Third Party Index

Snapshot 69301

Document
Data processing addendum
URL
https://www.apptoto.com/downloads/ApptotoStandardDataProcessingAddendum.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
204961 bytes
SHA-256 (raw)
f0ee9411068edd60a26f128bc0e5a7a195aadd17d65104a97fb80634d1970968
SHA-256 (normalized text)
f02b67ac69f9e770af76817c26a88a119f52e0548cc97ce393ab2ad78a3b524e

Normalized text

Scripts and page chrome removed; this is what change detection compares.

                        APPTOTO DATA PROCESSING ADDENDUM

This Apptoto Data Processing Addendum (this “Addendum”) constitutes a binding agreement
by and between Go-Cort, Inc., an Oregon corporation dba Apptoto (“Apptoto”) and you, the
customer (“Customer”). This Addendum is incorporated into and made part of the Apptoto End
User License Agreement (the “EULA”) previously or contemporaneously entered into by
Customer and governs the processing of personal data that Customer uploads or otherwise
provides to Apptoto. If you are entering into this Agreement on behalf of an entity or
organization, you are representing and warranting that you have the authority to bind the
Customer and you are agreeing to these terms on behalf of yourself and the Customer.
Collectively, this Addendum and the EULA are referred to in this Addendum as the “Apptoto
Agreement.” In the event of any conflict or inconsistency between any of the terms of this
Addendum and the terms of the EULA, the terms of this Addendum will prevail as it relates to
the subject matter herein. Except as specifically amended by this Addendum, the EULA and any
other applicable agreements between Customer and Apptoto remain unchanged and in full force
and effect.

1.     DEFINITIONS

“Apptoto Services” means any services or Software (as defined in the EULA) that Apptoto
provides to Customer in connection with the Apptoto Agreement.

“Controller” means the natural or legal person, public authority, agency, or other body, which,
alone or jointly with others, determines the purposes and means of the processing of Customer
Personal Data.

“Customer Personal Data” means Personal Data that Customer uploads, integrates, or
otherwise provides to Apptoto in connection with Apptoto Services.

 “General Data Protection Regulation” or “GDPR” means the European Union Regulation on
the protection of individuals with regard to the processing of personal data and on the free
movement of such data, repealing Directive 95/46/EC, and includes any applicable subsequent
legislation and regulations implementing the GDPR.

“Personal Data” means any information relating to an identified or identifiable natural person
(“Data Subject”); an identifiable natural person is one who can be identified, directly or
indirectly, in particular by reference to an identifier such as name, an identification number,
location data, an online identifier or to one or more factors specific to the physical, physiological,
genetic, mental, economic, cultural, or social identity of that natural person.

Page !1.       END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                      16934-001\1305393_3
“Personal Data Breach” means a breach of security leading to the accidental or unlawful
destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data
transmitted, stored, or otherwise processed.

“Processing” means any operation or set of operations which is performed on Personal Data or
on sets of Personal Data, whether or not by automated means, such as collection, recording,
organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure
by transmission, dissemination or otherwise making available, alignment or combination,
restriction, erasure, or destruction.

“Processor” means a natural or legal person, public authority, agency, or other body, which
processes Customer Personal Data on behalf of the Controller.

“Subprocessor” means any entity that provides processing services to Apptoto in furtherance of
Apptoto’s processing on behalf of Customer.

“Supervisory Authority” means an independent public authority established by a European
Union member state pursuant to Article 51 of the General Data Protection Regulation.

2.     DATA PROCESSING

       2.1.   Roles of the Parties. Customer is the Controller and Apptoto is the Processor of
       Customer Personal Data. Customer appoints Apptoto as Processor to process Customer
       Personal Data and to engage Subprocessors in accordance with this Addendum.

       2.2.    Scope of Processing. Apptoto will process Customer Personal Data as necessary
       to provide Apptoto Services, and as further instructed by Customer in writing in
       connection with the Apptoto Agreement.

               (a)    Duration of Processing. Subject to Section 7 of this Addendum, Apptoto
       will process Customer Personal Data for the duration of the Apptoto Agreement, unless
       otherwise agreed in writing.

               (b)    Categories of Data Subjects. Customer may submit Personal Data to
       Apptoto, the extent of which is determined and controlled by Customer in its sole
       discretion, and which may include, but is not limited to Personal Data relating to the
       following categories of Data Subjects:

                    (i)     Prospective clients, clients, business partners, and vendors of
       Customer (who are natural persons);

                     (ii)   Employees, agents, family members, and contact persons of
       Customer’s prospective clients, clients, business partners, and vendors;
Page !2.       END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                       16934-001\1305393_3
                      (iii)    Employees, agents, advisors, and freelancers of Customer (who are
       natural persons); or

                      (iv)     Users authorized by Customer to use Apptoto Services.

