Successware® Software License Agreement

Effective September 13, 2021

In connection with the Subscription Agreement, Successware licenses the Software licensed to, and paid for by, the Customer on the following terms and Conditions:

  1. LICENSE / TITLE.
    1. License. During the Term (defined below) of this Agreement and subject to Customer’s compliance with all terms and conditions herein, Successware grants to Customer and Customer accepts from Successware a limited, non-exclusive, non-transferrable, non-sublicensable license to install and use the Software licensed to and paid for by Customer on the number of computers for which Customer has purchased licenses (each a “Designated System”), in each case solely for Customer’s internal business use and not for the benefit of any other person or entity. Customer may make a reasonable number of backup copies of the Software solely for Customer’s internal use pursuant to the license granted in this Section.
    2. Ownership. Notwithstanding anything to the contrary in this Agreement, and except for the limited license rights expressly provided herein, Customer acknowledges that Successware and its suppliers and licensors have and will retain all rights, title and interest in and to the Software and all copies, modifications, and derivative works of the Software.
  2. SITE PREPARATION / DELIVERY / INSTALLATION.
    1. CUSTOMER SYSTEMS. Customer is responsible for (a) obtaining, deploying and maintaining all equipment necessary for Customer to access and use the Software on Customer Systems; (b) all maintenance and repairs to the Customer Systems; (c) obtaining and maintaining sufficient Internet access to accommodate remote support (d) providing competent personnel to operate and administer the Software who possess knowledge, training, and experience in accounting principles, practices, and business procedures; (e) providing sufficient opportunity for Successware to train Customer’s users at times and sites agreeable to Successware; and (f) paying all third-party fees and access charges incurred in connection with the foregoing. Except as specifically set forth in this Agreement or an applicable Subscription Agreement, Successware shall not be responsible for supplying any hardware, software or other equipment to Customer under this Agreement.
  3. RESTRICTIONS.
    1. Customer shall not, directly or indirectly, and Customer shall not permit any third party to: (a) reverse engineer, decompile, disassemble or otherwise attempt to discover the source code or underlying ideas or algorithms of the Software; (b) modify, translate, or create derivative works based on any element of the Software or any related documentation; (c) rent, lease, distribute, sell, resell, assign, or otherwise transfer its rights to use the Software; (d) use the Software for timesharing purposes or otherwise for the benefit of any person or entity other than for the benefit of Customer; (e) use the Software for any purpose other than its intended purpose; (f) interfere with or disrupt the integrity or performance of the Software; or (g) attempt to gain unauthorized access to the Software or its related systems or networks.
    2. Except as expressly permitted herein, Customer shall not copy, in whole or in part, any Software or documentation related to the Software. If Customer wishes to create an archival copy of the Software, Customer must receive written consent from Successware prior to making such copy.
    3. The Software is the Confidential Information of Successware and/or its licensors and vendors.
    4. Customer shall not remove or cause to be removed any copyright or proprietary notices from the Software or documentation and all such notices shall be retained or reproduced in their exact form on all permitted copies and versions, both in machine and human-readable language.
    5. Customer shall at all times maintain records specifically identifying the Software licensed hereunder, the location of each copy thereof, and the location of the Designated System on which the Software is installed. Such records shall be subject to inspection by Successware during regular business hours upon reasonable advanced notice for the purposes of enforcement of the terms and conditions of this Agreement.
  4. WARRANTIES / MAINTENANCE AND DISCLAIMER.
    1. SOFTWARE. Successware warrants, for the first ninety (90) days after the delivery of the Software (“Warranty Period”), that the Software will function substantially in conformance with Successware’s supplied user documentation (as revised by Successware from time to time). If Customer becomes aware of the Software not functioning in substantial conformance with such documentation (a “Defect”), Customer must provide Successware with written notice that includes a reasonably detailed explanation of the Defect within the Warranty Period. If Successware is able to reproduce the Defect in Successware’s own operating environment, Successware will use commercially reasonable efforts to promptly correct the Defect or provide a replacement software product to Customer with substantially similar functionality, or at Successware’s option, terminate this Agreement for the defective Software and refund to Customer the fees paid for the defective Software for the Initial Term. THE FOREGOING SETS FORTH SUCCESSWARE’S SOLE AND EXCLUSIVE REMEDY FOR ANY DEFECTIVE SOFTWARE.
