Skip to main content
Rethinking Email Security for the AI Era, August 25th

Terms and policies.

Data Processing Addendum

Last Updated: 08/17/2026

This Data Processing Addendum (this “DPA”), forms part of the Adaptive Master Subscription Agreement or other written or electronic agreement referencing this Addendum (the “Agreement”) between TeamGuard AI, Inc. d/b/a Adaptive Security (“Adaptive”) and Customer. This Addendum amends the Agreement and is effective upon its incorporation into the Agreement, as specified in the Agreement itself or in any Order (“Effective Date”). Upon its incorporation into the Agreement, this Addendum will form part of the Agreement. Adaptive and Customer may be referred to herein collectively as the “Parties” or individually as a “Party”.

Customer enters into this DPA on behalf of itself and its Affiliates to the extent Adaptive Processes Customer Personal Data in performance of the Services for such Affiliates. For the purposes of this DPA only, and except where indicated otherwise in this DPA, the term “Customer” will include Customer and its Affiliates.

How This DPA Applies

This DPA is binding on the Parties only to the extent applicable Data Protection Laws govern the Processing of Customer Personal Data in performance of the Services. This DPA is fully incorporated into and made a part of the Agreement. This DPA replaces any existing terms, exhibits, schedules, appendices, addendums, or other attachments related to the Processing of Customer Personal Data unless otherwise expressly stated in this DPA. In the event of any inconsistency between the terms of this DPA and any terms of the Agreement with respect to Customer Personal Data, the terms of this DPA will govern and control.

Data Processing Terms

The Parties agree that the terms of this DPA govern the Processing of Customer Personal Data in performance of the Services. Each Party, acting reasonably and in good faith, will comply with the terms of this DPA. Any other Processing of Personal Data with respect to Customer and Customer’s users conducted by Adaptive as a Data Controller, including business relationship administration and system security, will be carried out in accordance with Adaptive’s then-current privacy policy located at the following hyperlink: https://www.adaptivesecurity.com/legal#privacy-policy (or any successor hyperlink).

  1. Definitions and Interpretation

    Capitalized terms used in this DPA shall have the meanings set forth in this Section 1 and elsewhere in this DPA. All other capitalized terms not defined in this DPA will have the meanings set forth in the Agreement. For purposes of this DPA: (i) the words “include,” “includes,” and “including” are deemed to be followed by the words “without limitation;” (ii) the word “or” is not exclusive; (iii) words denoting the singular have a comparable meaning when used in the plural, and vice-versa; and (iv) words denoting any gender include all genders.

