(Andeavour as Supplier) — Signature Version
Download the signed PDF versionThis Data Processing Agreement ("DPA") applies to the Processing of Personal Data by Andeavour on Customer's behalf when providing the Andeavour Offerings described in the relevant Agreement between Customer and Alliance Andeavour Ltd. (collectively, the "Parties"). In the event of a conflict between the terms of the Agreement and this DPA, the terms of this DPA shall control. In the event of a conflict between the terms of this DPA and the EU Standard Contractual Clauses, the terms of the EU Standard Contractual Clauses shall control. Andeavour reserves the right to periodically update this DPA, which is available at www.andeavour.io/data-processing-agreement.pdf.
Capitalized terms that are used but not otherwise defined in this DPA shall have the meanings given in the applicable Agreement or Data Protection Legislation.
"Agreement" means the underlying agreement(s) and any applicable order form in effect between the Parties relating to the Andeavour Offerings, including attachments and exhibits, or other written or electronic terms of service or subscription agreement, including without limitation this DPA upon its effectiveness.
"Affiliate" shall have the meaning given in the Agreement; if no definition is set forth in the Agreement, it shall mean any entity that Customer directly or indirectly controls (e.g. subsidiary), or is controlled by (e.g. parent) or which is under common control (e.g. sibling). "Control" means the ownership, direct or indirect, of a majority of an entity's stock or other interest allowing the owner to direct the affairs of such entity.
"Authorized Affiliate" shall mean an Affiliate of Customer that has not signed a separate agreement with Andeavour, but is either a Controller or Processor for the Personal Data processed by Andeavour pursuant to the Agreement, for so long as such entity remains an Affiliate of Customer.
"Approved Jurisdiction" means a jurisdiction that has either been approved as having adequate legal protections for data by the European Commission or the United Kingdom Information Commissioner's Office, or where data transfers contemplated by this Agreement are not otherwise restricted under the relevant Data Protection Legislation.
"Controller" shall have the meaning attributed to it in the EU GDPR or the UK GDPR or US CCPA, as applicable.
"Customer" shall mean the end customer who has purchased the relevant Andeavour Offerings, whether directly from Andeavour or through an authorized channel partner, together with all Affiliates of Customer that are authorized to purchase or use Andeavour Offerings for their own account pursuant to the Agreement.
"Data Protection Legislation" means all applicable data protection laws, regulations, and regulatory requirements in the relevant jurisdiction applicable to the respective Party in its role in the Processing of Personal Data under the Agreement and this DPA, which may include (1) the EU GDPR, the UK GDPR, and other relevant data protection laws of the EU and its Member States, Iceland, Liechtenstein, Norway, and the Swiss Federal Data Protection Act ("FADP"); and (2) the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), any other United States state privacy legislation of similar scope to the aforementioned statutes that become enforceable after execution of this DPA, all of which as may be amended from time to time.
"Data Subject" shall mean an identified or identifiable natural person to whom Personal Data relates.
"DPA Effective Date" shall be the last to occur of the effective date of the Agreement or the date of initial delivery of the Andeavour Offerings to which this DPA relates (but not later than the first date of Processing of Personal Data for such purpose).
"EEA" means the European Economic Area. "EU" means the European Union. "EU GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
"EU Standard Contractual Clauses" or "EU SCCs" means the standard data protection clauses for the transfer of Personal Data to processors established in third countries, as described in Article 46 of the EU GDPR pursuant to the European Commission's decision (C(2010)593) of 5 February 2010 on Standard Contractual Clauses, as approved by the European Commission in the European Commission's Implementing Decision 2021/914/EU of 4 June 2021.
"Andeavour" means Alliance Andeavour Ltd. and its direct and indirect subsidiaries. "Andeavour Offering(s)" means Andeavour-branded hardware, software and Services procured by Customer directly from Andeavour or through an authorized channel partner.
"Personal Data" means any personal data, personal information or similar term as defined in the Data Protection Legislation, that Andeavour Processes in connection with the Andeavour Offering. "Processing" or "Process" shall have the meaning attributed to it in the applicable Data Protection Legislation.
