Data Processing Agreement
Archipelago Data Processing Agreement
Last Updated: August 28, 2026
The Parties have entered into a Master Subscription Agreement whereby the Customer subscribes to the Archipelago Analytics, Inc. ("Provider") SaaS service and/or other Provider services (the "Agreement"). This Data Processing Agreement (“DPA”) forms part of the Agreement. To the extent that the Provider processes any personal data as a Processor (as defined below) on behalf of the Customer (or, where applicable, Customer Affiliates) in connection with the provision of the Service, and where that personal data falls within the scope of the GDPR (and/or, if applicable the UK GDPR and/or the Swiss Data Protection Laws as defined in Schedule A of the DPA), the Parties have agreed that it shall do so pursuant to the terms of this DPA.
1. DEFINITIONS
1.1 “Affiliate” means an entity controlled, controlling trolling or under common control with a party, where control means at least 50% ownership or power to direct an entity’s management.
1.2 “Audit” and “Audit Parameters” are defined in Section 9.3 below.
1.3 “Audit Report” is defined in Section 9.2 below.
1.4 “Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of Processing of Personal Data.
1.5 "Customer" is identified in the Agreement.
1.6 “Customer Data” means Customer Data as defined in the Agreement.
1.7 “Customer Instructions” is defined in Section 3.1 below.
1.8 “Customer Personal Data” means Personal Data in Customer Data.
1.9 “Data Protection Laws” means all laws and regulations applicable to the Processing of Customer Personal Data under the Agreement, including, as applicable: (i) U.S. state and federal privacy laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and any binding regulations promulgated thereunder (“CCPA”), (ii) any other U.S. state or federal security requirements applicable to the Processing of Protected Information, including the Gramm-Leach-Bliley Act, as amended from time to time and as implemented by the various states, (iii) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR” or “GDPR”), (iii) the Swiss Federal Act on Data Protection (“FADP”), (iv) the EU GDPR as it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended by the Data Use and Access Act 2025 (collectively, the "UK GDPR"); (v) (the European e-Privacy Directive 2002/58/EC; and (vi) the UK Data Protection Act 2018; in each case, as updated, amended or replaced from time to time. Data Protection Laws includes any other applicable data privacy and security law enacted after the Effective Date which is applicable to the Processing of Customer Personal Data, to the extent such law contains similar requirements as set forth in this DPA.
1.10 “Data Subject” means the identified or identifiable natural person to whom Customer Personal Data relates.
1.11 “DPA Effective Date” is the Effective Date of the Agreement.
1.12 “EEA” means European Economic Area.
1.13 "EU Standard Contractual Clauses" or "EU SCCs" means the Standard Contractual Clauses approved by the European Commission in decision 2021/914.
1.14 “Personal Data” means information about an identified or identifiable natural person or which otherwise constitutes “personal data”, “personal information”, “personally identifiable information” or similar terms as defined in Data Protection Laws.
1.15 “Processing” and inflections thereof refer to any operation or set of operations that is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
1.16 “Processing Details” means the Subject Matter and Details of Processing specified on Schedule D and Security Measures specified on Schedule F.
1.17 “Processor” means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Controller.
1.18 “Restricted Transfer” means: (i) where EU GDPR applies, a transfer of Customer Personal Data from the EEA to a country outside the EEA that is not subject to an adequacy determination, (ii) where UK GDPR applies, a transfer of Customer Personal Data from the United Kingdom to any other country that is not subject to an adequacy determination or (iii) where FADP applies, a transfer of Customer Personal Data from Switzerland to any other country that is not subject to an adequacy determination.
1.19 “Security Incident” means any data breach or breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data being Processed by Provider.
1.20 “Security Measures” means the technical and organizational security measures for the Service as set forth in the Agreement or, if not set forth in the Agreement, as specified on Schedule F.
1.21 "Provider" is identified on the first page of this DPA.
1.22 “Service” means the services provided by Provider to Customer under the Agreement.
1.23 “Specified Notice Period” is 72 hours.
1.24 “Subprocessor” means any third party authorized by Provider to Process any Customer Personal Data.
1.25 “Subprocessor List” means the list of Provider’s Subprocessors as identified or linked to on Schedule E.
1.26 "Subprocessor Notice Method" means email or in-product notification to an administrator.
1.27 "UK International Data Transfer Agreement" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, Version B1.0, in force as of March 21, 2022.
2. SCOPE AND DURATION
2.1 Roles of the Parties. This DPA applies to Provider as a Processor of Customer Personal Data and to Customer and/or Customer’s Affiliates as a Controller or Processor of Customer Personal Data.