    1. 1.1 “Affiliate”of a Party means any other entity that directly or indirectly, through one or more intermediaries, controls, is controlled by, or is under common control with, such Party. The term “control” (including the terms “controlled by” and “under common control with”) means the direct or indirect power to direct or cause the direction of the management and policies of an entity, whether through the ownership of voting securities, by contract, or otherwise.
    2. 1.2 “Authorized User” means an employee or contractor of Customer who is authorized by Customer to access and use the Services on behalf of and for the benefit of Customer.
    3. 1.3 “Customer Personal Data” means Personal Data Processed by Adaptive (or any Subprocessor) as a Data Processor on behalf of and at the direction of Customer in performance of the Services.
    4. 1.4 “Data Controller” (or equivalent term under applicable Data Protection Laws) means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
    5. 1.5 “Data Processor” (or equivalent term under applicable Data Protection Laws) means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Data Controller.
    6. 1.6 “Data Protection Laws”means any applicable laws or regulations governing the Processing of Customer Personal Data in performance of the Services, including, to the extent applicable, the European General Data Protection Regulation (Regulation (EU) 2016/679) (the “GDPR”), the GDPR as it forms part of the UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (as amended, including by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019) (the “UK GDPR”), the Swiss Federal Act on Data Protection in its revised version of 25 September 2020 (“FADP”), the Singapore Personal Data Protection Act 2012 (“PDPA”), the Australian Privacy Act of 1988 (Cth) (“APA”), the Brazilian Personal Data Protection Law (“LGPD”), the Saudi Arabia Personal Data Protection Law implemented by Royal Decree M/19 of 9/2/1443H (16 September 2021) and amended by Royal Decree No. M147 of 5/9/1444H (27 March 2023) (the “KSA PDPL”), the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (“UAE PDPL”), and the US State Privacy Laws.
    7. 1.7 “Data Subject” means an identified or identifiable natural person to whom Customer Personal Data relates. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
    8. 1.8 “Personal Data” means any information relating to a Data Subject that is subject to protection under applicable Data Protection Laws.
    9. 1.9 “Personal Data Breach”means a breach of Adaptive’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Adaptive’s possession, custody or control. For clarity, Personal Data Breach does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data (such as unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems).
    10. 1.10 “Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, retention, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
    11. 1.11 “Restricted Transfer” means: (a) a transfer or disclosure of Customer Personal Data from Customer to Adaptive; or (b) an onward transfer or disclosure of Customer Personal Data from Adaptive to a Subprocessor; in each case, where such transfer or disclosure would be prohibited by applicable Data Protection Laws in the absence of appropriate safeguards, including the Standard Contractual Clauses or UK International Data Transfer Addendum (as applicable).
    12. 1.12 “Services”means the services provided by Adaptive to Customer (or Customer’s Affiliates, as the case may be) under the Agreement.
    13. 1.13 “Service Data”means any data relating to the use, support and/or operation of the Services, which is collected by Adaptive from and/or about Authorized Users of the Services and/or Customer’s use of the Service for use for Adaptive’s own purposes (certain of which may constitute Personal Data). Service Data includes Personal Data of Customer’s business representatives.
    14. 1.14 “Standard Contractual Clauses”or “SCCs” means the Commission Implementing Decision (EU) 2021/914 establishing Standard Contractual Clauses for data transfers to third countries (as amended, modified, or replaced from time to time). Specifically, the applicable module within the Standard Contractual Clauses is MODULE TWO (Transfer Controller to Processor). For the avoidance of doubt, MODULE ONE (Transfer Controller to Controller), MODULE THREE (Transfer Processor to Processor), and MODULE FOUR (Transfer Processor to Controller) do not apply to this DPA.
    15. 1.15 “Subprocessor” means a Data Processor engaged by Adaptive for the purpose of Processing Customer Personal Data in performance of the Services.
    16. 1.16 “Supervisory Authority” means the relevant governmental body or bodies having jurisdiction over the Processing of Customer Personal Data under this DPA.
    17. 1.17 “UK International Data Transfer Addendum” means the template Addendum B.1.0 issued by the UK Information Commissioner’s Office (ICO) and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of the UK Mandatory Clauses included in Part 2 thereof.
    18. 1.18 “US State Privacy Laws”means, collectively, the comprehensive state-specific data privacy laws and their regulations currently in effect and applicable to Adaptive’s Processing of Personal Data under the Agreement.
  2. Processing of Customer Personal Data
    1. 2.1 Roles of the Parties. To the extent Adaptive Processes Customer Personal Data in performance of the Services, the Parties agree that Customer is the Data Controller and Adaptive is the Data Processor, with the exception of Service Data, as to which Adaptive is the Data Controller.
    2. 2.2 Adaptive as Data Processor. Adaptive, when acting as a Data Processor, will Process Customer Personal Data only on the documented instructions of Customer as provided in Section 2.5 and Section 2.6 of this DPA. Adaptive will not Process Customer Personal Data for any other purpose, except to the extent Processing of Customer Personal Data is required by applicable laws.
    3. 2.3 US State Privacy Law-Specific Terms. If Adaptive is Processing Customer Personal Data as a Data Processor within the scope of the US State Privacy Laws in performance of the Services, such Processing shall be subject to Annex 3 (US State Privacy Laws Annex) to this DPA.
    4. 2.4 Customer as Data Controller. Customer, as Data Controller, agrees that Customer:
      • is solely responsible for the accuracy, quality, and legality of Customer Personal Data, including the means by which Customer acquires Customer Personal Data;
      • is solely responsible for any registration, notice, or other authorization under applicable laws to engage Adaptive to perform the Services;
      • has the authority to transmit or disclose Customer Personal Data to Adaptive (or permit Adaptive to access Customer Personal Data); and
      • will provide Adaptive with lawful instructions with respect to the Processing of Customer Personal Data.
    5. 2.5 Customer’s Instructions. Customer instructs Adaptive (and authorizes Adaptive to instruct each Subprocessor) to Process Customer Personal Data in performance of the Services, including any necessary Restricted Transfers. The Parties agree that the scope of Customer’s instructions for the Processing of Customer Personal Data is defined by: (i) the Agreement; (ii) any applicable ordering documents, including service orders, order forms, statements of work, and product or service descriptions; (iii) this DPA; and (iv) any Modified Instructions (as defined in Section 2.6).
    6. 2.6 Modified Instructions. Customer may request amendments to Customer’s instructions, where such amendments are required to ensure that Customer complies with applicable Data Protection Laws and Customer cannot achieve Customer’s compliance with applicable Data Protection Laws unless Adaptive implements such instructions (“Modified Instructions”), by submitting a written request to Adaptive in accordance with the change control or amendment procedures set forth in the Agreement. Customer and Adaptive may mutually agree in writing to amend the Agreement to effect such Modified Instructions. If Adaptive notifies Customer that it is infeasible or impracticable to implement any Modified Instructions, Customer may terminate the applicable Service by providing Adaptive with written notice within thirty (30) days of Adaptive’s notification and receive a prorated refund of prepaid fees applicable to the terminated Service for the period after termination. This Section 2.6 states Customer’s sole and exclusive remedy, and Adaptive’s sole liability, with regard to Modified Instructions.
    7. 2.7 Duty to Inform. To the extent required by applicable Data Protection Laws, Adaptive will inform Customer if, in Adaptive’s opinion, any Customer instruction violates such applicable Data Protection Laws.
    8. 2.8 Details of the Processing of Customer Personal Data. The details of the Processing of Customer Personal Data are set forth in Annex 1 (Processing Details) to this DPA.
  3. Confidentiality Obligations of Adaptive Personnel

