Data Processing Addendum
Last updated: May 1, 2026
The Data Processing Addendum (“DPA”) is entered into as of Effective Date by and between F2 AI, Inc. (“F2 AI”) and Subscriber. This DPA supplements and forms part of the Master Subscription Agreement between the Parties pursuant to which the F2 AI provides services to Subscriber (the “Agreement”). Capitalized terms not defined in the DPA are defined in the main body of the Agreement.
- Definitions
For purposes of this DPA, the terms below have the meanings set forth below.Capitalized terms that are used but not defined in this DPA have the meanings given in the Agreement.- Affiliate means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where “control” refers to the power to direct or cause the direction of the subject entity, whether through ownership of voting securities, by contract or otherwise.
- Authorized User means an employee or contractor of Subscriber who is authorized by Subscriber to access and use the Service on behalf of and for the benefit of Subscriber.
- End-User means an individual end-user who is authorized by Subscriber to access, use, experience or benefit from the Service or to whom the Subscriber makes the Service available, other than Authorized Users.
- Applicable Data Protection Laws means, as and to the extent applicable, the State Privacy Laws, GDPR, and FADP.
- Controller means the entity that, alone or jointly with others, determines the purposes or means of the Processing of Personal Data, including, as applicable, any “business” as that term is defined by the California Consumer Privacy Act.
- Subscriber Data means information provided or made available by Subscriber to F2 AI for Processing on Subscriber’s behalf to perform the Services.
- Data Subject means the identified or identifiable natural person to whom Personal Data relates.
- EEA means the European Economic Area.
- FADP means the Swiss Federal Act on Data Protection in its revised version of 25 September 2020.
- FDPIC means Swiss Federal Data Protection and Information Commissioner.
- GDPR means, as and where applicable to Processing concerned: (i) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”); and/or (ii) the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (as amended, including by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019) (“UK GDPR”), including, in each case (i) and (ii) any applicable national implementing or supplementary legislation (e.g., the UK Data Protection Act 2018), and any successor, replacement, amendment or re-enactment, to or of the foregoing. References to “Articles” and “Chapters” of, and other relevant defined terms in, the GDPR shall be construed accordingly.
- Information Security Incident means an actual breach of F2 AI’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in F2 AI’s possession, custody or control. Information Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.
- Personal Data means Subscriber Data that constitutes “personal data,” “personal information,” or “personally identifiable information” as defined in Applicable Data Protection Laws, except that Personal Data does not include such information received by F2 AI directly or from other sources (such as its other customers) independent of F2 AI’s relationship with Subscriber.
- Process or Processing means any operation or set of operations which is performed by F2 AI on behalf of Subscriber under this Agreement, on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Processor means the entity that Processes Personal Data on behalf and at the direction of the Controller, including, as applicable, any “service provider” as that term is defined by the California Consumer Privacy Act.
- Restricted Transfer means the disclosure, grant of access or other transfer of Personal Data to any person located in: (i) when transferred from the EEA, any country or territory outside the EEA which does not benefit from an adequacy decision from the European Commission (an “EU Restricted Transfer”); (ii) when transferred from the UK, any country or territory outside the UK, which does not benefit from an adequacy decision from the UK Government (a “UK Restricted Transfer”); and (iii) when transferred from Switzerland, a country or territory outside of Switzerland which does not benefit from an adequacy decision from the Swiss authorities (a “Swiss Restricted Transfer”), in each case, which would be prohibited without a legal basis under the GDPR or FADP.
- SCCs means the applicable (C-to-C, C-to-P, P-to-P or P-to-C) standard contractual clauses approved by the European Commission pursuant to implementing Decision (EU) 2021/914)
- Security Measures has the meaning given in Section 4(a) (F2 AI Security Measures).
- Service Data means any data relating to the use, support and/or operation of the Services, which is collected by F2 AI from and/or about Authorized Users or End Users of the Services and/or Subscriber’s use of the Service for use for F2 AI’s own purposes (certain of which may constitute Personal Data).Service Data includes Personal Data of Subscriber’s business representatives and Performance Data.
- Services means the services that F2 AI performs for Subscriber under the Agreement.
- State Privacy Laws means, collectively, the comprehensive state-specific data privacy laws and their regulations currently in effect and applicable to F2 AI’s Processing of Personal Data under the Agreement.
- Subprocessors means third parties that F2 AI engages to Process Personal Data in relation to the Services.
- Supervisory Authority means any entity with the authority to enforce Applicable Data Protection Laws, including, (i) in the context of the EEA and the EU GDPR, shall have the meaning given to that term in the EU GDPR; (ii) in the context of the UK and the UK GDPR, means the UK Information Commissioner’s Office (ICO); and (iii) in the context of Switzerland and the FADP, means the FDPIC.
- UK Transfer Addendum means the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of the Mandatory Clauses included in Part 2 thereof.
- Duration and Scope of DPA
- This DPA will remain in effect so long as F2 AI Processes Personal Data, notwithstanding the expiration or termination of the Agreement.
