Data Processing Addendum
Effective Date: September 9, 2026
Last Updated: September 9, 2026
Version: 1
This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between Bot B2B, Inc. ("BotB2B", "Processor", "we", "us") and the customer that accepted the Agreement ("Customer", "Controller", "you"). It applies automatically to the extent we process Personal Data on your behalf in providing the Services. No signature is required; you may request a countersigned copy at [email protected]. Capitalized terms not defined here have the meanings given in the Agreement.
Summary (not part of the DPA). You own and control the personal data in your Workspace; we process it only to run the features you use, with the vendors listed in our Sub-processor List, under security measures described in Annex 2, and we delete it when you leave. We give notice before adding vendors, tell you about breaches within 48 hours of confirming them, help you answer requests from individuals, and provide the cross-border transfer clauses required by your country (EU, UK, Switzerland, Brazil, Argentina, Colombia, Quebec and others). We also meet the "service provider" requirements of U.S. state privacy laws.
1. Definitions
1.1. "Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under the Agreement, including, as applicable: U.S. state privacy laws (such as the California Consumer Privacy Act as amended by the California Privacy Rights Act, "CCPA", and the comprehensive privacy laws of other states, together "US State Laws"); Canada's PIPEDA and provincial laws including Quebec's Act respecting the protection of personal information in the private sector ("Quebec Law 25"); Brazil's Lei Geral de Proteção de Dados (Law 13.709/2018, "LGPD"); Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares (2025); Argentina's Law 25.326; Chile's Law 19.628 and Law 21.719; Colombia's Law 1581/2012 and Decree 1377/2013; Peru's Law 29733; Uruguay's Law 18.331; Ecuador's LOPDP; the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, and the Swiss Federal Act on Data Protection ("FADP").
1.2. "Personal Data" means any information relating to an identified or identifiable natural person that is contained in Customer Content and processed by us on your behalf. It includes "personal information" as defined by US State Laws and "dados pessoais" under the LGPD.
1.3. "Data Subject" means the individual to whom Personal Data relates (including End Users, your Members and employees, and your counterparties).
1.4. "Processing", "Controller", "Processor", "Sub-processor", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR, and the corresponding meanings under other Applicable Data Protection Law (for example "business", "service provider" and "contractor" under the CCPA; "controlador" and "operador" under the LGPD; "responsable" and "encargado" under Mexican, Argentine and Colombian law; "responsable" and "mandatario" under Peruvian law).
1.5. "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914, as amended or replaced.
1.6. "Restricted Transfer" means a transfer of Personal Data to a country that Applicable Data Protection Law treats as not providing an adequate level of protection, such that a transfer instrument is required.
2. Roles and scope
2.1. Roles. You are the Controller (or business) of Personal Data in Customer Content and we are your Processor (or service provider). Where you act as a processor for another controller (for example an agency running Bots for its clients), you warrant that you are authorized to instruct us, and we act as your sub-processor; you remain our sole point of contact.
2.2. Our own processing. We are an independent controller of Account holders' contact, billing, usage and consent data described in our Privacy Policy, and of data we must process to comply with law, secure the Services and enforce the Agreement. This DPA does not apply to that processing.
2.3. Details of processing. The subject matter, nature, purpose and duration of processing, the types of Personal Data and the categories of Data Subjects are described in Annex 1.
3. Your instructions and responsibilities
3.1. Instructions. We process Personal Data only on your documented instructions, which are: (a) the Agreement and this DPA; (b) your configuration and use of the Services (including the Channels, integrations, AI Models, Skills, MCP Servers and External AI Clients you connect and the features you enable); and (c) any further written instructions agreed between the parties. We will inform you if we believe an instruction infringes Applicable Data Protection Law, without being obliged to review the law of your jurisdiction, and may suspend the instruction until it is clarified. We may process Personal Data to comply with a legal obligation, in which case we inform you unless the law prohibits it.
3.2. Your obligations. You are responsible for (a) the accuracy, quality and lawfulness of Personal Data and of the means by which you obtained it; (b) providing all notices and obtaining all consents and authorizations required for us to process Personal Data as instructed (including for recording, transcription and workplace reporting, and for any import of data from third-party systems); (c) not submitting Sensitive Data unless permitted by Section 5.7 of the Agreement; (d) responding to Data Subjects; (e) carrying out any privacy impact assessment, transfer assessment, registration or consultation required by your law before using the Services (for example under Quebec Law 25 sections 3.3 and 17); (f) configuring the Services (access controls, retention, deletion, Bot instructions and greetings, optional safeguards) in a manner consistent with your obligations; and (g) complying with the AUP.
