This Data Processing Addendum (“Addendum”) forms part of the End User License Agreement (“Principal Agreement”) between: (i) Cyolo Security Ltd. (or, if applicable, the other Cyolo Security entity specified in the Order Form) (“Vendor”) acting on its own behalf and as agent for each Vendor affiliate; and (ii) the customer specified in the Order Form or the Product registration page, as the case may be (“Company”).
In consideration of the mutual obligations set out herein, the Parties hereby agree that the terms and conditions set out below shall be added as an Addendum to the Principal Agreement. Except where the context requires otherwise, references in this Addendum to the Principal Agreement are to the Principal Agreement as amended by, and including, this Addendum. Except as modified below, the terms of the Principal Agreement shall remain in full force and effect. This Addendum shall prevail for Personal Data purposes in case of contradiction with the Principal Agreement.
Under the Principal Agreement the nature and purposes of processing Personal Data by the Vendor as data processor shall be limited to those set forth in Schedule 1.
Definitions
In this Addendum, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:
“Applicable Laws” means (a) European Union or Member State laws with respect to any Company Personal Data in respect of which any Company is subject to EU Data Protection Laws; (b) the California Privacy Rights Act (“CPRA”) with respect to any Company Personal Data in respect of which any Company Group Member is subject to the CPRA, (c) Israeli Data Protection Law and underlying regulations, and (d) any other applicable law with respect to any Company Personal Data in respect of which any Company is subject to any other Data Protection Laws;
“Adequacy Recognition” means the recognition of a territory by the European Commission as providing adequate protection to Personal Data;
“Company Personal Data” means any Personal Data Processed by Vendor on behalf of a Company pursuant to or in connection with the Principal Agreement;
“Data Protection Laws” means EU Data Protection Laws, the CPRA and, to the extent applicable, the data protection or privacy laws of any other country;
“EEA” means the European Economic Area;
“EU Data Protection Laws” means the GDPR and any applicable national data protection laws implementing or supplementing the GDPR, in each case as amended, replaced or superseded from time to time;
“GDPR” means EU General Data Protection Regulation 2016/679;
“Restricted Transfer” means:
a transfer of Company Personal Data from any Company to Vendor; or
an onward transfer of Company Personal Data from Vendor to a Sub-processor, or between two establishments of Vendor,
in each case, where such transfer would be prohibited by Data Protection Laws (or by the terms of data transfer agreements put in place to address the data transfer restrictions of Data Protection Laws) in the absence of appropriate safeguards such as the Standard Contractual Clauses, the EU-US Data Privacy Framework or any other lawful transfer mechanism recognized under the applicable Data Protection Laws;
“Services” means the services and other activities to be supplied to or carried out by or on behalf of Vendor for Company pursuant to the Principal Agreement;
“Standard Contractual Clauses” means the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, as adopted by the European Commission in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as may be amended, replaced or supplemented from time to time;
“Sub-processor” means any person (including any third party and any Vendor affiliate, but excluding an employee of Vendor or any of its sub-contractors) appointed by or on behalf of Vendor to Process Personal Data on behalf of the Company in connection with the Principal Agreement;
“Vendor” means Vendor and any entity that owns or controls, is owned or controlled by or is or under common control or ownership with Vendor, where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise;
“Party”/”Parties” means the Company and the Vendor separately, or jointly, as the case may be;
“Purpose” means as described in Schedule 1; and
“Supervisory Authority” means any court, regulatory agency or authority which, according to Applicable Laws and/or regulations, supervises privacy issues and/or the processing of personal data.
The terms, “commission”, “controller”, “data subject”, “member state”, "service provider", “contractor”, "business", "customer", "business purpose", "commercial purpose", “personal data” or "personal information", or "Information of Special Sensitivity", “personal data breach”, “processing”, “processor”, "sale", “share” and “supervisory authority” shall have the same meaning as in the GDPR or in the CPRA, or in the Israeli Data Protection Law as applicable, and their cognate terms shall be construed accordingly. In addition, each of the terms defined in this section 4.2 shall have the meaning of its equivalent in the GDPR or in the CPRA, as applicable.
