Third Party Index

Snapshot 78710

Document
Data processing addendum
URL
https://itextpdf.com/sites/default/files/2023-02/Apryse_Data_Processing_Agreement.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
144917 bytes
SHA-256 (raw)
f02da02e8e8847ab3956e23ec076a6416f87b694392bb2d9034ed86c9eb2f81d
SHA-256 (normalized text)
722f9af1d2c1d0fcc1bb3020abc165218485c9bc3d958ff5f5478c39c38169e3

Normalized text

Scripts and page chrome removed; this is what change detection compares.

DATA PROCESSING AGREEMENT

(APRYSE ACTING AS PROCESSOR)

1.     Scope

1.1    This Data Processing Agreement (within the meaning of Article 28.3 GDPR) (“DPA”) forms part
       of the agreement(s) for the purchase, use and/or licensing of products or services of Apryse
       (“Services”), together with its exhibits, statements of works or other incorporated or referenced
       documents and any other agreement(s) governed by such agreement(s) (“Agreement”) between
       Apryse and Customer.

1.2    In the course of providing the Services to Customer under the Agreement, Apryse may Process
       Personal Data on behalf of the Customer in which case parties agree to comply with the provisions
       of this DPA. The provisions of this DPA shall only apply to the extent that (and as the case may
       be) Apryse (as the Processor) Processes Personal Data on behalf of the Customer (as the
       Controller) under the Agreement.

1.3    In case of conflict between any provision of this DPA and any provision or another part of the
       Agreement, this DPA shall prevail.

1.4    If at any time any provision of this DPA is or becomes illegal, invalid or unenforceable in any
       respect under any law of any jurisdiction, in whole or in part neither the legality, validity or
       enforceability of the remaining provisions of this DPA nor the legality, validity or enforceability of
       such provisions under the laws of any other jurisdiction will in any way be affected or impaired.
       Parties shall make all reasonable efforts and take all necessary actions to replace any illegal,
       invalid or unenforceable provision of this DPA with a valid, legal and enforceable provision having
       the same economic and legal effect for parties and reflecting to the fullest extent permitted by law
       the provision to be replaced.

1.5    The DPA is entered into for the term of the Agreement and remains in full force until the
       Processing of Personal Data is no longer required in the framework or pursuant to the Agreement
       or longer, if required by law or Data Protection Legislation.

1.6    If the Customer has any questions regarding the Processing of Personal Data by Apryse,
       Customer may send such questions to privacy@apryse.com.

2.     Definitions

2.1.   For the purpose of this DPA, the following terms shall have the following meaning. In case of any
       doubt or differences with the terms defined in the Data Protection Legislation, the definitions
       stipulated in the relevant Data Protection Legislation shall prevail.

                                                                                                           1
“Controller” means the natural or legal person, public authority, agency or any other body which,
alone or jointly with others, determines the purposes and means of the Processing of Personal
Data carried out under its authority, for the purposes of the Consultancy Agreement and the DPA,
being the Customer.

“Data Protection Legislation” means the GDPR together with any other (data protection) laws
resulting from the GDPR and/or all other applicable laws of any country with regard to the
protection of Personal Data or privacy.

“Data Subject” means an identified or identifiable natural person to whom the Personal Data
relates. An identifiable person is one who can be identified, directly or indirectly, in particular by
reference to an identifier such as a name, an identification number, location data, online identifier
or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural
or social identity of that person. The relevant categories of Data Subjects are identified in this
DPA.

“GDPR” means the Regulation 2016/679 of the European Parliament and of the Council of 27
April 2016 on the protection of natural persons with regard to the processing of personal data and
on the free movement of such data.

“Apryse”: Apryse Group NV, with registered office at Kerkstraat 108, 9050 Gentbrugge (Belgium),
with company registration number 0895.263.973.

“Personal Data” means any information relating to a Data Subject within the meaning of Article 4,
1) GDPR. The relevant categories of Personal Data that are provided to Apryse by, or on behalf
of, the Customer, are identified in this DPA.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful
destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted,
stored or otherwise Processed in connection with the Agreement and the provision of the
Services.

