Third Party Index

Snapshot 35800

Document
Data processing addendum
URL
https://assets.freebusy.io/assets/freebusy.io/FreeBusy-Data-Processing-Addendum.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
277699 bytes
SHA-256 (raw)
dd905cb2007bd748c0818e33f01b843bb0920ec2fb08251cbb94f4f0c98e1b98
SHA-256 (normalized text)
7aeeec5dd9c9ec350daa39476d6160e13662046afbf16cd3a81c1cc60c690cd8

Normalized text

Scripts and page chrome removed; this is what change detection compares.

                                                     FREEBUSY, INC

                                           DATA PROCESSING ADDENDUM

This Data Processing Addendum (this "DPA") is made as of the last date set forth on the signature page hereto (the
“Effective Date”) by and between FreeBusy, Inc., a corporation organized and existing under the laws of the State of
Washington, U.S.A. ("FreeBusy"), and the entity or person set forth on the signature page hereto ("Customer"),
pursuant to the Agreement (as defined below). This DPA will be void ab initio, with no force or effect, if the entity or
person signing this DPA is not a party to an effective Agreement (as defined below) directly with FreeBusy. FreeBusy
and Customer are sometimes referred to herein individually as a "party" or together as the "parties".

This DPA is supplemental to the Agreement and sets out the terms that apply when Personal Data is processed by
FreeBusy under the Agreement.

1. Definitions

1.1 For the purposes of this DPA, the following terms shall have their respective meanings set forth below and other
capitalized terms used but not defined in this DPA have the same meanings as set forth in the Agreement:

(a)      "Agreement" means the Terms of Service or SaaS Agreement, as applicable, between the parties, in each
         case providing for the provision by FreeBusy to Customer of the services described therein.

(b)      “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control
         with the subject entity, where “control” refers to the power to direct or cause the direction of the subject entity,
         whether through ownership of voting securities, by contract or otherwise.

(c)      "EEA" means the European Economic Area (including the United Kingdom).

(d)      "EU Data Protection Legislation" means Regulation 2016/679 of the European Parliament and of the Council
         on the protection of natural persons with regard to the processing of personal data and on the free movement
         of such data, and repealing Directive 95/46/EC ("GDPR") (as amended, replaced or superseded).

(e)      "California Consumer Privacy Act" means the California Consumer Privacy Act of 2018 and any subsequent
         amendments (“CCPA”).

(f)      “Virginia Consumer Data Protection Act” means the Virginia Consumer Data Protection Act of 2021 and
         any subsequent amendments (“VCDPA”).

(g)      “Brazilian General Data Protection Law“ means the Lei Geral de Proteção de Dados that went into effect in
         2020 in Brazil (“LGPD”)

(h)      “Standard Contractual Clauses” or “SCCs” means, depending on the circumstances unique to Customer,
         the EU 2021 Standard Contractual Clauses ("EU SCCs") or UK International Data Transfer Addendum.

(i)      "Controller" means the entity which, alone or jointly with others, determines the purposes and means of the
         processing of Personal Data.

(j)      "Processor" means an entity which processes Personal Data on behalf of the Controller.

(k)      "Personal Data" means any information relating to an identified or identifiable natural person.

(l)      "Security Incident" has the meaning given in the GDPR.

(m)      "Sensitive Data" means (a) social security number, passport number, driver's license number, or similar
         identifier (or any portion thereof), (b) credit or debit card number (other than the truncated (last four digits) of a
         credit or debit card), (c) employment, financial, genetic, biometric or health information; (d) racial, ethnic,
         political or religious affiliation, trade union membership, or information about sexual life or sexual orientation;
         (e) account passwords; (f) date of birth; (g) criminal history; (h) mother's maiden name; and (i) any other
         information that falls within the definition of "special categories of data" under EU Data Protection Legislation,
         California Consumer Privacy Act or any other applicable law relating to privacy and data protection.
2. Relationship with Agreement

2.1 Except as amended by this DPA, the Agreement will remain in full force and effect.

2.2 If there is a conflict between the Agreement and this DPA, the terms of this DPA will control.

2.3 Any claims brought under this DPA shall be subject to the terms and conditions, including but not limited to, the
exclusions and limitations set forth in the Agreement.

3. Applicability of this DPA

3.1 Applicability. This Addendum only applies to the extent that FreeBusy is processing Personal Data from the EEA,
California, Virginia, or Brazil on behalf of Customer. If the EU Data Protection Legislation, LGPD, VCDPA, CCPA apply
to the processing of Customer Personal Data, the parties acknowledge and agree that:
•   the subject matter and details of the processing are described in Annex A, as amended from time to time;
•   FreeBusy is a processor of that Personal Data under the EU Data Protection Legislation, VCDPA, or LGPD, and/or
    a Service Provider with respect to that Personal Data under the CCPA, as applicable;
•   Customer is a either a controller or processor of that Personal Data under EU Data Protection Legislation, VCDPA,
    or LGPD, and/or a Business with respect to that Personal Data under the CCPA, as applicable; and
•   each party will comply with the obligations applicable to it under the applicable Global Data Protection Legislation
    with respect to the processing of that Personal Data.

3.2 GDPR. The parties agree that Annex B to this DPA will apply only on and after 4 June 2021. Where the GDPR
materially or adversely impacts FreeBusy's continued provision of the Services (including its costs in providing the
Services) and / or Customer's receipt of the Services, the Parties shall discuss in good faith and acting reasonably what
changes may be necessary and operationally, technically and commercially feasible to the Agreement and/or the DPA
and/or the Services (including, without limitation, the fees payable by Customer to FreeBusy for the Services) in order
to enable FreeBusy to continue providing the Services. No such changes shall be effective unless agreed between the
Parties pursuant to this Clause.

3.3. Authorization by Third Party Controller. Authorization by Third Party Controller. If the EU Data Protection Legislation
applies to the processing of Personal Data and Customer is a processor, Customer warrants to FreeBusy that
Customer’s instructions and actions with respect to that Personal Data, including its appointment of FreeBusy as another
processor and its consent to FreeBusy’s onward transfers of Personal Data to its Subprocessors, have been authorized
by the relevant controller.

3.4 Service Data. Notwithstanding anything in this DPA, FreeBusy will have the right to collect, extract, compile,
synthesize and analyze aggregated, non-personally identifiable data or information (data or information that does not
identify Customer or any other entity or natural person as the source thereof) resulting from Customer's use or operation
of the Services (“Service Data”) including, by way of example and without limitation, information relating to volumes,
frequencies, recipients, scheduling, rescheduling, and cancellation rates, or any other information regarding the calendar
data and other communications Customer, its end users or recipients generate and send using the Services. To the
extent any Service Data is collected or generated by FreeBusy, such data will be solely owned by FreeBusy and may
be used by FreeBusy for any lawful business purpose without a duty of accounting to Customer or its recipients. For the
avoidance of doubt, this DPA will not apply to Service Data.

