean the courts of Switzerland.
3. Governing Law; Forum and Jurisdiction. In Clause 17 and Clause 18(b), the EU SCCs will be governed by the laws
   of Switzerland, and disputes will be resolved before the courts of Switzerland.

PART E – BRAZIL
1. Restricted Transfers from Brazil. If and solely to the extent that Personal Data under this DPA is transferred by
   or on behalf of Customer from within Brazil, the Standard Contractual Clauses for International Data Transfers
   issued by the Autoridade Nacional de Proteção de Dados (ANPD) under Resolution CD/ANPD No. 19/2024, as
   amended or superseded from time to time (the “Brazilian SCCs”), are incorporated by reference to provide the
   appropriate safeguards required of such a transfer. Customer is considered the “Designated Party” under the
   Brazilian SCCs, subject to the following elections:
      Brazilian SCC            Title                           Application
      Reference
      Clause 1 and 2           Identification of the parties   Clauses 1 and 2 are deemed completed with the information
                               and Object                      set out in Schedules 1 and 3.

      Clause 3                 Subsequent Transfers            Option B, including compliance with Clause 18, will apply.
                                                               Option B is deemed completed with the information set out in
                                                               Section 3.1 of this DPA and Schedules 1 and 3.
      Clause 4                 Responsibilities of the         In Option A, Exporter is chosen for all provisions in Option A
                               parties                         where indicated.
      Clause 21 and            Security Measures               The description of the security measures is deemed
      Section III                                              completed with the information set out in Schedule 2.

alteryx.com                                                                                                   v.2026.08 |Page 13 of 13