Third Party Index

Snapshot 21142

Document
Subprocessor list
URL
https://pathify.com/data-processing-addendum/#subprocessors
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
441863 bytes
SHA-256 (raw)
da9ec8bead9ad01af7998433472f40334b3b33b2a5f296c0d2eef643e6e43844
SHA-256 (normalized text)
b4ff6c4ed98e446e4bb082285985c57b30048964d154ce88e736e57874a6e9d0

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Data Processing Addendum
Version 2026-09-07: Current version published at pathify.com/data-processing-addendum
Last Updated: September 7, 2026
This Data Processing Addendum (“DPA”) is incorporated into and forms a part of the Master Services & Software License Agreement (the “Agreement”) between Path Education Inc., a Delaware corporation d/b/a Pathify (“Pathify”), and the institution or organization that has executed the Agreement or an Order Form referencing the Agreement (“Customer”). Capitalized terms used in this DPA have the meanings given in this DPA. Where a term is not defined here, it has the meaning given in the Agreement and, only where not defined there, in Pathify’s applicable privacy notices. Where the Agreement is an earlier form that does not define a term used in this DPA, the term has the meaning given in Data Protection Laws or, absent that, its ordinary meaning in the context of the processing described. “AAIP” means Pathify’s Acceptable AI Policy and AI Impact Analysis, identified by its version date, as that document is defined in the Agreement. This DPA is published by Pathify and forms part of, or is incorporated into, the Agreement.
1. Definitions
In this DPA, the following terms (and derivations thereof) have the meanings set out below. Terms not defined in this DPA but defined in the Agreement or an applicable Pathify privacy notice have the meanings given in those documents.
“Affiliate” means any person or entity that owns or controls, is owned or controlled by, or is under common control or ownership with, a Party, where “control” means the direct or indirect power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract, or otherwise.
“AI Agent” means the conversational artificial intelligence interface included within the Services, powered by the Model Provider, that retrieves and surfaces institutional information in response to user prompts.
“AI Agent Function” means each distinct function of the AI Agent as described and classified in the Agreement and the AAIP.
“AI Model Provider” or “Model Provider” means the third party that provides the underlying generative AI technology used by the AI Agent, currently Google LLC with respect to the Google Gemini service, as further described in Schedule 5 (Subprocessor List).
“Applicable Law” means all laws, regulations, rules, orders, and binding guidance applicable to a Party’s performance of its obligations under this DPA, including Data Protection Laws, FERPA, SB 26-189, and other laws addressed in this DPA.
“CCPA/CPRA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, together with its implementing regulations.
“Controller” means the individual or entity that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the CCPA/CPRA applies to Customer, the term includes “business” as defined in that law, and the term includes equivalent terms under other Data Protection Laws where those laws apply.
“CPA” means the Colorado Privacy Act, codified at C.R.S. § 6-1-1301 through C.R.S. § 6-1-1313.
“Customer Content” means any data, file attachments, text, images, reports, personal information, or other content that is uploaded or submitted to the Services by Customer or by Users and is Processed by Pathify on behalf of Customer. Customer Content does not include usage, statistical, learned, or technical information that does not reveal the actual contents of Customer Content.
“Customer Personal Data” means Personal Data that is contained within Customer Content or is otherwise Processed by Pathify on behalf of Customer under the Agreement.
“Data Protection Laws” means, to the extent applicable to a Party in connection with the Processing of Customer Personal Data: (i) the European Union General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”); (ii) the United Kingdom General Data Protection Regulation and the UK Data Protection Act 2018 (“UK GDPR”); (iii) the Swiss Federal Act on Data Protection; (iv) the CCPA/CPRA; (v) the CPA; (vi) other United States state comprehensive privacy laws; (vii) FERPA; and (viii) any other privacy, data protection, or data security law applicable to the Processing of Customer Personal Data.
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates. The term includes “consumer” under the CCPA/CPRA and equivalent terms under other Data Protection Laws.
“End User” means an individual who accesses or uses the Services through Customer’s subscription.
“FERPA” means the Family Educational Rights and Privacy Act of 1974, codified at 20 U.S.C. § 1232g, together with its implementing regulations at 34 CFR Part 99.
“FERPA Records” means Customer Content that qualifies as “education records” within the meaning of FERPA and 34 CFR § 99.3, and any Personal Data derived from such records.
“Parties” or “Party” means Customer and Pathify, individually or together as the context requires.
“Pathify Personnel” means any individual employed or engaged by Pathify, or by a Pathify Affiliate, who is authorized to Process Customer Personal Data in the course of performing services for Pathify.
“Personal Data” means any information relating to, identifying, describing, or capable of being associated with a Data Subject, and includes “personal information” under the CCPA/CPRA and equivalent terms under other Data Protection Laws.
“Process” and “Processing” mean any operation or set of operations performed upon Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, alignment, combination, restriction, erasure, destruction, or disclosure by transmission, dissemination, or otherwise making available.
“Processor” means the individual or entity that Processes Personal Data on behalf of a Controller. The term includes “service provider” under the CCPA/CPRA and “processor” under the CPA and equivalent terms under other Data Protection Laws.
“SB 26-189” means Part 17 of Article 1 of Title 6 of the Colorado Revised Statutes, as enacted by Colorado Senate Bill 26-189 (which repealed and reenacted the former Colorado Artificial Intelligence Act), effective January 1, 2027, as such Part 17 may be amended, recodified, renumbered, superseded, or replaced from time to time, together with any successor statute and any rules or guidance implementing it.
“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data. For the avoidance of doubt, a Security Incident does not include an unsuccessful attack or intrusion, as further described in Section 9.5.
“Services” means the Subscription Services, any professional services provided by Pathify under the Agreement, and any other online service or application provided or controlled by Pathify for use with the Subscription Services, as further described in the Agreement.
“Standard Contractual Clauses” has the meaning given in Schedule 3.
“Subprocessor” means any third party (excluding Pathify Personnel) appointed by or on behalf of Pathify to Process Customer Personal Data in connection with the Agreement, including the Model Provider and the entities identified in Schedule 5 (Subprocessor List).
“Subscription Services” means the subscription-based online services and applications provisioned or controlled by Pathify, including the Campus Experience Platform (“CXP”) and the AI Agent.
“Supervisory Authority” means an independent competent public authority established or recognized under Data Protection Laws.
“Usage Data” means analytical, statistical, learned, or technical information derived from use of the Services that does not include or reveal the contents of Customer Content and does not identify, and cannot reasonably be used to identify, an individual End User. “User” has the same meaning as “End User.”
2. Roles of the Parties
2.1. General. As between the Parties with respect to the Processing of Customer Personal Data under the Agreement, and except as expressly provided with respect to Usage Data in Schedule 3 (Cross-Border Transfer Mechanisms) and Schedule 4 (Jurisdiction Specific Terms):
Customer is the Controller of Customer Personal Data and, where the CCPA/CPRA applies to Customer, the business; and
Pathify is the Processor (and, under the CCPA/CPRA, the service provider) of Customer Personal Data.
Each Party is solely responsible for its compliance with Data Protection Laws applicable to it and for fulfilling any related obligations to third parties, including Data Subjects and Supervisory Authorities.
2.2. Customer as Controller.
2.2.1. Customer is solely responsible for the accuracy, quality, and legality of Customer Personal Data and for the legality of the means by which Customer acquires, discloses, and Processes Customer Personal Data.
2.2.2. Customer’s instructions to Pathify to Process Customer Personal Data will comply with Data Protection Laws and will be duly authorized, with all necessary rights, permissions, and consents secured.
2.2.3. Customer is responsible for providing any privacy notices required under Data Protection Laws to Data Subjects about the Processing of Customer Personal Data by Pathify and its Subprocessors.
2.3. Pathify as Processor. Pathify’s role and obligations as Processor are set out in Section 3 (Pathify’s Processing Obligations).
2.4. Relationship to Customer’s Privacy Notice. Pathify acknowledges that Customer typically publishes a privacy notice to Users describing the Processing of Customer Personal Data by Pathify acting as Customer’s Processor. Customer may use the form of privacy notice made available by Pathify for this purpose (the “CXP Privacy Policy”), or Customer may use a privacy notice of its own design. Pathify’s separate privacy notice addressed to visitors of Pathify’s own websites (the “Pathify Website Privacy Policy”) does not govern the Processing of Customer Personal Data by Pathify acting as Customer’s Processor; that Processing is governed by this DPA and Customer’s privacy notice to Users.
