Snapshot 19453
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Data Processing Addendum
This Data Processing Addendum (the “DPA”) forms part of and is incorporated into the Master
Services Agreement between Benevity, Inc. (“Benevity”) and Client (as defined in the applicable
Order Document) (the “Agreement”). Benevity and Client are each a “Party” and together are the
“Parties.” This DPA applies where and to the extent that Benevity Processes Personal Data on behalf
of Client in connection with the Agreement.
For the avoidance of doubt, this DPA governs the Parties’ Processing of Personal Data under
Applicable Data Protection Law (as defined below). To the extent Regulation (EU) 2023/2854
applies to either Party, the Parties’ rights and obligations relating to data access, use, sharing,
disclosure, portability, compensation, confidentiality, trade secrets and public sector requests under
that regulation shall be governed by the EU Data Act Addendum (Appendix D). In the event of conflict
between this DPA and the EU Data Act Addendum, the EU Data Act Addendum shall prevail with
respect to matters within its scope.
Capitalized terms used but not defined in this DPA have the meanings given to them in the
Agreement.
RECITALS :-
(A) All terms of the Agreement including all disclaimers, limitations of liability,
agreements and indemnities apply to this DPA.
(B) In the event of any conflict or inconsistency between the following documents, the
order of precedence shall be as follows (highest to lowest):
(a) the applicable Data Privacy Framework, where relied upon for the relevant
Transfer;
(b) the Standard Contractual Clauses, UK Addendum, and/or Swiss Addendum,
as applicable;
(c) the EU Data Act Addendum (Appendix D);
(d) the body of this DPA;
(e) the Appendices (excluding the EU Data Act Addendum); and
(f) the Agreement.
(C) For Personal Data subject to US Privacy Laws, the terms “business,” “business
purpose,” “commercial purpose,” “consumer,” “controller,” “personal
information,” “processor,” “sale,” “sell,” “service provider,” and “share” shall have
the meanings given to them in the applicable US Privacy Laws, as amended from
time to time. Where applicable, with respect to US Privacy Laws, Client is a
“business” or “Controller” and is engaging Benevity as a “service provider” or
2
“Processor” to Process Covered Personal Data in the performance of the
Services on behalf of Client.
(D) For purposes of applicable U.S. Privacy Laws (including the CCPA), Benevity
processes Covered Personal Data solely to provide the Services and not in
exchange for monetary or other valuable consideration, and such Processing
does not constitute a sale or sharing of Personal Data.
Benevity shall:
(a) process Covered Personal Data only for the limited and specified business
purposes described in this Agreement;
(b) comply with applicable obligations under U.S. Privacy Laws and provide the
same level of privacy protection required thereunder;
(c) notify Client if it determines it can no longer meet its obligations under this
Section or applicable law; and
(d) cooperate with Client’s reasonable steps to verify compliance and to stop and
remediate any unauthorized Processing.
Benevity is prohibited from selling or sharing Covered Personal Data, or retaining, using, or disclosing
it for any purpose other than the Permitted Purpose, including any commercial purpose outside the
direct business relationship with Client.
1. Definitions: In this DPA, the following terms shall have the following meanings:
(a) “Applicable Data Protection Law” means all applicable laws and regulations
relating to the processing of Personal Data in force from time to time, including,
as applicable: (i) Regulation (EU) 2016/679 (the “GDPR”); (ii) in respect of the
United Kingdom, the Data Protection Act 2018 and the GDPR as incorporated
into United Kingdom law pursuant to section 3 of the European Union
(Withdrawal) Act 2018 (the “UK GDPR”); (iii) in respect of Switzerland, the
Federal Act on Data Protection (“Swiss FADP”); (iv) in respect of the United
States, applicable federal and state privacy and data protection laws, including,
without limitation, the California Consumer Privacy Act, Cal. Civ. Code §
1798.100 et seq., as amended by the California Privacy Rights Act (the “CCPA”);
and (v) any other applicable data protection or privacy laws.
(b) “Controller” “Data Subject”, “Personal Data”, “Covered Personal Data”,
“Processor” will have the meanings given in the GDPR, and the terms “process”,
“processing” and “processed” shall be construed accordingly. Where Applicable
Data Protection Law uses equivalent or analogous terms (including, for example,
“business”, “service provider” or “contractor” under the CCPA/CPRA), such
terms shall be interpreted to correspond to the definitions set out above, to the
extent required by such laws.
(c) “Data Breach” means the accidental or unlawful destruction, loss, alteration,
unauthorized disclosure of, or access to, Personal Data transmitted, stored or
otherwise Processed.
