Third Party Index

Snapshot 19453

Document
Data processing addendum
URL
https://go.benevity.com/hubfs/website/legal/Benevity-Data-Processing-Addendum.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
573401 bytes
SHA-256 (raw)
809bc5fe028d6fb81eaaa553ad2e5681f8f3cf5b92866b6b7939591898c43588
SHA-256 (normalized text)
3e81656c9f2563c8fa2b0be15d82172ec4edeb50f232ed92cff1db183faa8d35

Normalized text

Scripts and page chrome removed; this is what change detection compares.

                          Data Processing Addendum
This Data Processing Addendum (the “DPA”) forms part of and is incorporated into the Master
Services Agreement between Benevity, Inc. (“Benevity”) and Client (as defined in the applicable
Order Document) (the “Agreement”). Benevity and Client are each a “Party” and together are the
“Parties.” This DPA applies where and to the extent that Benevity Processes Personal Data on behalf
of Client in connection with the Agreement.

For the avoidance of doubt, this DPA governs the Parties’ Processing of Personal Data under
Applicable Data Protection Law (as defined below). To the extent Regulation (EU) 2023/2854
applies to either Party, the Parties’ rights and obligations relating to data access, use, sharing,
disclosure, portability, compensation, confidentiality, trade secrets and public sector requests under
that regulation shall be governed by the EU Data Act Addendum (Appendix D). In the event of conflict
between this DPA and the EU Data Act Addendum, the EU Data Act Addendum shall prevail with
respect to matters within its scope.

Capitalized terms used but not defined in this DPA have the meanings given to them in the
Agreement.

RECITALS :-

       (A)​    All terms of the Agreement including all disclaimers, limitations of liability,
               agreements and indemnities apply to this DPA.

       (B)​    In the event of any conflict or inconsistency between the following documents, the
               order of precedence shall be as follows (highest to lowest):

                 (a)​    the applicable Data Privacy Framework, where relied upon for the relevant
                         Transfer;
                 (b)​    the Standard Contractual Clauses, UK Addendum, and/or Swiss Addendum,
                         as applicable;
                 (c)​    the EU Data Act Addendum (Appendix D);
                 (d)​    the body of this DPA;
                 (e)​    the Appendices (excluding the EU Data Act Addendum); and
                 (f)​    the Agreement.​​

        (C)​ For Personal Data subject to US Privacy Laws, the terms “business,” “business
               purpose,” “commercial purpose,” “consumer,” “controller,” “personal
               information,” “processor,” “sale,” “sell,” “service provider,” and “share” shall have
               the meanings given to them in the applicable US Privacy Laws, as amended from
               time to time. Where applicable, with respect to US Privacy Laws, Client is a
               “business” or “Controller” and is engaging Benevity as a “service provider” or
                                                                                                           2

              “Processor” to Process Covered Personal Data in the performance of the
              Services on behalf of Client.

        (D) For purposes of applicable U.S. Privacy Laws (including the CCPA), Benevity
              processes Covered Personal Data solely to provide the Services and not in
              exchange for monetary or other valuable consideration, and such Processing
              does not constitute a sale or sharing of Personal Data.

              Benevity shall:
                 (a)​    process Covered Personal Data only for the limited and specified business
                         purposes described in this Agreement;
                 (b)​    comply with applicable obligations under U.S. Privacy Laws and provide the
                         same level of privacy protection required thereunder;
                 (c)​    notify Client if it determines it can no longer meet its obligations under this
                         Section or applicable law; and
                 (d)​    cooperate with Client’s reasonable steps to verify compliance and to stop and
                         remediate any unauthorized Processing.

Benevity is prohibited from selling or sharing Covered Personal Data, or retaining, using, or disclosing
it for any purpose other than the Permitted Purpose, including any commercial purpose outside the
direct business relationship with Client.

 1.​    Definitions: In this DPA, the following terms shall have the following meanings:

       (a)​   “Applicable Data Protection Law” means all applicable laws and regulations
              relating to the processing of Personal Data in force from time to time, including,
              as applicable: (i) Regulation (EU) 2016/679 (the “GDPR”); (ii) in respect of the
              United Kingdom, the Data Protection Act 2018 and the GDPR as incorporated
              into United Kingdom law pursuant to section 3 of the European Union
              (Withdrawal) Act 2018 (the “UK GDPR”); (iii) in respect of Switzerland, the
              Federal Act on Data Protection (“Swiss FADP”); (iv) in respect of the United
              States, applicable federal and state privacy and data protection laws, including,
              without limitation, the California Consumer Privacy Act, Cal. Civ. Code §
              1798.100 et seq., as amended by the California Privacy Rights Act (the “CCPA”);
              and (v) any other applicable data protection or privacy laws.

       (b)​   “Controller” “Data Subject”, “Personal Data”, “Covered Personal Data”,
              “Processor” will have the meanings given in the GDPR, and the terms “process”,
              “processing” and “processed” shall be construed accordingly. Where Applicable
              Data Protection Law uses equivalent or analogous terms (including, for example,
              “business”, “service provider” or “contractor” under the CCPA/CPRA), such
              terms shall be interpreted to correspond to the definitions set out above, to the
              extent required by such laws.

