DMARCsimple Data Processing Addendum

Confidential

This Data Processing Addendum (the “DPA”), dated as of the date of the last signature below (the “DPA Effective Date”), forms part of DMARCsimple’s Terms of Service, which are available at https://portal.dmarcsimple.com/terms, entered into by and between DMARCsimple, Inc. (“DMARCsimple”) and _________________________ (“Customer”) under which DMARCsimple provides certain Domain Message Authentication, Reporting & Conformance (DMARC) services (“Services”) to Customer, unless Customer has entered into a superseding written master subscription agreement with DMARCsimple regarding the Services, in which case, this DPA forms a part of such written agreement (in either case, the “Agreement”). All capitalized terms not defined herein shall have the meaning set forth in the Agreement. Except as modified below, the terms of the Agreement shall remain in full force and effect.

1. Effectiveness

a. Scope. This DPA shall only apply to the extent required by Data Protection Laws with regard to the relevant Customer Personal Data. In case of any conflict between the provisions of the Agreement and the provisions of this DPA with respect to such Processing, the provisions of this DPA shall apply.

b. Termination. This DPA will terminate upon the earliest of: (i) termination of the Agreement (and without prejudice to the survival of accrued rights and liabilities of the parties and any obligations of the parties which either expressly or by implication survive termination); (ii) as earlier terminated pursuant to the terms of this DPA; or (iii) as agreed by the parties in writing. Upon termination of the Agreement, Customer acknowledges and agrees that it is Customer’s responsibility to stop sending any Customer data, including Customer Personal Data, to DMARCsimple by updating Customer’s DNS records and/or terminating forwarding of DMARC data to DMARCsimple.

2. Definitions

As used in this DPA:

3. Processing of Personal Data

a. Roles of the Parties. The parties acknowledge and agree that, as between the parties, with regard to the Processing of Customer Personal Data under the Agreement, Customer is a Controller and DMARCsimple is a Processor. Each party will comply with the obligations applicable to it in such role under Data Protection Laws with respect to the Processing of Customer Personal Data.

b. Customer Instructions. DMARCsimple will Process Customer Personal Data only in accordance with Customer’s documented instructions unless otherwise required by applicable law, in which case DMARCsimple will inform Customer of such Processing unless notification is prohibited by applicable law. Customer hereby instructs DMARCsimple to Process Customer Personal Data: (i) to provide the Services to Customer; (ii) to perform its obligations and exercise its rights under the Agreement and this DPA; and (iii) as necessary to prevent or address technical problems with the Services. DMARCsimple will notify Customer if, in its opinion, an instruction of Customer infringes upon Data Protection Laws. Customer’s instructions for the Processing of Customer Personal Data shall comply with Data Protection Laws. Customer shall be responsible for: (A) giving adequate notice and making all appropriate disclosures to Data Subjects regarding Customer’s use and disclosure and DMARCsimple’s Processing of Customer Personal Data; and (B) obtaining all necessary rights, and, where applicable, all appropriate and valid consents to disclose such Customer Personal Data to DMARCsimple to permit the Processing of such Customer Personal Data by DMARCsimple for the purposes of performing DMARCsimple’s obligations under the Agreement or as may be required by Data Protection Laws. Customer shall notify DMARCsimple of any changes in, or revocation of, the permission to use, disclose, or otherwise Process Customer Personal Data that would impact DMARCsimple’s ability to comply with the Agreement, this DPA, or Data Protection Laws.

c. Details of Processing. The parties acknowledge and agree that the nature and purpose of the Processing of Customer Personal Data, the types of Customer Personal Data Processed, the categories of Data Subjects, and other details regarding the Processing of Customer Personal Data are as set forth in Appendix 1.