3.3. Workforce Insights and automated processing. If you use Workforce Insights, you are the employer-controller and are responsible for the legal basis, employee notices, impact assessments, works-council or union consultation, and human review required by your law. We do not make decisions producing legal or similarly significant effects on Data Subjects; the Services are designed for human review as described in the AI Transparency Statement. Where your law gives Data Subjects rights regarding automated processing (for example LGPD Article 20, Quebec Law 25 section 12.1, GDPR Article 22), you are responsible for honoring them and we will provide the information about the logic and factors used in the Services that you reasonably need.
4. Confidentiality and personnel
4.1. We ensure that persons authorized to process Personal Data are bound by confidentiality obligations, receive appropriate instructions and training, and access Personal Data only to the extent needed to perform the Services (including support on your request under Section 3.4 of the Agreement).
5. Sub-processors
5.1. General authorization. You authorize us to engage the Sub-processors listed in the Sub-processor List at https://botb2b.ai/documents/sub-processors (the "List"), including the Model Providers that generate Output, and to engage new or replacement Sub-processors under this Section.
5.2. Notice of changes. We will update the List at least ten (10) days before a new Sub-processor starts processing your Personal Data, and we will notify by email the customers who have subscribed to updates as described on the List. Where replacement is urgently needed for security or continuity, we may update the List as soon as practicable after the change.
5.3. Objection. If you have a reasonable, documented objection based on data protection grounds, notify us within ten (10) days after the List is updated. We will work with you in good faith to address the objection (for example by not routing your requests to the Sub-processor, if technically feasible). If we cannot, you may terminate the affected Services or the Agreement on written notice and receive a refund of prepaid fees for the unused period, as your sole remedy.
5.4. Flow-down and liability. We impose on each Sub-processor data protection obligations that provide at least the same level of protection as this DPA, to the extent applicable to the services it provides, and we remain liable to you for the performance of Sub-processors as for our own. On request we provide a summary of the data protection terms of a Sub-processor, subject to confidentiality.
5.5. Model Providers. Our contracts with Model Providers prohibit them from using your Personal Data to train or improve their models and limit their retention of request data. Which Model Provider processes a given request depends on the AI Model you select and on the fallback rules in Section 6.5 of the Agreement; the AI Model actually used is shown in your Token ledger. You may restrict the AI Models available in your Workspace.
6. Security
6.1. We implement and maintain the technical and organizational measures described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing and the risks to Data Subjects. We may update the measures provided that the overall level of protection does not decrease.
6.2. You are responsible for security within your control: Member credentials, permissions, the security of your own systems and Channels, the credentials you connect, and the data you export or send to third parties.
7. Personal Data Breach
7.1. We notify you without undue delay, and in any event within forty-eight (48) hours after confirming a Personal Data Breach affecting your Personal Data, by email to the Owner Account address and, where appropriate, in the Services, so that you can meet the notification deadlines that apply to you (for example 48 hours in Peru, 72 hours in Uruguay, Panama, El Salvador and under the GDPR, three business days in Brazil, and 15 business days in Colombia).
7.2. The notification describes, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. We provide updates as information becomes available.
7.3. We cooperate with you and take reasonable steps to contain, investigate and remediate the breach. Notifications to Data Subjects and authorities are your responsibility as Controller, unless the law requires us to notify directly; we will not notify authorities or Data Subjects on your behalf without your instruction unless the law requires it.
7.4. Our notification is not an admission of fault or liability.
8. Assistance and Data Subject requests
8.1. Requests. The Services allow you to find, export, correct and delete Personal Data of Data Subjects (for example contacts, conversations, leads, reports). If a Data Subject contacts us directly about your Personal Data, we will (where identifiable) refer the request to you and will not respond substantively except as required by law.
8.2. Assistance. Taking into account the nature of processing, we assist you with reasonable technical and organizational measures, insofar as possible, in fulfilling your obligations to respond to Data Subject requests, to ensure security, to notify breaches, and to carry out data protection impact assessments and prior consultations with Supervisory Authorities, by providing the information available to us about the Services. We may charge reasonable fees for assistance that goes beyond the standard functionality of the Services or is excessive.