       (c)​   “Data Breach” means the accidental or unlawful destruction, loss, alteration,
              unauthorized disclosure of, or access to, Personal Data transmitted, stored or
              otherwise Processed.

       (d)​   “Data Privacy Framework” means, as applicable, the EU-US Data Privacy
                                                                                                  3

             Framework, the UK Extension to the EU-US Data Privacy Framework, and the
             Swiss-US Data Privacy Framework, set forth by the U.S. Department of
             Commerce and, as applicable, the European Commission, the UK Government,
             and the Swiss Federal Administration.

      (e)​   "International Data Transfer Agreement” or “IDTA” means the template IDTA
             B1.0 issued by the United Kingdom’s Information Commissioner’s Office together
             with the relevant tables set out in the Annexes and Appendices of this
             Addendum.

      (f)​   “Restricted Transfer” means: (i) where the GDPR applies, a transfer of Personal
             Data from the EEA to a country outside the EEA that is not subject to an
             adequacy decision by the European Commission; (ii) where the UK GDPR
             applies, a transfer of Personal Data from the United Kingdom to a country that is
             not subject to UK adequacy regulations; and (iii) where the Swiss FADP applies, a
             transfer of Personal Data to a country outside Switzerland that does not ensure
             an adequate level of protection as determined by the Swiss Federal Council.

      (g)​   “Standard Contractual Clauses” or “SCCs” means: (i) where the GDPR applies,
             the standard contractual clauses annexed to European Commission
             Implementing Decision (EU) 2021/914 of 4 June 2021 (the “EU SCCs”); (ii)
             where the UK GDPR applies, the EU SCCs as supplemented by the UK
             International Data Transfer Addendum issued by the UK Information
             Commissioner (the “UK Addendum”) or, where applicable, the UK International
             Data Transfer Agreement (“IDTA”); and (iii) where the Swiss FADP applies, the
             EU SCCs as adapted or supplemented as necessary for transfers subject to
             Swiss data protection law.

      (h)​   “Subprocessor” means any third party (including any Affiliate of the Processor)
             engaged by the Processor to process Personal Data on behalf of the Controller.

      (i)​   “Transfer” means to disclose or otherwise make Personal Data available to a
             third party (including to any affiliate or Subprocessor), either by physical
             movement of the Personal Data to a third party or by enabling access to the
             Personal Data by other means.

      (j)​   “Transfer Impact Assessment” means an assessment carried out in connection
             with a Transfer of Personal Data to a third country, which evaluates, in the
             context of the specific transfer, whether the laws and practices of that country
             and any applicable safeguards ensure a level of protection for the Personal Data
             that is essentially equivalent to that guaranteed under applicable Data
             Protection Laws, including with respect to access by public authorities and the
             availability of enforceable rights and effective legal remedies for Data Subjects.

      (k)​   “UK Addendum” means the International Data Transfer Addendum to the EU
             Commission Standard Contractual Clauses issued by the UK Information
             Commissioner’s Office on 2 February 2022, as may be amended, updated or
             replaced from time to time.

2.​   Data Privacy Framework Certification: Benevity represents that Benevity International,
                                                                                                                             4

            Inc., an Affiliate of Benevity, is self-certified under the applicable Data Privacy
            Framework. To the extent Personal Data is transferred to Benevity International, Inc.
            and such transfer falls within the scope of its certification, such transfers may be made
            in reliance on the Data Privacy Framework.

            Benevity shall ensure that Benevity International, Inc. maintains such certification for so
            long as it relies on the Data Privacy Framework and shall promptly notify Client if such
            certification expires, is withdrawn, or otherwise ceases to be valid.

    3.​     Relationship of the Parties: Client as the Controller appoints Benevity as its Processor
            to Process the Personal Data provided to Benevity by Client.1 Each party shall comply
            with the obligations that apply to it under Applicable Data Protection Law. The Client
            retains control of the Personal Data and remains responsible for its compliance
            obligations under the Applicable Data Protection Law, including but not limited to
            providing any required notices and obtaining all required consents, and for the written
            processing instructions it gives to Benevity.​
            ​
            Where Benevity acts as an independent Controller, it shall comply with all obligations
            applicable to Controllers under Applicable Data Protection Laws, and nothing in this
            DPA shall be construed as creating a joint controllership relationship between the
            Parties unless expressly stated.
                       ​
             Any processing carried out by Benevity in its capacity as an independent Controller
             shall be separate and distinct from the processing performed on behalf of the Client
             and shall not diminish or modify Benevity’s obligations when acting as a Processor
             under this DPA.

