Snapshot 69301
Normalized text
Scripts and page chrome removed; this is what change detection compares.
APPTOTO DATA PROCESSING ADDENDUM
This Apptoto Data Processing Addendum (this “Addendum”) constitutes a binding agreement
by and between Go-Cort, Inc., an Oregon corporation dba Apptoto (“Apptoto”) and you, the
customer (“Customer”). This Addendum is incorporated into and made part of the Apptoto End
User License Agreement (the “EULA”) previously or contemporaneously entered into by
Customer and governs the processing of personal data that Customer uploads or otherwise
provides to Apptoto. If you are entering into this Agreement on behalf of an entity or
organization, you are representing and warranting that you have the authority to bind the
Customer and you are agreeing to these terms on behalf of yourself and the Customer.
Collectively, this Addendum and the EULA are referred to in this Addendum as the “Apptoto
Agreement.” In the event of any conflict or inconsistency between any of the terms of this
Addendum and the terms of the EULA, the terms of this Addendum will prevail as it relates to
the subject matter herein. Except as specifically amended by this Addendum, the EULA and any
other applicable agreements between Customer and Apptoto remain unchanged and in full force
and effect.
1. DEFINITIONS
“Apptoto Services” means any services or Software (as defined in the EULA) that Apptoto
provides to Customer in connection with the Apptoto Agreement.
“Controller” means the natural or legal person, public authority, agency, or other body, which,
alone or jointly with others, determines the purposes and means of the processing of Customer
Personal Data.
“Customer Personal Data” means Personal Data that Customer uploads, integrates, or
otherwise provides to Apptoto in connection with Apptoto Services.
“General Data Protection Regulation” or “GDPR” means the European Union Regulation on
the protection of individuals with regard to the processing of personal data and on the free
movement of such data, repealing Directive 95/46/EC, and includes any applicable subsequent
legislation and regulations implementing the GDPR.
“Personal Data” means any information relating to an identified or identifiable natural person
(“Data Subject”); an identifiable natural person is one who can be identified, directly or
indirectly, in particular by reference to an identifier such as name, an identification number,
location data, an online identifier or to one or more factors specific to the physical, physiological,
genetic, mental, economic, cultural, or social identity of that natural person.
Page !1. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
“Personal Data Breach” means a breach of security leading to the accidental or unlawful
destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data
transmitted, stored, or otherwise processed.
“Processing” means any operation or set of operations which is performed on Personal Data or
on sets of Personal Data, whether or not by automated means, such as collection, recording,
organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure
by transmission, dissemination or otherwise making available, alignment or combination,
restriction, erasure, or destruction.
“Processor” means a natural or legal person, public authority, agency, or other body, which
processes Customer Personal Data on behalf of the Controller.
“Subprocessor” means any entity that provides processing services to Apptoto in furtherance of
Apptoto’s processing on behalf of Customer.
“Supervisory Authority” means an independent public authority established by a European
Union member state pursuant to Article 51 of the General Data Protection Regulation.
2. DATA PROCESSING
2.1. Roles of the Parties. Customer is the Controller and Apptoto is the Processor of
Customer Personal Data. Customer appoints Apptoto as Processor to process Customer
Personal Data and to engage Subprocessors in accordance with this Addendum.
2.2. Scope of Processing. Apptoto will process Customer Personal Data as necessary
to provide Apptoto Services, and as further instructed by Customer in writing in
connection with the Apptoto Agreement.
(a) Duration of Processing. Subject to Section 7 of this Addendum, Apptoto
will process Customer Personal Data for the duration of the Apptoto Agreement, unless
otherwise agreed in writing.
(b) Categories of Data Subjects. Customer may submit Personal Data to
Apptoto, the extent of which is determined and controlled by Customer in its sole
discretion, and which may include, but is not limited to Personal Data relating to the
following categories of Data Subjects:
(i) Prospective clients, clients, business partners, and vendors of
Customer (who are natural persons);
(ii) Employees, agents, family members, and contact persons of
Customer’s prospective clients, clients, business partners, and vendors;
Page !2. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
(iii) Employees, agents, advisors, and freelancers of Customer (who are
natural persons); or
(iv) Users authorized by Customer to use Apptoto Services.
