Snapshot 25510
Normalized text
Scripts and page chrome removed; this is what change detection compares.
SKYDIVE DATA PROCESSING ADDENDUM
Last Updated: July 29, 2026
This Data Processing Addendum (this "DPA") is between Create, Inc. ("Create") and the customer identified in an executed Order Form that expressly incorporates this DPA ("Customer"). This DPA is incorporated into that Order Form and the agreement it forms, and is effective for that Customer on the Order Effective Date (as defined in the Order Form) or, if this DPA is first incorporated by a later signed amendment, on the effective date of that amendment (the "Effective Date"). "Agreement" means that executed Order Form together with the agreement governing the Services under it (the separate written master agreement between the Parties, if one is in effect, and otherwise the Skydive Terms of Service (the "Terms")) and the other documents the Order Form incorporates. The "Last Updated" date shown above identifies the posted version of this DPA and is not the customer-specific Effective Date; Create maintains an archive of prior versions at skydive.com/dpa. Create and Customer may be referred to herein collectively as the "Parties" or individually as a "Party."
Customer enters into this DPA on behalf of itself and each Affiliate authorized to use the Services under the applicable Order Form, to the extent Create Processes Customer Personal Data in performance of the Services for such Affiliates. Customer remains responsible for its Affiliates' compliance with this DPA, and all claims by Customer and its Affiliates under this DPA are subject in the aggregate to the limitations of liability in the Agreement as described in Section 12.1. For the purposes of this DPA only, and except where indicated otherwise in this DPA, the term "Customer" will include Customer and such Affiliates.
How This DPA Applies
This DPA is binding on the Parties only to the extent applicable Data Protection Laws govern the Processing of Customer Personal Data in performance of the Services under the executed Order Form, and this DPA applies only to that Processing. This DPA continues in effect as described in Section 14.5. This DPA replaces any prior data processing terms between the Parties for the covered Services unless otherwise expressly stated in this DPA; the Parties may preserve a previously executed data processing agreement, security addendum, or business associate agreement by identifying it in the Order Form. If the documents conflict with respect to the Processing of Customer Personal Data, they control in this order: (i) the mandatory terms of the applicable SCCs, the UK Addendum, and the Swiss adaptations described in Annex 2, for the Restricted Transfers they govern; (ii) any Order Form term that expressly identifies and overrides a provision of this DPA, including any express authorization of a specific training use, except that no Order Form or other term may reduce the commitments in clauses (a) through (d) of Section 2.10, the routing restriction in Section 2.10, or Section 2.11; (iii) this DPA, for data-protection matters; (iv) the remaining terms of the Order Form; (v) any product- or service-specific terms; (vi) the Terms; and (vii) the Policies.
Data Processing Terms
The Parties agree that the terms of this DPA govern the Processing of Customer Personal Data in performance of the Services. Each Party, acting reasonably and in good faith, will comply with the terms of this DPA. Create is an independent Data Controller only of Account Data and Usage Data as described in Section 13, which Create Processes in accordance with Section 13 and its then-current Privacy Policy located at skydive.com/privacy (or any successor hyperlink). Customer Personal Data does not become Account Data or Usage Data merely because it is used for support or security or appears within a trace or log.
1. Definitions and Interpretation
Capitalized terms used in this DPA shall have the meanings set forth in this Section 1 and elsewhere in this DPA. All other capitalized terms not defined in this DPA will have the meanings set forth in the Agreement. If a term defined in this DPA is also defined in the Agreement, the definition in this DPA controls with respect to the Processing of Customer Personal Data. For purposes of this DPA: (i) the words "include," "includes," and "including" are deemed to be followed by the words "without limitation;" (ii) the word "or" is not exclusive; (iii) words denoting the singular have a comparable meaning when used in the plural, and vice-versa; and (iv) words denoting any gender include all genders.
"Account Data" means Personal Data that Create collects in its direct business relationship with Customer for account administration, billing, support, security, fraud and abuse prevention, and legal compliance, including Personal Data of Customer's business representatives. Account Data excludes Customer Content.
"Affiliate" of a Party means any other entity that directly or indirectly, through one or more intermediaries, controls, is controlled by, or is under common control with, such Party. The term "control" (including the terms "controlled by" and "under common control with") means the direct or indirect power to direct or cause the direction of the management and policies of an entity, whether through the ownership of voting securities, by contract, or otherwise.
"Anonymous Data" means information that no longer relates to an identified or identifiable natural person under applicable Data Protection Laws, taking account of all the means reasonably likely to be used by Create or any other person to identify the natural person, directly or indirectly.
"Authorized User" means an individual whom Customer authorizes to access and use the Services under Customer's account or Workspace, including an administrator, employee, contractor, or other named user. An Agent is not an Authorized User, and an End User is not an Authorized User unless separately given an account.
"Customer Personal Data" means Personal Data within Customer Content or otherwise Processed by Create (or any Subprocessor) as a Data Processor on behalf of and at the direction of Customer in performance of the Services. Customer Personal Data excludes Account Data and Usage Data only to the extent Section 13 applies to them.
"Data Controller" (or equivalent term under applicable Data Protection Laws) means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
"Data Processor" (or equivalent term under applicable Data Protection Laws) means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Data Controller.
"Data Protection Laws" means any applicable laws or regulations governing the Processing of Customer Personal Data in performance of the Services, including, but not limited to, to the extent applicable, the European General Data Protection Regulation (Regulation (EU) 2016/679) (the "GDPR"), the GDPR as it forms part of the UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (as amended, including by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019) (the "UK GDPR"), the Swiss Federal Act on Data Protection in its revised version of 25 September 2020 ("FADP"), and the US State Privacy Laws.
"Data Subject" means an identified or identifiable natural person to whom Customer Personal Data relates. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
"EEA" means the European Economic Area.
"Personal Data" means any information relating to a Data Subject that is subject to protection under applicable Data Protection Laws.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data Processed by Create or any Subprocessor. For clarity, Personal Data Breach does not include unsuccessful attempts or activities that do not compromise the confidentiality, integrity, or availability of Customer Personal Data (such as unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems).
"Processing" means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, retention, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
"Restricted Transfer" means: (a) a transfer or disclosure of Customer Personal Data from Customer to Create; or (b) an onward transfer or disclosure of Customer Personal Data from Create to a Subprocessor; in each case, where such transfer or disclosure would be prohibited by applicable Data Protection Laws in the absence of appropriate safeguards, including the SCCs.
"Services" means the services provided by Create to Customer (or Customer's Affiliates, as the case may be) under the Agreement.
"Usage Data" means telemetry, logs, metering, diagnostic, and performance data generated through operation of the Services, including Agent execution traces, task trajectories, and tool-invocation records, plus aggregated or de-identified data derived from the Services. Usage Data is limited to this operational and structural data and does not include Customer Content, including the contents of requests, responses, files, communications, or Outputs carried within a trace.
"Special Data Categories" means Personal Data subject to specific heightened processing and/or security protections under applicable Data Protection Laws, including, but not limited to, protected health information subject to the Health Insurance Portability and Accountability Act ("HIPAA").
