Request a 30-minute demo

Our product expert will guide you through our demo to show you how to automate testing for every part of your workflow.

See data diffing in real time
Data stack integration
Discuss pricing and features
Get answers to all your questions
By providing this information, you agree to be kept informed about Datafold's products and services.
Submit your credentials
Schedule date and time
for the demo
Get a 30-minute demo
and see datafold in action
Current version

Datafold Data Processing Addendum

EffectiveStatus
October 2, 2026Current version
July 1, 2023Previous version

This Data Processing Addendum (the "DPA") forms part of the Agreement (defined below), including each Order Form and Statement of Work under it, between Datafold, Inc., a Delaware corporation, 224 W 35th St, Ste 500 PMB 45, New York, NY 10001 ("Datafold"), and the customer party to it ("Customer"). It is effective when the Agreement, or the first Order Form or Statement of Work incorporating it, becomes effective or, if signed as an exhibit before then, on the date of the last signature below (the "DPA Effective Date").

How this DPA applies

(a) This DPA applies to the extent Data Protection Laws govern Datafold's Processing of Customer Personal Data in providing the Services under a Statement of Work (including a proof of concept) or an Order Form. It forms part of the Agreement where it is attached to the Agreement or a Statement of Work as a signed exhibit, or where Section 7.2 of the Agreement incorporates it by reference to its URL, the version at that URL on the DPA Effective Date then governing subject to Section 16.4. It applies to each Order Form and Statement of Work under the Agreement unless that document names another signed data processing agreement as governing Customer Personal Data under it.

(b) Customer enters into this DPA for itself and, to the extent Data Protection Laws require, its Affiliates authorized to use the Services ("Authorized Affiliates"), which "Customer" includes in this DPA and which may enforce it only through Customer.

(c) Section 12.1 of the Agreement governs precedence, and nothing in this DPA enlarges either party's liability beyond Section 9 of the Agreement (Section 15). For the Processing of Customer Personal Data only, the Standard Contractual Clauses and the UK Addendum prevail where they apply, a Business Associate Agreement prevails for PHI (Section 13), and this DPA prevails over the remainder of the Agreement.

1. Definitions

1.1 Agreement. "Agreement" means the agreement under which Datafold provides the Services to Customer: the Datafold Master Subscription Agreement as amended for Professional Services, dated October 2, 2026 and published at https://www.datafold.com/legal/msa, or, where the parties have signed another agreement for the Services, that agreement. Capitalized terms used but not defined in this DPA have the meanings given in the Agreement. Where the Agreement is not on that Datafold form, a reference in this DPA to a Section of the Agreement is read as a reference to the corresponding provision of that agreement, and Section 15.1 states the rule where it has no limitation of liability.

1.2 "Confirmation" means for a Security Incident, the earlier of (a) the time Datafold's security function determines on reasonable evidence that it has occurred and (b) the time Datafold has, or with the diligence reasonably expected of a service provider in its position would have, a reasonable degree of certainty that it has occurred ("Confirmed" has the corresponding meaning, and a "Confirmed Incident" is a Security Incident after its Confirmation).

1.3 "Controller", "Processor", "Data Subject", "Personal Data", "Processing" (and "Process"), "Personal Data Breach", "Special Category Data" and "Supervisory Authority" have the meanings given to those terms (or their equivalents, such as "business", "service provider", "consumer" and "personal information") in the applicable Data Protection Laws.

1.4 "Customer Personal Data" means Personal Data in Customer Data that Datafold Processes on Customer's behalf in providing the Services.

1.5 "Data Privacy Framework" or "DPF" means the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Data Privacy Framework.

1.6 "Data Protection Laws" means all laws applicable to a party's Processing of Customer Personal Data under the Agreement, including, as applicable, Regulation (EU) 2016/679 (the "GDPR"); the GDPR as retained in United Kingdom law, with the Data Protection Act 2018 (the "UK GDPR"); the Swiss Federal Act on Data Protection of 25 September 2020 (the "FADP"); and the US State Privacy Laws, each as amended or replaced.

1.7 "Deployment Model" means a deployment model identified in the Security Addendum, as elected in the Order Form or Statement of Work.

1.8 "Documentation" means Datafold's then-current published user documentation for the Service.

1.9 "Inputs" means Customer Data submitted to AI Features by or on behalf of Customer, including code, schemas, metadata, queries and, where so configured, data values; "Outputs" means content that AI Features generate in response to Inputs.

1.10 "Restricted Transfer" means a transfer of Customer Personal Data from Customer to Datafold, or onward from Datafold to a Subprocessor, that Data Protection Laws would prohibit absent a Transfer Mechanism, including from the European Economic Area ("EEA"), the United Kingdom or Switzerland to a country without an adequacy decision.

1.11 "Security Incident" means a breach of Datafold's security measures, or of the security of systems, devices, accounts or credentials that Datafold or Datafold Personnel operate or control, that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Customer Data processed by or on behalf of Datafold, including Customer Data within Platform components that Datafold operates in Customer's environment; unsuccessful attempts and events that do not compromise Customer Data are not Security Incidents.

1.12 "Sensitive Data" means protected health information, cardholder data, government-issued identifiers and other categories of data subject to heightened regulatory requirements, including special categories of Personal Data under Data Protection Laws.