(c) Categories of Customer Personal Data. Customer may submit Personal
Data to Apptoto, the extent of which is determined and controlled by Customer in its sole
discretion, and which may include, but is not limited to the following categories of
Personal Data:
(i) First, middle, and last name and nicknames;
(ii) Title;
(iii) Email address;
(iv) Phone number;
(v) Other contact information;
(vi) Appointment information (event title, location, notes, time);
(vii) IP address; or
(viii) Personal life data (including additional notes added by user).
(d) Compliance with Law. Customer is solely responsible for the lawfulness
of the Processing of Customer Personal Data and the lawfulness of the means by which
Customer acquires Customer Personal Data, including, without limitation, the scope and
adequacy of consent from Data Subjects. Customer agrees that its use of Apptoto
Services for the Processing of Customer Personal Data will comply with applicable law,
including, without limitation, the GDPR.
2.3. Compliance with Customer Instructions. Apptoto will process Customer
Personal Data on behalf of Customer and in accordance with Customer’s instructions for
the purposes described in the Apptoto Agreement and for the purposes of and as initiated
by Customer’s users of the Apptoto Services. If Apptoto believes that an instruction from
Customer violates applicable law, including, without limitation, the GDPR, Apptoto will
notify Customer without undue delay and may suspend performance until Customer has
modified or confirmed the lawfulness of the instruction in writing.
Page !3. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
2.4. Other Controllers. Customer will serve as a single point of contact for Apptoto
with respect to Customer Personal Data. To the extent that other Controllers may have
any rights as joint Controllers with Customer with respect to Customer Personal Data,
Customer agrees to exercise all such rights on their behalf and to obtain all necessary
approvals and consents from the other Controllers. Apptoto will have no obligation to
inform or notify such other Controllers when Apptoto has provided such information or
notice to Customer.
3. SECURITY MEASURES AND BREACH RESPONSE
3.1. Security Measures. Apptoto will implement and maintain technical and
organizational measures as set forth in Exhibit 1 (“Security Measures”) to ensure a level
of security appropriate to the risk for Apptoto’s scope of responsibility. These measures
are subject to technical progress and further development. Apptoto reserves the right to
modify these measures from time to time, so long as the functionality and security of
Apptoto Services materially comply with applicable law.
3.2. Notice to Customer of Personal Data Breach. Apptoto will notify Customer
without undue delay after becoming aware of a Personal Data Breach with respect to
Apptoto Services.
3.3. Assistance to Customer. Apptoto will reasonably assist Customer, at Customer’s
expense, in ensuring compliance with Customer’s obligations relating to the security of
Processing, the notification of a Personal Data Breach, and the conduct of a data
protection impact assessment, taking into account the information available to Apptoto.
3.4. Personal Data Breach Response. Apptoto will promptly investigate a Personal
Data Breach if it occurred on Apptoto infrastructure or in another area for which Apptoto
is responsible. Apptoto will make reasonable efforts to identify the cause of such Personal
Data Breach and take those steps as Apptoto deems necessary and reasonable in order to
remediate the cause of such a Personal Data Breach to the extent the remediation is
within Apptoto’s reasonable control. The obligations in this Section 3.4 will not apply to
incidents that are caused by Customer or Customer’s users.
4. DATA SUBJECT RIGHTS AND REQUESTS.
4.1. Data Subject Requests. Apptoto will, to the extent legally permitted, promptly
notify Customer if Apptoto receives a request from a Data Subject to exercise the Data
Subject’s right of access, right to rectification, restriction of Processing, erasure (“right to
be forgotten”), data portability, object to the Processing, or its right not to be subject to
automated individual decision making (“Data Subject Request”). Customer is solely
responsible for responding to a Data Subject Request. To the extent practicable by
appropriate technical and organizational measures, and to the extent Apptoto is
Page !4. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
legally permitted to do so, Apptoto will use commercially reasonable efforts to assist
Customer, at Customer’s expense, in complying with Customer’s obligation to
respond to a Data Subject Request in accordance with applicable law, including,
without limitation, the GDPR.