- Processing of Personal Data subject to the GDPR shall be subject to Annex 2 (European Annex).
- Processing of Personal Data subject to the State Privacy Laws with respect to which Subscriber is a Business, Controller, Processor, or Service Provider and F2 AI is Subscriber’s service provider or processor (as such terms are defined in State Privacy Laws) shall be subject to Annex 3 (State Privacy Laws Annex) to this DPA.
- Subscriber Instructions
F2 AI will Process Personal Data as a Processor only in accordance with Subscriber’s instructions to F2 AI.By entering into this DPA, Subscriber instructs F2 AI to Process Personal Data to provide the Services and to perform its other obligations and exercise its rights under the Agreement. The Parties acknowledge and agree that the details of F2 AI’s Processing of Personal Data (including the respective roles of the Parties relating to such Processing) are as described in Annex 1 (Data Processing Details) to the DPA. - Security
- F2 AI Security Measures. F2 AI will implement and maintain technical, administrative, physical and organizational measures designed to protect Personal Data against Information Security Incidents as described in Annex 4 (the “Security Measures”).F2 AI may update the Security Measures from time to time, so long as the updated measures do not materially decrease the overall protection of Personal Data.
- Security Compliance by F2 AI Staff. F2 AI shall require that its personnel who are authorized to access Personal Data are subject to appropriate confidentiality obligations.
- Information Security Incidents. F2 AI will notify Subscriber without undue delay of any Information Security Incident of which F2 AI becomes aware. Such notifications will describe available details of the Information Security Incident, including steps taken to mitigate the potential risks and steps F2 AI recommends Subscriber take to address the Information Security Incident. F2 AI’s notification of or response to an Information Security Incident will not be construed as F2 AI’s acknowledgement of any fault or liability with respect to the Information Security Incident. F2 AI shall reasonably co-operate with Subscriber and take such commercially reasonable steps as may be directed by Subscriber to assist in the investigation of any such Information Security Incident. Subscriber is solely responsible for complying with notification laws applicable to Subscriber and fulfilling any third-party notification obligations related to any Information Security Incident. If Subscriber determines that an Information Security Incident must be notified to any Supervisory Authority, any Data Subject(s), the public or others under Applicable Data Protection Laws, to the extent such notice directly or indirectly refers to or identifies F2 AI, where permitted by applicable laws, Subscriber agrees to (i) notify F2 AI in advance, and (ii) in good faith, consult with F2 AI and consider any clarifications or corrections F2 AI may reasonably recommend or request to any such notification, which: (i) relate to F2 AI’s involvement in or relevance to such Information Security Incident; and (ii) are consistent with applicable laws.
- Subscriber’s Security Responsibilities. Subscriber agrees that Subscriber is solely responsible for its use of the Services, including (a) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Subscriber Data; (b) securing the account authentication credentials, systems and devices Subscriber uses to access the Services; (c) securing Subscriber’s systems and devices that F2 AI uses to provide the Services; and (d) backing up Personal Data.
- Subscriber’s Security Assessment. Subscriber has determined that the Services, the Security Measures and F2 AI’s commitments under this DPA are adequate to meet Subscriber’s needs, including with respect to any security obligations of Subscriber under Applicable Data Protection Laws, and provide a level of security appropriate to the risk in respect of the Personal Data.
- Data Subject Rights
- Data Subject Request Assistance. F2 AI will (taking into account the nature of the Processing of Personal Data) provide Subscriber with assistance reasonably necessary and technically feasible for Subscriber to perform its obligations under Applicable Data Protection Laws to fulfill requests by Data Subjects to exercise their rights under Applicable Data Protection Laws (“Data Subject Requests”) with respect to Personal Data in F2 AI’s possession or control, including but not limited to, access, correction, deletion, and cessation of Processing of Personal Data.Subscriber shall compensate F2 AI for any such assistance at F2 AI’s then-current professional services rates, which shall be made available to Subscriber upon request.
- Subscriber’s Responsibility for Requests. If F2 AI receives a Data Subject Request, F2 AI will (i) notify Subscriber; and (ii) advise the Data Subject to submit the request to Subscriber. Subscriber will be solely responsible for responding to any such request.
- Subscriber Responsibilities
- Subscriber shall ensure (and is solely responsible for ensuring) that it has given such notices to and obtained such consents and permissions from third parties (including, without limitation, Data Subjects), and has all rights, in each case, as may be required under applicable law or otherwise for F2 AI to Process Personal Data as contemplated by the Agreement.