4. Roles and responsibilities

4.1 Parties' Roles. Customer, as Controller, appoints FreeBusy as a Processor to process the Personal Data described
in Annex A on Customer's behalf.

4.2 Purpose Limitation. FreeBusy shall process the Personal Data for the purposes described in Annex A and only in
accordance with the lawful, documented instructions of Customer, except where otherwise required by applicable law.
The Agreement and this DPA sets out Customer's complete instructions to FreeBusy in relation to the processing of the
Personal Data and any processing required outside of the scope of these instructions will require prior written agreement
between the parties.
4.3 Prohibited Data. Customer will not provide (or cause to be provided) any Sensitive Data to FreeBusy for processing
under the Agreement, and FreeBusy will have no liability whatsoever for Sensitive Data, whether in connection with a
Security Incident or otherwise. For the avoidance of doubt, this DPA will not apply to Sensitive Data.

4.4 Description of Processing. A description of the nature and purposes of the processing, the types of Personal Data,
categories of data subjects, and the duration of the processing are set out further in Annex A.

4.5 Compliance. Customer shall be responsible for ensuring that:

(a)      it has complied, and will continue to comply, with all applicable laws relating to privacy and data protection,
         including EU Data Protection Legislation or California Consumer Privacy Act (as applicable), in its use of the
         Services and its own processing of Personal Data (except as otherwise required by applicable law); and

(b)      it has, and will continue to have, the right to transfer, or provide access to, the Personal Data to FreeBusy for
         processing in accordance with the terms of the Agreement and this DPA.

5. Security

5.1. FreeBusy’s Security Measures. FreeBusy will implement and maintain technical and organizational measures to
protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access
to Personal Data. FreeBusy may update or modify the Security Measures from time to time provided that such updates
and modifications do not materially decrease the overall security of the Services.

5.2. Security Compliance by FreeBusy Staff. FreeBusy will grant access to Customer Personal Data only to employees,
contractors and Subprocessors who need such access for the scope of their performance and are subject to appropriate
confidentiality arrangements.

5.3. FreeBusy’s Security Assistance. FreeBusy will (taking into account the nature of the processing of Personal Data
and the information available to FreeBusy) provide Customer with reasonable assistance necessary for Customer to
comply with its obligations in respect of Personal Data under Global Data Protection Legislation, including but not limited
to: (i) Articles 32 to 34 (inclusive) of the GDPR; (ii) Section 59.1-579 of VCDPA; and (iii) Articles 6 and 46 of the LGPD

6. International transfers

6.1 International Transfers. Customer (as "data exporter") and FreeBusy (as "data importer") hereby enter into the
Standard Contractual Clauses attached hereto in respect of any Personal Data that FreeBusy processes (or causes to
be processed) in a country that has not been designated by the European Commission as providing an adequate level
of protection for Personal Data.

7. Security Incidents

7.1 Security Incidents. Upon becoming aware of a Security Incident, FreeBusy shall notify Customer without undue
delay and shall provide such timely information as Customer may reasonably require, including to enable Customer to
fulfil any data breach reporting obligations under EU Data Protection Legislation. FreeBusy shall take appropriate and
commercially reasonable steps to mitigate the effects of such a Security Incident on the Personal Data under this
Agreement.

8. Sub-processing

8.1 Sub-processors. Customer agrees that FreeBusy may engage FreeBusy affiliates and third party sub-processors
(collectively, "Sub-processors") to process the Personal Data on FreeBusy's behalf. The Sub-processors currently
engaged by FreeBusy and authorized by Customer are listed in the Privacy Policy. Customer shall be notified by
FreeBusy in advance of any new Sub-processor being appointed or authorized to process Customer Personal Data.

8.2 Objection to Sub-processors. Customer may object in writing to the appointment of an additional Sub-processor
within five (5) calendar days after receipt of FreeBusy's notice in accordance with the mechanism set out at Section 8.1
above. In the event that Customer objects on reasonable grounds relating to the protection of the Personal Data, then
the parties shall discuss commercially reasonable alternative solutions in good faith. If no resolution can be reached,
FreeBusy will, at its sole discretion, either not appoint Sub-processor, or permit Customer to suspend or terminate the
affected FreeBusy service in accordance with the termination provisions of the Agreement, before the new Sub-
processor shall be authorized to process Customer Personal Data. For the avoidance of doubt, if Agreement is
terminated under this Section 8.2. any unused or prepaid fees will not be refunded.

8.3 Sub-processor obligations. Where a Sub-processor is engaged by FreeBusy as described in this Section 8,
FreeBusy shall:

(a)      restrict the Sub-processor’s access to Personal Data only to what is necessary to perform the subcontracted
         services;

(b)      impose on such Sub-processors in writing data protection terms that are substantially the same as provided
         for by this DPA; and

(c)      remain liable for any breach of the DPA caused by a Sub-processor.

9. Cooperation

9.1 Cooperation and data subjects' rights. FreeBusy shall, taking into account the nature of the processing, provide
reasonable assistance to Customer insofar as this is possible, to enable Customer to respond to requests from a data
subject seeking to exercise their rights under EU Data Protection Legislation. In the event that such request is made
directly to FreeBusy, FreeBusy shall promptly inform Customer of the same.

9.2 Data Protection Impact Assessments. FreeBusy shall, to the extent required by EU Data Protection Legislation and
at Customer’s expense, taking into account the nature of the processing and the information available to FreeBusy,
provide Customer with commercially reasonable assistance with data protection impact assessments or prior
consultations with data protection authorities that Customer is required to carry out under EU Data Protection Legislation.

10. Audits

10.1 Audits. Whilst it is the parties' intention ordinarily to rely on the provision of the documentation to verify FreeBusy's
compliance with this DPA, FreeBusy shall permit the Customer (or its appointed third-party auditors) to carry out an
audit of FreeBusy processing of Personal Data under the Agreement following a Security Incident suffered by FreeBusy,
or upon the instruction of a data protection authority. Any such audit shall be subject to FreeBusy's security and
confidentiality terms. If FreeBusy declines to follow any instruction requested by Customer regarding audits, Customer
is entitled to terminate this DPA and the Agreement.

10.2. Objections to Third Party Auditor. FreeBusy may object to the auditor if the auditor is, in FreeBusy’s reasonable
opinion, not suitably qualified or independent, a competitor of FreeBusy, or otherwise manifestly unsuitable. Such
objection by FreeBusy will require Customer to appoint another auditor.

