Data Processing Agreement

Data Processing Agreement V2026 08

This Data Processing Agreement (the “DPA”) forms part of and is incorporated into the xyzt.ai Software as a Service Agreement and any applicable Order entered into between xyzt.ai BV, with registered office at Kempischesteenweg 303/200, 3500 Hasselt, Belgium, VAT BE 0721.781.156 (the “Service Provider”), and the customer identified in the applicable Order (the “Customer”).

The Service Provider and the Customer may individually be referred to as a “Party” and jointly as the “Parties”.

This DPA applies where and to the extent that the Service Provider processes Personal Data on behalf of the Customer in connection with the provision of the Services under the Agreement.

For purposes of this DPA, the Customer acts as Controller and the Service Provider acts as Processor, unless the circumstances of a particular processing activity require a different qualification under applicable Data Protection Law.

This DPA is intended to satisfy the requirements applicable to agreements between controllers and processors under Article 28 of Regulation (EU) 2016/679 (the “GDPR”).

Capitalised terms not otherwise defined in this DPA shall have the meanings given to them in the Agreement.

1. Definitions and Scope

1.1 For purposes of this DPA

“Agreement” means the xyzt.ai Software as a Service Agreement, together with the applicable Order and any schedules or documents incorporated therein by reference.

“Applicable Data Protection Law” means all laws and regulations applicable to the processing of Personal Data under this DPA, including the GDPR and applicable Belgian data protection legislation, in each case as amended, replaced or supplemented from time to time.

“Controller”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing”, “Processor” and “Supervisory Authority” shall have the meanings given to them in the GDPR.

“Customer Personal Data” means any Personal Data contained in Customer Data that is processed by the Service Provider on behalf of the Customer in connection with the Services.

“Sub-Processor” means any Processor engaged by or on behalf of the Service Provider to process Customer Personal Data in connection with the Services.

“Restricted Transfer” means a transfer of Personal Data to a third country or international organisation that requires an appropriate safeguard or other transfer mechanism under Chapter V GDPR.

1.2 This DPA applies only to the extent that the Service Provider processes Customer Personal Data on behalf of the Customer in connection with the provision of the Services.

1.3 The subject matter and duration of the Processing, the nature and purpose of the Processing, the types of Personal Data processed, the categories of Data Subjects and the rights and obligations of the Customer are described in this DPA, the Agreement, the applicable Order and Annex I (Processing Details) to this DPA.

1.4 The Processing shall continue for the duration of the applicable Services and thereafter only for such period as Customer Personal Data remains in the possession or control of the Service Provider in accordance with the Agreement, this DPA or applicable law.

2. Roles and Responsibilities of the Parties

2.1 The Customer is responsible for determining the purposes and means of the Processing of Customer Personal Data and shall act as Controller in respect of such Processing. The Service Provider shall act as Processor and shall process Customer Personal Data only on behalf of and in accordance with the documented instructions of the Customer, except where otherwise required by applicable law.

2.2 The Customer shall ensure that:

  • its instructions to the Service Provider comply with Applicable Data Protection Law;
  • it has an appropriate legal basis for the Processing of Customer Personal Data and for instructing the Service Provider to process such Personal Data;
  • all required notices have been provided to Data Subjects and all required consents, permissions or other authorisations have been obtained, where applicable;
  • Customer Personal Data provided or made accessible to the Service Provider is adequate, relevant and limited to what is necessary for the purposes for which it is processed; and
  • it does not instruct the Service Provider to process Customer Personal Data in a manner that would violate Applicable Data Protection Law.

2.3 The Service Provider shall comply with the obligations applicable to processors under Applicable Data Protection Law in relation to its Processing of Customer Personal Data.

2.4 Nothing in this DPA shall prevent the Service Provider from processing Personal Data, other than Customer Personal Data processed on behalf of the Customer, as an independent Controller where such Processing is necessary for its own legitimate business purposes, including account administration, billing, fraud prevention, security, compliance with legal obligations or the establishment, exercise or defence of legal claims, provided that such Processing is carried out in accordance with Applicable Data Protection Law.

2.5 The Customer retains control over Customer Personal Data and remains responsible for responding to Data Subjects and Supervisory Authorities in its capacity as Controller, except to the extent the Service Provider is required to respond directly under applicable law.

3. Processing Instructions and Processor Obligations

3.1 Processing instructions

The Service Provider shall process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers of Customer Personal Data to a third country or international organisation, unless the Service Provider is required to process such Personal Data under applicable Union or Member State law.

