Customer Data Processing Addendum


This Data Processing Agreement, including its schedules and annexes, (collectively, this "DPA") forms part of the Corridor Terms of Service, Master Services Agreement, and any initial Order Form or subsequent Order Form, or any other legally entered and binding written or electronic agreement (collectively, the "Agreement") entered into between Corridor Security Inc. ("Corridor") and Customer, acting on its own behalf and on behalf of its Affiliates (defined below). This DPA sets forth each party's respective obligations regarding the processing of Personal Data (defined below) in connection with the Services (defined below) provided pursuant to the Agreement.

This DPA is effective as of the Effective Date of the Agreement. All capitalized terms not defined in this DPA will have the meaning given to them in the Agreement.


AGREED TERMS

1. Definitions

The following definitions and rules of interpretation apply in this DPA.

"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity.

"Business Purposes" means the Services described in the Agreement and any other purposes identified in ANNEX A. DETAILS OF PROCESSING, Section 4. Processing Details.

"Customer Authorized Privacy Contact" means the persons or categories of persons that Customer authorizes to give Corridor personal data processing instructions as identified in ANNEX A. DETAILS OF PROCESSING, Section 1. Data Exporter.

"Customer Personal Data" means Personal Data provided by or made available by Customer to Corridor or collected by Corridor on behalf of Customer, which Corridor Processes to perform the Services.

"Data Protection Laws" means all applicable global laws, regulations, or treaties concerning privacy, data security, data protection, or the Processing of Personal Data including, but not limited to, European Data Protection Laws and federal and state privacy laws in the United States, such as the California Consumer Privacy Act of 2018 ("CCPA"), each as amended, replaced, or superseded from time to time and the guidance and codes of practice issued by the relevant data protection or supervisory authorities and applicable to a Party.

"Disclosure Request" means (a) any order, demand, warrant, or any other document requesting or purporting to compel the production of Customer Personal Data (for example, by oral questions, interrogatories, requests for information or documents in legal proceedings, subpoenas, civil investigative demands, regulatory inspection or other similar processes); or (b) any other request, inquiry, or complaint involving Customer Personal Data or the Processing of such Customer Personal Data from any governmental, regulatory authority or law enforcement department, including, but not limited to, a data protection authority, or similar regulatory authority.

"European Data Protection Laws" means (a) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation) ("GDPR"); (b) the European Union ("EU") e-Privacy Directive (Directive 2002/58/EC); (c) any and all applicable local data protection laws of any Member State of the EU or country within the European Economic Area ("EEA") made under or pursuant to (a) or (b); (d) Swiss Data Protection Laws; and (e) United Kingdom ("UK") Data Protection Laws; in each case as may be amended, superseded, or replaced from time to time.

"Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise Processed.

The "Parties" means Corridor and Customer.

"Sensitive Personal Data" or "Sensitive Personal Information" has the same meaning as "Sensitive Data" as defined in the Agreement.

"Services" means the Corridor products and services provided to the Customer in connection with the Customer's purchase of a Subscription, Professional Services, and/or other services from Corridor under the Agreement.

"Standard Contractual Clauses" ("SCCs") means the Standard Contractual Clauses for the transfer of Personal Data to third countries approved pursuant to Commission Decision (EU) 2021/914 of 4 June 2021, as currently set out at https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en, as updated, amended, or replaced from time to time.

"Sub-Processor" means any Processor engaged by Corridor in accordance with the terms of this DPA, including, but not limited to, any Affiliate of Corridor. "Sub-processor" shall include the entities set forth under ANNEX C. APPROVED LIST OF SUB-PROCESSORS to this DPA.

"Swiss Data Protection Laws" means all laws relating to data protection, the Processing of Personal Data, privacy and/or electronic communication in force from time to time in Switzerland, including the Swiss Federal Act on Data Protection of 19 June 1992, SR 235.1, as amended, superseded, or replaced from time to time.

"UK Data Protection Laws" means all laws relating to data protection, the Processing of Personal Data, privacy and/or electronic communication in force from time to time in the UK including the Data Protection Act 2018, the Data (Use and Access) Act 2025, the Privacy and Electronic Communications Directive 2002/58/EC (as updated by Directive 2009/136/EC) and the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426), each as amended, superseded, or replaced from time to time.

"UK International Transfer Addendum" means the United Kingdom's addendum to the European Commission's Standard Contractual Clauses for international data transfers version B1.0 issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act of 2018 and entering into force on 21 March 2022, as updated, amended, or replaced from time to time.

