Snapshot 20678
Normalized text
Scripts and page chrome removed; this is what change detection compares.
EVS SA, Rue du Bois Saint-Jean 13, 4102 Seraing, BELGIUM (Register of Legal Entities of Liège 0452.080.178)
EVS BROADCAST EQUIPMENT INC, 3rd Floor, 700 Route 46 East, Fairfield, NJ 07004, USA
EVS BROADCAST EQUIPMENT LTD, Room A 35/F Lee & Man Commercial Center, 169 Electric Road North Point HONG KONG
EVS NETHERLANDS BV, Hercules 28, 5126 RK Gilze, THE NETHERLANDS
DATA PROCESSING ADDENDUM
EVS AS PROCESSOR – CUSTOMER AS CONTROLLER
1. SCOPE and against all claims and damages, due to a breach of the foregoing
1.1. This Data Processing Addendum shall apply with the framework the warranties.
provision of support, trade-in and video production management services Without prejudice to the independence of the Parties, the Personal Data
(the “services”) to be provided by EVS SA or any of its affiliates (“EVS”) to shall only be processed in accordance with the instructions of Customer
you (“Customer”) based on existing contractual provisions (the “Principal and solely for the Purposes, to the exclusion of any other purposes.
Agreement”) in accordance with the Data Protection Law. This Data Customer hereby generally instructs EVS to process Personal Data for the
Processing Addendum supersedes any other terms and conditions of Purposes and to the extent necessary to provide the Services in
Customer relating to a similar subject matter, even if these have not been compliance with EVS' obligations under this Addendum.
specifically rejected by EVS. The provisions of the Principal Agreement Without prejudice to the independence of the Parties, EVS represents and
that are not expressly modified by this Addendum shall remain unchanged warrants that EVS and any person acting under the authority of or on behalf
and in force for the duration of the Principal Agreement. of EVS and having access to the Personal Data shall only process the
Personal Data in accordance with the instructions of Customer, except in
2. DEFINITIONS case of a legal obligation, and in accordance with the Data Protection Law.
2.1. Except when expressly specified otherwise in this Addendum, the To this end, EVS shall inform all persons acting under its authority and
capitalized terms shall have the meaning set forth in the Principal having access to the Personal Data about the provisions of Data Protection
Agreement. Law.
If the Data Protection Laws apply to the Processing of Personal Data, and
3. MODIFICATIONS OF THE PRINCIPAL AGREEMENT Customer is itself a processor, Customer warrants to EVS that Customer’s
It is hereby agreed to add the following provisions to the Principal instructions with respect to Personal Data have been authorized by the
Agreement in a new Clause related to data protection and privacy: applicable controller, including the appointment of EVS as another
processor or Subprocessor.
Data Protection and Privacy
4 Restricted transfer
1 Definitions In the event EVS further proceeds to a Restricted Transfer (in accordance
For the purposes of this Clause 1, the following capitalized terms shall have with article 5), the Parties agree that EVS will act as a data exporter and
the meaning specified below: shall be solely responsible for complying with the obligations applicable to
(a) "Data Protection Law" means the EU General data Protection data exporter pursuant to Data Protection Laws and Regulations, including
Regulation 2016/679; together with all other applicable legislation but not limited to:
relating to privacy or data protection and the terms "personal data", i. The obligation to provide an adequate level of protection to
"personal data breach", "data subject", "controller", "processor" and any Personal Data that is transferred;
"process" (and its derivatives) shall have the meanings given them in ii. The obligation to sign the appropriate module of the EU
the Data Protection Laws. SCC with the data importer;
(b) “EU SCC” shall mean the standard contractual clauses annexed to the iii. If deemed necessary, the obligation to perform a data
European Commission Implementing Decision of 4 June 2021 on transfer impact assessment prior to any Restricted Transfer
standard contractual clauses for the transfer of personal data to third of Personal Data to a third party;
countries pursuant to Regulation (EU) 2016/679 of the European iv. The obligation to implement all necessary supplementary
Parliament and of the Council. “Module One”, “Module Two”, “Module measures (contractual, technical and organizational) to
Three” and “Module Four” shall refer to the respective Modules set secure Restricted Transfers.
forth therein and the relevant terms thereof. EVS represents and warrants that neither EVS nor – to its knowledge - any
(c) "Instructions" means the documented instructions from the Customer of its Sub-processor have received a request from any public or
to EVS as attached to this Addendum in Annex 1; governmental authority to access European Personal Data Processed by
(d) "Purposes" shall mean the limited, specific and legitimate purposes of EVS or its Sub-processor(s) in connection with the Services or
the Processing, namely the performance of the services; substantially similar services for other clients.
