Políticas e Termos de Uso
ÍNDICE
  1. Capítulo1

Data Protection Addendum

The customer who agrees to these terms (“Customer”) has entered into a Terms of Use Agreement or SaaS Services Agreement with The Enlighten Company S/A (“Enspace”) under which Enspace agreed to provide services to the Customer (as amended from time to time, the “Agreement”).

This Data Protection Addendum, including its applicable Appendices (the “Addendum”) will take effect and supersede any previously applicable data processing and security terms as of the Effective Date of the Addendum (as defined below). This Amendment forms part of the Agreement.

Any capitalized term used but not otherwise defined in this Addendum shall have the meaning provided to it in the Agreement.

1. Definitions

For the purposes of this Addendum, the terms below shall have the meanings set forth below. Capitalized terms used but not otherwise defined in this Addendum shall have the meanings set forth in the Agreement.

1.1 “Addendum Effective Date” means the date on which the parties agreed to this Addendum.

1.2 “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where “control” refers to the power to direct or cause direction of the subject entity, whether through the ownership of voting securities, by contract, or otherwise.

1.3 “Audit Reports” has the meaning given in Section 5.4.4 (Audit Reports).

1.4 “CCPA” means the California Consumer Privacy Act of 2018.

1.5 “Customer Personal Data” means any personal data or personal information of the data subjects contained in the data provided or accessed by Enspace by or on behalf of the Customer or the Customer's end users in connection with the Services.

1.6 “Global Data Protection Legislation” means European Data Protection Legislation, CCPA, and LGPD as applicable to the processing of Customer Personal Data under the Agreement.

1.7 “EEA” means the European Economic Area.

1.8 “EU” means the European Union.

1.9 “European Data Protection Legislation” means the GDPR and other data protection laws of the EU, its Member States, Switzerland, Iceland, Liechtenstein, and Norway, and the United Kingdom, applicable to the processing of Customer Personal Data under the Agreement.

1.10 “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of individuals with regard to the processing of personal data of EU data subjects and on the free movement of such data, and repealing Directive 95/46/EC.

1.11 “Information Security Incident” means a breach of Enspace's security that leads to accidental or illegal destruction, loss, alteration, unauthorized disclosure, or access to Customer Personal Data in Enspace's possession, custody, or control. “Information security incidents” will not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, including unsuccessful login attempts, pings, port checks, denial of service attacks, and other network attacks on firewalls or networked systems.

1.12 “LGPD” means the Brazilian General Data Protection Law.

1.13 “Standard Contractual Clauses” or “SCCs” have the meaning defined for Appendix 3 (Cross-Border Transfer Solutions) of this Addendum.

1.14 “Security Documentation” means all documents and information made available by Enspace in Section 5.4.1 (Audits).

1.15 “Security Measures” has the meaning given in Section 5.1.1 (Enspace Security Measures).

1.16 “Services” means the services and/or products to be provided by Enspace to the Customer under the Agreement.

1.17 “Sub-processors” means third parties authorized under this Addendum to process Customer Personal Data in connection with the Services.

1.18 “Term” means the period from the Effective Date of the Addendum to the end of the provision of the Services by Enspace.

1.19 “Transfer Solution” means the Standard Contractual Clauses or another solution that allows the legal transfer of personal data to a third country in accordance with Article 45 or 46 of the GDPR.

1.20 The terms “personal data”, “data subject”, “processing”, “controller”, “processor” and “supervisory authority” as used in this Addendum have the meanings assigned in the GDPR and LGPD, as applicable, and the terms “data importer” and “data exporter” have the meanings given in the Standard Contractual Clauses. The terms “personal information”, “commercial” and “service provider” have the meanings defined in the CCPA.

2. Addendum Duration

3. Data Processing

This Addendum will take effect on the Effective Date of the Addendum and, notwithstanding the expiration of the Term, will remain in effect until, and will automatically expire upon the deletion of all Customer Personal Data by Enspace, as described in this Addendum.

3.1 Papers and Regulatory Compliance; Authorization.

3.1.1 Responsibilities of the Processor and the Controller. This Addendum applies only to the extent that we are processing Customer Personal Data on behalf of the Customer. If European Data Protection Legislation, LGPD or CCPA applies to the processing of Customer Personal Data, the parties acknowledge and agree that:

(a) the object and details of the processing are described in Appendix 1; (b) Enspace is a processor of that Customer Personal Data under European Data Protection Legislation or LGPD, and/or a Service Provider with respect to such Customer Personal Data under the CCPA, as applicable; (c) the Customer is a controller or processor of that Customer Personal Data under European Data Protection Legislation or LGPD, and/or a Company with respect to that Customer Personal Data under the CCPA, as applicable; and (d) each party will comply with obligations applicable to it in accordance with the applicable Global Data Protection Legislation with respect to the processing of such Customer Personal Data.

