Snapshot 68420
Normalized text
Scripts and page chrome removed; this is what change detection compares.
DATA PROCESSING AGREEMENT 1. Preamble 2. Definitions 3. Processing of Personal Data 4. Security and Accountability 5. Subcontracting 6. Jurisdiction-Specific Terms 7. Indemnification 8. General Annex I Nature and purpose of personal data processing Duration of personal data processing Categories of data subjects Categories of personal data Special categories of personal data or sensitive data Frequency of processing Annex II 1. IT security governance 2. Certification and assurance of processes and service delivery 3. Personnel Security 4. Data protection 5. Availability and resilience of processing systems and services 6. Access control 7. Physical security 8. Secure system configuration 9. Data minimisation, retention and deletion 10. Supply chain security 11. Incident management Annex III Preamble 1.1 This Data Processing Agreement (“DPA“) supplements and forms part of the Master Service Agreement, Terms of Service or other written or electronic agreement (“Agreement“) between Route Mobile Limited (a Proximus Global company), hereinafter called “Contractor“, that has entered into such Agreement to provide messaging, communications, mobile connectivity, identity verification, analytics, and/or fraud detection services (“Services“) to a user of such Services (“Client“). Contractor and Client are also hereinafter, each referred to as a “Party” and collectively as the “Parties“. 1.2 For the purposes of this DPA, the Services include services provided directly by the Contractor as well as services resold or otherwise made available by the Contractor from other entities within the Proximus Global group or its Affiliates. This DPA is necessary to ensure secure information processing since the provision of the Services under the Agreement may give rise to the exchange of certain information including personal data about individuals. 2. Definitions 2.1 Unless the context requires otherwise, the following terms shall when used in this DPA have the meaning set out hereunder: “Affiliate” means a company, person or entity that is owned or controlled by, that owns or controls or is under common ownership or control with a Party. Ownership means direct or indirect ownership of more than 50% of the shares in a company or entity, and control means any power to appoint persons to the board of directors of a company or entity. “Applicable Data Protection Law” means all applicable data protection, privacy, and information security laws and regulations – including but not limited to the EU General Data Protection Regulation (“EU GDPR“) and any national implementing legislation, the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CCPA“), Colombia’s Statutory law 1581 of 2012, Brasil’s Lei Geral de Proteção de Dados Pessoais 13.709/2018 (“LGPD“), India’s Digital Personal Data Protection Act 2023 (“DPDP“) and Law No. 27 of 2022 concerning Personal Data Protection (“PDP Law”) , together with their implementing rules – that are applicable to either Party and/or its processing of personal data in connection with the Agreement. “Controller” means the natural or legal person, which, alone or jointly with others, determines the purposes and means of the processing of personal data. “Data Subject” means an identified or identifiable natural person whose personal data is processed. “Processor” means a natural or legal person which processes personal data on behalf of a Controller. “Restricted Transfer” means: (i) where the EU GDPR applies, a transfer of personal data from the European Economic Area to a country outside of the European Economic Area which is not subject to an adequacy determination by the European Commission; (ii) where the UK GDPR applies, a transfer of personal data from the United Kingdom to any other country which is not based on adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018; and (iii) where the Swiss DPA applies, a transfer of personal data from Switzerland to any other country which is not based on an adequacy decision recognized under the Swiss DPA. “Standard Contractual Clauses” means: (i) where the EU GDPR applies, the contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (“EU SCCs“); (ii) where the UK GDPR applies, the “International Data Transfer Addendum to the EU Commission Standard Contractual Clauses” issued by the Information Commissioner under s.119A(1) of the Data Protection Act 2018 (“UK Addendum“); and (iii) where the Swiss DPA applies, the EU SCC’s with the Swiss additions (“Swiss SCCs”). “Sub-processor” means any sub-contractor or agent who is engaged by a Processor and agrees to receive personal data and process same on behalf of the Controller and/or Processor. 2.2 The terms “ personal data“, “personal data breach“, “process“, “processing“, and “supervisory authority” when used shall have the meanings given to them under Article 4 of the EU GDPR. 2.3 The terms “sell” and “share” when used shall have the meanings given to them under the CCPA. 2.4 The terms used in this DPA not defined hereunder shall have their meanings given within the Applicable Data Protection Law. 2.5 Words used in the singular, where the context so permits, shall be deemed to include the plural and vice versa. 