Third Party Index

Snapshot 49859

Document
Data processing addendum
URL
https://salescookie.com/Content/Downloads/DPA.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
433678 bytes
SHA-256 (raw)
0a3604fde9d6c94b93f44c4051537419022118329c84526359e7b6d73e7dfe80
SHA-256 (normalized text)
3272c12d7a77cee389f620afb137df04c3a9cb7f07db45576a49604fd6f3c009

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Data Processing Agreement
Addendum to Sales Cookie Terms of Service
Revision December 2025

Executing the Agreement
This Data Processing Agreement (the “DPA”) is entered into by and between Ninth Floor Technologies LLC
doing business as Sales Cookie, a WA State limited liability company (“Sales Cookie”) and the entity you
represent (the “Customer” or “you”).
The parties agree that this DPA sets forth their obligations with respect to the processing and security of
Customer Data and Personal Data in connection with Sales Cookie’s Services (collectively, the “Services”). The
DPA is incorporated by reference into the Sales Cookie’s Terms of Service. The parties also agree that, unless a
separate written agreement exists, this DPA governs the processing and security of all Customer Data and
Personal Data. The provisions of the DPA Terms supersede any conflicting provisions of the Sales Cookie
Privacy Policy Statement that otherwise may apply to processing of Customer Data, or Personal Data as defined
herein. The provisions of the DPA Terms do not supersede Sales Cookie’s Terms of Service.
The Customer enters into this DPA on behalf of itself and its authorized affiliates. To execute the DPA,
Customer must complete and sign the DPA’s signature page and send the DPA to Sales Cookie by email at
privacy@salescookie.com for counter-signature. Once the DPA has been signed by the Customer and Sales
Cookie, the DPA shall be in effect and legally bind the parties.

Applicable DPA Terms and Updates
New Features, Supplements, or Related Capabilities
Notwithstanding the foregoing limits on updates, when Sales Cookie introduces features, supplements or related
capabilities that are new (i.e., that were not previously included with a Customer’s subscription), Sales Cookie
may provide terms or make updates to the DPA that apply to Customer’s use of those new features,
supplements or capabilities. If those terms include any material adverse changes to the DPA Terms, Sales
Cookie will provide Customer a choice to use the new features, supplements, or related software, without loss
of existing functionality of the Services. If Customer does not use the new features, supplements, or related
software, the corresponding new terms will not apply.

Government Regulation and Requirements
Notwithstanding the foregoing limits on updates, Sales Cookie may modify or terminate the Services in any
country or jurisdiction where there is any current or future government requirement or obligation that (1)
subjects Sales Cookie to any regulation or requirement not generally applicable to businesses operating there,
(2) presents a hardship for Sales Cookie to continue operating the Services without modification, and/or (3)
causes Sales Cookie to believe the DPA Terms or the Services may conflict with any such requirement or
obligation.
Electronic Notices
Sales Cookie may provide Customer with information and notices about the Services electronically, including
via email, through the Sales Cookie website, or through a website that Sales Cookie identifies. Notice is given
as of the date it is made available by Sales Cookie.

Definitions
Capitalized terms used but not defined in this DPA will have the meanings provided in the Sales Cookie’s
Terms of Service. The following defined terms are used in this DPA:
“Customer Data” means all data, including all text, sound, video, or image files, and software, which are
provided to Sales Cookie by, or on behalf of, Customer through use of the Services or otherwise obtained or
processed by or on behalf of Sales Cookie through a professional services engagement with the Customer.
“Data Protection Requirements” means the GDPR, Local EU/EEA Data Protection Laws, and any applicable
laws, regulations, and other legal requirements relating to (a) privacy and data security; and (b) the use,
collection, retention, storage, security, disclosure, transfer, disposal, and other processing of any Personal Data.
“Diagnostic Data” means data collected or obtained by Sales Cookie from Customer in connection with the
Services. Diagnostic Data may also be referred to as telemetry. Diagnostic Data does not include Customer Data
or Service Generated Data.
“DPA Terms” means the terms in the DPA. In the event of any conflict or inconsistency between the DPA and
Sales Cookie’s Terms of Service, Sales Cookie’s Terms of Service shall prevail.
“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on
the protection of natural persons with regard to the processing of personal data and on the free movement of
such data and repealing Directive 95/46/EC (General Data Protection Regulation).
“Local EU/EEA Data Protection Laws” means any subordinate legislation and regulation implementing the
GDPR.
“GDPR Terms” means the terms regarding processing of Personal Data as per Article 28 of the GDPR.
“Personal Data” means any information relating to an identified or identifiable natural person. An identifiable
natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such
as a name, an identification number, location data, an online identifier or to one or more factors specific to the
physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Services” means usage of any aspect of the Site as defined in Sales Cookie’s Terms of Service, including any
professional services provided by Sales Cookie in relation to the Site.
“Service Generated Data” means data generated or derived by Sales Cookie through the operation of Services.
Service Generated Data does not include Customer Data or Diagnostic Data.
“Standard Contractual Clauses” means the standard contractual clauses for the transfer of Personal Data to third
countries pursuant to Regulation (EU) 2016/679 of the European Parliament and the Council approved by
European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 in the form set out at Annex 2.
“Sub processor” means other processors used by Sales Cookie to process Customer Data and Personal Data, as
described in Article 28 of the GDPR.
“Support Data” means all data, including all text, sound, video, image files, or software, which are provided to
Sales Cookie by or on behalf of Customer (or that Customer authorizes Sales Cookie to obtain from Services)
through Sales Cookie to obtain technical support for Services covered under this agreement. Support Data is a
subset of Customer Data.
Lower case terms used but not defined in this DPA, such as “personal data breach”, “processing”, “controller”,
“processor”, “profiling”, “personal data”, and “data subject” will have the same meaning as set forth in Article 4
of the GDPR, irrespective of whether GDPR applies. The terms “data importer” and “data exporter” have the
meanings given in the Standard Contractual Clauses.
For clarity, and as detailed above, data defined as Customer Data, Diagnostic Data, and Service Generated Data
may contain Personal Data. For illustrative purposes, please see the chart inserted below:
        Customer Data
        (“provided” by Customer)
        Diagnostic Data                                                                Personal Data
        (“collected” or “obtained” from Customer)                               (“information relating to an
        Service Generated Data                                                identified or identifiable natural
                                                                                          person”)
        (“generated” or “derived” by Sales Cookie)
        Support Data
        (“provided” by Customer in connection with technical support)

Above is a visual representation of the data types defined in the DPA. All Personal Data is processed as a part
of one of the other data types (all of which also include non-personal data). The DPA Terms focus on Customer
Data and Personal Data.

General Terms
Compliance with Laws
Sales Cookie will comply with all laws and regulations applicable to its provision of the Services, including
security breach notification law and data protection requirements. However, Sales Cookie is not responsible for
compliance with any laws or regulations applicable to Customer or Customer’s industry that are not generally
applicable to SaaS service providers. Sales Cookie does not determine whether Customer Data includes
information subject to any specific law or regulation. All Security Incidents are subject to the Security Incident
Notification terms below.
Customer must comply with all laws and regulations applicable to its use of Services, including laws related to
biometric data, confidentiality of communications, and Data Protection Requirements. Customer is responsible
for determining whether the Services are appropriate for storage and processing of information subject to any
specific law or regulation and for using the Services in a manner consistent with Customer’s legal and
regulatory obligations. Customer is responsible for responding to any request from a third-party regarding
Customer’s use of Services, such as a request to take down content under the U.S. Digital Millennium
Copyright Act or other applicable laws.
Data Processing Terms
This section of the DPA includes the following subsections:

•   Scope                                                      •   Processor Confidentiality Commitment
•   Nature of Data Processing; Ownership                       •   Notice and Controls on Use of Sub processors
•   Disclosure of Processed Data                               •   California Consumer Privacy Act (CCPA)
•   Processing of Personal Data; GDPR                              Terms
•   Data Security                                              •   Biometric Data
•   Security Incident Notification                             •   Limitation of Liability
•   Data Transfers and Location                                •   How to Contact Sales Cookie
•   Data Retention and Deletion                                •   Annex 1 – Standard Contractual Clauses
•   Annex 2 – Security Measures

Scope
The DPA Terms apply to all Sales Cookie Services.

