Third Party Index

Snapshot 58918

Document
Data processing addendum
URL
https://airgus.com/data-processing-addendum/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
303635 bytes
SHA-256 (raw)
23de53be0866805d0554dd734dd2e706288cc0183b6537c8c1053a4d2fc59f09
SHA-256 (normalized text)
067aca96ae945be04ec148c52d535b466df4f0c3ba01e0be138a8a1f495ecce2

Normalized text

Scripts and page chrome removed; this is what change detection compares.

51.81.169.195 Data Processing Addendum - Ai-RGUS
Data Processing Addendum
Last updated on: February 26th, 2026
This Data Processing Addendum (“Addendum”) forms part of the agreement (the “Agreement”) between Security Camera Maintenance Company (d/b/a Ai-RGUS) (“Ai-RGUS”) and the customer agreeing to these terms (“Customer”) (each a “party” and collectively the “parties”), and reflects the parties’ agreement with regard to the processing of Personal Data in accordance with the requirements of the applicable Data Protection Legislation.
The terms used in this Addendum shall have the meanings set forth in this Addendum. Capitalized terms not otherwise defined herein shall have the meaning given to them elsewhere in the Agreement (including in the Terms of Service).
Definitions And Interpretations
The following terms shall have the following meanings:
“Applicable Law” means all applicable laws, statutes, codes, ordinances, decrees, rules, regulations, municipal by-laws, judgments, orders, decisions, rulings or awards of any government, quasi-government, statutory or regulatory body, ministry, government agency or department, court, agency or association of competent jurisdiction;
“Controller” means an entity which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, and shall also mean a “Business”, where applicable, as defined by the Data Protection Legislation;
“Customer Personal Data” shall have the meaning given to it in Clause 3.1;
“Data Protection Legislation” means all laws and regulations, including (without limitation) state, federal and national laws and regulations of the European Union (“EU”), the European Economic Area (“EEA”), their Member States, the United Kingdom and the United States, which are applicable to the processing of Personal Data under the Agreement including (without limitation) the GDPR and US privacy laws such as the California Consumer Privacy Act of 2018, Cal. Civ. Code §§ 1798.100 –1798.199, as amended by the California Privacy Rights Act and its implementing regulations (the “CCPA”), each as amended, repealed or replaced from time to time;
“GDPR” means either or both the General Data Protection Regulation (EU) 2016/679 (“EU GDPR”) and the EU GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”) as the context may require;
“Group Company” means, in relation to a party, an entity that owns or controls, is owned or controlled by or is under common control or ownership with the party, where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise;
“Personal Data” means any information relating to an identified or identifiable natural person (a “Data Subject”) and/or any such information as may be defined as constituting personal data, personally identifiable information or any equivalent thereof, in any applicable Data Protection Legislation;
“Process” and variants of it, such as “processing” and “processed” (whether capitalized or not) means any operation or set of operations performed upon Personal Data or sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
“Processor” means an entity which processes Personal Data on behalf of a Controller and shall also mean a “Service Provider”, where applicable, as defined by Data Protection Legislation;
“Restricted Transfer” means, as applicable:
a transfer of Customer Personal Data from the Customer to Ai-RGUS; or
an onward transfer of Customer Personal Data from Ai-RGUS to a Subprocessor, or between two establishments of Ai-RGUS,
in each case, where such transfer would be prohibited by Data Protection Legislation in the absence of an approved method of lawful transfer, including through (i) an adequacy decision by a Supervisory Authority; (ii) Standard Contractual Clauses; or (iii) by the terms of other recognized forms of data transfer agreements or other lawful processes approved by a Supervisory Authority;
“Services” shall mean the services and other activities to be performed by Ai-RGUS pursuant to the Agreement including, but not limited to, the provision of the Platform;
“Standard Contractual Clauses” means, as applicable:
the standard contractual clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission in Decision (EU) 2021/914 (either Module 2 or Module 3 as appropriate) as supplemented by the Appendix to the Standard Contractual Clauses as set out in Schedule 3, or any set of clauses approved by the European Commission or a Supervisory Authority which subsequently amends, replaces or supersedes the same as amended under Clause 7.3 (“EU Standard Contractual Clauses”); and/or
the UK International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses as approved by the UK Information Commissioner’s Office under section 119A(1) of the UK Data Protection Act 2018 as set out in Schedule 4, or any set of clauses approved by a Supervisory Authority which subsequently amends, replaces or supersedes the same as amended under Clause 6.5 (“UK Addendum”).
