Third Party Index

Snapshot 80024

Document
Data processing addendum
URL
https://media.bazaarvoice.com/Bazaarvoice-DPA-Signed-Dec-2022.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
544197 bytes
SHA-256 (raw)
f7094d612be71367d9646cd782e3dba440361562a6f90645ab89681c3210c620
SHA-256 (normalized text)
5c698ba0ab40ae3eba0fae80b2d66f26e1c26bcb675eedbb411b3ec291fe9b10

Normalized text

Scripts and page chrome removed; this is what change detection compares.

DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

         DATA PROCESSING ADDENDUM
          BETWEEN CLIENT (CONTROLLER/EXPORTER)

          Client
          Address
          Data Protection Key Contact:

          AND BAZAARVOICE (DATA PROCESSOR/IMPORTER)

          Bazaarvoice, Inc.
          10901 Stonelake Blvd, Austin, TX 78759, USA
          Data Protection Key Contact: Christian Schmoll (Christian.schmoll@bazaarvoice.com)

         This Data Processing Addendum ("DPA") shall be effective as of the date of the last signature (“DPA Effective Date”) and shall be an
         integral part of the Principal Agreement concluded between the Client and Bazaarvoice.

          STRUCTURE/LIST OF CONTENTS OF THIS DATA PROCESSING ADENDUM

          •         Data Processing Addendum (DPA)
          •         Schedule 1: Details of Processing
          •         Schedule 2: Technical and Organisational Measures
          •         Schedule 3: Sub-Processors
          •         Schedule 4: UK Addendum

          Client                                                                 Bazaarvoice

          Name and title/function                                                Name and title/function

                                                                                 Katie Kuhn       Sr. Director, Finance
          Date:                                                                  Date:

                                                                                 12/2/2022

          Signature:                                                             Signature:

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                                                                         Page 1 of 15
DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

         DEFINITIONS
         "Appropriate safeguards" means such legally enforceable mechanism(s) for transfers of Personal Data as may be permitted under
         Data Protection Laws from time to time.
         “Client Personal Data" means the personal data processed by Bazaarvoice on behalf and on instruction of the Client in connection
         with the provision of the services provided by Bazaarvoice;
         “Data Controller“ means the natural or legal person, public authority, agency or other body which, alone or jointly with others,
         determines the purposes and means of the processing of personal data; where the purposes and means of such processing are
         determined by Data Protection Laws, the controller or the specific criteria for its nomination may be provided for by Data Protection
         Laws.
         “Data Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of
         the controller.
         ”Data Subject“ means an identified or identifiable natural person whose rights are protected by Data Protection Laws.
         "Data Protection Laws" means any and all laws as defined herein, codes and regulations as applicable to, the Services from time to
         time limited to: (i) General Data Protection Regulation (EU) 2016/679 (“GDPR”); (ii) Privacy and Electronic Communication (EC
         Directive) Regulations 2003 and other similar regulations as applicable in France; (iii) the UK General Data Protection Regulation (UK
         GDPR) (iv) the Swiss Federal Act on Data Protection (v) California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq., and its
         implementing regulations (“CCPA”); (vi) the California Privacy Rights Act; (vii) the Virginia Consumer Data Protection Act; (viii) the
         Colorado Privacy Act and (ix) Privacy Act 1988 of Australia.
         "EEA" means the European Economic Area.
         "GDPR" means Regulation (EU) 2016/679 (the "EU GDPR") or, where applicable the “UK GDPR” as defined in the UK Data Protection,
         Privacy and Electronic Communications (Amendment Etc.) (EU Exit) Regulations 2019.
         "Personal Data" means any information relating to an identified or identifiable natural person and subject to Data Protection laws
         which is submitted by or collected and processed on behalf and on instruction of Client.
         “Personal Data Breach” means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised
         disclosure of, or access to, any Personal Data.
         "Process/Processing" means any operation or set of operations which is performed on personal data or on sets of personal data,
         whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration,
         retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination,
         restriction, erasure or destruction.
         “Services“ has the meaning given to the term under the Principal Agreement.
         “Standard Contractual Clauses” means Module Two (controller to processor) and/or Module Three (processor to processor) annexed
         to Commission Implementing Decision (EU) 2021/914.
         “Sub-Processor” shall include: (i) an entity engaged by the Data Processor in order to perform Processing of Personal Data related to
         this Agreement; and (ii) entities defined as a “Sub-processor” under the Applicable Data Protection Law;
         “Supervisory Authority” means any local, national, or multinational agency, department, official, parliament, public or statutory
         person or any government or professional body, regulatory or supervisory authority, board or other legislative body responsible for
         administering Data Protection Laws.

         1.     SUBJECT OF THE DPA AND ROLE OF THE PARTIES
         1.1    Bazaarvoice and Client entered into one or more written services principal Agreement (the “Principal Agreement(s)”) which
                involve Processing of Personal Data of Data Subjects subject to Data Protection Laws in the context of the Services. All
                capitalized terms not defined herein shall have the meaning set forth in the Principal Agreement.
         1.2    Pursuant to the Principal Agreement, Bazaarvoice provides services to Client which may include hosted online customer
                feedback services, and associated consulting and support. This DPA specifies the obligations of the Parties regarding data
                protection, and applies to all activities related to the Principal Agreement in which Bazaarvoice processes Personal Data on
                behalf of and in accordance with the instructions of the Client as its data processor. The scope of this DPA shall also govern
                Personal Data of third parties as a sub-processor of the Client.
         1.3    Unless specifically agreed in writing by the parties, the parties acknowledge and agree that with regard to the Processing of
                Personal Data, Client is the Data Controller, Bazaarvoice is a Data Processor and that any subcontractors engaged by
                Bazaarvoice pursuant to the requirements set forth herein will be Sub-Processor.