    2. DISCLAIMER. EXCEPT FOR THE EXPRESS WARRANTIES SET FORTH IN THIS SECTION 4.2, THE SOFTWARE AND ANY RELATED SERVICES PROVIDED BY SUCCESSWARE ARE PROVIDED ON AN AS-IS BASIS. CUSTOMER’S USE OF THE SOFTWARE IS AT ITS OWN RISK. SUCCESSWARE DOES NOT MAKE, AND HEREBY DISCLAIMS, TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, ANY AND ALL OTHER EXPRESS, STATUTORY AND IMPLIED REPRESENTATIONS AND WARRANTIES, INCLUDING, BUT NOT LIMITED TO, WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NONINFRINGEMENT AND TITLE, AND ANY WARRANTIES ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE. SUCCESSWARE DOES NOT WARRANT THAT: (A) THE USE OF THE SOFTWARE WILL BE TIMELY, UNINTERRUPTED OR ERROR-FREE OR OPERATE IN COMBINATION WITH ANY OTHER HARDWARE, SOFTWARE, SYSTEM OR DATA; (B) THE SOFTWARE WILL MEET CUSTOMER’S REQUIREMENTS OR EXPECTATIONS; (C) THE SOFTWARE IS FREE OF MALICIOUS CODE; OR (D) THE SOFTWARE WILL BE ERROR-FREE OR THAT ERRORS OR DEFECTS IN THE SOFTWARE WILL BE CORRECTED.
  5. Reporting. Customer will promptly notify Successware if the number of Customer Systems exceeds the number of Customer Systems for which Customer has paid the applicable fees. In its notice, Customer will include both the number of additional Customer Systems and the date(s) on which such Customer Systems were put into use. Successware will invoice Customer for the applicable Software for such Customer Systems on a pro-rata basis and Customer will pay for such Software in accordance with this Agreement.
  6. Inspection. During the Term, Successware or its designated agent may inspect and review Customer's records in order to verify Customer's compliance with this Agreement.
  7. GENERAL.
    1. Notice. Successware may give notice to Customer by means of electronic mail to Customer’s e-mail address on record with Successware, or by written communication sent by first class postage prepaid mail or nationally recognized overnight delivery service to Customer’s address on record with Successware. Customer may give notice to Successware by written communication sent by first class postage prepaid mail or nationally recognized overnight delivery service addressed to SuccessWare SPE, LLC Inc., PO Box 568, Clarence, NY 14031, Attention: President. Notice shall be deemed to have been given upon receipt or, if earlier, two (2) business days after mailing, as applicable. All communications and notices to be made or given pursuant to this Agreement shall be in the English language. All communications and notices to be made or given pursuant to this Agreement shall be in the English language.
    2. Venue and Governing Law. This Agreement and the rights and obligations of the parties to and under this agreement shall be governed by and construed under the laws of the United States and the State of Delaware as applied to agreements entered into and to be performed in such State without giving effect to conflicts of laws rules or principles. The parties agree that the United Nations Convention on Contracts for the International Sale of Goods is specifically excluded from application to this Agreement. The parties further agree to waive and opt-out of any application of the Uniform Computer Information Transactions Act (UCITA), or any version thereof, adopted by any state of the United States in any form. Any disputes arising out of or in connection with this Agreement, including but not limited to any question regarding its existence, interpretation, validity, performance or termination, or any dispute between the parties arising from the parties’ relationship created by this Agreement, shall be heard in the state and federal courts located in or servicing the State of Delaware and the parties hereby consent to exclusive jurisdiction and venue in such courts.
    3. Freedom to Use Ideas. Customer grants Successware a worldwide, non-exclusive license to any ideas, methods, concepts, know-how, structures, techniques, inventions, developments, processes, discoveries, improvements and other information and materials developed in and during the course of this Agreement.
    4. Non-solicitation. Customer agrees that, during the term of this Agreement and for a period of one (1) year following its termination, it will not directly solicit for employment the employees of Successware without Successware’s prior written consent; provided, however, that the foregoing prohibition shall not preclude the hiring by Customer of any individual who responds to a general solicitation or advertisement, whether in print or electronic form, only job postings and social networking sites.
    5. Government Entities. If Customer is a United States Federal Government entity (“Federal Government”), Successware provides the Software, including related software and technology, for ultimate Federal Government end use solely in accordance with the following: Federal Government technical data rights include only those rights customarily provided to the public with a commercial item or process and Federal Government software rights related to the Software include only those rights customarily provided to the public, as defined in this Agreement. The technical data rights and customary commercial software license is provided in accordance with FAR 12.211 (Technical Data) and FAR 12.212 (Software) and, for Department of Defense transactions, DFAR 252.227-7015 (Technical Data – Commercial Items) and DFAR 227.7202-3 (Rights in Commercial Computer Software or Computer Software Documentation). If greater rights are needed, a mutually acceptable written addendum specifically conveying such rights must be included in this Agreement.