3.1.2 Authorization by the Third Party Controller. If European Data Protection Legislation applies to the processing of Customer Personal Data and the Customer is a processor, the Customer warrants to Enspace that the Customer's instructions and actions with respect to that Customer Personal Data, including your appointment of Enspace as another processor and your consent to Enspace for subsequent transfers of Customer Personal Data to its Sub-processors have been authorized by the relevant controller.

3.2 Scope of Processing.

3.2.1 Customer Instructions. By entering this Addendum, the Customer instructs Enspace to process Customer Personal Data only in accordance with applicable law: (a) to provide the Services; (b) as authorized by the Agreement, including this Addendum and its Appendices; and (c) as documented in any other written instructions provided by the Customer and acknowledged in writing by Enspace as constituting instructions for the purposes of this Addendum.

3.2.2 Enspace Compliance with the Instructions. Enspace will only process Customer Personal Data in accordance with the Customer's instructions described in Section 3.2.1 (including with respect to data transfers) (“Customer Instructions”), unless the applicable Global Data Protection Legislation to which Enspace is subject requires other processing of Customer Personal Data Enspace, in which case Enspace will notify the Customer (unless the law prohibits Enspace from doing so for important reasons of public interest).

4. Deletion of data

4.1 Exclusion on Termination. Unless otherwise provided in the Agreement, upon expiration of the Term, the Customer instructs Enspace to delete all Customer Personal Data (including existing copies) from the Enspace systems as required and in accordance with applicable law as soon as reasonably possible, unless applicable law prevents Enspace from deleting such data. To the extent that the Customer is subject to laws or regulations that require Enspace to retain Customer Personal Data after the Term has expired and the Customer fails to inform Enspace of these retention obligations, the Customer will be solely responsible for any deletion of such data by Enspace in accordance with this Section 4.1.

5. Data security

5.1 Enspace Security Measures, Controls, and Assistance.

5.1.1 Enspace security measures. Enspace will implement and maintain technical and organizational measures to protect Customer Personal Data against accidental or illegal destruction, loss, alteration, unauthorized disclosure, or access to Customer Personal Data as described in Appendix 2 (the “Technical and Organizational Security Measures”). Enspace may update or modify the Security Measures from time to time, provided that such updates and modifications do not materially diminish the overall security of the Services.

5.1.2 Security compliance by the Enspace team. Enspace will grant access to Customer Personal Data only to employees, contractors, and Subprocessors who require such access for the scope of their performance and are subject to appropriate confidentiality agreements.

5.1.3 Enspace Security Assistance. Enspace will (taking into account the nature of the processing of the Customer's Personal Data and the information available to Enspace) provide the Customer with the reasonable assistance necessary for the Customer to fulfill its obligations in relation to the Customer's Personal Data under the Global Data Protection Legislation, including Articles 32 to 34 (inclusive) of the GDPR and articles 6 and 46 of the LGPD, by:
(a) implement and maintain Security Measures in accordance with Section 5.1.1 (Enspace Security Measures);
(b) comply with the terms of Section 5.2 (Information Security Incidents); and
(c) provide the Customer with Security Documentation in accordance with Section 5.4.1 (Security Documentation Revisions) and the Agreement, including this Addendum.

5.2 Information Security Incidents.

5.2.1 Notification of Information Security Incidents. If Enspace becomes aware of an Information Security Incident, Enspace will: (a) notify the Customer of the Information Security Incident without undue delay after becoming aware of the Information Security Incident; and (b) take reasonable steps to identify the case of such Information Security Incident, minimize damage and prevent a recurrence.

5.2.2 Information Security Incident Details. Notifications made in accordance with this Section 5.2 (Information Security Incidents) will describe, to the extent possible, the details of the Information Security Incident, including (i) the nature of the Information Security Incident, including whenever possible, the categories and approximate number of data subjects in question and the categories and approximate number of personal data records in question; (ii) the name and contact details of the data protection officer or other point of contact where more information can be obtained, (iii) the probable consequences of the Information Security Incident; (iv) measures taken, or proposed to be taken, to mitigate potential risks and measures that Enspace recommends that the Customer take to deal with the Information Security Incident, including, where appropriate, measures to mitigate its potential adverse effects.

5.2.3 Notification. The Customer is solely responsible for complying with the incident notification laws applicable to the Customer and for complying with any third-party notification obligations related to any Information Security Incident (s).

5.2.4 No fault recognition by Enspace. Enspace's notification or response to an Information Security Incident under this Section 5.2 (Information Security Incidents) will not be construed as an acknowledgement by Enspace of any fault or liability with respect to the Information Security Incident.