(d) “Data Privacy Framework” means, as applicable, the EU-US Data Privacy
3
Framework, the UK Extension to the EU-US Data Privacy Framework, and the
Swiss-US Data Privacy Framework, set forth by the U.S. Department of
Commerce and, as applicable, the European Commission, the UK Government,
and the Swiss Federal Administration.
(e) "International Data Transfer Agreement” or “IDTA” means the template IDTA
B1.0 issued by the United Kingdom’s Information Commissioner’s Office together
with the relevant tables set out in the Annexes and Appendices of this
Addendum.
(f) “Restricted Transfer” means: (i) where the GDPR applies, a transfer of Personal
Data from the EEA to a country outside the EEA that is not subject to an
adequacy decision by the European Commission; (ii) where the UK GDPR
applies, a transfer of Personal Data from the United Kingdom to a country that is
not subject to UK adequacy regulations; and (iii) where the Swiss FADP applies, a
transfer of Personal Data to a country outside Switzerland that does not ensure
an adequate level of protection as determined by the Swiss Federal Council.
(g) “Standard Contractual Clauses” or “SCCs” means: (i) where the GDPR applies,
the standard contractual clauses annexed to European Commission
Implementing Decision (EU) 2021/914 of 4 June 2021 (the “EU SCCs”); (ii)
where the UK GDPR applies, the EU SCCs as supplemented by the UK
International Data Transfer Addendum issued by the UK Information
Commissioner (the “UK Addendum”) or, where applicable, the UK International
Data Transfer Agreement (“IDTA”); and (iii) where the Swiss FADP applies, the
EU SCCs as adapted or supplemented as necessary for transfers subject to
Swiss data protection law.
(h) “Subprocessor” means any third party (including any Affiliate of the Processor)
engaged by the Processor to process Personal Data on behalf of the Controller.
(i) “Transfer” means to disclose or otherwise make Personal Data available to a
third party (including to any affiliate or Subprocessor), either by physical
movement of the Personal Data to a third party or by enabling access to the
Personal Data by other means.
(j) “Transfer Impact Assessment” means an assessment carried out in connection
with a Transfer of Personal Data to a third country, which evaluates, in the
context of the specific transfer, whether the laws and practices of that country
and any applicable safeguards ensure a level of protection for the Personal Data
that is essentially equivalent to that guaranteed under applicable Data
Protection Laws, including with respect to access by public authorities and the
availability of enforceable rights and effective legal remedies for Data Subjects.
(k) “UK Addendum” means the International Data Transfer Addendum to the EU
Commission Standard Contractual Clauses issued by the UK Information
Commissioner’s Office on 2 February 2022, as may be amended, updated or
replaced from time to time.
2. Data Privacy Framework Certification: Benevity represents that Benevity International,
4
Inc., an Affiliate of Benevity, is self-certified under the applicable Data Privacy
Framework. To the extent Personal Data is transferred to Benevity International, Inc.
and such transfer falls within the scope of its certification, such transfers may be made
in reliance on the Data Privacy Framework.
Benevity shall ensure that Benevity International, Inc. maintains such certification for so
long as it relies on the Data Privacy Framework and shall promptly notify Client if such
certification expires, is withdrawn, or otherwise ceases to be valid.
3. Relationship of the Parties: Client as the Controller appoints Benevity as its Processor
to Process the Personal Data provided to Benevity by Client.1 Each party shall comply
with the obligations that apply to it under Applicable Data Protection Law. The Client
retains control of the Personal Data and remains responsible for its compliance
obligations under the Applicable Data Protection Law, including but not limited to
providing any required notices and obtaining all required consents, and for the written
processing instructions it gives to Benevity.
Where Benevity acts as an independent Controller, it shall comply with all obligations
applicable to Controllers under Applicable Data Protection Laws, and nothing in this
DPA shall be construed as creating a joint controllership relationship between the
Parties unless expressly stated.
Any processing carried out by Benevity in its capacity as an independent Controller
shall be separate and distinct from the processing performed on behalf of the Client
and shall not diminish or modify Benevity’s obligations when acting as a Processor
under this DPA.
4. Purpose Limitation: Except where Benevity acts as an independent Controller as
described in this DPA, or where disclosure, access, sharing or use is required or
expressly permitted by applicable law, including Regulation (EU) 2023/2854 where
applicable, Benevity shall Process Personal Data solely as a Processor for the
Permitted Purpose of performing its obligations under the Agreement and in
accordance with Client’s documented instructions (the “Permitted Purpose”), and in
compliance with Applicable Data Protection Laws. The subject matter, nature, duration
of Processing, and categories of Personal Data are as set out in the Agreement.