"Security Documentation" means the documentation describing the Security Measures and any other documents and information made available by Andeavour. "Security Incident" means the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Andeavour's possession, custody or control. "Security Measures" has the meaning given in Section 5.2 (Andeavour Security Measures).
"Services" means any services provided by Andeavour pursuant to the Agreement, including but not limited to support and maintenance services and professional services. "Sub-processors" means third parties engaged by Andeavour to Process Personal Data in relation to the Andeavour Offering. "Term" means the period from the DPA Effective Date until the end of Andeavour's provision of the applicable Andeavour Offering pursuant to the Agreement. "Third-Party Controller" means an entity other than Customer or Andeavour that is a Controller with respect to Personal Data being processed hereunder.
"UK Addendum" means the template addendum B.1.0 issued by the UK Information Commissioner and laid before the UK Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 thereof. "UK GDPR" means the Retained Regulation (EU) 2016/679 (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
This DPA will take effect on the DPA Effective Date and, notwithstanding the expiration of the Term, will remain in effect until, and automatically expire upon termination or expiration of the Agreement, or until such time as Andeavour no longer Processes Personal Data. This DPA applies where and only to the extent that Andeavour Processes Personal Data on behalf of Customer as Data Processor in the course of providing the Andeavour Offerings. Notwithstanding the foregoing, Andeavour will continue to comply with the relevant provisions of this DPA until Customer's Personal Data has been deleted in accordance with Section 4 of this DPA.
The parties acknowledge and agree that: (3.1.1) the subject matter and details of the Processing are described in Appendix 1; (3.1.2) Andeavour is a Processor of that Personal Data under Data Protection Legislation, in each case regardless of whether Customer acts as a Controller or as a Processor on behalf of a Third-Party Controller; (3.1.3) Customer is a Controller of that Personal Data under Data Protection Legislation; (3.1.4) Andeavour will inform Customer if it believes that Customer's instructions with respect to the Processing of Personal Data violate the EU GDPR, UK GDPR or Member State provisions; and (3.1.5) each party will comply with the obligations applicable to it in such role under the Data Protection Legislation with respect to that Personal Data.
Customer agrees that: (a) Customer has established, or ensured that another party has established, a legal basis for Andeavour's Processing of Personal Data contemplated by this DPA; (b) to the extent required by Data Protection Legislation given the context of the Processing and unless another legal basis supports the lawfulness of Processing, all notices have been given to, and consents and rights have been obtained from, the relevant Data Subjects and any other party as may be required under applicable law; (c) Personal Data does not and will not contain Special Categories of Personal Data, as defined in Article 9.1 of the EU GDPR and the UK GDPR; (d) Customer will keep the amount of Personal Data provided to Andeavour to the minimum necessary for the provision of the relevant Andeavour Offerings; and (e) Customer will ensure a level of security appropriate to the particular content of the Personal Data in accordance with the requirements of the applicable Data Protection Legislation, including without limitation pseudonymizing and backing-up Personal Data and securing the account authentication credentials, systems and devices Customer uses to access the Andeavour Offerings.
3.3.1 Customer's Instructions. By entering into this DPA, Customer instructs Andeavour to Process Personal Data: (a) to provide the Andeavour Offerings, including Processing initiated by Customer's users in their use of Offerings; (b) as authorized by the Agreement, including this DPA; and (c) as further documented in any other written instructions given by Customer and acknowledged in writing by Andeavour. Where applicable, Customer shall be responsible for any communications, notifications, assistance and/or authorizations that may be required in connection with a Third-Party Controller.
3.3.2 Andeavour's Compliance with Instructions. Andeavour will only Process Personal Data in accordance with Customer's instructions described in Section 3.3.1 unless Data Protection Legislation requires otherwise, in which case Andeavour will notify Customer in writing (unless that law prohibits Andeavour from doing so on important grounds of public interest).