    3.1 Confidentiality Obligations of Adaptive Personnel. Adaptive will ensure that any person it authorizes to Process Customer Personal Data is: (a) subject to confidentiality and restricted use obligations that are no less protective than the confidentiality and restricted use obligations set forth in the Agreement; or (b) under an appropriate statutory obligation of confidentiality.

  4. Information Security Program

    4.1 Information Security Program. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Adaptive will in relation to Customer Personal Data implement a written information security program that includes technical and organizational measures designed to protect such Customer Personal Data against unauthorized access, use, disclosure, alteration, or destruction, including the measures set forth in Article 32(1) of the GDPR (and corresponding provisions of the UK GDPR) to the extent such measures are applicable to Adaptive’s Processing of Customer Personal Data in performance of the Services (“Information Security Program”). As of the Effective Date of this DPA, a summary of such Information Security Program is set forth in Adaptive’s Security Controls section of its trust center available at https://security.adaptivesecurity.com/controls, which serves as the security annex to this DPA (“Security Annex”). Adaptive may update the Information Security Program from time to time, provided the updated measures do not materially decrease the overall protection of Customer Personal Data.

  5. Subprocessing
    1. 5.1 Use of Subprocessors; Liability. Customer generally authorizes Adaptive to use Subprocessors, including Adaptive Affiliates, for the purpose of providing the Services. Adaptive will enter into a written agreement with each Subprocessor containing data protection obligations not less protective than those set forth in this DPA with respect to the Processing of Customer Personal Data. Adaptive will remain responsible for any Processing of Customer Personal Data by Subprocessors.
    2. 5.2 Initial Subprocessor List. Customer expressly authorizes the use of the Subprocessors set forth in Annex 4 (Subprocessors) to this DPA.
    3. 5.3 Notification. For notification of engagement of any new Subprocessors used by Adaptive, any engagement of a new Subprocessor will be listed on https://security.adaptivesecurity.com/subprocessors (the “Subprocessor List Site”). Customer is obliged to observe the Subprocessor List Site on an on-going basis and shall, in connection with executing the Agreement or other documents which this DPA is scheduled to, register for updates of the Subprocessor List Site; provided, however, that Adaptive may implement mechanisms by which Customer can receive automated notifications of new Subprocessor engagements (each, an “Automated Notification Mechanism”) at no additional cost to Customer. If Adaptive implements an Automated Notification Mechanism, Adaptive will notify Customer and provide detailed instructions on the use of such Automated Notification Mechanism. Customer agrees to register for and use any Automated Notification Mechanism if it is made available by Adaptive.
    4. 5.4 Customer’s Right to Object to New Subprocessors. Customer will have ten (10) days from the date of a notification or an update to the Subprocessor List Site, as the case may be, to reasonably object to the engagement of any new Subprocessor by providing written notice to Adaptive. If Customer objects to the engagement of a new Subprocessor and the Parties cannot reach an agreement as to the use of the new Subprocessor, Customer may terminate the portion of the Service for which the new Subprocessor is engaged as its sole and exclusive remedy. If Customer has not notified Adaptive of its objection within the time period set forth in this Section 5.4, Customer will be deemed to have approved the use of the new Subprocessor.
    5. 5.5 Restricted Transfers to Subprocessors. To the extent Adaptive makes a Restricted Transfer to a Subprocessor, Adaptive will establish appropriate safeguards for such Restricted Transfer as required by applicable Data Protection Laws.
  6. Assistance to Customer Related to Data Subject Requests
    1. 6.1 Data Subject Request Notification. Adaptive will promptly notify Customer if Adaptive receives a request from a Data Subject to exercise his or her rights under applicable Data Protection Laws with respect to Customer Personal Data.
    2. 6.2 Customer’s Responsibility with respect to Data Subject Requests. Customer will be solely responsible for responding to requests, complaints, and all other communications from Data Subjects; provided, however, Adaptive may confirm to the Data Subject that Adaptive received his or her communication. To the extent that Customer can respond to such requests by using its access to Customer Personal Data or any “self-service” functionality of the Services, Customer will do so.
    3. 6.3 Assistance in Responding to Data Subject Requests. Upon Customer’s written instruction and to the extent required by applicable Data Protection Laws, Adaptive will provide Customer with assistance to fulfill Customer’s obligations to respond to requests from Data Subjects to exercise his or her rights under applicable Data Protection Laws by implementing appropriate technical and organizational measures, insofar as it is possible, taking into account the nature of the Processing.
  7. Assistance with Customer’s Other Data Protection Rights and Obligations
    1. 7.1 Assistance Related to Customer’s Other Data Protection Rights and Obligations. Taking into account the nature of the Processing and the information available to Adaptive, Adaptive will provide assistance required to be provided by Data Processors to Data Controllers under applicable Data Protection Laws, including the assistance required under Article 28(3) of the GDPR (and the corresponding provisions of the UK GDPR) to the extent such assistance is applicable to Adaptive’s Processing of Customer Personal Data in performance of the Services.
    2. 7.2 Information Security Materials. Upon Customer’s written request, Adaptive will make available to Customer the relevant information security materials for the applicable Service (the “Information Security Materials”) through an access-restricted website (https://security.adaptivesecurity.com/) in read-only format. The Information Security Materials are the Confidential Information of Adaptive. Adaptive may modify, amend, or replace the Information Security Materials without notice to Customer. To the extent available for the applicable Service, the Information Security Materials may contain the following:
      • A summary of any third-party audits or certifications relating to the security controls of the applicable Service, including any Service Organization Control (SOC) Type 2 reports; and
      • Any other published materials made available by Adaptive, which further describe Adaptive’s principles, programs, and practices regarding information security and privacy.
  8. Customer Audit Rights