3. Pathify’s Processing Obligations
3.1. Processing on Documented Instructions. Pathify will Process Customer Personal Data only: (a) as instructed by Customer in writing or as initiated by authorized Users through the Services; (b) as necessary to provide the Services and to prevent or address technical problems with the Services, violations of the Agreement or this DPA, or use of the AI Features otherwise than as described in the AAIP; or (c) as required by Applicable Law. Schedule 1 (Details of Processing of Customer Personal Data) sets out a description of Pathify’s Processing of Customer Personal Data. Pathify will promptly inform Customer if Pathify becomes aware that any Customer instruction to Process Customer Personal Data, in Pathify’s reasonable opinion, violates Data Protection Laws, and Pathify may suspend Processing under any such instruction pending resolution.
3.2. Confidentiality of Pathify Personnel. Pathify will ensure that Pathify Personnel: (a) access Customer Personal Data only to the extent necessary to perform Pathify’s obligations under this DPA and the Agreement; (b) are bound by written or statutory confidentiality obligations with respect to Customer Personal Data that are substantially as protective as those set forth in this DPA and the Agreement; and (c) are subject to appropriate training relating to the Processing of Customer Personal Data, the requirements of this DPA, and Pathify’s information security program.
3.3. No Sale or Sharing. Pathify will not sell or share Customer Personal Data within the meaning of the CCPA/CPRA and will not Process Customer Personal Data for cross-context behavioral advertising. Pathify will not Process Customer Personal Data outside of the direct business relationship between Pathify and Customer, and will not combine Customer Personal Data with Personal Data that Pathify receives from another entity or collects from individuals, except as expressly permitted by Data Protection Laws for a service provider or Processor.
3.4. Purpose Limitation. Pathify will Process Customer Personal Data solely for the purpose of providing the Services to Customer under the Agreement and for the related purposes described in Schedule 1. Pathify will not retain, use, or disclose Customer Personal Data for any commercial purpose other than providing the Services.
3.5. Uniform Handling of Customer Content. Pathify does not classify Customer Content at the field level to identify regulated data types. On the basis of Customer’s representation that Customer Content may include FERPA Records, Pathify applies uniform handling consistent with the requirements applicable to FERPA Records to all Customer Content submitted through the Services, whether or not Pathify has been informed that particular Customer Content constitutes FERPA Records, and applies the same uniform security, access, and retention controls without regard to whether specific Customer Content fields constitute Personal Data, FERPA Records, or other regulated categories. Customer is responsible for configuring the Services and providing instructions that reflect the legal character of the Customer Content being Processed. This Section 3.5 does not relieve Pathify of its obligations under Section 6 (FERPA Provisions) when Pathify has been informed that Customer Content constitutes FERPA Records.
3.6. Return or Deletion on Termination. On termination of the DPA or the Agreement, Pathify will return or delete Customer Content in accordance with the Agreement and Section 13 (Termination; Return and Deletion) of this DPA.
4. Security
4.1. Security Program. Pathify will implement and maintain technical, physical, and organizational measures and controls designed to protect and secure Customer Personal Data against Security Incidents, as further set out in Schedule 2 (Technical and Organizational Security Measures). Pathify will not materially diminish the overall level of protection described in Schedule 2 during the term of the Agreement.
4.2. Customer Responsibilities. Customer acknowledges that, through its Users:
Customer controls the type and substance of Customer Content;
Customer configures the Services, including access permissions, role assignments, and AI Agent activation choices, through Customer’s administrator settings; and
Customer is responsible for independently assessing and implementing the security configuration settings made available by Pathify as Customer deems necessary to meet Customer’s requirements and legal obligations under Applicable Law.
4.3. Security Assessments. Customer is responsible for reviewing and evaluating whether the documented functionality of the Services and the controls described in Schedule 2 meet Customer’s own security obligations relating to Customer Personal Data under Applicable Law, including the security requirements applicable to FERPA Records.
5. Subprocessors
5.1. General Authorization. Customer provides a general written authorization for Pathify to appoint Subprocessors to Process Customer Personal Data in connection with the provision of the Services, subject to this Section 5. Customer’s execution of the Agreement constitutes authorization for the Subprocessors identified in Schedule 5 (Subprocessor List) as of the Effective Date of the Agreement.
5.2. Subprocessor List. Pathify maintains a list of its Subprocessors that Process Customer Personal Data in Schedule 5 (Subprocessor List). Pathify will update the list as Subprocessors are added or replaced.
5.3. Notice of New Subprocessors. Pathify will provide Customer with at least thirty (30) days’ prior written notice before appointing a new Subprocessor that will Process Customer Personal Data, which notice may be delivered by updating the Subprocessor List and providing notice through the Services or by email to the administrator contact on file for Customer.
5.4. Objection Rights. Customer may object in writing to the appointment of a new Subprocessor on reasonable grounds relating to data protection within thirty (30) days following Pathify’s notice. If Customer objects, the Parties will discuss the objection in good faith. If the Parties are unable to reach a commercially reasonable resolution, Customer’s sole and exclusive remedy will be to terminate the affected Services under the Agreement without early termination fees, with a pro-rata refund of any prepaid fees for the period following the effective date of termination.
5.5. Subprocessor Agreements. Pathify will carry out appropriate due diligence on each Subprocessor and will enter into a written agreement with each Subprocessor that imposes data protection obligations that are no less protective than those set forth in this DPA, including, where applicable, the provisions required under Article 28(3) of the GDPR and the data protection terms required by the CCPA/CPRA for service providers.
5.6. Liability for Subprocessors. Pathify is liable for the acts and omissions of its Subprocessors relating to the Processing of Customer Personal Data to the same extent Pathify would be liable if performing the acts directly under this DPA, subject to the limitations of liability in the Agreement.
6. FERPA Provisions
6.1. Scope. This Section 6 applies to Customer Content that constitutes FERPA Records, and to Pathify’s Processing of FERPA Records in the course of providing the Services to Customer.
6.2. School Official Designation. With respect to FERPA Records Processed by Pathify in the course of providing the Services:
Pathify performs for Customer an institutional service or function for which Customer would otherwise use its own employees, and on that basis Customer designates Pathify as a “school official” of Customer within the meaning of 34 CFR § 99.31(a)(1)(i)(B), subject to the requirements of that regulation and of this Section 6;
Pathify acknowledges that it has a legitimate educational interest in the FERPA Records solely to the extent necessary to perform the Services for Customer; and
Pathify acknowledges that Customer retains direct control over Pathify’s use and maintenance of FERPA Records, as further described in this Section 6.
6.3. Direct Control. Pathify acknowledges that Customer’s direct control over Pathify’s Processing of FERPA Records is exercised through:
Customer’s configuration of the Services, including role-based access controls, permissions, and AI Agent activation choices;
Customer’s written instructions under Section 3.1; and
Pathify’s obligations under this DPA and the Agreement to Process Customer Personal Data only for the purposes of providing the Services.
6.4. Use and Redisclosure. Pathify will Process FERPA Records only for the purpose of performing the Services for Customer and will not use or redisclose FERPA Records except as permitted by 34 CFR § 99.33(a) and, in the case of any further disclosure made on behalf of Customer, 34 CFR § 99.33(b), or as otherwise authorized in writing by Customer.
6.5. Further Disclosure to the Model Provider. Where an AI Agent Function transmits FERPA Records to the Model Provider, that transmission is a further disclosure made by Pathify on behalf of Customer, in the course of performing the institutional function for which Customer has designated Pathify a school official under 34 CFR § 99.31(a)(1)(i)(B). Customer authorizes that further disclosure under 34 CFR § 99.33(b). The Model Provider is an authorized Subprocessor and further recipient acting on Customer’s behalf and not on its own behalf, is bound by the use and redisclosure restrictions in 34 CFR § 99.33(a) as applied through Pathify’s written agreement with it, and is not permitted to use FERPA Records for its own purposes. Pathify will record each such further disclosure as required by 34 CFR § 99.32(b) and will make that record available to Customer on request.
