Data Processing Addendum
This Data Processing Addendum (“DPA”) is entered into by and between the Ease customer identified in one or more agreements or orders (“Subscriber”) and Ease, Inc. (“Ease”) that incorporate the DPA by reference (the “Agreement”). This DPA is incorporated into and supplemental to the Agreement which governs the provision of the Ease hosted software as a service offering (the “Ease Service”). Except as modified below, the terms of the Agreement shall remain in full force and effect.
- Definitions: Capitalized terms not defined herein shall have the meaning given in the Agreement. In this DPA, the following terms (and derivations of such terms) shall have the following meanings:
- “Applicable Data Protection Law” means all privacy and data protection laws that apply to Ease’s processing of Data under the Agreement (including, where applicable, the California Consumer Privacy Act of 2018 including its associated regulations and as amended (including by the California Privacy Rights Act of 2020) (the “CCPA”), and European Data Protection Law). For the avoidance of doubt, “Applicable Data Protection Law” includes, where applicable, privacy and data protection laws in effect in Colorado, Connecticut, Montana, Oregon, Texas, Utah, or Virginia as of the Effective Date, and qualifying privacy and data protection laws, rules, or regulations taking effect in other U.S. states during the Term, in each case as amended or superseded from time to time (collectively, “U.S. Data Protection Laws”)
- “Controller” means the entity that determines the purposes and means of the processing of Personal Data;
- “Data” means Personal Data provided by Subscriber (directly or indirectly) to Ease for processing under the Agreement as more particularly identified in Appendix A (Processing Particulars);
- “European Data Protection Law” means all EU and U.K. regulations or other legislation applicable (in whole or in part) to the processing of Personal Data under the Agreement (such as Regulation (EU) 2016/679 (the “GDPR“), the U.K. GDPR (defined below), and the Swiss Federal Data Protection Act of 25 September 2020 and its Ordinance (“Swiss Addendum”); the national laws of each EEA member state and the U.K. implementing any EU directive applicable (in whole or in part) to the processing of Personal Data (such as Directive 2002/58/EC); and any other national laws of each EEA member state and the U.K. applicable (in whole or in part) to the Processing of Personal Data; in each case as amended or superseded from time to time.
- “Model Clauses” means the standard contractual clauses attached to the European Commission’s Implementing Decision of 4 June 2021 under Article 28 (7) of Regulation (EU) 2016/679 of the European Parliament and of the Council and Article 29 (7) of Regulation (EU) 2018/1725 of the European Parliament and of the Council, on standard contractual clauses, selecting Module Two between controllers and processors in any case where Subscriber is a Controller, and Module Three between processors in any case where Subscriber is a Processor, and excluding optional clauses unless otherwise specified), and any replacement, amendment or restatement of the foregoing, as issued by the European Commission, on or after the effective date of this DPA.
- “Personal Data” means any information relating to an identified or identifiable natural person (a “Data Subject”), the processing of which is governed by Applicable Data Protection Law; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Where the CCPA applies, ‘Personal Data’ includes “personal information” as defined by the CCPA. Personal Data does not include anonymous or de-identified information or aggregated information derived from Personal Data.
- “Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organizing, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- “Processor” means an entity that processes Personal Data on behalf of the Controller. Where applicable, Processor includes “service provider” as defined by the CCPA.
- “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Data.
- “Sensitive Data” means any Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person’s sex life or sexual orientation, or data relating to criminal convictions or offences.
- “Sub-Processor” means an entity engaged by the Processor or any further sub-contractor to process Personal Data on behalf of and under the instructions of the Controller.
- “U.K. GDPR” means the GDPR, as it forms part of the domestic law of the United Kingdom by virtue of Section 3 of the European Union (Withdrawal) Act 2018.
- “Applicable Data Protection Law” means all privacy and data protection laws that apply to Ease’s processing of Data under the Agreement (including, where applicable, the California Consumer Privacy Act of 2018 including its associated regulations and as amended (including by the California Privacy Rights Act of 2020) (the “CCPA”), and European Data Protection Law). For the avoidance of doubt, “Applicable Data Protection Law” includes, where applicable, privacy and data protection laws in effect in Colorado, Connecticut, Montana, Oregon, Texas, Utah, or Virginia as of the Effective Date, and qualifying privacy and data protection laws, rules, or regulations taking effect in other U.S. states during the Term, in each case as amended or superseded from time to time (collectively, “U.S. Data Protection Laws”)
- Data Protection
- Relationship of the parties: As between the parties and for the purposes of this DPA, Subscriber appoints Ease as a Processor to process the Data on behalf of Subscriber. Where applicable, Ease is a “service provider” as defined in the CCPA. Each party shall be responsible for complying with its own obligations under Applicable Data Protection law. In the case of Subscriber, the foregoing obligations include but are not limited to providing notice to Data Subjects and obtaining and periodically refreshing the consent of Data Subjects, where required, to authorize Subscriber’s transfer of Data to Ease in connection with its use of Ease’s Services and Subscriber’s own processing of Data. In the case of Ease, the foregoing obligations include but are not limited to assisting Subscriber in meeting its obligations as a Controller under Applicable Data Protection Law on the terms described in this DPA.
