Hazeltree Data Processing Addendum

DATA PROCESSING ADDENDUM EXHIBIT

1.INTERPRETATION.

1.1Hazeltree’s obligations under this Exhibit are in addition to its other obligations under the Agreement.

1.2In the event of a conflict amongst the other terms of the Agreement, the terms of this Exhibit and the terms of the Annexes hereto, the more protective terms with regard to Personal Data will apply.

1.3Capitalized terms used but not defined in this Exhibit (including in Section 9 (Definitions)) shall have the meanings provided elsewhere in the Agreement.

1.4The following Annexes are attached to and incorporated into this Exhibit, as applicable:

Annex 1 – EU Standard Contractual Clauses

Annex 2 – UK Addendum to the EU Standard Contractual Clauses

Annex 3 – Switzerland Addendum to the EU Standard Contractual Clauses

Annex 4 – Transfer Requirements for Other Jurisdictions

Annex 5 – Authorized Sub-Processors

2.SCOPE OF PROCESSING PERSONAL DATA.

2.1Roles and Responsibilities.

(a)To the extent applicable under Data Protection Laws, Hazeltree shall be a Processor (or Service Provider) on behalf of Licensee as a Controller (or Business) or a Sub-Processor on behalf of Licensee as a Processor (acting on its Controller client’s behalf).

(b)As a Controller, Licensee shall comply with Data Protection Laws in respect of its Processing of Personal Data.

2.2Purpose of Processing.

(a)Hazeltree shall Process and permit the Processing of Personal Data only as and to the extent:

(i)necessary for the purposes of fulfilling its obligations under the Agreement;

(ii)required for the limited and specific business purposes of performing the Services pursuant to the Agreement and as set out in Annex I to the Appendix of the Standard Contractual Clauses, as applicable; and

(iii)as required for the purposes of security and fraud prevention related to the Services.

(b)Hazeltree shall not:

(i)retain, use or disclose Personal Data: (A) for any purpose other than for the limited and specific business purposes of performing Services pursuant to the Agreement and as set out in Annex I to the Appendix of the Standard Contractual Clauses, as applicable; or (B) outside of the direct business relationship between Licensee and Hazeltree; or

(ii)combine Personal Data with any Personal Data that is received from or on behalf of any third party or collected via Hazeltree’s own interaction with a Data Subject, unless expressly permitted by applicable law.

(c)Hazeltree shall treat the Personal Data as Confidential Information under the Agreement (except that any exclusion from the definition of Confidential Information in the Agreement or any other agreement between the parties will not apply to Personal Data) and other than as expressly permitted by this Exhibit or by Data Protection Laws, Hazeltree shall not sell, share, disclose, transfer or otherwise make the Personal Data available:

(i)to a third party in exchange for monetary or other valuable consideration; or

(ii)to a third party for cross-context behavioral or targeted advertising.

2.3Permitted Processing by Hazeltree.

(a)Hazeltree shall only Process Personal Data on Licensee’s behalf and in accordance with the express documented instructions of Licensee throughout the term of the Agreement, including in the Agreement.

(b)For the purpose of complying with applicable Data Protection Laws, the subject-matter, nature and purpose of the Processing to be undertaken by Hazeltree and the types of Personal Data and categories of Data Subjects involved are specified in Annex I of the Appendix to the Standard Contractual Clauses.

(c)Hazeltree shall immediately notify Licensee if Hazeltree reasonably determines that:

(i)it can no longer meet its obligations under this Exhibit (including to follow Licensee’s instructions) or Data Protection Laws; or

(ii)any Processing instruction of Licensee violates Data Protection Laws;

and, in such event, Hazeltree shall enter into further agreements as requested by Licensee which are required to comply with Data Protection Laws.

2.4Duration of Processing by Hazeltree.

Except to the extent, and for the duration, that Personal Data must be retained by Hazeltree under applicable laws (provided that these do not infringe applicable Data Protection Laws and subject to Hazeltree continuing to observe the terms of this Exhibit and the confidentiality, privacy and security terms in the Agreement), Hazeltree shall promptly after the earlier of termination of the Agreement and the end of Processing of the Personal Data by Hazeltree: (a) make available Personal Data to Licensee through the SaaS Services or Software; and/or (b) cause the deletion of Personal Data processed by Hazeltree or any Sub-Processor; in each case as directed by Licensee. Hazeltree shall provide a written letter or certificate of destruction promptly upon request.

3.COMPLIANCE.