“Subprocessor” means any person or entity appointed by or on behalf of Ai-RGUS (or the relevant intermediate Subprocessor) to process Personal Data as described in Clause 5; and
“Supervisory Authority” means a supervisory authority established by an EEA Member State or the United Kingdom, pursuant to Article 51 of the GDPR, or any other competent government authority with jurisdiction over the processing of Personal Data under the Agreement.
In this Addendum (except where the context otherwise requires):
any reference to a Clause or Schedule is a reference to the relevant, clause or schedule of or to the Addendum;
the Clause headings are included for convenience only and shall not affect the interpretation of the Addendum;
use of the singular includes the plural and vice versa;
any reference to “persons” includes natural persons, firms, partnerships, companies, corporations, associations, organizations, governments, governmental agencies and departments, states, foundations and trusts (in each case whether or not having separate legal personality);
any reference to a statute, statutory provision or subordinate legislation shall (except where the context otherwise requires) be construed as referring to such legislation as amended and in force from time to time and to any legislation which re-enacts or consolidates (with or without modification) any such legislation; and
any phrase introduced by the terms “including”, “include”, “in particular” or any similar expression shall be construed as illustrative and shall not limit the sense of the words preceding those terms.
Roles Of The Parties
Both parties will comply with all applicable requirements of the Data Protection Legislation. This Clause 2.1 is in addition to, and does not relieve, remove or replace, either party’s obligations under the Data Protection Legislation.
The parties acknowledge and agree that for the purposes of applicable Data Protection Legislation, either: (i) Customer is a Controller and Ai-RGUS is a Processor; or (ii) Customer is a Processor and Ai-RGUS is a subprocessor appointed by Customer on behalf of the ultimate Controller.
Customer shall ensure that it has and will continue to have, the right to transfer, or provide access to, Customer Personal Data to Ai-RGUS for processing in accordance with the Agreement. For the avoidance of doubt, Customer’s instructions for the processing of Customer Personal Data shall comply with applicable Data Protection Legislation. Ai-RGUS will inform Customer if it considers, in its opinion, that any of Customer’s instructions infringe applicable Data Protection Legislation. As between Customer and Ai-RGUS, Customer shall have sole responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquires Customer Personal Data, and shall be responsible for ensuring that the processing of Personal Data, which Ai-RGUS is instructed to perform, has a valid legal basis.
The terms of this Addendum shall apply equally to any Personal Data Processed by or on behalf of Ai-RGUS for any Customer Group Company. Customer represents and warrants that it is and will at all relevant times remain duly and effectively authorized to enter into this Addendum and perform all of its obligations hereunder on behalf of each such Customer Group Company. Customer shall at all times be liable for Customer’s Group Company’s compliance with this Addendum and all acts and omissions by Customer’s Group Companies receiving Services under the Agreement are deemed acts and omissions of Customer.
Scope Of Processing
Customer agrees that Ai-RGUS may process Personal Data on behalf of Customer to perform its obligations under the Agreement for the term of the Agreement (“Customer Personal Data”) in accordance with this Addendum. A list of the categories of data subjects, types of Customer Personal Data and the processing activities are set out in Schedule 1. The duration of the processing corresponds to the duration of the Services, unless otherwise stated in the Agreement or this Addendum. The purpose and subject matter of the processing is the provision of the Services.
Ai-RGUS shall process Customer Personal Data only on the documented instructions of Customer unless Ai-RGUS is required by Applicable Law to otherwise process Customer Personal Data. Where Ai-RGUS is relying on Applicable Law as the basis for processing Customer Personal Data, Ai-RGUS shall notify Customer of this before performing the processing required by the Applicable Law unless Applicable Law prohibits Ai-RGUS from so notifying Customer.
The following is deemed an instruction by Customer to process Customer Personal Data, subject to Ai-RGUS’s compliance with this Addendum and the Data Protection Legislation: (i) processing necessary to perform the Services in accordance with the Agreement; (ii) processing initiated by Customer (or its authorized representative) in their use of the Platform; (iii) processing necessary to comply with other reasonable instructions provided by Customer where such instructions are consistent with the Agreement; and (iv) processing of Customer Personal Data for the purpose of improving the accuracy of the Services, including through the training, testing and validation of machine learning models used to deliver the Services in which case, it is de-identified to the extent it can remain usable for the stated purpose.