6.6. Customer FERPA Annual Notification Representations. Customer represents and warrants that:
Customer’s annual FERPA notification to students (or their parents or guardians, as applicable) specifies criteria for determining who constitutes a school official and what constitutes a legitimate educational interest, as required by 34 CFR § 99.7, and those criteria encompass contractors and service providers such as Pathify; and
Customer has completed, or will complete before activating any AI Agent Function or feature of the Services that transmits FERPA Records to an AI Model Provider (or other Subprocessor), any additional consent, notice, or directory information procedures required under Customer’s own FERPA policies and under Applicable Law.
Pathify is entitled to rely on Customer’s activation choices in the Services and on the representations in this Section 6.6 for purposes of the FERPA school official framework.
6.7. FERPA-Specific Termination Cooperation. If Customer determines, in good faith and based on a reasoned review of Applicable Law and Customer’s own FERPA policies, that continued Processing of FERPA Records by a specific Subprocessor (including the Model Provider) is inconsistent with Customer’s FERPA obligations, Customer may provide Pathify written notice requesting termination of the Processing activity involving that Subprocessor. On receipt of the notice, Pathify will use commercially reasonable efforts to offer Customer one or more of the following: (a) termination of the affected feature or Services; (b) a reconfiguration that removes the Subprocessor from the Processing activity; or (c) replacement of the Subprocessor with an alternative Subprocessor acceptable to Customer. If none of these options is commercially reasonably available, Customer may terminate the affected Services under the Agreement without early termination fees, with a pro-rata refund of any prepaid fees for the period following the effective date of termination.
7. AI Agent and Model Provider Processing
7.1. Scope. This Section 7 applies to Processing of Customer Personal Data through the AI Agent and to transmission of Customer Personal Data to the Model Provider, including Google LLC with respect to the Google Gemini service.
7.2. Relationship to the AAIP. The AAIP describes how the AI Agent operates, including the AI Agent Function framework, AI Agent activation controls, and the categories of Customer Content transmitted to the Model Provider. The AAIP is provided for notice and information and is not incorporated into this DPA. Where the AAIP and this DPA address the same subject matter, this DPA governs and controls. The AAIP does not govern, and this DPA governs and controls, with respect to Pathify’s Processing obligations as Processor, Subprocessor restrictions, FERPA commitments, and the other data protection subject matter described in Section 14.1, even where those matters relate to AI Agent operation. For AI Agent subjects that involve both operation and data processing, this DPA governs Pathify’s processor, Subprocessor, FERPA, and data-transfer obligations, the Agreement governs the commercial allocation, and the AAIP describes activation gating, function-based activation conditions, and operational safeguards; no other Pathify Policy Document overrides the data-protection obligations of this DPA unless this DPA expressly so provides.
7.3. Function and Configuration Acknowledgment. Pathify acknowledges that the scope of Customer Personal Data transmitted to the Model Provider depends on the AI Agent Functions and configurations that Customer has activated, as described in the AAIP. Customer is responsible for activating only those AI Agent Functions and configurations that are consistent with Customer’s own obligations under Applicable Law, including FERPA.
7.4. Model Provider as Subprocessor. The Model Provider is a Subprocessor under this DPA and, with respect to FERPA Records, an authorized further recipient acting on behalf of Customer as described in Section 6.5. Pathify does not hold the Model Provider out as an agent of Customer. Pathify will maintain a written agreement with the Model Provider that includes data protection obligations consistent with Section 5.5 of this DPA, including, with respect to Google LLC, the terms of the Google Cloud Data Processing Addendum for paid services. Pathify will not authorize the Model Provider to use Customer Personal Data to train general-purpose foundation models, to sell Customer Personal Data, or to Process Customer Personal Data for purposes other than providing the AI Agent service to Pathify for Pathify’s provision of the Services to Customer.
7.5. Data Handling. Pathify’s configuration of the AI Agent, as further described in the AAIP, determines what Customer Personal Data is transmitted to the Model Provider for a given AI Agent Function. Where an AI Agent Function is configured to use a User’s own record context to generate a response or perform the function, the underlying record values themselves (for example, grades, enrollment status, or financial aid information), and not merely a reference to or summary of them, are transmitted to the Model Provider as needed for that purpose. Transmissions of FERPA Records to the Model Provider in this manner are further disclosures made on behalf of Customer as described in Section 6.5, and are governed by the FERPA school official framework and the contractual arrangements with the Model Provider referenced in Section 7.4 and the AAIP. Pathify does not represent that institution-sourced record values are withheld from, or abstracted away from, the Model Provider. Query text submitted by the User may itself contain personal data and, where transmitted to the Model Provider, is processed within the data-flow envelope applicable to the active AI Agent Function and configuration. Pathify transmits to the Model Provider only the categories of Customer Personal Data that the active AI Agent Function and configuration require, consistent with the AAIP.
7.6. SB 26-189. The Parties acknowledge that certain provisions of SB 26-189 may apply to the AI Agent depending on the AI Agent Function activated and the decision-making context in which the AI Agent is used. The allocation of responsibilities between Pathify (as developer under SB 26-189 with respect to the AI Agent) and Customer (as deployer under SB 26-189 with respect to Customer’s use of the AI Agent) is set out in the Agreement and the AAIP. Nothing in this DPA reallocates those responsibilities.
7.7. Safety and Topic Detection. Where the Customer enables it, the AI Agent may screen conversation content to detect potential safety concerns or Customer-designated topics and may route or notify Customer-designated staff. This Processing is performed as a protective and routing measure under the Customer’s control, is fallible, and is subject to this DPA and the AAIP. This detection is performed by prompting the Model Provider, so the conversation content screened for safety or Customer-designated topics is transmitted to the Model Provider for that classification. It is designed to operate within the same data-flow envelope otherwise applicable to the active AI Agent Function and configuration and not, by itself, to expand the categories of Customer Content or personal data transmitted to the Model Provider beyond the conversation content already within that envelope.
8. Data Subject Requests
8.1. Notification to Customer. Pathify will notify Customer in writing without undue delay, and in any event within five (5) business days (or sooner if reasonably necessary to enable Customer to meet an applicable response deadline under Data Protection Laws), following receipt of any verifiable request Pathify receives directly from a Data Subject that relates to Customer Personal Data Processed under the Agreement. Pathify will respond directly to such a Data Subject only: (a) to confirm that the request relates to Customer and direct the Data Subject to Customer; (b) as required by Applicable Law; or (c) with Customer’s written consent. Except as provided in this Section 8.1, Pathify, as Processor, does not intend to respond to or fulfill Data Subject requests relating to Customer Personal Data.
8.2. Assistance to Customer. At Customer’s written request, and to the extent Customer is unable to access the relevant Customer Personal Data through the Services or through self-service tools made available by Pathify, Pathify will provide reasonable assistance to Customer in responding to Data Subject requests. To the extent legally permitted, Customer will be responsible for any expenses attributable to Pathify’s assistance efforts that fall outside the ordinary course of support provided under the Agreement.
9. Security Incidents
9.1. Notification. Pathify will notify Customer in writing without undue delay after Pathify confirms that a Security Incident affecting Customer Personal Data has occurred.
9.2. Investigation and Remediation. Pathify will investigate and, as necessary, mitigate and remediate the Security Incident in accordance with Pathify’s security incident response policies and procedures (“Incident Response”).
9.3. Incident Information. Pathify will provide Customer with the information reasonably available to Pathify as a result of its Incident Response, including the nature of the Security Incident, the categories and approximate number of affected Data Subjects and records, the likely consequences, the measures taken or proposed to address the Security Incident and to mitigate its possible adverse effects, and the name and contact details of a Pathify contact point from whom further information can be obtained (the “Incident Information”). Pathify will provide the Incident Information in the notification required under Section 9.1 to the extent then known and will update Customer as additional Incident Information becomes available.
9.4. Additional Cooperation. If Customer requires specific information about the Security Incident in addition to the Incident Information, and to the extent Customer is unable to access that information on its own, Pathify will reasonably cooperate with Customer to attempt to collect and provide the additional information.
9.5. Unsuccessful Attempts. An unsuccessful attack or intrusion is not a Security Incident under this Section 9. An “unsuccessful attack or intrusion” is one that does not result in unauthorized or unlawful access to Customer Personal Data and includes, without limitation, pings and other broadcast attacks on firewalls or edge servers, port scans, unsuccessful log-on attempts, denial of service attacks, packet sniffing that does not result in access beyond IP addresses or TCP/UDP headers, and similar incidents.