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                                                                          Page 2 of 15
DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

         1.4    The parties agree to comply with the provisions of this DPA with respect to the processing of any and all Personal Data
                collected on behalf of or submitted by the Client in relation to the provision or receipt of the Services. In accordance with Data
                Protection Laws, the parties enter into this DPA which shall govern the Processing of Personal Data of Data Subjects subject
                to Data Protection Laws in the context of the Services. This DPA, is incorporated into the Principal Agreement by reference
                and as an annex, is an integral part of the Principal Agreement.
         1.5    The Services are provided by Bazaarvoice under a Software as a Service (SaaS) model. Namely, Client brings its own data,
                largely controls the upload and handles directly the use of Personal Data that is Processed in conjunction with the Services. It
                is therefore the sole responsibility and liability of Client to ensure that Personal Data is collected and transmitted to
                Bazaarvoice in compliance with applicable Data Protection Laws and, in particular, to have a legal basis for Processing and to
                properly inform Data Subjects of the collection and Processing of their Personal Data.

         2.     DATA PROCESSING
                The Processing of Personal Data by Bazaarvoice for Client is such as is strictly required in the performance of the contracted
                Services under the Principal Agreement. Further details of the Personal Data and Data Subjects required to provide the contracted
                Services can be found in Schedule 1.

         3.     OBLIGATIONS OF THE PROCESSOR
         3.1    Bazaarvoice shall in relation to Personal Data processed by Bazaarvoice on behalf of Client as a Data Processor:
                (a)     process the Personal Data only on the instructions of the Client, including with regard to transfers of Personal Data to
                        a third country or an international organization, unless required to do so by law to which Bazaarvoice is subject. In
                        such a case, Bazaarvoice shall inform Client of that legal requirement before Processing, unless that law prohibits such
                        information on grounds of public interest. Client’s instructions may be specific instructions or standing instructions of
                        general application in relation to the performance of Bazaarvoice’s obligations under the Principal Agreement; and
                (b)     ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are
                        under an appropriate statutory obligation of confidentiality; and
                (c)     take all measures required pursuant to Article 32 of the GDPR and clause 10 of this DPA with respect to the security
                        of Processing; and
                (d)     respect the conditions of the Data Protection Laws and clause 7 of this DPA for engaging a Sub-Processor; and
                (e)     assist Client in ensuring compliance with the obligations under Data Protection Laws with respect to:
                        (i)     security of Processing; and
                        (ii)    notifications to the Supervisory Authority in case of any Personal Data Breach; and
                        (iii)   communications to Data Subjects by the Client in response to any Personal Data Breach; and
                        (iv)    as in accordance with Article 28(3) of the GDPR, Bazaarvoice will cooperate and assist Client with any data
                                protection impact assessments which are referred to in Article 35 of the GDPR or with any regulatory
                                consultations that Client is legally required to make in respect of Personal Data, taking into account the nature
                                of the Processing and the information made available to Bazaarvoice;
                        (v)     prior consultation with a Supervisory Authority regarding high risk Processing;
                (f)     at Client’s choice, delete or return all the Personal Data to Client:
                        (vi)    once Processing by Bazaarvoice of any Personal Data is no longer required for the purpose of Bazaarvoice’s
                                performance of its relevant obligations under this DPA or the Principal Agreement(s) due to termination for
                                any reason; or
                        (vii)   on request by the Client;
                        and delete existing copies unless Data Protection Laws requires storage of the Personal Data and inform the Client of
                        such requirement;
                (g)     subject to clause 7, make available to Client all information necessary to demonstrate compliance with the obligations
                        laid down in this DPA and allow for and contribute to audits. For this purpose, Bazaarvoice may provide certifications,
                        reports or report extracts from independent entities (e.g. auditors, inspectors, data security officers, IT security
                        departments, data protection auditors, quality assurance auditors) or appropriate certification from an IT security or
                        data security audit.
         3.2    Notification of access requests and complaints: To the extent legally permitted, Bazaarvoice shall promptly notify Client of:
                (i) any request received directly by Bazaarvoice from a Data Subject to exercise the Data Subject’s right of access or have

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                                                                             Page 3 of 15
DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

                copies of Personal Data, right to rectification, restriction of Processing, erasure, data portability, object to the Processing, or
                its right not to be subject to an automated individual decision making pertaining to his or her Personal Data; or (ii) any
                complaint or allegation made to Bazaarvoice relating to Personal Data, either from a Data Subject, a Supervisory Authority or
                other third party (each a "Data Protection Communication"). In addition and in accordance with Data Protection Laws,
                Bazaarvoice shall:
                3.2.1   not respond to a Data Protection Communication unless Bazaarvoice is authorized to do so by Client or Bazaarvoice is
                        legally compelled to respond;
                3.2.2   When taking into account the nature of the Processing, Bazaarvoice shall assist Client by appropriate technical and
                        organizational measures, insofar as this is possible, for the fulfilment of Client’s obligation to respond to a Data
                        Protection Communication under Data Protection Laws;
                3.2.3   In addition, to the extent Client, in its use of the Services, does not have the ability to address a Data Protection
                        Communication, Bazaarvoice shall upon Client’s request provide commercially reasonable efforts to assist Client in
                        responding to such Data Protection Communication, to the extent Bazaarvoice is legally permitted to do so and the
                        response to the Data Protection Communication is required under Data Protection Laws. To the extent legally
                        permitted, Client shall be responsible for any costs arising from Bazaarvoice's provision of such assistance.
         3.3    Bazaarvoice shall immediately notify Client if, in its opinion, an instruction infringes Data Protection Laws, provided that to
                the maximum extent permitted by mandatory law, Bazaarvoice shall have no liability arising for any losses, costs, expenses or
                liabilities arising from or in connection with any Processing in accordance with the Client's Processing instructions, following
                the Client's receipt of that notification.
         3.4    Bazaarvoice shall not unreasonably withhold, delay or condition its agreement to any change to this DPA requested by Client
                in order to ensure Client can comply with Data Protection Laws.