- Purpose limitation: Each party acknowledges and agrees that all Data is disclosed by Subscriber hereunder only for those limited and specified purposes set forth in the Agreement and this DPA. Ease shall process the Data as a Processor only as necessary to perform the Services for Subscriber under the Agreement, and strictly in accordance with the documented instructions of Subscriber (including those in this DPA and the Agreement). In no event shall Ease process the Data for its own purposes or those of any third party. Ease may also anonymize or deidentify Data in accordance with Applicable Data Protection Law. Subscriber shall only give lawful instructions that comply with Applicable Data Protection Law and shall ensure that Ease’s processing of Data, when done in accordance with Subscriber’s instructions, will not cause Ease to violate Applicable Data Protection Law. Ease shall inform Subscriber if, in its opinion, an instruction infringes Applicable Data Protection Law. In any case where confirmation of a Controller’s instructions is required by Applicable Data Protection Law, the parties agree that the Agreement, together with this DPA, represents the complete and final documented instructions from the Controller of the Data to Ease as of the date of this DPA for the processing of Data. For the avoidance of doubt, Ease may anonymize or deidentify Data in accordance with Applicable Data Protection Laws (“Deidentified Data”), provided Ease (i) implements technical safeguards that prohibit re-identification of the Data Subject to whom the information may pertain; (ii) implements business Processes that specifically prohibit reidentification of the Deidentified Data and prevent the inadvertent release of Deidentified Data; and (iii) makes no attempt to reidentify the Deidentified Data. Notwithstanding anything to the contrary, Subscriber authorizes Ease to further Process Personal Data for the following limited internal business purposes: (i) detecting security incidents, and protecting against malicious, deceptive, fraudulent, or illegal activity; (ii) debugging to identify and repair errors that impair intended functionality of the Ease products and services and other activities needed to maintain the quality and/or safety of the products; (iii) communications with Subscriber and its authorized users related to the Ease products and services; and (iv) internal operational activities such as responding to data subject requests, making back-ups as part of disaster recovery/business continuity programs, confirming usage quantities, and processing required for legal or regulatory compliance. When engaged in further processing, Ease is acting as a data controller for the limited purposes of engaging in that processing activity.
- International transfers of Data: Ease is located in the United States and Processes the Data in the United States unless otherwise agreed upon by the parties. Ease also makes available regional hosting environments, and the location of Processing depends on the environment in which Subscriber is provisioned. Where Subscriber is provisioned in Ease’s European Union environment, the Data is hosted in the AWS Europe (Frankfurt) region and is not transferred outside the European Economic Area, including for backup. Where Subscriber is provisioned in Ease’s GovCloud environment, the Data is hosted in AWS GovCloud (US) regions. Unless otherwise agreed with respect to alternative regional hosting environments, for Ease to perform Services for Subscriber pursuant to the Agreement, Subscriber transfers (directly or indirectly) Personal Data to Ease in the United States. For Personal Data subject to European Data Protection Law, Ease agrees to abide by and process the Data in compliance with the Model Clauses, which are incorporated in full by reference and form an integral part of this DPA. Ease additionally maintains an active self-certification under the EU–U.S. Data Privacy Framework, the U.K. Extension to the EU–U.S. Data Privacy Framework, and the Swiss–U.S. Data Privacy Framework. For the purposes of the Model Clauses, the parties agree that:
- Ease is the “data importer” and Subscriber is the “data exporter” (notwithstanding that Subscriber may itself be located outside the EEA/UK and/or a Processor acting on behalf of a third-party Controller);
- Appendix A (Processing Particulars), Appendix B (Specific Security Measures), and Appendix C (Sub-processor List) of this DPA shall form Annex I, Annex II, and Annex III of the Model Clauses, respectively;
- Option 2 under clause 9 of the Model Clauses will apply with respect to Sub-Processors. Annex III of the Model Clauses shall be subject to General Written Authorization, where “General Written Authorization” means that Ease has Subscriber’s general authorization (or the general authorization of the Controller of the Data) for the engagement of sub-processor(s) from the list set forth in Appendix C, which shall be amended from time to time in accordance with the terms of the Agreement, this DPA, and all Applicable Data Protection Law;
- Audits described in clause 8.9 of the Model Clauses shall be carried out in accordance with the audit provisions detailed in Section 2.12 of this DPA;
- The option under clause 11 of the Model Clauses shall not apply;
- For purposes of clauses 17 and 18 of the Model Clauses, this DPA shall be governed by the laws of the Republic of Ireland. Any dispute arising from this DPA shall be resolved by the courts of the Republic of Ireland, and each party agrees to submit themselves to the jurisdiction of the same; and
- It is not the intention of either party, nor the effect of this DPA, to contradict or restrict any of the provisions set forth in the Model Clauses. Accordingly, if and to the extent the Model Clauses conflict with any provision of this DPA, the Model Clauses shall prevail to the extent of such conflict with respect to Personal Data processed pursuant to the Model Clauses. Subscriber warrants it will not transfer any Sensitive Data to Ease.
