Bonterms | Data Protection Addendum Version 2.0 (Signable Version)
The Bonterms Data Protection Addendum Version 2.0 (Signable Version) | Designed to enable a provider and customer to comply with GDPR, CCPA, and other data privacy laws in a SaaS/cloud services context.
Bonterms | Data Protection Addendum Version 2.0 (Signable Version) Download PDF Playbook Resources Download PDF Playbook Resources Download PDF Playbook Resources Bonterms Standard Agreement Data Protection Addendum v2.0 (Signable Version) This Bonterms Data Protection Addendum Version 2.0 (Signable Version) ("DPA") is a set of standard terms that is entered into between Customer and Provider by completing the DPA Details and executing this DPA in the space provided below. Definitions. "Additional Terms" means any additions to, or modifications of, this DPA (including any Exhibits) agreed by the parties. "Affiliate" means an entity controlled, controlling or under common control with a party, where control means at least 50% ownership or power to direct an entity's management. "Audit" and "Audit Parameters" are defined in Section 9.3 below. "Audit Report" is defined in Section 9.2 below. "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of Processing of Personal Data. "Customer" is identified in the DPA Details. "Customer Data" means Customer Data as defined in the Main Agreement. "Customer Instructions" is defined in Section 3.1 below. "Customer Personal Data" means Personal Data in Customer Data. "Data Protection Laws" means all laws and regulations applicable to the Processing of Customer Personal Data under the Main Agreement, including, as applicable: (i) U.S. state privacy laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and any binding regulations promulgated thereunder ("CCPA"), (ii) the General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR" or "GDPR"), (iii) the Swiss Federal Act on Data Protection ("FADP"), (iv) the EU GDPR as it forms part of the law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended by the Data (Use and Access) Act 2025 (collectively, the "UK GDPR") and (v) the UK Data Protection Act 2018; in each case, as updated, amended or replaced from time to time. "Data Subject" means the identified or identifiable natural person to whom Customer Personal Data relates. "DPA Details" means the Key Terms, Processing Details and any Additional Terms as set forth below. "DPA Effective Date" is specified in the DPA Details. "EEA" means European Economic Area. "EU Standard Contractual Clauses" or "EU SCCs" means the Standard Contractual Clauses approved by the European Commission in decision 2021/914. "Exhibit" means each of Exhibit A (Cross-Border Transfer Mechanisms) and Exhibit B (Region-Specific Terms), as may be modified or replaced by the parties through Additional Terms. "Key Terms" means Main Agreement, DPA Effective Date, Subprocessor List, Designated EU Governing Law and Designated EU Member State as specified by the parties in the DPA Details. "Main Agreement" means the agreement between Customer and Provider under which Provider provides the Service to Customer. "Personal Data" means information about an identified or identifiable natural person or which otherwise constitutes "personal data", "personal information", "personally identifiable information" or similar terms as defined in Data Protection Laws. "Processing" and inflections thereof refer to any operation or set of operations that is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. "Processing Details" means the Subject Matter and Details of Processing and Security Measures specified by the parties in the DPA Details. "Processor" means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Controller. "Provider" is identified in the DPA Details. "Restricted Transfer" means: (i) where EU GDPR applies, a transfer of Customer Personal Data from the EEA to a country outside the EEA that is not subject to an adequacy determination, (ii) where UK GDPR applies, a transfer of Customer Personal Data from the United Kingdom to any other country that is not subject to an adequacy determination or (iii) where FADP applies, a transfer of Customer Personal Data from Switzerland to any other country that is not subject to an adequacy determination. "Security Incident" means any breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data being Processed by Provider. "Security Measures" means the technical and organizational security measures for the Service as set forth in the Main Agreement or, if not set forth in the Main Agreement, as specified in the DPA Details. "Service" means the services provided by Provider to Customer under the Main Agreement. "Specified Notice Period" is 48 hours. "Subprocessor" means any third party authorized by Provider to Process any Customer Personal Data. "Subprocessor List" means the list of Provider's Subprocessors as identified or linked to in the DPA Details. "Subprocessor Notice Method" means email or in-product notification to an administrator. Scope and Duration. Roles of the Parties. This DPA applies to Provider as a Processor of Customer Personal Data and to Customer as a Controller or Processor of Customer Personal Data. Scope of DPA. This DPA applies to Provider's Processing of Customer Personal Data under the Main Agreement to the extent such Processing is subject to Data Protection Laws. This DPA is governed by the governing law of the Main Agreement unless otherwise required by Data Protection Laws. Duration of DPA. This DPA commences on the DPA Effective Date and terminates upon expiration or termination of the Main Agreement (or, if later, the date on which Provider has ceased all Processing of Customer Personal Data). Exhibits. Exhibit A (Cross-Border Transfer Mechanisms) and Exhibit B (Region-Specific Terms) are incorporated into this DPA. Relationship to Main Agreement. This DPA (including the DPA Details) is incorporated into the Main Agreement. Order of Precedence. In the event of any conflict or inconsistency among the following documents, the order of precedence will be: (1) any Standard Contractual Clauses or other measures set forth in Exhibit A (Cross-Border Transfer Mechanisms), (2) Exhibit B (Region-Specific Terms), (3) any Additional Terms, (4) this DPA and (5) the Main Agreement. To the fullest extent permitted by Data Protection Laws, any claims brought in connection with this DPA will be subject to the terms and conditions, including, but not limited to, the exclusions and limitations, set forth in the Main Agreement. Processing of Personal Data. Customer Instructions. Provider will Process Customer Personal Data as a Processor only: (i) in accordance with Customer Instructions or (ii) to comply with Provider's obligations under applicable laws, subject to any notice requirements under Data Protection Laws. "Customer Instructions" means: (i) Processing to provide the Service and perform Provider's obligations in the Main Agreement (including this DPA) and (ii) other reasonable documented instructions of Customer consistent with the terms of the Main Agreement. Details regarding the Processing of Customer Personal Data by Provider are set forth in the Processing Details. Provider will notify Customer if it receives an instruction that Provider reasonably determines infringes Data Protection Laws (but Provider has no obligation to actively monitor Customer's compliance with Data Protection Laws). Confidentiality. Provider will protect Customer Personal Data in accordance with its confidentiality obligations as set forth in the Main Agreement. Provider will ensure personnel who Process Customer Personal Data either enter into written confidentiality agreements or are subject to statutory obligations of confidentiality. Compliance with Laws. Provider and Customer will each comply with Data Protection Laws applicable to their respective Processing of Customer Personal Data. Customer will comply with Data Protection Laws in its issuing of Customer Instructions to Provider. Customer will ensure that it has established all necessary lawful bases under Data Protection Laws to enable Provider to lawfully Process Customer Personal Data for the purposes contemplated by the Main Agreement (including this DPA), including, as applicable, by obtaining all consents from, and giving all necessary notices to, Data Subjects, as required by Data Protection Laws. Changes to Laws. The parties will work together in good faith to negotiate an amendment to this DPA as either party reasonably considers necessary to address the requirements of Data Protection Laws from time to time. Subprocessors. Use of Subprocessors. Customer generally authorizes Provider to engage Subprocessors to Process Customer Personal Data. Customer further agrees that Provider may engage its Affiliates as Subprocessors. Provider will: (i) enter into a written agreement with each Subprocessor imposing data Processing and protection obligations substantially the same as those set out in this DPA and (ii) remain liable for Provider's compliance with its obligations under this DPA and for any acts or omissions of a Subprocessor that cause Provider to breach any of its obligations under this DPA. Subprocessor List. Provider will maintain an up-to-date list of its Subprocessors, including their functions and locations, as specified in the Subprocessor List. Notice of New Subprocessors. Provider may update the Subprocessor List from time to time. At least 30 days before any new Subprocessor Processes any Customer Personal Data, Provider will add such Subprocessor to the Subprocessor List and notify Customer in accordance with the Subprocessor Notice Method. Objection to New Subprocessors. If, within 30 days after notice of a new Subprocessor, Customer notifies Provider in writing that Customer objects to Provider's appointment of such new Subprocessor based on reasonable data protection concerns, the parties will discuss such concerns in good faith. If the parties are unable to reach a mutually agreeable resolution to Customer's objection to a new Subprocessor, Customer, as its sole and exclusive remedy, may terminate the affected portion of the Service by providing written notice to Provider, and Provider will refund any prepaid, unused fees attributable to the terminated portion of the Service as of the date of such termination. Security. Technical and Organizational Measures. Provider will implement and maintain reasonable and appropriate technical and organizational measures, procedures and practices, as appropriate to the nature of the Customer Personal Data, that are designed to protect the security, confidentiality, integrity and availability of Customer Personal Data and protect against Security Incidents, in accordance with Provider's Security Measures. Provider will regularly monitor its compliance with such Security Measures. Incident Notice and Response. Provider will implement and follow procedures to detect and respond to Security Incidents. Provider will: (i) notify Customer without undue delay and, in any event, not later than the Specified Notice Period, after becoming aware of a Security Incident affecting Customer and (ii) make reasonable efforts to identify the cause of the Security Incident, mitigate the effects and remediate the cause to the extent within Provider's reasonable control. Upon Customer's request and taking into account the nature of the applicable Processing, Provider will assist Customer by providing, when available, information reasonably necessary for Customer to meet its Security Inciden…