Snapshot 81527
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Privacy Terms Service Provider Data Processing Addendum (Controller-Processor) Last Updated: December 23, 2025 This Data Processing Addendum (“Addendum”) is made part of the Agreement (“Agreement”) entered into by and between Ramp Business Corporation (“Ramp”) and Provider (“Service Provider”), each a “party” and together the “parties.” This Addendum may be modified or amended only in writing signed by both parties. In the event of any conflict or inconsistency between this Addendum and the Agreement, the provision of this Addendum will control. Capitalized terms used, but not otherwise defined in this Addendum have the meaning provided in the Agreement. 1. Definitions Permanent link: 1. Definitions a. “Data Protection Law” means any laws, rules, or regulations in effect relating to the Processing of Personal Data that are applicable to a party in the performance of its obligations under the Agreement, including, but not limited to: (1) California Civil Code Section 1798.100 et seq. (“CCPA”); (2) Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (“GDPR”), the GDPR as applicable in the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018, the UK Data Protection Act 2018 (“UK GDPR”), and the Swiss Federal Data Protection Act (“FADP”); and (3) Canada’s Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (“PIPEDA”). b. “Personal Data” means any data Processed by Service Provider, its Subprocessors, or their subprocessors in connection with the Agreement or this Addendum that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual, household, or device, or that is personal data, personal information, or similarly protected data as ascribed under Data Protection Law. c. “Process” means any operation or set of operations that are performed on Personal Data or on sets of personal information, whether or not by automated means. d. “Restricted Transfer” means, where GDPR, UK GDPR, or FADP applies, a transfer of Personal Data from the European Economic Area, Switzerland or the United Kingdom (as applicable) to a country outside of the European Economic Area, Switzerland or the United Kingdom (as applicable) which is not subject to (a) an adequacy determination by the European Commission, the Swiss Federal Data Protection or the Information Commissioner (as applicable), or, (b) where the UK GDPR applies, adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018. e. “Services” has the meaning set out in the Agreement, and if not set out therein, means the services provided to Ramp pursuant to the Agreement. f. “Standard Contractual Clauses” or “SCC” means, as applicable: (1) the standard contractual clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj) (the “EU SCCs”); (2) the EU SCCs with appropriate references to the Swiss Federal Act on Data Protection (FADP) (and, where applicable, the term “member state” must not be interpreted in such a way as to exclude individuals in Switzerland from the possibility of suing to enforce their rights in their place of habitual residence); and (3) the EU SCCs with the International Data Transfer Addendum to the EU SCCs, issued by the Information Commissioner and laid before Parliament in accordance with s.119A of the Data Protection Act 2018 on 2 February 2022 available at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf) (the “UK Addendum”) appended. g. “Subprocessor” means any person or entity that Processes Personal Data for or on behalf of Service Provider in connection with the Agreement. Where applicable, the terms “controller,” “business,” “processor,” “service provider,” “contractor,” “data subject,” “consumer,” “sell,” “share,” “business purpose,” “commercial purpose,” “subprocessor,” “supervisory authority,” and “third-party” (or any equivalent terms) shall have the meaning ascribed to them under the relevant Data Protection Law. 2. Data Processing Permanent link: 2. Data Processing a. This Addendum applies to Personal Data Processed by Service Provider, its Subprocessors, or their subprocessors. Where Ramp acts as a controller or business, Service Provider is a processor or service provider to Ramp, and where Ramp acts as a processor, service provider, or contractor to another person, Service Provider is a subprocessor. b. Ramp hereby instructs Service Provider to Process Personal Data only in accordance with Ramp’s written instructions, including as set out in the Agreement and this Addendum and only for the business purposes specified in the Agreement. Ramp discloses Personal Data to Service Provider only for these limited purposes. If Service Provider must Process Personal Data as otherwise required by applicable law, Service Provider must inform Ramp of that legal requirement before Processing Personal Data, unless prohibited by applicable law. c. Service Provider must not: (1) sell or share Personal Data; (2) retain, use, or disclose Personal Data for any purpose other than for the business purposes specified in the Agreement, including retaining, using, or disclosing Personal Data for a commercial purpose other than the business purposes specified in the Agreement, or as otherwise permitted by Data Protection Law; (3) retain, use, or disclose Personal Data outside of the direct business relationship between Service Provider and Ramp; or (4) combine Personal Data with Personal Data that it receives from, or on behalf of, another person or persons, or collects from its own interaction with an individual. 