         4.     TECHNICAL/ORGANISATIONAL MEASURES
         4.1    In relation to the Processing of Personal Data, Bazaarvoice shall implement and maintain, at its cost and expense, a suitable
                information security program taking into account the state of art, the costs of implementation and the nature, scope, context
                and purposes of Processing the Personal Data as well as the risk of varying likelihood and severity for the rights and freedoms
                of the Clients Users. Such program shall include technical and organisational measures no less stringent than those set out in
                Schedule 2.
         4.2    Technical and organisational measures are subject to technical advancements and future developments. Bazaarvoice is,
                therefore, permitted to make use of adequate alternate measures in this respect. Such alternate measures may not, however,
                fall below the level of security stipulated in the Data Protection Laws for these measures. Substantive changes shall be properly
                documented and notified to Client.

         5.     SUB-PROCESSORS
         5.1    The provision of the Services by Bazaarvoice requires the use of Subprocessors. Client hereby authorizes Bazaarvoice to use
                the sub-processors listed under Schedule 3.
         5.2    Bazaarvoice shall expressly notify the Client in writing at least 14 days in advance of any intended changes concerning the
                inclusion or replacement of Subprocessors and the Client shall be given the opportunity to object to such changes for material
                reasons.
         5.3    Bazaarvoice shall impose obligations on all Subprocessors by way of a contract or other legally binding agreement that provide
                at least substantially the same level of protection for the Personal Data Processed under this DPA as the obligations provided
                for in this DPA, in particular by providing safeguards for the implementation of appropriate technical and organizational
                measures so that the Processing complies with the requirements of (i) this DPA and (ii) the Data Protection Laws. If the
                Subprocessor fails to comply with its data protection obligations, Bazaarvoice shall remain fully liable to the Client for the
                performance of the Subprocessor's obligations.
         5.4    If the Client is located in the EEA or Switzerland and Bazaarvoice uses a Subprocessor in a third country where an adequate
                level data protection is not ensured, Bazaarvoice will provide Appropriate Safeguards in relation to the Subprocessor.
         5.5    Services that Bazaarvoice uses from third parties as a purely ancillary service in order to carry out its business activities are
                not considered subcontracting relationships. This includes, for example, cleaning services, pure telecommunication services
                without concrete reference to services that Bazaarvoice provides for the Client, postal and courier services, transport services,
                guarding services. Bazaarvoice is nevertheless obliged, also in case of ancillary services provided by third parties, to ensure
                that adequate precautions and technical and organizational measures have been taken to ensure the protection of personal
                data. The maintenance and servicing of IT systems or applications shall constitute subprocessing under this DPA and a
                subcontracting relationship requiring consent if the maintenance and servicing concern such IT systems that are also used in

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                                                                              Page 4 of 15
DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

                connection with the provision of services for the Client and personal data processed on behalf of the Client can be accessed
                during the maintenance.

         6.     INTERNATIONAL DATA TRANSFERS
         6.1    The provision of the Services under the Principal Agreement may require the transfer or processing of the Personal Data
                processed under the Service Order. For the purposes of GDPR, this will mean that data is transferred to third countries outside
                the EEA, including but not limited to the United Kingdom and Switzerland.
         6.2    The Parties agree that the terms of the Standard Contractual Clauses Module Two (Controller to Processor) and Module Three
                (Processor to Processor) apply to any transfers of Customer Personal Data falling within the scope of the GDPR from Customer
                (as data exporter) to Bazaarvoice (as data importer) as specified below:
                (a) Module Two shall apply in instances where Customer functions as a controller, whereas Bazaarvoice functions as a
                processor. Module Three shall apply in the case where Customer functions as a processor on behalf of Customer’s customers
                where Customer and Customer’s customer have concluded a data processing agreement in relation to the processing of
                personal data of Customer’s customers.
                (b) To the extent that the processing of Customer Personal Data is subject to UK data protection laws, the UK Addendum set
                out in Schedule 4 shall apply.
         6.3    The Standard Contractual Clauses shall apply as follows:
                (a)     Annex I.A (List of Parties) shall be deemed to be Client, Client Affiliate, and Bazaarvoice;
                (b)     Annex I.B (Description of Transfer) shall be deemed to incorporate the information in Schedule 1;
                (c)     Annex I.C (Competent Supervisory Authority) shall be deemed to refer to the supervisory authority of Bavaria,
                        Germany (BayLDA) in the EEA and the ICO in the UK;
                (d)     Annex II (Technical and Organisational Measures) shall be deemed to incorporate the information in Schedule 2;
                (e)     in Clause 7, the optional docking clause shall apply;
                (f)     or the purposes of Clause 8.1 (a), the Principal Agreement and this DPA shall be the Client's final instructions for the
                        processing of Client Personal Data;
                (g)     for the purposes of Clause 9 of the Standard Contractual Clauses, the Client gives Bazaarvoice the general authorisation
                        to engage sub-processors from an agreed list and Schedule 3 sets out the list of sub-processors agreed by the Parties
                        and the time period fpr information in advance of any intended changes to the list through the addition or replacement
                        of sub-processors shall be at least 14 days.
                (h)     in Clause 11, the optional language shall not apply;
                (i)     the certification of deletion described in Clause 16 (d) shall be provided by Bazaarvoice to Client upon Client's written
                        request;
                (j)     for the purposes of Clause 15 (1) (a), Bazaarvoice shall notify Client and not the relevant data subject(s) in case of
                        government access requests, and Client shall be solely responsible for notifying the relevant data subjects as
                        necessary;
                (k)     in Clause 17, option 1 shall apply and the Standard Contractual Clauses shall be governed by German law; and
                (l)     in Clause 18 (b), disputes shall be resolved before the courts of Munich, Germany;
         6.4    In the event of any conflict between the applicable Standard Contractual Clauses and the main body of this DPA, the provisions
                of the applicable Standard Contractual Clauses shall prevail. Any conflict between the terms of the Standard Contractual
                Clauses and the UK Addendum will be resolved in accordance with Section 10 and Section 11 of the UK Addendum.

