Third Party Index

Snapshot 19848

Document
Subprocessor list
URL
https://www.automationanywhere.com/legal/dpa#subprocessors
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
291625 bytes
SHA-256 (raw)
d94ce600bc1f6e7a05c2151beab95361201f727b870d4061adafd6e513705787
SHA-256 (normalized text)
f920eac97155edf1036f86a31916d1ddc800859555583e1ea22961fea06a4a9a

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Automation Anywhere, Inc.
Data Processing Agreements
Customer
Partner
DATA PROCESSING ADDENDUM
This Notice was last updated on September 25, 2026
This Data Processing Addendum ("DPA") is entered into and forms part of the Intelligent Automation Agreement (including any former designations such as Cloud Automation Agreement or On-Premise Software License Agreement) or any other agreement under which AAI provides Services to Customer which does not exclude the processing of Personal Data - each, as applicable, the "Agreement") between the customer identified in such Agreement (“Customer”) and Automation Anywhere, Inc. ("AAI"). Customer and AAI are each referred to as a “Party” and collectively as the “Parties”. Customer enters into this DPA on behalf of itself and, to the extent required under Applicable Privacy Law, in the name and on behalf of its Authorized Affiliates, if and to the extent AAI processes Personal Data for which such Authorized Affiliates qualify as the Controller or Processor. AAI may modify this DPA but any such amendment(s) shall not materially increase Customer’s liabilities and/or obligations nor shall it materially decrease AAI’s obligations and/or liabilities unless required by Applicable Privacy Law.
All capitalized terms not defined herein shall have the meaning set forth in the Agreement. In providing Services to Customer pursuant to the Agreement, AAI may process Customer Personal Data on behalf of Customer and the parties agree to comply with the following provisions with respect to any Customer Personal Data.
Definitions. The terms used in this DPA shall have the meanings set forth in this DPA or as defined by Applicable Privacy Law, whichever is broader. Capitalized terms not otherwise defined herein or defined by Applicable Privacy Law shall have the meaning given to them in the Agreement. The following terms have the meanings set forth below:
“Affiliate” means any entity not under sanctions or embargo restrictions by the U.S. Government that directly or indirectly controls, is controlled by, or is under common control with the subject entity. “Control,” for purposes of this definition, means possessing, directly or indirectly, the power to direct or cause the direction of the management, policies and operations of such entity, whether through ownership of voting securities, by contract or otherwise.
“Authorized Affiliate” means any of Customer’s Affiliate(s) which (a) is subject to Applicable Privacy Law, and (b) is permitted to use the Services pursuant to the Agreement between Customer and AAI, but has not signed its own Order Form with AAI and is not a “Customer” as defined under the Agreement.
“Applicable Privacy Law” means the following laws and regulations applicable to the Processing of Customer Personal Data under the Agreement: (a) the California Consumer Privacy Act as amended by the California Privacy Rights Act and any binding regulations promulgated thereunder (“CCPA”), (b) the Colorado Privacy Act (“CPA”), (c) the Virginia Consumer Data Protection Act (“VCDPA”), (d) the Connecticut Data Protection Act (“CTDPA”), (e) the Utah Consumer Privacy Act (“UCPA”) (f) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”), (g) the Swiss Federal Act on Data Protection (“FADP”), (h) the EU GDPR as it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act 2018 and the UK Data Protection Act 2018 (the “UK GDPR”); (i) the Argentine Law 25,326 Personal Data Protection Law (“PDPL”); and (j) the data privacy laws of any country, state, or territory in which Customer and AAI have agreed, in writing, to process Personal Data(“Agreed Laws””), in each case, as updated, amended or replaced from time to time.
“EEA” means the European Economic Area.
“Data Subject” means an identified or identifiable natural person, or such other similar term as may be defined by Applicable Privacy Law.
“Personal Data” means (a) personal data, personal information, personally identifiable information, or similar term as defined by Applicable Privacy Law or (b) if not defined by Applicable Privacy Law, any information that relates to a Data Subject; in each case, to the extent Processed by AAI, on behalf of Customer, in connection with AAI’s performance of the Services.
“Privacy Authority” means any competent supervisory authority, attorney general, or other regulator with responsibility for privacy or data protection matters.
“Process”, “Processes”, “Processing” or “Processed” means any operation or set of operations, as defined in the Applicable Privacy Law, performed upon Personal Data whether or not by automatic means, including collecting, recording, organizing, storing, adapting or altering, retrieving, consulting, using, disclosing, making available, aligning, combining, blocking, erasing and destroying Personal Data.
“Restricted Transfer” means: (a) where EU GDPR applies, a transfer of Personal Data to a country outside the EEA that is not subject to an adequacy determination, (b) where UK GDPR applies, a transfer of Personal Data from the United Kingdom to any other country that is not subject to an adequacy determination, (c) where FADP applies, a transfer of Personal Data to a country outside Switzerland that is not subject to an adequacy determination, (d) where PDPL applies, a transfer of Personal Data to a country outside Argentina that is not subject to an adequacy determination, and (e) with respect to any other country where Applicable Privacy Law apply that restrict overseas transfers, an overseas transfer to a country that is not subject to an adequacy decision or otherwise requires some form of transfer mechanism to be implemented in order to comply with such Applicable Privacy Law (such transfer being any “Other Restricted Transfer”).
“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data while being processed by AAI. For purposes of this DPA, Security Incident shall also include any other similar term as defined by Applicable Privacy Law. Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks or other network attacks on firewalls or networked systems.
“Services” means (a) the technical support that AAI provides to Customer (the “Support Services”) as part of the Agreement and, to the extent applicable (b) AAI’s software-as-a-service intelligent automation platform and related applications (including downloaded components) available as a connected suite of applications or as separate applications and hosted in AAI’s cloud environment (the “Cloud Services”) and AAI’s proprietary software applications in machine-readable, object code form only, which are hosted in Customer’s virtual private cloud or otherwise operated in a Customer environment (to the extent information is provided to or collected by AAI) in each case as provided by or on behalf of AAI under the Agreement.
“Standard Contractual Clauses” means (a) with respect to restricted transfers (as such term is defined under Applicable Privacy Law) which are subject to the EU GDPR and /or the FADP, the Controller-to-Processor standard contractual clauses or the Processor-to-Processor standard contractual clauses (as applicable), as set out in the European Commission’s Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to GDPR, as may be amended or replaced by the European Commission from time to time (the “EU SCCs”), (b) with respect to restricted transfers subject to the UK GDPR, the International Data Transfer DPA to the EU Commission Standard Contractual Clauses of 21 March 2022, as may be amended or replaced by the UK Information Commissioner’s Office from time to time (the “UK SCCs”), (c) with respect to restricted transfers subject to PDPL, the standard international transfer contractual clauses contained in Appendix II (provision of services), as set out in Regulation No. 60-E/2016 (“Argentinian SCCs”), and (d) with respect to restricted transfers subject to Agreed Laws, such standard contract clauses as may be required by the Agreed Laws to be implemented between AAI and Customer (“Other Applicable Transfer Clauses”).
“Subprocessor” means any third party or AAI Affiliate engaged by AAI to Process Personal Data on behalf of AAI.
Scope. This DPA applies to AAI as a Processor of Personal Data and to Customer as a Controller or Processor of Personal Data, and to AAI’s Processing of Personal Data under the Agreement to the extent such Processing is subject to Applicable Privacy Law. This DPA is governed by the governing law of the Agreement unless otherwise set forth herein or required by Applicable Privacy Law.
Processing Requirements.
