Announcement: We’re excited to share that we’ve raised our next investment round, led by People Ventures and EIFO. Read about it here.


KLAAY DATA PROCESSING ADDENDUM
This Data Processing Addendum, including its annexes and the Standard Contractual Clauses, (“DPA”) forms a part of the Terms of Service Agreement (the “Agreement”) or other superseding written agreement between the customer identified at the time of registration (“Customer”) and the Klaay Affiliate into which Customer has entered into an Agreement (collectively “Klaay”) that governs Customer’s use of the Klaay Subscription Services.
All capitalized terms not defined in this DPA shall have the meaning set forth in the Agreement.
1. DEFINITIONS
1.1 “Affiliate” means an entity that directly or indirectly Controls, is Controlled by or is under common Control with an entity. “Control” means an ownership, voting or similar interest representing fifty percent (50%) or more of the total interests (as measured on a fully-diluted basis) then outstanding of the entity in question. The term “Controlled” will be construed accordingly.
1.2 “Applicable Data Protection Laws” means data protection and privacy laws and regulations applicable to Klaay’s provision of the Subscription Services to its customers generally without regard to Customer’s particular use of the Subscription Services (except to the extent the obligation specified hereunder is Customer’s obligation, in which case such term shall include such laws specific to Customer’s particular uses); for the avoidance of doubt, Applicable Data Protection Laws includes, without limitation: (a) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (“EU GDPR”), (b) in respect of the UK, the EU GDPR as saved into United Kingdom law by virtue of section 3 of the United Kingdom's European Union (Withdrawal) Act 2018 (“UK GDPR”) and the Data Protection Act 2019 (together, “UK Data Protection Laws”), (c) the Swiss Federal Data Protection Act and its implementing regulations (“Swiss Data Protection Act”), and (d) the CCPA, in each case, as may be amended, superseded or replaced.
1.3 “Authorized Affiliate” means a Customer Affiliate who is authorized under the Agreement to use the Subscription Services.
1.4 “CCPA” means the California Consumer Privacy Act of 2018 or Cal. Civ. Code § 1798.100, et seq., as amended.
1.5 “Customer Content” means, if not defined within the Agreement, the data made available through the Subscription Services by Customer and its Authorized Users for processing within the Subscription Services.
1.6 “Customer Personal Data” means the personal data made available by Customer for processing by, or use within, the Subscription Services.
1.7 “Europe” means for the purposes of this DPA the European Economic Area (“EEA”), United Kingdom (“UK”) and Switzerland.
1.8 “GDPR” means, unless a specific version is indicated, all of the EU GDPR, the UK Data Protection Laws and the Swiss Data Protection Act.
1.9 "Personal Data” means personal data as defined in the GDPR that is subjected to the Subscription Services under the Agreement.
1.10 “Processing” means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
1.11 “Restricted Transfer” means: (i) where the EU GDPR applies, a transfer of personal data originating from the EEA to a country outside of the EEA which is not subject to an adequacy determination by the European Commission; (ii) where the UK GDPR applies, a transfer of personal data originating from the UK to any other country which is not based on adequacy regulations pursuant to Section 17A of the Data Protection Act 2018; and (iii) where the Swiss Data Protection Act applies, a transfer of personal data to a country outside of Switzerland which is not included on the list of adequate jurisdictions published by the Swiss Federal Data Protection and Information Commissioner.
1.12 “Security Annex” means the Security Annex (or such other location as Klaay may provide, and as may be updated from time to time in accordance with this DPA).
1.13 “Security Breach” means a breach of security leading to any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored or otherwise processed by Klaay. A Security Breach shall not include an unsuccessful Security Breach, which is one that results in no accidental or unlawful destruction loss, alteration, unauthorized disclosure of, or access to Customer Personal Data or to any Klaay equipment or facilities processing the Customer Personal Data.
