This Data Processing Agreement (“DPA”) is by and between PDF Dot Net LLC (“pdf.net”) and the undersigned individual or entity (“Customer”) and supplements and amends the terms and conditions of that certain agreement between pdf.net and Customer (the “Agreement”). This DPA shall, effective as of the date last executed below, be incorporated into and become a part of the Agreement. In the event that any provisions of this DPA conflict with the terms of the Agreement between the parties, the provisions of this DPA shall govern. Except as otherwise provided herein, the Agreement between the parties shall remain in full force and effect.
1. Definitions
Terms used in this DPA shall have the meaning indicated below unless otherwise defined in this DPA.
1.1 “Business Purpose” means use of Personal Data for (i) performing services on behalf of Customer, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of Customer; (ii) auditing related to counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with this specification and other standards, (iii) helping to ensure security and integrity to the extent the use of the Data Subject’s Personal Data is reasonably necessary and proportionate for these purposes; (iv) debugging to identify and repair errors that impair existing intended functionality; (v) short-term, transient use, including, but not limited to, non-personalized advertising shown as part of a Data Subject’s current interaction with Customer, provided that the Data Subject’s Personal Data is not disclosed to another third party and is not used to build a profile about the Data Subject or otherwise alter the Data Subject’s experience outside the current interaction with the Customer; (vi) providing advertising and marketing services, except for cross-context behavioral advertising, to the Data Subject’s provided that, for the purpose of advertising and marketing, pdf.net shall not combine the Personal Data of opted-out consumers that pdf.net receives from, or on behalf of, Customer with Personal Data that pdf.net receives from, or on behalf of, another person or persons or collects from its own interaction with consumers; (vii) undertaking internal research for technological development and demonstration; and (viii) undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by pdf.net, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by pdf.net.
1.2 “Customer Personal Data” shall mean the Personal Data described in Schedule 1 of this DPA, in respect of which Customer is the Controller and which is Processed by pdf.net on behalf of Customer.
1.3 “Controller” has the meaning given in Data Protection Requirements from time to time. A Controller may also be referred to as a Business under Data Protection Requirements.
1.4 “Data Protection Requirements” shall mean any laws or regulations applicable to the Processing of Personal Data to which pdf.net or Customer is subject, including, without limitation, the California Consumer Privacy Act (Cal. Civ. Code §§ 1798.100-1798.199) (“CCPA”), the California Consumer Privacy Rights Act ("CPRA," and together with CCPA, "CCPA/CPRA"), data breach notification and reporting laws which may apply based upon the location of Data Subjects whose Personal Data may be Processed, the General Data Protection Regulation of the European Union (Regulation EU 2016/679) (“GDPR”), and the e-Privacy Directive (Directive 2002 58/EC), the Data Protection Act 2018, as well as the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419) (“UK GDPR”), and the UK Data Privacy and Digital Bill, and the Swiss Federal Act on Data Protection (“Swiss FDPA”), each as they may be amended.
1.5 “EEA” shall mean the European Economic Area.
1.6 “Member State” shall mean any country within the EU/EEA.
1.7 “Processor” has the meaning given in Data Protection Requirements from time to time. A Processor may also be referred to as a Service Provider under Data Protection Requirements.
1.8 “Restricted Transfer” means: (i) where GDPR applies, a transfer of Customer Personal Data from the EEA to a country outside of the EEA which is not subject to an adequacy determination by the European Commission; (ii) where the UK GDPR applies, a transfer of Customer Personal Data from the United Kingdom to any other country which is not based on adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018; and (iii) where the Swiss FADP applies, a transfer of Customer Personal Data from Switzerland to any other country which is not subject to legislation that guarantees adequate protection and/or is not recognized as providing an adequate level of data protection by the Swiss Federal Data Protection and Information Commissioner.
1.9 “Standard Contractual Clauses” or “SCC” shall mean the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 or any subsequent version thereof released by the European Commission (which will automatically apply), which may be found here.
1.10 “Subprocessor” means any agent, subcontractor or other third party (excluding its employees) engaged by pdf.net for carrying out any Processing activities on behalf of Customer in respect of the Customer Personal Data.
1.11 “Swiss SCC” shall mean the applicable standard data protection clauses issued, approved or recognized by the Swiss Federal Data Protection and Information Commissioner.
1.12 “UK SCC” shall mean the UK ‘International data transfer addendum to the European Commission’s Standard contractual clauses for international data transfers’, available at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf as adopted, amended or updated by the UK's Information Commissioner's Office, Parliament or Secretary of State.
1.13 “Personal Data”, “Data Subject”, “Personal Data Breach”, “Process”, “Processing”, “Processed”, “Sell,” “Share,” and “Supervisory Authority” will each have the meaning given to them in Data Protection Requirements from time to time. “Personal Data” may also be referred to as “Personal Information” under Data Protection Requirements. “Data Subject” may also be referred to as a “Consumer” under Data Protection Requirements.
Any other terms that are capitalized but not defined below shall have the meanings set forth in Data Protection Requirements and/or the Agreement, as applicable.