3.1Hazeltree shall:

(a)comply with Data Protection Laws applicable to Hazeltree’s Processing of Personal Data;

(b)comply with Data Protection Laws; and

(c)without prejudice to Hazeltree’s other obligations under this Exhibit, provide at least the same level of protection for Personal Data as is required of Licensee under Data Protection Laws.

3.2Hazeltree shall enter into further agreements as required by Licensee in order to comply with Data Protection Laws.

3.3Hazeltree certifies that it understands and shall comply with Data Protection Laws and its obligations in this Exhibit to the extent it is considered a Contractor as defined under the CCPA.

3.4In addition to Licensee’s other rights under this Exhibit, Licensee shall have the right to take all reasonable and appropriate steps to:

(a)ensure that the Personal Data is used by Hazeltree in a manner that is consistent with Licensee’s obligations under Data Protection Laws; and

(b)stop and remediate any unauthorized use by Hazeltree of Personal Data;

and Hazeltree shall co-operate fully with any exercise by Licensee of the above rights.

3.5Hazeltree shall take reasonable steps to ensure the reliability of each employee, agent or contractor of Hazeltree or its Sub-Processors who may have access to the Personal Data, ensuring that access is granted only to those individuals who need to know / access the relevant Personal Data, only to the extent strictly necessary for the purposes of the Agreement and that each individual:

(a)has undertaken appropriate training in relation to the applicable Data Protection Laws and their responsibilities for compliance; and

(b)is subject to confidentiality undertakings or professional or statutory obligations of confidentiality that protect the Personal Data.

3.6Requests by Regulators and Other Authorities.

(a)Hazeltree shall promptly notify Licensee of any complaints received or any notices of investigation or non-compliance from any Regulator relating to the collection or Processing of Personal Data. Unless Licensee notifies Hazeltree that Hazeltree will be responsible for handling a particular communication or correspondence with a Regulator, Licensee will handle all communications and correspondence with Regulators relating to Personal Data and the provision or receipt of the Services.

(b)Hazeltree shall cooperate with Licensee and the relevant Regulator in the event of any investigation or litigation concerning Personal Data and shall abide by the advice of the relevant Regulator with regard to the Processing of such Personal Data.

(c)If any Personal Data provided to Hazeltree by or on behalf of Licensee or otherwise accessed in connection with the provision of Services is requested or subject to an order for compelled disclosure by any law enforcement or security authorities or other government agencies, or Hazeltree has any reason to believe that such request may be made, in each case Hazeltree shall:

(i)promptly redirect the third party to request the data directly from Licensee and notify Licensee, unless prohibited under applicable law or by the relevant authority, in which case Hazeltree shall use all lawful efforts to waive the prohibition and shall communicate as much information to Licensee as soon as possible;

(ii)use all lawful efforts to challenge the request or order for disclosure on the basis of any legal deficiencies under the applicable laws or any relevant conflicts with Data Protection Laws;

(iii)upon request by Licensee, suspend or cease Processing any Personal Data provided to it by or on behalf of Licensee with immediate effect and without penalty or termination fee or other liability to Licensee; and

(iv)not make transfers of Personal Data to any law enforcement or security authorities or other government agencies in breach of Data Protection Laws or the Agreement, unless such transfer is required under applicable law.

4.COOPERATION.

4.1Hazeltree’s Assistance with Data Subject Requests.

(a)Hazeltree shall notify Licensee without undue delay and, in any event, not later than forty-eight (48) hours following Hazeltree’s receipt of a Data Subject Request.

(b)Hazeltree shall not respond to any such Data Subject Request without Licensee’s prior written instructions, except to the extent required by Data Protection Laws, in which case Hazeltree shall:

(i)respond directly to the Data Subject Request and, to the extent permitted by such Data Protection Laws, inform Licensee of that legal requirement before Hazeltree responds to the Data Subject Request; or

(ii)direct the requesting individual to submit the Data Subject Request directly to Licensee as set out in the privacy notice on Licensee’s website from time to time.

(c)Hazeltree shall provide reasonable assistance to Licensee sufficiently and promptly enough to enable Licensee to respond to Data Subject Requests in accordance with Licensee’s obligations under Data Protection Laws including meeting any deadlines imposed by such obligations. To the extent required under Data Protection Laws, Hazeltree shall promptly notify third parties of their obligations to assist Licensee in relation to Data Subject Requests.

4.2Hazeltree’s Assistance with High-Risk Personal Data.