5. THIRD PARTY REQUESTS; CONFIDENTIALITY
5.1. No Unauthorized Disclosure. Except in accordance with the Apptoto Agreement
and as permitted by applicable law, Apptoto will not disclose Customer Personal Data to
any third party. If a Supervisory Authority demands access to Customer Personal Data,
Apptoto will notify Customer prior to disclosure, unless prohibited by applicable law, in
which case no prior notice is required.
5.2. Restrictions on Use. Apptoto shall treat all Customer Personal Data as
confidential and shall process Customer Personal Data in accordance with the Apptoto
Agreement and for no other purpose unless required by applicable law.
6. AUDIT
6.1. Cooperation. Apptoto will allow for and contribute to audits, including
inspections, conducted by Customer or another auditor designated by Customer of
Apptoto’s Processing of Customer Personal Data, subject to the following procedures:
(a) On Customer’s written request, Apptoto will provide Customer or its
designated auditor with the most recent certifications and/or summary audit report(s),
which Apptoto has procured to regularly test, assess, and evaluate the effectiveness of its
Security Measures.
(b) Apptoto will reasonably cooperate with Customer by providing available
additional information concerning its Security Measures, to help Customer better
understand such Security Measures.
(c) If Customer needs further information to comply with its own or another
Controller’s audit obligations or a competent Supervisory Authority’s request, Customer
will inform Apptoto in writing to enable Apptoto to provide such information or to grant
Customer access to it.
(d) To the extent it is not possible to otherwise satisfy an audit obligation
mandated by applicable law, only legally mandated entities (such as a governmental
regulatory agency having oversight of Customer’s operations), Customer, or its
designated auditor may conduct an onsite visit of the facilities used to perform Processing
pursuant to the Apptoto Agreement, during normal business hours and only in a manner
that causes minimal disruption to Apptoto’s business, subject to coordinating the timing
Page !5. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
of such visit and in accordance with any audit procedures reasonably necessary in order
to reduce any risk to Apptoto’s other customers.
6.2. Costs. Each party will bear its own costs of performing its obligations under
Sections 6.1(a) and 6.1(b). Any further assistance with be at Customer’s sole expense
unless otherwise agreed to in writing by Apptoto.
7. RETURN OR DELETION OF CUSTOMER PERSONAL DATA
7.1. Deletion On Termination. On expiration or earlier termination of the Agreement,
Apptoto will either delete or return Customer Personal Data in its possession or control,
unless otherwise required or permitted by applicable law.
8. SUBPROCESSORS
8.1. Subprocessing Permitted. Customer authorizes Apptoto to engage
subcontractors to process Customer Personal Data. A list of current Subprocessors is set
out in attached Exhibit 2. Apptoto will give Customer not less than 10 days’ advance
written notice of any changes to Appptoto’s Subprocessors. Within ten (10) days after
Apptoto’s notification of the intended change, Customer can object to the addition of a
Subprocessor on the basis that such addition would cause Customer to violate applicable
law. Customer’s objection will be in writing and include Customer’s specific reasons for
its objection, including the applicable legal requirements, and options to mitigate, if any.
If Customer does not object within such period, the respective Subprocessor may be
authorized to process Customer Personal Data. Apptoto will impose substantially similar
data protection obligations as set out in this Addendum on any approved Subprocessor
prior to the Subprocessor Processing any Customer Personal Data.
8.2. Notice of Objection. If Customer legitimately objects to the addition of a
Subprocessor and Apptoto cannot reasonably accommodate Customer’s objection,
Apptoto will notify Customer. Customer may terminate the Apptoto Agreement with
respect only to those Apptoto Services that cannot be provided by Apptoto without the
use of the objectionable Subprocessor by providing Apptoto with a written notice within
thirty (30) days of Apptoto’s notice. Apptoto will refund a prorated portion of any prepaid
charges for the period after such termination date, without penalty for such termination.
9. TRANSBORDER DATA PROCESSING
9.1. Standard Contractual Clauses. By agreeing to this Addendum, Customer is
entering into the EU Standard Contractual Clauses as referred to in attached Exhibit 3,
with the Subprocessors established outside either the European Economic Area or
countries considered by the European Commission to have adequate protection (“Data
Importers”).
