Data Processing Addendum
This Data Processing Addendum sets out how Mtrix handles personal data on your behalf when you use the platform. It is part of your agreement with us, applies automatically to every plan, and prevails over the Terms whenever the two conflict on a question of personal-data processing.
1. Introduction, scope & order of precedence
This DPA governs how Mtrix processes personal data on your behalf. It is built into your agreement, applies to every plan without a separate signature, and wins over the Terms on any conflict about data protection.
This Data Processing Addendum (the “DPA”) forms part of and is incorporated into the agreement between Mtrix Inc. (“Mtrix”, “we”, “us”) and the customer that uses the Services (“Customer”, “you”), comprising our Terms of Service, any applicable Order Form and Product-Specific Terms, and this DPA (together, the “Agreement”). It reflects the parties’ commitments regarding the processing of personal data in connection with the Services.
This DPA takes effect on the effective date of the Agreement and continues for as long as Mtrix processes personal data on your behalf. It is self-executing and applies to all plans by default, so no separate signature is required for it to be binding. If your procurement process needs a countersigned copy, write to privacy@mtrix.io and we will arrange execution.
This DPA covers all of the Services and every module you use, including product analytics and event tracking, A/B testing and experimentation, session recording and replay, heatmaps, performance monitoring, error tracking, the visual website and CMS builder, and user management.
This DPA applies to the Customer that enters into the Agreement and to its Affiliates that use the Services under that Agreement. The contracting Customer represents that it is authorised to enter into this DPA on behalf of those Affiliates and remains responsible for their acts and omissions in relation to the Services.
Order of precedence. Where documents conflict, the following order applies, from highest to lowest: (1) the applicable Order Form; (2) any Product-Specific Terms; (3) this DPA, for conflicts concerning the processing of personal data; (4) the Terms of Service; and (5) the Acceptable Use Policy. On any conflict about how personal data is processed, this DPA prevails over the Terms. The Terms set out the full order of precedence and the rest of the commercial relationship.
Capitalized terms not defined in this DPA have the meaning given to them in our Terms of Service.
2. Definitions
The following definitions apply throughout this DPA. Terms such as Controller, Processor, Sub-processor, Data Subject, Personal Data and Personal Data Breach carry the meaning given to them in the applicable Data Protection Laws.
- Data Protection Laws
- All laws and regulations applicable to the processing of personal data under the Agreement, including the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “EU GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), and applicable US state privacy laws such as the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”).
- Customer End-User Data
- Personal data about your end users and website visitors that Mtrix processes on your behalf as a processor: analytics and clickstream events, session recordings (masked DOM interactions), A/B experiment-exposure metadata, performance and error or stack-trace telemetry, device, browser and operating-system signals, IP address and derived city, region and country, timestamps and URLs.
- Customer Account Data
- Personal data about you and your team that Mtrix processes as an independent controller: admin names, email addresses, login credentials and billing details.
- Service Operations Data
- The narrow telemetry Mtrix uses, as an independent controller, to secure, operate, debug, bill for and improve the Services, such as security and fraud signals and product-usage logs.
- Special-Category / Sensitive Data
- Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data processed to uniquely identify a person, data concerning health, sex life or sexual orientation, and any equivalent categories treated as sensitive under applicable law.
- Prohibited Data
- Data you are not permitted to submit to the Services without a separate written agreement, including payment-card data subject to PCI DSS, protected health information under HIPAA absent a Business Associate Agreement, government-classified data, and the categories listed in our Acceptable Use Policy.
- Data Subject Request
- A request from or on behalf of a data subject to exercise a right under Data Protection Laws, such as access, rectification, erasure, restriction, portability or objection.
- SCCs
- The Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, including Module Two (controller to processor) and Module Three (processor to processor).
- UK Addendum / IDTA
- The UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
- TOMs
- The technical and organisational security measures Mtrix maintains under Article 32 of the GDPR, summarised in Annex II and described in full on our Security page.
- Masking
- The default suppression and redaction of sensitive inputs in session recordings and of personal data in error and performance payloads, as described in section 6.
The three buckets above — Customer End-User Data, Customer Account Data and Service Operations Data — are the shared vocabulary used across this DPA, the Terms and our Privacy Policy.
3. Roles of the parties
For the visitor data you capture through Mtrix, you are the controller and we are your processor — we only act on your instructions. For our own account and operational data, we are an independent controller.
