Third Party Index

Snapshot 21140

Document
Subprocessor list
URL
https://netenrich.com/legal/data-processing-addendum#subprocessors
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
206477 bytes
SHA-256 (raw)
217255d53db13cd4d97284203c4dad9350368932aab92242152797ccfc21524a
SHA-256 (normalized text)
b4e447a4fc02e5d27f1aa4367e43f35087bc6eb8b21537cc60b2374a18c973b6

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Netenrich, Inc.
Data Processing Addendum
Last Modified: September 22, 2025
This Data Processing Addendum, including the annexes hereto (this “DPA”) forms a part of the Netenrich Master Services Agreement between Netenrich and Customer to which this addendum is attached (the “Agreement”) and sets out the parties’ agreement with respect to the Processing of Personal Data in relation to the Agreement. Terms in this DPA that are capitalized, but undefined, have the meanings given to them in the Agreement. Netenrich, Inc. and its Affiliates operate in the United States of America, the Republic of India and in various European countries. This DPA is meant to cover Agreements for customers which operate in any of those countries.
1. Definitions
a. “Affiliate” of a party means any entity controlling, under common control with, or controlled by the party, where “control” means ownership of more than 50% of the equity of such entity.
b. “Controller” means the natural or legal person, public authority, agency or other body that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. For clarity, the term "Controller" expressly includes a "Data Fiduciary" as defined under the DPDP Act.
c. “Data Protection Regulations” means all applicable privacy and data protection laws and regulations in the jurisdictions in which either the Customer or Netenrich operates, and includes without limitation, India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”), and the California Consumer Privacy Act of 2018 (as amended from time to time, the “CCPA”).
d. “FADP” means the Swiss Federal Act on Data Protection of 25 September 2020 (as amended), including any implementing regulations, and any guidance issued by the Swiss Federal Data Protection and Information Commissioner.
e. “GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council.
f. “Instructions” mean any documented instructions given by Customer with respect to the lawful Processing of Personal Data. Instructions may include, without limitation, the correction, erasure and/or the blocking of Personal Data in the legal responsibility of the Controller and instructions delivered by Customer through user functionality in the Services.
g. “Personal Data” means information relating to an identified or identifiable natural person (a “Data Subject” or alternatively, a “Data Principal”) or that meets the definition of “personal information” under the Data Protection Regulations and that, in either case, is Processed by Netenrich on behalf of Customer in connection with the Services.
h. “Processing”and/or Process mean any operation or set of operations that is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
i. “Processor” means a natural or legal person, public authority, agency or other body that Processes Personal Data on behalf of the Controller.
j. "Service(s)” means the services Netenrich provides to Customer and/or, if applicable, Customer’s Affiliates, under the terms of the Agreement.
k. "Sub-Processor” means, as applicable, (i) Netenrich, when Netenrich Processes Personal Data on behalf of Customer where Customer itself is a Processor of such Personal Data, or (ii) third-party processors engaged by Netenrich pursuant to Section 6 below.
l. "SCCs” means the contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.
m. "UK GDPR” means Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419).
2. Data Processing
a. The parties acknowledge and agree that with respect to Personal Data, (i) Customer is the Controller and Netenrich is the Processor of Personal Data, or (ii) Customer is the Processor and Netenrich is the Sub-Processor of Personal Data.
b. Each party will comply with the obligations applicable to it under Data Protection Regulations in relation to Personal Data. In particular, Customer as Controller shall ensure that it has obtained all consents and provided all notices as required for Netenrich to lawfully process the Customer’s Personal Data for the purposes of the Agreement.
c. Netenrich shall not Process Personal Data for any purpose other than providing the Services, fulfilling its contractual obligations under the Agreement and this DPA, and complying with Data Protection Regulations. Netenrich shall Process Personal Data only on behalf of Customer and in accordance with the Agreement, this DPA, and Customer’s Instructions.
d. As between Customer and Netenrich, all Personal Data are the property of Customer and Netenrich shall promptly, at Customer’s option, delete or return Personal Data to Customer upon request. Where Customer has not expressed a request with respect to the Personal Data, Netenrich shall delete the Personal Data within 30 days of the expiry or termination of this DPA and the Agreement, except where Data Protection Regulations or other applicable laws mandate a longer retention period.
