This Data Processing Addendum ("DPA") forms part of the Agreement between Customer and Efficiently, LLC ("Efficiently"). For purposes of applicable Data Protection Law, Customer acts as the controller or business (or as processor or service provider on behalf of a third-party controller or business, as applicable), and Efficiently acts as a processor or service provider solely with respect to Personal Data that Customer submits to the Services for Processing on Customer’s behalf ("DPA Data"). This DPA does not apply to Account Data, Operational Metrics, deidentified data, aggregated data, or information that Efficiently processes as an independent controller under Section 1.
1. Roles and Scope
Efficiently shall Process DPA Data only in accordance with Customer's documented Instructions, the terms of the Agreement, and applicable Data Protection Law ("DP Law”), in each case as applicable to Efficiently in its role as processor or service provider. Efficiently shall not Process DPA Data for any purpose other than as necessary to provide, secure, support, and improve the Services, fulfill its obligations under the Agreement, comply with Customer’s Instructions, or as otherwise permitted by applicable Data Protection Law.
The subject matter and nature of the Processing is the provision of the Services, including SaaS platform and website access, account administration, support, integrations, and related processing initiated by Customer or its Users; the purpose of the Processing is the performance of Efficiently’s obligations under the Agreement and as described in the Documentation; the duration of the Processing is the applicable Project Term(s), together with any period thereafter reasonably necessary for deletion or return of DPA Data in accordance with Section 11; and the categories of DPA Data and of data subjects are those contained in the Customer Data, communications, content, and other materials that Customer or its Users submit to the Services.
As between the parties, all DPA Data remains the property of Customer. Efficiently acquires no rights or interest in DPA Data except the limited rights necessary to provide, secure, support, maintain, and improve the Services; perform its obligations under the Agreement and this DPA; comply with applicable law; and exercise rights expressly reserved under this DPA.
Efficiently acts as an independent controller, and not as a processor on Customer’s behalf, with respect to data concerning its own business relationship with Customer. This data is limited to (a) account, billing, and contact information relating to Customer and its authorized users and administrators (“Account Data”), and (b) Operational Metrics and other telemetry, logs, and usage data generated through the provision and operation of the Services. It does not include the contents of DPA Data.
Efficiently processes Account Data and Operational Metrics as a controller solely to (i) provide, secure, optimize, and maintain the Services; (ii) invoice and manage Customer’s account; (iii) detect, prevent, and investigate fraud, security incidents, and misuse; (iv) comply with its legal and regulatory obligations; and (v) other purposes permitted under applicable Data Protection Law. This Processing is governed by Efficiently’s Privacy Notice and not by the controller-to-processor terms of this DPA. Efficiently shall not use Account Data or Operational Metrics for user profiling, advertising, or the sale or brokering of Personal Data.
Efficiently may create, use, disclose, and retain data derived from DPA Data, Account Data, or Operational Metrics that has been deidentified, anonymized, or aggregated so that it does not identify Customer, any User, or any data subject, for analytics, benchmarking, product improvement, security, support, and other lawful business purposes. Efficiently shall not attempt to reidentify such data except as permitted by applicable Data Protection Law.
2. Certain Defined Terms
The following terms, when capitalized in this DPA, have the meanings set forth below. Capitalized terms used but not defined in this DPA shall have the meanings set forth in the Agreement.
“Account Data” has the meaning set forth in Section 1.
“Data Protection Law” or “DP Law” means all applicable laws and regulations relating to the processing of Personal Data, including the GDPR, UK GDPR, FADP, CCPA/CPRA, and other U.S. state privacy laws.
“DPA Data” means Personal Data that Customer submits to the Services for Processing by Efficiently, as described in the Agreement and this DPA.
“Instructions” means the documented instructions provided by Customer to Efficiently regarding the Processing of DPA Data, as set forth in Section 3 of this DPA.
“Personal Data” means any information relating to an identified or identifiable natural person, and includes “personal information” or any equivalent term as defined under applicable Data Protection Law.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to DPA Data. A Personal Data Breach does not include unsuccessful attempts or activities that do not compromise the security of DPA Data, including unsuccessful log-in attempts, pings, port scans, denial-of-service attacks, and other network attacks on firewalls or networked systems.