Customer End-User Data. You act as the Controller of this data (or, where you process it on behalf of your own clients, as a processor). Mtrix acts as your Processor (or, in that processor-to-processor scenario, as a Sub-processor). To cover both situations, the international-transfer mechanism in section 13 wires in both Module Two and Module Three of the SCCs.
Customer Account Data and Service Operations Data. Mtrix processes this data as an independent Controller for the purposes described in section 16 and in our Privacy Policy. The parties are independent controllers for this data and are not joint controllers.
Processing only on documented instructions. Mtrix processes Customer End-User Data only on your documented instructions, which comprise the Agreement, this DPA, the product Documentation, your in-product configuration (including your masking and retention settings), and any further written instructions you give that the parties agree to. Mtrix will process this data to provide and support the Services, as instructed, and as required by laws to which Mtrix is subject (in which case Mtrix will inform you of that legal requirement before processing, unless the law prohibits it). If Mtrix considers that an instruction infringes Data Protection Laws, it will inform you without undue delay; Mtrix is not obliged to give legal advice or to monitor the lawfulness of your processing.
4. Description of processing
The subject matter, duration, nature and purpose of the processing, the categories of data subjects and the categories of personal data are summarised here and set out in full in Annex I.
- Subject matter and duration. Processing of Customer End-User Data to provide the Services, for the duration of the Subscription Term and the post-termination wind-down described in section 15.
- Nature and purpose. Collecting, structuring, storing, analysing and displaying behavioural data so you can measure, test and improve your store: analytics and event tracking, experimentation, session replay, heatmaps, performance monitoring, error tracking and CMS/builder content delivery.
- Categories of data subjects. Your end users and website visitors, and the Authorized Users on your team.
- Categories of personal data. The categories making up Customer End-User Data, as defined in section 2. Mtrix does not require, and you should not submit, special-category or Prohibited Data except as expressly agreed in writing.
5. Our obligations as processor
When acting as your processor, Mtrix will:
- process Customer End-User Data only on your documented instructions, as described in section 3;
- ensure that the personnel authorised to process the data are bound by appropriate obligations of confidentiality and process the data only on a need-to-know basis;
- implement and maintain the technical and organisational measures required by Article 32 of the GDPR, as described in section 9 and Annex II;
- tell you without undue delay if, in our reasonable opinion, an instruction infringes Data Protection Laws;
- taking into account the nature of the processing and the information available to us, provide reasonable assistance with your obligations under Articles 32 to 36 of the GDPR — security of processing, personal-data-breach notification, data-protection impact assessments and prior consultation with a supervisory authority;
- assist you, by appropriate technical and organisational measures and insofar as possible, to respond to Data Subject Requests, as described in section 8;
- make available to you the information reasonably necessary to demonstrate compliance with this DPA and allow for audits as described in section 14; and
- respect the sub-processor, transfer, breach-notification and deletion commitments set out in this DPA.
6. Session replay, sensitive inputs & data minimisation
Mtrix is built to capture as little sensitive data as possible. By default we mask form inputs, never capture passwords or payment fields, suppress those values on the visitor’s own device before anything is sent, and scrub error and performance payloads for personal data.
Session replay and error tooling are designed to minimise the personal data they handle. The following protections apply by default:
-
Inputs are masked by default. Mtrix masks the contents of text inputs, form
fields and payment fields. Passwords and fields carrying standard sensitive attributes —
for example
type=passwordandautocomplete=cc-*— are never captured at all. - Suppression happens on the device. Sensitive inputs are suppressed on the end user’s device, in the browser, before any data leaves it, so the raw values never reach Mtrix.
-
You control capture. You can tighten or loosen capture using CSS-selector
blocklists and allowlists and the
data-mtrix-maskanddata-mtrix-unmaskattributes. You are responsible for configuring masking appropriately and for obtaining any consent your use requires. - Error and performance payloads are scrubbed. Stack traces, request and response bodies and URLs in error and performance telemetry are scrubbed for personal data by default.
- No sale, no ad-sharing. Mtrix never sells personal data and never shares it for cross-context behavioural advertising.
- Isolated storage. Any inputs or recordings you choose to capture as sensitive are held in isolated, access-restricted storage.
- Signals honoured. Where we receive a Global Privacy Control signal we honour it as described in our Privacy Policy.
Because masking is configurable, the responsibility for choosing what is recorded, and for the lawfulness of that choice, sits with you. Do not disable default masking in order to capture Prohibited Data.
