Third Party Index

Snapshot 39926

Document
Subprocessor list
URL
https://www.acumatica.com/media/2026/07/Acumatica-Customer-Data-Processing-Addendum-July-2026.pdf#subprocessors
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
245213 bytes
SHA-256 (raw)
efa6d86967199ede0b1f0e5c13bf943a00ce670ba99e52f42b0cf1caf77d82e6
SHA-256 (normalized text)
6c2a25ef9b362ce469a006ac861536e19731cb0ce1f54fca2aa10edd808b1c31

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Last Updated: July 2026

                                                  Acumatica, Inc.

                                         DATA PROCESSING ADDENDUM

This Data Processing Addendum (“DPA”) is incorporated into and forms part of the applicable End-User License
Agreement or Acumatica Subscription SaaS Agreement (the “Agreement”) between the Subscriber and Acumatica,
Inc. (“Acumatica”). This DPA reflects the parties’ agreement with respect to the Processing of Personal Data (as
defined below) to ensure compliance with the requirements of Data Protection Laws. This DPA will control with respect
to the subject matter herein in the event of any conflict with the Agreement. This DPA includes the Standard
Contractual Clauses, which are incorporated by reference below.

Definitions. Capitalized terms used herein and not otherwise defined in this DPA shall have the meaning set forth in
the Agreement:

“Data Controller” means the entity that determines the purposes and means of Processing Personal Data (in this
case, Subscriber) and shall include a "business" as such term is defined by the CCPA / CPRA and any similar or
analogous designation under Data Protection Laws.

"Data Exporter" means Subscriber or its Affiliate who transfers the Personal Data out of the EEA, Switzerland or the
United Kingdom.

"Data Importer" means Acumatica or its Affiliate who receives Personal Data from the EEA, Switzerland or the United
Kingdom.

"Data Processor" means the entity that Processes Personal Data on behalf of the Data Controller (in this case,
Acumatica) and shall include a "service provider" as such term is defined by the CCPA / CPRA and any similar or
analogous designation under Data Protection Laws.

"Data Protection Laws" means any data protection laws and regulations applicable to a party and its respective
Processing of Personal Data under the Agreement, including, where applicable, EU/UK Data Protection Law, US
Data Protection Law and the Swiss DPA.

"Data Subject" means the individual to whom Personal Data relates and shall include a "consumer" as such term is
defined by the CCPA / CPRA and any similar or analogous designation under Data Protection Laws.

"EEA" means the European Economic Area as constituted at the time of the transfer.

"EU/UK Data Protection Law" means: (i) Regulation 2016/679 of the European Parliament and of the Council on
the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such
data (General Data Protection Regulation) (the "EU GDPR"); (ii) the EU GDPR as saved into United Kingdom law
by virtue of section 3 of the United Kingdom's European Union (Withdrawal) Act 2018 (the "UK GDPR"); (iii) the EU
e-Privacy Directive (Directive 2002/58/EC); and (iv) any and all applicable national data protection laws made under,
pursuant to or that apply in conjunction with any of (i), (ii) or (iii); in each case as may be amended or superseded
from time to time.

"Personal Data" means any Subscriber Data that is protected as "personal data", "personal information", "personally
identifiable information" or the like under Data Protection Laws that is Processed by Acumatica as a Data Processor
in connection with the Service.

"Processing", "Processes", or "Process" means any operation or set of operations performed upon Personal
Data, whether or not by automated means, such as collection, recording, organization, storage, adaptation, or
alteration, retrieval, consultation, use, disclosure, dissemination, erasure, or destruction.

"Restricted Transfer" means: (i) where the EU GDPR applies, a transfer of personal data from the EEA to a country
outside of the EEA which is not subject to an adequacy determination by the European Commission; (ii) where the
UK GDPR applies, a transfer of personal data from the United Kingdom to any other country which is not based on
adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018; and (iii) where the
Swiss DPA applies, a transfer of personal data from Switzerland to any other country which is not determined to
Last Updated: July 2026

provide adequate protection for personal data by the Federal Data Protection and Information Commission or Federal
Council (as applicable).

"Standard Contractual Clauses" or "EU SCCs" means the contractual clauses annexed to the European
Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of
personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council,
as amended, superseded or replaced from time to time.

"Sub-processor" means any third-party Data Processor that Processes Personal Data for Acumatica.

"Subscriber" means the entity procuring the SaaS services under the Agreement.