               (c)    Categories of Customer Personal Data. Customer may submit Personal
       Data to Apptoto, the extent of which is determined and controlled by Customer in its sole
       discretion, and which may include, but is not limited to the following categories of
       Personal Data:

                      (i)      First, middle, and last name and nicknames;

                      (ii)     Title;

                      (iii)    Email address;

                      (iv)     Phone number;

                      (v)      Other contact information;

                      (vi)     Appointment information (event title, location, notes, time);

                      (vii)    IP address; or

                      (viii)   Personal life data (including additional notes added by user).

               (d)    Compliance with Law. Customer is solely responsible for the lawfulness
       of the Processing of Customer Personal Data and the lawfulness of the means by which
       Customer acquires Customer Personal Data, including, without limitation, the scope and
       adequacy of consent from Data Subjects. Customer agrees that its use of Apptoto
       Services for the Processing of Customer Personal Data will comply with applicable law,
       including, without limitation, the GDPR.

       2.3.    Compliance with Customer Instructions. Apptoto will process Customer
       Personal Data on behalf of Customer and in accordance with Customer’s instructions for
       the purposes described in the Apptoto Agreement and for the purposes of and as initiated
       by Customer’s users of the Apptoto Services. If Apptoto believes that an instruction from
       Customer violates applicable law, including, without limitation, the GDPR, Apptoto will
       notify Customer without undue delay and may suspend performance until Customer has
       modified or confirmed the lawfulness of the instruction in writing.

Page !3.      END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                    16934-001\1305393_3
       2.4.    Other Controllers. Customer will serve as a single point of contact for Apptoto
       with respect to Customer Personal Data. To the extent that other Controllers may have
       any rights as joint Controllers with Customer with respect to Customer Personal Data,
       Customer agrees to exercise all such rights on their behalf and to obtain all necessary
       approvals and consents from the other Controllers. Apptoto will have no obligation to
       inform or notify such other Controllers when Apptoto has provided such information or
       notice to Customer.

3.     SECURITY MEASURES AND BREACH RESPONSE

       3.1.    Security Measures. Apptoto will implement and maintain technical and
       organizational measures as set forth in Exhibit 1 (“Security Measures”) to ensure a level
       of security appropriate to the risk for Apptoto’s scope of responsibility. These measures
       are subject to technical progress and further development. Apptoto reserves the right to
       modify these measures from time to time, so long as the functionality and security of
       Apptoto Services materially comply with applicable law.

       3.2.   Notice to Customer of Personal Data Breach. Apptoto will notify Customer
       without undue delay after becoming aware of a Personal Data Breach with respect to
       Apptoto Services.

       3.3.    Assistance to Customer. Apptoto will reasonably assist Customer, at Customer’s
       expense, in ensuring compliance with Customer’s obligations relating to the security of
       Processing, the notification of a Personal Data Breach, and the conduct of a data
       protection impact assessment, taking into account the information available to Apptoto.

       3.4.    Personal Data Breach Response. Apptoto will promptly investigate a Personal
       Data Breach if it occurred on Apptoto infrastructure or in another area for which Apptoto
       is responsible. Apptoto will make reasonable efforts to identify the cause of such Personal
       Data Breach and take those steps as Apptoto deems necessary and reasonable in order to
       remediate the cause of such a Personal Data Breach to the extent the remediation is
       within Apptoto’s reasonable control. The obligations in this Section 3.4 will not apply to
       incidents that are caused by Customer or Customer’s users.

4.     DATA SUBJECT RIGHTS AND REQUESTS.

       4.1.    Data Subject Requests. Apptoto will, to the extent legally permitted, promptly
       notify Customer if Apptoto receives a request from a Data Subject to exercise the Data
       Subject’s right of access, right to rectification, restriction of Processing, erasure (“right to
       be forgotten”), data portability, object to the Processing, or its right not to be subject to
       automated individual decision making (“Data Subject Request”). Customer is solely
       responsible for responding to a Data Subject Request. To the extent practicable by
       appropriate technical and organizational measures, and to the extent Apptoto is

Page !4.       END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                       16934-001\1305393_3
       legally permitted to do so, Apptoto will use commercially reasonable efforts to assist
       Customer, at Customer’s expense, in complying with Customer’s obligation to
       respond to a Data Subject Request in accordance with applicable law, including,
       without limitation, the GDPR.