2.2 Scope of DPA. This DPA applies to Provider’s Processing of Customer Personal Data under the Agreement to the extent such Processing is subject to Data Protection Laws. This DPA is governed by the governing law of the Agreement unless otherwise required by Data Protection Laws.
2.3 Duration of DPA. This DPA commences on the DPA Effective Date and terminates upon expiration or termination of the Agreement (or, if later, the date on which Provider has ceased all Processing of Customer Personal Data).
2.4 Schedules. Schedule A (Cross-Border Transfer Mechanisms) and Schedule B (Region-Specific Terms), Schedule C (Parties to Processing), Schedule D (Details of Processing), Schedule E (Subprocessors) and Schedule F (Technical and Organizational Measures) are incorporated into and form part of this DPA.
2.5 Order of Precedence. In the event of any conflict or inconsistency among the following documents, the order of precedence will be: 1) any Standard Contractual Clauses or other measures set forth in Schedule A (Cross-Border Transfer Mechanisms), 2) Schedule B (Region-Specific Terms), 3) Schedules C through F, 4) this DPA and 5) the Agreement. To the fullest extent permitted by Data Protection Laws, any claims brought in connection with this DPA will be subject to the terms and conditions, including, but not limited to, the exclusions and limitations, set forth in the Agreement.
3. PROCESSING OF PERSONAL DATA
3.1 Customer Instructions.
-
- Provider will Process Customer Personal Data as a Processor only: (i) in accordance with Customer or Customer Affiliates’ Instructions or (ii) to comply with Provider’s obligations under applicable laws, subject to any notice requirements under Data Protection Laws.
- “Customer Instructions” means: (i) Processing to provide the Service and perform Provider’s obligations in the Agreement (including this DPA) and (ii) other reasonable documented instructions of Customer consistent with the terms of the Agreement.
- Details regarding the Processing of Customer Personal Data by Provider are set forth in the Processing Details.
- Provider will notify Customer if it receives an instruction that Provider reasonably determines infringes Data Protection Laws (but Provider has no obligation to actively monitor Customer’s compliance with Data Protection Laws).
- To the extent that any of the Customer Instructions require processing of Customer Personal Data in a manner that falls outside the scope of the Service, Provider may make the performance of any such instructions subject to the payment by the Customer of any costs and expenses incurred by Provider or such additional charges as Provider may reasonably determine; or terminate the Agreement and the Service.
3.2 Confidentiality
-
- Provider will protect Customer Personal Data in accordance with its confidentiality obligations as set forth in the Agreement.
- Provider will ensure personnel who Process Customer Personal Data either enter into written confidentiality agreements or are subject to statutory obligations of confidentiality.
3.3 Customer Affiliates.
-
- The obligations and rights of Customer under this DPA apply equally to Customer Affiliates.
- Customer warrants that, with respect to the Customer Affiliates directly or indirectly bound by the Agreement, it is duly authorized (i) to conclude this DPA for and on behalf of any such Customer Affiliates, and that each Customer Affiliate that transfers Customer Personal Data to Provider shall be bound by the terms of this DPA as if they were the Customer; and (ii) to receive and respond to any notices or communications under this DPA on behalf of Customer Affiliates.
- The Parties agree that any notice or communication sent by Provider to the Customer shall satisfy any obligation to send such notice or communication to a Customer Affiliate.
3.4 Compliance with Laws.
-
- Provider (and its Affiliates) and Customer (and its Affiliates) will each comply with Data Protection Laws applicable to their respective Processing of Customer Personal Data.
- Customer will comply with Data Protection Laws in its issuing of Customer Instructions to Provider. Customer will ensure that it has established all necessary lawful bases under Data Protection Laws to enable Provider to lawfully Process Customer Personal Data for the purposes contemplated by the Agreement (including this DPA), including, as applicable, by obtaining all consents from, and giving all necessary notices to, Data Subjects, as required by Data Protection Laws.
3.5 Changes to Laws. The Parties will work together in good faith to negotiate an amendment to this DPA as either party reasonably considers necessary to address the requirements of Data Protection Laws from time to time.
4. Subprocessors
4.1 Use of Subprocessors.
-
- Customer generally authorizes Provider to engage Subprocessors to Process Customer Personal Data. Customer further agrees that Provider may engage its Affiliates as Subprocessors.
- Provider will: (i) enter into a written agreement with each Subprocessor imposing data Processing and protection obligations substantially the same as those set out in this DPA and (ii) remain liable for compliance with the obligations of this DPA and for any acts or omissions of a Subprocessor that cause Provider to breach any of its obligations under this DPA.