10.3. Request for Audit. To request an audit, Customer must submit a detailed proposed audit plan to FreeBusy at least
one month in advance of the proposed audit date. The proposed audit plan must describe the proposed scope, duration,
and start date of the audit. FreeBusy will review the proposed audit plan and provide Customer with any concerns or
questions (for example, any request for information that could compromise FreeBusy security, privacy, employment or
other relevant policies). FreeBusy will work cooperatively with Customer to agree on a final audit plan. Nothing in this
Section 10 (Audits) shall require FreeBusy to breach any duties of confidentiality.

10.4. Conduct of Audit. The audit must be conducted during regular business hours at the applicable facility, subject to
the agreed final audit plan and FreeBusy’s health and safety or other relevant policies, and may not unreasonably
interfere with FreeBusy business activities.

10.5. Conditions of Audit. Customer will promptly notify FreeBusy of any non-compliance discovered during the course
of an audit and provide FreeBusy any audit reports generated in connection with any audit under this Section 10 (Audits),
unless prohibited by applicable Global Data Protection Legislation or otherwise instructed by a supervisory authority.
Customer may use the audit reports only for the purposes of meeting Customer’s regulatory audit requirements and/or
confirming compliance with the requirements of this Addendum. The audit reports and any FreeBusy information shared
during the audit process are Confidential Information of the parties to the extent permissible by applicable Global Data
Protection Legislation, and may only be used by or disclosed to persons or entities who have a need to know in
connection with the performance of an audit requested under this Section 10.
10.6. Expenses of Audit. Any audits are at Customer’s expense. Customer shall reimburse FreeBusy for any time
expended by FreeBusy or its Subprocessors in connection with any audits or inspections under this Section 10 (Audits)
at FreeBusy’s then-current professional services rates, which shall be made available to Customer upon request.
Customer will be responsible for any fees charged by any auditor appointed by Customer to execute any such audit.

10.7. Standard Contractual Clauses. The parties agree that this Section 10 (Audits) shall satisfy FreeBusy’s obligations
under the audit requirements of the 2021 Standard Contractual Clauses (as defined in Appendix B) applied to Data
Importer under Clause 8 and Clause 13(a) and to any Subprocessors under Clause 9.

10.8 Information Requests. FreeBusy shall further provide written responses (on a confidential basis) to all reasonable
requests for information made by Customer, including responses to information security and audit questionnaires that
are necessary to confirm FreeBusy's compliance with this DPA or applicable law.

11. Deletion / return of data

11.1 Deletion or return of data: Upon termination or expiry of the Agreement, or at Customer’s reasonable request,
FreeBusy shall at Customer’s election, delete or return to Customer the Personal Data (including copies) in FreeBusy's
possession (and procure the deletion/return of such data), save to the extent that FreeBusy is required by any applicable
law to retain some or all of the Personal Data.

12. Liability

12.1. Liability Cap. The total combined liability of either party and its Affiliates towards the other party and its Affiliates,
whether in contract, tort or any other theory of liability, under or in connection with the Agreement, this Addendum, and
the Standard Contractual Clauses if entered into, will be limited to limitations on liability or other liability caps agreed to
by the parties in the Agreement, subject to Section 11.2 (Liability Cap Exclusions).

12.2. Liability Cap Exclusions. Nothing in Section 11.1 (Liability Cap) will affect any party’s liability to data subjects under
the third party beneficiary provisions of the Standard Contractual Clauses to the extent limitation of such rights is
prohibited by the European Data Protection Legislation.

                                               [Signatures on Following Page]
SIGNED by the parties or their duly authorized representatives:

Customer Execution:

Name: ……………………………………….

Position: ………………………………………

Address: ……………………………………….

Signature……………………………………….

FreeBusy Execution:

Name: Stefan Negritoiu

Position: CEO

Address: 440 N Barranca Ave Suite 2890, Covina CA 91723

Signature……………………………………….
                                                      ANNEX A

                                          DESCRIPTION OF PROCESSING

Nature and purposes of processing

FreeBusy is a USA-headquartered, cloud-based provider of solutions for automated appointment booking, meeting
coordination, scheduling and management, and analytics services. These services consist primarily of sharing calendar
availability and scheduling calendar and/or web conferencing events on behalf of the Customer and of collecting meeting
proposals from its meeting participants containing such content as are determined by the Customer and its meeting
participants in their sole discretion. FreeBusy also provides the Customer with analytic reports concerning the meetings
scheduled on the Customer's behalf.

Associated with the activity of automated appointment booking, FreeBusy will also send communications (notifications)
to Customer and its meeting participants primarily, but not limited to, e-mail communications. FreeBusy employs third-
party vendors (Sub-processors, for the purpose of this DPA) to send such notifications.

Otherwise, the data processing will involve any such processing that is necessary for the purposes set out in the
Agreement, the DPA, or as otherwise agreed between the parties.

Categories of data subjects

The personal data transferred concerns any data subject who proposes, organizes, or participates in a meeting (calendar
and/or web conferencing event) which the Customer instructs FreeBusy to collect, schedule (create, update, delete), or
otherwise assist with.

Data subjects may also include individuals who are mentioned within the notes of meetings collected or scheduled, on
behalf of, or by the Customer and its meeting participants using FreeBusy's services.

Categories of data

The personal data transferred concerns the following categories of data for the data subjects:
•   Organizer, participant, and proposer identification information (first and last name), contact information (address,
    telephone number, e-mail address), employment information (job title); and
•   Any other personal data that the Customer and/or its meeting participants choose to include within the notes of the
    meeting proposed or scheduled using FreeBusy's services.

The personal data transferred to FreeBusy for processing is determined and controlled by the Customer and/or its
meeting participants in their sole discretion. As such, FreeBusy has no control over the volume and sensitivity of
personal data processed through its service by the Customer and/or its meeting participants.

Special categories of data (if appropriate)

None.

Under the Agreement, the Customer agrees not to provide special categories of data to FreeBusy at any time.

Duration of processing

The personal data will be processed for the term of the Agreement, or as otherwise required by law or agreed between
the parties.
                                                              ANNEX B

                                  STANDARD CONTRACTUAL CLAUSES (MODULE TWO)

                                                              SECTION I

                                                              Clause 1

                                                       Purpose and scope

(a)          The purpose of these standard contractual clauses is to ensure compliance with the requirements of
             Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection
             of natural persons with regard to the processing of personal data and on the free movement of such data
             (General Data Protection Regulation) for the transfer of personal data to a third country.