Special Undertakings of the Parties
Roles, ownership of personal data, processing and purpose
The Company shall be considered, in the context of the CPRA as the business, and in the context of the GDPR as the controller of the personal data processed on its behalf and in accordance with its instructions, which concerns its respective data subjects, or customer, as applicable. The Vendor shall be considered, in the context of the CPRA as the service provider or the contractor, and in the context of the GDPR, as a processor of the personal data processed on behalf of the Company.
The Company pays Vendor service fees in consideration for the Services to be provided by Vendor pursuant to the Principal Agreement. Vendor does not receive from the Company and the Company does not pay Vendor any monetary or other valuable consideration for Vendor’s Collection of the Company Personal Data on behalf of the Company.
The Vendor may only process the Company Personal Data for the Purpose and to the extent it is necessary for the fulfilment of the Vendor’s obligations under this Addendum or the Principal Agreement.
Vendor is prohibited from: (i) Selling or sharing Company personal data; (ii) retaining, using, or disclosing Company personal data for any purpose, including for a commercial purpose, as defined in the CPRA, other than for the purposes specified in Schedule 1 or as permitted under this Section 5.1.4; (iii) retaining, using, or disclosing Company personal data outside of the direct business relationship between Vendor and Company; and (iv) combining the Company personal information that received pursuant to this Addendum or the Principal Agreement with personal information that the Vendor receives from or on behalf of another person or persons, or collects from its own interaction with the customer, except as permitted under this Section 5.1.4. Notwithstanding the foregoing, Vendor may use Company personal data in aggregated, de-identified, or anonymized form (in a manner that cannot reasonably identify any individual) to improve and develop its services and technology, provided that such use: (i) does not involve selling or sharing the data with third parties; and (ii) complies with all applicable Data Protection Laws. Vendor shall provide the Company with a certification that it understands the above restrictions and will comply with them.
This Addendum shall apply to the actions of any of Vendor or Company’s affiliates performing tasks and obligations in the context of this Addendum and any such affiliates shall have all rights and obligations set forth in this Addendum as if they were Vendor or Company, as applicable.
Special undertakings of the Company
The Company undertakes to:
Ensure that there is a legal ground for processing the personal data covered by this Addendum;
Ensure that any disclosure or transfer of Company Personal Data to Vendor confirms to the Applicable Laws.
Inform the Vendor about any erroneous, rectified, updated or deleted personal data subject to the Vendor’s processing;
Fully comply with any request of data subjects and with any data subject rights under Applicable Laws;
Provide the Vendor with documented instructions regarding the Vendor’s processing of the personal data, as may be required from time to time; and
Ensure that, to the extent it collects by itself the Personal Data processed by Vendor under this Addendum, or otherwise makes available such Personal Data to Vendor, it (i) collects, obtains and processes Personal Data lawfully, without violating any third parties' rights, contractual obligations or Data Protection Laws; (ii) it has all rights, consents, authorization and title to grant the rights and permissions to use the Personal Data under the terms of the Principal Agreement; (iii) its processing and use of the Personal Data will not violate the customers' rights and other third parties, including without limitation privacy, data protection, good-will, good name, publicity, confidentiality and intellectual property rights.
Ensure that only such employees that are handling consumer inquiries about the business’s privacy practices or the business’s compliance with the CPRA, have received appropriate training and instructions regarding the CPRA and especially sections 1798.100, 1798.105, 1798.106, 1798.110, 1798.115, 1798.120, 1798.121, 1798.125 and 1798.130 of the CPRA, and how to direct consumers to exercise their rights under such sections.