“Processing”, “Process(es)” or “Processed” means any operation or set of operation which is
performed upon Personal Data or on sets of Personal Data, whether or not by automatic means,
such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval,
consultation, use, disclosure by transmission, dissemination or otherwise making available,
alignment or combination, restriction, erasure or destruction.

“Processor” means a natural or legal person, public authority, agency or any other body which is
authorised to process Personal Data on behalf of the Customer, being Apryse.

“Security Measures” means the technical and organizational measures within the meaning of
Article 32 GDPR aiming at protecting Personal Data against accidental or unlawful destruction or
loss, as well as against non-authorised access, alteration or transmission.

                                                                                                     2
       “SSCs”: means the standard contractual clauses of which the European Commission on the basis
       of Article 26 (4) of Directive 95/46/EC decided that these offer sufficient safeguards for transfers
       of personal data to a third country, or the data protection clauses adopted by the European
       Commission or by a supervisory authority and approved by the European Commission in
       accordance with the examination procedure referred to in Article 93(2) of the GDPR. Data
       protection clauses adopted in accordance with the GDPR shall replace and prevail over any
       standard contractual clauses adopted on the basis of Directive 95/46/EC to the extent that they
       intend to cover the same kind of data transfer relationship.

       “Sub-processor” means any Processor engaged as a sub-processor or subcontractor by Apryse
       and processes Personal Data for, on behalf of and in accordance with the instructions of Apryse.

       “Supervisory Authority” means an independent public authority which is established by a Member
       State pursuant to Article 51 GDPR.

       “Third Party” means any party who is not a Data Subject, Controller, Processor or Sub-processor
       under this DPA or a person who is authorised to process Personal Data under the direct authority
       of the Customer or Apryse.

2.2.   Any other terms used in this DPA but not defined will have the same meaning as in the Data
       Protection Legislation or the Agreement.

3.     Details of the Processing

3.1.   Subject-nature: the Processing of Personal Data by Apryse (as Processor) on behalf of Customer
       (as Controller) relates to the performance of the Services as described in the Agreement and/or
       as further specified in the Services-related documentation, and/or as further instructed by the
       Customer in its use of the Services of Apryse.

3.2. Means of the Processing: systems, software, products, Services, tools and/or servers of Apryse.

3.3.   Categories of Personal Data: identification data (including contact details), financial data and
       electronic / connection data (IP address, username, ID data for authentication purposes).

3.4.   Categories of Data Subjects: customers and/or prospective customers, end-users (authorized by
       the Customer to use the Services), partners, employees, agents or other service providers or
       contractors of the Customer.

3.5.   Purposes of the Processing: to perform the Services as described in the Agreement, CRM,
       support desk and other customer management services or services related hereto and/or to
       comply with other documented or written reasonable instructions provided by the Customer where
       such instructions are consistent with the terms of the Agreement.

                                                                                                         3
3.6.   Retention period(s): Apryse will Process Personal Data for the term of the Agreement, unless
       otherwise agreed upon in writing or as required by applicable law and no longer than is necessary
       for the purposes for which the Personal Data are Processed, unless applicable law requires longer
       storage of the Personal Data.

4.     General

4.1.   Apryse Processes the Personal Data only on behalf of the Customer and in accordance with the
       documented or written instructions of the Customer, including with regard to transfers of Personal
       Data to a third country or an international organization, unless required to do so by (Union or
       Member State) law to which Apryse is subject; in such a case, Apryse shall inform the Customer
       of that legal requirement before Processing, unless that law prohibits such information on
       important grounds of public interest. The Agreement, including this DPA, is the Customer’s
       complete instruction to Apryse with regard to the Processing of Personal Data. Any additional or
       alternate instructions must be given in writing and agreed upon by the parties.