5.3 Customer Responsibilities and Safety Assessment.

5.3.1 Customer Security Responsibilities. The Customer agrees that, without prejudice to Enspace's obligations under Section 5.1 (Enspace Security Measures, Controls, and Assistance) and Section 5.2 (Information Security Incidents):
(a) The Customer is solely responsible for the use of the Services, including:
(i) make appropriate use of the Services to ensure a level of security appropriate to the risk in relation to the Customer's Personal Data;
(ii) protect the credentials, systems, and account authentication devices that the Customer uses to access the Services; and
(iii) protect the Customer's systems and devices that Enspace uses to provide the Services; and
(iv) back up your Customer Personal Data.
(b) Enspace has no obligation to protect Customer Personal Data that the Customer chooses to store or transfer outside of Enspace's systems and its Subprocessors (for example, offline or on-premises storage).

5.3.2 Customer Security Assessment.
(a) The Customer is solely responsible for reviewing the Security Documentation and evaluating for himself whether the Services, Security Measures, and Enspace's commitments under this Section 5 (Data Security) will meet the Customer's needs, including with respect to any Customer's security obligations under the applicable Global Data Protection Legislation.
(b) The Customer acknowledges and agrees that (taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of the processing of Customer Personal Data, as well as risks to individuals) the Security Measures implemented and maintained by Enspace as defined in Section 5.1.1 (Enspace Security Measures) provide a level of security appropriate to the risk in relation to the Customer's Personal Data.

5.4 Compliance Reviews and Audits.

5.4.1 Audits. The Customer may audit Enspace's compliance with its obligations under this Addendum up to once a year. In addition, to the extent required by applicable Global Data Protection Legislation, including when required by the Customer's supervisory authority, the Customer or the Customer's supervisory authority may carry out more frequent audits (including inspections). Enspace will contribute to such audits by providing the Customer or the Customer's supervisory authority with the information and assistance reasonably necessary to conduct the audit, including any relevant records of processing activities applicable to the Services.

5.4.2 Objections to the Third Party Auditor. If a third party conducts the audit, Enspace may object to the auditor if the auditor is, in Enspace's reasonable opinion, not adequately qualified or independent, a competitor of Enspace, or manifestly inadequate. This Enspace objection will require the Customer to appoint another auditor or to conduct the audit on its own.

5.4.3 Audit Request. To request an audit, the Customer must submit a detailed proposed audit plan to Enspace at least two weeks in advance of the proposed audit date. The proposed audit plan must describe the proposed scope, duration, and start date of the audit. Enspace will review the proposed audit plan and provide the Customer with any concerns or questions (for example, any request for information that could compromise Enspace's security, privacy, employment, or other relevant policies). Enspace will work cooperatively with the Customer to reach an agreement on a final audit plan. Nothing in this Section 5.4 (Compliance Reviews and Audits) will require Enspace to violate any confidentiality obligations.

5.4.4 Audit Reports. If the requested audit scope is addressed in an SSAE 16/18/ISAE 3402 Type 2, AICPA SOC 2 (SOC for Service Organizations: Trust Services Criteria), or similar audit report conducted by a qualified third-party auditor (“Audit Reports”) within twelve (12) months of the Customer's audit request and Enspace confirms that there are no known material changes to the audited controls, the Customer agrees to accept those findings instead of requesting an audit of the controls covered by the report.

5.4.5 Conducting the Audit. The audit must be conducted during normal business hours at the applicable facility, subject to the agreed final audit plan and Enspace's health and safety or other relevant policies, and must not unreasonably interfere with Enspace's business activities.

5.4.6 Audit Conditions. The Customer will immediately notify Enspace of any non-compliance discovered during an audit and will provide Enspace with any audit reports generated in connection with any audit under this Section 5.4 (Compliance Reviews and Audits), unless prohibited by applicable Global Data Protection Legislation or otherwise instructed by a supervisory authority. The Customer may use the audit reports only to meet the Customer's regulatory auditing requirements and/or confirm compliance with the requirements of this Addendum. The audit reports and any Enspace information shared during the auditing process are the parties' Confidential Information under the Agreement.

5.4.7 Audit Expenses. Any audits are at the Customer's expense. The Customer will reimburse Enspace for any time spent by Enspace or its Subprocessors in connection with any audits or inspections under this Section 5.4 (Compliance Reviews and Audits) with Enspace's current professional services fees, which will be made available to the Customer upon request. The Customer will be responsible for any fees charged by any auditor appointed by the Customer to perform such an audit.