5.     THIRD PARTY REQUESTS; CONFIDENTIALITY

       5.1.    No Unauthorized Disclosure. Except in accordance with the Apptoto Agreement
       and as permitted by applicable law, Apptoto will not disclose Customer Personal Data to
       any third party. If a Supervisory Authority demands access to Customer Personal Data,
       Apptoto will notify Customer prior to disclosure, unless prohibited by applicable law, in
       which case no prior notice is required.

       5.2.   Restrictions on Use. Apptoto shall treat all Customer Personal Data as
       confidential and shall process Customer Personal Data in accordance with the Apptoto
       Agreement and for no other purpose unless required by applicable law.

6.     AUDIT

       6.1.    Cooperation. Apptoto will allow for and contribute to audits, including
       inspections, conducted by Customer or another auditor designated by Customer of
       Apptoto’s Processing of Customer Personal Data, subject to the following procedures:

              (a)    On Customer’s written request, Apptoto will provide Customer or its
       designated auditor with the most recent certifications and/or summary audit report(s),
       which Apptoto has procured to regularly test, assess, and evaluate the effectiveness of its
       Security Measures.

              (b)     Apptoto will reasonably cooperate with Customer by providing available
       additional information concerning its Security Measures, to help Customer better
       understand such Security Measures.

               (c)    If Customer needs further information to comply with its own or another
       Controller’s audit obligations or a competent Supervisory Authority’s request, Customer
       will inform Apptoto in writing to enable Apptoto to provide such information or to grant
       Customer access to it.

               (d)    To the extent it is not possible to otherwise satisfy an audit obligation
       mandated by applicable law, only legally mandated entities (such as a governmental
       regulatory agency having oversight of Customer’s operations), Customer, or its
       designated auditor may conduct an onsite visit of the facilities used to perform Processing
       pursuant to the Apptoto Agreement, during normal business hours and only in a manner
       that causes minimal disruption to Apptoto’s business, subject to coordinating the timing

Page !5.      END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                   16934-001\1305393_3
       of such visit and in accordance with any audit procedures reasonably necessary in order
       to reduce any risk to Apptoto’s other customers.

       6.2.    Costs. Each party will bear its own costs of performing its obligations under
       Sections 6.1(a) and 6.1(b). Any further assistance with be at Customer’s sole expense
       unless otherwise agreed to in writing by Apptoto.

7.     RETURN OR DELETION OF CUSTOMER PERSONAL DATA

       7.1.    Deletion On Termination. On expiration or earlier termination of the Agreement,
       Apptoto will either delete or return Customer Personal Data in its possession or control,
       unless otherwise required or permitted by applicable law.

8.     SUBPROCESSORS

       8.1.    Subprocessing Permitted. Customer authorizes Apptoto to engage
       subcontractors to process Customer Personal Data. A list of current Subprocessors is set
       out in attached Exhibit 2. Apptoto will give Customer not less than 10 days’ advance
       written notice of any changes to Appptoto’s Subprocessors. Within ten (10) days after
       Apptoto’s notification of the intended change, Customer can object to the addition of a
       Subprocessor on the basis that such addition would cause Customer to violate applicable
       law. Customer’s objection will be in writing and include Customer’s specific reasons for
       its objection, including the applicable legal requirements, and options to mitigate, if any.
       If Customer does not object within such period, the respective Subprocessor may be
       authorized to process Customer Personal Data. Apptoto will impose substantially similar
       data protection obligations as set out in this Addendum on any approved Subprocessor
       prior to the Subprocessor Processing any Customer Personal Data.

       8.2.     Notice of Objection. If Customer legitimately objects to the addition of a
       Subprocessor and Apptoto cannot reasonably accommodate Customer’s objection,
       Apptoto will notify Customer. Customer may terminate the Apptoto Agreement with
       respect only to those Apptoto Services that cannot be provided by Apptoto without the
       use of the objectionable Subprocessor by providing Apptoto with a written notice within
       thirty (30) days of Apptoto’s notice. Apptoto will refund a prorated portion of any prepaid
       charges for the period after such termination date, without penalty for such termination.

9.     TRANSBORDER DATA PROCESSING

       9.1.   Standard Contractual Clauses. By agreeing to this Addendum, Customer is
       entering into the EU Standard Contractual Clauses as referred to in attached Exhibit 3,
       with the Subprocessors established outside either the European Economic Area or
       countries considered by the European Commission to have adequate protection (“Data
       Importers”).