AAI shall comply with all Applicable Privacy Law in the Processing of Personal Data and only Process Personal Data for the purposes of providing the Services and in accordance with Customer’s instructions, which shall include Processing for purposes of performing the Services in accordance with the Agreement. AAI shall promptly inform Customer if (a) in AAI’s opinion, an instruction from Customer violates Applicable Privacy Law; or (b) AAI is required by applicable law to otherwise Process Personal Data, unless AAI is prohibited by that law from notifying Customer.
AAI shall provide to Customer such cooperation, assistance and information as Customer may reasonably request to enable it to comply with its obligations under Applicable Privacy Law and co-operate and comply with the directions or decisions of a relevant Privacy Authority, in each case (a) solely to the extent applicable to AAI’s provision of the Services, and (b) within such reasonable time as would enable Customer to meet any time limit imposed by the Privacy Authority.
Customer Responsibilities
Customer shall, in its use of the Services, Process Personal Data in accordance with the requirements of Applicable Privacy Law, including without limitation in accordance with any requirements to obtain consent, or other legal basis, for processing by, or transfer to, AAI. For the avoidance of doubt, Customer’s instructions for the Processing of Personal Data shall comply with Applicable Privacy Law. Customer shall have sole responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired Customer Personal Data.
Support. Customer acknowledges and agrees that Personal Data provided or made available to AAI for Processing in connection with support shall consist of business contact information only, in the form of support ticket authentication data, relating to Customer’s employees, agents or contractors only (“Support Authentication Data”). Support Authentication Data contains the following categories of data: First and Last Name, Title, Location, Employer and Contact Information (company, email, phone, physical business address), Username, optional avatar if provided for the support community, language preference, preferred hours of contact and IP Address. Customer and its users are prohibited from submitting attachments to, or screensharing with, support when such attachments or screensharing contain Personal Data or protected health information.
Multifactor Authentication (“MFA”). AAI offers the ability for Customer to access the Services using MFA and Customer is strongly encouraged to use MFA to access the Services whenever Customer submits health data, financial data, critical infrastructure data, or any other sensitive data to the Services.
Subprocessors
Customer generally authorizes AAI to engage Subprocessors to Process Personal Data. Customer further agrees that AAI may engage its Affiliates as Subprocessors. AAI will maintain an up-to-date list of its Subprocessors, including their functions and locations. AAI’s current list of Subprocessors for Services is attached hereto as Exhibit C to this DPA (“DPA Exhibit C”).
AAI may update the Subprocessor List from time to time. At least 30 days before any new Subprocessor Processes any Customer Personal Data, AAI will add such Subprocessor to the Subprocessor List and notify Customer through email and/or the support portal.
If Customer wishes to object to a new Subprocessor based on reasonable data protection concerns, it can do so within 30 days after notice of a new Subprocessor by following any process described by AAI in its notification to Customer or via registered letter sent to:
Attention: Legal Department (Privacy Counsel)
Automaton Anywhere, Inc.
633 River Oaks Pkwy
San Jose, CA 95134
United States of America
[email protected]
AAI shall respond to such objections within a reasonable time frame so long as such objections have a reasonable basis.
AAI will: (a) enter into a written agreement with each Subprocessor, imposing data processing and protection safeguards substantially the same as those set out in Exhibit B to this DPA (“DPA Exhibit B”), and (b) remain liable for compliance with the obligations of this DPA and for any acts or omissions of a Subprocessor that cause AAI to breach any of its obligations under this DPA.
Security of Personal Data.
In addition to any data security provisions in the Agreement, AAI represents and warrants that it has implemented and will maintain reasonable and appropriate physical, technical, organizational and administrative safeguards to preserve and protect the confidentiality, security, integrity, availability, and authenticity of the Personal Data and to protect against Security Incidents, including the security measures set forth in DPA Exhibit B.
AAI shall ensure personnel who Process Personal Data either enter into written confidentiality agreements or are subject to statutory obligations of confidentiality.
Customer is responsible for reviewing the information made available by AAI relating to data security and making an independent determination as to whether the Services meet Customer’s requirements and legal obligations under Applicable Privacy Law.
Customer is solely responsible for complying with Security Incident notification laws applicable to Customer and fulfilling any obligations to give notices to government authorities, affected individuals or others relating to any Security Incidents.
Breach Notification.
AAI will (a) notify Customer without undue delay and, in any event, not later than 72 hours, after becoming aware of a Security Incident affecting Customer and (b) make reasonable efforts to identify the cause of the Security Incident, mitigate the effects, and remediate the cause to the extent within AAI’s reasonable control. Customer acknowledges that AAI’s notification of a Security Incident is not an acknowledgement by AAI of its fault or liability.
Upon Customer’s request and taking into account the nature of the applicable Processing, AAI will assist Customer by providing, when available, information reasonably necessary for Customer to meet its Security Incident notification obligations under Applicable Privacy Law.
Data Protection Impact Assessment. Upon Customer’s request and taking into account the nature of the applicable Processing, AAI will provide Customer with assistance in fulfilling Customer’s obligations under Applicable Privacy Law to carry out a data protection impact or similar risk assessment related to Customer’s use of the Services, to the extent such information is available to AAI, including, if required by Applicable Privacy Law, to assist Customer in consultations with relevant Privacy Authorities.
Audit Rights. Upon 30 days’ written notice by Customer and subject to the confidentiality obligations set forth in the Agreement, AAI shall make available to Customer its procedures relevant to the protection of Customer Personal Data in the form of AAI’s third-party certifications and audit reports to the extent that AAI makes them generally available to its customers (“Audit Records”). Customer may request Audit Records through AAI’s compliance portal at https://www.automationanywhere.com/compliance-portal. In the event of a Security Incident, Customer shall have the right to request a copy of the most recent Audit Records, a root cause of the Security Incident report, a remediation plan, and upon completion, a copy of a remediation report showing any identified root cause remediated.
Deletion of Personal Data. Unless instructed earlier by Customer or subject to an earlier deletion schedule by the specific Services in accordance with Documentation (as defined in the Agreement), AAI shall delete Customer Personal Data processed in connection with (a) its provision of the Support Services within 90 days after the associated help desk ticket is closed and (b) its provision of the Cloud Services within 30 days after termination of the Agreement, in each case unless otherwise required by law.
CCPA. In the event of AAI Processing the Personal Data of Data Subjects who are California consumers under the CCPA, the required contractual clauses of the CCPA, as may be amended or replaced from time to time, are incorporated herein. Customer and AAI hereby acknowledge and agree that in no event shall the transfer of Personal Data from Customer to AAI constitute a sale of Personal Data or transfer of Personal Data for valuable consideration to AAI, and that nothing shall be construed as providing for the sale or transfer for valuable consideration of Personal Data to AAI. AAI shall not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than to perform the Services; (c) retain, use, or disclose Personal Data outside of the direct business relationship between Customer and AAI; or (d) combine Personal Data with personal information that AAI receives from or on behalf of another business or person, or that it collects from its own interactions with individuals, unless otherwise permitted by the CCPA. Furthermore, (i) the specific Business Purpose(s) for which AAI is processing Personal Data is contained in the Agreement and AAI acknowledges that Customer is disclosing the Personal Data to AAI only for the limited and specified Services set forth in the Agreement; (ii) AAI shall comply with all applicable sections of the CCPA, including providing the same level of privacy protection as required of Customer by the CCPA with respect to the Personal Data as specified in DPA Exhibit B ; (iii) Customer has the right to take reasonable and appropriate steps to ensure AAI uses the Personal Data in a manner consistent with Customer’s obligations under the CCPA, and such steps will be in the form of receiving copies of AAI’s Audit Records. To the extent steps beyond the review of Audit Records is required by the CCPA, and so long as there is a mutual agreement as to the scope of the assessment in advance, AAI shall allow Customer or its designee (who shall not be a competitor of AAI and shall enter into an appropriate confidentiality agreement with AAI), upon 30-day notice during normal business hours, and at Customer’s expense, assess AAI’s compliance with the CCPA specifically as to Customer’s Personal Data; (iv) Customer has the right, upon written notice, to take reasonable and appropriate steps to stop and remediate AAI’s unauthorized use of Customer’s Personal Data; (v) AAI shall notify the Customer, should it determine that AAI can no longer meet its obligations with respect to Customer’s Personal Data under the CCPA; and (vi) AAI and Customer shall enable each other to comply with consumer requests regarding the Personal Data which are made pursuant to the CCPA by forwarding any applicable consumer request made pursuant to the CCPA by email to Customer (in case of notice necessary to Customer) or to [email protected] if notice is necessary to AAI and provide the other party with any information necessary to comply with the request. AAI will include the restrictions and the requirements of the CCPA in any contracts with subcontractors who process Personal Data and will notify Customer of any new Subprocessor in accordance with Section 5 herein.