         7.     AUDIT
         7.1    Bazaarvoice uses external auditors to validate the adequacy of its security standards and controls (Bazaarvoice Audit).
                Bazaarvoice Audit activities: (i) will be performed by Bazaarvoice no more than once per annum; (ii) will be performed by
                independent third-party security professionals at Bazaarvoice's selection and expense; and (iii) will result in the generation of
                an audit report (Audit Report), which will be deemed Bazaarvoice’s confidential information.
         7.2    At Client's written request, Bazaarvoice will provide Client with the Audit Report summarizing the elements set forth in Section
                7.1 above so that Client can reasonably verify Bazaarvoice's compliance with its obligations under this DPA.
         7.3    In accordance with Clause 3.1 (g) and to the extent required by Data Protection Laws, including where mandated by Client’s
                Supervisory Authority, the Client or Client’s Supervisory Authority may perform an audit (collectively, “Client Audit”) subject

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                                                                            Page 5 of 15
DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

                to Bazaarvoice will contribute to such Client Audits by providing Client or Client’s Supervisory Authority with the information
                and assistance reasonably necessary to conduct the Client Audit, including any relevant records of Processing activities
                applicable to the Services. Provided always that the Client:
                (a)     notifies Bazaarvoice in writing with reasonable notice (not less than 30 working days) that such request for
                        information, audit and/or inspection is required by Client;
                (b)     that where a third party is engaged to conduct an audit that said third party signs a Bazaarvoice NDA;
                (c)     that parties mutually agree the scope of any such Client Audit;
                (d)     ensures that all information received or generated by the Client or its auditor(s) in connection with the requests for
                        information, inspections and audits is kept strictly confidential (except for disclosure to the Supervisory Authority or
                        as otherwise required under the Data Protection Laws) and;
                (e)     ensures that the audit or inspection takes place during normal business hours and causes as little disruption as possible
                        to the business operations of Bazaarvoice, the business operations of the Sub-processors and the business operations
                        of any other clients of Bazaarvoice, and provided that no more than one such audit or inspection shall be conducted
                        in any 12-month period, unless required by a competent regulatory authority.
                For the avoidance of doubt any external penetration testing of any of Bazaarvoice’ s systems is strictly prohibited.
         7.4    If a third party is to conduct the Client Audit, the third party must be approved by Bazaarvoice (except if such third party is a
                competent Supervisory Authority). Bazaarvoice will not unreasonably withhold its consent to a third-party auditor requested
                by Client. The third party must execute a written confidentiality agreement acceptable to Bazaarvoice or otherwise be bound
                by a statutory confidentiality obligation before conducting the Client Audit.
         7.5    Client will provide Bazaarvoice any audit reports generated in connection with any Client Audit, unless prohibited by
                Applicable Law or otherwise instructed by a Supervisory Authority. Client may use the audit reports only for the purposes of
                meeting Client’s regulatory audit requirements and/or confirming compliance with the requirements of this DPA. The audit
                reports are Confidential Information of Bazaarvoice under the terms of the Principal Agreement.
         7.6    Any Client Audits are at Client’s sole expense. The parties will negotiate in good faith with respect to any charges or fees that
                may be incurred by Bazaarvoice to provide assistance with a Client Audit that requires the use of resources different from or
                in addition to those required for the provision of the Services.

         8.     REPORTING VIOLATIONS
         8.1    Bazaarvoice shall in all cases notify the Client, without undue delay and where feasible not later than 48 hours after becoming
                aware, of any Personal Data Breach or any breach of the specifications set down in the Principal Agreement, and provide the
                Client with details of any Personal Data Breach. Such notification shall at least:
                (a)     describe the nature of the Personal Data Breach including where possible, the categories and approximate number of
                        data subjects concerned and the categories and approximate number of personal data records concerned;
                (b)     communicate the name and contact details of the Data Protection Officer or other contact point where more
                        information can be obtained;
                (c)     describe the measures taken or proposed to be taken by the processor to address the Personal Data Breach, including,
                        where appropriate, measures to mitigate its possible adverse effects.
                Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in
                phases without undue further delay.
         8.2    It is recognized that, pursuant to Data Protection Laws, an obligation to provide information may exist in the event that
                Personal Data is lost or unlawfully accessed/disclosed. Therefore, the Client should be notified of such incidents, regardless of
                the cause. This also applies to serious disruptions in operations or other irregularities in handling the Client’s Personal Data.
                In cooperation with the Client, Bazaarvoice shall take appropriate steps to secure the data and mitigate possible negative
                effects on the affected parties.