9.6. Customer-Caused Incidents. Where unauthorized or unlawful access to Customer Personal Data results from Customer’s configuration settings, compromise of a User’s login credentials for which Pathify is not responsible, or the sharing or disclosure of Customer Content by Customer or a User, Pathify will notify Customer in accordance with Section 9.1 and provide the Incident Information available to it, and Customer is responsible for assessing and discharging its own notification obligations and for the costs of investigation and remediation attributable to the cause. Nothing in this Section relieves Pathify of its obligations under Sections 9.1 to 9.4. Customer is responsible for maintaining accurate administrator contact information in the Services.
9.7. Delivery of Notifications. Pathify will deliver notifications under this Section 9 to one or more of Customer’s system administrator Users by any reasonable means Pathify selects, including email.
10. Audit Rights
10.1. Relationship to the Agreement. The audit rights in this Section 10 supplement, and are coordinated with, any audit cooperation, regulatory inquiry, and data protection impact assessment cooperation obligations under Applicable Laws, and any voluntary function-specific impact analysis or assessment cooperation obligations, set out in the Agreement. Customer may exercise audit rights under either this DPA or the Agreement, but Customer will not be entitled to duplicative audits of the same subject matter in a given calendar year.
10.2. External Audits. Pathify will engage external auditors at Pathify’s expense to audit Pathify’s information security program on at least an annual basis. The audit will: (a) be performed by independent third party security professionals selected by Pathify; (b) include testing of the security measures and controls of the Services according to AICPA SOC 2 standards (or substantially equivalent alternative standards) and will result in a SOC 2 report or substantive equivalent; and (c) include penetration testing of the Services and result in a penetration test report. The resulting reports (the “Audit Reports”) are Pathify’s Confidential Information. Pathify will make the Audit Reports available to Customer on written request no more than once per calendar year, subject to the confidentiality obligations of the Agreement or a mutually agreed non-disclosure agreement.
10.3. Customer Audit. If Customer requires information for Customer’s compliance with Data Protection Laws beyond the information available in the Audit Reports and in self-service tools made available by Pathify, and to the extent Customer is unable to access that information on its own, Pathify will allow for and cooperate with a Customer-mandated audit conducted by a third-party auditor in relation to Pathify’s Processing of Customer Personal Data (a “Customer Audit”), provided that:
10.3.1. Customer provides Pathify at least thirty (30) days’ advance written notice, including the identity of the auditor and the anticipated date and scope of the Customer Audit;
10.3.2. Pathify approves the auditor, with approval not to be unreasonably withheld;
10.3.3. Customer and the auditor execute a non-disclosure agreement reasonably acceptable to Pathify and conduct the Customer Audit in a manner designed to avoid damage to, or disruption of, Pathify’s premises, equipment, business operations, or the Services of other Pathify customers;
10.3.4. Customer initiates no more than one Customer Audit in any calendar year, unless an additional Customer Audit is required by a Supervisory Authority, in which case Sections 10.3.1 through 10.3.3 and Section 10.3.5 continue to apply to that audit; and
10.3.5. Customer bears its own costs of the Customer Audit and reimburses Pathify for Pathify’s reasonable costs of cooperating with the Customer Audit.
10.4. Data Protection Impact Assessments. Pathify will provide Customer with reasonable assistance in relation to Customer’s data protection impact assessments and prior consultations with Supervisory Authorities, taking into account the nature of the Processing and the information available to Pathify.
11. International Transfers
11.1. General. The Parties acknowledge that the Processing of Customer Personal Data by Pathify may involve an international transfer of Customer Personal Data (an “International Transfer”).
11.2. Jurisdictional Terms. To the extent Pathify Processes Customer Personal Data that is subject to the Data Protection Laws of one of the jurisdictions addressed in Schedule 4 (Jurisdiction Specific Terms), the terms of Schedule 4 for that jurisdiction apply in addition to the terms of this DPA.
11.3. Transfer Mechanisms. To the extent Customer’s use of the Services requires a valid transfer mechanism to lawfully transfer Customer Personal Data from the European Economic Area (“EEA”), the United Kingdom or Switzerland to Pathify located outside of that jurisdiction (a “Transfer Mechanism”), the terms of Schedule 3 (Cross-Border Transfer Mechanisms) apply. For any other jurisdiction addressed in Schedule 4, the transfer requirements set out in Schedule 4 for that jurisdiction apply.
11.4. Transfer Mechanism Failure. If any Transfer Mechanism fails as a lawful data transfer mechanism for an International Transfer, the Parties will act in accordance with Section 15.8 (Variations in Data Protection Laws).
12. Customer Obligations and Representations
12.1. Lawful Basis. Customer represents and warrants that Customer has a lawful basis under Data Protection Laws for instructing Pathify to Process Customer Personal Data, and that Customer has provided any notices, obtained any consents, and fulfilled any other requirements under Data Protection Laws necessary to enable Pathify’s lawful Processing of Customer Personal Data as contemplated by this DPA and the Agreement.
12.2. Accuracy of Customer Content. Customer is responsible for the accuracy of Customer Content and for ensuring that Users are trained and authorized to submit Customer Content to the Services.
12.3. Configuration Choices. Customer is responsible for the AI Agent Function and configuration activation choices Customer makes in the Services and for ensuring that those choices are consistent with Customer’s obligations under Applicable Law, including FERPA. Pathify is entitled to rely on Customer’s configuration choices.
12.4. FERPA Representations. The FERPA-specific Customer representations are set out in Section 6.6.
13. Termination; Return and Deletion
13.1. Duration. This DPA is effective as of the Effective Date of the Agreement and remains in effect for the term of the Agreement.
13.2. Return or Deletion of Customer Content. Within a reasonable period following termination or expiration of the Agreement, and in any event within ninety (90) days unless the Parties agree to a different period, Pathify will, at Customer’s choice, return Customer Content to Customer in a commercially reasonable format or delete Customer Content from Pathify’s production systems. Where Customer makes no election within thirty (30) days of termination or expiration, Pathify will return Customer Content and then delete it. Pathify may retain Customer Content in archival or backup media in accordance with Pathify’s ordinary retention and deletion schedules, subject to the continuing obligations of this DPA. Pathify may also retain a configuration record, consisting solely of the configuration change made, the administrator who made it, and the time of the change, for up to ten years from the date the change is recorded, as an independent controller, and solely as evidence of Customer authorization and of the Parties’ performance of the Agreement. Pathify will not use a configuration record for any other purpose, and each configuration record remains subject to the continuing obligations of this DPA. This exception does not extend to any other record of End User activity, which is subject to the return-or-deletion obligations of this Section. The return-or-deletion obligations of this Section apply to Customer Content wherever Pathify processes or stores it, including in any secondary analytics store such as Google Cloud (BigQuery and related analytics services) identified in the Subprocessor list, and Pathify will, on Customer’s written request, provide a certificate confirming completion of the deletion.
13.3. Retention Required by Law. Notwithstanding Section 13.2, Pathify may retain Customer Content to the extent required by Applicable Law, subject to the continuing confidentiality and security obligations of this DPA.
14. Order of Precedence and Stack Integration
14.1. DPA Governs Data Protection Subject Matter. This DPA governs the Processing of Customer Personal Data by Pathify. In the event of a conflict between this DPA and any other written agreement between the Parties (including the Agreement) on a subject matter specifically addressed by this DPA, this DPA will govern and control with respect to that subject matter. Data protection subject matter includes: Pathify’s Processing obligations as Processor; Subprocessor engagement; Data Subject request handling; Security Incident notification; international transfers; Pathify’s information security obligations; compliance with Data Protection Laws; and the FERPA school official framework as it relates to Pathify’s direct Processing role.
14.2. Agreement Governs Operational Subject Matter. The Agreement governs the overall commercial and legal relationship between the Parties. The AAIP describes the operational characteristics of the AI Agent and does not govern the Parties’ obligations. On subject matter specifically addressed by the Agreement that is not data protection subject matter under Section 14.1, the Agreement governs. This includes the allocation of responsibilities under SB 26-189 as between Pathify and Customer, End-User-facing terms, and End-User-facing privacy disclosures. The AI Agent Function framework is described in the AAIP and is not a matter the Agreement or this DPA governs.