Ensure that, to the extent required under Applicable Laws, any database, filing, registration, notification, or report in respect of the Company Personal Data, or Information of Special Sensitivity is duly made with, or provided to, the competent Supervisory Authority or other competent authority, and that all such obligations are fulfilled in a timely and lawful manner.
Special undertakings of the Vendor
The Vendor undertakes to:
Only process the Company Personal Data in accordance with Applicable Laws and the Company documented instructions, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Applicable Laws; in such a case, the Vendor shall inform the Company of that legal requirement before processing the personal data, unless such information is prohibited by the Applicable Laws on important grounds of public interest;
Only use, retain or disclose Company personal information to the extent it is reasonably necessary to achieve the purposes of the processing under this Addendum or the Principal Agreement ;
Taking into account the nature of the processing, implement appropriate technical and organisational measures to reasonably ensure a level of security appropriate to the risk and reasonably assist the Company by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the obligations of the controller or the business, as applicable, to respond to requests for exercising the rights of the data subject or customer, as applicable, or with respect to data breaches in Applicable Laws;
To implement reasonable security procedures and practices appropriate to the nature of the Company personal information, at the same privacy protection level as the Company is required to under the CPRA; and
Make available to the Company all information reasonably necessary to demonstrate compliance with the obligations laid down in this Addendum and to notify the Company if the Vendor can no longer meet its obligations under this Addendum.
Processing of Company Personal Data
The Company:
instructs Vendor (and authorises Vendor to instruct each Sub-processor) to:
process Company Personal Data; and
in particular, transfer Company Personal Data to any country or territory,
as reasonably necessary for the provision of the Services and consistent with the Principal Agreement; and
Schedule 1 to this Addendum sets out certain information regarding the Vendor’s processing of the Company Personal Data. Company shall immediately inform Vendor of any required amendments to Schedule 1 by written notice to Vendor, and the Parties shall negotiate in good-faith the amendment of Schedule 1.
Confidentiality
Vendor shall take reasonable steps to ensure the reliability of any employee, agent or contractor of Vendor who may have access to the Company Personal Data, and to ensure that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.
Data Security.
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Vendor shall in relation to the Company Personal Data implement appropriate technical and organizational measures to reasonably ensure a level of security appropriate to that risk.
Taking into account the nature of the personal information and the privacy protection level the Company is required to under the CPRA, when applicable, Vendor shall implement reasonable security procedures and practices appropriate to protect the personal information from unauthorized or illegal access, destruction, use, modification or disclosure.
Sub-processing
Company authorizes Vendor to appoint (and permit each Sub-processor appointed in accordance with this Section 9 to appoint) the Sub-processors listed in Schedule 2 attached hereto, in accordance with this Section 9 and any restrictions in the Principal Agreement. Vendor shall be entitled (as a general written authorization) to add any sub-processor from Schedule 2 by updating Vendor’s then-current list of Sub-processors in Schedule 2 at the applicable URL set forth therein (and Company shall check the URL from time to time to see the most updated list), provided that the Company does not object the addition of any Sub-processor within three (3) days thereafter, provided that any such objection is based on reasonable and documented grounds relating to the Sub-processor's ability to comply with applicable Data Protection Laws. If Company objects to the addition of any Sub-processor to Schedule 2, the parties shall review such objection in good faith for a period of 30 days. If the parties are unable to reach agreement during such period, either party may terminate, as its sole remedy, this Addendum and the Principal Agreement, and all fees due to Vendor shall be immediately paid.
With respect to each Sub-processor, Vendor shall:
ensure that the arrangement between the Vendor, and the Sub-processor, is governed by a written contract including terms which offer at least the same level of protection for Company Personal Data as those set out in this Addendum; and
if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one Vendor and the Sub-processor.
Data Subject Rights
Vendor shall:
promptly notify Company if Vendor receives a request from a data subject or a customer, as applicable, under any Data Protection Law in respect of Company Personal Data; and
not respond to that request except on the documented instructions of Company or as required by Applicable Laws to which the Vendor is subject.