    4.​     Purpose Limitation: Except where Benevity acts as an independent Controller as
            described in this DPA, or where disclosure, access, sharing or use is required or
            expressly permitted by applicable law, including Regulation (EU) 2023/2854 where
            applicable, Benevity shall Process Personal Data solely as a Processor for the
            Permitted Purpose of performing its obligations under the Agreement and in
            accordance with Client’s documented instructions (the “Permitted Purpose”), and in
            compliance with Applicable Data Protection Laws. The subject matter, nature, duration
            of Processing, and categories of Personal Data are as set out in the Agreement.

            If Benevity reasonably determines that any Processing required to comply with
            applicable law falls outside Client’s instructions, Benevity shall, to the extent legally
            permitted, inform Client prior to such Processing.

            Benevity shall not Process Personal Data for its own purposes or for the purposes of
            any third party.

    5.​     International Transfers: Benevity shall not Transfer the Personal Data (nor permit the
            Personal Data to be Transferred) across country borders unless it: (a) has first obtained

1
    The Parties acknowledge that Benevity may, for certain processing activities identified in the Benevity Privacy Notice
(https://benevity.com/legal/privacy-notice), determine its own purposes and means of processing Personal Data and shall
therefore act as an independent Controller in respect of those processing activities.
                                                                                                  5

      Client's prior written consent; (b) takes measures as are necessary and legally required,
      such as entering into applicable Standard Contractual Clauses; and (c) has
      implemented all necessary additional measures and safeguards as required by
      Applicable Data Protection Laws, such as conducting a Transfer Impact Assessment as
      necessary.

      Client hereby consents to the Transfer of Personal Data between Canada and the
      United States and across country borders as may be required to facilitate the Services,
      further, and for the avoidance of doubt (and where applicable only), the Client hereby
      consents to the appointment by Benevity of Subprocessors located outside the UK and
      the EEA, and the Client authorizes Benevity to enter into the SCCs contained in this
      DPA with such of its Subprocessors as is appropriate.

6.​   Confidentiality of Processing: Benevity shall ensure that any person that it authorizes to
      Process the Personal Data (including Benevity's staff, agents and subcontractors) (an
      "Authorized Person(s)") shall be subject to a strict duty of confidentiality (whether a
      contractual duty or a statutory duty), and shall not permit any person to Process the
      Personal Data who is not under such a duty of confidentiality. Benevity shall ensure that
      all Authorized Persons process the Personal Data only as necessary for the Permitted
      Purpose.

7.​   Security: Benevity shall implement appropriate technical and organizational measures
      to protect the Personal Data from Data Breaches in accordance with Benevity's
      Information Security Addendum available here
      (https://benevity.com/information-security-addendum). Such measures shall have
      regard to the state of the art, the costs of implementation and the nature, scope,
      context and purposes of Processing as well as the risk of varying likelihood and severity
      for the rights and freedoms of natural persons. At a minimum, such measures shall
      include the measures identified in Annex II to the Standard Contractual Clauses, listed
      at Appendix A of this DPA.

      Benevity also maintains an AI Policy, available here
      (https://benevity.com/legal/responsible-ai-policy#1-purpose) which describes
      Benevity’s internal governance and operational practices relating to the use of
      AI-enabled functionality, to the extent relevant to the Processing of Personal Data
      under the Agreement.

      Additionally, Benevity will ensure that, as appropriate, its employees:

      (a)​   are informed of the confidential nature of the Personal Data and are bound by
             confidentiality obligations and use restrictions in respect of the Personal Data;

      (b)​   have undertaken training on the Applicable Data Protection Law relating to
             handling Personal Data and how it applies to their particular duties; and

      (c)​   are aware of their duties and obligations to support the Security measures set
             out in Annex II to the Standard Contractual Clauses in Appendix B of this DPA.

8.​   Subprocessing: Client hereby provides a general written authorization for Benevity to
                                                                                                   6

       engage subprocessors in accordance with Article 28 of the GDPR, including those
       listed at: https://benevity.com/subprocessors. Where the Standard Contractual
       Clauses apply, this authorization shall constitute the Client’s general written
       authorization under Clause 9.

       For the avoidance of doubt, Benevity may transfer Personal Data to its Affiliates,
       including Benevity International, Inc., as Subprocessors in accordance with this Section.
       Where such Affiliate is certified under the Data Privacy Framework, transfers to that
       Affiliate may be made in reliance on such certification.

       Where Benevity engages a new Subprocessor to Process Personal Data, Benevity shall
       provide written notification to Client before the addition of any new Subprocessor,
       including details of the scope of Processing it performs or will perform and the location
       and identity of the Subprocessor. For each new Subprocessor, Benevity shall: (a)
       conduct adequate due diligence on the Subprocessor to ensure it is capable of
       providing the level of protection of Personal Data required by this DPA; (b) impose data
       protection terms on the Subprocessor that protect the Personal Data to the same
       standard provided for by this DPA. Benevity remains fully liable for any breach of this
       DPA that is caused by an act, error or omission of its Subprocessors. In the event that
       Client objects to the processing of its Personal Data by any proposed Subprocessor on
       reasonable grounds relating to data protection, Client shall inform Benevity in writing
       by emailing [email protected] within ten (10) days of initial notification. In such an
       event, the Parties shall negotiate in good faith a solution to Client’s objection. If the
       Parties cannot reach resolution within thirty (30) days of Benevity’s receipt of Client’s
       objection, then either: (a) Benevity will instruct the Subprocessor not to process
       Client's Personal Data, in which event this DPA shall continue unaffected, or (b) Client
       may elect to suspend or terminate the Agreement without penalty.