1.14 “Sensitive Data” means any unencrypted (i) bank, credit card or other financial account numbers or login credentials; (ii) social security, tax, driver’s license or other government-issued identification numbers; (iii) health information identifiable to a particular individual; (iv) information that could reasonably be used to determine the GPS location of a particular individual; or (v) any “special” or “sensitive” or other similar categories of data as those terms are defined according to the GDPR or any other Applicable Data Protection Laws. For the purposes of the prior sentence, “unencrypted” means a failure to utilize industry standard encryption methods to prevent Klaay, the Subscription Services, and Klaay’s personnel, including any subcontractors, from accessing the relevant data in unencrypted form.
1.15 “Subscription Services” means the services directly provided by Klaay that require the processing by Klaay of Customer Personal Data on Customer’s behalf.
1.16 “Standard Contractual Clauses” or “SCCs” means: (i) where the EU GDPR applies, the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 (“EU SCCs”); (ii) where the UK GDPR applies, the applicable standard data protection clauses for processors adopted pursuant to Article 46(2)(c) or (d) of the UK GDPR (“UK SCCs”); and (iii) where the Swiss Data Protection Act applies, the applicable standard data protection clauses issued, approved or recognized by the Swiss Federal Data Protection and Information Commissioner.
1.17 “Subprocessor” means any third party engaged by Klaay (including any Klaay Affiliate but not including any Klaay employees, contractors or consultants) to process Customer Personal Data on behalf of Customer.
1.18 “System” means any application, computing or storage device, or network.
1.19 “Usage Data” means usage data and telemetry collected by Klaay relating to Customer's use of the Subscription Services. Usage Data may occasionally contain queries entered by an Authorized User but not the results of those queries.
1.20 The terms “controller,” “data subject,” “supervisory authority”, and “processor,” have the meanings given to them in Applicable Data Protection Laws. The term controller includes ‘businesses’ (as defined in the CCPA), the term data subject includes ‘consumers’ (as defined in the CCPA), the term processor includes ‘service providers’ (as defined in the CCPA), and the term personal data includes ‘personal information’ (as defined in the CCPA) to the extent the rights and obligations in this DPA apply under the CCPA.
2. DATA PROCESSING
2.1 Applicability. This DPA, except as set forth in Section 2.5, applies only to the extent that Klaay processes Customer Personal Data on behalf of Customer as a processor or sub-processor in the course of providing the Subscription Services (including as described in Annex A of this DPA).
2.2 Party Roles. As between the parties, Customer is either the controller or processor of Customer Personal Data and Klaay is the processor or sub-processor of Customer Personal Data.
2.3 Compliance with Laws. Each party will comply with all laws, rules and regulations applicable to it in the exercise of its rights or performance of its obligations under the Agreement or this DPA, including Applicable Data Protection Laws. If Applicable Data Protection Laws and corresponding obligations related to the processing of personal data change, the parties shall discuss in good faith any necessary amendments to this DPA. Klaay will not ‘sell’ (as such term is defined in the CCPA) Customer Personal Data.
2.4 Instruction to Process.
(1) Klaay shall process Customer Personal Data pursuant to Customer’s use of the Subscription Services in accordance with Customer’s documented lawful instructions as set forth in this DPA and the Agreement(s) and as otherwise necessary to provide the Subscription Services (together “Processing Instructions”). Additional instructions outside the scope of the Processing Instructions (if any) require prior written agreement between the parties. Customer shall ensure that its Processing Instructions comply with Applicable Data Protection Laws. Taking into account the nature of the processing, Customer agrees that it is unlikely Klaay can form an opinion on whether the Processing Instructions violate Applicable Data Protection Laws. If Klaay forms such an opinion, it shall, unless prohibited from doing so under applicable laws, inform Customer, in which case, Customer is entitled to withdraw or modify its Processing Instructions. Klaay may without penalty refuse further processing of personal data under this DPA that it believes to be in violation of any law or regulation, including any Applicable Data Protection Laws.