If Benevity reasonably determines that any Processing required to comply with
applicable law falls outside Client’s instructions, Benevity shall, to the extent legally
permitted, inform Client prior to such Processing.
Benevity shall not Process Personal Data for its own purposes or for the purposes of
any third party.
5. International Transfers: Benevity shall not Transfer the Personal Data (nor permit the
Personal Data to be Transferred) across country borders unless it: (a) has first obtained
1
The Parties acknowledge that Benevity may, for certain processing activities identified in the Benevity Privacy Notice
(https://benevity.com/legal/privacy-notice), determine its own purposes and means of processing Personal Data and shall
therefore act as an independent Controller in respect of those processing activities.
5
Client's prior written consent; (b) takes measures as are necessary and legally required,
such as entering into applicable Standard Contractual Clauses; and (c) has
implemented all necessary additional measures and safeguards as required by
Applicable Data Protection Laws, such as conducting a Transfer Impact Assessment as
necessary.
Client hereby consents to the Transfer of Personal Data between Canada and the
United States and across country borders as may be required to facilitate the Services,
further, and for the avoidance of doubt (and where applicable only), the Client hereby
consents to the appointment by Benevity of Subprocessors located outside the UK and
the EEA, and the Client authorizes Benevity to enter into the SCCs contained in this
DPA with such of its Subprocessors as is appropriate.
6. Confidentiality of Processing: Benevity shall ensure that any person that it authorizes to
Process the Personal Data (including Benevity's staff, agents and subcontractors) (an
"Authorized Person(s)") shall be subject to a strict duty of confidentiality (whether a
contractual duty or a statutory duty), and shall not permit any person to Process the
Personal Data who is not under such a duty of confidentiality. Benevity shall ensure that
all Authorized Persons process the Personal Data only as necessary for the Permitted
Purpose.
7. Security: Benevity shall implement appropriate technical and organizational measures
to protect the Personal Data from Data Breaches in accordance with Benevity's
Information Security Addendum available here
(https://benevity.com/information-security-addendum). Such measures shall have
regard to the state of the art, the costs of implementation and the nature, scope,
context and purposes of Processing as well as the risk of varying likelihood and severity
for the rights and freedoms of natural persons. At a minimum, such measures shall
include the measures identified in Annex II to the Standard Contractual Clauses, listed
at Appendix A of this DPA.
Benevity also maintains an AI Policy, available here
(https://benevity.com/legal/responsible-ai-policy#1-purpose) which describes
Benevity’s internal governance and operational practices relating to the use of
AI-enabled functionality, to the extent relevant to the Processing of Personal Data
under the Agreement.
Additionally, Benevity will ensure that, as appropriate, its employees:
(a) are informed of the confidential nature of the Personal Data and are bound by
confidentiality obligations and use restrictions in respect of the Personal Data;
(b) have undertaken training on the Applicable Data Protection Law relating to
handling Personal Data and how it applies to their particular duties; and
(c) are aware of their duties and obligations to support the Security measures set
out in Annex II to the Standard Contractual Clauses in Appendix B of this DPA.
8. Subprocessing: Client hereby provides a general written authorization for Benevity to
6
engage subprocessors in accordance with Article 28 of the GDPR, including those
listed at: https://benevity.com/subprocessors. Where the Standard Contractual
Clauses apply, this authorization shall constitute the Client’s general written
authorization under Clause 9.
For the avoidance of doubt, Benevity may transfer Personal Data to its Affiliates,
including Benevity International, Inc., as Subprocessors in accordance with this Section.
Where such Affiliate is certified under the Data Privacy Framework, transfers to that
Affiliate may be made in reliance on such certification.
Where Benevity engages a new Subprocessor to Process Personal Data, Benevity shall
provide written notification to Client before the addition of any new Subprocessor,
including details of the scope of Processing it performs or will perform and the location
and identity of the Subprocessor. For each new Subprocessor, Benevity shall: (a)
conduct adequate due diligence on the Subprocessor to ensure it is capable of
providing the level of protection of Personal Data required by this DPA; (b) impose data
protection terms on the Subprocessor that protect the Personal Data to the same
standard provided for by this DPA. Benevity remains fully liable for any breach of this
DPA that is caused by an act, error or omission of its Subprocessors. In the event that
Client objects to the processing of its Personal Data by any proposed Subprocessor on
reasonable grounds relating to data protection, Client shall inform Benevity in writing
by emailing [email protected] within ten (10) days of initial notification. In such an
event, the Parties shall negotiate in good faith a solution to Client’s objection. If the
Parties cannot reach resolution within thirty (30) days of Benevity’s receipt of Client’s
objection, then either: (a) Benevity will instruct the Subprocessor not to process
Client's Personal Data, in which event this DPA shall continue unaffected, or (b) Client
may elect to suspend or terminate the Agreement without penalty.