3. Security and Compliance Permanent link: 3. Security and Compliance a. Service Provider must comply with Data Protection Law, must provide at least the same level of security for Personal Data protection as is required by Data Protection Law, and must not cause Ramp to violate Data Protection Law. Service Provider must promptly notify Ramp if Service Provider determines that it can no longer meet its obligations under Data Protection Law. b. Service Provider must implement and maintain a comprehensive, written information security program that includes appropriate technical and organizational measures designed to ensure the protection, confidentiality, and integrity of Personal Data. Service Provider’s information security program must comply with applicable law and include, at a minimum, policies, standards, or procedures that address: (1) information security; (2) data governance, classification, and retention; (3) asset inventory, device management, and end-of-life management; (4) access controls, including remote access and identity management; (5) business continuity and disaster recovery; (6) information system availability and back-ups; (7) security awareness and training; (8) system and application security and privacy-by-design; (9) physical security and environmental controls, as applicable; (10) Personal Data handling; (11) supply chain risk management; (12) risk assessments; (13) security incident management and notification; and (14) vulnerability and patch management. Further, Service Provider must, at a minimum, implement and maintain the technical and organizational measures in Annex 2. Service Provider must regularly monitor compliance with those measures. c. Service Provider grants Ramp the right to take reasonable and appropriate steps to help ensure that Service Provider uses Personal Data in accordance with Data Protection Law and the Agreement and, upon reasonable notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data. Service Provider shall ensure that persons authorized to carry out Processing have committed themselves to confidentiality or are under the appropriate statutory obligation of confidentiality. Service Provider shall preserve Personal Data in accordance with Ramp instructions and requests, including any retention schedules and/or litigation hold orders provided by Ramp to Service Provider, independent of where the Personal Data is stored. 4. Security Incidents Permanent link: 4. Security Incidents In the event of any actual or reasonably suspected accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure of, or access to Personal Data, other confidential information, or information systems made available to Service Provider or its Subprocessors by or on behalf of Ramp (“Security Incident”), Service Provider must, at its own expense: (1) provide prompt written notice to Ramp no more than forty-eight (48) hours following discovery of the Security Incident; (2) use best efforts and take all necessary actions to prevent, contain, and mitigate the impact of the Security Incident; (3) collect, preserve, and document all evidence concerning the discovery, cause, vulnerability, remedial actions and impact related to such Security Incident, which shall meet reasonable expectations of forensic admissibility; and (4) fully cooperate with Ramp and its designees for purposes of Security Incident response. If requested by Ramp, providing notice to individuals or entities whose Personal Data was or may have been affected in a manner and format specified by Ramp. The content of any filings, communications, notices, press releases or reports related to any Security Incident must be approved by Ramp in writing prior to their publication or communication unless prohibited by law. Service Provider will be responsible for and will reimburse Ramp for all costs (including reasonable attorney’s fees) incurred by Ramp in connection with any such Security Incident. 5. Subprocessors Permanent link: 5. Subprocessors a. Ramp provides general written authorization for Service Provider’s use of the Subprocessors identified in the Agreement. Service Provider must not disclose or otherwise make available Personal Data to any potential or actual Subprocessors without first: (1) conducting a reasonable investigation of the recipient’s safeguards to ensure such safeguards at least meet the requirements the Subprocessors must follow under this Addendum; and (2) imposing contractual obligations on the recipient that are at least as protective as those imposed on Service Provider under this Addendum. At Ramp’s request, Service Provider will provide Ramp with evidence that it has entered into appropriate contractual arrangements with its Subprocessors. Service Provider may redact the text of its agreement with its Subprocessor prior