色盒直播

Data Processing Addendum

How we process Personal Data on your behalf in connection with providing services or use of the 色盒直播 Platform.

You can sign this Data Processing Addendum .

Data Processing Addendum

1. Parties and Background

a. CUSTOMER as named in the relevant order form, exhibit, attachment, addendum or 聽other agreement (the 鈥淐ustomer鈥); and PARTNERSTACK INC., a corporation incorporated under the laws of Delaware, having its registered office at 1000 Brickell Avenue Suite #715 (PMB-315) Miami, FL 33131 (鈥溕兄辈モ) (each a 鈥淧arty鈥 and together the 鈥淧arties鈥) entered into a services agreement as dated in the relevant order form, exhibit, attachment, addendum or other agreement (the 鈥淎greement鈥). This Data Processing Addendum forms part of the Agreement and shall be effective as of the effective date of the Agreement and shall continue in effect until 色盒直播 deletes or returns Customer Personal Data as set forth herein.

b. To the extent that 色盒直播 processes Customer Personal Data (as defined below) on behalf of Customer or its affiliates in connection with providing the Services, the Parties have agreed that it shall do so under the terms of this Data Processing Addendum (鈥淒PA鈥).

c. In the event of any conflict between this DPA and the Agreement, the DPA shall control with respect to any processing of Customer Personal Data.

2. Roles of the Parties

a. The Parties acknowledge and agree that:

i. for the purposes of the GDPR, Customer is the Data Controller and 色盒直播 is the Data Processor; and

ii. for the purposes of the CCPA, 色盒直播 is a Service Provider to Customer.

3. Details of Data Processing

a. The details of data processing (such as subject matter, nature and purpose of the processing, categories of Personal Data and data subjects) are described in the Agreement and in Appendix 1.

b. 色盒直播 will only process Customer Personal Data according to the instructions of Customer and in accordance with applicable law. The Agreement and this DPA constitute Customer's instructions for 色盒直播鈥檚 processing of Customer Personal Data.

c. In using the 色盒直播 Platform, Customer represents and warrant that they: (i) will at all times comply with all applicable laws (including all applicable privacy laws); and (ii) have obtained all required rights, authorizations, consents and permissions for all information, material, or content that they enter into the Platform including any information about identifiable individuals (鈥淧ersonal Information"). 聽If Customer has collected Personal Information from another site and are sharing it on the Platform, Customer represents that they have disclosed that fact in a publicly facing and appropriate privacy policy.

d. If 色盒直播 believes Customer鈥檚 instructions are not compliant with applicable law or outside the scope of the Agreement or the DPA, 色盒直播 will promptly inform Customer thereof, unless prohibited by applicable law (without prejudice to the SCCs) and will not further process Customer Personal Data until the issue is resolved. 聽

e. 色盒直播 may anonymize Customer Personal Data through a reliable state of the art anonymization procedure and may use such anonymized data for its own business purposes, including for research, development of new products and services, and security purposes.

4. Sub-Processors

a. 色盒直播 may utilize Sub-processors to process Customer Personal Data subject to Section 4 (b). 色盒直播鈥檚 current Sub-processors are identified as of the Effective Date. 聽

b. 色盒直播 shall (i) enter into a written agreement with each Sub-processor imposing data protection obligations no less protective of Customer Personal Data than 色盒直播鈥檚 obligations under this DPA to the extent applicable to the nature of the services provided by such Sub-processor; and (ii) remain liable for each Sub-processor鈥檚 compliance with the obligations under this DPA.

c. Should 色盒直播 elect to engage another Sub-processor (including any addition or replacement of any Sub-processors), it shall provide Customer with at least thirty (30) days' notice. Customer may object to the new Sub-processor by providing 色盒直播 with written notice of the objection within ten (10) days after 色盒直播 has provided notice to Customer of such proposed change (an "Objection"). With an Objection, Customer and 色盒直播 will work together in good faith to resolve the Objection. If the parties cannot resolve the Objection within a reasonable time, either party may, as its sole and exclusive remedy, terminate the Agreement by providing written notice to the other party. During any such Objection period, 色盒直播 may suspend the affected portion of the Services. 聽If Customer does not object during the period set forth above, it shall be deemed to have consented to the use of the new Sub-processor.