4.2 Subprocessor List. Provider will maintain an up-to-date list of its Subprocessors, including their functions and locations, as specified in the Subprocessor List.
4.3 Notice of New Subprocessors. Provider may update the Subprocessor List from time to time. At least 30 days before any new Subprocessor Processes any Customer Personal Data, Provider will add such Subprocessor to the Subprocessor List and notify Customer in accordance with the Subprocessor Notice Method.
4.4 Objection to New Subprocessors.
-
- If, within 30 days after notice of a new Subprocessor, Customer notifies Provider in writing that Customer objects to Provider’s appointment of such new Subprocessor based on reasonable data protection concerns, including by providing documentary evidence that reasonably shows that the Subprocessor does not or cannot comply with the requirements in this DPA (an "Objection"), the Parties will discuss such Objection in good faith.
- In the event of an Objection, Provider will use reasonable endeavors to work with Customer to address the issues raised in the objection or will recommend a commercially reasonable alternative to prevent the applicable sub-processor from processing the Customer Personal Data which Provider may consider.
- If the Parties are unable to reach a mutually agreeable resolution to Customer’s objection to a new Subprocessor within a reasonable period of time, which shall not exceed 60 days from the date when the objection was raised, Customer, as its sole and exclusive remedy, may terminate the Agreement and cancel the Service by providing not less than 30 days' written notice to Provider, and Provider will refund any prepaid, unused fees under the Agreement as of the date of such termination.
5. SECURITY; INCIDENTS
5.1 Technical and Organizational Measures. Provider will implement and maintain reasonable and appropriate technical and organizational measures, procedures and practices, as appropriate to the nature of the Customer Personal Data, that are designed to protect the security, confidentiality, integrity and availability of Customer Personal Data and protect against Security Incidents, in accordance with Provider’s Security Measures. Provider will regularly monitor its compliance with such Security Measures.
5.2 Incident Notice and Response.
-
- Provider will implement and follow procedures to detect and respond to Security Incidents.
- Provider will: (i) notify Customer without undue delay and not later than the Specified Notice Period, after becoming aware of a Security Incident affecting Customer and (ii) make reasonable efforts to identify the cause of the Security Incident, remediate the cause to the extent within Provider's reasonable control, and mitigate the effects of the Security Incident.
- Upon Customer’s request and taking into account the nature of the applicable Processing, Provider will assist Customer by providing, when available, information reasonably necessary for Customer to meet its Security Incident notification obligations under Data Protection Laws.
- Customer acknowledges that Provider’s notification of a Security Incident is not an acknowledgement by Provider of its fault or liability.
- Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, including unsuccessful login attempts, pings, port scans, denial of service attacks or other network attacks on firewalls or networked systems.
5.3 Customer Responsibilities.
-
- Customer is responsible for reviewing the information made available by Provider relating to data security and making an independent determination as to whether the Service meets Customer’s requirements and legal obligations under Data Protection Laws.
- Customer is solely responsible for complying with Security Incident notification laws applicable to Customer and fulfilling any obligations to give notices to government authorities, affected individuals or others relating to any Security Incidents.
6. DATA PROTECTION IMPACT ASSESSMENT
Upon Customer’s request and taking into account the nature of the applicable Processing, to the extent such information is available to Provider, Provider will assist Customer in fulfilling Customer’s obligations under Data Protection Laws to carry out a data protection impact or similar risk assessment related to Customer’s use of the Service, including, if required by Data Protection Laws, by assisting Customer in consultations with relevant government authorities.
7. DATA SUBJECT REQUESTS
7.1 Assisting Customer. Upon Customer’s request and taking into account the nature of the applicable Processing, Provider will assist Customer by appropriate technical and organizational measures, insofar as possible, in complying with Customer’s obligations under Data Protection Laws to respond to requests from individuals to exercise their rights under Data Protection Laws, provided that Customer cannot reasonably fulfill such requests independently (including through use of the Service).
7.2 Data Subject Requests. If Provider receives a request from a Data Subject in relation to the Data Subject’s Customer Personal Data, Provider will notify Customer and advise the Data Subject to submit the request to Customer (but not otherwise communicate with the Data Subject regarding the request except as may be required by Data Protection Laws), and Customer will be responsible for responding to any such request.
8. DATA RETURN OR DELETION
8.1 During the Term of the Agreement. During the term of the Agreement, Customer may, through the features of the Service or such other means specified in the Additional Terms, access, return to itself or delete Customer Personal Data.
8.2 Post Termination.
-
-
Following termination or expiration of the Agreement, Provider will, in accordance with its obligations under the Agreement, delete all Customer Personal Data from Provider’s systems. If the Agreement contains no such obligations, Provider will delete or return to Customer all Customer Personal Data in Provider's possession, custody, or control as soon as reasonably practicable after such termination or expiration.