    8.1 Customer Audit Rights. In order to satisfy any audit or inspection request by Customer under applicable Data Protection Laws or the Standard Contractual Clauses and/or UK International Data Transfer Addendum, Adaptive will provide Customer with the assistance and Information Security Materials set forth in Section 7 of this DPA in order to verify Adaptive’s compliance with its obligations under this DPA.

  9. Return or Deletion of Customer Personal Data

    9.1 Return or Deletion of Customer Personal Data. Upon termination of the Agreement, Adaptive will delete, return, or provide Customer with a mechanism to allow Customer to obtain a copy of or delete all Customer Personal Data, except to the extent Adaptive or its Affiliates are required to retain such Customer Personal Data under applicable laws or document retention policies adopted in accordance with such laws; provided, however, the confidentiality and restricted use obligations set forth in the Agreement will continue to apply to such Customer Personal Data for the duration of such retention.

  10. Personal Data Breach of Customer Personal Data
    1. 10.1 Personal Data Breach Notification. If Adaptive becomes aware of a Personal Data Breach of the Services involving Customer Personal Data, Adaptive will notify Customer of such Personal Data Breach without undue delay, and in no event later than seventy-two (72) hours after becoming aware of it, unless prohibited by law or as otherwise requested by a governmental authority.
    2. 10.2 Personal Data Breach Assistance. If Adaptive notifies Customer of a Personal Data Breach in accordance with Section 10.1 of this DPA, Adaptive will provide Customer with assistance in relation to handling a Supervisory Authority’s request for information with respect to such Personal Data Breach as required by applicable Data Protection Laws.
  11. Restricted Transfers

    11.1 Standard Contractual Clauses. To the extent that Customer makes a Restricted Transfer to Adaptive, the Parties agree that the Standard Contractual Clauses will apply to such Restricted Transfer as described in Annex 2 (Restricted Transfer Annex).

  12. Limitations of Liability

    12.1 Terms of the Agreement. The Parties agree that all liability and limitations of liability under this DPA shall be governed by the applicable language in the Agreement.