3. Processing of Personal Data 3.1 Each Party shall comply with its obligations under the Applicable Data Protection Law in relation to the processing of personal data. For the avoidance of doubt, this DPA is in addition to, and does not relieve, remove or replace, a Party’s obligations under the Applicable Data Protection Law. 3.2 To the extent that Contractor processes personal data as a Processor, on behalf of the Client (or Client’s customer) acting as a Controller, in connection with the Agreement, Contractor shall fully comply with the obligations as set out hereunder: process the personal data only as necessary for the performance of the Agreement and strictly in accordance with the Client’s documented instructions, and inform the Client immediately if, in its opinion, an instruction of the Client infringes Applicable Data Protection Law. The permitted purposes of Contractor’s processing of persona data are as outlined in Annex I to this DPA. If the Contractor would be required by any law to process any personal data otherwise than as permitted by the Client, the Contractor shall inform the Client of the requirement before processing, unless that law prohibits such information on important grounds of public interest. treat the personal data as confidential information, entrust only such employees or agents who have been bound to confidentiality and have previously been familiarised with the data protection provisions relevant to their work with the processing of personal data, and ensure that disclosure of or access to personal data is restricted to its employees or agents that strictly require such personal data to perform the tasks assigned to them in relation to the Services. implement appropriate technical and organizational security measures as set out in Annex II to this DPA, prior to and during processing of any personal data to protect the security, confidentiality and integrity of the personal data and to protect the personal data against any form of accidental, unlawful or unauthorized processing. co-operate with the Client to enable the Client to comply with its obligations with regard to personal data security, taking into account the nature of the processing and the information available to Contractor. provide reasonable co-operation and assistance to the Client, if and when the Client is required to perform a data protection impact assessment, an international data transfer impact assessment, or consultation with a supervisory authority having appropriate jurisdiction. Contractor shall promptly inform the Client if Contractor becomes aware that certain processing activities are likely to result in a high risk to the rights and freedoms of data subjects. co-operate, at its own expense, as requested by the Client to enable it to respond and comply with (i) the exercise of rights of data subjects pursuant to Applicable Data Protection Law (such as their right of access, right to rectification, right to object to the processing of their personal data, right to erasure and right to restrict processing of their personal data and their right to data portability) and (ii) any other correspondence, enquiry or complaint received from a Data Subject, regulatory authority or any other third party in respect of personal data processed by Contractor under this DPA. promptly inform the Client of any requests relating to the exercise of such rights or complaints, enquiry or correspondence if they are received directly by Contractor and shall provide all details thereof. Contractor shall provide all information requested by the Client, within a reasonable timescale specified by the Client and shall provide such assistance to the Client to comply with the relevant request within the applicable timeframes. If necessary, Contractor shall co-operate with the competent supervisory authority. upon Client’s request, make available to the Client all records, appropriate personnel, data processing facilities, and any relevant materials relating to personal data processing, to enable the Client to demonstrate compliance with its obligations under Applicable Data Protection Law. promptly return or delete the personal data and any existing copies thereof, as soon as it is no longer required for the performance of the Services, unless any applicable law requires the further storage of the personal data. Where deletion is necessary and the Contractor cannot destroy or delete the personal data due to technical reasons, the Contractor will take all appropriate steps to (a) come to the closest possible to a complete and permanent deletion of the personal data and to fully and effectively anonymize the remaining personal data; and (b) make the remaining personal data which is not deleted or effectively anonymized unavailable for any further processing except to the extent required by any applicable law. promptly notify the Client if: (i) the Contractor cannot comply with this DPA; (ii) it has breached or is likely to breach Applicable Data Protection Law; or (iii) Applicable Data Protection Law no longer permits lawful processing or transfer of personal data. The Contractor shall take reasonable steps to remedy such issues or cease processing as instructed by the Client. 