    6. Export Controls. The Software utilizes software and technology that may be subject to United States and foreign export controls. Customer acknowledges and agrees that the Services shall not be used, and none of the underlying information, software, or technology may be transferred or otherwise exported or re-exported to countries as to which the United States maintains an embargo (collectively, “Embargoed Countries”), or to or by a national or resident thereof, or any person or entity on the U.S. Department of Treasury’s List of Specially Designated Nationals or the U.S. Department of Commerce’s Table of Denial Orders (collectively, “Designated Nationals”). The lists of Embargoed Countries and Designated Nationals are subject to change without notice. By using the Software, Customer represents and warrants that it is not located in, under the control of, or a national or resident of an Embargoed Country or Designated National. The Software may use encryption technology that is subject to licensing requirements under the U.S. Export Administration Regulations, 15 C.F.R. Parts 730-774 and Council Regulation (EC) No. 1334/2000. Customer agrees to comply strictly with all applicable export laws and assume sole responsibility for obtaining licenses to export or re-export as may be required. Successware and its licensors make no representation that the Software is appropriate or available for use in other locations.
    7. Electronic Signature and Disclosure Consent Notice. Customer agrees to the use of electronic documents and records in connection with this Agreement and all future documents and records in connection with the Software and Services—including this electronic signature and disclosure notice—and that this use satisfies any requirement that Successware provides Customer these documents and their content in writing. If Customer does not agree, do not enter into this Agreement. Customer has the right to receive a paper copy of all documents and records if and to the extent required under applicable law. Customer may (a) obtain a paper copy of any document or record (free of charge), (b) withdraw Customer’s consent to the use of electronic documents and records, or (c) update Customer’s contact information through Customer’s account. To receive or access electronic documents and records, Customer must have the following equipment and software: (i) a device that is capable of accessing the Internet, (ii) a compatible Internet browser, and (iii) software that permits Customer to receive and access Portable Document Format or "PDF" files, such as Adobe Acrobat Reader 8.0 or higher. To retain documents and records, Customer’s device must have the ability to download and store PDF files. Your access to this page verifies that Customer’s system and device meets the above receipt, access, and retention requirements.
    8. Assignment / Modifications. Customer shall not assign its rights hereunder, or delegate the performance of any of its duties or obligations hereunder, whether by merger, acquisition, sale of assets, operation of law, or otherwise, without the prior written consent of Successware. Any purported assignment by Customer in violation of the preceding sentence is null and void. We have the right to transfer or assign all or any portion of our rights or obligations under this Agreement to any person or legal entity. The assignee will expressly assume our obligations and become solely responsible for them from the effective date of assignment. Successware can sell our assets, sell securities in a public offering or in a private placement; merge with, acquire, or be acquired by another company; or undertake a refinancing, recapitalization, leveraged buy-out, or other economic or financial restructuring, without restriction and without affecting Customer’s obligations under this Agreement. Subject to the foregoing, this Agreement shall be binding upon, and inure to the benefit of, the successors and assigns of the parties thereto. Except as otherwise specified in this Agreement, this Agreement may be amended or supplemented only by a writing that refers explicitly to this Agreement and that is signed on behalf of both parties.
    9. Waiver. No waiver will be implied from conduct or failure to enforce rights. No waiver will be effective unless in a writing signed on behalf of the party against whom the waiver is asserted. If any of this Agreement is found invalid or unenforceable that term will be enforced to the maximum extent permitted by law and the remainder of this Agreement will remain in full force.
    10. Independent Contractors. The parties are independent contractors and nothing contained herein shall be construed as creating an agency, partnership, or other form of joint enterprise between the parties.
    11. Entire Agreement This Agreement, including all applicable Subscription Agreements, constitute the entire agreement between the parties relating to this subject matter and supersedes all prior or simultaneous understandings, representations, discussions, negotiations, and agreements, whether written or oral.
    12. Force Majeure. Except for Customer’s payment obligations hereunder, neither party shall be liable to the other party or any third party for failure or delay in performing its obligations under this Agreement when such failure or delay is due to any cause beyond the control of the party concerned, including, without limitation, acts of God, governmental orders or restrictions, fire, or flood, provided that upon cessation of such events such party shall thereupon promptly perform or complete the performance of its obligations hereunder.