7. Your obligations as controller
As the controller of Customer End-User Data, you agree that:
- you have, and will maintain, a valid lawful basis for the processing, and you have provided all notices and obtained all consents required under Data Protection Laws (including ePrivacy and cookie consent where applicable);
- your instructions to Mtrix, and your configuration of the Services (including masking, retention and capture settings), comply with Data Protection Laws and do not cause Mtrix to breach them;
- you will not submit special-category or sensitive data, or Prohibited Data, to the Services unless expressly agreed in writing in advance and supported by an appropriate lawful basis and safeguards;
- you are responsible for the accuracy, quality and legality of the data and for the means by which you acquired it; and
- you lead responses to Data Subject Requests relating to Customer End-User Data, with Mtrix providing the assistance and tooling described in section 8.
8. Data-subject rights
You handle your visitors’ data-subject requests. We give you the tooling to find, export and delete one end user across every module, and we forward any request a visitor sends us directly to you.
Mtrix provides tooling in the Services that lets you locate, export and delete the data of a single end user across all modules — analytics, session recordings, experiment exposures, heatmaps, and performance and error telemetry — so you can fulfil access, portability and erasure requests. Heatmaps are derived from event data and are addressed by acting on the underlying events.
If Mtrix receives a Data Subject Request relating to Customer End-User Data directly from a data subject, it will not respond to that request itself (except to acknowledge it where required) and will, without undue delay, forward the request to you or direct the data subject to you, so that you can respond as the controller. Mtrix’s assistance is limited to the data that is available within the Services.
9. Security & technical measures
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects, Mtrix implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to that risk, in line with Article 32 of the GDPR.
These measures include encryption of data in transit and at rest, least-privilege access control with role-based permissions, multi-factor authentication for staff and single sign-on for customers, multi-tenant logical isolation, isolated and access-restricted storage for sensitive and session-replay data, secure software-development practices with code review and vulnerability scanning, logging and monitoring, and backup and disaster-recovery processes. The measures are summarised in Annex II and described and kept current on our Security page, which forms the authoritative statement of our TOMs.
Mtrix operates a security programme aligned with recognised industry frameworks and holds SOC 2 Type II and ISO/IEC 27001 certification; current reports and certificates are available to Customers under NDA on request, as described in section 14 (Audits). Mtrix is also HIPAA-compliant and will act as a Business Associate under a signed BAA (see section 18).
10. Personal-data-breach notification
If we confirm a personal-data breach affecting your data, we will tell you without undue delay and within 72 hours, with the detail you need to meet your own reporting duties.
Mtrix will notify you without undue delay and within 72 hours of confirming a Personal Data Breach affecting Customer End-User Data. The notification will, to the extent known and as it becomes available, describe the nature of the breach (including, where possible, the categories and approximate number of data subjects and records concerned), the likely consequences, and the measures taken or proposed to address it and mitigate its effects, consistent with Article 33(3) of the GDPR. Mtrix will provide reasonable assistance to help you meet your own breach-notification obligations to supervisory authorities and data subjects.
A notification under this section is not, and may not be construed as, an acknowledgement or admission by Mtrix of any fault or liability in respect of the incident.
11. Sub-processors
You give us general permission to use vetted sub-processors, listed in Annex III. We give you at least 30 days’ notice before adding one, you have 30 days to object on reasonable grounds, and we stay responsible for what our sub-processors do.
You provide a general authorisation for Mtrix to engage Sub-processors to process Customer End-User Data in connection with the Services. The Sub-processors engaged at the date of this DPA are listed in Annex III.
Mtrix will give you at least 30 days’ advance notice of any intended addition or replacement of a Sub-processor, giving you the opportunity to object. You may object on reasonable grounds relating to data protection by notifying us within 30 days of that notice; if you do not object within that window, the change is deemed accepted. If you object on reasonable grounds, the parties will work together in good faith to find a workable solution; if no solution is reached within a reasonable time, you may terminate the affected part of the Services and receive a pro-rata refund of prepaid fees for the terminated, unused portion of the Subscription Term.
Mtrix imposes on each Sub-processor, by written contract, data-protection obligations that are materially equivalent to those in this DPA, including the relevant SCC obligations where the Sub-processor is located outside the EEA. Mtrix remains responsible to you for the acts and omissions of its Sub-processors to the same extent as for its own.
12. AI, machine learning & no-training
We do not use your visitors’ data to train foundation models. In-product machine learning runs on your data, for you, inside your instance — and any AI sub-processors are contractually barred from training on or retaining your data.