5.4.8 Standard Contractual Clauses. The parties agree that this Section 5.4 (Compliance Reviews and Audits) must satisfy Enspace's obligations in accordance with the auditing requirements of the 2021 Standard Contractual Clauses applied to the Data Importer in accordance with Clause 8 and Clause 13 (a) and to any Subprocessors in accordance with Clause 9.

6. Impact assessments and inquiries

Enspace will (taking into account the nature of the processing and the information available to Enspace) reasonably assist the Customer in complying with its obligations under the applicable Global Data Protection Legislation regarding data protection impact assessments and prior consultation, including, if applicable, obligations under articles 35 and 36 of the GDPR, by:

6.1 Audit Reports and Security Measures. Make copies of the Audit Reports or other documentation that describe relevant aspects of the Enspace information security program and the security measures applied in relation to it available for review;

6.2 Additional Information. Provide the information contained in the Agreement, including this Addendum.

7. Data Subject Rights

7.1 Customer Responsibility for Requests. During the Term, if Enspace receives any request from a data subject regarding Customer Personal Data, Enspace will, at its sole discretion, (i) notify the Customer of the request, (ii) advise the data subject to submit their request to the Customer, and/or (iii) notify the data subject that their request was forwarded to the Customer. The Customer will be responsible for responding to any such request.

7.2 Request for Assistance from the Enspace Data Subject. Enspace will (taking into account the nature of the processing of Customer Personal Data) provide the Customer with self-service functionality through the Services or other reasonable assistance as necessary for the Customer to fulfill its obligation under the applicable Global Data Protection Legislation to respond to requests from data subjects, including, if applicable, the Customer's obligation to respond to requests to exercise the data subject's rights established in Chapter III of the GDPR, in articles 18 and 19 of the LGPD, or in CCPA section 1798.105. The Customer will reimburse Enspace for any assistance other than the provision of self-service features included as part of the Services in Enspace's current professional services fees, which will be made available to the Customer upon request.

8. Data transfers

8.1 Data storage and processing facilities. Enspace may, in accordance with Section 8.2 (Data Transfers Outside the EEA), store and process Customer Personal Data anywhere that Enspace or its Subprocessors maintain facilities.

8.2 Data Transfers Outside the EEA.

8.2.1 Enspace Transfer Obligations. If the storage and/or processing of Customer Personal Data (as established in Section 8.1 (Data Storage and Processing Facilities)) involves transfers of Customer Personal Data outside the EEA, United Kingdom, or Switzerland, and European Data Protection Legislation applies to transfers of such data (“Transferred Personal Data”), the terms set out in Annex 3 (International Transfer Solutions) will apply. Enspace will make these transfers in accordance with a Transfer Solution and will provide information to the Customer about that Transfer Solution upon request.

8.2.2 Customer Transfer Obligations. With respect to the Transferred Personal Data, the Customer agrees that, if in accordance with European Data Protection Legislation, Enspace reasonably requires the Customer to use another Transfer Solution offered by Enspace (in addition to the Standard Contractual Clauses, attached to this document as Appendix 3 and incorporated by reference to the extent that the Customer is transferring Customer Personal Data outside the EEA, United Kingdom, or Switzerland to Enspace) and Enspace reasonably requests that the Customer take any action (which may include the execution of documents) necessary to give full effect to such a solution, the Customer will do so.

8.3 Disclosure of Confidential Information Containing Personal Data. If the Customer has entered into Standard Contractual Clauses as described in Section 8.2 (Data Transfers Outside the EEA), Enspace will, notwithstanding any contrary term in the Agreement, make any disclosure of the Customer's Confidential Information containing personal data and any notifications related to such disclosures, in accordance with such Standard Contractual Clauses. For the purposes of the Standard Contractual Clauses, the Customer and Enspace agree that (i) the Customer will act as an exporter of
data on behalf of the Customer itself and on behalf of any of the Customer's entities and (ii) Enspace or its relevant Affiliate will act on its own behalf and/or on behalf of the Enspace Affiliates as data importers.

9. Sub processors

9.1 Consent to hire a sub-processor. The Customer generally authorizes the hiring of any other third parties as Sub processors and authorizes the subsequent transfer of the Customer's Personal Data to any Subprocessors contracted by Enspace. If the Customer has entered into Standard Contractual Clauses as described in Section 8.2 (Data Transfers Outside the EEA), the above authorizations constitute the Customer's prior written consent to the outsourcing by Enspace of the processing of Customer Personal Data if such consent is required under the Standard Contractual Clauses.

9.2 Information about Sub processors. Information about Sub processors, including their functions and locations, is available at sales@be-enlighten.com (as may be updated periodically by Enspace in accordance with this Addendum).