Where Company is required to delete or rectify Personal Data about a Data Subject, or customer, as applicable, it will direct Vendor accordingly and Vendor undertakes to immediately rectify or delete the Personal Data from its records.
Personal Data Breach
Vendor shall notify Company without any delay, but no later than within 48 hours, upon becoming aware of a Personal Data Breach affecting Company Personal Data, providing Company with reasonably sufficient information to allow Company to meet its obligations to report or inform Data Subjects or customers, as applicable, of the Personal Data Breach under the Data Protection Laws.
Vendor shall make reasonable efforts to identify the cause of such Personal Data Breach and take those steps as Vendor deems necessary, possible and reasonable in order to remediate the cause of such a Personal Data Breach to the extent the remediation is within Vendor’s reasonable control.
Vendor agrees to reasonably assist Company in advising the Supervisory Authority and data subjects or customers, as applicable, about Personal Data Breach. It shall not, however, inform any third party of any Personal Data Breach without first obtaining Company’s prior written consent, other than to inform a complainant (if any) that the matter has been forwarded to Company, or if otherwise required under any Applicable Law.
Data Protection Impact Assessment and Prior Consultation
Vendor shall provide reasonable assistance to Company, at Company’s expense, with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, in each case solely in relation to Processing of Company Personal Data by, and taking into account the nature of the Processing and information available to, the Vendor.
Cooperation and Coordination
Upon reasonable request by Company, Vendor shall as promptly and as reasonably practicable provide Company with information reasonably requested by Company relating to: (i) any security event and Personal Data Breach; or (ii) compliance with this Addendum. In addition, Vendor shall provide Company with any documents reasonably requested by Company related to the foregoing, including without limitation, any information security assessment and security control audit reports.
Deletion or Return of Company Personal Data
Subject to Section 14.2 Vendor shall promptly and in any event within fourteen (14) days of the date of termination or expiration of any Services involving the Processing of Company Personal Data (the “End Date”), or of the date of a written notice by Company, delete and procure the deletion of all copies of those Company Personal Data.
Vendor may retain Company Personal Data to the extent required by Applicable Laws and only to the extent and for such period as required by Applicable Laws and always provided that Vendor shall ensure the confidentiality of all such Company Personal Data and shall ensure that such Company Personal Data is only Processed as necessary for the purpose(s) specified in the Applicable Laws requiring its storage and for no other purpose.
Audit Rights
Vendor shall conduct site audits of the information technology and information security controls for all facilities used in complying with its obligations under this Addendum. Company shall treat such audit reports as Vendor’s confidential information.
Company shall have the right to perform the audits described in this Section 15, at Company’s own costs and expenses, not more than once per calendar year and upon prior written notice of at least thirty (30) days to Vendor, in order to verify the Vendor’s, and any Sub-processor’s, compliance with this Addendum. The audit shall be confined to processing documentation prepared by the Vendor and logged and documented information regarding its information security measures, and in any event will not entitle Company to conduct technological investigations on the Vendor’s information systems.
Company shall make (and ensure that each of its mandated auditors makes) reasonable endeavours to avoid causing (or, if it cannot avoid, to minimise) any damage, injury or disruption to the Vendor's premises, equipment, personnel and business while its personnel are on those premises in the course of such an audit or inspection.
If any Supervisory Authority: (i) contacts the Vendor with respect to its systems or any processing of Company Personal Data carried out by the Vendor, (ii) conducts, or gives notice of its intent to conduct, an inspection of the Vendor with respect to the processing of Company Personal Data, or (iii) takes, or gives notice of its intent to take, any other regulatory action alleging improper or inadequate practices with respect to any processing of Company Personal Data carried out by the Vendor, then the Vendor shall immediately notify the Company and shall subsequently supply the Company with all information pertinent thereto to the extent permissible by law.