-
Deletion will be in accordance with industry-standard secure deletion practices. Provider will issue a certificate of deletion upon Customer’s request.
-
Notwithstanding the foregoing, Provider may retain Customer Personal Data: (i) as required by Data Protection Laws or (ii) in accordance with its standard backup or record retention policies, provided that, in either case, Provider will (x) maintain the confidentiality of, and otherwise comply with the applicable provisions of this DPA with respect to, retained Customer Personal Data and (y) not further Process retained Customer Personal Data except for such purpose(s) and duration specified in such applicable Data Protection Laws.
-
9. AUDITS
9.1 Provider Records Generally. Provider will keep records of its Processing in compliance with Data Protection Laws and, upon Customer’s request, make available to Customer any records reasonably necessary to demonstrate compliance with Provider’s obligations under this DPA and Data Protection Laws.
9.2 Third-Party Compliance Program.
-
-
Provider will describe its third-party audit and certification programs (if any) and make summary copies of its audit reports (each, an “Audit Report”) available to Customer upon Customer’s written request at reasonable intervals (subject to confidentiality obligations).
-
Customer may share a copy of Audit Reports with relevant government authorities as required upon their request.
-
Customer agrees that any audit rights granted by Data Protection Laws will be satisfied by Audit Reports and the procedures of Section 9.3 (Customer Audit) below.
-
9.3 Customer Audit.
-
-
Subject to the terms of this Section 9.3, Customer has the right, at Customer’s expense, to conduct an audit of reasonable scope and duration pursuant to a mutually agreed-upon audit plan with Provider that is consistent with the Audit Parameters (an “Audit”).
-
Customer may exercise its Audit right: (i) to the extent Provider’s provision of an Audit Report does not provide sufficient information for Customer to verify Provider’s compliance with this DPA or the Parties’ compliance with Data Protection Laws, (ii) as necessary for Customer to respond to a government authority audit or (iii) in connection with a Security Incident.
- Each Audit must conform to the following parameters (“Audit Parameters”): (i) be conducted by an independent third party that will enter into a confidentiality agreement with Provider, (ii) be limited in scope to matters reasonably required for Customer to assess Provider’s compliance with this DPA and the Parties’ compliance with Data Protection Laws, (iii) occur at a mutually agreed date and time and only during Provider’s regular business hours, (iv) occur no more than once annually (unless required under Data Protection Laws or in connection with a Security Incident), (v) cover only facilities controlled by Provider, (vi) restrict findings to Customer Personal Data only and (vii) treat any results as confidential information to the fullest extent permitted by Data Protection Laws.
-
10. COSTS
10.1 Customer shall pay to Provider all costs, including reasonable labor costs calculated on a time-spent basis and expenses incurred by Provider in connection with: (i) implementing any modifications to the delivery of the Service pursuant to the process set out under Section 3.1(e); (ii) facilitating and contributing to any audits of Provider under or Clauses 8.9(c) and (d) of the EU SCCs; (iii) facilitating and contributing to any audits of the Customer conducted by a supervisory authority; (iv) responding to queries or requests for information from the Customer relating to the processing of Customer Personal Data under Clauses 8.9(a), (c) or (e) of the EU SCCs; (v) any assistance provided by Provider to the Customer with its fulfilment of its obligations to respond to data subjects' requests for the exercise of their rights under the GDPR and under Clauses 10(a), (b) or (c) of the SCCs; and (vi) any assistance provided by Provider to the Customer with any data protection impact assessments or prior consultation with any supervisory authority of the Customer.
10.2 Remediation Efforts. Customer is solely responsible for complying with Security Incident notification laws applicable to Customer and fulfilling any obligations to give notices to government authorities, affected individuals or others relating to any Security Incidents. Upon request of Customer, Provider shall take prompt action, at its own expense, to investigate the Security Incident and to identify, prevent, and mitigate the effects of the Security Incident and, with Customer’s prior written approval, to carry out any recovery or other action necessary to remedy the Security Incident. Provider shall not release or publish any filing, communication, notice, press release, or report concerning the Security Incident without Customer’s prior written approval (except where Provider is required to do so by law)
11. LIABILITY FOR BREACH OF THIS DPA
11.1 [Provider shall reimburse Customer for reasonable, documented costs Customer incurs to send all notifications as required by Data Protection Laws, provide credit monitoring and identity theft protection services to affected consumers, and for any forensic investigation, regulatory investigation, or litigation fees, including attorneys’ fees, costs, fines, and damages relating to the Security Incident, all of the foregoing only to the extent caused by Provider’s negligence or breach of its obligations under this DPA.]
