Version 1.0 · Last Updated: February 26, 2025

    Alaigned Data Processing Addendum

    This Data Processing Addendum represents an addendum to Customer's (also referred as "You") existing commercial agreement with Alaigned (also referred as "Provider") governing Customer's use of Provider products or Services ("Agreement") (each, a "Party" and together, the "Parties") ("Addendum"/"DPA") and is hereby incorporated into the Agreement. In the event of any conflict between this Addendum and any data processing terms contained in the Agreement between the Parties, the terms of this Addendum regarding the transfer of Personal Data shall control and supersede the terms set forth in the Agreement.

    1. Definitions

    All capitalized terms not otherwise defined herein shall have the meaning set forth in the Agreement or the Applicable Data Protection Law, as applicable.

    1.1. "Audit" and "Audit Parameters" are defined in Section 9.3. below.

    1.2. "Audit Report" is defined in Section 9.2. below.

    1.3. "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of Processing of Personal Data.

    1.4. "Customer Instructions" is defined in Section 3.1. below.

    1.5. "Customer Personal Data" means Personal Data in Customer Data (as defined in the Agreement).

    1.6. "Data Protection Laws" means all laws and regulations applicable to the Processing of Customer Personal Data under the Agreement, including, as applicable: (i) the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and any binding regulations promulgated thereunder ("CCPA"), (ii) the General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR" or "GDPR"), (iii) the Swiss Federal Act on Data Protection ("FADP"), (iv) the EU GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 (the "UK GDPR") and (v) the UK Data Protection Act 2018.

    1.7. "Data Subject" means the identified or identifiable natural person to whom Customer Personal Data relates.

    1.8. "EEA" means European Economic Area.

    1.9. "Personal Data" means information about an identified or identifiable natural person or which otherwise constitutes "personal data", "personal information", "personally identifiable information" or similar terms as defined in Data Protection Laws.

    1.10. "Processing" and inflections thereof refer to any operation or set of operations that is performed on Personal Data or on sets of Personal Data, whether or not by automated means.

    1.11. "Processor" means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Controller.

    1.12. "Restricted Transfer" means: (i) where EU GDPR applies, a transfer of Customer Personal Data from the EEA to a country outside the EEA that is not subject to an adequacy determination, (ii) where UK GDPR applies, a transfer of Customer Personal Data from the United Kingdom to any other country that is not subject to an adequacy determination or (iii) where FADP applies, a transfer of Customer Personal Data from Switzerland to any other country that is not subject to an adequacy determination.

    1.13. "Services" means: Subscription Services and Professional Services (as defined in the Agreement).

    1.14. "Schedules" means one or more schedules incorporated by the Parties to this Addendum.

    Schedule 1Subject Matter and Details of Processing
    Schedule 2Technical and Organizational Measures
    Schedule 3Cross-Border Transfer Mechanisms
    Schedule 4Region-Specific Terms

    1.15. "Security Incident" means any breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data being Processed by Provider.

    1.16. "Specified Notice Period" is 48 hours.

    1.17. "Subprocessor" means any third party authorized by Provider to Process any Customer Personal Data.

    1.18. "Subprocessor List" means the list of Provider's Subprocessors as listed at https://alaigned.com/subprocessors.

    2. Scope and Duration

    2.1. Roles of the Parties. This DPA applies to Provider as a Processor of Customer Personal Data and to Customer as a Controller or Processor of Customer Personal Data.

    2.2. Scope of DPA. This DPA applies to Provider's Processing of Customer Personal Data under the Agreement to the extent such Processing is subject to Data Protection Laws.

    2.3. Duration of DPA. This DPA terminates upon expiration or termination of the Agreement (or, if later, the date on which Provider has ceased all Processing of Customer Personal Data).

    2.4. Order of Precedence. In the event of any conflict or inconsistency among the following documents, the order of precedence will be: (1) any Standard Contractual Clauses or other measures to which the Parties have agreed in Schedule 3 or Schedule 4, (2) this DPA and (3) the Agreement.

    3. Processing of Personal Data

    3.1. Customer Instructions

    (a) Provider will Process Customer Personal Data as a Processor only: (i) in accordance with Customer Instructions or (ii) to comply with Provider's obligations under applicable laws.

    (b) "Customer Instructions" means: (i) Processing to provide Services and perform Provider's obligations in the Agreement (including this DPA) and (ii) other reasonable documented instructions of Customer consistent with the terms of the Agreement.