2. General Provisions
2.1 General Provisions.
2.1.1 This DPA applies to the Processing of Customer Personal Data. If Data Protection Requirements recognize the roles of Controller and Processor as applied to Customer Personal Data then, as between pdf.net and Customer, Customer acts as Controller and pdf.net acts as a Processor of Customer Personal Data.
2.1.2 Schedule 1 to this DPA sets out the subject matter and duration of the Processing, the nature and purpose of the Processing, the type of Customer Personal Data and categories of Data Subject. pdf.net may make reasonable amendments to Schedule 1 from time to time by sending an updated or an additional Schedule 1 to Customer. pdf.net shall Process Customer Personal Data for an indefinite term for as long as the Agreement is in effect.
2.2 Customer Obligations.
2.2.1 Customer shall comply with its obligations as a Controller under all applicable laws relating to privacy and data protection in respect of its use of services provided by pdf.net.
2.2.2 Customer shall provide instructions to pdf.net pursuant to this DPA that comply with Data Protection Requirements. Nothing in this DPA relieves Customer of any responsibilities or liabilities under any Data Protection Requirements. The parties agree that such instructions are contained in the Agreement and this DPA and that pdf.net may Process Customer Personal Data as necessary to enable pdf.net to fulfill its obligations to Customer under the Agreement. Any additional or different instructions require a signed agreement between pdf.net and Customer and may be subject to additional fees.
2.2.3 Customer shall have sole responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired Customer Personal Data. Customer shall ensure that Customer has the right to transfer, or provide access to, Customer Personal Data to pdf.net for Processing pursuant to the Agreement and this DPA.
2.2.4 Where provided by Data Protection Requirements, and in accordance with Section 10 of this DPA, Customer shall have the right to take reasonable and appropriate steps to ensure that pdf.net uses the Customer Personal Data that it received from, or on behalf of, the Customer in a manner consistent with Customer’s obligations under the Data Protection Requirements. Where required by Data Protection Requirements, Customer shall have the right, upon reasonable advance written notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data; provided such steps shall not interfere with pdf.net’s regular business operations, shall not require pdf.net to disclose any trade secrets or confidential information of pdf.net, its customers or its Subprocessors, service providers, contractors or third parties, and that Customer shall bear all related expenses, including any expenses related to business interruptions or other indirect expenses.
2.2.5 Customer hereby warrants that it has provided all required notices and obtained all required permissions or, if applicable and sufficient under Data Protection Requirements, another valid legal basis, required under Data Protection Requirements for pdf.net to Process any Customer Personal Data of the Data Subjects specified in Schedule 1 to this DPA. Customer acknowledges that pdf.net is reliant on Customer for direction as to the extent to which pdf.net is entitled to Process Customer Personal Data.
2.2.6 Customer Personal Data may not include any sensitive or special data that imposes specific data security or data protection obligations on pdf.net in addition to or different from those specified in any documentation or which are not provided as part of the Agreement or this DPA.
2.3 pdf.net Obligations.
2.3.1 pdf.net is receiving Customer Personal Data for the limited and specified purpose to perform services for or on behalf of Customer and as further set forth in this DPA and the Agreement. pdf.net will only Process Customer Personal Data as a Processor on behalf of and in accordance with Customer’s prior written instructions, including with respect to transfers of Customer Personal Data, unless Processing is required by Data Protection Requirements to which pdf.net is subject, in which case pdf.net shall, to the extent permitted by applicable law, inform Customer of that legal requirement before so Processing that Customer Personal Data.
2.3.2 pdf.net shall Process Customer Personal Data in compliance with the obligations placed on it under Data Protection Requirements and the terms of this DPA. pdf.net will inform Customer if, in its opinion, an instruction from Customer infringes the Data Protection Requirements, providing a reasonable level of detail as to the instructions with which it cannot comply and the reasons why it cannot comply, to the greatest extent permitted by applicable law; provided, however, pdf.net is not responsible for performing legal research and/or for providing legal advice to Customer.
2.3.3 In addition to any non-conflicting terms contained in the Agreement, pdf.net shall: (i) not Sell or Share Customer Personal Data; (ii) not retain, use, or disclose Customer Personal Data for any other purpose, other than for the Business Purpose, including retaining, using, or disclosing the Customer Personal Data for a commercial purpose other than the Business Purpose or as otherwise permitted by Data Protection Requirements; (iii) not retain, use, or disclose Customer Personal Data outside of the direct business relationship between the parties, except as may be permitted by the Data Protection Requirements; and (iv) not combine the Customer Personal Data that it receives from, or on behalf of, Customer with Personal Data that it receives from, or on behalf of, another person or persons, or collects from its own interaction with a Data Subject, provided that pdf.net may combine Personal Data to perform the Business Purposes. pdf.net shall notify Customer if it determines that it can no longer meet its obligations under the Data Protection Requirements.