Page !6. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
9.2. Other Controllers. Customer agrees on behalf of any other Controller of
Customer Personal Data, or if unable to agree, will procure agreement of such Controller,
to be an additional data exporter with respect to the EU Standard Contractual Clauses
concluded between Apptoto and Customer. Apptoto accepts the agreement of such other
Controller. Customer agrees and, if applicable, procures the agreement of any other
Controller that the EU Standard Contractual Clauses, including any claims arising from
them, are subject to the terms set forth in the Apptoto Agreement, including, without
limitation, the exclusions and limitations of liability. In case of conflict, the EU Standard
Contractual Clauses will prevail.
10. INDEMNITY; LIMITATION OF LIABILITY
10.1. Indemnity. In addition to and not in lieu of existing indemnification obligations
in the EULA, Customer agrees to indemnify, defend, and hold Apptoto harmless for,
from, and against, any and all costs, charges, damages, expenses (including attorney’s
fees), and losses arising from or related to Customer’s breach of this Addendum,
including, without limitation, non-compliance with the GDPR.
10.2. Limitation of Liability. Each party’s liability arising out of or related to this
Addendum, whether in contract, tort, or under any other theory of liability, is subject to
any and all limitations of liability in the EULA.
APPTOTO CUSTOMER
By: By:
Name Name
: :
Title: Title:
Page !7. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
Page !8. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
EXHIBIT 1
SECURITY MEASURES
1. Access
a. Access to private information about data subjects is limited to employees of
Apptoto. Those employees include support and operations personnel.
b. Support personnel may see the information but only to provide support requested
by Customer. All access is logged and monitored. Our CEO and Chief Privacy
Officer is notified every time support personnel access Customer Personal Data.
Two-factor authentication is required for use by support personnel.
c. Operations personnel have access to the infrastructure used to run Apptoto
(including servers and databases). Operations personnel may see the information
within a Customer’s account through server consoles, but only while performing
operations required to support Apptoto’s processing.
d. All support and operations personnel undergo extensive background checks
before being hired.
2. Encryption
a. All data is strongly encrypted (minimum key length is 256 bits) in transit
between:
i. Customer and Apptoto (through website portal and API)
ii. Apptoto and Subprocessors (through API)
b. All data is strongly encrypted at rest on disk.
3. Security (System, Physical, Environmental)
a. All servers under control of Apptoto run virus detection software.
b. All workstations under control of Apptoto run virus detection software.
c. All personnel are required to leverage password managers and 2FA when
available.
d. All servers and databases are only accessible to operations personnel through
VPN and Bastion gateways.
Page !9. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
4. Periodic Assessments
a. Periodic virus detection software assessment
b. Periodic assessment of Acceptable Use Policy by personnel (see https://
www.apptoto.com/downloads/security_policies/
apptoto_acceptable_use_policy.pdf)
c. Monthly web application security assessments through
i. OWASP ZAP
ii. Tinfoil Security Scanner
5. Incident Response
a. https://www.apptoto.com/downloads/security_policies/
apptoto_data_breach_response.pdf
Page !10. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
EXHIBIT 2
SUBPROCESSORS
● Amazon Web Services
● Armor.com (for Healthcare clients)
● Twilio
● Sendgrid
● Mailgun
● Clicksend
Page !11. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
EXHIBIT 3
STANDARD CONTRACTUAL CLAUSES (PROCESSORS)
For the purposes of Article 26(2) of Directive 95/46/EC for the transfer of personal data to
processors established in third countries which do not ensure an adequate level of data protection
Name of the data exporting organisation:
Address:
Tel.: _______________; fax: _______________; e-mail: _______________
Other information needed to identify the organization:
(the data exporter)
And
Name of the data importing organisation: Apptoto
Address: 61149 South Highway 97 #505, Bend, OR 97701
Tel.: _888-318-3765__; e-mail: ___support@apptoto.com_______
Other information needed to identify the organisation:
(the data importer)
each a ‘party’; together ‘the parties’,
HAVE AGREED on the following Contractual Clauses (the Clauses) in order to adduce adequate
safeguards with respect to the protection of privacy and fundamental rights and freedoms of
individuals for the transfer by the data exporter to the data importer of the personal data specified
in Appendix 1.