- Law enforcement requests.
- If Ease becomes aware that any law enforcement, regulatory, judicial or governmental authority (an “Authority”) wishes to obtain access to or a copy of some or all Data, whether on a voluntary or a mandatory basis, then unless legally prohibited as part of a mandatory legal compulsion that requires disclosure of Data to such Authority, Ease shall:
- promptly notify Subscriber of such Authority’s data access request;
- inform the Authority that any and all requests or demands for access to Data should be notified to or served upon Subscriber in writing; and
- not provide the Authority with access to Data unless and until authorized by Subscriber.
- If Ease is under a legal prohibition that prevents it from complying with Section 2.4.1(a)-(c) in full, Ease shall use reasonable and lawful efforts to challenge such prohibition (and Subscriber acknowledges that such challenge may not always be reasonable or possible in light of the nature, scope, context and purposes of the intended Authority access request). If Ease makes a disclosure of Data to an Authority (whether with Subscriber’s authorization or due to a mandatory legal compulsion), Ease shall only disclose such Data to the extent Ease is legally required to do so.
- Section 2.4.1 shall not apply, in the event, that taking into account the nature, scope, context and purposes of the intended Authority’s access to the Data, Ease has a reasonable and good-faith belief that urgent access is necessary to prevent an imminent risk of serious harm to any individual. In such event, Ease shall notify Subscriber as soon as possible following such Authority’s access and provide Subscriber with full details of the same, unless and to the extent that Ease is legally prohibited from doing so;
- Solely with respect to Data that is subject to the GDPR, and/or where Data whose disclosure is otherwise restricted by Applicable Data Protection Law, Ease shall not knowingly disclose Data to an Authority in a massive, disproportionate, and indiscriminate manner that goes beyond what is necessary in a democratic society. Ease shall have in place, maintain and comply with a policy governing Personal Data access requests from Authorities which at minimum prohibits:
- massive, disproportionate or indiscriminate disclosure of Personal Data relating to Data Subjects in the EEA and the United Kingdom; and
- disclosure of Personal Data relating to data subjects in the EEA, and the United Kingdom to an Authority without a subpoena, warrant, writ, decree, summons or other legally binding order that compels disclosure of such Personal Data.
- If Ease becomes aware that any law enforcement, regulatory, judicial or governmental authority (an “Authority”) wishes to obtain access to or a copy of some or all Data, whether on a voluntary or a mandatory basis, then unless legally prohibited as part of a mandatory legal compulsion that requires disclosure of Data to such Authority, Ease shall:
- Confidentiality of processing: Ease shall ensure that any person that it authorizes to process the Data (including Ease’s staff, agents and subcontractors) shall be subject to a strict duty of confidentiality (whether a contractual duty or a statutory duty) and shall not permit any person to process the Data who is not under such a duty of confidentiality.
- Security: Ease shall implement appropriate technical and organizational measures to protect the Data from (i) accidental or unlawful destruction, and (ii) loss, alteration, unauthorized disclosure of, or access to the Data. At a minimum, such measures shall include the security measures identified in Appendix B. With respect to evaluation of the appropriate level of security for the processing of the Data, each party represents and warrants that:
- It has taken due account of the state of the art, the costs of implementation, the nature, scope, context and purpose(s) of processing and the risks involved in the processing for the Data; and
- It has evaluated the use of encryption and/or pseudonymization for the Data and has determined that the level provided by Ease is appropriate for the Data.
- To the extent that the CCPA applies to the processing of the Data, the party has determined that the technical and organizational measures provided by Ease is no less than the level of security required by the CCPA.