(a)Hazeltree shall provide reasonable assistance to Licensee where necessary and upon request to enable Licensee to ensure compliance with Licensee’s obligations under Data Protection Law to carry out any data protection impact assessments or prior consultation of a Regulator.

(b)Where Hazeltree Processes on behalf of Licensee any Personal Data revealing financial data, Hazeltree shall assist Licensee in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR and other applicable Data Protection laws taking into account the nature of processing and the information available to the Licensee, including implementing any specific restrictions and/or additional safeguards as agreed with Licensee and entering into further agreements as requested by Licensee which are required to comply with Data Protection Laws.

4.3Hazeltree’s Audit and Inspection Obligations.

In addition to any audit rights granted in the Agreement, Hazeltree shall promptly and adequately make available to Licensee and any Regulator, on request, all information necessary to demonstrate compliance with this Exhibit, including such information as may be required to deal with an enquiry from Licensee relating to Hazeltree’s Processing of Personal Data. Hazeltree shall provide cooperation to Licensee and any Regulator in relation to any audit, including allowing for audits and inspections by Licensee or another auditor mandated by Licensee, any of its affiliates or any Regulator of any premises and facilities and the relevant records, processes and systems where the Processing of Personal Data or management decisions in relation to the Processing of Personal Data take place, in order to assess compliance with this Exhibit. Hazeltree shall immediately inform Licensee if, in its opinion, an instruction pursuant to this Section infringes any Data Protection Laws.

5.SECURITY.

5.1Data Security.

(a)Hazeltree shall implement and maintain appropriate technical, physical, administrative and organizational measures to ensure the confidentiality, integrity, availability and resilience of systems used for Processing Personal Data and to protect against Data Breaches.

(b)Hazeltree shall ensure a level of security appropriate to the risk, taking into account the state of the art and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons; provided, however, that such measures shall at a minimum include, as applicable:

(i)the technical, physical, administrative and organizational measures described in the Agreement, any cybersecurity, business continuity and disaster recovery requirements in the Agreement and those measures set out in Annex II to the Appendix to the Standard Contractual Clauses, which shall apply whenever Hazeltree Processes Personal Data;

(ii)the findings or recommendations arising from Hazeltree’s responses to any technology risk questionnaire completed prior to entering into or during the term of the Agreement;

(iii)the pseudonymization, deidentification or encryption of Personal Data, as appropriate;

(iv)the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and

(v)a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the Processing.

(c)Licensee shall cooperate with Hazeltree to the extent required by Data Protection Laws.

5.2Data Breaches.

(a)Hazeltree shall notify Licensee and in any event within forty-eightseventy-twoforty-eight (4848[DP1] (#_msocom_1) ) hours of Hazeltree or any Sub-Processor becoming aware of or suspecting (with a reasonable degree of certainty) a Data Breach, providing Licensee with sufficient information to allow Licensee and its affiliates to meet any obligations to report to Regulators or inform Data Subjects of the Data Breach under Data Protection Laws.

(b)Hazeltree shall immediately investigate any suspected Data Breach and shall cooperate with Licensee and its affiliates and take such reasonable commercial steps as are directed by Licensee to assist in the investigation, mitigation and remediation of each such Data Breach or suspected Data Breach.

(c)Notwithstanding any other provisions of the Agreement, in the event of a Data Breach involving unencrypted Personal Data due to Hazeltree’s breach of the security requirements[DP2] (#_msocom_2) , Hazeltree shall provide the following at Hazeltree’s expense upon Licensee’s request: (i) notice to individuals whose Personal Data was affected by the Data Breach in a manner and format determined by Licensee, in its sole discretion, as well as to any other third parties, such as regulatory, law enforcement, or consumer reporting agencies, that Licensee determines should be notified of the Data Breach, in its sole discretion; (ii) one year of credit monitoring; (iii) any other relief service(s) as required by applicable law to affected individuals; and (iv) reasonable cooperation with Licensee to offer any other remediation services deemed necessary by Licensee or which are customarily provided to individuals impacted by a breach in confidentiality of their Personal Data in the relevant jurisdictions.

(d)Licensee shall cooperate to the extent required by Data Protection Laws in relation to any notifications to Regulators or to Data Subjects (to the extent these are required to be made under Data Protection Laws by Hazeltree) following a Data Breach.

6.Sub-Processor Controls.