Nature of Data Processing; Ownership
Sales Cookie will use and otherwise process Customer Data and Personal Data only (a) to provide Customer the
Services in accordance with Customer’s documented instructions, and (b) for Sales Cookie’s legitimate business
operations incident to delivery of the Services to Customer, each as detailed and limited below. As between the
parties, Customer retains all right, title and interest in and to Customer Data. Sales Cookie acquires no rights to
Customer Data, other than the rights Customer grants to Sales Cookie in this section. This paragraph does not
affect Sales Cookie’s rights over software or services Sales Cookie licenses to Customer.

Processing to Provide Customer the Services
For purposes of this DPA, “to provide” Services consists of:

    •   Delivering functional capabilities (calculating and managing commissions);
    •   Troubleshooting issues (monitoring, detecting, and repairing errors); and
    •   Ongoing improvement (installing updates, improving software).
When providing Services, Sales Cookie will not use or otherwise process Customer Data or Personal Data for:
(a) user profiling, (b) advertising or similar commercial purposes, or (c) market research aimed at creating new
functionalities, services, or products or any other purpose, unless such use or processing is in accordance with
Customer’s documented instructions.

Processing for Sales Cookie’s Legitimate Business Operations
For purposes of this DPA, “Sales Cookie’s legitimate business operations” consist of the following, each as
incident to delivery of the Services to Customer: (1) billing and account management; (2) commission
management (e.g., configuring and calculating incentive compensation including commissions and bonuses for
internal and external payees); (3) reporting and business modeling (e.g., incentive compensation planning,
management and administration); (4) combatting fraud, cybercrime, or cyber-attacks that may affect Sales
Cookie’s Services; (5) improving accessibility or security of the Services; and (6) and compliance with
accounting and legal obligations (subject to the limitations on disclosure of Processed Data outlined below).
When processing for Sales Cookie’s legitimate business operations, Sales Cookie will not use or otherwise
process Customer Data or Personal Data for: (a) user profiling, (b) advertising or similar commercial purposes,
or (c) any other purpose, other than for the purposes set out in this section.

Disclosure of Processed Data
Sales Cookie will not disclose or provide access to any Processed Data except: (1) as Customer directs; (2) as
described in this DPA; or (3) as required by law. For purposes of this section, “Processed Data” means: (a)
Customer Data; (b) Personal Data; and (c) any other data processed by Sales Cookie in connection with the
Services that is Customer’s confidential information under the Sales Cookie Terms. All processing of Processed
Data is subject to Sales Cookie’s obligation of confidentiality under the Sales Cookie Terms.
Sales Cookie will not disclose or provide access to any Processed Data to law enforcement unless required by
law. If law enforcement contacts Sales Cookie with a demand for Processed Data, Sales Cookie will attempt to
redirect the law enforcement agency to request that data directly from Customer. If compelled to disclose or
provide access to any Processed Data to law enforcement, Sales Cookie will promptly notify Customer and
provide a copy of the demand unless legally prohibited from doing so.
Upon receipt of any other third-party request for Processed Data, Sales Cookie will promptly notify Customer
unless prohibited by law. Sales Cookie will reject the request unless required by law to comply. If the request is
valid, Sales Cookie will attempt to redirect the third party to request the data directly from Customer.
Sales Cookie will not provide any third party: (a) direct, indirect, blanket, or unfettered access to Processed
Data; (b) platform encryption keys used to secure Processed Data or the ability to break such encryption; or (c)
access to Processed Data if Sales Cookie is aware that the data is to be used for purposes other than those stated
in the third party’s request.
In support of the above, Sales Cookie may provide Customer’s basic contact information to the third party.

Processing of Personal Data; GDPR
All Personal Data processed by Sales Cookie in connection with the Services is obtained as either Customer
Data, Diagnostic Data, or Service Generated Data. Personal Data provided to Sales Cookie by, or on behalf of,
Customer through use of the Services is also Customer Data. Pseudonymized identifiers may be included in
Diagnostic Data or Service Generated Data and are also Personal Data. Any Personal Data pseudonymized, or
de-identified but not anonymized, or Personal Data derived from other data is also Personal Data.
To the extent Sales Cookie is a processor or sub processor of Personal Data subject to the GDPR, the GDPR
Terms govern that processing, and the parties also agree to the following terms in this sub-section (“Processing
of Personal Data; GDPR”):
Processor and Controller Roles and Responsibilities
Customer and Sales Cookie agree that Customer is the controller of Personal Data and Sales Cookie is the
processor of such data, except (a) when Customer acts as a processor of Personal Data, in which case Sales
Cookie is a sub processor; or (b) as stated otherwise in the Services Terms or this DPA. When Sales Cookie acts
as the processor or Sub processor of Personal Data, it will process Personal Data only on documented
instructions from Customer. Customer agrees that Sales Cookie Services (including the DPA Terms and any
applicable updates), along with the product documentation and Customer’s use and configuration of features in
the Services, are Customer’s complete documented instructions to Sales Cookie for the processing of Personal
Data. Information on Sales Cookie’s Terms of Service can be found at https://salescookie.com/Home/Terms or
a successor location. Any additional or alternate instructions must be agreed to according to the Customer
specific agreement with Sales Cookie. In any instance where the GDPR applies and Customer is a processor,
Customer warrants to Sales Cookie that Customer’s instructions, including appointment of Sales Cookie as a
processor or sub processor, have been authorized by the relevant controller.
To the extent Sales Cookie uses or otherwise processes Personal Data subject to the GDPR for Sales Cookie’s
legitimate business operations incident to delivery of the Services to Customer, Sales Cookie will comply with
the obligations of an independent data controller under GDPR for such use. Sales Cookie is accepting the added
responsibilities of a data “controller” for processing in connection with its legitimate business operations to: (a)
act consistent with regulatory requirements, to the extent required under GDPR; and (b) provide increased
transparency to Customers and confirm Sales Cookie’s accountability for such processing. Sales Cookie
employs safeguards to protect Customer Data and Personal Data in processing, including those identified in this
DPA and those contemplated in Article 6(4) of the GDPR.

Processing Details
The parties acknowledge and agree that:
Subject Matter. The subject-matter of the processing is limited to Personal Data within the scope of the section
of this DPA entitled “Nature of Data Processing; Ownership” above and the GDPR.
Duration of the Processing. The duration of the processing shall be in accordance with Customer instructions
and the terms of the DPA.
Nature and Purpose of the Processing. The nature and purpose of the processing shall be to provide the
Services pursuant to Sales Cookie’s Terms of Service and for Sales Cookie’s legitimate business operations
incident to delivery of the Services to Customer (as further described in the section of this DPA entitled “Nature
of Data Processing; Ownership” above).
Categories of Data. The types of Personal Data processed by Sales Cookie when providing the Services
include: (i) Personal Data that Customer elects to include in Customer Data; and (ii) those expressly identified
in Article 4 of the GDPR that may be contained in Diagnostic Data or Service Generated Data. The types of
Personal Data that Customer elects to include in Customer Data may be any categories of Personal Data
identified in records maintained by Customer acting as controller pursuant to Article 30 of the GDPR, including
the categories of Personal Data set forth in The Standard Contractual Clauses (Processors) of the DPA.
Data Subjects. The categories of data subjects are Customer’s representatives and end users, such as
employees, contractors, collaborators, and customers, and may include any other categories of data subjects as
identified in records maintained by Customer acting as controller pursuant to Article 30 of the GDPR, including
the categories of data subjects set forth in The Standard Contractual Clauses (Processors) of the DPA.
Data Subject Rights; Assistance with Requests
Sales Cookie will make available to Customer, in a manner consistent with the functionality of the Services and
Sales Cookie’s role as a processor of Personal Data of data subjects, the ability to fulfill data subject requests to
exercise their rights under the GDPR. If Sales Cookie receives a request from Customer’s data subject to
exercise one or more of its rights under the GDPR in connection with Services for which Sales Cookie is a data
processor or Sub processor, Sales Cookie will redirect the data subject to make its request directly to Customer.
Customer will be responsible for responding to any such request including, where necessary, by using the
functionality of the Services. Sales Cookie shall comply with reasonable requests by Customer to assist with
Customer’s response to such a data subject request.
Records of Processing Activities
To the extent the GDPR requires Sales Cookie to collect and maintain records of certain information relating to
Customer, Customer will, where requested, supply such information to Sales Cookie and keep it accurate and
up to date. Sales Cookie may make any such information available to the supervisory authority if required by
the GDPR.