DATA PROCESSING ADDENDUM

This Data Processing Addendum (“Addendum”) forms a part of any applicable terms and conditions, agreements, exhibits, annexes, appendices, or other attachments which it is incorporated into between the named Customer in the applicable agreement (“Customer”) and Successware SPE LLC (“Service Provider”) related to Service Provider’s provision of certain products and services (collectively, the “Services”) (the “Agreement”). Except as modified herein, the terms of the Agreement shall remain in full force and effect.

The parties hereby agree that the terms and conditions set out below shall be added as an Addendum to the Agreement.

  1. Definitions. For purposes of this Addendum, the following terms will have the meanings set forth below. Capitalized terms used but not otherwise defined in this Addendum will have the meaning given to them in the Agreement.
    1. “Affiliate” means an entity that owns or controls, is owned or controlled by, or is under common control or ownership with, either Customer or Service Provider, respectively. “Control,” for purposes of this definition, means the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise.
    2. “Customer Personal Data” means any Personal Data received by Service Provider or a Subprocessor on behalf of Customer in connection with the Agreement, or any Personal Data created or otherwise Processed by Service Provider or Subprocessor pursuant to the Agreement.
    3. “Data Protection Laws” means any and all laws, rules and regulations related to privacy, security, data protection, and/or the Processing of Personal Data, in any relevant jurisdiction, each as amended, replaced or superseded from time to time.
    4. “Data Subject” means the identified or identifiable person to whom Personal Data relates.
    5. “Deidentified Information” means information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular Data Subject.
    6. “Personal Data” means (a) information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular person or household; and (b) any information defined as “personal data”, “personal information,” or other similar terms under applicable Data Protection Laws.
    7. “Personal Data Breach” means the accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise Processed by Service Provider or any Subprocessor.
    8. “Processing” means any operation or set of operations that is performed upon Personal Data, whether or not by automatic means, such as access, collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, return or destruction. The terms “Process”, “Processes” and “Processed” will be construed accordingly.
    9. “Processor” means any person or entity which Processes Customer Personal Data, including as applicable any “service provider” or “contractor” as those terms are defined by applicable Data Protection Laws.
    10. “Regulator” means any independent public authority, government agency, and any similar regulatory authority responsible for the enforcement of Data Protection Laws.
    11. “Subprocessor” means any Processor (including any third party and any Service Provider Affiliate) appointed by or on behalf of Service Provider who may Process Customer Personal Data.
  2. Processing of Personal Data
    1. Subject to Service Provider’s compliance with this Addendum, Customer agrees to make Customer Personal Data available to Service Provider for the limited and specified purpose of providing the Services as contemplated by the Agreement. The subject-matter and details of Service Provider’s Processing (including the duration of the Processing, the nature and purpose of the Processing, the types of Personal Data and categories of Data Subjects) are set forth in Exhibit 1 attached to this Addendum.
    2. Service Provider acknowledges and agrees that, with regard to the Processing of Customer Personal Data, Service Provider is acting as a Processor. Service Provider further certifies that Service Provider (a) understands the obligations and restrictions imposed on it by applicable Data Protection Laws in its role as a Processor; (b) will comply with all such obligations, including providing the same level of privacy protection as required by applicable Data Protection Laws; and (c) will notify Customer immediately if Service Provider determines it can no longer meet its obligations under applicable Data Protection Laws or this Addendum. Customer reserves the right to take reasonable and appropriate steps to help ensure that Service Provider Processes Customer Personal Data in a manner consistent with Customer’s obligations under Data Protection Laws, including without limitation, the right upon notice to stop and remediate any unauthorized Processing of Customer Personal Data.
    3. Service Provider will only Process Customer Personal Data on behalf of Customer (a) to the extent, and in such a manner, as is necessary for the purposes of fulfilling its obligations under the Agreement; and (b) in accordance with the terms of the Agreement and this Addendum, which together constitute Customer’s instructions. The restrictions set forth in this section shall not restrict Service Provider’s ability to Process Customer Personal Data where required/permitted to do so by applicable laws to which Service Provider is subject; provided, however, Service Provider shall notify Customer of such legal requirement before Processing, where required by applicable Data Protection Laws and unless such law prohibits such notification.