8.3. Government requests. If we receive a legally binding request from a public authority for your Personal Data, we will (unless legally prohibited) notify you promptly, challenge requests we consider unlawful or overbroad, disclose only the minimum required, and document the request.
9. Retention, return and deletion
9.1. During the term you may export and delete Personal Data through the Services and by request.
9.2. On termination of the Agreement or deletion of your Workspace we delete Personal Data as described in Section 17 of the Agreement: within ten (10) days after confirmed deletion, or thirty (30) days after other terminations, with backups retained for up to ninety (90) days and then deleted. Before deletion you may export your data. On request we confirm deletion in writing.
9.3. We may retain Personal Data to the extent required by law or for the records listed in Section 17.4 of the Agreement, in which case we continue to protect it under this DPA and process it only for those purposes. Members' own Accounts are personal accounts and survive the deletion of a Workspace as bare profiles without your content.
10. Audits and information
10.1. On request, not more than once per year (or more often after a Personal Data Breach or where required by a Supervisory Authority), we make available the information reasonably necessary to demonstrate compliance with this DPA, including the description of our security measures in Annex 2, completed security questionnaires and, when available, summaries of penetration tests and third-party certifications or audit reports.
10.2. If the information is insufficient to meet a legal requirement, you (or an independent auditor bound by confidentiality and not a competitor) may conduct an audit of our relevant controls, on at least thirty (30) days' written notice, during business hours, without disrupting our operations, limited in scope to your Personal Data, at your expense, and subject to our reasonable security and confidentiality requirements. Findings are Confidential Information. Audits do not extend to Sub-processors' premises, for which we provide their audit reports where available.
11. International transfers
11.1. Locations. We process Personal Data in the locations stated in the List (currently hosting in the European Union, with Model Providers and other Sub-processors mainly in the United States, and some in Canada and the EU). We may change locations with notice under Section 5.2. You acknowledge that use of the Services involves transfers of Personal Data to the United States.
11.2. Transfer instruments. Where a transfer is a Restricted Transfer, the instruments set out in Annex 3 apply and are incorporated into this DPA. If a Supervisory Authority or court invalidates an instrument or requires additional measures, the parties will cooperate in good faith to implement an alternative lawful instrument or measures.
11.3. Transfer assessments. We maintain a transfer impact assessment for our Sub-processors and provide a summary on request to support your own assessments (including under Quebec Law 25 section 17 and Clause 14 of the SCCs).
12. US State Law service provider terms
To the extent Personal Data is subject to US State Laws, the following applies, and the parties intend that we act as a "service provider" or "processor" and that our provision of the Services does not constitute a "sale" or "sharing" of personal information:
12.1. We process Personal Data only for the Business Purposes of providing the Services as described in the Agreement and Annex 1 and for no other purpose. We will not (a) sell or share Personal Data; (b) retain, use or disclose Personal Data for any purpose other than the Business Purposes, including for any commercial purpose other than providing the Services; (c) retain, use or disclose Personal Data outside the direct business relationship between us and you; or (d) combine Personal Data with personal information we receive from other persons or collect from our own interactions with individuals, except as permitted by law (for example to detect security incidents or to perform internal operations that do not include building profiles for other customers).
12.2. We certify that we understand the restrictions in Section 12.1 and will comply with them. We will notify you within five (5) business days if we determine that we can no longer meet our obligations under US State Laws. You may take reasonable and appropriate steps, in accordance with Section 10, to ensure that we use Personal Data consistently with your obligations, and to stop and remediate unauthorized use.
12.3. We will comply with applicable obligations under US State Laws and provide the same level of privacy protection required of businesses; we will assist you in responding to verifiable consumer requests, including by deleting Personal Data as instructed; we will flow down these obligations to our Sub-processors by written contract; and we will honor opt-out preference signals as required.
12.4. Nothing in this Section requires us to breach a legal obligation, and the parties acknowledge that we are not required to review Customer Content proactively for compliance.
13. LGPD and Latin America terms
13.1. Brazil. To the extent the LGPD applies, we act as operador and you as controlador. We process Personal Data in accordance with your instructions and the LGPD (Article 39), maintain records of processing operations (Article 37), adopt the security measures in Annex 2 (Article 46), notify you of security incidents that may cause relevant risk or harm to Data Subjects within the period in Section 7 so that you can notify the ANPD and Data Subjects (Article 48), and assist you in responding to Data Subject rights requests (Article 18). Our data protection officer (encarregado) can be reached at [email protected]. Because the ANPD has not recognized any country as providing an adequate level of protection, every transfer of Brazilian Personal Data outside Brazil (to our hosting in the European Union and to our Sub-processors in the United States and elsewhere) is made under the standard contractual clauses approved by the ANPD (Annex 3, Part D) or another hypothesis of Article 33 of the LGPD, and information addressed to Data Subjects under those clauses is provided in Portuguese. Personal Data of Brazilian Data Subjects held in application access logs is retained for at least six (6) months as required by Article 15 of the Marco Civil da Internet.
