← All legal documents

Data Transfer Addendum

Last updated: August 1st, 2026

1. Introduction

This Data Transfer Addendum ("DTA") is incorporated by reference into the Data Processing Addendum ("DPA") between the parties. The DTA governs the Processing of DPA Data when such Processing involves a transfer of personal data from one jurisdiction to another and a lawful transfer mechanism is required under applicable Data Protection Law.

Capitalized terms not defined herein have the meanings set forth in the DPA or the Agreement. In the event of any conflict between this DTA and the DPA, this DTA shall control with respect to cross-border data transfers.

2. Order of Precedence

Where multiple transfer mechanisms apply to a particular transfer of DPA Data, the following order of precedence shall govern:

(a) The EU–U.S. Data Privacy Framework (including the UK Extension and Swiss–U.S. Data Privacy Framework);

(b) The UK International Data Transfer Addendum ("UK IDTA");

(c) The European Economic Area Standard Contractual Clauses ("EEA SCCs");

(d) Any other valid transfer mechanism recognized under applicable Data Protection Law.

For the avoidance of doubt, a higher-priority mechanism shall take precedence to the extent it provides a lawful basis for the transfer, but shall not invalidate the applicability of a lower-priority mechanism where the higher-priority mechanism does not cover the transfer in question.

3. Data Privacy Framework

Efficiently has self-certified its compliance with the EU–U.S. Data Privacy Framework, the UK Extension to the EU–U.S. Data Privacy Framework, and the Swiss–U.S. Data Privacy Framework, as administered by the U.S. Department of Commerce.

Efficiently shall comply with the Data Privacy Framework Principles with respect to all DPA Data received from the European Economic Area, the United Kingdom, and Switzerland in reliance on the applicable Data Privacy Framework.

If Efficiently's self-certification under any Data Privacy Framework is withdrawn, lapsed, or otherwise invalidated, Efficiently shall promptly notify Customer and the parties shall cooperate to implement an alternative lawful transfer mechanism.

4. EU Standard Contractual Clauses

To the extent that a transfer of DPA Data from the European Economic Area is not covered by the Data Privacy Framework, the parties agree that the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 (the "EEA SCCs") are hereby incorporated by reference and shall apply as follows:

Module 2 — Controller to Processor

The EEA SCCs shall apply under Module 2 (Controller to Processor), where Customer acts as the data exporter and controller, and Efficiently acts as the data importer and processor.

The following clause-specific elections apply:

  • Clause 7 (Docking Clause): The optional docking clause shall not apply.
  • Clause 9 (Use of Sub-processors): Option 2 (General Written Authorization) applies. Efficiently shall provide Customer with at least 30 days' prior notice of any intended addition or replacement of sub-processors.
  • Clause 11(a) (Independent Dispute Resolution Body): The optional provision shall not be used.
  • Clause 17 (Governing Law): Option 1 applies. The EEA SCCs shall be governed by the laws of Ireland.
  • Clause 18(b) (Choice of Forum and Jurisdiction): Any disputes arising under the EEA SCCs shall be resolved before the courts of Ireland.

5. Appendix to Module 2

Annex I — Parties and Description of Transfer

Data Exporter

The data exporter is the entity identified as the Customer under the Agreement, acting in its capacity as controller (or processor, as applicable) of DPA Data.

Data Importer

efficiently, LLC
12 Penny Lane, Gallatin Gateway, MT 59730
Contact: success@efficiently.com

The data importer is Efficiently, acting in its capacity as processor of DPA Data on behalf of the data exporter.

Description of Transfer

The subject matter, nature, purpose, duration, categories of data subjects, and types of personal data are as described in the DPA and the Agreement.

Competent Supervisory Authority

The competent supervisory authority shall be determined in accordance with Clause 13 of the EEA SCCs.

Annex II — Technical and Organizational Measures

The technical and organizational security measures implemented by the data importer are as described in the Security Addendum to the Agreement.

Annex III — List of Sub-processors

The current list of sub-processors authorized by the data exporter is maintained and made available as described in the DPA (Subprocessors section).

6. UK International Data Transfer Addendum

To the extent that a transfer of DPA Data from the United Kingdom is not covered by the Data Privacy Framework, the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (the "UK IDTA"), as issued by the UK Information Commissioner under Section 119A of the Data Protection Act 2018, is hereby incorporated by reference.

Part 1: Tables

  • Table 1 (Parties): The parties are as identified in Annex I above. The parties are deemed to have signed the UK IDTA by their use of the Service.
  • Table 2 (Selected SCCs, Modules, and Selected Clauses): The EEA SCCs as set out in Section 4 above, including the Module 2 selections, form the Approved EU SCCs for purposes of the UK IDTA.
  • Table 3 (Appendix Information): As set forth in Annex I, Annex II, and Annex III above.
  • Table 4 (Ending the UK IDTA): Neither party may end the UK IDTA in accordance with Section 19 of the UK IDTA.

Part 2: Mandatory Clauses

Part 2 of the UK IDTA is incorporated without modification.

7. Personal Data Transfers from Switzerland

To the extent that a transfer of DPA Data is subject to the Swiss Federal Act on Data Protection ("FADP"), the EEA SCCs as set out in Section 4 shall apply with the following adaptations:

  • References to the GDPR shall be interpreted as references to the FADP, and corresponding concepts shall be interpreted in accordance with Swiss law.
  • The competent supervisory authority under Clause 13 of the EEA SCCs shall be the Swiss Federal Data Protection and Information Commissioner ("FDPIC").
  • References to EU Member State law shall be interpreted as references to Swiss law, and the governing law and jurisdiction provisions shall be adapted accordingly.
  • The term "data subject" shall be interpreted to include legal entities to the extent required by the FADP.

These adaptations shall apply until such time as the revised FADP and its implementing ordinances fully align with the GDPR transfer mechanism framework, at which point the standard EEA SCC provisions shall govern.