14.3. SCCs Prevail on Transfer Matters. To the extent there is any conflict between the Standard Contractual Clauses and any other terms in this DPA, including Schedule 4, the provisions of the applicable Standard Contractual Clauses prevail with respect to the matters specifically addressed by the Standard Contractual Clauses.
14.4. Supersession. Any data processing agreement previously in effect between the Parties is superseded and replaced in its entirety by this DPA.
14.5. Status of this DPA. Where the Agreement provides for the update, incorporation, and conflict resolution of Pathify-maintained documents incorporated by reference, including any floor on material diminishment of Pathify’s commitments and any restriction on materially expanding Customer’s obligations without Customer’s written agreement, those provisions apply to this DPA to the same extent, as further reconciled by this Section 14. Where the Customer’s agreement with Pathify is an earlier form that contains no such provisions, this DPA is updated in accordance with its own terms.
15. General
15.1. Amendment; Waiver. Except as otherwise expressly stated in this DPA, this DPA may be modified only by a written agreement executed by an authorized representative of each Party. A waiver of any breach of this DPA is effective only if in writing, and no waiver operates as a waiver of any subsequent breach.
15.2. Severance. If any provision of this DPA is held unenforceable, that provision will be construed by modifying it to the minimum extent necessary to make it enforceable (if permitted by law) or by disregarding it (if modification is not permitted). The rest of this DPA remains in effect. If modifying or disregarding the unenforceable provision would result in the failure of an essential purpose of this DPA, the entire DPA will be considered null and void.
15.3. Notices. Unless otherwise expressly stated, the Parties will provide notices under this DPA in accordance with the notices provision of the Agreement. Notices under this DPA may be sent by email.
15.4. Governing Law; Jurisdiction. Unless prohibited by Data Protection Laws, this DPA is governed by the laws stipulated in the Agreement, and the Parties submit to the choice of jurisdiction and venue stipulated in the Agreement for disputes arising under this DPA.
15.5. Enforcement. Regardless of whether Customer, Customer’s Affiliates, or a third party is a Controller of Customer Personal Data, and unless otherwise required by Applicable Law: (a) only Customer has the right to enforce the terms of this DPA against Pathify; and (b) Pathify’s obligations under this DPA, including notification obligations, run only to Customer.
15.6 Liability. As between the Parties, each Party’s liability and remedies under this DPA are subject to the aggregate liability limitations and damages exclusions set forth in the Agreement. The disclaimers, exclusions, and limitations of liability applicable to Pathify under the Agreement apply for the benefit of Pathify, Pathify Holdings, Inc. and Ucroo Pty Ltd, each of which may enforce them.
15.7. Reservation of Rights. Notwithstanding anything in this DPA to the contrary: (a) Pathify may withhold information the disclosure of which would pose a security risk to Pathify, Pathify’s customers, or other third parties, or that is prohibited by Applicable Law or contractual obligation to a third party; and (b) Pathify’s notifications, responses, or provision of information or cooperation under this DPA are not an acknowledgement of fault or liability.
15.8. Variations in Data Protection Laws. If any variation to this DPA is required as a result of a change in, or newly applicable, Data Protection Law, either Party may provide written notice to the other Party of the change. The Parties will then discuss and negotiate in good faith any variations to this DPA necessary to address the change, with a view to agreeing and implementing those variations as soon as practicable, provided that the variations are reasonable in light of the functionality and performance of the Services and Pathify’s business operations.
15.9. Regulatory Requests. If Pathify is required by Applicable Law or legal process to disclose Customer Personal Data, Pathify, to the extent legally permitted, will give Customer prior notice of the disclosure to afford Customer a reasonable opportunity to appear, object, and obtain a protective order or other appropriate relief.
15.10. Counterparts. This DPA may be executed in counterparts, including by electronic signature, each of which is deemed an original and all of which together constitute one instrument.
SCHEDULE 1: DETAILS OF PROCESSING OF CUSTOMER PERSONAL DATA
This Schedule 1 sets out the details of Pathify’s Processing of Customer Personal Data required under Article 28(3) of the GDPR and equivalent provisions of other Data Protection Laws.
Subject matter of the Processing: The subject matter of the Processing is Pathify’s provision of the Services to Customer under the Agreement, including hosting and operation of the CXP, the AI Agent, and related features, and the Processing of Customer Personal Data as necessary to provide those Services.
Duration of the Processing: The Processing will continue for the term of the Agreement and for the return-or-deletion period described in Section 13.2 of this DPA.
Nature and purpose of the Processing: Pathify Processes Customer Personal Data to: (a) provision and operate the Services; (b) authenticate and authorize Users; (c) provide communications, notifications, content retrieval, and AI-assisted responses through the Services; (d) secure, monitor, and defend the Services against threats; (e) provide technical support and platform administration; (f) generate analytics and reports for Customer; and (g) perform other functions necessary to provide the Services as described in the Agreement and any Order Form.
Categories of Data Subjects: Customer determines the categories of Data Subjects in its sole discretion. Categories typically include: prospective students, current students, alumni, parents and authorized guardians, faculty, staff, and other individuals affiliated with Customer who are Users of the Services.
Categories of Personal Data: Customer determines the categories of Personal Data in its sole discretion. Categories typically include: identifiers (name, email address, student or institutional identifier); authentication and account information; profile information (role, program, affiliation); academic and enrollment information (which may constitute FERPA Records); communications and content authored or uploaded through the Services; usage and technical information (log data, device identifiers, IP addresses); and, to the extent Customer configures the Services to collect or process it, other categories of Customer Personal Data.
Sensitive categories of Personal Data: Customer determines whether Customer Content includes sensitive or special categories of Personal Data under Data Protection Laws. Pathify does not require Customer to submit sensitive categories and will Process any sensitive categories present in Customer Content in accordance with this DPA.
Frequency of the transfer: Continuous, for the duration of the Agreement.
Obligations and rights of the Controller: Customer’s obligations and rights are set out in this DPA and the Agreement.
Identity of Subprocessors: See Schedule 5 (Subprocessor List).
SCHEDULE 2: TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
Where applicable, this Schedule 2 serves as Annex II to the Standard Contractual Clauses. Capitalized terms used in this Schedule 2 have the meanings given in Section 1 of the DPA.
1. Information Security Program
1.1. Program. Pathify maintains a comprehensive written information security program, including policies, standards, procedures, and related documents that establish criteria, means, methods, and measures governing the Processing and security of Customer Personal Data and the Pathify systems or networks used to Process or secure Customer Personal Data in connection with providing the Services. Pathify maintains this program in alignment with applicable established industry standards and frameworks, including ISO/IEC 27001 and the National Institute of Standards and Technology (“NIST”) standards and guidance, and subjects the program to an annual SOC 2 audit against the AICPA SOC 2 criteria.
1.2. Confidentiality and Training. Pathify ensures that Pathify Personnel: (a) are bound by written or statutory confidentiality obligations with respect to Customer Personal Data substantially as protective as those set forth in the Agreement; and (b) are subject to appropriate training relating to the Processing of Customer Personal Data, the requirements of this DPA, and Pathify’s information security program.
2. Security Controls
In accordance with its information security program, Pathify implements appropriate physical, organizational, and technical controls designed to: (a) ensure the security, integrity, and confidentiality of Customer Personal Data Processed by Pathify; and (b) protect Customer Personal Data from known or reasonably anticipated threats or hazards, including Security Incidents. Without limiting the foregoing, Pathify uses the following controls as appropriate:
2.1. Firewalls. Pathify installs and maintains firewalls to protect data accessible via the Internet.
2.2. Updates. Pathify maintains programs and routines to keep Pathify’s information systems up to date with the latest upgrades, updates, bug fixes, new versions, and other modifications.
2.3. Anti-Malware. Pathify deploys and maintains anti-malware software to mitigate threats from viruses, spyware, and other malicious code.
2.4. Testing. Pathify regularly tests its security systems, processes, and controls to ensure they meet the requirements of these security measures.