Mtrix does not use Customer End-User Data to train, fine-tune or improve any foundation model or general-purpose AI model, whether its own or any third party’s. Machine-learning features inside the product — such as multi-armed-bandit optimisation, anomaly detection and similar in-product analytics — operate on your data, within your instance, to deliver results back to you, and are not used to build cross-customer models. Where Mtrix uses an AI Sub-processor to deliver a feature, that Sub-processor is contractually bound not to train on or retain Customer End-User Data beyond what is strictly necessary to return the requested output.
13. International data transfers
Your data is hosted in the EU/EEA by default. When a sub-processor sits outside the EEA, we use an EU adequacy decision where one exists, otherwise the EU Standard Contractual Clauses, plus the UK and Swiss equivalents — all governed by Estonian law.
Mtrix is established in Estonia and hosts and primarily processes Customer End-User Data and Customer Account Data in the European Union and EEA. EU data residency is offered as the default.
Where a Sub-processor is located outside the EEA, Mtrix, as data exporter, relies on the following transfer mechanisms, in order of precedence:
- an EU adequacy decision, where one exists for the destination country; otherwise
- the EU Standard Contractual Clauses (Commission Decision 2021/914), incorporating Module Two where you act as controller and Module Three where you act as processor; and, where the importer is a US entity certified under the EU-US Data Privacy Framework, Mtrix may also rely on that certification.
For UK end-user data leaving the United Kingdom, Mtrix relies on the UK International Data Transfer Addendum to the EU SCCs. For Swiss data, Mtrix relies on the Swiss adaptation of the SCCs recognised by the Federal Data Protection and Information Commissioner. The governing law and forum for the SCCs are those of Estonia, aligning with the governing law of the Terms. The specific module and clause elections are set out in Annex IV.
Government and law-enforcement requests. If Mtrix receives a legally binding request from a public authority for Customer End-User Data, it will, unless legally prohibited, notify you, will challenge requests that are unlawful or overbroad, and will disclose only the minimum data legally required.
14. Audits & compliance documentation
We satisfy audit rights with documentation first — our reports and this DPA under NDA. An on-site audit is available at most once a year, on 30 days’ notice, by an independent non-competitor auditor, at your cost.
Mtrix makes available the information reasonably necessary to demonstrate compliance with this DPA. In the ordinary course, audit and inspection rights are satisfied by Mtrix providing its security and compliance documentation — including audit reports such as SOC 2 or ISO certifications as they become available, and the information in this DPA — under an obligation of confidentiality.
Where documentation is not sufficient to address a specific, reasonable concern, you (or an independent third-party auditor on your behalf) may conduct an on-site audit subject to the following: at most once per 12 months; at least 30 days’ prior written notice; during normal business hours; under a non-disclosure agreement; conducted by an independent auditor who is not a competitor of Mtrix; with you bearing your own and the on-site costs. An audit may not access other customers’ data, Mtrix confidential information unrelated to your processing, or anything that would compromise the security of the Services. More frequent audits are available only where required by a supervisory authority or following a confirmed Personal Data Breach affecting your data.
15. Retention, return & deletion
You set the retention windows in-product. When the contract ends, you have 30 days to export, then we delete or return your data within 90 days, with backups ageing out within a further 90 days.
During the term. Retention is configurable in-product. The defaults below apply unless you change them:
- Session recordings: 30 days by default (customer-configurable, 7 to 180 days).
- Raw analytics and event data: 24 months by default.
- Heatmap data: derived from events, retained for the same window as events.
- Performance and error telemetry, including stack traces: 12 months by default.
- A/B experiment-assignment data: the duration of the experiment plus 12 months.
These are defaults you can change in your settings, not fixed limits.
On termination. After the Agreement ends, Mtrix makes Customer End-User Data available for export for 30 days. After that export window, Mtrix deletes or returns the Customer End-User Data within 90 days. Data in routine backups is purged on the standard backup cycle, within a further 90 days. Mtrix may retain data where required by law or under a legal hold, in which case it remains subject to this DPA’s confidentiality and security obligations for as long as it is retained.
16. Mtrix as an independent controller
Mtrix acts as an independent controller for a narrow set of data: Customer Account Data and Service Operations Data, as defined in section 2. It processes this data to provide, secure, operate, debug, bill for and improve the Services, as described in our Privacy Policy.
