Third Party Index

Snapshot 19068

Document
Data processing addendum
URL
https://c3.ai/api/media/file/c3-ai-data-processing-agreement-2025-01-23.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
249289 bytes
SHA-256 (raw)
bc00e3a4723f74f83b1cfd25823e816fad394726ab9184e0ff18ecf73bdf8a4a
SHA-256 (normalized text)
f6ee8691894a82c782c9e0f15e06475cf9c23b240af074c391783004197eadb1

Normalized text

Scripts and page chrome removed; this is what change detection compares.

                                        C3 AI DATA PROCESSING AGREEMENT

    This Data Processing Agreement ("DPA") forms part of the End User License Agreement ("Agreement") between: (i)
    Customer (“Customer” or “You”) acting on its own behalf and as agent for each Customer Affiliate; and (ii) C3.ai,
    Inc. (“C3” or “Us”) acting on its own behalf and as agent for each C3 Affiliate, and shall apply to any Customer
    Personal Data submitted by or on behalf of Client for evaluation with the C3 AI Software.

    All capitalized terms not defined herein shall have the meaning set forth in the Agreement. Except as modified below,
    the terms of the Agreement shall remain in full force and effect.

    In consideration of the mutual obligations set out herein, the Parties hereby agree that the terms and conditions set out
    below shall be added to the Agreement. Except where the context requires otherwise, references in the DPA to the
    Agreement are to the Agreement as amended by, and including, this DPA.

    1.       Definitions

    1.1      In this DPA, the following terms shall have the meanings set out below and cognate terms shall be construed
             accordingly:

             •     “Authorized Affiliate” means any of Customer's Affiliate(s) which is permitted to use the C3 AI Services
                   or C3 AI Software pursuant to the Agreement between Customer and C3 AI.

             •     “C3 AI Group” means C3 AI and its Affiliates engaged in the Processing of Customer Personal Data.

             •     “Customer Personal Data” means Personal Data included in the “Customer Data” (as such term is
                   defined in the Agreement).

             •     “Data Protection Laws and Regulations” means all laws and regulations, including laws and
                   regulations of the United States, European Union and their Member States and the United Kingdom,
                   applicable to the Processing of Personal Data under the Agreement, including (i) the GDPR; (ii) the
                   Federal Act on Data Protection of 19 June 1992 (Switzerland FADP); (iii) the California Consumer
                   privacy Act of 2018, as amended from time to time including by the California Privacy Rights Act
                   [1798.100 - 1798.199], and its implementing regulations (the “CCPA”); and (iv) the Virginia Consumer
                   Data Protection Act, as amended from time to time, and the Personal Information Protection and
                   Electronics Documents Act of Canada (PIPEDA).

             •     "Data Transfer" means (1) a transfer of Customer Personal Data from the Customer or any Customer
                   Authorized Affiliate to a C3 AI Group member or a Sub-processor; or (2) an onward transfer of Customer
                   Personal Data from a C3 AI Group member to a Sub-processor, or between two establishments of a Sub-
                   processor, in each case, where such transfer originates from the European Union, to countries which do
                   not ensure an adequate level of data protection within the meaning of Data Protection Laws and
                   Regulations of the foregoing territories.

             •     “GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27
                   April 2016 on the protection of natural persons with regard to the processing of personal data and on the
                   free movement of such data (the “EU GDPR”), and the “UK GDPR” (the EU GDPR as incorporated
                   into UK law by the UK Data Protection Act 2018 and amended by the Data Protection, Privacy and

January 23, 2025
                Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (each as amended or
                replaced from time to time)).

           •    “Standard Contractual Clauses” or “SCCs” means with respect to Member States of the European
                Economic Area (“EEA”), Switzerland and Brazil, the standard contractual clauses adopted by the
                European Commission as of June 4, 2021, the text of which is available at: https://eurlex.europa.eu/legal-
                content/EN/TXT/HTML/?uri=CELEX:32021D0914&from=EN                  (“EU       Standard        Contractual
                Clauses”), and with respect to the United Kingdom, the EU Standard Contractual Clauses supplemented
                by the International Data Transfer Addendum to the EU Commission Standard Contractual
                Clauses,     the      text    of      which    is    available      at:       https://ico.org.uk/media/for-
                organisations/documents/4019483/international-data-transfer-addendum.pdf (“International Data
                Transfer Addendum”) (together with the EU Standard Contractual Clauses, the “UK Standard
                Contractual Clauses”), including any updated, amended, or subsequent version thereof approved by the
                respective data protection authority.