Where the Service Provider is required by applicable law to process Customer Personal Data other than on the Customer's documented instructions, the Service Provider shall inform the Customer of that legal requirement before carrying out the Processing, unless such law prohibits the Service Provider from providing such information on important grounds of public interest.

The Agreement, the applicable Order, this DPA and the Customer's use and configuration of the Services in accordance with the Documentation shall constitute documented instructions from the Customer for purposes of this DPA.

The Service Provider shall immediately inform the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. The Service Provider may suspend performance of the affected Processing until the Parties have resolved the matter.

3.2 Confidentiality of personnel

The Service Provider shall ensure that persons authorised to process Customer Personal Data are subject to appropriate obligations of confidentiality or are under an appropriate statutory obligation of confidentiality.

Access to Customer Personal Data shall be limited to persons who require such access for the provision, support, security or maintenance of the Services or otherwise for the performance of the Service Provider's obligations under the Agreement.

3.3 Security

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the Processing, as well as the risks to the rights and freedoms of natural persons, the Service Provider shall implement and maintain appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk in accordance with Article 32 GDPR.

The applicable technical and organisational measures are described in Annex II (Technical and Organisational Measures) to this DPA.
The Service Provider may update its technical and organisational measures from time to time, provided that such updates do not materially reduce the overall level of security applicable to Customer Personal Data during the applicable Term.

3.4 Personal Data Breach

The Service Provider shall notify the Customer without undue delay and, in any event, within thirty-six (36) hours after becoming aware of a Personal Data Breach affecting Customer Personal Data.

Such notification shall, to the extent the relevant information is reasonably available to the Service Provider at the time of notification:

  • describe the nature of the Personal Data Breach;
  • identify, where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
  • describe the likely consequences of the Personal Data Breach;
  • describe the measures taken or proposed to be taken by the Service Provider to address and mitigate the Personal Data Breach; and
  • provide details of an appropriate contact point from whom further information may be obtained.

Where it is not possible to provide all information at the same time, the Service Provider may provide information in phases without undue further delay.

Notification of a Personal Data Breach shall not constitute an acknowledgement of fault or liability by the Service Provider.

3.5 Data Subject requests

Taking into account the nature of the Processing, the Service Provider shall provide reasonable assistance to the Customer, through appropriate technical and organisational measures insofar as reasonably possible, for the fulfilment of the Customer's obligations to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

If the Service Provider receives a request directly from a Data Subject relating to Customer Personal Data, the Service Provider shall, unless prohibited by applicable law, refer the Data Subject to the Customer or promptly notify the Customer and shall not respond substantively to the request except on the Customer's documented instructions or where required by applicable law.

3.6 Compliance assistance

Taking into account the nature of the Processing and the information available to the Service Provider, the Service Provider shall provide reasonable assistance to the Customer in connection with the Customer's obligations under Articles 32 to 36 GDPR, including security of Processing, Personal Data Breach notifications, data protection impact assessments and prior consultations with Supervisory Authorities, where applicable.

Where the Customer requests material assistance beyond that reasonably required for the Service Provider to comply with its obligations under Applicable Data Protection Law, the Parties may agree in advance on reasonable professional services fees for such additional assistance.

3.7 Regulatory and legally compelled disclosure

The Service Provider shall not disclose Customer Personal Data to a third party except:

  • to authorised Sub-Processors in accordance with this DPA;
  • pursuant to the Customer's documented instructions; or
  • where required by applicable law, court order, governmental authority or Supervisory Authority.

Where disclosure is required under paragraph (c), the Service Provider shall, to the extent legally permitted, notify the Customer before making such disclosure and shall limit the disclosure to the Personal Data legally required to be disclosed.

3.8 Cooperation

The Parties shall reasonably cooperate with each other in relation to inquiries, investigations or requests from a Supervisory Authority concerning the Processing of Customer Personal Data under this DPA.

4. Sub-Processors

4.1 General authorisation

The Customer grants the Service Provider general written authorisation to engage Sub-Processors for the Processing of Customer Personal Data in connection with the provision of the Services.

The Service Provider shall maintain an up-to-date list of its Sub-Processors in Annex III (Sub-Processors) to this DPA or on a webpage identified in Annex III.

4.2 Appointment of Sub-Processors

Where the Service Provider engages a Sub-Processor, it shall enter into a written agreement with that Sub-Processor imposing the same data protection obligations as set out in this DPA, insofar as applicable to the Processing performed by that Sub-Processor, including appropriate technical and organisational measures designed to ensure that the Processing meets the requirements of Applicable Data Protection Law.