         9.     DELETING DATA
         9.1    Should the Client issue a deletion instruction in writing to Bazaarvoice, the latter is thereby authorized and obligated to
                commence the permanent deletion no later than one week after receipt of such instruction unless Data Protection Laws
                require storage of the Personal Data.
         9.2    Bazaarvoice will commence permanent deletion of the Client’s Personal Data upon expiry or termination of the Principal
                Agreement.

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                                                                            Page 6 of 15
DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

         9.3    Documentation which serves to provide proof that data Processing occurred properly and pursuant to contract shall be
                retained by Bazaarvoice beyond the term of the Principal Agreement in accordance with the appropriate retention schedules.
         9.4    For the avoidance of doubt, Client acknowledges and agrees that as in accordance with Art. 6 (1) lit. f) GDPR Bazaarvoice
                retains the right to retain key elements of the Personal Data (“Key Data”) collected and processed in connection with Services
                for the purposes of anti-fraud monitoring as laid out under the Authenticity Policy which can be found at the page:
                www.bazaarvoice.com/legal/authenticity-policy.
         9.5    For the purposes of the Agreement and this Section 9, “Key Data” means any personal data including but not limited to “Author
                IP address” and “Author Device Fingerprint” that is required strictly for the purposes of anti-fraud and authenticity services
                that are a mandatory requirement of the Bazaarvoice Services.

         10.    UNITED STATES PRIVACY LAWS
         10.1   Client discloses Personal Data to Bazaarvoice for a business purpose.
         10.2   Bazaarvoice is prohibited from: (i) selling Client’s Personal Data; (ii) retaining, using, or disclosing Client’s Personal Data for
                any purpose other than for the specific purpose of performing the Services specified in the Principal Agreement; (iii) retaining,
                using, or disclosing Client’s Personal Data outside of the Principal Agreement or direct business relationship between Client
                and Bazaarvoice and (iv) combining or updating Personal Information it receives from or on behalf of Client with Personal
                Information that it received from another source except as permitted by Data Protection Laws or as directed by Client.
         10.3   Certification. By signing this DPA, Bazaarvoice hereby certifies that in receiving Client’s Personal Data, Bazaarvoice
                understands the requirements and restrictions associated with its status as a Service Provider, and shall comply with the
                applicable requirements set forth in the Data Protection Laws in effect in the United States and any implementing regulations.
         10.4   For the purpose of this Section 6, the terms “consumer”, “commercial purpose” and “sale” shall have the meaning given to
                them by the CCPA.

         11.    LIABILITY
                The liability of each party under this DPA shall be subject to the exclusions and limitations of liability set out in the Principal
                Agreement. Any reference to “limitation of liability” of a party in the Principal Agreement shall be read to mean the aggregate
                liability of a party and all of its Affiliates under the Principal Agreement and this DPA.

         12.    GENERAL PROVISIONS
         12.1   The Processing of Personal Data under this DPA is governed by the law of the Principal Agreement and supersedes and replaces
                any prior agreements in respect of the processing of personal data. Any disputes between the parties relating to the Processing
                of Personal Data under this DPA will be subject to the exclusive jurisdiction of the courts set forth in the Principal Agreement.
         12.2   With respect to the subject matter described above, this DPA, including the Annexes attached hereto, constitutes the entire
                agreement between the parties and supersedes all prior communications, representations, understandings, and agreements,
                whether oral, electronic or written.
         12.3   To the extent of inconsistencies between the provisions of this DPA and other agreements between the parties, including but
                not limited to the Principal Agreement, the provisions of this DPA shall prevail. In cases of doubt, this DPA shall prevail, in
                particular, where it cannot be clearly established whether a clause relates to a party's data protection obligations.
         12.4   This DPA may only be modified by a written amendment signed by authorized representatives of each of the parties.
         12.5   This DPA will become effective as of the date the parties have executed it and, notwithstanding expiry of the term of the
                Principal Agreement, will remain in effect until, and will automatically expire upon, deletion of all Personal Data by Bazaarvoice
                and/or any applicable Subprocessors.
         12.6   Unless stated otherwise, each party shall perform its obligations under this DPA at its own cost.
         12.7   If any provision of this DPA is found by any court or administrative body of competent jurisdiction to be invalid or
                unenforceable, the invalidity or unenforceability of such provision shall not affect any other provision of this DPA and all
                provisions not affected by such invalidity or unenforceability will remain in full force and effect.

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                                                                              Page 7 of 15
DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

         SCHEDULE 1: DETAILS OF PROCESSING
         Categories of data subjects whose personal data is processed/transferred:
         Client’s customers and users of Client’s products and services and visitors of Client’s websites
         Categories of personal data transferred:
         user email address, user IP address, user device fingerprint, timestamp, user-generated content
         Sensitive data transferred:
         None (unless any sensitive data is contained in the user-generated content)
         Frequency of the transfer:
         continuously during the term of the contract
         Nature of the processing:
         Provision of a software platform (software as a service) that enables Client to collect, display, and distribute user-
         generated content, as defined in further detail in the Principal Agreement and the respective Service Orders
         Purpose(s) of the data transfer and further processing:
         Fulfilment of a contract for the use of the Bazaarvoice software platform
         Duration for which the personal data will be stored or, if this is not possible, the criteria for determining this duration:
         Duration of the contract
         In the case of data transfers to (sub)processors, the subject, type and duration of the processing shall also be
         indicated:
         For transfers to sub-processors, specify subject matter, nature and duration of the processing: as set out in Schedule 3.
         Competent supervisory authority:
         The data protection supervisory authority of Bavaria, Germany (Bayerische Landesamt für Datenschutzaufsicht).