6.1Without limiting any other terms of the Agreement regarding subcontracting, Hazeltree shall not engage or permit (including by assignment, delegation or novation) a Sub-Processor to Process Personal Data without prior specific or general authorization by Licensee and in each case Hazeltree shall:

(a)carry out adequate due diligence on the Sub-Processor to ensure it is capable of providing the level of protection of Personal Data required by this Exhibit;

(b)provide Licensee with full details of the Processing including location and scope of Processing and identity of the Sub-Processor;

(c)inform the Sub-Processor that it acts as a Processor under the instructions of Licensee and its affiliates as Controller; and

(d)include terms in its contract with the Sub-Processor at least as protective as those set out in this Exhibit, including a third-party beneficiary clause whereby - in the event HazelTree has factually disappeared, ceased to exist in law or has become insolvent -Licensee shall have the right to terminate the Sub-Processor contract and to instruct the Sub-Processor to erase or return the personal data; and

(e)remain fully liable to Licensee for the Sub-Processor’s performance and compliance with this Exhibit and the Data Protection Laws, and Hazeltree shall promptly notify Licensee of any failure by the Sub-Processor to fulfil its obligations.

6.2Licensee specifically authorizes any Sub-Processors set out in Annex 5 (Authorized Sub-Processors), which constitutes the agreed list as at the date of this Exhibit for the purposes of Clause 9(a) of the Standard Contractual Clauses. Hazeltree shall provide at least ninety (90) days’ prior notice by email to Licensee of any proposed addition of a new or changed Sub-Processor to such Sub-Processor list. [DP3] (#_msocom_3) [DP4] (#_msocom_4) Upon request, Hazeltree shall promptly provide Licensee with a current list of the names and contract information of any Sub-Processors.

6.3If Licensee objects in writing to Hazeltree’s proposed use of a new Sub-Processor based on commercially reasonable grounds, Hazeltree shall not permit the objected to Sub-Processor to Process Personal Data on behalf of Licensee and Hazeltree will use reasonable efforts to determine a way of preventing such objected to Sub-Processor from Processing Personal Data without adversely impacting the Services or Licensee. If Hazeltree determines that it cannot avoid such an adverse impact despite such reasonable efforts, Hazeltree shall notify Licensee of such determination. Upon receipt of such notice, Licensee may terminate the Agreement without penalty or liability (other than for fees due and owing to Hazeltree for Services performed prior to such termination) effective immediately upon written notice of such termination to Hazeltree. Hazeltree shall promptly refund Licensee any prepaid fees for the period following the effective date of termination.

6.4Without prejudice to any of Hazeltree’s other obligations, if Hazeltree contracts, delegates or assigns any of Hazeltree’s rights or obligations concerning Personal Data under the Agreement to a third party, Hazeltree shall notify Licensee of such matter, and shall enter into a written agreement with the relevant third party that imposes obligations on the third party that are equivalent to those imposed on Hazeltree under this Exhibit.

7.Cross-Border Transfers.

7.1General.

(a)Hazeltree shall not permit Personal Data to be Processed in any jurisdiction without ensuring compliance with Data Protection Laws.

(b)Hazeltree shall not permit Personal Data to be Processed in China, Iran, North Korea, Russia, or any country on the Office of Foreign Assets Control (“OFAC”) list, without Licensee’s prior specific written approval.

(c)Hazeltree acknowledges that transfers of Personal Data may be subject to Data Protection Laws and may require Hazeltree to enter into an appropriate data transfer agreement or additional terms with Licensee to achieve compliance.

7.2Hazeltree’s Transfers of Personal Data as a Processor.

Hazeltree shall not permit Personal Data to be Processed outside the country in which it is received by Hazeltree or any Sub-Processors permitted under this Exhibit from Licensee or its affiliates except in accordance with Licensee’s prior documented instructions. Licensee instructs Hazeltree to transfer Personal Data to the locations set out in the Sub-Processor list at Annex 5 (Authorized Sub-Processors), subject to compliance with this Section 7 (Cross-Border Transfers).

7.3Transfer Risk Assessments and Supplementary Measures.

(a)Hazeltree shall support Licensee in its efforts to ensure compliance with Data Protection Law and other applicable law for the transfer of Personal Data of Data Subjects located in the UK, Switzerland or the EEA to third countries including by undertaking and documenting a transfer risk assessment in accordance with Data Protection Laws and the Standard Contractual Clauses before first transferring Personal Data and then annually.

(b)Hazeltree shall ensure that the appropriate technical and organizational measures it implements and maintains as required by Data Protection Laws, the Standard Contractual Clauses and this Exhibit, address the risks associated with the transfer of Personal Data to a third country and Hazeltree shall implement any further additional safeguards required by its transfer risk assessment and/or as agreed with Licensee.