4.2.   Apryse shall only Process Personal Data in accordance with the purposes specified in section 3.5
       above.

4.3.   Apryse shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR
       or other Data Protection Legislation.

4.4.   Any Processing of Personal Data by Apryse under the Agreement shall be performed in
       accordance with the applicable Data Protecion Legislation, including the GDPR. Apryse is
       however not responsible for compliance with any laws applicable to the Customer or the
       Customer’s industry that are generally applicable to Apryse. The Customer shall comply with the
       applicable Data Protection Legislation, including the GDPR, as well as any other laws applicable
       to the Customer or the Customer’s industry. The Customer is solely responsible for the lawfulness
       of the Personal Data. The Customer represents and warrants that, where it provides any Personal
       Data to Apryse for Processing, it has duly informed the relevant Data Subject of their rights and
       obligations, and in particular has informed them of the possibility of Apryse processing their
       Personal Data on the Customer’s behalf and in accordance with its instructions. The Customer
       represents and warrants that the Processing of the Personal Data under the DPA is lawful.

4.5.   Apryse ensures that the Personal Data is only disclosed to the personnel or persons acting on
       behalf of Apryse and that are authorized to Process the Personal Data and who need it to perform
       the Services and/or tasks under the Agreement. Apryse ensures that persons authorized to
       Process the Personal Data and/or its Sub-processors have committed themselves to
       confidentiality or are under an appropriate statutory obligation of confidentiality.

                                                                                                       4
5.     Transfer of Personal Data

5.1.   Apryse agrees to keep all Personal Data and its Processing strictly secret and shall not disclose
       or reveal it, in whole or in part, directly or indirectly, to any Third Party, unless with prior written
       consent by the Customer or required by law.

5.2.   The Customer agrees to allow transfers of Personal Data outside the country from which it was
       originally collected provided that such transfers are required in connection with the provision of
       the Services under the Agreement and such transfers take place in accordance with Data
       Protection Legislation, including, without limitation, completing any prior assessments required by
       Data Protection Legislation.

5.3.   Where Apryse transfers Personal Data collected in the European Economic Area to a country
       outside the European Economic Area and without an adequacy decision under Article 45 of the
       GDPR, Apryse shall transfer Personal Data pursuant to the European Commission’s decision
       2010/87/EU on SSCs (for the transfer of personal data to processors established in third countries
       under Directive 95/46/EC). These SSCs are attached hereto (Exhibit 1), are hereby incorporated
       in their entirety into this DPA and, to the extent applicable, Apryse shall ensure that its
       Subprocessors comply with the obligations of a data importer (as defined in the SSCs).

6.     Security Measures

       Apryse shall implement and maintain all appropriate Security Measures to ensure a level of
       security to the risks in accordance with Article 32 GDPR. The Customer may request Apryse to
       provide an updated description of the implemented Security Measures

7.     Sub-processors

7.1.   The Customer acknowledges and agrees that Apryse may engage Sub-processors for the
       provision of the Services under the Agreement and that Apryse can transfer Personal Data to
       these Subprocessors in this context. Apryse shall inform the Customer upon request about all
       Sub-processors engaged and that Process Personal Data under the Agreement.

7.2.   Apryse shall also inform the Customer of any intended changes concerning the addition or
       replacement of Sub-processors, thereby giving the Customer the opportunity to object to such
       changes. Customer may object by notifying Apryse in writing within ten (10) business days after
       receipt of Apryse’s communication advising of the new Sub-processor or changes.

7.3.   Apryse shall enter into a written agreement with any engaged Sub-processor that contains data
       protection obligations no less protective than those contained in this DPA.

                                                                                                             5
7.4.   Where such Sub-processor fails to fulfil its Personal Data protection obligations in accordance
       with this DPA and/or Data Protection Legislation, Apryse shall be liable for the performance of
       that Sub-processor’s obligations.

8.     Assistance and information obligations

8.1.   Taking into account the nature of the Processing and the information available to Apryse, Apryse
       shall assist the Customer (i) by appropriate technical and organization measures, insofar as this
       is possible, for the fulfilment of the Customer’s obligation to respond to requests for exercising the
       Data Subject’s rights laid down in Chapter III of the GDPR and (ii) in ensuring compliance with
       the obligations pursuant to Article 32-36 GDPR. Apryse shall assist the Customer as it carries out
       Data Protection Impact Assessments in accordance with Article 35 GDPR.

8.2.   Apryse shall make available to the Customer all information necessary to demonstrate
       compliance the GDPR and in particular with the obligations laid down in Article 28 GDPR.