(2) Where Customer is itself a processor of the Customer Personal Data acting on behalf of another third party controller (or on behalf of other intermediaries of the ultimate controller): (i) Customer represents and warrants to Klaay that the Processing Instructions and its actions with respect to Customer Personal Data, including its appointment of Klaay as a processor or sub-processor pursuant to this DPA, reflect and do not conflict with the instructions of such third parties; (ii) Customer agrees at Klaay’s request to serve as the sole point of contact for Klaay with regard to such third parties; (iii) Klaay need not interact directly with (including seeking authorizations directly from) any such third party (other than through the regular provision of the Subscription Services to the extent required by the Agreement); and (iv) where Klaay would (including for the purposes of the SCCs) otherwise be required to provide information, assistance, co-operation or anything else to such third party controller, Klaay may provide it solely to Customer as the sole point of contact. Notwithstanding the foregoing, Klaay shall be entitled to follow the instructions of such third party with respect to Customer Personal Data for which they are controller instead of Customer's if Klaay reasonably believes this is legally required in the circumstances.
(3) Taking into account the nature of the processing, Customer agrees that it is unlikely that Klaay would become aware that Customer Personal Data transferred under the Standard Contractual Clauses is inaccurate or outdated. Nonetheless, if Klaay becomes aware that Customer Personal Data transferred under the Standard Contractual Clauses is inaccurate or outdated, it will inform Customer without undue delay. Klaay provides certain controls and functionality within the Subscription Services to enable the Customer to correct Customer Personal Data that is inaccurate or outdated. It is Customer’s responsibility to make any necessary corrections.
2.5 Usage Data. Klaay may collect Usage Data. Klaay shall process Usage Data in accordance with its obligations as a controller under Applicable Data Protection Laws and the Agreement. Notwithstanding the foregoing, Klaay will never share (other than with Subprocessors or third parties providing services to Klaay who agree to terms at least as restrictive regarding the processing of Usage Data as those set forth herein) or publicly make available any Usage Data that identifies Customer or its users, data subjects, or customers. Without limiting the foregoing, Klaay will not “sell” (as such term is defined in the CCPA) any Usage Data that contains personal data subject to the CCPA.
2.6 Authorized Affiliates. Klaay obligations set forth in this DPA shall also extend to Authorized Affiliates, subject to the following conditions:
(1) Customer must exclusively communicate any additional Processing Instructions requested pursuant to Section 2.4 directly to Klaay, including instructions from its Authorized Affiliates;
(2) Customer shall be responsible for Authorized Affiliates’ compliance with this DPA and all acts and/or omissions by an Authorized Affiliate with respect to Customer’s obligations in this DPA shall be considered the acts and/or omissions of Customer; and
(3) Authorized Affiliates shall not bring a claim directly against Klaay. If an Authorized Affiliate seeks to assert a legal demand, action, suit, claim, proceeding or otherwise against Klaay (“Authorized Affiliate Claim”): (i) Customer must bring such Authorized Affiliate Claim directly against Klaay on behalf of such Authorized Affiliate, unless Applicable Data Protection Laws require the Authorized Affiliate be a party to such claim; and (ii) all Authorized Affiliate Claims shall be considered claims made by Customer and shall be subject to any liability restrictions set forth in the Agreement, including any aggregate limitation of liability.
3. PLATFORM ARCHITECTURE
3.1 Shared Responsibility Deployment. Certain components of the Subscription Services are under Customer’s control as further described in the Agreement. Each party shall be responsible for implementing appropriate technical and organizational security measures in order to protect Customer Content under its control, which for Klaay shall be the implementation of the Security Measures set forth in Section 6.2. Without limiting the foregoing, Customer acknowledges and agrees that it is responsible for (i) protecting the security of credentials used to access the Subscription Services and (ii) any security or other issues resulting from any Customer Content, and Customer expressly assumes the risks associated with the foregoing responsibilities.
3.2 Data Agnostic. Customer solely chooses what Customer Content (including any Customer Personal Data) it processes in the Subscription Services. Customer acknowledges that Klaay will be generally unaware of the types of or details regarding the Customer Content processed within the Subscription Services.
3.3 Sensitive Data. Customer will not provide or process Sensitive Data in the Subscription Services without Klaay’s prior written approval (which approval may be set forth in an applicable Order Form).
3.4 No Data Backup. Klaay and the Klaay Subscription Services do not provide backup services or disaster recovery for Customer Content. Klaay does provide functionality within the Subscription Services that may permit Customer to backup certain Customer Content on its own. It is Customer’s obligation to backup any Customer Content if desired.