Except as otherwise defined in this DPA, "Business," "Controller," "Data Subject," "Personal Data" or "Personal Information," "Process" or "Processing," "Processor," "Sell" or "Selling," "Service Provider," "Share" or "Sharing," are as defined under the relevant Data Protection Laws, and the conjugation of these terms shall be defined accordingly. For purposes of this DPA, the term "Controller" shall also refer to the term "Business" and the term "Processor" shall also refer to the term "Service Provider."

2. Purpose and Scope of Processing

Roles of the Parties. Customer and Corridor acknowledge and agree that under Data Protection Laws and this DPA, Customer may act as either a Controller or Processor. Where Customer is a Controller, Corridor is a Processor. Where Customer is a Processor, Corridor is a Sub-processor. All obligations placed on Processors under this DPA shall apply to Corridor regardless of whether Corridor acts as a Processor or Sub-processor.

Details of Processing. The subject matter, duration, nature and purpose of Processing, categories of Customer Personal Data, and Data Subject type(s), in respect of which Corridor may Process to fulfill the Business Purposes are described in ANNEX A. DETAILS OF PROCESSING of this DPA.

3. Customer Processing Obligations

Processing Instructions. Customer instructs Corridor to Process Customer Personal Data: (a) to provide and maintain the Services; (b) as may be further specified through Customer's use of the Services; (c) as documented in the Agreement; and (d) as documented in any other written instructions given by Customer and acknowledged by Corridor about Processing Personal Data under this DPA. Customer warrants and represents that Customer shall comply with and Customer's instructions for the Processing of the Customer Personal Data shall comply with Data Protection Laws. Customer is solely responsible for the accuracy, quality, and legality of (a) the Customer Personal Data provided to Corridor by or on behalf of Customer, (b) the means by which Customer acquired the Customer Personal Data provided to Corridor, and (c) the instructions it provides to Corridor regarding the Processing of Customer Personal Data. Customer shall provide to Corridor the minimum amount of Customer Personal Data necessary for the provision of the Services and shall not provide or make available to Corridor any Customer Personal Data other than as specified in ANNEX A. DETAILS OF PROCESSING, Section 4. Processing Details.

Prohibited Sensitive Personal Data. Customer shall not provide Sensitive Personal Data to Corridor or use any Services to Process Sensitive Personal Data. Corridor shall have no liability for Sensitive Personal Data, whether in connection with a Data Breach or otherwise.

Customer Affiliates. Customer enters into this DPA on behalf of itself and in the name and on behalf of its Affiliates, as applicable, thereby establishing a separate DPA between Customer and each such Customer Affiliate. Customer Affiliates shall be entitled to enforce the terms of this DPA as if each was a signatory to it. Customer shall remain responsible for coordinating all communication with Corridor under this DPA and be entitled to make and receive any communication in relation to this DPA on behalf of its Affiliates.

4. Corridor Processing Obligations

Compliance with DPA and Data Protection Laws. Corridor shall comply with all Data Protection Laws with respect to performing the Services and Processing the Customer Personal Data. Corridor shall not Process Customer Personal Data for any other purpose or in a way that does not comply with this DPA or applicable laws, including the Data Protection Laws. Corridor shall promptly notify Customer if Corridor is unable to comply with its obligations under this DPA or Data Protection Laws.

Processing Limitations. Corridor shall only Process Customer Personal Data to the extent, and in such a manner, as is necessary for the Business Purposes in accordance with this DPA and Customer's written instructions. Corridor shall not collect, disclose, use, or otherwise Process Customer Personal Data: (a) except as necessary to perform the Services and the Business Purposes described this DPA; (b) outside of the direct business relationship between Customer and Corridor; or (c) for its own purposes or those of any third party. Corridor shall not sell or share Customer Personal Data, as "sell" and "share" are defined under Data Protection Laws. Corridor shall not combine the Customer Personal Data received with Personal Data received from another business or that Corridor collects itself (unless such combination is necessary for certain business purposes identified in the Applicable Data Protection Laws).

Artificial Intelligence (AI) Training. Corridor will not use Customer Personal Data, including any Customer Personal Data that may be contained in any AI Input or AI Output, for any purpose other than as necessary to provide the AI Features as part of the Services. For the avoidance of doubt, Corridor will not use Customer Personal Data to train or otherwise improve any AI Feature.