3.3 To the extent Contractor is an independent Controller of personal data that is collected, exchanged, or otherwise processed in connection with Contractor’s performance of the Agreement or delivery of the Services, Contractor will comply with its Controller obligations under Applicable Data Protection Law, for example by providing protection for the personal data, ensuring data minimization and that the personal data is processed lawfully, fairly and in a transparent manner in relation to the Data Subject, as well as responding to Data Subjects’ requests to exercise their rights. 4. Security and Accountability 4.1 Contractor shall implement appropriate and sufficient, technical and organisational security measures prior to and during processing of any personal data to protect the security, confidentiality and integrity of the personal data and to protect the personal data against any form of accidental, unlawful or unauthorized processing. In particular, without limitation, Contractor shall protect the personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, use or access to personal data transmitted, stored or otherwise processed and against any form of unlawful processing. 4.2 Contractor shall ensure a level of security appropriate to the risks presented by the processing of personal data and the nature of such personal data. Such measures shall include, as appropriate: (i) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (ii) the ability to restore the availability and access to the personal data in a timely manner in the event of a physical or technical incident; and (iii) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing. At a minimum, such measures shall include the organisational and technical measures, which meet or exceed relevant industry practice. These measures shall remain in place throughout the duration that Contractor provides Services to the Client or until Contractor ceases to process personal data, whichever is later. As of the effective date of the Agreement, Contractor has implemented the security measures set out in Annex II to this DPA. Contractor may update or modify such security measures from time to time provided that such updates and modifications do not result in the material degradation of the security of the Services. 4.3 Contractor shall upon becoming aware of any personal data breach, promptly inform the Client of the breach without undue delay and shall provide all such timely information and cooperation as the Client may reasonably require including in order for the Client to fulfil its personal data breach reporting obligations under and in accordance with the timescales required by Applicable Data Protection Law. Contractor shall further take all such measures and actions as are necessary to remedy or mitigate the effects of the breach and shall keep the Client up to date about all developments in connection with the breach 4.4 Contractor shall make available to Client, on request, all information reasonably necessary to demonstrate compliance with this DPA. Contractor may demonstrate compliance by providing either (i) a certification as to compliance with ISO 27001 or another information security management standard implemented by Contractor; or (ii) an audit or attestation report of an independent third-party. To the extent that Client requires further evidence of Contractor’s compliance with the DPA or further assurances of information security, Client or its appointed third-party auditor may upon written reasonable request conduct an inspection of the Contractor’s records, processes and systems, to the extent necessary according to Applicable Data Protection Law. Such inspection shall be conducted (i) with at least 90 days prior notice; (ii) during regular business hours and under a duty of confidentiality; (iii) with minimal disruption to Contractor’s business operations; and (iv) entirely at Client’s expense. Such inspection shall be conducted no more than once annually unless (i) further inspections are required by instruction of a competent supervisory authority or (ii) the Client believes that further inspections are necessary due to a personal data breach suffered by Contractor. Client and its agents may (at Contractor’s election) be accompanied by a member of Contractor’s staff should Client require access to Contractor’s premises during the inspection. 5. Subcontracting 5.1 Client allows Contractor to be assisted by Contractor’s subcontractors and Affiliates, and allows Contractor to appoint those subcontractors and Affiliates as Sub-processors of personal data involved in the Services, with a view to delivering, facilitating and improving the Services, provided that Contractor shall: (i) prior to appointing a Sub-processor, carry out appropriate due diligence on the Sub-processor; (ii) inform the Client at least 30 days in advance and by means of a written communication about its intention to engage a new Sub-processor, including details on the identity of the Sub-processor, the location where the personal data will be processed by such Sub-processor and the concerned data processing activities; (iii) enter into written agreements with such appointed Sub-processor guaranteeing at least the level of data protection and information security provided in this DPA; and (iv) remain liable to the