(b)          The Parties:

             (i)     the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter “entity/ies”)
                     transferring the personal data, as listed in Annex I.A. (hereinafter each “data exporter”), and

             (ii)    the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly
                     via another entity also Party to these Clauses, as listed in Annex I.A. (hereinafter each “data importer”)

            have agreed to these standard contractual clauses (hereinafter: “Clauses”).

(c)          These Clauses apply with respect to the transfer of personal data as specified in Annex I.B.

(d)          The Appendix to these Clauses containing the Annexes referred to therein forms an integral part of these
             Clauses.

                                                              Clause 2

                                             Effect and invariability of the Clauses

      (a)    These Clauses set out appropriate safeguards, including enforceable data subject rights and effective legal
             remedies, pursuant to Article 46(1) and Article 46 (2)(c) of Regulation (EU) 2016/679 and, with respect to data
             transfers from controllers to processors and/or processors to processors, standard contractual clauses
             pursuant to Article 28(7) of Regulation (EU) 2016/679, provided they are not modified, except to select the
             appropriate Module(s) or to add or update information in the Appendix. This does not prevent the Parties from
             including the standard contractual clauses laid down in these Clauses in a wider contract and/or to add other
             clauses or additional safeguards, provided that they do not contradict, directly or indirectly, these Clauses or
             prejudice the fundamental rights or freedoms of data subjects.

      (b)    These Clauses are without prejudice to obligations to which the data exporter is subject by virtue of Regulation
             (EU) 2016/679.

                                                              Clause 3

                                                    Third-party beneficiaries

(a)          Data subjects may invoke and enforce these Clauses, as third-party beneficiaries, against the data exporter
             and/or data importer, with the following exceptions:

             (i)     Clause 1, Clause 2, Clause 3, Clause 6, Clause 7;

             (ii)    Clause 8 - Clause 8.1(b), 8.9(a), (c), (d) and (e);

             (iii)   Clause 9 - Clause 9(a), (c), (d) and (e);

             (iv)    Clause 12 - Clause 12(a), (d) and (f);

             (v)     Clause 13;
         (vi)     Clause 15.1(c), (d) and (e);

         (vii)    Clause 16(e);

         (viii)   Clause 18 - Clause 18(a) and (b);

(b)      Paragraph (a) is without prejudice to rights of data subjects under Regulation (EU) 2016/679.

                                                           Clause 4

                                                        Interpretation

(a)      Where these Clauses use terms that are defined in Regulation (EU) 2016/679, those terms shall have the
         same meaning as in that Regulation.

(b)      These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679.

(c)      These Clauses shall not be interpreted in a way that conflicts with rights and obligations provided for in
         Regulation (EU) 2016/679.

                                                           Clause 5

                                                          Hierarchy

In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties,
existing at the time these Clauses are agreed or entered into thereafter, these Clauses shall prevail.

                                                           Clause 6

                                                 Description of the transfer(s)

The details of the transfer(s), and in particular the categories of personal data that are transferred and the purpose(s)
for which they are transferred, are specified in Annex I.B.

                                                           Clause 7

                                                       Docking clause

(a)      An entity that is not a Party to these Clauses may, with the agreement of the Parties, accede to these Clauses
         at any time, either as a data exporter or as a data importer, by completing the Appendix and signing Annex
         I.A.

(b)      Once it has completed the Appendix and signed Annex I.A, the acceding entity shall become a Party to these
         Clauses and have the rights and obligations of a data exporter or data importer in accordance with its
         designation in Annex I.A.

(c)      The acceding entity shall have no rights or obligations arising under these Clauses from the period prior to
         becoming a Party.

                                    SECTION II – OBLIGATIONS OF THE PARTIES

                                                           Clause 8

                                                 Data protection safeguards

The data exporter warrants that it has used reasonable efforts to determine that the data importer is able, through the
implementation of appropriate technical and organisational measures, to satisfy its obligations under these Clauses.

8.1     Instructions

(a)      The data importer shall process the personal data only on documented instructions from the data exporter.
         The data exporter may give such instructions throughout the duration of the contract.
(b)       The data importer shall immediately inform the data exporter if it is unable to follow those instructions.

8.2     Purpose limitation

The data importer shall process the personal data only for the specific purpose(s) of the transfer, as set out in Annex
I.B, unless on further instructions from the data exporter.

8.3     Transparency

On request, the data exporter shall make a copy of these Clauses, including the Appendix as completed by the Parties,
available to the data subject free of charge. To the extent necessary to protect business secrets or other confidential
information, including the measures described in Annex II and personal data, the data exporter may redact part of the
text of the Appendix to these Clauses prior to sharing a copy, but shall provide a meaningful summary where the data
subject would otherwise not be able to understand the its content or exercise his/her rights. On request, the Parties shall
provide the data subject with the reasons for the redactions, to the extent possible without revealing the redacted
information. This Clause is without prejudice to the obligations of the data exporter under Articles 13 and 14 of Regulation
(EU) 2016/679.

8.4     Accuracy

If the data importer becomes aware that the personal data it has received is inaccurate, or has become outdated, it shall
inform the data exporter without undue delay. In this case, the data importer shall cooperate with the data exporter to
erase or rectify the data.

8.5     Duration of processing and erasure or return of data

Processing by the data importer shall only take place for the duration specified in Annex I.B. After the end of the provision
of the processing services, the data importer shall, at the choice of the data exporter, delete all personal data processed
on behalf of the data exporter and certify to the data exporter that it has done so, or return to the data exporter all
personal data processed on its behalf and delete existing copies. Until the data is deleted or returned, the data importer
shall continue to ensure compliance with these Clauses. In case of local laws applicable to the data importer that prohibit
return or deletion of the personal data, the data importer warrants that it will continue to ensure compliance with these
Clauses and will only process it to the extent and for as long as required under that local law. This is without prejudice
to Clause 14, in particular the requirement for the data importer under Clause 14(e) to notify the data exporter throughout
the duration of the contract if it has reason to believe that it is or has become subject to laws or practices not in line with
the requirements under Clause 14(a).

8.6     Security of processing

(a)       The data importer and, during transmission, also the data exporter shall implement appropriate technical and
          organisational measures to ensure the security of the data, including protection against a breach of security
          leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to that data
          (hereinafter “personal data breach”). In assessing the appropriate level of security, the Parties shall take due
          account of the state of the art, the costs of implementation, the nature, scope, context and purpose(s) of
          processing and the risks involved in the processing for the data subjects. The Parties shall in particular
          consider having recourse to encryption or pseudonymisation, including during transmission, where the
          purpose of processing can be fulfilled in that manner. In case of pseudonymisation, the additional information
          for attributing the personal data to a specific data subject shall, where possible, remain under the exclusive
          control of the data exporter. In complying with its obligations under this paragraph, the data importer shall at
          least implement the technical and organisational measures specified in Annex II. The data importer shall carry
          out regular checks to ensure that these measures continue to provide an appropriate level of security.