Clause 1
Definitions
For the purposes of the Clauses:
(a ‘personal data’, ‘special categories of data’, ‘process/processing’, ‘controller’, ‘processor’,
) ‘data subject’ and ‘supervisory authority’ shall have the same meaning as in Directive 95/46/
EC of the European Parliament and of the Council of 24 October 1995 on the protection of
individuals with regard to the processing of personal data and on the free movement of such
data;
(b ‘the data exporter’ means the controller who transfers the personal data;
)
Page !12. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
(c ‘the data importer’ means the processor who agrees to receive from the data exporter
) personal data intended for processing on his behalf after the transfer in accordance with his
instructions and the terms of the Clauses and who is not subject to a third country’s system
ensuring adequate protection within the meaning of Article 25(1) of Directive 95/46/EC;
(d ‘the sub-processor’ means any processor engaged by the data importer or by any other sub-
) processor of the data importer who agrees to receive from the data importer or from any
other sub-processor of the data importer personal data exclusively intended for processing
activities to be carried out on behalf of the data exporter after the transfer in accordance with
his instructions, the terms of the Clauses and the terms of the written subcontract;
(e ‘the applicable data protection law’ means the legislation protecting the fundamental rights
) and freedoms of individuals and, in particular, their right to privacy with respect to the
processing of personal data applicable to a data controller in the Member State in which the
data exporter is established;
( f ‘technical and organisational security measures’ means those measures aimed at protecting
) personal data against accidental or unlawful destruction or accidental loss, alteration,
unauthorised disclosure or access, in particular where the processing involves the
transmission of data over a network, and against all other unlawful forms of processing.
Clause 2
Details of the transfer
The details of the transfer and in particular the special categories of personal data where
applicable are specified in Appendix 1 which forms an integral part of the Clauses.
Clause 3
Third-party beneficiary clause
1. The data subject can enforce against the data exporter this Clause, Clause 4(b) to (i), Clause
5(a) to (e), and (g) to (j), Clause 6(1) and (2), Clause 7, Clause 8(2), and Clauses 9 to 12 as
third-party beneficiary.
2. The data subject can enforce against the data importer this Clause, Clause 5(a) to (e) and (g),
Clause 6, Clause 7, Clause 8(2), and Clauses 9 to 12, in cases where the data exporter has
factually disappeared or has ceased to exist in law unless any successor entity has assumed
the!13
Page entire
. legal
END obligations of the data exporter
USER AGREEMENT – DATAby contract or by operation
PROCESSING ADDENDUMof law, as a result
16934-001\1305393_3
3. The data subject can enforce against the sub-processor this Clause, Clause 5(a) to (e) and (g),
Clause 6, Clause 7, Clause 8(2), and Clauses 9 to 12, in cases where both the data exporter
and the data importer have factually disappeared or ceased to exist in law or have become
insolvent, unless any successor entity has assumed the entire legal obligations of the data
exporter by contract or by operation of law as a result of which it takes on the rights and
obligations of the data exporter, in which case the data subject can enforce them against such
entity. Such third-party liability of the sub-processor shall be limited to its own processing
operations under the Clauses.
4. The parties do not object to a data subject being represented by an association or other body
if the data subject so expressly wishes and if permitted by national law.