5. Data Subject Requests

a. Customer shall have sole responsibility to respond to requests by any Data Subject related to their rights in relation to Customer Personal Data (鈥淒ata Subject Request鈥).

b. If 色盒直播 receives a Data Subject Request, it will forward it to Customer without undue delay and may advise the individual to submit their request directly to Customer.

c. 色盒直播 will (taking into account the nature of the processing of Customer Personal Data) provide Customer with reasonable assistance as necessary and at Customer鈥檚 expense to allow Customer to fulfil its obligation to respond to Data Subject Requests, including if applicable, Customer鈥檚 obligation to respond to requests to exercising the rights set out in the GDPR or CCPA.

6. Security and Audits

a. Taking into account the state of the art, the implementation costs as well as the nature, scope, context and purposes of processing, 色盒直播 will implement and maintain appropriate technical and organizational measures designed to ensure security of Customer Personal Data, including, without limitation, protection against unauthorized or unlawful processing, unauthorized or unlawful disclosure of, access to and/or alteration of Customer Personal Data and against accidental loss, destruction, or damage of or to Customer Personal Data.

b. 色盒直播 will ensure that its personnel who are authorized to access Customer Personal Data are subject to appropriate confidentiality obligations.

c. 色盒直播 will implement and maintain the measures set out in Annex II. 色盒直播 may periodically update or modify the security measures set out in Annex II.

d. Upon thirty (30) days鈥 notice and at Customer鈥檚 expense, Customer or its independent third-party auditor reasonably acceptable to 色盒直播 may audit 色盒直播鈥檚 compliance with its obligations under this DPA up to once per year unless more frequent audits are required by a competent data authority or following a Security Incident. 聽All such audits must be conducted during regular business hours and may not unreasonably interfere with 色盒直播 business activities. 聽

e. Customer will promptly notify 色盒直播 of any non-compliance discovered by an audit and provide 色盒直播 any audit reports generated in connection with any audit, unless prohibited by applicable law or otherwise instructed by a regulatory or governmental authority. Customer may use the audit reports only for the purposes of meeting Customer鈥檚 regulatory audit requirements and/or confirming compliance with the requirements of this DPA.

f. 色盒直播 shall audit its Sub-processors on a regular basis and will, upon Customer鈥檚 request, confirm their compliance with data protection law and the obligations set upon Sub-processors according to the data processing agreement concluded with them.

7. Security Incidents

a. 色盒直播 shall notify the Customer without undue delay after becoming aware of any incident where the security of Customer Personal Data has been compromised or is likely to have been compromised (a 鈥淪ecurity Incident鈥). 色盒直播 will investigate the Security Incident and provide the Customer with such co-operation and assistance as may be reasonably required to comply with any notification or reporting obligations which may apply in respect of any such personal data breach.

8. Deletion and Return

a. 色盒直播 shall, within 45 days of the date of termination or expiry of the Agreement, (a) if requested to do so by Customer within that period, return a complete copy of all Customer Personal Data by secure file transfer in such a format as notified by Customer to 色盒直播; and (b) delete and use all reasonable efforts to procure the deletion of all other copies of Customer Personal Data processed by 色盒直播 or any Sub-processors unless EU law or the laws of an EU Member State require storage of the personal data.

9. Impact Assessments

a. 色盒直播 will (taking into account the nature of the Processing and the information available to 色盒直播) reasonably assist Customer at Customer鈥檚 expense in complying with its obligations under Articles 35 and 36 of the GDPR, by (a) making available documentation describing relevant aspects of 色盒直播鈥檚 information security program and the security measures applied in connection therewith and (b) providing the other information contained in the Agreement, including this DPA.