"Subscriber Data" means any data or information provided by the Subscriber to Acumatica for Processing under the
Agreement.

"Subscriber Data Incident" means a confirmed breach of security leading to any accidental or unlawful destruction,
loss, alteration, unauthorized disclosure of, or access to Personal Data Processed in environments controlled by
Acumatica or its Sub-processors.

"Swiss DPA" means the Swiss Federal Act on Data Protection 1992 (including as amended or superseded).

"UK Addendum" means the International Data Transfer Addendum (version B1.0) issued by Information
Commissioners Office under S.119(A) of the UK Data Protection Act 2018, as amended, superseded or replaced from
time to time.

"US Data Protection Law" means (i) the California Consumer Privacy Act (the “CCPA”), as amended by the California
Privacy Rights Act ("CPRA") when effective, as well as any regulations and guidance that may be issued thereunder;
and, where applicable, (ii) the Virginia Consumer Data Protection Act ("CDPA") when effective; (iii) the Colorado
Privacy Act ("CPA") when effective; (iv) the Utah Consumer Privacy Act when effective (“UCPA”); (v) the Connecticut
Data Privacy Act ("CTDPA") when effective; in each case as may be amended or superseded from time to time.

Processing of Personal Data. Subscriber controls the categories of Data Subjects and any Personal Data
Processed under this Agreement, the details of which are set out in Annex I. Acumatica has no knowledge of, or
control over, the specific Personal Data that Subscriber provides for Processing in the course of the Services.
Subscriber is solely responsible for: (a) the accuracy, quality, and legality of the Subscriber Data and the means by
which it acquired the Subscriber Data; and (b) ensuring that its submission of Personal Data to Acumatica and
instructions for the Processing of Personal Data comply with Data Protection Laws. Acumatica is not responsible
determining if Subscriber's Processing instructions are compliant with applicable law; however, Acumatica will inform
Subscriber without delay if, in Acumatica’s opinion, Subscriber’s instructions violate Data Protection Laws, and
Acumatica shall not be required to comply with such instructions. Taking into account the nature of the Processing,
Subscriber agrees that it is unlikely that Acumatica would become aware if Personal Data Processed by Acumatica
is inaccurate or outdated. To the extent Acumatica becomes aware of such inaccurate or outdated data, Acumatica
will inform the Subscriber of this.

Processing Instructions. Acumatica will Process Personal Data on behalf of and in accordance with Subscriber’s
lawful documented instructions. For these purposes, Subscriber instructs Acumatica to Process Personal Data to (i)
perform the Services in accordance with the Agreement (including this DPA and all documents incorporated into the
Agreement) and (ii) to comply with Subscriber’s other reasonable instructions communicated to Acumatica to the
extent those instructions are consistent with the Agreement ("Permitted Purposes"). The parties agree that the
Agreement (including this DPA) sets out Subscriber's complete and final instructions to Acumatica in relation to the
Processing of Personal Data and Processing outside the scope of these instructions (if any) shall require prior written
agreement between the parties. Apart from such Processing, Acumatica will not Process Personal Data to or for
third parties unless required to do so by applicable law; if such a requirement arises Acumatica will make reasonable
efforts to inform Subscriber in advance of the required Processing, unless such notice is prohibited by law.

Purpose Limitation. Subscriber is disclosing the Personal Data to Acumatica only for the Permitted Purposes.
Acumatica shall comply with all applicable requirements of Data Protection Laws and provide the same level of privacy
protection under Data Protection Laws. Acumatica shall inform Subscriber as soon as reasonably practicable, unless
prohibited from doing so under applicable law, if (i) it becomes aware or believes that any processing instruction from
Last Updated: July 2026

Subscriber violates Data Protection Laws; (ii) it is makes a determination that it can no longer meet its obligations
under Data Protection Laws and/or this DPA for any reason; and/or (iii) it is required by applicable law to process
Personal Data for any other purpose other than in accordance with Subscriber's processing instructions. In the event
of any such non-compliance and/or if Subscriber is aware or has reason to believe that Acumatica has breached or
will breach its obligations under Data Protection Laws and/or this DPA, but without prejudice to any other right or
remedy available to Subscriber under the Agreement and this DPA:
         (a)       Subscriber shall have the right to take any reasonable and appropriate steps to ensure that
                   Acumatica uses the Personal Data in a manner consistent with Subscriber’s obligations under Data
                   Protection Laws;
         (b)       Acumatica shall work with Subscriber and promptly take all reasonable and appropriate steps to
                   remediate (if remediable) any non-compliance; and/or
         (c)       Subscriber may, upon written notice, elect to suspend or terminate the processing of Personal Data
                   under the Agreement and/or terminate the Agreement without any further liability or obligation to
                   Acumatica.