2.3.4 pdf.net shall treat the Customer Personal Data Processed as confidential and shall not disclose such data to any third parties, except as necessary for pdf.net to perform its obligations under the Agreement or this DPA, unless authorized by Customer and in accordance with this DPA. In accordance with Data Protection Requirements, pdf.net shall put procedures in place designed to ensure that all persons acting under its authority entrusted with the Processing of Customer Personal Data (i) have committed themselves to keep such data confidential and not to use such data for any purposes except as permitted under this DPA, or (ii) are under an appropriate contractual or statutory obligation of confidentiality.
3. International Transfers
3.1 The parties agree that when the transfer of Customer Personal Data from Customer to pdf.net is a Restricted Transfer and Data Protection Requirements require that appropriate safeguards are put in place, such transfers shall be subject to Standard Contractual Clauses, UK SCC, or Swiss SCC, as applicable. Such applicable Standard Contractual Clauses, UK SCC, or Swiss SCC shall be deemed incorporated by reference and form an integral part of this DPA.
3.2 Where Customer Personal Data originating from the EEA is subject to a Restricted Transfer, in addition to the terms set forth in Schedule 1 of this DPA, the following specifications shall also apply to SCC clauses between Customer and pdf.net:
3.2.1 Instructions. For the purposes of clause 8.1(a) of the SCC, the instructions by Customer to Process Customer Personal Data are set out in Section 2 of this DPA;
3.2.2 Cost and Certification. The cost to return or delete Customer Personal Data shall be at Customer’s cost and expense. The certification of deletion of Customer Personal Data described in clauses 8.5 and 16(d) of this DPA shall be provided by pdf.net only upon Customer’s written request;
3.2.3 Security of Processing. For the purpose of clause 8.6(a), Customer agrees that the technical and organizational measures set forth in this DPA provide a level of security appropriate to the risk with respect to Customer’s Personal Data. For the purpose of clause 8.6(c), Personal Data Breaches will be handled in accordance with Section 6 of this DPA;
3.2.4 Audits. The audits described in clause 8.9 shall be carried out in accordance with Section 10 of this DPA;
3.2.5 Data Subject Rights. For the purpose of clause 10, Data Subject requests and related assistance shall be handled in accordance with Sections 7 of this DPA;
3.2.6 Liability. For the avoidance of doubt, pdf.net’s liability under clause 12(b) shall be limited as specified in Article 82 of the GDPR;
3.2.7 Notification of Government Access Requests. For the purpose of clause 15(1), pdf.net shall provide notification to Customer only and not individual Data Subjects;
3.2.8 Additional provisions applicable to Customer Personal Data transferred pursuant to the SCC and based on the “Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data” are set forth in Schedule 2.
3.2.9 In the event of any conflict between any terms in the SCC and terms in the DPA, the SCC shall prevail to the extent of the conflict.
3.3 With respect to any Restricted Transfer subject to the UK SCC and Data Protection Requirements applicable in the United Kingdom, the SCCs (as incorporated by reference) shall be read in accordance with, and deemed amended by, the provisions of Part 2 (Mandatory Clauses) of the UK International Data Transfer Agreement (“UK IDTA”), and the parties confirm that the information required for the purposes of Part 1 (Tables) of the UK IDTA is set out in Schedule 1 of this DPA. Additionally, the parties agree that: (i) general and specific references in the SCC to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 have the same meaning as the equivalent reference in UK SCC and Data Protection Requirements applicable in the United Kingdom; (ii) references in the SCC to the “EU,” “Union,” a “Member State” and “Member State law” mean the United Kingdom and “United Kingdom law” and references to a “supervisory authority” shall mean the UK Information Commissioner’s Office; (iii) any other obligation in the SCC determined by the Member State in which the data exporter is established refer to an equivalent obligation under UK SCC and Data Protection Requirements applicable in the United Kingdom; and (iv) the term “Member State” shall not be interpreted in such a way as to exclude data subjects in the United Kingdom from the possibility of suing for their rights in their place of habitual residence (i.e., United Kingdom). In the event of any conflict between any terms in the UK SCC and terms in the DPA, the UK SCC shall prevail to the extent of the conflict.
3.4 With respect to any Restricted Transfer subject to the Swiss SCC and Data Protection Requirements applicable in the Switzerland, the SCCs (as incorporated by reference) shall be read in accordance with, and deemed amended by and adapted as follows: (i) general and specific references in the Swiss SCC to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 have the same meaning as the equivalent reference in Swiss Data Protection Requirements; (ii) references in the SCC to the “EU,” “Union,” a “Member State” and “Member State law” mean Switzerland and “Swiss law” and references to a “supervisory authority” shall mean the Swiss Federal Data Protection and Information Commissioner; (iii) any other obligation in the SCC determined by the Member State in which the data exporter is established refer to an equivalent obligation under Swiss Data Protection Requirements; and (iv) the term “Member State” shall not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (i.e., Switzerland). In the event of any conflict between any terms in the Swiss SCC and terms in the DPA, the Swiss SCC shall prevail to the extent of the conflict.