Restricted Transfers.
EU Transfers. In the event of a Restricted Transfer to a recipient outside of the EEA, then such transfers shall be governed by the EU SCCs (Module Two for Controller to Processor transfers and Module Three for Processor to Processor transfers), which shall be entered into and incorporated into this DPA by this reference and:
(a) Customer is the “data exporter” and AAI is the “data importer”;
(b) Where applicable the following applies as to the EU SCCs:
(i) the optional docking clause in Clause 7 does not apply;
(ii) in Clause 9, Option 2 will apply, the minimum time period for prior notice of a new Subprocessor shall be 30 days, and AAI shall fulfill its notification obligations by notifying Customer of any new Subprocessor in accordance with this DPA;
(iii) in Clause 11, the optional language does not apply;
(iv) in Clause 13, all square brackets are removed with the text remaining;
(v) in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Irish law;
(vi) in Clause 18(b), disputes will be resolved before the courts of Ireland;
(vii) Exhibit A of this DPA (“DPA Exhibit A”)(Subject Matter and Details of Processing) and/or the Order Form contains the information required in Annex 1 of the EU SCCs; and
(viii) DPA Exhibit B (Details of the Technical and Organizational Measures) contains the information required in Annex 2 of the EU SCCs.
Swiss Transfers. In the event of a Restricted Transfer to a recipient outside of Switzerland, then such transfers shall be governed by the EU SCCs as set forth in Section 12.1 above, which shall be entered into and incorporated into this DPA by reference and modified as follows:
(a) in Clause 13 the competent supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner;
(b) in Clause 17 (Option 1), the EU SCCs will be governed by the laws of Switzerland;
(c) in Clause 18(b), disputes will be resolved before the courts of Switzerland;
(d) the term Member State must not be interpreted in such a way as to exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence in accordance with Clause 18(c); and
(e) all references to the EU GDPR in this DPA are also deemed to refer to the FADP.
UK Transfers. In the event of a Restricted Transfer to a recipient outside of the United Kingdom, then such transfers shall be governed by the UK SCCs, which shall be entered into and incorporated into this DPA by reference and:
(a) in Table 1 of the UK SCCs, the parties’ key contact information is located in DPA Exhibit A and/or the Order Form;
(b) in table 2 of the UK SCCs, the EU SCCs shall apply, including the Appendix Information (as defined in the UK SCCs) and with only the following modules, clauses or optional provisions of the EU SCCs brought into effect for the purposes of this DPA:
(i) The applicable Module is Controller to Processor or Processor to Processor, as applicable;
(ii) the optional docking clause in Clause 7 does not apply;
(iii) in Clause 9, Option 2 will apply, the minimum time period for prior notice of a new Subprocessor shall be 30 days, and AAI shall fulfill its notification obligations by notifying Customer of any new Subprocessor in accordance with this DPA;
(iv) in Clause 11, the optional language does not apply;
(c) in Table 3 of the UK SCCs
(i) the list of parties is located in DPA Exhibit A;
(ii) the description of transfer is located in DPA Exhibit A;
(iii) Annex II is located in DPA Exhibit B; and
(iv) The list of Subprocessors is as set forth in DPA Exhibit C.
(d) in Table 4 to the UK SCCs, neither party can terminate the DPA due to a change in law (the respective box is deemed checked).
(e) incorporated herein are Part 2 (Mandatory Clauses) of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.
Argentinian Transfers. In the event of a Restricted Transfer to a recipient outside of Argentina, then such transfers shall be governed by Appendix II (provision of services) of the Argentinian SCCs, which shall be entered into and incorporated into this DPA by reference and:
(a) DPA Exhibit A and DPA Exhibit B provide details of the Restricted Transfer and technical and organizational measures; and
(b) Disputes relating to the Argentinian SCC shall be governed by applicable Argentinian law and resolved before the courts of Argentina.
Other Restricted Transfers. In the event of any Other Restricted Transfer, such transfers shall be governed by such Other Applicable Transfer Clauses as may be required under Applicable Privacy Law, which shall be entered into and incorporated into this DPA by reference and:
(a) DPA Exhibit A and DPA Exhibit B provide details of the Restricted Transfer and technical and organizational measures; and
(b) Disputes relating to the Other Restricted Transfer shall be governed by the applicable laws of the country from which the Other Restricted Transfer takes place and resolved before the courts of such country.
AAI shall provide a signed copy of the applicable Standard Contractual Clauses upon request.
Data Subject Requests.
Upon Customer’s request and taking into account the nature of the applicable Processing, AAI will assist Customer by appropriate technical and organizational measures, insofar as possible, in complying with Customer’s obligations under Applicable Privacy Law to respond to requests from individuals to exercise their rights under Applicable Privacy Law, provided that Customer cannot reasonably fulfill such requests independently (including through use of the Services).
If AAI receives a request from a Data Subject in relation to the Data Subject’s Personal Data, AAI will notify Customer and advise the Data Subject to submit the request to Customer (but not otherwise communicate with the Data Subject regarding the request except as may be required by Applicable Privacy Law), and Customer will be responsible for responding to any such request.
Authorized Affiliates.
The parties acknowledge and agree that, by executing the Agreement, the Customer enters into this DPA on behalf of itself and, as applicable, in the name and on behalf of its Authorized Affiliates, thereby establishing a separate DPA between AAI and each such Authorized Affiliate subject to the provisions of the Agreement. Each Authorized Affiliate agrees to be bound by the obligations under this DPA and, to the extent applicable, the Agreement. For the avoidance of doubt, an Authorized Affiliate is not and does not become a party to the Agreement and is only a party to this DPA. All access to and use of the Services by Authorized Affiliates must comply with the terms and conditions of the Agreement and DPA and any violation of the terms and conditions of the Agreement or DPA by an Authorized Affiliate shall be deemed a violation by Customer.
The Customer that is the contracting party to the Agreement shall remain responsible for coordinating all communication with AAI under this DPA and be entitled to make and receive any communication in relation to this DPA on behalf of its Authorized Affiliates.
Where an Authorized Affiliate becomes a party to this DPA, it shall to the extent required under Applicable Privacy Law, be entitled to exercise the rights and seek remedies under this DPA, subject to the following: Except where Applicable Privacy Law require the Authorized Affiliate to exercise a right or seek any remedy under this DPA against AAI directly by itself, the parties agree that (i) solely the Customer that is the contracting party to the Agreement shall exercise any such right or seek any such remedy on behalf of the Authorized Affiliate, and (ii) the Customer that is the contracting party to the Agreement shall exercise any such rights under this DPA not separately for each Authorized Affiliate individually but in a combined manner for all of its Authorized Affiliates together.