1.13 "Services" means the Service as defined in the Agreement, including Professional Services; "Platform" means the Software and hosted components of the Service, as distinct from Professional Services.

1.14 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914, as amended or replaced; only Module Two (controller to processor) and Module Three (processor to processor) apply under this DPA.

1.15 "Subprocessor" means a Processor, including a Datafold Affiliate and a Datafold-Managed Model Provider, engaged by Datafold to Process Customer Personal Data on Datafold's behalf in performing the Services; Datafold Personnel and the provider of a Customer-Provided Model Endpoint are not Subprocessors.

1.16 "Transfer Mechanism" means a lawful basis for a Restricted Transfer under Data Protection Laws, including the DPF, the SCCs, the UK Addendum and any successor mechanism.

1.17 "Trust Portal" means Datafold's trust portal, at the address stated in the Security Addendum, through which Datafold makes security documentation available under confidentiality obligations.

1.18 "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0) issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, as revised.

1.19 "US State Privacy Laws" means the comprehensive consumer privacy laws of U.S. states and their regulations, in effect and applicable to Datafold's Processing of Customer Personal Data, including the California Consumer Privacy Act as amended (the "CCPA").

1.20 "Usage Data" means technical logs, telemetry, metadata and statistics about the access, use and performance of the Service, excluding Customer Data (Section 4.3 of the Agreement); "Account Data" means business contact information, account credentials, administrative settings, billing information and support communications relating to Customer's account and its users.

1.21 Interpretation. "Including" means "including without limitation"; "SOW" means Statement of Work. Legacy or descriptive names for defined terms or hosting arrangements in the Agreement, an Order Form or a Statement of Work are read as the Security Addendum provides.

2. Roles, scope and instructions

2.1 Roles. For Customer Personal Data, Customer is the Controller (or, acting for a third-party Controller, a Processor) and Datafold the Processor (or Subprocessor). Datafold is an independent Controller of Account Data, to the extent it is Personal Data, and of Usage Data, under Section 14 and its privacy policy at https://www.datafold.com/privacy-policy (the "Privacy Policy").

2.2 Customer as Processor. Where Customer is a Processor, it represents that its instructions are consistent with its agreement with the relevant Controller, that it holds any authorization needed to engage Datafold as a Subprocessor, and that it is Datafold's sole point of contact for that Controller.

2.3 Documented instructions. Customer instructs Datafold (and authorizes Datafold to instruct each Subprocessor) to Process Customer Personal Data as necessary to provide the Services, including any necessary Restricted Transfers. The documented instructions are (a) the Agreement; (b) each Order Form and Statement of Work, including its description of the Deployment Model, data flows, validation data handling, any Customer-Provided Model Endpoint election and retention of validation artifacts; (c) Customer's configuration of the Services (sources connected, columns excluded or hashed, AI Features enabled); (d) this DPA; and (e) Modified Instructions under Section 2.4.

2.4 Modified Instructions. Customer may request changes to its instructions that Data Protection Laws require ("Modified Instructions") by written notice under the Agreement's change procedure. Datafold will implement those that are technically feasible and consistent with the Services, at the cost Section 7.3 provides. If Datafold notifies Customer that one is infeasible or would materially change the Services, Customer may, as its sole remedy, terminate the affected Order Form or Statement of Work on written notice within thirty (30) days and receive a pro-rata refund of prepaid fees for the unused term.

2.5 Duty to inform; other purposes. Datafold will inform Customer if, in its opinion, an instruction infringes Data Protection Laws (without a duty of legal review) and may suspend it until Customer confirms or modifies it. Datafold Processes Customer Personal Data only on Customer's documented instructions, except as law applicable to Datafold requires, in which case it will inform Customer beforehand unless the law prohibits it.

2.6 Details of Processing. Annex I describes the subject matter, duration, nature and purpose of the Processing and the categories of Data Subjects and Personal Data.

3. Customer responsibilities; sensitive data

3.1 Lawfulness and authority. Customer is solely responsible for the accuracy, quality and lawfulness of Customer Personal Data and how it acquired it; for the notices, consents, authorizations and registrations Data Protection Laws require for Datafold's Processing; for its right to give Datafold access to Customer Personal Data; and for issuing lawful instructions.

3.2 Configuration and minimization. Customer determines which data sources, schemas, tables and columns are exposed to the Services and which AI Features are enabled, and will use the minimization controls the Security Addendum and the Documentation describe to limit the Customer Personal Data Processed to what its purposes require.

3.3 Sensitive Data. For Customer Personal Data that is Sensitive Data, Customer decides what Sensitive Data it exposes to the Services and to Datafold Personnel, configures the access it grants accordingly, identifies that Sensitive Data in the Order Form or Statement of Work and puts in place any agreement applicable law requires before exposing it, for PHI a Business Associate Agreement under Section 13. Datafold's obligations for Sensitive Data so Processed are those in this DPA, the Security Addendum, the Statement of Work and any Business Associate Agreement.

4. Personnel and confidentiality

4.1 Datafold will ensure that each of the Datafold Personnel authorized to Process Customer Personal Data is bound by written confidentiality obligations no less protective than those in the Agreement or by an appropriate statutory obligation of confidentiality, has completed the training described in the Security Addendum, and Processes Customer Personal Data only as their role requires. Datafold will limit access to Datafold Personnel who need it to perform the Services, maintain the screening described in the Security Addendum and complete any additional screening or onboarding a Statement of Work requires.

