Third Party Index

Snapshot 80006

Document
Data processing addendum
URL
https://go.sensortower.com/rs/351-RWH-315/images/ST%20Customer%20DPA%20v3.2.0.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
206289 bytes
SHA-256 (raw)
ca5ca2b82e4738792d697e6bde8bd77d8ee6cd9142c120ba6462fa29e447ea49
SHA-256 (normalized text)
f3bd9dd8dbb0414d427656c3a77fd9e8acf218a0b579da7230463d2df8e320ca

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Data Processing Addendum
This Data Processing Addendum (“DPA”), including its Annexes A, B, C, and D, forms part of
the Master Service Agreement, which is defined as either the Terms of Service (available at
https://sensortower.com/tos) agreed to and accepted by Customer upon signing up for the
Services or the separate written master service agreement executed by Company and
Customer (the “Service Agreement”) for the purchase of the Services. In this DPA Company
and Customer may each be referred to as a “Party” and may collectively be referred to as the
Parties.

Customer enters into this DPA on behalf of itself and, to the extent required under applicable
Data Protection Laws (defined hereinafter), in the name and on behalf of its Authorized
Affiliates, if and to the extent Company processes Customer Personal Data (defined
hereinafter) for which such Authorized Affiliates qualify as the Controller. For the purposes of
this DPA only, and except where indicated otherwise, the term “Customer” shall include
Customer and its Authorized Affiliates. All capitalized terms not defined herein shall have the
meaning set forth in the Service Agreement.

In the course of providing the Services to Customer pursuant to the Service Agreement,
Company may process Customer Personal Data (defined hereinafter) on behalf of Customer
and the Parties agree to comply with the following provisions with respect to any Customer
Personal Data, each acting reasonably and in good faith.
Execution of this DPA by Customer shall be deemed to constitute signature and acceptance by
Customer of the Standard Contractual Clauses (defined hereinafter) and their Appendices,
which are incorporated herein by reference herein in their entireties. This DPA will become
legally binding upon receipt by Company of the validly completed and fully executed DPA.

If the Customer entity entering into this DPA is not a party to a Service Agreement, this DPA is
not valid and is not legally binding.

Definitions

“Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under
common control with the subject entity. “Control,” for purposes of this definition, means direct
or indirect ownership or control of more than 50% of the voting interests of the subject entity.

“Authorized Affiliate” means any of Customer’s Affiliate(s) which (a) is subject to the data
protection laws and regulations of the European Union, the European Economic Area and/or

                             Company Data Processing Addendum (v3.2)
                                          Page 1 of 21
their member states, Switzerland and/or the United Kingdom (“UK”), and (b) is permitted to use
the Services pursuant to the Service Agreement but has not signed its own Service Agreement
with Company and is not a “Customer” as defined under this DPA.

“California Consumer Privacy Act” (“CCPA”) means Cal. Civ. Code Title 1.81.5, § 1798.100
et seq. and its implementing regulations.

“Controller” means the entity which determines the purposes and means of the Processing of
Personal Data.

“Customer Personal Data” means any and all Personal Data provided by Customer to
Company and processed by Company in the course of providing the Services under the
Service Agreement.

“Data Protection Laws” mean all data protection and privacy laws applicable to the
processing of Personal Data under the Service Agreement, including, where applicable, the
laws and regulations of the European Economic Area (EEA), Switzerland, the United Kingdom
(UK), and the United States (US) and its states, applicable to the Processing of Personal Data
under the Service Agreement as amended from time to time.

“Europe” means the EU, the EEA, Switzerland, and the UK.

“EU” means the European Union.

“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of
27 April 2016 on the protection of natural persons with regard to the processing of personal
data and on the free movement of such data, and repealing Directive 95/46/EC (General Data
Protection Regulation) including as implemented or adopted under the laws of the UK.

“Personal Data” means any information relating to (i) an identified or identifiable natural
person and, (ii) an identified or identifiable legal entity (where such information is protected
similarly as Personal Data or personally identifiable information under applicable Data
Protection Laws and Regulations).

“Processing” means any operation or set of operations which is performed upon Personal
Data, whether or not by automatic means, such as collection, recording, organization,
structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by
transmission, dissemination or otherwise making available, alignment or combination,
restriction, erasure or destruction.

                              Company Data Processing Addendum (v3.2)
                                           Page 2 of 21
“Processor” means the entity which Processes Customer Personal Data on behalf of the
Controller, including as applicable any “service provider” as that term is defined by the CCPA.

