1. Introduction
This Data Transfer Addendum ("DTA") is incorporated by reference into the Data Processing Addendum ("DPA") between the parties. The DTA governs the Processing of DPA Data when such Processing involves a transfer of personal data from one jurisdiction to another and a lawful transfer mechanism is required under applicable Data Protection Law.
Capitalized terms not defined herein have the meanings set forth in the DPA or the Agreement. In the event of any conflict between this DTA and the DPA, this DTA shall control with respect to cross-border data transfers.
2. Order of Precedence
Where multiple transfer mechanisms apply to a particular transfer of DPA Data, the following order of precedence shall govern:
(a) The EU–U.S. Data Privacy Framework (including the UK Extension and Swiss–U.S. Data Privacy Framework);
(b) The UK International Data Transfer Addendum ("UK IDTA");
(c) The European Economic Area Standard Contractual Clauses ("EEA SCCs");
(d) Any other valid transfer mechanism recognized under applicable Data Protection Law.
For the avoidance of doubt, a higher-priority mechanism shall take precedence to the extent it provides a lawful basis for the transfer, but shall not invalidate the applicability of a lower-priority mechanism where the higher-priority mechanism does not cover the transfer in question.
3. Data Privacy Framework
Efficiently has self-certified its compliance with the EU–U.S. Data Privacy Framework, the UK Extension to the EU–U.S. Data Privacy Framework, and the Swiss–U.S. Data Privacy Framework, as administered by the U.S. Department of Commerce.
Efficiently shall comply with the Data Privacy Framework Principles with respect to all DPA Data received from the European Economic Area, the United Kingdom, and Switzerland in reliance on the applicable Data Privacy Framework.
If Efficiently's self-certification under any Data Privacy Framework is withdrawn, lapsed, or otherwise invalidated, Efficiently shall promptly notify Customer and the parties shall cooperate to implement an alternative lawful transfer mechanism.
4. EU Standard Contractual Clauses
To the extent that a transfer of DPA Data from the European Economic Area is not covered by the Data Privacy Framework, the parties agree that the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 (the "EEA SCCs") are hereby incorporated by reference and shall apply as follows:
Module 2 — Controller to Processor
The EEA SCCs shall apply under Module 2 (Controller to Processor), where Customer acts as the data exporter and controller, and Efficiently acts as the data importer and processor.
The following clause-specific elections apply:
- Clause 7 (Docking Clause): The optional docking clause shall not apply.
- Clause 9 (Use of Sub-processors): Option 2 (General Written Authorization) applies. Efficiently shall provide Customer with at least 30 days' prior notice of any intended addition or replacement of sub-processors.
- Clause 11(a) (Independent Dispute Resolution Body): The optional provision shall not be used.
- Clause 17 (Governing Law): Option 1 applies. The EEA SCCs shall be governed by the laws of Ireland.
- Clause 18(b) (Choice of Forum and Jurisdiction): Any disputes arising under the EEA SCCs shall be resolved before the courts of Ireland.
5. Appendix to Module 2
Annex I — Parties and Description of Transfer
Data Exporter
The data exporter is the entity identified as the Customer under the Agreement, acting in its capacity as controller (or processor, as applicable) of DPA Data.
Data Importer
efficiently, LLC
12 Penny Lane, Gallatin Gateway, MT 59730
Contact: success@efficiently.com
The data importer is Efficiently, acting in its capacity as processor of DPA Data on behalf of the data exporter.
Description of Transfer
The subject matter, nature, purpose, duration, categories of data subjects, and types of personal data are as described in the DPA and the Agreement.
Competent Supervisory Authority
The competent supervisory authority shall be determined in accordance with Clause 13 of the EEA SCCs.
Annex II — Technical and Organizational Measures
The technical and organizational security measures implemented by the data importer are as described in the Security Addendum to the Agreement.
Annex III — List of Sub-processors
The current list of sub-processors authorized by the data exporter is maintained and made available as described in the DPA (Subprocessors section).
6. UK International Data Transfer Addendum
To the extent that a transfer of DPA Data from the United Kingdom is not covered by the Data Privacy Framework, the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (the "UK IDTA"), as issued by the UK Information Commissioner under Section 119A of the Data Protection Act 2018, is hereby incorporated by reference.
Part 1: Tables
- Table 1 (Parties): The parties are as identified in Annex I above. The parties are deemed to have signed the UK IDTA by their use of the Service.
- Table 2 (Selected SCCs, Modules, and Selected Clauses): The EEA SCCs as set out in Section 4 above, including the Module 2 selections, form the Approved EU SCCs for purposes of the UK IDTA.
- Table 3 (Appendix Information): As set forth in Annex I, Annex II, and Annex III above.
- Table 4 (Ending the UK IDTA): Neither party may end the UK IDTA in accordance with Section 19 of the UK IDTA.
Part 2: Mandatory Clauses
Part 2 of the UK IDTA is incorporated without modification.
7. Personal Data Transfers from Switzerland
To the extent that a transfer of DPA Data is subject to the Swiss Federal Act on Data Protection ("FADP"), the EEA SCCs as set out in Section 4 shall apply with the following adaptations:
- References to the GDPR shall be interpreted as references to the FADP, and corresponding concepts shall be interpreted in accordance with Swiss law.
- The competent supervisory authority under Clause 13 of the EEA SCCs shall be the Swiss Federal Data Protection and Information Commissioner ("FDPIC").
- References to EU Member State law shall be interpreted as references to Swiss law, and the governing law and jurisdiction provisions shall be adapted accordingly.
- The term "data subject" shall be interpreted to include legal entities to the extent required by the FADP.
These adaptations shall apply until such time as the revised FADP and its implementing ordinances fully align with the GDPR transfer mechanism framework, at which point the standard EEA SCC provisions shall govern.