5. Security

5.1 Security measures. Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of Processing and the risks to Data Subjects, Datafold will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against Security Incidents and to meet Article 32 GDPR and equivalent provisions of other Data Protection Laws: the Security Measures (as defined in the Security Addendum), which Annex II incorporates.

5.2 Updates. Updates to the Security Addendum are made as the Security Addendum provides.

5.3 Deployment Model responsibilities. The Security Addendum allocates the security and operational controls between the parties for the elected Deployment Model; the Security Measures apply to the controls it allocates to Datafold, and the controls it allocates to Customer, including the security of a Customer-Provided Model Endpoint, are Customer's responsibility.

5.4 Customer-specific measures. Measures Customer requires beyond the Security Addendum must be stated in the Order Form or Statement of Work, as the Security Addendum provides; they are subject to Datafold's confirmation of feasibility, may carry fees and do not amend this DPA.

6. Subprocessors and Model Providers

6.1 General authorization. Customer generally authorizes Datafold to engage Subprocessors, including Datafold Affiliates and Datafold-Managed Model Providers, to Process Customer Personal Data to provide the Services, and specifically authorizes the Subprocessors and Datafold-Managed Model Providers identified on the Subprocessor List (Annex III), as updated under this Section 6.

6.2 Subprocessor obligations. Datafold will bind each Subprocessor by written agreement to data protection obligations no less protective in substance than those in this DPA, including confidentiality, security, security-incident notification, return or deletion and onward sub-processing, and remains responsible to Customer for each Subprocessor's performance as for its own.

6.3 Notice of changes. Datafold gives notice of the addition or replacement of a Subprocessor (including a Datafold-Managed Model Provider) by posting it on the Subprocessor List at least ten (10) days before the new Subprocessor Processes Customer Personal Data (where the SCCs apply, the Clause 9(a) period completed in Annex IV); the posting is the notice, and Customer is responsible for reviewing the Subprocessor List. This Section 6 is the procedure for changes to the Subprocessor List under Section 3.5 of the Agreement and applies to every Subprocessor. Where a Subprocessor must be replaced urgently to preserve the security or continuity of the Services, Datafold may post on shorter notice where the applicable Transfer Mechanism permits, stating the circumstances, and the objection period runs from that posting.

6.4 Objection. Customer may object to a new Subprocessor within ten (10) days after its posting on reasonable, documented data-protection or security grounds by written notice to the address for data-protection notices stated in the Order Form. The parties will discuss the objection in good faith for thirty (30) days; if it is not resolved, Customer may, as its sole remedy, disable the affected feature or select a Customer-Provided Model Endpoint or, where the Services under an Order Form or Statement of Work cannot be provided without the new Subprocessor, terminate that document on written notice within thirty (30) days after the discussion period with a pro-rata refund of prepaid fees for the unused term. Failure to object in time is approval.

6.5 Model Providers. Datafold may use any one or more of the Datafold-Managed Model Providers identified on the Subprocessor List, alone or in combination, as Section 3.5 of the Agreement provides, and adds or replaces one under Sections 6.3 and 6.4. This DPA does not name them; they process Inputs and Outputs under their own standard commercial terms, linked on the Subprocessor List.

6.6 Restricted Transfers to Subprocessors. Datafold will put in place a Transfer Mechanism for a Restricted Transfer to a Subprocessor as Data Protection Laws require; Customer's authorization under this Section 6 is its documented instruction for onward transfers under Clause 8.8 of the SCCs.

6.7 Customer-Provided Model Endpoints. Section 3.5 of the Agreement governs a Customer-Provided Model Endpoint: its provider is engaged by Customer, is Customer's Processor, service provider or vendor and not a Subprocessor, and Sections 6.1 to 6.6 do not apply to it. Datafold's transmission of Inputs to, and receipt of Outputs from, the endpoint is Processing on Customer's documented instruction, recorded for Article 28(3)(a) GDPR by the Order Form, Statement of Work or Platform configuration designating it, which Datafold will retain for the term of the Agreement; endpoint credentials Customer issues are Customer's Confidential Information.

7. Assistance to Customer

7.1 Data Subject requests. Datafold will notify Customer without undue delay of a Data Subject's request concerning Customer Personal Data and will not respond except to acknowledge it and refer the Data Subject to Customer, unless Customer instructs otherwise or law requires a response. Taking into account the nature of the Processing, Datafold will assist Customer by appropriate technical and organizational measures, insofar as possible, in responding; Customer will respond itself where it can through the Services or its own access to the connected data sources, where the Customer Personal Data remains.

7.2 Other assistance. Taking into account the nature of the Processing and the information available to it, Datafold will reasonably assist Customer with its obligations under Articles 32 to 36 GDPR and equivalent provisions of other Data Protection Laws, including impact assessments and prior consultation, to the extent they relate to the Services and the information is not already on the Trust Portal or in the Security Addendum. To the extent legally permitted, Datafold will promptly inform Customer of any complaint, inquiry or request from a Supervisory Authority or other public authority relating to Customer Personal Data and will not respond except as law requires or Customer agrees.