(e) “Restricted Transfer" means a transfer of personal data from the EVS represents and warrants that no other entity of the group of
European Economic Area to a country outside of the European companies to which it belongs established outside Europe has a sufficient
Economic Area which does not ensure an adequate level of data degree of control over EVS that would enable it to compel EVS to
protection and where no appropriate safeguard exists. communicate personal data to this entity in case the latter wishes to
(f) “Subprocessor” shall mean any person (excluding an employee of voluntarily cooperate or is legally required to cooperate with any public or
EVS) appointed by or on behalf of EVS to process Personal Data on governmental entity in the context of a request of access to European
behalf of Customer in connection with the Principal Agreement. and/or Swiss Personal Data Processed by EVS.
2 Qualification 5 Subprocessing – Onward transfer of Personal Data
For the avoidance of doubt, the Parties acknowledge that where Data Customer agrees that EVS may use Subprocessors to fulfill its contractual
Protection Law applies, Customer acts as the Controller and EVS as the obligations under this DPA or to provide certain services on its behalf, such
Processor of Personal Data to be processed. Accordingly, Customer as providing storage services. Annex 2 lists Subprocessors that are
remains solely responsible for determining the means and the purposes of engaged by EVS to carry out processing activities on Personal Data on
the EVS’ Processing of Personal Data under this Addendum. behalf of Customer. Such Annex 2 shall be updated from time to time to
reflect changes in Subprocessors. Where EVS engages a Subprocessor
3 Processing of Personal Data for carrying out specific processing activities on behalf of Customer, similar
Any Processing of Personal Data by EVS in respect of which EVS acts as protection obligations as contained herein shall be imposed on that
processor on behalf of Customer shall be carried out in accordance with Subprocessor by way of a written agreement, in particular providing
the Data Protection Law and the provisions of this Clause 3. sufficient guarantees to implement appropriate technical and
Customer agrees to comply with the requirements of the Data Protection organisational measures.
Law with respect to the Processing of Personal Data. With respect to each Subprocessor, EVS shallcarry out adequate due
Customer warrants that it owns or has obtained all necessary rights and/or diligence to ensure that the Subprocessor is capable of providing the level
consents and provided all necessary notices to Data Subjects as required of protection for Personal Data required by this Addendum.
by applicable Data Protection Law, with respect to any Personal Data and If the Customer reasonably objects to the Processing of Personal Data by
to the extent necessary for the Parties to Process such Personal Data, and one or more Subprocessors, then the Customer shall notify EVS in writing
that EVS’ use of any EVS Personal Data in accordance with the Principal (including e-mail) within 90 (ninety) calendar days after the publication of
Agreement will not violate any applicable law, rule or regulation. the use of such Subprocessor on EVS website.
Furthermore, Customer warrants that: (i) EVS’ Processing of any Personal In the event Customer objects to a Subprocessor, EVS will use reasonable
Data in accordance with any Customer instruction shall be in compliance efforts to change the affected services or to recommend another
with applicable Data Protection Law; and (ii) prior to transmitting Personal commercially reasonable change to the Customer’s use of the affected
Data to EVS, Customer shall inform EVS of any applicable requirements services to avoid the Processing of Personal Data by the Subprocessor
pertaining to the transmitted Personal Data. Customer shall be concerned. If EVS is unable to make available or propose such change
responsible for all liability and shall indemnify and hold EVS harmless from within (60) calendar days, the Customer may terminate the relevant part of
the Principal Agreement regarding those services which cannot be
Version 24.05 (12/06/2026)
EVS SA, Rue du Bois Saint-Jean 13, 4102 Seraing, BELGIUM (Register of Legal Entities of Liège 0452.080.178)
EVS BROADCAST EQUIPMENT INC, 3rd Floor, 700 Route 46 East, Fairfield, NJ 07004, USA
EVS BROADCAST EQUIPMENT LTD, Room A 35/F Lee & Man Commercial Center, 169 Electric Road North Point HONG KONG
EVS NETHERLANDS BV, Hercules 28, 5126 RK Gilze, THE NETHERLANDS
DATA PROCESSING ADDENDUM
EVS AS PROCESSOR – CUSTOMER AS CONTROLLER
provided by EVS without the use of the Subprocessor concerned. To that including, where appropriate, measures to mitigate its possible adverse
end, the Customer shall provide written notice of termination taking into effects.
account a notice period of 6 months and providing a reasonable motivation EVS shall co-operate with Customer and take such steps as are directed
for non-approval. by Customer to assist in the investigation, mitigation and remediation of
EVS shall not communicate, disclose or transfer, either free of charge or in each such Personal Data Breach.