Data Processing Obligations
Without prejudice to the generality of Clause 2.1, Ai-RGUS shall, in relation to any Customer Personal Data processed in connection with the performance by Ai-RGUS of its obligations under the Agreement:
ensure that it has in place appropriate technical and organizational measures to protect against unauthorized or unlawful processing of Customer Personal Data and against accidental loss or destruction of, or damage to, Customer Personal Data (“Personal Data Breach”), appropriate to the harm that might result from the unauthorized or unlawful processing or accidental loss, destruction or damage and the nature of the data to be protected, having regard to the state of technological development and the cost of implementing any measures;
ensure that any personnel who have access to and/or process Customer Personal Data are obliged to keep Customer Personal Data confidential;
taking into account the nature of the processing and the information available to Ai-RGUS, provide reasonable assistance to Customer in responding to any request from a Data Subject and in ensuring compliance with its obligations (or, where Customer is a Processor, the obligations of the ultimate Controller) under the Data Protection Legislation with respect to records of processing, security, breach notifications, impact assessments and consultations with supervisory authorities or regulators, only to the extent that the relevant information or means are not otherwise at the Customer’s disposal, and provided that Ai-RGUS may charge Customer on a time and materials basis for such assistance;
notify Customer without undue delay on becoming aware of a Personal Data Breach and shall provide Customer with further information about the Personal Data Breach in phases as such information becomes available to Ai-RGUS;
at the written direction of Customer, delete or return Customer Personal Data and copies thereof to Customer on termination of the Agreement unless required by Applicable Law to store Customer Personal Data;
not combine Customer Personal Data with the Personal Data that it receives from any other party other than Group Companies of the Customer;
not sell or share (as defined under the applicable Data Protection Legislation) Customer Personal Data; and
notify Customer if it determines it can no longer meet its obligations under Data Protection Legislation. Upon such notice, Customer reserves the right to take reasonable and appropriate steps to stop and remediate Ai-RGUS’s unauthorized use of Customer Personal Data.
Upon Customer’s request, Ai-RGUS shall, no more than once per calendar year (unless required more frequently by Data Protection Legislation, an order of a Supervisory Authority or court, or in the event of a Personal Data Breach) make available for Customer’s review (or, where Customer is a Processor, the review of the ultimate Controller) copies of certifications or reports demonstrating Ai-RGUS’s compliance with this Addendum and the prevailing data security standards applicable to the processing of Customer Personal Data, including its then-current SOC 2 Type II report (or any successor or equivalent independent third-party audit report).
Where Customer (or, where Customer is a Processor, the ultimate Controller) reasonably believes the information provided under Clause 4.2 above is not sufficient to demonstrate Ai-RGUS’s compliance with this Addendum, at Customer’s expense and subject to Clause 5, Ai-RGUS shall permit Customer (or, where Customer is a Processor, the ultimate Controller), or their appointed third-party auditors (collectively, “Auditor”), to audit the architecture, systems and procedures relevant to Ai-RGUS’s compliance with this Addendum and shall make available to the Auditor all information, systems and staff necessary for the Auditor to conduct such audit provided that Ai-RGUS may charge Customer on a time and materials basis for any such excess hours. Notwithstanding the foregoing, where Ai-RGUS has made available its then-current SOC 2 Type II report (or any successor or equivalent independent third-party audit report), such report shall in the absence of manifest error be deemed sufficient for the purposes of clauses 4.2 and 4.3.
Audits
Before the commencement of an audit described in clause 4.3, Ai-RGUS and Customer will mutually agree upon the reasonable scope, start date, duration of and security and confidentiality controls applicable to the audit. Customer agrees that:
audits will be conducted during Ai-RGUS’s normal business hours;
it will not exercise its audit rights more than once per calendar year, (unless required more frequently by Applicable Data Protection Legislation, an order of a Supervisory Authority or court, or in the event of a Personal Data Breach);
it will be responsible for any fees charged by any third party auditor appointed by Customer to execute any such audit;
Ai-RGUS may object to any third-party auditor appointed by Customer to conduct an audit if the auditor is, in Ai-RGUS’s opinion, not suitably qualified or independent, a competitor of Ai-RGUS or otherwise manifestly unsuitable. Any such objection by Ai-RGUS will require Customer to appoint another auditor or conduct the audit itself;
nothing in this Clause 5 will require Ai-RGUS either to disclose to the Auditor, or to allow the Auditor access to (a) any data processed by Ai-RGUS on behalf of any other organisation, (b) any Ai-RGUS internal accounting or financial information, (c) any trade secret of Ai-RGUS, (d) any information that, in Ai-RGUS’s opinion, could (i) compromise the security of any Ai-RGUS systems or premises, or (ii) cause Ai-RGUS to breach its obligations to Customer or any third party, or (e) any information that the Auditor seeks to access for any reason other than the good faith fulfilment of Customer’s obligations under the Applicable Data Protection Legislation;
audits will be conducted subject to Customer treating any observations or information revealed in the course of such audit as confidential to Ai-RGUS;
before an audit, Ai-RGUS may require any ultimate Controller or Auditor to execute a confidentiality agreement with Ai-RGUS; and
Customer shall provide Ai-RGUS with copies of any audit reports completed by the Auditors.