Any use of data across tenants for benchmarking or comparative insights would be carried out only on aggregated and de-identified data, would not re-identify any individual, and would be subject to a separate opt-out addendum agreed with you. The parties are independent controllers for this data and are not joint controllers.
17. Limitation of liability
This DPA does not contain a separate or additional limitation of liability. Each party’s liability arising out of or related to this DPA, whether in contract, tort or any other theory, is subject to, and counts toward, the aggregate limitations of liability set out in the Terms — including the general cap and the higher super-cap that applies to security and data-protection breaches. Nothing in this DPA limits any liability that cannot be limited under applicable law, or affects the rights of data subjects under the SCCs or Data Protection Laws.
18. Jurisdiction-specific terms
The following overlays apply in addition to the rest of this DPA, to the extent the relevant law governs the processing.
EU GDPR, UK GDPR and Swiss FADP
Where the EU GDPR, UK GDPR or Swiss FADP applies, the corresponding regime governs, with the SCCs, UK IDTA and Swiss adaptation applied as described in section 13 and Annex IV. References to supervisory authorities include the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) as Mtrix’s lead authority, the UK Information Commissioner, and the Swiss Federal Data Protection and Information Commissioner, as applicable.
CCPA / CPRA and other US state laws
Where the CCPA/CPRA applies, Mtrix acts as a Service Provider with respect to Customer End-User Data. Mtrix will not sell or share that data, will not retain, use or disclose it for any purpose other than providing the Services or as otherwise permitted by the CCPA/CPRA, will not combine it with other personal information except as permitted by the CCPA/CPRA, and will not use it to train general-purpose AI models. Mtrix certifies that it understands and will comply with these restrictions. Equivalent service-provider or processor commitments apply under other US state privacy laws.
HIPAA
Mtrix can act as a Business Associate under the U.S. Health Insurance Portability and Accountability Act (HIPAA). You must not submit protected health information (PHI) to the Services unless a separate Business Associate Agreement (BAA) has been executed with Mtrix; a BAA is available to eligible customers on request. Where a BAA is in place, it governs PHI and controls over this DPA to the extent of any conflict. Without a signed BAA, you must not use the Services to collect, capture, or store PHI, and you remain responsible for configuring masking and exclusions so that PHI is not captured by analytics, session recording, or error and performance telemetry.
19. General
Updates. Mtrix may update this DPA from time to time. For changes that materially affect the legal protections of this DPA, Mtrix will give at least 30 days’ notice before they take effect. Routine operational changes — such as adding or replacing a Sub-processor or updating a transfer mechanism — take effect through the notice and posting process in section 11 and Annex III and your continued use of the Services, and will never diminish the protections in this DPA.
Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force, and the invalid provision is replaced by a valid one that most closely reflects its intent.
Notices. Notices and requests under this DPA, including audit and data-protection matters, should be sent to privacy@mtrix.io or to Mtrix Inc., Tornimäe tn 5, Kesklinna linnaosa, Tallinn, Harju maakond, 10145, Estonia.
Execution. This DPA is binding on acceptance of the Agreement (including by click-acceptance). A countersigned copy is available on request from privacy@mtrix.io. Except where the SCCs specify a different governing law or forum, this DPA is governed by the laws of Estonia and the courts of Harju County, Tallinn, Estonia, consistent with the Terms.
Annex I — Description of processing
This Annex I sets out the details of processing required by Article 28(3) of the GDPR and populates Annex I of the SCCs where they apply.
- Data exporter
- The Customer, acting as controller (or as processor for its own clients) of Customer End-User Data.
- Data importer
- Mtrix Inc., acting as processor (or sub-processor) of Customer End-User Data.
- Subject matter
- Provision of the Mtrix analytics and experimentation Services, processing Customer End-User Data on the Customer’s behalf.
- Duration
- The Subscription Term, plus the post-termination export and deletion period described in section 15, and any period required by law or legal hold.
- Nature and purpose
- Collecting, structuring, storing, analysing, displaying and deleting behavioural data to provide product analytics and event tracking, A/B testing and experimentation, session recording and replay, heatmaps, performance monitoring, error tracking, the CMS and builder, and user management.
- Categories of data subjects
- The Customer’s end users and website visitors, and the Customer’s Authorized Users.
- Categories of personal data
- Analytics and clickstream events; session recordings (masked DOM interactions); A/B experiment-exposure metadata; performance and error or stack-trace telemetry; device, browser and operating-system signals; IP address and derived city, region and country; timestamps and URLs.