“Processing” or “Process” means any operation performed on DPA Data, including the collection, organization, recording, storage, adaptation, retrieval, use, disclosure, erasure, or destruction of such DPA Data.
“Standard Contractual Clauses” means (a) the European Union Standard Contractual Clauses, (b) the UK International Data Transfer Addendum, and (c) the European Economic Area Standard Contractual Clauses as adapted for transfers subject to the Swiss Federal Act on Data Protection, in each case as set out in Annex IV.
“Sub-processor” means a third party engaged by Efficiently to Process DPA Data on behalf of Customer.
3. Customer Instructions
The Agreement (including this DPA), the Documentation, Customer's use and configuration of the Services, and Customer’s submission of DPA Data constitute Customer's complete and documented Instructions to Efficiently for the Processing of DPA Data ("Instructions"). Customer is responsible for ensuring that its Instructions comply with applicable Data Protection Law and that Efficiently’s Processing in accordance with those Instructions is lawful. Efficiently shall Process DPA Data only in accordance with such Instructions unless required to do otherwise by applicable law, in which case Efficiently shall inform Customer of that legal requirement before Processing unless prohibited by law from doing so.
If Efficiently reasonably believes that an Instruction from Customer infringes applicable Data Protection Law, Efficiently shall promptly notify Customer and may suspend or decline the infringing Instruction until Customer has confirmed, withdrawn, or modified it. Efficiently is not responsible for assessing the lawfulness of Customer’s Instructions except to the extent required of a processor under applicable Data Protection Law.
4. Confidentiality of Personnel
Efficiently shall ensure that all personnel authorized to Process DPA Data are bound by appropriate confidentiality obligations, whether by contract or by operation of law. Such obligations shall survive the termination of the individual's engagement with Efficiently.
5. Security
Efficiently shall implement and maintain the technical and organizational security measures described in the Information Security Addendum to the Agreement. Such measures are designed to protect DPA Data against unauthorized or unlawful Processing, accidental loss, destruction, or damage, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing. Efficiently may update or modify those measures from time to time, provided that such updates do not materially decrease the overall security of the Services during the applicable Project Term.
6. Subprocessors
Customer grants Efficiently general written authorization to engage Sub-processors for the Processing of DPA Data. The current list of authorized Sub-processors is available at:
https://efficiently.com/legal
Efficiently shall provide notice of any intended addition or replacement of a Sub-processor by updating its Sub-processor list or by other reasonable means. Except where a shorter period is necessary to address security, availability, legal, or operational needs, Efficiently shall provide such notice at least 15 days before the Sub-processor Processes DPA Data. Customer may object to a new or replacement Sub-processor by notifying Efficiently in writing within 10 days of such notice, provided that the objection is based on reasonable and documented data protection grounds.
If Customer objects, Efficiently shall use commercially reasonable efforts to make available a change in the Services or recommend a commercially reasonable alternative to avoid the Processing of DPA Data by the objected-to Sub-processor. If Efficiently is unable to provide such an alternative within a reasonable period, Customer may terminate the applicable Order Form or the Agreement with respect to the affected Services as Customer’s sole and exclusive remedy, and any refund will be determined in accordance with the Agreement.
Efficiently shall impose contractual obligations on each Sub-processor that are no less protective than the terms of this DPA with respect to the protection of DPA Data. Subject to the exclusions, waivers, and limitations of liability in the Agreement, Efficiently shall be responsible for the acts and omissions of its Sub-processors to the same extent it would be responsible if performing the relevant Processing directly.
7. Data Subject Requests
If Efficiently receives a request from a data subject relating to DPA Data, Efficiently shall, to the extent legally permitted and where the request identifies Customer, advise the data subject to submit the request directly to Customer, and Customer shall be solely responsible for responding to the request.
Taking into account the nature of the Processing, Efficiently shall provide Customer with reasonable assistance through the Services’ available functionality and, where required by applicable Data Protection Law, other appropriate technical and organizational measures reasonably available to Efficiently, to help Customer fulfill its obligations to respond to data subject requests. Efficiently is not required to locate, retrieve, modify, delete, or provide DPA Data except to the extent Customer cannot reasonably do so through the Services, and Customer shall reimburse Efficiently for reasonable, documented costs for assistance outside the standard functionality of the Services.