Limitation of Liability.
THE RESPECTIVE LIABILITIES OF AAI AND CUSTOMER, AND EACH OF THEIR AFFILIATES AND/OR AUTHORIZED AFFILIATES, UNDER THIS DPA, SHALL BE LIMITED IN ACCORDANCE WITH THE APPLICABLE LIMITATIONS OF LIABILITY CONTAINED IN THE AGREEMENT.
For the avoidance of doubt, AAI’s and its Affiliates’ total liability for all claims from the Customer and all of its Authorized Affiliates arising out of or related to the Agreement and each DPA shall apply in the aggregate for all claims under both the Agreement and such DPAs, including by Customer and all Authorized Affiliates, and, in particular, shall not be understood to apply individually and severally to Customer and/or any Authorized Affiliate that is a contractual party to any such DPA.
Legal Effect. This DPA shall only become legally binding between Customer and AAI when (a) Customer signs this DPA or (b) when this DPA is incorporated by reference into an executed Agreement (via a “click to accept” procedure online or through written signature.
Order of Precedence. In the event of inconsistencies between the provisions of the Standard Contractual Clauses and this DPA or other agreements between the Parties regarding the processing of Personal Data, the order of precedence shall be: the applicable Standard Contractual Clauses, followed by the DPA, followed by other agreements between the Parties.
DPA EXHIBIT A
Details of the Processing of Personal Data
A. LIST OF PARTIES
Data exporter(s):
1. Customer Name: As specified in the Order Form
Customer Trading Name (if different):
Customer Main Address (if a company registered address): As specified in the Order Form
Customer’s Official Registration Number (if any) (company number or similar identifier):
Customer’s key contact person’s name: As specified in the Order Form
Key contact’s position: As specified in the Order Form
Key contact’s contact details: As specified in the Order Form
Customer’s DPO’s name and contact information (if any):
Customer’s EU Representative name and contact information (if any):
Activities relevant to the data transferred under these Clauses: Submitting data (which may include Personal Data) to the Services for Processing in accordance with the Agreement between Customer and Automation Anywhere Inc.
Role: Controller or Processor
Data importer:
1. Name: Automation Anywhere, Inc.
Trading Name (if different):
Main Address: 633 River Oaks Parkway, San Jose, CA 95134
Official Registration Number (if any) (company number or similar identifier): California Entity Number 3321728
Key contact person’s name, position and contact details: Kevan Fornasero, Director, Legal Counsel (Privacy, Product, & AI Governance), [email protected]
Activities relevant to the data transferred under these Clauses: Processing data (which may include Personal Data) submitted by Customer’s users to the Services, and collecting Personal Data from users of the Services, each for Processing in accordance with the Agreement between Customer and Automation Anywhere Inc.
Role: Processor
Categories of data subjects whose personal data is transferred
The Personal Data transferred includes the following categories of data subjects:
1. Actual customers of Customer and their employees
2. Employees of Customer
3. Suppliers of Customer and their employees
4. Any other data subjects’ Personal Data submitted to the Services by Customer
Categories of personal data transferred
1. Personal Data as determined by Customer
2. Telemetry and usage data including but not limited to: username, user email address, device IDs, audit logs, product features used, and error logs.
3. Support Authentication Data for provisioning of support services:
First and Last Name
Phone Number
Company Name
Title
Location (Country)
IP Addresses
E-Mail
Username
Optional avatar (if provided for the support community)
Language preference
Preferred hours of contact
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
As determined by Customer with the technical and organizational measures described in DPA Exhibit B.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
Continuous for the duration of the services
Nature of the processing
Collection, recording, analysis, structure, host, transfer, erasure, and any other activity customer instructs the services to perform on the Personal Data. Data Importer shall process Personal Data for purposes of the provision of services to the Data Exporter, in accordance with the terms and conditions of this DPA and the Agreement.
Purpose(s) of the data transfer and further processing
Provision of automation and/or automation discovery services, and support for such services (if applicable), as further specified in the Agreement and Order Form.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
As specified in the section titled “Deletion of Personal Data” in this DPA.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
See DPA Exhibit C– Subprocessor List – continuous for duration of the use of the applicable service.
DPA EXHIBIT B
Details of the Technical and Organizational Measures
In addition to maintaining ISO27001:2013, ISO22301:2019, Type 2 SOC 1, and Type 2 SOC 2 certifications, AAI has implemented and shall maintain a written comprehensive data protection program that includes the following safeguards:
Appropriate user authentication controls, including secure methods of assigning, selecting, and storing access credentials and restricting access to active users.
Secure access controls, including controls that limit access to Customer Personal Data to individuals who have a demonstrable genuine business need-to-know, supported by appropriate policies, protocols, and controls to facilitate access authorization, establishment, modification, and termination.
Appropriate and timely adjustments to AAI’s data protection program based on: periodic risk assessments; regular comprehensive evaluations (such as third-party assessments) of the AAI's data protection program; monitoring and regular testing of the effectiveness of safeguards, including vulnerability assessment and penetration testing; and a review of safeguards at least annually and whenever there is a material change in AAI’s technical environment or business practices that may implicate the confidentiality, availability, integrity, or security of the data importer’s information systems.
Appropriate ongoing training and awareness programs designed to ensure workforce members and others acting on AAI’s behalf are aware of and adhere to AAI’s data protection program’s policies, procedures, and protocols.
Appropriate monitoring of information systems in a manner designed to ensure data integrity and prevent loss or unauthorized access to, or acquisition, use, or disclosure of, Personal Data within the Cloud Services and within AAI’s devices and network infrastructure.
Appropriate technical security measures designed to prevent unauthorized intrusions and access, including firewall protection, antivirus protection, security patch management, logging of access to or use or disclosure of Personal Data, and intrusion detection for Cloud Services and within AAI’s devices and network infrastructure. AAI releases periodic security patches for AAI’s on-premise software.
Appropriate use of encryption of Personal Data submitted to the Cloud Services.
With respect to storage of Personal Data in Cloud Services, contracting with subprocessors who have appropriate facility security measures, including access controls, designed to prevent unauthorized access to premises, information systems, and data.
Safeguards ensuring disposal of Personal Data in Cloud Services renders that data permanently unreadable and unrecoverable.
Additional technical and organizational measures for the use of the software portion of the Services, along with certifications and SOC2 Type 2 report, can be found at the following link: https://www.automationanywhere.com/compliance-portal
For Support, AAI utilizes Salesforce’s Sales, Service and Community Clouds and has implemented Salesforce Platform Encryption (At Rest and In Motion). Additional technical and organizational measures for the use of Support can be found at the following links: https://www.salesforce.com/content/dam/web/en_us/www/documents/legal/misc/salesforce-securityprivacy-and-architecture.pdf https://developer.salesforce.com/docs/atlas.enus.securityImplGuide.meta/securityImplGuide/salesforce_security_guide.htm.
DPA EXHIBIT C
Subprocessor List
Notes:
-“A360 Cloud” includes the following: Automation 360 Pure Cloud – Base Package, Intelligent Automation – Enterprise Platform Plus Bundle, Agent InterOperability, AI Evaluation, Automator AI (includes Co-Pilot for Automators, Autopilot, and Generative Recorder), Bot Insights, Conversational Automation, Co-Pilot for Business Users, Discovery Bot, Document Automation, EnterpriseClaw, IQ Bot, and UI Agent.