10. Data Transfers

a. 色盒直播 and its sub-processors may process personal data outside the EEA in one or more countries that have not received an adequacy decision as required by GDPR. The transfer of personal data from the Customer to 色盒直播 in these circumstances shall be governed by the Standard Contractual Clauses, which are hereby incorporated into this DPA. For the purpose of the Standard Contractual Clauses:

i. The data exporter is the Customer;

ii. The data importer is 色盒直播;

b. For the purpose of Annex I to the Appendix to the Standard Contractual Clauses, the (A) list of parties, (B) description of the transfer, and (C) competent supervisory authority. are as set out or referenced in Annex I to this DPA;

c. For the purpose of Annex II to the Appendix to the Standard Contractual Clauses, the technical and organisational measures implemented by 色盒直播 are set out or referenced in Annex II to this DPA;

d. For the purpose of Annex III to the Appendix to the Standard Contractual Clauses, the list of sub-processors is set forth in Section 4(a) of this DPA; and

11. Customer Personal Data Subject to UK and Swiss Data Protection Laws

a. To the extent that the processing of Customer Personal Data is subject to UK or Swiss data protection laws, the UK Addendum and/or Swiss Addendum (as applicable) set out in Schedule 1 shall apply.

12. Customer Personal Data Subject to the CCPA

a. To the extent that the processing of Customer Personal Data is subject to the CCPA, 色盒直播: 聽(a) acknowledges that Personal Information is disclosed by Customer only for limited and specified purposes described in the Agreement, pursuant to which 色盒直播 will provide Customer with its services; (b) shall comply with applicable obligations under the CCPA and shall provide the same level of privacy protection to Personal Information as is required by the CCPA; (c) agrees that Customer has the right to take reasonable and appropriate steps to help to ensure that 色盒直播鈥檚 use of Personal Information is consistent with Customer鈥檚 obligations under the CCPA; (d) shall notify Customer in writing of any determination made by 色盒直播 聽that it can no longer meet its obligations under the CCPA; and (e) agrees that Customer has the right, upon notice, including pursuant to the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information.

b. The Parties intend that 色盒直播 be a Service Provider with respect to its processing of Customer Personal Data. 聽色盒直播 聽shall not (a) Sell or Share Personal Information; (b) retain, use or disclose any Personal Information for any purpose other than for the Business Purposes specified in the Agreement, including retaining, using or disclosing Personal Information for a Commercial Purpose other than the Business Purpose specified in the Agreement, or as otherwise permitted by CCPA; (c) retain, use or disclose Personal Information outside of the direct business relationship between 色盒直播 聽and Customer; or (d) except as permitted by the CCPA, combine Personal Information received pursuant to the Agreement with Personal Information (i) received from or on behalf of another person; or (ii) collected from 色盒直播鈥檚 own interaction with any Consumer to whom such Personal Information pertains. 色盒直播 certifies that it understands the obligations under this Section and will comply with them.

c. Compliance with Section 4 of the DPA shall satisfy 色盒直播 鈥檚 obligation under the CCPA to give notice of Subprocessor engagements.

d. The Parties acknowledge and agree that (a) 色盒直播 鈥檚 access to Personal Information is not part of the consideration exchanged by the parties in respect of the Agreement; and (b) Customer鈥檚 instructions documented in the DPA are integral to 色盒直播 鈥檚 provision of the Services and the business relationship between the Parties.

13. Definitions

Capitalized terms used but not defined within this DPA shall have the meaning set forth in the Agreement. The following capitalized terms used in this DPA shall be defined as follows:

a. 鈥Affiliate" means an entity that, directly or indirectly, owns or controls, is owned or is controlled by, or is under common ownership or control with a Party and is a beneficiary of the Agreement.

b. "Approved Addendum" means the template Addendum issued by the UK Information Commissioner and laid before the UK Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of the Mandatory Clauses;

c. "CCPA" means the California Consumer Privacy Act, Cal. Civ. Code 搂搂 1798.100 et seq., including any amendments and any implementing regulations thereto that become effective on or after the Effective Date of this DPA;

d. "Customer Personal Data" means the Personal Data processed by 色盒直播 on behalf of Customer in connection with the provision of the Services;

e. "EEA" means the European Economic Area;

f. "GDPR" means Regulation (EU) 2016/679 (the "EU GDPR") or, where applicable, the "UK GDPR" as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the UK European Union (Withdrawal) Act 2018 or, where applicable, the equivalent provision under Swiss data protection law;

g. "Mandatory Clauses" means Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the UK Information Commissioner and laid before the UK Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses;

h. "Member State" means a member state of the EEA, being a member state of the European Union, Iceland, Norway, or Liechtenstein;

i. "Personal Data" means any information relating to an identified or identifiable individual or device, or is otherwise "personal data," "personal information," "personally identifiable information" and similar terms, and such terms shall have the same meaning as defined by applicable data protection laws.

j. "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to (including unauthorized internal access to), Customer Personal Data.

k. "Standard Contractual Clauses" or 鈥SCCs鈥 means Module Two (controller to processor) of the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914; and

l. "Sub-processor" means 色盒直播 Affiliates and third-party processors appointed by 色盒直播 to process Customer Personal Data.

m. 鈥UK鈥 means the United Kingdom of Great Britain and Northern Ireland.

