Third Party Index

Snapshot 34895

Document
Data processing addendum
URL
https://3803013.fs1.hubspotusercontent-na1.net/hubfs/3803013/Website%20Content/241223%20-%20essentry%20-%20Data%20Processing%20Agreement%20US.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
305384 bytes
SHA-256 (raw)
fe855b3308af20573a40c232332c2f4a3d4d55942326b84168d826d529fb894e
SHA-256 (normalized text)
b1df0b8be346bf26e3e662775dc1ef3f64e50fa7803eda78f63a7dc0c0d8a1bb

Normalized text

Scripts and page chrome removed; this is what change detection compares.

 Essentry Inc.

                                                                                                   -     shall not “share” the personal data, as such term is defined in the
Data Processing Agreement pursuant to Art.                                                               CCPA (regardless of whether the CCPA applies) or otherwise
28 (3) GDPR and other applicable law                                                                     disclose it for targeted advertising purposes;
                                                                                                   -     shall not retain, use, or disclose any such data outside of the direct
                                                                                                         business relationship between the Client and the Contractor, or for
1.         General                                                                                       any purpose (including any commercial purpose) other than the
                                                                                                         limited business purposes specified in this agreement and as
1.1. Essentry Inc. (hereinafter referred to as the "Contractor") operates systems
                                                                                                         permitted by applicable law;
     for the digital administration of access management processes and
                                                                                                   -     shall comply with any restrictions under applicable law on combining
     concludes contracts with Clients for the use of the "essentry" system
                                                                                                         the personal data that Contractor receives from, or on behalf of,
     (hereinafter referred to as "system contracts" or "system contract").
                                                                                                         Client with personal data that Contractor receives from, or on behalf
1.2. This agreement (together with its annexes described in more detail below)                           of, another person or persons, or that Contractor collects from any
     on data processing in accordance with Art. 28 GDPR and other applicable                             other interaction between Contractor and a data subject;
     law (hereinafter also referred to as the "Agreement") specifies the legal                     -     shall provide the same level of protection for any personal data
     rights and obligations arising for the Contractor and the Client from the                           subject to the CCPA as is required of businesses under the CCPA,
     General Data Protection Regulation (Regulation (EU) 2016/679,                                       and shall promptly inform the Client if the Contractor determines that
     hereinafter also referred to as the "GDPR") and other privacy and data                              it can no longer meet its obligations under the CCPA;
     protection laws (such as the California Consumer Privacy Act, as                              -     hereby certifies that it understands the restrictions and obligations
     amended, and its regulations (hereinafter also collectively referred to as                          set forth in this agreement and that it will comply with them.
     the “CCPA”)) if the Contractor processes personal data for the Client within
     the scope of the system contracts or carries out commissioned
     maintenance (hereinafter also referred to as "data processing").
                                                                                             5.          Duration of the data processing
1.3. The Contractor acknowledges that the GDPR and other applicable laws                     5.1. The term of this agreement depends on the duration of the system
     protect the fundamental rights and freedoms of natural persons and in                        contracts.
     particular their right to the protection of personal data and that these                5.2. The agreement ends automatically and without the need for termination if
     principles also apply to the Contractor.                                                     the Contractor no longer carries out any data processing or commissioned
                                                                                                  maintenance for the Client.
2.         Definitions                                                                       5.3. The right to ordinary termination is - subject to the termination option under
                                                                                                  section 5.4 - is excluded. The right to extraordinary termination for good
2.1. The definitions in Art. 4 and Art. 9 GDPR and the following additional
                                                                                                  cause in accordance with § 314 BGB remains unaffected.
     definitions apply:
                                                                                             5.4. The Client may terminate a system contract, irrespective of any conflicting
2.2. "Commissioned maintenance" means services provided by the Contractor
                                                                                                  provisions in the system contract, if the Contractor breaches a statutory
     (e.g. care, maintenance or other services on computer programs or
                                                                                                  data protection provision or an obligation under this agreement or
     technical objects for information processing), during the performance of
                                                                                                  breaches a guarantee. In this case, the notice period shall be three (3)
     which it cannot be ruled out that the Contractor will gain access to personal