Confidentiality. Corridor shall protect the confidentiality of the Customer Personal Data in accordance with the terms of this DPA and ensure that any Customer Personal Data is not disclosed or otherwise made available to other persons or used in violation of this DPA. Corridor shall ensure that any person that it authorizes to Process Customer Personal Data are informed of the confidential nature of the Customer Personal Data and are subject to an appropriate duty of confidentiality.

Compliance Assistance. Corridor shall reasonably assist Customer with meeting Customer's compliance obligations under the Data Protection Laws, taking into account the nature of Corridor's Processing and the information available to Corridor. For example, Corridor shall provide reasonable information to enable Customer to carry out Data Protection Impact Assessments or similar evaluations or assessments required under Data Protection Laws, and Corridor shall provide reasonable assistance to Customer in its cooperation or prior consultation with supervisory or other regulatory authorities.

Data Subject Rights. If Corridor receives a request from a Data Subject for access to Customer Personal Data or to exercise any of their related rights under the Data Protection Laws, Corridor shall notify Customer. Upon Customer's reasonable request, Corridor shall reasonably assist Customer to comply with the rights of Data Subjects under the Data Protection Laws and to respond to any inquiry, complaint, or other correspondence from a Data Subject.

Disclosure Requests, Complaints, and Other Communications. If Corridor receives a Disclosure Request, complaint, or any other communication regarding the Processing of Customer Personal Data or about either party's compliance with the Data Protection Laws, Corridor shall promptly notify Customer, unless prohibited to do so by law. Unless required by law, Corridor shall not disclose Customer Personal Data with any third party other than at Customer's request or instruction. Subject to applicable law, Corridor shall oppose any Disclosure Request, and if legally required to respond, shall provide the minimal amount of Customer Personal Data or information about Processing of Customer Personal Data in response to such request or inquiry. Corridor shall reasonably assist Customer in responding to any Disclosure Requests, complaints, or other communications regarding the processing of Customer Personal Data by Corridor.

Data Destruction or Return. Corridor shall securely destroy or return and not retain, all Customer Personal Data Processed subject to this DPA in its possession within thirty (30) days after the expiry or termination of the Agreement, except where retention of Customer Personal Data is required by any law, regulation, or government or regulatory body, in which case the protections of this DPA shall continue to apply to such retained Customer Personal Data for the period of time during which it is retained.

5. Security and Audits

Security Measures. Corridor shall implement appropriate technical and organizational measures against unauthorized or unlawful Processing, access, or disclosure of Customer Personal Data and against accidental or unlawful loss, destruction, alteration, disclosure or damage of Customer Personal Data including, but not limited to, the security measures set out in ANNEX B. SECURITY MEASURES. Corridor shall periodically review and test the effectiveness of such security measures.

Data Breach. Corridor shall notify the Customer Authorized Privacy Contact no later than forty-eight (48) hours upon becoming aware of a Data Breach and promptly take such steps as Corridor deems necessary and reasonable to investigate, contain, and mitigate such Data Breach. When notice is provided, Corridor shall provide all reasonable information in Corridor's possession to the extent it affects Customer, including: (a) a summary of the nature of the Data Breach, including the types of Customer Personal Data impacted and, to the extent Personal Data is impacted, the categories and approximate number of both Data Subjects concerned; (b) the likely consequences; and (c) description of the measures taken or proposed to be taken to mitigate its possible adverse effects. Corridor shall use reasonable efforts to provide Customer with additional updates regarding the Data Breach to the extent it affects Customer.

Audit Reports and Documentation. At Customer's written request at reasonable intervals, Corridor shall provide Customer with the most recent copies of external third-party audit reports, certifications, or other documentation regarding Corridor's compliance with the obligations in this DPA.

On-Site Audits. If the Customer reasonably believes the audit reports, certifications, or other documentation provided under Section 5.3 Audit Reports and Documentation above are inadequate to demonstrate compliance with the obligations of this DPA, Customer may reasonably request an on-site audit in writing and with no less than 30 days notice. An on-site audit may also be requested if Corridor has notified Customer of a Data Breach affecting Customer Personal Data or such an audit is required by Data Protection Laws or by the Customer's competent supervisory authority. Corridor shall cooperate in good faith with Customer to schedule any such audit on a mutually agreed upon date and time during Corridor's normal business hours (such agreement not to be unreasonably withheld by either party). In the event of any data protection deficiencies identified by the audit, Corridor shall produce and provide Customer with a copy of a written report that includes plans to remedy such deficiencies and remedy any deficiencies identified.