- Subscriber represents and warrants to F2 AI that Subscriber Data does not and will not contain any Personal Data that containsracial, ethnic or national origin; religious or philosophical beliefs; political opinions; protected health information subject to the Health Insurance Portability and Accountability Act (“HIPAA”); other mental or physical health condition, diagnosis, history, treatment or other health data; health insurance information; pregnancy; sex life, sexuality or sexual orientation; status as transgender or non-binary; citizenship; citizenship or immigration status; union membership; status as a victim of crime; genetic, biometric, neural or biological data; personal information of children or teens; precise location information; Social Security number; driver’s license number; state identification card number; passport number; other government-issued identification numbers; account login information; financial information or account number; tax return data; contents of a communication to which you were not a party; or any bulk U.S. sensitive personal data or U.S. government-related data, in each case as defined in the U.S. Department of Justice’s Final Rule on Prohibition on Bulk Data Transfers to Foreign Adversaries (28 C.F.R. Part 202), as amended, or any successor or similar rule, law, or regulation (collectively, “Restricted Data”).
- Subscriber represents and warrants that there is, and will be throughout the term of the Agreement, a valid legal basis for the Processing by F2 AI of Personal Data in accordance with this DPA and the Agreement (including, any and all instructions issued by Subscriber from time to time in respect of such Processing) for the purposes of all Applicable Data Protection Laws (including Article 6, Article 9(2) and/or Article 10 of the GDPR (where applicable)).
- Subscriber shall ensure that all Data Subjects have (i) been presented with all required notices and statements (including as required by Article 12-14 of the GDPR (where applicable)); and (ii) provided all required consents, in each case (i) and (ii) relating to the Processing by F2 AI of Personal Data.
- Subprocessors
- Consent to Subprocessor Engagement. Subscriber generally authorizes F2 AI to engage third parties as Subprocessors in accordance with this Section 7.
- Information about Subprocessors. Information about Subprocessors, including their functions and locations, is available at https://security.f2.ai/?tab=subprocessors (the “Subprocessor Site”). F2 AI may continue to use those Subprocessors already engaged by F2 AI as at the date of this DPA.
- Requirements for Subprocessor Engagement. When engaging any Subprocessor, F2 AI will enter into a written contract with such Subprocessor containing data protection obligations not less protective than those in this DPA with respect to Personal Data to the extent applicable to the nature of the services provided by such Subprocessor. F2 AI shall be liable for all obligations subcontracted to, and all acts and omissions of, the Subprocessor in connection with the services they provide to F2 AI to the same extent as F2 AI would have been had it performed the Processing itself.
- Opportunity to Object to Subprocessor Changes. When F2 AI engages any new Subprocessor after the effective date of the DPA, F2 AI will notify Subscriber of the engagement (including the name and location of the relevant Subprocessor and the activities it will perform) by updating the Subprocessor Site or by other written means.If Subscriber objects to such engagement in a written notice to F2 AI within 15 days after being informed of the engagement on reasonable grounds relating to the protection of Personal Data, Subscriber and F2 AI will work together in good faith to find a mutually acceptable resolution to address such objection. If the parties are unable to reach a mutually acceptable resolution within a reasonable timeframe, Subscriber may, as its sole and exclusive remedy, terminate the Agreement and cancel the Services by providing written notice to F2 AI and pay F2 AI for all amounts due and owing under the Agreement as of the date of such termination.
- Audits
Reviews and Audits of Compliance. Subscriber may audit F2 AI’s compliance with its obligations under this DPA up to once per year and on such other occasions as may be required by Applicable Data Protection Laws. F2 AI will contribute to such audits by providing Subscriber with the information and assistance reasonably necessary to conduct the audit.Due to the nature of the Services, on-site audits are not necessary for Subscriber to audit F2 AI’s compliance with this DPA.If a third party is to conduct the audit, F2 AI may object to the auditor if the auditor is, in F2 AI’s reasonable opinion, not independent, a competitor of F2 AI, or otherwise manifestly unsuitable.Such objection by F2 AI will require Subscriber to appoint another auditor or conduct the audit itself.To request an audit, Subscriber must submit a proposed audit plan to F2 AI at least two weeks in advance of the proposed audit date and any third-party auditor must sign a customary non-disclosure agreement mutually acceptable to the parties (such acceptance not to be unreasonably withheld) providing for the confidential treatment of all information exchanged in connection with the audit and any reports regarding the results or findings thereof. The proposed audit plan must describe the proposed scope, duration, and start date of the audit. F2 AI will review the proposed audit plan and provide Subscriber with any concerns or questions (for example, any request for information that could compromise F2 AI security, privacy, employment or other relevant policies). F2 AI will work cooperatively with Subscriber to agree on a final audit plan.Nothing in this Section 8 shall require F2 AI to breach any duties of confidentiality.If the controls or measures to be assessed in the requested audit are addressed in a SOC 2 Type 2, ISO, NIST or similar audit report performed by a qualified third-party auditor within twelve (12) months of Subscriber’s audit request and F2 AI has confirmed there have been no known material changes in the controls audited since the date of such report, Subscriber agrees to accept such report in lieu of requesting an audit of such controls or measures.The audit must be conducted during regular business hours, subject to the agreed final audit plan and F2 AI’s safety, security or other relevant policies, and may not unreasonably interfere with F2 AI business activities.Subscriber will promptly notify F2 AI of any non-compliance discovered during the course of an audit and provide F2 AI the audit reports generated in connection with the audit(s) under this Section 8, unless prohibited by Applicable Data Protection Laws. Subscriber may use the audit reports only for the purposes of meeting Subscriber’s regulatory audit requirements and/or confirming compliance with the requirements of this DPA.Any audits are at Subscriber’s sole expense. Subscriber shall reimburse F2 AI for any time expended by F2 AI and any third parties in connection with any audits or inspections under this Section 8 at F2 AI’s then-current professional services rates, which shall be made available to Subscriber upon request. Subscriber will be responsible for any fees charged by any auditor appointed by Subscriber to execute any such audit. - Return and Deletion
- Subject to Sections 9(b) and 9(c), upon the date of cessation of any Services involving the Processing of Personal Data (the “Cessation Date”), F2 AI shall promptly cease all Processing of Personal Data for any purpose other than for storage or as otherwise permitted or required under this DPA.