3.5 If and to the extent there are contradictions or inconsistencies between this DPA and its Schedules, the applicable Schedule(s) shall prevail, unless and to the extent the relevant DPA provision is required under Data Protection Requirements.
4. Security Measures
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, pdf.net has implemented and will maintain appropriate physical, technical and organizational measures designed to protect against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise Processed (described under Annex II to Schedule 1). pdf.net may update its security practices from time to time but will not materially decrease the overall security for so long as pdf.net Processes or retains Customer Personal Data. Such measures shall include process for regularly testing, assessing and evaluating the effectiveness of the measures.
5. Subcontracting Authorization
When subcontracting to another pdf.net entity or a third party, if the subcontractor will Process Customer Personal Data, such subcontractor shall be a Subprocessor and pdf.net will enter into a binding written agreement with the Subprocessor that imposes on the Subprocessor substantially the same level of restrictions that apply to pdf.net under this DPA, to the extent that such requirements are applicable to the Processing to be done under such subcontract. A list of pdf.net current Subprocessors is available in Annex III of Schedule 1 (“Subprocessor List”). For the avoidance of doubt, the above constitutes Customer’s general authorization for pdf.net’s engagement of Subprocessors and pdf.net’s appointment of additional Subprocessors or replacement of any Subprocessors identified on the Subprocessor List. pdf.net may add or replace Subprocessors or make updates the Subprocessor List at any time. pdf.net will provide details of any change in Subprocessors as soon as reasonably practicable. Customer agrees to provide any objections promptly (in any event no later than ten (10) days following any notification or update), provided such objections are based on documented evidence that the Subprocessor does not or cannot comply with this DPA or Data Protection Requirements and identifies the reasonable data protection basis for the objection (“Objection”), so that pdf.net can evaluate the Objection and determine any appropriate action. In the event of an Objection, Customer and pdf.net will work together in good faith to find a mutually acceptable resolution to address such Objection, including but not limited to reviewing additional documentation supporting the Subprocessor’s compliance with the DPA or Data Protection Requirements. If pdf.net is unable to perform its obligations under the Agreement or this DPA (in whole or in part) without use of the new Subprocessor that Customer reasonably objects to and if the parties are unable to resolve Customer’s concerns, Customer may discontinue the part of the services only that pdf.net is unable to perform without such Subprocessor, upon written notice to pdf.net, without penalty or early termination fee. Such discontinuation will be without prejudice to any fees incurred by Customer prior to the discontinuation of the affected services. If pdf.net does not receive such notice of Objection, the replacement or addition of a Subprocessor will be deemed to be accepted by Customer. pdf.net may replace a Subprocessor without advance notice where the reason for the change is outside of pdf.net’s reasonable control and prompt replacement is required for security or other urgent reasons. In this case, pdf.net will inform Customer of the replacement Subprocessor as soon as possible following its appointment. Customer’s objection and termination right in this Section 5 applies accordingly. pdf.net shall remain fully liable to Customer under this DPA for the performance of its Subprocessors to the same extent pdf.net is liable for its own performance hereunder.
6. Personal Data Breach Notification
6.1 pdf.net will provide Customer written notice without undue delay of any Personal Data Breach impacting Customer Personal Data. Any such notification is not an acknowledgement of fault or responsibility. pdf.net agrees, at Customer’s cost and expense (including fees and expense to compensate pdf.net and its Subprocessors for their time and out of pocket costs involved in responding to any audit requests), to reasonably cooperate with Customer in Customer's handling of the matter, including without limitation any investigation, reporting or other obligations required by applicable law or regulation, or as otherwise required by Customer, and will work with Customer to otherwise respond to and mitigate any damages caused by the Personal Data Breach. Customer and pdf.net shall work together in good faith within the timeframes required by Data Protection Requirements to provide notifications and to finalize the content of any such notifications to Data Subjects or Supervisory Authorities, as required by Data Protection Requirements. pdf.net’s prior written approval shall be required for any statements regarding, or references to, the Personal Data Breach or pdf.net made by Customer in any such notifications. pdf.net shall not notify any third party of the Personal Data Breach without Customer’s prior written authorization, unless otherwise required by Data Protection Requirements. Notwithstanding the foregoing sentence, pdf.net shall not be restricted from notifying its other customers that may be impacted by the same Personal Data Breach or from consulting its own suppliers in the event of a breach (i.e. counsel, forensic investigators, insurance), provided pdf.net does not disclose or make reference to Customer, its Data Subjects, or any Customer Personal Data in such notice.