e. Netenrich retains backups in accordance with its internal policies and procedures for business operation and security purposes that may contain Personal Data. Upon the expiry or termination of this DPA and the Agreement, to the extent that Netenrich’s backups contain Personal Data, such Personal Data (i) shall not be further Processed by Netenrich, (ii) shall be protected by Netenrich in accordance with the terms of this DPA so long as Netenrich retains such Personal Data, and (iii) shall be destroyed in accordance with Netenrich’s data retention policies.
3. Data Security
a. Netenrich has implemented, and shall maintain so long as Netenrich Processes Personal Data, the technical and organizational measures set out in Annex 2 to protect the confidentiality, integrity, and accuracy of Personal Data.
b. Netenrich shall ensure that the technical and organizational measures implemented to protect the confidentiality, integrity, and accuracy of Personal Data satisfy the requirements of Section 8 of the DPDP Act.
c. Netenrich shall ensure that its personnel who have access to Personal Data are subject to a duty of confidentiality with respect to the Personal Data.
c. Security Incidents.
If Netenrich becomes aware of any actual or reasonably suspected breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data (each a “Security Incident”), Netenrich shall, without undue delay and in any event, within 24 hours of becoming aware, notify Customer of the Security Incident, providing reasonably relevant known or suspected details of the incident.
Netenrich shall take all reasonable steps consistent with good industry practices to remediate the Security Incident and mitigate its impact and to identify and remediate its cause(s).
Netenrich shall provide any assistance reasonably requested or required by Customer to comply with Customer’s obligations under Data Protection Regulations including to notify regulatory authorities and/or Data Subjects impacted by a Security Incident.
4. Assistance and Cooperation
a. For the term of the Agreement and taking into account the nature of the Processing, Netenrich shall provide Customer with the ability to correct, delete, or block Processing of Personal Data, or, upon Customer’s Instructions, make such corrections, deletions, or blockages on Customer’s behalf.
b. Netenrich shall, to the limited extent relevant to the Services, provide commercially reasonable assistance to Customer with respect to (a) requests from Data Subjects exercising their rights to access, rectify, erase, or object to processing of Personal Data pursuant to Data Protection Regulations, or avail of grievance redressal mechanisms mandated under Data Protection Regulations to the extent applicable; and (b) privacy (including transfer) impact assessments carried out by Customer. Netenrich reserves the right to charge a fee to Customer, consistent with Data Protection Regulations, for complying with a request for assistance requiring significant effort and/or resources.
c. Netenrich shall allow for and contribute to reasonable and customary remote, document-based review audits (including reasonable interviews of relevant Netenrich management) by Customer, or a third party designated by Customer, in each case, as reasonably requested and required to demonstrate Netenrich’s compliance with this DPA, at Customer’s expense and with reasonable prior notice to Netenrich and, except where required by a data protection authority or in response to a Security Incident, no more than once per calendar year, provided that all audits, and any findings or reports resulting from any audit, will be subject to the confidentiality obligations set forth in the Agreement.
d. Netenrich shall promptly notify Customer if, in Netenrich’s reasonable opinion, any Instructions violate Data Protection Regulations.
e. If any regulatory authority (e.g., a data protection authority or the Indian Data Protection Board) wishes to conduct an audit of Netenrich’s facilities that includes Customer Personal Data, Netenrich will inform Customer (unless legally prohibited) and will cooperate with the authority.