Page !6.      END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                    16934-001\1305393_3
         9.2.    Other Controllers. Customer agrees on behalf of any other Controller of
         Customer Personal Data, or if unable to agree, will procure agreement of such Controller,
         to be an additional data exporter with respect to the EU Standard Contractual Clauses
         concluded between Apptoto and Customer. Apptoto accepts the agreement of such other
         Controller. Customer agrees and, if applicable, procures the agreement of any other
         Controller that the EU Standard Contractual Clauses, including any claims arising from
         them, are subject to the terms set forth in the Apptoto Agreement, including, without
         limitation, the exclusions and limitations of liability. In case of conflict, the EU Standard
         Contractual Clauses will prevail.

10.      INDEMNITY; LIMITATION OF LIABILITY

         10.1. Indemnity. In addition to and not in lieu of existing indemnification obligations
         in the EULA, Customer agrees to indemnify, defend, and hold Apptoto harmless for,
         from, and against, any and all costs, charges, damages, expenses (including attorney’s
         fees), and losses arising from or related to Customer’s breach of this Addendum,
         including, without limitation, non-compliance with the GDPR.

         10.2. Limitation of Liability. Each party’s liability arising out of or related to this
         Addendum, whether in contract, tort, or under any other theory of liability, is subject to
         any and all limitations of liability in the EULA.

APPTOTO                                                 CUSTOMER

By:                                                     By:
Name                                                    Name
:                                                       :
Title:                                                  Title:

Page !7.        END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                      16934-001\1305393_3
Page !8.   END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                     16934-001\1305393_3
                                             EXHIBIT 1

                                     SECURITY MEASURES

   1. Access

             a. Access to private information about data subjects is limited to employees of
                Apptoto. Those employees include support and operations personnel.

             b. Support personnel may see the information but only to provide support requested
                by Customer. All access is logged and monitored. Our CEO and Chief Privacy
                Officer is notified every time support personnel access Customer Personal Data.
                Two-factor authentication is required for use by support personnel.

             c. Operations personnel have access to the infrastructure used to run Apptoto
                (including servers and databases). Operations personnel may see the information
                within a Customer’s account through server consoles, but only while performing
                operations required to support Apptoto’s processing.

             d. All support and operations personnel undergo extensive background checks
                before being hired.

   2.      Encryption

             a. All data is strongly encrypted (minimum key length is 256 bits) in transit
                between:

                     i. Customer and Apptoto (through website portal and API)

                     ii. Apptoto and Subprocessors (through API)

             b. All data is strongly encrypted at rest on disk.

   3.      Security (System, Physical, Environmental)

             a. All servers under control of Apptoto run virus detection software.

             b. All workstations under control of Apptoto run virus detection software.

             c. All personnel are required to leverage password managers and 2FA when
                available.

             d. All servers and databases are only accessible to operations personnel through
                VPN and Bastion gateways.

Page !9.         END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                     16934-001\1305393_3
   4.   Periodic Assessments

            a. Periodic virus detection software assessment

            b. Periodic assessment of Acceptable Use Policy by personnel (see https://
               www.apptoto.com/downloads/security_policies/
               apptoto_acceptable_use_policy.pdf)

            c. Monthly web application security assessments through

                   i. OWASP ZAP

                   ii. Tinfoil Security Scanner

   5.   Incident Response

            a. https://www.apptoto.com/downloads/security_policies/
               apptoto_data_breach_response.pdf

Page !10.      END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                 16934-001\1305393_3
                                      EXHIBIT 2

                                  SUBPROCESSORS

   ● Amazon Web Services

   ● Armor.com (for Healthcare clients)

   ● Twilio

   ● Sendgrid

   ● Mailgun

   ● Clicksend

Page !11.     END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                        16934-001\1305393_3
                                            EXHIBIT 3

                STANDARD CONTRACTUAL CLAUSES (PROCESSORS)

For the purposes of Article 26(2) of Directive 95/46/EC for the transfer of personal data to
processors established in third countries which do not ensure an adequate level of data protection
Name of the data exporting organisation:
Address:
Tel.: _______________; fax: _______________; e-mail: _______________
Other information needed to identify the organization:
                                        (the data exporter)
                                                And
Name of the data importing organisation: Apptoto
Address: 61149 South Highway 97 #505, Bend, OR 97701
Tel.: _888-318-3765__; e-mail: ___support@apptoto.com_______
Other information needed to identify the organisation:
                                        (the data importer)
                               each a ‘party’; together ‘the parties’,
HAVE AGREED on the following Contractual Clauses (the Clauses) in order to adduce adequate
safeguards with respect to the protection of privacy and fundamental rights and freedoms of
individuals for the transfer by the data exporter to the data importer of the personal data specified
in Appendix 1.