Limited Processing under US Data Protection Law: Acumatica represents and warrants that it shall not create,
collect, receive, access, use, or otherwise process the Personal Data for any purpose other than the Permitted
Purposes or in violation of any Data Protection Laws. Acumatica further represents and warrants that it shall not “sell”
Personal Data, as such term is defined under the CCPA / CPRA (regardless of whether the CCPA / CPRA applies),
CDPA, CPA, or other US Data Protection Law, and will also not “share” Personal Data within the meaning of the CPRA
(regardless of whether the CPRA applies). Acumatica shall process the Personal Data solely and exclusively for the
purposes for which the Personal Data, or access to it, is provided pursuant to the terms and conditions of the
Agreement and this DPA. Acumatica shall not retain, use, or disclose Personal Data outside of the direct business
relationship between Acumatica and Subscriber for any purpose other than the Permitted Purposes, nor shall
Acumatica retain, use, or disclose Personal Data for any purposes other than the Permitted Purposes or as otherwise
permitted under Data Protection Laws. To the extent required by Data Protection Laws, Acumatica certifies that it
understands the foregoing restrictions and will comply with them. In all cases, Acumatica will comply with any
applicable restrictions under Data Protection Laws on combining personal data received from Subscriber with personal
data that Acumatica receives from, or on behalf of, another person or persons, or that Acumatica may collect from any
interaction between it and a data subject.

Data Subject Requests. Acumatica shall, to the extent legally permitted and where the Subscriber is identified or
identifiable from the request, promptly notify Subscriber if Acumatica receives: (i) a request from a Data Subject
seeking to exercise any of its rights under Data Protection Law in connection with the Processing of Personal Data,
including rights of access, rectification, restriction, erasure, data portability, objection or opt-out (“Data Subject
Request”) and (ii) any other correspondence, enquiry or complaint received from a Data Subject, regulator, data
protection authority, Attorney General or other third party in connection with the processing of the Personal Data. In
addition, to the extent Subscriber does not have the ability to address a Data Subject Request because it does not
have custody or control of the necessary information technology systems (and Acumatica does) and taking into
account the nature of the Processing, Acumatica shall provide Subscriber with commercially reasonable assistance
(including by appropriate technical and organizational measures, in so far as is possible) to enable Subscriber to
respond to a Data Subject Request. To the extent Subscriber requires any additional assistance, Subscriber shall be
responsible and will indemnify Acumatica for any costs arising from Acumatica providing such assistance.

Acumatica Personnel. Acumatica shall ensure its personnel engaged in the Processing of Personal Data are
informed of the confidential nature of the Personal Data, have received appropriate training on their responsibilities,
are subject to a duty of confidentiality (whether contractual or statutory) and that they will only Process Personal Data
for the Permitted Purposes. Acumatica shall ensure that access to Personal Data is limited to those personnel who
require access to perform services or Process Personal Data in accordance with the Agreement.

Sub-processors. Subject to compliance with this paragraph, Subscriber expressly authorizes Acumatica to use Sub-
processors, including those listed in Annex III of this DPA (the "Sub-processor List").

Acumatica shall ensure that: (a) Sub-processors shall be bound by a written agreement, including data protection
and security measures, no less protective of Personal Data than the Agreement and this DPA; (b) Acumatica shall
be liable for any breach of this DPA caused by an act, error or omission of its Sub-processors to the extent Acumatica
would have been liable had such breach been caused by Acumatica; and (c) Acumatica will notify Subscriber in
writing if it adds a new Sub-processor to the Sub-processor List at least thirty (30) days in advance. If within thirty
(30) days of receipt of such notice, Subscriber objects, in writing, to Acumatica’s appointment of a new Sub-processor
Last Updated: July 2026

on reasonable grounds relating to data protection, the parties will discuss such concerns in good faith with a goal of
achieving resolution, failing which Subscriber may terminate the Agreement and this DPA without further liability upon
written notice to Acumatica. Upon request, Acumatica will provide an up-to-date Sub-processor List.