4. SUBPROCESSING
4.1 Authorization. Customer provides a general authorization for Klaay to appoint Subprocessors to process Customer Personal Data, including those Subprocessors listed at https://klaay.com/trust/subprocessors (“Subprocessor List”).
4.2 Klaay Subprocessor Obligations. Klaay (i) shall enter into a written agreement with its Subprocessors which includes data protection and security measures no less protective of Customer Personal Data than the Agreement and this DPA and (ii) remains fully liable for any breach of this DPA or the Agreement that is caused by an act, error or omission of such Subprocessor to the extent Klaay would have been liable for such act, error or omission had it been caused by Klaay.
4.3 Subprocessor Changes. Prior to the addition of any new Subprocessor, Klaay shall provide notice to Customer not less than 30 calendar days prior to the date on which the Subprocessor shall commence processing Customer Personal Data. Such notice will be sent to individuals who have signed up to receive updates to the Subprocessor List via the mechanism(s) indicated on the Subprocessor List (which mechanisms will include at a minimum email).
4.4 Subprocessor Objections. Customer may reasonably object on data protection grounds to Klaay’s use of a new Subprocessor by notifying Klaay in writing within 10 calendar days after notice has been provided by Klaay. In the event of Customer’s timely objection on such reasonable grounds relating to data protection, Klaay will either: (i) work with Customer to address Customer’s objections to its reasonable satisfaction; (ii) instruct the Subprocessor to not process Customer Content (including any Customer Personal Data); provided that Customer acknowledges this may result in new or improved Subscription Services features not being available to Customer; or (iii) notify Customer of its option to terminate this DPA and the Agreement. Customer shall have 14 calendar days in which to exercise its option to terminate this DPA and the Agreement after receiving notice of a right to terminate. If Customer timely exercises its right to terminate the Agreement, Klaay will provide Customer with a pro rata reimbursement of any prepaid, but unused, fees as of the date Customer notifies Klaay of its choice to exercise such right.
4.5 Non-Klaay Subscription Services. Customer acknowledges that any third party services (other than Subprocessors) that may be linked to or used within the Subscription Services and that Customer may choose to use at its option (“Non-Klaay Subscription Services”) are governed solely by the terms and conditions and privacy policies of such Non-Klaay Subscription Services. Klaay does not endorse, is not responsible or liable for, and makes no representations as to any aspect of such Non-Klaay Subscription Services, including, without limitation, their content or the manner in which they handle your Customer Content (including Customer Personal Data) or any interaction between Customer and the provider of such Non-Klaay Subscription Services. Klaay is not liable for any damage or loss caused or alleged to be caused by or in connection with Customer’s enablement, access or use of any such Non-Klaay Subscription Services, or Customer’s reliance on the privacy practices, data security processes or other policies of such Non-Klaay Subscription Services. The providers of Non-Klaay Subscription Services shall not be deemed Subprocessors for any purpose under this DPA.
5. COOPERATION
5.1 Data Subject Requests. If Klaay receives a request from a data subject seeking to exercise their rights under Applicable Data Protection Laws that identifies Customer and relates to Customer Personal Data (“DSR”), Klaay shall promptly pass on such communication to Customer. Customer is responsible for responding to and complying with any DSR. The Subscription Services include controls that Customer may use to assist it to respond to a DSR. If Customer is unable to access any relevant Customer Personal Data that is under Klaay’s control using such controls, Klaay shall, taking into account the nature of the processing, reasonably cooperate with Customer to enable Customer to respond to the DSR.
5.2 Government Inquiries. If Klaay receives a subpoena, court order, warrant or other legal demand from law enforcement or public or judicial authorities seeking the disclosure of Customer Content, Klaay shall, to the extent permitted by applicable laws, promptly notify Customer in writing of such request and reasonably cooperate with Customer to limit, challenge or protect against such disclosure.
5.3 Assistance. Klaay will (i) at Customer’s request and expense assist Customer to conduct a data protection impact assessment and, where legally required, consult with applicable data protection authorities; and (ii) respond to reasonable requests for additional information if necessary for Customer to demonstrate its compliance with Applicable Data Protection Laws.