8. Personal Data Breach
Efficiently shall notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting DPA Data, as required by applicable Data Protection Law. The notification may be provided in phases and shall include, to the extent reasonably available to Efficiently at the time of notification:
- A general description of the nature of the Personal Data Breach, including, where known, the categories and approximate number of data subjects and records concerned;
- The name and contact details of Efficiently's data protection point of contact;
- A description of the known or reasonably anticipated consequences of the Personal Data Breach;
- A description of the measures taken or proposed to be taken to address the Personal Data Breach, including measures to mitigate its possible adverse effects.
Efficiently shall provide reasonable cooperation and additional information reasonably available to Efficiently to assist Customer in fulfilling breach notification obligations under applicable Data Protection Law. Customer is responsible for determining whether notice to data subjects, regulators, or other third parties is required, and Efficiently shall not be obligated to provide notices on Customer’s behalf unless expressly agreed in writing.
Efficiently’s notification of, or response to, a Personal Data Breach under this Section shall not be construed as an acknowledgement by Efficiently of any fault or liability with respect to the Personal Data Breach.
9. Data Protection Impact Assessments
Efficiently shall provide Customer with reasonable assistance in connection with data protection impact assessments ("DPIAs") and prior consultations with supervisory authorities, solely to the extent required under applicable Data Protection Law, taking into account the nature of the Processing and the information available to Efficiently. Customer shall be responsible for conducting any DPIA and prior consultation and shall reimburse Efficiently for reasonable, documented costs for assistance beyond the standard functionality or documentation of the Services.
10. Audits
Efficiently shall make available to Customer audit reports, certifications, and other documentation as described in the Information Security Addendum to demonstrate compliance with the obligations set forth in this DPA. Such reports and certifications shall be treated as Confidential Information of Efficiently.
If the audit reports, certifications, and other documentation made available by Efficiently under this Section are not sufficient to demonstrate Efficiently’s compliance with this DPA or applicable Data Protection Law, Efficiently shall make available additional information reasonably necessary to demonstrate such compliance. Any audit must be conducted by Customer or an independent, accredited third-party auditor that is not a competitor of Efficiently and is bound by confidentiality obligations reasonably acceptable to Efficiently, and must be (a) conducted no more than once per calendar year, except as required by a supervisory authority or following a confirmed Personal Data Breach affecting DPA Data; (b) conducted remotely unless an on-site audit is required by applicable Data Protection Law or a supervisory authority; (c) conducted on at least 30 days’ prior written notice, during regular business hours, and in a manner that does not unreasonably disrupt Efficiently’s operations; (d) limited to information, systems, and facilities relevant to the Processing of DPA Data; (e) designed to exclude other customers’ data, source code, trade secrets, vulnerability information, and Efficiently’s confidential information not relevant to the audit; and (f) at Customer’s expense. Customer shall promptly share with Efficiently the results of any such audit.
11. Deletion or Return
Upon termination or expiration of the Agreement, Customer shall have a period of 30 days to export DPA Data from the Platform using the Platform’s standard export functionality. Efficiently has no obligation to provide custom export tools, convert data to a non-standard format, or retain DPA Data after the export period except as expressly required by this DPA or applicable law.
Following expiration of the 30-day export period, Efficiently shall delete DPA Data in its possession or control within 90 days in accordance with its standard deletion procedures, except to the extent that applicable law requires further retention. DPA Data stored in backups, archives, logs, or disaster recovery systems may be retained until overwritten or deleted in the ordinary course, provided that Efficiently maintains the confidentiality and security of such data and does not actively Process it except as necessary for backup, recovery, security, or legal compliance. Efficiently shall certify deletion upon Customer's written request where required by applicable Data Protection Law.
