Data Processing Addendum
This Data Processing Addendum (this “DPA”), forms part of the Terms of Service or other written or electronic agreement referencing this DPA (the “Agreement”) between Town.com, Inc. (“Town”) and the customer identified in the Agreement (“Customer”). This DPA amends the Agreement and is effective upon its incorporation into the Agreement, as specified in the Agreement itself or in any Order (“Effective Date”). Upon its incorporation into the Agreement, this DPA will form part of the Agreement. Town and Customer may be referred to herein collectively as the “Parties” or individually as a “Party.”
Customer enters into this DPA on behalf of itself and its Affiliates to the extent Town Processes Customer Personal Data in performance of the Services for such Affiliates. For the purposes of this DPA only, and except where indicated otherwise in this DPA, the term “Customer” will include Customer and its Affiliates.
How This DPA Applies
This DPA is binding on the Parties only to the extent applicable Data Protection Laws govern the Processing of Customer Personal Data in performance of the Services. This DPA is fully incorporated into and made a part of the Agreement. This DPA replaces any existing terms, exhibits, schedules, appendices, DPAs, or other attachments related to the Processing of Customer Personal Data unless otherwise expressly stated in this DPA. In the event of any inconsistency between the terms of this DPA and any terms of the Agreement with respect to Customer Personal Data, the terms of this DPA will govern and control.
Data Processing Terms
The Parties agree that the terms of this DPA govern the Processing of Customer Personal Data in performance of the Services. Each Party, acting reasonably and in good faith, will comply with the terms of this DPA. Any other Processing of Personal Data with respect to Customer and Customer’s users conducted by Town as a Data Controller, including business relationship administration and system security, will be carried out in accordance with Town’s then-current privacy policy located at the following hyperlink: https://www.town.com/privacy-policy (or any successor hyperlink).
1. Definitions and Interpretation
Capitalized terms used in this DPA shall have the meanings set forth in this Section 1 and elsewhere in this DPA. All other capitalized terms not defined in this DPA will have the meanings set forth in the Agreement. For purposes of this DPA: (i) the words “include,” “includes,” and “including” are deemed to be followed by the words “without limitation;” (ii) the word “or” is not exclusive; (iii) words denoting the singular have a comparable meaning when used in the plural, and vice-versa; and (iv) words denoting any gender include all genders.
- “Affiliate” of a Party means any other entity that directly or indirectly, through one or more intermediaries, controls, is controlled by, or is under common control with, such Party. The term “control” (including the terms “controlled by” and “under common control with”) means the direct or indirect power to direct or cause the direction of the management and policies of an entity, whether through the ownership of voting securities, by contract, or otherwise.
- “Authorized User” means an employee or contractor of Customer who is authorized by Customer to access and use the Services on behalf of and for the benefit of Customer.
- “Chat Interactions Data” means chat history, messages, files, and other content generated by or on behalf of an individual Authorized User within a chat session in the Services that is specific to such Authorized User and is not accessible to or otherwise shared with other Authorized Users.
- “Customer Personal Data” means Personal Data Processed by Town (or any Sub-Processor) as a Data Processor on behalf of and at the direction of Customer in performance of the Services.
- “Data Controller” (or equivalent term under applicable Data Protection Laws) means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
- “Data Processor” (or equivalent term under applicable Data Protection Laws) means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Data Controller.
- “Data Protection Laws” means any applicable laws or regulations governing the Processing of Customer Personal Data in performance of the Services, including, but not limited to, to the extent applicable, the European General Data Protection Regulation (Regulation (EU) 2016/679) (the “GDPR”), the GDPR as it forms part of the UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (as amended, including by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019) (the “UK GDPR”), the Swiss Federal Act on Data Protection in its revised version of 25 September 2020 (“FADP”), and the US State Privacy Laws.
- “Data Subject” means an identified or identifiable natural person to whom Customer Personal Data relates. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- “Personal Data” means any information relating to a Data Subject that is subject to protection under applicable Data Protection Laws.
- “Personal Data Breach” means a breach of Town’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Town’s possession, custody or control. For clarity, Personal Data Breach does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data (such as unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems).
- “Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, retention, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- “Restricted Transfer” means: (a) a transfer or disclosure of Customer Personal Data from Customer to Town; or (b) an onward transfer or disclosure of Customer Personal Data from Town to a Subprocessor; in each case, where such transfer or disclosure would be prohibited by applicable Data Protection Laws in the absence of appropriate safeguards, including the SCCs.
- “Services” means the services provided by Town to Customer (or Customer’s Affiliates, as the case may be) under the Agreement.