13.2. Mexico. To the extent Mexican law applies, we act as encargado and you as responsable; you are responsible for your aviso de privacidad and for obtaining consent where required. We process Personal Data only under your instructions, keep it confidential, do not transfer it except as instructed by you or required by law, implement the security measures in Annex 2, and delete it at the end of the relationship as described in Section 9. Communication of Personal Data to us as encargado is a remisión and not a transferencia.
13.3. Argentina. To the extent Law 25.326 applies, we process Personal Data as encargado de tratamiento under Article 25 and only for the purposes of the Agreement; international transfers are covered by the model clauses approved by the Agencia de Acceso a la Información Pública (Annex 3, Part E).
13.4. Colombia. To the extent Law 1581/2012 applies, the communication of Personal Data to us is a "transmisión" to an encargado under a contract that complies with Article 25 of Decree 1377/2013: we process Personal Data only for the purposes and under the instructions of the responsable, ensure security and confidentiality, honor Data Subject rights as instructed, and do not use the data for other purposes. Onward transfers to Sub-processors outside Colombia are made under Annex 3.
13.5. Chile, Peru, Uruguay, Ecuador and other countries. To the extent the data protection law of another Latin American country applies, this DPA constitutes the processor (encargado / mandatario) agreement required by that law, and Annex 3 provides the contractual clauses for international transfers. Where a law requires registration or notification of a transfer or database, you are responsible for it as Controller and we provide the information you need.
14. Canada terms
To the extent PIPEDA or Quebec Law 25 applies: we process Personal Data only for the purposes of the Agreement; we keep it confidential; we do not use or communicate it for other purposes; we do not retain it after the end of the mandate except as provided in Section 9; we notify you of any breach or attempted breach of confidentiality as provided in Section 7; and we allow you to verify our compliance as provided in Section 10 (Quebec Law 25, section 18.3). Personal Data is communicated outside Quebec and outside Canada (to the United States and the European Union) as described in the List; we provide the information in Section 11.3 to support your assessment under section 17 of Quebec Law 25.
15. GDPR, UK and Swiss terms (where applicable)
To the extent the GDPR, the UK GDPR or the FADP applies, this DPA constitutes the contract required by Article 28(3) GDPR (and its UK and Swiss equivalents), Annex 1 describes the processing as required by Article 28(3), and Annex 3 Parts A to C provide the transfer instruments. We keep records of processing under Article 30(2). We will inform you if we are required to appoint a representative in the EU or the UK and publish the details. Model Providers act as our Sub-processors under Article 28(4).
16. Liability and precedence
16.1. Each party's liability under this DPA is subject to the exclusions and limitations in Section 19 of the Agreement, in the aggregate with liability under the Agreement, except where the SCCs or Applicable Data Protection Law require otherwise for Data Subjects and Supervisory Authorities.
16.2. This DPA prevails over the Agreement for the processing of Personal Data. The transfer instruments in Annex 3 prevail over this DPA for Restricted Transfers to the extent of any conflict.
16.3. This DPA lasts as long as we process Personal Data on your behalf and survives termination for that period.
Annex 1 — Details of processing
Subject matter. Provision of the BotB2B platform: AI chatbots on messaging, web and marketplace Channels; CRM, tasks, notes and calendar; Knowledge Bases; My AI; AI Managers; MCP Servers; Workforce Insights; integrations; and related support.
Duration. The term of the Agreement plus the deletion periods in Section 9.
Nature and purpose. Hosting, storage, transmission, transcription, summarization, generation of Output through AI Models, embedding for retrieval, analysis and display for the Customer's business purposes; backup; security; support on the Customer's request.
Categories of Data Subjects. (a) End Users: customers, prospects, visitors and counterparties of the Customer who interact with Bots, widgets, Channels or whose data the Customer stores in the CRM; (b) representatives of the Customer's business counterparties; (c) the Customer's Members, employees and contractors who use the Services or submit work reports; (d) other persons mentioned in Customer Content.