    (c) Details regarding the Processing of Customer Personal Data by Provider are set forth in Schedule 1.

    (d) Provider will notify Customer if it receives an instruction that Provider reasonably determines infringes Data Protection Laws.

    3.2. Confidentiality

    (a) Provider will protect Customer Personal Data in accordance with its confidentiality obligations as set forth in the Agreement.

    (b) Provider will ensure personnel who Process Customer Personal Data either enter into written confidentiality agreements or are subject to statutory obligations of confidentiality.

    3.3. Compliance with Laws

    (a) Provider and Customer will each comply with Data Protection Laws in their respective Processing of Customer Personal Data.

    (b) Customer will comply with Data Protection Laws in its issuing of Customer Instructions to Provider.

    3.4. Changes to Laws

    The Parties will work together in good faith to negotiate an amendment to this DPA as either Party reasonably considers necessary to address the requirements of Data Protection Laws from time to time.

    4. Subprocessors

    4.1. Use of Subprocessors

    (a) Customer generally authorizes Provider to engage Subprocessors to Process Customer Personal Data.

    (b) Provider will: (i) enter into a written agreement with each Subprocessor imposing data Processing and protection obligations substantially the same as those set out in this DPA and (ii) remain liable for compliance with the obligations of this DPA and for any acts or omissions of a Subprocessor.

    4.2. Subprocessor List

    Provider will maintain an up-to-date list of its Subprocessors, including their functions and locations, as specified in the Subprocessor List.

    4.3. Notice of New Subprocessors

    Customer authorizes Provider to add and/or modify its Subprocessor List, on the condition that Provider furnishes at least thirty (30) days' prior written notice of the addition and/or modification of any Subprocessor.

    4.4. Objection to New Subprocessors

    (a) If, within 30 days after written notice of a new Subprocessor, Customer notifies Provider in writing that Customer objects to Provider's appointment of such new Subprocessor based on reasonable data protection concerns, the Parties will discuss such concerns in good faith.

    (b) Customer's continued use of Provider's Services thirty (30) days after any changes or revisions to the Subprocessor List have been published shall indicate its agreement with the terms of such revised list.

    5. Security

    5.1. Security Measures

    Provider will implement and maintain reasonable and appropriate technical and organizational measures, procedures and practices, as appropriate to the nature of the Customer Personal Data, that are designed to protect the security, confidentiality, integrity and availability of Customer Personal Data and protect against Security Incidents.

    5.2. Incident Notice and Response

    (a) Provider will implement and follow procedures to detect and respond to Security Incidents.

    (b) Provider will: (i) notify Customer without undue delay and, in any event, not later than the Specified Notice Period, after becoming aware of a Security Incident affecting Customer and (ii) make reasonable efforts to identify the cause of the Security Incident, mitigate the effects and remediate the cause.

    (c) Upon Customer's request, Provider will assist Customer by providing, when available, additional information reasonably necessary for Customer to meet its Security Incident notification obligations under Data Protection Laws.

    (d) Customer acknowledges that Provider's notification of a Security Incident is not an acknowledgement by Provider of its fault or liability.

    (e) Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data.

    5.3. Customer Responsibilities

    (a) Customer is responsible for reviewing the information made available by Provider relating to data security and making an independent determination as to whether the Services meets Customer's requirements and legal obligations under Data Protection Laws.

    (b) Customer is solely responsible for complying with Security Incident notification laws applicable to Customer.

    6. Data Protection Impact Assessment

    Upon Customer's request and taking into account the nature of the applicable Processing, to the extent such information is available to Provider, Provider will assist Customer in fulfilling Customer's obligations under Data Protection Laws to carry out a data protection impact or similar risk assessment related to Customer's use of the Services.

    7. Data Subject Requests

    7.1. Assisting Customer

    Upon Customer's request and taking into account the nature of the applicable Processing, Provider will assist Customer by appropriate technical and organizational measures, insofar as possible, in complying with Customer's obligations under Data Protection Laws to respond to requests from individuals to exercise their rights.

    7.2. Data Subject Requests

    If Provider receives a request from a Data Subject in relation to the Data Subject's Customer Personal Data, Provider will notify Customer and advise the Data Subject to submit the request to Customer, and Customer will be responsible for responding to any such request.