2.5. Access Controls. Pathify secures Customer Personal Data Processed by Pathify’s information systems by:
2.5.1. assigning a unique identifier to each member of Pathify Personnel with access to Pathify’s information systems;
2.5.2. restricting access to Pathify’s information systems to Pathify Personnel and services that require access to perform a specified obligation permitted by the Agreement;
2.5.3. regularly reviewing (at least once every ninety (90) days) the list of Pathify Personnel and services with access to Pathify’s information systems and removing accounts that no longer require access;
2.5.4. prohibiting the use of manufacturer-supplied default passwords, requiring system-enforced strong passwords, and requiring that passwords and access credentials be kept confidential and not shared;
2.5.5. requiring that Pathify production passwords: (i) meet length and composition requirements consistent with current NIST-aligned authentication guidance, and in any event contain at least twelve (12) characters; (ii) not match previous passwords, the user’s login, or a common name; (iii) be changed whenever an account compromise is suspected or assumed; and (iv) be regularly replaced;
2.5.6. enforcing account lockout by disabling accounts Processing Customer Personal Data when an account exceeds a designated number of incorrect password attempts within a defined period;
2.5.7. maintaining log data for all use of accounts or credentials by Pathify Personnel for access to Pathify’s information systems and regularly reviewing access logs for signs of malicious behavior or unauthorized access.
2.6. Policies. Pathify maintains and enforces appropriate information security, confidentiality, and acceptable use policies for Pathify Personnel that meet the standards set forth in these security measures, including methods to detect and log policy violations.
2.7. Development. Development and testing environments are separate from Pathify’s production information systems.
2.8. Deletion. Consistent with the standards alignment described in Section 1.1 of this Schedule 2, Pathify uses procedures consistent with, at a minimum, NIST Special Publication 800-88 Revision 1 recommendations (or a successor standard widely used in the industry) to render Customer Personal Data unrecoverable prior to disposal of media.
2.9. Encryption. Pathify uses cryptographic standards with authorized algorithms, key length requirements, and key management processes consistent with or exceeding industry standards, including NIST recommendations. Pathify uses hardening and configuration requirements consistent with industry standards, including recommendations from the SANS Institute, NIST, or the Center for Internet Security (“CIS”). Pathify encrypts Customer Personal Data at rest within the Services and allows only encrypted connections to the Services for the transfer of Customer Personal Data.
2.10. Remote Access. Access from outside of Pathify’s protected corporate or production environments to Pathify’s information systems or to Pathify’s corporate or development workstation networks requires appropriate connection controls, including multi-factor authentication for all privileged and remote administrative access, and connection through a Virtual Private Network (“VPN”) or equivalent controlled channel.
3. Use of Third Parties
3.1. General. Third parties engaged by Pathify in accordance with the Agreement are required to maintain security measures that are no less protective than those set out in these security measures, consistent with Section 5.5 of this DPA.
3.2. Data Hosting. Pathify ensures that any third-party hosting provider (an “Infrastructure-as-a-Service” or “IaaS” provider) used by Pathify to Process Customer Personal Data meets the following requirements:
3.2.1. Base Requirements. IaaS providers must: (a) maintain adequate physical security and access controls consistent with Section 2.5 of this Schedule 2; (b) use professional heating, ventilation, and air conditioning (“HVAC”) and environmental controls; (c) use professional network and cabling environments; (d) use professional fire detection and suppression capabilities; and (e) maintain a comprehensive business continuity plan.
3.2.2. Annual Audit; Assessment. IaaS providers must conduct annual independent risk assessments and audits. Assessment and audit reports will be provided to Pathify and, where required by law, made available to Customer (with commercial and confidential information unrelated to security practices removed). Pathify conducts annual reviews and assessments of any critical IaaS provider to validate that the IaaS provider’s security measures meet the requirements of this Schedule 2.
3.2.3. Enhanced Requirements. IaaS providers must possess the requirements and capabilities of a highly-available, redundant (so-called “N+1”) data center, where multiple components each have at least one independent backup component so that system functionality continues at acceptable performance levels in the event of a system failure.
4. System Availability
Pathify maintains (and, for systems controlled by third parties, ensures that the relevant third parties maintain) a disaster recovery (“DR”) program designed to recover the availability of the Subscription Services following a disaster. The DR program includes, at a minimum: (a) routine validation of procedures to regularly and programmatically create retention copies of Customer Personal Data for the purpose of recovering lost or corrupted data; (b) inventories, updated at minimum annually, that list all critical Pathify information systems; (c) annual review and update of the DR program; and (d) annual testing of the DR program designed to validate the DR procedures and recoverability of the Services.
5. Security Incident Response
The Security Incident notification and response procedures are set out in Section 9 of the DPA.
6. Auditing and Reporting
6.1. Monitoring. Pathify monitors the effectiveness of its information security program on an ongoing basis by conducting audits, risk assessments, and other monitoring activities.
6.2. Audit Reports. The external audit framework applicable to Pathify’s information security program is set out in Section 10 of the DPA.
SCHEDULE 3: CROSS-BORDER TRANSFER MECHANISMS
1. Definitions
1.1. “Standard Contractual Clauses” means, as applicable to a given International Transfer:
1.1.1. the EEA Standard Contractual Clauses; and
1.1.2. the UK Standard Contractual Clauses.
1.2. “EEA Standard Contractual Clauses” or “Approved EU SCCs” means the Standard Contractual Clauses approved by the European Commission in decision 2021/914 of June 4, 2021.
1.3. “UK Standard Contractual Clauses”, which are the approved addendum rather than a separate set of clauses, means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner’s Office (“ICO”) and laid before Parliament in accordance with section 119A of the UK Data Protection Act 2018 on February 2, 2022, as amended or replaced from time to time (the “UK Addendum”).
2. EEA Standard Contractual Clauses
For data transfers from the EEA that are subject to the EEA Standard Contractual Clauses, the EEA Standard Contractual Clauses apply as follows:
2.1. Module One (Controller to Controller) applies where Pathify Processes Usage Data as a Controller. Usage Data has the meaning given in Section 1 of this DPA, and is used by Pathify to provide, support, secure, and defend the Services.
2.2. Module Two (Controller to Processor) applies where Customer is a Controller of Customer Personal Data and Pathify is a Processor of Customer Personal Data. 2.2.1. Module Three (Processor to Processor) applies to onward transfers of Customer Personal Data by Pathify, acting as Processor, to a Subprocessor established outside the EEA, including the Model Provider. Pathify will ensure that each such onward transfer is made under Module Three of the EEA Standard Contractual Clauses or under another transfer mechanism recognised under Chapter V of the GDPR, and will identify the applicable mechanism to Customer on request.
2.3. For each module, where applicable:
2.3.1. In Clause 7, the optional docking clause does not apply.
2.3.2. In Clause 9, Option 2 applies, and the process for providing notice and the time period for objections to Subprocessor changes is as set forth in Section 5 of this DPA.
2.3.3. In Clause 11, the optional language does not apply.
2.3.4. In Clause 17, the EEA Standard Contractual Clauses are governed by the laws of Ireland.
2.3.5. In Clause 18(b), disputes will be resolved before the courts of Ireland.
2.3.6. Annex I, Part A.
Data Exporter: Customer and authorized Affiliates of Customer.
Data Exporter Contact Details: Customer’s account owner email address, or the email address or addresses for which Customer has elected to receive privacy communications.
Data Exporter Role: As set forth in Section 2 of the DPA.
Signature and Date: By entering into the DPA, the Data Exporter is deemed to have signed these Standard Contractual Clauses, including their annexes, as of the Effective Date of the Agreement.
Data Importer: Path Education Inc., a Delaware corporation d/b/a Pathify.
Data Importer Contact Details: [email protected], or the email address published for privacy communications on Pathify’s website from time to time.
Data Importer Role: As set forth in Section 2 of the DPA.
Signature and Date: By entering into the DPA, the Data Importer is deemed to have signed these Standard Contractual Clauses, including their annexes, as of the Effective Date of the Agreement.
2.3.7. Annex I, Part B.
Categories of Data Subjects: As described in Schedule 1.
Categories of Personal Data: As described in Schedule 1.
Sensitive Data: As described in Schedule 1.
Frequency of the Transfer: Continuous, for the duration of the Agreement.
Nature of the Processing: As described in Schedule 1.
Purpose of the Processing: As described in Schedule 1.
Period of the Processing: As described in Section 13 of the DPA.
2.3.8. Annex I, Part C. In accordance with Clause 13, the competent supervisory authority is identified as follows:
Where the data exporter is established in an European Union (“EU”) Member State: the supervisory authority with responsibility for ensuring compliance by the data exporter with Regulation (EU) 2016/679 will act as competent supervisory authority.