d. Processing Subject to the CCPA. As used in this Section 3(d), the terms “Sell,” “Share,” “Business Purpose,” and “Commercial Purpose” shall have the meanings given in the CCPA and “Personal Information” shall mean any personal information (as defined in the CCPA) contained in Customer Personal Data. DMARCsimple will not: (i) Sell or Share any Personal Information; (ii) retain, use, or disclose any Personal Information (A) for any purpose other than for the Business Purposes specified in the Agreement, including for any Commercial Purpose other than the Business Purposes specified in the Agreement, or as otherwise permitted by the CCPA, or (B) outside of the direct business relationship between Customer and DMARCsimple; or (iii) combine Personal Information received from, or on behalf of, Customer with Personal Data received from or on behalf of any third party, or collected from DMARCsimple’s own interaction with Data Subjects, except to perform any Business Purpose permitted by the CCPA. DMARCsimple hereby certifies that it understands the foregoing restrictions under this Section 3(d) and will comply with them. The parties acknowledge that the Personal Information disclosed by Customer to DMARCsimple is provided to DMARCsimple only for the limited and specified purposes set forth in the Agreement and this DPA. DMARCsimple will comply with applicable obligations under the CCPA and provide the same level of privacy protection to Personal Information as is required by the CCPA. Customer has the right to take reasonable and appropriate steps to help ensure that DMARCsimple uses the Personal Information transferred in a manner consistent with Customer’s obligations under the CCPA by exercising Customer’s audit rights in Section 8. DMARCsimple will notify Customer if it makes a determination that DMARCsimple can no longer meet its obligations under the CCPA. If DMARCsimple notifies Customer of unauthorized use of Personal Information, including under the foregoing sentence, Customer will have the right to take reasonable and appropriate steps to stop and remediate such unauthorized use by limiting the Personal Information shared with DMARCsimple, terminating the portion of the Agreement relevant to such unauthorized use, or such other steps mutually agreed between the parties in writing.

4. DMARCsimple Personnel

DMARCsimple restricts its personnel from Processing Customer Personal Data without authorization by DMARCsimple and will limit the Processing to that which is needed for the specific individual’s job duties in connection with DMARCsimple’s provision of the Services under the Agreement. DMARCsimple will impose appropriate contractual obligations on its personnel, including relevant obligations regarding confidentiality, data protection, and data security.

5. Data Subject Rights

DMARCsimple will, taking into account the nature of the Processing of Customer Personal Data and the functionality of the Services, provide reasonable assistance to Customer by appropriate technical and organizational measures, insofar as this is possible, as necessary for Customer to fulfill its obligations under Data Protection Laws to respond to requests by Data Subjects to exercise their rights under Data Protection Laws. DMARCsimple reserves the right to charge Customer on a time and materials basis in the event that DMARCsimple considers that such assistance is onerous, complex, frequent, or time-consuming. If DMARCsimple receives a request from a Data Subject under any Data Protection Laws with respect to Customer Personal Data, DMARCsimple will advise the Data Subject to submit the request to Customer and Customer will be responsible for responding to any such request.

6. Subprocessors

DMARCsimple may engage such Subprocessors as DMARCsimple considers reasonably appropriate for the Processing of Customer Personal Data. A complete list of DMARCsimple’s current Subprocessors, including their functions and locations, is set forth in Appendix 4 and may be updated by DMARCsimple from time to time in accordance with this DPA. DMARCsimple shall notify Customer of the addition or replacement of any Subprocessor at least 30 days prior to engagement and Customer may, on reasonable grounds, object to a new or replaced Subprocessor by notifying DMARCsimple in writing within 30 days of receipt of DMARCsimple’s notification, giving reasons for Customer’s objection. Upon receiving such objection, DMARCsimple shall: (a) work with Customer in good faith to make available a commercially reasonable change in the provision of the Services which avoids the use of that proposed Subprocessor; and (b) where such change cannot be made within 30 days of DMARCsimple’s receipt of Customer’s notice, Customer may by written notice to DMARCsimple with immediate effect terminate the portion of the Agreement or any relevant Order Form to the extent that it relates to the Services which require the use of the proposed Subprocessor. This termination right is Customer’s sole and exclusive remedy to Customer’s objection of any Subprocessor appointed by DMARCsimple. When engaging any Subprocessor, DMARCsimple will enter into a written contract with such Subprocessor containing data protection obligations not less protective than those in this DPA with respect to Customer Personal Data. DMARCsimple shall be liable for the acts and omissions of the Subprocessor to the extent DMARCsimple would be liable under the Agreement and this DPA.