11.2 Any exclusions or limitations of liability set out in the Agreement shall also apply to any Losses suffered by either Party (whether in contract, tort (including negligence) or for restitution, or for breach of statutory duty or misrepresentation or otherwise) under this DPA. "Losses" means any demand, contribution, claim, action, proceeding, liability, loss, damage, costs, expenses and charges. Nothing in this DPA or the Agreement shall limit or exclude any liability of either Party pursuant to Clause 12 of the EU SCCs.
12. MODIFICATIONS
Provider may modify or supplement this DPA, with notice to Customer, (i) if required to do so by a supervisory authority or other government or regulatory entity, (ii) if necessary to comply with applicable law, (iii) to implement amended Standard Contractual Clauses laid down by the European Commission or (iv) to adhere to a code of conduct or certification mechanism approved or certified pursuant to Art. 40, 42 and 43 of the GDPR. Customer shall notify Provider if it does not agree to a modification no more than thirty (30) days following the effective date of the modification, in which case Provider may terminate this DPA and the Agreement with thirty (30) days prior notice, whereby in the case of an objection not based on non-compliance of the modifications with applicable data protection law, Provider shall remain entitled to its agreed remuneration until the end of the original term of the Agreement.
13. CROSS-BORDER TRANSFERS/REGION-SPECIFIC TERMS
13.1 Cross-Border Data Transfers.
-
-
Provider (and its Affiliates) may Process and transfer Customer Personal Data globally as necessary to provide the Service.
-
If Provider engages in a Restricted Transfer, it will comply with Schedule A (Cross-Border Transfer Mechanisms).
-
13.2 Region-Specific Terms. To the extent that Provider Processes Customer Personal Data protected by Data Protection Laws in one of the regions listed in Schedule B (Region-Specific Terms), then the terms specified therein with respect to the applicable jurisdiction(s) will apply in addition to the terms of this DPA.
SCHEDULE A: CROSS-BORDER TRANSFER MECHANISMS
- EU Transfers. Where Customer Personal Data is protected by EU GDPR and is subject to a Restricted Transfer, the following applies:
- The EU SCCs are hereby incorporated by reference as follows:
- Module 2 (Controller to Processor) applies where Customer is a Controller of Customer Personal Data and Provider is a Processor of Customer Personal Data;
- Module 3 (Processor to Processor) applies where Customer is a Processor of Customer Personal Data (on behalf of a third-party Controller) and Provider is a Processor of Customer Personal Data;
- Customer is the "data exporter" and Provider is the "data importer"; and
- by entering into this DPA, each party is deemed to have signed the EU SCCs (including their Annexes) as of the DPA Effective Date.
- For each Module, where applicable the following applies:
- the optional docking clause in Clause 7 does not apply;
- in Clause 9, Option 2 will apply, the minimum time period for prior notice of Subprocessor changes shall be as set out in Section 4.3 of this DPA, and Provider shall fulfill its notification obligations by notifying Customer of any Subprocessor changes in accordance with Section 4.3 of this DPA;
- in Clause 11, the optional language does not apply;
- in Clause 13, all square brackets are removed with the text remaining;
- in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Designated EU Governing Law;
- in Clause 18(b), disputes will be resolved before the courts of the Designated EU Member State;
- Schedule C contains the information required in Annex 1.A (List of Parties) of the EU SCCs; and
- Schedule D contains the information required in Annex 1.B (List of Transfer) of the EU SCCs; and
- Schedule F contains the information required in Annex 2 of the EU SCCs.
- Where context permits and requires, any reference in this DPA to the EU SCCs shall be read as a reference to the EU SCCs as modified in the manner set forth in this Section 1.
- The EU SCCs are hereby incorporated by reference as follows:
- Swiss Transfers. Where Customer Personal Data is protected by the FADP and is subject to a Restricted Transfer, the following applies:
- The EU SCCs apply as set forth in Section 1 (EU Transfers) of this Schedule A with the following modifications:
- in Clause 13, the competent supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner;
- in Clause 17 (Option 1), the EU SCCs will be governed by the laws of Switzerland;
- in Clause 18(b), disputes will be resolved before the courts of Switzerland;
- the term Member State must not be interpreted in such a way as to exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence in accordance with Clause 18(c); and
- all references to the EU GDPR in this DPA are also deemed to refer to the FADP.