Client for the Sub-processor’s acts, errors or omissions resulting in a breach of Applicable Data Protection Law. Client may within 15 days of Contractor’s notification of a new Sub-processor, object to the appointment of the Sub-processor on reasonable grounds relating to the protection of the personal data, in which case the Parties shall then work together promptly and in good faith to resolve the Client’s objections and to agree upon a mutually satisfactory solution. Contractor’s current subcontractors and Affiliates are detailed in Annex III to this DPA. Jurisdiction-Specific Terms 6.1 To the extent that either Party processes personal data originating from or otherwise subject to the data protection or security law of a particular jurisdiction, the corresponding jurisdiction-specific terms set out below shall apply in addition to, and in the event of conflict prevail over, the foregoing terms of this DPA. European Economic Area, United Kingdom and Switzerland – International Data Transfers 6.2 Contractor shall not make or permit a Restricted Transfer of any personal data (whether as an exporter or as an importer) unless an adequate level of protection in accordance with the Applicable Data Protection Law is ensured. The Parties agree that when the transfer of personal data from Client to Contractor is a Restricted Transfer it shall be subject to the appropriate Standard Contractual Clauses as follows: EU GDPR (Controller to Controller): in relation to personal data that is protected by the EU GDPR where Contractor is a Controller, the EU SCCs will apply completed as follows: (i) Module One will apply; (ii) in Clause 7, the optional docking clause will apply; (iii) in Clause 11, the optional language will not apply; (iv) in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Belgian law; (v) in Clause 18(b), disputes shall be resolved before the courts of Belgium; (vi) Annex I of the EU SCCs shall be deemed completed with the information set out in Annex I to this DPA; and (vii) Annex II of the EU SCCs shall be deemed completed with the information set out in Annex II to this DPA. EU GDPR (Controller to Processor): in relation to personal data that is protected by the EU GDPR where Contractor is a Processor and Client is the Controller, the EU SCCs will apply completed as follows: (i) Module Two will apply; (ii) in Clause 7, the optional docking clause will apply; (iii) in Clause 9, Option 1 will apply, and the time period for prior notice of Sub-processor changes shall be as set out in Clause 2.2(c) of this DPA; (iv) in Clause 11, the optional language will not apply; (v) in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Belgian law; (vi) in Clause 18(b), disputes shall be resolved before the courts of Belgium; (vii) Annex I of the EU SCCs shall be deemed completed with the information set out in Annex I to this DPA; (viii) Annex II of the EU SCCs shall be deemed completed with the information set out in Annex II to this DPA; and (ix) Annex III of the EU SCCs shall be deemed completed with the information set out in Annex III to this DPA. EU GDPR (Processor to Processor): in relation to personal data that is protected by the EU GDPR where Contractor is a Sub-processor and Client is a Processor of the personal data on behalf of a third party Controller, the EU SCCs will apply completed as follows: (i) Module Three will apply; (ii) in Clause 7, the optional docking clause will apply; (iii) in Clause 9, Option 1 will apply, and the time period for prior notice of Sub-processor changes shall be as set out in Clause 2.2(c) of this DPA; (iv) in Clause 11, the optional language will not apply; (v) in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Belgian law; (vi) in Clause 18(b), disputes shall be resolved before the courts of Belgium; (vii) Annex I of the EU SCCs shall be deemed completed with the information set out in Annex I to this DPA; (viii) Annex II of the EU SCCs shall be deemed completed with the information set out in Annex II to this DPA; and (ix) Annex III of the EU SCCs shall be deemed completed with the information set out in Annex III to this DPA. UK GDPR: in relation to personal data that is protected by the UK GDPR, the UK Addendum will apply completed as follows: The EU SCCs, completed as set out above in Clause 3.2(a)-(c) of this DPA shall also apply to transfers of such personal data; Tables 1 to 3 of the UK Addendum shall be deemed completed with relevant information from the EU SCCs, completed as set out above; and the option “neither party” shall be deemed checked in Table 4. The start date of the UK Addendum (as set out in Table 1) shall be the date of this DPA. Swiss DPA: In relation personal data that is protected by the Swiss DPA, the EU SCCs as implemented in accordance with Clause 3.2(a)-(c) will apply provided that: (i) references in the EU SCCs to “Regulation (EU) 2016/679” or the “GDPR” shall be interpreted as references to the Swiss DPA; (ii) references to “EU”, “Union” and “Member State law” shall be interpreted as references to Switzerland and to Swiss law, as the case may be; (iii) the term ‘member state’ shall not be interpreted in such a way as to exclude Data Subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland); (iv) the EU SCCs should be interpreted