9.3 Requirements for Sub Processor Involvement. When hiring any Subprocessor, Enspace will enter into a written contract with such Subprocessor containing data protection obligations no less protective than those in the Agreement (including this Addendum) with respect to the protection of Customer Personal Data to the extent applicable to the nature of the Services provided by such Subprocessor. Enspace will be responsible for all subcontracted obligations and for all acts and omissions of the Subprocessor.

9.4 Opportunity to contest changes to the Sub processor. When any new Subprocessor is hired during the Term, Enspace will, at least 30 days before the new Subprocessor processes any Customer Personal Data, notify the hiring by email (including the name and location of the relevant Subprocessor and the activities that it will carry out). To receive email notifications related to Sub Processor changes, the Customer can register using the portal found at sales@be-enlighten.com.

When any new Subprocessor is hired during the Term, Enspace will, at least 30 days before the new Subprocessor processes any Customer Personal Data, notify the Customer of the hiring (including the name and location of the relevant Subprocessor and the activities that it will carry out).

The Customer may object to any new Subprocessor by providing written notice to Enspace within ten (10) business days after being informed of the hiring of the Subprocessor as described above. Should the Customer object to a new Subprocessor, the Customer and Enspace will work together in good faith to find a mutually acceptable resolution to address such objection. If the parties are unable to reach a mutually acceptable resolution within a reasonable time, the Customer may, as its sole and exclusive remedy, terminate the Agreement upon written notice to Enspace.

10. Processing records

10.1 Enspace Processing Records. The customer acknowledges that Enspace is required by the GDPR to: (a) collect and keep records of certain information, including the name and contact details of each processor and/or controller on behalf of which Enspace is acting and, where applicable, of such processor or local representative of the controller and data protection officer; and (b) make this information available to supervisory authorities. Consequently, if the GDPR applies to the processing of Customer Personal Data, the Customer will, when requested, provide this information to Enspace and will ensure that all information provided is kept accurate and up to date.

11. Responsibility

11.1 Limitation of Liability The total combined liability of either party and its Affiliates with respect to the other party and its Affiliates, whether in contract, tort, or any other theory of liability, under or in connection with the Agreement, this Addendum, and the Standard Contractual Clauses if entered into as described in Section 8.2 (Data Transfers outside the EEA) combined will be limited to limitations of liability or other limits of liability agreed upon by the parties to the Agreement, subject to Section 11.2 (Exclusions of liability limit).

11.2 Limitation of Liability Exclusions. Nothing in Section 11.1 (Limit of Liability) will affect the liability of any party to data subjects under the provisions of third-party beneficiaries of the Standard Contractual Clauses to the extent that the limitation of such rights is prohibited by European Data Protection Legislation.

12. Analytics

The Customer acknowledges and agrees that Enspace may create and derive from the processing related to the Services anonymous and/or aggregated data that does not identify the Customer or any individual, and use, disclose, or share such data with third parties to improve Enspace products and services and for its other legitimate business purposes.

13. Advisories

Notwithstanding any provision to the contrary in the Agreement, any notifications required or permitted to be provided by Enspace to the Customer may be provided (a) in accordance with the notification clause of the Agreement; (b) to Enspace's main points of contact with the Customer; and/or (c) to any email provided by the Customer for the purpose of providing communications or alerts related to the Service. The customer is solely responsible for ensuring that such email addresses are valid.

14. Effect of these Terms

Notwithstanding anything to the contrary in the Agreement, to the extent of any conflict or inconsistency between this Addendum and the other terms of the Agreement, this Addendum will prevail.

Appendix 1

Subject and details of data processing

This Appendix 1 is incorporated into the Addendum and is also part of the Standard Contractual Clauses (if such Standard Contractual Clauses are applicable to the Customer).

Data importer

The Data Importer (or Service Provider/Processor) is Enspace, a productivity solutions provider.

Data exporter

The Data Exporter (or Company/Controller) is the Customer that is part of the Addendum.

subject

The provision of the Services to the Customer by Enspace, as set out in the Agreement and the Addendum.

Duration of Processing

The Term plus the period from the expiration of the Term to the deletion of all Customer Personal Data by Enspace in accordance with the Addendum.

Nature and Purpose of the Processing

Enspace will receive, process, and store Customer Personal Data for the purpose of providing the Services to the Customer in accordance with the Agreement and the Addendum, to communicate with the Customer and its end users, to provide customer service, to monitor, maintain, and improve the Services, and to otherwise fulfill its obligations under the Agreement. Enspace does not sell Customer Personal Data or Customer end user personal data and does not share that end user information with third parties for compensation or for those third parties' own business interests.