7. Handling of Complaints, Inquiries and Orders
To the extent a Data Subject identifies Customer as the entity that collected its Personal Data, pdf.net shall notify Customer of the Data Subject’s complaints and inquiries (e.g., regarding the rectification, deletion and blocking of or the access to Personal Data, or any other rights Data Subject has under Data Protection Requirements) (“Data Subject Inquiry”) received by pdf.net. To the extent permitted by Data Protection Requirements, pdf.net shall also notify Customer of all orders and inquires of courts, law enforcement, or other governmental authorities (“Privacy Communication”). pdf.net shall comply with Customer’s instructions regarding the handling of a Data Subject Inquiry or Privacy Communication, subject to the terms of Section 2.2 and this Section 7. Taking into account the nature of the Processing, pdf.net shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, in the fulfilment of Customer's obligations to respond to Data Subject Inquiry or Privacy Communication under Data Protection Requirements. To the extent Customer does not have the ability to address a Data Subject Inquiry or Privacy Communication without pdf.net’s assistane, then at Customer’s cost and expense (including fees and expenses to compensate pdf.net and its subcontractors for their time and out of pocket costs involved in responding to any request), pdf.net shall provide assistance to Customer to respond to such Data Subject Inquiry or Privacy Communication in a timely manner. pdf.net shall not independently respond to Data Subject Inquiries without Customer's prior approval, except as provided in this DPA or where required by Data Protection Requirements. pdf.net will instruct Data Subjects that do not identify a relevant customer to contact the correct customer.
8. Term
The term of this DPA is identical with the term of the Agreement. Save as otherwise agreed herein, termination rights and requirements shall be the same as set forth in the Agreement.
9. Data Retention
Within thirteen (13) months after expiration or termination of this DPA or pursuant to written instructions provided by Customer, pdf.net shall, return to Customer, at Customers cost and expense (including fees and expenses to compensate pdf.net and its subcontractors for their time and out of pocket costs involved in responding to any request) or securely destroy all copies of Customer Personal Data Processed on behalf of Customer in pdf.net’ role as a Processor. pdf.net may retain Customer Personal Data to the extent contained in its electronic data back-up and recovery systems, until destroyed in accordance with pdf.net’s records retention policy, or to the extent required by applicable laws, provided where retention is required by applicable laws, pdf.net shall retain such Customer Personal Data only for such period as required by applicable laws, or as necessary to protect its legal rights. pdf.net shall protect the confidentiality of all such retained Customer Personal Data and Process such Customer Personal Data only as necessary for the relevant purpose(s) requiring its storage and for no other purpose.
10. Information, Audits, and Assistance
10.1 pdf.net shall at all times during the term of this DPA keep books and records sufficient to show its compliance with the terms of this DPA. pdf.net will cooperate in good faith with Company’s efforts to ensure pdf.net’s reasonable compliance with this DPA, by making available to Customer a copy of pdf.net’s most recent audit report. Such audit report shall be considered pdf.net’s confidential information.
10.2 To the extent that pdf.net’s provision of an audit report does not provide sufficient information for Customer to verify pdf.net’s compliance with this DPA, pdf.net will, upon Customer’s written request, at Customer’s expense (including fees and expenses to compensate pdf.net and its subcontractors for their time and out of pocket costs involved in responding to any request), and subject to the confidentiality obligations set forth in the Agreement, remotely make available to Customer information which pdf.net reasonably believes will substantiate pdf.net’ compliance with this DPA and Data Protection Requirements. pdf.net may exclude information and documentation from such review that pdf.net is under obligation to keep confidential to third parties. Customer may only use such information to confirm pdf.net’ compliance with this DPA and to assist Customer with complying with its obligations under Data Protection Requirements. Any requests for information will be with thirty (30) days’ advance notice to pdf.net, and shall be limited to once per year, unless Customer has reasonable concerns about pdf.net’s data protection compliance following a Personal Data Breach or following instruction from a Supervisory Authority.
10.3 If requested by Customer, solely in order to support Customer’s compliance with Data Protection Requirements, pdf.net shall provide, at Customer’s expense (including fees and expenses to compensate pdf.net and its subcontractors for their time and out of pocket costs involved in responding to any request), reasonably required assistance to Customer in ensuring its compliance relating to data protection impact assessments and prior consultation with Supervisory Authorities, taking into account the nature of the Processing and the information available to pdf.net. All such information provided shall be pdf.net’ confidential information.
11. Invalidity and/or Unenforceability
Should any provision of this DPA be found invalid or unenforceable by a competent court of law, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall be amended as necessary to ensure its validity and enforceability, while preserving the parties’ intentions as closely as possible or, should this not be possible, construed in a manner as if the invalid or unenforceable part had never been contained therein.
12. Liability
Indemnification, liability, limitations of liability and any applicable exclusions under this DPA shall be governed by the Agreement to the extent permitted by Data Protection Requirements.
13. Corporate Restructuring
pdf.net may share and disclose Customer Personal Data and other data of Customer in connection with, or during the negotiation of, any merger, sale of company assets, consolidation or restructuring, financing, or acquisition of all or a portion of pdf.net’ business by or to another company, including the transfer of contact information and data of Customers, partners and end users.
14. Amendments for Additional Local Data Protection Requirements
To the extent that additional country-specific (or state, regional, provincial, or other geographic area specific) provisions are required under Data Protection Requirements, the parties agree to incorporate such provisions solely to the extent they are required and solely to the extent they are applicable to particular Customer Personal Data Processed by pdf.net.