Notwithstanding the foregoing, Efficiently may retain DPA Data to the extent required by applicable law, for legitimate recordkeeping or evidence purposes, or pursuant to a litigation hold under the Records Custodian and Litigation Hold Policy, provided that Efficiently shall (i) limit such retention to the minimum scope reasonably required, (ii) maintain the confidentiality and security of such data, and (iii) delete the data once the retention requirement has expired.
The deletion and return obligations in this Section do not apply to Account Data, Operational Metrics, or deidentified, anonymized, or aggregated data that Efficiently may retain and use in accordance with this DPA and applicable Data Protection Law.
12. Limits on Submission
Customer shall submit DPA Data to Efficiently only through the mechanisms agreed upon in the Agreement and Documentation. Customer shall not include DPA Data in support tickets, emails to Efficiently's support or sales teams, website forms, or other communication channels that are not specifically designated for the Processing of DPA Data.
Customer shall not submit, and Efficiently has no obligation to Process, any payment card information subject to PCI-DSS, protected health information as defined under HIPAA, special categories of Personal Data or biometric identifiers under applicable law, or other Sensitive Data, unless expressly identified and agreed to in an Order Form or an addendum to this DPA executed by the parties. If Efficiently determines that prohibited data has been submitted, Efficiently may suspend Processing of, or delete, such data upon notice to Customer, and Customer shall cooperate promptly to remediate.
Customer is responsible for establishing a lawful basis for, providing any notices, and obtaining any consents or authorizations required in connection with the Personal Data it submits to the Services, including Personal Data contained in third-party communications ingested through the Project Mailbox or otherwise made available through SaaS or website access. Customer is responsible for the accuracy, quality, legality, and minimization of DPA Data and for configuring the Services, managing User access, and using the Services in compliance with applicable Data Protection Law.
13. Cross-Border Data Transfers
DPA Data is stored and processed in the United States by default, and Customer authorizes Efficiently and its Sub-processors to Process DPA Data in the United States and other jurisdictions in which Efficiently or its Sub-processors maintain operations, subject to this DPA. To the extent that the Processing of DPA Data involves a transfer from a jurisdiction that restricts cross-border transfers of Personal Data, and Efficiently is the data importer for that transfer, the applicable cross-border transfer mechanism set forth in Annex IV shall apply.
14. No Training; No Selling or Sharing
Efficiently shall not use DPA Data for the purposes of training artificial intelligence or machine learning models for general commercial release, whether for Efficiently's own products or for the benefit of any third party, except to the extent Customer expressly authorizes such use in writing. This restriction does not limit Efficiently’s right to use deidentified, anonymized, or aggregated data in accordance with this DPA and applicable Data Protection Law.
Efficiently shall require Sub-processors to Process DPA Data only as necessary for the provision of the Services, as otherwise permitted by this DPA, or as required by applicable law. Sub-processors may retain transient, backup, log, or security copies of DPA Data only in accordance with their applicable retention, security, and deletion practices and the contractual obligations imposed by Efficiently.
To the extent that Efficiently is deemed a "service provider" under applicable U.S. state privacy laws (including the California Consumer Privacy Act, as amended by the California Privacy Rights Act), Efficiently shall not “sell” or “share” DPA Data, as those terms are defined under applicable law.
15. CCPA/CPRA Service Provider Terms
To the extent that Efficiently Processes DPA Data that constitutes "personal information" as defined under California Civil Code Section 1798.140, Efficiently acts as a "service provider" and/or “contractor” as those terms are defined in Cal. Civ. Code §1798.140. Efficiently shall:
- Process such personal information only for the business purposes specified in the Agreement;
- Not sell or share (as defined under the CCPA/CPRA) such personal information;
- Not retain, use, or disclose such personal information outside of the direct business relationship with Customer except as permitted by the CCPA/CPRA and this DPA;
- Not combine such personal information with personal information received from other sources, except as permitted by the CCPA/CPRA, including to detect security incidents, protect against fraudulent or illegal activity, or provide the Services;
- Comply with applicable service provider and contractor obligations under the CCPA/CPRA and provide the level of privacy protection required of service providers and contractors under the CCPA/CPRA.
Customer may take reasonable and appropriate steps, through the audit and documentation rights in this DPA, to ensure that Efficiently uses DPA Data in a manner consistent with Customer's obligations under the CCPA/CPRA.
