--------------------------------

CHEQ Data Processing Agreement

(Controller to Controller)

This Data Processing Addendum, including Schedule A and Annexes I-II (“DPA”), forms an integral part of the main agreement (“Agreement”) between CHEQ (2018) AI Technologies Ltd. and its Affiliates (“Company”) and between the customer whose details are set forth in Agreement (hereinafter “Customer”) and applies to the extent that the Parties processes Personal Data in the course of their performance of obligations under the Agreement. Hereinafter, each of Company and Customer shall be referred to as a “Party” and together as the “Parties”.

By accepting this DPA (personally or on behalf of Customer), you warrant that: (a) you have full legal authority to enter into this DPA; (b) you have read and understood this DPA and agree to its terms. If you do not have the legal authority to enter into this DPA on behalf of yourself or Customer, please do not accept this DPA.

  1. Introduction
    1. This DPA reflects the Parties’ agreement on the processing of Personal Data in connection with the Data Protection Laws.
    2. Any ambiguity in this DPA shall be resolved to permit the Parties to comply with all Data Protection Laws.
    3. In the event and to the extent that the Data Protection Laws impose stricter obligations on the parties than under this DPA, the Data Protection Laws shall prevail.
  2. Definitions and Interpretation
    1. In this DPA:
      1. Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with, a party.
      2. Approved Jurisdiction” means a jurisdiction approved as having adequate legal protections for data by the European Commission (or by the UK Information Commissioner’s Office, where applicable).
      3. Data Protection Laws” means, any and all applicable domestic and foreign laws, rules, directives and regulations, on any local, provincial, state, federal or national level, pertaining to data privacy, data security or the protection of Personal Data, including the Privacy and Electronic Communications Directive 2002/58/EC (and respective local implementing laws) concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications; “ePrivacy Directive”), Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”), Data Protection Act 2018 and the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”), US Data Protection Laws, and any amendments or replacements to the foregoing.
      4. Data Subject” means a natural person to whom Personal Data relates. Where applicable, the term Data Subject shall include “Consumer“, as this term is defined under US Data Protection Laws.
      5. Security Incident” shall mean any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access, to Personal Data. For the avoidance of doubt, any Personal Data Breach (as defined under the GDPR) will comprise a Security Incident.
      6. Special Categories of Data” means personal data as defined under Article 9 of the GDPR and where applicable, sensitive personal information, as defined under US Data Protection Laws.
      7. UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, which entered into force on 21 March, 2022.
      8. Standard Contractual Clauses” means the applicable module of the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council from June 4th 2021, as available here: eur-lex.europa.eu/eli/dec_impl/2021/914/oj?uri=CELEX:32021D0914&locale=en.
      9. US Data Protection Laws” means, any and all applicable laws, rules, acts, decrees, directives, regulations and binding regulatory guidance, on any state or federal level, pertaining to data privacy, data security and the protection of Personal Data, including, without limitation, in California, Colorado, Connecticut, Utah, Virginia, Texas, Oregon, Florida, Montana, Iowa, Delaware, New Jersey, New Hampshire, Nebraska, as well as any future laws, amendments, or regulations that may be enacted or promulgated governing data protection within the United States.
      10. The terms “controller”, “Personal Data” “process(ing)” and “processor” as used in this DPA have the meanings given to them in Data Protection Laws. Where applicable, controller shall be deemed “Business”, processor shall be deemed “Service Provider” or “Contractor”, and Personal Data shall be deemed “Personal Information” as these terms are defined under US Data Protection Laws.
      11. Any reference to a legal framework, statute or other legislative enactment is a reference to it as amended or re-enacted from time to time.
  3. Application of this DPA
    1. This DPA will only apply to the extent all of the following conditions are met:
      1. Company processes Personal Data that is made available by the Customer in connection with the Agreement;
      2. Any of the Data Protection Laws apply to the processing of Personal Data.
    2. This DPA will only apply to the services for which the Parties agreed to in the Agreement (“Services”), which incorporates the DPA by reference.
  4. Roles and Restrictions on Processing
    1. The duration, nature and purposes of the processing, as well as the types of Personal Data processed and categories of Data Subjects processed under this DPA are further specified in Annex I of this DPA.
    2. Independent Controllers. Each party:
      1. is an independent controller of Personal Data under the Data Protection Laws;
      2. will individually determine the purposes and means of its processing of Personal Data; and
      3. will comply with the obligations applicable to it under the Data Protection Laws with respect to the processing of Personal Data.
    3. Disclosing Personal Data. In performing its obligations under the Agreement, a party may disclose Personal Data to the other party. Each party shall process Personal Data only for the purposes set forth in the Agreement or as otherwise agreed to in writing by the parties, provided such processing strictly complies with (a) Data Protection Laws and (b) its obligations under this DPA. Neither Party shall knowingly share with the other party any Personal Data (i) that allows Data Subjects to be directly identified (for example by reference to their name and e-mail address); (ii) that contains Personal Data relating to children under 16 years.