Appointment Of Subprocessors
Customer authorises Ai-RGUS to appoint (and permit each Subprocessor appointed in accordance with this Clause 6 to appoint) Subprocessors in accordance with this Clause 6 and any restrictions in the Agreement.
Ai-RGUS may continue to use those Subprocessors already engaged by Ai-RGUS as at the date of this Addendum, (a list of which will be provided on Customer’s written request), subject to Ai-RGUS in each case as soon as practicable meeting the obligations set out in Clause 6.4.
Ai-RGUS shall give Customer prior notice of any intended changes concerning the appointment or replacement of Subprocessors. If, within twenty-one (21) days of receipt of that notice, Customer notifies Ai-RGUS in writing of any objections (on reasonable grounds) to the proposed appointment:
Ai-RGUS shall work with Customer in good faith to make available a commercially reasonable change in the provision of the Services which avoids the use of that proposed Subprocessor; and
where such a change cannot be made within thirty (30) days from receipt by Ai-RGUS of Customer’s notice, notwithstanding anything in the Agreement, Customer may by written notice to Ai-RGUS terminate those Services which cannot be provided by Ai-RGUS without the use of the objected-to Subprocessor. This termination right is Customer’s sole and exclusive remedy if Customer objects to any proposed Subprocessor.
With respect to each Subprocessor, Ai-RGUS shall:
ensure that the arrangement between on the one hand (a) Ai-RGUS, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum;
to the extent that Subprocessor processes Customer Personal Data subject to the GDPR outside of the EEA and/or the UK or makes a Restricted Transfer, Ai-RGUS will ensure that appropriate safeguards (such as the Standard Contractual Clauses) are at all relevant times incorporated into the agreement between on the one hand (a) Ai-RGUS, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first processes Customer Personal Data procure that it enters into an agreement incorporating appropriate safeguards; and
provide to Customer for review such copies of the agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time.
Ai-RGUS may replace a Subprocessor if the need for the change is urgent and necessary to provide the Services and the reason for the change is beyond Ai-RGUS’s reasonable control. In such instance, Ai-RGUS shall notify Customer of the replacement as soon as reasonably practicable, and Customer shall retain the right to object to the replacement Subprocessor pursuant to Clause 6.3 above.
Where a Subprocessor fails to fulfil its data protection obligations, Ai-RGUS shall remain fully liable to Customer for the performance of that Subprocessor’s obligations.
Restricted Transfers
To the extent that Ai-RGUS processes Customer Personal Data to which the GDPR applies in a territory outside of the EEA and/or UK that does not provide adequate protection for Personal Data (as determined by applicable Data Protection Legislation), Ai-RGUS and Customer hereby enter into the Standard Contractual Clauses (which are incorporated by reference in, and form an integral part of, this Addendum) in respect of any transfer of Customer Personal Data from Customer (as “data exporter”) to Ai-RGUS (as “data importer”) where such transfer would be prohibited by Data Protection Legislation (or by the terms of data transfer agreements put in place to address the data transfer restrictions of Data Protection Legislation) in the absence of the Standard Contractual Clauses. The Standard Contractual Clauses are supplemented by the detail set out in Schedules 3 and 4 to this Addendum.
The Standard Contractual Clauses shall not apply to a Restricted Transfer unless the effect, together with all compliance steps required under Data Protection Legislation (which, for the avoidance of doubt, do not include obtaining consents from individuals), is to allow the Restricted Transfer to take place without breach of applicable Data Protection Legislation. The Standard Contractual Clauses shall come into effect on the commencement of a Restricted Transfer as described in this Clause 7.