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                                                                  Page 8 of 15
DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

         SCHEDULE 2: TECHNICAL AND ORGANISATIONAL MEASURES
         Minimum technical and organisational measures implemented by Bazaarvoice for the security and protection of
         Personal Data:
         1.     Measures for the Prevention of Unauthorised Access to Commercial Premises and Installations Used for
                Processing Personal Data
                • Physical access to corporate sites is controlled via badge access, which are to be present with the employee
                  at all times. All employees and contractors requiring physical access to a site receive this access during the
                  New Hire Onboarding process controlled by People Operations, and upon separation from the company, a
                  termination process also owned by People Operations revokes badge/key authority.
                • Vendors, contractors, and other visitors requiring temporary access to a site are required to register at the
                  front desk where a badge is issued allowing access to only main office areas and they are controlled and
                  monitored. Visitors have to register at the front desk, are issued a temporary visitor identification tag, and
                  are to be always escorted.
                • Physical access to critical IT areas is restricted to those with a legitimate business need. Systems and data
                  processing is hosted in a vetted and top industry cloud hosting provider.
         2.     Measures for the Prevention of Unauthorised Access to IT Systems
                • Unique accounts and logons are required for users’ daily activity.
                • Passwords are to be at least 8 characters long and comply with at least three of the four complexity
                  requirements.
                • Two-factor authentication is required for user login to the network.
                • Access to IT systems (network equipment, devices, servers, and applications) is controlled by the Bazaarvoice
                  Information Security Policy
                • Remote access to Bazaarvoice corporate infrastructure is controlled via Virtual Private Network, using two-
                  factor authentication. Access to VPN is granted for Bazaarvoice employees, is controlled via Active Directory
                  and managed by People Operations New Hire/Termination processes.
                • Bazaarvoice wireless network is secured according to industry standards and leverages a minimum of 128 bit
                  key. Two wireless networks are provided, one for guest access with a published password on the intranet,
                  and one for employees with access to corporate network where access is pre-configured by IT personnel on
                  authorized equipment.
         3.     Data Access Controls Measures
                • Authorised users only have access to data which are in their area of responsibility and, where Processing
                  Personal Data, that these data cannot be read, copied, changed or deleted without appropriate authorisation.
                • Employees working in the operational area only are authorised to access the database and administer it, and
                  also to modify and delete data. The logins and all database accesses of all employees working in the
                  operational area are logged.
                • The implementation engineer assigned to the client has access to the client data and can view and process
                  these, but only using tools from Bazaarvoice and not via the interface of the database management system.
                  All changes to the data made using these tools are logged.
         4.     Disclosure Control Measures
                • The data in the Bazaarvoice databases are protected during transfer between the Data Controller and
                  Bazaarvoice using TLS encryption.
                • The token assigned uniquely to a user and used to identify the user is encoded before transfer to Bazaarvoice
                  using a unique, client-specific token which is supplied to the client as a key.
         5.     Input Control Measures
                • The administration tasks performed on servers are logged by the Operations Department, including the bash
                  and login history.

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                                                             Page 9 of 15
DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

                • Data manipulations including addition, deletion, approval or rejection of content data are logged using
                  Bazaarvoice's content moderation system.
                • Logging of data changes is also performed via the Bazaarvoice Workbench portal tool.
         6.     Job Control Measures
                Measures to ensure that personal data are only processed on behalf of the Controller on the express instruction
                of the Controller:
                • Background checks are performed on all new employees, as permitted by local laws.
                • There are mandatory training courses, including data protection and information security for new employees.
                • New employees have only limited access rights until the training measures have been completed during the
                  first week of employment.
                • Secure coding training is required for all personnel who develop code.
                • All development work is inspected in accordance with the peer review Principal, ensuring that all system
                  changes are reviewed in advance by two people.
                • A violation of the company's protocols and procedures, results in immediate sanctions up to and including
                  the withdrawal of all access rights and, where appropriate, termination.
         7.     Availability Control Measures:
                • Bazaarvoice maintains a Business Continuity Program which applies to processes critical to Bazaarvoice
                  operations.
                • Appropriate availability controls and processes are in place to ensure availability of operations in the cloud
                  hosting environment.
                • Virus protection is required on all desktop and laptop computers in the Bazaarvoice network.
                • The server environment is predominantly linux-based; additional controls are in place, such as web
                  application firewalls, system hardening, patch management and reduced access controls to protect the
                  production environment.
                • All source code, build, and configuration elements are managed in a source code repository
         8.     Security Testing and Evaluation Measures:
                • Internal and external vulnerability scans are performed no less than quarterly by the Bazaarvoice Security
                  team. The results are documented, reviewed by the Information Security Officer (ISO) and prioritised by the
                  cross-organisational Security Leadership Team. Critical and high findings are closed within 30 days pending
                  environmental impact, and informational findings are acted upon on a case by case basis in line with Risk
                  Management processes.
                • An external penetration test is performed annually by a third party. The results are documented, reviewed
                  by the ISO and prioritized by the cross-organisation Security leadership team. Findings and remediation plans
                  are documented and resolved within timelines per severity.
         9.     Separation Control Measures:
                • Client data is logically separated and stored using a unique customer ID. A client will under no circumstances
                  be able to access data of other clients.
                • Due to the nature of their role, employees of the operations department have access to client data in order
                  to troubleshoot and support client needs as they arise.
                • Implementation engineers only have access to the data related to projects for which they are responsible,
                  and only via tools supplied by Bazaarvoice.

