Third Party Index

Snapshot 56837

Document
Data processing addendum
URL
https://www.kinaxis.com/sites/default/files/saas-services-data-privacy-addendum-for-customers-kinaxis.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
251710 bytes
SHA-256 (raw)
d20ee9eb3ec4c0f7977ceba31d0528d3702c9d2bcc252d69debe357d1e7762d0
SHA-256 (normalized text)
bf9bf16235085fc9dc01b85e9900fc62eaaaafa9803e5fd267548249dc1a0a03

Normalized text

Scripts and page chrome removed; this is what change detection compares.

                              DATA PROCESSING AGREEMENT
                                                 (“DPA”)

1.      Scope and Applicability

        1.1     This DPA, including its Schedules, is incorporated into and forms part of each of the
                written agreement(s) between Kinaxis and Customer for the provision of certain software
                as a service and related professional and implementation services by Kinaxis to
                Customer (“Main Agreement”), as such services are further specified in the Main
                Agreements (the “Services”). This DPA applies to Kinaxis’s Processing of Customer
                Personal Data, subject to Applicable Data Protection Laws.

        1.2     The schedules to this DPA set out the applicable (i) subject-matter, (ii) nature and
                purpose of the processing, (iii) types of Personal Data, (iv) categories of Data Subject(s)
                and (v) technical and organizational measures. Additional or more specific descriptions
                of Processing activities may be included in the Main Agreement or the applicable order
                form.

2.      Data Processing Terms

The following terms shall have the following meanings for the purposes of this DPA:

        2.1     “Affiliate” means any legal entity which directly or indirectly controls, is controlled by, or
                is under common control of the subject entity (as used herein, “control” means ownership
                of more than 50% of assets or stock with control over day-to-day operations).

        2.2     “Applicable Data Protection Laws” means all data privacy or data protection laws or
                regulations globally that are applicable to the Processing of Personal Data under this
                DPA, including, but not limited to, (i) the EU General Data Protection Regulation
                EU/2016/679, as supplemented by applicable EU Member State law and as incorporated
                into the EEA Agreement, (ii) the Swiss Federal Act of 19 June 1992 on Data Protection,
                as amended, (iii) the EU General Data Protection Regulation EU/2016/679, as it forms
                part of the law of England and Wales, Scotland and Northern Ireland by virtue of section
                3 of the European Union (Withdrawal) Act 2018 pursuant to amendments to the EU
                General Data Protection Regulation EU/2016/679 made by The Data Protection, Privacy
                and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 and
                2020 (“UK GDPR”), (iv) the UK Data Protection Act 2018, as amended, (v) the California
                Consumer Privacy Act as amended (“CCPA”) and other US State laws.

        2.3     “Personal Data Breach” means a breach of security leading to the accidental or
                unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer
                Personal Data transmitted, stored or otherwise Processed by Kinaxis through the
                Services.

        2.4     “Personal Data”, “Process/Processing”, “Data Controller”, “Data Processor”, “Data
                Subject”, “Service Provider”, “Sell”, “Share”, “Business Purpose”, and
                “Commercial Purpose” (or the equivalent terms) have the meaning set forth under
                Applicable Data Protection Laws.

        2.5     “Kinaxis” means the Kinaxis Affiliate that has executed the Main Agreement.

        2.6     “Kinaxis Affiliate(s)” means the Affiliate of Kinaxis Inc. that may Process Customer
            Personal Data under this DPA.

     2.7    “Customer” means the customer entity that has executed the Main Agreement, including
            Affiliates of such customer entity who have executed any order forms, statements of
            work, statements of service or other related transaction documents thereunder.

     2.8    “Standard Contractual Clauses” or “SCCs” means:

            (a)     For Personal Data subject to data protection laws of the European Union or a
                    member state of the European Union or the European Economic Area: the
                    standard contractual clauses adopted by the European Commission under
                    Commission Implementing Decision (EU) 2021/914, not including any clauses
                    marked as optional, and as further described in Schedule 2 of this DPA (“EU
                    SCCs”)

            (b)     For Personal Data subject to data protection laws of the United Kingdom: the
                    EU SCC together with the United Kingdom International Data Transfer
                    Addendum to the EU Commission Standard Contractual Clauses, issued by the
                    ICO in accordance with s119A of the Data Protection Act (“UK SCCs”).