Transfer of Personal Data
In the event that the processing activities under this Addendum are considered Restricted Transfer, the Company (as “data exporter”) and Vendor, (as “data importer”) hereby enter into the Standard Contractual Clauses, or alternative appropriate safeguard under applicable Data Protection Laws in respect of any Restricted Transfer from that Company to Vendor.
General Terms
GOVERNING LAW AND JURISDICTION
Without prejudice to Mediation and Jurisdiction and Governing Law sections of the Standard Contractual Clauses:
the Parties to this Addendum hereby submit to the choice of jurisdiction stipulated in the Principal Agreement with respect to any disputes or claims howsoever arising under this Addendum, including disputes regarding its existence, validity or termination or the consequences of its nullity; and
this Addendum and all non-contractual or other obligations arising out of or in connection with it are governed by the laws of the country or territory stipulated for this purpose in the Principal Agreement.
ASSIGNATION OF RIGHTS OR OBLIGATIONS
Neither Party may assign its rights or obligations under this Addendum without the prior written consent of the other Party.
NOTICES
All notices to a Party under this Addendum shall be in writing and sent to its address as set forth at the beginning of this Addendum, or to such other address as such Party has provided the other in writing for such purpose. Notices may be sent by post, courier, fax or email.
Notices shall be deemed to have been duly given (i) on the day of delivery when delivered in person or by courier, (ii) three (3) business days after the day when the notice was sent when sent by post, and (iii) on the day when the receiver has manually confirmed that it is received when sent per fax or email.
TERM AND TERMINATION
This Addendum shall enter into force on the date hereof. Unless terminated earlier (i) due to a material breach of the terms of this Addendum, in which case this Addendum shall be terminated with immediate effect if the other Party fails to cure such breach in a satisfactory manner within fifteen (15) days after the other Party’s written demand thereof, or (ii) this Addendum shall remain in force until the termination or expiration of the Principal Agreement, whereupon it shall terminate automatically without further notice. The termination or expiration of this Addendum shall immediately terminate any processing agreement entered into between Vendor and any Sub-processor.
Either Party may terminate this Addendum by giving the other Party thirty (30) days written notice.
LIABILITY AND INDEMNIFICATION
Each Party shall indemnify and hold the other Party harmless from and against all direct losses due to claims from third parties including government/authority fines and penalties resulting from, arising out of or relating to any breach by such first-mentioned Party of this Addendum and in the applicable Data Protection Laws.
Any loss suffered by a Party resulting from, arising out of or relating to a breach of this Addendum shall be governed by the provisions regarding liability and limitation of liability in the Principal Agreement.
The Project
The Vendor's Zero Trust Network Access (ZTNA) platform securely connects onsite and remote users to authorized assets, in the organizational network, cloud or IoT environments and even offline networks, regardless of where they are or what device they are using. the Vendor ensures secure access to applications, resources, workstations, servers and files, without granting risky network access to information assets.
Data Subjects
The personal data processed concern the following categories of data subjects:
Users of the Products as defined in the Principal Agreement.
Categories of Personal Data
The personal data processed concern the following categories of personal data:
Full Name, E-mail address, User Locations, IP number, location tracking, phone number.
Purpose of the Personal Data Processing
To ensure Company's continuity with controlled access and secure remote access;
To facilitate collaboration with secure cross organizational connectivity;
To employ dynamic risk-based access to improve security and user experience;
To increase accuracy of secure access with granular visibility and control;
To use MFA;
To optimize management with easy deployment and scaling abilities of the Company.
Processing Operations
The personal data processed will be subject to the following basic processing activities:
Collection of data, storage and anonymization.
Duration of Processing
The personal data will be processed during the term of the Principal Agreement.
Security Measures
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Vendor shall in relation to the Company Personal Data implement appropriate technical and organizational measures to reasonably ensure a level of security appropriate to that risk.
The Vendor’s current list of Sub-processors is available at the following URL (as may be updated by Vendor from time to time):