Personal Data Categories

First and last name, Title, Position, Employer, Contact information (company, email, telephone, physical business address) identification data, connection data, location data, Other electronic data sent, stored, sent, or received by an end user (which may include special categories of personal data in accordance with the GDPR or sensitive personal data in accordance with the LGPD, to the extent that such data is sent, stored, sent, or received by an end user; Enspace does not request or require any category sensitive or special personal data for the provision of the Services) Information related to invoices or payments made for the Enspace service. Usage Information.

Sensitive data

Enspace does not request or require any sensitive or special categories of personal data for the provision of the Services) Customer Personal Data. Sensitive data may, from time to time, be processed through the Services where the Customer or its end users choose to include sensitive data in communications transmitted using the Services or to upload sensitive data to the Services. The Customer is responsible for ensuring that appropriate protections are in place before transmitting or processing, or before allowing the Customer's end users to transmit or process any sensitive data through the Services.

Data subjects

Employees, agents, consultants, and/or freelancers of the Customer (who are individuals) and/or individuals about whom data is provided to Enspace through the Services by (or under the guidance of) the Customer/End Users authorized by the Customer to use the Services

Sub processors

The customer consents to sub-processing by the indicated entities.

Annex 2

Technical and Organizational Security Measures

As of the Effective Date of the Addendum, Enspace will implement and maintain the defined technical and organizational Security Measures.

Enspace may update or modify such Security Measures from time to time, provided that such updates and modifications do not materially diminish the overall security of the Services.

The following table provides more information about the technical and organizational security measures defined below:

Technical and Organizational Security Measure

See Data Privacy Policy.

Anonymization and encryption measures for personal data

See Data Privacy Policy.

Measures to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems and services

See Data Privacy Policy.

Measures to ensure the ability to restore availability and access to personal data in a timely manner in the event of a physical or technical incident

See Data Privacy Policy.

Processes for regularly testing, evaluating, and evaluating the effectiveness of technical and organizational measures to ensure processing security

See Data Privacy Policy.

Measures for user identification and authorization

See Data Privacy Policy.

Measures for data protection during transmission

See Data Privacy Policy.

Measures for data protection during storage

See Data Privacy Policy.

Measures to ensure the physical security of the places where personal data is processed

See Data Privacy Policy.

Measures to ensure the registration of events

See Data Privacy Policy.

Measures to ensure system configuration, including default configuration

See Data Privacy Policy.

Measures for governance and internal management of IT and IT security

See Data Privacy Policy.

Certification/guarantee measures for processes and products

See Data Privacy Policy.

Measures to ensure data minimization

See Data Privacy Policy.

Measures to ensure data quality

See Data Privacy Policy.

Measures to ensure accountability

See Data Privacy Policy.

Measures to allow data portability and ensure erasure

See Data Privacy Policy.

Technical and organizational measures to be taken by the (sub) processor to provide assistance to the controller and, for transfers from a processor to a (sub) processor, to the Customer.

When Enspace contracts with a Subprocessor, Enspace and the Subprocessor enter into an agreement with data protection obligations substantially similar to those contained in this Addendum. Each Sub Processor Agreement must ensure that Enspace is able to fulfill its obligations to the Customer. In addition to implementing technical and organizational measures to protect personal data, Subprocessors must (a) notify Enspace in the event of a Security Incident so that Enspace can notify the Customer; (b) delete personal data when instructed by Enspace in accordance with the Customer's instructions to Enspace; (c) not hire additional Sub processors without Enspace's authorization; (d) not change the location where the personal data is processed;

Annex 3

Cross-border data transfer solutions

1. Definitions

For the purposes of the Clauses:

For the purposes of this Addendum, the terms below shall have the meanings set forth below. Capitalized terms used but not otherwise defined in this Addendum shall have the meanings set forth in the Agreement.

1.1 “Standard Contractual Clauses” means, depending on the Customer's unique circumstances, any of the following:

1.1.1 UK International Data Transfer Addendum, or;

1.1.2 EU Standard Contractual Clauses 2021 (“EU CECs”).

1.2 “UK International Data Transfer Addendum” means: the UK International Data Transfer Addendum (“IDTA”) to the EU Commission's Standard Contractual Clauses (“EU SCCs”) (Version B1.0) issued by the UK Information Commissioner for Parties making Transfers (which may be amended, updated, or replaced from time to time).

1.3 “2021 Standard Contractual Clauses” means the Standard Contractual Clauses approved by the European Commission in decision 2021/914.