"SCCs" means the Commission Implementing Decision (EU) 2021/914 establishing Standard Contractual Clauses for data transfers to third countries (as amended, modified, or replaced from time to time). The applicable module within the SCCs is MODULE TWO (Transfer Controller to Processor) where Customer acts as a Data Controller, and MODULE THREE (Transfer Processor to Processor) where Customer acts as a Data Processor on behalf of another Data Controller. MODULE ONE (Transfer Controller to Controller) and MODULE FOUR (Transfer Processor to Controller) do not apply under this DPA; any transfer requiring Module One or Module Four must be governed by a separately executed or incorporated transfer addendum that selects and fully populates that module and accurately states the Parties' roles.
"Subprocessor" means a Data Processor engaged by Create for the purpose of Processing Customer Personal Data in performance of the Services.
"Supervisory Authority" means the relevant governmental body or bodies having jurisdiction over the Processing of Customer Personal Data under this DPA.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0) issued by the UK Information Commissioner's Office (ICO) and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of the Mandatory Clauses included in Part 2 thereof.
"US State Privacy Laws" means, collectively, the comprehensive state-specific data privacy laws and their regulations in effect during the term of the Agreement and applicable to Create's Processing of Personal Data under the Agreement.
2. Processing of Customer Personal Data
2.1 Roles of the Parties
To the extent Create Processes Customer Personal Data in performance of the Services, the Parties agree that: (a) where Customer determines the purposes and means of the Processing, Customer is the Data Controller and Create is the Data Processor; (b) where Customer Processes Customer Personal Data as a Data Processor on behalf of another Data Controller, Customer is the Data Processor and Create is a subprocessor of Customer, and Customer represents that it is authorized to appoint Create and to issue the instructions in this DPA; and (c) Create is a Data Controller only of Account Data and Usage Data as described in Section 13.
2.2 Create as Data Processor
Create, when acting as a Data Processor, will Process Customer Personal Data only on the documented instructions of Customer as provided in Section 2.5 and Section 2.6 of this DPA, including with regard to Restricted Transfers. Create will not Process Customer Personal Data for any other purpose, except to the extent Processing of Customer Personal Data is required by applicable laws to which Create is subject; in such a case, Create will inform Customer of that legal requirement before Processing, unless that law prohibits such notice on important grounds of public interest.
2.3 US State Privacy Law-Specific Terms
If Create is Processing Customer Personal Data as a Data Processor, service provider, or contractor within the scope of the US State Privacy Laws in performance of the Services, such Processing shall be subject to Annex 3 (US State Privacy Laws Annex) to this DPA.
2.4 Customer as Data Controller
Customer, as Data Controller, agrees that Customer:
a) is solely responsible for the accuracy, quality, and legality of Customer Personal Data, including the means by which Customer acquires Customer Personal Data;
b) is solely responsible for any registration, notice, or other authorization under applicable laws to engage Create to perform the Services;
c) has the authority to transmit or disclose Customer Personal Data to Create (or permit Create to access Customer Personal Data); and
d) will provide Create with lawful instructions with respect to the Processing of Customer Personal Data.
Customer acknowledges that it has assessed the Security Measures described in Section 4 and Attachment 2 to Annex 2, and has determined that they are appropriate for the nature of the Customer Personal Data that Customer submits to the Services. This acknowledgment does not limit Create's obligations under this DPA. Nothing in this Section 2.4 relieves Create of responsibility for its own compliance with this DPA and applicable Data Protection Laws, for its Subprocessors, or for its independent Processing under Section 13. Customer is also responsible for providing any notices and obtaining any consents required for End Users of Customer-deployed Agents and for Customer's use of Connected Accounts and Channels.
2.5 Customer's Instructions
Customer instructs Create (and authorizes Create to instruct each Subprocessor) to Process Customer Personal Data in performance of the Services, including any necessary Restricted Transfers. The Parties agree that the scope of Customer's instructions for the Processing of Customer Personal Data is defined by: (i) the Agreement; (ii) the executed Order Form and any other applicable ordering documents; (iii) this DPA, including Sections 2.10 and 2.11; (iv) Customer's configuration of the Services, including Workspace and organization settings, in-product controls, and requests made through supported features of the Services; (v) Customer's other written directions consistent with the Agreement; and (vi) any Modified Instructions (as defined in Section 2.6). Where Customer directs the Services to transmit Customer Personal Data to a Third-Party Service with which Customer directly contracts and for which Customer supplies the connection or keys (including a Connected Account or a provider Customer selects outside the managed set using Customer-provided keys), that transmission is a documented instruction; such a Third-Party Service is not a Subprocessor, its handling of data after receipt is governed by Customer's agreement with that service, and Create remains responsible under this DPA for the transmission itself, including the routing restrictions in Sections 2.10 and 2.11. Model and routing providers in Create's managed set that Process Customer Personal Data are Subprocessors under Section 5 regardless of Customer's model selection, including any Workspace-level selection among managed model sets. A Workspace's selection of a managed model set does not make a managed-set provider a Third-Party Service selected by Customer. For purposes of this DPA, Create's "managed set" comprises the model providers Create contracts with directly and the Routing Subprocessors through which Create routes requests; a downstream inference provider that serves a request routed through a Routing Subprocessor is not part of the managed set and is addressed in Section 5.2.
2.6 Modified Instructions
Customer may request amendments to Customer's instructions where such amendments are required for Customer to comply with applicable Data Protection Laws ("Modified Instructions") by submitting a written request to Create. The Parties will cooperate in good faith to agree on a feasible implementation of the Modified Instructions and any reasonable, pre-approved fees for extraordinary work as described in Section 14.1. If Create cannot lawfully or reasonably implement a Modified Instruction, Create will explain the basis for that position and work with Customer to identify a reasonable alternative. This Section 2.6 states Customer's sole and exclusive remedy, and Create's sole liability, with regard to Modified Instructions.
2.7 Duty to Inform
Create will inform Customer immediately, and in any event before carrying out the affected instruction, if in Create's opinion an instruction from Customer infringes the GDPR or other Union or Member State data protection provisions. For other applicable Data Protection Laws, Create will notify Customer promptly to the extent that law imposes a corresponding duty. Create may suspend the affected Processing until the Parties resolve the issue.
2.8 Details of the Processing of Customer Personal Data
The details of the Processing of Customer Personal Data are set forth in Annex 1 (Data Processing Details) to this DPA.
2.9 Processing of Special Data Categories
Customer will not direct the Services to Process Special Data Categories as a systematic part of its use case unless an Order Form or a separate written agreement between the Parties expressly authorizes that category and sets out any required additional safeguards (including a business associate agreement where required by HIPAA). Incidental Processing of Special Data Categories contained within Customer Content does not breach this Section 2.9 and receives the safeguards described in Section 4 and Attachment 2 to Annex 2. Secrets and authentication credentials required for ordinary operation of the Services are permitted and are protected by the measures described in Section 4 and Attachment 2 to Annex 2; their Processing does not by itself constitute authorization of any other Special Data Categories.
2.10 Model Training
Create will not use Customer Content, Customer Personal Data, or Anonymous Data derived from either to train, fine-tune, reinforce, or evaluate any model. This no-training default applies regardless of any training setting, default, or disclosure in the Terms or Create's Privacy Policy, and no Workspace or organization setting turns training on for Customer. Create may perform a specific training use only if an Order Form or later signed amendment between the Parties expressly describes and authorizes that use. Any authorized use remains subject to clauses (a) through (d) of this Section 2.10 and Section 2.11. This Section 2.10 applies prospectively from the Effective Date.