Data Security
Security Practices and Policies
Sales Cookie will implement and maintain appropriate technical and organizational measures to protect
Customer Data and Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized
disclosure of, or access to, personal data transmitted, stored or otherwise processed. Those measures shall be set
forth in a Sales Cookie Security Policy. Sales Cookie will make that policy available to Customer, along with
descriptions of the security controls in place for the Services and other information reasonably requested by
Customer regarding Sales Cookie security practices and policies. In addition, those measures shall comply with
the requirements set forth in ISO 27001, ISO 27002, and ISO 27018. Services implement and maintain security
measures set forth in Annex 2 for the protection of Customer Data.

Data Encryption
Customer Data (including any Personal Data therein) in transit over public networks between Customer and
Sales Cookie, or between Sales Cookie data centers, is encrypted by default. Sales Cookie also encrypts
Customer Data stored at rest in Services.
Data Access
Sales Cookie employs least privilege access mechanisms to control access to Customer Data (including any
Personal Data therein). For Services, Sales Cookie maintains Access Control mechanisms described in the table
entitled “Security Measures” in Annex 2 – Notices, and there is no standing access by Sales Cookie personnel
to Customer Data. Role-based access controls are employed to ensure that access to Customer Data required for
service operations is for an appropriate purpose, for a limited time, and approved with management oversight.

Customer Responsibilities
Customer is solely responsible for making an independent determination as to whether the technical and
organizational measures for Services meet Customer’s requirements, including any of its security obligations
under applicable Data Protection Requirements. Customer acknowledges and agrees that (taking into account
the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing of
its Personal Data as well as the risks to individuals) the security practices and policies implemented and
maintained by Sales Cookie provide a level of security appropriate to the risk with respect to its Personal Data.
Customer is responsible for implementing and maintaining privacy protections and security measures for
components that Customer provides or controls.

Auditing Compliance
Sales Cookie will maintain commercially reasonable internal security controls and auditing procedures to audit
its security measures. Upon request, we will provide (on a confidential basis) a summary of our previous audit
results.
To the extent Customer’s audit requirements under the Standard Contractual Clauses or Data Protection
Requirements cannot reasonably be satisfied through audit reports, documentation or compliance information
Sales Cookie makes generally available to its customers, Sales Cookie will promptly respond to Customer’s
additional audit instructions. Before the commencement of an audit, Customer and Sales Cookie will mutually
agree upon the scope, timing, duration, control and evidence requirements, and fees for the audit, provided that
this requirement to agree will not permit Sales Cookie to unreasonably delay performance of the audit. To the
extent needed to perform the audit, Sales Cookie will make the processing systems, facilities and supporting
documentation relevant to the processing of Customer Data and Personal Data by Sales Cookie, its Affiliates,
and its Sub processors available. Such an audit will be conducted by an independent, accredited third-party
audit firm, during regular business hours, with reasonable advance notice to Sales Cookie, and subject to
reasonable confidentiality procedures. Neither Customer nor the auditor shall have access to any data from
Sales Cookie’s other customers or to Sales Cookie systems or facilities not involved in the Services. Customer
is responsible for all costs and fees related to such audit, including all reasonable costs and fees for any and all
time Sales Cookie expends for any such audit, in addition to the rates for services performed by Sales Cookie. If
the audit report generated as a result of Customer’s audit includes any finding of material non-compliance,
Customer shall share such audit report with Sales Cookie and Sales Cookie shall promptly cure any material
non-compliance.
Nothing in this section of the DPA varies or modifies the standard Sales Cookie’s Terms of Service or affects
any supervisory authority’s or data subject’s rights under the Standard Contractual Clauses or Data Protection
Requirements.

Security Incident Notification
If Sales Cookie becomes aware of a breach of security leading to the accidental or unlawful destruction, loss,
alteration, unauthorized disclosure of, or access to Customer Data or Personal Data while processed by Sales
Cookie (each a “Security Incident”), Sales Cookie will promptly and without undue delay (1) notify Customer
of the Security Incident; (2) investigate the Security Incident and provide Customer with detailed information
about the Security Incident; (3) take reasonable steps to mitigate the effects and to minimize any damage
resulting from the Security Incident.
Notification(s) of Security Incidents will be delivered to one or more of Customer’s administrators by any
means Sales Cookie selects, including via email. It is Customer’s sole responsibility to ensure Customer’s
administrators maintain accurate contact information on each applicable Services portal. Customer is solely
responsible for complying with its obligations under incident notification laws applicable to Customer and
fulfilling any third-party notification obligations related to any Security Incident.
Sales Cookie shall make reasonable efforts to assist Customer in fulfilling Customer’s obligation under GDPR
Article 33 or other applicable law or regulation to notify the relevant supervisory authority and data subjects
about such Security Incident. Sales Cookie’s notification of or response to a Security Incident under this section
is not an acknowledgement by Sales Cookie of any fault or liability with respect to the Security Incident.
Customer must notify Sales Cookie promptly about any possible misuse of its accounts or authentication
credentials or any security incident related to Services.

Data Transfers and Location
Data Transfers
Customer Data and Personal Data that Sales Cookie processes on Customer’s behalf may not be transferred to
or stored and processed in a geographic location except in accordance with the DPA Terms and the safeguards
provided below in this section. Taking into account such safeguards, Customer appoints Sales Cookie to
transfer Customer Data and Personal Data to the United States or any other country in which Sales Cookie or its
Sub processors operate and to store and process Customer Data and Personal Data to provide the Services,
except as described elsewhere in the DPA Terms.
Sales Cookie will abide by the requirements of European Economic Area and Swiss data protection law
regarding the collection, use, transfer, retention, and other processing of Personal Data from the European
Economic Area, United Kingdom, and Switzerland. All transfers of Personal Data to a third country or an
international organization will be subject to appropriate safeguards as described in Article 46 of the GDPR and
such transfers and safeguards will be documented according to Article 30(2) of the GDPR.
In addition, Sales Cookie complies with the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks and the
commitments they entail, although Sales Cookie does not rely on the EU-U.S. Privacy Shield Framework as a
legal basis for transfers of Personal Data in light of the judgment of the Court of Justice of the EU in Case C-
311/18. Sales Cookie agrees to notify Customer if it makes a determination that it can no longer meet its
obligation to provide the same level of protection as is required by the Privacy Shield principles.

Location of Customer Data at Rest
For the Services, Sales Cookie will store Customer Data at rest within the United States only. Sales Cookie does
not control or limit the regions from which Customer or Customer’s end users may access or move Customer
Data.