           •    “Sub-processor” means any Processor engaged by C3 AI or a member of the C3 AI Group and that
                Processes Customer Personal Data.

           •    “Technical Specification C3001: C3 AI Suite, Applications, and Data Security” means the Security,
                Privacy and Architecture Documentation applicable to the specific C3 AI Services and C3 AI Software
                purchased by Customer, as updated from time to time.

   1.2   The terms “Business,” “collect,” “Commercial Purpose,” “Consumer,” “Controller,” “Data Subject,”
           “Member State,” “Personal Data,” “Personal Data Breach,” “Processing,” “Processor,” “sell,” “Service
           Provider,” “share,” “Supervisory Authority,” and “Verifiable Consumer Request,” shall have the same
           meaning as in the applicable Data Protection Laws and Regulations. For avoidance of doubt, the term
           “Personal Data” also includes “personal information,” “personally identifiable information,” and any similar
           term used in Data Protection Laws and Regulations.

   2.      Processing of Customer Personal Data

   2.1 Roles of the Parties. The Parties acknowledge and agree that if Customer’s use of the C3 AI Services or C3 AI
          Software requires the Processing by C3 AI of Customer Personal Data, Customer shall be the Controller (or
          Business), C3 AI shall be the Processor (or Service Provider) and the terms of this DPA shall apply to such
          Processing.

   2.2 Processing of Personal Data by Customer. Customer shall, in its use of the C3 AI Services or C3 AI Software,
           Process Personal Data in accordance with the requirements of Data Protection Laws and Regulations. For the
           avoidance of doubt, Customer’s instructions for the Processing of Customer Personal Data shall comply with
           Data Protection Laws and Regulations. Customer shall have sole responsibility for the accuracy, quality, and
           legality of processing Customer Personal Data, and the means by which Customer acquired Personal Data.

   2.3 Processing of Personal Data by C3 AI. C3 AI shall treat Customer Personal Data as confidential information
          and shall only Process Customer Personal Data on behalf of and in accordance with Customer’s documented
          instructions for the following purposes: (i) Processing in accordance with the Agreement and applicable Order
          Form(s); (ii) Processing initiated by Users in their use of the C3 AI Services or C3 AI Software; and (iii)
          Processing to comply with other documented reasonable instructions provided by Customer (e.g., via email)
          where such instructions are consistent with the terms of the Agreement.

   2.4 Details of the Processing. The nature and subject-matter of Processing of Customer Personal Data by C3 AI is
          the performance of the C3 AI Services and C3 AI Software pursuant to the Agreement. The duration of the
          Processing is the duration of the Agreement and applicable Order Form(s), unless otherwise agreed by the in
          writing. The categories of Data Subjects and types of Personal Data Processed under this DPA are as notified

January 23, 2025                                                                                                         2
           in advance by Customer to C3 AI, and the extent of which is determined and controlled by Customer in its
           sole discretion.

   2.5 Appropriateness of C3 Software and Services. Customer acknowledges that it has assessed the C3 Software,
          C3 Services, and applicable security measures implemented by C3 AI, and that Customer considers the C3
          Software, C3 Services and the security measures to be appropriate taking into account the risk, likelihood,
          and severity for the rights and freedoms of Data Subjects resulting from the Processing of Customer Personal
          Data and, as between the Parties and the Data Subjects and Supervisory Authorities, Customer is solely
          responsible for such determination of appropriateness.

   2.6 CCPA Service Provider Obligations. Each party hereto shall comply with all applicable sections of the CCPA
         and take all actions necessary to enable the other party to comply with its obligations thereunder.
         Without limiting the foregoing, C3 AI expressly acknowledges and agrees that:
          (a) C3 AI is acting as a service provider to Customer in connection with its provision of services to
                Customer pursuant to the Agreement;

             (b) C3 AI shall not sell or share personal information it collects pursuant to the Agreement;

             (c)   the business purpose for which C3 AI is processing personal information pursuant to the Agreement is
                   solely for the provision of services to Customer specifically described in the Agreement, and Customer
                   is disclosing personal information to C3 only for such limited business purpose;