- “Service Data” means any data relating to the use, support and/or operation of the Services, which is collected by Town from and/or about Authorized Users of the Services and/or Customer’s use of the Service for use for Town’s own purposes (certain of which may constitute Personal Data). Service Data includes Personal Data of Customer’s business representatives.
- “Special Data Categories” means Personal Data subject to specific heightened processing and/or security protections under applicable Data Protection Laws, including, but not limited to, protected health information subject to the Health Insurance Portability and Accountability Act (“HIPAA”).
- “SCCs” means the Commission Implementing Decision (EU) 2021/914 establishing Standard Contractual Clauses for data transfers to third countries (as amended, modified, or replaced from time to time). Specifically, the applicable module within the SCCs is MODULE TWO (Transfer Controller to Processor). For the avoidance of doubt, MODULE ONE (Transfer Controller to Controller), MODULE THREE (Transfer Processor to Processor), and MODULE FOUR (Transfer Processor to Controller) do not apply to this DPA.
- “Subprocessor” means a Data Processor engaged by Town for the purpose of Processing Customer Personal Data in performance of the Services.
- “Supervisory Authority” means the relevant governmental body or bodies having jurisdiction over the Processing of Customer Personal Data under this DPA.
- “UK International Data Transfer DPA” means the template DPA B.1.0 issued by the UK Information Commissioner’s Office (ICO) and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of the UK Mandatory Clauses included in Part 2 thereof.
- “US State Privacy Laws” means, collectively, the comprehensive state-specific data privacy laws and their regulations currently in effect and applicable to Town’s Processing of Personal Data under the Agreement.
2. Processing of Customer Personal Data
2.1 Roles of the Parties
To the extent Town Processes Customer Personal Data in performance of the Services, the Parties agree that Customer is the Data Controller and Town is the Data Processor, with the exception of Service Data, as to which Town is the Data Controller.
2.2 Town as Data Processor
Town, when acting as a Data Processor, will Process Customer Personal Data only on the documented instructions of Customer as provided in Section 2.5 and Section 2.6 of this DPA. Town will not Process Customer Personal Data for any other purpose, except to the extent Processing of Customer Personal Data is required by applicable laws.
2.3 US State Privacy Law-Specific Terms
If Town is Processing Customer Personal Data as a Data Processor within the scope of the US State Privacy Laws in performance of the Services, such Processing shall be subject to Annex 3 (US State Privacy Laws Annex) to this DPA.
2.4 Customer as Data Controller
Customer, as Data Controller, agrees that Customer:
- a) is solely responsible for the accuracy, quality, and legality of Customer Personal Data, including the means by which Customer acquires Customer Personal Data;
- b) is solely responsible for any registration, notice, or other authorization under applicable laws to engage Town to perform the Services;
- c) has the authority to transmit or disclose Customer Personal Data to Town (or permit Town to access Customer Personal Data); and
- d) will provide Town with lawful instructions with respect to the Processing of Customer Personal Data.
2.5 Customer’s Instructions
Customer instructs Town (and authorizes Town to instruct each Subprocessor) to Process Customer Personal Data in performance of the Services, including any necessary Restricted Transfers. The Parties agree that the scope of Customer’s instructions for the Processing of Customer Personal Data is defined by: (i) the Agreement; (ii) any applicable ordering documents, including service orders, order forms, statements of work, and product or service descriptions; (iii) this DPA; and (iv) any Modified Instructions (as defined in Section 2.6).
2.6 Modified Instructions
Customer may request amendments to Customer’s instructions, where such amendments are required to ensure that Customer complies with applicable Data Protection Laws and Customer cannot achieve Customer’s compliance with applicable Data Protection Laws unless Town implements such instructions (“Modified Instructions”), by submitting a written request to Town in accordance with the change control or amendment procedures set forth in the Agreement, to the extent such procedures apply. Customer and Town may mutually agree in writing to amend the Agreement to effect any Modified Instructions. If Town notifies Customer that it is infeasible or impracticable to implement any Modified Instructions, Customer may terminate the applicable Service by providing Town with written notice within thirty (30) days of Town’s notification. This Section 2.6 states Customer’s sole and exclusive remedy, and Town’s sole liability, with regard to Modified Instructions.
2.7 Duty to Inform
To the extent required by applicable Data Protection Laws, Town will inform Customer if, in Town’s opinion, any Customer instruction violates such applicable Data Protection Laws.
2.8 Details of the Processing of Customer Personal Data
The details of the Processing of Customer Personal Data are set forth in Annex 1 (Processing Details) to this DPA.
2.9 Processing of Special Data Categories
Any Processing of Special Data Categories is subject to mutual agreement of the Parties and must be set forth in a schedule to this DPA or a separate written agreement between the Parties.