return for payment, the Personal Data to any other legal person or
individual, except where such communication, disclosure or transfer: (i) is 9 Audit and inspection
necessary to perform the Services or for the Purposes, subject to the EVS shall, at the request of Customer, no more frequently than once
limitations set forth in the present Addendum; or (ii) is required by any annually, make available to Customer information reasonably requested
applicable law, regulation, or governmental authority in which case EVS by Customer to demonstrate EVS’ compliance with its obligations relating
will, wherever possible, notify Customer promptly in writing prior to to the Processing of Customer’s Personal Data. Such audit shall be
complying with any such request for communication, disclosure or transfer performed by Customer or a third party (selected by Customer and
and shall comply with all reasonable directions of Customer with respect reasonably acceptable to EVS) to act on its behalf, at Customer’s expense,
to such communication, disclosure or transfer. at EVS’ offices or at another mutually agreed location during normal
business hours upon thirty (30) days prior written notice and shall make
6 Security reasonable endeavors to avoid causing any damage, injury, or disruption
EVS shall ensure – having regard to the state of technological development in EVS’ premises, equipment, personnel and business while its personal
and the cost of implementing any such measures as well as the sensitive are on those premises in the course of such an audit or inspection. Audit
nature of the Personal Data to be processed – that appropriate technical reports shall only include detail sufficient to verify EVS’ compliance with its
and organizational measures are taken against accidental or unauthorized obligations under this Clause 9.
destruction, accidental loss, as well as against alteration of, access to and For the performance of the audit or inspection, Customer will give a list of
any other unauthorized processing of the Personal Data. Without limitation authorized person(s) (“Authorized Person”). EVS undertakes to give
to the foregoing and without prejudice to those obligations contained in the access to its premises to the Authorized Person provided that such
applicable policies (if any) which may be communicated from time to time Authorized Person:
to EVS, EVS shall, in particular, take adequate technical and (i) produces reasonable evidence of identity;
organizational measures to: (ii) works during normal business hours of EVS unless the
i. ensure that access to the Personal Data is only granted to audit needs to be conducted on an emergency basis.
persons acting under its authority and strictly on a need-to-know
basis; 10 Data Protection Impact Assessment
ii. prevent the use of data processing systems by unauthorized EVS shall reasonably assist Customer with any relevant data protection
persons ; impact assessment and prior consultations with Supervisory Authorities or
iii. ensure that the Personal Data cannot be read, copied, modified other competent data privacy authorities that would be required under
or removed without authorization EVS during electronic transfer Articles 35 or 36 of the GDPR, subject to terms and conditions and fees to
or during transport or storage on data media and that it is be agreed upon on a case-by-case basis.
possible to check and determine to whom communication of the
Personal Data is made through data transfer facilities; 11 Deletion or return of Personal Data
iv. ensure that the Personal Data is only processed in accordance EVS shall ensure that any copies of Personal Data in the possession of
with Customer’s instructions; EVS are promptly, and in any event within one month of the date of
v. ensure the reliability of any employee, agent or contractor of potential cessation of any services, returned to Customer or destroyed
Customer or any Subprocessor and that they are subject to upon Customer’s request and/or when they are no longer required for the
confidentiality obligations; performance of EVS’ obligations under the Principal Agreement, whichever
vi. ensure that the Personal Data is protected against accidental occurs first, and EVS shall delete existing copies unless Data Protection
destruction or loss. Law requires storage of the Personal Data.
EVS shall adapt such measures systematically to the development of
regulations, technology and other aspects and supplemented with the 12 Liability
applicable technical and organizational measures of Subprocessors, as EVS shall be liable for the Processing of the Personal Data which is
the case may be. consigned to it by Customer. EVS undertakes to indemnify and hold
harmless Customer, its directors and employees against any and all costs,
7 Cooperation charges, damages, expenses and losses (including costs incurred in
EVS shall provide in a prompt manner such co-operation as is reasonably recovering same), that are incurred by Customer as a result of any breach
necessary to enable Customer to ensure compliance with the Data by EVS of any representation or warranty as contained herein or the failure
Protection Law and to the extent the necessary information is solely in the to comply with any of its obligations as contained herein. EVS shall remain
possession of EVS or its Subprocessors, including but not limited to in any event fully liable to Customer for the performance of such
providing co-operation where Customer must respond to requests for Subprocessor's obligations. In any event, the aggregate maximum liability
exercising the Data Subject's rights granted by Data Protection Law. In of EVS as Processor of Personal Data under the present Addendum shall
particular, EVS shall: be limited to the lower of (i) the price paid by the Customer to EVS under
i. without undue delay notify Customer if EVS or any the Principal Agreement in the 12-month period immediately preceding the
Subprocessor receives a request from a Data Subject earliest event giving rise to the liability, or (ii) EUR 10,000.
under any Data Protection Law in respect of Personal Data;
and 13 Modifications of the applicable Data Protection Law
ii. ensure that EVS and/or any Subprocessor only responds EVS may, by providing at least thirty (30) calendar days' written notice to
to such request upon express written instructions of the Customer, make variations to or replace the template EU SCC and
Customer or as required by applicable laws to which EVS enter into amended or new EU SCC as per Clause 5, subsection (ii), where
and/or the Subprocessor is subject. such variations or replacements are required as a result of any change in,
EVS shall conform to any time-scales set out in the Data Protection Law or decision of a competent authority under, the Data Protection Law, to
for Data Processor and, if applicable, correct or delete any inaccuracies in allow the Restricted Transfers r to be made (or continue to be made) in
Personal Data, as directed by Customer. compliance with the Data Protection Law.