If Client terminates the Agreement pursuant to this Section 8, it does so without
penalty or liability (other than for fees due and owing to Benevity prior to such
termination).
9. Cooperation and Data Subjects’ Rights: Taking into account the nature of the
Processing, Benevity shall provide reasonable assistance (including by appropriate
technical and organizational measures) to Client to enable Client to respond to: (a) any
request from a Data Subject to exercise any of its rights under Applicable Data
Protection Law (including its rights of access, correction, objection, erasure, and data
portability, as applicable); and (b) any other correspondence, enquiry or complaint
received from a Data Subject, regulator or other third party in connection with the
Processing of the Personal Data (together, a “Request”). In the event that any such
Request is made directly to Benevity, Benevity shall promptly inform the Client
providing full details of the same.
10. Regulator Requests: Benevity shall promptly notify Client of any complaints,
investigations, or notices of non-compliance received from any regulatory authority
relating to the Processing of Personal Data (“Regulator Requests”).
Except where Benevity is required under Applicable Data Protection Law to
7
communicate directly with a regulatory authority, Client shall have primary
responsibility for responding to and managing all communications with such
authorities relating to the Data and the Services. Where Benevity is required to
communicate directly, it shall, to the extent legally permitted, notify Client in advance
and keep Client reasonably informed of such communications.
Benevity shall reasonably cooperate with Client and any relevant regulatory authority in
connection with any investigation, inquiry, or proceeding relating to the Processing of
Data, including by providing relevant information and assistance as required.
Benevity shall not disclose or transfer Data to any regulatory authority, law
enforcement body, or government agency except (a) as directed by Client, or (b)
where required by applicable law, in which case Benevity shall, to the extent legally
permitted, notify Client in advance of such disclosure.
Notwithstanding the foregoing, nothing in this DPA shall prevent a Party from
responding to a legally valid request or obligation under Regulation (EU) 2023/2854,
including requests relating to user access, user-directed third-party sharing, or public
sector access, provided the responding Party complies with any notice, minimisation,
confidentiality, and trade secret protections required by applicable law.
11. Data Protection Impact Assessment: Taking into account the nature, scope, context and
purposes of the Processing, if the Client directs, or if Benevity believes or becomes
aware that its Processing of the Personal Data is likely to result in a high risk to the data
protection rights and freedoms of Data Subjects, Benevity shall provide reasonable
assistance to Client as necessary to enable Client to comply with its obligations relating
to:
(a) data protection impact assessments;
(b) prior consultation with supervisory authorities; and
(c) transfer impact assessments where applicable.
12. Data Breaches: Upon becoming aware of a Data Breach affecting the Client’s Personal
Data, Benevity shall inform Client without undue delay. Benevity shall provide timely
information and cooperation as Client may reasonably require in order for Client to fulfil
its data breach reporting obligations under (and in accordance with the timescales
required by) Applicable Data Protection Law. Such notification shall include, at a
minimum: (a) a description of the nature of the breach (including, where possible,
categories and approximate number of Data Subjects and Personal Data records
concerned); (b) details of a contact point where more information can be obtained; (c)
a description of the likely consequences of the Data Breach; and (d) a description of
the measures taken or proposed to address the Data Breach, including measures to
mitigate its possible adverse effects. Benevity shall further take all such measures and
actions as are reasonably necessary to remedy or mitigate the effects of the Personal
Data Breach and shall keep Client up-to-date about all developments in connection
with the Personal Data Breach.
8
13. Deletion or Return of Personal Data: Upon termination or expiry of the Agreement,
Benevity shall, at Client’s written election, either return or securely destroy Personal
Data in its possession or control, including copies of such Personal Data, except as
otherwise permitted under this Section. Notwithstanding the foregoing, Benevity may
retain Personal Data to the extent required or permitted by applicable law, or as
reasonably necessary for the prevention of fraud, enforcement of its legal rights, or
compliance with taxation, accounting, and regulatory record retention requirements,
which may generally require retention for a period of up to seven (7) years from the
date of termination or expiry of the Agreement. The obligation to return or destroy
Personal Data shall not apply to Personal Data that Benevity is required or permitted to
retain pursuant to the foregoing. In such circumstances, Benevity shall implement
appropriate measures to isolate and protect such Personal Data from further
Processing, except to the extent required for the purposes described in this Section.