The terms "controller", "processor", "data subject", "process", and "supervisory authority" shall have the same meaning as set out in the GDPR.

The terms 鈥sell鈥 and 鈥service provider鈥 shall have the same meaning as set out in the CCPA.

ANNEX I

A. LIST OF PARTIES

MODULE TWO: Transfer controller to processor

Data exporter(s): Identity and contact details of the data exporter(s) and, where applicable, of its/their data protection officer and/or representative in the European Union

Name: As contained in the relevant order form, exhibit, attachment, addendum or other agreement.

Address: As contained in the relevant order form, exhibit, attachment, addendum or other agreement.

Contact person鈥檚 name, position and contact details: 聽As contained in the relevant order form, exhibit, attachment, addendum or other agreement.

Activities relevant to the data transferred under these Clauses: As per Agreement

Role (controller/processor): Controller

Data importer(s): Identity and contact details of the data importer(s), including any contact person with responsibility for data protection

Name: 色盒直播 Inc.

Address: 1000 Brickell Avenue Suite #715 (PMB-315) Miami, FL 33131

Data protection officer: privacy@partnerstack.com

Activities relevant to the data transferred under these Clauses: As per Agreement

Role (controller/processor): Processor

B. DESCRIPTION OF TRANSFER

MODULE TWO: Transfer controller to processor

Categories of data subjects whose personal data is transferred

鈥 Customer鈥檚 employees, contractors, agents, and/or representatives

鈥 Customer鈥檚 customers and affiliates, and their employees, contractors, agents, representatives, and customers (some of which may be end users of Customer鈥檚 software products and services)

Categories of personal data transferred

Demographic data: first name, last name, e-mail, IP address, postal address, phone number; may include data of birth. There is also data generated when users view products of a customer

Contact data: Personal/work email address; Personal/work telephone number; Work postal address

Digital Identifiers: IP Address, MAC Address

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.

鈥 Not Applicable

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).

鈥 Continuous basis

Nature of the processing

鈥 The scope and nature of the processing is the provision of services by 色盒直播 to Customer as set forth in the Agreement.

Purpose(s) of the data transfer and further processing

鈥 The purpose of the data transfer and further processing is to enable 色盒直播 to fulfil its obligations to Customer under the Agreement.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

鈥 7 Years since last used. 聽

For transfers to (sub) processors, also specify subject matter, nature and duration of the processing, see list of subprocessors

Duration of the Processing: Continues until service is terminated with Sub-processors

C. COMPETENT SUPERVISORY AUTHORITY

MODULE TWO: Transfer controller to processor

Identify the competent supervisory authority/ies in accordance with Clause 13

ANNEX II

TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

Description of the technical and organisational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons.

Measures of pseudonymisation and encryption of personal data

鈥 All data at rest is encrypted

鈥 Personally identifiable information is used on a principles of least privilege and need to know basis

鈥 Analytics data is always anonymized through aggregation and identifiers removed

Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services

鈥 Holistic Information Security Management System that scopes in all the critical processing systems and services

Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident

鈥 Business Continuity and Disaster Recovery Plan

鈥 Annual testing of BC and DR plans

Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures in order to ensure the security of the processing

鈥 Annual audits (SOC 2)

鈥 Annual penetration testing done by a third-party

Measures for user identification and authorisation

鈥 All access requires unique identification and/or logging to ensure auditability and accountability

Measures for the protection of data during transmission

鈥 Data in transit is encrypted

Measures for the protection of data during storage

鈥 Data at rest is encrypted

Measures for ensuring physical security of locations at which personal data are processed

鈥 Usage of subservice providers that meet the high level of physical security of locations that hold critical data