Clause 4
Obligations of the data exporter
The data exporter agrees and warrants:
(a that the processing, including the transfer itself, of the personal data has been and will
) continue to be carried out in accordance with the relevant provisions of the applicable data
protection law (and, where applicable, has been notified to the relevant authorities of the
Member State where the data exporter is established) and does not violate the relevant
provisions of that State;
(b that it has instructed and throughout the duration of the personal data-processing services
) will instruct the data importer to process the personal data transferred only on the data
exporter’s behalf and in accordance with the applicable data protection law and the Clauses;
(c that the data importer will provide sufficient guarantees in respect of the technical and
) organisational security measures specified in Appendix 2 to this contract;
(d that after assessment of the requirements of the applicable data protection law, the security
) measures are appropriate to protect personal data against accidental or unlawful destruction
or accidental loss, alteration, unauthorised disclosure or access, in particular where the
processing involves the transmission of data over a network, and against all other unlawful
forms of processing, and that these measures ensure a level of security appropriate to the
risks presented by the processing and the nature of the data to be protected having regard to
the state of the art and the cost of their implementation;
(e) that
Page !14. it willEND
ensure compliance
USER with the security
AGREEMENT – DATAmeasures;
PROCESSING ADDENDUM
16934-001\1305393_3
( f that, if the transfer involves special categories of data, the data subject has been informed or
) will be informed before, or as soon as possible after, the transfer that its data could be
transmitted to a third country not providing adequate protection within the meaning of
Directive 95/46/EC;
(g to forward any notification received from the data importer or any sub-processor pursuant to
) Clause 5(b) and Clause 8(3) to the data protection supervisory authority if the data exporter
decides to continue the transfer or to lift the suspension;
(h to make available to the data subjects On request a copy of the Clauses, with the exception
) of Appendix 2, and a summary description of the security measures, as well as a copy of any
contract for sub-processing services which has to be made in accordance with the Clauses,
unless the Clauses or the contract contain commercial information, in which case it may
remove such commercial information;
( i that, in the event of sub-processing, the processing activity is carried out in accordance with
) Clause 11 by a sub-processor providing at least the same level of protection for the personal
data and the rights of data subject as the data importer under the Clauses; and
(j) that it will ensure compliance with Clause 4(a) to (i).
Clause 5
Obligations of the data importer
The data importer agrees and warrants:
(a to process the personal data only on behalf of the data exporter and in compliance with its
) instructions and the Clauses; if it cannot provide such compliance for whatever reasons, it
agrees to inform promptly the data exporter of its inability to comply, in which case the data
exporter is entitled to suspend the transfer of data and/or terminate the contract;
(b that it has no reason to believe that the legislation applicable to it prevents it from fulfilling
) the instructions received from the data exporter and its obligations under the contract and
that in the event of a change in this legislation which is likely to have a substantial adverse
effect on the warranties and obligations provided by the Clauses, it will promptly notify the
change to the data exporter as soon as it is aware, in which case the data exporter is entitled
to suspend the transfer of data and/or terminate the contract;
Page !15. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
(c that it has implemented the technical and organisational security measures specified in
) Appendix 2 before processing the personal data transferred;
(d that it will promptly notify the data exporter about:
) (i) any legally binding request for disclosure of the personal data by a law enforcement
authority unless otherwise prohibited, such as a prohibition under criminal law to preserve
the confidentiality of a law enforcement investigation;
(ii) any accidental or unauthorised access; and
(iii) any request received directly from the data subjects without responding to that
request, unless it has been otherwise authorised to do so;
(e to deal promptly and properly with all inquiries from the data exporter relating to its
) processing of the personal data subject to the transfer and to abide by the advice of the
supervisory authority with regard to the processing of the data transferred;
( f at the request of the data exporter to submit its data-processing facilities for audit of the
) processing activities covered by the Clauses which shall be carried out by the data exporter
or an inspection body composed of independent members and in possession of the required
professional qualifications bound by a duty of confidentiality, selected by the data exporter,
where applicable, in agreement with the supervisory authority;
(g to make available to the data subject On request a copy of the Clauses, or any existing
) contract for sub-processing, unless the Clauses or contract contain commercial information,
in which case it may remove such commercial information, with the exception of Appendix
2 which shall be replaced by a summary description of the security measures in those cases
where the data subject is unable to obtain a copy from the data exporter;
(h that, in the event of sub-processing, it has previously informed the data exporter and
) obtained its prior written consent;
( i that the processing services by the sub-processor will be carried out in accordance with
) Clause 11;
Page !16. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
( j to send promptly a copy of any sub-processor agreement it concludes under the Clauses to
) the data exporter.
Clause 6
Liability
1. The parties agree that any data subject, who has suffered damage as a result of any breach of
the obligations referred to in Clause 3 or in Clause 11 by any party or sub-processor is
entitled to receive compensation from the data exporter for the damage suffered.