6. Cross-border Transfers

Adequate Measures for Transfers. Corridor shall not transfer or otherwise Process Personal Data outside of the country of origin of such Personal Data, either directly or via onward transfer, unless Corridor takes measures to ensure the transfer in compliance with Data Protection Laws and guidance from data protection regulatory authorities in relevant jurisdictions.

Transfer Assessment. To the extent required under or necessitated by Data Protection Laws and/or guidance issued by data protection regulatory authorities in relevant jurisdictions, Corridor shall conduct a risk assessment of any such international transfer to determine if the level of protection provided under the laws of the recipient country are adequate to protect the Personal Data in advance of engaging in any such transfer ("Transfer Assessment") and implement additional measures as necessary to ensure the protection of the Personal Data.

Standard Contractual Clauses. The Parties agree that the Standard Contractual Clauses shall apply to transfers of Personal Data from the EEA, UK, or Switzerland to Corridor under this DPA where such Personal Data is Processed in third countries not recognized by the European Commission or the relevant competent regulatory authority as providing an adequate level of protection for Personal Data. Where and as applicable, the Parties agree that the UK International Transfer Addendum shall be incorporated into the SCCs. The Parties agree that Modules 2 and 3 of the SCCs and the UK International Transfer Addendum are incorporated into this DPA by reference. The information in ANNEX D. APPROVED STANDARD CONTRACTUAL CLAUSES to this DPA sets forth the operative provisions of the SCCs and shall be deemed to complete the relevant tables in the SCCs and UK International Transfer Addendum.

7. Sub-processors

General Authorization. Customer acknowledges and agrees that Corridor may subcontract Processing of Customer Personal Data to a Sub-processor to provide Services. Corridor's current list of Sub-processors are listed in ANNEX C. APPROVED LIST OF SUB-PROCESSORS of this DPA.

Liability for Sub-processors. Prior to disclosing any Customer Personal Data to any Sub-processor, Corridor shall: (a) enter into a written agreement with each such Sub-processor that imposes obligations that are no less protective than the obligations in this DPA; and (b) remain liable to Customer and responsible for the Sub-processor's acts, errors, and omissions, and any failure to perform its obligations with respect to the Processing of Customer Personal Data and under Data Protection Laws.

New Sub-processor. Prior to engaging any new Sub-processors that Process Customer Personal Data, Corridor shall notify Customer by posting an updated version of its subprocessor list and allowing Customer the opportunity to object to the updated list. If Customer has legitimate objections to the appointment of any new Sub-processor, the Parties shall work together in good faith to resolve the grounds for the objection for no less than thirty (30) calendar days. Failing any such resolution, Customer may terminate the part of the Services performed under this DPA that cannot be performed by Corridor without use of the objectionable Sub-processor. For the avoidance of doubt, Corridor shall comply with the obligations set forth in Section 7.2 with respect to any new Sub-processor.

8. Term and Termination

Survival. This DPA shall remain in full force and effect so long as Corridor retains any Customer Personal Data in its possession or control, even if Corridor has fulfilled its obligations under all existing Order Forms.

Material Breach. A party's failure to comply with the terms of this DPA is a material breach. In the event of a material breach by either party, the other party may terminate this DPA, in whole or in part, effective immediately on written notice without further liability or obligation.

Noncompliance. If a change in any Data Protection Law prevents either party from fulfilling all or part of its obligations under this DPA, the Parties shall suspend the Processing of Customer Personal Data until that Processing complies with the new requirements. If the Parties are unable to bring the Processing of Customer Personal Data into compliance with the Data Protection Laws within sixty (60) days, they may terminate this DPA on written notice to the other Party.

9. General

Annexes. The Annexes form part of this DPA and shall have effect as if set out in full in the body of this DPA. Any reference to this DPA includes the Annexes.

Conflicts with SCCs or DPA. In the event of any conflict or inconsistency between the Agreement, the DPA, the provisions of the following documents (in order of precedence) shall prevail: (a) the Standard Contractual Clauses or UK International Transfer Addendum; then (b) the DPA; and then (c) the Agreement.

Limitation of Liability. To the maximum extent permitted under applicable Data Protection Laws, liability arising out of or related to this DPA shall be subject to the liability terms in the Agreement.

Choice of Law. Without prejudice to Standard Contractual Clauses or the UK International Data Transfer Addendum, this DPA shall be governed by and construed in accordance with the laws of the Agreement. Any disputes or claims arising under this DPA shall be brought in the State of Delaware.