            (c)     For Personal Data subject to the Swiss Federal Acts on Data Protection: the EU
                    SCCs, including the amendments listed in Schedule 2 of this DPA (“Swiss
                    SCCs”).

     1.1    “Security and Infrastructure Guide” means the Kinaxis Security and Infrastructure
            Guide included as an attachment to the Main Agreement or made available online
            through the Kinaxis Knowledge Network.

     1.2    “Subprocessor” or “sub-processor” means Kinaxis Affiliates and third parties engaged
            by Kinaxis for the provision of the Services and which process Customer Personal Data
            in accordance with this DPA.

     1.3    “Security Terms” means the Security and Infrastructure Guide and any other security
            or privacy technical measures as mutually agreed upon by the Parties and included in
            the Main Agreement.

     1.4    “Third Country” means any country, organization or territory not acknowledged, in
            accordance with Applicable Data Protection Laws, as a safe country with an adequate
            level of data protection.

     1.5    Other capitalized terms have the definitions provided for them in the Main Agreement.

2.   Roles and Responsibilities

     2.1    For the Processing of Customer Personal Data under this DPA as part of the provision
            of the Services, Kinaxis shall act as a Data Processor and Customer shall act as a Data
            Controller, on behalf of itself, any applicable Customer Affiliates and any other Data
            Controllers relevant to the Processing of Customer Personal Data under this DPA (or
            any such equivalent terms under the Applicable Data Protection Laws). Each party shall
            comply with its own obligations under Applicable Data Protection Laws.

                                                                                                      2
     2.2    Customer warrants that it has obtained (i) all relevant authorizations, consents and
            permissions for the processing of Customer Personal Data under this DPA and (ii) the
            required authorizations to act as a single point of contact for Kinaxis and issue
            instructions under this DPA, acting both on behalf of itself and on behalf of any other
            Data Controllers relevant to the Processing of Customer Personal Data under this DPA.
            Should such consent or authorization be revoked by the Data Subject or the applicable
            Data Controller, the Customer is responsible for communicating such revocation to
            Kinaxis.

     2.3    Kinaxis shall process Customer Personal Data solely at Customer’s documented
            instruction. This DPA, the Main Agreement and the applicable order form, statements of
            work, statements of service or any other related transaction documents thereunder
            constitute such documented initial instructions, and each use of the Services then
            constitutes Customer’s further instructions. Kinaxis will use reasonable efforts to follow
            any other Customer documented instructions, to the extent they are required by
            Applicable Data Protection Laws, technically feasible, and do not require changes to the
            Services. If Kinaxis cannot comply with a documented instruction or is of the opinion
            that a documented instruction infringes Applicable Data Protection Laws, Kinaxis will
            promptly notify Customer and the Parties will work together in good faith to find a
            suitable solution.

     2.4    Kinaxis may also Process Customer Personal Data where required to do so by
            applicable law or regulation. If required to do so, Kinaxis shall inform Customer of such
            legal requirement before Processing, to the extent permitted by such applicable law or
            regulation.

     2.5    Kinaxis shall comply with all restrictions applicable to its Processing of Customer
            Personal Data based on its role under Applicable Data Protection Laws. Kinaxis shall
            not: (i) sell or share Customer Personal Data; (ii) retain, use, or disclose Customer
            Personal Data for any commercial purpose or any other purpose except for those
            specified in the Main Agreement and this DPA; (iv) retain, use, or disclose Customer
            Personal Data outside of the direct business relationship between Kinaxis and
            Customer; or (v) combine or update Customer Personal Data with Personal Data that
            Kinaxis obtains from other sources or collects from its own interaction with the Data
            Subject.