(c)Hazeltree warrants on an ongoing basis that it is able, through the implementation of appropriate technical and organizational measures, to satisfy its obligations under Data Protection Laws, the Standard Contractual Clauses and this Exhibit.

(d)Hazeltree certifies that: (i) it has not and will not create back doors (non-transparent access capabilities) or similar programming that could be used to access its systems and/or the Personal Data; (ii) it has not and will not change its business processes in a way which facilitates unauthorized access to its systems and/or the Personal Data; and (iii) applicable law does not require Hazeltree to create or maintain back doors or to facilitate unauthorized access to its systems and/or the Personal Data or for Hazeltree to be in possession of or to hand over to any third party keys to decrypt the Personal Data.

7.4Application of the Standard Contractual Clauses.

(a)The appropriate Module (as determined by Section 2.1 (Roles and Responsibilities)) of the Standard Contractual Clauses shall apply where Personal Data undergoing Processing are transferred from the EEA, the UK (subject to Annex 2 (UK Addendum to the EU Standard Contractual Clauses)), Switzerland (subject to Annex 3 (Switzerland Addendum to the EU Standard Contractual Clauses)) or any other jurisdiction which accepts the Standard Contractual Clauses (subject to Section 7.3(b)), either directly or via onward transfer, to any recipient:

(i)that is not located in a country recognised by the European Commission or the relevant Regulator as providing an adequate level of protection for Personal Data; or

(ii)that is not covered by a framework recognised by the relevant authorities or courts as providing an adequate level of protection for Personal Data, including but not limited to Binding Corporate Rules or the Trans-Atlantic Data Privacy Framework, (each such recipient, a “Third Country Recipient”).

(b)Where the Standard Contractual Clauses apply to a transfer of Personal Data from any other jurisdiction which accepts the Standard Contractual Clauses as appropriate safeguards under Data Protection Laws, Annex 4 (Transfer Requirements for Other Jurisdictions) shall apply, and any amendments required by such jurisdiction’s Regulator shall be deemed to be made to the Standard Contractual Clauses as are necessary to comply with Data Protection Laws.

7.5Standard Contractual Clauses.

(a)The Standard Contractual Clauses will be deemed executed between Licensee as Data Exporter and Hazeltree as Data Importer by virtue of the Parties having signed the Agreement.

(b)If so required by Data Protection Laws, the Parties shall execute or re-execute the Standard Contractual Clauses as separate documents setting out the proposed transfers of Personal Data in such manner as may be required by Data Protection Laws.

(c)The following sections of this Exhibit shall apply to the Standard Contractual Clauses, provided that these shall not operate to contradict the Standard Contractual Clauses:

(i)Section 2.3(a) of this Exhibit shall apply to the instructions issued to Data Importer under the Standard Contractual Clauses;

(ii)Section 4.1 (Hazeltree’s Assistance with Data Subject Requests) of this Exhibit shall apply to any enquiries or requests that Hazeltree receives from a Data Subject that Hazeltree is obliged to deal with in accordance with Clause 10 of the Standard Contractual Clauses;

(iii)Section 4.1 (Hazeltree’s Assistance with Data Subject Requests) of this Exhibit shall apply to any complaints that Hazeltree receives from a Data Subject and Hazeltree shall promptly deal with such complaint as required by Clause 11 of the Standard Contractual Clauses, as if it were a Data Subject Request; and

(iv)Section 6 (Sub-Processor Controls) of this Exhibit shall apply in respect of any sub-Processing by the Data Importer under Clause 9 of the Standard Contractual Clauses.

7.6Conflicts.

(a)Nothing in this Exhibit or the Agreement shall contradict, directly or indirectly, the Standard Contractual Clauses, or prejudice the fundamental rights or freedoms of Data Subjects. In the event of such a contradiction, the Standard Contractual Clauses shall prevail.

(b)In the event that the Standard Contractual Clauses are at any time no longer deemed to provide adequate protection to Personal Data transferred to Third Country Recipients, the Parties shall enter into and/or adopt such alternative data transfer solution to replace the Standard Contractual Clauses as is required by the European Commission or the appropriate Regulator to comply with applicable Data Protection Laws.

8.CHOICE OF LAW.

8.1To the extent required by applicable Data Protection Laws, this Exhibit shall be governed by the law of the applicable jurisdiction. In all other cases, this Exhibit shall be governed by the laws of the jurisdiction specified in the Agreement as governing the Agreement.

9.DEFINITIONS.