7.3 Costs. Assistance under this Section 7 and the implementation of Modified Instructions are free of charge to the extent they consist of information Datafold makes available to customers generally or require immaterial effort; beyond that, or where they result from Customer's specific configuration or instructions, Datafold may charge its reasonable, documented costs at the rates in the Agreement or, if none, its then-current professional services rates, after giving an estimate.

8. Security Incident notification

8.1 Notification. Datafold will notify Customer of a Confirmed Incident affecting Customer Personal Data without undue delay, and in any event within the period stated in Section 7.2 of the Agreement after Confirmation, at the security contacts designated in the Order Form. As the Agreement and the Security Addendum provide, a Security Incident includes one in Customer's environment or a Customer-Provided Model Endpoint to the extent it arises from Platform components Datafold operates or from Datafold Personnel, devices or credentials.

8.2 Content and cooperation. Notification under Section 8.1 will describe the nature of the Security Incident, the categories and approximate number of Data Subjects and records concerned (Article 33(3) GDPR), its likely consequences and the measures taken or proposed, and is supplemented in phases as information becomes available. Datafold will contain and remediate the Security Incident, keep Customer informed until resolution, provide on request a written root-cause summary, preserve evidence and give the cooperation and information Customer reasonably requires to notify Supervisory Authorities and Data Subjects in time. Datafold will not name Customer in a public statement about a Security Incident without Customer's consent unless law requires, and a notification is not an admission of fault or liability.

8.3 Who notifies. Customer decides whether and how to notify Supervisory Authorities, Data Subjects and others; where Data Protection Laws require Datafold to notify directly, it will, where legally permitted and practicable, share the proposed notification with Customer in advance and coordinate timing and content in good faith.

9. Return and deletion

9.1 During the term. Customer may retrieve Customer Data through the Services and request deletion of specified Customer Personal Data held in the Platform, which Datafold will perform within thirty (30) days where feasible without deleting other Customer Data and consistent with the Services ordered.

9.2 On termination. Customer may export Customer Data through the Services, including their application programming interface, at any time during the term and for thirty (30) days after expiration or termination of the applicable Order Form or Statement of Work (the "Export Period"). Within thirty (30) days after the end of the Export Period, or after Customer's earlier written request, Datafold will delete all Customer Personal Data in its possession, custody or control (including on Datafold-managed devices and systems, and in Outputs or unassigned Deliverables that embody it) and return or relinquish the credentials Customer issued; where the Security Addendum allocates the deployment infrastructure to Customer, Customer Data in that infrastructure remains in Customer's environment and its deletion is Customer's responsibility unless the Statement of Work provides otherwise.

9.3 Backups. Customer Personal Data in encrypted backups is deleted in the ordinary course of Datafold's backup rotation, within the backup-retention periods the Security Addendum states, and is not restored or otherwise Processed meanwhile except to restore the Services after a disaster, after which the restored data is deleted promptly.

9.4 Retained copies. Datafold retains Customer Personal Data after deletion only as law requires, subject to the confidentiality and security obligations of the Agreement and this DPA and without other Processing.

9.5 Working data and retained results. In performing the Services, the Platform and, under a Statement of Work, Datafold Personnel query and read data in Customer's source and target systems and run code against them as Customer authorizes; the Platform does not copy whole tables into Datafold's environment, and in a Deployment Model hosted in Customer's environment working data stays there. Query results, samples and other working data are held only as the Services require. The Platform retains, in the application database of the applicable Deployment Model, comparison statistics and a bounded set of row-level examples of differences, within the limits the Security Addendum describes. Under a Statement of Work, Datafold retains working data and those examples for the duration of the engagement and purges them no later than thirty (30) days after Final Acceptance (as defined in the Statement of Work) or earlier termination of the Statement of Work, unless the Statement of Work states another period; for Customer's own use of the Platform, Customer configures the retention period per data source and the Platform purges the examples when it expires. Temporary tables and other working data the Platform creates in, or transfers from, Customer's systems are removed as the Security Addendum describes.

9.6 Certificate. On Customer's written request and, where the SCCs apply, without request, Datafold will certify in writing, signed by an authorized officer, that deletion under this Section 9 is complete.

9.7 Security logs. Datafold may retain security and audit logs that incidentally contain Customer Personal Data (identifiers or query fragments recorded in error conditions) for the log retention period stated in the Security Addendum, protected by the Security Measures, accessible only to Datafold Personnel in security and operations roles, used only for security, audit and operations, and then deleted or de-identified.

10. Audit and information

10.1 Tier 1 — Trust Portal. Datafold will make available through the Trust Portal, under the confidentiality terms of the Agreement (or a click-through non-disclosure agreement of equivalent effect), the evidence the Security Addendum describes, including its current SOC 2 Type II report (or a successor report under an equivalent standard) and its most recent penetration test report with remediation status, and, on request, a certificate of insurance, all Datafold's Confidential Information.

10.2 Tier 2 — written questions. Once in any twelve (12)-month period, and additionally where reasonably required after a Security Incident affecting Customer Personal Data, on a Supervisory Authority's written instruction or after a notified material change to the Services or Deployment Model, Datafold will answer within twenty (20) business days Customer's reasonable written security and privacy questions not answered by the Tier 1 materials.