8.3.   Apryse shall be entitled to invoice the Customer on a time and material basis at the then-current
       prices for any time expended for any such assistance within the meaning of this section 8.

9.     Audits

9.1.   The Customer is entitled to reasonably verify Apryse’s compliance with the DPA and the Data
       Protection Legislation, provided that Apryse shall have no obligation to provide confidential and/or
       proprietary information. To this extent, the Customer may, upon request in writing and with prior
       notice of thirty (30) calendar days, at its own expense, instruct acknowledged audit professionals
       to execute such audit or inspection: (i) once every twelve (12) months provided that such
       additional audit inquiries take place during normal office hours and shall not unreasonably impact
       in an adverse manner Apryse’s regular operations and do not prove to be incompatible with the
       applicable legislation or with the instructions of a competent authority; (ii) where a competent data
       protection authority requires this under Data Protection Legislation (including the GDPR); or (iii)
       following a Personal Data Breach.

9.2.   Before the commencement of any such audit inquiries, parties shall mutually agree upon the
       scope, timing and duration of the audit, including conditions of confidentiality. During such audit,
       Apryse shall provide reasonable cooperation and assistance to the auditors.

9.3.   The Customer shall promptly notify Apryse with information regarding any non-compliance
       discovered during the course of such audit. Audit reports, any other information to which the
       Customer or the audit professionals have access pursuant to any audit activities, as well as an
       attestation of the implementation of the Security Measures, will be considered confidential
       information.

                                                                                                           6
9.4.     Apryse shall be entitled to invoice the Customer on a time and material basis at the then-current
         applicable prices for any time expended for any such audit inquiries. The Customer shall not be
         entitled to claim compensation for any kind of audit expenses incurred by the Customer (unless
         the audit has revealed any breach or any failure by Apryse in which case Apryse shall bear the
         costs related to this breach or failure).

10.      Personal Data Breaches

10.1. In the event of a Personal Data Breach, and irrespective of its cause, Apryse shall notify the
         Customer without undue delay after having become aware of such Personal Data Breach,
         specifying where known or readily identifiable: (i) the nature of the Personal Data Breach; (ii) the
         categories and approximate number of Data Subjects and Personal Data records concerned; (iii)
         as the case may be, any remedial actions taken or proposed to be taken to address the Personal
         Data Breach, to mitigate its effects and to prevent re-occurrence and (iv) the identity and contact
         details of any other contact person from whom more information can be obtained.

10.2. The Party responsible for the Personal Data Breach shall without undue delay further investigate
        the Personal Data Breach and shall keep the other Party informed of the progress of the
        investigation and take reasonable steps to further minimize the impact. Both parties agree to fully
        cooperate with such investigation and to assist each other in complying with any notification
        requirements and procedures.

11.      Return and/or deletion of Personal Data

11.1. Upon termination of the DPA and/or the Agreement, Apryse shall delete or anonymize all Personal
         Data on its systems (without prejudice to any backup archives) at the latest sixty (60) calendar
         days after the last effective day of the DPA and/or the Agreement, unless otherwise instructed by
         the Customer or unless applicable law requires longer storage of the Personal Data.

11.2. Upon written request of the Customer, Apryse will provide the Customer with a readable copy in
         a standard format of the Personal Data on its systems. The costs related to such request / copy
         are at the Customer’s expense.

12.      Liability

12.1.      Apryse is only liable for the damage caused by the Processing of Personal Data under the DPA
           and/or the Agreement where it has not complied with the applicable Data Protection Legislation,
           including the GDPR, specifically directed to Processors and/or where it has acted outside or
           contrary to lawful instructions of the Customer.

12.2.      The provisions of the Agreement on (limitation of) liability fully apply for the Processing of
           Personal Data by Apryse under the DPA and/or the Agreement. In any event, Apryse’s
           aggregate maximum liability under this DPA will be limited to the sum equal to the highest of the
           following amounts: (i) the fees paid under the Agreement by the Customer to Apryse or (ii) the

                                                                                                           7
amount of the insurance coverage offered by any of Apryse’s relevant insurance policies. The
right to claim damages attributable to Apryse will be forfeited irrevocably six (6) months after the
occurrence of the alleged error. The Customer must serve a notice of default within the
aforementioned term, providing a detailed description thereof.