- The EU SCCs apply as set forth in Section 1 (EU Transfers) of this Schedule A with the following modifications:
- UK Transfers. Where Customer Personal Data is protected by the UK GDPR and is subject to a Restricted Transfer, the following applies:
-
- The EU SCCs apply as set forth in Section 1 (EU Transfers) of this Schedule A with the following modifications:
- each party shall be deemed to have signed the “UK Addendum to the EU Standard Contractual Clauses” (“UK Addendum”) issued by the Information Commissioner’s Office under section 119 (A) of the Data Protection Act 2018;
- the EU SCCs shall be deemed amended as specified by the UK Addendum in respect of the transfer of Customer Personal Data;
- in Table 1 of the UK Addendum, the Parties’ key contact information is located in the Processing Details;
- in Table 2 of the UK Addendum, information about the version of the EU SCCs, modules and selected clauses which this UK Addendum is appended to are located above in this Schedule A;
- in Table 3 of the UK Addendum:
- the list of parties is located in Schedule C;
- the description of transfer is located in Schedule D;
- Annex II is located in Schedule F; and
- the list of Subprocessors is located in Schedule E.
- in Table 4 of the UK Addendum, both the Importer and the Exporter may end the UK Addendum in accordance with its terms (and the respective box for each is deemed checked); and
- in Part 2: Part 2 - Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with section 119 (A) of the Data Protection Act 2018 on 2 February 2022, as it is revised under section 18 of those Mandatory Clauses.
- The EU SCCs apply as set forth in Section 1 (EU Transfers) of this Schedule A with the following modifications:
-
-
Data Privacy Framework. For clarity, a transfer of Customer Personal Data from the EU, UK or Switzerland to Provider in the United States subject to the EU-U.S. Data Privacy Shield Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and/or the Swiss-U.S. Data Privacy Shield Framework, as applicable (collectively, the “DPF”), shall not constitute a Restricted Transfer so long as Provider maintains an active certification to the DPF and certification to the DPF remains a legal basis for transfer of Personal Data to the United States under the GDPR, UK GDPR or FADP, as applicable.
SCHEDULE B: REGION-SPECIFIC TERMS
A. CALIFORNIA
- Definitions. CCPA and other capitalized terms not defined in this Schedule are defined in the DPA.
- “business purpose”, “commercial purpose”, “personal information”, “sell”, “service provider” and “share” have the meanings given in the CCPA.
- The definition of “Data Subject” includes “consumer” as defined under the CCPA.
- The definition of “Controller” includes “business” as defined under the CCPA.
- The definition of “Processor” includes “service provider” as defined under the CCPA.
- Obligations.
- Customer is providing the Customer Personal Data to Provider under the Agreement for the limited and specific business purposes of providing the Service as described in the Processing Details and otherwise performing under the Agreement.
- Provider will comply with its applicable obligations under the CCPA and provide the same level of privacy protection to Customer Personal Data as is required by the CCPA.
- Provider acknowledges that Customer has the right to: (i) take reasonable and appropriate steps under Section 9 (Audits) of this DPA to help to ensure that Provider’s use of Customer Personal Data is consistent with Customer’s obligations under the CCPA, (ii) receive from Provider notice and assistance under Section 7 (Data Subject Requests) of this DPA regarding consumers’ requests to exercise rights under the CCPA and (iii) upon notice, take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
- Provider will notify Customer promptly after it makes a determination that it can no longer meet its obligations under the CCPA.
- Provider will not retain, use or disclose Customer Personal Data: (i) for any purpose, including a commercial purpose, other than the business purposes described in Section A.2.1 of this Schedule or (ii) outside of the direct business relationship between Provider with Customer, except, in either case, where and to the extent permitted by the CCPA.
- Provider will not sell or share Customer Personal Data received under the Agreement.
- Provider will not combine Customer Personal Data with other personal information except to the extent a service provider is permitted to do so by the CCPA.