Create may create and use Anonymous Data for security, fraud and abuse prevention, metering and billing, reliability, analytics, capacity planning, and improving the Services, provided those uses do not include training, fine-tuning, reinforcing, or evaluating any model and Create does not attempt to re-identify the data.
If Create determines the purposes or essential means of any Processing of data that remains Personal Data, Create is an independent Data Controller for that Processing and must separately establish and disclose its lawful basis; this DPA does not authorize that Processing on a processor basis. Create will never use any of the following to train, fine-tune, reinforce, or evaluate a model: (a) data accessed through the Google or Slack APIs, and any data to the extent derived from it; (b) data accessed through any other Connected Account to the extent the applicable Third-Party Service's terms prohibit that use; (c) End User data; and (d) Secrets. Create also will not use Personal Data about other individuals that Create Processes on Customer's behalf to train models or for advertising. Whatever model or keys Customer selects, Create will never route the data described in clauses (a) through (d) of this Section 2.10 to any provider on terms that permit training.
2.11 Google and Slack Limited Use
Customer's instructions under this DPA incorporate the following limits. Google user data is used only to provide and improve user-facing features of the Services that Customer or its users request, is not used for advertising, is not used to train generalized AI or machine-learning models, and is transferred to third parties only as necessary to provide those features, for security, or to comply with law. Create's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Whenever an Agent's task involves Google user data, Create routes model requests only to providers operating in zero-data-retention configurations, under which the provider does not retain the content of the request or response after the request is served, apart from transient processing required to serve it. Slack data is used only to provide the features Customer or its users request. Relevant Slack message content may be transmitted to model providers for inference only where those providers are contractually prohibited from using it to train their models, including, for a request routed through a Routing Subprocessor (as defined in Section 5.2), where the terms applicable to that route contractually prohibit that use. Create does not route Slack data to a provider on terms that permit training and does not use Slack data to train its own models. No provision of this DPA, no Order Form or other agreement term, no model or key selection, and no routing disclosure overrides this Section 2.11.
3. Confidentiality Obligations of Create Personnel
3.1 Confidentiality Obligations of Create Personnel
Create will limit access to Customer Personal Data to personnel who need access in order to perform the Services, and will ensure that persons authorized to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4. Information Security Program
4.1 Information Security Program
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Create will in relation to Customer Personal Data implement and maintain a written information security program that includes administrative, technical, and organizational measures designed to protect such Customer Personal Data against unauthorized access, use, disclosure, alteration, or destruction and to ensure the confidentiality, integrity, availability, and resilience of the systems Processing Customer Personal Data, including the measures set forth in Article 32(1) of the GDPR (and corresponding provisions of the UK GDPR) to the extent such measures are applicable to Create's Processing of Customer Personal Data in performance of the Services ("Information Security Program"). The Information Security Program includes the technical and organizational measures set forth in Attachment 2 to Annex 2 (the "Security Measures"). Create monitors and periodically tests the effectiveness of the Security Measures. Create may update the Information Security Program from time to time, provided the updated measures do not materially decrease the overall protection of Customer Personal Data.
4.2 Security Monitoring and Response
Create will monitor compliance with its Information Security Program and will maintain procedures reasonably designed to detect, respond to, mitigate the effects of, remediate, and recover from Personal Data Breaches.
5. Subprocessing
5.1 Use of Subprocessors; Liability
Customer generally authorizes Create to use Subprocessors, including Create Affiliates, for the purpose of providing the Services. Create will enter into a written agreement with each Subprocessor imposing data protection obligations that satisfy applicable Data Protection Laws (including Article 28 of the GDPR, where applicable) and that are not less protective than those set forth in this DPA with respect to the Processing of Customer Personal Data, appropriate to the services the Subprocessor provides. Create will remain responsible to Customer for each Subprocessor's performance of those data protection obligations.
5.2 Initial Subprocessor List
The Subprocessor List Site describes these routing controls, and Create will identify to Customer, on request, the providers then eligible to serve requests routed for Customer. Create engages each Routing Subprocessor as a Subprocessor and holds the written agreement required by Section 5.1 with it. A downstream inference provider that serves a routed request receives Customer Personal Data through the Routing Subprocessor's service and under the routing controls described in this Section 5.2. Create does not engage that provider directly and does not represent that it holds, or that the Routing Subprocessor holds, a separate written data protection agreement with each such provider.
5.3 Notification
Create will give Customer direct written notice of its intended engagement of any new or replacement Subprocessor, at least fifteen (15) calendar days before that Subprocessor begins Processing Customer Personal Data. Create will send the notice by email to the notice contact identified in the Order Form, to another contact Customer designates in writing for Subprocessor notices, or through an in-product mechanism that affirmatively delivers the notice to Customer. Create will also update the Subprocessor List Site, but updating the Subprocessor List Site alone is not notice under this Section 5.3 and does not begin the objection period in Section 5.4. A change in which downstream inference provider serves requests routed through a Routing Subprocessor is not the engagement of a new or replacement Subprocessor and does not require notice under this Section 5.3, provided the routing controls described in Section 5.2 continue to apply to the route. Create will give notice under this Section 5.3, at least fifteen (15) calendar days in advance and with the same objection rights under Section 5.4, before materially relaxing those routing controls, including before disabling or narrowing the no-training routing configuration or making available for selection a route that does not satisfy the controls described in Section 5.2. Nothing in this paragraph limits any notice, listing, or objection right required by the SCCs or the UK Addendum for a transfer they govern.
If Create reasonably believes that a new or replacement Subprocessor is urgently necessary to address an imminent security risk, to comply with applicable law, or to maintain continuity of the Services, Create may engage that Subprocessor before the notice period ends. Create will give as much advance written notice as reasonably practicable, together with the reasons for the urgent engagement, and Customer retains its rights under Section 5.4 to object to the Subprocessor and to terminate the affected Services. Nothing in this Section 5.3 shortens a notice period required by the SCCs or the UK Addendum.
For each Module Three transfer, Customer represents and warrants that the applicable Data Controller has granted Create general written authorization to engage the Subprocessors on the Subprocessor List Site, including the routing of requests through a Routing Subprocessor to downstream inference providers as described in Section 5.2. Before any Module Three Processing begins, Customer will provide Create, in the Order Form or another binding written record, with the identity of each applicable Data Controller, and will promptly notify Create of any change to a Data Controller. Create will send each notice required by this Section 5.3 to Customer, and Customer represents and warrants that it will promptly forward each such notice to, and obtain any required authorization from, each applicable Data Controller. Create may suspend the affected Module Three Processing if Customer confirms that a required authorization was not obtained.
5.4 Customer's Right to Object to New Subprocessors
Customer will have fifteen (15) calendar days from the date of Create's notice under Section 5.3 to object to the engagement of the new or replacement Subprocessor on reasonable, documented data-protection grounds by providing written notice to Create. Upon receipt of a timely objection, Create will use commercially reasonable efforts to avoid using the new Subprocessor to Process Customer Personal Data, to offer a reasonable alternative, or to mitigate the risk identified in the objection. If the Parties cannot resolve a timely objection, Customer may terminate the affected Services or the affected Order Form before the new Subprocessor begins Processing Customer Personal Data, and Create will provide a prorated refund of prepaid fees for the unused portion of the terminated Services. If Customer does not object within the period set forth in this Section 5.4, Customer authorizes the use of the new Subprocessor. This Section 5.4 does not limit Customer's rights or remedies with respect to any separate breach of this DPA.