- Subcontracting: A list of Ease’s current Sub-Processors is available in Appendix C (the “List”). Ease shall keep the List current throughout the term of the Agreement in accordance with this section. From time to time, Ease may amend the List to add newly appointed Sub-processors and to remove terminated Sub-Processors. Ease shall not subcontract any processing of the Data to a third-party Sub-Processor unless: (i) Ease provides to Subscriber an up-to-date list of its then-current Sub-Processors upon request; and (ii) Ease provides at least thirty (30) days’ prior notice of the addition or removal of any Sub-Processor (including the details of the processing it performs or will perform, and the location of such processing). If Subscriber objects to Ease’s appointment of a third-party Sub-Processor on reasonable grounds relating to the protection of the Data, then either Ease will not appoint the Sub-Processor, or Subscriber may elect to suspend or discontinue the affected Services by providing written notice to Ease. Notice of objection may be sent to Ease’s Privacy Officer at privacy@ease.io. Subscriber shall notify Ease of its objection within ten (10) business days after its receipt of Ease’s notice, and Subscriber’s objection shall be sent to and explain the reasonable grounds for Subscriber’s objection. If a timely objection is not made, Ease will be deemed to have been authorized by Subscriber (or, if Subscriber is a Processor of the Data, by the Controller of the Data) to appoint the new Sub-Processor. Ease shall impose the same data protection terms on any Sub-Processor it appoints as those provided for by this DPA and Ease shall remain fully liable for any breach of Ease’s obligations under this DPA that is caused by an act, error or omission of its Sub-Processor.
- Cooperation and individuals’ rights: Subscriber is responsible for responding to Data Subject requests using Subscriber’s own access to the relevant Data. Ease shall provide all reasonable and timely assistance to enable Subscriber to respond to: (i) any request from an individual to exercise any of its rights under Applicable Data Protection Law, and (ii) any other correspondence received from a regulator or public authority in connection with the processing of the Data. In the event, that any such communication is made directly to Ease, Ease shall promptly (and in any event, no later than within forty-eight (48) hours of receiving such communication) inform Subscriber providing full details of the same and shall not respond to the communication unless specifically required by law or authorized by Subscriber.
- Data Protection Impact Assessment: Taking into account the nature of the processing and the information available to Ease, Ease shall provide Subscriber with reasonable and timely assistance with any data protection impact assessments as required by Applicable Data Protection Law and, where necessary, consultations with data protection authorities.
- Security Incidents: Upon becoming aware of a Security Incident, Ease shall inform Subscriber without undue delay, and in any event within seventy two (72) hours and shall provide all such timely information and cooperation to enable Subscriber to fulfill its data breach reporting obligations under (and in accordance with the timescales required by) Applicable Data Protection Law. Ease shall further take such measures and actions as are necessary to remedy or mitigate the effects of the Security Incident and shall keep Subscriber informed of all material developments in connection with the Security Incident. Ease shall not notify any third parties of a Security Incident affecting the Data unless and to the extent that: (a) Subscriber has agreed to such notification, and/or (b) notification is required to be made by Ease under Applicable Data Protection Law.
- Deletion or return of Data: Upon termination or expiry of the Agreement, Ease shall (at Subscriber’s election) delete or return all Data, including copies in Ease’s possession or control no later than within thirty (30) days of Subscriber’s election. This requirement shall not apply to the extent that Ease is required by applicable laws to retain some or all of the Data, in which event Ease shall isolate and protect the Data from any further processing except to the extent required by such law, shall only retain such Data for as long as it is required under applicable laws, and shall continue to ensure compliance with all Applicable Data Protection Law during such retention. Please note that any backups containing customer data will not age out until 31 days after the deletion request has been actioned. During this period, the data remains secure and inaccessible, in compliance with Ease’s data protection policies.
- Audit: Ease uses an external auditor to verify the adequacy of its security measures and controls for its Services. The audit is conducted annually by an independent third-party in accordance with AICPA SOC2 standards and results in the generation of a SOC2 report (“Audit Report”) which is Ease’s confidential information. Upon written request, Ease shall provide Subscriber with a copy of the most recent Audit Report subject to confidentiality obligations of the Agreement or a non-disclosure agreement covering the Audit Report. If documentation beyond the Audit Report and other information that Ease provides to Subscriber is necessary to enable Subscriber to comply with its obligations with respect to the processing of Data under Applicable Data Protection Law (such as Article 28(3)(h) of GDPR where applicable), Ease shall permit Subscriber to audit Ease’s compliance with this DPA using an independent third party and shall make available all such information, systems and staff reasonably necessary to conduct such audit. Subscriber shall not exercise its audit rights more than once per year except following a Security Incident or following an instruction by a regulator or public authority. Subscriber shall give Ease forty-five (45) days prior written notice of its intention to audit, conduct its audit during normal business hours, take all reasonable measures to prevent unnecessary disruption to Ease’s operations, restrict findings to only data relevant to Subscriber, and provide Ease with a copy of the auditor’s report. Ease and Subscriber shall mutually agree in advance on the date, scope, duration, and security and confidentiality controls applicable to the audit. Subscriber shall reimburse Ease for actual expenses and costs incurred to allow for and contribute to Subscriber’s audit.