    4. Lawful grounds and transparency. Each party shall maintain a publicly-accessible privacy policy on its mobile apps and websites that is available via a prominent link that satisfies transparency disclosure requirements of Data Protection Laws. Each party warrants and represents that it has provided Data Subjects with appropriate transparency regarding data collection and use and all required notices and obtained any and all consents or permissions necessary under Data Protection Laws. It is hereby clarified that Customer is the initial Controller of Personal Data. Where Customer relies on consent as its legal basis to Process Personal Data, it shall ensure that it obtains a proper affirmative act of consent from Data Subjects in accordance with Data Protection Law in order for itself and the other party to Process such Personal Data as set out herein. Customer shall : (a) ensure that appropriate notice and consent mechanisms are displayed and implemented on all applicable Customer properties; and (b) ensure that any opt-out signals or preferences communicated by Data Subjects are promptly transmitted to the Company. Both parties will cooperate in good faith in order to identify the information disclosure requirements and each party hereby permits the other party to identify it in the other party’s privacy policy, and to provide a link to the other party’s privacy policy in its privacy policy.
    5. Data Subject Rights. It is agreed that where either party receives a request from a Data Subject in respect of Personal Data controlled by such party, then such party shall be responsible to exercise the request, in accordance with Data Protection Laws.
    6. Mutual Assistance. Each Party shall:
      1. provide the other Party with such assistance as the other Party may reasonably request from time to time to enable it to comply with its obligations under the Data Protection Laws including (without limitation) with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or other regulators;
      2. provide the other Party with such information as it may reasonably request in order to: (a) monitor the technical and organizational measures being taken to ensure compliance with the Data Protection Laws, or (b) satisfy any legal or regulatory requirements, including information reporting, disclosure and other related obligations to any regulatory authority from time to time;
    7. Resolution of Disputes with Data Subjects or Supervisory Authorities.
      1. If either Party is the subject of a claim by a Data Subject or a supervisory authority or receives a notice or complaint from a supervisory authority relating to its respective processing activities (a “Data Protection Claim“), it shall promptly inform the other party of the Data Protection Claim and provide the other party with such information as it may reasonably request regarding the Data Protection Claim.
      2. Where the Data Protection Claim concerns the respective processing activities of one Party only, then that Party shall assume sole responsibility for disputing or settling the Data Protection Claim.
      3. Where the Data Protection Claim concerns the respective processing activities of both Parties, then the Parties shall use all reasonable endeavors to cooperate with a view to disputing or settling the Claim in a timely manner; provided always that neither Party shall make any admission or offer of settlement or compromise without using all reasonable endeavors to consult with the other Party in advance.
  5. Personal Data Transfers
    1. Transfers of Personal Data Out of the European Economic Area. Either Party may transfer Personal Data outside the European Economic Area, or the UK, as applicable if it complies with the provisions on the transfer of personal data to third countries in the applicable Data Protection Laws (such as where the transfer of Personal Data is to an Approved Jurisdictions or through the use of Standard Contractual Clauses, or other applicable frameworks).
    2. To the extent that Company processes Personal Data outside the EEA, UK, or an Approved Jurisdiction, then the Parties shall be deemed to enter into the Standard Contractual Clauses, and the UK Addendum (as applicable), subject to any amendments contained in Schedule A, in which event: (i) the Standard Contractual Clauses are incorporated herein by reference; and (ii) the Customer shall be deemed the data exporter and the Company shall be deemed the data importer (as these terms are defined therein).
  6. Protection of Personal Data.
    1. The Parties will provide a level of protection for Personal Data that is at least equivalent to that required under Data Protection Laws. Both Parties shall implement appropriate technical and organizational measures to protect the Personal Data.
    2. In the event that a Party suffers a confirmed Security Incident, each Party shall notify the other Party without undue delay and the Parties shall cooperate in good faith to agree on such measures as may be necessary to mitigate or remedy the effects of the Security Incident. In the event that a Party suffers a confirmed Security Incident, then such Party shall be responsible to notify the supervisory authority or the Data Subjects with respect to such Security Incident, as required under Data Protection Laws.
  7. Priority
    1. If there is any conflict or inconsistency between the terms of this DPA and the remainder of the Agreement then, the terms of this DPA will govern. Subject to the amendments in this DPA, the Agreement remains in full force and effect.
    2. Unless stated otherwise in the DPA, Standard Contractual Clauses or the UK Addendum, in case of a conflict between the provisions of the DPA and the provisions of the Standard Contractual Clauses and the UK Addendum, the provisions providing the more stringent protection to Personal Data and the rights of individuals shall govern.
  8. Changes to this DPA.
    1. Company may change this DPA if the change is required to comply with Data Protection Laws, a court order or guidance issued by a governmental regulator or agency, provided that such change does not: (i) seek to alter the categorization of the parties as independent controllers of Personal Data under the Data Protection Laws; (ii) expand the scope of, or remove any restrictions on, either Party’s rights to use or otherwise process Personal Data; or (iii) have a material adverse impact on Customer, as reasonably determined by Company.
    2. Notification of Changes. If Company intends to change this DPA under this Section, and such change will have a material adverse impact on Customer, as reasonably determined by Company, then Company will use commercially reasonable efforts to inform Customer at least 30 days (or such shorter period as may be required to comply with applicable law, applicable regulation, a court order or guidance issued by a governmental regulator or agency) before the change will take effect.