to sharing a copy to the extent necessary to protect confidential information and Personal Data. b. Service Provider must notify Ramp in writing of any new Subprocessor at least thirty (30) days before authorizing that new Subprocessor to Process Personal Data, and Ramp may object to the new Subprocessor within thirty (30) days of Ramp’s receipt of notice. If Ramp does not object within thirty (30) days, Service Provider may use the new Subprocessor. If Ramp objects to the new Subprocessor, Service Provider must not use the new Subprocessor to process Personal Data. If Service Provider is unable to provide the Services without using the new Subprocessor, Service Provider must immediately notify Ramp in writing. In such case, Ramp may terminate the Service requiring the new Subprocessor upon written notice and Service Provider must provide Ramp a pro-rated refund for any prepaid fees for Services not yet received or the remainder of the remaining subscription term for such Services, as applicable. c. Service Provider remains fully liable for the performance of the Services in accordance with the Agreement and this Addendum, including any acts and omissions of any Subprocessors in Processing Personal Data. 6. Requests and Assistance Permanent link: 6. Requests and Assistance To the extent legally permitted, Service Provider must: (1) promptly notify Ramp if Service Provider receives a request from an individual to exercise their rights under Data Protection Law or receives a request or complaint from a supervisory authority or other third party relating to Personal Data (“Request”); and (2) not respond to the Request without written approval from Ramp. Taking into account the nature of the Processing, Service Provider shall assist Ramp in the fulfilment of Ramp’s obligation to respond to the Request, including by providing all information necessary and in Service Provider’s possession for Ramp to comply with such request. Upon request by Ramp, Service Provider shall assist Ramp as necessary to carry out data protection impact assessments related to Ramp’s use of the Services, and in the cooperation or prior consultation with supervisory authorities in the performance of Service Provider’s tasks relating to the data protection impact assessments. 7. Return and Destruction Permanent link: 7. Return and Destruction Service Provider shall return or destroy all Personal Data (such that Personal Data is rendered unusable and unreadable) at Ramp’s written request, when such Personal Data is no longer needed to perform the Services, or thirty (30) days following termination of the Agreement. Service Provider shall destroy all existing copies unless applicable law requires retention of the Personal Data, in which case Service Provider must inform Ramp of the applicable law and Personal Data required to be retained and must not Process the Personal Data except as necessary to comply with the applicable law. Upon request by Ramp, Service Provider shall provide written certification that all such Personal Data has been returned or deleted. 8. Audit and Monitoring Permanent link: 8. Audit and Monitoring a. At Ramp’s request, Service Provider will make available to Ramp all information reasonably necessary to demonstrate Service Provider’s compliance with its obligations under this Addendum and Data Protection Law. Service Provider must allow for and contribute to audits or inspections conducted by Ramp or an independent third-party auditor mandated by Ramp or under Data Protection Law. Ramp may also monitor Service Provider’s compliance with this Addendum through measures including, but not limited to, ongoing manual reviews and automated scans, and regular assessments, audits, or other technical and operational testing at least once every twelve (12) months. b. Service Provider must conduct a comprehensive independent third-party audit of its privacy and data security measures at least once per year and provide such audit findings to Ramp. Service Provider must promptly implement any required safeguards as identified by a third-party auditor or Ramp or as necessary for Service Provider to comply with this Addendum and Data Protection Law. Any audits under this Section 8 are in addition to any other audit rights in the Agreement. c. During an audit or inspection, Service Provider may restrict access to data or information if Ramp’s access to the information would negatively impact Service Provider’s intellectual property rights, confidentiality obligations, or other obligations under applicable law. 9. Data Transfer Permanent link: 9. Data Transfer a. Service Provider may only transfer Personal Data from one jurisdiction to another jurisdiction subject to ensuring such transfer (1) complies with this Addendum and Data Protection Law; and (2) will not cause Ramp to be in breach of this Addendum or Data Protection Law. For any Restricted Transfers of Personal Data subject to European Data Protection Law, the parties hereby agree to, and incorporate herein, the Standard Contractual Clauses, with the modifications set out below: (1) when Ramp acts as a controller, Module Two will apply, and when Ramp