                                                                                                  8
Exhibit 1. EU Standard Contractual Clauses (2010/87/EU)

These SCCs are attached to and made part of this DPA. For the purposes of Article 26(2) of Directive
95/46/EC for the transfer of personal data to processors established in third countries which do not
ensure an adequate level of data protection. The data exporter and data importer are as described in
the DPA and HAVE AGREED on the following Contractual Clauses (the “Clauses”) in order to adduce
adequate safeguards with respect to the protection of privacy and fundamental rights and freedoms of
individuals for the transfer by the data exporter to the data importer of the personal data specified in
Appendix 1.

                                                 Clause 1

                                                Definitions

For the purposes of the Clauses:

(a)      ‘personal data’, ‘special categories of data’, ‘process/processing’, ‘controller’, ‘processor’, ‘data
         subject’ and ‘supervisory authority’ shall have the same meaning as in Directive 95/46/EC of
         the European Parliament and of the Council of 24 October 1995 on the protection of individuals
         with regard to the processing of personal data and on the free movement of such data;

(b)      ‘the data exporter’ means the controller who transfers the personal data;

(c)      ‘the data importer’ means the processor who agrees to receive from the data exporter personal
         data intended for processing on his behalf after the transfer in accordance with his instructions
         and the terms of the Clauses and who is not subject to a third country’s system ensuring
         adequate protection within the meaning of Article 25(1) of Directive 95/46/EC;

(d)      ‘the sub-processor’ means any processor engaged by the data importer or by any other
         subprocessor of the data importer who agrees to receive from the data importer or from any
         other sub-processor of the data importer personal data exclusively intended for processing
         activities to be carried out on behalf of the data exporter after the transfer in accordance with
         his instructions, the terms of the Clauses and the terms of the written subcontract;

(e)      ‘the applicable data protection law’ means the legislation protecting the fundamental rights and
         freedoms of individuals and, in particular, their right to privacy with respect to the processing
         of personal data applicable to a data controller in the Member State in which the data exporter
         is established;

(f)      ‘technical and organisational security measures’ means those measures aimed at protecting
         personal data against accidental or unlawful destruction or accidental loss, alteration,
         unauthorised disclosure or access, in particular where the processing involves the
         transmission of data over a network, and against all other unlawful forms of processing.

                                                                                                            9
                                                Clause 2

                                         Details of the transfer

The details of the transfer and in particular the special categories of personal data where applicable are
specified in Appendix 1 which forms an integral part of the Clauses.

                                                Clause 3

                                    Third-party beneficiary clause

1.      The data subject can enforce against the data exporter this Clause, Clause 4(b) to (i), Clause
        5(a) to (e), and (g) to (j), Clause 6(1) and (2), Clause 7, Clause 8(2), and Clauses 9 to 12 as
        third-party beneficiary.

2.      The data subject can enforce against the data importer this Clause, Clause 5(a) to (e) and (g),
        Clause 6, Clause 7, Clause 8(2), and Clauses 9 to 12, in cases where the data exporter has
        factually disappeared or has ceased to exist in law unless any successor entity has assumed
        the entire legal obligations of the data exporter by contract or by operation of law, as a result of
        which it takes on the rights and obligations of the data exporter, in which case the data subject
        can enforce them against such entity.

3.      The data subject can enforce against the sub-processor this Clause, Clause 5(a) to (e) and (g),
        Clause 6, Clause 7, Clause 8(2), and Clauses 9 to 12, in cases where both the data exporter
        and the data importer have factually disappeared or ceased to exist in law or have become
        insolvent, unless any successor entity has assumed the entire legal obligations of the data
        exporter by contract or by operation of law as a result of which it takes on the rights and
        obligations of the data exporter, in which case the data subject can enforce them against such
        entity. Such third-party liability of the sub-processor shall be limited to its own processing
        operations under the Clauses.

4.      The parties do not object to a data subject being represented by an association or other body if
        the data subject so expressly wishes and if permitted by national law.