For so long as Benevity retains any Personal Data pursuant to this Section: (i) Benevity
shall continue to comply with its obligations of confidentiality and security under the
Agreement and this DPA; (ii) such Personal Data shall not be used for any purpose
other than those justifying its retention; and (iii) Benevity shall delete or securely
destroy such Personal Data in accordance with its standard data retention and
destruction policies once retention is no longer required or permitted.
14. Security Package, Audit and Inspection:
(a) Security Package. Benevity will make available to Client, without charge: (i)
Benevity’s audit reports and applicable certifications performed and/or provided by
independent third-parties; (ii) PCI DSS attestations of compliance from payment
processors (where available); (iii) information on Benevity’s information security and
privacy programs; and (iv) a completed industry-standard information security
questionnaire and frequently asked questions; (together, the “Security Package'').
Benevity will assist Clients with reasonable inquiries or clarifications, and items that may
not be covered by the Security Package at [email protected]. Where a Client
requests that Benevity complete a custom security questionnaire, or where responses
are duplicative of material available in the Security Package, Benevity may charge a
reasonable agreed-upon fee to the Client for such additional assistance.
(b) Audit and Inspection. To the extent that Client’s audit obligations under
Applicable Data Protection Laws are not reasonably satisfied through the
Security Package, Benevity shall permit Client, or its designated third-party
auditors, to conduct audits or inspections of Benevity’s compliance with this
DPA, as required by Applicable Data Protection Laws. Such audits or inspections
shall be subject to the Parties’ mutual agreement on scope, timing, and duration.
Client shall provide at least thirty (30) days’ prior written notice and shall
conduct any audit during normal business hours in a manner that minimizes
disruption to Benevity’s operations. Client shall ensure that its personnel and any
third-party auditors comply with Benevity’s reasonable security requirements
and are bound by confidentiality obligations no less protective than those set
out in the Agreement. Except where an audit or inspection is required as a result
9
of a Data Breach, Benevity may charge Client a reasonable, pre-agreed fee for
any additional assistance provided in connection with such audit or inspection.
(c) Annual Request. Client will not exercise its audit and inspection rights more than
once in any twelve (12) calendar month period, except: (i) if and when required
by instruction of a competent data protection authority, Applicable Data
Protection Law or the Standard Contractual Clauses; (ii) Client is seeking
information at the request of a competent data protection authority which
cannot otherwise be reasonably obtained from Benevity or through the use of
the Security Package; or (iii) Client reasonably believes a further audit is
necessary due to a Data Breach suffered by Benevity.
(d) EU Data Act. To the extent the EU Data Act Addendum applies, the Parties shall
also implement appropriate technical and organisational measures to protect
non-personal data, trade secrets, and other confidential information subject to
disclosure or sharing under Regulation (EU) 2023/2854.
15. Limitation of Liability: This DPA shall be subject to the limitations of liability agreed
between the Parties set forth in the Agreement and any reference to the liability of a
Party means that Party and its Affiliates in the aggregate. For the avoidance of doubt,
Client acknowledges and agrees that Benevity’s total liability for all claims from Client
or its Affiliates arising out of or related to the Agreement and this DPA shall apply in
aggregate for all claims under both the Agreement and this DPA.
This section shall not be construed as limiting the liability of either Party with respect to
claims brought by data subjects under the EU SCCs’ and/or the UK Addendum.
No provision of the Agreement or this DPA shall apply to the extent prohibited or
rendered unenforceable by Regulation (EU) 2023/2854, including the provisions on
unfair contractual terms in business-to-business data sharing.
16. Standard Contractual Clauses: To the extent Personal Data is transferred to Benevity
International, Inc. (or another Affiliate of Benevity that is certified under the applicable
Data Privacy Framework), and such transfer falls within the scope of that entity’s
certification, the Parties agree that such Transfer shall be made in reliance on the
applicable Data Privacy Framework.
To the extent a Transfer is not, or can no longer be, lawfully made in reliance on the
applicable Data Privacy Framework, and Applicable Data Protection Law requires
appropriate safeguards, such Transfer shall be governed by the applicable Standard
Contractual Clauses, which are hereby incorporated by reference into and form part of
this DPA.
For Transfers subject to the GDPR, the applicable SCC module shall apply as follows:
(i) Module One (Controller to Controller) shall apply where the Parties are acting
as independent controllers;
(ii) Module Two (Controller to Processor) shall apply where Client acts as controller
and Benevity acts as processor;
10
(iii) Client is the data exporter and Benevity is the data importer;
(iv) Clause 7 (Docking Clause) shall apply;
(v) Clause 9, Option 2 shall apply, with Subprocessor notice as set out in Section
8 of this DPA;
(vi) Clause 11 optional language shall not apply;
(vii) Clause 17, Option 1 (Irish law) shall apply;
(viii) Clause 18(b), Irish courts shall apply.