             (d) C3 AI shall not retain, use, or disclose personal information it collects pursuant to the Agreement for
                 any purpose other than to provide the services in accordance with the Agreement or as otherwise
                 permitted by the CCPA;

             (e)   C3 AI shall not retain, use, or disclose personal information it collects pursuant to the Agreement for
                   any commercial purpose other than to provide the services thereunder, unless expressly permitted by
                   the CCPA;

             (f)   C3 AI shall not retain, use or disclose personal information it collects pursuant to the Agreement
                   outside the direct business relationship between C3 AI and Customer, unless expressly permitted by
                   the CCPA;

             (g) C3 AI shall not combine the personal information it receives from or on behalf of Customer with
                 personal information C3 AI receives from or on behalf of another person or persons, or collects from
                 its own interaction with a consumer;

             (h) C3 AI shall provide the same level of privacy protection as required of businesses by the CCPA;

             (i)   C3 AI grants Customer the right to take reasonable and appropriate steps to ensure that C3 AI uses the
                   personal information that it collects pursuant to the Agreement in a manner consistent with Customer’s
                   obligations under the CCPA, which may include vulnerability scans of C3 AI’s system and regular
                   internal or third-party assessments, audits, or other technical and operational testing in accordance with
                   Section 10 hereof;

             (j)   C3 AI will promptly notify Customer if C3 AI determines that it can no longer meet its obligations
                   under the CCPA and upon such notice Customer may immediately terminate the Agreement upon
                   notice to C3 AI;

             (k) C3 AI will enable Customer to comply with consumer requests made pursuant to the CCPA.

           C3 AI and Customer expressly acknowledge and agree that Customer is not providing any Personal
           Information to C3 AI as part of any sale or for monetary or any other valuable consideration.

January 23, 2025                                                                                                            3
   3.       C3 AI and C3 AI Affiliate Personnel

            C3 AI and each C3 AI Affiliate shall take reasonable steps to ensure the reliability of any employee, agent or
            contractor of any C3 AI Group member who has access to the Customer Personal Data, ensuring in each case
            that access is limited to those individuals who need to know / access the relevant Customer Personal Data, as
            necessary for the purposes of the Agreement, ensuring that all such individuals are subject to confidentiality
            undertakings or professional or statutory obligations of confidentiality.

   4.       Security

   4.1 Controls for the Protection of Customer Data. C3 AI shall maintain technical and organizational measures for
          protection of the security, confidentiality and integrity of Customer Data, as set forth in the Annex II
          (TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND
          ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA). C3 AI regularly
          monitors compliance with these measures.

   5.       Sub-processing

   5.1 Appointment of Sub-processors. Customer acknowledges and agrees that (a) C3 AI’s Affiliates may be retained
          as Sub-processors; and (b) C3 AI and C3 AI’s Affiliates respectively may engage third-party Subprocessors
          in connection with the provision of the C3 AI Services and C3 AI Software, subject to this Section 5. Prior to
          providing any Sub-processors’ access to or processing of Customer Data C3 AI or a C3 AI Affiliate has
          entered or will enter into a written agreement with each Sub-processor (i) containing data protection and
          confidentiality obligations not less protective than those in this DPA with respect to the protection of Customer
          Data to the extent applicable to the nature of the services provided by such Sub-processor; (ii) permitting
          Sub-processor to access and use Customer Data only to deliver the services such Sub-processor is retained to
          provide and (iii) prohibiting use of Customer Personal Data by sub-processor for any other purpose; and (iv)
          requiring Sub-processor to adhere to substantially the same data protection obligations as those binding C3
          AI under this DPA and (if applicable) the SCCs. Where the SCCs apply, the Parties agree to use “Option 2”
          in clause 9 of the SCC.

   5.2 List of Current Sub-processors and Notification of New Sub-processors. The current list of Sub-processors
          for the C3 AI Services and C3 AI Software is attached to this DPA. C3 AI shall provide at least 30 days prior
          notification to Customer of a new Sub-processor (in accordance with clause 9(a) of the SCCs if applicable)
          before authorizing any new Sub-processor to Process Customer Personal Data in connection with the
          provision of the applicable C3 AI Services or C3 AI Software.