                                                                                                  months to the end of the month. Claims of the Contractor due to premature
     data for which the Client is responsible.
                                                                                                  termination of the contract, in particular claims for damages, are excluded.
2.3. "System Contract" means the respective legal relationship between the
     Client and the Contractor based on which the Contractor carries out data
     processing or commissioned maintenance for the Client as intended.
                                                                                             6.          Place of data processing
2.4. "Subcontractor" means third parties within the meaning of Art. 4 No. 10                 6.1. Subject to the following provisions, the data processing may only take
     GDPR, which the Contractor uses with the written consent of the Client to                    place in a member state of the European Union or in another state party to
     provide services under the system contract.                                                  the Agreement on the European Economic Area.
2.5. Further definitions can be made contextually in the respective clause of                6.2. Any data processing outside a member state of the European Union or
     this agreement.                                                                              outside another state party to the Agreement on the European Economic
                                                                                                  Area (hereinafter referred to as "third country") requires the prior written
                                                                                                  consent of the Client.
3.         Components of the agreement
                                                                                             6.3. Consent to data processing in a third country will not be granted in
3.1. Data processing or commissioned maintenance by the Contractor shall                          particular if the special requirements of Art. 44 f. GDPR are not
     always be carried out based on a system contract between the Contractor                      permanently fulfilled, in particular if there is no adequate level of protection
     and the Client. The system contract is decisive for the subject matter,                      in the third country or if there are no suitable guarantees to ensure an
     duration, type, and purpose of the data processing, as well as for                           adequate level of protection.
     determining the type of personal data and the categories of data subjects
                                                                                             6.4. The Contractor shall ensure at its own expense that an appropriate level
     (hereinafter also referred to as "subject matter of the order"). To determine
                                                                                                  of protection is ensured in the third country and shall provide evidence of
     the subject matter of the order, the Contractor and the Client shall use the
                                                                                                  this to the Client when obtaining approval, in particular by:
     Annex 1: Subject-matter of the data processing and add it to the
     corresponding system contract in a legally binding manner.                                    -     an adequacy decision by the EU Commission (Art. 45 (3) GDPR);
                                                                                                   -     binding internal data protection rules (Art. 46 section 2 lit. b. in
3.2. This agreement contains provisions on data processing and commissioned
                                                                                                         conjunction with Art. 47 GDPR);
     maintenance that apply to all system contracts concluded between the
                                                                                                   -     Standard data protection clauses (Art. 46 section 2 lit. c and lit. d
     Client and the Contractor. Binding components of this agreement are
                                                                                                         GDPR);
      -     Annex 1: Subject-matter of the data processing                                         -     approved codes of conduct (Art. 46 section 2 lit. e in conjunction with
      -     Annex 2: Security of processing                                                              Art. 40 GDPR);
      -     Annex 3: Contact persons                                                               -     approved certification mechanisms (Art. 46 section 2 lit. f. in
      -     Annex 4: Subcontractors                                                                      conjunction with Art. 42 GDPR); or
      -     Annex 5: Notification form for data protection breaches                                -     other measures (Art. 46 section 2 lit. a., section 3 lit. a and lit. b
3.3. The provisions of this agreement, including its annexes, shall take                                 GDPR).
     precedence over any contradictory provisions of a system contract.
                                                                                             7.          Instructions from the Client
4.         Principles for data processing
                                                                                             7.1. Notwithstanding binding stipulations within the meaning of section 3.1 of
The Contractor processes personal data exclusively in accordance with the                         this Agreement, the Contractor acknowledges that the Client alone
system contract, in accordance with this agreement and within the scope of the                    determines the purposes of the data processing and may also order this
Client's instructions. Without limiting the foregoing restrictions on Contractor’s                by means of individual instructions, and that any processing by the
processing of the personal data, the Contractor:                                                  Contractor outside the intended purpose or an instruction is unlawful. Art.
                                                                                                  28 section 3 lit. a GDPR is decisive for exceptions to this.
      -     shall not “sell” the personal data, as such term is defined in the CCPA
            and similar U.S. state privacy laws;