10.3 Tier 3 — audit and inspection. Customer (or an independent auditor it mandates, bound by written confidentiality obligations and not a competitor of Datafold) may audit Datafold's compliance with this DPA, including by inspection, as Data Protection Laws (including Article 28(3)(h) GDPR) and, where they apply, Clause 8.9 of the SCCs contemplate: (a) once in any twelve (12)-month period, unless a Security Incident affecting Customer Personal Data has been Confirmed since the last audit or a Supervisory Authority requires it; (b) on thirty (30) days' written notice stating the scope, or the shorter period a Supervisory Authority requires; (c) first by review of the Tier 1 and Tier 2 materials, then remotely by documentary review and interviews, and on site at Datafold's premises or facilities only where the remote review is insufficient, a Security Incident affecting Customer Personal Data was Confirmed in the preceding twelve (12) months or a Supervisory Authority so requires; (d) within a scope, duration and methodology agreed in advance, each party acting reasonably, limited to systems and records relevant to the Processing of Customer Personal Data and without access to other customers' data or Datafold's source code; (e) under Datafold's security and confidentiality policies and, on site, in business hours; and (f) at Customer's cost, including Datafold's reasonable, documented time and expenses beyond one (1) person-day.

10.4 Results; scope. Customer will give Datafold a copy of any findings, treat them as Datafold's Confidential Information (save for disclosure to a Supervisory Authority on its request and under Clause 8.9(d) of the SCCs) and discuss any non-conformity and a reasonable remediation plan in good faith. Audits under Clause 8.9 of the SCCs and the UK Addendum are conducted under this Section 10, which does not expand any audit right in the Agreement or grant a right to audit Subprocessors directly; Datafold will use reasonable efforts to make its infrastructure Subprocessors' audit reports available under Tier 1.

11. International transfers; processing locations

11.1 Data Privacy Framework. Datafold is not certified under the DPF and Restricted Transfers are made under Section 11.2; if Datafold obtains certification it may on notice rely on the DPF, the SCCs continuing as a fallback.

11.2 SCCs; UK Addendum; Swiss variations. To the extent a Restricted Transfer from Customer to Datafold is not covered by the DPF or another Transfer Mechanism, the SCCs apply and are incorporated by reference: for transfers subject to the GDPR as populated in Annex IV Part 1; for transfers subject to the UK GDPR as varied by the UK Addendum and completed in Annex IV Part 2; for transfers subject to the FADP with the variations in Annex IV Part 3; and for other Restricted Transfers, the SCCs with the minimum variations the exporting jurisdiction's Data Protection Laws require, to the extent they recognize or do not preclude them. Module Two applies where Customer is a Controller and Module Three where Customer is a Processor for a third-party Controller.

11.3 Execution; full-form copies. Execution of the Agreement or this DPA is execution of the SCCs and the UK Addendum by each party, as data exporter (Customer) and data importer (Datafold). Where a Supervisory Authority, Data Subject or third-party Controller requires it, Datafold will on written request provide an executed full-form copy populated per Annex IV for Customer's countersignature.

11.4 Successor mechanisms. If the SCCs, the UK Addendum or the DPF are amended, replaced or invalidated, Datafold may on notice substitute the successor or another Transfer Mechanism enabling lawful transfer, populated consistently with Annex IV, and Customer will cooperate, including by executing documents where required.

11.5 Processing locations. The processing region and the backup region are those stated in the Order Form or Statement of Work, if any; where none is stated, Datafold processes Customer Personal Data in the regions its Subprocessors document, under the Transfer Mechanisms in this Section 11, and Datafold will not change a region stated in the Order Form or Statement of Work without Customer's consent. A restriction on the locations from which Datafold Personnel access Customer Data applies only where the Order Form or Statement of Work states one. On Customer's reasonable written request, not more than once in any twelve (12)-month period, Datafold will inform Customer of the countries from which Datafold Personnel then access Customer Data. Access from a location to Customer Personal Data hosted elsewhere is a Restricted Transfer only to the extent Data Protection Laws so provide, and Section 11.2 then applies.

11.6 Government access requests. Datafold will (a) review the legality of a binding public-authority request for access to Customer Personal Data and challenge it where there are reasonable grounds; (b) unless legally prohibited, notify Customer promptly and, where possible, before disclosure so that Customer may seek a protective order; (c) disclose only the minimum legally required; and (d) on Customer's written request, not more than once in any twelve (12)-month period, inform Customer of the number and type of such requests received in the preceding year (which may be nil).

12. US State Privacy Laws

12.1 Application. This Section 12 applies to the extent Datafold Processes Customer Personal Data that is "personal information" (or the equivalent) under US State Privacy Laws, whose definitions apply to the terms used in it ("business", "consumer", "sell", "share", "targeted advertising", "service provider", "contractor", "processor", "deidentified" and the like).

12.2 Role. Datafold is a service provider, contractor or processor and Customer a business or controller for such personal information, which Customer discloses to Datafold only for the limited and specified business purposes described in the Agreement and Annex I.