    4. Without limiting Service Provider’s obligations under Section 2.3, Service Provider will not:
      1. retain, use, or disclose Customer Personal Data for any purpose other than to perform its obligations under the Agreement, which for the avoidance of doubt prohibits Service Provider from retaining, using, or disclosing Customer Personal Data outside of the direct business relationship with Customer or for any other purpose;
      2. “sell” or “share” (as those terms are defined by applicable Data Protection Laws) Customer Personal Data; or
      3. combine Customer Personal Data with Personal Data Service Provider receives from or on behalf of another person or entity or collects from its own interactions with a Data Subject except to perform a business purpose as defined in regulations adopted pursuant to Cal. Civ. Code 1798.185(a)(10).
    5. If Service Provider receives Deidentified Information from Customer, or creates Deidentified Information at Customers instruction, Service Provider will (a) take reasonable measures to ensure the Deidentified Information cannot be associated with a Data Subject or household, (b) publicly commit to maintain and use the Deidentified Information in deidentified form, and (c) not attempt to reidentify the Deidentified Information except for the sole purpose of determining whether the Service Provider’s deidentification processes satisfy the requirements of applicable Data Protection Laws.
    6. Notwithstanding any other provision in this Section, Service Provider may internally use Customer Personal Data to build or improve the quality of the Services it provides to Customer.
    7. If Customer is a franchisee of Service Provider’s parent, AB Assetco LLC or its Affiliates (“Authority Brands”), Customer hereby acknowledges that Service Provider may, except as prohibited by applicable Data Protection Laws, share Personal Data and other information received from Customer with other franchisees of Authority Brands. This Section 2.7 does not apply if Customer is not an Authority Brands franchisee.
  3. Service Provider Personnel. Service Provider will take reasonable steps to ensure that access to Customer Personal Data is limited to those of its Affiliates, employees, agents, and subcontractors who (a) have a need to know or otherwise access Customer Personal Data to enable Service Provider to perform its obligations under the Agreement and this Addendum, and (b) who are bound in writing by confidentiality obligations sufficient to protect the confidentiality of Customer Personal Data in accordance with the terms of this Addendum.
  4. Security. Service Provider will implement and maintain appropriate technical and organizational safeguards to protect Customer Personal Data that are no less rigorous than accepted industry standards for information security and will ensure that all such safeguards comply with applicable Data Protection Laws. Such safeguards are further specified in Exhibit 2 attached to this Addendum. In assessing the appropriate level of security, Service Provider will take into account the risks that are presented by Processing, in particular from accidental, unauthorized, or unlawful destruction, loss, alteration, damage, disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise Processed.
  5. Personal Data Breach. In the event of a Personal Data Breach impacting Customer Personal Data, Service Provider will (a) notify Customer as soon as practicable under the circumstances, after Service Provider or any Subprocessor becomes aware of such Personal Data Breach; (b) provide Customer with sufficient details of the Personal Data Breach to allow Customer to meet any obligations under Data Protection Laws to report or inform Data Subjects or relevant Regulators of the Personal Data Breach; and (c) cooperate, and require any Subprocessor to cooperate, with Customer in the investigation, mitigation, and remediation of any such Personal Data Breach.
  6. Subprocessors
    1. Customer hereby authorizes those Subprocessors listed in Exhibit 1 to this Addendum. Service Provider shall provide written notice to Customer of any subsequent changes in the list of pre-approved Subprocessors and will provide Customer a reasonable amount of time to reasonably object to the appointment of a new Subprocessor. If Customer does not object to the engagement of a new Subprocessor in accordance with Section 6.1, that Subprocessor will be deemed as authorized.
    2. If Customer reasonably objects to an engagement in accordance with Section 6.1 and Service Provider cannot provide a commercially reasonable alternative within a reasonable period of time, Service Provider may terminate the Agreement or this Addendum. Termination shall not relieve Customer of any fees owed to Service Provider under the Agreement, for Services rendered up to the effective date of the termination, unless such engagement would result in Service Provider’s material breach of this Addendum.
    3. With respect to any authorized Subprocessor, Service Provider will enter into a written agreement with each Subprocessor containing the same obligations imposed on Service Provider under this Addendum and applicable Data Protection Laws with respect to Customer Personal Data.
  7. Data Subject Rights