  13. Service Data
    1. 13.1 Permitted Uses. Customer acknowledges that Adaptive may collect, use and disclose Service Data for its own business purposes: (i) for accounting, tax, billing, audit, and compliance purposes; (ii) to provide, improve, develop, optimise, market and maintain the Services; (iii) to investigate fraud, spam, wrongful or unlawful use of the Services; (iv) to combine Service Data with other data; (v) to de-identify Personal Data so the de-identified data can be used and disclosed by Adaptive for lawful business purposes; and/or (vi) as otherwise permitted or required by applicable law.
    2. 13.2 Processing of Service Data. In respect of any such Processing described in Section 13.1, Adaptive: (i) independently determines the purposes and means of such Processing; (ii) shall comply with Data Protection Laws (if and as applicable in the context); (iii) shall process requests from Data Subjects that are forwarded to Adaptive by Customer to the extent required by Data Protection Laws and upon request provide documentation to Customer that it has done so; (iv) shall Process such Service Data as described in Adaptive’s relevant privacy notices/policies, as updated from time to time; and (v) where possible, shall apply technical and organizational safeguards to any relevant Personal Data that are no less protective than those described in the Security Annex.
  14. Miscellaneous
    1. 14.1 Assistance Costs. To the extent legally permitted, Customer is responsible for the reasonable costs and fees associated with Adaptive’s provision of assistance under this DPA and implementation of any Modified Instructions.
    2. 14.2 Expansion or Modification of Customer Audit Rights. For the avoidance of doubt, no provision in this DPA will be deemed to expand or modify the audit rights of Customer under the Agreement.
    3. 14.3 Choice of Law. Except with respect to the Standard Contractual Clauses, this DPA is governed by the laws that govern the Agreement, and any dispute between the Parties will be handled as set forth in the Agreement.
    4. 14.4 Entire Agreement; Amendments and Modifications. This DPA, together with all exhibits, schedules, addenda, and appendices attached to this DPA and any other documents incorporated into this DPA by reference, constitutes the sole and entire agreement of the Parties with respect to the subject matter of this DPA and supersedes all prior and contemporaneous understandings, agreements, and representations and warranties, both written and oral, with respect to such subject matter. Except as expressly provided in this DPA, the terms of the Agreement are and will remain in full force and effect. This DPA may only be amended by a written amendment that specifically references this DPA and the intent of the Parties to modify this DPA.

Annex 1 — Data Processing Details

Adaptive / “Data Importer” Details

Name: TeamGuard AI, Inc. is a U.S. corporation
Address: 149 E 23rd Street, Suite 1818, New York, NY 10010
Contact Details for Data Protection: Mike Remondi — CTO, Email: security@adaptivesecurity.com
Adaptive Activities: Adaptive provides a platform for AI-powered email security, AI governance, and cybersecurity training. These activities include the data processing activities that are described in the Agreement.
Role: Processor (and Controller of Service Data)

Customer / “Data Exporter” Details

Name: The entity or other person who is a counterparty to the Agreement
Customer’s address is: As set forth in the Agreement
Customer’s Contact Details for Data Protection: As designated by Customer in the Agreement
Customer Activities:Customer’s activities relevant to this DPA are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement as part of its ongoing business operations.
Role: Controller
Categories of Data Subjects:Relevant Data Subjects include any Data Subjects of Personal Data that Customer causes Adaptive to process as part of the provisions of the Service, including Authorized Users, as well as any other data subjects such as Customer’s employees, contractors, and personnel whose activities, communications, devices, or systems are subject to monitoring, assessment, simulation, or security controls delivered as part of the Services, whose personal data may be included in Customer Personal Data to which the Customer provides Adaptive access in order to provide the Services.

Categories of Personal Data: Relevant Personal Data includes any Categories of Personal Data Customer causes Adaptive to process as part of the provisions of the Service, including:

  • Personal details — for example any information that identifies the Data Subject, including name, and contact information.
  • Authentication details — for example usernames, session tokens, and access protocols.
  • Email Data and Metadata— for example emails sent to, from, or within Customer’s connected email environment, including incoming, outgoing, and internal emails, and any files attachments to emails.
  • Browser Data and Metadata— data sent to, from, or within the Data Subject’s browsing environment such as downloaded and uploaded data, website information, website interactions, browser information, browser plugins, browser settings information, device information, and other information related to use of the applicable browser.
  • Technological details — for example internet protocol (IP) addresses, unique identifiers and numbers (including unique identifier in tracking cookies or similar technology), pseudonymous identifiers, precise and imprecise location data, internet / application / program activity data, and device IDs and addresses.

Sensitive Categories of Data, and associated additional restrictions/safeguards: Customer controls the data that is submitted to the Services and Processed, which may incidentally include sensitive data. All data is subject to the safeguards described in Section 4.1 of the DPA.
Frequency of transfer: Ongoing — as initiated by Customer in and through its use, or use on its behalf, of the Services.
Nature of the Processing: Processing operations required in order to provide the Services in accordance with the Agreement.
Purpose of the Processing: to provide the Services in accordance with (i) the Agreement; and (ii) any applicable ordering documents, including service orders, order forms, statements of work, and product or service descriptions, and to comply with any other reasonable instructions provided by Customer in accordance with Section 2.6 of the DPA.
Duration of Processing / Retention Period: For the period determined in accordance with the Agreement and DPA, including Section 9 of the DPA.
Transfers to (sub)processors: As set out in Section 5 of the DPA.