Categories of Personal Data. Identification and contact data (name, phone, email, messenger identifiers, addresses, company and position); conversation content and metadata (messages, attachments, timestamps, Channel identifiers, lead details, orders and requests); CRM records (deals, tasks, notes, interaction history); Knowledge Base content the Customer uploads; work reports of Members (text, voice recordings for transcription, transcripts, self-reported completion, energy and stress levels if provided, tasks and goals, mentions of colleagues), employment details entered by the Customer (role, schedule, absences, cost of employment); AI Manager conversation and file content; usage and audit data within the Workspace.
Sensitive Data. Not intended to be processed. The Customer must not submit Sensitive Data except as permitted by Section 5.7 of the Agreement; if it does, the Customer is responsible for the lawful basis and safeguards, and Annex 2 measures apply.
Frequency. Continuous, as determined by the Customer's use.
Sub-processors and locations. As stated in the Sub-processor List.
Retention. As stated in Section 9 and in Section 17 of the Agreement.
Annex 2 — Technical and organizational measures
- Governance. Named security owner; information security and privacy policies; confidentiality agreements for all personnel; security and privacy training on onboarding and annually; vendor due diligence and data processing terms with all Sub-processors; records of processing.
- Access control. Individual accounts; role-based access (Owner, Admin, Manager, Employee) and department scoping; least-privilege administrative access limited to a minimal number of authorized administrators; multi-factor authentication for administrators on hosting, code and vendor consoles; SSH key authentication; review of administrative access at least quarterly; immediate revocation on offboarding.
- Authentication. Passwords hashed with Argon2; short-lived access tokens (15 minutes) and rotating refresh tokens (15 days); revocation of all sessions on request and on deletion; API keys stored hashed and revocable; OAuth-scoped MCP connections with hashed 30-day rotating refresh tokens; reCAPTCHA and rate limiting on public endpoints.
- Encryption. TLS 1.2+ for all data in transit, including to Sub-processors; encryption at rest of files and backups in cloud object storage; AES-256-GCM encryption of stored payment-provider secrets; payment card data handled exclusively by Stripe.
- Segregation. Logical separation of Workspaces by identifiers enforced at application and database layers; per-customer isolated containers for AI Managers; private storage buckets with signed, time-limited URLs.
- Data minimization in AI processing. Only the content needed for a request is sent to Model Providers; optional masking of contact data in standard formats can be enabled for a Workspace on request; no training on Customer Content; Model Providers bound by no-training and limited-retention terms; Customer control over AI Model selection.
- Logging and monitoring. Application logs; team audit log of administrative actions in Workspaces; append-only membership and consent journals; Token ledger recording each AI request and the model used; error monitoring with scrubbing of sensitive values; alerting on failures and anomalies.
- Vulnerability and change management. Version-controlled code with review; dependency updates and priority patching of critical vulnerabilities; separation of development and production; periodic internal security reviews.
- Availability and backup. Redundant infrastructure at the hosting provider; regular backups with restricted access; backups retained up to 90 days and then deleted, with deletions re-applied after any restore; restoration testing; AI Manager backups retained 90 days.
- Incident response. Documented procedure for detection, containment, eradication, recovery, root-cause analysis and notification; customer notification within 48 hours of confirming a Personal Data Breach.
- Deletion. Customer self-service deletion of conversations, contacts, Knowledge Bases, AI Managers and Workspaces; confirmed deletion with one-time code; automated destruction after 10 days (30 days after other terminations); anonymization of records that must be kept; secure deletion of storage objects and vector embeddings.
- Physical security. Data centers of hosting providers with ISO 27001 certification, access control, surveillance, redundant power and cooling; no Customer Data on portable media.
- Sub-processor management. Published list updated at least 10 days before a new Sub-processor starts processing; email notice to subscribed customers; contractual flow-down; periodic review of Sub-processors' certifications and terms.