 Data Processing Agreement                                                  Ver. 1.6 from 12/23/2024                                                                Page 1 of 8
 Essentry Inc.

7.2. Every instruction from the Client obliges the Contractor to carry out,                          documented measures will form the basis of the respective data
     tolerate or refrain from ("actions") every process specified in the instruction                 processing and will be used as Annex 2: Security of processing to this
     (e.g. collection, storage, transmission, deletion or destruction of personal                    agreement.
     data) in accordance with the instructions. The Client's right to issue                    10.3. The Contractor is free to prove the suitability of the technical and
     instructions includes, in particular, that the Client may lawfully determine                    organizational measures to be taken - in particular in accordance with Art.
     vis-à-vis the Contractor how the system contract is to be implemented in                        32 GDPR - by complying with approved rules of conduct in accordance
     terms of data protection law, as well as to request order-related information                   with Art. 40 GDPR or by complying with an approved certification
     and to request actions that may serve to fulfill a legal, sovereign or official                 procedure in accordance with Art. 42 GDPR. Proof can only be provided
     requirement to which the Client is subject.                                                     (and only for as long as) the Contractor presents the Client with a valid
7.3. Instructions must always be issued in writing (Section 126 BGB) or in text                      certificate issued by an accredited certification body in accordance with
     form (Section 126b BGB). Verbal instructions are only permissible in                            Art. 43 GDPR for those processing procedures and locations that are
     exceptional cases; they must be documented by the Contractor in writing                         relevant for the processing operations under this Agreement or the
     (Section 126 BGB) or text form (Section 126b BGB). The Contractor must                          corresponding system contract. The Contractor must notify the Client
     inform the Client immediately if it is of the opinion that an instruction                       immediately of any changes to the certificate or its expiry.
     violates data protection regulations. The Contractor shall be entitled to                 10.4. The submission of the aforementioned certification does not diminish the
     suspend the implementation of the corresponding instruction until it is                         Contractor's responsibility and does not replace the Contractor's obligation
     confirmed or amended by the Client.                                                             to guarantee that the requirements under this section 10 and the Annex
                                                                                                     2: Security of processing within the meaning of Art. 32 GDPR are in
8.          Adjustments and further development                                                      place as well as maintained and updated.
                                                                                               10.5. To increase the security and further development of the essentry app, the
8.1. When processing personal data, interpreting the requirements of the
                                                                                                     Contractor evaluates anonymized usage data. This information cannot be
     GDPR and interpreting this Agreement, the applicable recommendations
                                                                                                     assigned to any person and the Contractor does not merge this data with
     of the Art. 29 Working Party or its successor organization (European Data
                                                                                                     other data sources. For this purpose, the Contractor performs the
     Protection Board) must be taken into account appropriately.
                                                                                                     anonymization on behalf of the Client.
8.2. The Client and the Contractor agree to adapt and amend this Agreement,
                                                                                               10.6. The Contractor is permitted to take and implement a technical measure
     including annexes, by mutual agreement and free of charge for the Client
                                                                                                     other than one expressly described if the security level of the processing
     in the event of changes, adaptations and/or additions to data protection
                                                                                                     is thereby maintained or increased, and the measure is documented and
     regulations - in particular the GDPR and/or the applicable national
                                                                                                     communicated to the Client.
     implementation laws, the CCPA, or similar laws.
                                                                                               10.7. The Client shall be entitled at any time to demand compliance with the
                                                                                                     obligations and guarantees entered in this Clause in accordance with
9.          Duty of confidentiality
                                                                                                     section 16 to check. Any breaches of duty identified shall be remedied by
9.1. The Contractor guarantees that it has obligated the persons employed by                         the Contractor without delay.
     it for processing to maintain confidentiality and that it will also comply with
     this obligation through organizational precautions, in particular that                    11.         Subcontractor
     personal data will not be processed without authorization, only in
     accordance with the order or in accordance with instructions, and that this               11.1. The subcontracting of processing by the Contractor to a subcontractor is
     obligation will continue to apply even after the end of their activities (Art.                  not permitted unless the following conditions are met:
     28 section 3 lit. b); Art. 29; Art. 32 section 4 GDPR). The same applies to               11.1.1.     The Client has expressly consented to the subcontracting in writing
     other confidentiality and/or protection provisions under data protection law,                         (in this agreement or in a system contract).
     insofar as these are relevant to the processing.
                                                                                               11.1.2.     The Contractor has carefully selected the subcontractor and has
9.2. Upon request, the Client shall be provided with corresponding evidence                                given the Client a guarantee that the subcontractor will perform all
     free of charge. The Contractor is at liberty to provide evidence by                                   subcontracted services in accordance with all relevant provisions of
     complying with approved rules of conduct (Art. 40 GDPR) or by complying                               this Agreement and the relevant statutory provisions, including,
     with an approved certification procedure (Art. 42 GDPR), provided that this                           where applicable, the GDPR.
     shows that the persons involved in the processing in accordance with
                                                                                               11.1.3.     The Contractor has ensured through appropriate agreements with
     section 9.1 are obliged to maintain confidentiality.
                                                                                                           the subcontractor and demonstrated to the Client that the Client can
                                                                                                           also exercise all rights to which it is entitled vis-à-vis the Contractor
10.         Safety of processing                                                                           vis-à-vis the subcontractor during the term of the subcontracting; this
                                                                                                           also includes rights of inspection of documents and contracts
10.1. The Contractor confirms that it has taken the measures required in its area
                                                                                                           relevant to data protection and information about processes relevant
      of responsibility in accordance with Art. 32 GDPR. The Contractor
                                                                                                           to data protection law.
      undertakes to design and update its internal organization accordingly,
      taking into account the respective state of the art, the implementation costs            11.2. The processing, and in particular the transfer of personal data to or by the
      and the nature, scope and circumstances and purposes of the processing                         subcontractor, is only permitted (and only for as long as) the conditions set
      and the different probability of occurrence and severity of the risk to the                    out in section 11.1 are demonstrably fulfilled and the Client has not
      rights and freedoms of the data subjects, so that they comply with the                         withdrawn its consent in accordance with section 11.4 has revoked its
      special requirements of data protection under the GDPR and ensure the                          consent.
      protection of the rights of the data subjects. In general, the technical and             11.3. Subcontractors approved at the time of conclusion of this agreement
      organizational measures (TOM) to be taken include in particular                                between the Client and the Contractor are listed in Annex 4:
10.1.1.     protecting the confidentiality, integrity, availability and resilience of                Subcontractors and any addenda thereto shall be made in writing. The
            the systems and services in connection with the processing of the                        right to authorize subcontractors in the system contract remains
            data;                                                                                    unaffected.

10.1.2.     as appropriate, the encryption of personal data and, where possible,               11.4. The Client may revoke its consent to the use of a subcontractor in justified
            its pseudonymization;                                                                    cases - in particular in the event of a breach of law or other breach of duty.
                                                                                                     The Contractor shall immediately cease the subcontracting.
10.1.3.     the ability to quickly restore the availability of personal data and
            access to it in the event of a physical or technical incident;                     11.5. If the Client does not agree to the use of a new subcontractor or revokes
                                                                                                     its consent to an already approved subcontractor, both parties have a
10.1.4.     the implementation and maintenance of procedures to regularly
                                                                                                     special right to terminate the contract and this data processing agreement
            review, assess and evaluate the effectiveness of the technical and
                                                                                                     with one month's notice.
            organizational measures to ensure the security of the processing at
            intervals of no longer than twenty-four (24) calendar months.
                                                                                               12.         Rights of the data subjects
10.2. The Contractor shall present the measures to which it commits to the Client
      correctly, completely, and clearly in advance of the award of the contract,              12.1. The Client is responsible for safeguarding the rights of data subjects in
      document them with regard to the specific execution of the contract and                        accordance with Chapter 3 of the GDPR and other applicable law. The
      submit them to the Client for review. If accepted by the Client, the                           Contractor is only permitted to implement the rights of data subjects in