Schedule 1 — Appendix to the Standard Contractual Clauses
Annex I
A. List of Parties
| Name (Data Exporter) | The Data Exporter is the entity identified as “Customer” in the DPA. |
|---|---|
| Address | As set forth in the Agreement. |
| Contact person’s name, position and contact details | As set forth in the notices provision in the Agreement. |
| Activities relevant to the data transferred under the Clauses | In addition to the information described below (Section B. Description of Transfer), the activities relevant to the data transferred for pdf.net’s performance of the services more fully described in the Agreement and applicable ordering documents. |
| Role (Controller / Processor) | Controller, except when Processing data on behalf of another entity, in which case Data Exporter is a Processor. |
| Name (Data Importer) | PDF Dot Net, LLC |
|---|---|
| Address | 1875 Century Park E, Los Angeles, CA 90067 |
| Contact person’s name, position and contact details | Legal Department — legal@pdf.net |
| Activities relevant to the data transferred under the Clauses | In addition to the information described below (Section B. Description of Transfer), the activities relevant to the data transferred for pdf.net’s performance of the services more fully described in the Agreement and applicable ordering documents. |
| Role (Controller / Processor) | Processor, or Subprocessor if Data Exporter is a Processor |
B. Description of Transfer
1. Processing Information.
| Categories of Data Subjects affected by the Processing | Users of pdf.net services and end customers of Customer placing orders via the pdf.net services. |
|---|---|
| Categories of Personal Data that will be Processed by pdf.net | Name, Address, Email Address, and Phone Number |
| Categories of Sensitive Personal Data that will be Processed by pdf.net | pdf.net does not require any sensitive data or special categories of data in order to provide its products and services. Unless otherwise specified in the Agreement, Customer shall not provide and must receive prior written consent of pdf.net before transferring any special categories of data or sensitive data to pdf.net. |
| Frequency of the transfer | Continuous and for so long as Customer uses pdf.net’s services, and for the termination and transition period thereafter, if any is set forth in the DPA and/or the Agreement. |
| Nature of the Processing / Purpose of the data transfer and further Processing | pdf.net shall collect, Process and use all Customer Personal Data solely for the purpose of the Processing as specified in the Agreement, the DPA, and any accompanying ordering documents and according to documented instructions on behalf of the Customer, including to provide related technical support and professional services under the Agreement (as applicable), discussing a potential business relationship, and improving/enhancing such products and services and support services. pdf.net also retains the right to Process the Customer Personal Data for purposes including enforcing its legal rights, complying with legal requirements, and other permitted purposes under applicable law, and, provided such Customer Personal Data does not identify Customer or Customer’s Data Subjects, for providing information on products and services, training resources, and opportunities for upgrades and enhancements, as set forth in its Privacy Policy. |
| Period for which the Customer Personal Data will be retained or criteria used to determine that period | The retention period of the Customer Personal Data is for the duration of the Agreement or as otherwise described therein |
| Subprocessor transfers – subject matter, nature, and duration of Processing | Subprocessors shall Process Customer Personal Data solely for the purpose of the Processing as specified in the Agreement, the DPA, and any accompanying ordering documents and according to documented instructions on behalf of the Customer and subject to obligations essentially equivalent to those described in this DPA. |
2. Signatures and Start Date
| Signatures | The parties agree that the EU SCCs and the UK International Transfer Addendum are incorporated by reference and that by executing the DPA, each party is deemed to have executed the SCCs and the UK Transfer Addendum. |
|---|---|
| Start Date | As indicated in the Agreement and accompanying ordering documents. |
3. EU SCCs and UK Transfer International Addendum Information
| SCC Clause | GDPR | Swiss FDPA | UK GDPR |
|---|---|---|---|
| Clause 7 Docking Clause | Module Two The optional Docking Clause (Clause 7) shall not apply. | Module Two The optional Docking Clause (Clause 7) shall not apply. | Module Two The optional Docking Clause (Clause 7) shall not apply. |
| Clause 9(a) – use of sub-processors | Module Two Clause 9(a) Option 2 (General Written Authorization) is selected, and will be enforced in accordance with Section 5 of this DPA; | Module Two Clause 9(a) Option 2 (General Written Authorization) is selected, and will be enforced in accordance with Section 5 of this DPA; | Module Two Clause 9(a) Option 2 (General Written Authorization) is selected, and will be enforced in accordance with Section 5 of this DPA; |
| Clause 11 (Redress) | Module Two Optional language in Clause 11 shall not apply. | Module Two Optional language in Clause 11 shall not apply. | Module Two Optional language in Clause 11 shall not apply. |
| Clause 13 (Supervision) | Module Two The supervisory authority of one of the Member States in which the Data Subjects whose Personal Data is transferred under the SCC in relation to the offering of goods or services to them, or whose behaviour is monitored, are located, as indicated in Clause 17 shall act as competent supervisory authority | Module Two The supervisory authority of one of the Member States in which the Data Subjects whose Personal Data is transferred under the SCC in relation to the offering of goods or services to them, or whose behaviour is monitored, are located, as indicated in Clause 17 shall act as competent supervisory authority | Module Two The supervisory authority of one of the Member States in which the Data Subjects whose Personal Data is transferred under the SCC in relation to the offering of goods or services to them, or whose behaviour is monitored, are located, as indicated in Clause 17 shall act as competent supervisory authority |