                                             Clause 1

                                            Definitions
For the purposes of the Clauses:

(a ‘personal data’, ‘special categories of data’, ‘process/processing’, ‘controller’, ‘processor’,
) ‘data subject’ and ‘supervisory authority’ shall have the same meaning as in Directive 95/46/
   EC of the European Parliament and of the Council of 24 October 1995 on the protection of
   individuals with regard to the processing of personal data and on the free movement of such
   data;

 (b ‘the data exporter’ means the controller who transfers the personal data;
 )
Page !12.      END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                     16934-001\1305393_3
(c ‘the data importer’ means the processor who agrees to receive from the data exporter
) personal data intended for processing on his behalf after the transfer in accordance with his
   instructions and the terms of the Clauses and who is not subject to a third country’s system
   ensuring adequate protection within the meaning of Article 25(1) of Directive 95/46/EC;

(d ‘the sub-processor’ means any processor engaged by the data importer or by any other sub-
) processor of the data importer who agrees to receive from the data importer or from any
   other sub-processor of the data importer personal data exclusively intended for processing
   activities to be carried out on behalf of the data exporter after the transfer in accordance with
   his instructions, the terms of the Clauses and the terms of the written subcontract;

(e ‘the applicable data protection law’ means the legislation protecting the fundamental rights
) and freedoms of individuals and, in particular, their right to privacy with respect to the
   processing of personal data applicable to a data controller in the Member State in which the
   data exporter is established;

( f ‘technical and organisational security measures’ means those measures aimed at protecting
) personal data against accidental or unlawful destruction or accidental loss, alteration,
    unauthorised disclosure or access, in particular where the processing involves the
    transmission of data over a network, and against all other unlawful forms of processing.

                                              Clause 2

                                      Details of the transfer
The details of the transfer and in particular the special categories of personal data where
applicable are specified in Appendix 1 which forms an integral part of the Clauses.

                                              Clause 3

                                 Third-party beneficiary clause

1. The data subject can enforce against the data exporter this Clause, Clause 4(b) to (i), Clause
   5(a) to (e), and (g) to (j), Clause 6(1) and (2), Clause 7, Clause 8(2), and Clauses 9 to 12 as
   third-party beneficiary.

2. The data subject can enforce against the data importer this Clause, Clause 5(a) to (e) and (g),
   Clause 6, Clause 7, Clause 8(2), and Clauses 9 to 12, in cases where the data exporter has
   factually disappeared or has ceased to exist in law unless any successor entity has assumed
   the!13
Page    entire
          .    legal
                 END obligations of the data exporter
                       USER AGREEMENT           – DATAby contract or by operation
                                                         PROCESSING       ADDENDUMof law, as a result
                                                                                      16934-001\1305393_3
3. The data subject can enforce against the sub-processor this Clause, Clause 5(a) to (e) and (g),
   Clause 6, Clause 7, Clause 8(2), and Clauses 9 to 12, in cases where both the data exporter
   and the data importer have factually disappeared or ceased to exist in law or have become
   insolvent, unless any successor entity has assumed the entire legal obligations of the data
   exporter by contract or by operation of law as a result of which it takes on the rights and
   obligations of the data exporter, in which case the data subject can enforce them against such
   entity. Such third-party liability of the sub-processor shall be limited to its own processing
   operations under the Clauses.

4. The parties do not object to a data subject being represented by an association or other body
   if the data subject so expressly wishes and if permitted by national law.

                                            Clause 4

                                Obligations of the data exporter
The data exporter agrees and warrants:

(a that the processing, including the transfer itself, of the personal data has been and will
) continue to be carried out in accordance with the relevant provisions of the applicable data
   protection law (and, where applicable, has been notified to the relevant authorities of the
   Member State where the data exporter is established) and does not violate the relevant
   provisions of that State;

(b that it has instructed and throughout the duration of the personal data-processing services
) will instruct the data importer to process the personal data transferred only on the data
   exporter’s behalf and in accordance with the applicable data protection law and the Clauses;

(c that the data importer will provide sufficient guarantees in respect of the technical and
) organisational security measures specified in Appendix 2 to this contract;