       If Client terminates the Agreement pursuant to this Section 8, it does so without
       penalty or liability (other than for fees due and owing to Benevity prior to such
       termination).

9.​    Cooperation and Data Subjects’ Rights: Taking into account the nature of the
       Processing, Benevity shall provide reasonable assistance (including by appropriate
       technical and organizational measures) to Client to enable Client to respond to: (a) any
       request from a Data Subject to exercise any of its rights under Applicable Data
       Protection Law (including its rights of access, correction, objection, erasure, and data
       portability, as applicable); and (b) any other correspondence, enquiry or complaint
       received from a Data Subject, regulator or other third party in connection with the
       Processing of the Personal Data (together, a “Request”). In the event that any such
       Request is made directly to Benevity, Benevity shall promptly inform the Client
       providing full details of the same.

10.​   Regulator Requests: Benevity shall promptly notify Client of any complaints,
       investigations, or notices of non-compliance received from any regulatory authority
       relating to the Processing of Personal Data (“Regulator Requests”).

       Except where Benevity is required under Applicable Data Protection Law to
                                                                                                       7

       communicate directly with a regulatory authority, Client shall have primary
       responsibility for responding to and managing all communications with such
       authorities relating to the Data and the Services. Where Benevity is required to
       communicate directly, it shall, to the extent legally permitted, notify Client in advance
       and keep Client reasonably informed of such communications.

       Benevity shall reasonably cooperate with Client and any relevant regulatory authority in
       connection with any investigation, inquiry, or proceeding relating to the Processing of
       Data, including by providing relevant information and assistance as required.

       Benevity shall not disclose or transfer Data to any regulatory authority, law
       enforcement body, or government agency except (a) as directed by Client, or (b)
       where required by applicable law, in which case Benevity shall, to the extent legally
       permitted, notify Client in advance of such disclosure.

       Notwithstanding the foregoing, nothing in this DPA shall prevent a Party from
       responding to a legally valid request or obligation under Regulation (EU) 2023/2854,
       including requests relating to user access, user-directed third-party sharing, or public
       sector access, provided the responding Party complies with any notice, minimisation,
       confidentiality, and trade secret protections required by applicable law.

11.​   Data Protection Impact Assessment: Taking into account the nature, scope, context and
       purposes of the Processing, if the Client directs, or if Benevity believes or becomes
       aware that its Processing of the Personal Data is likely to result in a high risk to the data
       protection rights and freedoms of Data Subjects, Benevity shall provide reasonable
       assistance to Client as necessary to enable Client to comply with its obligations relating
       to:

       (a)​     data protection impact assessments;

       (b) ​    prior consultation with supervisory authorities; and

       (c)​     transfer impact assessments where applicable.

12.​   Data Breaches: Upon becoming aware of a Data Breach affecting the Client’s Personal
       Data, Benevity shall inform Client without undue delay. Benevity shall provide timely
       information and cooperation as Client may reasonably require in order for Client to fulfil
       its data breach reporting obligations under (and in accordance with the timescales
       required by) Applicable Data Protection Law. Such notification shall include, at a
       minimum: (a) a description of the nature of the breach (including, where possible,
       categories and approximate number of Data Subjects and Personal Data records
       concerned); (b) details of a contact point where more information can be obtained; (c)
       a description of the likely consequences of the Data Breach; and (d) a description of
       the measures taken or proposed to address the Data Breach, including measures to
       mitigate its possible adverse effects. Benevity shall further take all such measures and
       actions as are reasonably necessary to remedy or mitigate the effects of the Personal
       Data Breach and shall keep Client up-to-date about all developments in connection
       with the Personal Data Breach.
                                                                                                     8

13.​   Deletion or Return of Personal Data: Upon termination or expiry of the Agreement,
       Benevity shall, at Client’s written election, either return or securely destroy Personal
       Data in its possession or control, including copies of such Personal Data, except as
       otherwise permitted under this Section. Notwithstanding the foregoing, Benevity may
       retain Personal Data to the extent required or permitted by applicable law, or as
       reasonably necessary for the prevention of fraud, enforcement of its legal rights, or
       compliance with taxation, accounting, and regulatory record retention requirements,
       which may generally require retention for a period of up to seven (7) years from the
       date of termination or expiry of the Agreement. The obligation to return or destroy
       Personal Data shall not apply to Personal Data that Benevity is required or permitted to
       retain pursuant to the foregoing. In such circumstances, Benevity shall implement
       appropriate measures to isolate and protect such Personal Data from further
       Processing, except to the extent required for the purposes described in this Section.
       For so long as Benevity retains any Personal Data pursuant to this Section: (i) Benevity
       shall continue to comply with its obligations of confidentiality and security under the
       Agreement and this DPA; (ii) such Personal Data shall not be used for any purpose
       other than those justifying its retention; and (iii) Benevity shall delete or securely
       destroy such Personal Data in accordance with its standard data retention and
       destruction policies once retention is no longer required or permitted.