| Clause 17 Governing Law | Module Two These Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third-party beneficiary rights. The parties agree that this shall be the law of Ireland. | Module Two The parties agree that these clauses shall be governed by the law of Switzerland. | Module Two The parties agree that these clauses shall be governed by the law of England and Wales. |
| Clause 18 Choice of Forum and Jurisdiction | Module Two (b) The parties agree that those shall be the court of Ireland. | Module Two (b) The parties agree that those shall be the court of Switzerland. | Module Two The parties agree that those shall be the court of England and Wales. |
| Annex 1A List of Parties | Module Two The name, address, and contact person’s name, position, and contact details, and each party’s role in Processing Personal Data are provided in Section A above. | Module Two The name, address, and contact person’s name, position, and contact details, and each party’s role in Processing Personal Data are provided in Section A above. | Module Two The name, address, and contact person’s name, position, and contact details, and each party’s role in Processing Personal Data are provided in Section A above. |
| Annex 1B – Description of Transfer | Module Two This information can be found in Section B above. | Module Two This information can be found in Section B above. | Module Two This information can be found in Section B above. |
| Annex 1C – Competent Supervisory Authority | Module Two Identify the competent supervisory authority/ies in accordance with Clause 13: | Module Two Identify the competent supervisory authority/ies in accordance with Clause 13: | Module Two Identify the competent supervisory authority/ies in accordance with Clause 13: |
| Data Protection Commission 6 Pembroke Row, Dublin 2, D02 X963 Dublin 2 Tel. +3531 7650100 +353 1800437 737 Email: info@dataprotection.ie Member: Dr Des Hogan - Data Protection Commissioner | FDPIC | UK ICO | |
| Annex II – Technical and Organizational Measures | Module Two The description of technical and organization measures designed to ensure the security of Customer Personal Data is described more fully in Annex II to this DPA. | Module Two The description of technical and organization measures designed to ensure the security of Customer Personal Data is described more fully in Annex II to this DPA. | Module Two The description of technical and organization measures designed to ensure the security of Customer Personal Data is described more fully in Annex II to this DPA. |
| Annex II – Technical and Organizational Measures – Subprocessors | Module Two The description of technical and organization measures designed to ensure the security of Customer Personal Data Processed by Subprocessors is described more fully in Annex II to this DPA. | Module Two The description of technical and organization measures designed to ensure the security of Customer Personal Data Processed by Subprocessors is described more fully in Annex II to this DPA. | Module Two The description of technical and organization measures designed to ensure the security of Customer Personal Data Processed by Subprocessors is described more fully in Annex II to this DPA. |
| Annex III – List of Subprocessors | Module Two See Annex III to this Schedule 1 | Module Two See Annex III to this Schedule 1 | Module Two See Annex III to this Schedule 1 |
| Ending the UK Transfer Addendum when the Approved Addendum changes | N/A | N/A | Module One and Two Which parties may end this Addendum as set out in Section 19: ☒ Importer ☒ Exporter ☐ Neither Party |
Annex II
Technical and organizational measures including technical and organizational measures to ensure the security of the Customer Personal Data:
Information Security Governance
- A comprehensive set of information security policies and standards are documented, approved, and regularly reviewed.
- Personnel with access to Customer Personal Data are subject to confidentiality obligations.
Network Security
- Network security is maintained using industry standard techniques, including, for example, firewalls, intrusion detection systems, access control lists, and routing protocols.
- Network, application, and server authentication passwords are required to meet minimum complexity guidelines and be changed periodically.
- WiFi networks are secured and encrypt data in transit.
- An intrusion detection or prevention system covers network traffic to pdf.net information systems.
- Network changes are tested prior to production deployment.
- Firewalls are appropriately configured and implemented. Firewall policies are reviewed on a regular basis.
Encryption
- pdf.net encrypts all Customer Personal Data at rest and in transit across open networks in accordance with industry best practices. If Customer Personal Data is transmitted on internal pdf.net networks, it shall be transmitted through an encrypted protocol that meets industry best practices.
Identity and Access Management
- Data Processing systems handling Customer Personal Data are subject to measures designed to prevent access, loss or use without authorization.
- Employees or contractors with access to Customer Personal Data are assigned unique IDs.
- pdf.net limits and controls use of administrative privileges following industry best practices.
- Access rights are assigned using the principle of least privilege and need-to-know. Access is revoked upon termination of the employee or contractor.
- Systems Processing Customer Personal Data implement session or screen lockouts after a predetermined period of inactivity.
Physical Security
- Physical access to pdf.net buildings by unauthorized personnel is restricted.
- Physical access controls, such as surveillance cameras and identification badges, are implemented for pdf.net’s facilities.