- Subject to Section 9(d), to the extent technically possible in the circumstances (as determined in F2 AI’s sole discretion), on Subscriber’s written request to F2 AI (to be made no later than fourteen (14) days after the Cessation Date (“Post-cessation Storage Period”)), F2 AI shall within fourteen (14) days of such request, at Subscriber’s election either: (i) return a complete copy of all structured Personal Data within F2 AI’s possession to Subscriber by secure file transfer, promptly following which F2 AI shall delete or anonymize all other copies of such Personal Data, or (ii) either (at F2 AI’s option) delete or anonymize all structured Personal Data within F2 AI’s possession.
- In the event that during the Post-cessation Storage Period, Subscriber does not instruct F2 AI in writing to either delete or return Personal Data pursuant to Section 9(b), F2 AI shall, subject to Section 9(d), promptly after the expiry of the Post-cessation Storage Period either (at its option) delete; or render anonymous, all structured Personal Data then within F2 AI possession to the fullest extent technically possible in the circumstances.
- Notwithstanding the above, F2 AI may retain Personal Data, where permitted or required by applicable law, for such period as may be permitted or required by such applicable law, provided that F2 AI shall (i) maintain measures designed to protect all such Personal Data, and (ii) Process the Personal Data only as necessary for the purpose(s) specified in the applicable law permitting or requiring such retention.
- Service Data
- Subscriber acknowledges that F2 AI may collect, use and disclose Service Data for its own business purposes: (i) for accounting, tax, billing, audit, and compliance purposes; (ii) to provide, improve, develop, optimise, market and maintain the Services; (iii) to investigate fraud, spam, wrongful or unlawful use of the Services; (iv) to combine Service Data with other data; (v) to de-identify Personal Data so the de-identified data can be used and disclosed by F2 AI for lawful business purposes; and/or (vi) as otherwise permitted or required by applicable law.
- In respect of any such Processing described in Section 10(b), F2 AI: (i) independently determines the purposes and means of such Processing; (ii) shall comply with Applicable Data Protection Laws (if and as applicable in the context); (iii) shall process consumer sale/share opt-out requests that are forwarded to F2 AI by Subscriber to the extent required by Applicable Data Protection Laws and upon request provide documentation to Subscriber that it has done so; (iv) shall Process such Service Data as described in F2 AI’s relevant privacy notices/policies, as updated from time to time; and (iv) where possible, shall apply technical and organizational safeguards to any relevant Personal Data that are no less protective than the Security Measures.
- Use of AI
- F2 AI may use aggregated data, de-identified data, usage data, metadata, and derived data generated through Subscriber’s use of the Services, for the purposes of: (i) developing, training, improving, and optimizing F2 AI’s and Third Party AI Models, algorithms, and Services, and (ii) enhancing the performance, functionality, and security of F2 AI’s offerings. AI Models means machine learning models, algorithms, or artificial intelligence systems developed, maintained, improved or used by F2 AI. AI Models may be F2 AI-developed AI Models or Third Party-developed AI Models.
- F2 AI shall not use Subscriber Data in a manner that identifies Subscriber or any individual, or that would reasonably be expected to re-identify such data, when used for AI Model training or product improvement.]
- F2 AI will not re-identify de-identified Personal Data.
- Miscellaneous
- Except as expressly modified by the DPA, the terms of the Agreement remain in full force and effect. Notwithstanding anything in the Agreement or any order form entered in connection therewith to the contrary, the parties acknowledge and agree that F2 AI’s access to Personal Data does not constitute part of the consideration exchanged by the parties in respect of the Agreement.Notwithstanding anything to the contrary in the Agreement, any notices required or permitted to be given by F2 AI to Subscriber under this DPA may be given (i) in accordance with any notice clause of the Agreement; (ii) to F2 AI’s primary points of contact with Subscriber; or (iii) to any email provided by Subscriber for the purpose of providing it with Services-related communications or alerts. Subscriber is solely responsible for ensuring that such email addresses are valid.
- F2 AI agrees to cooperate in good faith with Subscriber concerning any amendments as may be reasonably necessary to address compliance with the Applicable Data Protection Laws.