    8. Data Return or Deletion

    8.1. During Subscription Term. During the Subscription Term, Customer may, through the features of the Services, access, return to itself or delete Customer Personal Data. In addition, Provider will delete all Customer Personal Data at any time during the Subscription Term upon a Customer written request.

    8.2. Post Termination.

    (a) Following termination or expiration of the Agreement, Provider will, in accordance with its obligations under the Agreement, delete all Customer Personal Data from Provider's systems.

    (b) Deletion will be in accordance with industry-standard secure deletion practices. Provider will issue a certificate of deletion upon Customer's written request.

    (c) Notwithstanding the foregoing, Provider may retain Customer Personal Data: (i) as required by Data Protection Laws or (ii) in accordance with its standard backup or record retention policies.

    9. Audits

    9.1. Provider Records Generally. Provider will keep records of its Processing in compliance with Data Protection Laws.

    9.2. Compliance Program. Provider will describe its internal and/or third-party audit and certification programs (if any) and make summary copies of its audit reports ("Audit Report") available to Customer upon Customer's written request on an annual basis and subject to confidentiality obligations.

    9.3. Customer Audit. Subject to the terms of this Section 9.3., Customer has the right, at Customer's expense, to conduct an audit of reasonable scope and duration pursuant to a mutually agreed-upon audit plan with Provider that is consistent with the Audit Parameters (an "Audit").

    10. Cross-Border Transfers / Region-Specific Terms

    10.1. Cross-Border Data Transfers

    (a) Provider (and its Affiliates) may Process and transfer Customer Personal Data globally as necessary to provide the Services under the Agreement.

    (b) If Provider engages in a Restricted Transfer, it will comply with Schedule 3 (Cross-Border Transfer Mechanisms).

    10.2. Region-Specific Terms

    To the extent that Provider Processes Customer Personal Data protected by Data Protection Laws in one of the regions listed in Schedule 4, then the terms specified therein with respect to the applicable jurisdiction(s) will apply in addition to the terms of this DPA.

    11. Liability

    11.1. Liability Cap. Subject to Section 11.2., the total combined liability of either Party and its Affiliates towards the other Party and its Affiliates under or in connection with the Agreement and this Addendum combined will be limited to the agreed Liability Cap for the relevant Party under the Agreement.

    11.2. Liability Cap Exclusions. Nothing in Section 11.1. will affect the remaining terms of the Agreement relating to liability (including any specific exclusions from any limitation of liability).

    Schedule 1: Subject Matter and Details of Processing

    Provider / 'Data Exporter' Details

    Name:Alaigned s.r.o.
    Contact details for data protection:Radovan Janeček, CEO — privacy@alaigned.com
    Main address:Na Strži 2102/61a, 140 00 Prague 4, Czechia
    Provider activities:Performance of the Agreement
    Role:Processor

    Customer / 'Data Importer' Details

    Name:Customer (as defined in the Agreement)
    Contact details for data protection:(as provided by Customer during registration or in the Agreement)
    Main address:(as provided by Customer in the Agreement)
    Customer activities:Performance of the Agreement
    Role:Controller

    Details of Processing

    Categories of Data Subjects:Customers, Prospects, Business Partners and Employees and Contractors of the Customer
    Categories of Customer Personal Data:First and Last Name, Title and Employer, Business Contact Information, Personal Contact Information, Email Content
    Sensitive Categories of Data:No Sensitive Categories of Data will be transferred
    Frequency of transfer:Ongoing
    Nature of the Processing:Storing, analyzing, combining, enriching, and distributing of Personal Data to perform Services under the Agreement
    Purpose of the Processing:Performance of the Agreement
    Duration of Processing / retention period:For the duration of the Agreement
    Transfers to Subprocessors:As per Subprocessors List

    Schedule 2: Technical and Organizational Measures

    1. Physical Access Controls: the Processor shall take reasonable measures to prevent physical access, such as security personnel and secured buildings and factory premises, to prevent unauthorized persons from gaining access to Personal Data.

    2. System Access Controls: the Processor shall implement appropriate measures to prevent unauthorized use of Personal Data.

    3. Data Access Controls: the Processor shall take reasonable measures to provide that Personal Data is accessible and manageable only by properly authorized staff.

    4. Transmission Controls: the Processor shall take reasonable measures to ensure that it is possible to check and establish to which entities the transfer of Personal Data by means of data transmission facilities is envisaged.