acts as a processor, Module Three will apply; (2) in Clause 7 (Docking clause), the optional docking clause will apply; (3) in Clause 9 (Use of subprocessors), under Modules 2 and 3, Option 2 will apply and the time period for prior notice of Subprocessor change shall be set out in Section 5 of this Addendum; (4) Clause 11 (Redress), the optional language shall not apply; (5) in Clause 17 (Governing Law), under Modules 2 and 3, Option 1 applies, and the member state is Ireland; (6) in Clause 18 (Choice of Forum and Jurisdiction), under Modules 2 and 3, the member state will be Ireland; (7) Annex I is completed as set out in Annex 1 of this Addendum; (8) Annex II is completed as set out in Annex 2 of this Addendum; and (9) Annex III is completed as set out in the Agreement. b. For purposes of the UK Addendum, as permitted by clause 17 of the UK Addendum, the parties agree to change the format of the information set out in Part 1 of the UK Addendum so that: (1) the details of the parties in Table 1 of the UK Addendum shall be as set out in Annex 1 hereto, with Ramp as the exporter and Service Provider as the importer (with no requirement for signature), and by signing this Addendum, the exporter and importer will be deemed to have signed the UK Addendum; (2) for the purposes of Table 2, the UK Addendum are appended to the EU SCCs as modified in Section 9.1 above and including the Annexes; (3) the appendix information listed in Table 3 is set out in the Annexes of this Addendum; and (4) either Party may end the UK Addendum as set out in Section 19 of the UK Addendum. c. Notwithstanding anything to the contrary, without prior written approval from Ramp, Service Provider must not engage in any “Covered Data Transaction” or similar commercial transactions involving “Bulk U.S. Sensitive Personal Data” or “Government-Related Data” with any “Country of Concern” or “Covered Person,” as those terms are defined in 28 C.F.R. Part 202 implementing Executive Order 14117 of February 28, 2024 or other related rules or regulations. Service Provider must implement and maintain measures to ensure that its subprocessors or subcontractors comply with this restriction. Service Provider must promptly, and at least within fourteen (14) days, notify Ramp in writing of violations of this provision by Service Provider or its Subprocessors. 10. Insurance Permanent link: 10. Insurance Service Provider must obtain and maintain, without interruption, a professional liability policy and security and privacy liability policy as follows: (1) covering liability arising out of Security Incidents; (2) with limits of liability equaling at least ten million dollars ($10,000,000) per claim or occurrence and in the aggregate; (3) including an endorsement listing Ramp as an additional insured under such policy for claims arising out of the wrongful acts and Security Incidents of Service Provider or Subprocessors; (4) issued by an insurance company having a rating of at least A+ in Best’s Key Rating Guide; and (5) that is primary, and not excess over or contributing with any insurance maintained by Ramp. Upon request, Service Provider must deliver to Ramp certificates of insurance as evidence of the insurance and limits stipulated above, with provisions for not less than thirty (30) days prior written notice to Ramp in the event of material alteration or cancellation of such insurance. 11. Material Breach Permanent link: 11. Material Breach The following shall be considered Service Provider’s material breach of the Agreement: (1) a Security Incident; and (2) Service Provider’s (or its Subprocessors’) failure to comply with any of its obligations set forth in this Addendum. 12. Indemnification Permanent link: 12. Indemnification Service Provider agrees to indemnify, defend, and hold harmless Ramp and its affiliates, subsidiaries, successors, and assigns (and their officers, directors, employees, sublicensees, customers and agents) from and against any and all claims, losses, demands, liabilities, damages, settlements, expenses and costs (including attorneys’ fees and costs), arising from, in connection with, or based on allegations of, any Security Incident or Service Provider’s (or its Subprocessors’) failure to comply with any of its obligations set forth in this Addendum. This indemnification obligation is not subject to any limitation of liability elsewhere in the Agreement. 