   5.3   Objection Right for New Sub-processors. Customer may object to C3 AI’s use of a new Sub-processor on
           compelling grounds relating to personal data protection by notifying C3 AI promptly in writing within ten
           (10) business days after receipt of C3 AI’s notice in accordance with the mechanism set out in Section 5.2. In
           the event Customer objects to a new Sub-processor, as permitted in the preceding sentence, C3 AI will, in its
           sole discretion, either (i) use reasonable efforts to make available to Customer a change in the applicable C3
           AI Services or C3 AI Software, (ii) recommend a commercially reasonable change to Customer’s
           configuration or use of the C3 AI Services or C3 AI Software to avoid Processing of Customer Personal Data
           by the objected-to new Sub-processor without unreasonably burdening the Customer, or (iii) propose an
           alternate Sub-processor.

   5.4 Liability. C3 AI will remain liable to Customer for (i) its obligations under this DPA even if such obligations are
          delegated to a Sub-processor, including the proper and timely performance of services, and (ii) the acts or
          omissions of any person or entity to which C3 AI delegates any such obligation in its performance of the
          delegated obligation.

January 23, 2025                                                                                                          4
   6.       Data Subject Rights

   6.1 Notification. C3 AI shall, to the extent legally permitted, promptly notify Customer if C3 AI receives a request
          from a Data Subject to exercise the Data Subject's rights of access, rectification, restriction of Processing,
          erasure (“right to be forgotten”), data portability, objection to the Processing, as well as its right not to be
          subject to an automated individual decision making (“Data Subject Request”).

   6.2 Assistance. Taking into account the nature of the Processing, C3 AI shall assist Customer by appropriate technical
           and organizational measures, insofar as this is reasonably possible, for the fulfilment of Customer’s obligation
           to respond to a Data Subject Request under Data Protection Laws and Regulations. In addition, to the extent
           Customer, in its use of the C3 AI Services or C3 AI Software, does not have the ability to address
           a Data Subject Request, C3 AI shall upon Customer’s request provide commercially reasonable efforts to
           assist Customer in responding to such Data Subject Request, to the extent C3 AI is legally permitted to do so
           and if the response to such Data Subject Request is required under Data Protection Laws and Regulations.
           Customer shall be responsible for any costs arising from C3 AI’s provision of any such assistance.

   7.       Personal Data Breach

   7.1 C3 AI maintains security incident management policies and procedures specified in the Technical Specification
          C3001: C3 AI Suite, Applications, and Data Security and shall notify Customer without undue delay upon C3
          AI or any Sub-processor becoming aware of a Personal Data Breach affecting Customer Personal Data by
          providing Customer with available information to help Customer meet its obligations under the Data
          Protection Laws and Regulations to report or inform the Supervisory Authority and Data Subjects of the
          Personal Data Breach.

   7.2   C3 AI shall reasonably cooperate with Customer and take such reasonable commercial steps to investigate,
           mitigate and remediate each such Personal Data Breach, to the extent the remediation is within C3 AI’s
           reasonable control. Customer shall be responsible for any costs arising therefrom with respect to incidents
           that are caused by Customer or Customer’s Users.

   8.       Data Protection Impact Assessment and Prior Consultation

            If, pursuant to Data Protection Laws and Regulations, Customer (or its Controllers) is required to perform a
            data protection impact assessment or prior consultation with a regulator, upon Customer’s request, C3 AI
            shall provide Customer with reasonable cooperation and assistance needed to fulfil Customer’s obligation
            under Data Protection Laws and Regulations to carry out a data protection impact assessment related to
            Customer’s use of the C3 AI Services and C3 AI Software, to the extent Customer does not otherwise have
            access to the relevant information, and to the extent such information is available to C3 AI. C3 AI shall
            provide reasonable assistance to Customer with respect to the latter’s cooperation or prior consultation with
            the Supervisory Authority and/or applicable regulator(s) in the performance of its tasks relating to a data
            protection impact assessment. Customer shall be responsible for any costs arising from C3 AI’s provision of
            such assistance.

   9.       Return and Deletion of Customer Personal Data

   9.1 Upon written request to C3 AI within thirty (30) days of the date of cessation of any C3 AI Services or C3 AI
         Software involving the Processing of Customer Personal Data (the "Cessation Date"), C3 AI will make
         available to Customer a complete copy of all Customer Personal Data in the then-current format in which it
         is stored.