5. Sub-processors
a. Netenrich may engage Netenrich Affiliates and other third parties as Sub-Processors to provide or help it deliver the services subject to this DPA. A list of Netenrich’s Sub-processors as of the initial effective date of this DPA is provided in Annex 3.
b. Netenrich shall permit Sub-Processors to Process Personal Data only as necessary to perform the services Netenrich has engaged them to provide to Netenrich and shall prohibit Sub-Processors from Processing Personal Data for any other purpose.
c. Prior to making any Personal Data available to a Sub-Processor, Netenrich or a Netenrich Affiliate shall have entered into a written agreement with the Sub-Processor containing data protection obligations substantially as protective of Personal Data as those in this DPA.
d. Netenrich shall notify Customer of each intended additional or replacement Sub-Processor at least thirty (30) days prior to such addition or replacement (the “Sub-Processor Notice Period”) during which period Customer may object by notice to Netenrich to the use of the Sub-Processor in which case the parties shall promptly negotiate in good faith to reach a mutually acceptable resolution. If the parties are unable to reach a mutually acceptable resolution within a reasonable period following the objection (not to exceed 15 days, or as extended by mutual agreement), Customer may terminate the Services or specific feature of the Services that cannot reasonably be provided by Netenrich without the use of the objected-to Sub-Processor.
e. Netenrich shall remain at all times responsible to Customer for the Sub-Processors’ compliance with this DPA.
6. Cross-border Data Transfer
a. To the extent any Personal Data subject to the GDPR, the UK GDPR, or the FADP is Processed by Netenrich outside the European Economic Area or a country deemed adequate by the European Commission, such Personal Data will be transferred and Processed in accordance with Sections 6.b– 6.d below.
b. Where a transfer of Personal Data is subject to the GDPR or the FADP, the SCCs will apply. The SCCs are hereby incorporated by reference into this DPA and completed as follows:
The text of module 2 (Controller to Processor) will apply where Customer is the Controller, and Netenrich is the Processor. The text of module 3 (Processor to Processor) will apply where Customer is the Processor, and Netenrich is the Sub-Processor;
The optional docking clause of clause 7 will apply;
In clause 9(a), option 2 will apply. The time period for providing advance notice of any intended changes to the list of Sub- Processors will be thirty (30) days;
In clause 11(a), the optional language will not apply;
In clause 17, option 1 will apply, and the SCCs will be governed by the laws of Ireland;
In clause 18(b), any dispute arising from the SCCs will be resolved by the courts of Ireland; and
The information required by Annex I and Annex II of the SCCs is as set out in Annex 1 and Annex 2 of this DPA, respectively.
c. Where a transfer of Personal Data is subject to the UK GDPR, the SCCs will apply, as amended by the UK Addendum to the SCCs issued by the Information Commissioner’s Office under s.119A(1) of the UK Data Protection Act 2018 and attached hereto as Annex 4.
d. Where a transfer of Personal Data is subject to the FADP, in addition to the provisions of Section 6.b above, the terms set forth on Annex 5 will apply.
e. Customer agrees and acknowledges that Netenrich will not transfer or allow access to Indian Personal Data to any country or entity prohibited by the Government of India.
f. To the extent any provision of this DPA contradicts or is inconsistent with the terms of the SCCs with respect to the transferred Personal Data or otherwise, the terms of the SCCs will prevail and the inconsistent provision of this DPA will be deemed amended accordingly.
g. If the DPDP Act or rules thereunder introduce model contract clauses or other transfer instruments, the parties will work together in good faith to incorporate those into this DPA (potentially as an addendum or by replacing the relevant sections) to ensure continuing compliance.
h. If, at any time:
the laws or regulatory procedures of any jurisdiction require any further steps to be taken in order to permit the transfer of Personal Data as contemplated under this DPA (including, without limitation, executing or re-executing the SCCs as a separate document setting out the proposed transfers of Personal Data, and entering into additional cross-border transfer clauses); and/or
the transfer mechanisms in this Section 6 are amended, replaced or repealed under Data Protection Regulations;
declared invalid by a court of competent jurisdiction; or
otherwise terminated, annulled, replaced or repealed under Data Protection Regulations; then the parties shall work together to take all steps reasonably required and negotiate in good faith any other solution to enable a transfer in compliance with Data Protection Regulations.