“Public Authority” means a government agency or law enforcement authority, including
judicial authorities.

“Standard Contractual Clauses” or “SCCs” mean Standard Contractual Clauses for the
transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the
European Parliament and the Council approved by European Commission Implementing
Decision (EU) 2021/914 of 4 June 2021, as currently set out at https://eur-
lex.europa.eu/eli/dec_impl/2021/914/oj.

“Sub-processors” means any third-party Processor engaged by Company.

“Term” means the term of this DPA, which is the same term as in the Service Agreement.

Other Terms. Capitalized terms not defined in this DPA will have the meaning ascribed to
them in the Service Agreement. The terms “data subject”, “data controller”, “data
processor”, “representative” and “supervisory authority”, as used herein, have the
meanings given in the Data Protection Laws.

Processing of Customer Personal Data

Roles of Parties. The Parties acknowledge and agree that with regard to the Processing of
Customer Personal Data, Customer is the Controller, Company is the Processor and that
Company will engage Sub-processors pursuant to the requirements set forth in the Sub-
processors section below.

Company’s Processing of Customer Personal Data. Company shall treat Customer
Personal Data as Confidential Information and shall Process Customer Personal Data on
behalf of and only in accordance with Customer’s documented instructions for the following
purposes: (i) Processing in accordance with the Service Agreement and Annex A; (ii)
Processing initiated by users in their use of the Services; and (iii) Processing to comply with
other documented reasonable instructions provided by Customer (e.g., via email) where such
instructions are consistent with the terms of the Service Agreement.

Customer’s Processing of Customer Personal Data. Customer shall, in its use of the
Services, Process Customer Personal Data in accordance with the requirements of Data
Protection Laws, including any applicable requirement to provide notice to Data Subjects of the
use of Company as Processor. For the avoidance of doubt, Customer’s instructions for the

                             Company Data Processing Addendum (v3.2)
                                          Page 3 of 21
Processing of Customer Personal Data shall comply with Data Protection Laws. Customer
shall have sole responsibility for the accuracy, quality, and legality of Customer Personal Data
and the means by which Customer acquired the Customer Personal Data. Customer
specifically acknowledges and agrees that its use of the Services will not violate the rights of
any Data Subject, including those that have opted-out from sales or other disclosures of
Personal Data, to the extent applicable under Data Protection Laws.

Details of Processing. The subject-matter and details of the data processing covered by this
DPA is described in Annex A and/or the Service Agreement including any order forms or
statements of work (each a “Description of Personal Data Processing”). The processing will be
carried out until the Term lapses.

Processing Details. The subject-matter of Processing of Customer Personal Data by
Company is the performance of the Services pursuant to the Service Agreement. The duration
of the Processing, the nature and purpose of the Processing, the types of Customer Personal
Data and categories of Data Subjects Processed under this DPA are further specified in Annex
A to this DPA.

Return and Removal of Customer Personal Data

Upon Customer’s request, Company will return all Customer Personal Data in Company’s
possession or reasonable control to Customer via a mutually agreed upon secure transmission
format. In addition, unless otherwise requested by Customer in writing, Company is
responsible for and will, to the extent allowed by applicable law, delete Customer Personal
Data in accordance with its written data deletion policy.

Rights of Data Subjects
Company shall, to the extent legally permitted, promptly notify Customer if Company receives
a request from a Data Subject in relation to the Customer Personal Data to exercise the data
subject’s right of access, right to rectification, restriction of Processing, erasure (“right to be
forgotten”), data portability, object to the Processing, or its right not to be subject to an
automated individual decision making, each such request being a “Data Subject Request”.
Taking into account the nature of the Processing, Company shall assist Customer by
appropriate technical and organizational measures, insofar as this is possible, for the fulfillment
of Customer’s obligation to respond to a Data Subject Request under Data Protection Laws. In
addition, to the extent Customer, in its use of the Services, does not have the ability to address
a Data Subject Request, Company shall upon Customer’s request provide commercially
reasonable efforts to assist Customer in responding to such Data Subject Request, to the

                              Company Data Processing Addendum (v3.2)
                                           Page 4 of 21
extent Company is legally permitted to do so and the response to such Data Subject Request
is required under Data Protection Laws.