5.5 Restricted Transfers to Subprocessors
To the extent Create makes a Restricted Transfer to a Subprocessor, Create will establish appropriate safeguards for such Restricted Transfer as required by applicable Data Protection Laws, including, as applicable, an adequacy decision, the applicable SCCs, the UK Addendum, the Swiss adaptations described in Annex 2, or another valid transfer mechanism, together with supplementary measures where required.
6. Assistance to Customer Related to Data Subject Requests
6.1 Data Subject Request Notification
Create will notify Customer without undue delay if Create receives a request from a Data Subject to exercise their rights under applicable Data Protection Laws with respect to Customer Personal Data. Create will not respond substantively to such a request except on Customer's documented instructions or as required by applicable law, in which case Create will inform Customer of that legal requirement before responding unless the law prohibits such notice; Create may, however, confirm to the Data Subject that Create received their communication and refer the Data Subject to Customer.
6.2 Customer's Responsibility with respect to Data Subject Requests
Customer will be responsible for responding to requests, complaints, and all other communications from Data Subjects. To the extent that Customer can respond to such requests by using its access to Customer Personal Data or any self-service functionality of the Services, Customer will do so. This Section 6.2 does not limit Create's assistance obligations under Section 6.3.
6.3 Assistance in Responding to Data Subject Requests
Taking into account the nature of the Processing, Create will provide Customer with assistance, through appropriate technical and organizational measures and insofar as it is possible, to fulfill Customer's obligations to respond to requests from Data Subjects to exercise their rights under applicable Data Protection Laws, including rights of access, deletion, correction, restriction, portability, objection, and opt-out. Extraordinary, custom assistance is subject to Section 14.1.
7. Assistance with Customer's Other Data Protection Rights and Obligations
7.1 Assistance Related to Customer's Other Data Protection Rights and Obligations
Taking into account the nature of the Processing and the information available to Create, Create will provide reasonable assistance to Customer in complying with Customer's obligations under applicable Data Protection Laws with respect to: (a) the security of Processing; (b) the assessment, notification, and documentation of Personal Data Breaches; (c) data protection impact assessments and comparable risk assessments; (d) prior consultation with Supervisory Authorities; (e) inquiries from Supervisory Authorities or other regulators; and (f) transfer impact assessments relating to Restricted Transfers.
7.2 Information Security Materials
Upon Customer's written request, Create will make available to Customer the then-available information security materials for the applicable Services (the "Information Security Materials"), which may be provided through an access-restricted website in read-only format. The Information Security Materials are confidential information of Create. Customer may disclose Information Security Materials to its professional advisers, auditors, and regulators subject to confidentiality obligations at least as protective as those applicable between the Parties, or as required by law. To the extent available for the applicable Services, the Information Security Materials may contain the following:
a) A summary of any then-available third-party audits, assessments, or certifications relating to the security controls of the applicable Services, together with penetration-test summaries and responses to standard security questionnaires, in each case only to the extent they exist. As of the Last Updated date of this DPA, Create is pursuing SOC 2 compliance and does not represent that any SOC 2 or ISO 27001 report or certification has been completed; and
b) Any other published materials made available by Create, which further describe Create's principles, programs, and practices regarding information security and privacy.
8. Customer Audit Rights
8.1 Customer Audit Rights
Create will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and applicable Data Protection Laws, and will allow for and contribute to audits, including inspections, conducted by Customer or an independent third-party auditor mandated by Customer that is not a competitor of Create and is bound by written confidentiality obligations. Customer will ordinarily first review the assistance, records, and Information Security Materials described in Sections 7.1 and 7.2 of this DPA before requesting an inspection. Unless a Supervisory Authority requires otherwise, a material Personal Data Breach has occurred, those materials are insufficient to demonstrate compliance, or Customer has reasonable, documented grounds to suspect material noncompliance with this DPA, audits involving an inspection are limited to once in any twelve (12) month period, require at least thirty (30) days' prior written notice, and will follow a scope, timing, and duration agreed by the Parties in advance, acting reasonably. Every audit will be conducted during normal business hours, will not unreasonably disrupt Create's operations, will not provide access to data of Create's other customers, and will be limited to relevant systems and premises Create directly controls. No procedural limit in this Section 8.1 will prevent an audit or inspection necessary for Customer to comply with applicable Data Protection Laws, the SCCs, or the UK Addendum.
9. Return or Deletion of Customer Personal Data
9.1 Upon Termination
Upon termination of the Agreement, at Customer's choice, Create will return Customer's exportable Customer Content to Customer and/or delete Customer Personal Data in accordance with this Section 9.1. For sixty (60) days after termination, Create will make Customer's exportable Customer Content, including transcripts, Agent memory, Agent Code, and files, available for export through self-service tools or on request, unless Customer instructs earlier deletion. Create will delete Customer Personal Data from its active systems within ninety (90) days of termination and will delete existing copies. Copies in routine backups that cannot reasonably be isolated will be put beyond use, will remain subject to this DPA, and will be deleted in the ordinary course of Create's documented backup cycle. Create may retain Customer Personal Data after Customer has chosen return or deletion only to the extent and for the duration that applicable law requires storage; Create will isolate and protect the retained data, continue to apply this DPA to it, Process it solely for the legally required retention purpose, and delete it when the requirement ends. Security, billing, investigations, disputes, and internal document-retention policies do not independently authorize retention after Customer has chosen return or deletion. By entering into this DPA, Customer instructs Create to delete, rather than return, Secrets and OAuth tokens upon disconnection of the applicable Connected Account or upon termination, subject to the backup rule above. Upon Customer's written request, Create will certify the deletion of Customer Personal Data; the certification will identify any Customer Personal Data retained under this Section 9.1 as required by applicable law. No category of Customer Personal Data is excluded from this Section 9.1 as non-exportable; exportable Customer Content includes Agent memory, transcripts, and files, and Customer Personal Data that is not technically exportable will be deleted, not retained, except as this Section 9.1 expressly permits.
9.2 User-Initiated Deletion
Customer and its Authorized Users may, subject to Customer's Workspace administration controls and shared-record needs, delete Agents, transcripts, Agent memory, files, and Secrets, and disconnect Connected Accounts, through the Services. Create will remove deleted Customer Content from its active systems within thirty (30) days and from backups on backup expiration. When a Connected Account is disconnected, Create stops accessing it and deletes the associated tokens. All other Customer Personal Data related to a deleted user account or Workspace will continue to be Processed in accordance with the Agreement and this DPA.
10. Personal Data Breach of Customer Personal Data
10.1 Personal Data Breach Notification
If Create becomes aware of a Personal Data Breach involving Customer Personal Data, Create will notify Customer of such Personal Data Breach without undue delay, and in no event later than forty-eight (48) hours after becoming aware of it, at the notice contact identified in Customer's Order Form (or another address Customer designates in writing for security notices or, if none is identified, the Primary Contact Email identified in the Order Form). Create becomes "aware" of a Personal Data Breach when Create's incident response lead, security officer, or legal counsel knows of facts reasonably indicating that a Personal Data Breach has occurred; initial notice may be preliminary and will not be delayed pending a completed investigation. Create's notice may be delayed only to the extent applicable law prohibits such notice, and Create will provide the notice promptly after the legal prohibition is lifted. Create's notification of, or response to, a Personal Data Breach is not an acknowledgment of any fault or liability.