- Additional Terms for CCPA Data: With respect to Data that is subject to the CCPA (“CCPA Data”), the parties acknowledge and agree as follows:
- The terms “service provider,” “sale,” “sell”, “share”, and “sharing”, as used in this section, are as defined in Section 1798.140 of the CCPA, and shall be understood as Processing for purposes of this section.
- Ease will Process CCPA Data for the limited and specified purposes of providing the Services under the Agreement or as otherwise permitted by the CCPA, and that, except and unless expressly permitted under this DPA, the Agreement, and the CCPA, Ease shall not sell or share any CCPA Data, retain, use or disclose CCPA Data to any party or for any other purpose (commercial or otherwise) outside of the direct business relationship between Ease and Subscriber. Ease shall comply with all obligations of the CCPA applicable to service providers and/or contractors, including, without limitation:
- notifying Subscriber if Ease determines it can no longer meet its obligations under the CCPA;
- not combining the CCPA Data relating to a specific consumer with any other data about the same consumer in Ease’s possession and/or control, whether received from or on behalf of another person or persons or collected by Ease from its own interaction(s) with the consumer; and
- ensuring that each and all persons authorized by Ease to access the CCPA Data (which may include, without limitation, Ease’s employees, independent contractors, Sub-Processors, agents, and other personnel) complies with all of the foregoing obligations.
- to the extent required by the CCPA, assisting Subscriber in taking reasonable and appropriate steps (i) to stop and remediate unauthorized use of the Data, and (ii) to ensure that Ease Processes the Data in a manner consistent with Subscriber’s obligations under the CCPA.
- Additional Terms for U.S. Laws: With respect to Data that is subject to U.S. Data Protection Laws, Ease agrees that it shall adhere to Subscriber’s instructions in the Processing of such Personal Data to the extent required to comply with such laws, and shall assist Subscriber in meeting its obligations under applicable U.S. Data Protection Laws on the terms described in this DPA. Without limiting the foregoing, and taking into account the nature of the Processing and the information available to Ease, Ease shall provide reasonable assistance to Subscriber with any risk assessments, cybersecurity audits, and assessments relating to the use of automated decision making technology that Subscriber is required to conduct under applicable U.S. Data Protection Laws, including the CCPA and its implementing regulations.
- Miscellaneous
- The obligations placed upon each party under this DPA shall survive so long as Ease and/or its Sub-Processors process Data on behalf of Subscriber.
- Except for the changes made by this DPA, the Agreement remains unchanged and in full force and effect. If there is any conflict between this DPA and the Agreement, this DPA shall prevail to the extent of that conflict.
- It is not the intention of either party, nor shall it be the effect of this DPA, to contradict or restrict any provision of the Model Clauses and/or any Applicable Data Protection Law. To the extent that any provision of the Model Clauses conflicts with this DPA, the Model Clauses shall prevail to the extent of such conflict with respect to Personal Data which is subject to the Model Clauses. In no event shall this DPA restrict or limit the rights of any Data Subject or of any Authority.
- No amendment to or modification or waiver of this DPA is effective unless:
- It is in a physical writing and manually signed by an authorized representative of each party;
- Ease may amend this DPA without Subscriber’s express prior written consent to the extent indicated in Section 3.4.2(a) or 3.4.2(b), provided that the amendment shall not diminish the privacy or security of the Data below the standards by Applicable Data Protection Law:
- Ease may amend this DPA to the extent that Ease determines to be reasonably necessary to comply with Applicable Data Protection Law (including any changes thereto taking effect during the term of this DPA), Ease provides written notice of the proposed amendment to Subscriber no fewer than thirty (30) days prior to the effective date of the amendment.
- Ease may amend this DPA for reasons other than as necessary to comply with Applicable Data Protection Law, provided that (i) Ease provides notice of the proposed amendment to Subscriber no fewer than sixty (60) days prior to the effective date of the amendment, and (ii) such amendments shall not take effect until the subscription term immediately following the term in which Subscriber receives such notice. If Subscriber does not wish to agree to the proposed amendments, Subscriber may elect not to renew its subscription in accordance with the Agreement. In the event of an objection, the parties shall further negotiate in good faith to amend the terms of the DPA affecting Subscriber to the extent reasonably necessary to comply with Applicable Data Protection Law.