Where the data exporter is not established in an EU Member State but falls within the territorial scope of Regulation (EU) 2016/679 under Article 3(2) and has appointed a representative under Article 27(1): the supervisory authority of the Member State in which the representative is established will act as competent supervisory authority.
Where the data exporter is not established in an EU Member State, falls within the territorial scope of Regulation (EU) 2016/679 under Article 3(2), and is not required to appoint a representative under Article 27(2): the competent supervisory authority is the supervisory authority of a Member State in which the data subjects whose Personal Data is transferred are located, in accordance with Clause 13 of the EEA Standard Contractual Clauses.
Where the data exporter is established in the United Kingdom or falls within the territorial scope of UK Data Protection Laws: the Information Commissioner’s Office will act as competent supervisory authority.
Where the data exporter is established in Switzerland or falls within the territorial scope of Swiss Data Protection Laws, the EEA Standard Contractual Clauses apply with the following adaptations, and references in this Part C to the competent supervisory authority are to the Swiss Federal Data Protection and Information Commissioner insofar as the relevant data transfer is governed by Swiss Data Protection Laws: references to the GDPR are to the Swiss Federal Act on Data Protection; references to EU or Member State law are to Swiss law; the term “member state” does not exclude data subjects in Switzerland from enforcing their rights in Switzerland; and adequacy is determined by the Swiss Federal Council.
2.3.9. Annex II. Schedule 2 of this DPA serves as Annex II to the Standard Contractual Clauses.
2.3.10. Annex III. Schedule 5 of this DPA serves as Annex III (list of Subprocessors) to the Standard Contractual Clauses.
3. UK Standard Contractual Clauses
For data transfers from the United Kingdom that are subject to the UK Standard Contractual Clauses, the UK Standard Contractual Clauses apply as follows:
3.1. The EEA Standard Contractual Clauses, incorporated by reference into this DPA, also apply to UK data transfers, subject to this Schedule 3.
3.2. The UK Addendum is deemed executed between the Parties, and the EEA Standard Contractual Clauses are deemed amended as specified in the UK Addendum in relation to UK data transfers. For the purposes of Part 1 of the UK Addendum, Table 1 is completed by the parties and their details set out in Annex I of Schedule 3; Table 2 selects Module Two and, for onward transfers, Module Three of the EEA Standard Contractual Clauses; Table 3 is completed by Annexes I and II of Schedule 3; and for Table 4, neither Party may end the UK Addendum as set out in Section 19 of the UK Addendum. Part 2 of the UK Addendum applies, and the Alternative Part 2 Mandatory Clauses set out in the UK Addendum are incorporated by reference.
SCHEDULE 4: JURISDICTION-SPECIFIC TERMS
1. United States General
1.1. Scope of Data Protection Laws. The definition of “Data Protection Laws” includes any federal or state privacy or data protection law of the United States applicable to Pathify’s Processing of Customer Personal Data.
1.2. Key Defined Terms. The terms “business,” “commercial purpose,” “service provider,” “sell,” “share,” and “personal information” have the meanings given in the applicable United States Data Protection Law in the context of Customer Personal Data Processed under this DPA.
1.3. Service Provider Status. Pathify is a service provider or processor (as applicable) under United States Data Protection Laws with respect to Customer Personal Data.
1.4. Service Provider Restrictions. Pathify will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the specific purpose of providing the Services under the Agreement, including for a commercial purpose other than providing the Services, such as providing services to a different customer; (c) retain, use, or disclose Customer Personal Data outside of the direct business relationship between Pathify and Customer; or (d) combine Customer Personal Data with Personal Data that Pathify receives from another entity or collects from individuals, except as permitted by Applicable Law or as authorized by Customer.
1.5. No Consideration. Notwithstanding anything in the Agreement or any order form entered under the Agreement, the Parties acknowledge that Pathify’s access to Customer Personal Data does not constitute part of the consideration exchanged by the Parties under the Agreement.
1.6. Pathify as Business for Usage Data. To the extent Usage Data is considered personal information, Pathify is the business (or equivalent term under other United States Data Protection Laws) with respect to that Usage Data and will Process it in accordance with the Pathify Website Privacy Policy. Usage Data has the meaning given in Section 1 of this DPA, and is used by Pathify to provide, support, secure, and defend the Services. Customer Personal Data that identifies an individual End User is not Usage Data and remains subject to this DPA in full.
1.7. Remediation. Customer has the right to take reasonable and appropriate steps to: (a) verify that Pathify Processes Customer Personal Data in a manner consistent with this DPA, which may include performing a Customer Audit in accordance with this DPA; (b) stop and remediate Pathify’s unauthorized use of Customer Personal Data; and (c) take other remediation efforts reasonably agreed between the Parties.
1.8. Certification. Pathify certifies that it understands and will comply with the restrictions on its Processing of Customer Personal Data set forth in this DPA and the Agreement.
2. Colorado
2.1. Scope of Data Protection Laws. The definition of “Data Protection Laws” includes the CPA.
2.2. CPA Processor Obligations. Pathify is a processor under the CPA with respect to Customer Personal Data. Where Customer Personal Data relates to a minor, Pathify will also provide the assistance required of a processor under C.R.S. 6-1-1305.5, including assistance with Customer’s duties in relation to minors and with any related data protection assessment. Pathify will:
2.2.1. Process Customer Personal Data on behalf of Customer and in accordance with Customer’s documented instructions, consistent with Section 3 of this DPA;
2.2.2. assist Customer, taking into account the nature of the Processing and the information reasonably available to Pathify, in meeting Customer’s obligations under the CPA with respect to security of Processing, notification of Security Incidents, data protection assessments, and responses to consumer rights requests;
2.2.3. engage Subprocessors only in accordance with Section 5 of this DPA, including requiring that each Subprocessor be bound by data protection terms consistent with the CPA; and
2.2.4. on termination of the Agreement, return or delete Customer Personal Data in accordance with Section 13 of this DPA.
2.3. SB 26-189 Coordination. The SB 26-189-specific allocation of responsibilities between the Parties is addressed in the Agreement and the AAIP and is referenced in Section 7.6 of this DPA.
3. EEA
3.1. Scope. The definition of “Data Protection Laws” includes the GDPR.
3.2. Subprocessor Protection Standards. When Pathify engages a Subprocessor, Pathify will:
3.2.1. require the Subprocessor to protect Customer Personal Data to the standard required by Data Protection Laws, including the data protection obligations referred to in Article 28(3) of the GDPR, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in a manner that ensures Processing meets the requirements of the GDPR; and
3.2.2. require the Subprocessor to agree in writing to Process data only in a country that the European Commission has declared to have an adequate level of protection, or subject to the Standard Contractual Clauses or another transfer mechanism recognised under Chapter V of the GDPR.
3.3. GDPR Penalties. Notwithstanding anything in this DPA or the Agreement to the contrary (including either Party’s indemnification obligations), neither Party is responsible for any GDPR fines issued or levied under Article 83 of the GDPR against the other Party by a regulatory authority or governmental body in connection with such other Party’s violation of the GDPR.
4. Switzerland
4.1. Scope. The definition of “Data Protection Laws” includes the Swiss Federal Act on Data Protection.
4.2. Subprocessor Protection Standards. When Pathify engages a Subprocessor, Pathify will:
4.2.1. require the Subprocessor to protect Customer Personal Data to the standard required by Data Protection Laws, including obligations at least as protective as those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in a manner that ensures Processing meets the requirements of the Swiss Federal Act on Data Protection; and
4.2.2. require the Subprocessor to agree in writing to Process data only in a country that the Swiss Federal Council has determined to provide an adequate level of protection, or subject to appropriate safeguards recognised under the Swiss Federal Act on Data Protection.
4.3. Swiss Proceedings. To the extent allowed and required by the Swiss Federal Act on Data Protection, a Data Subject may bring legal proceedings against the data exporter or data importer before the courts of Switzerland.
4.4. Legal Entities.
5. United Kingdom
5.1. Scope. References in this DPA to the GDPR will, to that extent, be deemed references to the corresponding laws of the United Kingdom, including the UK GDPR, the UK Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025, including the automated decision-making provisions at Articles 22A to 22D of the UK GDPR, which replaced Article 22 for general processing), and any code of practice on AI and automated decision-making issued under the UK Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026.