Data Retention and Deletion
At all times during the term of Customer’s subscription, Customer will have the ability to access, extract and
delete Customer Data stored in Sales Cookie.
Except for free trials and free subscription services, Sales Cookie will retain Customer Data that remains stored
in a limited function account for 30 days after expiration or termination of Customer’s subscription so that
Customer may extract the data. After the 30-day retention period ends, Sales Cookie will disable Customer’s
account and delete the Customer Data and Personal Data, unless Sales Cookie is permitted or required by
applicable law, or authorized under this DPA, to retain such data.
The Services may not support retention or extraction of software provided by Customer. Sales Cookie has no
liability for the deletion of Customer Data or Personal Data as described in this section.

Processor Confidentiality Commitment
Sales Cookie will ensure that its personnel engaged in the processing of Customer Data and Personal Data (i)
will process such data only on instructions from Customer or as described in this DPA, and (ii) will be obligated
to maintain the confidentiality and security of such data even after their engagement ends. Sales Cookie shall
provide periodic and mandatory data privacy and security training and awareness to its employees with access
to Customer Data and Personal Data in accordance with applicable Data Protection Requirements and industry
standards.

Notice and Controls on use of Sub processors
Sales Cookie may hire sub processors to provide certain limited or ancillary services on its behalf. Customer
consents to this engagement and to Sales Cookie Affiliates as sub processors. The above authorizations will
constitute Customer’s prior written consent to the subcontracting by Sales Cookie of the processing of
Customer Data and Personal Data if such consent is required under the Standard Contractual Clauses or the
GDPR Terms.
Sales Cookie is responsible for its sub processors’ compliance with Sales Cookie’s obligations in this DPA.
Sales Cookie makes available information about sub processors on a Sales Cookie website. When engaging any
sub processor, Sales Cookie will ensure via a written contract that the Sub processor may access and use
Customer Data or Personal Data only to deliver the services Sales Cookie has retained them to provide and is
prohibited from using Customer Data or Personal Data for any other purpose. Sales Cookie will ensure that sub
processors are bound by written agreements that require them to provide at least the level of data protection
required of Sales Cookie by the DPA, including the limitations on disclosure of Processed Data. Sales Cookie
agrees to oversee the Sub processors to ensure that these contractual obligations are met.
From time to time, Sales Cookie may engage new sub processors. Sales Cookie will give Customer notice (by
updating the website and providing Customer with a mechanism to obtain notice of that update) of any new sub
processor at least 30 days in advance of providing that sub processor with access to Customer Data.
Additionally, Sales Cookie will give Customer notice (by updating the website and providing Customer with a
mechanism to obtain notice of that update) of any new sub processor at least 30 days in advance of providing
that sub processor with access to Personal Data other than that which is contained in Customer Data. If Sales
Cookie engages a new sub processor for new Services, Sales Cookie will give Customer notice prior to
availability of that Services.
If Customer does not approve of a new sub processor, then Customer may terminate any subscription for the
affected Services without penalty by providing, before the end of the relevant notice period, written notice of
termination. Customer may also include an explanation of the grounds for non-approval together with the
termination notice, in order to permit Sales Cookie to re-evaluate any such new sub processor based on the
applicable concerns. If the affected Services is part of a suite (or similar single purchase of services), then any
termination will apply to the entire suite. After termination, Sales Cookie will remove payment obligations for
any subscriptions for the terminated Services from subsequent invoices to the Customer.

California Consumer Privacy Act (CCPA)
If Sales Cookie is processing Personal Data within the scope of the CCPA, Sales Cookie makes the following
additional commitments to Customer. Sales Cookie will process Customer Data and Personal Data on behalf of
Customer and, not retain, use, or disclose that data for any purpose other than for the purposes set out in the
DPA Terms and as permitted under the CCPA, including under any “sale” exemption. In no event will Sales
Cookie sell any such data. These CCPA terms do not limit or reduce any data protection commitments Sales
Cookie makes to Customer in the DPA Terms, Sales Cookie Terms, or other agreement between Sales Cookie
and Customer.

Biometric Data
If Customer uses Services to process Biometric Data, Customer is responsible for: (i) providing notice to data
subjects, including with respect to retention periods and destruction; (ii) obtaining consent from data subjects;
and (iii) deleting the Biometric Data, all as appropriate and required under applicable Data Protection
Requirements. Sales Cookie will process that Biometric Data following Customer’s documented instructions (as
described in the “Processor and Controller Roles and Responsibilities” section above) and protect that
Biometric Data in accordance with the data security and protection terms under this DPA. For purposes of this
section, “Biometric Data” will have the meaning set forth in Article 4 of the GDPR and, if applicable,
equivalent terms in other Data Protection Requirements.

Limitation of Liability
The limitations of liability in the Sales Cookie’s Terms of Service apply.

How to Contact Sales Cookie
If Customer believes that Sales Cookie is not adhering to its privacy or security commitments, Customer may
contact Sales Cookie’s Data Protection Officer at privacy@salescookie.com. Sales Cookie’s mailing address is:
Sales Cookie
100 N Howard St, Ste R
Spokane, WA, 99201
USA

Legal Effect
This DPA shall only become legally binding between the Customer and Sales Cookie when the steps set out in
the section “Executing the Agreement” above have been fully completed.

EXECUTED BY THE PARTIES’ AUTHORIZED REPRESENTATIVES:

Ninth Floor Technologies LLC                                        Customer: ______________________
Signature: ______________________                                   Signature: ______________________
Name: _________________________                                     Name: _________________________
Title: __________________________                                   Title: __________________________
Date: ________________________                                      Date: _________________________
Annex 1 – Standard Contractual Clauses

                                                 SECTION I

                                                   Clause 1
                                              Purpose and scope
(a)    The purpose of these standard contractual clauses is to ensure compliance with the requirements of
       Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the
       protection of natural persons with regard to the processing of personal data and on the free movement of
       such data (General Data Protection Regulation) for the transfer of personal data to a third country.
(b)    The Parties:
       (i)    the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter
              “entity/ies”) transferring the personal data, as listed in Annex 1.A. (hereinafter each “data
              exporter”), and
       (ii)   the entity/ies in a third country receiving the personal data from the data exporter, directly or
              indirectly via another entity also Party to these Clauses, as listed in Annex I.A. (hereinafter each
              “data importer”)
       have agreed to these standard contractual clauses (hereinafter: “Clauses”).
(c)    These Clauses apply with respect to the transfer of personal data as specified in Annex I.B.
(d)    The Appendix to these Clauses containing the Annexes referred to therein forms an integral part of these
       Clauses.

                                                   Clause 2
                                    Effect and invariability of the Clauses
(a)    These Clauses set out appropriate safeguards, including enforceable data subject rights and effective
       legal remedies, pursuant to Article 46(1) and Article 46 (2)(c) of Regulation (EU) 2016/679 and, with
       respect to data transfers from controllers to processors and/or processors to processors, standard
       contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679, provided they are not
       modified, except to select the appropriate Module(s) or to add or update information in the Appendix.
       This does not prevent the Parties from including the standard contractual clauses laid down in these
       Clauses in a wider contract and/or to add other clauses or additional safeguards, provided that they do
       not contradict, directly or indirectly, these Clauses or prejudice the fundamental rights or freedoms of
       data subjects.
(b)    These Clauses are without prejudice to obligations to which the data exporter is subject by virtue of
       Regulation (EU) 2016/679.
                                                       Clause 3
                                              Third-party beneficiaries
(a)      Data subjects may invoke and enforce these Clauses, as third-party beneficiaries, against the data
         exporter and/or data importer, with the following exceptions:
         (i)    Clause 1, Clause 2, Clause 3, Clause 6, Clause 7;
         (ii)   Clause 8 - Clause 8.1(b), 8.9(a), (c), (d) and (e);
         (iii) Clause 9 - Module Two: Clause 9(a), (c), (d) and (e);
         (iv) Clause 12 - Clause 12(a), (d) and (f);
         (v)    Clause 13;
         (vi) Clause 15.1(c), (d) and (e);
         (vii) Clause 16(e);
         (viii) Clause 18 - Clause 18(a) and (b).
(b)      Paragraph (a) is without prejudice to rights of data subjects under Regulation (EU) 2016/679.