The Service Provider shall remain responsible to the Customer for the performance of the data protection obligations of its Sub-Processors to the extent required by Applicable Data Protection Law.

4.3 Changes to Sub-Processors

The Service Provider shall provide the Customer with prior notice of any intended addition or replacement of a Sub-Processor, including by email or another electronic notification mechanism designated by the Service Provider.

Such notice shall be provided at least fourteen (14) calendar days before the new or replacement Sub-Processor begins Processing Customer Personal Data, unless a shorter period is reasonably necessary due to an emergency, security requirement or other circumstance outside the Service Provider's reasonable control.

4.4 Customer objections

The Customer may object to the appointment of a new or replacement Sub-Processor on reasonable and documented grounds relating specifically to the protection of Customer Personal Data.

Any objection must:

  • be submitted in writing within fourteen (14) calendar days following receipt of the notice referred to in Clause 4.3;
  • identify the Sub-Processor concerned; and
  • explain in reasonable detail the data protection grounds for the objection.

The Parties shall cooperate in good faith to seek a commercially reasonable solution to the Customer's objection.

Where reasonably practicable, the Service Provider may choose not to use the affected Sub-Processor for the Customer.

If no commercially reasonable alternative is available and the Parties are unable to resolve the objection, the Service Provider may elect not to provide the affected part of the Services. Where the Customer cannot lawfully continue to use the affected Services as a direct result of the appointment of the relevant Sub-Processor, the Customer may terminate only the affected part of the Services upon written notice. Any such termination shall not affect Charges accrued prior to termination or Charges relating to unaffected Services.

An objection shall not entitle the Customer to suspend payment of Charges relating to Services already provided or unaffected Services.

4.5 Emergency appointments

Where the Service Provider is required to appoint or replace a Sub-Processor without the notice period specified in Clause 4.3 because of an urgent security, legal, operational or service continuity requirement, the Service Provider may do so and shall notify the Customer without undue delay thereafter.

4.6 Sub-Processors and international transfers

Where a Sub-Processor processes Customer Personal Data outside the European Economic Area, the Service Provider shall ensure that the Processing complies with Clause 5 and Applicable Data Protection Law.

5. International Transfers

5.1 General rule

The Service Provider shall not make a Restricted Transfer of Customer Personal Data except in accordance with Chapter V GDPR and Applicable Data Protection Law.

5.2 Adequacy decisions

Where Customer Personal Data is transferred to a country, territory, sector or international organisation that is subject to a valid adequacy decision of the European Commission under Article 45 GDPR, the Service Provider may rely on such adequacy decision for the relevant transfer for so long as that decision remains valid and applicable.

5.3 Standard Contractual Clauses

Where no applicable adequacy decision exists and an appropriate safeguard under Article 46 GDPR is required, the Service Provider shall implement an appropriate transfer mechanism.

Where appropriate, such mechanism may consist of the Standard Contractual Clauses adopted by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended, replaced or superseded from time to time (the “SCCs”).

Where the SCCs apply to a Restricted Transfer under this DPA:

  • the module of the SCCs applicable to the roles of the relevant data exporter and data importer shall apply, and the applicable optional clauses, competent Supervisory Authority, governing law, forum and other selections required under the SCCs shall be determined in accordance with Annex I to this DPA or the applicable transfer documentation;
  • the SCCs shall be deemed incorporated into this DPA by reference to the extent legally permitted;
  • the information required for Annexes I to III of the SCCs shall be deemed completed by the corresponding information contained in this DPA, the applicable Order and the Annexes to this DPA, to the extent that such information satisfies the requirements of the SCCs;
  • in the event of a conflict between the SCCs and this DPA relating specifically to the relevant Restricted Transfer, the SCCs shall prevail to the extent of that conflict.

5.4 Supplementary measures

Where required under Applicable Data Protection Law, the Service Provider shall assess whether supplementary technical, organisational or contractual measures are reasonably necessary to ensure an adequate level of protection for Customer Personal Data in connection with a Restricted Transfer and shall implement such measures where appropriate.

5.5 Changes in transfer mechanism

If a transfer mechanism relied upon under this Clause becomes invalid, unavailable or otherwise insufficient under Applicable Data Protection Law, the Service Provider shall use commercially reasonable efforts to implement an alternative lawful transfer mechanism.