13. SCCs Incorporated by Reference Permanent link: 13. SCCs Incorporated by Reference To the extent applicable, by signing this Addendum, the parties will be deemed to have signed the Standard Contractual Clauses, including the Annexes and, to the extent applicable, the UK Addendum. Annex 1: Details of Processing Activities Permanent link: Annex 1: Details of Processing Activities A. List of Parties Permanent link: A. List of Parties Data exporter(s): Name: Ramp Business Corporation. Address: 28 West 23rd Street, Floor 2, New York, NY 10010, United States of America Contact person’s name, position and contact details: As set out in the Agreement. Activities relevant to the data transferred under these Clauses: Use of the Service pursuant to the Agreement. Signature and date: This Annex 1 shall be deemed executed upon execution of the Agreement. Role: Controller/Processor Data importer(s): Name: As set out in the Agreement. Address: As set out in the Agreement. Contact person’s name, position and contact details: As set out in the Agreement. Activities relevant to the data transferred under these Clauses: Processing necessary to provide the Services pursuant to the Agreement. Signature and date: This Annex 1 shall be deemed executed upon execution of the Agreement. Role: Processor B. Description of Transfer Permanent link: B. Description of Transfer Categories of data subjects whose personal data is transferred The categories of data subjects whose Personal Data is Processed include: (1) end users of Ramp; (2) personnel and agents of Ramp; (3) personnel and agents of Ramp’s customers, business partners, and Service Providers; and (4) any other natural persons authorized by Ramp. Categories of personal data transferred The categories of Personal Data Processed include: As described in the Agreement. Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures. The sensitive data transferred includes: As described in the Agreement. The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis). The frequency of the transfer of Personal Data will be on a continuous basis. Nature of the processing The nature of the Processing is the Services as described in the Agreement. Purpose(s) of the data transfer and further processing The purpose of the Processing is for Service Provider to provide the Services to Ramp as set out in the Agreement. The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period The duration of the Processing is until the earlier of (1) request by Ramp to stop further Processing; (2) expiration/termination of the Addendum; or (3) when Processing is no longer necessary for purposes of Service Provider performing its obligations pursuant to the Addendum. For transfers to (sub) processors, also specify subject matter, nature and duration of the processing The subject matter, nature and duration of the Processing shall be as specified in the Agreement. C. Competent Supervisory Authority Permanent link: C. Competent Supervisory Authority In respect of the SCCs, means the competent supervisory authority determined in accordance with Clause 13 of the SCCs. In respect of the UK Addendum, means the UK Information Commissioner’s Office. Annex 2: Technical and Organizational Measures to Ensure the Security of Data Permanent link: Annex 2: Technical and Organizational Measures to Ensure the Security of Data This Annex 2 describes the technical and organizational measures implemented by Service Provider to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the Processing, and the risks for the rights and freedoms of natural persons. Minimum Technical and Organizational Measures Permanent link: Minimum Technical and Organizational Measures Service Provider has implemented and will maintain reasonable and appropriate technical and organizational measures to protect all data and information made available or provided by Ramp or on behalf of Ramp to Service Provider (“Data”) against accidental loss, destruction or alteration, unauthorized disclosure or access, or unlawful destruction, including the policies, and procedures and internal controls set forth in this Annex 2. More specifically, Service Provider’s security program shall include, at a minimum: Access Control of Processing Areas Service Provider has implemented and will maintain reasonable and appropriate measures to prevent unauthorized access to the data Processing equipment (namely telephones, database and application servers and related hardware) where Data is Processed or used, including: establishing security areas and physical controls; protection and restriction of access paths; establishing access authorizations for employees and third parties, including the respective documentation; all access to the data center where Data is hosted is logged, monitored, and tracked; and the data center where Data is hosted is secured by a security alarm system, and other appropriate security measures. Access Control to Data Processing Systems Service Provider has implemented and will maintain reasonable and appropriate measures to prevent data processing systems where Data is Processed and used from being used by unauthorized persons, including: use of multi-factor authentication for access to data processing systems; use of industry best encryption technologies, including for data at rest and in-transit; identification of the terminal and/or the terminal user to Service Provider and processing systems; automatic temporary lock-out of user terminal if left idle, identification and password required to reopen; automatic temporary lock-out of the user ID when several erroneous passwords are entered, log file of events, monitoring of break-in-attempts (alerts); and all access to data content is logged, monitored, and tracked. Access Control to Use Specific Areas of Data Processing Systems Service Provider commits that the persons entitled to use their data processing system are only