    1. Service Provider will promptly notify Customer if it receives a request from a Data Subject regarding Customer Personal Data, including a request by a Data Subject to exercise a right under Data Protection Laws.
    2. Service Provider will provide reasonable assistance to Customer in fulfilling Customer’s obligations to respond to such requests, including at minimum, maintaining the ability to access, modify, remove from Processing, or irrevocably delete or destroy the Personal Data of an individual Data Subject when requested by Customer.
    3. Should the Service Provider or any Subprocessor directly perform any data collection from Data Subjects in connection with the Customer’s instructions, the Service Provider will ensure that Data Subjects receive the Customer’s Privacy Policy at or before the point at which any information is collected about the Data Subject.
  8. Deletion or Return of Customer Personal Data
    1. At any time during the term of the Agreement at Customer’s request, or upon the termination or expiration of the Agreement for any reason, Service Provider will, and will instruct all Subprocessors to, promptly or in any event within sixty (60) calendar days of the effective date of termination (a) return to Customer all copies of Customer Personal Data in its possession, or the possession of such Subprocessor, or (b) delete and procure the deletion of all other copies of Customer Personal Data Processed by Service Provider or any Subprocessor. Service Provider will comply with all reasonable directions provided by Customer with respect to the return or deletion of Customer Personal Data.
    2. Notwithstanding Section 8.1 above, Service Provider may retain Customer Personal Data if required by applicable Data Protection Laws, but only to the extent and for such period as required by such legal requirement. Service Provider will notify Customer in writing if it believes that such a legal requirement exists. If required by law to retain Customer Personal Data, Service Provider will continue to ensure the security and confidentiality of such Customer Personal Data and only Process such Customer Personal Data as necessary for the purpose specified in the applicable Data Protection Laws requiring such storage.
  9. Compliance and Audits
    1. Upon Customer’s request, Service Provider will provide such assistance as Customer reasonably requires in ensuring compliance with Customer’s obligations under applicable Data Protection laws, including but not limited to any data protection impact assessments and any prior consultations with any Regulator where required.
    2. In addition to any audit rights Customer may have under the Agreement, Service Provider will make available to Customer all reasonably requested information necessary to demonstrate Service Provider’s compliance with this Addendum, as well as any applicable Data Protection Laws, and will allow for and contribute to audits or a third-party auditor mandated by Customer, at Customer’s sole expense, in order to assess Service Provider’s compliance. Service Provider will provide reasonable cooperations with such audits or assessments by providing reasonable access to knowledgeable personnel; and any relevant records, documentation, processes, and systems in order that Customer may satisfy itself of Service Provider’s compliance with this Addendum.
    3. Service Provider will notify Customer if it determines (a) it is not in compliance with this Agreement or Data Protection Law, or (b) it can no longer meet its obligations under this Agreement or Data Protection Law.
  10. International Data Transfers. Service Provider will not transfer (nor permit to be transferred) Customer Personal Data to a third party or a location outside the territory from which the Customer Personal Data originated without Customer’s prior written consent unless applicable Data Protection Laws permit such transfers. Insofar as the Agreement involves the transfer of Customer Personal Data from a jurisdiction where applicable Data Protection Laws requires that additional steps, or safeguards, be imposed before the data can be transferred to a second jurisdiction, Service Provider agrees to cooperate with Customer to take appropriate steps to comply with applicable Data Protection Laws. If Customer is located in Canada, note that Personal Data will be transferred and retained in the US.
  11. Changes in Data Protection Laws. If any variation is required to this Addendum as a result of a change in or subsequently applicable Data Protection Laws, Service Provider may make any variations to this Addendum necessary to address such changes.
  12. General Terms. Should any provision of this Addendum be invalid or unenforceable, then the remainder of this Addendum will remain valid and in force. The invalid or unenforceable provision will be either: (a) amended as necessary to ensure its validity and enforceability, while preserving the intent of the provision as closely as possible or, if this is not possible, (b) construed in a manner as if the invalid or unenforceable part had never been contained therein. This Addendum and the other portions of the Agreement will be read together and construed, to the extent possible, to be in concert with each other. In the event of any conflict between the Agreement and this Addendum, this Addendum will govern with respect to the subject matter of this Addendum.