5.6 Customer cooperation

The Customer shall provide reasonable cooperation and information requested by the Service Provider where necessary to implement or maintain an appropriate transfer mechanism under this Clause.

6. Compliance Information and Records

6.1 Compliance information

The Service Provider shall make available to the Customer such information as is reasonably necessary to demonstrate compliance with the obligations applicable to the Service Provider under Article 28 GDPR and this DPA.

Where reasonably available and appropriate, the Service Provider may satisfy such requests by providing relevant compliance documentation, certifications, audit reports, security documentation, policies or summaries thereof.

6.2 Records of Processing

The Service Provider shall maintain records of Processing activities for which it is responsible to the extent required by Article 30 GDPR and shall make such records available to the competent Supervisory Authority where required by Applicable Data Protection Law.

6.3 Information requests

The Customer shall use reasonable efforts to avoid requesting information that:

  • has already been provided by the Service Provider;
  • is publicly available;
  • is not reasonably relevant to the Customer's obligations under Applicable Data Protection Law; or
  • would require disclosure of information relating to other customers, the Service Provider's confidential security information or information protected by legal privilege.

The Service Provider may provide summaries, extracts or redacted information where reasonably necessary to protect the confidentiality, security or rights of the Service Provider or third parties, provided that such measures do not materially prevent the Customer from assessing the Service Provider's compliance with its obligations under this DPA.

6.4 Supervisory Authorities

Nothing in this Clause shall limit any obligation of the Service Provider to provide information directly to a competent Supervisory Authority where required by Applicable Data Protection Law.

7. Audits

7.1 Audit rights

The Service Provider shall make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations applicable to the Service Provider under Article 28 GDPR and this DPA and shall allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer, in accordance with this Clause 7.

7.2 Documentation-first approach

Before requesting an on-site or other intrusive audit, the Customer shall first review the information and documentation made available by the Service Provider pursuant to Clause 6, including any relevant certifications, audit reports, security documentation or compliance information.

An additional audit may be requested where the information already provided is not reasonably sufficient to demonstrate compliance with this DPA or Applicable Data Protection Law.

7.3 Audit conditions

Except where otherwise required by Applicable Data Protection Law, a competent Supervisory Authority or following a Personal Data Breach materially affecting Customer Personal Data, audits shall:

(a) be conducted no more than once in any twelve (12) month period;

(b) be subject to at least thirty (30) calendar days' prior written notice;

(c) take place during normal business hours;

(d) be limited to systems, processes, facilities and documentation relevant to the Processing of Customer Personal Data;

(e) be conducted in a manner that does not unreasonably interfere with the Service Provider's business operations or compromise the confidentiality, security or availability of the Services or information relating to other customers; and

(f) be subject to reasonable confidentiality and security requirements imposed by the Service Provider.

7.4 Independent auditor

Where an audit is conducted by a third party, such auditor shall be independent, professionally qualified, not be a competitor of the Service Provider and be bound by appropriate confidentiality obligations.

The Service Provider shall not unreasonably withhold or delay approval of a proposed auditor.

7.5 Scope and cooperation

The Parties shall agree a reasonable audit scope, timing and methodology in advance.

The Service Provider shall reasonably cooperate with the audit and provide access to relevant information, personnel and systems to the extent reasonably necessary to demonstrate compliance with this DPA.

Nothing in this Clause requires the Service Provider to disclose:

  • information relating to other customers;
  • information that would materially compromise the security of the Services or Managed Infrastructure;
  • source code, proprietary algorithms or other trade secrets, except to the extent such disclosure is expressly required by Applicable Data Protection Law or a competent Supervisory Authority; or
  • information protected by legal professional privilege.

Where appropriate, the Service Provider may satisfy an audit request through redacted information, summaries or equivalent evidence, provided that this does not materially prevent the Customer from verifying compliance.

7.6 Audit costs

Each Party shall bear its own costs relating to an audit.

Where an audit requested by the Customer requires material time or resources beyond the Service Provider's ordinary compliance obligations, the Service Provider may charge reasonable professional services fees for such additional assistance, provided that such fees are communicated to and agreed with the Customer in advance.

The Service Provider shall not charge the Customer for an audit to the extent the audit is required as a direct result of a material breach of this DPA by the Service Provider or where charging would be prohibited by Applicable Data Protection Law.

7.7 Supervisory Authorities

Nothing in this Clause shall restrict the powers of a competent Supervisory Authority or any obligation of the Service Provider to cooperate directly with such authority under Applicable Data Protection Law.