                                                       Clause 4
                                                    Interpretation
(a)      Where these Clauses use terms that are defined in Regulation (EU) 2016/679, those terms shall have the
         same meaning as in that Regulation.
(b)      These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679.
(c)      These Clauses shall not be interpreted in a way that conflicts with rights and obligations provided for in
         Regulation (EU) 2016/679.

                                                       Clause 5
                                                      Hierarchy
In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties,
existing at the time these Clauses are agreed or entered into thereafter, these Clauses shall prevail.

                                                       Clause 6
                                            Description of the transfer(s)
The details of the transfer(s), and in particular the categories of personal data that are transferred and the
purpose(s) for which they are transferred, are specified in Annex I.B.
                                                     Clause 7
                                                 Docking clause
(a)      An entity that is not a Party to these Clauses may, with the agreement of the Parties, accede to these
         Clauses at any time, either as a data exporter or as a data importer, by completing the Appendix and
         signing Annex I.A.
(b)      Once it has completed the Appendix and signed Annex I.A, the acceding entity shall become a Party to
         these Clauses and have the rights and obligations of a data exporter or data importer in accordance with
         its designation in Annex I.A.
(c)      The acceding entity shall have no rights or obligations arising under these Clauses from the period prior
         to becoming a Party.

                             SECTION II – OBLIGATIONS OF THE PARTIES

                                                     Clause 8
                                           Data protection safeguards
The data exporter warrants that it has used reasonable efforts to determine that the data importer is able, through
the implementation of appropriate technical and organisational measures, to satisfy its obligations under these
Clauses.

8.1    Instructions
(a)      The data importer shall process the personal data only on documented instructions from the data exporter.
         The data exporter may give such instructions throughout the duration of the contract.
(b)      The data importer shall immediately inform the data exporter if it is unable to follow those instructions.

8.2      Purpose limitation
The data importer shall process the personal data only for the specific purpose(s) of the transfer, as set out in
Annex I.B, unless on further instructions from the data exporter.

8.3      Transparency
On request, the data exporter shall make a copy of these Clauses, including the Appendix as completed by the
Parties, available to the data subject free of charge. To the extent necessary to protect business secrets or other
confidential information, including the measures described in Annex II and personal data, the data exporter may
redact part of the text of the Appendix to these Clauses prior to sharing a copy, but shall provide a meaningful
summary where the data subject would otherwise not be able to understand the its content or exercise his/her
rights. On request, the Parties shall provide the data subject with the reasons for the redactions, to the extent
possible without revealing the redacted information. This Clause is without prejudice to the obligations of the
data exporter under Articles 13 and 14 of Regulation (EU) 2016/679.
8.4      Accuracy
If the data importer becomes aware that the personal data it has received is inaccurate, or has become outdated, it
shall inform the data exporter without undue delay. In this case, the data importer shall cooperate with the data
exporter to erase or rectify the data.

8.5      Duration of processing and erasure or return of data
Processing by the data importer shall only take place for the duration specified in Annex I.B. After the end of the
provision of the processing services, the data importer shall, at the choice of the data exporter, delete all personal
data processed on behalf of the data exporter and certify to the data exporter that it has done so, or return to the
data exporter all personal data processed on its behalf and delete existing copies. Until the data is deleted or
returned, the data importer shall continue to ensure compliance with these Clauses. In case of local laws applicable
to the data importer that prohibit return or deletion of the personal data, the data importer warrants that it will
continue to ensure compliance with these Clauses and will only process it to the extent and for as long as required
under that local law. This is without prejudice to Clause 14, in particular the requirement for the data importer
under Clause 14(e) to notify the data exporter throughout the duration of the contract if it has reason to believe
that it is or has become subject to laws or practices not in line with the requirements under Clause 14(a).

8.6      Security of processing
(a)      The data importer and, during transmission, also the data exporter shall implement appropriate technical
         and organisational measures to ensure the security of the data, including protection against a breach of
         security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access
         to that data (hereinafter “personal data breach”). In assessing the appropriate level of security, the Parties
         shall take due account of the state of the art, the costs of implementation, the nature, scope, context and
         purpose(s) of processing and the risks involved in the processing for the data subjects. The Parties shall
         in particular consider having recourse to encryption or pseudonymisation, including during transmission,
         where the purpose of processing can be fulfilled in that manner. In case of pseudonymisation, the
         additional information for attributing the personal data to a specific data subject shall, where possible,
         remain under the exclusive control of the data exporter. In complying with its obligations under this
         paragraph, the data importer shall at least implement the technical and organisational measures specified
         in Annex II. The data importer shall carry out regular checks to ensure that these measures continue to
         provide an appropriate level of security.
(b)      The data importer shall grant access to the personal data to members of its personnel only to the extent
         strictly necessary for the implementation, management and monitoring of the contract. It shall ensure
         that persons authorised to process the personal data have committed themselves to confidentiality or are
         under an appropriate statutory obligation of confidentiality.
(c)      In the event of a personal data breach concerning personal data processed by the data importer under
         these Clauses, the data importer shall take appropriate measures to address the breach, including
         measures to mitigate its adverse effects. The data importer shall also notify the data exporter without
         undue delay after having become aware of the breach. Such notification shall contain the details of a
         contact point where more information can be obtained, a description of the nature of the breach
         (including, where possible, categories and approximate number of data subjects and personal data
         records concerned), its likely consequences and the measures taken or proposed to address the breach
         including, where appropriate, measures to mitigate its possible adverse effects. Where, and in so far as,
         it is not possible to provide all information at the same time, the initial notification shall contain the
         information then available and further information shall, as it becomes available, subsequently be
         provided without undue delay.
(d)      The data importer shall cooperate with and assist the data exporter to enable the data exporter to comply
         with its obligations under Regulation (EU) 2016/679, in particular to notify the competent supervisory
         authority and the affected data subjects, taking into account the nature of processing and the information
         available to the data importer.

8.7      Sensitive data
Where the transfer involves personal data revealing racial or ethnic origin, political opinions, religious or
philosophical beliefs, or trade union membership, genetic data, or biometric data for the purpose of uniquely
identifying a natural person, data concerning health or a person’s sex life or sexual orientation, or data relating to
criminal convictions and offences (hereinafter “sensitive data”), the data importer shall apply the specific
restrictions and/or additional safeguards described in Annex I.B.

8.8      Onward transfers
The data importer shall only disclose the personal data to a third party on documented instructions from the data
exporter. In addition, the data may only be disclosed to a third party located outside the European Union (in the
same country as the data importer or in another third country, hereinafter “onward transfer”) if the third party is
or agrees to be bound by these Clauses, under the appropriate Module, or if:
         (i)    the onward transfer is to a country benefitting from an adequacy decision pursuant to Article 45 of
                Regulation (EU) 2016/679 that covers the onward transfer;
         (ii)   the third party otherwise ensures appropriate safeguards pursuant to Articles 46 or 47 Regulation
                of (EU) 2016/679 with respect to the processing in question;
         (iii) the onward transfer is necessary for the establishment, exercise or defence of legal claims in the
               context of specific administrative, regulatory or judicial proceedings; or
         (iv) the onward transfer is necessary in order to protect the vital interests of the data subject or of
              another natural person.