The following terms have the following meanings when used in this Exhibit:

“Controller” means, for the purpose of certain Data Protection Laws, the entity which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Controller includes Business as defined under any Data Protection Laws.

Data Breach” means any Personal Data Breach (as defined in GDPR) or other incident that has resulted, or is reasonably likely to result, in any accidental, unauthorised or unlawful destruction, loss, alteration, disclosure of, access to, or use of Personal Data.

“Data Protection Laws” means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including: the FADP, the UK Data Protection Laws; the US Data Protection Laws; and the GDPR and other laws and regulations of the European Union, the EEA and their member states relating to data protection; along with any binding guidance or opinions issued by any Regulator.

“Data Subject” means the individual to whom Personal Data relates.

“Data Subject Request” means: (a) a request by or on behalf of a Data Subject to exercise that Data Subject’s rights under Data Protection Laws in respect of that Data Subject’s Personal Data, including, without limitation, the right to access, correct, amend, transfer, obtain a copy of, object to the processing of, block or delete such Personal Data; or (b) a complaint from a Data Subject in relation to Licensee, the Personal Data, the Services or the Agreement.

“EEA” means the European Economic Area.

“FADP” means the Swiss Federal Act on Data Protection as may be amended from time to time.

“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation) and any other Data Protection Laws modelled on the foregoing.

“Personal Data” means any information made available to or Processed by or on behalf of a Party in connection with the Services or the Agreement that: (i) identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual (or, in California, a household); or (ii) is personal data, personal information, personally identifiable information or other analogous term as defined under any Data Protection Laws.

“Processing” or “Process” means any operation or set of operations which is performed by or on behalf of a Party on Personal Data, whether or not by automated means, such as collection, recording, organisation, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction.

“Processor” means, for the purpose of certain Data Protection Laws, the entity which Processes Personal Data on behalf of the Controller. Processor includes Service Provider as defined under any Data Protection Laws.

“Regulator” means any data protection authority or other regulatory, governmental or supervisory authority with authority over all or any part of: (a) the provision or receipt of the Services; (b) the Processing of Personal Data in connection with the Services; or (c) Hazeltree’s or Licensee’s business or personnel relating to the Services.

“Services” means the services to be provided by Hazeltree to Licensee and/or Licensee’s affiliates under the Agreement.

“Standard Contractual Clauses” means the agreement subject to Section 7 (Cross-Border Transfers) which is set out in Annex 1 (EU Standard Contractual Clauses) and executed by and between the Data Exporter and Data Importer in the form in the C(2021) 3972 final Annex to the Commission Implementing Decision on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.

“Sub-Processor” means another Processor engaged by or on behalf of Hazeltree (including a third party or affiliate of Hazeltree but excluding an employee of Hazeltree or any of its sub-contractors) that will Process Personal Data as part of the performance of the Services.

“UK” means The United Kingdom of England and Wales, Scotland and Northern Ireland.

“UK Data Protection Laws” means all laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including: (a) the Data Protection Act 2018; and (b) the UK GDPR.

“UK GDPR” means The United Kingdom General Data Protection Regulation, as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, as modified by Schedule 1 to the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019.

“US” means the United States of America (including the 50 States and the District of Columbia) and its territories, and possessions.

“US Data Protection Laws” means all applicable US federal and/or state security, confidentiality, and/or privacy laws, standards, guidelines, policies, regulations, and procedures that are applicable to the Processing of Personal Data under the Agreement, including but not limited to the California Consumer Privacy Act of 2018, as amended (including, without limitation, by the California Privacy Rights Act of 2020) (“CCPA”), Colorado Privacy Act, the Virginia Consumer Data Protection Act, the Utah Consumer Privacy Act, Connecticut’s Act Concerning Personal Data Privacy and Online Monitoring, and all laws implementing, supplementing or amending the foregoing, including any final regulations promulgated thereunder.

Note: Do not recommend this change as clients think (mistakenly) that they only have a total of 72 hours to notify regulators in the EU/UK. The actual time frame for Hazeltree is without undue delay, and the controller/clients have 72 hours to notify. It doesn’t matter what the legal answer is—what happens is that most companies think the total time is 72 hours and their vendor’s time gets cut. If you put 72 hours, then the clients will think (incorrectly) that they don’t have any wiggle room.

Note: This will invite changes and could be moved into the agreement.

This is actually stricter than it needs to be. Can Hazeltree post the sub-processors somewhere? Let’s discuss.

Note: As discussed on the call, insert new mechanism—portal, etc.