For transfers subject to UK or Swiss law, the SCCs shall apply as supplemented by the
UK Addendum and/or Swiss Addendum.
If neither the Data Privacy Framework nor the SCCs (including UK/Swiss adaptations)
provide a lawful transfer mechanism, the Parties shall implement an alternative lawful
transfer mechanism.
17. Subject to terms required by Applicable Data Protection Law, the term of this DPA shall
be for the period in which the Agreement remains in force (“DPA Term”) and shall not
be terminated prior to the end of the DPA Term unless there is a material breach of this
DPA or the parties agree in writing.
11
Appendix A - SCC Annexes
Application of Annexes
The parties agree that:
(a) Annex II (Technical and Organisational Measures) and Annex III (List of Sub-processors) to
the SCCs shall apply solely in respect of processing activities subject to Module 2 (Controller
to Processor); and
(b) Annex II and Annex III shall not apply to processing activities subject to Module 1 (Controller to
Controller).
For the avoidance of doubt, where Module 1 applies, each party shall be independently responsible for
implementing appropriate technical and organisational measures in accordance with Applicable Data
Protection Law.
12
Annex I - Description of the Transfer
A. List of Parties
Data Exporter
Name: Client, a user of the Services in the Agreement
Address: Address as listed in the Agreement
Contact person’s name, position Contact information as listed in the Agreement
and contact details:
Activities relevant to the data The data exporter has licensed certain software and associated
transferred under these Clauses: technology of the data importer and utilizes data importer’s support
services to enable and facilitate the administration of aspects of the
data exporter’s corporate social responsibility and charitable giving
programs. The data exporter will transfer personal data of authorized
users (e.g. the data exporter’s employees) to the data importer, which
will be hosted by a third-party data hosting facility, currently located
in the United States. The data exporter consents to the transfer of
personal data to the data importer’s third-party hosting facility.
Role Module 1: Controller
Role Module 2: Controller
Data Importer
Name: Benevity, Inc.
Address: #700, 611 Meredith Road NE, Calgary, Alberta, T2E 2W5
Contact person’s name, position Director, Risk & Compliance, [email protected]
and contact details:
Activities relevant to the data The software, associated technology and support services licensed or
transferred under these Clauses: utilized by the data exporter requires personal data such as name and
business e-mail address for identity verification and sign-on. In some
cases, home address and other personal data of the data subject is
provided by the data subject to access certain functionality, such as
the generation of charitable tax receipts.
Role Module 1: Controller
Role Module 2: Processor
*(Execution of the Agreement into which this DPA is incorporated constitutes execution of
this DPA and, accordingly, of these Clauses)*
13
B. Description of Transfer
Categories of data subjects whose personal data is transferred
Users authorized by the data exporter to use the software. This may include employees, contractors
or any other person authorized by the data exporter to be provided with access to the software (and
could include Clients’ workforce (employees, contractors, volunteers, temporary and casual workers),
and other personnel or workforce members).
Categories of personal data transferred
The personal data transferred pursuant to these Clauses is determined by the data exporter in its sole
discretion, and may include, without limitation, the following categories of data:
● Basic Contact information: First and last name, email address
● Business contact information, such as company name, business email, phone,
business address, business unit, office or division, geographic business location, job
title or role, reporting lines;
● Employment information, such as employee, payroll or workforce ID number;
● Transactional information such as giving, volunteering, Personal data pertaining
to donation transactions (as defined below).
● Technical information related to data subjects, their systems or devices, and/or
the use of their or third party systems or devices, including IP addresses, location
data, usage data, usernames and other account information or credentials.
● Categories of personal data as otherwise agreed upon between Client and
Service Provider in Agreements, including its exhibits, appendices, attachments
and amendments.
Sensitive data transferred (if applicable)
No sensitive data is transferred.
The frequency of the transfer
Continuous with use of the Services as described in the Agreement.
Nature of the processing
The provision of the Services to Client in accordance with the Agreement.
Purpose(s) of the data transfer and further processing
Benevity will process Personal Data as necessary to perform the Services pursuant to the Agreement,
and as further instructed by Client in the use of the Services in order to enable and facilitate the
administration of aspects of the data exporter’s corporate social responsibility and charitable giving
programs.
14
The period for which the personal data will be retained, or, if that is not possible, the criteria used to
determine that period
Personal data pertaining to donation transactions made through the platform must be retained in
accordance with applicable income tax laws, generally around 7 years, depending on the tax
jurisdiction.