3.3.3 CCPA. As used in this sub-Section, the terms "Sell," "Share," "Business Purpose," and "Commercial Purpose" shall have the meanings given in the CCPA and "Personal Information" shall mean any personal information (as defined in the CCPA) contained in Personal Data. To the extent the CCPA applies, Andeavour will not: (a) Sell or Share any Personal Information; or (b) retain, use, or disclose any Personal Information (i) for any purpose other than for the Business Purposes specified in the Agreement, including for any Commercial Purpose other than the Business Purposes specified in the Agreement, or as otherwise permitted by the CCPA, or (ii) outside of the direct business relationship between Andeavour and Customer; or (c) combine Personal Information received from, or on behalf of, Customer with Personal Data received from or on behalf of any third party, or collected from Andeavour's own interaction with Data Subjects, except to perform any Business Purpose permitted by the CCPA. Andeavour hereby certifies that it understands the foregoing restrictions and will comply with them. Andeavour will comply with applicable obligations under the CCPA and provide the same level of privacy protection to Personal Information as is required by the CCPA. Customer has the right to take reasonable and appropriate steps to help ensure that Andeavour uses the Personal Information transferred in a manner consistent with Customer's obligations under the CCPA by exercising Customer's audit rights in Section 7. Andeavour will notify Customer if it makes a determination that it can no longer meet its obligations under the CCPA.
Andeavour's obligations set forth in this DPA shall also extend to Authorized Affiliates, subject to the following conditions: (3.4.1) Customer must exclusively communicate any additional Processing instructions requested pursuant to 3.3.2 directly to Andeavour, including instructions from Authorized Affiliates; (3.4.2) Customer shall be responsible for Authorized Affiliates' compliance with this DPA and all acts and/or omissions by an Authorized Affiliate with respect to Customer's obligations in this DPA shall be considered the acts and/or omissions of Customer; and (3.4.3) Authorized Affiliates may only bring a claim directly against Andeavour if they have acceded in writing to this DPA. Otherwise, Customer must bring such Authorized Affiliate Claim directly against Andeavour on behalf of such Authorized Affiliate, unless Data Protection Legislation requires the Authorized Affiliate be a party to such claim.
4.1 Deletion on Termination. On termination of the Agreement or expiry or termination of the Term and at the choice of the Customer, Andeavour will either delete or return (in a commonly machine-readable format) the Personal Data to the Customer unless Data Protection Legislation requires or permits continued retention and Processing of the Personal Data.
4.2 Retention. Personal Data will be retained as needed to fulfill the purposes for which it was collected, such as delivery of the Andeavour Offerings, and as necessary for Andeavour to comply with its business requirements, legal obligations, resolve disputes, protect its assets, and enforce its rights and agreements ("Business Requirements"). Andeavour will use commercially reasonable efforts to implement and maintain appropriate retention periods for Personal Data in accordance with Data Protection Legislation, and will delete Personal Data when retention is no longer necessary for the purposes of Processing under this DPA, subject only to situations where a longer period is necessary for Andeavour's Business Requirements or is required under applicable law.
5.1 General. Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons, the Parties shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
5.2 Andeavour Security Measures. Andeavour will implement and maintain technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Personal Data as described in the Security Measures Addendum to this DPA, which may be found at www.andeavour.io/security-measures-addendum.pdf (the "Security Measures"), and which is hereby incorporated into this DPA by reference.
5.3 Security Controls; Confidentiality of Processing. Andeavour may grant access to Personal Data to employees, contractors and Sub-processors under an appropriate obligation of confidentiality (whether a contractual or statutory duty) when such access is required to perform their job duties.
5.4 Andeavour Security Assistance. Andeavour will (taking into account the nature of the Processing of Personal Data and the information available to Andeavour) provide Customer with reasonable assistance necessary for Customer to comply with its obligations in respect of Personal Data under Data Protection Legislation, including Articles 32 to 36 (inclusive) of the EU GDPR and UK GDPR, by (5.4.1) implementing and maintaining the Security Measures in accordance with Section 5.2, and (5.4.2) complying with the terms of Section 6 (Notice and Communication).