Security. Acumatica shall implement and maintain appropriate technical and organizational safeguards designed to
protect the confidentiality, integrity, and security of Subscriber Data, including protection from Subscriber Data
Incidents, as further described in Annex II of this DPA ("Security Measures"). Acumatica may update the Security
Measures from time to time, provided that any updates shall not materially diminish the overall security of Subscriber
Data. Acumatica shall notify Subscriber without undue delay after becoming aware of Subscriber Data Incident.
Acumatica shall make reasonable efforts to identify the cause of such Subscriber Data Incidents and take steps it
deems necessary and reasonable to remediate the cause of such incidents to the extent doing so is within
Acumatica’s control. To the extent that a Subscriber Data Incident is caused by Subscriber, its affiliates, or users, the
Subscriber will be responsible for any costs Acumatica incurred while meeting these Security obligations.

Data Protection Impact Assessments. Upon Subscriber’s request, Acumatica shall provide Subscriber with
reasonable cooperation and assistance to the extent needed for Subscriber to fulfil its obligations under the GDPR or
applicable Data Protection Laws to conduct a data protection impact assessment related to Subscriber’s use of the
Service, but only where Subscriber does not have access to relevant information that is only available from Acumatica.
To the extent required by the GDPR or applicable Data Protection Laws, in connection with the tasks in this section,
Acumatica will provide reasonable assistance to Subscriber in cooperation, or prior to consultation, with any
Supervisory Authority. For the avoidance of doubt, this section shall also apply where a risk assessment, data
protection assessment or other similar assessment is required under US Data Protection Law, including, if necessary,
to assist Acumatica to consult with a data protection agency or Attorney General.

Return or deletion of Subscriber Data: Upon termination or expiry of the Agreement, on Subscriber's written
request Acumatica shall delete all Personal Data in its possession or control in accordance with the Agreement, save
that this requirement shall not apply to the extent Acumatica is required by applicable law to retain some or all of the
Personal Data, or to Personal Data it has archived on back-up systems, which data Acumatica shall securely isolate
and protect from any further processing and delete in accordance with its deletion practices, except to the extent
required by applicable law.

Data Transfers. Where Subscriber makes a Restricted Transfer of Personal Data to Acumatica, then the Standard
Contractual Clauses shall be deemed incorporated into and form an integral part of this DPA as follows:
    a.    in relation to Personal Data protected by the EU GDPR, the EU SCCs will be completed as follows:
          •   Module Two will apply;
          •   in Clause 7, the optional docking clause will apply;
          •   in Clause 9, Option 2 will apply, and the time period for prior notice of Sub-processor changes shall be
              as set out in the section headed " Sub-processors" above;
          •   in Clause 11, the optional language will not apply;
          •   in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Irish law;
          •   in Clause 18(b), disputes shall be resolved before the courts of Ireland;
          •   Annex I of the EU SCCs shall be deemed completed with the information set out in Annex I to this
              Agreement;
          •   Annex II of the EU SCCs shall be deemed completed with the information set out in Annex II to this
              Agreement, as updated in accordance with this DPA.
     b.   in relation Personal Data protected by the UK GDPR, the Standard Contractual Clauses:
          •   shall apply as completed in accordance with paragraph (a) above; and
          •   shall be deemed amended as specified by the UK Addendum, which shall be deemed executed between
              the transferring Subscriber and Acumatica, and incorporated into and form an integral part of this DPA.
              In addition, Tables 1 to 3 in Part 1 of the UK Addendum shall be deemed completed with the information
              set out in the DPA (including its Annexes) and Table 4 in Part 1 shall be deemed completed by selecting
              "importer"; and
          •   any conflict between the terms of the Standard Contractual Clauses and the UK Addendum shall be
Last Updated: July 2026