(d that after assessment of the requirements of the applicable data protection law, the security
) measures are appropriate to protect personal data against accidental or unlawful destruction
   or accidental loss, alteration, unauthorised disclosure or access, in particular where the
   processing involves the transmission of data over a network, and against all other unlawful
   forms of processing, and that these measures ensure a level of security appropriate to the
   risks presented by the processing and the nature of the data to be protected having regard to
   the state of the art and the cost of their implementation;

 (e) that
Page !14. it willEND
                  ensure compliance
                      USER          with the security
                            AGREEMENT         – DATAmeasures;
                                                      PROCESSING ADDENDUM
                                                                                   16934-001\1305393_3
( f that, if the transfer involves special categories of data, the data subject has been informed or
) will be informed before, or as soon as possible after, the transfer that its data could be
    transmitted to a third country not providing adequate protection within the meaning of
    Directive 95/46/EC;

(g to forward any notification received from the data importer or any sub-processor pursuant to
) Clause 5(b) and Clause 8(3) to the data protection supervisory authority if the data exporter
   decides to continue the transfer or to lift the suspension;

(h to make available to the data subjects On request a copy of the Clauses, with the exception
) of Appendix 2, and a summary description of the security measures, as well as a copy of any
   contract for sub-processing services which has to be made in accordance with the Clauses,
   unless the Clauses or the contract contain commercial information, in which case it may
   remove such commercial information;

( i that, in the event of sub-processing, the processing activity is carried out in accordance with
) Clause 11 by a sub-processor providing at least the same level of protection for the personal
    data and the rights of data subject as the data importer under the Clauses; and

(j) that it will ensure compliance with Clause 4(a) to (i).

                                             Clause 5

                                Obligations of the data importer
The data importer agrees and warrants:

(a to process the personal data only on behalf of the data exporter and in compliance with its
) instructions and the Clauses; if it cannot provide such compliance for whatever reasons, it
   agrees to inform promptly the data exporter of its inability to comply, in which case the data
   exporter is entitled to suspend the transfer of data and/or terminate the contract;

(b that it has no reason to believe that the legislation applicable to it prevents it from fulfilling
) the instructions received from the data exporter and its obligations under the contract and
   that in the event of a change in this legislation which is likely to have a substantial adverse
   effect on the warranties and obligations provided by the Clauses, it will promptly notify the
   change to the data exporter as soon as it is aware, in which case the data exporter is entitled
   to suspend the transfer of data and/or terminate the contract;

Page !15.      END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                     16934-001\1305393_3
(c that it has implemented the technical and organisational security measures specified in
) Appendix 2 before processing the personal data transferred;

(d that it will promptly notify the data exporter about:
) (i)       any legally binding request for disclosure of the personal data by a law enforcement
   authority unless otherwise prohibited, such as a prohibition under criminal law to preserve
   the confidentiality of a law enforcement investigation;

   (ii)     any accidental or unauthorised access; and

   (iii)  any request received directly from the data subjects without responding to that
   request, unless it has been otherwise authorised to do so;

(e to deal promptly and properly with all inquiries from the data exporter relating to its
) processing of the personal data subject to the transfer and to abide by the advice of the
   supervisory authority with regard to the processing of the data transferred;

( f at the request of the data exporter to submit its data-processing facilities for audit of the
) processing activities covered by the Clauses which shall be carried out by the data exporter
    or an inspection body composed of independent members and in possession of the required
    professional qualifications bound by a duty of confidentiality, selected by the data exporter,
    where applicable, in agreement with the supervisory authority;

(g to make available to the data subject On request a copy of the Clauses, or any existing
) contract for sub-processing, unless the Clauses or contract contain commercial information,
   in which case it may remove such commercial information, with the exception of Appendix
   2 which shall be replaced by a summary description of the security measures in those cases
   where the data subject is unable to obtain a copy from the data exporter;

(h that, in the event of sub-processing, it has previously informed the data exporter and
) obtained its prior written consent;

( i that the processing services by the sub-processor will be carried out in accordance with
) Clause 11;

Page !16.      END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                   16934-001\1305393_3
( j to send promptly a copy of any sub-processor agreement it concludes under the Clauses to
) the data exporter.

                                            Clause 6

                                            Liability

1. The parties agree that any data subject, who has suffered damage as a result of any breach of
   the obligations referred to in Clause 3 or in Clause 11 by any party or sub-processor is
   entitled to receive compensation from the data exporter for the damage suffered.