5.5 No Assessment of Personal Data by Andeavour. Andeavour shall have no obligation to assess the contents or accuracy of Personal Data, including to identify information subject to any specific legal, regulatory, or other requirement. Customer is responsible for reviewing the information made available by Andeavour relating to data security and making an independent determination as to whether the Offerings meet Customer's requirements and legal obligations under Data Protection Legislation.
6.1 Notification of Security Incident. If Andeavour becomes aware of a Security Incident, Andeavour will (a) promptly take reasonable steps to investigate the Security Incident and (b) notify Customer of the Security Incident without undue delay, in accordance with governing law.
6.2 Communication. Andeavour shall provide Customer timely information about the Security Incident including, to the extent known to Andeavour: (a) a description of the nature of the Security Incident, (b) the name and contact details for the contact point to find more information, (c) a description of likely consequences of the Security Incident, (d) a description of the measures taken or proposed to be taken to address the Security Incident including, where appropriate, measures to mitigate its possible adverse effects, and (e) such other information as is necessary for Customer to carry out Customer's notification obligations related to the Security Incident, including assisting Customer in complying with Articles 33 and 34 of the EU GDPR. Customer acknowledges that because Andeavour personnel may not have visibility to the content of Personal Data, it may be unlikely that Andeavour can provide information as to the particular nature of the Personal Data, or the identities, number or categories of affected Data Subjects. Communications in connection with a Security Incident shall not be construed as an acknowledgment by Andeavour of any fault or liability.
6.3 Complaints or Notices Related to Personal Data. If Andeavour receives any official complaint, notice, or communication that relates to Andeavour's Processing of Personal Data or either Party's compliance with Data Protection Legislation in connection with Personal Data, to the extent legally permitted, Andeavour shall promptly notify Customer and provide commercially reasonable cooperation and assistance in relation to any such complaint, notice, or communication. Customer shall be responsible for any reasonable costs arising from Andeavour's provision of assistance in relation to any official complaint, notice, or communication that relates to Customer's compliance with Data Protection Legislation.
7.1 Audit. Customer may audit Andeavour's compliance with its obligations under this DPA as required by Data Protection Legislation, but not more than once per year unless required by Data Protection Legislation, including where mandated by Customer's supervisory authority. Andeavour will contribute to such audits by providing Customer or Customer's supervisory authority with the information and assistance reasonably necessary to conduct the audit.
7.2 Third Party. If a third party is to conduct the audit, Andeavour may object to the auditor if the auditor is, in Andeavour's reasonable opinion, a competitor of Andeavour. Such objection will require Customer to appoint another auditor or conduct the audit itself.
7.3 Process. Subject to Section 6 in relation to a Security Incident and aside from in the event of an investigation of a supervisory authority, to request an audit Customer must submit a detailed proposed audit plan to Andeavour at least thirty (30) days in advance of the proposed audit date, and any third-party auditor must sign a customary non-disclosure agreement mutually acceptable to the parties. The proposed audit plan must describe the proposed scope, duration, and start date of the audit. Andeavour will review the plan and work cooperatively with Customer to agree on a final audit plan. Nothing in this Section shall require Andeavour to disclose any information where such disclosure would result in a breach of any duties of confidentiality.
7.4 Documents. If the controls or measures to be assessed are addressed in an SSAE 16/ISAE 3402 Type 2, ISO, NIST or similar audit report performed by a qualified third-party auditor within twelve (12) months of Customer's audit request and Andeavour has confirmed there are no known material changes in the controls audited, Customer agrees to accept such report in lieu of requesting an audit of such controls or measures.
7.5 Timing. The audit must be conducted during regular business hours, subject to the agreed final audit plan and Andeavour's safety, security or other relevant policies, and may not unreasonably interfere with Andeavour business activities.
7.6 Reports. Customer will promptly notify Andeavour of any non-compliance discovered during an audit and provide Andeavour any audit reports generated, unless prohibited by Data Protection Legislation or otherwise instructed by a supervisory authority. Customer may use the audit reports only for the purposes of meeting Customer's regulatory audit requirements and/or confirming compliance with this DPA. The reports, audit, and any information arising therefrom shall be considered Andeavour's Confidential Information.