8. Return and Deletion of Customer Personal Data

8.1 Return or deletion

Upon expiry or termination of the Services involving the Processing of Customer Personal Data, the Service Provider shall, at the Customer's choice, delete or return the Customer Personal Data processed on behalf of the Customer and delete existing copies, unless applicable Union or Member State law requires continued storage of such Personal Data.

8.2 Retrieval period

The Customer shall be responsible for retrieving Customer Personal Data within the retrieval or transition period applicable under the Agreement, including Article 10.7 thereof where the EU Data Act applies.

Where Customer Personal Data remains available for retrieval following termination or expiry of the Services, the Service Provider shall continue to protect such Personal Data in accordance with this DPA for the duration of that period.

8.3 Deletion

Following expiry of the applicable retrieval period, the Service Provider may irretrievably delete Customer Personal Data from its active systems and shall do so where required under Applicable Data Protection Law or the Agreement.

Customer Personal Data contained in backup systems may remain until deleted in accordance with the Service Provider's ordinary backup retention cycles, provided that such Personal Data remains protected in accordance with this DPA and is not actively processed except as required for backup restoration, security, legal compliance or disaster recovery purposes.

8.4 Legal retention

Where the Service Provider is required by applicable Union or Member State law to retain Customer Personal Data following termination or expiry of the Services, the Service Provider shall:

  • retain only the Personal Data required by such law;
  • process such Personal Data only for the purpose required by applicable law; and
  • continue to apply the protections required by this DPA for so long as the Personal Data is retained.

8.5 Relationship with switching obligations

The modalities for retrieval, return, transfer and deletion of Customer Personal Data shall be consistent with Article 10.7 of the Agreement and applicable law, including Regulation (EU) 2023/2854 (the EU Data Act) where applicable.

Nothing in this DPA shall permit the Service Provider to impose a switching charge prohibited under applicable law.

8.6 Confirmation of deletion

Upon the Customer's reasonable written request following completion of the applicable deletion process, the Service Provider shall confirm that Customer Personal Data has been deleted in accordance with this Clause, subject to any Personal Data retained pursuant to Clause 8.3 or 8.4.

9. Data Minimisation and Customer Responsibilities

9.1 Data minimisation

The Customer shall use reasonable efforts to ensure that Customer Personal Data provided or made accessible to the Service Provider is adequate, relevant and limited to what is necessary for the purposes for which such Personal Data is processed through the Services.

9.2 Special categories and unnecessary Personal Data

Unless expressly agreed in the applicable Order or otherwise expressly supported by the Services, the Customer shall not intentionally provide or make available to the Service Provider special categories of Personal Data within the meaning of Article 9 GDPR, Personal Data relating to criminal convictions and offences within the meaning of Article 10 GDPR, or other Personal Data that is not reasonably necessary for the Customer's intended use of the Services.

Where appropriate and reasonably practicable having regard to the Customer's intended Processing purposes, the Customer should anonymise or pseudonymise Personal Data before uploading or otherwise making it available through the Services.

9.3 Customer responsibility

The Customer remains responsible for determining whether the Services are appropriate for the nature and sensitivity of the Customer Personal Data it elects to process through the Services and for configuring and using the Services in a manner consistent with Applicable Data Protection Law.

9.4 No monitoring obligation

Except to the extent required by Applicable Data Protection Law or expressly agreed in the applicable Order, the Service Provider is not responsible for independently reviewing or monitoring Customer Personal Data for the purpose of determining whether the Customer has complied with its obligations under this Clause.

If the Service Provider becomes aware that Customer Personal Data is being processed in a manner that materially conflicts with this DPA, the Agreement or Applicable Data Protection Law, the Service Provider may take reasonable steps in accordance with the Agreement, including notifying the Customer and, where necessary, suspending the affected Processing.

10. Customer Warranties and Indemnity

10.1 The Customer represents and warrants that:

  • it has all rights, permissions and authorisations necessary to provide or make Customer Personal Data available to the Service Provider for Processing in accordance with this DPA;
  • its Processing instructions to the Service Provider comply with Applicable Data Protection Law;
  • it has an appropriate legal basis for the Processing of Customer Personal Data and, where required, has provided all necessary notices to Data Subjects and obtained all necessary consents or other authorisations; and
  • the Processing of Customer Personal Data in accordance with the Customer's documented instructions will not, in itself, cause the Service Provider to violate Applicable Data Protection Law.