12.3 Datafold covenants. Datafold will: (a) not sell or share personal information or Process it for targeted advertising or cross-context behavioral advertising; (b) not retain, use or disclose it for any purpose, including any commercial purpose, other than the specific business purpose of providing the Services under the Agreement or as the US State Privacy Laws otherwise permit; (c) not retain, use or disclose it outside the direct business relationship between Datafold and Customer; (d) not combine it with personal information received from or on behalf of another person or collected from Datafold's own interactions with the consumer, except as permitted for service providers or processors; (e) comply with the obligations of service providers, contractors and processors under the US State Privacy Laws and provide the same level of privacy protection they require; (f) notify Customer in writing without undue delay if it determines that it can no longer meet those obligations; (g) grant Customer the right, on reasonable notice, to take reasonable and appropriate steps to ensure that Datafold uses personal information consistently with Customer's obligations, including through Section 10, and to stop and remediate unauthorized use; (h) ensure that each person and Subprocessor Processing personal information is bound by a duty of confidentiality and by written obligations meeting the US State Privacy Laws; and (i) not attempt to re-identify deidentified, pseudonymized or aggregated data received from Customer, except to test deidentification with Customer's consent.

12.4 Deidentified data. For deidentified data derived from Customer Personal Data (including Usage Data and aggregated statistics under Section 14), Datafold will take reasonable measures to prevent association with an individual or household, publicly commit to keep and use it only in deidentified form without re-identification, and bind any recipient to the same.

12.5 Consumer requests; notices; certification. Datafold will assist with consumer requests under Section 7 and act on Customer's verified instruction to delete, correct or restrict personal information within the periods the US State Privacy Laws require and in any event within fifteen (15) business days. Notice of Subprocessors under Section 6 satisfies any US State Privacy Laws requirement to notify Customer of, and let it object to, Datafold's subcontractors. Datafold certifies that it understands the restrictions in this Section 12 and will comply with them.

13. Protected Health Information

13.1 Datafold Processes protected health information as defined in 45 C.F.R. § 160.103 ("PHI") only under a Business Associate Agreement between Datafold and Customer (or, on an engagement delivered through a partner, a partner-level instrument that expressly permits Datafold's access to PHI) (a "BAA"), and Customer will not make PHI available to Datafold through or in connection with the Services before one is in effect (Section 3.3).

13.2 A BAA governs Datafold's Processing of PHI and prevails over this DPA in a conflict; Sections 6, 8, 9 and 15 continue to apply to PHI to the extent not inconsistent with it.

14. Account Data and Usage Data

14.1 Datafold Processes Account Data, to the extent it is Personal Data, as an independent Controller to administer Customer's account, provide support, invoice, communicate about the Services, comply with law and maintain security, in accordance with the Privacy Policy.

14.2 Datafold Processes Usage Data, which does not include Customer Data, as an independent Controller to operate, secure, support, analyze and improve the Services; where Usage Data or aggregated statistics could be associated with an individual, Datafold deidentifies them under Section 12.4 before using them for improvement or analytics and does not disclose them in a form that identifies Customer or a Data Subject.

14.3 No training. Section 3.5 of the Agreement (Datafold does not use Customer Data to train or improve models made available to third parties) applies to Customer Personal Data; Datafold's rights in Datafold Technology under Section 4.4 of the Agreement are not a use of Customer Data under that Section. Nothing in this DPA prevents the Processing of Account Data and Usage Data under this Section 14.

15. Liability

15.1 Each party's and its Affiliates' aggregate liability arising out of or relating to this DPA (including, as between the parties and to the extent they permit, the SCCs and the UK Addendum), on any theory and however framed, is subject to Section 9 of the Agreement, as is liability under the Security Addendum or a BAA; a party's liability under that Section means the aggregate liability of that party and its Affiliates under the Agreement, this DPA, any BAA and any DPA of an Authorized Affiliate together, and the caps are not cumulative. Where the Agreement contains no limitation of liability, Section 9 of the Datafold Master Subscription Agreement as amended for Professional Services applies to claims under this DPA as if set out in full. This DPA is not an express override for purposes of Section 12.1 of the Agreement.

15.2 Nothing in this Section 15 limits either party's liability to Data Subjects under Clause 12 of the SCCs or under Data Protection Laws where it cannot lawfully be limited, or either party's right to contribution under the Agreement.

16. Term, precedence and general

16.1 Term. This DPA takes effect on the DPA Effective Date and remains in force for as long as Datafold Processes Customer Personal Data under the Agreement, notwithstanding its expiry or termination.

16.2 Governing law and disputes. Except as the SCCs or the UK Addendum provide, this DPA is governed by the law governing the Agreement and disputes are resolved as the Agreement provides.

16.3 Costs. Except as stated in this DPA, each party bears its own costs of compliance.

16.4 Updates. Datafold may update the published version of this DPA by posting the new version, with its version history, at the URL stated in the Agreement, and no update materially reduces the protection of Customer Data during a then-current term; Customer may object to any other change that materially reduces its protections by written notice within thirty (30) days after it is published, in which case the prior version continues to apply to its then-current Order Forms and Statements of Work until their next renewal. A copy signed as an exhibit is updated only by written agreement, except under Section 11.4.

16.5 Severability; third parties. An invalid provision is modified to the minimum extent necessary and the remainder continues in force; except for Data Subjects as the SCCs provide, no third party has rights under this DPA.

16.6 Notices. Notices are given as Section 12.6 of the Agreement provides, to the addresses stated in the Order Form; the Order Form identifies the addresses for data-protection and security-incident notices to each party.