Company Personnel
Confidentiality. Company shall ensure that its personnel engaged in the Processing of
Customer Personal Data are informed of the confidential nature of the Customer Personal
Data, have received appropriate training on their responsibilities and have executed written
confidentiality agreements. Company shall ensure that such confidentiality obligations survive
the termination of the personnel engagement.

Reliability. Company shall take commercially reasonable steps to ensure the reliability of any
Company personnel engaged in the Processing of Customer Personal Data.

Limitation of Access. Company shall ensure that Company’s access to Customer Personal
Data is limited to those personnel performing Services in accordance with the Service
Agreement.

Data Protection Officer. Company has appointed a data protection officer. The appointed
person may be reached at data-protection@sensortower.com.

Security and Incident Management

Controls for Protection of Customer Personal Data. Company shall maintain appropriate
technical and organizational measures for protection of the security (including protection
against unauthorized or unlawful Processing and against accidental or unlawful destruction,
loss or alteration or damage, unauthorized disclosure of, or access to, Customer Personal
Data), confidentiality and integrity of Customer Personal Data, as set forth in Annex B.
Company regularly monitors compliance with these measures. Company will not materially
decrease the overall security of the Services during a subscription term.

Data Protection Impact Statement. Upon Customer’s request, Company shall provide
Customer with reasonable cooperation and assistance needed to fulfill Customer’s obligation
under the Data Protection Laws to carry out a data protection impact assessment related to
Customer’s use of the Services, to the extent Customer does not otherwise have access to the
relevant information, and to the extent such information is available to Company. Company
shall provide reasonable assistance to Customer in the cooperation or prior consultation with
the relevant supervisory authority in the performance of its tasks under this section to the
extent required under the GDPR.

                            Company Data Processing Addendum (v3.2)
                                         Page 5 of 21
Audits.Once annually, Company shall allow Customer and its respective auditors or
authorized agents to conduct an or inspection at its own cost during the term of the Service
Agreement, which shall include providing reasonable access to resources and personnel used
by Company in connection with the provision of the Application Services, and provide all
reasonable assistance in order to assist Customer in exercising its audit rights under this
Clause. The purposes of an audit pursuant to this Clause include to verify that Company is
processing Customer Personal Data in accordance with its obligations under the DPA and
applicable Data Protection Laws. Notwithstanding the foregoing, such audit shall consist solely
of: (i) the provision by Company of written information (including, without limitation,
questionnaires and information about security policies) that may include information relating to
subcontractors; and (ii) interviews with Company’s IT personnel. Such an audit may be carried
out by Customer or an inspection body composed of independent members and in possession
of the required professional qualifications bound by a duty of confidentiality. For the avoidance
of doubt, no access to any part of Company’s IT system, data hosting sites or centers, or
infrastructure will be permitted.

Incident Management. If Company becomes aware of any accidental, unauthorized or
unlawful destruction, loss, alteration, or disclosure of, or access to the Customer Personal
Data that is processed by Company in the course of providing the Application Services (an
“Incident”) under the Service Agreement, it shall without undue delay notify Customer and
provide Customer (as soon as possible) with a description of the Incident as well as periodic
updates to information about the Incident, including its impact on Customer Personal Data.
Company shall additionally take action to investigate the Incident and reasonably prevent or
mitigate the effects of the Incident. The obligations herein shall not apply to Incidents that are
caused by Customer or Customer’s Users.

Sub-processors

Appointment of Sub-processors. Customer acknowledges and agrees Company may
engage third-party Sub-processors in connection with the provision of the Services. Company
shall enter into a written agreement with each Sub-processors containing data protection
obligations at least as protective as those in the Service Agreement and the DPA with respect
to the protection of Customer Personal Data to the extent applicable to the nature of the
Services provided by such Sub-processors.

List of Current Sub-processors and Notification of New Sub-processors. Upon written
request, Company shall make available to Customer the current list of Sub-processors for the
Services (“Sub-processors List”).

                              Company Data Processing Addendum (v3.2)
                                           Page 6 of 21
Liability. Company shall be liable for the acts and omissions of its Sub-processors to the
same extent Company would be liable if performing the services of each such Sub-processors
directly under the terms of this DPA, except as otherwise set forth in the Service Agreement.