Additional terms for Standard Contractual Clauses:
For the purposes of Clause 8.1(a) of the Standard Contractual Clauses, the processing described in Clause 3 of this Addendum is deemed an instruction by Customer to process Customer Personal Data, subject to Ai-RGUS’s compliance with applicable Data Protection Legislation.
Pursuant to Clause 9(a) of the Standard Contractual Clauses, Customer agrees that Ai-RGUS may continue to use those Subprocessors already engaged by Ai-RGUS as at the date of this Addendum, subject to Ai-RGUS in each case as soon as practicable meeting the obligations set out in Clause 6.4.
Pursuant to Clause 9(a) of the Standard Contractual Clauses, Customer agrees that Ai-RGUS may engage new Subprocessors as detailed in Clause 6 of this Addendum.
Customer agrees that the audits described in Clause 8.9 of the Standard Contractual Clauses shall be carried out in accordance with Clauses 4 and 5 of this Addendum.
In the event of any conflict or inconsistency between this Addendum and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.
The parties’ acceptance of the Terms of Service (including by clicking on any “I Agree” or similar button, or otherwise using the Platform) shall be considered as signature to the Standard Contractual Clauses.
Ai-RGUS may propose variations to this Addendum and the Standard Contractual Clauses which Ai-RGUS reasonably considers to be necessary to address the requirements of any Data Protection Legislation, and the parties shall promptly discuss the proposed variations and negotiate in good faith with a view to agreeing and implementing those or alternative variations designed to address the requirements identified in Ai-RGUS’s notice as soon as is reasonably practicable.
In the event that Ai-RGUS (as “data importer”) self-certifies under any applicable adequacy decision or adequacy framework by a Supervisory Authority, Ai-RGUS shall notify the Customer promptly of such self-certification and the parties agree and acknowledge that any Restricted Transfer will be subject to such adequacy decision or framework instead of the Standard Contractual Clauses. Ai-RGUS shall at all times during the term of the Agreement maintain compliance with any applicable rules of the adequacy decision and framework and provide Customer with evidence of its compliance upon request.
General Terms
Termination and Survival. The parties agree that this Addendum shall terminate automatically upon termination of the Agreement. Notwithstanding the foregoing, any obligation imposed on Ai-RGUS under this Addendum in relation to the processing of Customer Personal Data shall survive any termination or expiration of this Addendum.
Governing Law. This Addendum shall be governed by the governing law of the Agreement.
Jurisdiction. The parties to this Addendum hereby submit to the choice of jurisdiction stipulated in the Agreement with respect to any disputes or claims howsoever arising under this Addendum.
Order of precedence. Nothing in this Addendum reduces Ai-RGUS’s obligations under the Agreement in relation to the protection of Customer Personal Data or permits Ai-RGUS to process (or permit the processing of) Customer Personal Data in a manner which is prohibited by the Agreement. In the event of any inconsistency between this Addendum and any other agreements between the parties, including but not limited to the Agreement, the Addendum shall prevail.
Severance. Should any provision of this Addendum be invalid or unenforceable, then the remainder of this Addendum shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability, while preserving the parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.
Schedule 1
Data Processing Details
This Schedule includes certain details of the processing of Personal Data as required by article 28(3) of the GDPR.
Subject Matter of processing	The provision of the Platform and the performance of the Services.
Duration of processing	The processing shall continue until the later of:
the Agreement being terminated or expiring in accordance with its terms and any notice period or transition period prescribed by the Agreement having expired; and
Ai-RGUS no longer being subject to an applicable legal or regulatory requirement to continue to process any Personal Data.
Nature and purpose of processing	The processing is being conducted to facilitate the provision of the Platform and the performance of the Services, as documented in the Agreement, including the continuous monitoring and analysis of camera feeds to ensure system functionality, and ongoing improvement and optimization of the Services.
Types of personal data	Personal data contained in any footage captured by video cameras or security systems connected to the Platform.
Types of sensitive personal data	Not intentionally processed.
Categories of Data Subject	Any identifiable individual who passes in front of a video camera or security system connected to the Platform at the specific times of daily image verification.
Customer’s obligations and rights (as data controller)	As set out in this Addendum and the Agreement.
Schedule 2
List Of Third Parties Processing Personal Data On Behalf Of Vendor
Provided on written request, in accordance with Section 6.2
Schedule 3
Appendix to the EU Standard Contractual Clauses
This Appendix forms part of the EU Standard Contractual Clauses and must be completed by the parties.
Annex I
A. List of parties
Data exporter
The data exporter is:	The data exporter is the Customer.