3. Confidentiality Obligations of Town Personnel
3.1 Confidentiality Obligations of Town Personnel
Town will ensure that any person it authorizes to Process Customer Personal Data is: (a) subject to confidentiality and restricted use obligations that are no less protective than the confidentiality and restricted use obligations set forth in the Agreement; or (b) under an appropriate statutory obligation of confidentiality.
4. Information Security Program
4.1 Information Security Program
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Town will in relation to Customer Personal Data implement a written information security program that includes technical and organizational measures designed to protect such Customer Personal Data against unauthorized access, use, disclosure, alteration, or destruction, including the measures set forth in Article 32(1) of the GDPR (and corresponding provisions of the UK GDPR) to the extent such measures are applicable to Town’s Processing of Customer Personal Data in performance of the Services (“Information Security Program”). As of the Effective Date of this DPA, a summary of such Information Security Program is set forth in the Town Information Security Annex available at https://www.town.com/security-practices/ (“Security Annex”). Town may update the Information Security Program from time to time, provided the updated measures do not materially decrease the overall protection of Customer Personal Data.
5. Subprocessing
5.1 Use of Subprocessors; Liability
Customer generally authorizes Town to use Subprocessors, including Town Affiliates, for the purpose of providing the Services. Town will enter into a written agreement with each Subprocessor containing data protection obligations not less protective than those set forth in this DPA with respect to the Processing of Customer Personal Data. Town will remain responsible for any Processing of Customer Personal Data by Subprocessors.
5.2 Initial Subprocessor List
Customer expressly authorizes the use of the Subprocessors set forth at https://www.town.com/subprocessors/ (the “Subprocessor List Site”).
5.3 Notification
For notification of engagement of any new Subprocessors used by Town, any engagement of a new Sub-Processor will be listed on the Subprocessor List Site. Customer is obliged to observe the Subprocessor List Site on an on-going basis and shall, in connection with executing the Agreement or other documents which this DPA is scheduled to, register for updates of the Subprocessor List Site; provided, however, that Town may implement mechanisms by which Customer can receive automated notifications of new Subprocessor engagements (each, an “Automated Notification Mechanism”) at no additional cost to Customer. If Town implements an Automated Notification Mechanism, Town will notify Customer and provide detailed instructions on the use of such Automated Notification Mechanism. Customer agrees to register for and use any Automated Notification Mechanism if it is made available by Town.
5.4 Customer’s Right to Object to New Subprocessors
Customer will have ten (10) days from the date of a notification or an update to the Subprocessor List Site, as the case may be, to reasonably object to the engagement of any new Subprocessor by providing written notice to Town. If Customer objects to the engagement of a new Subprocessor and the Parties cannot reach an agreement as to the use of the new Subprocessor, Customer may terminate the portion of the Service for which the new Subprocessor is engaged as its sole and exclusive remedy. If Customer has not notified Town of its objection within the time period set forth in this Section 5.4, Customer will be deemed to have approved the use of the new Subprocessor.
5.5 Restricted Transfers to Subprocessors
To the extent Town makes a Restricted Transfer to a Subprocessor, Town will establish appropriate safeguards for such Restricted Transfer as required by applicable Data Protection Laws.
6. Assistance to Customer Related to Data Subject Requests
6.1 Data Subject Request Notification
Town will promptly notify Customer if Town receives a request from a Data Subject to exercise their rights under applicable Data Protection Laws with respect to Customer Personal Data.
6.2 Customer’s Responsibility with respect to Data Subject Requests
Customer will be solely responsible for responding to requests, complaints, and all other communications from Data Subjects; provided, however, Town may confirm to the Data Subject that Town received their communication. To the extent that Customer can respond to such requests by using its access to Customer Personal Data or any “self-service” functionality of the Services, Customer will do so.
6.3 Assistance in Responding to Data Subject Requests
Upon Customer’s written instruction and to the extent required by applicable Data Protection Laws, Town will provide Customer with assistance to fulfill Customer’s obligations to respond to requests from Data Subjects to exercise their rights under applicable Data Protection Laws by implementing appropriate technical and organizational measures, insofar as it is possible, taking into account the nature of the Processing.
7. Assistance with Customer’s Other Data Protection Rights and Obligations
7.1 Assistance Related to Customer’s Other Data Protection Rights and Obligations
Taking into account the nature of the Processing and the information available to Town, Town will provide assistance required to be provided by Data Processors to Data Controllers under applicable Data Protection Laws, to the extent such assistance is applicable to Town’s Processing of Customer Personal Data in performance of the Services.