Government Access Requests
Company Requirements. In its role as a Processor, Company shall maintain appropriate
measures to protect Customer Personal Data in accordance with the requirements of Data
Protection Laws, including by implementing appropriate technical and organizational
safeguards to protect Customer Personal Data against any interference that goes beyond what
is necessary in a democratic society to safeguard national security, defense and public
security. If Company receives a legally binding request to access Personal Data from a Public
Authority, Company shall, unless otherwise legally prohibited, promptly notify Customer
including a summary of the nature of the request. To the extent Company is prohibited by law
from providing such notification, Company shall use commercially reasonable efforts to obtain
a waiver of the prohibition to enable Company to communicate as much information as
possible, as soon as possible. Further, Company shall challenge the request if, after careful
assessment, it concludes that there are reasonable grounds to consider that the request is
unlawful. Company shall pursue possibilities of appeal. When challenging a request, Company
shall seek interim measures with a view to suspending the effects of the request until the
competent judicial authority has decided on its merits. It shall not disclose the Personal Data
requested until required to do so under the applicable procedural rules. Company agrees it will
provide the minimum amount of information permissible when responding to a request for
disclosure, based on a reasonable interpretation of the request. Company shall promptly notify
Customer if Company becomes aware of any direct access by a Public Authority to Personal
Data and provide information available to Company in this respect, to the extent permitted by
law. For the avoidance of doubt, this DPA shall not require Company to pursue action or
inaction that could result in civil or criminal penalty for Company such as contempt of court.

Sub-processors. Where feasible, Company shall ensure that Sub-processors involved in the
Processing of Personal Data are subject to the relevant commitments regarding Government
Access Requests in the Standard Contractual Clauses.

Data Transfers
Definitions

“EU C2P Transfer Clauses” means Standard Contractual Clauses sections I, II, III and IV (as
applicable) to the extent they reference Module Two (Controller-to-Processor).

“EU P2P Transfer Clauses” means Standard Contractual Clauses sections I, II III and IV (as
applicable) to the extent they reference Module Three (Processor-to-Processor).

                            Company Data Processing Addendum (v3.2)
                                         Page 7 of 21
Transfer Mechanisms. If, in the performance of the Services, Processing of Personal Data
includes transfers from the EEA, Switzerland, or the United Kingdom to countries which are
deemed to provide inadequate levels of data protection (“Other Countries”), if required by Data
Protection Laws, the Parties shall: (i) execute the Standard Contractual Clauses adopted by
the relevant data protection authorities of the European Commission or the UK Secretary of
State as set forth in this section (if applicable); or (ii) comply with any of the other mechanisms
provided for under Data Protection Laws for transferring Customer Personal Data to such
Other Countries. Additional information required by the Standard Contractual Clauses is set
forth in the Annexes to this DPA.

EU SCC Modules. The Parties agree that for transfers of Personal Data from the EEA, the
Standard Contractual Clauses are hereby incorporated by reference into this DPA as follows:

   ● The EU C2P Transfer Clauses. Where Customer is a Controller and a data exporter of
     Customer Personal Data and Company is a Processor and data importer with respect to
     that Customer Personal Data, then the Parties shall comply with the EU C2P Transfer
     Clauses, subject to the additional terms in section 1 of Annex D; and/or
   ● The EU P2P Transfer Clauses. Where Customer is a Processor acting on behalf of a
     Controller and a data exporter of Customer Personal Data and Company is a Processor
     and data importer with respect to that Customer Personal Data, the Parties shall comply
     with the terms of the EU P2P Transfer Clauses, subject to the additional terms in
     sections 1 and 2 of Annex D.

UK Model Clauses. The Parties agree that for transfers of Personal Data from the United
Kingdom, the International Data Transfer Addendum to the EU Commission Standard
Contractual Clauses, issued by the UK ICO under S119A(1) Data Protection Act 2018 and in
force March 21, 2022 (the “UK Addendum”), shall apply. The start date in Table 1 of the UK
Addendum shall be the date that the Parties have executed Annex A. The selection of modules
and optional clauses shall be as described in the sections above, subject to any revisions or
amendments required by the UK Addendum. All other information required by Tables 1-3 is set
forth in Annexes to this DPA. For the purposes of Table 4, the parties agree that both the
Importer and Exporter may end the UK Addendum.

Swiss Data Transfers. The Parties agree that for transfers of Personal Data from Switzerland,
the terms of the Standard Contractual Clauses shall be amended and supplemented as
specified by the relevant guidance of the Swiss Federal Data Protection and Information
Commissioner, and the competent supervisory authority shall be the Swiss Federal Data
Protection and Information Commissioner.