 Data Processing Agreement                                                    Ver. 1.6 from 12/23/2024                                                                Page 2 of 8
 Essentry Inc.

      accordance with the instructions of the Client. However, the Contractor is               14.6. Where required by law, the Contractor is obliged to appoint a data
      obliged to fully support the Client in fulfilling requests and claims of data                  protection officer who can carry out their activities in accordance with Art.
      subjects in accordance with Chapter 3 of the GDPR and other applicable                         37, 38 GDPR. The contact details of the data protection officer or another
      law.                                                                                           contact person for data protection issues - insofar as a data protection
12.2. If data subject rights are asserted directly against the Contractor, the                       officer is not to be appointed - shall be provided to the Client for the
      Contractor must forward the request to the Client without delay. If it is not                  purpose of direct contact.
      possible for the Contractor to identify the personal data of the individual
      making the request, the Contractor shall prove the lack of identifiability to            15.         Release of personal data
      the Client (including, where applicable, in accordance with Art. 11 section
      2 GDPR). If requests are not forwarded immediately, the Contractor shall                 15.1. The Contractor acknowledges that the Client must be entitled to demand
      be liable to the Client for any delays in processing requests from data                        the surrender of personal data from the Contractor at any time as a result
      subjects, considering the processing periods specified in Art. 12 section 3                    of its role as controller. The Contractor therefore guarantees the Client that
      GDPR or other applicable law, unless the Contractor is not responsible for                     it has taken technical and organizational measures to be able to fulfill the
      the delay.                                                                                     claim for surrender without delay and waives any objections and defenses
                                                                                                     against the claim for surrender.

13.         Reporting of data protection incidents                                             15.2. The right to disclosure includes all personal data processed by the
                                                                                                     Contractor under the responsibility of the Client, in particular personal data
13.1. The Contractor shall notify the Client in any case in which it becomes                         transmitted by the Client and personal data that has been changed,
      aware of (i) a breach of the protection of personal data by it or the persons                  created, or generated in the course of the performance of a system
      employed by it, (ii) a breach of regulations on the protection of personal                     contract.
      data or (iii) a breach of the provisions made in this Agreement (hereinafter             15.3. Once the Client has confirmed the successful release of the personal data
      "Data Protection Incident").                                                                   in writing or text form, it must be deleted immediately from the Contractor's
13.2. The notification must be made immediately, at the latest within forty-eight                    storage media in such a way that it can no longer be reproduced. The
      (48) hours of becoming aware of it.                                                            Contractor shall guarantee the corresponding deletion of this personal data
13.3. Upon becoming aware of a data protection incident, the Contractor shall                        on the storage media of any subcontractors. Upon request, the Contractor
      immediately take the necessary measures to secure the data and mitigate                        shall provide the Client with evidence that this deletion has been carried
      any adverse effects for the data subjects and the Client.                                      out by means of suitable documents or appropriate insurance. The above
                                                                                                     shall apply accordingly if the processing of personal data by the Contractor
13.4. The notification of a data protection incident must - as far as possible -                     ends, but the Client expressly waives the surrender to the Contractor and
      contain all information required by the Client to fulfill its obligations under                no agreement to the contrary has been made.
      Art. 33 and Art. 34 GDPR; in particular
                                                                                               15.4. The Contractor may store certain personal data in blocked form instead of
13.4.1.     a description of the nature of the personal data breach, including,                      deleting it, as long as and to the extent that the Contractor is subject to
            where possible, the categories and approximate number of data                            mandatory statutory provisions that oblige it to retain it. The lawfulness of
            subjects concerned, the categories concerned and the approximate                         access to blocked data is assessed according to the legal provision on the
            number of personal data records concerned;                                               basis of which the personal data had to be blocked.
13.4.2.     the name and contact details of the Contractor's data protection                   15.5. In the event of the removal or seizure of a storage medium by a third party
            officer or a person of the Contractor who can provide information on                     on which the Client's personal data is stored, or in the event of foreclosure
            the matter;                                                                              of such a storage medium by a third party, the Contractor shall immediately
13.4.3.     a description of the likely consequences of the personal data breach;                    inform both the third party of the fact that the Client's personal data is
13.4.4.     a description of the measures already taken and those proposed by                        located on the data carrier concerned and the Client of the corresponding
            the Contractor to address the personal data breach and, where                            measure. Any legal remedies of the Client against the measures of the
            appropriate, measures to mitigate its possible adverse effects.                          third party shall remain unaffected.

