dpa

DATA PROCESSING ADDENDUM

HOW THIS DPA APPLIES

If the Customer entity signing this DPA is a party to the Agreement, this DPA is an addendum to and forms part of the Agreement. In such case, the Own entity that is party to the Agreement is party to this DPA.

If the Customer entity signing this DPA has executed an Order Form with Own or its Affiliate pursuant to the Agreement, but is not itself a party to the Agreement, this DPA is an addendum to that Order Form and applicable renewal Order Forms, and the Own entity that is party to such Order Form is party to this DPA.

If the Customer entity signing this DPA is neither a party to an Order Form nor the Agreement, this DPA is not valid and is not legally binding. Such entity should request that the Customer entity that is a party to the Agreement execute this DPA.

If the Customer entity signing the DPA is not a party to an Order Form nor a Master Subscription Agreement directly with Own, but is instead a customer indirectly via an authorized reseller of Own services, this DPA is not valid and is not legally binding. Such entity should contact the authorized reseller to discuss whether an amendment to its agreement with that reseller is required.

In the event of any conflict or inconsistency between this DPA and any other agreement between Customer and Own (including, without limitation, the Agreement or any data processing addendum to the Agreement), the terms of this DPA shall control and prevail.

1. DEFINITIONS

“CCPA” means the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et. seq., as amended by the California Privacy Rights Act of 2020 and together with any implementing regulations.

“Controller” means the entity which determines the purposes and means of the Processing of Personal Data and is deemed to also refer to a “business” as defined in the CCPA.

“Customer” means the entity named above and its Affiliates.

“Data Privacy Framework” means the EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework and/or UK Extension to the EU-U.S. Data Privacy Framework, as applicable.

“Data Protection Laws and Regulations” means all laws and regulations of the European Union and its member states, the European Economic Area and its member states, the United Kingdom, Switzerland, the United States, Canada, New Zealand, and Australia, and their respective political subdivisions, applicable to the Processing of Personal Data.

“Data Subject” means the identified or identifiable person to whom Personal Data relates and includes “consumer” as defined in Data Protection Laws and Regulations.

“GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

2. PROCESSING OF PERSONAL DATA

a. Scope. The parties agree that this DPA shall apply solely to the Processing of Personal Data within the Personal Data Processing Services.

b. Roles of the Parties. The parties agree that with regard to the Processing of Personal Data, Customer is the Controller and Own is the Processor.

c. Own’s Processing of Personal Data. Own shall treat Personal Data as Confidential Information and shall Process Personal Data on behalf of and only in accordance with Customer’s documented instructions for the following purposes: (i) Processing in accordance with the Agreement and applicable Orders; (ii) Processing initiated by Customer personnel in their use of the SaaS Services; and (iii) Processing to comply with other documented reasonable instructions provided by Customer (e.g., via email) where such instructions are consistent with the terms of the Agreement.

d. Processing Restrictions. Own shall not: (i) “sell” or “share” Personal Data; (ii) retain, use, disclose or Process Personal Data for any commercial or other purpose other than to perform the SaaS Services; or (iii) retain, use, or disclose Personal Data outside of the direct business relationship between Customer and Own.

3. REQUESTS FOR CUSTOMER DATA

a. Requests from Data Subjects. Own shall, to the extent legally permitted, promptly notify Customer if Own receives a request from a Data Subject to exercise the Data Subject's rights. Taking into account the nature of the Processing, Own shall assist Customer by appropriate technical and organizational measures, to the fulfilment of Customer’s obligation to respond to a Data Subject Request under Data Protection Laws and Regulations.

b. Requests from Other Third Parties. If Own receives a request from a third party other than a Data Subject (including, without limitation, a government agency) for Customer Data, Own shall where permitted by law direct the requesting party to the Customer and promptly notify the Customer of the request.

4. OWN PERSONNEL

Own shall ensure that its personnel engaged in the Processing of Personal Data are informed of the confidential nature of the Personal Data, have received appropriate training on their responsibilities and have executed written confidentiality agreements.

5. SUB-PROCESSORS

a. Appointment of Sub-processors. Customer grants Own a general authorization to appoint third-party Sub-processors in connection with the SaaS Services.

b. Current Sub-processors and Notification of New Sub-processors. A list of Sub-processors for the SaaS Services, as of the date this DPA is executed, is attached in Schedule 1.

c. Objection Right for New Sub-processors. Customer may object to Own’s use of a new Sub-processor by notifying Own in writing within 30 days after receipt of a notice.

6. SECURITY

a. Controls for the Protection of Customer Data. Own shall maintain appropriate physical, technical and organizational measures for protection of the security of Customer Data.

SCHEDULE 1

Current Sub-Processor List

SaaS Services Sub-Processor Activity Sub-Processor Name and Address Location of Processing
Recover for ServiceNow Customer support and system administration Own Data Company Ltd., 41st Floor, Derech Menachem Begin 121, Tel Aviv 6701203, Israel Israel
Recover for ServiceNow Application hosting Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, Washington 98109, USA USA, Canada, Germany, United Kingdom, or Australia
Archive for ServiceNow Customer support and system administration Own Data Company Ltd., 41st Floor, Derech Menachem Begin 121, Tel Aviv 6701203, Israel Israel

SCHEDULE 2

SaaS Services Applicable to Personal Data Processing

SCHEDULE 3

Details of the Processing

Data Exporter

Data Importer

Nature and Purpose of Processing

Categories of Data Subjects

Type of Personal Data

SCHEDULE 4

Own Security Controls

1. Introduction

Own software-as-a-service applications (SaaS Services) were designed from the beginning with security in mind.

2. Audits and Certifications

3. Web Application Security Controls

4. Encryption

5. Monitoring and Auditing

6. Request for audit

SCHEDULE 5

European Provisions

Transfer Mechanism for Data Transfers. The Standard Contractual Clauses apply to any Outside Europe Transfers, subject to applicable Data Protection Laws.