                              Company Data Processing Addendum (v3.2)
                                           Page 8 of 21
Impact of local laws. As of the Effective Date of the Service Agreement, Company has no
reason to believe that the laws and practices in any third country of destination applicable to its
Processing of the Personal Data as set forth in the Infrastructure and Sub-processors
Documentation, including any requirements to disclose Personal Data or measures authorizing
access by a Public Authority, prevent Company from fulfilling its obligations under this DPA. If
Company reasonably believes that any existing or future enacted or enforceable laws and
practices in the third country of destination applicable to its Processing of the Personal Data
("Local Laws") prevent it from fulfilling its obligations under this DPA, it shall promptly notify
Customer. In such a case, Company shall use reasonable efforts to make available to the
affected Customer a change in the Services or recommend a commercially reasonable change
to Customer’s configuration or use of the Services to facilitate compliance with the Local Laws
without unreasonably burdening Customer. If Company is unable to make available such
change promptly, Customer may terminate the applicable Order Form(s) and suspend the
transfer of Personal Data in respect only to those Services which cannot be provided by
Company in accordance with the Local Laws by providing written notice. Customer shall
receive a refund of any prepaid fees for the period following the effective date of termination for
such terminated Services.

Instructions. This DPA and the Service Agreement are Customer’s complete and final
documented instructions at the time of signature of the Service Agreement to Company for the
Processing of Customer Personal Data. Any additional or alternate instructions must be
agreed upon separately.

Conflict. In the event of any conflict or inconsistency between the body of this DPA and any of
its Schedules (not including the Standard Contractual Clauses) and the Standard Contractual
Clauses, the Standard Contractual Clauses shall prevail.

Signatures

By signing this DPA, the Parties hereby accept all of the terms and conditions of this DPA.

                              Company Data Processing Addendum (v3.2)
                                           Page 9 of 21
Sensor Tower, Inc.                           CUSTOMER

By:                                          By:

Print Name: Michel Bohn                      Print Name:

Title: CCO                                   Title:

Date: July 2, 2024                           Date:

Notice, If to Sensor Tower, Inc.             Notice, If to Customer
2261 Market Street #4331, San Francisco,
CA 94114

With a copy to: data-
protection@sensortower.com

                                             With a copy to:
On matters specifically related to the
processing of Personal Data in the UK or
Europe, you may send a notice to
Company’s GDPR Article 27
representative at:

UK Representative
Osano UK Compliance LTD
ATTN: 8QL4
42-46 Fountain Street
Belfast, Antrim
BT1 - 5EF

EU Representative
Osano International Compliance Services
Limited
ATTN: 8QL4
3 Dublin Landings, North Wall Quay
Dublin 1
D01C4E0

                             Company Data Processing Addendum (v3.2)
                                         Page 10 of 21
                                        Appendix
Annex A: Description of Personal Data Processing

A: List of Parties

Data exporter(s):

Name:

Address:

Contact person’s name, position and contact details:

Activities relevant to the data transferred under these Clauses: Receipt of Services under
Service Agreement and Processing as outlined in this DPA.

Signature: _______________________

Date: ______________

Role: Controller

Data importer(s):

Name: Sensor Tower, Inc.

Address: 2261 Market Street #4331, San Francisco, CA 94114

Contact person’s name, position and contact details: Michel Bohn, Data Protection Officer,
data-protection@sensortower.com

Activities relevant to the data transferred under these Clauses: Provision of Services under
Service Agreement and Processing as outlined in this DPA.

Signature: _______________________

        July 2, 2024
Date: ______________

Role: Processor

                             Company Data Processing Addendum (v3.2)
                                         Page 11 of 21
B. Description of Transfer

1.     Categories of data subjects whose personal data is transferred:

Registered users of Customer.

2.     Categories of personal data transferred:

Name, email address, phone number, IP address, user role, user agent,
device information, subscription and purchase information, usage data,
account information, and location information.

3.     Sensitive data transferred (if applicable) and applied restrictions or safeguards
that fully take into consideration the nature of the data and the risks involved, such as
for instance strict purpose limitation, access restrictions (including access only for staff
having followed specialized training), keeping a record of access to the data, restrictions
for onward transfers or additional security measures.
None

4.     The frequency of the transfer:
Continuous.

5.     Nature of the processing
Provision of Services under the Service Agreement.

6.     Purpose(s) of the data transfer and further processing:

To authenticate an authorized user, create an account, and grant the
user access to and use of the Services; to assess usage and secure the
Services; to provide technical and customer support; and to access and
make use of Company’s APIs, which are documented at
https://sensortower.com/api/v1/index.