7.2 Information Security Materials
Upon Customer’s written request, Town will make available to Customer the relevant information security materials for the applicable Service (the “Information Security Materials”) through an access-restricted website in read-only format. The Information Security Materials are the Confidential Information of Town. Town may modify, amend, or replace the Information Security Materials without notice to Customer. To the extent available for the applicable Service, the Information Security Materials may contain the following:
- a) A summary of any third-party audits or certifications relating to the security controls of the applicable Service, including any Service Customer Control (SOC) Type 2 reports and ISO 27001; and
- b) Any other published materials made available by Town, which further describe Town’s principles, programs, and practices regarding information security and privacy.
8. Customer Audit Rights
8.1 Customer Audit Rights
In order to satisfy any audit or inspection request by Customer under applicable Data Protection Laws or the SCCs and/or UK International Data Transfer DPA, Town will provide Customer with the assistance and Information Security Materials set forth in Section 7 of this DPA in order to verify Town’s compliance with its obligations under this DPA.
9. Return or Deletion of Customer Personal Data
9.1 Upon Termination
Upon termination of the Agreement, Town will delete, return, or provide Customer with a mechanism to allow Customer to obtain a copy of or delete all Customer Personal Data. The foregoing obligation shall not apply to: (a) Memory Data or (b) Chat Interactions Data between the Town Service and individual Authorized Users, each of which shall be subject to the provisions below. In addition, Town and its Affiliates may retain Customer Personal Data to the extent required under applicable laws or document retention policies adopted in accordance with such laws. Any Customer Personal Data retained pursuant to this Section 9.1 shall remain subject to the confidentiality and restricted use obligations set forth in the Agreement for the duration of such retention. With respect to Memory Data and Chat Interactions Data: (i) Memory Data is stored in a format integral to the Services and is not exportable or transferable, and Customer shall not be entitled to receive a copy of Memory Data; and (ii) unless an individual Authorized User expressly provides otherwise to Town, Chat Interactions Data is accessible only to the applicable Authorized User and is not visible to Customer or other Authorized Users, as further described in the Agreement, and, accordingly, Customer shall not be entitled to receive a copy of such Chat Interactions Data; provided, however, that where Customer is an individual using the Services for Customer's own benefit and not on behalf of an organization (i.e., Customer has no other Authorized Users), Customer may request a copy of Customer’s own Chat Interactions Data, and Town will make such data available to Customer. Upon termination of the Agreement, Town will delete or otherwise cease processing Memory Data and Chat Interactions Data associated with Customer’s Authorized Users.
9.2 User-Initiated Deletion
Town provides Customer’s Authorized Users with the option to delete their accounts at any time. In such event, Town will delete the individual Authorized User’s chat interactions data between the Town Service and the individual Authorized User (unless the individual Authorized User has expressly chosen to share such data with Customer prior to deleting their account) and delete or cease processing Memory Data of such individual Authorized User in accordance with its standard procedures. All other Customer Personal Data related to that user’s account will continue to be processed in accordance with the Agreement and this DPA.
10. Personal Data Breach of Customer Personal Data
10.1 Personal Data Breach Notification
If Town becomes aware of a Personal Data Breach of the Services involving Customer Personal Data, Town will notify Customer of such Personal Data Breach without undue delay unless prohibited by law or as otherwise requested by a governmental authority.
10.2 Personal Data Breach Assistance
If Town notifies Customer of a Personal Data Breach in accordance with Section 10.1 of this DPA, Town will provide Customer with assistance in relation to handling a Supervisory Authority’s request for information with respect to such Personal Data Breach as required by applicable Data Protection Laws.
11. Restricted Transfers
11.1 SCCs
To the extent that Customer makes a Restricted Transfer to Town, the Parties agree that the SCCs will apply to such Restricted Transfer as described in Annex 2 (Restricted Transfer Annex).
12. Limitations of Liability
12.1 Terms of the Agreement
The parties agree that all liability and limitations of liability under this DPA shall be governed by the applicable language in the Agreement.
13. Service Data
13.1 Permitted Uses
Customer acknowledges that Town may collect, use and disclose Service Data for its own business purposes:
- (i) for accounting, tax, billing, audit, and compliance purposes;
- (ii) to provide, improve, develop, optimize, market and maintain the Services;
- (iii) to investigate fraud, spam, wrongful or unlawful use of the Services;
- (iv) to combine Service Data with other data;
- (v) to de-identify Personal Data so the de-identified data can be used and disclosed by Town for lawful business purposes; and/or
- (vi) as otherwise permitted or required by applicable law.