14.​   Security Package, Audit and Inspection:

       (a)​    Security Package. Benevity will make available to Client, without charge: (i)
       Benevity’s audit reports and applicable certifications performed and/or provided by
       independent third-parties; (ii) PCI DSS attestations of compliance from payment
       processors (where available); (iii) information on Benevity’s information security and
       privacy programs; and (iv) a completed industry-standard information security
       questionnaire and frequently asked questions; (together, the “Security Package'').

       Benevity will assist Clients with reasonable inquiries or clarifications, and items that may
       not be covered by the Security Package at [email protected]. Where a Client
       requests that Benevity complete a custom security questionnaire, or where responses
       are duplicative of material available in the Security Package, Benevity may charge a
       reasonable agreed-upon fee to the Client for such additional assistance.

       (b)​   Audit and Inspection. To the extent that Client’s audit obligations under
              Applicable Data Protection Laws are not reasonably satisfied through the
              Security Package, Benevity shall permit Client, or its designated third-party
              auditors, to conduct audits or inspections of Benevity’s compliance with this
              DPA, as required by Applicable Data Protection Laws. Such audits or inspections
              shall be subject to the Parties’ mutual agreement on scope, timing, and duration.
              Client shall provide at least thirty (30) days’ prior written notice and shall
              conduct any audit during normal business hours in a manner that minimizes
              disruption to Benevity’s operations. Client shall ensure that its personnel and any
              third-party auditors comply with Benevity’s reasonable security requirements
              and are bound by confidentiality obligations no less protective than those set
              out in the Agreement. Except where an audit or inspection is required as a result
                                                                                                        9

                   of a Data Breach, Benevity may charge Client a reasonable, pre-agreed fee for
                   any additional assistance provided in connection with such audit or inspection.

       (c)​        Annual Request. Client will not exercise its audit and inspection rights more than
                   once in any twelve (12) calendar month period, except: (i) if and when required
                   by instruction of a competent data protection authority, Applicable Data
                   Protection ​      Law or the Standard Contractual Clauses; (ii) Client is seeking
                   information at the request of a competent data protection authority which
                   cannot otherwise be reasonably obtained from Benevity or through the use of
                   the Security Package; or (iii) Client reasonably believes a further audit is
                   necessary due to a Data Breach suffered ​ by Benevity.

       (d)​        EU Data Act. To the extent the EU Data Act Addendum applies, the Parties shall
                   also implement appropriate technical and organisational measures to protect
                   non-personal data, trade secrets, and other confidential information subject to
                   disclosure or sharing under Regulation (EU) 2023/2854.

15.​   Limitation of Liability: This DPA shall be subject to the limitations of liability agreed
       between the Parties set forth in the Agreement and any reference to the liability of a
       Party means that Party and its Affiliates in the aggregate. For the avoidance of doubt,
       Client acknowledges and agrees that Benevity’s total liability for all claims from Client
       or its Affiliates arising out of or related to the Agreement and this DPA shall apply in
       aggregate for all claims under both the Agreement and this DPA.

       This section shall not be construed as limiting the liability of either Party with respect to
       claims brought by data subjects under the EU SCCs’ and/or the UK Addendum.

       No provision of the Agreement or this DPA shall apply to the extent prohibited or
       rendered unenforceable by Regulation (EU) 2023/2854, including the provisions on
       unfair contractual terms in business-to-business data sharing.

16.​   Standard Contractual Clauses: To the extent Personal Data is transferred to Benevity
       International, Inc. (or another Affiliate of Benevity that is certified under the applicable
       Data Privacy Framework), and such transfer falls within the scope of that entity’s
       certification, the Parties agree that such Transfer shall be made in reliance on the
       applicable Data Privacy Framework.​
       ​
       To the extent a Transfer is not, or can no longer be, lawfully made in reliance on the
       applicable Data Privacy Framework, and Applicable Data Protection Law requires
       appropriate safeguards, such Transfer shall be governed by the applicable Standard
       Contractual Clauses, which are hereby incorporated by reference into and form part of
       this DPA.

       For Transfers subject to the GDPR, the applicable SCC module shall apply as follows:
           (i)​     Module One (Controller to Controller) shall apply where the Parties are acting
                    as independent controllers;
           (ii)​    Module Two (Controller to Processor) shall apply where Client acts as controller
                    and Benevity acts as processor;
                                                                                                  10

       (iii)​   Client is the data exporter and Benevity is the data importer;
       (iv)​    Clause 7 (Docking Clause) shall apply;
       (v)​     Clause 9, Option 2 shall apply, with Subprocessor notice as set out in Section
                ​ 8 of this DPA;
       (vi)​    Clause 11 optional language shall not apply;
       (vii)​   Clause 17, Option 1 (Irish law) shall apply;
       (viii)​ Clause 18(b), Irish courts shall apply.