Annex 2 — Restricted Transfer Annex

Restricted Transfers

EU Restricted Transfers. To the extent that any Processing of Personal Data under this DPA involves the disclosure, grant of access or other transfer of Personal Data when transferred from the EEA, to any person located in any country or territory outside the EEA which does not benefit from an adequacy decision from the European Commission (an “EU Restricted Transfer”) from Customer to Adaptive, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:

  • populated in accordance with Part 1 of Attachment 1 to Annex 2 (Restricted Transfer Annex); and
  • entered into by the Parties and incorporated by reference into this DPA.

UK Restricted Transfers. To the extent that any Processing of Personal Data under this DPA involves the disclosure, grant of access or other transfer of Personal Data when transferred from the UK, to any person located in any country or territory outside the UK, which does not benefit from an adequacy decision from the UK Government (a “UK Restricted Transfer”) from Customer to Adaptive, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:

  • varied to address the requirements of the UK GDPR in accordance with UK Transfer Addendum and populated in accordance with Part 2 of Attachment 1 to Annex 2 (Restricted Transfer Annex); and
  • entered into by the Parties and incorporated by reference into this DPA.

Swiss Restricted Transfers. To the extent that any Processing of Personal Data under the DPA involves the disclosure, grant of access or other transfer of Personal Data, when transferred from Switzerland, to any person located in a country or territory outside of Switzerland which does not benefit from an adequacy decision from the Swiss authorities (a “Swiss Restricted Transfer”) from Customer to Adaptive, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:

  • varied to address the requirements of the FADP and populated in accordance with Part 3 of Attachment 1; and
  • entered into by the Parties and incorporated by reference in the DPA.

Nothing in any applicable SCCs (as deemed amended pursuant to Section 1.3) should be interpreted or construed in such a way as would limit or exclude the rights of Data Subjects under Clause 18(c) of those SCCs (as deemed amended pursuant to Section 1.3) to bring legal proceedings before the courts in Switzerland where Switzerland is that Data Subject’s place of habitual residence.

Other Restricted Transfers. To the extent that any Processing of Personal Data under this DPA involves a Restricted Transfer from Customer to Adaptive other than as described above, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:

  • varied to address the requirements of applicable Data Protection Laws and populated in accordance with Part 4 of Attachment 1 to Annex 2 (Restricted Transfer Annex); and
  • entered into by the Parties and incorporated by reference into this DPA.

Adoption of New Transfer Mechanism

Adaptive may on notice vary this DPA and replace the relevant SCCs with:

  • any new form of the relevant SCCs or any replacement therefor prepared and populated accordingly (e.g., standard data protection clauses adopted by the European Commission for use specifically in respect of transfers to data importers subject to Article 3(2) of the EU GDPR); or
  • another transfer mechanism, other than the SCCs, that enables the lawful transfer of Personal Data to Adaptive under this DPA in compliance with applicable Data Protection Laws.

Provision of Full-Form SCCs

In respect of any given Restricted Transfer, if requested of Customer by a Supervisory Authority, Data Subject or further Controller (where applicable) — on specific written request (made to the contact details set out in Annex 1 (Data Processing Details); accompanied by suitable supporting evidence of the relevant request), Adaptive shall provide Customer with an executed version of the relevant set(s) of SCCs responsive to the request made of Customer (amended and populated in accordance with Attachment 1 to Annex 2 (Restricted Transfer Annex) in respect of the relevant Restricted Transfer) for countersignature by Customer, onward provision to the relevant requestor and/or storage to evidence Customer’s compliance with applicable Data Protection Laws.