13.2 Processing Service Data
In respect of any such Processing described in Section 13.1, Town:
- (i) independently determines the purposes and means of such Processing;
- (ii) shall comply with Data Protection Laws (if and as applicable in the context);
- (iii) shall process requests from Data Subjects that are forwarded to Town by Customer to the extent required by Data Protection Laws and upon request provide documentation to Customer that it has done so;
- (iv) shall Process such Service Data as described in Town’s privacy policy (https://www.town.com/privacy-policy (or any successor hyperlink)), as updated from time to time; and
- (v) where possible, shall apply technical and organizational safeguards to any relevant Personal Data that are no less protective than those described in the Security Annex.
14. Miscellaneous
14.1 Assistance Costs
To the extent legally permitted, Customer is responsible for the reasonable costs and fees associated with Town’s provision of assistance under this DPA and implementation of any Modified Instructions.
14.2 Expansion or Modification of Customer Audit Rights
For the avoidance of doubt, no provision in this DPA will be deemed to expand or modify the audit rights of Customer under the Agreement.
14.3 Choice of Law
Except with respect to the SCCs, this DPA is governed by the laws that govern the Agreement, and any dispute between the Parties will be handled as set forth in the Agreement.
14.4 Entire Agreement; Amendments and Modifications
This DPA, together with all exhibits, schedules, addenda, and appendices attached to this DPA and any other documents incorporated into this DPA by reference, constitutes the sole and entire agreement of the Parties with respect to the subject matter of this DPA and supersedes all prior and contemporaneous understandings, agreements, and representations and warranties, both written and oral, with respect to such subject matter. Except as expressly provided in this DPA, the terms of the Agreement are and will remain in full force and effect. This DPA may only be amended by a written amendment that specifically references this DPA and the intent of the Parties to modify this DPA.
Annex 1. Data Processing Details
TOWN / ‘DATA IMPORTER’ DETAILS
- Name: Town.com, Inc.
- Address: 222 Kearny St, Suite #650, San Francisco, CA 94108
- Contact Details for Data Protection: privacy@corp.town.com
- Town Activities: Town provides a cloud-based AI-powered productivity platform that integrates with third-party services to perform work on behalf of users, including triaging inboxes, drafting communications, managing schedules, briefing for meetings, summarizing updates, conducting research, and running user-defined workflows with configurable oversight.
- Role: Processor (and Controller of Service Data)
ORGANIZATION / ‘DATA EXPORTER’ DETAILS
- Name: The entity or other person who is a counterparty to the Agreement
- Customer’s address is: As provided in the Agreement
- Customer’s Contact Details for Data Protection: As provided in the Agreement.
- Customer Activities: Customer’s activities relevant to this DPA are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement as part of its ongoing business operations.
- Role: Controller
Categories of Data Subjects
Relevant Data Subjects include any Data Subjects of Personal Data that Customer causes Town to process as part of the provisions of the Service, including individual authorized users, as well as any other data subjects whose personal data may be included in Customer Personal Data to which the Customer provides Town access in order to provide the Services.
Categories of Personal Data
Relevant Personal Data includes any Categories of Personal Data Customer causes Town to process as part of the provisions of the Service, including:
- Personal details– for example any information that identifies the Data Subject, including name, and contact information.
- Authentication details – for example username, password or PIN code, security questions and other access protocols.
- Technological details – for example internet protocol (IP) addresses, unique identifiers and numbers (including unique identifier in tracking cookies or similar technology), pseudonymous identifiers, precise and imprecise location data, internet / application / program activity data, and device IDs and addresses.
- Email and communications data – for example contents of emails and other communications as provided or permitted by the individual user and/or Customer.
Sensitive Categories of Data, and associated additional restrictions/safeguards
- Categories of sensitive data: Determined by the individual user and/or Customer.
- Additional safeguards for sensitive data: N/A
Frequency of transfer
Ongoing – as initiated by Customer in and through its use, or use on its behalf, of the Services.
Nature of the Processing
Processing operations required in order to provide the Services in accordance with the Agreement.
Purpose of the Processing
as necessary to provide the Services as initiated by Customer in its use thereof, and to comply with any other reasonable instructions provided by Customer in accordance with the terms of this DPA, specifically for the purposes of collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction.
Duration of Processing / Retention Period
For the period determined in accordance with the Agreement and DPA, including Section 9 of the DPA.
Transfers to (sub)processors
As set out in Section 5 of the DPA.
Annex 2. Restricted Transfer Annex
1. RESTRICTED TRANSFERS
EU Restricted Transfers
To the extent that any Processing of Personal Data under this DPA involves the disclosure, grant of access or other transfer of Personal Data when transferred from the EEA, to any person located in any country or territory outside the EEA which does not benefit from an adequacy decision from the European Commission (an “EU Restricted Transfer”) from Customer to Town, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:
- 1) populated in accordance with Part 1 of Attachment 1 to Annex 2 (Restricted Transfer Annex); and
- 2) entered into by the Parties and incorporated by reference into this DPA.