       For transfers subject to UK or Swiss law, the SCCs shall apply as supplemented by the
       UK Addendum and/or Swiss Addendum.

       If neither the Data Privacy Framework nor the SCCs (including UK/Swiss adaptations)
       provide a lawful transfer mechanism, the Parties shall implement an alternative lawful
       transfer mechanism.

17.​   Subject to terms required by Applicable Data Protection Law, the term of this DPA shall
       be for the period in which the Agreement remains in force (“DPA Term”) and shall not
       be terminated prior to the end of the DPA Term unless there is a material breach of this
       DPA or the parties agree in writing.
                                                                                                        11

Appendix A - SCC Annexes

Application of Annexes

The parties agree that:

 (a)​   Annex II (Technical and Organisational Measures) and Annex III (List of Sub-processors) to
         the SCCs shall apply solely in respect of processing activities subject to Module 2 (Controller
         to Processor); and

 (b)​   Annex II and Annex III shall not apply to processing activities subject to Module 1 (Controller to
         Controller).

For the avoidance of doubt, where Module 1 applies, each party shall be independently responsible for
implementing appropriate technical and organisational measures in accordance with Applicable Data
Protection Law.
                                                                                                     12

                         Annex I - Description of the Transfer

A.​   List of Parties

Data Exporter

Name:                              Client, a user of the Services in the Agreement

Address:                           Address as listed in the Agreement

Contact person’s name, position    Contact information as listed in the Agreement
and contact details:

Activities relevant to the data    The data exporter has licensed certain software and associated
transferred under these Clauses:   technology of the data importer and utilizes data importer’s support
                                   services to enable and facilitate the administration of aspects of the
                                   data exporter’s corporate social responsibility and charitable giving
                                   programs. The data exporter will transfer personal data of authorized
                                   users (e.g. the data exporter’s employees) to the data importer, which
                                   will be hosted by a third-party data hosting facility, currently located
                                   in the United States. The data exporter consents to the transfer of
                                   personal data to the data importer’s third-party hosting facility.

Role Module 1:                     Controller

Role Module 2:                     Controller

Data Importer

Name:                              Benevity, Inc.

Address:                           #700, 611 Meredith Road NE, Calgary, Alberta, T2E 2W5

Contact person’s name, position    Director, Risk & Compliance, [email protected]
and contact details:

Activities relevant to the data    The software, associated technology and support services licensed or
transferred under these Clauses:   utilized by the data exporter requires personal data such as name and
                                   business e-mail address for identity verification and sign-on. In some
                                   cases, home address and other personal data of the data subject is
                                   provided by the data subject to access certain functionality, such as
                                   the generation of charitable tax receipts.

Role Module 1:                     Controller

Role Module 2:                     Processor
*(Execution of the Agreement into which this DPA is incorporated constitutes execution of
this DPA and, accordingly, of these Clauses)*
                                                                                                         13

B.​        Description of Transfer

Categories of data subjects whose personal data is transferred

Users authorized by the data exporter to use the software. This may include employees, contractors
or any other person authorized by the data exporter to be provided with access to the software (and
could include Clients’ workforce (employees, contractors, volunteers, temporary and casual workers),
and other personnel or workforce members).

Categories of personal data transferred

The personal data transferred pursuant to these Clauses is determined by the data exporter in its sole
discretion, and may include, without limitation, the following categories of data:
      ●​      Basic Contact information: First and last name, email address
      ●​      Business contact information, such as company name, business email, phone,
              business address, business unit, office or division, geographic business location, job
              title or role, reporting lines;
      ●​      Employment information, such as employee, payroll or workforce ID number;
      ●​      Transactional information such as giving, volunteering, Personal data pertaining
              to donation transactions (as defined below).
      ●​      Technical information related to data subjects, their systems or devices, and/or
              the use of their or third party systems or devices, including IP addresses, location
              data, usage data, usernames and other account information or credentials.
      ●​      Categories of personal data as otherwise agreed upon between Client and
              Service Provider in Agreements, including its exhibits, appendices, attachments
              and amendments.

Sensitive data transferred (if applicable)

No sensitive data is transferred.

The frequency of the transfer

Continuous with use of the Services as described in the Agreement.

Nature of the processing

The provision of the Services to Client in accordance with the Agreement.

Purpose(s) of the data transfer and further processing

Benevity will process Personal Data as necessary to perform the Services pursuant to the Agreement,
and as further instructed by Client in the use of the Services in order to enable and facilitate the
administration of aspects of the data exporter’s corporate social responsibility and charitable giving
programs.
                                                                                                             14

The period for which the personal data will be retained, or, if that is not possible, the criteria used to
determine that period

Personal data pertaining to donation transactions made through the platform must be retained in
accordance with applicable income tax laws, generally around 7 years, depending on the tax
jurisdiction.