6. DATA ACCESS
6.1 Confidentiality. Klaay shall ensure that any person it authorizes (including Klaay’s employees, contractors and Subprocessors) to process Customer Content is subject to a duty of confidentiality substantially as protective of Customer Content as this DPA and the Agreement.
6.2 Security Measures. Klaay will implement and maintain appropriate technical and organizational security measures designed to preserve the security and confidentiality of Customer Content in accordance with the Security Annex (“Security Measures”). Klaay may update the Security Annex and its Security Measures, provided that any updates shall not materially diminish the overall security of Customer Content or the Subscription Services. Customer must review the Security Measures prior to providing Klaay with access to Customer Content to determine that the Security Measures meet the Customer’s requirements and obligations under Applicable Data Protection Laws.
7. SECURITY BREACH
7.1 Breach Notifications. In the event of a Security Breach, Klaay shall provide written notice to Customer without undue delay and in no event later than seventy-two (72) hours after becoming aware of the Security Breach and will provide updates to Customer, including the type of data affected and the identity of affected person(s) as soon as such information becomes known to Klaay. Klaay will reasonably cooperate with Customer as required to fulfill Customer’s obligations under Applicable Data Protection Laws. Klaay shall take measures and actions appropriate and reasonable to remedy or mitigate the effects of the Security Breach.
7.2 Communications. The decision whether to provide notification, public/regulatory communication or a press release (each, a “Notification”) concerning the Security Breach shall be solely at Customer’s discretion, but the content of any Notification that names Klaay or from which Klaay’s identity could reasonably be determined shall be, except as otherwise required by applicable laws, subject to the prior approval of Klaay, which approval shall not be unreasonably withheld, conditioned or delayed, and provided that conditioning of the Notification on Klaay’s approval shall not prevent Customer from complying with Applicable Data Protection Laws.
8. AUDITS
8.1 Audits. Klaay may utilize an independent third-party security professional to audit its Security Measures. Such audit will be performed (i) at least annually; and (ii) according to SOC2 standards or such other alternative standards that are substantially equivalent to SOC2 (“ISMS Certification”).
8.2 Reports. At Customer’s written request no more than once per year, Klaay will provide Customer with (i) its most current ISMS Certification; and (ii) a report from the audit affirming that Klaay’s data security controls achieve industry standards under Service Organization Controls No. 2 (SOC2) or such other alternative standards that are substantially equivalent to SOC 2 (“Report”). The Report and any summaries thereof will constitute Klaay’s Confidential Information.
9. TRANSFER MECHANISM
9.1 Deployment Region. Customer’s Data will be hosted in accordance with the Security Annex, and Klaay will not move such hosting without the express permission of Customer.
9.2 Restricted Transfers. Subject to Section 9.3 below, where there is a Restricted Transfer of Customer Personal Data to Klaay, such Restricted Transfer shall be governed by the Standard Contractual Clauses, which shall be deemed incorporated into and form part of this DPA in accordance with Annex B of this DPA.
9.3 Alternative Transfer Mechanism. To the extent that Klaay adopts an alternative data export mechanism (including any new version of or successor to the Standard Contractual Clauses adopted pursuant to Applicable Data Protection Laws or the EU-US Data Privacy Framework (or similar) (“Alternative Transfer Mechanism”)), the Alternative Transfer Mechanism shall automatically apply instead of any applicable transfer mechanism described in this DPA (but only to the extent such Alternative Transfer Mechanism complies with and enables Customer to meet is obligations under the Applicable Data Protection Laws applicable to Europe and extends to territories to which Customer Personal Data is transferred).
10. DELETION & RETURN
The Subscription Services include controls that Customer may use at any time during the term of the Agreement to retrieve or delete Customer Content. Subject to the terms of the Agreement, Klaay will delete Customer Content from the Subscription Services when Customer uses such controls to send an instruction to delete. Additionally, upon Customer’s written request upon termination or expiration of the Agreement, Klaay will delete or assist Customer in deleting Customer Content contained therein within the time specified in the Agreement following the cancellation of such Agreement. In the event the Agreement is silent on data retention, Klaay may retain Customer Content where and to the extent permitted by applicable law. In such event, Klaay will (i) to the extent practical, isolate such data; and (ii) protect such data from any further processing, except to the extent permitted by applicable law.