as protecting the data of legal entities until the entry into force of the revised Swiss DPA; (v) references to the “competent supervisory authority” and “competent courts” shall be interpreted as references to the Swiss Federal Data Protection and Information Commissioner (FDPIC) and competent courts in Switzerland; and (vi) if the Restricted Transfer is subject to both the Swiss DPA and the GDPR, then a parallel supervision takes place: FDPIC, insofar as the data Restricted Transfer is governed by the Swiss DPA; and the competent EU supervisory authority insofar as the Restricted Transfer is governed by the GDPR (the criteria of Clause 13a for the selection of the competent authority must be observed). European Economic Area – Digital Operational Resilience Act (Regulation (EU) 2022/2554) (“DORA”) and Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (“NIS2 Directive”) 6.3 To the extent applicable, the Contractor shall provide the Client with all necessary information and assistance to enable the Client to comply with its obligations under the DORA and NI2 Directive, including with respect to ICT risk management, incident handling, and operational resilience. Contractor will: implement and maintain risk management measures aligned with the DORA conducting regular risk assessments related to data processing, performing impact analyses to evaluate the potential consequences of ICT-related incidents on data security and availability, and ensuring continuous monitoring of systems and controls to promptly detect, mitigate, and respond to operational and security risks. In alignment with DORA and NIS2 requirements, Contractor shall classify and report major ICT-related incidents to the relevant authorities and impacted parties within 72 hours of becoming aware of such incidents, based on severity and applicable regulatory thresholds. conduct annual Threat-Led Penetration Testing (TLPT), performed by qualified and independent third-party security experts, simulating realistic and targeted cyberattacks to assess the effectiveness of Contractor’s security controls and incident response capabilities. The scope of such testing shall include critical systems and infrastructure involved in the data processing. Contractor shall remediate any identified vulnerabilities or weaknesses within a reasonable timeframe based on severity. Upon written request, Contractor shall provide the Client with a high-level summary of the TLPT findings and remediation actions, subject to reasonable confidentiality and security considerations. appoint one or more designated security officers responsible for overseeing and ensuring compliance with applicable cybersecurity and operational resilience regulations, including the DORA and the NIS2 Directive. These officers shall coordinate internal security efforts, monitor regulatory developments, and ensure that relevant policies, controls, and response procedures remain aligned with legal and industry obligations. California US – CCPA 6.4 To the extent that Contractor acts as a “Service Provider” as defined in CCPA Section 1798.140(ag)(1), Contractor will: comply with the restrictions imposed on Service Providers under the CCPA, and accordingly (i) not sell or share personal data; (ii) not retain, use, or disclose personal data for any purpose other than for the business purposes specified in the Agreement (including retaining, using, or disclosing it for a commercial purpose other than the business purposes specified in the Agreement or as otherwise permitted under Applicable Data Protection Law); (iii) not retain, use, or disclose personal data outside of the direct business relationship between Client and Contractor; and (iv) not combine it with personal data it receives from or on behalf of another entity or that it collects from its own interaction with the Data Subject unless permitted by the CCPA. regardless of its role under the CCPA, (i) process personal data only for the limited and specified purposes under the Agreement and this DPA; (ii) comply with applicable obligations under the CCPA and provide the same level of privacy protection as is required by the CCPA; (iii) allow Client to take reasonable and appropriate steps to ensure that Contractor uses personal data in a manner consistent with Client’s obligations under the CCPA; (iv) notify Client if Contractor makes a determination that it can no longer meet its obligations under the CCPA; and (v) allow Client upon reasonable notice to stop and remediate Contractor’s unauthorized use of personal data. 7. Indemnification 7.1 Contractor acknowledges that the obligations set forth in this DPA are essential and that any violation thereof may seriously harm the Client. Contractor shall have full and sole liability for all damages resulting from a failure on its part to comply with the provisions of this DPA subject to the limitations of liability set forth in the Agreement. Should any Data Subject to whom the personal data relates, a supervisory authority, a court or any other regulatory body lodge a claim for compensation against the Client that results from Contractor’s breach of its obligations under the Applicable Data Protection Law, Contractor shall assist and intervene in the Client’s defence against such claim upon the Client’s request and shall indemnify and hold harmless the Client against all costs and damages resulting from such claim subject to the limitations of liability set forth in the Agreement. The Client shall give Contractor prompt written notice of any such claim and shall provide all reasonable co-operation in the defence and settlement of such claim, at Contractor’s expense. The Client shall not make any admission as to Contractor’s liability in respect any claim and shall not agree to any settlement in respect of a claim without Contractor’s written consent. 