Specifically, Personal data pertaining to donation transactions is what is required to prepare a
tax-deductible receipt, acceptable in accordance with applicable income tax law. This includes:
      ●​     Donor’s first and last name
      ●​     Donor’s business email
      ●​     Donor’s address for tax deductible receipt
      ●​     Date of donation
      ●​     Nominated cause
      ●​     Donation amount
      ●​     Donor’s comments shared with cause, if any

All other Personal data will only be retained as per client instructions for the duration of the contract.
Personal data may be deleted (anonymized) upon request of the data subject, or per Client
instructions.

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing

The subject matter, nature and duration of the processing are specified above and in the Agreement.

C.​        Competent Supervisory Authority
MODULE TWO: Transfer controller to processor

Client agrees the competent supervisory authority will be the Data Protection Commission (DPC) of
Ireland.
                                                                                                        15

                   Annex II to the EU Standard Contractual Clauses

​
TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND
ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

MODULE TWO: Transfer controller to processor

The data importer has implemented an information security management system (ISMS) based on
industry leading standards ISO 27001 and COBIT. This system is governed by a dedicated Risk &
Compliance function, which oversees related policies, procedures, and controls related to technical
and organizational security measures related to safeguarding client information.

A description of Benevity’s current technical and organizational security measures can be found in
Benevity’s Information Security Addendum “ISA” located here:
https://benevity.com/information-security-addendum. Benevity reserves the right to update its
security program from time to time; provided, however, any update will not materially reduce the
overall protections set forth in this document.

As described in this DPA, Benevity has measures in place to provide assistance to controllers as
needed. Such measures include, but are not limited to, the ability to delete all Data associated with
the Services, subject to Applicable Data Protection Law. With regard to Data Subject Requests, in the
event the controller is unable to address a Data Subject Request in its use of the Service, Benevity
will, upon request, provide commercially reasonable efforts to assist the controller in responding to
such Data Subject Request, to the extent Benevity is legally permitted to do so and the response to
such Data Subject Request is required under Applicable Data Protection Law. Data Subjects may also
exercise their rights by contacting Benevity at [email protected].
                                                                                                     16

                            Annex III Approved Subprocessors

Benevity maintains a current list of current Subprocessors at: https://benevity.com/subprocessors.
                                                                                                        17

Appendix B - UK Addendum

To the extent applicable, this UK Addendum Exhibit is incorporated into the DPA. If there is any
conflict between any provision of the UK Addendum and any provision of the DPA or any other
agreement (including without limitation any other exhibit, schedule, or other attachment thereto),
then the provision of the UK Addendum will control to the extent of such conflict with respect to the
Personal Data that is subject to the UK Addendum.
In the event of a Restricted Transfer, the parties enter into this Addendum as issued by the ICO and as
amended from time to time to the extent necessary to operate to provide Appropriate Safeguards for
Restricted Transfers in accordance with Article 46 of the UK GDPR.

                                            PART 1: TABLES

  TABLE 1
  PARTIES                     The Parties are set out in Annex I A of the Appendix to the Approved
                              EU SCCs.
  TABLE 2

  SELECTED SCCS,
                              The Approved EU SCCs are Commission Implementing Decision (EU)
  MODULES AND
                              2021/914, including:
  SELECTED CLAUSES
                                ●​ Module 1 (Controller to Controller)
                                ●​ Module 2 (Controller to Processor)

  TABLE 3

  APPENDIX​                   Annex I, II and III are set out in Appendix A to this DPA.
  INFORMATION

  TABLE 4

  ENDING THIS                 Neither Party shall have the right to end this Addendum pursuant to
  ADDENDUM WHEN               Section 19.
  THE APPROVED
  ADDENDUM
  CHANGES
                                  PART 2: MANDATORY CLAUSES

  The mandatory clauses of the International Data Transfer Addendum issued by the UK
  Information Commissioner and laid before Parliament in accordance with section 119A of the Data
  Protection Act 2018 (the “UK Addendum”), as revised from time to time in accordance with
  Section 18 of those mandatory clauses, are incorporated by reference.
                                                                                                        18

Appendix C – Switzerland Addendum

Where the Standard Contractual Clauses apply to a transfer of Personal Data subject to the Swiss
Federal Act on Data Protection (“Swiss FADP”), the Standard Contractual Clauses shall be deemed
amended as necessary to ensure compliance with the Swiss FADP, including as follows:

 (a)​   references to “Member State” shall be interpreted to include Switzerland, and data subjects in
         Switzerland shall be entitled to exercise their rights under the Standard Contractual Clauses;
 (b)​   the “competent supervisory authority” shall be the Swiss Federal Data Protection and
         Information Commissioner;
 (c)​   references to the “General Data Protection Regulation” or “Regulation (EU) 2016/679” shall
         be interpreted to include the Swiss FADP, as applicable; and
 (d)​   to the extent applicable, references to “personal data” shall include data relating to identified
         or identifiable legal entities until such time as Swiss law no longer applies to such data.
                                                                                                      19

Appendix D – EU Data Act

This EU Data Act Addendum (the “Addendum”) forms part of and is incorporated into the Data
Processing Addendum (“DPA”) and the Agreement between Benevity, Inc. (“Benevity”) and Client
(each a “Party” and together the “Parties”).