             resolved in accordance with Section 10 and Section 11 of the UK Addendum.
    c.   In relation to transfers of Personal Data protected by the Swiss DPA, the Standard Contractual Clauses
          shall apply completed in accordance with paragraph (a) above with the following modifications:
         •   references to “Regulation (EU) 2016/679” and specific articles therein shall be interpreted as references
             to the Swiss DPA and the equivalent articles or sections therein;
         •   references to “EU”, “Union”, “Member State” and “Member State law” shall be replaced with references
             to “Switzerland” and “Swiss law” and references to the “competent supervisory authority” and
             “competent courts” shall be replaced with references to the “Swiss Federal Data Protection Information
             Commissioner” and “competent Swiss courts”; and
         •   the Standard Contractual Clauses shall be governed by the laws of Switzerland and disputes shall be
             resolved before the competent Swiss courts.
    d.   If there is any conflict between the body of this DPA and the Standard Contractual Clauses, the Standard
         Contractual Clauses will prevail.
Audit. Upon Subscriber's written request, and subject to obligations of confidentiality, Acumatica shall provide
Subscriber a summary copy of its most recent SOC II audit report ("Report") so that Subscriber (or its third-party
auditors) can audit and verify Acumatica's compliance with this DPA. If the Report does not, in Subscriber's
reasonable judgement, provide sufficient information to confirm Acumatica's compliance with this DPA, then
Acumatica shall provide written responses (on a confidential basis) to all reasonable requests for information made
by Subscriber, including responses to information security and audit questionnaires that are necessary to confirm
Acumatica's compliance with this DPA.
Subscriber will not exercise its audit rights more than once in any twelve (12) calendar month period, except (i) if
and when required by instruction of a competent data protection authority (or other relevant authority competent for
enforcing Data Protection Laws); or (ii) Subscriber believes a further audit is necessary due to a Subscriber Data
Incident suffered by Acumatica.
Subscriber acknowledges and agrees that it shall exercise its audit rights under this DPA (including, where
applicable, the Standard Contractual Clauses) by instructing Acumatica to comply with the audit measures
described in this Section.

Onsite Audits: Except where otherwise required by Data Protection Laws or a data protection authority, the parties
agree that the audits right in the "Audit" section of this DPA satisfies Subscriber's requirements. Where Data
Protection Laws or a data protection authority requires it, Subscriber may provide Acumatica with thirty (30) days'
prior written notice requesting that a third party conduct an audit of Acumatica's relevant systems; provided that (i)
any such audit shall be conducted at Subscriber's expense; (ii) the parties shall mutually agree upon the scope,
timing and duration of such audit; (iii) the audit shall not unreasonably impact Acumatica's regular operations; and
(iv) in no event shall Subscriber obtain any access to data of any other Subscriber or third party.
Last Updated: July 2026

                      ANNEX I - DATA PROCESSING DESCRIPTION

 This Annex forms part of the DPA and describes the processing that Acumatica will perform on behalf of the
 Subscriber.

 A.      LIST OF PARTIES

 Controller(s) / Data exporter(s):

  1.    Name:                                         Subscriber, as defined in the Subscription SaaS
                                                      Services Agreement (“Agreement”)
        Address:                                      As set out in the Agreement and applicable Order
                                                      Forms.
        Contact person’s name, position and           The administrator contacts registered by the Subscriber
        contact details:                              when creating an account with Acumatica.
        Activities relevant to the data               Subscriber (data exporter) will use Acumatica's (data
        transferred under these Clauses:              importer's) enterprise resourcing planning platform for
                                                      personnel management purposes.

        Signature and date:                           This Annex I shall be deemed executed upon execution
                                                      of the Agreement.
        Role (controller/processor):                  Controller

Processor(s) / Data importer(s): [Identity and contact details of the processor(s) /data importer(s), including any
contact person with responsibility for data protection]

 1.    Name:                                         Acumatica, Inc. (“Acumatica”).
       Address:                                      3933 Lake Washington Blvd NE #350, Kirkland,
                                                     Washington 98033, USA.

       Contact person’s name, position and           Acumatica's legal counsel with responsibility for privacy
       contact details:                              can be contacted at [email protected].
       Activities relevant to the data transferred   Acumatica (data importer) is a provider of a cloud-
       under these Clauses:                          based enterprise resource planning platform.

       Signature and date:                           This Annex I shall be deemed executed upon execution
                                                     of the Agreement.
       Role (controller/processor):                  Processor

B. DESCRIPTION OF TRANSFER
 Categories of data subjects whose personal data is        The Data Exporter may submit Personal Data to
 transferred:                                              the Service, the extent of which is determined
                                                           and controlled by the Data Exporter in its sole
                                                           discretion.

                                                           The Personal Data may include but is not limited
                                                           to Personal Data concerning the Data Exporter’s
                                                           end users including employees, contractors and
                                                           the personnel of the Subscriber and its
                                                           suppliers, collaborators, and subcontractors.
                                                           Data Subjects also includes individuals
                                                           attempting to communicate with or transfer
                                                           Personal Data to the Data Exporter’s end users.