- F2 AI may on notice vary this DPA to the extent that (acting reasonably) it considers necessary to address the requirements of Applicable Data Protection Laws from time to time, including by varying or replacing the SCCs in the manner described in Paragraph 3.3 of Annex 2 (European Annex).
- In the event of any conflict or inconsistency between (i) this DPA and the Agreement, this DPA shall prevail to the extent of such conflict or inconsistency, or (ii) any SCCs entered into pursuant to Paragraph 2 of Annex 2 (European Annex) and this DPA and/or the Agreement, the SCCs shall prevail in respect of the Restricted Transfer to which they apply.
- Limitation of Liability.
The total aggregate liability of either Party towards the other Party, howsoever arising, under or in connection with THE AGREEMENT, this DPA and the SCCs (if and as they apply) will under no circumstances exceed any limitations or caps on, and shall be subject to any exclusions of, liability and loss agreed by the Parties in the Agreement; provided that, nothing in this Section 10(d) will affect any person’s liability to Data Subjects under the third-party beneficiary provisions of the SCCs (if and as they apply).
Annex 1
Data Processing Details
F2 AI / ‘DATA IMPORTER’ DETAILS
Name: F2 AI, Inc is a U.S. corporation
Address: 30 Broad Street, FL 29, New York, NY 10004
Contact Details for Data Protection: CTO [email protected]
F2 AI Activities: Processing of data and enrichment of data designed to investors with corporate financial analysis by generating comprehensive, auditable reports
Role: Processor (and Controller of Service Data)
SUBSCRIBER / ‘DATA EXPORTER’ DETAILS
Name: The entity or other person who is a counterparty to the Agreement
Subscriber’s address is: [counterpartySignerTextField_A0snB7L||1]
Subscriber’s Contact Details for Data Protection:
- First & Last Name: [counterpartySignerTextField_BD6qcBJ]
- Contact Email: [counterpartySignerTextField_L5ol0Su||4]
Subscriber Activities: Subscriber’s activities relevant to this DPA are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement as part of its ongoing business operations.
Role: Controller
Categories of Data Subjects: Relevant Data Subjects include any Data Subjects of Personal Data that Subscriber causes F2 AI to process as part of the provisions of the Service, including End-Users, Authorized Users, employees, job candidates, customers, and prospective customers of Subscriber’s products and services.
Categories of Personal Data: Relevant Personal Data includes any Categories of Personal Data Subscriber causes F2 AI to process as part of the provisions of the Service, including:
- Personal details –for example any information that identifies the Data Subject, including name, and contact information.
- Authentication details –for example username, password or PIN code, security questions and other access protocols.
- Technological details –for example internet protocol (IP) addresses, unique identifiers and numbers (including unique identifier in tracking cookies or similar technology), pseudonymous identifiers, precise and imprecise location data, internet / application / program activity data, and device IDs and addresses.
- Transactional data- for example information relating to or needed to complete orders, including order numbers and transaction history. This includes purchase considerations, consuming history and tendencies.
- Demographic data – for example city, state, country of residence, postal code, gender, physical characteristics, stated income or income range, economic standing, and age. Profile data, such as biographical details, job title, avatar, photograph or picture, date of birth, interests, preferences, links to profiles on social media networks.
- Call/video recordings – for example recordings of customer support calls.
Sensitive Categories of Data, and associated additional restrictions/safeguards:
- Categories of sensitive data:None – as noted in Section 6(b) of the DPA, Subscriber agrees that Restricted Data, which includes ‘sensitive data’ (as defined in Clause 8.7 of the SCCs), must not be submitted to the Services.
- Additional safeguards for sensitive data:N/A
Frequency of transfer: Ongoing – as initiated by Subscriber in and through its use, or use on its behalf, of the Services.
Nature of the Processing: Processing operations required in order to provide the Services in accordance with the Agreement.
Purpose of the Processing: Subscriber Personal Data will be processed as necessary to provide the Services as initiated by Subscriber in its use thereof, including to conduct deal intelligence and as described more comprehensively in Exhibit A, the F2 AI Order Form, and complying with any other reasonable instructions provided by Subscriber in accordance with the terms of this DPA.
Duration of Processing / Retention Period: For the period determined in accordance with the Agreement and DPA, including Section 9 of the DPA.
Transfers to (sub)processors: Transfers to Subprocessors are as, and for the purposes, described from time to time in the subprocessor site (https://security.f2.ai/?tab=subprocessors)
Annex 2
European Annex
1. PROCESSING OF PERSONAL DATA
1.1. Where F2 AI receives an instruction from Subscriber that, in its reasonable opinion, infringes the GDPR, F2 AI shall inform Subscriber.
1.2. Subscriber acknowledges and agrees that any instructions issued by Subscriber with regards to the Processing of Personal Data by or on behalf of F2 AI pursuant to or in connection with the Agreement shall be in strict compliance with the GDPR and all other applicable laws.
2. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION
2.1. F2 AI, taking into account the nature of the Processing and the information available to F2 AI, shall provide reasonable assistance to Subscriber, at Subscriber’s cost, with any data protection impact assessments and prior consultations with Supervisory Authorities which Subscriber reasonably considers to be required of it by Article 35 or Article 36 of the GDPR, in each case solely in relation to Processing of Personal Data by F2 AI.
2.2. Except to the extent prohibited by applicable law, Subscriber shall be fully responsible for all time spent by F2 AI (at F2 AI’s then-current professional services rates) in F2 AI’s provision of any cooperation and assistance provided to Subscriber under Paragraph 2.1, and shall on demand reimburse F2 AI any such costs incurred by F2 AI.
3. RESTRICTED TRANSFERS
EU Restricted Transfers
3.1. To the extent that any Processing of Personal Data under this DPA involves an EU Restricted Transfer from Subscriber to F2 AI, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:
(a) populated in accordance with Part 1 of Attachment 1 to Annex 2 (European Annex); and
(b) entered into by the Parties and incorporated by reference into this DPA.
UK Restricted Transfers
3.2. To the extent that any Processing of Personal Data under this DPA involves a UK Restricted Transfer from Subscriber to F2 AI, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:
(a) varied to address the requirements of the UK GDPR in accordance with UK Transfer Addendum and populated in accordance with Part 2 of Attachment 1 to Annex 2 (European Annex); and
(b) entered into by the Parties and incorporated by reference into this DPA.
Swiss Restricted Transfers
3.3. To the extent that any Processing of Personal Data under the DPA involves a Swiss Restricted Transfer from Subscriber to F2 AI, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:
(a) varied to address the requirements of the FADP and populated in accordance with Part 3 of Attachment 1;and
(b) entered into by the Parties and incorporated by reference in the DPA.
(c) Nothing in any applicable SCCs (as deemed amended pursuant to this Section 3.3) should be interpreted or construed in such a way as would limit or exclude the rights of Data Subjects under Clause 18(c) of those SCCs (as deemed amended pursuant to this Section 3.3) to bring legal proceedings before the courts in Switzerland where Switzerland is that Data Subject’s place of habitual residence.
Adoption of new transfer mechanism
3.3. F2 AI may on notice vary this DPA and replace the relevant SCCs with:
(a) any new form of the relevant SCCs or any replacement therefor prepared and populated accordingly (e.g., standard data protection clauses adopted by the European Commission for use specifically in respect of transfers to data importers subject to Article 3(2) of the EU GDPR); or
(b) another transfer mechanism, other than the SCCs, that enables the lawful transfer of Personal Data to F2 AI under this DPA in compliance with Chapter V of the GDPR.
Provision of full-form SCCs
3.4. In respect of any given Restricted Transfer, if requested of Subscriber by a Supervisory Authority, Data Subject or further Controller (where applicable) – on specific written request (made to the contact details set out in Annex 1 (Data Processing Details); accompanied by suitable supporting evidence of the relevant request), F2 AI shall provide Subscriber with an executed version of the relevant set(s) of SCCs responsive to the request made of Subscriber (amended and populated in accordance with Attachment 1 to Annex 2 (European Annex) in respect of the relevant Restricted Transfer) for countersignature by Subscriber, onward provision to the relevant requestor and/or storage to evidence Subscriber’s compliance with Applicable Data Protection Laws.
Operational clarifications
3.5. When complying with its transparency obligations under Clause 8.3 of the SCCs, Subscriber agrees that it shall not provide or otherwise make available, and shall take all appropriate steps to protect, F2 AI’s and its licensors’ trade secrets, business secrets, confidential information and/or other commercially sensitive information.
3.6. Where applicable, for the purposes of Clause 10(a) of Module Three of the SCCs, Subscriber acknowledges and agrees that there are no circumstances in which it would be appropriate for F2 AI to notify any third-party controller of any Data Subject Request and that any such notification shall be the sole responsibility of Subscriber.
3.7. For the purposes of Clause 15.1(a) of the SCCs, except to the extent prohibited by applicable law and/ or the relevant public authority, as between the Parties, Subscriber agrees that it shall be solely responsible for making any notifications to relevant Data Subject(s) if and as required.
3.8. The terms and conditions of Section 7 of the DPA apply in relation to F2 AI’s appointment and use of Subprocessors under the SCCs. Any approval by Subscriber of F2 AI’s appointment of a Subprocessor that is given expressly or deemed given pursuant to that Section 7 constitutes Subscriber’s documented instructions to effect disclosures and onward transfers to any relevant Subprocessors if and as required under Clause 8.8 of the SCCs.
3.9. The audits described in Clauses 8.9(c) and 8.9(d) of the SCCs shall be subject to any relevant terms and conditions detailed in Section 8 of the DPA.
3.10. Certification of deletion of Personal Data as described in Clauses 8.5 and 16(d) of the SCCs shall be provided only upon Subscriber’s written request.
Attachment 1
To Annex 2 (European Annex)
POPULATION OF SCCs
Note
- In the context of any EU Restricted Transfer, the SCCs populated in accordance with Part 1 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Paragraph 3.1 of Annex 2 (European Annex) to the DPA).