Role:	Controller (or Processor, where applicable).
Data importer
The data importer is:	The data importer is Ai-RGUS.
Role:	Processor (or subprocessor, where applicable).
B. Description of transfer
Data subjects	As set out in Schedule 1.
The Personal Data transferred concern the following categories of data subjects:
Categories of data
The Personal Data transferred concern the following categories of data:	As set out in Schedule 1.
Sensitive data transferred (if appropriate)
The Personal Data transferred concern the following sensitive data:	As set out in Schedule 1.
The sensitive data transferred will be subject to the following applied restrictions and safeguards that fully take into consideration the nature of the data and the risks involved:	As set out in Annex II.
Frequency of the transfer
(e.g. whether the data is to be transferred on a one-off or continuous basis):	Continuous
Nature of the processing
The Personal Data transferred will be subject to the following basic processing activities:	Receiving data via live feeds to connected cameras
Processing data to provide the Services (e.g., identifying issues with the cameras and/or footage)
Holding and storing reference images
Holding and storing data
Protecting data including restricting, encrypting and security testing
Erasing data, including destruction and deletion
Purpose(s) of the data transfer and further processing
The Personal Data is transferred for the following purpose(s):	For the provision of Services as detailed in the Agreement.
The period for which the personal data will be retained
If that is not possible, the criteria used to determine that period:	The duration of the Services as described in the Agreement, unless otherwise stated in the Agreement or this Addendum.
Transfers to subprocessors
Specify the subject matter, nature and duration of the processing:	Transfers to Subprocessors will occur where necessary for the provision of the Services in accordance with the Agreement and the Addendum, for the term of the Agreement.
C. Description of transfer
Competent supervisory authority/ies in accordance with Clause 13:	Irish Data Protection Commission
Governing law in accordance with Clause 17:	Republic of Ireland.
Choice of forum and jurisdiction in accordance with Clause 18:	Republic of Ireland
Annex II
TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
Description of the technical and organizational security measures implemented by the data importer:
Please see: https://trust.ai-rgus.com
Annex III
List Of Subprocessors
Data exporter has authorized the use of the following (sub) processors:Provided on written request, in accordance with Section 6.2
Schedule 4
UK Addendum To The EU Standard Contractual Clauses
Table 1: Parties
The Parties	Exporter (who sends the Restricted Transfer)	Importer (who receives the Restricted Transfer)
Parties’ details	Customer	Ai-RGUS
Signature (if required for the purposes of Section 2)	The parties’ signature and date on the Addendum constitutes their signature and date on this UK Addendum.	The parties’ signature and date on the Addendum constitutes their signature and date on this UK Addendum.
Table 2: Selected SCCs, Modules and Selected Clauses
Addendum EU SCCs	The version of the Approved EU SCCs, which this Addendum is appended to, including the Appendix Information.
Table 3: Appendix Information
“Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in:
Annex 1A: List of Parties: As set out in the Agreement.
Annex 1B: Description of Transfer: As set out in Annex I to Schedule 3.
Annex II: Technical and organizational measures including technical and organizational measures to ensure the security of the data: As set out in Annex II to Schedule 3.
Annex III: List of Sub processors (Modules 2 and 3 only): As set out in Schedule 2.
Table 4: Ending this Addendum when the Approved Addendum changes
Ending this Addendum when the Approved Addendum changes	Which Parties may end this Addendum as set out in Section 19:
Importer
Part 2 Mandatory Clauses
Mandatory Clauses	Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with section 119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section ‎‎18 of those Mandatory Clauses.
Transfer Risk Assessment
The Exporter has completed a transfer risk assessment (TRA). It has relied on the Department for Science, Innovation and Technology’s Analysis of the UK Extension to the EU-US data privacy framework published in September 2023 (the DSIT analysis). The Exporter is satisfied that the DSIT analysis concludes that US laws and practices provide adequate protections for people whose personal information is transferred to the US for risks to people’s rights: (i) arising in the US from third parties that are not bound by this IDTA accessing the transferred personal information in particular, government and public bodies; and (ii) arising from difficulties enforcing the IDTA. The Exporter considers that it is reasonable and proportionate for it to rely on the DSIT analysis, given the scope of this assessment is as required under Article 45 UK GDPR, and the enactment of adequacy regulations under Section 17A DPA 2018 by the Secretary of State and Parliament, on the basis of that assessment. The Exporter will review this TRA if a new or amended version of the DSIT analysis is published, or the DSIT analysis is withdrawn.