 

Schedule A – SCC

  1. If Customer is a controller – the Parties shall be deemed to enter into the Controller to Controller Standard Contractual Clauses (Module One); if Customer is a processor – the Parties shall be deemed to enter into the Processor to Controller Standard Contractual Clauses (Module Four).
  2. This Schedule A sets out the Parties’ agreed interpretation of their respective obligations under the Standard Contractual Clauses.
  3. The Parties shall complete Annexes I–II below, which are incorporated in the Standard Contractual Clauses by reference.
  4. The Parties agree that for the purpose of transfer of Personal Data between the Company and the Recipient, the following shall apply:
    1. Clause 7 of the Standard Contractual Clauses shall not be applicable.
    2. In Clause 11, data subjects shall not be able to lodge a complaint with an independent dispute resolution body.
    3. In Clause 17, option 1 shall apply. The Parties agree that the clauses shall be governed by the law of the state of Ireland.
    4. In Clause 18(b) the Parties choose the courts of Dublin, Ireland as their choice of forum and jurisdiction.
  5. To the extent the UK Addendum applies, the following shall apply:
    1. All the information provided under the Standard Contractual Clauses shall apply to the UK Addendum with the necessary changes per the requirement of the UK Addendum. Annex I below shall replace Annexes 1A and 1B of the UK Addendum, Annexes 2-3 shall be replaced with Annex II below.
    2. In Table 4 of the UK Addendum, either party may terminate the agreement in accordance with section 19 of the UK Addendum.
    3. By entering into this DPA, the Parties hereby agree to the format changes made to the UK Addendum.
  6. To the extent the FADP applies, the following shall apply:
    1. references to the GDPR are to be understood as references to the FADP;
    2. the competent supervisory authority shall be the FDPIC;
    3. references to ‘EU’, ‘Union’ and ‘Member State’ are replaced with ‘Switzerland’;
    4. In Clause 17, Option 1 shall apply. The Parties agree that the clauses shall be governed by the law of Switzerland;
    5. In Clause 18(b) the Parties choose the courts of Zurich, Switzerland as their choice of forum and jurisdiction.

 

Annex I – Description of processing activities

The “Data exporter”: Customer

The “Data importer”: Company

Duration of the data processing

The duration of the data processing shall be the duration of the Agreement or as otherwise subject to each Party’s retention policies.

Data subjects

The personal data transferred may concern the following categories of data subjects:

Customer’s properties’ end users (site visitors)

Categories of data

The personal data transferred may concern the following categories of data:

☒ Contact data (name, address, telephone number, email address)

☒ Pseudonymous data such as device identifiers and internet or electronic network activity (IP addresses, GAID/IDFA, browsing history, timestamps)

☐ Other: ___________

Purpose of processing operations

The transfer of personal data is made for the following purposes and subject to the below processing activities, as may be further set forth in contractual agreements entered into from time to time between the Company and Partner:

Provision of the Services per the Parties’ Agreement

Special Categories of Data (if appropriate)

The Personal Data transferred concern the following special categories of data (please specify):

None

The frequency of the transfer

The frequency of the transfer:

Continuous

Nature of the processing

☒ Collection

Recording

Organization or structuring

☒ Storage

Adaptation or alteration

Retrieval

Consultation

Disclosure, dissemination or otherwise making available

☒ Analysis

Erasure or destruction

Other: ________

Retention period

Personal Data will be retained for the term of the Agreement or otherwise subject to each Party’s retention policies.

 

Annex II – Technical and Organizational Measures to Ensure the Security of the Data

Located at: https://cheq.ai/appendix-a-cheq-security-requirements/