5.2. Subprocessor Protection Standards. When Pathify engages a Subprocessor, Pathify will:
5.2.1. require the Subprocessor to protect Customer Personal Data to the standard required by Data Protection Laws, including the data protection obligations referred to in Article 28(3) of the UK GDPR, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in a manner that ensures Processing meets the requirements of the UK GDPR; and
5.2.2. require the Subprocessor to agree in writing to Process data only in a country that the United Kingdom recognizes as providing an adequate level of protection, or to Process data only on terms equivalent to the UK Standard Contractual Clauses.
6. Australia
6.1. Scope and Definitions. For purposes of Pathify’s Processing of Customer Personal Data where Customer is subject to Australian privacy law, whether the Privacy Act 1988 (Cth) or a State or Territory privacy law applicable to Customer: (a) the definition of “Data Protection Laws” includes the Privacy Act 1988 (Cth) (the “Privacy Act”), including the Australian Privacy Principles (the “APPs”) in the Privacy Act and the Notifiable Data Breaches scheme (the “NDB Scheme”) in Part IIIC of the Privacy Act, and, where Customer is a public university or other entity governed by a State or Territory privacy law rather than the Privacy Act, that law and its information privacy principles; (b) the term “Personal Data” includes “Personal Information” as defined in the Privacy Act; and (c) the term “Supervisory Authority” includes the Office of the Australian Information Commissioner (the “OAIC”).
6.2. Purpose and Customer Notifications. Pathify will handle Personal Information only for the purposes of performing the Services, as directed by Customer, or as required by law. Customer is responsible for ensuring it has provided any notifications and obtained any consents required by the Privacy Act for Pathify to handle Personal Information as the Customer’s processor or service provider.
6.3. Security of Personal Information. Pathify will take reasonable steps to protect Personal Information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure, consistent with APP 11 and the security measures set out in this DPA.
6.4. Access and Correction. Taking into account the nature of the Services, Pathify will provide reasonable assistance (at the Customer’s cost where outside the normal course) to enable Customer to respond to requests by individuals to access or correct their Personal Information.
6.5. Notifiable Data Breaches Scheme. Pathify will notify Customer without undue delay and as soon as practicable after becoming aware of an actual or suspected data breach that may be an Eligible Data Breach under the NDB Scheme involving Personal Information handled for the Customer.
6.6. Overseas Disclosures and Subprocessors. Customer acknowledges that Personal Information may be disclosed to Subprocessors located outside Australia. Pathify will take reasonable steps to ensure that such Subprocessors are subject to contractual obligations that together provide a substantially similar level of protection to the APPs, and Pathify remains liable for the acts and omissions of its Subprocessors as set out in this DPA.
6.7. Return and Deletion. Pathify will, at the Customer’s election and subject to applicable law, return or destroy Personal Information in accordance with this DPA and will take reasonable steps to de-identify or destroy any remaining copies that Pathify is not legally required to retain.
7. New Zealand
7.1. Scope and Definitions. For purposes of Pathify’s Processing of Customer Personal Data originating from New Zealand: (a) the definition of “Data Protection Laws” includes the Privacy Act 2020 (NZ) (the “NZ Privacy Act”), including the Information Privacy Principles (the “IPPs”) set out in the NZ Privacy Act and any code of practice issued by the New Zealand Privacy Commissioner that applies to the Processing; (b) the term “Personal Data” includes “personal information” as defined in the NZ Privacy Act; and (c) the term “Supervisory Authority” includes the New Zealand Office of the Privacy Commissioner (the “OPC”).
7.2. Purpose and Customer Notifications. Pathify will handle personal information only for the purposes of performing the Services, as directed by Customer, or as required by law. Customer is responsible for ensuring it has provided the notifications and obtained any authorisations required by the NZ Privacy Act for Pathify to handle personal information as the Customer’s service provider.
7.3. Security of Personal Information. Pathify will take reasonable security safeguards to protect personal information against loss, unauthorised access, use, modification, disclosure or other misuse, consistent with IPP 5 and the security measures set out in this DPA.
7.4. Access and Correction. Taking into account the nature of the Services, Pathify will provide reasonable assistance (at the Customer’s cost where outside the normal course) to enable Customer to respond to requests by individuals to access or correct their personal information consistent with IPPs 6 and 7.
7.5. Notifiable Privacy Breaches. Pathify will notify Customer without undue delay and as soon as practicable after becoming aware of any privacy breach involving personal information handled for the Customer, whether or not Pathify has determined that it is likely to cause serious harm within the meaning of the NZ Privacy Act, to enable Customer to comply with its notification obligations to the OPC and affected individuals.
7.6. Cross-Border Disclosures and Subprocessors. Customer acknowledges that personal information may be disclosed to Subprocessors located outside New Zealand. Where a Subprocessor holds personal information solely as Pathify’s agent for storage or processing on Customer’s behalf, that engagement is not an overseas disclosure for the purposes of IPP 12. Where a Subprocessor uses or discloses personal information for its own purposes, Pathify will take reasonable steps to ensure that the Subprocessor is subject to contractual obligations that satisfy IPP 12, and Pathify remains liable for the acts and omissions of its Subprocessors as set out in this DPA.
7.7. Return and Deletion. Pathify will, at the Customer’s election and subject to applicable law, return or destroy personal information in accordance with this DPA and will take reasonable steps to de-identify or destroy any remaining copies that Pathify is not legally required to retain.
SCHEDULE 5: SUBPROCESSOR LIST
This Schedule 5 sets forth the Subprocessors that Process Customer Personal Data as of the Last Updated date of this DPA. Pathify will update this Schedule 5 as Subprocessors are added or replaced, in accordance with Section 5 of this DPA. The current version of this DPA published by Pathify is the authoritative source.
As of the Last Updated date of this DPA, the Subprocessors that Process Customer Personal Data include:
Subprocessor
Purpose
Processing Location
Google LLC
Provision of the Google Gemini generative AI service underlying the AI Agent
Endpoints selected by Google, which may be located in any region in which Google operates and are predominantly located in the United States
Google Cloud (Google Cloud Platform IaaS)
Hosting and infrastructure for the CXP and the Services
The region corresponding to Customer’s data sovereignty requirements, being Australia for Australian customers, the European Union for European customers, and the United States for United States customers
Twilio SendGrid (Twilio Inc.)
Transactional email and in-platform notifications
United States and other locations within Twilio’s global infrastructure. Twilio offers regional data residency for the European Union only; no Australian residency option is offered
Google Cloud (BigQuery and related analytics services)
Aggregated analytics of anonymized user actions, producing administrator-level views, subject to the restrictions in Section 7 of this DPA
United States
Sentry
Non-personalized HTTP logs for diagnostic purposes
United States
Canny
Customer support case management
United States
Subprocessor: Google LLC
Purpose: Provision of the Google Gemini generative AI service underlying the AI Agent
Processing Location: Endpoints selected by Google, which may be located in any region in which Google operates and are predominantly located in the United States
Subprocessor: Google Cloud (Google Cloud Platform IaaS)
Purpose: Hosting and infrastructure for the CXP and the Services
Processing Location: The region corresponding to Customer’s data sovereignty requirements, being Australia for Australian customers, the European Union for European customers, and the United States for United States customers
Subprocessor: Twilio SendGrid (Twilio Inc.)
Purpose: Transactional email and in-platform notifications
Processing Location: United States and other locations within Twilio’s global infrastructure. Twilio offers regional data residency for the European Union only; no Australian residency option is offered
Subprocessor: Google Cloud (BigQuery and related analytics services)
Purpose: Aggregated analytics of anonymized user actions, producing administrator-level views, subject to the restrictions in Section 7 of this DPA
Processing Location: United States
Subprocessor: Sentry
Purpose: Non-personalized HTTP logs for diagnostic purposes
Processing Location: United States
Subprocessor: Canny
Purpose: Customer support case management
Processing Location: United States
Each Subprocessor listed above is engaged under a written agreement that imposes data protection obligations materially as protective as those in this DPA. Where a Subprocessor Processes Customer Personal Data outside the Customer’s region, an appropriate transfer mechanism (such as the Standard Contractual Clauses or the UK Addendum) applies.
Pathify maintains the current Subprocessor list in Schedule 5, stating for each Subprocessor its name, purpose, and location of Processing.