13.5. For reports, please use the form in attached hereto.Annex 5: Notification
      form for data protection breaches The Contractor is obliged to document                  16.         Control rights of the Client
      data protection incidents in detail, including their effects and the remedial
                                                                                               16.1. The Client has the right to take reasonable and appropriate steps to (a)
      measures taken. The documentation must be made available to the Client
                                                                                                     ensure that Contractor is using the personal data consistent with Client’s
      without delay.
                                                                                                     obligations under applicable law and (b) stop and remediate unauthorized
                                                                                                     use of the personal data. During the term of this agreement and until the
14.         Obligations of the Contractor to cooperate                                               general limitation period for claims arising from this agreement has
                                                                                                     expired, the Client shall have the right to carry out inspections or, in
14.1. With regard to its area of responsibility, the Contractor is obliged to keep
                                                                                                     individual cases, to have them carried out by third parties or auditors who
      detailed documentation on the processing of personal data and to make
                                                                                                     are obliged to maintain confidentiality. In particular, the Client shall have
      this available to the Client immediately upon first request. Based on the
                                                                                                     the right to satisfy itself of the Contractor's compliance with this Agreement
      documentation, the Client must be able to prove the correctness of the
                                                                                                     by means of random checks in its business operations during normal
      data processing in accordance with Art. 24 section 1 GDPR in a suitable
                                                                                                     business hours. The Contractor may assert a claim for remuneration for
      manner at any time.
                                                                                                     enabling the Client to carry out inspections.
14.2. With regard to its area of responsibility, the Contractor is obliged to provide
                                                                                               16.2. In deviation from section 16.1 the rights of control referred to in this clause
      the data and information required for the Client's process register in
                                                                                                     shall continue to exist beyond the term of this Agreement and the general
      accordance with Art. 30 (1) GDPR.
                                                                                                     limitation period to the extent that and for as long as the Contractor
14.3. The Contractor shall support the Client in complying with the obligations                      processes personal data in accordance with section 15.4 stores personal
      set out in Articles 32 to 36 of the GDPR and equivalent requirements in                        data.
      other applicable laws. in particular, those relating to the security of
                                                                                               16.3. This includes the right to enter the property, the business premises and the
      personal data, reporting obligations in the event of data breaches, data
                                                                                                     locations of the Contractor's information technology systems and to carry
      protection impact assessments and prior consultations. For this purpose,
                                                                                                     out inspections and tests there or have them carried out, as well as to
      the Contractor shall provide the Client with all documents, records and
                                                                                                     inspect business documents and stored data and data processing
      evidence required for Art. 32 - 36 GDPR and such other applicable laws.
                                                                                                     programs, insofar as this is necessary for order control.
14.4. The Client must be informed immediately of any inspections and measures
                                                                                               16.4. As a rule, inspections must be announced with a lead time of fourteen (14)
      taken by the supervisory authority or other government authority in relation
                                                                                                     days. In urgent cases, the Client may shorten the notice period to 24 hours.
      to the Client of the Client’s personal data, including in accordance with Art.
                                                                                                     An urgent case exists in particular in the case of inspections by data
      58 GDPR. This also applies if a competent authority investigates the
                                                                                                     protection supervisory authorities, other sovereign supervisory authorities
      Contractor.                                                                                    or in the case of any reportable incidents.
14.5. The Contractor is obliged to regularly check the performance of the                      16.5. The Contractor shall ensure that the Client or the auditors commissioned
      processing itself for conformity with this agreement. If errors or
                                                                                                     by the Client can satisfy themselves that the Contractor is complying with
      irregularities are discovered during the inspection, the Client must be
                                                                                                     its obligations under Art. 28 GDPR.
      informed immediately.

 Data Processing Agreement                                                    Ver. 1.6 from 12/23/2024                                                                Page 3 of 8
 Essentry Inc.

17.         Obligations of the Client                                                                  necessary. If the adjustment is refused by the Contractor or its conclusion
                                                                                                       is delayed, the Client may terminate the contract extraordinarily or withhold
17.1. The Client shall be responsible for compliance with the statutory provisions                     payments to the Contractor, regardless of the legal relationship, until the
      applicable to it regarding the protection of personal data.                                      necessary adjustment agreement has been concluded. "Change of
17.2. The Client shall inform the Contractor immediately and in full if it discovers                   ownership" means any change in control of the Contractor, whether as a
      errors or irregularities with regard to data protection regulations when                         result of the acquisition of voting rights, conversions or agreements. The
      checking the processing results.                                                                 above shall apply accordingly to subcontractors of the Contractor.
17.3. If the Client is subject to the GDPR, the Client is obliged to keep a record            18.2. The partial or complete assignment or transfer of claims, rights and
      of processing activities in accordance with Art. 30 GDPR. The Contractor's                    obligations arising from this agreement by the Contractor is not permitted
      obligation to keep its own record of processing activities in accordance with                 unless the Client has given its prior written consent. § Section 354a HGB
      Art. 30 (2) GDPR remains unaffected by this.                                                  remains unaffected.
17.4. The Client shall designate a contact person responsible for data protection             18.3. Any amendment to this agreement must be made in writing to be effective.
      issues arising within the scope of the contract and provide their contact                     This also applies to any waiver of the written form requirement itself.
      details for the purpose of direct contact.                                              18.4. The law of the Federal Republic of Germany shall apply to the exclusion
                                                                                                    of the UN Convention on Contracts for the International Sale of Goods.
18.         Other obligations and provisions                                                  18.5. The place of jurisdiction for all disputes arising from or in connection with
                                                                                                    this agreement and data protection-related disputes arising from system
18.1. The Contractor shall inform the Client as soon as a change of ownership,
                                                                                                    contracts is Frankfurt am Main. The Client shall also be free to assert any
      as defined below, is likely to occur. Insofar as the change of ownership
                                                                                                    claims arising from this agreement at the court with subject-matter and
      requires an adjustment to this Agreement under the law of the European
                                                                                                    local jurisdiction for the Contractor's registered office. Statutory regulations
      Union or the Federal Republic of Germany applicable to the Client, the
                                                                                                    on exclusive jurisdiction remain unaffected
      Contractor shall agree the adjustment with the Client to the extent