List of Exhibits:

Exhibit 1: Details of Processing

Exhibit 2: Description of Technical and Organizational Security Measures

Exhibit 1

Details of Processing

  1. Subject Matter of Processing
    The subject-matter of Processing of Customer Personal Data by Service Provider is the performance of the Services pursuant to the Agreement.
  2. Nature and Purpose of Processing
    Customer Personal Data will be Processed as necessary to perform the Services pursuant to the Agreement.
  3. Duration of Processing
    Subject to section 8 of the Addendum, Service Provider will Process Customer Personal Data for the duration of the Agreement, unless otherwise agreed upon in writing.
  4. Categories of Data Subjects
    The types of Data Subject shall be as is contemplated or related to the Processing described in the Agreement.
  5. Types of Personal Data
    The types of Customer Personal Data shall be as is contemplated or related to the Processing described in the Agreement.
  6. List of Subprocessors
    The following table sets out the list of Subprocessors that Customer has specifically authorized as of the Effective Date.

Entity Name

Entity Country

Description of Service/Processing Activity

Cybersource Corporation

United States

Payment Processing

Hubspot, Inc.

United States

Contract management and customer communications

Zendesk, Inc.

United States

Customer support

Microsoft Corporation

United States

Business analytics

Exhibit 2

Description of Technical and Organizational Security Measures

Service Provider will implement and maintain appropriate technical and organizational measures to meet its obligations under applicable Data Protection Laws. For example, Service Provider will:

Access Control

  • Role-based access control (RBAC) to ensure only authorized personnel have access to systems and data.
  • Strong password policies and multi-factor authentication (MFA) for system access.

Physical Security

  • Data centers operated by certified third-party providers with 24/7 security, surveillance, and restricted access controls.
  • Access to facilities is limited to authorized personnel with appropriate clearance.

Data Backup and Recovery

  • Regular, automated backups of systems storing Personal Data.

Incident Detection and Response

  • Formal incident response procedures including investigation, containment, and notification in compliance with applicable laws.

Employee Awareness and Training

  • Security and privacy awareness training for all employees.
  • Confidentiality agreements signed by employees and contractors with access to Personal Data.

Vendor and Subprocessor Oversight

  • Subprocessors are contractually obligated to implement security measures equivalent to those of the Processor.

Data Minimization and Retention

  • Personal Data is limited to what is necessary for the processing purpose.
  • Retention periods are defined and enforced based on legal and business requirements.