Specifically, Personal data pertaining to donation transactions is what is required to prepare a
tax-deductible receipt, acceptable in accordance with applicable income tax law. This includes:
● Donor’s first and last name
● Donor’s business email
● Donor’s address for tax deductible receipt
● Date of donation
● Nominated cause
● Donation amount
● Donor’s comments shared with cause, if any
All other Personal data will only be retained as per client instructions for the duration of the contract.
Personal data may be deleted (anonymized) upon request of the data subject, or per Client
instructions.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
The subject matter, nature and duration of the processing are specified above and in the Agreement.
C. Competent Supervisory Authority
MODULE TWO: Transfer controller to processor
Client agrees the competent supervisory authority will be the Data Protection Commission (DPC) of
Ireland.
15
Annex II to the EU Standard Contractual Clauses
TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND
ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
MODULE TWO: Transfer controller to processor
The data importer has implemented an information security management system (ISMS) based on
industry leading standards ISO 27001 and COBIT. This system is governed by a dedicated Risk &
Compliance function, which oversees related policies, procedures, and controls related to technical
and organizational security measures related to safeguarding client information.
A description of Benevity’s current technical and organizational security measures can be found in
Benevity’s Information Security Addendum “ISA” located here:
https://benevity.com/information-security-addendum. Benevity reserves the right to update its
security program from time to time; provided, however, any update will not materially reduce the
overall protections set forth in this document.
As described in this DPA, Benevity has measures in place to provide assistance to controllers as
needed. Such measures include, but are not limited to, the ability to delete all Data associated with
the Services, subject to Applicable Data Protection Law. With regard to Data Subject Requests, in the
event the controller is unable to address a Data Subject Request in its use of the Service, Benevity
will, upon request, provide commercially reasonable efforts to assist the controller in responding to
such Data Subject Request, to the extent Benevity is legally permitted to do so and the response to
such Data Subject Request is required under Applicable Data Protection Law. Data Subjects may also
exercise their rights by contacting Benevity at [email protected].
16
Annex III Approved Subprocessors
Benevity maintains a current list of current Subprocessors at: https://benevity.com/subprocessors.
17
Appendix B - UK Addendum
To the extent applicable, this UK Addendum Exhibit is incorporated into the DPA. If there is any
conflict between any provision of the UK Addendum and any provision of the DPA or any other
agreement (including without limitation any other exhibit, schedule, or other attachment thereto),
then the provision of the UK Addendum will control to the extent of such conflict with respect to the
Personal Data that is subject to the UK Addendum.
In the event of a Restricted Transfer, the parties enter into this Addendum as issued by the ICO and as
amended from time to time to the extent necessary to operate to provide Appropriate Safeguards for
Restricted Transfers in accordance with Article 46 of the UK GDPR.
PART 1: TABLES
TABLE 1
PARTIES The Parties are set out in Annex I A of the Appendix to the Approved
EU SCCs.
TABLE 2
SELECTED SCCS,
The Approved EU SCCs are Commission Implementing Decision (EU)
MODULES AND
2021/914, including:
SELECTED CLAUSES
● Module 1 (Controller to Controller)
● Module 2 (Controller to Processor)
TABLE 3
APPENDIX Annex I, II and III are set out in Appendix A to this DPA.
INFORMATION
TABLE 4
ENDING THIS Neither Party shall have the right to end this Addendum pursuant to
ADDENDUM WHEN Section 19.
THE APPROVED
ADDENDUM
CHANGES
PART 2: MANDATORY CLAUSES
The mandatory clauses of the International Data Transfer Addendum issued by the UK
Information Commissioner and laid before Parliament in accordance with section 119A of the Data
Protection Act 2018 (the “UK Addendum”), as revised from time to time in accordance with
Section 18 of those mandatory clauses, are incorporated by reference.
18
Appendix C – Switzerland Addendum
Where the Standard Contractual Clauses apply to a transfer of Personal Data subject to the Swiss
Federal Act on Data Protection (“Swiss FADP”), the Standard Contractual Clauses shall be deemed
amended as necessary to ensure compliance with the Swiss FADP, including as follows:
(a) references to “Member State” shall be interpreted to include Switzerland, and data subjects in
Switzerland shall be entitled to exercise their rights under the Standard Contractual Clauses;
(b) the “competent supervisory authority” shall be the Swiss Federal Data Protection and
Information Commissioner;
(c) references to the “General Data Protection Regulation” or “Regulation (EU) 2016/679” shall
be interpreted to include the Swiss FADP, as applicable; and
(d) to the extent applicable, references to “personal data” shall include data relating to identified
or identifiable legal entities until such time as Swiss law no longer applies to such data.