- In the context of any UK Restricted Transfer, the SCCs as varied by the UK Transfer Addendum and populated in accordance with Part 2 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Paragraph 3.2 of Annex 2 (European Annex) to the DPA).
- In the context of any Swiss Restricted Transfer, the SCCs as varied and populated by Part 3 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Section 3.3 of Annex 2 (European Annex) to the DPA.
PART 1: POPULATION OF THE SCCs
1. SIGNATURE OF THE SCCs:
Where the SCCs apply in accordance with Paragraph 3.1 of Annex 2 (European Annex) to the DPA each of the Parties is hereby deemed to have signed the SCCs at the relevant signature block in Annex I to the Appendix to the SCCs.
2. MODULES
The following modules of the SCCs apply in the manner set out below (having regard to the role(s) of Subscriber set out in Attachment 1 to Annex 2 (European Annex) to the DPA):
(a) Module Two of the SCCs applies to any EU Restricted Transfer and/or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Subscriber is a Controller in its own right; and/or
(b) Module Three of the SCCs applies to any EU Restricted Transfer and/or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Subscriber is itself acting as a Processor on behalf of any other person.
3. POPULATION OF THE BODY OF THE SCCs
3.1. For each Module of the SCCs, the following applies as and where applicable to that Module and the Clauses thereof:
(a) The optional ‘Docking Clause’ in Clause 7 is not used and the body of that Clause 7 is left intentionally blank.
(b) In Clause 9:
(i) OPTION 2: GENERAL WRITTEN AUTHORISATION applies, and the minimum time period for advance notice of the addition or replacement of Subprocessors shall be the advance notice period set out in Section 7(d) of the DPA; and
(ii) OPTION 1: SPECIFIC PRIOR AUTHORISATION is not used and that optional language is deleted; as is, therefore, Annex III to the Appendix to the SCCs.
(c) In Clause 11, the optional language is not used and is deleted.
(d) In Clause 13, all square brackets are removed and all text therein is retained.
(e) In Clause 17:
i. OPTION 1 applies, and the Parties agree that the SCCs shall be governed by the law of Ireland in relation to any EU Restricted Transfer; and
Ii. OPTION 2 is not used and that optional language is deleted.
(f) For the purposes of Clause 18, the Parties agree that any dispute arising from the SCCs in relation to any EU Restricted Transfer shall be resolved by the courts of Ireland, and Clause 18(b) is populated accordingly.
3.2. In this Paragraph 3, references to “Clauses” are references to the Clauses of the SCCs.
4. POPULATION OF ANNEXES TO THE APPENDIX TO THE SCCs
4.1. Annex I to the Appendix to the SCCs is populated with the corresponding information detailed in Annex 1 (Data Processing Details) to the DPA, with:
(a) Subscriber being ‘data exporter’; and
(b) F2 AI being ‘data importer’.
4.2. Part C of Annex I to the Appendix to the SCCs is populated as below:
The competent supervisory authority shall be determined as follows:
- Where Subscriber is established in an EU Member State: the competent supervisory authority shall be the supervisory authority of that EU Member State in which Subscriber is established.
- Where Subscriber is not established in an EU Member State, Article 3(2) of the GDPR applies and Subscriber has appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State in which Subscriber’s EU representative relevant to the processing hereunder is based (from time-to-time).
- Where Subscriber is not established in an EU Member State, Article 3(2) of the GDPR applies, but Subscriber has not appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State notified in writing to F2 AI’s contact point for data protection identified in Attachment 1 to Annex 2 (European Annex) to the DPA, which must be an EU Member State in which the data subjects whose personal data is transferred under these Clauses in relation to the offering of goods or services to them, or whose behavior is monitored, are located.
4.3. Annex II to the Appendix to the SCCs is populated as below:
General:
- Please refer to Section 4 of the DPA and Annex 4 (Security Measures) to the DPA.
- In the event that Subscriber receives a Data Subject Request under the EU GDPR and requires assistance from F2 AI, Subscriber should email F2 AI’s contact point for data protection identified in Annex 1 (Data Processing Details) to the DPA.
Subprocessors: When F2 AI engages a Subprocessor under these Clauses, F2 AI shall enter into a binding contractual arrangement with such Subprocessor that imposes upon them data protection obligations which, in substance, meet or exceed the relevant standards required under these Clauses and the DPA – including in respect of:
- applicable information security measures;
- notification of Information Security Incidents to F2 AI;
- return or deletion of Personal Data as and where required; and engagement of further Subprocessors.
PART 2: UK RESTRICTED TRANSFERS
1. UK TRANSFER ADDENDUM
1.1. Where relevant in accordance with Paragraph 3.2 of Annex 2 (European Annex) to the DPA, the SCCs also apply in the context of UK Restricted Transfers as varied by the UK Transfer Addendum in the manner described below –
(a) Part 1 to the UK Transfer Addendum. As permitted by Section 17 of the UK Transfer Addendum, the Parties agree:
(i) Tables 1, 2 and 3 to the UK Transfer Addendum are deemed populated with the corresponding details set out in Annex 1 (Data Processing Details) and the foregoing provisions of this Attachment 1 (subject to the variations effected by the Mandatory Clauses described in (b) below); and
(ii) Table 4 to the UK Transfer Addendum is completed by the box labelled ‘Data Importer’ being deemed to have been ticked.