7.7 Costs. Any audits are at Customer's expense. Customer will be responsible for any fees charged by any auditor appointed by Customer. Andeavour may charge a reasonable fee, to be mutually agreed in advance, taking into account the resources expended by Andeavour.
Andeavour will provide reasonably requested information regarding the Andeavour Offerings to enable Customer to carry out impact assessments or prior consultations with data protection authorities as required by applicable Data Protection Legislation, including Customer's obligations pursuant to Articles 35 and 36 of the EU GDPR and UK GDPR, by (a) making available for review copies of the Security Documentation or other documentation or information describing relevant aspects of Andeavour's information security program and the security measures applied in connection therewith; and (b) providing the other information contained in the Agreement including this DPA. Andeavour shall additionally provide such reasonable assistance to Customer, taking into consideration the nature of the Offerings provided, to the extent needed by Customer in connection with a data protection impact assessment.
9.1 Customer's Responsibility for Requests. Andeavour shall promptly notify Customer if Andeavour receives a request from a Data Subject that identifies Personal Data related to Customer or that otherwise identifies Customer, including where the Data Subject seeks to exercise any of its rights under applicable Data Protection Legislation. To the extent legally permitted, Andeavour will advise the Data Subject to submit their request to Customer and Customer will be responsible for responding to any such request, subject to the assistance provided by Andeavour pursuant to Section 9.2.
9.2 Andeavour's Data Subject Request Assistance. Andeavour will provide (taking into account the nature of the Processing of Personal Data) Customer with reasonable assistance as necessary for Customer to perform its obligation under Data Protection Legislation to respond to requests by Data Subjects, including Customer's obligation to respond to requests for exercising the Data Subject's rights set out in Chapter III of the EU GDPR and in the UK GDPR.
10.1 Data Storage and Processing Facilities. Andeavour may, subject to this Section 10, store and Process Personal Data in the United States or anywhere Andeavour or its Sub-processors maintains facilities.
10.2 Transfer Mechanisms. For any transfers of Personal Data from the EEA and its member states, United Kingdom and/or Switzerland or other jurisdictions to a country which is not an Approved Jurisdiction, such transfers and Processing shall be governed by a valid mechanism for the lawful transfer of Personal Data recognized under applicable Data Protection Legislation.
10.2.1 EU Standard Contractual Clauses. With respect to transfers of Personal Data protected by the EU GDPR outside an Approved Jurisdiction, such transfers shall be subject to the EU Standard Contractual Clauses, which shall be deemed incorporated into and form part of this DPA, including the following elections (any optional clauses not expressly selected are not included): (a) the Module 2 terms shall apply (Controller to Processor); (b) the optional Clause 7 in Section I is incorporated, and Authorized Affiliates may accede in a signed writing to this DPA and the SCCs under the same terms and conditions as Customer, subject to Section 3.4; (c) for purposes of Clause 9, Option 2 ("General written authorization") is selected and the process and time period for the addition or replacement of Sub-processors shall be as described in Section 11; (d) the optional paragraph in Clause 11 is not incorporated; (e) for purposes of Clause 13 and Annex 1.C, Option 1 will apply if Customer has an establishment in the European Union, Option 2 will apply if Customer is not established in the European Union and has an appointed representative, and Option 3 will apply if Customer has neither an establishment nor a representative in the European Union; (f) for purposes of Clause 17 and Clause 18, Option 1 of Clause 17 is selected and the Member State for purposes of governing law and jurisdiction shall be the Federal Republic of Germany; (g) for purposes of Annex 1.A, the "data importer" shall be Andeavour and the "data exporter" shall be Customer and any Authorized Affiliates that have acceded to the SCCs pursuant to this DPA; (h) for purposes of Annex 1.B, the description of the transfer is as described in Appendix 1 of this DPA; (i) for purposes of Annex 1.C, the competent supervisory authority in accordance with Clause 13 is the supervisory authority associated with Customer's establishment or representative; and (j) for purposes of Annex II, the technical and organizational measures are those described in Section 5.2.