2. If a data subject is not able to bring a claim for compensation in accordance with paragraph 1
against the data exporter, arising out of a breach by the data importer or his sub-processor of
any of their obligations referred to in Clause 3 or in Clause 11, because the data exporter has
factually disappeared or ceased to exist in law or has become insolvent, the data importer
agrees that the data subject may issue a claim against the data importer as if it were the data
exporter, unless any successor entity has assumed the entire legal obligations of the data
exporter by contract of by operation of law, in which case the data subject can enforce its
rights against such entity.
The data importer may not rely on a breach by a sub-processor of its obligations in order to
avoid its own liabilities.
3. If a data subject is not able to bring a claim against the data exporter or the data importer
referred to in paragraphs 1 and 2, arising out of a breach by the sub-processor of any of their
obligations referred to in Clause 3 or in Clause 11 because both the data exporter and the data
importer have factually disappeared or ceased to exist in law or have become insolvent, the
sub-processor agrees that the data subject may issue a claim against the data sub-processor
with regard to its own processing operations under the Clauses as if it were the data exporter
or the data importer, unless any successor entity has assumed the entire legal obligations of
the data exporter or data importer by contract or by operation of law, in which case the data
subject can enforce its rights against such entity. The liability of the sub-processor shall be
limited to its own processing operations under the Clauses.
Clause 7
Mediation and jurisdiction
1. The data importer agrees that if the data subject invokes against it third-party beneficiary
rights and/or claims compensation for damages under the Clauses, the data importer will
Page !17. the decision
accept END USERof the AGREEMENT
data subject: – DATA PROCESSING ADDENDUM
16934-001\1305393_3
2. The parties agree that the choice made by the data subject will not prejudice its substantive or
procedural rights to seek remedies in accordance with other provisions of national or
international law.
Clause 8
Cooperation with supervisory authorities
1. The data exporter agrees to deposit a copy of this contract with the supervisory authority if it
so requests or if such deposit is required under the applicable data protection law.
2. The parties agree that the supervisory authority has the right to conduct an audit of the data
importer, and of any sub-processor, which has the same scope and is subject to the same
conditions as would apply to an audit of the data exporter under the applicable data protection
law.
3. The data importer shall promptly inform the data exporter about the existence of legislation
applicable to it or any sub-processor preventing the conduct of an audit of the data importer,
or any sub-processor, pursuant to paragraph 2. In such a case the data exporter shall be
entitled to take the measures foreseen in Clause 5(b).
Clause 9
Governing law
The Clauses shall be governed by the law of the Member State in which the data exporter is
established.
Clause 10
Variation of the contract
The parties undertake not to vary or modify the Clauses. This does not preclude the parties from
adding clauses on business related issues where required as long as they do not contradict the
Clause.
Clause 11
Sub-processing
1. The data importer shall not subcontract any of its processing operations performed on behalf
of the
Page !18. data exporter
END USERunderAGREEMENT
the Clauses without the PROCESSING
– DATA prior written consent of the data exporter.
ADDENDUM
16934-001\1305393_3
2. The prior written contract between the data importer and the sub-processor shall also provide
for a third-party beneficiary clause as laid down in Clause 3 for cases where the data subject
is not able to bring the claim for compensation referred to in paragraph 1 of Clause 6 against
the data exporter or the data importer because they have factually disappeared or have ceased
to exist in law or have become insolvent and no successor entity has assumed the entire legal
obligations of the data exporter or data importer by contract or by operation of law. Such
third-party liability of the sub-processor shall be limited to its own processing operations
under the Clauses.
3. The provisions relating to data protection aspects for sub-processing of the contract referred
to in paragraph 1 shall be governed by the law of the Member State in which the data
exporter is established, namely …
4. The data exporter shall keep a list of sub-processing agreements concluded under the Clauses
and notified by the data importer pursuant to Clause 5(j), which shall be updated at least once
a year. The list shall be available to the data exporter’s data protection supervisory authority.
Clause 12
Obligation after the termination of personal data-processing services
1. The parties agree that on the termination of the provision of data-processing services, the data
importer and the sub-processor shall, at the choice of the data exporter, return all the personal
data transferred and the copies thereof to the data exporter or shall destroy all the personal
data and certify to the data exporter that it has done so, unless legislation imposed On the
data importer prevents it from returning or destroying all or part of the personal data
transferred. In that case, the data importer warrants that it will guarantee the confidentiality of
the personal data transferred and will not actively process the personal data transferred
anymore.