10.2 Personal Data Breach Assistance
If Create notifies Customer of a Personal Data Breach in accordance with Section 10.1 of this DPA, Create will: (a) provide Customer with information about the Personal Data Breach in phases as it becomes available, including, to the extent known, the nature of the breach, relevant dates, the categories and approximate numbers of Data Subjects and records concerned, likely consequences, measures taken or proposed to contain and remediate it, and a contact point; (b) take reasonable steps to contain and investigate the Personal Data Breach, mitigate its effects, and remediate its causes to the extent within Create's control; (c) provide reasonable rolling updates as the investigation progresses; and (d) provide reasonable assistance to Customer in relation to Customer's obligations to notify Supervisory Authorities, other regulators, other Data Controllers, and Data Subjects, and in handling any Supervisory Authority request for information with respect to such Personal Data Breach.
11. Restricted Transfers
11.1 SCCs
To the extent that a Restricted Transfer is made and is not covered by an adequacy decision or another valid transfer mechanism, the Parties agree that the SCCs (Module Two where Customer is a Data Controller, and Module Three where Customer is a Data Processor acting on behalf of another Data Controller), the UK Addendum, and the Swiss adaptations, as applicable, will apply to such Restricted Transfer as described in Annex 2 (Restricted Transfer Annex), and will prevail over the other terms of this DPA with respect to that Restricted Transfer. Create does not rely on the EU-U.S. Data Privacy Framework unless and until Create has certified to it.
12. Limitations of Liability
12.1 Terms of the Agreement
The Parties agree that all liability and limitations of liability under this DPA are governed by the exclusions and limitations of liability set forth in the Agreement, including any enhanced liability cap in the Agreement applicable to breaches of the Agreement's security provisions. This DPA creates no separate indemnity. The aggregate liability caps in the Agreement apply in the aggregate to all claims under this DPA by Customer and its covered Affiliates together. Claims against Create arising out of or relating to this DPA, including claims by Customer's Affiliates, may be brought only by the Customer entity that executed the applicable Order Form, on its own behalf and on behalf of its covered Affiliates. Nothing in this Section 12.1 limits: (a) any liability to Data Subjects or Supervisory Authorities that cannot lawfully be limited; or (b) either Party's liability under Clause 12 of the SCCs, or the corresponding provisions of the UK Addendum, to the extent such liability cannot lawfully be limited.
13. Account Data and Usage Data
13.1 Permitted Uses
Customer acknowledges that Create, as an independent Data Controller, may collect, use, and disclose Account Data and Usage Data for the following purposes:
(i) for contracting, accounting, tax, billing, audit, and compliance purposes, and to administer Customer's account, support, and business relationship;
(ii) to provide, operate, secure, meter, diagnose, and maintain the Services and to plan capacity;
(iii) to investigate and prevent fraud, spam, abuse, and wrongful or unlawful use of the Services;
(iv) to evaluate and improve the Services using only aggregated or de-identified data that does not identify Customer or any Data Subject, and Create will not attempt to re-identify such data; and
(v) as otherwise required by applicable law.
Create will not sell or share Account Data or Usage Data, use them for targeted advertising, use them for marketing other than communications to Customer's business representatives consistent with Create's Privacy Policy, use them to train, fine-tune, reinforce, or evaluate any model on Customer Content, or combine them with other data except as necessary for the purposes stated above or as required by applicable law.
13.2 Processing Account Data and Usage Data
In respect of any such Processing described in Section 13.1, Create:
(i) independently determines the purposes and means of such Processing;
(ii) shall comply with Data Protection Laws (if and as applicable in the context);
(iii) shall process requests from Data Subjects that are forwarded to Create by Customer to the extent required by Data Protection Laws and upon request provide documentation to Customer that it has done so;
(iv) shall Process such Account Data and Usage Data as described in Create's privacy policy (skydive.com/privacy (or any successor hyperlink)), as updated from time to time; and
(v) shall not attempt to re-identify de-identified data. If a record within Account Data or Usage Data contains Customer Content, that content remains Customer Personal Data governed by this DPA.
14. Miscellaneous
14.1 Assistance Costs
To the extent legally permitted, Customer is responsible for the reasonable costs and fees associated with Create's provision of extraordinary or custom assistance under this DPA and implementation of any Modified Instructions, in each case except to the extent the assistance or Modified Instruction is required because of Create's breach of this DPA.
14.2 Expansion or Modification of Customer Audit Rights
The audit process in Section 8 of this DPA supersedes any restriction on Customer's audit rights in the Agreement to the extent necessary to satisfy applicable Data Protection Laws, US State Privacy Laws, the SCCs, or the UK Addendum. An Order Form may grant Customer broader audit rights.
14.3 Choice of Law
Except with respect to the SCCs, the UK Addendum, the Swiss adaptations, and any other mandatory requirements of applicable Data Protection Laws, this DPA is governed by the laws that govern the Agreement and any dispute between the Parties will be handled as set forth in the Agreement.
14.4 Entire Agreement; Amendments and Modifications
This DPA, together with all annexes, attachments, and appendices to this DPA and any other documents incorporated into this DPA by reference, constitutes the sole and entire agreement of the Parties with respect to the subject matter of this DPA and supersedes all prior and contemporaneous understandings, agreements, and representations and warranties, both written and oral, with respect to such subject matter. Except as expressly provided in this DPA, the terms of the Agreement are and will remain in full force and effect. This DPA may only be amended by a written amendment that specifically references this DPA and the intent of the Parties to modify this DPA.
14.5 Duration and Survival
This DPA takes effect on the Effective Date and remains in force, notwithstanding expiration or termination of the Agreement, until Create and its Subprocessors have ceased Processing Customer Personal Data as described in Section 9. Customer Personal Data retained under Section 9.1 remains subject to the protections of this DPA until it is deleted.
14.6 Severability
If any provision of this DPA is held invalid or unenforceable, that provision will be modified to the minimum extent necessary to make it valid and enforceable, and the remaining provisions of this DPA will remain in full force and effect. No such modification will alter the mandatory terms of the SCCs, the UK Addendum, or the Swiss adaptations.
Annex 1. Data Processing Details
CREATE / 'DATA IMPORTER' DETAILS
Name: Create, Inc.
Address: 214 Grant Ave, Suite 3, San Francisco, CA 94108
Contact Details for Data Protection: [email protected]; for security incidents: [email protected]
Create Activities: Create provides Skydive, a hosted agent-compute platform through which customers create, configure, and deploy AI Agents across web and desktop apps, Slack, email, text and similar messaging, and API/SDK/CLI channels, with cloud sandboxes and code execution, Agent memory, secrets storage with execution-time credential injection, model inference and routing, Connected Accounts, and customer-deployed Agents interacting with End Users.
Role: Processor or Subprocessor of Customer Personal Data (and independent Controller of Account Data and Usage Data as described in Section 13 of the DPA)
CUSTOMER / 'DATA EXPORTER' DETAILS
Name: The Customer legal entity identified in the executed Order Form
Customer's address is: As provided in the executed Order Form
Customer's Contact Details for Data Protection: The privacy contact identified in the executed Order Form. For Module Three Processing, the applicable Data Controller(s) and their notice contacts are those identified in the executed Order Form or another binding written record provided under Section 5.3 of the DPA.