-Aisera line of products includes: Agent Assist, AI OPS, Aisera Copilot, Analytics, Channels, Conv AI 2.0, Ingestion Pipeline, Knowledge Generation, Prompt Studio, Ticket Concierge, Ticket Learning, and Workflow/Hyperflows
-The following products have new names:
Automation Co-Pilot and AARI are now Intelligent Automation for Co-Pilot for Business Users
Fortress IQ is now Process Discovery
Subprocessor Legal Name
Applicable Services
Function of Subprocessor
Subprocessor Privacy Contact
Address of the Subprocessor
Google, LLC
The following Cloud Products: A360 Cloud and Enterprise Platform
Cloud hosting infrastructure, file and data storage services
+1-855-548-2777 https://support.google.com/policies/contact/general_privacy_form
1600 Amphitheatre Parkway, Mountain View, California 94043, United States
Google, LLC
The following Products: IQ Bot and Document Automation
Data extraction using Google Document AI, Vision AI optical character recognition, Apigee
+1-855-548-2777 https://support.google.com/policies/contact/general_privacy_form
1600 Amphitheatre Parkway, Mountain View, California 94043, United States
Google, LLC
Co-Pilot for Automators
AI Services
+1-855-548-2777 https://support.google.com/policies/contact/general_privacy_form
1600 Amphitheatre Parkway, Mountain View, California 94043, United States
Amazon Web Services, Inc. (subsidiary of Amazon.com, Inc.)
The following Cloud Products: A360 Cloud, Enterprise Platform, and Aisera Line of Products
Cloud hosting infrastructure, provisioning service, file and data storage services, data base and reporting
https://pages.awscloud.com/DSAR_RTF.html Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, ATTN: AWS Legal
410 Terry Avenue North Seattle, Washington 98109- 5210, United States
Amazon Web Services, Inc. (subsidiary of Amazon.com, Inc.)
The following Product: Document Automation, Co-Pilot for Automators, and Aisera Line of Products
AI Services
https://pages.awscloud.com/DSAR_RTF.html Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, ATTN: AWS Legal
410 Terry Avenue North Seattle, Washington 98109-5210, United States
Microsoft Corporation
The following Products: IQ Bot and Document Automation
Form recognition
https://www.microsoft.com/en-us/ concern/privacyrequest-other
One Microsoft Way, Redmond, Washington 98052 United States
Microsoft Corporation
Aisera Line of Products
Cloud hosting infrastructure, provisioning service, file and data storage services, data base and reporting
https://www.microsoft.com/en-us/concern/privacyrequest-other
One Microsoft Way, Redmond, Washington 98052 United States
Microsoft Corporation
The following Products: Document Automation, Co-Pilot for Automators, Generative Recorder, Autopilot, Aisera Line of Products
AI Services
https://www.microsoft.com/en-us/ concern/privacyrequest-other
One Microsoft Way, Redmond, Washington 98052 United States
Open AI
Aisera Line of Products
AI Services
https://privacy.openai.com/policies/
1455 3rd Street, San Francisco, CA 94158 United States
Cockroach Labs Inc
The following Cloud Products: A360 Cloud
Database
[email protected]
125 W 25th Street 11th Floor New York, New York 10001, United States
Auth0, Inc. (subsidiary of Okta, Inc.)
The following Cloud Products: A360 Cloud
Single Sign-on - Automation Anywhere 0Auth implementation; OAuth authorization support
[email protected]
10800 NE 8th Street, Ste. 600, Bellevue, Washington, 98004, United States
PixieBrix, Inc.
The following Cloud Products: Automation Co-Pilot, Automation Co-Pilot+
Function integrations for Google Chrome extensions
[email protected]
245 8th Ave 1083, New York, New York 10011 United States
Pendo.io, Inc.
All Cloud and On-Premise Services other than Process Discovery
In-product guides, spotlights, informational tips and other contextual user assistance elements within the product to help onboard and educate users about Automation Anywhere solutions; Anonymized user analytics to understand usage patterns of Automation Anywhere's product; In product user notifications; User feedback on product features
[email protected]
301 Hillsborough St Ste 1900, Raleigh, North Carolina, 27603, United States
Provectus IT, Inc.
The following cloud products: A360 Cloud
Engineering resources
[email protected]
125 University Avenue, Suite 295, Palo Alto, California, 94301, United States
Waverley Software, Inc.
The following cloud products: A360 Cloud
Engineering resources
[email protected]
855 El Camino Real, 13A-222, Palo Alto, California 94301- 2305, United States
Kloudfuse, Inc.
The following cloud products: A360 Cloud and Process Discovery
Event logging, cloud monitoring, telemetry collection
[email protected]
20370 Town Center Lane, 211, Cupertino, California 95014, United States
Sumo Logic, Inc.
The following cloud products: A360 Cloud and Process Discovery
Event logging, cloud monitoring, telemetry collection
[email protected]
855 Main St Ste 100, Redwood City, California, 94063, United States
Elasticsearch, Inc
The following cloud products: A360 Cloud, Process Discovery, and Enterprise Platform
Database and reporting
[email protected]
800 W El Camino Real, Suite 350, Mountain View, California 94040 United States
Google, LLC
Process Discovery
Cloud hosting, infrastructure, optical character recognition, Google Kubernetes Engine - open source container orchestration technology
+1-855-548-2777 https://support.google.com/policies/contact/general_privacy_form
1600 Amphitheatre Parkway, Mountain View, California 94043, United States
Straiker, Inc.
A360 Cloud, Aisera line of products
Runtime monitoring, detection and blocking of AI-related security threats and attacks, and protective guardrails for AI agents, agentic workflows and applications, and model operations
[email protected]
157 S. Murphy Avenue, Sunnyvale, California 94086 United States
Narada, Inc.
UI Agent
AI-powered web automation and services
[email protected]
2081 Center Street, Berkeley, California 94704 United States
Trantor Inc.
Process Discovery
Engineering resources
[email protected]
3723 Haven Avenue Suite 107,119,120, Menlo Park, California 94025 United States
Shibumi.com, Inc.
COE Manager
Pipeline and ROI tracking for automations, support escalation for COE Manager, and professional services for customization requests
[email protected]
50 Washington Street Suite 302E, Norwalk, Connecticut 06854 United States
One Realm, Inc.
AAI Enterprise Knowledge
GenAI with Retrieval Augmented Generation (RAG) capabilities
[email protected]
One Realm Inc (Odin AI) 4011 Adriatic St Oxnard, California 93035 United States
Qualesce LLC
Customer Support for SAP Accelerator
Product specific customer support
[email protected]
2591 Dallas Parkway, STE 300. Frisco, Texas 75043, United States
Abbyy USA Software House, Inc.
Customer Support for A360 on premise optical character recognition
Product specific customer support
[email protected]
860 Hillview Court, Suite 330, Milpitas, California 95035, United States
Gainsight, Inc.
Customer Support in the form of a Customer Community
External customer community
[email protected]
350 Bay Street, Suite 100, San Francisco, California 94133 United States
Salesforce, Inc.
Customer Support Application
Cloud Provider & Customer Support Ticketing System; Single Sign On - User Authentication for access to Knowledgebase and forums; Community Cloud - Knowledge base and external customer community, and customer self service tool for provisioning and license management
[email protected]; [email protected]; [email protected]
Salesforce Tower. 415 Mission Street, 3rd Floor. San Francisco, California 94105 United States
Grazitti Interactive LLP/ Grazitti Interactive, Inc.
Customer Support Application
Locate information across multiple applications
[email protected]
Plot No – 198, Industrial Area Phase 2, Panchkula, Haryana – 134113, India/ 340 E Middlefield Rd, Mountain View, California 94043, United States
Atlassian Corporation Plc/ Atlassian, Inc.