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                                                            Page 10 of 15
DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

         SCHEDULE 3: SUB-PROCESSORS
         The controller has authorised the use of the sub-processors listed at:
         https://knowledge.bazaarvoice.com/wp-content/knowledge/en_US/vendorlist.html

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                             Page 11 of 15
DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

         SCHEDULE 4: UK ADDENDUM
         Standard Data Protection Clauses to be issued by the Commissioner under S119A(1) Data Protection Act 2018
         International Data Transfer Addendum to the EU Commission Standard Contractual Clauses
         This Addendum has been issued by the Information Commissioner for Parties making Restricted Transfers. The Information
         Commissioner considers that it provides Appropriate Safeguards for Restricted Transfers when it is entered into as a legally binding
         contract.
         Part 1: Tables
         Table 1: Parties

          Start Date                      The start date of this Data Transfer Addendumshall be the DPA Effective Date.
          Parties’ Details                The Exporter and Importer details shall be the Client and Bazaarvoice, as specified above.
          Key Contact                     The Exporter and Importer key contacts shall be as defined above (on top of the DPA)

         Table 2: Selected SCCs, Modules and Selected Clause

          Addendum EU SCCs

         Table 3: Appendix Information
         “Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the
         Approved EU SCCs (other than the Parties), and which for this Addendum is set out in:

          Annex 1A: List of Parties                                                     Listed above
          Annex 1B: Description of Transfer                                             See Schedule 1 above
          Annex II: Technical and organisational measures including technical and       See Schedule 2 above
          organisational measures to ensure the security of the data
          Annex III: List of Sub processors                                             See Schedule 3 above

         Table 4: Ending this Addendum when the Approved Addendum Changes

          Ending this Addendum when the Approved Addendum changes                       Neither Party may end this Addendum as set out in
                                                                                        Section 19.

         Part 2: Mandatory Clauses
         Entering into this Addendum
         1.     Each Party agrees to be bound by the terms and conditions set out in this Addendum, in exchange for the other Party also
                agreeing to be bound by this Addendum.
         2.     Although Annex 1A and Clause 7 of the Approved EU SCCs require signature by the Parties, for the purpose of making
                Restricted Transfers, the Parties may enter into this Addendum in any way that makes them legally binding on the Parties
                and allows data subjects to enforce their rights as set out in this Addendum. Entering into this Addendum will have the same
                effect as signing the Approved EU SCCs and any part of the Approved EU SCCs.
         Interpretation of this Addendum
         3.     Where this Addendum uses terms that are defined in the Approved EU SCCs those terms shall have the same meaning as in
                the Approved EU SCCs. In addition, the following terms have the following meanings:

          Addendum                                     This International Data Transfer Addendum which is made up of this Addendum
                                                       incorporating the Addendum EU SCCs.
          Addendum EU SCCs                             The version(s) of the Approved EU SCCs which this Addendum is appended to, as set
                                                       out in Table 2, including the Appendix Information.
          Appendix Information                         As set out in Table 3.

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                                                                            Page 12 of 15
DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

          Appropriate Safeguards                       The standard of protection over the personal data and of data subjects’ rights, which
                                                       is required by UK Data Protection Laws when you are making a Restricted Transfer
                                                       relying on standard data protection clauses under Article 46(2)(d) UK GDPR.
          Approved Addendum                            The template Addendum issued by the ICO and laid before Parliament in accordance
                                                       with s119A of the Data Protection Act 2018 on 28 January 2022, as it is revised under
                                                       Section 18.
          Approved EU SCCs                             The Standard Contractual Clauses set out in the Annex of Commission Implementing
                                                       Decision (EU) 2021/914 of 4 June 2021.
          ICO                                          The Information Commissioner.
          Restricted Transfer                          A transfer which is covered by Chapter V of the UK GDPR.
          UK                                           The United Kingdom of Great Britain and Northern Ireland.
          UK Data Protection Laws                      All laws relating to data protection, the processing of personal data, privacy and/or
                                                       electronic communications in force from time to time in the UK, including the UK
                                                       GDPR and the Data Protection Act 2018.
          UK GDPR                                      As defined in section 3 of the Data Protection Act 2018.

         4.     This Addendum must always be interpreted in a manner that is consistent with UK Data Protection Laws and so that it fulfils
                the Parties’ obligation to provide the Appropriate Safeguards.
         5.     If the provisions included in the Addendum EU SCCs amend the Approved SCCs in any way which is not permitted under the
                Approved EU SCCs or the Approved Addendum, such amendment(s) will not be incorporated in this Addendum and the
                equivalent provision of the Approved EU SCCs will take their place.
         6.     If there is any inconsistency or conflict between UK Data Protection Laws and this Addendum, UK Data Protection Laws
                applies.
         7.     If the meaning of this Addendum is unclear or there is more than one meaning, the meaning which most closely aligns with
                UK Data Protection Laws applies.
         8.     Any references to legislation (or specific provisions of legislation) means that legislation (or specific provision) as it may
                change over time. This includes where that legislation (or specific provision) has been consolidated, re-enacted and/or
                replaced after this Addendum has been entered into.
         Hierarchy
         9.     Although Clause 5 of the Approved EU SCCs sets out that the Approved EU SCCs prevail over all related agreements between
                the parties, the parties agree that, for Restricted Transfers, the hierarchy in Section 10 will prevail.
         10.    Where there is any inconsistency or conflict between the Approved Addendum and the Addendum EU SCCs (as applicable),
                the Approved Addendum overrides the Addendum EU SCCs, except where (and in so far as) the inconsistent or conflicting
                terms of the Addendum EU SCCs provides greater protection for data subjects, in which case those terms will override the
                Approved Addendum.
         11.    Where this Addendum incorporates Addendum EU SCCs which have been entered into to protect transfers subject to the
                General Data Protection Regulation (EU) 2016/679 then the Parties acknowledge that nothing in this Addendum impacts
                those Addendum EU SCCs.
         Incorporation of and changes to the EU SCCs
         12.    This Addendum incorporates the Addendum EU SCCs which are amended to the extent necessary so that:
                a.      together they operate for data transfers made by the data exporter to the data importer, to the extent that UK Data
                        Protection Laws apply to the data exporter’s processing when making that data transfer, and they provide
                        Appropriate Safeguards for those data transfers;
                b.      Sections 9 to 11 override Clause 5 (Hierarchy) of the Addendum EU SCCs; and
                c.      this Addendum (including the Addendum EU SCCs incorporated into it) is (1) governed by the laws of England and
                        Wales and (2) any dispute arising from it is resolved by the courts of England and Wales, in each case unless the laws
                        and/or courts of Scotland or Northern Ireland have been expressly selected by the Parties.
         13.    Unless the Parties have agreed alternative amendments which meet the requirements of Section 12, the provisions of Section
                15 will apply.