UK Restricted Transfers
To the extent that any Processing of Personal Data under this DPA involves the disclosure, grant of access or other transfer of Personal Data when transferred from the UK, to any person located in any country or territory outside the UK, which does not benefit from an adequacy decision from the UK Government (a “UK Restricted Transfer”) from Customer to Town, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:
- 1) varied to address the requirements of the UK GDPR in accordance with UK Transfer DPA and populated in accordance with Part 2 of Attachment 1 to Annex 2 (Restricted Transfer Annex); and
- 2) entered into by the Parties and incorporated by reference into this DPA.
Swiss Restricted Transfers
To the extent that any Processing of Personal Data under the DPA involves the disclosure, grant of access or other transfer of Personal Data, when transferred from Switzerland, to any person located in a country or territory outside of Switzerland which does not benefit from an adequacy decision from the Swiss authorities (a “Swiss Restricted Transfer”) from Customer to Town, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:
- 1) varied to address the requirements of the FADP and populated in accordance with Part 3 of Attachment 1; and
- 2) entered into by the Parties and incorporated by reference in the DPA.
Nothing in any applicable SCCs (as deemed amended pursuant to Section 1.3) should be interpreted or construed in such a way as would limit or exclude the rights of Data Subjects under Clause 18(c) of those SCCs (as deemed amended pursuant to Section 1.3) to bring legal proceedings before the courts in Switzerland where Switzerland is that Data Subject’s place of habitual residence.
Other Restricted Transfers
To the extent that any Processing of Personal Data under this DPA involves a Restricted Transfer from Customer to Town other than as described in Section 1.1, 1.2, or 1.3 above, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be:
- 1) varied to address the requirements of applicable Data Protection Laws and populated in accordance with Part 4 of Attachment 1 to Annex 2 (Restricted Transfer Annex); and
- 2) entered into by the Parties and incorporated by reference into this DPA.
Adoption of new transfer mechanism
Town may on notice vary this DPA and replace the relevant SCCs with:
- 1) any new form of the relevant SCCs or any replacement therefor prepared and populated accordingly (e.g., standard data protection clauses adopted by the European Commission for use specifically in respect of transfers to data importers subject to Article 3(2) of the EU GDPR); or
- 2) another transfer mechanism, other than the SCCs, that enables the lawful transfer of Personal Data to Town under this DPA in compliance with applicable Data Protection Laws.
Provision of full-form SCCs
In respect of any given Restricted Transfer, if requested of Customer by a Supervisory Authority, Data Subject or further Controller (where applicable) – on specific written request (made to the contact details set out in Annex 1 (Data Processing Details); accompanied by suitable supporting evidence of the relevant request), Town shall provide Customer with an executed version of the relevant set(s) of SCCs responsive to the request made of Customer (amended and populated in accordance with Attachment 1 to Annex 2 (Restricted Transfer Annex) in respect of the relevant Restricted Transfer) for countersignature by Customer, onward provision to the relevant requestor and/or storage to evidence Customer’s compliance with applicable Data Protection Laws.
Operational clarifications
When complying with its transparency obligations under Clause 8.3 of the SCCs, Customer agrees that it shall not provide or otherwise make available, and shall take all appropriate steps to protect, Town’s and its licensors’ trade secrets, business secrets, confidential information and/or other commercially sensitive information.
For the purposes of Clause 15.1(a) of the SCCs, except to the extent prohibited by applicable law and/ or the relevant public authority, as between the Parties, Customer agrees that it shall be solely responsible for making any notifications to relevant Data Subject(s) if and as required.
The terms and conditions of Section 5 of the DPA apply in relation to Town’s appointment and use of Subprocessors under the SCCs. Any approval by Customer of Town’s appointment of a Subprocessor that is given expressly or deemed given pursuant to that Section 5 constitutes Customer’s documented instructions to effect disclosures and onward transfers to any relevant Subprocessors if and as required under Clause 8.8 of the SCCs.
The audits described in Clauses 8.9(c) and 8.9(d) of the SCCs shall be subject to any relevant terms and conditions detailed in Section 8 of the DPA.
Certification of deletion of Personal Data as described in Clauses 8.5 and 16(d) of the SCCs shall be provided only upon Customer’s written request.
Attachment 1 to Annex 2 (Restricted Transfer Annex) — Population of SCCs
Note
- In the context of any EU Restricted Transfer, the SCCs populated in accordance with Part 1 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Section 1.1 of Annex 2 (Restricted Transfer Annex) to the DPA).