Customer Support Application
Bug tracking and management system
[email protected]
Level 6, 341 George Street, Sydney, NSW 2000, Australia/ 350 Bush Street Floor 13, San Francisco, California 94104, United States
SupportLogic, Inc.
Customer Support Application
Artificial intelligence customer support case review for escalation avoidance
[email protected];
[email protected];
[email protected]
356 Santana Row 1000 San Jose, California 95128, United States
Zoho Corporation
Customer Support Application
Support chat (at the option of the Customer, may include screen sharing), analytics, and workflows
[email protected];
[email protected]
4141 Hacienda Drive, Pleasanton, California 94588, United States
Tableau Software, Inc. (subsidiary of Salesforce, Inc.)
Customer Support Application
Data visualization software
[email protected];
[email protected]
Salesforce Tower. 415 Mission Street, 3rd Floor. San Francisco, California 94105 United States
Qualtrics International Inc.
Customer Support Application
Support and Customer Success surveys
[email protected]
333 West River Park Drive Provo, Utah 84604, United States
One Realm, Inc.
Customer Support Application
Artificial intelligence and large language model to assist with customer support case resolution
[email protected]
One Realm Inc (Odin AI) 4011 Adriatic St Oxnard, California 93035 United States
Zoom Video Communications, Inc.
Customer Support Application
Video communication platform to provide support which may include screen-sharing
[email protected]
55 Almaden Blvd, Suite 600 San Jose, California 95113, United States
Adobe Inc.
All Cloud and On-Premise Services
Product updates messaging and critical product communications
[email protected]
345 Park Avenue San Jose, California 95110- 2704, United States
Amazon Web Services, Inc. (subsidiary of Amazon.com, Inc.)
All Cloud and On-Premise Services
Critical product communications
https://pages.awscloud.com/DSAR_RTF.html
Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, ATTN: AWS Legal
410 Terry Avenue North Seattle, Washington 98109- 5210, United States
Zoomin Software, Inc.
Technical Documentation
Documentation portal to provide AAI’s technical documentation
[email protected]
33 West 60th St., 11th Floor, New York, New York 10023 United States
Toptal, LLC
The following cloud products: Document Automation, IQ Bot
Engineering resources
[email protected]
548 Market St #36879 San Francisco, CA 94104
AAI may also engage one or more of the following AAI Affiliates as Subprocessors to deliver some or all of the Services provided to Customer:
Subprocessor Name
Location
Automation Anywhere, Inc.
Delaware, United States
Automation Anywhere Software Pvt. Ltd.
India
Automation Anywhere India Private Limited
India
Automation Anywhere UK Limited
United Kingdom
Automation Anywhere Australia Pty. Ltd.
Australia
Automation Anywhere Singapore Pte. Ltd.
Singapore
Automation Anywhere Japan, Co., Ltd.
Japan
Automation Anywhere GmbH
Germany
Automation Anywhere Canada Ltd.
Canada
Automation Anywhere HK Limited
Hong Kong
Automation Anywhere Korea LLC
South Korea
Automation Anywhere France (SAS)
France
Automation Anywhere South Africa (Pty) Ltd.
South Africa
Automation Anywhere FZ-LLC
United Arab Emirates
SmartForce Tecnologia, Consultoria e Servicos Ltda
Brazil
Workforce Digital, S.A. de C.V.
Mexico
Automation Anywhere Netherlands B.V.
Netherlands
Automation Anywhere Spain, S.L.
Spain
Automation Anywhere Colombia S.A.S.
Colombia
Partner Data Processing Agreement
Controller to Controller
This Partner Data Processing Agreement ("DPA") is entered into and forms part of the AAI Reseller Agreement (including any former designations such as AAI Direct Reseller Agreement, AAI Tiered Reseller Agreement, and Master Reseller Agreement), Master Distributor Agreement, Foundational Partner Agreement, and/or Partner Agreement for Lead Passing, each as applicable (the “Agreement”) between Automation Anywhere, Inc. (“AAI”) and the partner identified in such Agreement (“Partner”). AAI may modify this DPA but any such amendment(s) shall not materially increase Partner’s liabilities and/or obligations nor shall it materially decrease AAI’s obligations and/or liabilities unless required by Applicable Privacy Law.
Both AAI and Partner (each a “Party” or together, the “Parties") will act as independent Controllers of the Personal Data which is provided by AAI to Partner or obtained by Partner on behalf of AAI, in connection with the Agreement and this DPA sets out the terms of the provision of the Personal Data and how it may be used.
THE FOLLOWING IS HEREBY AGREED:
DEFINITIONS AND INTERPRETATION
In this DPA:
(a) "Applicable Privacy Law" means all international, federal, state, and local laws relating to data protection or the privacy of Data Subjects as applicable to the Processing of Personal Data under the Agreement, including, without limitation: (a) the California Consumer Privacy Act as amended by the California Privacy Rights Act and any binding regulations promulgated thereunder (“CCPA”), (b) the Colorado Privacy Act (“CPA”), (c) the Virginia Consumer Data Protection Act (“VCDPA”), (d) the Connecticut Data Protection Act (“CTDPA”), (e) the Utah Consumer Privacy Act (“UCPA”) (f) the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), (g) the Swiss Federal Act on Data Protection (“FADP”), (h) the EU GDPR as it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act 2018 and the UK Data Protection Act 2018 (the “UK GDPR”); and (i) the Argentine Law 25,326 Personal Data Protection Law (“PDPL”); in each case, as updated, amended or replaced from time to time.
(b)"Controller", "Data Subject", "Personal Data Breach", "Process/Processing", and "Processor" and/or other similar terms and concepts shall have the meanings as defined in Applicable Privacy Law, including the GDPR.
(c)“End User” or “End Customer” means licensees who (i) have been registered by Partner or through Partner’s Resellers, with AAI pursuant to the Agreement, and (ii) enter into an End Customer Agreement with AAI.
(d)“End Customer Agreement” means the agreement between AAI and the End User or End Customer which grants the End User or End Customer with the right to use the Products solely for such End User’s own internal business purposes and not for resale, sublicensing or distribution.
(e)“Partner Systems” means the infrastructure managed by Partner for the Processing of Personal Data under the Agreement.
(f)“Personal Data” means (a) personal data, personal information, personally identifiable information, or similar term as defined by Applicable Privacy Law or (b) if not defined by Applicable Privacy Law, any information that relates to a Data Subject.
(g)“Product” or “Products” means (a) the support and maintenance that AAI provides to End User or End Customer, to the extent applicable (the “Support Services”) as part of the Agreement and, to the extent applicable (b) AAI’s software-as-a-service intelligent automation platform and related applications (including downloaded components) available as a connected suite of applications or as separate applications and hosted in AAI’s cloud environment (the “Cloud Services”) and AAI’s proprietary software applications in machine-readable, object code form only, which are hosted in an End Customer’s virtual private cloud or otherwise operated in an End Customer’s environment (to the extent information is provided to or collected by AAI from End User or End Customer) in each case as provided by or on behalf of AAI under the End Customer Agreement.
(h) “Restricted Transfer” means: (a) where GDPR applies, a transfer of Personal Data to a country outside the European Economic Area (“EEA”) that is not subject to an adequacy determination, (b) where UK GDPR applies, a transfer of Personal Data from the United Kingdom to any other country that is not subject to an adequacy determination, (c) where FADP applies, a transfer of Personal Data to a country outside Switzerland that is not subject to an adequacy determination, and (d) with respect to any other country where Applicable Privacy Law apply that restrict overseas transfers, an overseas transfer to a country that is not subject to an adequacy decision or otherwise requires some form of transfer mechanism to be implemented in order to comply with such Applicable Privacy Law (such transfer being any “Other Restricted Transfer”).