Customer Activities: Customer's activities relevant to this DPA are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement as part of its ongoing business operations.
Role: Controller or Processor, as described in Section 2.1 of the DPA
Categories of Data Subjects
Relevant Data Subjects include: Authorized Users and administrators; Customer personnel and contractors; End Users who interact with Customer-deployed Agents; individuals whose Personal Data appears in Customer Content, Connected Accounts, messages, emails, files, calendar entries, contacts, tickets, records, or repositories; senders and recipients of communications handled through the Services; and any other Data Subjects whose Personal Data Customer causes Create to Process in performance of the Services.
Categories of Personal Data
Relevant Personal Data includes any Categories of Personal Data Customer causes Create to process as part of the provision of the Services, including:
Personal details – for example any information that identifies the Data Subject, including name, and contact information.
Authentication details – for example username, password or PIN code, security questions and other access protocols.
Technological details – for example internet protocol (IP) addresses, unique identifiers and numbers (including unique identifier in tracking cookies or similar technology), pseudonymous identifiers, precise and imprecise location data, internet / application / program activity data, and device IDs and addresses.
Email and communications data – for example contents of emails and other communications as provided or permitted by the individual user and/or Customer.
Product and execution data – for example prompts, messages, transcripts, files, Connected Account content, Agent memory, summaries, embeddings, Outputs, Agent Code and repositories, sandbox, browser, and session data, agent actions and tool calls, and the contents of communications carried within execution traces.
Credentials and Secrets – for example OAuth tokens, API keys, passwords, and similar sensitive material stored for Agents to use.
End User data – for example Personal Data of End Users who interact with Customer-deployed Agents.
Sensitive Categories of Data, and associated additional restrictions/safeguards
Categories of sensitive data: Customer and its users determine the sensitive data submitted to the Services. Customer may direct the Processing of credentials, tokens, Secrets, and other sensitive content supported by the Services. Special Data Categories are permitted only as described in Section 2.9 of the DPA.
Additional safeguards for sensitive data: The measures set forth in Attachment 2 to Annex 2, including encryption in transit and at rest, secrets-management infrastructure with execution-time credential injection, sandbox isolation for agent execution, network-level monitoring of agent traffic, access controls, and logging.
Frequency of transfer
Ongoing – continuous or episodic, as initiated by Customer, its Authorized Users, its Agents, its End Users, connected integrations, and configured workflows in and through the use, or use on Customer's behalf, of the Services.
Nature of the Processing
Processing operations required in order to provide the Services in accordance with the Agreement, including collection, receipt, hosting, storage, organization, retrieval, transmission, routing, inference, tool invocation, code and browser execution, memory and personalization, inspection as permitted for network-control and security functions, analysis, generation, modification, disclosure to authorized recipients, return, and deletion.
Purpose of the Processing
As necessary to provide the Services as initiated by Customer in its use thereof, and to comply with any other reasonable instructions provided by Customer in accordance with the terms of this DPA, including to provide, secure, support, troubleshoot, meter, and administer the Services; to operate Agents and sandboxes; to maintain Agent memory; to perform authorized actions and communications; to connect accounts and inject credentials; to route inference requests; to support Customer's compliance with Data Subject rights and applicable law; and to create Anonymous Data for the operational purposes authorized by Section 2.10 of the DPA.
Duration of Processing / Retention Period
For the period determined in accordance with the Agreement and DPA, including Section 9 of the DPA. Without limiting Section 9: content deleted by users is removed from active systems within 30 days; exportable Customer Content is available for export for 60 days after termination; Customer Content is deleted from active systems within 90 days of termination; content-level network logs are retained for no more than 30 days absent an active investigation, billing dispute, or legal obligation; and backups are deleted on their cycle and in all events as described in Section 9.1 of the DPA. Any metadata, metering, security log, execution trace, or network log that constitutes Customer Personal Data follows Section 9 of the DPA. Only Account Data and Usage Data that validly fall within Section 13 of the DPA and contain no Customer Personal Data may be retained under Create's separately disclosed controller retention schedule, under which metadata, metering, and security logs are retained for up to 12 months.
Transfers to (sub)processors
As set out in Section 5 of the DPA and the Subprocessor List Site. Processing may occur in the United States and in the other countries where the listed Subprocessors operate, subject to Annex 2 of the DPA.
Annex 2. Restricted Transfer Annex
1. RESTRICTED TRANSFERS
1.1 EU Restricted Transfers
To the extent that any Processing of Personal Data under this DPA involves a transfer of Customer Personal Data by Customer, as a Data Controller or Data Processor subject to the GDPR for the relevant Processing, to Create or another recipient in a country or territory outside the EEA, where Chapter V of the GDPR requires an appropriate safeguard and no applicable adequacy decision from the European Commission or other valid transfer mechanism covers the transfer, regardless of Customer's geographic location (an "EU Restricted Transfer"), the Parties shall comply with their respective obligations set out in the SCCs (Module Two where Customer is a Data Controller, and Module Three where Customer is a Data Processor), which apply and are effective as of the Effective Date, before the relevant transfer begins, and are hereby deemed to be:
1) populated in accordance with Part 1 of Attachment 1 to Annex 2 (Restricted Transfer Annex); and
2) entered into by the Parties and incorporated by reference into this DPA.
1.2 UK Restricted Transfers
To the extent that any Processing of Personal Data under this DPA involves a transfer of Customer Personal Data by Customer, as a Data Controller or Data Processor subject to the UK GDPR for the relevant Processing, to Create or another recipient outside the UK, where the UK transfer regime requires an appropriate safeguard and no applicable adequacy regulation or other valid transfer mechanism covers the transfer, regardless of Customer's geographic location (a "UK Restricted Transfer"), the Parties shall comply with their respective obligations set out in the SCCs, as varied by the UK Addendum effective as of the Effective Date, before the relevant transfer begins, which are hereby deemed to be:
1) varied to address the requirements of the UK GDPR in accordance with the UK Addendum and populated in accordance with Part 2 of Attachment 1 to Annex 2 (Restricted Transfer Annex); and
2) entered into by the Parties and incorporated by reference into this DPA.
1.3 Swiss Restricted Transfers
To the extent that any Processing of Personal Data under the DPA involves the disclosure, grant of access or other transfer of Personal Data, when transferred from Switzerland, to any person located in a country or territory outside of Switzerland which does not benefit from an adequacy decision from the Swiss authorities (a "Swiss Restricted Transfer") from Customer to Create, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:
1) varied to address the requirements of the FADP and populated in accordance with Part 3 of Attachment 1; and
2) entered into by the Parties and incorporated by reference in the DPA.
Nothing in any applicable SCCs (as deemed amended pursuant to Section 1.3) should be interpreted or construed in such a way as would limit or exclude the rights of Data Subjects under Clause 18(c) of those SCCs (as deemed amended pursuant to Section 1.3) to bring legal proceedings before the courts in Switzerland where Switzerland is that Data Subject's place of habitual residence.
1.4 Other Restricted Transfers
To the extent that any Processing of Personal Data under this DPA involves a Restricted Transfer from Customer to Create other than as described in Section 1.1, 1.2, or 1.3 above, the Parties will comply with the transfer mechanism legally recognized for that transfer under applicable Data Protection Laws and will execute or incorporate any jurisdiction-specific terms required for that mechanism. No such Restricted Transfer will begin until the legally required mechanism has been executed or validly incorporated, and Create may suspend the affected transfer if no valid mechanism is available.