2. The data importer and the sub-processor warrant that On request of the data exporter and/or
of the supervisory authority, it will submit its data-processing facilities for an audit of the
measures referred to in paragraph 1.
Page !19. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
On behalf of the data exporter:
Name (written out in full):
Position:
Address:
Other information necessary in order for the contract to be binding (if any):
Signature_____________________________
On behalf of the data importer:
Name (written out in full): Frank Cort
Position: President
Address: 61149 South Highway 97 #505, Bend, OR 97701
Other information necessary in order for the contract to be binding (if any):
Signature_____________________________
Page !20. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
APPENDIX 1 TO THE STANDARD CONTRACTUAL CLAUSES
This Appendix forms part of the Clauses and must be completed and signed by the parties.
The Member States may complete or specify, according to their national procedures, any
additional necessary information to be contained in this Appendix.
Data exporter
The data exporter is:
Data importer
The data importer is:
Apptoto
Data subjects
The personal data transferred concern the following categories of data subjects:
• Prospective clients, clients, business partners, and vendors of Customer (who are natural
persons);
• Employees, agents, family members, and contact persons of Customer’s prospective
clients, clients, business partners, and vendors;
• Employees, agents, advisors, and freelancers of Customer (who are natural persons); or
• Users authorized by Customer to use Apptoto Services.
Categories of data
The personal data transferred concern the following categories of data:
• First, middle, and last name and nicknames;
• Title;
• Email address;
• Phone number;
• Other contact information;
• Appointment information (event title, location, notes, time);
Page !21. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
• IP address; or
• Personal life data (including additional notes added by user).
Special categories of data (if appropriate)
The personal data transferred concern the following special categories of data:
• Health data.
Processing operations
The personal data transferred will be subject to the following basic processing activities:
Processing of Appointment Data in order to send automated messages before, during, and after
appointments. Also processing of Appointment Data to facilitate scheduling of new
appointments.
DATA EXPORTER
Name:
Authorised Signature _____________________________
DATA IMPORTER
Name:
Authorised Signature _____________________________
Page !22. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
APPENDIX 2 TO THE STANDARD CONTRACTUAL CLAUSES
This Appendix forms part of the Clauses and must be completed and signed by the parties.
Description of the technical and organisational security measures implemented by the data
importer in accordance with Clauses 4(d) and 5(c):
1. Access
a. Access to private information about data subjects is limited to employees of
Apptoto. Those employees include support and operations personnel.
b. Support personnel may see the information but only to provide support requested
by Customer. All access is logged and monitored. Our CEO and Chief Privacy
Officer is notified every time support personnel access Customer Personal Data.
Two-factor authentication is required for use by support personnel.
c. Operations personnel have access to the infrastructure used to run Apptoto
(including servers and databases). Operations personnel may see the information
within a Customer’s account through server consoles, but only while performing
operations required to support Apptoto’s processing.
d. All support and operations personnel undergo extensive background checks
before being hired.
2. Encryption
a. All data is strongly encrypted (minimum key length is 256 bits) in transit
between:
i. Customer and Apptoto (through website portal and API)
ii. Apptoto and Subprocessors (through API)
b. All data is strongly encrypted at rest on disk.
3. Security (System, Physical, Environmental)
a. All servers under control of Apptoto run virus detection software.
b. All workstations under control of Apptoto run virus detection software.
c. All personnel are required to leverage password managers and 2FA when
available.
Page !23. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3
d. All servers and databases are only accessible to operations personnel through
VPN and Bastion gateways.
4. Periodic Assessments
a. Periodic virus detection software assessment
b. Periodic assessment of Acceptable Use Policy by personnel (see https://
www.apptoto.com/downloads/security_policies/
apptoto_acceptable_use_policy.pdf)
c. Monthly web application security assessments through
i. OWASP ZAP
ii. Tinfoil Security Scanner
5. Incident Response
a. https://www.apptoto.com/downloads/security_policies/
apptoto_data_breach_response.pdf
Page !24. END USER AGREEMENT – DATA PROCESSING ADDENDUM
16934-001\1305393_3