- If any provision of this DPA is deemed invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended to ensure its validity and enforceability while preserving the parties’ intentions as closely as possible; or (ii) if that is not possible, then construed in a manner as if the invalid or unenforceable part had never been included herein.
- The term of this DPA will terminate automatically without requiring any further action by either party upon the later of (i) the termination of the Agreement, or (ii) when all Personal Data is removed from Ease’s systems and records, and/or is otherwise rendered unavailable to Ease for further Processing.
APPENDIX A – PROCESSING PARTICULARS
A. LIST OF PARTIES
Data exporter(s): Identity and contact details of the data exporter(s) and, where applicable, of its/their data protection officer and/or representative in the European Union]
Name: Subscriber set forth in Agreement
Address: As set forth in the Agreement, or as set forth below.
Role: Controller or Processor
Data importer(s):
Name: Ease, Inc.
Address: 210 Progress, Suite #150, Irvine, CA 92618
Role: Processor
B. DESCRIPTION OF TRANSFER
Categories of data subjects whose personal data is transferred
Subscriber may submit Personal Data, the extent of which is determined and controlled by Subscriber in its sole discretion, and which may include, but is not limited to, Personal Data relating to the following categories of data subjects:
- Employees, agents, advisors, freelancers of Subscriber (who are natural persons); and
- Subscriber’s users, partners, and customers and the users and employees of those entities.
Categories of personal data transferred
Subscriber may submit Personal Data, the extent of which is determined and controlled by Subscriber (including Subscriber’s users, partners, and customers, in each case as applicable) in its sole discretion, and which may include, but is not limited to, the following types of Personal Data:
- Identification and contact data (name, title, address, phone number, email address);
- Employment data (employer, job title, academic and professional qualifications, geographic location, area of responsibility, affiliated organization, area of responsibility and industry);
- Purchase and usage history data;
- IT related data (IP addresses of visitors to data exporter’s customer’s websites, online navigation data, browser type, language preferences, pixel data, cookies data, web beacon data);
- IT information (computer ID, user ID and password, domain name, IP address, log files, software and hardware inventory, software usage pattern tracking information (i.e. cookies and information recorded for operation and training purposes); and
- If the parties mutually agree on expanded use case, financial information (account details, payment information.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
No sensitive data is transferred.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
Data is transferred on a continuous basis during the term of the Ease Master Subscription Agreement and this DPA.
Nature of the processing
The nature of the processing of Subscriber Data is set out in the Ease Master Subscription Agreement and this DPA.
Purpose(s) of the data transfer and further processing
The purpose of the processing of Subscriber Data are set out in the Ease Master Subscription Agreement and this DPA.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
Personal Data shall be retained by Ease for no longer than necessary to effect the services set out in the Ease Master Subscription Agreement and this DPA, subject to exemptions as set forth in Section 2.11 of this DPA.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
Ease transfers the Personal Data listed above to certain Sub-Processors (listed in Appendix C) for the sole purpose of facilitating Ease’s provision of services under the Ease Master Subscription Agreement. Sub-Processors have been instructed to retain any Personal Data processed by Ease for no longer than necessary to render sub-processing services for Ease.
APPENDIX B – SPECIFIC SECURITY MEASURES
TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
Description of the technical and organizational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons.
1. Measures of pseudonymization and encryption of personal data; measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services
Network Security
Ease services are accessible only over HTTPS (TLS 1.3 for all public production endpoints). Traffic over HTTPS is encrypted and is protected from interception by unauthorized third parties. Ease uses only strong encryption algorithms with a key length of at least 256 bits.
All network access, both within the datacenter and between the datacenter and outside services, is restricted by firewall and routing rules. Network access is logged and logs are retained for a minimum of 30 days.
Ease servers are only accessible through HTTPS and deny access to other ports. Administrative access is granted only to select employees of Ease, based on role and business need.
Access to databases used in the Ease Services is provided via an encrypted link (TLS).
2. Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; Processes for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing
Development Process
Ease developers have been trained in secure coding practices. Ease application architecture includes mitigation measures for common security flaws such as the OWASP Top 10. The Ease application uses industry standard, high-strength algorithms including AES 256. Periodic security tests are conducted, including using scanning and fuzzing tools to check for vulnerabilities.
3. Measures for user identification and authorization
Authentication
Clients login to Ease using a password which is known only to them and done only over secure (HTTPS) connections. Clients are required to have reasonably strong passwords. Passwords are not stored unencrypted; instead, as is standard practice, only a secure hash of the password is stored in the database. Because the hash is relatively expensive to compute, and because a “salting” method is used, brute-force guessing attempts are relatively ineffective, and password reverse-engineering is difficult even if the hash value were to be obtained by a malicious party.