                                                                                              2.3. The Contractor shall anonymize and evaluate data from the essentry
Annex 1: Subject-matter of the data processing
                                                                                                   platform for the purpose of providing statistical overviews to the Client. This
                                                                                                   data is anonymized in accordance with the anonymization method of k-
1.          Subject-matter of the data processing                                                  anonymity. The k=7 anonymization method is used. This means that 7
                                                                                                   different data records of each category of data are required for them to be
1.1. Digital access management: programming, customization, provision,                             included in the statistical analysis.
1.2. and operation of the software for digital access management. Hosting,
     support, and maintenance of the software. Project management and
                                                                                              3.            Type of personal data
     training.
                                                                                              3.1.1.         List of those affected
2.          Nature and purpose of processing                                                                The following groups of persons are affected by data processing:

2.1. Purpose of processing: Digital access management including identity                           -        Employees of the Client
     verification of authorized persons and other persons with temporary                           -        Authorized persons, interested parties, customers, suppliers and
     access authorization.                                                                                  service providers of the Client
2.2. Type of processing:                                                                      3.1.2.         Data categories
      -     Recording the names and identification features of individuals who                              The following types or categories of data are subject to collection,
            wish to enter a site, building or part of a building of the Client                              processing and/or use by the Contractor:
      -     Verification of government issued photo ID documents
      -     Capture a photograph of the person for comparison with the ID
            document
      -     Recording information on the issue of access media issued to these
            persons and assigned access profiles
      -     Storage of this data for a period specified by the Client

                                                                                                                           Data type according to
No.          Data field name                                                             Group of people
                                                                                                                           deletion concept

001          First name                                                                  Authorized persons                Master data of the authorized persons

002          Surname                                                                     Authorized persons                Master data of the authorized persons

003          Company                                                                     Authorized persons                Master data of the authorized persons

004          Email address                                                               Authorized persons                Master data of the authorized persons

005          Date of birth (optional, can be deactivated)                                Authorized persons                Master data of the authorized persons

006          ID number (optional, can be deactivated)                                    Authorized persons                Master data of the authorized persons

             Cut-out photograph of the authorized person from the identification                                           Cut-out photograph of the authorized person from
007                                                                                      Authorized persons
             document                                                                                                      the identification document

                                                                                                                           Photo of the authorized person taken by the self-
008          Photo of the authorized person taken by the self-service kiosk              Authorized persons
                                                                                                                           service kiosk

                                                                                         Users / employees / access
009          First name                                                                                                    Employee data
                                                                                         managers

                                                                                         Users / employees / access
010          Surname                                                                                                       Employee data
                                                                                         managers

 Data Processing Agreement                                                   Ver. 1.6 from 12/23/2024                                                                 Page 4 of 8
 Essentry Inc

                                                                                                                       Data type according to
No.         Data field name                                                            Group of people
                                                                                                                       deletion concept

                                                                                       Users / employees / access
011         Email address                                                                                              Employee data
                                                                                       managers

                                                                                       Users / employees / access
012         Password                                                                                                   Employee data
                                                                                       managers

                                                                                       Authorized persons /
013         Start time of the appointment                                              persons responsible for         Access data
                                                                                       access

                                                                                       Authorized persons /
014         End time of the appointment                                                persons responsible for         Access data
                                                                                       access

                                                                                       Authorized persons /
015         Check-in time                                                              persons responsible for         Access data
                                                                                       access

                                                                                       Authorized persons /
016         Check-out time                                                             persons responsible for         Access data
                                                                                       access

                                                                                       Authorized persons /
017         Name of the person responsible for access                                  persons responsible for         Access data
                                                                                       access

                                                                                       Authorized persons /
018         Location of the appointment                                                persons responsible for         Access data
                                                                                       access

If necessary, further user-defined data fields can be collected, processed and stored as part of the "master data of authorized persons" if the customer's administrator
activates further data in the essentry SaaS platform for querying at the self-service kiosk or the reception dashboard.

Annex 2: Security of processing                                                                  -       HTTPS is used for the connection from the user's browser to the
                                                                                                         essentry servers. The specific version of the protocol and the type of
                                                                                                         encryption depend on the browser used. The essentry servers only
1.         Pseudonymization and encryption of personal data                                              accept secure protocols.
           (Art. 32 section 1 lit. a GDPR)
1.1. Pseudonymization: Processing of personal data in such a way that the                   2.           Measures to protect confidentiality (Art. 32 section 1
     personal data can no longer be attributed to a specific data subject without                        lit. b GDPR)
     the use of additional information, provided that this additional information
     is kept separately and is subject to technical and organizational measures.            2.1. Access control: Technical and organizational measures for access
                                                                                                 control, in particular for the legitimation of authorized persons:
           Description of the measures taken:
                                                                                                         Description of the measures taken:
      -    No direct pseudonymization of personal data can take place in order
           to fulfill the purpose of the order.                                                      -   Protection of physical access to data centers through structural
                                                                                                         measures and a locking system
      -    Evaluations and queries for statistical purposes, are carried out
           anonymously.                                                                              -   Personal reception of customers and authorized persons