10.2 The Customer shall indemnify and hold the Service Provider harmless against third-party claims, damages, liabilities, costs and reasonable expenses to the extent arising from:

  • the Customer's material breach of this DPA or Applicable Data Protection Law;
  • the Customer's lack of a valid legal basis or necessary rights for the Processing of Customer Personal Data; or
  • Processing carried out by the Service Provider in accordance with the Customer's documented instructions where such instructions violate Applicable Data Protection Law.

11. Liability

11.1 Subject to Applicable Data Protection Law, each Party's liability arising out of or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement.

11.2 Nothing in this DPA or the Agreement shall limit or exclude a Party's liability to the extent such limitation or exclusion is prohibited by Applicable Data Protection Law.

11.3 Nothing in this Clause affects any liability that a Party may have directly towards a Data Subject or Supervisory Authority under Applicable Data Protection Law.

11.4 Where either Party becomes liable to a Data Subject or Supervisory Authority as a result of Processing under this DPA, the allocation of responsibility between the Parties shall, to the extent permitted by Applicable Data Protection Law, reflect each Party's respective responsibility for the event giving rise to such liability.

12. Term and Survival

12.1 This DPA shall take effect when the Agreement becomes effective and shall remain in force for so long as the Service Provider Processes Customer Personal Data on behalf of the Customer.

12.2 Expiry or termination of the Agreement or an applicable Order shall not automatically terminate this DPA to the extent the Service Provider continues to Process Customer Personal Data in connection with retrieval, return, deletion, backup retention, legal retention or any other permitted post-termination activity.

12.3 This DPA shall terminate once the Service Provider has completed its obligations relating to the return or deletion of Customer Personal Data in accordance with Clause 8 and no longer Processes Customer Personal Data on behalf of the Customer.

12.4 Clauses which by their nature are intended to survive termination or expiry, including Clauses relating to confidentiality, return and deletion, liability, audit rights in respect of Processing occurring before termination, and any obligations arising under Applicable Data Protection Law, shall survive for so long as necessary to give effect to their purpose.

13. Order of Precedence

13.1 In the event of a conflict between this DPA and the Agreement concerning the Processing or protection of Customer Personal Data, this DPA shall prevail.

13.2 In all other respects, the Agreement shall prevail.

13.3 Where Standard Contractual Clauses or another mandatory transfer mechanism apply to a Restricted Transfer and conflict with this DPA or the Agreement in relation to that transfer, the applicable Standard Contractual Clauses or mandatory transfer mechanism shall prevail to the extent of such conflict.

13.4 Nothing in this DPA shall be interpreted as reducing the level of protection or limiting the rights of Data Subjects provided under Applicable Data Protection Law.

14. Amendments and Changes in Law

14.1 The Service Provider may update this DPA where reasonably necessary to:

  • comply with changes in Applicable Data Protection Law;
  • reflect binding guidance, decisions or requirements of a competent Supervisory Authority or court;
  • implement or update a lawful international transfer mechanism; or
  • reflect changes to the Services, Processing activities, security measures or Sub-Processors that reasonably require corresponding changes to this DPA, provided that such update does not materially reduce the overall level of protection afforded to Customer Personal Data under this DPA.

14.2 Where an update materially affects the Customer's rights or obligations under this DPA, the Service Provider shall provide reasonable prior notice of the change, except where an earlier effective date is required by applicable law or a competent authority.

14.3 Changes to Sub-Processors shall remain subject to the notification and objection procedure set out in Clause 4.

15. Miscellaneous

15.1 Governing law and jurisdiction

Unless mandatory Applicable Data Protection Law requires otherwise, this DPA shall be governed by the same governing law and jurisdiction provisions as the Agreement.

15.2 Severability

If any provision of this DPA is held to be invalid, unlawful or unenforceable, such provision shall be deemed modified to the minimum extent necessary to make it valid and enforceable. If such modification is not possible, the affected provision shall be severed without affecting the validity or enforceability of the remaining provisions.

15.3 No waiver

A failure or delay by either Party to exercise any right or remedy under this DPA shall not constitute a waiver of that or any other right or remedy.

15.4 Electronic incorporation and acceptance

This DPA may be incorporated into the Agreement or an Order by reference and may be accepted electronically, including through execution or acceptance of the applicable Agreement or Order.

15.5 Headings

Headings are included for convenience only and shall not affect the interpretation of this DPA.

Annex I – Processing Details

Annex II – Technical and Organisational Measures

Annex III – Sub-Processors