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                                                                         Page 13 of 15
DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

         14.    No amendments to the Approved EU SCCs other than to meet the requirements of Section 12 may be made.
         15.    The following amendments to the Addendum EU SCCs (for the purpose of Section 12) are made:
                a.      References to the “Clauses” means this Addendum, incorporating the Addendum EU SCCs;
                b.      In Clause 2, delete the words: “and, with respect to data transfers from controllers to processors and/or processors
                        to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679”;
                 c.     Clause 6 (Description of the transfer(s)) is replaced with: “The details of the transfers(s) and in particular the
                        categories of personal data that are transferred and the purpose(s) for which they are transferred) are those specified
                        in Annex I.B where UK Data Protection Laws apply to the data exporter’s processing when making that transfer.”;
                 d.     Clause 8.7(i) of Module 1 is replaced with: “it is to a country benefitting from adequacy regulations pursuant to
                        Section 17A of the UK GDPR that covers the onward transfer”;
                 e.     Clause 8.8(i) of Modules 2 and 3 is replaced with: “the onward transfer is to a country benefitting from adequacy
                        regulations pursuant to Section 17A of the UK GDPR that covers the onward transfer;”
                 f.     References to “Regulation (EU) 2016/679”, “Regulation (EU) 2016/679 of the European Parliament and of the Council
                        of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free
                        movement of such data (General Data Protection Regulation)” and “that Regulation” are all replaced by “UK Data
                        Protection Laws”. References to specific Article(s) of “Regulation (EU) 2016/679” are replaced with the equivalent
                        Article or Section of UK Data Protection Laws;
                 g.     References to Regulation (EU) 2018/1725 are removed;
                 h.     References to the “European Union”, “Union”, “EU”, “EU Member State”, “Member State” and “EU or Member State”
                        are all replaced with the “UK”;
                 i.     The reference to “Clause 12(c)(i)” at Clause 10(b)(i) of Module one, is replaced with “Clause 11(c)(i)”;
                 j.     Clause 13(a) and Part C of Annex I are not used;
                 k.     The “competent supervisory authority” and “supervisory authority” are both replaced with the “Information
                        Commissioner”;
                 l.     In Clause 16(e), subsection (i) is replaced with: “the Secretary of State makes regulations pursuant to Section 17A of
                        the Data Protection Act 2018 that cover the transfer of personal data to which these clauses apply;”;
                 m.     Clause 17 is replaced with: “These Clauses are governed by the laws of England and Wales.”;
                 n.     Clause 18 is replaced with: “Any dispute arising from these Clauses shall be resolved by the courts of England and
                        Wales. A data subject may also bring legal proceedings against the data exporter and/or data importer before the
                        courts of any country in the UK. The Parties agree to submit themselves to the jurisdiction of such courts.”; and
                 o.     The footnotes to the Approved EU SCCs do not form part of the Addendum, except for footnotes 8, 9, 10 and 11.
         Amendments to this Addendum
         16.    The Parties may agree to change Clauses 17 and/or 18 of the Addendum EU SCCs to refer to the laws and/or courts of Scotland
                or Northern Ireland.
         17.    If the Parties wish to change the format of the information included in Part 1: Tables of the Approved Addendum, they may
                do so by agreeing to the change in writing, provided that the change does not reduce the Appropriate Safeguards.
         18.    From time to time, the ICO may issue a revised Approved Addendum which:
                a.      makes reasonable and proportionate changes to the Approved Addendum, including correcting errors in the
                        Approved Addendum; and/or
                b.      reflects changes to UK Data Protection Laws;
                The revised Approved Addendum will specify the start date from which the changes to the Approved Addendum are effective
                and whether the Parties need to review this Addendum including the Appendix Information. This Addendum is automatically
                amended as set out in the revised Approved Addendum from the start date specified.
         19.    If the ICO issues a revised Approved Addendum under Section 18, if any Party selected in Table 4 “Ending the Addendum
                when the Approved Addendum changes”, will as a direct result of the changes in the Approved Addendum have a substantial,
                disproportionate and demonstrable increase in:
                a.      its direct costs of performing its obligations under the Addendum; and/or

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                                                                          Page 14 of 15
DocuSign Envelope ID: 5849B063-5F11-4C8C-8195-F3359294234E

                b.      its risk under the Addendum, and in either case it has first taken reasonable steps to reduce those costs or risks so
                        that it is not substantial and disproportionate, then that Party may end this Addendum at the end of a reasonable
                        notice period, by providing written notice for that period to the other Party before the start date of the revised
                        Approved Addendum.
         20.    The Parties do not need the consent of any third party to make changes to this Addendum, but any changes must be made
                in accordance with its terms.

          Bazaarvoice, Inc.
          Data Processing Addendum 20221007                                                                                        Page 15 of 15