8. General 8.1 If any provision in this DPA shall be held to be illegal, invalid or unenforceable, in whole or in part, the provision shall apply with whatever modification is necessary so that the provision is legal, valid and enforceable and gives effect to the Parties’ intent. 8.2 In the event of a conflict between the provisions of this DPA and those of the Agreement in respect of the processing and protection of personal data, the provisions of this DPA will prevail. 8.3 This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions set out in the Agreement, and any disputes arising out of or in connection with this DPA shall be subject to such provisions. 8.4 This DPA may from time to time be updated by Contractor, as necessary, to reflect regulatory or operational changes. DPA updates shall be deemed automatically incorporated into and made a part of this DPA upon (i) Contractor’s publication of the updates on its website (at routemobile.com/dpa and (ii) Contractor’s notification of the updates to Client. Annex I Nature and purpose of personal data processing Client accesses one or more of Contractor’s messaging, communications, mobile connectivity, identity verification, analytics, and fraud detection services, including the associated support and infrastructure services provided by Contractor, to communicate or facilitate communication with an individual and/or evaluate attributes or accuracy of the individual’s phone number and other personal details. Processing activities may include, as applicable: transmitting, routing, storing, and delivering communications authenticating users, verifying identifiers, and assessing risk signals detecting, preventing, and mitigating fraud, abuse, and security incidents monitoring service performance, availability, and quality troubleshooting, debugging, and error resolution billing, reconciliation, and usage reporting complying with applicable legal, regulatory, and telecommunications obligations maintaining, improving, testing, and developing services, systems, and infrastructure, including through aggregated or anonymized analytics. Duration of personal data processing Personal data is processed for the duration of the transaction, and thereafter for so long as necessary to complete ongoing or incidental transactions, or as required to comply with legal, regulatory, accounting, or record keeping obligations, or as necessary to resolve disputes, enforce rights, or meet contractual obligations, after which the personal data is deleted or returned in accordance with the Agreement, unless retention is required by Applicable Data Protection Law. Categories of data subjects Client’s customers or prospective customers Telecommunication subscribers or users of communication channels and digital services operated or supported by Cient Client’s employees, contractors, or agents Categories of personal data Core personal data e.g. name, gender, date of birth Contact data e.g. phone number, email address, physical address Communication data e.g., message content, headers, metadata, delivery status, timestamps, read receipts, interaction logs Technical and device data e.g., IP address, device type, operating system, browser, network information, compatibility data Usage and interaction data e.g., click rates, response rates, session data, conversation history, channel interaction metrics Authentication and verification data e.g., one time passwords, verification status, risk indicators, fraud related signals Billing and transactional data e.g., usage records, transaction identifiers, reconciliation data Troubleshooting data e.g. content provided by the Client for Contractor to render support or resolve error Support platform data e.g. username, user ID, account ID, portal preferences and settings of Client’s employees Special categories of personal data or sensitive data None Frequency of processing On a continuous basis, corresponding to Client’s use of the Services Annex II Technical and Organizational Security Measures This document describes the technical and organizational security measures implemented by Contractor, as a Proximus Global company, in connection with the provision of the Services to Client, in order to ensure a level of security appropriate to the risks associated with the processing of personal data. These measures may evolve over time to reflect changes in technology, threats, and business operations, provided that the overall level of security is not decreased. 