Adoption of new transfer mechanism
Create may, on at least thirty (30) days' advance written notice where reasonably practicable, vary this DPA and replace the relevant SCCs with:
1) any new form of the relevant SCCs or any replacement therefor prepared and populated accordingly (e.g., standard data protection clauses adopted by the European Commission for use specifically in respect of transfers to data importers subject to Article 3(2) of the GDPR); or
2) another transfer mechanism, other than the SCCs, that enables the lawful transfer of Personal Data to Create under this DPA in compliance with applicable Data Protection Laws; provided that any replacement mechanism must be legally valid, must not materially reduce the protection of Customer Personal Data, and, where a replacement materially disadvantages Customer and no lawful alternative exists, Customer may object and terminate the affected transfers as described in Section 5.4 of the DPA.
Provision of full-form SCCs
In respect of any given Restricted Transfer, upon Customer's reasonable written request (made to the contact details set out in Annex 1 (Data Processing Details)), Create shall provide Customer with a version of the relevant set(s) of SCCs (amended and populated in accordance with Attachment 1 to Annex 2 (Restricted Transfer Annex) in respect of the relevant Restricted Transfer, reflecting the executed Order Form) for countersignature by Customer, onward provision to any relevant Supervisory Authority, Data Subject, or further Controller, and/or storage to evidence Customer's compliance with applicable Data Protection Laws. No evidence of a third-party request is required.
Operational clarifications
When complying with its transparency obligations under Clause 8.3 of the SCCs, Customer agrees that it shall take appropriate steps to protect Create's and its licensors' trade secrets, business secrets, confidential information and/or other commercially sensitive information, including by redaction, in each case only to the extent permitted by, and without frustrating Data Subjects' rights under, the SCCs.
For the purposes of Clause 15.1(a) of the SCCs, except to the extent prohibited by applicable law and/or the relevant public authority, each Party will comply with its own notification obligations under the SCCs, and the Parties will coordinate in good faith regarding any notifications to relevant Data Subjects.
The terms and conditions of Section 5 of the DPA apply in relation to Create's appointment and use of Subprocessors under the SCCs, to the extent consistent with Clause 9 of the SCCs. Any approval by Customer of Create's appointment of a Subprocessor that is given expressly or pursuant to that Section 5 constitutes Customer's documented instructions to effect disclosures and onward transfers to any relevant Subprocessors if and as required under Clause 8.8 of the SCCs.
The audits described in Clauses 8.9(c) and 8.9(d) of the SCCs shall be subject to any relevant terms and conditions detailed in Section 8 of the DPA, to the extent those terms do not narrow audit or inspection rights under the SCCs that cannot lawfully be limited.
Certification of deletion of Personal Data as described in Clauses 8.5 and 16(d) of the SCCs shall be provided upon Customer's written request.
Attachment 1 to Annex 2 (Restricted Transfer Annex) — Population of SCCs
Note
In the context of any EU Restricted Transfer, the SCCs populated in accordance with Part 1 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Section 1.1 of Annex 2 (Restricted Transfer Annex) to the DPA).
In the context of any UK Restricted Transfer, the SCCs as varied by the UK Addendum and populated in accordance with Part 2 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Section 1.2 of Annex 2 (Restricted Transfer Annex) to the DPA).
In the context of any Swiss Restricted Transfer, the SCCs as varied and populated by Part 3 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Section 1.3 of Annex 2 (Restricted Transfer Annex) to the DPA).
PART 1: POPULATION OF THE SCCs
SIGNATURE OF THE SCCs
Where the SCCs apply in accordance with Section 1.1 of Annex 2 (Restricted Transfer Annex) to the DPA, each Party agrees that its execution of the Order Form incorporating this DPA constitutes its signature of the applicable module of the SCCs and of Annex I to the Appendix to the SCCs, as of the Effective Date. Upon either Party's reasonable request, the Parties will also execute a separately signed copy of the populated SCCs.
MODULES
The following modules of the SCCs apply in the manner set out below (having regard to the role(s) of Customer set out in Attachment 1 to Annex 2 (Restricted Transfer Annex) to the DPA):
1) Module Two of the SCCs applies to any EU Restricted Transfer and/or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Customer is a Controller in its own right; and 2) Module Three of the SCCs applies to any EU Restricted Transfer and/or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Customer is itself a Processor acting on behalf of another Controller.
POPULATION OF THE BODY OF THE SCCs
For each Module of the SCCs, the following applies as and where applicable to that Module and the Clauses thereof:
1) The optional 'Docking Clause' in Clause 7 is not used and the body of that Clause 7 is left intentionally blank.
2) In Clause 9: 1) OPTION 2: GENERAL WRITTEN AUTHORISATION applies, and the minimum time period for advance notice of the addition or replacement of Subprocessors shall be fifteen (15) calendar days, consistent with Section 5 of the DPA; and 2) OPTION 1: SPECIFIC PRIOR AUTHORISATION is not used and that optional language is deleted. Annex III to the Appendix to the SCCs is populated by the Subprocessor List Site, as updated in accordance with Section 5 of the DPA.
3) In Clause 11, the optional language is not used and is deleted.
4) In Clause 13, all square brackets are removed and all text therein is retained.
5) In Clause 17: 1) OPTION 1 applies, and the Parties agree that the SCCs shall be governed by the law of Ireland; and 2) OPTION 2 is not used and that optional language is deleted.
6) For the purposes of Clause 18, the Parties agree that any dispute arising from the SCCs shall be resolved by the courts of Ireland, and Clause 18(b) is populated accordingly. This choice does not limit Data Subjects' rights under Clause 18(c).
In this Paragraph 3, references to "Clauses" are references to the Clauses of the SCCs.
POPULATION OF ANNEXES TO THE APPENDIX TO THE SCCs
Annex I to the Appendix to the SCCs is populated with the corresponding information detailed in Annex 1 (Data Processing Details) to the DPA, with:
1) Customer being 'data exporter'; and
2) Create being 'data importer'.
Part C of Annex I to the Appendix to the SCCs is populated as below:
The competent supervisory authority shall be determined as follows:
Where Customer is established in an EU Member State: the competent supervisory authority shall be the supervisory authority of that EU Member State in which Customer is established.
Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies and Customer has appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State in which Customer's EU representative relevant to the processing hereunder is based (from time-to-time).
Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies, but Customer has not appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State notified in writing to Create's contact point for data protection identified in Annex 1 (Data Processing Details) to the DPA, which must be an EU Member State in which the data subjects whose personal data is transferred under these Clauses in relation to the offering of goods or services to them, or whose behavior is monitored, are located.
Annex II to the Appendix to the SCCs is populated as below:
General:
The technical and organizational measures set forth in Attachment 2 to Annex 2 to the DPA.
In the event that Customer receives a data subject request under the GDPR and requires assistance from Create, Customer should email Create's contact point for data protection identified in Annex 1 (Data Processing Details) to the DPA ([email protected]).
Subprocessors: When Create engages a Subprocessor under these Clauses, Create shall enter into a binding contractual arrangement with such Subprocessor that imposes upon them data protection obligations which, in substance, meet or exceed the relevant standards required under these Clauses and the DPA – including in respect of:
applicable information security measures;
notification of information security incidents to Create;
return or deletion of Personal Data as and where required; and engagement of further Subprocessors.