7. California Consumer Privacy Act
To the extent the CCPA applies to the Processing of Personal Data, the parties acknowledge and agree that Customer has engaged Netenrich as a service provider and Netenrich shall comply with the obligations of a service provider under the CCPA with respect to Netenrich’s Processing of Personal Data and Netenrich shall notify Customer within the 5 days following the date on which Customer determines that Netenrich can no longer meet its obligations under the CCPA and/or this DPA. Netenrich shall provide the same level of privacy protection for Personal Data as is required of a “business” under the CCPA and shall cooperate with Customer in responding to and complying with consumer requests made pursuant to the CCPA. Netenrich authorizes Customer to take reasonable and appropriate steps to stop and remediate Netenrich’s unauthorized use of Personal Data. Netenrich shall not, and shall ensure that any third party to which Netenrich provides access to Personal Data for Processing does not:
a. Sell or share Personal Data as “sell” and “share” are defined in the CCPA; or
b. Retain, use or disclose Personal Data:
for any purpose other than for the purposes described under the “nature and purposes of processing” in Annex 1 (the “Business Purpose”) and in accordance with the Agreement and the Instructions;
for (x) any commercial purpose other than the Business Purpose or (y) for the benefit of any third party outside the Agreement; or
outside the direct business relationship between Customer and Netenrich. For purposes of this Section 7, the terms “business”, “consumer”, “service provider”, “commercial purposes”, “sell”, and “share” have the definitions ascribed to them in the CCPA.
8. Third Party Request for Access
Unless prohibited by applicable law, Netenrich shall promptly inform Customer of any request, correspondence, inquiry, or complaint received by Netenrich from a Data Subject, regulatory authority, or other third party in connection with Netenrich’s Processing of Personal Data. Netenrich shall not directly respond to such requests without Customer’s prior consent except where legally required.
9. Limitation of Liability
The liability of each party and its respective Affiliates arising out of or related to this DPA and the Agreement will not, when taken together in the aggregate, exceed the limitation of liability set forth in the Agreement. To the extent governed by the DPDP Act, it is clarified that Netenrich shall be liable solely for penalties or damages imposed directly upon the Processor by the Data Protection Board of India due to Processor's material breach of its express obligations under this Agreement or under the DPDP Act.
10. Customer Responsibilities and Undertakings
a. Customer warrants that the Personal Data have been collected, Processed, and transferred by Customer in accordance with the laws applicable to Customer, including Data Protection Regulations, and with an appropriate legal basis for instructing Netenrich to process such data on the Customer’s behalf.
b. Customer is solely responsible for the accuracy, quality, and such legal compliance relating to the Personal Data as and when made available to Netenrich for Processing under this DPA. Customer acknowledges that Netenrich has no control over the nature, scope, or origin of, or the means by which Customer acquires, the Personal Data. Without limiting Netenrich’s obligations under this DPA, Customer retains responsibility for responding to any Data Subject requests or inquiries regarding the Personal Data. Customer shall not use the Services to Process any sensitive or special categories of Personal Data where such Processing would impose on Netenrich any data security or data protection obligations that differ from or are in addition to those set out in the Agreement and this DPA.
11. Miscellaneous
a. If any provision in this DPA is found to be ineffective or void, it will not affect the remaining provisions. The parties shall endeavor in good faith to replace the ineffective or void provision with a lawful provision that reflects the business purpose of the ineffective or void provision. The parties shall similarly add necessary and appropriate provisions where such provisions are missing.
b. The governing law of this DPA will be the same as the governing law in the Agreement, provided that where 6.b.vi of this DPA is applicable, then the law identified therein shall be applicable in such limited context.
c. This DPA prevails over any additional, conflicting, or inconsistent terms and conditions appearing in the Agreement and/or any document submitted by either party regarding the Processing of Personal Data
d. This DPA will become effective upon the parties’ execution of the Agreement (the “DPA Effective Date”) and will remain in effect for so long as Netenrich has in its possession or otherwise Processes Personal Data.
e. This DPA may not be modified except in a writing executed by the parties or otherwise in accordance with its terms.
ANNEX 1: DETAILS OF THE PROCESSING
ANNEX 2: Summary of Technical and Organizational Measures
ANNEX 3: List of Sub-processors
ANNEX 4: UK Addendum to the EU Commission Standard Contractual Clauses
ANNEX 5: Switzerland
PREVIOUS VERSIONS
March 2, 2023