- In the context of any UK Restricted Transfer, the SCCs as varied by the UK Transfer DPA and populated in accordance with Part 2 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Section 1.2 of Annex 2 (Restricted Transfer Annex) to the DPA).
- In the context of any Swiss Restricted Transfer, the SCCs as varied and populated by Part 3 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Section 1.3 of Annex 2 (Restricted Transfer Annex) to the DPA).
- In the context of any other Restricted Transfer, the SCCs as varied and populated by Part 4 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Section 1.5 of Annex 2 (Restricted Transfer Annex) to the DPA).
PART 1: POPULATION OF THE SCCs
SIGNATURE OF THE SCCs
Where the SCCs apply in accordance with Paragraph 1.1 of Annex 2 (Restricted Transfer Annex) to the DPA each of the Parties is hereby deemed to have signed the SCCs at the relevant signature block in Annex I to the Appendix to the SCCs.
MODULES
The following modules of the SCCs apply in the manner set out below (having regard to the role(s) of Customer set out in Attachment 1 to Annex 2 (Restricted Transfer Annex) to the DPA):
- 1) Module Two of the SCCs applies to any EU Restricted Transfer and/or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Customer is a Controller in its own right.
POPULATION OF THE BODY OF THE SCCs
For each Module of the SCCs, the following applies as and where applicable to that Module and the Clauses thereof:
- 1) The optional ‘Docking Clause’ in Clause 7 is not used and the body of that Clause 7 is left intentionally blank.
- 2) In Clause 9: 1) OPTION 2: GENERAL WRITTEN AUTHORISATION applies, and the minimum time period for advance notice of the addition or replacement of Subprocessors shall be the advance notice period set out in Section 5 of the DPA; and 2) OPTION 1: SPECIFIC PRIOR AUTHORISATION is not used and that optional language is deleted; as is, therefore, Annex III to the Appendix to the SCCs.
- 3) In Clause 11, the optional language is not used and is deleted.
- 4) In Clause 13, all square brackets are removed and all text therein is retained.
- 5) In Clause 17: 1) OPTION 1 applies, and the Parties agree that the SCCs shall be governed by the law of the jurisdiction of the data exporter in relation to any EU Restricted Transfer; and 2) OPTION 2 is not used and that optional language is deleted.
- 6) For the purposes of Clause 18, the Parties agree that any dispute arising from the SCCs in relation to any EU Restricted Transfer shall be resolved by the courts of the jurisdiction of the data exporter, and Clause 18(b) is populated accordingly.
In this Paragraph 3, references to “Clauses” are references to the Clauses of the SCCs.
POPULATION OF ANNEXES TO THE APPENDIX TO THE SCCs
Annex I to the Appendix to the SCCs is populated with the corresponding information detailed in Annex 1 (Data Processing Details) to the DPA, with:
- 1) Customer being ‘data exporter’; and
- 2) Town being ‘data importer’.
Part C of Annex I to the Appendix to the SCCs is populated as below:
The competent supervisory authority shall be determined as follows:
- Where Customer is established in an EU Member State: the competent supervisory authority shall be the supervisory authority of that EU Member State in which Customer is established.
- Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies and Customer has appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State in which Customer’s EU representative relevant to the processing hereunder is based (from time-to-time).
- Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies, but Customer has not appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State notified in writing to Town’s contact point for data protection identified in Attachment 1 to Annex 2 (Restricted Transfer Annex) to the DPA, which must be an EU Member State in which the data subjects whose personal data is transferred under these Clauses in relation to the offering of goods or services to them, or whose behavior is monitored, are located.
Annex II to the Appendix to the SCCs is populated as below:
General:
- Please refer to Section 7 of the DPA and the Security Annex.
- In the event that Customer receives a Data Subject Request under the EU GDPR and requires assistance from Town, Customer should email Town’s contact point for data protection identified in Annex 1 (Data Processing Details) to the DPA.
Subprocessors: When Town engages a Subprocessor under these Clauses, Town shall enter into a binding contractual arrangement with such Subprocessor that imposes upon them data protection obligations which, in substance, meet or exceed the relevant standards required under these Clauses and the DPA – including in respect of:
- applicable information security measures;
- notification of Information Security Incidents to Town;
- return or deletion of Personal Data as and where required; and engagement of further Subprocessors.