   9.2 After a 30-day period following the Cessation Date, C3 AI will permanently and irretrievably delete and procure
           the deletion of all copies of those Customer Personal Data Processed by C3 AI and any Sub-processor to the
           extent allowed by applicable law, in accordance with the procedures specified in the Technical Specification
           C3001: C3 AI Suite, Applications, and Data Security.

January 23, 2025                                                                                                          5
   9.3 The Parties agree that the certification of deletion of Customer Personal Data that is described in Clause 8 and 16
          of the Standard Contractual Clauses shall be provided by C3 AI to Customer only upon Customer’s request.

   10.      Audit rights

   10.1 Third-Party Certifications and Audits. C3 AI has obtained the third-party certifications and audits set forth in
          the Technical Specification C3001: C3 AI Suite, Applications, and Data Security.

   10.2 C3 AI uses external auditors to verify the adequacy of its security measures. This audit: (a) is performed at least
          annually; (b) is performed according to international standards (ISO 27001 standards or substantially
          equivalent alternatives); (c) is performed by independent third party security professionals
          selected by C3 AI and at C3 AI’s expense; and (d) results in the generation of an audit report (“Report”),
          which will be C3 AI’s Confidential Information.
   10.3 Upon Customer’s written request at reasonable intervals not to exceed annually, and subject to the confidentiality
          obligations set forth in the Agreement, C3 AI shall make available to Customer information regarding C3
          AI’s compliance with the obligations set forth in this DPA in the form of the third-party certifications and
          audits set forth in the Technical Specification C3001: C3 AI Suite, Applications, and Data Security, and the
          then-current confidential Report, so that Customer can reasonably verify C3 AI’s compliance with its
          obligations under this DPA.

   10.4    Customer agrees to exercise any right it may have to conduct an audit or inspection, including as applicable
           under the Standard Contractual Clauses, by instructing C3 AI to carry out the audit described in this Section
           10. Nothing in this Section varies or modifies the Standard Contractual Clauses nor affects any Supervisory
           Authority’s or Data Subject’s rights under the Standard Contractual Clauses.

   11.      Data Transfers

   11.1 Data Transfers. If the services and/or products provided by C3 AI under the Agreement involve an international
          transfer of Customer Personal Data between the Parties such transfer shall be in compliance with applicable
          Data Protection Laws and Regulations. If the Customer Personal Data transferred is governed by the GDPR,
          such transfer shall only occur subject to the conditions set out in section 11.3 and 11.4. For transfers of
          Customer Personal Data from the United Kingdom Section 11.2 shall apply.

   11.2   UK Standard Contractual Clauses. Parties agree that the SCCs supplemented by the International Data
           Transfer Addendum to the EU SCCs as provided by the UK ICO shall apply to transfers of Customer Personal
           Data from the United Kingdom, with Annex IA, Annex IB, Annex II and Annex III to this Agreement
           providing the relevant information where necessary.

   11.3 Standard Contractual Clauses. Depending on the circumstances of the transfer of Customer Personal Data,
   the Parties agree for transfers of Customer Personal Data from Customer or its Affiliates established in the EEA or
   Switzerland, as a data controller, to C3 AI established in a country outside the EEA, that the Controller to Processor
   Clauses of the SCCs shall apply. The Controller to Processor Clauses will only apply to Customer Personal Data that
   is transferred outside the EEA, either directly or via onward transfer, to any country not recognized by the European
   Commission as providing an adequate level of protection for Personal Data. Customer Personal Data that C3 AI
   processes on Customer’s behalf may only be disclosed to a third party located outside the EEA in accordance with
   clause 8.8 of the Controller to Processor Clauses.
   11.4 Instructions. This DPA and the Agreement are Customer’s complete and final documented instructions at the
             time of signature of the Agreement to C3 AI for the Processing of Customer Personal Data. For the purposes
             of the Standard Contractual Clauses, instructions by the Customer to Process Personal Data are described in
             Section 2.3 of this DPA.

   11.5 Sub-processors. Where the SCCs apply: (i) the Parties agree to use “Option 2” in clause 9, and (ii) Customer
          acknowledges and expressly agrees that C3 AI may use and/or engage Sub-processors as described in Section
          5 of this DPA.

January 23, 2025                                                                                                           6
   11.6   Audits. Where the SCCs apply: (i) the Parties agree that the audits mentioned in the Standard Contractual
           Clauses shall be carried out as described in Section 10 of this DPA; and (ii) to the extent Company’s audit
           requirements under the SCCs or Data Protection Laws cannot reasonably be satisfied through the Report, any
           other audit reports or other information C3 AI makes generally available to Customer, C3 AI will promptly
           respond to Customer’s additional audit instructions.