Any onward transfer is subject to compliance by the data importer with all the other safeguards under these
Clauses, in particular purpose limitation.
8.9   Documentation and compliance
(a)   The data importer shall promptly and adequately deal with enquiries from the data exporter that relate to
      the processing under these Clauses.
(b)   The Parties shall be able to demonstrate compliance with these Clauses. In particular, the data importer
      shall keep appropriate documentation on the processing activities carried out on behalf of the data
      exporter.
(c)   The data importer shall make available to the data exporter all information necessary to demonstrate
      compliance with the obligations set out in these Clauses and at the data exporter’s request, allow for and
      contribute to audits of the processing activities covered by these Clauses, at reasonable intervals or if
      there are indications of non-compliance. In deciding on a review or audit, the data exporter may take into
      account relevant certifications held by the data importer.
(d)   The data exporter may choose to conduct the audit by itself or mandate an independent auditor. Audits
      may include inspections at the premises or physical facilities of the data importer and shall, where
      appropriate, be carried out with reasonable notice.
(e)   The Parties shall make the information referred to in paragraphs (b) and (c), including the results of any
      audits, available to the competent supervisory authority on request.

                                                 Clause 9
                                          Use of sub-processors
(a)   The data importer has the data exporter’s general authorisation for the engagement of sub-processor(s)
      from an agreed list. The data importer shall specifically inform the data exporter in writing of any
      intended changes to that list through the addition or replacement of sub-processors at least 30 business
      days in advance, thereby giving the data exporter sufficient time to be able to object to such changes
      prior to the engagement of the sub-processor(s). The data importer shall provide the data exporter with
      the information necessary to enable the data exporter to exercise its right to object.
(b)   Where the data importer engages a sub-processor to carry out specific processing activities (on behalf of
      the data exporter), it shall do so by way of a written contract that provides for, in substance, the same
      data protection obligations as those binding the data importer under these Clauses, including in terms of
      third-party beneficiary rights for data subjects. The Parties agree that, by complying with this Clause,
      the data importer fulfils its obligations under Clause 8.8. The data importer shall ensure that the sub-
      processor complies with the obligations to which the data importer is subject pursuant to these Clauses.
(c)   The data importer shall provide, at the data exporter’s request, a copy of such a sub-processor agreement
      and any subsequent amendments to the data exporter. To the extent necessary to protect business secrets
      or other confidential information, including personal data, the data importer may redact the text of the
      agreement prior to sharing a copy.
(d)   The data importer shall remain fully responsible to the data exporter for the performance of the sub-
      processor’s obligations under its contract with the data importer. The data importer shall notify the data
      exporter of any failure by the sub-processor to fulfil its obligations under that contract.
(e)   The data importer shall agree a third-party beneficiary clause with the sub-processor whereby - in the
      event the data importer has factually disappeared, ceased to exist in law or has become insolvent - the
      data exporter shall have the right to terminate the sub-processor contract and to instruct the sub-processor
      to erase or return the personal data.

                                                  Clause 10
                                             Data subject rights

(a)   The data importer shall promptly notify the data exporter of any request it has received from a data
      subject. It shall not respond to that request itself unless it has been authorised to do so by the data
      exporter.
(b)   The data importer shall assist the data exporter in fulfilling its obligations to respond to data subjects’
      requests for the exercise of their rights under Regulation (EU) 2016/679. In this regard, the Parties shall
      set out in Annex II the appropriate technical and organisational measures, taking into account the nature
      of the processing, by which the assistance shall be provided, as well as the scope and the extent of the
      assistance required.
(c)   In fulfilling its obligations under paragraphs (a) and (b), the data importer shall comply with the
      instructions from the data exporter.

                                                  Clause 11
                                                   Redress
(a)   The data importer shall inform data subjects in a transparent and easily accessible format, through
      individual notice or on its website, of a contact point authorised to handle complaints. It shall deal
      promptly with any complaints it receives from a data subject.

(b)   In case of a dispute between a data subject and one of the Parties as regards compliance with these
      Clauses, that Party shall use its best efforts to resolve the issue amicably in a timely fashion. The Parties
      shall keep each other informed about such disputes and, where appropriate, cooperate in resolving them.
(c)   Where the data subject invokes a third-party beneficiary right pursuant to Clause 3, the data importer
      shall accept the decision of the data subject to:
      (i)    lodge a complaint with the supervisory authority in the Member State of his/her habitual residence
             or place of work, or the competent supervisory authority pursuant to Clause 13;
      (ii)   refer the dispute to the competent courts within the meaning of Clause 18.
(d)   The Parties accept that the data subject may be represented by a not-for-profit body, organisation or
      association under the conditions set out in Article 80(1) of Regulation (EU) 2016/679.
(e)   The data importer shall abide by a decision that is binding under the applicable EU or Member State law.
(f)   The data importer agrees that the choice made by the data subject will not prejudice his/her substantive
      and procedural rights to seek remedies in accordance with applicable laws.
                                                  Clause 12
                                                  Liability

(a)   Each Party shall be liable to the other Party/ies for any damages it causes the other Party/ies by any
      breach of these Clauses.
(b)   The data importer shall be liable to the data subject, and the data subject shall be entitled to receive
      compensation, for any material or non-material damages the data importer or its sub-processor causes
      the data subject by breaching the third-party beneficiary rights under these Clauses.
(c)   Notwithstanding paragraph (b), the data exporter shall be liable to the data subject, and the data subject
      shall be entitled to receive compensation, for any material or non-material damages the data exporter or
      the data importer (or its sub-processor) causes the data subject by breaching the third-party beneficiary
      rights under these Clauses. This is without prejudice to the liability of the data exporter and, where the
      data exporter is a processor acting on behalf of a controller, to the liability of the controller under
      Regulation (EU) 2016/679 or Regulation (EU) 2018/1725, as applicable.
(d)   The Parties agree that if the data exporter is held liable under paragraph (c) for damages caused by the
      data importer (or its sub-processor), it shall be entitled to claim back from the data importer that part of
      the compensation corresponding to the data importer’s responsibility for the damage.
(e)   Where more than one Party is responsible for any damage caused to the data subject as a result of a
      breach of these Clauses, all responsible Parties shall be jointly and severally liable and the data subject
      is entitled to bring an action in court against any of these Parties.
(f)   The Parties agree that if one Party is held liable under paragraph (e), it shall be entitled to claim back
      from the other Party/ies that part of the compensation corresponding to its / their responsibility for the
      damage.
(g)   The data importer may not invoke the conduct of a sub-processor to avoid its own liability.

                                                  Clause 13
                                                 Supervision
(a)   The supervisory authority with responsibility for ensuring compliance by the data exporter with
      Regulation (EU) 2016/679 as regards the data transfer, as indicated in Annex I.C, shall act as competent
      supervisory authority.
(b)   The data importer agrees to submit itself to the jurisdiction of and cooperate with the competent
      supervisory authority in any procedures aimed at ensuring compliance with these Clauses. In particular,
      the data importer agrees to respond to enquiries, submit to audits and comply with the measures adopted
      by the supervisory authority, including remedial and compensatory measures. It shall provide the
      supervisory authority with written confirmation that the necessary actions have been taken.
      SECTION III – LOCAL LAWS AND OBLIGATIONS IN CASE OF ACCESS BY PUBLIC
                                  AUTHORITIES

                                                    Clause 14
                       Local laws and practices affecting compliance with the Clauses