16.7 Counterparts. Where executed separately, this DPA may be executed in counterparts and by electronic signature.

Annex I — Details of Processing

Part A — Parties

Data exporter Data importer
Name Customer (as identified in the Agreement) and its Authorized Affiliates Datafold, Inc.
Address; registration As stated in the Agreement or Order Form 224 W 35th St, Ste 500 PMB 45, New York, NY 10001, USA; a Delaware corporation
Contact for data protection As stated in the Order Form or Statement of Work Datafold's security and data-protection lead, at the address for data-protection notices stated in the Order Form
Activities Use of the Services for Customer's internal business purposes under the Agreement Provision of the Services under the Agreement, each Order Form and Statement of Work
Role Controller (Module Two) or Processor for a third-party Controller (Module Three) Processor (Module Two) or Subprocessor (Module Three); independent Controller of Account Data and Usage Data
Signature and date Deemed signed on the DPA Effective Date (Section 11.3) Deemed signed on the DPA Effective Date (Section 11.3)

Part B — Description of the Processing

Item Description
Subject matter Platform Services under an Order Form, and Professional Services under a Statement of Work (data platform migrations, net-new data platform and pipeline builds, data application builds and other data engineering work), with the related Deliverables.
Purpose To provide the Services the Order Form or Statement of Work specifies, per Customer's configuration and documented instructions (the "Business Purpose" for purposes of the US State Privacy Laws).
Nature of Processing Connection to Customer's data sources, systems, code repositories and tooling with the credentials, OAuth grants or accounts Customer provides; running queries and code against those systems and reading, analysing and transforming the data and code in them as the Services require, by the Platform and, under a Statement of Work, by Datafold Personnel; collection of schema, metadata, statistics, query results and, where Customer so configures or the work requires, row-level values and samples; use of AI Features on that data and code; storage, display and export of results; retention as Section 9 provides.
Categories of Data Subjects (a) Customer's Authorized Users and personnel on the engagement; (b) individuals whose Personal Data is in the data sources, repositories, code and datasets Customer connects or places in scope (its customers, end users, employees, suppliers and other third parties, as Customer determines).
Categories of Personal Data For (a): name, business email, role, authentication identifiers, IP address, activity logs. For (b): the categories in the connected or in-scope sources as Customer determines (typically identifiers, contact details, transaction and behavioral data and other business records), to the extent Customer's configuration exposes them; source code, schemas and metadata may incidentally contain Personal Data.
Sensitive Data As Customer decides under Section 3.3 and identifies in the Order Form or Statement of Work; PHI only under a BAA (Section 13).
Frequency Continuous during the Subscription Term or the Statement of Work, as Customer's configuration and use or the engagement plan initiate.
Duration and retention The Subscription Term or the term of the Statement of Work, plus the Section 9 periods (Sections 9.5 and 9.7).
Onward transfers To the Subprocessors and Datafold-Managed Model Providers identified on the Subprocessor List, under the provider terms linked there (Annex III; Section 3.5 of the Agreement); a Customer-Provided Model Endpoint is not a Subprocessor.
Processing locations As Section 11.5 provides.

Part C — Competent Supervisory Authority (SCC Clause 13; UK Addendum Table 3)

Where Customer is established in an EU Member State, that Member State's Supervisory Authority; where Customer is subject to Article 3(2) GDPR and has an Article 27 representative, the Supervisory Authority of the Member State in which the representative is established; otherwise the Supervisory Authority of the Member State in which the Data Subjects concerned are predominantly located, as Customer notifies Datafold in writing. For UK Restricted Transfers, the Information Commissioner; for Swiss Restricted Transfers, the Federal Data Protection and Information Commissioner.


Annex II — Security Measures

Part A — Incorporation by reference

Datafold implements and maintains the technical and organizational measures described in the Security Addendum, published at the URL stated in the Agreement and updated as Section 5.2 provides, which constitutes Annex II to the SCCs and the technical and organisational measures for purposes of the UK Addendum. Where a text must be annexed, the parties may attach as Exhibit S-2 a PDF of the version in effect on the DPA Effective Date, identified by version and URL, as evidence of that text and not a maintained copy.

Part B — Technical and organizational measures

The technical and organizational measures are those described in the Security Addendum, incorporated into this Annex by reference in the version in effect on the DPA Effective Date and as updated as Section 5 provides; the Security Addendum allocates each measure between the parties by Deployment Model (its Section 4) and states the detection, response and notification measures on which Section 8 relies. Where the SCCs or the UK Addendum require an annexed description, the parties may attach that version as Exhibit S-2, as evidence of it and not a maintained copy.

Part C — Customer-specific measures

Measures agreed under Section 5.4 and the elections the Security Addendum refers to the Order Form or Statement of Work are recorded in that document and prevail over the Security Addendum to the extent stated there; absent such a record, the Security Addendum applies as published.


Annex III — Subprocessors and Model Providers

Part A — Incorporation by reference. The Subprocessors and Datafold-Managed Model Providers authorized under Section 6 are those identified on the Subprocessor List, published at the URL stated in Section 3.5 of the Agreement (Subprocessors in its Section 2; Datafold-Managed Model Providers in its Section 3), as updated by posting under Section 6 of this DPA. The Subprocessor List identifies each Subprocessor, with its purpose and a link to its processing-location documentation, and each Datafold-Managed Model Provider, with links to its own standard commercial terms (Section 3.5 of the Agreement); this Annex names none.