3.   Security and Confidentiality

     3.1    Kinaxis shall treat all Customer Personal Data as confidential and it shall allow only
            its employees, contractors, agents and/or sub-processors who have signed an
            appropriate confidentiality agreement, are otherwise bound to a duty of confidentiality,
            or are under an appropriate statutory obligation of confidentiality to process the
            Customer Personal Data on its behalf.

     3.2    Kinaxis has implemented and shall apply the technical and organizational measures
            described in its Security Terms for the provision of the Services. Customer agrees that
            it has reviewed such measures and that they are appropriate taking into account the
            state of the art, the costs of implementation, nature, scope, context and purposes of the
            processing of Customer Personal Data under this DPA.

                                                                                                         3
     3.3   The Security and Infrastructure Guide may be updated and amended by Kinaxis from
           time to time at Kinaxis’ sole discretion provided that any such amendments do not
           materially decrease the level of privacy or security afforded to the Customer Personal
           Data Processed under this DPA. Kinaxis will publish updated versions of the Security
           and Infrastructure Guide on the Kinaxis Knowledge Network and, where available,
           Customer may subscribe to receive e-mail notifications of such updated versions.

     3.4   Not more than once per year and subject to an agreed upon audit plan (unless otherwise
           required under Applicable Data Protection Laws or following a supervisory authority’s
           request), Customer (or an agreed upon third party representative) may verify Kinaxis’
           compliance with Kinaxis’ technical and organizational measures governing the
           protection, confidentiality, integrity and availability of Customer Personal Data
           (“Customer Audit”). The Customer Audit will be performed during regular business hours
           and may not unreasonably interfere with Kinaxis’ business activities. Kinaxis may use
           third party audit reports as evidence of its compliance. Each party will bear its own costs
           and fees in relation to the Customer Audit.

4.   Assistance and documentation

     4.1   Taking into account the nature of processing and the information available to Kinaxis,
           Kinaxis shall make available to the Customer all information reasonably necessary to
           demonstrate compliance with Kinaxis’s obligations under this DPA and shall reasonably
           assist the Customer in ensuring compliance with Customer’s own obligations under
           Applicable Data Protections Laws, including in relation to Data Subjects’ requests,
           Personal Data Breaches, data protection impact assessments, and litigation or
           regulatory inquiries.

     4.2   Kinaxis will promptly notify Customer of any Data Subject’s request or communications
           from a regulator, government body, or other supervisory authority relating to Customer
           Personal Data that Kinaxis or its Subprocessors Process. Kinaxis shall not respond to
           such requests except as instructed by Customer, unless otherwise required under
           Applicable Data Protection Laws.

     4.3   Each party is responsible for its own compliance with its documentation requirements,
           in particular maintaining records of processing where required, under Applicable Data
           Protection Laws. Each party shall reasonably assist the other party in its documentation
           requirements, in order to enable the other party to comply with any obligations under
           Data Protection Laws.

5.   Personal Data Breach

     5.1   Kinaxis will notify Customer promptly and without undue delay, but no later than seventy-
           two (72) hours after becoming aware of any Personal Data Breach and provide
           reasonable information in its possession to assist Customer to meet Customer’s
           obligations to report a Personal Data Breach as required under Data Protection Laws.

     5.2   As information becomes available, Kinaxis will also provide: (i) a description of the

                                                                                                         4
           nature of the Personal Data Breach, including where possible the categories and
           approximate number of data subjects concerned and the categories and approximate
           number of Personal Data records concerned; (ii) the name and contact details of
           Kinaxis’s data protection officer or another contact point where more information can be
           obtained; (iii) a description of the likely consequences of the Personal Data Breach; and
           (iv) a description of the measures taken or proposed to be taken by the Data Processor
           to address the incident including, where appropriate, measures to mitigate its possible
           adverse effects.

     5.3   Customer agrees to coordinate with Kinaxis on the content of any public statements or
           notice required under Applicable Data Protection Laws regarding the Personal Data
           Breach, prior to making such statements or notices.