PART 2: UK RESTRICTED TRANSFERS
UK ADDENDUM
Where relevant in accordance with Section 1.2 of Annex 2 (Restricted Transfer Annex) to the DPA, the SCCs also apply in the context of UK Restricted Transfers as varied by the UK Addendum in the manner described below:
1) Part 1 to the UK Addendum. As permitted by Section 17 of the UK Addendum, the Parties agree: 1) Tables 1, 2 and 3 to the UK Addendum are deemed populated with the corresponding details set out in Annex 1 (Data Processing Details), Attachment 2 to Annex 2, the Subprocessor List Site, and the foregoing provisions of this Attachment 1 (subject to the variations effected by the Mandatory Clauses described in (b) below); and 2) Table 4 to the UK Addendum is completed by the box labelled 'Data Importer' being deemed to have been ticked.
2) Part 2 to the UK Addendum. The Parties agree to be bound by the Mandatory Clauses of the UK Addendum.
In relation to any UK Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs shall be read as a reference to those SCCs as varied in the manner set out in this Part 2.
PART 3: SWISS RESTRICTED TRANSFERS
VARIATIONS FOR SWISS RESTRICTED TRANSFERS
Where applicable in accordance with Section 1.3 of Annex 2 (Restricted Transfer Annex), the SCCs also apply in the context of Swiss Restricted Transfers with the following adaptations:
1) references to the "GDPR" are read as references to the FADP only to the extent the relevant transfer is governed by the FADP;
2) references to the "European Union", "Union" and "Member State(s)" will not be interpreted to exclude Switzerland or to prevent a Data Subject from bringing legal proceedings in Switzerland where Switzerland is that Data Subject's place of habitual residence, and the elections of Irish law under Clause 17 and the Irish courts under Clause 18(b) made in Part 1 of this Attachment 1 remain in effect, except that the Parties may expressly elect Swiss law for a transfer governed solely by the FADP; and
3) "supervisory authority" means the Swiss Federal Data Protection and Information Commissioner ("FDPIC") to the extent the Swiss Restricted Transfer is governed by the FADP, and, where the GDPR also applies to the relevant Processing, the competent supervisory authority determined under Part 1 of this Attachment 1 is preserved.
In relation to any Swiss Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs shall be read as a reference to those SCCs as varied in the manner set out in this Part 3.
Attachment 2 to Annex 2 (Restricted Transfer Annex): Technical and Organizational Measures
This Attachment 2 sets out the technical and organizational measures Create implements to protect Customer Personal Data and populates Annex II to the Appendix to the SCCs. Create may update these measures as described in Section 4.1 of the DPA, provided the updates do not materially decrease the overall protection of Customer Personal Data.
Encryption: Create encrypts Customer Personal Data in transit and at rest.
Secrets management: OAuth tokens, API keys, and credentials are stored in secrets-management infrastructure with encryption at rest. API connections are designed for execution-time credential injection so that raw secrets are not exposed in an Agent's working context, and known credential patterns are redacted from logs.
Isolation: Agent execution occurs in isolated cloud sandboxes, and browser sessions operated by Agents are isolated.
Monitoring: Create uses network-level monitoring of agent traffic to apply Customer security rules and detect abuse.
Access controls: Create limits access to Customer Personal Data to personnel who need that access to provide the Services, as described in Section 3.1.
Logging: Create maintains network, security, and metering logs for operation and protection of the Services. Logs that contain Customer Personal Data are retained as described in Annex 1 and Section 9.
Assurance: Create is pursuing SOC 2 Type 2 compliance. Create provides its then-available Information Security Materials as described in Section 7.2.
Additional safeguards: Based on the nature of the Processing and risks to Customer Personal Data, Create applies the security monitoring and response measures in Section 4, the Subprocessor protections in Section 5, and the return and deletion measures in Section 9. For facilities operated by a cloud infrastructure Subprocessor identified on the Subprocessor List Site, physical and environmental security is provided by that Subprocessor.
Annex 3. US State Privacy Laws Annex
For purposes of this Annex 3, the terms "business," "commercial purpose," "sell," "share," "targeted advertising," "service provider," "contractor," and "processor" shall have the respective meanings given thereto in the applicable US State Privacy Laws, and "personal information" and "de-identified" data have the meanings given directly by the applicable US State Privacy Law, without limitation by this DPA's definitions of Personal Data or Data Subject.
It is the Parties' intent that with respect to any personal information, Create is a service provider, contractor, or processor, as applicable under the relevant US State Privacy Law (or, where Customer itself acts as a service provider, contractor, or processor, that Create acts as a permitted subcontractor or subprocessor in the corresponding role). Create (a) acknowledges that personal information is disclosed by Customer only for the limited and specified purposes described in Annex 1 and the Agreement; (b) shall comply with applicable obligations under the US State Privacy Laws and shall provide the same level of privacy protection to personal information as is required by the US State Privacy Laws; (c) agrees that Customer has the right to take reasonable and appropriate steps to help to ensure that Create's use of personal information is consistent with Customer's obligations under the US State Privacy Laws; (d) shall notify Customer in writing of any determination made by Create that it can no longer meet its obligations under the US State Privacy Laws; and (e) agrees that Customer has the right, upon notice, including pursuant to the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information. Create will impose restrictions at least equivalent to this Annex 3 on any subcontractor it engages to Process personal information.
Create shall not (a) sell or share any personal information or use it for targeted advertising; (b) retain, use or disclose any personal information for any purpose other than for the specific purpose of providing the Services, including retaining, using, or disclosing the personal information for a commercial purpose other than the provision of the Services; (c) retain, use or disclose the personal information outside of the direct business relationship between Create and Customer; or (d) combine personal information received pursuant to the Agreement with personal information (i) received from or on behalf of another person, or (ii) collected from Create's own interaction with any consumer to whom such personal information pertains, except in each case (a) through (d) as and to the extent expressly permitted of a service provider, contractor, or processor under the applicable US State Privacy Laws. Create may use information to evaluate or improve the Services, or for model training, only after that information no longer constitutes personal information under the applicable US State Privacy Law; Create will not attempt to re-identify such information and will require equivalent commitments from any recipient of it. The safeguards in Section 2.10 of this DPA apply cumulatively to any such use. Create hereby certifies that it understands its obligations under this Annex 3 and will comply with them.
Giving Customer notice of Subprocessor engagements in accordance with Section 5 of the DPA shall satisfy Create's obligation under the US State Privacy Laws to give notice of and an opportunity to object to such engagements.
Create agrees that Customer may conduct audits, in accordance with Section 8 of the DPA, to help ensure that Create's use of personal information is consistent with Create's obligations under the US State Privacy Laws.
The Parties acknowledge that Create's retention, use and disclosure of personal information authorized by Customer's instructions documented in the DPA are integral to Create's provision of the Services and the business relationship between the Parties. To the extent a then-applicable US State Privacy Law regulates Customer's use of the Services for automated decision-making or profiling, Create will provide reasonable information and assistance regarding the Services to support Customer's legally required notices, consumer rights responses, and risk assessments; Customer remains responsible for determining whether and how its use of the Services is subject to those requirements and for providing any legally required human review.