Operational Clarifications

  • When complying with its transparency obligations under Clause 8.3 of the SCCs, Customer agrees that it shall not provide or otherwise make available, and shall take all appropriate steps to protect, Adaptive’s and its licensors’ trade secrets, business secrets, confidential information and/or other commercially sensitive information.
  • Where applicable, for the purposes of Clause 10(a) of Module Three of the SCCs, Customer acknowledges and agrees that there are no circumstances in which it would be appropriate for Adaptive to notify any third-party controller of any Data Subject Request and that any such notification shall be the sole responsibility of Customer.
  • For the purposes of Clause 15.1(a) of the SCCs, except to the extent prohibited by applicable law and/or the relevant public authority, as between the Parties, Customer agrees that it shall be solely responsible for making any notifications to relevant Data Subject(s) if and as required.
  • The terms and conditions of Section 5 of the DPA apply in relation to Adaptive’s appointment and use of Subprocessors under the SCCs. Any approval by Customer of Adaptive’s appointment of a Subprocessor that is given expressly or deemed given pursuant to that Section 5 constitutes Customer’s documented instructions to effect disclosures and onward transfers to any relevant Subprocessors if and as required under Clause 8.8 of the SCCs.
  • The audits described in Clauses 8.9(c) and 8.9(d) of the SCCs shall be subject to any relevant terms and conditions detailed in Section 8 of the DPA.
  • Certification of deletion of Personal Data as described in Clauses 8.5 and 16(d) of the SCCs shall be provided only upon Customer’s written request.

Attachment 1 to Annex 2 — Population of SCCs

In the context of any EU Restricted Transfer, the SCCs populated in accordance with Part 1 below are incorporated by reference into and form an effective part of the DPA. In the context of any UK Restricted Transfer, the SCCs as varied by the UK Transfer Addendum and populated in accordance with Part 2 below are incorporated by reference into and form an effective part of the DPA. In the context of any Swiss Restricted Transfer, the SCCs as varied and populated by Part 3 below are incorporated by reference into and form an effective part of the DPA. In the context of any other Restricted Transfer, the SCCs as varied and populated by Part 4 below are incorporated by reference into and form an effective part of the DPA.

Part 1: Population of the SCCs

Signature of the SCCs. Where the SCCs apply in accordance with the EU Restricted Transfers provision above, each of the Parties is hereby deemed to have signed the SCCs at the relevant signature block in Annex I to the Appendix to the SCCs.

Modules. The following modules of the SCCs apply in the manner set out below (having regard to the role(s) of Customer set out in Annex 1 to the DPA):

  • Module Two of the SCCs applies to any EU Restricted Transfer and/or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Customer is a Controller in its own right; and/or
  • Module Three of the SCCs applies to any EU Restricted Transfer and/or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Customer is itself acting as a Processor on behalf of any other person.

Population of the body of the SCCs. For each Module of the SCCs, the following applies as and where applicable to that Module and the Clauses thereof:

  • The optional “Docking Clause” in Clause 7 is not used and the body of that Clause 7 is left intentionally blank.
  • In Clause 9: Option 2 (General Written Authorisation) applies, and the minimum time period for advance notice of the addition or replacement of Subprocessors shall be the advance notice period set out in Section 5 of the DPA; Option 1 (Specific Prior Authorisation) is not used and that optional language is deleted, as is Annex III to the Appendix to the SCCs.
  • In Clause 11, the optional language is not used and is deleted.
  • In Clause 13, all square brackets are removed and all text therein is retained.
  • In Clause 17: Option 1 applies, and the Parties agree that the SCCs shall be governed by the law of the jurisdiction of the data exporter in relation to any EU Restricted Transfer; Option 2 is not used and that optional language is deleted.
  • For the purposes of Clause 18, the Parties agree that any dispute arising from the SCCs in relation to any EU Restricted Transfer shall be resolved by the courts of the jurisdiction of the data exporter, and Clause 18(b) is populated accordingly.

Population of Annexes to the Appendix to the SCCs. Annex I to the Appendix to the SCCs is populated with the corresponding information detailed in Annex 1 (Data Processing Details) to the DPA, with Customer being the “data exporter” and Adaptive being the “data importer.” Part C of Annex I to the Appendix to the SCCs is populated as below — the competent supervisory authority shall be determined as follows:

  • Where Customer is established in an EU Member State: the competent supervisory authority shall be the supervisory authority of that EU Member State in which Customer is established.
  • Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies and Customer has appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State in which Customer’s EU representative relevant to the processing hereunder is based (from time-to-time).
  • Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies, but Customer has not appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State notified in writing to Adaptive’s contact point for data protection identified in Attachment 1 to Annex 2 (Restricted Transfer Annex) to the DPA, which must be an EU Member State in which the data subjects whose personal data is transferred under these Clauses in relation to the offering of goods or services to them, or whose behavior is monitored, are located.

Annex II to the Appendix to the SCCs is populated as below. Please refer to Section 7 of the DPA and the Security Annex. In the event that Customer receives a Data Subject Request under the EU GDPR and requires assistance from Adaptive, Customer should email Adaptive’s contact point for data protection identified in Annex 1 (Data Processing Details) to the DPA. When Adaptive engages a Subprocessor under these Clauses, Adaptive shall enter into a binding contractual arrangement with such Subprocessor that imposes upon them data protection obligations which, in substance, meet or exceed the relevant standards required under these Clauses and the DPA — including in respect of: applicable information security measures; notification of Information Security Incidents to Adaptive; return or deletion of Personal Data as and where required; and engagement of further Subprocessors.