(b)       The data importer shall grant access to the personal data to members of its personnel only to the extent strictly
          necessary for the implementation, management and monitoring of the contract. It shall ensure that persons
          authorised to process the personal data have committed themselves to confidentiality or are under an
          appropriate statutory obligation of confidentiality.

(c)       In the event of a personal data breach concerning personal data processed by the data importer under these
          Clauses, the data importer shall take appropriate measures to address the breach, including measures to
          mitigate its adverse effects. The data importer shall also notify the data exporter without undue delay after
          having become aware of the breach. Such notification shall contain the details of a contact point where more
          information can be obtained, a description of the nature of the breach (including, where possible, categories
          and approximate number of data subjects and personal data records concerned), its likely consequences and
          the measures taken or proposed to address the breach including, where appropriate, measures to mitigate its
          possible adverse effects. Where, and in so far as, it is not possible to provide all information at the same time,
          the initial notification shall contain the information then available and further information shall, as it becomes
          available, subsequently be provided without undue delay.

(d)       The data importer shall cooperate with and assist the data exporter to enable the data exporter to comply with
          its obligations under Regulation (EU) 2016/679, in particular to notify the competent supervisory authority and
          the affected data subjects, taking into account the nature of processing and the information available to the
          data importer.

8.7     Sensitive data

Where the transfer involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical
beliefs, or trade union membership, genetic data, or biometric data for the purpose of uniquely identifying a natural
person, data concerning health or a person’s sex life or sexual orientation, or data relating to criminal convictions and
offences (hereinafter “sensitive data”), the data importer shall apply the specific restrictions and/or additional safeguards
described in Annex I.B.

8.8     Onward transfers

The data importer shall only disclose the personal data to a third party on documented instructions from the data
exporter. In addition, the data may only be disclosed to a third party located outside the European Union (in the same
country as the data importer or in another third country, hereinafter “onward transfer”) if the third party is or agrees to be
bound by these Clauses, under the appropriate Module, or if:

          (i)     the onward transfer is to a country benefitting from an adequacy decision pursuant to Article 45 of
                  Regulation (EU) 2016/679 that covers the onward transfer;

          (ii)    the third party otherwise ensures appropriate safeguards pursuant to Articles 46 or 47 Regulation of
                  (EU) 2016/679 with respect to the processing in question;

          (iii)   the onward transfer is necessary for the establishment, exercise or defence of legal claims in the context
                  of specific administrative, regulatory or judicial proceedings; or

          (iv)    the onward transfer is necessary in order to protect the vital interests of the data subject or of another
                  natural person.

Any onward transfer is subject to compliance by the data importer with all the other safeguards under these Clauses, in
particular purpose limitation.

8.9     Documentation and compliance

(a)       The data importer shall promptly and adequately deal with enquiries from the data exporter that relate to the
          processing under these Clauses.

(b)       The Parties shall be able to demonstrate compliance with these Clauses. In particular, the data importer shall
          keep appropriate documentation on the processing activities carried out on behalf of the data exporter.

(c)       The data importer shall make available to the data exporter all information necessary to demonstrate
          compliance with the obligations set out in these Clauses and at the data exporter’s request, allow for and
          contribute to audits of the processing activities covered by these Clauses, at reasonable intervals or if there
          are indications of non-compliance. In deciding on a review or audit, the data exporter may take into account
          relevant certifications held by the data importer.

(d)       The data exporter may choose to conduct the audit by itself or mandate an independent auditor. Audits may
          include inspections at the premises or physical facilities of the data importer and shall, where appropriate, be
          carried out with reasonable notice.

(e)       The Parties shall make the information referred to in paragraphs (b) and (c), including the results of any audits,
          available to the competent supervisory authority on request.
                                                      Clause 9

                                             Use of sub-processors

(a)   GENERAL WRITTEN AUTHORISATION The data importer has the data exporter’s general authorisation for
      the engagement of sub-processor(s) from an agreed list. The data importer shall specifically inform the data
      exporter in writing of any intended changes to that list through the addition or replacement of sub-processors
      at least 5 (five) calendar days in advance, thereby giving the data exporter sufficient time to be able to object
      to such changes prior to the engagement of the sub-processor(s). The data importer shall provide the data
      exporter with the information necessary to enable the data exporter to exercise its right to object.

(b)   Where the data importer engages a sub-processor to carry out specific processing activities (on behalf of the
      data exporter), it shall do so by way of a written contract that provides for, in substance, the same data
      protection obligations as those binding the data importer under these Clauses, including in terms of third-party
      beneficiary rights for data subjects. The Parties agree that, by complying with this Clause, the data importer
      fulfils its obligations under Clause 8.8. The data importer shall ensure that the sub-processor complies with
      the obligations to which the data importer is subject pursuant to these Clauses.

(c)   The data importer shall provide, at the data exporter’s request, a copy of such a sub-processor agreement
      and any subsequent amendments to the data exporter. To the extent necessary to protect business secrets
      or other confidential information, including personal data, the data importer may redact the text of the
      agreement prior to sharing a copy.

(d)   The data importer shall remain fully responsible to the data exporter for the performance of the sub-processor’s
      obligations under its contract with the data importer. The data importer shall notify the data exporter of any
      failure by the sub-processor to fulfil its obligations under that contract.

(e)   The data importer shall agree a third-party beneficiary clause with the sub-processor whereby - in the event
      the data importer has factually disappeared, ceased to exist in law or has become insolvent - the data exporter
      shall have the right to terminate the sub-processor contract and to instruct the sub-processor to erase or return
      the personal data.

                                                     Clause 10

                                               Data subject rights

(a)   The data importer shall promptly notify the data exporter of any request it has received from a data subject. It
      shall not respond to that request itself unless it has been authorised to do so by the data exporter.

(b)   The data importer shall assist the data exporter in fulfilling its obligations to respond to data subjects’ requests
      for the exercise of their rights under Regulation (EU) 2016/679. In this regard, the Parties shall set out in Annex
      II the appropriate technical and organisational measures, taking into account the nature of the processing, by
      which the assistance shall be provided, as well as the scope and the extent of the assistance required.

(c)   In fulfilling its obligations under paragraphs (a) and (b), the data importer shall comply with the instructions
      from the data exporter.