2. Cross-border data transfer solutions

2.1 Order of Precedence. If the Services are covered by more than one Transfer Solution, the transfer of personal data will be subject to a single Transfer Solution in accordance with the following order of precedence: (a) the applicable Standard Contractual Clauses, as set out in Section 2.2 (UK Standard Contractual Clauses) or Section 2.3 (The 2021 Standard Contractual Clauses) of this Appendix 3; and, if neither (a) nor (b) are applicable, then (c) other Data Transfer Solutions permitted by applicable Global Data Protection Legislation.

2.2 2021 Standard Contractual Clauses. The parties agree that the 2021 Standard Contractual Clauses will apply to personal data transferred through the European Economic Area Services, directly or through a subsequent transfer, to any country or recipient outside the European Economic Area that is not recognized by the Commission as providing an adequate level of personal data protection. For data transfers from the European Economic Area that are subject to the 2021 Standard Contractual Clauses, the 2021 Standard Contractual Clauses will be considered concluded (and incorporated into this Addendum by this reference) and completed as follows:

2.2.1 Module Two (Controller to Processor) of the 2021 Standard Contractual Clauses will apply when the Customer is the controller of the Customer's Personal Data and Enspace is processing the Customer's Personal Data.

2.2.2 Module Three (Processor to Processor) of the 2021 Standard Contractual Clauses will apply when the Customer is a processor of Customer Personal Data and Enspace is processing Customer Personal Data.

2.2.3 For each Module, where applicable:

(a) in Clause 7 of the 2021 Standard Contractual Clauses, the optional anchor clause will not apply;
(b) in Clause 9 of the 2021 Standard Contractual Clauses, Option 2 “General Written Authorization” will apply and the period for prior notification of changes to the Subprocessor will be as set out in Section 9 (Subprocessors) of this Addendum;
(c) in Clause 11 of the 2021 Standard Contractual Clauses, the optional language will not apply;
(d) in Clause 17 (Option 1), the 2021 Standard Contractual Clauses will be governed by Irish law;
(e) in Clause 18 (b) of the 2021 Standard Contractual Clauses, disputes will be resolved before the courts of Ireland;
(f) in Annex I, Part A (List of Parties) of the 2021 Standard Contractual Clauses:
(i) Data Exporter: Customer.
(ii) Contact Details: The email address (s) designated by the Customer in the Customer's account through their notification preferences.
(iii) Role of the Data Exporter: The role of the Data Exporter is defined in Section 3.1 (Functions and Regulatory Compliance; Authorization) of this Addendum. The parties acknowledge and agree that, with respect to the processing of Customer Personal Data, the Customer may act as a controller or processor and Enspace is a processor. Enspace will process Customer Personal Data in accordance with Customer Instructions as set forth in Section 3.2.1.
(iv) Signature and Date: By entering into the Contract, the Data Exporter is considered to have signed these Standard Contractual Clauses incorporated herein, including their Annexes, as of the effective date of the Contract.
(v) Data importer: The Enlighten Company S/A dbo Enspace.
(vi) Address: 350 Tenth Ave Suite 500, San Diego, CA 92101
(vii) Contact Details: Enspace Data Security Team — data@enspace.io
(viii) Role of the Data Importer: The parties acknowledge and agree that, with respect to the processing of Customer Personal Data, the Customer may act as a controller or processor and Enspace is a processor. Enspace will process Customer Personal Data in accordance with Customer Instructions.
(xi) Signature and Date: When entering into the Contract, the Data Importer is considered to have signed these Standard Contractual Clauses, including their Annexes, as of the Effective Date of the Contract.
(g) in Annex I, Part B (Transfer Description) of the 2021 Standard Contractual Clauses:
(i) The categories of data subjects are described in the “Data Subject” Section of Appendix 1 (Object and Details of Data Processing) of this Addendum.
(ii) The categories of personal data transferred are described in the “Categories of Personal Data” Section of Appendix 1 (Subject and Details of Data Processing) of this Addendum.
(iii) The transferred Sensitive Data is described in the “Sensitive Data” Section of Appendix 1 (Subject and Details of Data Processing) to this Addendum.
(iv) Signature and Date: By entering into the Contract, the Data Exporter is considered to have signed these Standard Contractual Clauses incorporated herein, including their Annexes, as of the effective date of the Contract.
(v) The nature of the processing is described in the “Nature and Purpose of the Processing” Section of Appendix 1 (Subject and Details of Data Processing) to this Addendum.
(vi) The purpose of the processing is described in the “Nature and Purpose of the Processing” Section of Appendix 1 (Subject and Details of Data Processing) to this Addendum.
(vii) The period for which the personal data will be retained and the criteria used to determine this period are as follows: Prior to the termination of the Agreement, Enspace will process the stored Customer Personal Data for the permitted purposes set out in Section 3.1.1. (Customer Instructions) until the Customer chooses to delete or request the return of such Customer Personal Data in accordance with section 4 of the Addendum. Prior to the termination of the Contract, the Customer agrees that it is solely responsible for deleting the Customer's Personal Data through the Services. Upon termination of the Agreement, Enspace will (i) provide the Customer thirty (30) days after the effective date of termination to obtain a copy of any Customer Personal Data stored through the Services and (ii) delete any Customer Personal Data stored within thirty (30) days upon the customer's request, unless alternative deadlines for retention and/or deletion are otherwise established in the Agreement or later agreed upon by the parties in writing. Any customer personal data archived on Enspace's backup systems will be securely isolated and protected from any further processing, except as required by applicable law or regulation.
(h) in Annex I, Part C of the 2021 Standard Contractual Clauses: The Irish Data Protection Commission will be the competent supervisory authority.
(i) Appendix 2 (Technical and Organizational Security Measures) of this Amendment serves as Annex II of the Standard Contractual Clauses.