10.2.2 UK Addendum. With respect to transfers of Personal Data protected by the UK GDPR outside an Approved Jurisdiction, the EU SCCs will also apply in accordance with Sections 10.2.1(a)-(j) above, subject to the following modifications: Table 1 will be filled out with the Parties as set forth in Section 10.2.1(g); Table 2 with the selected SCCs, Modules and Selected Clauses as set forth in Sections 10.2.1(a)-(d); Table 3 with the information set forth in Sections 10.2.1(g), (h), (j) and the Sub-processor Addendum; and Table 4 by selecting "neither Party" may end the UK Addendum as set out in Section 19 of the UK Addendum. The Alternative Part 2 Mandatory Clauses of the Approved Addendum (template Addendum B.1.0 issued by the ICO and laid before the UK Parliament in accordance with s119A of the Data Protection Act 2018 on 28 January 2022) shall apply, as revised under Section 18 of those Mandatory Clauses.
10.2.3 Swiss Standard Contractual Clauses. With respect to transfers of Personal Data protected by the FADP, the EU SCCs will also apply in accordance with Sections 10.2.1(a)-(j) above, subject to the following modifications: (a) the term "member state" shall not be interpreted so as to exclude Data Subjects in Switzerland from suing for their rights in their place of habitual residence in accordance with Clause 18(c); (b) the SCCs shall also protect the data of legal entities until the entry into force of the revised FADP; (c) references to the GDPR or other governing law shall also be interpreted to include the FADP; and (d) the supervisory authority indicated in Annex I.C shall be the Swiss Federal Data Protection and Information Commissioner.
11.1 Authorized Sub-Processors. For purposes of Clause 9 of the Standard Contractual Clauses, Customer provides Andeavour with a general consent to engage Sub-processors, subject to Section 11.3 (Changes to Sub-processors), as well as Andeavour's current Sub-processors already engaged as of the DPA Effective Date and as listed in the Sub-processor Addendum to this DPA located at www.andeavour.io/sub-processor-addendum.pdf, which is hereby incorporated into this DPA by reference, subject to Andeavour ensuring those Sub-processors meet obligations in this DPA.
11.2 Sub-Processor Obligations. Andeavour shall: (i) enter into a written agreement with each Sub-processor imposing data protection obligations no less protective of Personal Data than Andeavour's obligations under this DPA to the extent applicable to the nature of the services provided by such Sub-processor; and (ii) remain liable for each Sub-processor's compliance with the obligations under this DPA. Upon written request, and subject to any confidentiality restrictions, Andeavour shall provide Customer all relevant information it reasonably can in connection with its applicable Sub-processor agreements where required to satisfy Customer's obligations under Data Protection Legislation.
11.3 Changes to Sub-Processors. Andeavour shall notify Customer (for example, by updating the Sub-processor Addendum, or by publishing this information at Andeavour's customer portal or by e-mail or in-application messaging) of any new Sub-processor at least fourteen (14) business days in advance of allowing the new Sub-processor to Process Personal Data (the "Objection Period"). During the Objection Period, objections (if any) must be provided to Andeavour in writing and based on reasonable grounds relating to data protection. The Parties will discuss those objections in good faith with a view to achieving resolution. If it can be reasonably demonstrated that the new Sub-processor is unable to Process Personal Data in compliance with this DPA and Andeavour cannot provide an alternative Sub-processor, Customer may provide written notice terminating the purchases with respect only to those aspects of the Offerings which cannot be provided without the use of the new Sub-processor.
If Andeavour receives a demand to retain, disclose, or otherwise Process Personal Data for any third party, including law enforcement or a government authority ("Third-Party Demand"), then Andeavour shall attempt to redirect the Third-Party Demand to Customer. Customer agrees that Andeavour can provide information to such third party as reasonably necessary to redirect the Third-Party Demand. If Andeavour cannot redirect the Third-Party Demand, then Andeavour shall, to the extent legally permitted, provide Customer reasonable notice as promptly as feasible under the circumstances to allow Customer to seek a protective order or other appropriate remedy. This section does not diminish Andeavour's obligations under the EU SCCs or UK Addendum with respect to access by public authorities.