When clients enable end users to connect to Ease using user-supplied credentials (Single Sign On), this is done using security tokens, OAuth, or SAML 2.0, and in those cases, no credentials need to be stored in the Ease system.
4. Measures for the protection of data during transmission; measures for the protection of data during storage
Hosting and Physical Security
Ease servers are hosted on Amazon Web Services (AWS). As such, Ease inherits the control environment which Amazon maintains and demonstrates via SSAE16 SOC 1, 2 and 3, ISO 27001 and FedRAMP/FISMA reports and certifications. Web servers and databases run on servers in secure datacenters. Physical access is restricted to authorized personnel. Premises are monitored and access is logged.
5. Measures for ensuring physical security of locations at which personal data are processed
Isolation of Services
Ease servers run in Windows virtual machines which are isolated from one another and from the underlying hardware layer. Server processes are restricted to a particular directory and do not have access to the local filesystem.
Employee Screening and Policies
As a condition of employment, all Ease employees undergo pre-employment background checks and agree to company policies including security and acceptable use policies.
Security Issues
Ease considers the security of its systems a top priority. Ease has implemented a responsible disclosure policy to ensure that problems are addressed quickly and safely. Members of Ease’s personnel are granted access to Personal Data only to the extent strictly necessary for the implementation, management and monitoring of the Agreement. Ease ensures that all persons authorized to process the personal data have committed themselves to confidentiality.
6. Measures for certification/assurance of processes and products
SOC 2 Audited
Ease is committed to maintaining the security of its subscribers’ information. Ease has completed a Service Organization Controls 2 (SOC 2) audit with a 3rd-party evaluator certified by The American Institute of CPAs (AICPA). This audit uses the Trust Services Principles, published by the AICPA, to evaluate the effectiveness of a service organization’s controls. Ease represents and warrants that it will continue to maintain its certified SOC 2 status.
APPENDIX C – LIST OF SUB-PROCESSORS
The controller has authorized the use of the following sub-processors:
| Name | Description of processing | Country / Data Location | |
| 1 | Amazon Web Services | Cloud infrastructure hosting all Ease production and non-production environments, databases, compute, storage, Lambda functions, and SES email relay. All other sub-processors marked “AWS” run within this environment. | AWS US (US East and US West); AWS Europe (Frankfurt) and AWS GovCloud (US) where Subscriber is provisioned in those environments |
| 2 | Google Cloud Platform provides the AI processing for the Ease application’s AI features, including audit analysis, real-time translation of assessment and audit content, and document content creation. Processing is limited to the customer content submitted to those features, and each AI feature is subject to a separate customer opt-in. Google also provides SSO authentication for Ease employee and internal accounts. | Google Cloud Platform, with regional enforcement aligned to the Ease environment in which Subscriber is provisioned | |
| 3 | Atlassian (Jira / Confluence / JSM) | Internal engineering, IT, and project management. Support-related tickets may contain customer names or email addresses where customers contact Ease to request data corrections or deletions. | AWS (US East and US West) |
| 4 | Salesforce | CRM platform storing contact records, account information, sales activity, and communication history for Ease’s customer accounts and prospect pipeline. Integrated with Gong for call logging and with Marketo for list sync. | AWS (US East and US West) |
| 5 | Slack | Internal team communications. Salesforce subsidiary. Customer names or account references may appear incidentally in internal channels related to account management. | AWS (US East and US West) |
| 6 | Zoom | Video conferencing for internal meetings and external customer calls. AI processing of meeting content (summaries, transcripts, action items) for calls where recording consent has been obtained. | AWS (US East and US West) |
| 7 | Gong | Sales call recording, transcription, and AI analysis. Processes audio, video, and transcript content from sales calls with prospects and customers where recording consent has been obtained. | United States |
| 8 | Zendesk | Customer support platform. Processes support ticket content and identifiers submitted by Subscriber’s end users when contacting Ease support at support.ease.io. | United States |
| 9 | Anthropic | AI language model provider (Claude). Processes queries and context submitted by Ease employees through approved internal workflows. Customer data is not submitted to Anthropic except as may be incidentally included in support or operational workflows under Ease’s AI use policy. | United States |
| 10 | Marketo (Adobe) | Automation platform processes EASE user contact data to communicate product-related updates, share educational content, and send invitations to product and training related webinars. | United States |
| 11 | Microsoft 365 | Office productivity platform providing Ease employee email (Exchange Online), document storage and collaboration (SharePoint and OneDrive), and Teams messaging. Customer names, email addresses, and correspondence may be present in employee mailboxes and in stored internal documents. | United States |
| 12 | Pendo | In-application product analytics and user guidance. Processes Ease application usage events and end-user identifiers to support feature adoption analytics, in-app guides, and customer communications. | United States |
APPENDIX D – COMPETENT SUPERVISORY AUTHORITY
For the purposes of any Personal Data subject to the GDPR and/or the GDPR as implemented in the domestic law of the United Kingdom by virtue of Section 3 of the European Union (Withdrawal) Act 2018, where such personal data processed in accordance with the Model Clauses, the competent supervisory authority shall be as follows:
- where Subscriber is established in an EU member state, the supervisory authority with responsibility for ensuring Subscriber’s compliance with the GDPR shall act as competent supervisory authority;
- where Subscriber is not established in an EU member state, but falls within the extra-territorial scope of the GDPR and has appointed a representative, the supervisory authority of the EU member state in which Subscriber’s representative is established shall act as competent supervisory authority; or
- where Subscriber is not established in an EU member state but falls within the extra-territorial scope of the GDPR without however having to appoint a representative, the supervisory authority of the EU member state in which the Data Subjects are predominantly located shall act as competent supervisory authority.