6.   Subprocessors

     6.1   Kinaxis is granted a general authorization to subcontract the processing of Customer
           Personal Data to Subprocessors, provided that:

           (a)     Kinaxis will perform a prior assessment of the security, privacy and
                   confidentiality practices of the Subprocessor prior to its engagement, to
                   establish that it has the capability of providing the level of protection of Personal
                   Data required by this DPA.

           (b)     Kinaxis shall only engage Subprocessors subject to a written (including in
                   electronic form) agreement consistent with the terms of this DPA in relation to
                   the Subprocessor’s processing of Personal Data.

           (c)     Kinaxis shall remain at all times liable for any breaches by the Subprocessor in
                   accordance with the terms of this DPA; and,

           (d)     Kinaxis’s list of Subprocessors in place on the effective date of this DPA is
                   published on the Kinaxis Knowledge Network or made available to Customer
                   upon request, including the name, country location and role of each
                   Subprocessor Kinaxis uses to provide the Services.

     6.2   Kinaxis will provide Customer with prior written notification (by email or by posting on
           the Kinaxis Knowledge Network) of any changes to the list of Subprocessors, including
           name, country location and role of the new Subprocessor.

     6.3   Customer may object to such changes within fourteen (14) days from the date of Kinaxis’
           notice. If the Customer does not object within this period, the new Subprocessor is
           deemed authorized by Customer. Where the Customer has a legitimate reason under
           Applicable Data Protection Laws to object to the new Subprocessors’ processing of
           Customer Personal Data, the parties will work together in good faith to find a suitable
           solution.

     6.4   Where no solution for the change in Subprocessor can be agreed upon by the parties,
           Customer may terminate the applicable order form, statement of service, statement of
           work or other transaction document with respect to which the Services cannot be

                                                                                                           5
            provided by Kinaxis without use of the new or changed Subprocessor. Any termination
            under this section shall be deemed to be without fault or further liability by either party
            and shall be subject to the terms of the Main Agreement.

     6.5    Kinaxis may replace a Subprocessor without advance notice where the reason for the
            change is outside of Kinaxis’s reasonable control and prompt replacement is required
            for security or other urgent reasons. In this case, Kinaxis will inform Customer of the
            replacement Subprocessor as soon as possible following its engagement. Sections 7.3
            and 7.4 of this DPA shall apply accordingly.

7.   International Data Transfers

     7.1    Kinaxis shall be entitled to Process Customer Personal Data, including by using
            Subprocessors, outside the country in which the Customer is located or from which the
            Customer Personal Data originates, in accordance with this DPA and as permitted under
            Data Protection Laws.

     7.2    Where Kinaxis is not located in a Third Country and acts as a data exporter, Kinaxis (or
            its applicable Affiliate on its behalf) has entered into the Standard Contractual Clauses
            with each applicable Subprocessor as the data importer. Module 3 (Processor to
            Processor) of the Standard Contractual Clauses shall apply to such transfer.

     7.3    Where Kinaxis is located in a Third Country, Kinaxis and Customer hereby enter into
            the Standard Contractual Clauses with Customer as the data exporter and Kinaxis as
            the data importer which shall apply as follows:

            (a)     Module 2 (Controller to Processor) shall apply where Customer is a Controller;
                    and

            (b)     Module 3 (Processor to Processor) shall apply where Customer is a Processor.
                    Where Customer acts as Processor under Module 3 (Processor to Processor)
                    of the Standard Contractual Clauses, Kinaxis acknowledges that Customer acts
                    as Processor under the instructions of its Controller(s).

     7.4    The parties will review any supplemental safeguards which may be required based on
            Data Protection Laws for the transfer of Customer Personal Data to Third Countries.
            The parties will work together in good faith to find a mutually acceptable resolution to
            address such supplementary measures, including any additional technical and
            organizational measures that may be required.