Part B — Agreed list for Clause 9 of the SCCs (Option 2). For purposes of Clause 9(a) of the SCCs and the UK Addendum, the agreed list of sub-processors is the Subprocessor List as published on the DPA Effective Date, incorporated by reference and updated by posting under Section 6.3; the parties may attach as Exhibit S-1 a PDF of the version current at signature, as evidence of it and not a maintained copy.

Part C — Customer-Provided Model Endpoints. Section 3.5 of the Agreement and Section 6.7 govern a Customer-Provided Model Endpoint; its provider is not a Subprocessor and is not listed as a Datafold-Managed Model Provider. A Customer-Provided Model Endpoint is identified in the Order Form, the Statement of Work or the Platform configuration.


Annex IV — Restricted Transfer Annex

Part 1 — EU Restricted Transfers: population of the Standard Contractual Clauses

  1. Application. Where the SCCs apply under Section 11.2 of the DPA to a transfer subject to the GDPR, the parties are deemed to have signed them at the signature blocks in Annex I to the Appendix to the SCCs, in the capacities stated in Annex I Part A of the DPA.

  2. Modules. Module Two applies where Customer is a Controller of the Customer Personal Data transferred; Module Three where Customer is a Processor for a third-party Controller. Modules One and Four do not apply.

  3. Clause-by-clause elections. (a) Clause 7 (docking clause): not used. (b) Clause 9(a): Option 2 (general written authorisation) applies; the minimum advance notice period for the addition or replacement of sub-processors is ten (10) days, being the posting period in Section 6.3 of the DPA; Option 1 is not used; Annex III of the DPA is the agreed list from which the general authorisation runs. (c) Clause 11(a): the optional independent dispute resolution language is not used. (d) Clause 13: the competent Supervisory Authority is determined under Annex I Part C of the DPA. (e) Clause 17: Option 1 applies; the SCCs are governed by the law of Ireland. (f) Clause 18(b): disputes are resolved by the courts of Ireland.

  4. Appendix. Annex I to the Appendix to the SCCs is populated with Annex I of the DPA (Parts A to C); Annex II with Annex II of the DPA (the Security Addendum); Annex III with Annex III of the DPA as the agreed list referred to in paragraph 3(b).

  5. Operational clarifications. (a) Clause 8.3: in meeting its transparency obligations Customer will protect, and may redact from any copy of the SCCs provided to Data Subjects, Datafold's trade secrets and confidential or commercially sensitive information. (b) Clauses 8.5 and 16(d): deletion is certified under Section 9.6 of the DPA and, where the SCCs apply, without request. (c) Clause 8.8: Customer's authorization of Subprocessors under Section 6 of the DPA is its documented instruction for onward transfers. (d) Clause 8.9: audits and inspections are conducted under Section 10 of the DPA. (e) Clause 10(a) (Module Three): Datafold will not notify a third-party Controller of a Data Subject request; that is Customer's responsibility.

Part 2 — UK Restricted Transfers: International Data Transfer Addendum (version B1.0)

Where the UK Addendum applies under Section 11.2 of the DPA to a transfer subject to the UK GDPR, the SCCs as populated in Part 1 are varied by the UK Addendum, the parties agree to be bound by its Part 2 Mandatory Clauses (the template Addendum B.1.0 issued by the ICO and laid before Parliament under s119A of the Data Protection Act 2018 on 2 February 2022, as revised under Section 18 of those Mandatory Clauses), and its Part 1 tables are completed as follows under Section 17 of the UK Addendum: Table 1 (Parties) is deemed populated with the details in Annex I Part A of the DPA, the start date being the DPA Effective Date and signature being deemed by execution of the Agreement or the DPA; Table 2 (Selected SCCs, Modules and Selected Clauses): the Approved EU SCCs, including the Appendix Information, with only the modules, clauses and optional provisions populated in Part 1 above brought into effect (Module Two where Customer is a Controller and Module Three where it is a Processor; Clause 7 not used; Clause 11 optional language not used; Clause 9(a) general authorisation (Option 2) with a time period of ten (10) days, being the notice period in Section 6.3 of this DPA); Table 3 (Appendix Information): Annex 1A is Annex I Part A of the DPA, Annex 1B is Annex I Parts B and C of the DPA, Annex II is Annex II of the DPA (the Security Addendum) and Annex III is Annex III of the DPA and the Subprocessor List; Table 4 (Ending this Addendum when the Approved Addendum changes): the Importer may end it as set out in Section 19 of the UK Addendum.

Part 3 — Swiss Restricted Transfers

Where the FADP applies to a Restricted Transfer, the SCCs as populated in Part 1 apply with these variations: (a) references to the "GDPR" are read as references to the FADP; (b) references to the "European Union", "Union" and "Member State" are read as references to Switzerland, and Data Subjects habitually resident in Switzerland may bring proceedings before the courts of Switzerland under Clause 18(c); (c) references to the "competent supervisory authority" are read as references to the Swiss Federal Data Protection and Information Commissioner; and (d) under Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland. Where a transfer is subject to both the GDPR and the FADP, the SCCs apply in parallel, the Swiss variations applying only to the FADP-governed transfer.