7.     The period for which the personal data will be retained, or, if that is not possible,
the criteria used to determine that period.

The period is for the Term of the Service Agreement

8.    For transfers to (sub-) processors, also specify subject matter, nature and
duration of the processing:

                            Company Data Processing Addendum (v3.2)
                                        Page 12 of 21
As provided for in Annex C of this DPA.

                            Company Data Processing Addendum (v3.2)
                                        Page 13 of 21
Annex B: Minimum Security Measures

Company considers protection of the data it receives and processes for Customer (“Customer
Data”) a top priority. As further described in these Security Measures, Company uses
commercially reasonable organizational and technical measures designed to prevent
unauthorized access, use, alteration or disclosure of Customer Data stored on systems under
Company’s control.

   1. Access to Customer Data. Company limits its personnel's access to Customer Data as
      follows:

         a. Requires unique user access authorization through secure logins and
            passwords, including multi-factor authentication for cloud hosting administrator
            access.

         b. Limits the Customer Data available to Company personnel on a "need to know"
            basis; Customer provides explicit consent for access.

         c. Restricts access to Company 's production environment by Company personnel
            on the basis of business need.

         d. Encrypts user security credentials for production access.

   2. Data Encryption. Company provides industry-standard encryption for Customer Data
      both as follows:

         a. Customer Data is encrypted at rest and over the internet in transit; and

         b. Uses strong encryption methodologies to protect Customer Data, including AES
            256-bit encryption.

   3. Data Management

         a. Company creates an audit trail for key verification with each integration.

         b. Company maintains measures designed to prevent Customer Data from being
            exposed to or accessed by other customers.

   4. Network Security, Physical Security and Environmental Controls

                            Company Data Processing Addendum (v3.2)
                                        Page 14 of 21
      a. Company uses a variety of techniques designed to prevent unauthorized access
         to systems processing Customer Data, including firewalls and network access
         controls.

      b. Company maintains measures designed to assess, test and apply security
         patches to relevant systems and applications used to provide the Service.

      c. The Service operates on Amazon Web Services ("AWS") and is protected by
         Amazon's security and environmental controls. Detailed information about AWS
         security is available at https://aws.amazon.com/security and
         http://aws.amazon.com/security/sharing-the-security-responsibility. For AWS
         SOC Reports, please see https://aws.amazon.com/compliance/soc-faqs/.

      d. Customer Data is securely stored and monitored and is encrypted in transit.

5. Incident Response. If Company becomes aware of a security incident (“Incident),
   Company will:

      a. Take reasonable measures to mitigate the harmful effects of the Incident and
         prevent further unauthorized access or disclosure.

      b. Upon confirmation of the Incident, notify Customer in writing of the Incident
         without undue delay. Notwithstanding the foregoing, Company is not required to
         make such notice to the extent prohibited by Laws, and Company may delay
         such notice as requested by law enforcement and/or in light of Company's
         legitimate needs to investigate or remediate the matter before providing notice.

      c. Each notice of an Incident will include:

           i.    The extent to which Customer Data has been, or is reasonably believed to
                 have been, used, accessed, acquired or disclosed during the Incident;

           ii.   A description of what happened, including the date of the Breach and the
                 date of discovery of the Incident, if known;

          iii.   The scope of the Incident, to the extent known; and

          iv.    A description of Company's response to the Incident, including steps
                 Company has taken to mitigate the harm caused by the Incident.

6. Business Continuity Management

                         Company Data Processing Addendum (v3.2)
                                     Page 15 of 21
     a. Company maintains processes to ensure failover redundancy with its systems,
        networks and data storage.

7. Personnel Management

     a. Company performs employment verification, including proof of identity validation
        and background checks for new employees and contractors.

     b. Company provides training for its personnel who are involved in the processing
        of the Customer Data to ensure they do not collect, process or use Customer
        Data without authorization and that they keep Customer Data confidential.

     c. Upon employee termination, whether voluntary or involuntary, Company
        immediately disables all access to critical and noncritical systems.