(i) “Standard Contractual Clauses” means (a) with respect to restricted transfers (as such term is defined under Applicable Privacy Law) which are subject to the GDPR and/or the FADP, the Controller-to-Controller standard contractual clauses, as set out in the European Commission’s Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to GDPR, as may be amended or replaced by the European Commission from time to time (the “EU SCCs”), (b) with respect to restricted transfers subject to the UK GDPR, the International Data Transfer DPA to the EU Commission Standard Contractual of 21 March 2022, as may be amended or replaced by the UK Information Commissioner’s Office from time to time (the “UK SCCs”), (c) with respect to restricted transfers subject to Argentina’s PDPL, the standard international transfer contractual clauses as set out in Regulation No. 60-E/2016 (“Argentinian SCCs”), and (d) with respect to restricted transfers subject to other Applicable Privacy Law, such other standard contract clauses as may be required to be implemented between AAI and Partner (“Other Applicable Transfer Clauses”).
COMPLIANCE WITH LAWS AND OTHER MATTERS
Both Parties will comply with the Applicable Privacy Law in the Processing of Personal Data they collect themselves, or transfer to or receive from the other Party, pursuant to the Agreement.
The Parties acknowledge and agree that they will both act as independent Controllers for their respective Processing activities pursuant to this Agreement. Partner’s scope of services involving Processing activities is set forth in the Agreement.
The Parties acknowledge and agree that neither of them will act as a Processor on behalf of the other, and that they are each responsible for meeting their respective compliance obligations under the Applicable Privacy Law.
Where required, the Parties will assist the other Party in complying with its obligations under Applicable Privacy Law, including, but not limited to, assisting each other with verifying the authenticity of Data Subjects and responding to Data Subject requests.
Both Parties agree to inform each other of any Personal Data Breaches as follows: (i) AAI will inform Partner and appropriate legal and supervisory authorities of any reportable Personal Data Breaches it experiences that affect Partner’s employees to the extent required by Applicable Privacy Law, and (ii) Partner will inform AAI, affected Data Subjects, and appropriate legal and supervisory authorities of any reportable Personal Data Breaches it experiences that affect or may impact Partner Systems where End Customer is Processed. The Parties will use reasonable efforts to inform each other about reportable Personal Data Breaches under this Section 2.5 before or around the same time as informing the relevant supervisory authority and/or the Data Subject. Where End Customer Personal Data has been involved in a reportable Personal Data Breach within an AAI Product, AAI will notify any applicable End Customers in accordance with the agreement between AAI and End Customer, and any appropriate legal and supervisory authorities as required by Applicable Privacy Law.
Both Parties have the right to choose their own Processors, for which each remains solely responsible.
OBLIGATION OF THE PARTIES
In relation to the Personal Data Processed by AAI under the Agreement, AAI agrees to:
(a) maintain its ISO27001:2013, ISO22301:2019, Type 2 SOC 1, and Type 2 SOC 2 certifications for the duration of the Agreement;
(b) implement the technical and organizational security measures described in Exhibit B of AAI’s Customer Data Processing Agreement located at https://www.automationanywhere.com/DPA.pdf with respect to AAI’s Products;
(c) to the extent that AAI makes them generally available to its customers and partners, make available documentation regarding the audits of its technical and organizational security measures at https://www.automationanywhere.com/compliance-portal;
(d) where AAI shares Personal Data with Partner, obtain, where required, consents from the Data Subjects or have another legal basis, for Partner to Process Personal Data as directed by AAI;
(e) notify Partner in the event AAI receives an opt out of sale request where such Personal Data was provided by AAI to Partner under the Agreement;
(f) to the extent required by Applicable Privacy Law, AAI agrees to process the Personal Data of End Users/End Customers in accordance with the End Customer Agreement between End Users/End Customers and AAI.
In relation to the Personal Data Processed by Partner under the Agreement, to the extent required by Applicable Privacy Law, Partner agrees to:
(a) process the Personal Data as described in Partner’s Privacy Policy;
(b) obtain express consent or other legal basis for processing, where required by Applicable Privacy Law, from any non AAI-provided Data Subject, where partner: (a) sends marketing materials regarding AAI products to Data Subjects under this Agreement or (b) shares Personal Data of Data Subjects with AAI;
(c) inform the Data Subjects of the Processing of their Personal Data;
(d) Process Personal Data lawfully and fairly, and collect and Process Personal Data only for specified, explicit, and legitimate purposes;
(e) collect and Process adequate and relevant data, limited to what is necessary in relation to the purposes for which the Personal Data is Processed;
(f) erase or rectify inaccurate Personal Data, having regard to the purposes for which the Personal Data is Processed;
(g) delete, block, or (pseudo)anonymize Personal Data if identification of Data Subjects is no longer necessary for the purposes for which the Personal Data is Processed;
(h) implement appropriate technical and organizational security measures on Partner Systems to protect Personal Data, including to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage as set out in Section 4 (Partner Implemented Security Measures);
(i) notify AAI in the event Partner receives a request to opt out of sale of Personal Data where such Personal Data was provided by Partner to AAI under the Agreement;
(j) respond promptly to all enquiries from AAI or from Data Subjects relating to the Personal Data processed under the Agreement, and in particular shall action all requests from Data Subjects to exercise their rights under Applicable Privacy Law on request from either the relevant Data Subject or from AAI. Data Subject requests regarding End Customer’s Personal Data processed by AAI in its Products shall be forwarded to AAI, whereby AAI will forward the Data Subject request on to the applicable End Customer for instructions from the End Customer;
(k) only transfer Personal Data outside the country of origin if it has a legal basis for the transfer and any required safeguards in place, including contractual clauses and technical and organizational security measures; and
(l) implement appropriate technical and organizational security measures for the Partner Systems in accordance with Section 4 (Partner Implemented Security Measures).
PARTNER IMPLEMENTED SECURITY MEASURES
Security Controls
(a) Partner shall maintain an information security management system, based on industry security standards (e.g. ISO 27001, BSI 100-1);
(b) Partner will adhere to the applicable requirements of Payment Card Industry Data Security Standard (PCI DSS) when Processing payment card data for End Customers (if applicable);
(c) Partner shall have a process in place to regularly test, assess, and evaluate the effectiveness of the implemented technical and organizational security measures applied to the Partner Systems;
(d) Partner shall regularly conduct external audits of its data centre facilities hosting Personal Data (e.g. SSAE 18, ISAE3402 Type II, ISO 27001, or equivalent) and will provide AAI with a copy of the most recent audit report upon written request;
(e) Partner shall have in place a change management control procedure of its information processing facilities and the Partner Systems; and
(f) Partner shall have in place a business continuity plan for service operations and a disaster recovery plan for the locations from which Partner performs services under the Agreement.
(g) Partner shall maintain incident management policies and procedures.
Personnel Controls
(a) Partner shall have in place an access management procedure for handling Partner personnel requests to access Personal Data to ensure access on a need to know basis only;
(b) Partner shall have in place a procedure for conducting appropriate background checks for its personnel with access to Personal Data; and
(c) Partner shall only grant access to its personnel bound to confidentiality and will require such personnel to attend security and privacy awareness training with regular intervals.
Technical Security Measures
Partner's technical security measures include:
(a) System (access) logging for relevant Partner Systems, keeping logs for at least one (1) year and limiting access to logs;
(b) Secure remote access to Partner Systems via multi-factor authentication;
(c) Malware control;
(d) Network-based intrusion detection;
(e) Data loss prevention software;
(f) System hardening; and
(g) Vulnerability management, including by means of infrastructure scans, application scans, external application vulnerability assessments, penetration testing, and containment and remediation procedures.