7. Security

a. Security Measures. Taking into account the state of the art, the costs of implementation and the nature, scope, context, and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, DMARCsimple shall implement appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, in accordance with the security standards in Appendix 2 (the “Security Measures”). Customer acknowledges that the Security Measures may be updated from time to time upon reasonable notice to Customer to reflect process improvements or changing practices, provided that the modifications will not materially decrease DMARCsimple’s security obligations hereunder.

b. Security Incidents. Upon becoming aware of a confirmed Security Incident, DMARCsimple will: (i) notify Customer of the Security Incident without undue delay after becoming aware of the Security Incident, but in no case later than 48 hours; and (ii) take reasonable steps to identify the cause of such Security Incident, minimize harm, and prevent a recurrence. DMARCsimple will take reasonable steps to provide Customer with information available to DMARCsimple that Customer may reasonably require to comply with its obligations under Data Protection Laws. DMARCsimple’s notification of or response to a Security Incident under this Section 7(b) will not be construed as an acknowledgement by DMARCsimple of any fault or liability with respect to the Security Incident.

c. Customer Responsibilities. Customer agrees that, without limitation of DMARCsimple’s obligations under this Section 7, Customer is solely responsible for its use of the Services, including: (i) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Customer Personal Data; and (ii) securing any account authentication credentials, systems, and devices Customer uses to access or connect to the Services, where applicable. Without limiting DMARCsimple’s obligations hereunder, Customer is responsible for reviewing the information made available by DMARCsimple relating to data security and making an independent determination as to whether the Services meet Customer’s requirements and legal obligations under Data Protection Laws.

8. Assessments and Prior Consultations

In the event that Data Protection Laws require Customer to conduct a data protection impact assessment, transfer impact assessment, or prior consultation with a Supervisory Authority in connection with DMARCsimple’s Processing of Customer Personal Data, following written request from Customer, DMARCsimple shall use reasonable commercial efforts to provide relevant information and assistance to Customer to fulfill such request, taking into account the nature of DMARCsimple’s Processing of Customer Personal Data and the information available to DMARCsimple. DMARCsimple reserves the right to charge Customer on a time and materials basis in the event that DMARCsimple considers that such assistance is onerous, complex, frequent, or time-consuming.

9. Return or Destruction of Customer Personal Data

Following termination or expiration of the Agreement, DMARCsimple shall, at Customer's option, delete or return Customer Personal Data and all copies to Customer, except as required by applicable law. If DMARCsimple retains Customer Personal Data pursuant to applicable law, DMARCsimple agrees that all such Customer Personal Data will continue to be protected in accordance with this DPA.

10. Audit

a. Report on Compliance. At Customer’s written request, DMARCsimple will provide Customer with all information reasonably necessary for Customer to verify DMARCsimple’s compliance with the security obligations under this DPA. The information will constitute DMARCsimple Confidential Information under the confidentiality provisions of the Agreement or a non-disclosure agreement executed by the parties. DMARCsimple shall allow for and contribute to audits, including inspections, by Customer or an auditor mandated by Customer in relation to the Processing of the Customer Personal Data by DMARCsimple or any Subprocessor in accordance with the provisions of this Section 10.

b. Applicability of this Section. Customer’s information and audit rights only arise under Section 10(a) hereof to the extent that the Agreement does not otherwise provide information and audit rights meeting the relevant requirements of Data Protection Laws.

c. Audit Procedure. An audit shall be conducted in accordance with and subject to the limitations of Section 6(c) (Security Audits) of the Agreement, provided however that: (i) an audit outside normal business hours shall be permitted if the audit or inspection shall be conducted on an emergency basis and where Customer has given DMARCsimple prior written notice of such emergency audit; and (ii) no limitation with respect to the frequency of audits conducted shall apply to any additional audits or inspections which Customer is required or requested to carry out by a Supervisory Authority or any similar regulatory authority responsible for the enforcement of Data Protection Laws, and where Customer has identified its concerns or the relevant requirement in its notice to DMARCsimple of the audit or inspection.

11. International Transfer of Data

DMARCsimple may, subject to Sections 11(b) and 11(c), Process Customer Personal Data in the United States or anywhere DMARCsimple or its Subprocessors maintains facilities. Customer is responsible for ensuring that its use of the Services complies with any cross-border data transfer restrictions of Data Protection Laws.

12. Limitation of Liability

Each party’s liability, taken together in the aggregate, arising out of or related to this DPA, whether in contract, tort or under any other theory of liability, is subject to the “Limitation of Liability” section of the Agreement. For the avoidance of doubt, DMARCsimple’s total liability for all claims from the Customer or any third party (other than Data Subject) arising out of or related to the Agreement and this DPA shall apply in the aggregate for all claims under both the Agreement and this DPA.

13. Jurisdiction and Governing Law

Except as otherwise provided in this DPA, the parties to this DPA hereby submit to the choice of jurisdiction stipulated in the Agreement with respect to any disputes or claims howsoever arising under this DPA, including disputes regarding its existence, validity or termination or the consequences of its nullity.