Measures for ensuring events logging

鈥 Dedicated Engineering infrastructure team is responsible for this

Measures for ensuring system configuration, including default configuration

鈥 Dedicated Engineering infrastructure team is responsible for this

Measures for internal IT and IT security governance and management

鈥 Information Security Management System implemented in accordance with ISO27001 and AICPA Trust Services Principles guideline

Measures for certification/assurance of processes and products

鈥 色盒直播 platform is SOC 2 Type 2 compliant

Measures for ensuring data minimisation

鈥 Annual risk assessment identifies and assesses risks pertaining to privacy, which includes data minimisation

Measures for ensuring data quality

鈥 Engineering quality reviews and standard development practices

鈥 Data engineering team dedicated to help ensuring data quality

Measures for ensuring limited data retention

鈥 Data retention policies are set at the data storage layer

Measures for ensuring accountability

鈥 Audit logging enabled at all critical layers of the system and platform

Measures for allowing data portability and ensuring erasure

鈥 Defined processes and tooling implemented for data portability and erasure scripts created by the Engineering team and supported by the Technical Support team

For transfers to (sub-) processors, also describe the specific technical and organisational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter

鈥 Dedicated vendor risk management program to help ensure (sub-)processors are able to meet the security standards set by our organization which includes requirements such as:

o Security certification programs (e.g. ISO27001, SOC 2, etc)

o Demonstration of a security management system/program

o Data Protection Agreements

o Other risk assessments as deemed necessary

Appendix 1 鈥 Details of Data Processing

Subject matter, nature and purpose of the processing
Subject matter of processing: personal data, as defined under applicable data protection laws.

Nature of Processing: the scope, nature and purpose of the processing is the provision of services by 色盒直播 to Customer as set forth in the Agreement.
Duration
Duration of the Agreement
Categories of data subjects
Customer鈥檚 employees, contractors, agents, and/or representatives.

Customer鈥檚 customers and affiliates, and their employees, contractors, agents, representatives, and customers (some of which may be end users of Customer鈥檚 software products and services).

Types of personal data i.e. any information relating to an identified or identifiable person.

Demographic Data
Includes, but is not limited to, first name, last name, e-mail, IP address, postal address, phone number; may include data of birth.

There is also data generated when users view products of a customer
Contact Details
Personal/work email address
Personal/work telephone number
Work postal address
Digital Identifiers
IP Address, MAC Address
Special Categories of Data
Not Applicable
Other
N/A

SCHEDULE 1

UK AND SWISS ADDENDUM

1. UK Addendum

With respect to any transfers of Customer Personal Data falling within the scope of the UK GDPR from Customer (as data exporter) to 色盒直播 (as data importer):

a. Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the UK Information Commissioner and laid before the UK Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses shall form part of this DPA, and the Standard Contractual Clauses shall be read and interpreted in light of the provisions of the Mandatory Clauses;

b. 色盒直播 聽(as data importer) may end this DPA, to the extent the Mandatory Clauses apply, in accordance with clause 鈥19 of the Mandatory Clauses;

c. Neither the Standard Contractual Clauses nor the DPA shall be interpreted in a way that conflicts with rights and obligations provided for in any laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the UK GDPR and the Data Protection Act 2018 (together, the "UK Data Protection Laws"); and

d. The Standard Contractual Clauses are deemed to be amended to the extent necessary so they operate:

i. for transfers made by Customer to 色盒直播 , to the extent that UK Data Protection Laws apply to the Customer鈥檚 processing when making that transfer; and

ii. to provide appropriate safeguards for the transfers in accordance with Article 46 of the UK GDPR;

2. SWISS ADDENDUM

As stipulated in Section 11 of the DPA, this Swiss Addendum shall apply to any processing of Customer Personal Data subject to Swiss data protection law or to both Swiss data protection law and the GDPR.

a. Interpretation of this Addendum

Where this Addendum uses terms that are defined in the Standard Contractual Clauses as further specified in this DPA, those terms shall have the same meaning as in the Standard Contractual Clauses. In addition, the following terms have the following meanings:

This Addendum
This Addendum to the Clauses
Clauses
The Standard Contractual Clauses as further specified in Schedule 1 of this DPA
Swiss Data Protection Laws
The Swiss Federal Act on Data Protection of 19 June 1992 and the Swiss Ordinance to the Swiss Federal Act on Data Protection of 14 June 1993, and any new or revised version of these laws that may enter into force from time to time.

