Data Processing Addendum

SCHEDULE 1 — DESCRIPTION OF THE PROCESSING OF PERSONAL DATA

  1. The Project

    The Vendor's Zero Trust Network Access (ZTNA) platform securely connects onsite and remote users to authorized assets, in the organizational network, cloud or IoT environments and even offline networks, regardless of where they are or what device they are using. the Vendor ensures secure access to applications, resources, workstations, servers and files, without granting risky network access to information assets.

  2. Data Subjects

    The personal data processed concern the following categories of data subjects:

    Users of the Products as defined in the Principal Agreement.

  3. Categories of Personal Data

    The personal data processed concern the following categories of personal data:

    Full Name, E-mail address, User Locations, IP number, location tracking, phone number.

  4. Purpose of the Personal Data Processing

    • To ensure Company's continuity with controlled access and secure remote access;

    • To facilitate collaboration with secure cross organizational connectivity;

    • To employ dynamic risk-based access to improve security and user experience;

    • To increase accuracy of secure access with granular visibility and control;

    • To use MFA;

    • To optimize management with easy deployment and scaling abilities of the Company.

  5. Processing Operations

    The personal data processed will be subject to the following basic processing activities:

    Collection of data, storage and anonymization.

  6. Duration of Processing

    The personal data will be processed during the term of the Principal Agreement.

  7. Security Measures

    Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Vendor shall in relation to the Company Personal Data implement appropriate technical and organizational measures to reasonably ensure a level of security appropriate to that risk.

SCHEDULE 2 — SUB PROCESSORS

The Vendor’s current list of Sub-processors is available at the following URL (as may be updated by Vendor from time to time):

https://status.cyolo.io/