- Physical security systems such as fire suppression systems, flood controls, smoke detection, and UPS are utilized.
Patch and Vulnerability Management
- Anti-malware and anti-virus software are in place and are updated on a regular cadence, including for pdf.net’s managed devices handling Customer Personal Data.
- pdf.net implements a patch management program designed to ensure security patches are appropriately applied to systems.
- Vulnerability scans for systems Processing Customer Personal Data are performed on a periodic basis.
- Any known critical vulnerabilities, as defined by pdf.net’s risk assessment, are assessed and remediated in a timely manner.
Continuous System Monitoring
- Audit logging is implemented in production system. Audit logs are retained for appropriate periods, including as required by applicable regulatory requirements.
- pdf.net reviews and analyzes information system audit records for indications of unusual activities.
Business Continuity Management
- Emergency and contingency plans are available and maintained in an effort to restore Customer Personal Data, where applicable, as reasonably deemed appropriate by pdf.net.
- Business continuity plans are tested and updated on a periodic basis, as reasonably deemed appropriate by pdf.net.
Incident Response
- pdf.net maintains a written incident response plan providing a standard process to investigate and address security incidents and regularly reviews the incident response plan.
- pdf.net will notify Customer of Personal Data Breaches in accordance with the DPA and its incident response plan.
- Customer may contact pdf.net for any available details regarding a Personal Data Breach.
Security Awareness
- Employees are required to undergo periodic privacy and information security training.
- Training is updated as deemed necessary by pdf.net.
Third Party Risk Management
- pdf.net has a program to review the information security risk and control of third-party service providers. The review is performed on new and existing vendors. This includes reviews of the effectiveness of the controls of pdf.net’s Subprocessors.
Additional and/or Supplemental Technical Security Measures
- Additional and/or supplemental technical security measures, and appropriate modifications to the measures listed above, may be established by pdf.net periodically depending on the products and services offered and the type of Customer Personal Data that is Processed by pdf.net.
- Storage media for Customer-facing systems are either destroyed or securely erased at the end of their lifecycle.
Annex III
List of pdf.net’s Subprocessors
Schedule 2 — Additional SCC Provisions Based on European Data Protection Board Recommendations 01/2020
1. If pdf.net receives legal process requiring disclosure of Customer Personal Data that was the subject of a Restricted Transfer to a public authority in a third country that does not benefit from an adequacy decision, pdf.net shall, unless prohibited by law or a legally binding order of an applicable body or agency, promptly, and as applicable:
(i) Notify Customer of any request for the disclosure of Customer Personal Data by a governmental or regulatory body or law enforcement authority (including any Supervisory Authority) (“Disclosure Request”) without responding to such request, unless otherwise required by applicable law (including to provide acknowledgement of receipt of the request);
(ii) Review applicable law to evaluate any Disclosure Request, for example the ability of the requesting authority to make the Disclosure Request;
(iii) Challenge the Disclosure Request if, after a careful assessment, it concludes that there are grounds under applicable law to do so, at Customer’s cost and expense (including fees and expense to compensate pdf.net and its Subprocessors for their time and out of pocket costs involved in responding to any requests). When challenging a Disclosure Request, pdf.net shall seek interim measures to suspend the effects of the Disclosure Request until an applicable court or other authority has decided on the merits;
(iv) Not disclose Customer Personal Data requested until required to do so under applicable law and then pdf.net shall only provide the minimum amount of Customer Personal Data permissible when responding to the Disclosure Request, based on a reasonable interpretation of the Disclosure Request; and
(v) If the Disclosure Request is incompatible with the SCCs or other data transfer mechanism utilized in accordance with Section 3 in the DPA, pdf.net will so notify the requesting authority and, if permitted by applicable law, notify the competent Supervisory Authority with jurisdiction over the Customer Personal Data subject to the Disclosure Request.
2. pdf.net has not created “back doors” or similar programming in its systems that provide products and services that could be used to access the systems and/or Customer Personal Data, nor has pdf.net created or changed its business processes in a manner that facilitates access to Customer Personal Data or its systems that provide the products and services. To the best of pdf.net’ knowledge, Data Protection Requirements of the United States do not require pdf.net to create or maintain “back doors” or to facilitate access to Customer Personal Data or systems that provide products and services or for pdf.net to possess or provide the encryption key in connection with a United States Disclosure Request.
3. pdf.net shall use reasonable efforts to assist Customer and its Data Subjects, as instructed by Customer (in accordance with Section 7 of the DPA), regarding Disclosure Requests, unless prohibited by applicable law, for example to provide information to Customer in connection with the Data Subject’s efforts to exercise its rights and obtain legally-available redress, provided pdf.net shall not be required to provide Customer or Data Subjects with legal advice.
4. Customer may request to review pdf.net information regarding access to Customer Personal Data, subject to the terms of Section 10 of the DPA.
5. In the event pdf.net receives a request to voluntarily disclose unencrypted Customer Personal Data to a government authority, pdf.net will first obtain Customer’s consent, either on its behalf or on behalf of the relevant Data Subject.