This Addendum shall be read and interpreted in the light of the provisions of Swiss Data Protection Laws, and so that if fulfils the intention for it to provide the appropriate safeguards as required by Article 46 GDPR and/or Article 6(2)(a) of the Swiss Data Protection Laws, as the case may be.

This Addendum shall not be interpreted in a way that conflicts with rights and obligations provided for in Swiss Data Protection Laws.

Any references to legislation (or specific provisions of legislation) means that legislation (or specific provision) as it may change over time. This includes where that legislation (or specific provision) has been consolidated, re-enacted and/or replaced after this Addendum has been entered into.

b. Hierarchy

In the event of a conflict or inconsistency between this Addendum and the provisions of the Clauses or other related agreements between the Parties, existing at the time this Addendum is agreed or entered into thereafter, the provisions which provide the most protection to data subjects shall prevail.

c. Incorporation of the Clauses

i. In relation to any processing of personal data subject to Swiss Data Protection Laws or to both Swiss Data Protection Laws and the GDPR, this Addendum amends the DPA including as further specified in Schedule 1 of this DPA to the extent necessary so they operate:

1. for transfers made by the data exporter to the data importer, to the extent that Swiss Data Protection Laws or Swiss Data Protection Laws and the GDPR apply to the data exporter鈥檚 processing when making that transfer; and

2. to provide appropriate safeguards for the transfers in accordance with Article 46 of the GDPR and/or Article 6(2)(a) of the Swiss Data Protection Laws, as the case may be.

ii. To the extent that any processing of personal data is exclusively subject to Swiss Data Protection Laws, the amendments to the DPA including the SCCs, as further specified in Schedule 1 of this DPA and as required by clause 2.1 of this Swiss Addendum, include (without limitation):

1. References to the "Clauses" or the "SCCs" means this Swiss Addendum as it amends the SCCs.

2. Clause 6 Description of the transfer(s) is replaced with:

"The details of the transfer(s), and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred, are those specified in Schedule 1 of this DPA where Swiss Data Protection Laws apply to the data exporter鈥檚 processing when making that transfer."

3. References to "Regulation (EU) 2016/679" or "that Regulation" or "鈥淕DPR" are replaced by "Swiss Data Protection Laws" and references to specific Article(s) of "Regulation (EU) 2016/679" or "GDPR" are replaced with the equivalent Article or Section of Swiss Data Protection Laws extent applicable.

4. References to Regulation (EU) 2018/1725 are removed.

5. References to the "European Union", "Union", "EU" and "EU Member State" are all replaced with "Switzerland".

6. Clause 13(a) and Part C of Annex I are not used; the "competent supervisory authority" is the Federal Data Protection and Information Commissioner (the 鈥淔DPIC鈥) insofar as the transfers are governed by Swiss Data Protection Laws;

7. Clause 17 is replaced to state:

These Clauses are governed by the laws of Switzerland insofar as the transfers are governed by Swiss Data Protection Laws.

8. Clause 18 is replaced to state:

Any dispute arising from these Clauses relating to Swiss Data Protection Laws shall be resolved by the courts of Switzerland. A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of Switzerland in which he/she has his/her habitual residence. The Parties agree to submit themselves to the jurisdiction of such courts.

Until the entry into force of the revised Swiss Data Protection Laws, the Clauses shall also protect personal data of legal entities and legal entities shall receive the same protection under the Clauses as natural persons.

iii. To the extent that any processing of personal data is subject to both Swiss Data Protection Laws and the GDPR, the DPA including the Clauses as further specified in Schedule 1 of this DPA will apply (i) as is and (ii) additionally, to the extent that a transfer is subject to Swiss Data Protection Laws, as amended by clauses 2.1 and 2.3 of this Swiss Addendum, with the sole exception that Clause 17 of the SCCs shall not be replaced as stipulated under clause 2.3(b)(vii) of this Swiss Addendum.

iv. Customer warrants that it and/or Customer Affiliates have made any notifications to the FDPIC which are required under Swiss Data Protection Laws.