Annex 3 — International transfer instruments
Part A — EU/EEA (GDPR). For Restricted Transfers of Personal Data subject to the GDPR, the SCCs are incorporated by reference with the following selections: Module Two (controller to processor) applies where you are a controller, and Module Three (processor to processor) applies where you are a processor; Clause 7 (docking) is included; in Clause 9, Option 2 (general written authorization) applies with the notice period in Section 5.2 of this DPA; in Clause 11, the optional language is not included; in Clause 13, the Supervisory Authority is that of the EU Member State in which you are established or, if none, that of your Article 27 representative or the Member State of the Data Subjects; in Clause 17, Option 1 applies and the governing law is the law of Ireland; in Clause 18, the courts of Ireland; Annex I.A and I.B of the SCCs are completed by Annex 1 of this DPA and the Agreement (parties' details), Annex I.C by Clause 13, Annex II by Annex 2 of this DPA, and Annex III by the Sub-processor List. You are the "data exporter" and we are the "data importer". Where our Sub-processors are located in third countries, we enter into Module Three SCCs (or rely on their Data Privacy Framework certification or another valid instrument) with them.
Part B — United Kingdom. For Restricted Transfers subject to the UK GDPR, the SCCs as set out in Part A apply as amended by the UK International Data Transfer Addendum issued by the Information Commissioner (version B1.0), with Tables 1 to 3 completed by the information in Part A and this DPA and Table 4 allowing either party to end the Addendum as set out in section 19 of the Addendum.
Part C — Switzerland. For Restricted Transfers subject to the FADP, the SCCs as set out in Part A apply with the following adaptations: references to the GDPR are read as references to the FADP; the competent supervisory authority is the Federal Data Protection and Information Commissioner; the term "Member State" is not interpreted to exclude Data Subjects in Switzerland from suing in Switzerland; and the SCCs also protect data of legal entities until the FADP no longer does so.
Part D — Brazil (LGPD). For international transfers of Personal Data subject to the LGPD, the parties adopt the standard contractual clauses approved by the ANPD in Resolution CD/ANPD No. 19 of 23 August 2024 (Annex II of the Regulation on International Data Transfer), which are incorporated into this DPA by reference as Schedule D in their official wording, without modification, with the Customer as the exporter and BotB2B as the importer, and with the annexes of those clauses completed by Annex 1 and Annex 2 of this DPA and the Sub-processor List. We provide Schedule D for signature together with this DPA on request at [email protected].
Part E — Argentina. For transfers of Personal Data subject to Law 25.326 to countries without an adequate level of protection, the parties adopt the model contract for international transfer of personal data to a data processor approved by the Agencia de Acceso a la Información Pública in Disposición 60-E/2016 (Annex II), which is incorporated into this DPA by reference as Schedule E in its official wording, without modification, completed by Annex 1 and Annex 2 of this DPA. We provide Schedule E for signature together with this DPA on request at [email protected].
Part F — Colombia. The transmission of Personal Data to us is governed by the transmission contract terms in Section 13.4 of this DPA (Decree 1377/2013, Article 25). Onward transfers to Sub-processors are made to countries that the Superintendencia de Industria y Comercio recognizes as adequate or under contractual clauses providing equivalent guarantees, or otherwise with the authorization of the Data Subject obtained by the Customer.
Part G — Other countries. For Chile (Law 19.628 and, from its entry into force, Law 21.719), Peru (Law 29733 and its regulations), Uruguay (Law 18.331), Ecuador (LOPDP), Mexico, Panama, Costa Rica, the Dominican Republic and other countries whose law requires contractual guarantees for international transfers, the parties agree that (i) we will process the transferred Personal Data only for the purposes in Annex 1 and under the Customer's instructions; (ii) we will apply the measures in Annex 2; (iii) we will honor Data Subject rights as instructed by the Customer; (iv) we will not onward-transfer Personal Data except to Sub-processors bound by equivalent obligations; (v) we will delete or return the Personal Data at the end of the Services; and (vi) Data Subjects may enforce these guarantees as third-party beneficiaries to the extent their law so provides. Where a law requires registration, notification or authorization of the transfer, the Customer is responsible for it and we provide the necessary information.
Part H — Canada and Quebec. Personal Data is communicated outside Canada and Quebec to the United States and the European Union under the safeguards in this DPA; the Customer performs any assessment required by section 17 of Quebec Law 25 with the information we provide under Section 11.3.
Schedule D — Standard contractual clauses approved by the ANPD (Resolution CD/ANPD No. 19 of 23 August 2024, Annex II of the Regulation on International Data Transfer), incorporated by reference in their official wording without modification; provided for signature together with this DPA on request at [email protected].
Schedule E — Model contract for the international transfer of personal data to a data processor approved by Argentina's Agencia de Acceso a la Información Pública (Disposición 60-E/2016, Annex II), incorporated by reference in its official wording without modification; provided for signature together with this DPA on request at [email protected].
Questions about this DPA: [email protected]