Each Party may propose any variations to this Addendum where such
8 Personal Data Breach Party reasonably considers to be necessary to address the requirements
In case of any Personal Data Breach, EVS shall promptly notify Customer of any Data Protection Law.
of such breach. The notification must, at least, describe the nature of the
Personal Data Breach including where possible, the categories and 4. ENTRY INTO FORCE
approximate number of Data Subjects concerned and the categories and This Addendum enters into force at the date EVS starts providing the
approximate number of Personal Data records concerned, describe the Services to Customer and remains into force for the entire duration of the
likely consequences of the Personal Data Breach, describe the measures Principal Agreement.
taken or proposed to be taken to address the Personal Data Breach,
Version 24.05 (12/06/2026)
EVS SA, Rue du Bois Saint-Jean 13, 4102 Seraing, BELGIUM (Register of Legal Entities of Liège 0452.080.178)
EVS BROADCAST EQUIPMENT INC, 3rd Floor, 700 Route 46 East, Fairfield, NJ 07004, USA
EVS BROADCAST EQUIPMENT LTD, Room A 35/F Lee & Man Commercial Center, 169 Electric Road North Point HONG KONG
EVS NETHERLANDS BV, Hercules 28, 5126 RK Gilze, THE NETHERLANDS
DATA PROCESSING ADDENDUM
EVS AS PROCESSOR – CUSTOMER AS CONTROLLER
ANNEX 1: Instructions ANNEX 2: EVS SUBPROCESSORS
1. Nature and purpose of the Processing: Personal Data will be Support, rental:
Processed for the purposes of the performance of the services under
the Principal Agreement including the following purposes: Company name Nature of service
a) Provision of appropriate support services depending on the Harmonic Potential Subprocessor, in the event support
issue at stake services are performed by Harmonic in relation
b) Provision of video production management services with Harmonic parts contained in the Products
c) Provision of appropriate trade-in services Arista Potential Subprocessor, if support services are
d) Management and follow-up of Customer’s requests, history and performed by Arista in relation with Arista parts
equipment in this respect contained in the Products
e) Provision of Software as a Service NSI Software Consultancy services to EVS on an ad-hoc basis
f) Continuous improvement of the services Services
g) Compliance with Data Protection Law, information security
requirements and service level agreements
h) Claims management with and between the Customer, EVS, the C-Cast:
Data Subject(s) and/or third parties, including beyond
termination of the Agreement for any reason whatsoever AWS Cloud
i) Any other purpose of Processing of Personal Data agreed upon Brightcove
between Parties in the relevant statement of work or any other
document of the Principal Agreement. MediaHub:
2. Type of Personal Data: The Personal Data transferred concerns all
relevant information that is required to deliver the requested services, Company name Nature of service
which may include (a subset of) the following categories of data: AWS Cloud Cloud provider
a) Personal details such as name, birth date, etc.
Alibaba Cloud provider
b) Contact details such as address, e-mail address, telephone
GTT (Interroute) Proxy streaming server
number, etc.
Google analytics Collection of information about SaaS usage
c) Authentication Credentials to use the Services, such as
username, IP address, PC Name, etc. Aspera File accelerator
d) Activities performed by Customer users in their use of the NSI Software Consultancy services to EVS on an ad-hoc
Services and/or SaaS. Services basis
e) Video content and images, and data related to it (thubnails, Approach Consultancy services to EVS on an ad-hoc
metadata, etc.). basis
f) Any other category of Personal Data agreed upon between Wasabi Archive system
Parties in the relevant statement of work or any other document
of the Principal Agreement.
3. Categories of Data Subject: employees and consultant of the
Customer and if applicable, persons identified or identifiable through
Customer’s video content and images.
4. Duration of the Processing: The duration during which the Processing
of Personal Data by EVS is allowed corresponds the duration of the
Principal Agreement.
5. Permitted purposes: All the Processing strictly necessary with regard
to the nature and purpose of the Processing, as set forth in section 1
of the present Annex 1 including: data consultation, storage, etc.
Version 24.05 (12/06/2026)