                       Company Data Processing Addendum (v3.2)
                                   Page 16 of 21
Annex C: List of Sub-Processors

Controller has authorized the use of the Sub-processors listed at https://trust.sensortower.com.

                             Company Data Processing Addendum (v3.2)
                                         Page 17 of 21
Annex D: Additional Data Transfer Terms

Section 1
For the purposes of the EU C2P Transfer Clauses and the EU P2P Transfer Clauses,
Customer is the data exporter and Company is the data importer and the Parties agree to the
following. Where this section 2 may not explicitly mention EU C2P Transfer Clauses or EU
P2P Transfer Clauses, it applies to both of them.

Reference to the Standard Contractual Clauses. The relevant provisions contained in the
Standard Contractual Clauses are incorporated by reference and are an integral part of this
DPA. The information required for the purposes of the Annexes I, II, and III in the Appendix to
the Standard Contractual Clauses are set out in Annexes A, B, and C of the Appendix of this
DPA, respectively.

Docking clause. The option under clause 7 shall not apply.

Instructions. This DPA and the Service Agreement are Customer’s complete and final
documented instructions at the time of signature of the Service Agreement to Company for the
Processing of Customer Personal Data. Any additional or alternate instructions must be
consistent with the terms of this DPA and the Service Agreement. For the purposes of clause
8.1(a), the instructions by Customer to Process Customer Personal Data are set out in the
Service Agreement and this DPA, and include onward transfers to a third party located outside
Europe for the purpose of the performance of the Services.

Certification of Deletion. The Parties agree that the certification of deletion of Customer
Personal Data that is described in clause 8.5 and 16(d) of the Standard Contractual Clauses
shall be provided by Company to Customer only upon Customer's written request.

Security of Processing. For the purposes of clause 8.6(a), Customer is solely responsible for
making an independent determination as to whether the technical and organizational
measures set forth in the Security, Privacy and Architecture Documentation meet Customer’s
requirements and agrees that (taking into account the state of the art, the costs of
implementation, and the nature, scope, context and purposes of the Processing of its
Customer Personal Data as well as the risks to individuals) the security measures and policies
implemented and maintained by Company provide a level of security appropriate to the risk
with respect to its Customer Personal Data. For the purposes of clause 8.6(c), personal data
breaches will be handled in accordance with the Security and Incident Management of this
DPA.

Audits of the SCCs. The Parties agree that the audits described in clause 8.9 of the SCCs
shall be carried out in accordance with the Audit section of this DPA.

                             Company Data Processing Addendum (v3.2)
                                         Page 18 of 21
General authorisation for use of Sub-processors. Option 2 under clause 9 shall apply. For
the purposes of clause 9(a), Company has Customer’s general authorization to engage Sub-
processors in accordance with this DPA, shall make available to Customer the current list of
Sub-processors in accordance this DPA, and shall provide requisite notice to Customer of any
Sub-processor additions. Where Company enters into the EU P2P Transfer Clauses with a
Sub-processor in connection with the provision of the Services, Customer hereby grants
Company and Company’s Affiliates authority to provide a general authorization on Controller's
behalf for the engagement of sub-processors by Sub-processors engaged in the provision of
the Services, as well as decision making and approval authority for the addition or replacement
of any such sub-processors.

Complaints - Redress. For the purposes of clause 11, and subject to this DPA, Company
shall inform data subjects on its website of a contact point authorized to handle complaints.
Company shall inform Customer if it receives a complaint by, or a dispute from, a Data Subject
of Customer with respect to Customer Personal Data and shall without undue delay
communicate the complaint or dispute to Customer. Company shall not otherwise have any
obligation to handle the request (unless otherwise agreed with Customer). The option under
clause 11 shall not apply.

Liability. Company's liability under clause 12(b) shall be limited to any damage caused by its
Processing where Company has not complied with its obligations under the GDPR specifically
directed to Processors, or where it has acted outside of or contrary to lawful instructions of
Customer, as specified in Article 82 GDPR.