19
Appendix D – EU Data Act
This EU Data Act Addendum (the “Addendum”) forms part of and is incorporated into the Data
Processing Addendum (“DPA”) and the Agreement between Benevity, Inc. (“Benevity”) and Client
(each a “Party” and together the “Parties”).
1. Purpose and Scope
This Addendum applies solely to the extent Regulation (EU) 2023/2854 (the “EU Data Act”) is
applicable to either Party.
This Addendum governs the Parties’ rights and obligations relating to access, use, sharing, disclosure,
and availability of data under the EU Data Act.
Except as expressly set out herein, this Addendum does not amend the Parties’ obligations under
Applicable Data Protection Law.
In the event of any conflict or inconsistency between this Addendum and the DPA or the Agreement,
this Addendum shall prevail with respect to matters within its scope.
2. Definitions
For the purposes of this Addendum:
“Data Act Data” means data generated by the use of a product or related service within the scope of
the EU Data Act, whether personal or non-personal.
“User” means a natural or legal person entitled to access or request sharing of Data Act Data under
the EU Data Act.
“Data Holder” means a Party that is obligated to make Data Act Data available under the EU Data Act.
Terms not defined in this Addendum shall have the meanings given to them in the DPA or the
Agreement, as applicable.
3. Role of the Parties
Each Party acknowledges that it may act as a Data Holder depending on the circumstances of the
processing and control of Data Act Data.
Each Party’s obligations under this Addendum apply only to the extent it qualifies as a Data Holder or
is otherwise subject to obligations under the EU Data Act.
Nothing in this Addendum shall be construed as modifying the Parties’ respective roles under the DPA
with respect to Personal Data.
4. Access to Data by Users
Where a Party acts as a Data Holder, it shall:
(a) make Data Act Data available to the User without undue delay;
(b) provide such data in a structured, commonly used, and machine-readable format;
20
(c) provide access in a manner that is technically feasible and proportionate, taking into account
the nature of the data and the services;
(d) not impose unjustified technical, contractual, or organizational barriers to access.
5. Sharing of Data with Third Parties
Where a Party is required under the EU Data Act to make Data Act Data available to a third party
designated by a User, that Party shall:
(a) implement reasonable measures to verify the validity and authenticity of the request;
(b) ensure secure transmission of the Data Act Data;
(c) limit disclosure to the data required under the EU Data Act.
A receiving Party or third party shall:
(i) use Data Act Data only for purposes agreed with the User and permitted under the EU Data
Act;
(ii) not use the Data Act Data to develop, enhance, or offer products or services that compete
with those of the Data Holder, except as permitted under the EU Data Act.
6. Personal and Non-Personal Data
The Parties acknowledge that Data Act Data may include both Personal Data and non-personal data.
(a) Personal Data shall continue to be processed in accordance with Applicable Data Protection
Law and the DPA;
(b) the EU Data Act shall apply to non-personal data and to access and sharing obligations arising
under it.
Nothing in this Addendum requires a Party to process or disclose Personal Data in violation of
Applicable Data Protection Law.
7. Protection of Trade Secrets and Confidential Information
Nothing in this Addendum requires a Party to disclose trade secrets or confidential information
without appropriate safeguards.
Where disclosure is required under the EU Data Act, the disclosing Party may:
(a) implement proportionate technical and organizational measures to preserve confidentiality;
(b) require the receiving Party to enter into appropriate confidentiality obligations;
(c) refuse, suspend, or condition disclosure where permitted under the EU Data Act to protect
trade secrets or security.
8. Security Measures
Each Party shall implement appropriate technical and organizational measures to protect Data Act
Data, including during access and sharing, against unauthorized access, loss, or disclosure.
9. Compensation
Where permitted by the EU Data Act, a Party acting as a Data Holder may charge reasonable
compensation for making Data Act Data available, limited to:
(a) costs directly related to making the data available; and
21
(b) any margin permitted under applicable law.
10. Public Sector Requests
Where a Party receives a request from a public sector body under the EU Data Act, it shall:
(a) assess the legal validity of the request;
(b) limit disclosure to what is strictly necessary;
(c) implement appropriate safeguards, including confidentiality protections;
(d) inform the other Party of such request where legally permitted.
11. Prohibition of Unfair Terms
The Parties shall not rely on or enforce contractual terms that are prohibited under the EU Data Act,
including those deemed unfair in business-to-business data sharing relationships.
12. Liability
Each Party shall be responsible for its own compliance with the EU Data Act.
Liability arising under this Addendum shall be subject to the limitations of liability set out in the
Agreement, except to the extent such limitations are restricted or prohibited by the EU Data Act.
13. Term
This Addendum shall remain in effect for the duration of the DPA and for so long as the EU Data Act
applies to either Party.
[END OF DPA]