                                                Clause 4

                                   Obligations of the data exporter

The data exporter agrees and warrants:

(a)      that the processing, including the transfer itself, of the personal data has been and will continue
         to be carried out in accordance with the relevant provisions of the applicable data protection
         law (and, where applicable, has been notified to the relevant authorities of the Member State
         where the data exporter is established) and does not violate the relevant provisions of that
         State;

(b)      that it has instructed and throughout the duration of the personal data-processing services will
         instruct the data importer to process the personal data transferred only on the data exporter’s
         behalf and in accordance with the applicable data protection law and the Clauses;

                                                                                                         10
(c)     that the data importer will provide sufficient guarantees in respect of the technical and
        organisational security measures specified in Appendix 2 to this contract;

(d)     that after assessment of the requirements of the applicable data protection law, the security
        measures are appropriate to protect personal data against accidental or unlawful destruction
        or accidental loss, alteration, unauthorised disclosure or access, in particular where the
        processing involves the transmission of data over a network, and against all other unlawful
        forms of processing, and that these measures ensure a level of security appropriate to the risks
        presented by the processing and the nature of the data to be protected having regard to the
        state of the art and the cost of their implementation;

(e)     that it will ensure compliance with the security measures;

(f)     that, if the transfer involves special categories of data, the data subject has been informed or
        will be informed before, or as soon as possible after, the transfer that its data could be
        transmitted to a third country not providing adequate protection within the meaning of Directive
        95/46/EC;

(g)     to forward any notification received from the data importer or any sub-processor pursuant to
        Clause 5(b) and Clause 8(3) to the data protection supervisory authority if the data exporter
        decides to continue the transfer or to lift the suspension;

(h)     to make available to the data subjects upon request a copy of the Clauses, with the exception
        of Appendix 2, and a summary description of the security measures, as well as a copy of any
        contract for sub-processing services which has to be made in accordance with the Clauses,
        unless the Clauses or the contract contain commercial information, in which case it may
        remove such commercial information;

(i)     that, in the event of sub-processing, the processing activity is carried out in accordance with
        Clause 11 by a sub-processor providing at least the same level of protection for the personal
        data and the rights of data subject as the data importer under the Clauses; and (j) that it will
        ensure compliance with Clause 4(a) to (i).

                                                Clause 5

                                   Obligations of the data importer

The data importer agrees and warrants:

(a)     to process the personal data only on behalf of the data exporter and in compliance with its
        instructions and the Clauses; if it cannot provide such compliance for whatever reasons, it
        agrees to inform promptly the data exporter of its inability to comply, in which case the data
        exporter is entitled to suspend the transfer of data and/or terminate the contract;

(b)     that it has no reason to believe that the legislation applicable to it prevents it from fulfilling the
        instructions received from the data exporter and its obligations under the contract and that in
        the event of a change in this legislation which is likely to have a substantial adverse effect on
        the warranties and obligations provided by the Clauses, it will promptly notify the change to the
        data exporter as soon as it is aware, in which case the data exporter is entitled to suspend the
        transfer of data and/or terminate the contract;

                                                                                                           11
(c)           that it has implemented the technical and organisational security measures specified in
              Appendix 2 before processing the personal data transferred;

(d)           that it will promptly notify the data exporter about:
      (i)       any legally binding request for disclosure of the personal data by a law enforcement authority
                unless otherwise prohibited, such as a prohibition under criminal law to preserve the
                confidentiality of a law enforcement investigation;

      (ii)      any accidental or unauthorised access; and
      (iii)     any request received directly from the data subjects without responding to that request,
                unless it has been otherwise authorised to do so;

(e)           to deal promptly and properly with all inquiries from the data exporter relating to its processing
               of the personal data subject to the transfer and to abide by the advice of the supervisory
               authority with regard to the processing of the data transferred;

(f)           at the request of the data exporter to submit its data-processing facilities for audit of the
              processing activities covered by the Clauses which shall be carried out by the data exporter or
              an inspection body composed of independent members and in possession of the required
              professional qualifications bound by a duty of confidentiality, selected by the data exporter,
              where applicable, in agreement with the supervisory authority;