(a)    The Parties warrant that they have no reason to believe that the laws and practices in the third country of
       destination applicable to the processing of the personal data by the data importer, including any
       requirements to disclose personal data or measures authorising access by public authorities, prevent the
       data importer from fulfilling its obligations under these Clauses. This is based on the understanding that
       laws and practices that respect the essence of the fundamental rights and freedoms and do not exceed
       what is necessary and proportionate in a democratic society to safeguard one of the objectives listed in
       Article 23(1) of Regulation (EU) 2016/679, are not in contradiction with these Clauses.
(b)    The Parties declare that in providing the warranty in paragraph (a), they have taken due account in
       particular of the following elements:
       (i)    the specific circumstances of the transfer, including the length of the processing chain, the number
              of actors involved and the transmission channels used; intended onward transfers; the type of
              recipient; the purpose of processing; the categories and format of the transferred personal data; the
              economic sector in which the transfer occurs; the storage location of the data transferred;
       (ii)   the laws and practices of the third country of destination– including those requiring the disclosure
              of data to public authorities or authorising access by such authorities – relevant in light of the
              specific circumstances of the transfer, and the applicable limitations and safeguards;
       (iii) any relevant contractual, technical or organisational safeguards put in place to supplement the
             safeguards under these Clauses, including measures applied during transmission and to the
             processing of the personal data in the country of destination.
(c)    The data importer warrants that, in carrying out the assessment under paragraph (b), it has made its best
       efforts to provide the data exporter with relevant information and agrees that it will continue to cooperate
       with the data exporter in ensuring compliance with these Clauses.
(d)    The Parties agree to document the assessment under paragraph (b) and make it available to the competent
       supervisory authority on request.
(e)    The data importer agrees to notify the data exporter promptly if, after having agreed to these Clauses and
       for the duration of the contract, it has reason to believe that it is or has become subject to laws or practices
       not in line with the requirements under paragraph (a), including following a change in the laws of the
       third country or a measure (such as a disclosure request) indicating an application of such laws in practice
       that is not in line with the requirements in paragraph (a). [For Module Three: The data exporter shall
       forward the notification to the controller.]
(f)    Following a notification pursuant to paragraph (e), or if the data exporter otherwise has reason to believe
       that the data importer can no longer fulfil its obligations under these Clauses, the data exporter shall
       promptly identify appropriate measures (e.g. technical or organisational measures to ensure security and
       confidentiality) to be adopted by the data exporter and/or data importer to address the situation. The data
       exporter shall suspend the data transfer if it considers that no appropriate safeguards for such transfer
       can be ensured, or if instructed by the competent supervisory authority to do so. In this case, the data
       exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data
       under these Clauses. If the contract involves more than two Parties, the data exporter may exercise this
       right to termination only with respect to the relevant Party, unless the Parties have agreed otherwise.
       Where the contract is terminated pursuant to this Clause, Clause 16(d) and (e) shall apply.

                                                   Clause 15
                   Obligations of the data importer in case of access by public authorities

15.1   Notification
(a)    The data importer agrees to notify the data exporter and, where possible, the data subject promptly (if
       necessary with the help of the data exporter) if it:
       (i)    receives a legally binding request from a public authority, including judicial authorities, under the
              laws of the country of destination for the disclosure of personal data transferred pursuant to these
              Clauses; such notification shall include information about the personal data requested, the
              requesting authority, the legal basis for the request and the response provided; or
       (ii)   becomes aware of any direct access by public authorities to personal data transferred pursuant to
              these Clauses in accordance with the laws of the country of destination; such notification shall
              include all information available to the importer.
(b)    If the data importer is prohibited from notifying the data exporter and/or the data subject under the laws
       of the country of destination, the data importer agrees to use its best efforts to obtain a waiver of the
       prohibition, with a view to communicating as much information as possible, as soon as possible. The
       data importer agrees to document its best efforts in order to be able to demonstrate them on request of
       the data exporter.
(c)    Where permissible under the laws of the country of destination, the data importer agrees to provide the
       data exporter, at regular intervals for the duration of the contract, with as much relevant information as
       possible on the requests received (in particular, number of requests, type of data requested, requesting
       authority/ies, whether requests have been challenged and the outcome of such challenges, etc.).
(d)    The data importer agrees to preserve the information pursuant to paragraphs (a) to (c) for the duration of
       the contract and make it available to the competent supervisory authority on request.
(e)    Paragraphs (a) to (c) are without prejudice to the obligation of the data importer pursuant to Clause 14(e)
       and Clause 16 to inform the data exporter promptly where it is unable to comply with these Clauses.

15.2   Review of legality and data minimisation
(a)    The data importer agrees to review the legality of the request for disclosure, in particular whether it
       remains within the powers granted to the requesting public authority, and to challenge the request if,
       after careful assessment, it concludes that there are reasonable grounds to consider that the request is
       unlawful under the laws of the country of destination, applicable obligations under international law and
       principles of international comity. The data importer shall, under the same conditions, pursue
       possibilities of appeal. When challenging a request, the data importer shall seek interim measures with a
       view to suspending the effects of the request until the competent judicial authority has decided on its
       merits. It shall not disclose the personal data requested until required to do so under the applicable
      procedural rules. These requirements are without prejudice to the obligations of the data importer under
      Clause 14(e).
(b)   The data importer agrees to document its legal assessment and any challenge to the request for disclosure
      and, to the extent permissible under the laws of the country of destination, make the documentation
      available to the data exporter. It shall also make it available to the competent supervisory authority on
      request.
(c)   The data importer agrees to provide the minimum amount of information permissible when responding
      to a request for disclosure, based on a reasonable interpretation of the request.

                                  SECTION IV – FINAL PROVISIONS

                                                  Clause 16
                             Non-compliance with the Clauses and termination
(a)   The data importer shall promptly inform the data exporter if it is unable to comply with these Clauses,
      for whatever reason.
(b)   In the event that the data importer is in breach of these Clauses or unable to comply with these Clauses,
      the data exporter shall suspend the transfer of personal data to the data importer until compliance is again
      ensured or the contract is terminated. This is without prejudice to Clause 14(f).
(c)   The data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of
      personal data under these Clauses, where:
      (i)    the data exporter has suspended the transfer of personal data to the data importer pursuant to
             paragraph (b) and compliance with these Clauses is not restored within a reasonable time and in
             any event within one month of suspension;
      (ii)   the data importer is in substantial or persistent breach of these Clauses; or
      (iii) the data importer fails to comply with a binding decision of a competent court or supervisory
            authority regarding its obligations under these Clauses.
      In these cases, it shall inform the competent supervisory authority of such non-compliance. Where the
      contract involves more than two Parties, the data exporter may exercise this right to termination only
      with respect to the relevant Party, unless the Parties have agreed otherwise.
(d)   Personal data that has been transferred prior to the termination of the contract pursuant to paragraph (c)
      shall at the choice of the data exporter immediately be returned to the data exporter or deleted in its
      entirety. The same shall apply to any copies of the data. The data importer shall certify the deletion of
      the data to the data exporter. Until the data is deleted or returned, the data importer shall continue to
      ensure compliance with these Clauses. In case of local laws applicable to the data importer that prohibit
      the return or deletion of the transferred personal data, the data importer warrants that it will continue to
      ensure compliance with these Clauses and will only process the data to the extent and for as long as
      required under that local law.
(e)   Either Party may revoke its agreement to be bound by these Clauses where (i) the European Commission
      adopts a decision pursuant to Article 45(3) of Regulation (EU) 2016/679 that covers the transfer of
      personal data to which these Clauses apply; or (ii) Regulation (EU) 2016/679 becomes part of the legal
        framework of the country to which the personal data is transferred. This is without prejudice to other
        obligations applying to the processing in question under Regulation (EU) 2016/679.

                                                   Clause 17
                                                Governing law
These Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third-
party beneficiary rights. The Parties agree that this shall be the law of the Republic of Ireland.

                                                   Clause 18
                                       Choice of forum and jurisdiction
(a)     Any dispute arising from these Clauses shall be resolved by the courts of an EU Member State.
(b)     The Parties agree that those shall be the courts of Republic of Ireland.
(c)     A data subject may also bring legal proceedings against the data exporter and/or data importer before the
        courts of the Member State in which he/she has his/her habitual residence.
(d)     The Parties agree to submit themselves to the jurisdiction of such courts.
                                                   APPENDIX

A. LIST OF PARTIES

Data exporter(s):
The individual or entity that has entered into the agreement with data importer for the provision of
application(s) as described in the agreement.

Activities relevant to the data transferred under these Clauses: Uploading of data into the application(s) of
processor.