1. Purpose and Scope
This Addendum applies solely to the extent Regulation (EU) 2023/2854 (the “EU Data Act”) is
applicable to either Party.

This Addendum governs the Parties’ rights and obligations relating to access, use, sharing, disclosure,
and availability of data under the EU Data Act.

Except as expressly set out herein, this Addendum does not amend the Parties’ obligations under
Applicable Data Protection Law.

In the event of any conflict or inconsistency between this Addendum and the DPA or the Agreement,
this Addendum shall prevail with respect to matters within its scope.

2. Definitions
For the purposes of this Addendum:

“Data Act Data” means data generated by the use of a product or related service within the scope of
the EU Data Act, whether personal or non-personal.

“User” means a natural or legal person entitled to access or request sharing of Data Act Data under
the EU Data Act.

“Data Holder” means a Party that is obligated to make Data Act Data available under the EU Data Act.

Terms not defined in this Addendum shall have the meanings given to them in the DPA or the
Agreement, as applicable.

3. Role of the Parties
Each Party acknowledges that it may act as a Data Holder depending on the circumstances of the
processing and control of Data Act Data.

Each Party’s obligations under this Addendum apply only to the extent it qualifies as a Data Holder or
is otherwise subject to obligations under the EU Data Act.

Nothing in this Addendum shall be construed as modifying the Parties’ respective roles under the DPA
with respect to Personal Data.

4. Access to Data by Users
Where a Party acts as a Data Holder, it shall:
   (a)​ make Data Act Data available to the User without undue delay;
   (b)​ provide such data in a structured, commonly used, and machine-readable format;
                                                                                                     20

    (c)​ provide access in a manner that is technically feasible and proportionate, taking into account
            the nature of the data and the services;
    (d)​ not impose unjustified technical, contractual, or organizational barriers to access.

5. Sharing of Data with Third Parties
Where a Party is required under the EU Data Act to make Data Act Data available to a third party
designated by a User, that Party shall:
 (a)​    implement reasonable measures to verify the validity and authenticity of the request;
 (b)​    ensure secure transmission of the Data Act Data;
 (c)​    limit disclosure to the data required under the EU Data Act.

A receiving Party or third party shall:
 (i)​    use Data Act Data only for purposes agreed with the User and permitted under the EU Data
          Act;
 (ii)​   not use the Data Act Data to develop, enhance, or offer products or services that compete
          with those of the Data Holder, except as permitted under the EU Data Act.

6. Personal and Non-Personal Data
The Parties acknowledge that Data Act Data may include both Personal Data and non-personal data.
 (a)​    Personal Data shall continue to be processed in accordance with Applicable Data Protection
          Law and the DPA;
 (b)​    the EU Data Act shall apply to non-personal data and to access and sharing obligations arising
          under it.

Nothing in this Addendum requires a Party to process or disclose Personal Data in violation of
Applicable Data Protection Law.

7. Protection of Trade Secrets and Confidential Information
Nothing in this Addendum requires a Party to disclose trade secrets or confidential information
without appropriate safeguards.

Where disclosure is required under the EU Data Act, the disclosing Party may:
 (a)​    implement proportionate technical and organizational measures to preserve confidentiality;
 (b)​    require the receiving Party to enter into appropriate confidentiality obligations;
 (c)​    refuse, suspend, or condition disclosure where permitted under the EU Data Act to protect
          trade secrets or security.

8. Security Measures
Each Party shall implement appropriate technical and organizational measures to protect Data Act
Data, including during access and sharing, against unauthorized access, loss, or disclosure.

9. Compensation
Where permitted by the EU Data Act, a Party acting as a Data Holder may charge reasonable
compensation for making Data Act Data available, limited to:
 (a)​    costs directly related to making the data available; and
                                                                                                        21

 (b)​    any margin permitted under applicable law.

10. Public Sector Requests
Where a Party receives a request from a public sector body under the EU Data Act, it shall:
 (a)​    assess the legal validity of the request;
 (b)​    limit disclosure to what is strictly necessary;
 (c)​    implement appropriate safeguards, including confidentiality protections;
 (d)​    inform the other Party of such request where legally permitted.

11. Prohibition of Unfair Terms
The Parties shall not rely on or enforce contractual terms that are prohibited under the EU Data Act,
including those deemed unfair in business-to-business data sharing relationships.

12. Liability
Each Party shall be responsible for its own compliance with the EU Data Act.

Liability arising under this Addendum shall be subject to the limitations of liability set out in the
Agreement, except to the extent such limitations are restricted or prohibited by the EU Data Act.

13. Term
This Addendum shall remain in effect for the duration of the DPA and for so long as the EU Data Act
applies to either Party.

                                             [END OF DPA]