RESTRICTED TRANSFERS
European Union Transfers. In the event of a Restricted Transfer to a recipient outside of the EEA, then such transfers shall be governed by MODULE ONE “Transfer Controller to Controller” of the EU SCCs, which shall be entered into and incorporated into this DPA by this reference. The following applies:
(a) the optional docking clause in Clause 7 does not apply;
(b) in Clause 11, the optional language does not apply;
(c) in Clause 13, all square brackets are removed with the text remaining;
(d) in Clause 17, Option 1 will apply and the EU SCCs will be governed by Irish law;
(e) in Clause 18, disputes will be resolved before the courts of Ireland;
(f) the information required in Annex 1 of the EU SCCs (Subject Matter and Details of Processing) is attached in this DPA as Annex 1;
(g) the information required in Annex 2 of the EU SCCs is contained in Sections 3 (Obligations of the Parties) and 4 (Partner Implemented Security Measures) of this DPA.
Swiss Transfers. In the event of a Restricted Transfer to a recipient outside of Switzerland, then such transfers shall be governed by the EU SCCs as set forth in Section 5.1 (European Union Transfers) above, which shall be entered into and incorporated into this DPA by reference and modified as follows:
(a) in Clause 13 the competent supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner;
(b) in Clause 17, Option 1 will apply and the EU SCCs will be governed by the laws of Switzerland;
(c) in Clause 18, disputes will be resolved before the courts of Switzerland;
(d) the term Member State must not be interpreted in such a way as to exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence in accordance with Clause 18(c); and
(e) all references to the GDPR in this DPA are also deemed to refer to the FADP.
UK Transfers. In the event of a Restricted Transfer to a recipient outside of the United Kingdom, then such transfers shall be governed by the UK SCCs, which shall be entered into and incorporated into this DPA by reference and:
(a) in Table 1 of the UK SCCs, the Partner’s key contact information is located in the registration filed with AAI. AAI’s Privacy Counsel contact is Shannon Salerno, Director, Legal - Product and Privacy Counsel, with an email address of [email protected]. Where one Party shares Personal Data with the other Party, such sharing Party acts as an exporter. Where one Party receives Personal Data from the other party, such recipient acts as an importer.
(b) in table 2 of the UK SCCs, the EU SCCs shall apply, including the Appendix Information and with only the following modules, clauses or optional provisions of the EU SCCs brought into effect for the purposes of this DPA:
(i) The Controller to Controller Module shall apply;
(ii) the optional docking clause in Clause 7 does not apply;
(iii) in Clause 11, the optional language does not apply;
(c) in Table 3 of the UK SCCs:
(i) the list of parties is the Partner and AAI;
(ii) the description of transfer is attached to this DPA as Annex 1; and
(iii) the Technical and Organization Measures are contained Sections 3 (Obligations of the Parties) and 4 (Partner Implemented Security Measures) of this DPA.
(d) in Table 4 of the UK SCCs, the data exporter and the data importer can terminate the DPA due to a change in law (the respective box is deemed checked).
(e) Incorporated herein are Part 2 (Mandatory Clauses) of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.
Argentinian Transfers. In the event of a Restricted Transfer to a recipient outside of Argentina, then such transfers shall be governed by the Argentinian SCCs, which shall be entered into and incorporated into this DPA by reference and Appendix I (disclosure of personal data) of the Argentinian SCCs shall apply.
(a) Annex 1 to this DPA provides details of the Restricted Transfer and details of the Parties;
(b) Sections 3 (Obligations of the Parties) and 4 (Partner Implemented Security Measures) of this DPA provide security and confidentiality measures taken by the Parties; and
(c) Disputes relating to the Argentinian SCC shall be governed by applicable Argentinian law and resolved before the courts of Argentina.
Other Restricted Transfers. In the event of any Other Restricted Transfer, such transfers shall be governed by such Other Applicable Transfer Clauses as may be required under Applicable Privacy Law which shall be entered into and incorporated into this DPA by reference and:
(a) Annex 1 to this to this DPA provides details of the Restricted Transfer;
(b) the Technical and Organization Measures are contained in Sections 3 (Obligations of the Parties) and 4 (Partner Implemented Security Measures) of this DPA; and
(c) disputes relating to the Other Restricted Transfer shall be governed by the applicable laws of the country from which the Other Restricted Transfer takes place and resolved before the courts of such country.
MISCELLANEOUS
To the maximum extent permitted by applicable law, all other rights and obligations contained in the Agreement or otherwise agreed between the Parties which govern the Processing of Personal Data, will be replaced in their entirety with the rights and obligations contained in this DPA. All other terms and conditions of this Agreement will remain in full force and effect.
Annex 1 of the SCCs (Subject Matter and Details of Processing)
A. LIST OF PARTIES
Name: Automation Anywhere, Inc.
Main Address: 633 River Oaks Parkway, San Jose, CA 95134 USA
Official Registration Number: California Entity No: 3321728
Key contact person’s name, position and contact details: Kevan Fornasero, Legal Director of AI Governance, Privacy, & Product, [email protected]
Activities relevant to the data transferred under these Clauses: Sharing contact information of End Customers and prospective End Customers with Partner, receiving contact information of End Customers and prospective End Customers from Partner, each for the purposes described in the Agreement.
Data Importer or Data Exporter: Data Exporter when AAI is sharing the End Customer contact information with Partner, and Data Importer when Partner is sharing the End Customer contact information with AAI.
Partner Name: As contained in the Agreement
Partner Main Address (if a company registered address): As contained in the Agreement
Official Registration Number: Partner’s Primary Business Contact contact person’s name: As contained in AAI’s partner portal
Primary business contact’s position: As contained in AAI’s partner portal
Primary business contact’s contact details: As contained in AAI’s partner portal
Partner’s DPO’s name and contact information (if any): As contained in AAI’s partner portal
Partner’s EU Representative name and contact information (if any): As contained in AAI’s partner portal
Activities relevant to the data transferred under these Clauses: Sharing contact information of End Customers and prospective End Customers with AAI, receiving contact information of End Customers and prospective End Customers from AAI, each for the purposes described in the Agreement.
Data Importer or Data Exporter: Data Importer when AAI is sharing the contact information with Partner, and Data Exporter when Partner is sharing the contact information with AAI.
B. DESCRIPTION OF TRANSFER
Categories of data subjects whose personal data is transferred:
End Customers and prospective End Customers of AAI
Categories of personal data transferred:
Business contact information, title, employer name
Sensitive data transferred (if applicable):
none
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis):
Continuous for the duration of the Agreement
Nature of the processing:
Storing contact data in a customer relationship management platform, contacting prospective End Customers and current End Customers to provide AAI Products or assist customer with support, sharing End Customer and Prospective End Customer contact information between the Parties.
Purpose(s) of the data transfer and further processing:
Market and sell AAI Products to potential End Customers and existing End Customers and deliver AAI Products to End Customers.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period:
AAI will retain contact data of End Customers and prospective End Customers in accordance with its personal data policies related to marketing. AAI will retain Personal Data submitted by End Customers to its Products in accordance with the End Customer Agreement between End Customer and AAI. Partner will retain contact data provided to Partner by AAI for End Customers and prospective End Customers for the time specified in the Agreement.
Try
For Businesses
Sign up to get quick access to a full, personalized product demo
Request Demo
For Students & Developers
Start automating instantly with FREE access to full-featured automation with Cloud Community Edition.
Get Community Edition
Contact