Efficiently shall notify Customer if Efficiently determines that it can no longer comply with its applicable service provider or contractor obligations under the CCPA/CPRA with respect to its Processing of DPA Data. Following such notice, Customer may take reasonable and appropriate steps, through the mechanisms set forth in this DPA and the Agreement, to stop and remediate any unauthorized use of DPA Data.
16. Recordkeeping
Efficiently shall maintain records of its Processing of DPA Data carried out on behalf of Customer to the extent required of a processor under applicable Data Protection Law, including the categories of Processing, the categories of DPA Data and data subjects, any cross-border transfers of DPA Data, and a general description of the technical and organizational security measures implemented. Upon Customer’s reasonable written request, and no more than once per twelve (12) month period except as required by applicable Data Protection Law or a supervisory authority, Efficiently shall make available to Customer the information in such records that is reasonably necessary to demonstrate Efficiently’s compliance with this DPA. Any reasonable costs incurred by Efficiently in compiling or providing such records shall be borne by Customer unless otherwise required by applicable Data Protection Law.
17. Cooperation; Government and Third-Party Requests
If Efficiently receives any subpoena, warrant, court order, or other request or demand from a third party (including any government, law-enforcement, or regulatory authority) for the disclosure of DPA Data, Efficiently shall, unless legally prohibited, (a) promptly notify Customer of the request and, where possible, redirect the requesting party to Customer; (b) disclose only the DPA Data that Efficiently reasonably determines it is legally required to disclose; and (c) provide Customer with reasonable cooperation, at Customer’s expense, to enable Customer to seek a protective order or other appropriate remedy. Efficiently shall not knowingly disclose DPA Data to any law-enforcement or government authority except as required by applicable law or valid legal process.
18. Limitation of Liability
Each party’s aggregate liability arising out of or related to this DPA, including Annex IV and the Standard Contractual Clauses, is subject to and counts toward the exclusions, waivers, and limitations of liability, including the liability caps, set forth in the Agreement. This DPA does not create any separate or additional liability cap, and any claim arising out of or related to this DPA may be brought only by the Customer entity that is a party to the Agreement. Nothing in this DPA limits any liability owed directly to a data subject under applicable Data Protection Law or under the Standard Contractual Clauses to the extent such limitation is not permitted by applicable law. Without limiting the foregoing, Efficiently shall have no liability under this DPA for a Personal Data Breach or violation of Data Protection Law to the extent it results from the acts, omissions, Instructions, systems, data, or configurations of Customer, its Users, or third parties acting on Customer’s behalf.
19. Order of Precedence
This DPA forms part of and supplements the Agreement. Notwithstanding any order of precedence set forth in the Agreement or any Order Form, in the event of any conflict or inconsistency solely with respect to the Processing of DPA Data, the following order of precedence shall control: (a) the Standard Contractual Clauses and Annex IV, with respect to cross-border data transfers; and (b) this DPA. For clarity, the Agreement controls with respect to commercial terms, fees, payment, ownership, disclaimers, exclusions, and limitations of liability, except to the extent expressly modified by this DPA or prohibited by applicable Data Protection Law.
20. Future Regulations
The parties acknowledge that data protection laws continue to evolve. If new or amended Data Protection Law materially affects the Processing of DPA Data under this DPA, the parties shall:
- Review the impact of such changes in good faith;
- Negotiate in good faith any amendments to this DPA that may be necessary to ensure continued compliance; and
- If the parties are unable to agree on necessary amendments within a reasonable period, or if compliance becomes unlawful or commercially infeasible, either party may terminate the affected portions of the Agreement upon written notice.
Annex I — Details of Processing
This Annex I sets out the details of Processing and constitutes the List of Parties and Description of the Transfer for purposes of the European Economic Area Standard Contractual Clauses ("EEA SCCs") and The UK International Data Transfer Addendum ("UK IDTA").
List of Parties
Data Exporter: The Customer under the Agreement, acting in its capacity as controller (or processor, as applicable) of DPA Data.
Data Importer: Efficiently, acting in its capacity as processor (or sub-processor, as applicable) of DPA Data on behalf of the data exporter.