Part 2: UK Restricted Transfers

Where relevant, the SCCs also apply in the context of UK Restricted Transfers as varied by the UK Transfer Addendum: as permitted by Section 17 of the UK Transfer Addendum, the Parties agree that Tables 1, 2 and 3 to the UK Transfer Addendum are deemed populated with the corresponding details set out in Annex 1 (Data Processing Details) and the foregoing provisions of this Attachment 1 (subject to the variations effected by the Mandatory Clauses), and Table 4 to the UK Transfer Addendum is completed by the box labelled “Data Importer” being deemed to have been ticked. The Parties agree to be bound by the Mandatory Clauses of the UK Transfer Addendum. In relation to any UK Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs shall be read as a reference to those SCCs as varied in the manner set out above.

Part 3: Swiss Restricted Transfers

Where applicable, the SCCs also apply in the context of Swiss Restricted Transfers with the following terms deemed to have the following substituted meanings: “GDPR” means the FADP; “European Union,” “Union” and “Member State(s)” each mean Switzerland; and “supervisory authority” means the FDPIC. In relation to any Swiss Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs shall be read as a reference to those SCCs as varied in the manner set out above.

Part 4: Other Restricted Transfers

Where applicable, the SCCs also apply in the context of other Restricted Transfers with the following terms deemed to have the following substituted meanings: “GDPR” means the applicable Data Protection Laws of the jurisdiction of the data exporter; “European Union,” “Union” and “Member State(s)” each mean the jurisdiction of the data exporter; and “supervisory authority” means the Supervisory Authority of the jurisdiction of the data exporter. In relation to any other Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs shall be read as a reference to those SCCs as varied in the manner set out above.

Annex 3 — US State Privacy Laws Annex

For purposes of this Annex 3, the terms “business,” “commercial purpose,” “sell,” “share,” “targeted advertising” and “service provider” shall have the respective meanings given thereto in the US State Privacy Laws, and “personal information” shall mean Personal Data that constitutes personal information governed by the US State Privacy Laws.

It is the parties’ intent that with respect to any personal information, Adaptive is a service provider. Adaptive (a) acknowledges that personal information is disclosed by Customer only for limited and specified purposes described in the Agreement; (b) shall comply with applicable obligations under the US State Privacy Laws and shall provide the same level of privacy protection to personal information as is required by the US State Privacy Laws; (c) agrees that Customer has the right to take reasonable and appropriate steps to help to ensure that Adaptive’s use of personal information is consistent with Customer’s obligations under the US State Privacy Laws; (d) shall notify Customer in writing of any determination made by Adaptive that it can no longer meet its obligations under the US State Privacy Laws; and (e) agrees that Customer has the right, upon notice, including pursuant to the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.

Adaptive shall not (a) sell or share any personal information or use it for targeted advertising; (b) retain, use or disclose any personal information for any purpose other than for the specific purpose of providing the Services, including retaining, using, or disclosing the personal information for a commercial purpose other than the provision of the Services; (c) retain, use or disclose the personal information outside of the direct business relationship between Adaptive and Customer; or (d) combine personal information received pursuant to the Agreement with personal information (i) received from or on behalf of another person, or (ii) collected from Adaptive’s own interaction with any Consumer to whom such personal information pertains, except in each case (a) through (d) as and to the extent necessary as a part of Adaptive’s provision of the Services or as otherwise permitted by a service provider or processor under the US State Privacy Laws. Adaptive hereby certifies that it understands its obligations under this Annex 3 and will comply with them.

Giving Customer notice of Subprocessor engagements in accordance with Section 5 of the DPA shall satisfy Adaptive’s obligation under the US State Privacy Laws to give notice of and an opportunity to object to such engagements.

Adaptive agrees that Customer may conduct audits, in accordance with Section 8 of the DPA, to help ensure that Adaptive’s use of personal information is consistent with Adaptive’s obligations under the US State Privacy Laws.

The parties acknowledge that Adaptive’s retention, use and disclosure of personal information authorized by Customer’s instructions documented in the DPA are integral to Adaptive’s provision of the Services and the business relationship between the parties.

Annex 4 — List of Subprocessors

Customer approves that Adaptive engages the Subprocessors listed at https://security.adaptivesecurity.com/subprocessors to Process Personal Data pursuant to this DPA.