1. IT security governance 1.1. Contractor maintains an information security management framework and has implemented risk management processes, ensuring risks are properly identified, registered, treated and approved. The risk management practice ensures that measures remain appropriate to evolving threats and the state of the art. 1.2. A clear internal responsibility for security governance has been assigned in the company. A dedicated security team composed of security specialists, reports to the Proximus Global Chief Information Security Officer. 1.3. Contractor has documented and maintains security policies supporting these frameworks and measures. 2. Certification and assurance of processes and service delivery 2.1. Contractor maintains an information security management framework consistent with the requirements of internationally recognized standards such as ISO 27001, ensures compliance with applicable laws and regulations, and implements risk management measures aligned with industry best practices. 2.2. Contractor performs regular testing and evaluation of its security measures, to verify compliance with the predefined requirements, and remediate any identified gaps. Contractor conducts periodic penetration tests, under which sensitive applications, systems or platforms are tested by qualified and independent third-party security experts, who assess the effectiveness of the security controls and incident response capabilities. 3. Personnel Security 3.1. Contractor’s personnel are required to conduct themselves in a manner consistent with the company’s guidelines regarding confidentiality, business ethics, appropriate usage, and professional standards. Contractor conducts reasonably appropriate background checks on any employees who will have access to Client data, to the extent legally permissible and in accordance with applicable local labour law, customary practice, statutory regulations, and in proportion to the data processed. Personnel are required to execute a confidentiality agreement and to always protect Client data. 3.2. Personnel are provided with privacy and security training on how to implement and comply with the information security program, at onboarding and periodically thereafter. Procedures are in place to ensure that personnel accesses are updated in the event of a role change and removed in the event of termination. 4. Data protection 4.1. Contractor protects sensitive data using strong encryption standards, to ensure information is secure both in transit and at rest, according to sensitivity, risk level and technical feasibility. 4.2. Encryption keys are managed through secure key management systems with strict access controls and segregation of duties to prevent unauthorized access. 4.3. When relevant and feasible, pseudonymisation techniques are applied. 5. Availability and resilience of processing systems and services 5.1. Contractor has developed and maintains a business continuity and disaster recovery program. The services that Contractor delivers are supported by redundant systems and backup mechanisms appropriate to the risks. 5.2. Backup procedures are in place, and periodic restoration testing is performed. 6. Access control 6.1. Contractor has implemented a formal access control policy that defines the principles, roles and responsibilities related to granting, modifying, reviewing and revoking access rights. Access is granted based on the principles of least privilege and need-to-know, ensuring that users only have access to the systems and data necessary to perform their job functions. Access provisioning and deprovisioning procedures are tied to HR processes. 6.2. A strong password policy is enforced, and multi-factor authentication is required for sensitive accesses (remote access, privileged activities). 6.3. Regular review of user privileges is performed, in order to validate the appropriateness of permissions, and remove those that are no longer necessary 7. Physical security 7.1. Physical access to any facility where data is being processed is controlled via badge systems or equivalent measures. Access is granted only to personnel who require such access to perform their duties. 7.2. A visitor process is in place: visitors’ accesses are logged, and visitors are escorted within the facilities. 7.3. Physical and environmental protections are in place in the facilities: fire detection, power backup, climate control, etc. 8. Secure system configuration 8.1. Contractor maintains documented secure configuration standards for infrastructure and applications. These standards are based on industry best practices and recognized frameworks. This includes system hardening procedures, removal and disabling of unnecessary services, ports and default accounts, enforcement of secure baseline configurations, and controlled change management procedures. 8.2. A vulnerability management program is in place, ensuring the identification, assessment and remediation of any identified weaknesses. Contractor performs periodic scanning of internal and external systems, prioritizes identified vulnerabilities based on their severity and associated risks, and defines remediation timelines. A patch management process is in place, to ensure timely application of security updates. 8.3. Contractor implements layered protection against malicious software across its network and infrastructure. Centrally managed anti-malware protection solutions are deployed and monitored. Email and web filtering are implemented, to detect malicious attachments and links, and to prevent access to known malicious domains. 