able to access the data within the scope and to the extent covered by their respective access permission (authorization) and that Data cannot be read, copied or modified or removed without authorization. This shall be accomplished by various measures including: employee policies and training in respect of each employee’s access rights to the Data; allocation of individual terminals and/or terminal user, and identification characteristics exclusive to specific functions; monitoring capability in respect of individuals who delete, add or modify the Data; release of data only to authorized persons, including allocation of differentiated access rights and roles; use of industry standard encryption technologies, including for data at rest and in-transit; and control of files, controlled and documented destruction of data. Availability Control Service Provider has implemented and will maintain reasonable and appropriate measures to ensure that Data is protected from accidental destruction or loss, including: infrastructure redundancy; and backup is stored at an alternative site and available for restore in case of failure of the primary system. Transmission Control Service Provider has implemented and will maintain reasonable and appropriate measures to prevent Data from being read, copied, altered or deleted by unauthorized parties during the transmission thereof or during the transport of the data media. This is accomplished by various measures including: use of industry standard firewall, VPN and encryption technologies to protect the gateways and pipelines through which the data travels; highly confidential employee data is encrypted within the system; providing user alert upon incomplete transfer of data (end to end check); and as far as possible, all data transmissions are logged, monitored and tracked. Input Control Service Provider has implemented and will maintain reasonable and appropriate input control measures, including: an authorization policy for the input, reading, alteration and deletion of data; authentication of the authorized personnel; protective measures for the data input into memory, as well as for the reading, alteration and deletion of stored data; utilization of unique authentication credentials or codes (passwords); providing that entries to data processing facilities (the rooms housing the computer hardware and related equipment) are kept locked; automatic log-off of user ID’s that have not been used for a substantial period of time; proof established within Service Provider’s organization of the input authorization; and electronic recording of entries. Separation of Processing for Different Purposes Service Provider has implemented and will maintain reasonable and appropriate measures to ensure that data collected for different purposes can be Processed separately, including: access to data is separated through application security for the appropriate users; modules within Service Provider’s database separate which data is used for which purpose, i.e. by functionality and function; at the database level, data is stored in different normalized tables, separated per module, or function they support; and interfaces, batch processes and reports are designed for only specific purposes and functions, so data collected for specific purposes is Processed separately. Documentation Service Provider will keep documentation of technical and organizational measures in case of audits and for the conservation of evidence. Service Provider will ensure that persons employed by it, and other persons at the place of work concerned, are aware of and comply with the technical and organizational measures set forth in this Annex 2. Monitoring Service Provider has implemented and will maintain reasonable and appropriate measures to monitor access restrictions to Service Provider’s system administrators and to ensure that they act in accordance with instructions received. This is accomplished by various measures including: individual appointment of system administrators; adoption of commercially reasonable and appropriate measures to register system administrators’ access logs to the infrastructure and keep them secure, accurate and unmodified for at least six months; yearly audits of system administrators’ activity to assess compliance with assigned tasks, the instructions received by Service Provider and Data Protection Law; and keeping an updated list with system administrators’ identification details (e.g. name, surname, function or organizational area) and tasks assigned and providing it promptly to data exporter upon request. Limits on Retention/Destruction Service Provider will destroy or dispose of records containing Data when there no longer exists any lawful basis for Processing. Service Provider has implemented and will maintain reasonable and appropriate measures to securely destroy all Data consistent with Data Protection Law. Methods of performing these actions may include the use of a third party disk scrubbing utility or destruction of the drive, such as by degaussing, shredding, or other means of physically destroying data through specialized equipment and services.