Role (controller/processor): Controller

Data importer(s):
Name: Ninth Floor Technologies LLC
Address: 100 N Howard St, Ste R, Spokane, WA, 99201, USA

Contact: Data Protection Officer - privacy@salescookie.com
Activities relevant to the data transferred under these Clauses: Processing of data uploaded into the
application(s) by data exporter.

Role (controller/processor): Processor

B. DESCRIPTION OF TRANSFER
Categories of data subjects whose personal data is transferred

The data subjects may include the data exporters customers, employees, suppliers, end-users, and other
individuals included in content uploaded to the application(s).

Categories of personal data transferred

The data exporter determines the categories of personal data included, if any, in the content uploaded to the
application(s).

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into
consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access
restrictions (including access only for staff having followed specialized training), keeping a record of access to
the data, restrictions for onward transfers or additional security measures.

Not Applicable.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).

The data exporter determines the frequency of the transfer through their use of the application(s).

Nature of the processing

The processing of personal data referred to under these Standard Contractual Clauses shall occur throughout the
term of this Standard Contractual Clauses and the provision of application(s).

Purpose(s) of the data transfer and further processing

To provide the application(s) as described in the agreement.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine
that period

Please see the applicable section of the processor agreement.

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing

The data exporter determines the subject matter, nature, and duration of processing of personal data transferred
to sub-processor(s).

C. COMPETENT SUPERVISORY AUTHORITY

The Irish supervisory authority, The Data Protection Commission
Annex 2 – Security Measures
Sales Cookie has implemented and will maintain for Customer Data in the Services the following security
measures, which in conjunction with the security commitments in this DPA (including the GDPR Terms), are
Sales Cookie’s only responsibility with respect to the security of that data.

 Domain                 Practices
                        Security Ownership. Sales Cookie has appointed a security officer responsible
                        for coordinating and monitoring the security rules and procedures.
                        Security Roles and Responsibilities. Sales Cookie personnel with access to
 Organization of        Customer Data are subject to confidentiality obligations.
 Information Security   Risk Management Program. Sales Cookie performed a risk assessment before
                        launching the Services and processing Customer Data.
                        Sales Cookie retains its security documents pursuant to its retention requirements
                        after they are no longer in effect.
                        Asset Handling
                        - Sales Cookie classifies Customer Data to help identify it and to allow for access
                        to it to be appropriately restricted.
                        - Sales Cookie imposes restrictions on printing Customer Data and has procedures
 Asset Management
                        for disposing of printed materials that contain Customer Data.
                        Sales Cookie personnel must obtain Sales Cookie authorization prior to storing
                        Customer Data on portable devices, remotely accessing Customer Data, or
                        processing Customer Data outside Sales Cookie’s facilities.
                        Security Training. Sales Cookie informs its personnel about relevant security
 Human Resources        procedures and their respective roles. Sales Cookie also informs its personnel of
 Security               possible consequences of breaching the security rules and procedures. Sales
                        Cookie will only use anonymous data in training.
                        Physical Access to Facilities. Sales Cookie limits access to facilities where
                        information systems that process Customer Data are located to identified
                        authorized individuals.
 Physical and           Protection from Disruptions. Sales Cookie uses a variety of industry standard
 Environmental Security systems to protect against loss of data due to power supply failure or line
                        interference.
                        Component Disposal. Sales Cookie uses industry standard processes to delete
                        Customer Data when it is no longer needed.
                        Operational Policy. Sales Cookie maintains security documents describing its
                        security measures and the relevant procedures and responsibilities of its personnel
                        who have access to Customer Data.
                        Data Recovery Procedures
 Communications and
                        - Sales Cookie utilizes Microsoft Azure’s data recovery procedures for all data
 Operations Management
                        stored in the Azure cloud.
                        - Sales Cookie has specific procedures in place governing access to copies of
                        Customer Data.
                        - Sales Cookie reviews data recovery procedures every twelve months.
Domain           Practices
                 - Sales Cookie logs data restoration efforts, including the person responsible, the
                 description of the restored data and where applicable, the person responsible and
                 which data (if any) had to be input manually in the data recovery process.
                 Malicious Software. Sales Cookie has anti-malware controls to help avoid
                 malicious software gaining unauthorized access to Customer Data, including
                 malicious software originating from public networks.
                 Data Beyond Boundaries
                 - Sales Cookie encrypts, or enables Customer to encrypt, Customer Data that is
                 transmitted over public networks.
                 Event Logging. Sales Cookie logs, or enables Customer to log, access and use of
                 information systems containing Customer Data, registering the access ID, time,
                 authorization granted or denied, and relevant activity.
                 Access Policy. Sales Cookie maintains a record of security privileges of
                 individuals having access to Customer Data.
                 Access Authorization
                 - Sales Cookie maintains and updates a record of personnel authorized to access
                 Sales Cookie systems that contain Customer Data.
                 - Sales Cookie deactivates authentication credentials that have not been used for a
                 period not to exceed six months.
                 - Sales Cookie identifies those personnel who may grant, alter or cancel
                 authorized access to data and resources.
                 - Sales Cookie ensures that where more than one individual has access to systems
                 containing Customer Data, the individuals have separate identifiers/log-ins.
                 Least Privilege
                 - Technical support personnel are only permitted to have access to Customer Data
                 when needed.
                 - Sales Cookie restricts access to Customer Data to only those individuals who
                 require such access to perform their job function.
Access Control   Integrity and Confidentiality
                 - Sales Cookie instructs Sales Cookie personnel to disable administrative sessions
                 when leaving premises Sales Cookie controls or when computers are otherwise
                 left unattended.
                 - Sales Cookie stores passwords in a way that makes them unintelligible while
                 they are in force.
                 Authentication
                 - Sales Cookie uses industry standard practices to identify and authenticate users
                 who attempt to access information systems.
                 - Where authentication mechanisms are based on passwords, Sales Cookie
                 requires that the passwords be renewed regularly.
                 - Where authentication mechanisms are based on passwords, Sales Cookie
                 requires the password to be at least eight characters long.
                 - Sales Cookie ensures that de-activated or expired identifiers are not granted to
                 other individuals.
                 - Sales Cookie monitors, or enables Customer to monitor, repeated attempts to
                 gain access to the information system using an invalid password.
Domain                 Practices
                       - Sales Cookie maintains industry standard procedures to deactivate passwords
                       that have been corrupted or inadvertently disclosed.
                       - Sales Cookie uses industry standard password protection practices, including
                       practices designed to maintain the confidentiality and integrity of passwords when
                       they are assigned and distributed, and during storage.
                       Network Design. Sales Cookie has controls to avoid individuals assuming access
                       rights they have not been assigned to gain access to Customer Data they are not
                       authorized to access.
                       Incident Response Process
                       - Sales Cookie maintains a record of security breaches with a description of the
                       breach, the time period, the consequences of the breach, the name of the reporter,
                       and to whom the breach was reported, and the procedure for recovering data.
                       - For each security breach that is a Security Incident, notification by Sales Cookie
Information Security
                       (as described in the “Security Incident Notification” section above) will be made
Incident Management
                       without undue delay and, in any event, within 72 hours.
                       - Sales Cookie tracks, or enables Customer to track, disclosures of Customer Data,
                       including what data has been disclosed, to whom, and at what time.
                       Service Monitoring. Sales Cookie security personnel verify logs at least every six
                       months to propose remediation efforts if necessary.
                       - Sales Cookie utilizes Microsoft Azure’s emergency and contingency plans for
                       the Customer Data stored in the Azure cloud.
Business Continuity
                       - Sales Cookie utilizes Microsoft Azure’s redundant storage and its procedures for
Management
                       recovering data are designed to attempt to reconstruct Customer Data in its
                       original or last-replicated state from before the time it was lost or destroyed.