      -    The application collects pseudonymized usage and traffic data on the                      -   Authorized persons are accompanied or supervised
           server side. This information is not merged with the bearer (user) of                     -   Sensitive company areas and rooms in which no employees are
           the pseudonym except for provision of the service features that                               working are locked
           require this.                                                                                 Organizational measures:
1.2. Encryption: Use of procedures and algorithms that convert the content of                        -   internal documentation and specifications for contract fulfillment, e.g.
     personal data into a non-readable form using digital or electronic codes or                         internal guidelines and instructions on data security and data
     keys. Symmetric and asymmetric encryption techniques can be used:                                   protection

           Description of the measures taken:                                                        -   Internal documentation and guidelines on data protection and data
                                                                                                         security
      -    Encryption of all data "in transit" (during transmission) and "at rest"
                                                                                            2.2. Access control: Technical (password / password protection) and
           (stored on the hard disk). Only strong cryptographic methods are
                                                                                                 organizational (user master data record) measures with regard to user
           used.
                                                                                                 identification and authentication:
      -    The Cloud KMS (Key Management Service) is used to store the keys
                                                                                                         Description of the measures taken:
           of the encrypted databases. This protects the keys on special
           hardware security modules (HSMs). The keys do not leave these                             -   The data processing systems are protected against unauthorized
           hardware modules and access to them is fully logged.                                          use by log-in and authorization procedures.
      -    TLS encryption                                                                            -   Password security includes personalized and automated login
      -    cloud.google.com/security                                                                     procedures.
      -    images.apple.com/business/docs/iOS_Security_Guide.pdf                                     -   Length and complexity requirements for passwords.
      -    android.com/intl/en_en/security-center/

 Data Processing Agreement                                                 Ver. 1.6 from 12/23/2024                                                                Page 5 of 8
 Essentry Inc.

      -     Access to the essentry SaaS platform via mobile systems and end                        -     Every change to the configuration is first tested on the test systems
            devices only takes place via secure and encrypted lines and                                  and changes are saved in log files for traceability. Regular security
            connections.                                                                                 scans of the servers are performed. Basic configurations of the
2.3. Access control: Demand-oriented design of the authorization concept                                 communication paths between instances are carried out by defined
     and access rights as well as their monitoring and logging:                                          administrators.

            Description of the measures taken:                                                4.2. Availability of the IT systems used
                                                                                                         Description of the measures taken:
      -     Access authorizations for employees to the IT systems are assigned
            restrictively.                                                                         -     Reasonable measures for fire protection, power supply, air
      -     Our employees only receive the authorizations that they actually                             conditioning, data backup, disaster recovery, etc. have been taken
            need for their work.                                                                         for our IT systems as part of an emergency concept.
      -     Employee access authorizations to the servers with customer data                       -     The Kubernetes cluster scheduler distributes the instances of the
            are restricted to what is absolutely necessary in accordance with the                        software in such a way that the different instances always run on
            principles of need-to-know and least privilege. Developers only have                         different servers. A hardware defect therefore generally does not
            access to test systems on which they can test new features. Only                             lead to the essentry system becoming unavailable.
            tested new features are transferred by an admin to the servers on                      -     The Client's customer data is processed in the Google Cloud.
            which essentry is running.                                                                   Reference is made here to Google's availability and resilience
      -     essentry servers are protected against hacking attacks by several                            measures.
            defense mechanisms including a firewall.                                                     cloud.google.com/compute/
                                                                                                         cloud.google.com/storage/
2.4. Separation control: Measures for separate processing (storage,
     modification, deletion, transmission) of data with different purposes:
                                                                                              5.         Measures to restore the availability of and access to
           Description of the measures taken:
                                                                                                         personal data in the event of a technical incident (Art.
      -     Data is stored on Google Cloud IT systems that are logically                                 32 lit. c GDPR)
            separate from data of other Google Cloud customers.
            cloud.google.com/security/                                                        5.1. Recovery / backup systems
                                                                                                         Description of the measures taken:
3.         Measures to protect integrity (Art. 32 section 1 lit. b
                                                                                                   -     Appropriate measures for fire protection, power supply, air
           GDPR)                                                                                         conditioning, data backup, disaster recovery, etc. have been taken
                                                                                                         for our IT systems as part of an emergency concept. A recovery time
3.1. Transfer control: Measures during transportation, transfer and
                                                                                                         of 24 hours is guaranteed.
     transmission or storage on data carriers (manually or electronically) as well
     as during subsequent verification:                                                            -     The Client's customer data is processed in the Google Cloud. Google
                                                                                                         guarantees an availability of over 99.99%. In addition, reference is
           Description of the measures taken:
                                                                                                         made to the measures taken by Google to restore availability.
      -     Transport encryption (TLS) is implemented for the transfer of                                cloud.google.com/compute/
            personal data from the respective end device to the server.                                  cloud.google.com/storage/
      -     A subsequent check of the transfer control can also be carried out
            by viewing the log files.                                                         6.         Procedure for the regular review, assessment, and
3.2. Input control: Measures to subsequently check whether and by whom                                   evaluation of technical and organizational measures;
     data has been entered, changed or removed (deleted):                                                data protection by default (Art. 32 section 1 lit. d
           Description of the measures taken:                                                            GDPR; Art. 25 section 1 GDPR)
      -     A subsequent check of the input control can also be carried out by                6.1. Data protection management
            viewing the log files.
                                                                                                         Description of the measures taken:

4.         Availability and resilience of systems and services
                                                                                                   -     A data protection management system (DPMS) is in use. The DPMS
                                                                                                         is provided by the Contractor's data protection officer and operated
           (Art. 32 lit. b GDPR)                                                                         together with the Contractor. Our procedures are regularly reviewed,
4.1. Availability control                                                                                assessed, and evaluated as part of resubmissions and regular
                                                                                                         meetings. Depending on the type of processing, these measures are
           Description of the measures taken:                                                            carried out after 3, 6 or a maximum of 12 months.
      -     The data backups of our IT systems are carried out according to a                 6.2. Data protection-friendly default settings (Privacy by Default)
            binding data backup concept. A backup of the databases is made
                                                                                                         Description of the measures taken:
            daily between 1:00 am and 3:00 am. It is stored for 30 days and is
            encrypted with AES256.                                                                 -     Default settings are protective of data. Client-specific development
                                                                                                         is carried out on the instructions of the Client. Data subjects can
      -     The Client's customer data is processed in the Google Cloud.
                                                                                                         obtain information about the use of their data at any time when using
            Reference is made here to Google's availability and resilience
                                                                                                         the software/app with the help of the data protection declaration.
            measures.
            cloud.google.com/compute/                                                              -     The Client specifies the categories of data to be collected.
            cloud.google.com/storage/                                                         6.3. Order control: Measures (technical / organizational) to delimit the
      -     The files requiring storage are stored redundantly at different                        competencies between Client and Contractor:
            locations to prevent loss. In addition, certain critical objects are                         Description of the measures taken:
            versioned, which means that the replacement or deletion of a file is
            logged and the old file is not lost but remains stored. All stored files               -     When processing personal data, contracts are concluded with
            are encrypted with AES256.                                                                   subcontractors in accordance with Art. 28 GDPR / EU Model
                                                                                                         Clauses.
      -     In the Google Cloud, computing capacity is automatically increased
            in the event of a sharp increase in requests or users.

 Data Processing Agreement                                                   Ver. 1.6 from 12/23/2024                                                               Page 6 of 8
 Essentry Inc.

Annex 3: Contact persons
Responsible and authorized persons of the Client and Contractor. Contractor: Essentry GmbH

Instruction recipient                    Name                             Email                                           Phone

CEO                                      Dr. Dennis Lips                  [email protected]                        will be announced separately

CTO                                      Christian Böhlke                 [email protected]                  will be announced separately

Other functions                          Name                             Email                                           Phone

External Data Protection Officer         Philipp Rothmann
                                                                          [email protected]                            will be announced separately
External Information Security Officer    Philipp Rothmann

Client shall inform Contractor of the persons responsible and authorized to issue instructions accordingly.

Annex 4: Subcontractors
Overview of all subcontractors working for the Contractor who directly collect, process and/or use the Client's data.
The following subcontractors work with the consent of the Client:
Subcontracting taker        Address                                 Field of activity
                            Gordon House, Barrow Street
Google Ireland Limited                                              Hosting of the databases and servers in Germany.
                            Dublin, D04 E5W5, Ireland

Amazon Web Services         38 Avenue John F. Kennedy               Sending e-mails and generating name tags for the printer; photo comparison;
EMEA SARL                   1855, Luxembourg                        data processing takes place within the EU

                            Stanisla-Kist-Str. 14A                  Management of kiosk devices including the installation of app and system updates, assignment of
Cubefinity GmbH
                            94330 Aiterhofen                        customer and location-specific profiles and remote monitoring in the event of problems and other
Product NinjaOne
                            Deutschland                             support cases. Data processing and storage takes place in the EU.

                            375 Beale Street
                            Suite 300                               Sending SMS and (video) telephony service. The subcontractor can only be used if the functionality is
Twilio Inc.
                            San Francisco                           explicitly ordered.
                            CA 94105, USA

 Data Processing Agreement                                                Ver. 1.6 from 12/23/2024                                                            Page 7 of 8
 Essentry Inc.

Annex 5: Notification form for data protection breaches

____________________________________________
Name (Contractor)                      Address (Contractor)

____________________________________________
Name (Client)                          Address (Client)

                                                                                                 More detailed description of the contractual relationship concerned:

Period of the incident (date, time):

Description of the data protection incident:
(personal data breach)

Personal data concerned:
(according to data categories)

Number of persons affected (approximate):

Number of data records affected (approximate):

Affected IT systems:

Responsible department / responsible IT department if applicable:

Name and contact details of the data protection officer or other contact point:

Author and date of the message:

Who has already been informed and by whom:
(e.g. data protection officer, data protection supervisory authority, etc.)

Learn about this through (source):

Description of the likely consequences of the data protection incident:

Description of the immediate measures taken by the Contractor to rectify the problem:

Proposal for measures to be taken:

Measures to mitigate possible adverse effects:

Overall risk:

Legally binding confirmation of the correctness and completeness of the above information:

__________________________________________________________________
Place, date                                       Signature                         Signature (Data Protection Officer)

 Data Processing Agreement                                                    Ver. 1.6 from 12/23/2024                                                      Page 8 of 8