(g)           to make available to the data subject upon request a copy of the Clauses, or any existing
              contract for sub-processing, unless the Clauses or contract contain commercial information, in
              which case it may remove such commercial information, with the exception of Appendix 2 which
              shall be replaced by a summary description of the security measures in those cases where the
              data subject is unable to obtain a copy from the data exporter;

(h)           that, in the event of sub-processing, it has previously informed the data exporter and obtained
              its prior written consent;

(i)           that the processing services by the sub-processor will be carried out in accordance with Clause
              11;

(j)           to send promptly a copy of any sub-processor agreement it concludes under the Clauses to
              the data exporter.

                                                      Clause 6

                                                      Liability

1.            The parties agree that any data subject, who has suffered damage as a result of any breach of
              the obligations referred to in Clause 3 or in Clause 11 by any party or sub-processor is entitled
              to receive compensation from the data exporter for the damage suffered.

2.            If a data subject is not able to bring a claim for compensation in accordance with paragraph 1
              against the data exporter, arising out of a breach by the data importer or his sub-processor of
              any of their obligations referred to in Clause 3 or in Clause 11, because the data exporter has
              factually disappeared or ceased to exist in law or has become insolvent, the data importer
              agrees that the data subject may issue a claim against the data importer as if it were the data
              exporter, unless any successor entity has assumed the entire legal obligations of the data

                                                                                                             12
           exporter by contract of by operation of law, in which case the data subject can enforce its rights
           against such entity.

           The data importer may not rely on a breach by a sub-processor of its obligations in order to
           avoid its own liabilities.

3.         If a data subject is not able to bring a claim against the data exporter or the data importer referred
           to in paragraphs 1 and 2, arising out of a breach by the sub-processor of any of their obligations
           referred to in Clause 3 or in Clause 11 because both the data exporter and the data importer
           have factually disappeared or ceased to exist in law or have become insolvent, the sub-
           processor agrees that the data subject may issue a claim against the data sub-processor with
           regard to its own processing operations under the Clauses as if it were the data exporter or the
           data importer, unless any successor entity has assumed the entire legal obligations of the data
           exporter or data importer by contract or by operation of law, in which case the data subject can
           enforce its rights against such entity. The liability of the sub-processor shall be limited to its own
           processing operations under the Clauses.

                                                    Clause 7

                                          Mediation and jurisdiction

1.          The data importer agrees that if the data subject invokes against it third-party beneficiary rights
            and/or claims compensation for damages under the Clauses, the data importer will accept the
            decision of the data subject:

     (a)      to refer the dispute to mediation, by an independent person or, where applicable, by the
              supervisory authority;

     (b)      to refer the dispute to the courts in the Member State in which the data exporter is
              established.
2.          The parties agree that the choice made by the data subject will not prejudice its substantive or
            procedural rights to seek remedies in accordance with other provisions of national or
            international law.

                                                    Clause 8

                                  Cooperation with supervisory authorities

1.         The data exporter agrees to deposit a copy of this contract with the supervisory authority if it so
           requests or if such deposit is required under the applicable data protection law.

2.         The parties agree that the supervisory authority has the right to conduct an audit of the data
           importer, and of any sub-processor, which has the same scope and is subject to the same
           conditions as would apply to an audit of the data exporter under the applicable data protection
           law.

3.         The data importer shall promptly inform the data exporter about the existence of legislation
           applicable to it or any sub-processor preventing the conduct of an audit of the data importer, or
           any sub-processor, pursuant to paragraph 2. In such a case the data exporter shall be entitled
           to take the measures foreseen in Clause 5(b).

                                                                                                              13
                                                Clause 9

                                             Governing law

The Clauses shall be governed by the law of the Member State in which the data exporter is established.

                                               Clause 10

                                       Variation of the contract

The parties undertake not to vary or modify the Clauses. This does not preclude the parties from adding
clauses on business related issues where required as long as they do not contradict the Clause.