 Categories of personal data transferred:                  The Data Exporter may submit Personal Data to
                                                           the Acumatica Service, the extent of which is
                                                           determined and controlled by the Data Exporter
Last Updated: July 2026

                                                            in its sole discretion, and which may include, but
                                                            is not limited to the following categories of
                                                            Personal Data:

                                                                •   First and last name
                                                                •   Title
                                                                •   Position
                                                                •   Employer
                                                                •   Contact information (company, email,
                                                                    phone, physical business address)
                                                                •   ID data (username, user ID)
                                                                •   Professional life data
                                                                •   Professional skills information
                                                                •   Personal life data
                                                                •   Employee compensation information
                                                                •   Connection data
                                                                •   Localisation data
                                                                •   Website and platform usage information
                                                                •   Email data
                                                                •   Communications data (e.g. contained in
                                                                    live chat customer support inquiries)
                                                                •   System usage data
                                                                •   Application integration data
                                                                •   Transaction information (including
                                                                    amount, status and payment terminal ID)
                                                                •   Other electronic data submitted, stored,
                                                                    sent, or received by end users via the
                                                                    Acumatica Service

 Sensitive data transferred (if applicable) and             The Data Exporter may submit special
 applied restrictions or safeguards that fully take into    categories of Personal Data to the Acumatica
 consideration the nature of the data and the risks         Service, the extent of which is determined and
 involved, such as for instance strict purpose              controlled by the Data Exporter in its sole
 limitation, access restrictions (including access          discretion, and which may include, but is not
 only for staff having followed specialised training),      limited to the following categories of sensitive
 keeping a record of access to the data, restrictions       Personal Data:
 for onward transfers or additional security
 measures:                                                      •   Health and medical information
                                                                •   Other electronic sensitive data submitted,
                                                                    stored, sent, or received by end users via
                                                                    the Acumatica Service

                                                           Any such special categories of data will be
                                                           protected in accordance with the measures set out
                                                           in Annex II.

 The frequency of the transfer (e.g. whether the data      Continuous for the duration of the Acumatica
 is transferred on a one-off or continuous basis):         Service.

 Nature of the processing:                                 The provision of the Acumatica Service to
                                                           Subscriber in accordance with the Agreement.

 Purpose(s) of the data transfer and further                The Permitted Purposes (as defined in the DPA)
 processing:                                                shall include Processing or providing support
                                                            services to the Subscriber for Subscriber’s end
                                                            users. The Data Exporter also instructs the Data
                                                            Importer to process Personal Data in countries
                                                            in which the Data Importer or its Sub-processors
Last Updated: July 2026

                                                             maintain facilities as necessary for it to provide
                                                             the Service.

 The period for which the personal data will be             Data processing will be for the term specified in the
 retained, or, if that is not possible, the criteria used   Agreement. For the term of the Agreement, and for
 to determine that period:                                  a reasonable period of time after the expiry or
                                                            termination of the Agreement, the Data Importer will
                                                            provide the Data Exporter with access to, and the
                                                            ability to export, the Data Exporter’s Personal Data
                                                            Processed pursuant to the Agreement, following
                                                            which the Personal Data will be deleted.

 For transfers to (sub-) processors, also specify           The nature and duration of the processing are as
 subject matter, nature and duration of the                 set out above and in the Agreement.
 processing:
                                                            The subject matter of the processing concerns the
                                                            processing of the Personal Data about the
                                                            categories of Data Subjects, each as set out in this
                                                            Annex I.

C.      COMPETENT SUPERVISORY AUTHORITY
 Identify the competent supervisory authority/ies in        The competent supervisory authority will be
 accordance (e.g. in accordance with Clause 13              determined in accordance with Clause 13 of these
 SCCs)                                                      Standard Contractual Clauses.
Last Updated: July 2026

                         ANNEX II – TECHNICAL AND ORGANIZATIONAL SECURITY
                                             MEASURES

Description of the technical and organizational measures implemented by the processor(s) / data
importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into
account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms
of natural persons.

1.    As a “Software as a Service” (“SaaS”) provider, Acumatica’s approach to information security is a risk
      management imperative we share with our customers.

2.    Our information security program is designed to be consistent with internationally accepted standards and
      involves a layered, defense-in-depth approach to protecting the confidentiality, integrity, and, availability of
      systems and data, deploying administrative, technical, and physical controls.