2.3 Data transfers from Switzerland. With respect to any transfer of personal data outside of Switzerland or of Personal Data governed by the Swiss Federal Data Protection Act (“FADP”) (and the revised FADP (“RevFADP”), when in effect), to a third country (without an appropriateness decision or equivalent issued by the European Commission or competent authority in Switzerland), the Parties agree that the EU SCCs in this Addendum must apply, subject to the following terms and conditions:

A. References: The terms “General Data Protection Regulation” or “Regulation (EU) 2016/679” as used in EU SCCs should be interpreted to include FADP and, where applicable, RevFADP.
B. Clause 13: To the extent that the transfer of Personal Data is subject only to the FADP/RevFADP, the Swiss Federal Data Protection and Information Commissioner (FDPIC) is the exclusive supervisory authority. To the extent that the transfer of Personal Data is governed by the GDPR and the FADP/RevFADP, the competent supervisory authority with parallel supervision (in accordance with Annex IC of the EU SCCs) is the FDPIC and to the extent that the transfer is governed by the GDPR, the criteria of Clause 13 (a) must be observed for the selection of the competent authority.
C. Clause 17: EU SCCs will be governed by Swiss law, if the transfer is subject exclusively to the FADP/RevFADP or, in other cases, to the law of one of the EU Member States, provided that the law of the member state allows third parties - rights of the party's beneficiary.
D. Clause 18 (b): Any dispute arising from EU SCCs will be resolved by the courts of Switzerland, if the transfer is subject exclusively to the FADP/RevFADP or to an EU Member State in other cases.
E. Clause 18 (c): The term “Member State” should not be interpreted to exclude data subjects in Switzerland from the possibility of claiming their rights at their place of usual residence (Switzerland) in accordance with Clause 18 (c) of the EU SCCs.
F. RevFADP: EU SCCs will protect legal entities' data until RevFADP comes into force.

2.4 UK International Data Transfer Addendum. The parties agree that the UK International Data Transfer Addendum will apply to personal data transferred through the UK Services, directly or by subsequent transfer, to any country or recipient outside the UK that is not recognized by the competent UK regulatory authority or UK government body as providing an adequate level of protection for personal data. For UK data transfers subject to the UK International Data Transfer Addendum, the UK International Data Transfer Addendum will be considered concluded (and incorporated into this Addendum by this reference) and completed as follows:

Part 1:
1) Table 1: Parts
one. The Start Date is the date of the last signature of the Parties to this Amendment or Agreement.
b. The Parties are defined in Annex IA of the EU SCCs to which this IDTA is attached.
2) Table 2: SCCs selected, modules, and clauses selected
one. EU SCC Addendum
Me. The version of the approved EU SCCs to which this IDTA is attached, including the information in the appendix, applies.
3) Table 3: Appendix Information
one. Annex 1A: List of Parties
Me. The Parties are defined in Annex IA of the EU SCCs to which this IDTA is attached.
b. Annex 1B: Description of the Transfer
Me. The Transfer Description is set out in Annex IB of the EU SCCs to which this IDTA is attached.
c. Annex II: Technical and organizational measures, including technical and organizational measures to ensure data security
Me. Technical and organizational measures are defined in Annex II of the EU SCCs to which this IDTA is attached.
c. Annex III: List of Subprocessors:
Me. Not applicable.
4) Table 4: Closing of this Addendum when the Approved Addendum Changes:
one. The Exporter and the Importer may terminate this IDTA as set forth in Section 19 of the IDTA.


Part 2:
Part 2 of the IDTA is incorporated here by reference.

2.5 Conflict. To the extent that there is any direct conflict between the Standard Contractual Clauses and any other terms of this Addendum, the Agreement, or the Privacy Policy, the provisions of the Standard Contractual Clauses will prevail.