Efficiently, LLC,
12 Penny Lane, Gallatin Gateway, MT 59730
Contact: success@efficiently.com
Description of the Transfer
The subject matter, nature, purpose, duration, categories of data subjects, and types of Personal Data are as described in this DPA and the Agreement.
Categories of data subjects: Customer’s personnel and authorized users; individuals who access or interact with the Services, SaaS platform, website, or Project Mailbox at Customer’s direction; and individuals whose Personal Data is contained in the communications and content Customer submits to the Services, including Customer’s employees, contractors, subcontractors, design professionals, vendors, and other project stakeholders.
Categories of Personal Data: names, business contact information, job titles and roles, login and usage information associated with authorized access, and any other Personal Data contained in emails, meeting recordings, documents, and other communications and content that Customer submits to the Services.
Special categories of Personal Data: None. Customer shall not submit special categories of Personal Data, as set out in the Limits on Submission section of this DPA.
Frequency of the transfer: Continuous, for the duration of the Project Term.
Nature and purpose of the Processing: Processing necessary to provide the Services and perform Efficiently’s obligations under the Agreement, as further described in the Roles and Scope section of this DPA.
Duration of the Processing: the applicable Project Term(s), together with any period thereafter until deletion or return of DPA Data in accordance with the Deletion or Return section of this DPA.
Competent supervisory authority: Determined in accordance with Clause 13 of the EEA SCCs; for transfers subject to the UK GDPR, the UK Information Commissioner’s Office.
Annex II — Security Measures
The technical and organizational security measures implemented by Efficiently, as Data Importer, are set out in the Information Security Addendum to the Agreement, which is incorporated into this DPA by reference and constitutes the Technical and Organizational Measures for purposes of the EEA SCCs and the UK IDTA.
Annex III — Subprocessors
Customer authorizes the Sub-processors made available at https://efficiently.com/legal as updated from time to time, which constitutes the list of Sub-processors for purposes of the EEA SCCs and the UK IDTA. Each Sub-processor’s name, the Processing service it performs, and its location are identified in that list. Additions or replacements of Sub-processors are subject to the notice and objection process set out in Section 6 of this DPA.
Annex IV — International Transfer Terms
This Annex IV governs the Processing of DPA Data when such Processing involves a transfer of Personal Data from one jurisdiction to another and a lawful transfer mechanism is required under applicable Data Protection Law. Capitalized terms not defined in this Annex IV have the meanings set forth in this DPA or the Agreement. In the event of any conflict between this Annex IV and the body of this DPA, this Annex IV shall control with respect to cross-border data transfers.
1. Order of Precedence
Where multiple transfer mechanisms apply to a particular transfer of DPA Data, the following order of precedence shall govern:
(a) The EU–U.S. Data Privacy Framework (including the UK Extension and the Swiss–U.S. Data Privacy Framework), to the extent Efficiently participates in and may lawfully rely on the applicable framework for the transfer;
(b) The UK International Data Transfer Addendum ("UK IDTA");
(c) The European Economic Area Standard Contractual Clauses ("EEA SCCs"); and
(d) Any other valid transfer mechanism recognized under applicable Data Protection Law.
For the avoidance of doubt, a higher-priority mechanism shall take precedence to the extent it provides a lawful basis for the transfer, but shall not invalidate the applicability of a lower-priority mechanism where the higher-priority mechanism does not cover the transfer in question.
2. Data Privacy Framework
To the extent Efficiently maintains an active self-certification under the EU–U.S. Data Privacy Framework, the UK Extension to the EU–U.S. Data Privacy Framework, and/or the Swiss–U.S. Data Privacy Framework, as administered by the U.S. Department of Commerce, Efficiently may rely on the applicable Data Privacy Framework for transfers covered by that certification.
Efficiently shall comply with the applicable Data Privacy Framework Principles with respect to DPA Data received from the European Economic Area, the United Kingdom, or Switzerland in reliance on the applicable Data Privacy Framework.
If Efficiently's self-certification under any Data Privacy Framework is not available, withdrawn, lapsed, or otherwise invalidated for a relevant transfer, Efficiently shall use an alternative lawful transfer mechanism, including the Standard Contractual Clauses where applicable.