8.   Legally required disclosures

     8.1    Kinaxis may be required by law to provide access to Customer Personal Data, such as
            to comply with a subpoena or other legal process, or to comply with a valid and binding
            order of a governmental or regulatory body.

     8.2    Unless prohibited from doing so or where there is a clear indication of illegal conduct in
            connection with the use of the Services, Kinaxis shall promptly and without undue delay
            notify the Customer before disclosing any Customer Personal Data.

                                                                                                          6
      8.3    All requests to disclose Customer Personal Data by any governmental or regulatory
             body shall be submitted to Kinaxis legal counsel for assessment and approval. Any
             related Customer Personal Data disclosure will only be processed upon approval and
             confirmation that the disclosure request is lawful and legally binding.

9.    Return and Deletion of Personal Data

      9.1    Upon termination or expiration of this DPA or the Main Agreement, Kinaxis will return
             and delete Customer Personal Data in accordance with the terms of the Main
             Agreement, unless otherwise required under applicable law.

      9.2    Where required by applicable law to store the Customer Personal Data for longer,
             Kinaxis shall inform Customer of such obligation and comply with the requirements of
             the Data Protection Laws until the Customer Personal Data is securely deleted or
             returned to Customer.

10.   Miscellaneous

      10.1   This DPA shall come into effect on the effective date of the Main Agreement.
             Termination or expiration of this DPA shall not discharge Kinaxis from its security and
             confidentiality obligations pursuant to Section 4, to the extent that Kinaxis remains in the
             possession or control of any Customer Personal Data.

      10.2   Order of Precedence. In the event of a conflict between any provisions of the Main
             Agreement and the provisions of this DPA, the provisions of this DPA shall govern and
             control.

      10.3   Notice. Any notices required or provided hereunder by either party to the other shall be
             given in writing to the addresses specified in the Main Agreement and for Kinaxis shall
             also be made to dpo@kinaxis.com

      10.4   Liability. The liability of each party and each party’s Subprocessors under this DPA shall
             be governed by the relevant provisions of the Main Agreement.

      10.5   Governing Law and Jurisdiction. This DPA shall be governed by and construed in
             accordance with governing law and jurisdiction provisions in the Main Agreement, unless
             required otherwise by Applicable Data Protection Laws.

                                                                                                            7
              SCHEDULE 1 DESCRIPTION OF THE PROCESSING

This DPA applies to the Processing of Personal Data as following:

       1.1    Data Subjects. Unless provided otherwise by the data exporter, Customer Personal Data
              relates to the following categories of Data Subjects: employees, contractors, business
              partners, customers or other individuals having their Personal Data Processed through
              the Services.

       1.2    Data Categories. Unless provided otherwise by the data exporter in writing, the Customer
              Personal Data typically concerns the following categories of data: name, e-mail address,
              job role and company, address data, system access / usage / authorization data, IP
              address or other device identifiers. The Services are not intended for Processing special
              categories of data and Customer shall ensure no such data is shared with Kinaxis or
              otherwise Processed through the Services.

       1.3    Purpose and Nature of Processing. Kinaxis and its Subprocessors will Process Customer
              Personal Data for the purpose of providing the Services, including related operational and
              customer support services, in accordance with the Main Agreement, this DPA and Data
              Protection Laws.

       1.4    Duration and data retention. Customer Personal Data shall be retained for the duration of
              the Main Agreement, unless otherwise required under applicable law.

       1.5    Transfers to (sub-) processors. For transfers to Subprocessors, the subject matter, nature,
              and duration of the Processing shall be on the same basis as set out in the DPA.

                                                                                                       8
               SCHEDULE 2 STANDARD CONTRACTUAL CLAUSES

 For the purposes of this DPA, the Standard Contractual Clauses shall be completed or amended
         as follows:

1.     EU SCCs

        1.1      Clause 7 – Docking Clause. The parties agree the Docking Clause shall not be used.

        1.2      Clause 9(a) – Use of sub-processors. The Parties agree that Option 2 ‘General Written
                 Authorization shall be used and that any Subprocessor change shall be handled in
                 accordance with Section 6 of the DPA.