(b) Part 2 to the UK Transfer Addendum. The Parties agreed to be bound by the Mandatory Clauses of the UK Transfer Addendum.
1.2. In relation to any UK Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs, shall be read as a reference to those SCCs as varied in the manner set out in Paragraph 1.1 of this Part 2.
PART 3: SWISS RESTRICTED TRANSFERS
1. VARIATIONS FOR SWISS RESTRICTED TRANSFERS
1.1 Where applicable in accordance with Section 6.4 of the DPA, the SCCs also apply in the context of Swiss Restricted Transfers with the following terms deemed to have the following substituted meanings:
(a) “GDPR” means the FADP;
(b) “European Union”, “Union” and “Member State(s)” each mean Switzerland; and
(c) “supervisory authority” means the FDPIC.
1.2 In relation to any Swiss Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs, shall be read as a reference to those SCCs as varied in the manner set out in Section 1.1 of this Part 3.
Annex 3
State Privacy Laws Annex
- For purposes of this Annex 3, the terms “business,” “commercial purpose,” “sell,” “share,” “targeted advertising” and “service provider” shall have the respective meanings given thereto in the State Privacy Laws, and “personal information” shall mean Personal Data that constitutes personal information governed by the State Privacy Laws.
- It is the parties’ intent that with respect to any personal information, F2 AI is a service provider. F2 AI (a) acknowledges that personal information is disclosed by Subscriber only for limited and specified purposes described in the Agreement; (b) shall comply with applicable obligations under the State Privacy Laws and shall provide the same level of privacy protection to personal information as is required by the State Privacy Laws; (c) agrees that Subscriber has the right to take reasonable and appropriate steps to help to ensure that F2 AI’s use of personal information is consistent with Subscriber’s obligations under the State Privacy Laws; (d) shall notify Subscriber in writing of any determination made by F2 AI that it can no longer meet its obligations under the State Privacy Laws; and (e) agrees that Subscriber has the right, upon notice, including pursuant to the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
- F2 AI shall not (a) sell or share any personal information or use it for targeted advertising; (b) retain, use or disclose any personal information for any purpose other than for the specific purpose of providing the Services, including retaining, using, or disclosing the personal information for a commercial purpose other than the provision of the Services; (c) retain, use or disclose the personal information outside of the direct business relationship between F2 AI and Subscriber; or (d) combine personal information received pursuant to the Agreement with personal information (i) received from or on behalf of another person, or (ii) or collected from F2 AI’s own interaction with any Consumer to whom such personal information pertains, except in each case (a) through (d) as and to the extent necessary as a part of F2 AI’s provision of the Services or as otherwise permitted by a service provider or processor under the State Privacy Laws. F2 AI hereby certifies that it understands its obligations under this Section 2 and will comply with them.
- Giving Subscriber notice of Subprocessor engagements in accordance with Section 7 of the DPA shall satisfy F2 AI’s obligation under the State Privacy Laws to give notice of and an opportunity to object to such engagements.
- F2 AI agrees that Subscriber may conduct audits, in accordance with Section 8 of the DPA, to help ensure that F2 AI’s use of personal information is consistent with F2 AI’s obligations under the State Privacy Laws.
- The parties acknowledge that F2 AI’s retention, use and disclosure of personal information authorized by Subscriber’s instructions documented in the DPA are integral to F2 AI’s provision of the Services and the business relationship between the parties.
Annex 4
Security Measures
- Organizational management and dedicated staff responsible for the F2 AI’s information security program.
- Data security controls which include, at a minimum, logical segregation of data, restricted (e.g., role-based) access and monitoring, and utilization of commercially available industry standard technologies for Personal Data that is transmitted over public networks (i.e., the internet).
- Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions.
- Password controls designed to manage and control password strength, expiration and usage including prohibiting users from sharing passwords.
- Monitoring and maintenance of technology and information systems, including secure disposal of systems and media prior to final disposal or release from the F2 AI’s possession.
- Change management procedures and tracking mechanisms designed to test, approve and monitor all material changes to the F2 AI’s technology and information assets.
- Incident management procedures design to allow F2 AI to investigate, respond to, mitigate and notify of events related to the F2 AI’s technology and information assets.
- Network security controls that provide for the use of enterprise firewalls and intrusion detection systems designed to protect systems from intrusion and limit the scope of any successful attack.
- Vulnerability assessment, patch management and threat protection technologies designed to identify, assess, mitigate and protect against identified security threats, viruses and other malicious code.
- Business resiliency/continuity and disaster recovery procedures designed to maintain service and/or recovery from foreseeable emergencies or disasters.