   12.     General Terms

           Governing law and jurisdiction

   12.1    Without prejudice to Clauses 17 (Governing Law) and 18 (Choice of forum and jurisdiction) of the Standard
           Contractual Clauses:

            12.1.1 the Parties to this DPA hereby submit to the choice of jurisdiction stipulated in the Agreement with
            respect to any disputes or claims howsoever arising under this DPA, including disputes regarding its
            existence, validity or termination or the consequences of its nullity; and

            12.1.2      this DPA and all non-contractual or other obligations arising out of or in connection with it are
            governed by the laws of the country or territory stipulated for this purpose in the Agreement.

           Order of precedence and severance

   12.2   In the event of any conflict or inconsistency between this DPA and the Standard Contractual Clauses, the
            Standard Contractual Clauses shall prevail. With regard to the subject matter of this DPA, in the event of
            inconsistencies between the provisions of this DPA and any other agreements between the Parties, including
            the Agreement and including (except where explicitly agreed otherwise in writing, signed on behalf of the
            Parties) agreements entered into or purported to be entered into after the date of this DPA, the provisions of
            this DPA shall prevail.

   12.3    Should any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain
           valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure
           its validity and enforceability, while preserving the Parties’ intentions as closely as possible or, if this is not
           possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.

           List of Attachments

           Annex I:        Details of Processing of Personal Data
           Annex II:     TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND
                          ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

           Annex III:     List of Sub-Processors

January 23, 2025                                                                                                                 7
                                                      ANNEX I

A. LIST OF PARTIES

 •     Data exporter(s)/Controller: Customer is the data exporter/controller and user of services rendered by, and/or
       products provided under the DPA and Agreement.
         Name of the data exporting organization: Customer Address:
         As specified in the Agreement.
         Contact person’s name, position and contact details: Contact details for the data exporter are specified in the
         Agreement. Details about the data exporter’s data protection officer are available to the data importer in the
         administrator panel (where such details have been provided by the data exporter).
         Activities relevant to the data transferred under these Clauses: The data importer provides the Services to the
         data exporter in accordance with the Agreement.
         Signature and date: The Parties agree that execution of the Agreement by the data importer and the data
         exporter shall constitute execution of these Clauses as of the Terms effective date of the Agreement.
 •     Data importer(s)/Processor:
        C3.ai, Inc. is the data importer/Processor and provider of the services and/or products provided under the
         DPA and Agreement.

         Address: 1400 Seaport Blvd, Redwood City, CA 94063

         Contact person’s name, position and contact details: Andrew Thomases, General Counsel, 650-503-2200,
         [email protected]

B. DESCRIPTION OF TRANSFER

     In the event Customer requires C3 AI to process personally identifiable information, then Customer will
     notify C3 AI in writing prior to providing Us any access to any such personal information. Customer will
     not provide any information that is considered protected health information under HIPAA, except pursuant
     to a separate Business Associate Agreement mutually agreed to in writing between the Customer and C3
     AI. Customer will not instruct or cause C3 AI to perform any Processing of Personal Data that violates any
     Data Protection Laws and Regulations. C3 AI may suspend Processing based upon any Customer
     instructions that C3 AI reasonably suspects violate Data Protection Laws and Regulations. Subject to the
     cooperation of C3 AI as specified in this DPA, Customer will be solely responsible for safeguarding the
     rights of Data Subjects, including determining the adequacy of the security measures in relation to Personal
     Data, performing any necessary risk assessments and determinations, and providing any necessary notice
     to or obtaining any necessary consent from Data Subjects regarding the Processing.

     Subject matter, Nature and Purpose of Processing: C3 AI will Process Customer Personal Data as notified by
     Customer to perform the C3 AI Services and provide the C3 AI Software pursuant to the Agreement.

     Obligations and rights of Customer: The obligations and rights of Customer are set out in the Agreement and
     this DPA.

     Duration of Processing: Subject to notification by Customer and Section 9 of this DPA, C3 AI will Process
     Customer Personal Data for the duration of the Agreement, unless otherwise agreed upon in writing.