13.1 Notices. Notwithstanding anything to the contrary in the Agreement, any notices required or permitted to be given by Andeavour to Customer under this DPA may be given (a) in accordance with the notice clause of the Agreement; and/or (b) as described in Section 6.1 (Notification of Security Incident) if applicable; and/or (c) to Andeavour's primary points of contact with Customer.
13.2 General. The Parties agree that this DPA shall replace and supersede any existing data processing addendum, attachment, exhibit or standard contractual clauses that Andeavour and Customer may have previously entered into in connection with the Andeavour Offerings. Except as expressly modified by the DPA, the terms of the Agreement remain in full force and effect. To the extent of any conflict or inconsistency between this DPA and the remaining terms of the Agreement regarding the subject matter herein, this DPA shall govern. To the extent of any conflict between the body of this DPA and its Addenda (not including the Standard Contractual Clauses) and the relevant Standard Contractual Clauses in a way that materially affects the adequacy of the transfer, the Standard Contractual Clauses shall prevail. In the event of any conflict between this DPA and the relevant Data Protection Legislation, the provisions under the Data Protection Legislation shall prevail. Each Party's and all of its Affiliates' liability, taken together in the aggregate, arising out of or relating to this DPA, the SCCs, and any other data protection agreements in connection with the Agreement, shall be subject to any aggregate limitations on liability set out in the Agreement. Nothing in this DPA is intended to limit the Parties' direct liability towards Data Subjects or applicable supervisory data protection authorities that may not be limited under mandatory applicable law.
13.3 No Third Party Rights. In no event shall this DPA benefit or create any right or cause of action on behalf of a third party (including a Third-Party Controller), but without prejudice to the rights or remedies available to Data Subjects under Data Protection Legislation or this DPA (including the SCCs).
13.4 Governing Law. Except as otherwise set forth in this DPA, this DPA will be governed by and construed in accordance with governing law and jurisdiction provisions in the Agreement or, in the event that the Agreement is silent, in accordance with the law of the State of California and the United States without regard to conflicts of laws provisions.
| Subject Matter | Andeavour's delivery of Andeavour Offerings. |
|---|---|
| Duration of Processing | Duration of the applicable purchase order. |
| Nature of the Processing | Collection, storage, organization, retrieval, erasure, modification, and any other Processing operation anticipated by Customer using the Andeavour Offerings. |
| Purpose of the Processing | Andeavour's delivery of Andeavour Offerings. |
| Categories of Personal Data | Contact Information: Andeavour receives and uses contact information (name, email, title, phone, address) for Customer's employees for billing purposes. Andeavour may also receive contact information of Customer's employees when these employees contact Andeavour's Customer Success organization requesting assistance with product issues. Metadata: In select circumstances and only upon Customer's initiation and direction, Customer may provide network access to Andeavour's Support Engineers or Professional Services Team, or transmit select packet capture data (including metadata) to Andeavour's Support Team, and as a result Andeavour will have access to metadata associated with packets traveling through Customer's network for the sole purpose of providing Support or delivering Andeavour Professional Services. This metadata may contain domain, file or user names and, depending on naming conventions, may include Personal Data. |
| Sensitive data transferred | N/A |
| Frequency of the transfer | Continuous |
| Categories of Statutorily Defined Data Subjects for Whom the Customer's Personal Data Relates | Data Subjects such as Customer's system users' data and other individuals whose Personal Data Customer is responsible for, and which Personal Data is Processed in connection with support and/or delivery of Andeavour Offerings. |
| Transfers to Sub-processors | The subject matter, nature, and duration of Processing undertaken by Sub-processors will be the same as set forth in this DPA with respect to Andeavour. |
Questions regarding this DPA, requests for the current Sub-processor list, or security documentation should be directed to info@andeavour.io.