2. If a data subject is not able to bring a claim for compensation in accordance with paragraph 1
   against the data exporter, arising out of a breach by the data importer or his sub-processor of
   any of their obligations referred to in Clause 3 or in Clause 11, because the data exporter has
   factually disappeared or ceased to exist in law or has become insolvent, the data importer
   agrees that the data subject may issue a claim against the data importer as if it were the data
   exporter, unless any successor entity has assumed the entire legal obligations of the data
   exporter by contract of by operation of law, in which case the data subject can enforce its
   rights against such entity.
  The data importer may not rely on a breach by a sub-processor of its obligations in order to
  avoid its own liabilities.

3. If a data subject is not able to bring a claim against the data exporter or the data importer
   referred to in paragraphs 1 and 2, arising out of a breach by the sub-processor of any of their
   obligations referred to in Clause 3 or in Clause 11 because both the data exporter and the data
   importer have factually disappeared or ceased to exist in law or have become insolvent, the
   sub-processor agrees that the data subject may issue a claim against the data sub-processor
   with regard to its own processing operations under the Clauses as if it were the data exporter
   or the data importer, unless any successor entity has assumed the entire legal obligations of
   the data exporter or data importer by contract or by operation of law, in which case the data
   subject can enforce its rights against such entity. The liability of the sub-processor shall be
   limited to its own processing operations under the Clauses.

                                            Clause 7

                                  Mediation and jurisdiction

1. The data importer agrees that if the data subject invokes against it third-party beneficiary
   rights and/or claims compensation for damages under the Clauses, the data importer will
Page  !17. the decision
   accept       END USERof the AGREEMENT
                               data subject: – DATA PROCESSING ADDENDUM
                                                                                   16934-001\1305393_3
2. The parties agree that the choice made by the data subject will not prejudice its substantive or
   procedural rights to seek remedies in accordance with other provisions of national or
   international law.

                                             Clause 8

                           Cooperation with supervisory authorities

1. The data exporter agrees to deposit a copy of this contract with the supervisory authority if it
   so requests or if such deposit is required under the applicable data protection law.

2. The parties agree that the supervisory authority has the right to conduct an audit of the data
   importer, and of any sub-processor, which has the same scope and is subject to the same
   conditions as would apply to an audit of the data exporter under the applicable data protection
   law.

3. The data importer shall promptly inform the data exporter about the existence of legislation
   applicable to it or any sub-processor preventing the conduct of an audit of the data importer,
   or any sub-processor, pursuant to paragraph 2. In such a case the data exporter shall be
   entitled to take the measures foreseen in Clause 5(b).

                                             Clause 9

                                         Governing law
The Clauses shall be governed by the law of the Member State in which the data exporter is
established.

                                            Clause 10

                                    Variation of the contract
The parties undertake not to vary or modify the Clauses. This does not preclude the parties from
adding clauses on business related issues where required as long as they do not contradict the
Clause.

                                            Clause 11

                                         Sub-processing

1. The data importer shall not subcontract any of its processing operations performed on behalf
   of the
Page  !18. data exporter
                 END USERunderAGREEMENT
                               the Clauses without the PROCESSING
                                              – DATA   prior written consent of the data exporter.
                                                                        ADDENDUM
                                                                                    16934-001\1305393_3
2. The prior written contract between the data importer and the sub-processor shall also provide
   for a third-party beneficiary clause as laid down in Clause 3 for cases where the data subject
   is not able to bring the claim for compensation referred to in paragraph 1 of Clause 6 against
   the data exporter or the data importer because they have factually disappeared or have ceased
   to exist in law or have become insolvent and no successor entity has assumed the entire legal
   obligations of the data exporter or data importer by contract or by operation of law. Such
   third-party liability of the sub-processor shall be limited to its own processing operations
   under the Clauses.

3. The provisions relating to data protection aspects for sub-processing of the contract referred
   to in paragraph 1 shall be governed by the law of the Member State in which the data
   exporter is established, namely …

4. The data exporter shall keep a list of sub-processing agreements concluded under the Clauses
   and notified by the data importer pursuant to Clause 5(j), which shall be updated at least once
   a year. The list shall be available to the data exporter’s data protection supervisory authority.

                                             Clause 12

            Obligation after the termination of personal data-processing services

1. The parties agree that on the termination of the provision of data-processing services, the data
   importer and the sub-processor shall, at the choice of the data exporter, return all the personal
   data transferred and the copies thereof to the data exporter or shall destroy all the personal
   data and certify to the data exporter that it has done so, unless legislation imposed On the
   data importer prevents it from returning or destroying all or part of the personal data
   transferred. In that case, the data importer warrants that it will guarantee the confidentiality of
   the personal data transferred and will not actively process the personal data transferred
   anymore.