                                                     Clause 11

                                                      Redress

(a)   The data importer shall inform data subjects in a transparent and easily accessible format, through individual
      notice or on its website, of a contact point authorised to handle complaints. It shall deal promptly with any
      complaints it receives from a data subject.

(b)   In case of a dispute between a data subject and one of the Parties as regards compliance with these Clauses,
      that Party shall use its best efforts to resolve the issue amicably in a timely fashion. The Parties shall keep
      each other informed about such disputes and, where appropriate, cooperate in resolving them.

(c)   Where the data subject invokes a third-party beneficiary right pursuant to Clause 3, the data importer shall
      accept the decision of the data subject to:
       (i)    lodge a complaint with the supervisory authority in the Member State of his/her habitual residence or
              place of work, or the competent supervisory authority pursuant to Clause 13;

       (ii)   refer the dispute to the competent courts within the meaning of Clause 18.

(d)    The Parties accept that the data subject may be represented by a not-for-profit body, organisation or
       association under the conditions set out in Article 80(1) of Regulation (EU) 2016/679.

(e)    The data importer shall abide by a decision that is binding under the applicable EU or Member State law.

(f)    The data importer agrees that the choice made by the data subject will not prejudice his/her substantive and
       procedural rights to seek remedies in accordance with applicable laws.

                                                     Clause 12

                                                      Liability

(a)    Each Party shall be liable to the other Party/ies for any damages it causes the other Party/ies by any breach
       of these Clauses.

(b)    The data importer shall be liable to the data subject, and the data subject shall be entitled to receive
       compensation, for any material or non-material damages the data importer or its sub-processor causes the
       data subject by breaching the third-party beneficiary rights under these Clauses.

(c)    Notwithstanding paragraph (b), the data exporter shall be liable to the data subject, and the data subject shall
       be entitled to receive compensation, for any material or non-material damages the data exporter or the data
       importer (or its sub-processor) causes the data subject by breaching the third-party beneficiary rights under
       these Clauses. This is without prejudice to the liability of the data exporter and, where the data exporter is a
       processor acting on behalf of a controller, to the liability of the controller under Regulation (EU) 2016/679 or
       Regulation (EU) 2018/1725, as applicable.

(d)    The Parties agree that if the data exporter is held liable under paragraph (c) for damages caused by the data
       importer (or its sub-processor), it shall be entitled to claim back from the data importer that part of the
       compensation corresponding to the data importer’s responsibility for the damage.

(e)    Where more than one Party is responsible for any damage caused to the data subject as a result of a breach
       of these Clauses, all responsible Parties shall be jointly and severally liable and the data subject is entitled to
       bring an action in court against any of these Parties.

(f)    The Parties agree that if one Party is held liable under paragraph (e), it shall be entitled to claim back from the
       other Party/ies that part of the compensation corresponding to its / their responsibility for the damage.

(g)    The data importer may not invoke the conduct of a sub-processor to avoid its own liability.

                                                     Clause 13

                                                    Supervision

(a)    [Where the data exporter is established in an EU Member State:] The supervisory authority with responsibility
       for ensuring compliance by the data exporter with Regulation (EU) 2016/679 as regards the data transfer, as
       indicated in Annex I.C, shall act as competent supervisory authority.

      [Where the data exporter is not established in an EU Member State, but falls within the territorial scope of
      application of Regulation (EU) 2016/679 in accordance with its Article 3(2) and has appointed a representative
      pursuant to Article 27(1) of Regulation (EU) 2016/679:] The supervisory authority of the Member State in which
      the representative within the meaning of Article 27(1) of Regulation (EU) 2016/679 is established, as indicated
      in Annex I.C, shall act as competent supervisory authority.

      [Where the data exporter is not established in an EU Member State, but falls within the territorial scope of
      application of Regulation (EU) 2016/679 in accordance with its Article 3(2) without however having to appoint a
      representative pursuant to Article 27(2) of Regulation (EU) 2016/679:] The supervisory authority of one of the
      Member States in which the data subjects whose personal data is transferred under these Clauses in relation
      to the offering of goods or services to them, or whose behaviour is monitored, are located, as indicated in Annex
      I.C, shall act as competent supervisory authority.

(b)     The data importer agrees to submit itself to the jurisdiction of and cooperate with the competent supervisory
        authority in any procedures aimed at ensuring compliance with these Clauses. In particular, the data importer
        agrees to respond to enquiries, submit to audits and comply with the measures adopted by the supervisory
        authority, including remedial and compensatory measures. It shall provide the supervisory authority with
        written confirmation that the necessary actions have been taken.

      SECTION III – LOCAL LAWS AND OBLIGATIONS IN CASE OF ACCESS BY PUBLIC AUTHORITIES

                                                      Clause 14

                         Local laws and practices affecting compliance with the Clauses

(a)     The Parties warrant that they have no reason to believe that the laws and practices in the third country of
        destination applicable to the processing of the personal data by the data importer, including any requirements
        to disclose personal data or measures authorising access by public authorities, prevent the data importer from
        fulfilling its obligations under these Clauses. This is based on the understanding that laws and practices that
        respect the essence of the fundamental rights and freedoms and do not exceed what is necessary and
        proportionate in a democratic society to safeguard one of the objectives listed in Article 23(1) of Regulation
        (EU) 2016/679, are not in contradiction with these Clauses.

(b)     The Parties declare that in providing the warranty in paragraph (a), they have taken due account in particular
        of the following elements:

        (i)     the specific circumstances of the transfer, including the length of the processing chain, the number of
                actors involved and the transmission channels used; intended onward transfers; the type of recipient;
                the purpose of processing; the categories and format of the transferred personal data; the economic
                sector in which the transfer occurs; the storage location of the data transferred;

        (ii)    the laws and practices of the third country of destination– including those requiring the disclosure of
                data to public authorities or authorising access by such authorities – relevant in light of the specific
                circumstances of the transfer, and the applicable limitations and safeguards;

        (iii)   any relevant contractual, technical or organisational safeguards put in place to supplement the
                safeguards under these Clauses, including measures applied during transmission and to the processing
                of the personal data in the country of destination.

(c)     The data importer warrants that, in carrying out the assessment under paragraph (b), it has made its best
        efforts to provide the data exporter with relevant information and agrees that it will continue to cooperate with
        the data exporter in ensuring compliance with these Clauses.

(d)     The Parties agree to document the assessment under paragraph (b) and make it available to the competent
        supervisory authority on request.

(e)     The data importer agrees to notify the data exporter promptly if, after having agreed to these Clauses and for
        the duration of the contract, it has reason to believe that it is or has become subject to laws or practices not in
        line with the requirements under paragraph (a), including following a change in the laws of the third country or
        a measure (such as a disclosure request) indicating an application of such laws in practice that is not in line
        with the requirements in paragraph (a).