Supervision. Clause 13 shall apply as follows:

   ● Where Customer is established in an EU Member State, the supervisory authority with
     responsibility for ensuring compliance by Customer with Regulation (EU) 2016/679 as
     regards the data transfer shall act as competent supervisory authority.
   ● Where Customer is not established in an EU Member State, but falls within the territorial
     scope of application of Regulation (EU) 2016/679 in accordance with its Article 3(2) and
     has appointed a representative pursuant to Article 27(1) of Regulation (EU) 2016/679,
     the supervisory authority of the Member State in which the representative within the
     meaning of Article 27(1) of Regulation (EU) 2016/679 is established shall act as
     competent supervisory authority.
   ● Where Customer is not established in an EU Member State, but falls within the territorial
     scope of application of Regulation (EU) 2016/679 in accordance with its Article 3(2)
     without however having to appoint a representative pursuant to Article 27(2) of
     Regulation (EU) 2016/679, Commission nationale de l'informatique et des libertés
     (CNIL) - 3 Place de Fontenoy, 75007 Paris, France shall act as competent supervisory
     authority.

                            Company Data Processing Addendum (v3.2)
                                        Page 19 of 21
   ● Where Customer is established in the United Kingdom or falls within the territorial scope
     of application of UK Data Protection Laws, the Information Commissioner's Office shall
     act as competent supervisory authority.
   ● Where Customer is established in Switzerland or falls within the territorial scope of
     application of Swiss Data Protection Laws, the Swiss Federal Data Protection and
     Information Commissioner shall act as competent supervisory authority insofar as the
     relevant data transfer is governed by Swiss Data Protection Laws.

Notification of Government Access Requests. For the purposes of clause 15.1(a),
Company shall notify Customer (only) and not the Data Subject(s) in case of government
access requests. Customer shall be solely responsible for promptly notifying the Data Subject
as necessary.

Data Exports from the United Kingdom and Switzerland under the Standard Contractual
Clauses. In case of any transfers of Customer Personal Data from the United Kingdom and/or
transfers of Customer Personal Data from Switzerland subject exclusively to the Data
Protection Laws of Switzerland (“Swiss Data Protection Laws”), (i) general and specific
references in the Standard Contractual Clauses to GDPR or EU or Member State Law shall
have the same meaning as the equivalent reference in the Data Protection Laws of the United
Kingdom (“UK Data Protection Laws”) or Swiss Data Protection Laws, as applicable; and (ii)
any other obligation in the Standard Contractual Clauses determined by the Member State in
which the data exporter or Data Subject is established shall refer to an obligation under UK
Data Protection Laws or Swiss Data Protection Laws, as applicable. In respect of data
transfers governed by Swiss Data Protection Laws, the Standard Contractual Clauses also
apply to the transfer of information relating to an identified or identifiable legal entity where
such information is protected similarly as Customer Personal Data under Swiss Data
Protection Laws until such laws are amended to no longer apply to a legal entity.

Conflict. The Standard Contractual Clauses are subject to this DPA and the additional
safeguards set out hereunder. The rights and obligations afforded by the Standard Contractual
Clauses will be exercised in accordance with this DPA, unless stated otherwise. In the event of
any conflict or inconsistency between this DPA and the Standard Contractual Clauses, the
Standard Contractual Clauses shall prevail.

Section 2
For the purposes of the EU P2P Transfer Clauses (only), the Parties agree to the following.

Instructions and notifications. For the purposes of clause 8.1(a), Customer hereby informs
Company that it acts as Processor under the instructions of the relevant Controller with respect
to Customer Personal Data. Customer warrants that its Processing instructions as set out in
the Service Agreement and this DPA, including its authorizations to Company for the

                             Company Data Processing Addendum (v3.2)
                                         Page 20 of 21
appointment of Sub-processors in accordance with this DPA, have been authorized by the
relevant Controller. Customer shall be solely responsible for forwarding any notifications
received from Company to the relevant Controller where appropriate.

Security of Processing. For the purposes of clause 8.6(c) and (d), Company shall provide
notification of a personal data breach concerning Customer Personal Data Processed by
Company to Customer.

Documentation and Compliance. For the purposes of clause 8.9, all enquiries from the
relevant Controller shall be provided to Company by Customer. If Company receives an
enquiry directly from a Controller, it shall forward the enquiry to Customer and Customer shall
be solely responsible for responding to any such enquiry from the relevant Controller where
appropriate.

Data Subject Rights. For the purposes of clause 10 and subject to this DPA, Company shall
notify Customer about any request it has received directly from a Data Subject of Customer
without obligation to handle it (unless otherwise agreed), but shall not notify the relevant
Controller. Customer shall be solely responsible for cooperating with the relevant Controller in
fulfilling the relevant obligations to respond to any such request.

                             Company Data Processing Addendum (v3.2)
                                         Page 21 of 21