SCHEDULE C: PARTIES TO THE PROCESSING
1. Relevant Information on Provider / data importer and Customer / data exporter
| Party: | Customer / data exporter | Customer / data importer |
| Role | Controller | Processor |
| Contact | Customer Contact details as set out in the Master Subscription Agreement |
Name: Archipelago Analytics, Inc. (Company) Contact details as set out in the Master Subscription Agreement |
| Where applicable: Data protection officer and/or UK representative | As set out in Customer privacy notice | As set out in Provider privacy notice |
| Where applicable: Data protection officer and/or EU representative | As set out in Customer privacy notice | As set out in Provider privacy notice |
| Activities relevant to the data transferred | Use of Services | Provision of Services (as defined in the Agreement) |
| Competent supervisory authority | To the extent that the EU GDPR applies and the competent supervisory authority is not explicitly stipulated herein, the text set out in Footnote 1 shall be incorporated herein.] [To the extent that UK Data Protection Laws apply to the Customer's processing: The Information Commissioner] |
n/a |
1 Each supervisory authority of the EU and EEA is competent for the performance of the tasks assigned to and the exercise of the powers on the territory of its own Member State. A list of the supervisory authorities across the European Union and EEA can be found under the following link: https://edpb.europa.eu/about-edpb/about-edpb/members_en
As to Germany, the supervisory authority mentioned under the aforementioned link called "Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit" is responsible for supervising public authorities of the federal government, public-sector companies, insofar as they participate in the competition, and companies which process data from natural and legal persons in order to commercially provide telecommunication services while the responsibility for supervision does not already come from Section 115 para 4 of the Telecommunication Act ("Telekommunikationsgesetzes"). Additionally, there is also a supervisory authority in each federal state ("Bundesland") in Germany which is responsible for private entities established in its respective federal state. Please find a list of these German supervisory authorities under the following link: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html;jsessionid=1D7E492F9E963C3ADC18161A232AADBD.intranet241
2. Relevant Information of Customer Affiliates – To be completed by Customer as applicable and submitted to Provider
| Customer Affiliate |
[complete for each Affiliate]
Name: [***]
Address: [***]
|
| Role | Controller |
| Contact Person |
Name: [***] Position: [***] Contact details: [***] |
| Where applicable: Data protection officer and/or UK representative | [***] |
| Where applicable: Data protection officer and/or EU representative | [***] |
| Activities relevant to the data transferred | [***] |
| Competent supervisory authority | [***] [To the extent that the EU GDPR applies and the competent supervisory authority is not explicitly stipulated herein, the text set out in Footnote 1 shall be incorporated herein.] [To the extent that UK Data Protection Laws apply to the Customer Affiliate's processing: The Information Commissioner] |
SCHEDULE D: DETAILS OF PROCESSING
1. Categories of data subjectsThe categories of data subjects whose personal data may be transferred:
- Prospects, customers, business partners, and vendors of the data exporter (who are physical persons)
- Employees, contractors, affiliates, agents, advisors, and contact persons of data exporter customers, business partners, and vendors
- Employees, agents, advisors, and contractors of data exporter (who are physical persons)
- Data exporters end users and authorized by data exporter to use the Service
2. Categories of personal data
The transferred categories of personal data may include:
- Name, address and email address, job title
- Employer
- Employee ID data
- Biographical information excluding special category data
- Localization data
3. Special categories of personal data (if applicable)
The transferred personal data includes the following special categories of data:
- None
4. Frequency of the transfer
The frequency of the transfer is:
- Throughout the duration of the Agreement
5. Subject matter of processing
The subject matter of the processing is:
- Customer employee data: to manage relationship with Customer and related to the performance of the Agreement
- Customer and/or Customer’s Users and Customer’s service provider’s personal data: incidental processing related to the provision of the Services as set out in the Agreement
6. Nature of the processing
The nature of the processing is:
- transfer (by data exporter), recording, storage, erasure, and onward transfer
7. Purpose(s) of the data transfer and further processing
The purpose/s of the data transfer and further processing is/are:
- performance of the Services as described in the Agreement.
8. Duration
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: as stated in the Agreement.
9. Sub-processor (if applicable)
As set out in Schedule E
SCHEDULE E: SUBPROCESSORS
List of Company of sub-processors available at:
https://www.onarchipelago.com/customers/subprocessors
SCHEDULE F: TECHNICAL AND ORGANISATIONAL MEASURES
This Schedule F sets forth the Provider’s security principles and architecture with respect to the administrative, technical, and physical controls applicable to the Service. Capitalized terms in this attachment shall have the meaning assigned to them in the Agreement unless otherwise defined herein.
1. Principles.
The following principles guide the Provider’s design and implementation of its security program and practices: (a) physical and environmental security to protect the Services against unauthorized access or use; (b) maintenance of availability for operation and use of the Services; (c) confidentiality to protect Customer Personal Data; and (d) integrity to maintain the integrity of data maintained in the Services.
2. Security Program.
The Provider maintains an information security program, which includes: (a) a formal risk management program; (b) periodic risk assessments of systems and networks that process Customer Personal Data conducted on at least an annual basis; (c) monitoring for security incidents and maintenance of a tiered remediation plan to implement timely fixes to discovered vulnerabilities; (d) a written information security policy and incident response plan in furtherance of the security, confidentiality, integrity, and availability of Customer Personal Data.