11. GENERAL
11.1 The parties agree that this DPA shall replace any existing data processing addendum, attachment, exhibit or standard contractual clauses that the parties may have previously entered into in connection with the Subscription Services.
11.2 Notwithstanding Section 12.2 of the Framework Terms, this DPA may be modified by Klaay at any time by sending a notice to the email provided in the Agreement.
11.3 In no event shall this DPA benefit or create any right or cause of action on behalf of a third party (including a third party controller), but without prejudice to the rights or remedies available to data subjects under Applicable Data Protection Laws or this DPA (including the SCCs).
11.4 If any part of this DPA is held unenforceable, the validity of all remaining parts will not be affected.
11.5 In the event of any conflict between this DPA and any data privacy provisions set out in any agreements between the parties relating to the Subscription Services, the parties agree that the terms of this DPA shall prevail, provided that if and to the extent the Standard Contractual Clauses conflict with any provision of this DPA, the Standard Contractual Clauses control and take precedence.
11.6 Notwithstanding anything to the contrary in the Agreement or this DPA and to the maximum extent permitted by law, each party’s and all of its Affiliates’ liability, taken together in the aggregate, arising out of or related to this DPA (including all Annexes hereto), the SCCs or any data protection agreements in connection with the Agreement (if any), whether in contract, tort or under any other theory of liability, shall remain subject to the limitation of liability section of the Agreement and any reference in such section to the liability of a party means the aggregate liability of that party and all of its Affiliates under the Agreement and this DPA, including all Annexes hereto. Customer agrees that any regulatory penalties incurred by Klaay that arise as a result of Customer’s failure to comply with its obligations under this DPA or any laws or regulations including Applicable Data Protection Laws shall reduce Klaay’s liability under the Agreement as if such penalties were liabilities to Customer under the Agreement.
11.7 This DPA will be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, unless required otherwise by Applicable Data Protection Laws.
11.8 The obligations placed upon each party under this DPA and the Standard Contractual Clauses shall survive so long as Klaay processes Customer Personal Data on behalf of Customer.
ANNEX A
DESCRIPTION OF THE PROCESSING / TRANSFER
Annex 1(A): List of Parties
Data exporter. Name of the data exporter: the entity identified as the “Customer” in the Agreement and this DPA. Contact person’s name, position and contact details: the address and contact details associated with Customer's Klaay account, or as otherwise specified in the Agreement. Activities relevant to the data transferred: the activities specified in Annex 1(B) below. Signature and date: see front end of the DPA. Role (Controller/Processor): Controller (for Module 2) or Processor (for Module 3).
Data importer. Name of the data importer: Klaay ApS. Contact person’s name, position and contact details: Jacob Riff, DPO, privacy@klaay.com. Activities relevant to the data transferred: the activities specified in Annex 1(B) below. Signature and date: see front end of the DPA. Role (Controller/Processor): Processor.
Annex 1(B): Description of the Processing / Transfer
Categories of Data Subjects whose personal data is transferred: Data subjects include individuals about whom data is provided to Klaay via the Subscription Services (by or at the direction of Customer), which may include: (i) prospects, customers, business partners and vendors of Customer (who are natural persons); (ii) employees or contact persons of Customer’s prospects, customers, business partners and vendors; (iii) employees, agents, advisors, freelancers of Customer (who are natural persons); and/or (iv) Customer’s Authorized Users.
Categories of personal data transferred: The types of Customer Personal Data are determined and controlled by Customer in its sole discretion, and may include, but are not limited to the following types of personal data: (i) name, address, title, contact details; (ii) usage and log data; and/or (iii) IP addresses, usage data, cookies data, location data.
Sensitive Data transferred (if appropriate) and applied restrictions or safeguards: Subject to any applicable restrictions and/or conditions in the Agreement and this DPA, Customer should not use the Klaay Subscription Services to process any “special categories of personal data” or similarly sensitive personal data (as described or defined in Applicable Data Protection Laws).
Frequency of the Transfer (e.g. whether the data is transferred on a one-off or continuous basis): Continuous or one-off depending on the services being provided by Klaay.