     Categories of Data Subjects: Customer must notify and specify categories of personal data prior to processing
     by the C3 AI Services and C3 AI Software, the extent of which is determined and controlled by Customer in its
     sole discretion.
  Type of Personal Data: Customer must notify and specify categories of personal data prior to processing by the
  C3 AI Services and C3 AI Software, the extent of which is determined and controlled by Customer in its sole
  discretion.

  Restrictions Customer shall not use any PII of C3 AI or its employees outside the scope or purpose of the
  engagement.

C. COMPETENT SUPERVISORY AUTHORITY

  Identify the competent supervisory authority/ies in accordance with Clause 13:

      The Irish Supervisory Authority – The Data Protection Commission, unless the data exporter notifies the data
      importer of an alternative competent supervisory authority from time to time in accordance with the
      Agreement.
                                                      ANNEX II

          TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND
            ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

Description of the technical and organizational security measures implemented by the data importer:

The C3 AI Platform (formerly the C3 AI Suite) and C3 AI Applications employ advanced analytics and machine
learning at scale to deliver real-time or near real-time actionable insights for enterprise business imperatives. C3 AI
understands that the security, confidentiality, integrity, and availability of the C3 AI Platform and the C3 AI
Applications are important to customers.

Protecting Your data is a joint responsibility between you and C3 AI. C3 AI’s platform is built with security to protect
your data and applications. You can also implement your own security scheme to reflect the structure and needs of
your organization. C3 AI delivers a unified, cohesive suite of products through a scalable and secure hosting model:

C3 AI products are delivered as hosted PaaS and SaaS offerings deployed in secure Virtual Private Clouds. This
provides system scalability and data security combined with low overall cost of ownership.

C3 AI implements a rigorous Cyber Security Program to protect critical systems and information assets, constantly
monitoring and improving applications, systems, and processes to meet the growing demands and challenges of
security. Security of C3 AI’s hosting operations and C3 AI Platform has been validated in production deployments
for leading utility operators and large commercial and industrial organizations around the world.

C3 AI will maintain appropriate technical and organizational measures for protection of the security, confidentiality,
and integrity of Customer Data, as set forth in the Technical Specification C3001: C3 AI Suite, Applications, and Data
Security. The full text of C3 AI’s Technical Specification C3001: C3 AI Suite, Applications, and Data Security to
protect Customer Data is available to Customers upon request.
                                                ANNEX III

                                      LIST OF SUB-PROCESSORS

C3 AI is a Data Processor or Sub-processor and engages certain onward Sub-processors that may process Customer
Personal Data submitted to C3 AI’s Software and C3 AI Services by the Controller. The Sub-processors are listed
below are for C3 AI’s default offerings. This list may be updated by C3 AI from time to time as described in this
DPA.

Sub-Processor              Purpose                                Location                      PII
Amazon AWS                 Cloud Hosted Infrastructure and        United States, EMEA           Customer Data
                           Data Hosting                           (customer’s option)
Microsoft Azure            Cloud Hosted Infrastructure and        United States, EMEA           Customer Data
                           Data Hosting                           (customer’s option)
Google Cloud               Cloud Hosted Infrastructure and        United States, EMEA           Customer Data
                           Data Hosting                           (customer’s option)
Atlassian                  Customer Service & Support             United States                 User IDs
BGP Management             Customer Service & Support             Italy                         Per ticket
CCube SHPK                 Customer Service & Support             Albania                       Per ticket
Civilized Discourse        Customer Service & Support             United States                 Per ticket
Construction Kit, Inc.
Fractal Analytics          Security of Services & Performance     United States, India          Per ticket
                           Monitoring
Reply S.p.A.               Customer Service & Support             Europe                        Per ticket
ORTEC INT. USA, INC.       Customer Service & Support             United States, Europe         Per ticket
Pariveda Solutions         Customer Service & Support             United States                 Per ticket
Paradyme Management        Customer Service & Support             United States                 Pet ticket
Pendo                      Security of Services & Performance     United States                 User IDs
                           Monitoring
Zendesk                    Customer Support Ticketing             United States                 User IDs
                           Analysis
Optional
GitHub                     Code hosting platform for              United States                 User IDs
                           Customer-built Extensions
Okta                       Security of Services & Performance     United States                 User IDs
                           Monitoring
Splunk                     Logging Pipeline for Security Log,     United States                 User IDs
                           Storage, and Search