Changes in Data Protection Laws. In the event of any changes to Data Protection Laws that may require variation to this DPA, and upon notice from Customer, the Parties shall promptly discuss such variations and negotiate in good faith with a view to agreeing on and implementing variations to the DPA designed to address the requirements of any such changes in Data Protection Laws as soon as reasonably practical.

ANNEX A. DETAILS OF PROCESSING

1. Data Exporter

Company NameAddressCustomer Authorized Privacy Contact, position, and contact informationRole
Customer, as specified in the AgreementCustomer's address as specified in the AgreementCustomer's contact information, as specified in the AgreementController / Processor

2. Data Importer

Company NameAddressContact name, position, and contact informationRole
Corridor Security Inc.501 2nd St, Suite 625, San Francisco, California 94107, United States of AmericaJack Cable, contact@corridor.devProcessor / Subprocessor

3. Activities relevant to the data transferred

Activities related to data transferred are described below in Section 4. Processing Details, under the "Nature of the processing" and "Purpose of the data transfer and further processing" fields.

4. Processing Details

FieldDetails
Categories of data subjects whose Customer Personal Data is Processed by CorridorCustomer may use Services to process any data subjects as they determine is necessary, including, but not limited to: Customer's authorized employees, contractors, and other workers.
Categories of Customer Personal Data Processed by CorridorCustomer may use Services to process any data categories as they determine is necessary, including, but not limited to: Identification data (e.g., names, team names, addresses, telephone numbers, IP addresses, email addresses, usernames, user IDs); AI Conversation Data (e.g., user prompts and AI assistant responses, file, workspace and repository info); IT-related data (e.g., usage and event logs, session identifiers, timestamps)
Sensitive Personal Information Processed by CorridorNone - Customer is prohibited from providing Sensitive Personal Data to Corridor or using any Services to Process Sensitive Personal Data.
Frequency of the transferContinuous
Nature of the processingCorridor processes Personal Data in order to provide and secure the Services and provide any related technical support in accordance with the DPA.
Purpose of the data transfer and further processingCorridor processes Personal Data in order to provide and secure the Services and provide any related technical support in accordance with the DPA.
For Processing involving California consumers, select purpose(s) for Processing Customer Personal Data
  • Helping to ensure security and integrity to the extent the use of the consumer's personal information is reasonably necessary and proportionate for these purposes.
  • Debugging to identify and repair errors that impair existing intended functionality.
  • Performing services on behalf of Customer, including maintaining or servicing accounts, providing customer service, processing, or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of Customer.
  • Undertaking internal Services for technological development and demonstration.
  • Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by Customer, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by Customer.
  • To retain and employ a Subprocessor (subject to the requirements of this DPA).
  • To build or improve the quality of the services it is providing to Customer provided that Corridor does not use the Customer Personal Data to perform services on behalf of another person.
  • To prevent, detect, or investigate data security incidents or protect against malicious, deceptive, fraudulent, or illegal activity.
Period for which the Customer Personal Data will be retained or criteria used to determine that periodThe period for which Customer Personal Data will be retained is as described in this DPA.
Sub-processor transfers - subject matter, nature, and duration of processingThe subject matter, nature, and duration of the Processing is described in ANNEX C. APPROVED LIST OF SUB-PROCESSORS of this DPA.

ANNEX B. SECURITY MEASURES

Corridor has implemented the following security controls: https://trust.corridor.dev/controls

ANNEX C. APPROVED LIST OF SUB-PROCESSORS

The Sub-processors authorized to Process Customer Personal Data to help Corridor provide Services are listed here: https://trust.corridor.dev/subprocessors

ANNEX D. APPROVED STANDARD CONTRACTUAL CLAUSES

1. EEA Personal Data Transfers

Transfers of Customer Personal Data originating in the EEA by Customer to Corridor in Third Countries are subject to: (a) Module Two (Controller to Processor) where Customer is a Data Controller and Corridor is a Data Processor; and (b) Module Three (Processor to Processor) where Customer is a Data Processor and Corridor is a Sub-Processor. The information required for the purposes of the SCCs is provided in ANNEX B. SECURITY MEASURES to this DPA.

2. Swiss Personal Data Transfers

Where the Customer Personal Data is subject to the Swiss Federal Data Protection Act ("Swiss DPA"), the SCCs above shall apply and be read to be modified as follows:

  • 2.1 References to "Regulation (EU) 2016/679" and any articles therefrom shall be interpreted to include references to the Swiss DPA.
  • 2.2 References to "EU," "Union," and "Member State" shall be interpreted to include references to "Switzerland."