3.    Our ERP solutions are designed and developed pursuant to secure software development lifecycle
      processes, for example, strict control over access to source code, rigorous code review and testing, and
      securely segregated development, test, and production environments.

4.    We require our entire team to review and certify compliance with a comprehensive set of information security
      policies, which we then monitor and enforce.

5.    We provide regular training to raise awareness regarding cybersecurity and data privacy issues and strive to
      maintain a corporate culture where employees are vigilant for cyber-threats and prepared for cybersecurity
      incidents.

6.    By hosting our SaaS in Amazon Web Services, we provide our customers with the security benefits that
      come with the most advanced cloud computing infrastructure on the planet. Aside from the formidable
      infrastructure security provided by Amazon, Acumatica has architected its services so that customer
      environments are securely segregated. Administrative access to Acumatica’s AWS services is strictly limited
      to a small number of Acumatica personnel on the basis of “need to know” and “least privilege” and requires
      the use of Multi-Factor Authentication.

7.    These Acumatica employees, as well as those who support customers and may need to access customer
      databases for support purposes, can only do so through encrypted channels via an Acumatica IP address.
      This means that Acumatica’s access to a customer database for support purposes requires a connection
      through either an Acumatica physical facility or office or the Acumatica VPN, which uses TLS 1.2 or IPSEC.
      The data associated with such activity is logged by our security personnel.

8.    Availability of customer data is ensured through a system of redundant backups across AWS regions, daily,
      weekly, monthly, and quarterly. The backups are encrypted as well as regularly tested. Retention of the
      various backups is scheduled to provide recovery under multiple different scenarios and varying historical
      timing implications.

9.    Acumatica uses leading-edge technology to ensure that the person who is trying to access your company’s
      data is exactly who they say they are. For example, user logins can be limited to specific IP addresses, which
      means that no one without a recognizable IP address will be able to access the system. A variety of password
      protection measures can be put in place as well. You can decide how often users are prompted to change
      their passwords. Password complexity requirements can help ensure only difficult-to-crack passwords are
      chosen. Even one-time password and single-sign-on solutions can be installed, which means a unique multi-
      factor method of access is required to gain access at every log-in attempt.

10.   Acumatica allows customers to control user access to their data, functions, and features that are necessary
      to the user’s role using a role-based access control approach.

11.   Acumatica offers data encryption as the main feature. Acumatica uses the same encryption technology that
      protects financial institutions as well as the United States military. Sensitive fields such as credit card and
      social security numbers within your SQL databases are encrypted. For internal systems Advanced
      Encryption Standard (AES) 128, 192, or 256-bit encryption. External access to Acumatica portal is via TLS
Last Updated: July 2026

12.    Acumatica has a fully staffed, highly trained, 24/7 security operations center already. It’s their responsibility to
       monitor and protect your data.

                                         ANNEX III – LIST OF SUB-PROCESSORS

 Subscriber expressly authorizes Acumatica to use the following Sub-processors in accordance with this DPA.

   Entity Name                          Details of Processing Activity        Location(s) of Processing
                                                                              Activity

   Amazon Web Services                  Cloud infrastructure provider         United States, Canada, United
                                        (Infrastructure as a service),        Kingdom and Singapore
                                        including service hosting and
                                        data storage
   Microsoft Corporation                Cloud infrastructure provider         United States
   (Microsoft Azure)                    (Infrastructure as a service),
                                        including service hosting and
                                        data storage

   Plaid Financial Ltd, an              For customers who choose to           United Kingdom
   authorized payment institution       link their banking account with
   regulated by the Financial           their Acumatica account:
   Conduct Authority (firm              Open banking connection and
   reference number 804718)             management, which provides
   under the Payment Services           regulated account information
   Regulations 2017                     services through Acumatica as
                                        its agent. Their privacy
                                        statement is accessible at:
                                        https://plaid.com/legal/#end-
                                        user-privacy-policy

   Elasticsearch, Inc.                  Logging and analytics tool for        United States
                                        support and debugging
                                        purposes.

   Intercom, Inc. (doing business       Customer engagement and               United States, Ireland, Australia
   as Fin)                              support platform including live
                                        chat, automated messaging, and
                                        help desk ticketing to facilitate
                                        communication with Acumatica
                                        end users and to help resolve
                                        customer support inquiries.