(f)     Following a notification pursuant to paragraph (e), or if the data exporter otherwise has reason to believe that
        the data importer can no longer fulfil its obligations under these Clauses, the data exporter shall promptly
        identify appropriate measures (e.g. technical or organisational measures to ensure security and confidentiality)
        to be adopted by the data exporter and/or data importer to address the situation [for Module Three: , if
        appropriate in consultation with the controller]. The data exporter shall suspend the data transfer if it considers
        that no appropriate safeguards for such transfer can be ensured, or if instructed by the competent supervisory
        authority to do so. In this case, the data exporter shall be entitled to terminate the contract, insofar as it
        concerns the processing of personal data under these Clauses. If the contract involves more than two Parties,
        the data exporter may exercise this right to termination only with respect to the relevant Party, unless the
        Parties have agreed otherwise. Where the contract is terminated pursuant to this Clause, Clause 16(d) and
        (e) shall apply.

                                                       Clause 15

                      Obligations of the data importer in case of access by public authorities

15.1   Notification

(a)     The data importer agrees to notify the data exporter and, where possible, the data subject promptly (if
        necessary with the help of the data exporter) if it:

        (i)    receives a legally binding request from a public authority, including judicial authorities, under the laws
               of the country of destination for the disclosure of personal data transferred pursuant to these Clauses;
               such notification shall include information about the personal data requested, the requesting authority,
               the legal basis for the request and the response provided; or

        (ii)   becomes aware of any direct access by public authorities to personal data transferred pursuant to these
               Clauses in accordance with the laws of the country of destination; such notification shall include all
               information available to the importer.

(b)     If the data importer is prohibited from notifying the data exporter and/or the data subject under the laws of the
        country of destination, the data importer agrees to use its best efforts to obtain a waiver of the prohibition, with
        a view to communicating as much information as possible, as soon as possible. The data importer agrees to
        document its best efforts in order to be able to demonstrate them on request of the data exporter.

(c)     Where permissible under the laws of the country of destination, the data importer agrees to provide the data
        exporter, at regular intervals for the duration of the contract, with as much relevant information as possible on
        the requests received (in particular, number of requests, type of data requested, requesting authority/ies,
        whether requests have been challenged and the outcome of such challenges, etc.).

(d)     The data importer agrees to preserve the information pursuant to paragraphs (a) to (c) for the duration of the
        contract and make it available to the competent supervisory authority on request.

(e)     Paragraphs (a) to (c) are without prejudice to the obligation of the data importer pursuant to Clause 14(e) and
        Clause 16 to inform the data exporter promptly where it is unable to comply with these Clauses.

15.2   Review of legality and data minimisation

(a)     The data importer agrees to review the legality of the request for disclosure, in particular whether it remains
        within the powers granted to the requesting public authority, and to challenge the request if, after careful
        assessment, it concludes that there are reasonable grounds to consider that the request is unlawful under the
        laws of the country of destination, applicable obligations under international law and principles of international
        comity. The data importer shall, under the same conditions, pursue possibilities of appeal. When challenging
        a request, the data importer shall seek interim measures with a view to suspending the effects of the request
        until the competent judicial authority has decided on its merits. It shall not disclose the personal data requested
        until required to do so under the applicable procedural rules. These requirements are without prejudice to the
        obligations of the data importer under Clause 14(e).

(b)     The data importer agrees to document its legal assessment and any challenge to the request for disclosure
        and, to the extent permissible under the laws of the country of destination, make the documentation available
        to the data exporter. It shall also make it available to the competent supervisory authority on request.

(c)     The data importer agrees to provide the minimum amount of information permissible when responding to a
        request for disclosure, based on a reasonable interpretation of the request.

                                         SECTION IV – FINAL PROVISIONS

                                                       Clause 16
                                 Non-compliance with the Clauses and termination

(a)      The data importer shall promptly inform the data exporter if it is unable to comply with these Clauses, for
         whatever reason.

(b)      In the event that the data importer is in breach of these Clauses or unable to comply with these Clauses, the
         data exporter shall suspend the transfer of personal data to the data importer until compliance is again ensured
         or the contract is terminated. This is without prejudice to Clause 14(f).

(c)      The data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal
         data under these Clauses, where:

         (i)     the data exporter has suspended the transfer of personal data to the data importer pursuant to
                 paragraph (b) and compliance with these Clauses is not restored within a reasonable time and in any
                 event within one month of suspension;

         (ii)    the data importer is in substantial or persistent breach of these Clauses; or

         (iii)   the data importer fails to comply with a binding decision of a competent court or supervisory authority
                 regarding its obligations under these Clauses.

        In these cases, it shall inform the competent supervisory authority of such non-compliance. Where the contract
        involves more than two Parties, the data exporter may exercise this right to termination only with respect to the
        relevant Party, unless the Parties have agreed otherwise.

(d)      Personal data that has been transferred prior to the termination of the contract pursuant to paragraph (c) shall
         at the choice of the data exporter immediately be returned to the data exporter or deleted in its entirety. The
         same shall apply to any copies of the data. The data importer shall certify the deletion of the data to the data
         exporter. Until the data is deleted or returned, the data importer shall continue to ensure compliance with these
         Clauses. In case of local laws applicable to the data importer that prohibit the return or deletion of the
         transferred personal data, the data importer warrants that it will continue to ensure compliance with these
         Clauses and will only process the data to the extent and for as long as required under that local law.

(e)      Either Party may revoke its agreement to be bound by these Clauses where (i) the European Commission
         adopts a decision pursuant to Article 45(3) of Regulation (EU) 2016/679 that covers the transfer of personal
         data to which these Clauses apply; or (ii) Regulation (EU) 2016/679 becomes part of the legal framework of
         the country to which the personal data is transferred. This is without prejudice to other obligations applying to
         the processing in question under Regulation (EU) 2016/679.

                                                        Clause 17

                                                     Governing law

These Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third-party
beneficiary rights. The Parties agree that this shall be the law of Romania.

                                                        Clause 18

                                           Choice of forum and jurisdiction

(a)      Any dispute arising from these Clauses shall be resolved by the courts of an EU Member State.

(b)      The Parties agree that those shall be the courts of Romania.

(c)      A data subject may also bring legal proceedings against the data exporter and/or data importer before the
         courts of the Member State in which he/she has his/her habitual residence.