PART 2: UK RESTRICTED TRANSFERS
UK TRANSFER DPA
Where relevant in accordance with Paragraph 1.2 of Annex 2 (Restricted Transfer Annex) to the DPA, the SCCs also apply in the context of UK Restricted Transfers as varied by the UK Transfer DPA in the manner described below:
- 1) Part 1 to the UK Transfer DPA. As permitted by Section 17 of the UK Transfer DPA, the Parties agree: 1) Tables 1, 2 and 3 to the UK Transfer DPA are deemed populated with the corresponding details set out in Annex 1 (Data Processing Details) and the foregoing provisions of this Attachment 1 (subject to the variations effected by the Mandatory Clauses described in (b) below); and 2) Table 4 to the UK Transfer DPA is completed by the box labelled ‘Data Importer’ being deemed to have been ticked.
- 2) Part 2 to the UK Transfer DPA. The Parties agree to be bound by the Mandatory Clauses of the UK Transfer DPA.
In relation to any UK Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs, shall be read as a reference to those SCCs as varied in the manner set out in Paragraph 1.1 of this Part 2.
PART 3: SWISS RESTRICTED TRANSFERS
VARIATIONS FOR SWISS RESTRICTED TRANSFERS
Where applicable in accordance with Section 1.3 of Annex 2 (Restricted Transfer Annex), the SCCs also apply in the context of Swiss Restricted Transfers with the following terms deemed to have the following substituted meanings:
- 1) “GDPR” means the FADP;
- 2) “European Union”, “Union” and “Member State(s)” each mean Switzerland; and
- 3) “supervisory authority” means the FDPIC.
In relation to any Swiss Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs, shall be read as a reference to those SCCs as varied in the manner set out in Section 1.1 of this Part 3.
PART 4: OTHER RESTRICTED TRANSFERS
VARIATIONS FOR OTHER RESTRICTED TRANSFERS
Where applicable in accordance with Section 1.5 of Annex 2 (Restricted Transfer Annex), the SCCs also apply in the context of other Restricted Transfers with the following terms deemed to have the following substituted meanings:
- 1) “GDPR” means the applicable Data Protection Laws of the jurisdiction of the data exporter;
- 2) “European Union”, “Union” and “Member State(s)” each mean the jurisdiction of the data exporter; and
- 3) “supervisory authority” means the Supervisory Authority of the jurisdiction of the data exporter.
In relation to any other Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs, shall be read as a reference to those SCCs as varied in the manner set out in Section 1.1 of this Part 4.
Annex 3. US State Privacy Laws Annex
- For purposes of this Annex 3, the terms “business,” “commercial purpose,” “sell,” “share,” “targeted advertising” and “service provider” shall have the respective meanings given thereto in the US State Privacy Laws, and “personal information” shall mean Personal Data that constitutes personal information governed by the US State Privacy Laws.
- It is the parties’ intent that with respect to any personal information, Town is a service provider. Town (a) acknowledges that personal information is disclosed by Customer only for limited and specified purposes described in the Agreement; (b) shall comply with applicable obligations under the US State Privacy Laws and shall provide the same level of privacy protection to personal information as is required by the US State Privacy Laws; (c) agrees that Customer has the right to take reasonable and appropriate steps to help to ensure that Town’s use of personal information is consistent with Customer’s obligations under the US State Privacy Laws; (d) shall notify Customer in writing of any determination made by Town that it can no longer meet its obligations under the US State Privacy Laws; and (e) agrees that Customer has the right, upon notice, including pursuant to the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
- Town shall not (a) sell or share any personal information or use it for targeted advertising; (b) retain, use or disclose any personal information for any purpose other than for the specific purpose of providing the Services, including retaining, using, or disclosing the personal information for a commercial purpose other than the provision of the Services; (c) retain, use or disclose the personal information outside of the direct business relationship between Town and Customer; or (d) combine personal information received pursuant to the Agreement with personal information (i) received from or on behalf of another person, or (ii) or collected from Town’s own interaction with any Consumer to whom such personal information pertains, except in each case (a) through (d) as and to the extent necessary as a part of Town’s provision of the Services or as otherwise permitted by a service provider or processor under the US State Privacy Laws. Town hereby certifies that it understands its obligations under this Annex 3 and will comply with them.
- Giving Customer notice of Subprocessor engagements in accordance with Section 5 of the DPA shall satisfy Town’s obligation under the US State Privacy Laws to give notice of and an opportunity to object to such engagements.
- Town agrees that Customer may conduct audits, in accordance with Section 8 of the DPA, to help ensure that Town’s use of personal information is consistent with Town’s obligations under the US State Privacy Laws.
- The parties acknowledge that Town’s retention, use and disclosure of personal information authorized by Customer’s instructions documented in the DPA are integral to Town’s provision of the Services and the business relationship between the parties.



