3. EU Standard Contractual Clauses (Modules 2 and 3)
To the extent that a transfer of DPA Data from the European Economic Area is not covered by the Data Privacy Framework or another valid transfer mechanism, the parties agree that the EEA SCCs (Commission Implementing Decision (EU) 2021/914) are hereby incorporated by reference and shall apply under Module 2 (Controller to Processor) where Customer acts as the data exporter and controller, or Module 3 (Processor to Processor) where Customer acts as the data exporter and processor, and Efficiently acts as the data importer and processor or sub-processor, as applicable.
The following clause-specific elections apply:
- Clause 7 (Docking Clause): The optional docking clause shall not apply.
- Clause 9 (Use of Sub-processors): Option 2 (General Written Authorization) applies. Efficiently shall provide Customer with notice of intended additions or replacements of Sub-processors as set forth in Section 6 of this DPA.
- Clause 11(a) (Independent Dispute Resolution Body): The optional provision shall not be used.
- Clause 17 (Governing Law): Option 1 applies. The EEA SCCs shall be governed by the laws of Ireland.
- Clause 18(b) (Choice of Forum and Jurisdiction): Any disputes arising under the EEA SCCs shall be resolved before the courts of Ireland.
4. Appendix to the EEA SCCs (Modules 2 and 3)
The information required by the Appendix to the EEA SCCs is set out in Annex I (Details of Processing, including the List of Parties and Description of the Transfer), Annex II (Security Measures), and Annex III (Subprocessors) to this DPA.
5. UK International Data Transfer Addendum
To the extent that a transfer of DPA Data from the United Kingdom is not covered by the Data Privacy Framework or another valid transfer mechanism, the UK IDTA, as issued by the UK Information Commissioner under Section 119A of the Data Protection Act 2018, is hereby incorporated by reference.
Part 1: Tables
Table 1 (Parties): The parties are as identified in Annex I above. The parties are deemed to have signed the UK IDTA by their use of the Services.
Table 2 (Selected SCCs, Modules, and Selected Clauses): The EEA SCCs as set out in Section 3 of this Annex above, including the Module 2 and Module 3 selections where applicable, form the Approved EU SCCs for purposes of the UK IDTA.
Table 3 (Appendix Information): As set forth in Annex I, Annex II, and Annex III above.
Table 4 (Ending the UK IDTA): Neither party may end the UK IDTA in accordance with Section 19 of the UK IDTA.
Part 2: Mandatory Clauses
Part 2 of the UK IDTA is incorporated without modification.
6. Personal Data Transfers from Switzerland
To the extent that a transfer of DPA Data is subject to the Swiss Federal Act on Data Protection ("FADP"), the EEA SCCs as set out in Section 3 above shall apply with the following adaptations:
- References to the GDPR shall be interpreted as references to the FADP, and corresponding concepts shall be interpreted in accordance with Swiss law.
- The competent supervisory authority under Clause 13 of the EEA SCCs shall be the Swiss Federal Data Protection and Information Commissioner ("FDPIC").
- References to EU Member State law shall be interpreted as references to Swiss law, and the governing law and jurisdiction provisions shall be adapted accordingly.
- The term "data subject" shall be interpreted to include legal entities to the extent required by the FADP.
These adaptations shall apply until such time as the revised FADP and its implementing ordinances fully align with the GDPR transfer mechanism framework, at which point the standard EEA SCC provisions shall govern.
7. Government Access Requests; Supplementary Measures
In respect of any transfer of DPA Data made pursuant to the Standard Contractual Clauses: (a) Efficiently shall implement and maintain the technical and organizational measures described in Annex II; (b) if Efficiently receives a legally binding request from a public authority for DPA Data, Efficiently shall, unless legally prohibited, attempt to redirect the authority to Customer, notify Customer, and challenge any request that Efficiently reasonably considers unlawful or overbroad; and (c) the parties shall cooperate to assess, and implement where reasonably necessary and commercially reasonable, additional safeguards for the transfer in light of applicable supervisory-authority guidance.