(d)      The Parties agree to submit themselves to the jurisdiction of such courts.
                                               APPENDIX TO ANNEX B

ANNEX I

A. LIST OF PARTIES

Data exporter(s):

The Data Exporter (or Business/Controller) is the Customer that is a party to the Addendum

Role: Controller

Data importer(s):

The Data Importer (or Service Provider/Processor) is FreeBusy, a provider of scheduling solutions.

Role: Processor

B. DESCRIPTION OF TRANSFER

As described in Annex A of this Addendum

C. COMPETENT SUPERVISORY AUTHORITY

The Irish Data Protection Commission ………………….

ANNEX II - TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL
MEASURES TO ENSURE THE SECURITY OF THE DATA

1. Measures of pseudonymisation and encryption of personal data

FreeBusy protects all data in transit with TLS 1.2 and some data at rest with AES-256 encryption as described in
“Protecting Credentials with Encryption, Key Wrapping, and Separation of Duties” section of the Security Policy posted
at https://freebusy.io/security

2. Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems
   and services

Availability and Resiliency: FreeBusy services shall be configured in such a manner so as to withstand long-term outages
to individual servers, availability zones, and geographic regions. FreeBusy infrastructure and data is replicated in
multiple geographic regions to ensure this level of availability. FreeBusy availability and status information can be found
at status.freebusy.io.

Disaster Recovery: FreeBusy targets a Data Recovery Point Objective (RPO) of near-zero for at least 7 days, and up
to 24 hours beyond 7 days. Due to the distributed nature of FreeBusy services, Recovery Time Objectives (RTO) are
near-zero for geographic disasters. RTO for systemic disasters involving data recovery is targeted at 24 hours. FreeBusy
tests backup and recovery processes on at least a yearly basis.

Business Continuity:

•   Business Risk Assessment and Business Impact Analysis. FreeBusy's risk assessment committee will include
    business risk assessment and business impact analysis for each Key Business System that is used by the
    organization. The outcome of ongoing risk assessments will update or create recovery plans for Key Business
    Systems and update prioritization of systems compared to other key systems.
•   Distribution, Relocation, and Remote Work: FreeBusy prioritizes policies, tools, and equipment which enables
    independent, distributed remote work for all staff if emergencies or disasters strike. If the organization’s primary
    work site is unavailable, staff can work from home or an alternate work site shall be designated by management.
•   Notification and Communication: FreeBusy has established internal communications using secure, distributed
    providers using industry standard security protocols. Staff and management will be notified via existing channels
    during any emergency event, or when any data recovery plan is initiated or deactivated.

3. Measures for ensuring the ability to restore the availability and access to personal data in a timely manner
   in the event of a physical or technical incident

The FreeBusy security and development teams shall use all of the following measures to detect vulnerabilities that may
arise in FreeBusy’s information systems.

•   Cross-checking vulnerability databases with all systems and software packages that support critical FreeBusy
    services.
•   Automated source code scanners on every code commit.
•   Code reviews on every security-sensitive code commit.
•   Vulnerability scanning on FreeBusy services.
•   Annual penetration testing with an independent provider.

The FreeBusy security team shall evaluate the severity of every detected vulnerability in terms of the likelihood and
potential impact of an exploit, and shall develop mitigation strategies and schedules accordingly. Suitable mitigations
include complete remediation or implementing compensating controls.

4. Processes for regularly testing, assessing and evaluating the effectiveness of technical and organizational
   measures in order to ensure the security of the processing

FreeBusy maintains information security policies that defines behavioral, process, technical, and governance controls
pertaining to security at FreeBusy that all personnel are required to implement in order to ensure the confidentiality,
integrity, and availability of the FreeBusy service and data All personnel must review and be familiar with the rules and
actions set forth.

The FreeBusy security team oversees the implementation of these policies, including

    •   procurement, provisioning, maintenance, retirement, and reclamation of corporate computing resources,
    •   all aspects of service development and operation related to security, privacy, access, reliability, and survivability,
    •   ongoing risk assessment, vulnerability management, incident response, and
    •   security-related human resources controls and personnel training.

The security team maintains a Risk Management Framework which incorporates the following:

    •   Identification of relevant, potential threats.
    •   A scheme for assessing the strength of implemented controls.
    •   A scheme for assessing current risks and evaluating their severity.
    •   A scheme for responding to risks.

5. Measures for user identification and authorization

FreeBusy adheres to the principle of least privilege, and every action attempted by a user account is subject to access
control checks.

Role-based Access Control: FreeBusy employs a role-based access control (RBAC) model utilizing Google-supplied
facilities such as organizational units, user accounts, user groups, and sharing controls.

Web Browsers and Extensions: FreeBusy may require use of a specified web browser(s) for normal business use and
for access to corporate data such as email. For certain specified roles such as software development and web design,
job activities beyond those mentioned above necessitate the use of a variety of browsers, and these roles may do so
as needed for those activities. Any browser that is allowed to access corporate data such as email is subject to a
whitelist-based restriction on which browser extensions can be installed.
Administrative Access: Access to administrative operations is strictly limited to security team members and further
restricted still as a function of tenure and the principle of least privilege.

Regular Review: Access control policies are reviewed regularly with the goal of reducing or refining access whenever
possible. Changes in job function by personnel trigger an access review as well.

Termination: Upon termination of personnel, whether voluntary or involuntary, the security team will follow FreeBusy’s
personnel exit procedure, which includes revocation of the associated user account and reclamation of company-owned
devices, office keys or access cards, and all other corporate equipment and property prior to the final day of employment.

6. Measures for ensuring events logging

The FreeBusy security and development teams shall document the configuration of all adopted systems and services,
whether hosted by FreeBusy or are third party hosted. Industry best practices and vendor-specific guidance shall be
identified and incorporated into system configurations. All configurations shall be reviewed on at least an annual basis.
Any changes to configurations must be approved by appointed individuals and documented in a timely fashion.

System configurations must address the following controls in a risk-based fashion and in accordance with the remainder
of this policy:

    •   data-at-rest protection encryption
    •   data-in-transit protection of confidentiality, authenticity, and integrity for incoming and outgoing data
    •   data and file integrity
    •   malware detection and resolution
    •   capturing event logs
    •   authentication of administrative users
    •   access control enforcement
    •   removal or disabling of unnecessary software and configurations
    •   allocation of sufficient hardware resources to support loads that are expected at least twelve months into the
        future.
    •   production data is not used in development or test systems.

7. Measures for ensuring data minimization

More information about how FreeBusy processes personal data is set forth in the Privacy Policy available
at https://freebusy.io/privacy.

8. Measures for ensuring accountability

More information about how FreeBusy processes personal data is set forth in the Privacy Policy available
at https://freebusy.io/privacy.