Nature, subject matter and duration of the Processing: Nature: Klaay provides a cloud-based data compliance platform, as further described in the Agreement. Subject Matter: Customer Personal Data. Duration: The duration of the processing will be for the term of the Agreement and any period after the termination or expiry of the Agreement during which Klaay processes Customer Personal Data.
Purpose(s) of the data transfer and further processing: Klaay shall process Customer Personal Data for the following purposes: (i) as necessary for the performance of the Subscription Services and Klaay’s obligations under the Agreement (including the DPA), including processing initiated by Authorized Users in their use of the Subscription Services; and (ii) further documented, reasonable instructions from Customer agreed upon by the parties (the “Purposes”).
Period for which the personal data will be retained, or if that is not possible the criteria used to determinate that period, if applicable: Klaay will retain Customer Personal Data for the term of the Agreement and any period after the termination of expiry of the Agreement during which Klaay processes Customer Personal Data in accordance with the Agreement.
Annex 1(C): Competent Supervisory Authority
Competent supervisory authority: Danish Supervisory Authority.
ANNEX B
STANDARD CONTRACTUAL CLAUSES
1. Subject to Section 9.2 of the DPA, where the transfer of Customer Personal Data to Klaay is a Restricted Transfer and Applicable Data Protection Laws require that appropriate safeguards are put in place, such transfer shall be governed by the Standard Contractual Clauses, which shall be deemed incorporated into and form part of this DPA as follows:
1. Module Two terms apply (where Customer is the controller) and Module Three terms apply (where Customer is the processor of Customer Personal Data);
2. in Clause 7, the optional docking clause will apply and Authorized Affiliates may accede to this DPA and the SCCs under the same terms and conditions as Customer, subject to Section 2.6 (Authorized Affiliates) of this DPA via mutual agreement of the parties;
3. in Clause 9, Option 2 (“General Authorization”) is selected, and the process and time period for prior notice of Sub-processor changes shall be as set out in Section 4.3 of this DPA;
4. in Clause 11, the optional language will not apply;
5. in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Irish law;
6. in Clause 18(b), disputes shall be resolved before the courts of Ireland;
7. Annex I of the EU SCCs shall be deemed completed with the information set out in Annex A to this DPA;
8. Subject to Section 6.2 (Security Measures) of this DPA, Annex II of the EU SCCs shall be deemed completed with the information set out in the Security Annex.
2. In relation to transfers of Customer Personal Data protected by the Swiss Data Protection Act, the EU SCCs as implemented above will apply but with the following modifications:
1. references to “Regulation (EU) 2016/679” shall be interpreted as references to the Swiss Data Protection Act (as applicable);
2. references to specific Articles of “Regulation (EU) 2016/679” shall be replaced with the equivalent article or section of the Swiss Data Protection Act (as applicable);
3. references to “EU”, “Union”, “Member State” and “Member State law” shall be replaced with references to the “Switzerland” or “Swiss law” (as applicable);
4. the term “member state” shall not be interpreted in such a way as to exclude data subjects in the Switzerland from the possibility of suing for their rights in their place of habitual residence (i.e., Switzerland);
5. Clause 13(a) and Part C of Annex I are not used and the “competent supervisory authority” is the United Kingdom Information Commissioner or Swiss Federal Data Protection Information Commissioner (as applicable);
6. references to the “competent supervisory authority” and “competent courts” shall be replaced with references to the “Information Commissioner” and the “Swiss Federal Data Protection Information Commissioner” and “applicable courts of Switzerland” (as applicable);
7. in Clause 17, the Standard Contractual Clauses shall be governed by the laws of Switzerland;
8. with respect to transfers to which the Swiss Data Protection Act applies, Clause 18(b) shall state that disputes shall be resolved before the applicable courts of Switzerland.
3. In relation to transfers of Customer Personal Data protected by the UK GDPR, the UK SCCs shall be incorporated into and form an integral part of this DPA and shall apply to transfers governed by the UK GDPR. For the purposes of the UK SCCs, the relevant annexes, appendices or tables shall be deemed populated with the information set out in Annex A of this DPA and the Security Annex.