3. Data Centers.
The Provider currently uses Amazon Web Services (AWS) to provide management and hosting of production servers and databases. AWS employs a robust physical security program with multiple certifications, including SSAE 16 and ISO 27001 certification. For further details of these controls please visit: https://aws.amazon.com/compliance/data-center/controls/.
4. Access, Controls, and Policies.
Access to manage Provider’s AWS environment requires multi-factor authentication, ssh access to the Services is logged, and access to Customer Personal Data is restricted to a limited set of approved Provider personnel. All personnel with access to Customer Personal Data have passed background checks. Personnel are trained on documented information security and privacy procedures. Access to Provider’s AWS environment must be requested with a valid business reason / job duty responsibility and subject to approval by authorized personnel. Access is promptly revoked upon termination of employment or change of duties.
AWS networking features, such as security groups, are leveraged to restrict access to AWS instances and resources and are configured to restrict access using the principle of least privilege.
For support and onboarding purposes, the Provider application implements a role-based access control model allowing varying levels of access and explicit grants of access to Customer Personal Data for support and onboarding purposes. All access is logged.
All Customer Personal Data onboarding activity managed by Provider on the customer’s behalf is project managed and executed through an onboarding job application that allows an assigned data engineer to propose changes that are then reviewed and approved by a data manager before going live. An audit trail of changes is recorded.
5. Capture of Personal Data
Provider aims to capture the minimal personally identifiable information about its users in order to provide support for application functionality, analytics on application use, and communication.
Provider utilizes a robust third party identity service, currently Auth0, for user authentication and profile services. User profile data is stored in our Auth0 tenant instance. Privileged application roles are recorded in the Provider database by email. Auth0 provides logging and user lifecycle capabilities such as automated and manual blocking.
6. Encryption.
Customer Personal Data remains encrypted at rest and the connection to platform.onrchipelago.com is encrypted with 256-bit encryption and supports TLS 1.2 and annual key rotation. Logins and sensitive data transfer are performed over encrypted protocols such as TLS or SSH.
7. Isolation / Separation
The Provider application follows standard multi-tier web application architecture with the main web application being delivered and executed within the user’s web browser. This connects to a load balanced API tier over SSL. The API tier connects to the data tier over SSL. The minimal access required between tiers is enforced utilizing standard AWS features.
Code deployment and infrastructure management follows CI / CD best practices. All changes are peer reviewed and tested prior to code merge. The production release process is fully automated taking an existing certified build from the staging environment and deploying this to production after an approval action performed by authorized personnel.
8. Backup and Restoration.
Provider utilizes a two-tier strategy for database backups. First, the native AWS RDS backup and restore capability is utilized which performs automated daily snapshots and retains database logs in addition to enable near real time point in time restore. In addition, a second logical backup is scheduled daily which saves the data to an encrypted private S3 bucket. The database is configured with multiple availability zones and configured for automated failover to a standby in the event of primary database or AWS availability zone failure.
9. Vendor Management.
Provider takes reasonable steps to select and retain only third-party service providers that will maintain and implement the security measures consistent with the measures stated herein. Before software is implemented or a software vendor can be used by Provider, Provider security reviews the vendor’s security policies, certifications, protocols, and security track record. Provider security may reject use of any software or software vendor for failure to demonstrate the ability to sufficiently protect Provider’s data and Users.
10. Security Incident Response.
Provider maintains an incident response plan designed to establish a reasonable and consistent response to security incidents and suspected security incidents involving the accidental or unlawful destruction, loss, theft, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored, or otherwise processed by Provider.
11. Antivirus and Security Scans.
Anti-virus or anti-malware applications have been installed to detect or prevent unauthorized or malicious software. Provider runs security scans on a regular basis. For virus monitoring, Provider automatically or manually updates most software it runs and outsources to AWS when logical and possible. Provider maintains a vulnerability scanning process for production systems. The scope of vulnerability scans includes both external and internal systems in the production environment. Provider’s security team performs vulnerability scans at least quarterly and determines a severity rating for each vulnerability based on the assessment tools criteria such that high or higher-level ranked vulnerabilities require remediation Vulnerability scans are also run after any significant change to the production environment as determined by the Provider security team. A third party penetration test is run at least annually and identified vulnerabilities are resolved according to priority and severity.
12. Change Management.
Provider has established a change management policy to ensure changes meet Provider's security, confidentiality, and availability goals. Management reviews and approves the policy annually. Any change to production or IT configuration with unknown or foreseeable security consequences must be reviewed by the relevant teams holding the area of responsibility ("AoR") prior to deployment.
Provider reserves the right to update this document from time to time and modify its security practices, provided that such update or modification will not materially and adversely diminish the overall security of the Services during the customer’s Subscription Term.