8.4. A defense-in-depth approach protects Contractor’s network, including network segmentation, firewalls controlling inbound and outbound traffic, and intrusion detection and prevention mechanisms. 8.5. Logging and monitoring systems are implemented, to detect and respond to suspicious activity. Security events are logged and, where feasible, collected centrally. Alert mechanisms are defined to ensure a timely response in the event of an incident. Log retention is aligned with business and legal requirements. 9. Data minimisation, retention and deletion 9.1. Contractor applies the principle of data minimisation, so that only personal and business data strictly necessary for defined and legitimate purposes is collected and processed. The processing of personal data is limited to what is necessary for contractual, legal, or operational requirements. A privacy-by-design approach is embedded in system and process development. 9.2. A data retention policy defines retention periods, based on legal and regulatory requirements, contractual obligations and business and operational needs. 9.3. When the data is no longer necessary, secure deletion is performed, ensuring that data is irreversibly removed from the systems. Secure erasure methods are used for electronic data. Secure disposal of physical media is performed by certified companies. 10. Supply chain security 10.1. Contractor conducts due diligence and security assessment before onboarding suppliers. Suppliers are contractually obliged to ensure at least the same level of security that Contractor upholds. 10.2. Contractor regularly monitors its supply chain, to verify compliance with the security requirements. 11. Incident management 11.1. Contractor maintains a formal incident management framework designed to quickly identify, assess, and respond to security events. Contractor’s systems are continuously monitored for suspicious activity, with defined escalation procedures to ensure timely containment and remediation. 11.2. In the event of a confirmed incident, a team of experts is gathered to manage the incident. The team follows documented response and communication processes, including root cause analysis, and corrective actions, and, where required, external notification towards impacted Clients and/or regulatory notification in line with applicable laws. 11.3. Regular testing and post-incident reviews are performed to strengthen the controls and improve resilience. Annex III Route Mobile engages the following third-party service providers to perform specific processing activities in connection with the Services. Entity Name Role Processing Location Services Amazon Web Services (AWS) Cloud hosting, infrastructure, storage, communication, monitoring (CloudWatch, WAF, etc.) India, US, EU, Global RCS, WhatsApp, Masiv WhatsApp, Viber, Ocean, SMS, Email CloudWatch Monitoring AWS monitoring services Mumbai RCS, WhatsApp, Viber CtrlS Physical data center Bangalore Email Digital Ocean Physical data center US Email DNIF Hypercloud SIEM security solutions India SMS Etisalat OneCloud Cloud hosting & infrastructure UAE SMS Grafana Monitoring Infrastructure monitoring & SLA validation Mumbai RCS, WhatsApp, Viber Google RCS, Push services, Email services Global, US, India Ocean, SMS Google Cloud Services Cloud hosting & infrastructure Indonesia SMS Google India Domain services India Email Hetrix Tools Log monitoring Global Email Hetzner Physical data center Germany Email HPE Greenlake Server infrastructure Bangalore Email Inbox Monster Domain insights Global Email InterCloud Cloud hosting & infrastructure Bangladesh SMS Meta WhatsApp Business services Global Masiv WhatsApp, Ocean, Roubot MongoDB Atlas Data storage for campaigns/events LATAM, India Ocean Namecheap Domain services India Email NxtGen Cloud hosting & infrastructure India SMS Palo Alto Firewall/security India, Singapore, US SMS, Email Pioneer Elabs Internet services India Email Rackspace Cloud hosting & infrastructure US, UK SMS RML SMS Platform Cloud hosting & communication platform Global RCS, WhatsApp, Viber Robi Axiata Infrastructure support Bangladesh RCS SentinelOne Endpoint security (EDR) Singapore, India SMS Server Mania Physical data center US Email STC Cloud hosting & infrastructure Saudi Arabia SMS Stripo Email template creation Global Email WAF Firewall AWS firewall security Mumbai RCS, WhatsApp, Viber WBS Bank of Maharashtra On-prem infrastructure Pune, India Roubot Zoom Video conferencing US SMS The following entities are Route Mobile companies and Affiliates that may process data in connection with provision of the Services. Affiliates are engaged due to the global nature of Route Mobile’s operations, and each Affiliate is bound by intra-group data processing agreements that impose data protection obligations no less protective than those set out in this DPA. Entity Name Role Processing Location Address Telesign Corporation Operational support US 13274 Fiji Way Suite 600, Marina del Rey, CA 90292, US Belgacom International Carrier Services SA/NV Operational support Belgium Boulevard du Roi Albert II 27, 1030 Brussels, Belgium Proximus Global SA Operational support Belgium Boulevard du Roi Albert II 27, 1030 Brussels, Belgium