                                               Clause 11

                                            Sub-processing

1.      The data importer shall not subcontract any of its processing operations performed on behalf of
        the data exporter under the Clauses without the prior written consent of the data exporter. Where
        the data importer subcontracts its obligations under the Clauses, with the consent of the data
        exporter, it shall do so only by way of a written agreement with the sub-processor which imposes
        the same obligations on the sub-processor as are imposed on the data importer under the
        Clauses. Where the sub-processor fails to fulfil its data protection obligations under such written
        agreement the data importer shall remain fully liable to the data exporter for the performance of
        the sub-processor’s obligations under such agreement.

2.      The prior written contract between the data importer and the sub-processor shall also provide
        for a third-party beneficiary clause as laid down in Clause 3 for cases where the data subject is
        not able to bring the claim for compensation referred to in paragraph 1 of Clause 6 against the
        data exporter or the data importer because they have factually disappeared or have ceased to
        exist in law or have become insolvent and no successor entity has assumed the entire legal
        obligations of the data exporter or data importer by contract or by operation of law. Such
        thirdparty liability of the sub-processor shall be limited to its own processing operations under
        the Clauses.

3.      The provisions relating to data protection aspects for sub-processing of the contract referred to
        in paragraph 1 shall be governed by the law of the Member State in which the data exporter is
        established, namely …

4.      The data exporter shall keep a list of sub-processing agreements concluded under the Clauses
        and notified by the data importer pursuant to Clause 5(j), which shall be updated at least once
        a year. The list shall be available to the data exporter’s data protection supervisory authority.

                                               Clause 12

              Obligation after the termination of personal data processing services

1.      The parties agree that on the termination of the provision of data-processing services, the data
        importer and the sub-processor shall, at the choice of the data exporter, return all the personal

                                                                                                        14
        data transferred and the copies thereof to the data exporter or shall destroy all the personal data
        and certify to the data exporter that it has done so, unless legislation imposed upon the data
        importer prevents it from returning or destroying all or part of the personal data transferred. In
        that case, the data importer warrants that it will guarantee the confidentiality of the personal
        data transferred and will not actively process the personal data transferred anymore.

2.      The data importer and the sub-processor warrant that upon request of the data exporter and/or
        of the supervisory authority, it will submit its data-processing facilities for an audit of the
        measures referred to in paragraph 1.

Appendix 1 to the Standard Contractual Clauses

This Appendix forms part of the Clauses and has been agreed by the parties by virtue of their signing
the DPA.

The Member States may complete or specify, according to their national procedures, any additional
necessary information to be contained in this Appendix.

Data exporter

The data exporter is the legal entity that has executed the DPA and as a result has accepted the Clauses.

Data importer

The data importer is Apryse.

Data subjects

The personal data transferred concern the categories of data subjects specified under section 3.4 of the
DPA.

Categories of data

The personal data transferred concern the categories of data specified under section 3.3 of the DPA.

Processing operations

The personal data transferred will be subject to the following basic processing activities (please specify):
the performance of the Services under the Agreement.

                                                                                                         15
Appendix 2 to the Standard Contractual Clauses

This Appendix forms part of the Clauses and has been agreed by the parties by virtue of their signing
the DPA.

Description of the technical and organisational security measures implemented by the data
importer in accordance with Clauses 4(d) and 5(c) (or document/legislation attached):

 Use of Multi Factor Authentication for accounts that have access to Personal Data.

 Use of industry standard anti-virus and malware protection on clients, servers and other
 endpoints.

 All media (fixed or removable) should have strong encryption in place in order to prevent
 data loss when devices get lost or stolen.

 All databases or systems holding critical Personal Data should have encryption-at-rest and
 auditing enabled.

 All endpoints that have access to Personal Data that should be operated without local
 administrator rights.

 All network traffic, both internal and external, should be protected with SSL encryption.
 SHA-Z (Secure Hash Algorithms) will have to be the minimum cryptographic hash and the
 key length has to be 2048 at minimum, 4096 is preferred.

 Systems that hold, or have access to Personal Data, should be at an adequate patch level.
 Updates should be installed not later than 3 months after release by the vendor.

 A well-documented and audited incident response process should be in place and known
 by all staff working with Personal Data.

 Physical access to the datacenters should be registered and detailed information should
 be retained for auditing purposes.

                                                                                                  16