    5. Input Controls: the Processor shall take reasonable measures to provide that it is possible to check and establish whether and by whom Personal Data has been entered into data Processing systems, modified or removed.

    6. Data Backup: the Processor shall ensure that back-ups are taken on a regular basis, are secured, and encrypted when storing Personal Data.

    7. Logical Separation: the Processor shall ensure that data from the Controller is logically segregated on the Processor's systems.

    8. Shared Responsibilities for Information Security: Controller agrees that in accordance with applicable Data Protection Laws and before submitting any Personal Data to the Services, Controller will perform an appropriate risk assessment to determine whether the Security Measures within the Services provide an adequate level of security.

    Schedule 3: Cross-Border Transfer Mechanisms

    1. Definitions

    1.1. "EU Standard Contractual Clauses" or "EU SCCs" means the annex found in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679.

    1.2. "UK International Data Transfer Agreement" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, Version B1.0, in force as of March 21, 2022.

    2. EU Transfers

    Where Customer Personal Data is protected by EU GDPR and is subject to a Restricted Transfer, the EU SCCs are hereby incorporated by reference.

    (a) Module 3 (Processor to Processor) applies where Provider is a Processor and Customer is a Processor; (b) Module 4 (Processor to Controller) applies where Provider is a Processor and Customer is a Controller; (c) Provider is the "data exporter" and Customer is the "data importer"; (d) by entering into this DPA, each Party is deemed to have signed the EU SCCs as of the DPA Effective Date.

    For each Module, where applicable: (a) the optional docking clause in Clause 7 does not apply; (b) in Clause 9, Option 2 will apply; (c) in Clause 11, the optional language does not apply; (d) in Clause 13, all square brackets are removed; (e) in Clause 17, the EU SCCs will be governed by the Law of Czechia; (f) in Clause 18, disputes will be resolved before the courts of Czechia.

    3. Swiss Transfers

    Where Customer Personal Data is protected by the FADP and is subject to a Restricted Transfer, the EU SCCs apply as set forth in Section 2 with the following modifications: (a) the competent supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner; (b) EU SCCs will be governed by the laws of Switzerland; (c) disputes will be resolved before the courts of Switzerland.

    4. UK Transfers

    Where Customer Personal Data is protected by the UK GDPR and is subject to a Restricted Transfer, the EU SCCs apply as set forth in Section 2 with the following modifications: each Party shall be deemed to have signed the "UK Addendum to the EU Standard Contractual Clauses" issued by the Information Commissioner's Office under section 119(A) of the Data Protection Act 2018.

    Schedule 4: Region-Specific Terms

    A. California

    1. Definitions. CCPA and other capitalized terms not defined in this Schedule are defined in the DPA.

    1.1. "business purpose", "commercial purpose", "personal information", "sell", "service provider" and "share" have the meanings given in the CCPA.

    1.2. The definition of "Data Subject" includes "consumer" as defined under the CCPA.

    1.3. The definition of "Controller" includes "business" as defined under the CCPA.

    1.4. The definition of "Processor" includes "service provider" as defined under the CCPA.

    2. Obligations

    2.1. Customer is providing the Customer Personal Data to Provider under the Agreement for the limited and specific business purposes of providing the Services as described in Schedule 1.

    2.2. Provider will comply with its applicable obligations under the CCPA and provide the same level of privacy protection to Customer Personal Data as is required by the CCPA.

    2.3. Provider acknowledges that Customer has the right to: (i) take reasonable and appropriate steps to help ensure that Provider's use of Customer Personal Data is consistent with Customer's obligations under the CCPA, (ii) receive from Provider notice and assistance regarding consumers' requests to exercise rights under the CCPA and (iii) upon notice, take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.

    2.4. Provider will notify Customer promptly after it makes a determination that it can no longer meet its obligations under the CCPA.

    2.5. Provider will not retain, use or disclose Customer Personal Data: (i) for any purpose, including a commercial purpose, other than the business purposes described in Section 2.1. or (ii) outside of the direct business relationship between Provider with Customer, except where and to the extent permitted by the CCPA.

    2.6. Provider will not sell or share Customer Personal Data received under the Agreement.

    2.7. Provider will not combine Customer Personal Data with other personal information except to the extent a service provider is permitted to do so by the CCPA.