        1.3      Clause 11(a) – Redress. The parties agree the optional part of this clause shall not be
                 used.

        1.4      Clause 17 – Governing Law. The Parties agree that Option 1 shall be used, and that the
                 EU SCCs shall be governed by the laws of Ireland.

        1.5      Clause 18(b) - Choice of forum and jurisdiction. The Parties agree that any dispute arising
                 from the EU SCCs shall be resolved by the courts of Ireland.

        1.6      Annex I. List of Parties - Data Exporter. The data exporter under the Standard Contractual
                 Clauses is the Customer entity that executed the Main Agreement.

        1.7      Annex I. List of Parties- Data Importer. The data importer under the Standard Contractual
                 Clauses is the Kinaxis entity that executed the Main Agreement.

        1.8      Annex I. Description of Transfer. Schedule 1 of this DPA covers the description of
                 transfers under the Standard Contractual Clauses.

        1.9      Annex I. Description of Transfer – Frequency of Transfer. Transfers shall be made on a
                 continuous basis.

        1.10     Annex I. Competent Supervisory Authority – EU SCCs. For the purposes of the EU SCCs,
                 the Parties agree that the competent supervisory authority shall be the Irish Data
                 Protection Commission, unless a different competent supervisory authority is designated
                 in accordance with Clause 13 of the EU SCCs.

        1.11     Annex II - Technical and Organizational Measures. To ensure an appropriate level of
                 security, taking into account the nature, scope, context and purpose of the Processing,
                 and the risks for the rights and freedoms of natural persons, the Data Importer has
                 implemented the technical and organizational measures described in the Security
                 Measures, as such term is defined under the DPA.

        1.12     Annex III – List of Subprocessors. The list of the Data Importer’s Subprocessors is made
                 available to the Data Exporter in accordance with Section 6.1(d) of the DPA.

                                                                                                          9
2.   UK SCCs

     2.1    Table 1 – Parties details. The Parties details are as set out in Annex I of the EU SCC, with
            no requirement for further signature.

     2.2    Table 2 - Selected SCCs, Modules and Selected Clauses. The Parties agree the
            addendum shall be appended to the EU SCCs, including the modules, optional clauses
            and additions described in the DPA, including Sections 1.1 – 1.3 and Sections 2.4 – 2.6
            of this Schedule.

     2.3    Table 3- Appendix Information. The Parties agree the appendix information listed in table
            3 shall be as set out in the Annexes to the EU SCCs.

     2.4    Clause 17 – Governing Law. The Parties agree that Option 1 shall be used, and that the
            UK SCCs shall be governed by the laws of England and Wales.

     2.5    Clause 18(b) - Choice of forum and jurisdiction. The Parties agree that any dispute arising
            from the UK SCCs shall be resolved by the courts of England and Wales.

     2.6    Annex I. Competent Supervisory Authority – UK SCCs. For the purposes of the UK SCCs,
            the Parties agree that the competent supervisory authority shall be the Information
            Commissioner’s Office.

3.   Swiss SCCs

     3.1    General. References to the General Data Protection Regulation and the Regulation (EU)
            2016/679 are to be understood as references to the Swiss Federal Acts on Data
            Protection.

     3.2    Clause 17 – Governing Law. The Parties agree that Option 1 shall be used, and that the
            Swiss SCCs shall be governed by the laws of Switzerland.

     3.3    Clause 18(b) - Choice of forum and jurisdiction. For the purposes of the Swiss SCCs,
            Switzerland is to be considered as a Member State within the meaning of EU SCCs. The
            Parties agree that any dispute arising from the Swiss SCCs shall be resolved by the courts
            of the Canton of Zurich, Switzerland.

     3.4    Annex I. Competent Supervisory Authority – Swiss SCCs. For the purposes of the Swiss
            SCCs, the Parties agree that the competent supervisory authority shall be the Federal
            Data Protection and Information Commissioner.

                                                                                                     10