- Special-category data
- None is required or expected. The Customer must not submit special-category or sensitive data except as expressly agreed in writing, with appropriate safeguards.
- Frequency
- Continuous, for the duration of the Subscription Term.
Annex II — Technical & organisational measures
This Annex II summarises the technical and organisational security measures Mtrix maintains under Article 32 of the GDPR and populates Annex II of the SCCs where they apply. The authoritative and current description of these measures is maintained on our Security page.
- Encryption. Encryption of personal data in transit (TLS) and at rest.
- Access control. Least-privilege, role-based access control; multi-factor authentication for staff; single sign-on for customers; audit logging of access.
- Tenant isolation. Multi-tenant logical isolation, with isolated and access-restricted storage for sensitive and session-replay data.
- Application security. Secure software-development lifecycle, code review, change management, vulnerability scanning and periodic third-party penetration testing.
- Data protection by design. Session-replay masking and on-device suppression by default, and personal-data scrubbing of error and performance payloads, as described in section 6.
- Resilience. Backups, monitoring, and disaster-recovery processes to restore availability and access to personal data after an incident.
- Governance. Personnel confidentiality obligations, security training, and vendor and sub-processor management.
Annex III — Sub-processors
This Annex III lists the Sub-processors Mtrix engages to process Customer End-User Data, with the purpose and location of each. It populates Annex III of the SCCs where they apply. You provide a general authorisation for Mtrix to engage these Sub-processors, as set out in section 11.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. (AWS) | Cloud hosting, infrastructure, managed database & object storage — underpins the entire Mtrix Service (analytics, events, session recordings, error & performance data) | European Union — Ireland (eu-west-1) |
Where a provider is shown as a placeholder pending confirmation, the named vendor is being finalised; the purpose and region described are accurate, and the entry will be completed before that Sub-processor begins processing Customer End-User Data.
Notice of changes. Before adding or replacing a Sub-processor, Mtrix will give at least 30 days’ advance notice. You may object on reasonable data-protection grounds within 30 days of that notice; if you do not object within that window, the change is deemed accepted. If you object on reasonable grounds and the parties cannot agree a solution within a reasonable time, you may terminate the affected Services and receive a pro-rata refund of prepaid, unused fees, as set out in section 11. To receive notice of changes, keep a current contact on file and write to privacy@mtrix.io.
Annex IV — SCCs, UK IDTA & Swiss elections
This Annex IV records the parties’ elections for the data-transfer mechanisms described in section 13. Where personal data is transferred from the EEA, the United Kingdom or Switzerland to a country without an adequacy decision, the relevant clauses below are incorporated into this DPA by reference and take effect.
EU Standard Contractual Clauses
The SCCs approved by Commission Implementing Decision (EU) 2021/914 are incorporated by reference. Module Two (controller to processor) applies where you act as controller of Customer End-User Data; Module Three (processor to processor) applies where you act as a processor for your own clients. The elections are:
- Clause 7 (the docking clause) applies.
- Clause 9: Option 2 (general written authorisation) applies, with the minimum notice period for changes to Sub-processors set at 30 days, as described in section 11 and Annex III.
- Clause 11: the optional independent dispute-resolution body is not selected.
- Clause 17: the SCCs are governed by the law of Estonia.
- Clause 18: disputes are resolved before the courts of Harju County, Tallinn, Estonia.
- Annexes I, II and III of the SCCs are populated, respectively, by Annex I (Description of processing), Annex II (Technical and organisational measures) and Annex III (Sub-processors) of this DPA.
UK International Data Transfer Addendum
For transfers of UK end-user data, the UK International Data Transfer Addendum to the EU SCCs is appended to and forms part of this DPA. The EU SCCs above, as completed by their Annexes, are the Approved EU SCCs for the purposes of the UK Addendum, and references to supervisory authorities and governing law are read as referring to the UK Information Commissioner and, where the UK Addendum requires, the law of England and Wales.
Swiss adaptation
For transfers of Swiss data, the EU SCCs apply with the adaptations recognised by the Swiss Federal Data Protection and Information Commissioner: the FADP and, until its full revision, the Swiss Data Protection Act govern; the competent supervisory authority is the FDPIC; references to the GDPR are understood as references to the FADP where it provides equivalent protection; and the term “member state” is read so as not to deprive data subjects in Switzerland of their right to bring proceedings in their place of habitual residence.