3. UK Personal Information Transfers

For Customer Personal Data transfers subject to UK Data Protection Laws and transferred in accordance with the UK International Transfer Addendum, the Parties agree as follows:

  • 3.1 Each Party agrees to be bound by the terms and conditions set out in the UK International Transfer Addendum, in exchange for the other Party also agreeing to be bound by the UK International Transfer Addendum.
  • 3.2 The SCCs shall be interpreted in accordance with Part 2 of the UK International Transfer Addendum.
  • 3.3 Sections 9 to 11 of the UK International Transfer Addendum override Clause 5 (Hierarchy) of the SCCs.
  • 3.4 For the purposes of Section 12 of the UK International Transfer Addendum, the EU SCCs shall be amended in accordance with Section 15 of the UK International Transfer Addendum.
  • 3.5 Information required by Part 1 of the UK International Transfer Addendum is provided as ANNEX A. DETAILS OF PROCESSING of this DPA.
  • 3.6 To the extent that any revised transfer addendums or mechanisms are issued by the UK ICO, the Parties agree to incorporate such revisions in accordance with Section 18-20 of the UK International Transfer Addendum.

4. Other Country Transfers

For Customer Personal Data transfers subject to other Data Protection Laws which require the use of SCCs (or other measures) to transfer Customer Personal Data to Third Countries, the parties agree to implement such SCCs or other measures as soon as practicable and document such requirements for implementation.

5. Signatures

The Parties agree that the SCCs and the UK International Transfer Addendum are incorporated by reference and that by executing this DPA each party is deemed to have executed the SCCs and the UK International Transfer Addendum.

6. European Area SCC and UK Transfer Addendum Information

Where this Section 6 does not explicitly state that it applies to a particular Module of the Standard Contractual Clauses, it applies to both Modules.

SCC ClauseGDPRSwiss DPAUK Data Protection Laws
Clause 7 - Docking ClauseAn entity that is not a party to these clauses may, with the agreement of the parties, accede to these Clauses at any time, either as a data exporter or as a data importer, by completing the Appendix and signing Annex 1.A.
Clause 9(a) - Use of Sub-processorsGENERAL WRITTEN AUTHORISATION: The data importer has the data exporter's general authorisation for the engagement of sub-processor(s) in accordance with the terms of Section 7 of this DPA.
Clause 11 - RedressOptional language in Clause 11 shall not apply.
Clause 17 - Governing LawThe law of the relevant Member State in which the Data Exporter is established or has appointed a representative. Where Data Exporter is not established in an EU Member State and has no appointed representative, the law of Ireland.The law of Switzerland.The law of England and Wales.
Clause 18 - Choice of Forum and JurisdictionThe courts of the relevant Member State in which the Data Exporter is established or has appointed a representative. Where Data Exporter is not established in an EU Member State and has no appointed representative, the courts of Ireland.The competent courts of Switzerland.The competent courts of England and Wales.
Annex 1A - List of PartiesEach party's name, address, contact person's contact details, and role in Processing Customer Personal Data are provided in ANNEX A. DETAILS OF PROCESSING, Section 1 and Section 2 of this DPA above.
Annex 1B - Description of TransferThis information can be found in ANNEX A. DETAILS OF PROCESSING, Section 4. Processing Details of this DPA above. To the extent applicable, the descriptions of safeguards applied to the special categories of Customer Personal Data can be found in ANNEX B. SECURITY MEASURES of this DPA.
Clause 13 and Annex 1C - Competent Supervisory AuthorityThe relevant Supervisory Authority of the Data Exporter. Where Data Exporter is not established in an EU Member State and has no appointed representative, the Data Protection Commission of Ireland.FDPICUK Information Commissioner
Annex II - Technical and Organizational MeasuresThe description of technical and organization measures designed to ensure the security of Customer Personal Data is described more fully in ANNEX B. SECURITY MEASURES of this DPA.
Annex II - Technical and Organizational Measures - Sub-processorsThe description of technical and organization measures designed to ensure the security of Customer Personal Data Processed by Sub-processors is described more fully in ANNEX B. SECURITY MEASURES of this DPA.
Annex III - List of Sub-processorsThe list of sub-processors is included in ANNEX C. APPROVED LIST OF SUB-PROCESSORS of this DPA.
Ending the UK Transfer Addendum when the Approved Addendum changesN/AN/AExporter