In relation to Personal Data that is subject to the U.K. GDPR, the competent supervisory authority is the United Kingdom Information Commissioner’s Office, subject to the additional terms set forth in the International Data Transfer Addendum to the EU Model Clauses attached hereto as “Appendix E”.
In relation to Personal Data that is subject to the data privacy laws of Switzerland, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.
APPENDIX E – U.K. INTERNATIONAL DATA TRANSFER ADDENDUM
This U.K. INTERNATIONAL DATA TRANSFER ADDENDUM (“IDTA”) forms a part of the Data Processing Addendum (“DPA”) entered into by and between Ease, Inc. (“Ease”) and the party identified as the Subscriber in the DPA (“Subscriber”). Unless otherwise specified, all capitalized terms used in this IDTA have the meanings provided in the DPA.
- Scope of IDTA. The obligations set forth in this IDTA apply solely to Personal Data subject to the U.K. GDPR that is processed under the DPA (“U.K. Personal Data”).
- Incorporation of the U.K. Addendum. The parties agree that the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, as issued by the U.K. Information Commissioner’s Office under s.119A (1) of the U.K. Data Protection Act 2018 (“U.K. Addendum”) is incorporated by reference into and forms a part of this IDTA as if fully set forth herein. Each party agrees that execution of the DPA (to which this IDTA is attached as an appendix and incorporated by reference) shall have the same effect as if the parties had simultaneously executed a copy of the U.K. Addendum.
- Interpretation of the Model Clauses. For purposes of Processing U.K. Personal Data, any references in the DPA to the Model Clauses shall be read to incorporate the mandatory amendments to the Model Clauses set forth in the U.K. Addendum.
- Addendum Terms. Tables 1 through 4 of the U.K. Addendum shall be completed as follows:
- In Table 1 of the U.K. Addendum, the “Start Date” shall be the Effective Date of the DPA, and the details and contact information for the “data exporter” and the “data importer” shall be as specified in Appendix A of the DPA.
- In Table 2 of the U.K. Addendum:
- The version of the Model Clauses incorporated by reference into the DPA shall be the version applicable to this IDTA.
- Those provisions of the Model Clauses applicable under Module Two shall apply to this IDTA.
- The optional clauses and provisions of the Model Clauses applicable to this IDTA shall be those clauses and provisions specified in Section 2.3 of the DPA.
- In Table 3 of the U.K. Addendum, the information required in Annexes I (both 1A and 1B), II, and III shall be as provided in Appendices A, B, and C of the DPA, respectively.
- In Table 4 of the U.K. Addendum, if the ICO issues any revisions to the U.K. Addendum after the Effective Date (“ICO Revision”), Subscriber and Ease shall each have the right to terminate this IDTA in accordance with the U.K. Addendum, the DPA, and the Agreement. Upon such termination of this IDTA:
- Ease shall cease its Processing of the U.K. Personal Data; and
- Each party shall follow the processes described in Section 2.11 of the DPA with respect to the U.K. Personal Data.
- Notwithstanding the foregoing, termination of this IDTA in the event of an ICO Revision shall not terminate the DPA, the Agreement, and/or the obligations of either party arising thereunder with respect to Personal Data other than U.K. Personal Data, except and unless expressly agreed by and between the parties.
- No Amendments. The terms of the U.K. Addendum have not been amended in any way except as expressly stated herein.