2. The data importer and the sub-processor warrant that On request of the data exporter and/or
   of the supervisory authority, it will submit its data-processing facilities for an audit of the
   measures referred to in paragraph 1.

Page !19.      END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                      16934-001\1305393_3
On behalf of the data exporter:
Name (written out in full):
Position:
Address:
Other information necessary in order for the contract to be binding (if any):
                                                    Signature_____________________________
On behalf of the data importer:
Name (written out in full): Frank Cort
Position: President
Address: 61149 South Highway 97 #505, Bend, OR 97701

Other information necessary in order for the contract to be binding (if any):
                                                    Signature_____________________________

Page !20.      END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                16934-001\1305393_3
                APPENDIX 1 TO THE STANDARD CONTRACTUAL CLAUSES
   This Appendix forms part of the Clauses and must be completed and signed by the parties.
The Member States may complete or specify, according to their national procedures, any
additional necessary information to be contained in this Appendix.

Data exporter
The data exporter is:

Data importer
The data importer is:

Apptoto

Data subjects
The personal data transferred concern the following categories of data subjects:

   •   Prospective clients, clients, business partners, and vendors of Customer (who are natural
       persons);

   •   Employees, agents, family members, and contact persons of Customer’s prospective
       clients, clients, business partners, and vendors;

   •   Employees, agents, advisors, and freelancers of Customer (who are natural persons); or

   •   Users authorized by Customer to use Apptoto Services.

Categories of data
The personal data transferred concern the following categories of data:

   •   First, middle, and last name and nicknames;

   •   Title;

   •   Email address;

   •   Phone number;

   •   Other contact information;

   •   Appointment information (event title, location, notes, time);

Page !21.        END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                   16934-001\1305393_3
   •   IP address; or

   •   Personal life data (including additional notes added by user).

Special categories of data (if appropriate)
The personal data transferred concern the following special categories of data:

   •   Health data.

Processing operations
The personal data transferred will be subject to the following basic processing activities:
Processing of Appointment Data in order to send automated messages before, during, and after
appointments. Also processing of Appointment Data to facilitate scheduling of new
appointments.

DATA EXPORTER
Name:
Authorised Signature _____________________________

DATA IMPORTER
Name:
Authorised Signature _____________________________

Page !22.      END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                  16934-001\1305393_3
             APPENDIX 2 TO THE STANDARD CONTRACTUAL CLAUSES
   This Appendix forms part of the Clauses and must be completed and signed by the parties.

Description of the technical and organisational security measures implemented by the data
importer in accordance with Clauses 4(d) and 5(c):

   1. Access

            a. Access to private information about data subjects is limited to employees of
               Apptoto. Those employees include support and operations personnel.

            b. Support personnel may see the information but only to provide support requested
               by Customer. All access is logged and monitored. Our CEO and Chief Privacy
               Officer is notified every time support personnel access Customer Personal Data.
               Two-factor authentication is required for use by support personnel.

            c. Operations personnel have access to the infrastructure used to run Apptoto
               (including servers and databases). Operations personnel may see the information
               within a Customer’s account through server consoles, but only while performing
               operations required to support Apptoto’s processing.

            d. All support and operations personnel undergo extensive background checks
               before being hired.

   2.   Encryption

            a. All data is strongly encrypted (minimum key length is 256 bits) in transit
               between:

                    i. Customer and Apptoto (through website portal and API)

                    ii. Apptoto and Subprocessors (through API)

            b. All data is strongly encrypted at rest on disk.

   3.   Security (System, Physical, Environmental)

            a. All servers under control of Apptoto run virus detection software.

            b. All workstations under control of Apptoto run virus detection software.

            c. All personnel are required to leverage password managers and 2FA when
               available.

Page !23.      END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                    16934-001\1305393_3
            d. All servers and databases are only accessible to operations personnel through
               VPN and Bastion gateways.

   4.   Periodic Assessments

            a. Periodic virus detection software assessment

            b. Periodic assessment of Acceptable Use Policy by personnel (see https://
               www.apptoto.com/downloads/security_policies/
               apptoto_acceptable_use_policy.pdf)

            c. Monthly web application security assessments through

                    i. OWASP ZAP

                    ii. Tinfoil Security Scanner

   5.   Incident Response

            a. https://www.apptoto.com/downloads/security_policies/
               apptoto_data_breach_response.pdf

Page !24.      END USER AGREEMENT – DATA PROCESSING ADDENDUM
                                                                                  16934-001\1305393_3