LEGAL
Data Processing Addendum
PARADIGM STRATEGY INC
DATA PROCESSING ADDENDUM
This Data Processing Addendum (“DPA”) is entered into between Paradigm Strategy Inc. (“Paradigm”) and the entity accepting this DPA (“Customer”) (Paradigm and Customer, individually a “Party” and collectively the “Parties”) and supplements and is part of the Terms of Service (“Agreement”), to the extent processing Personal Data (defined below) is part of the Services. By accepting the Agreement or by accessing or using the Services, Customer agrees to be bound by this DPA. If there is a conflict between the terms of this DPA and the provisions of the Agreement, the terms of this DPA shall prevail with regard to the Processing of Personal Data. Unless otherwise defined in this DPA or in the Agreement, all capitalized terms used in this DPA will have the meanings given to them in Section 1 of this DPA or as defined by applicable Data Protection Laws. In consideration of the mutual obligations set out herein, the Parties hereby agree that the terms and conditions set out below shall be added as an addendum to the Agreement.
This DPA is effective as of the date Customer first accepts the Agreement or accesses or uses the Services, whichever is earlier (“Effective Date”), and amends, supersedes and replaces any prior data processing agreements that the Parties may have entered. Paradigm may update this DPA from time to time. If Paradigm makes a material change to this DPA, Paradigm will provide Customer with reasonable notice prior to the change taking effect, either by posting a notice on the Services or by sending Customer an email. Customer’s continued use of the Services after any such update constitutes Customer’s acceptance of such changes.
1. DEFINITIONS
1.1 “CCPA” means the California Consumer Privacy Act of 2018, as amended and updated including, without limitation, by the California Privacy Rights Act.
1.2 “Customer Data” means all Personal Data which Customer directs Paradigm to Process as part of its provision of the Services to Customer under the Agreement.
1.3 “Services” means the services that are ordered by the Customer from Paradigm under the Agreement involving the Processing of Personal Data on behalf of the Customer.
1.4 “Data Breach” means any confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, as well as the unauthorized acquisition, disclosure of, or access to, Customer Data transmitted, stored or otherwise Processed.
1.5 “Data Protection Laws” means all data protection laws and regulations applicable to the Processing of Personal Data hereunder including the General Data Protection Regulation 2016/679 (“GDPR”), the UK Data Protection Act of 2018, and the UK GDPR (collectively “UK Data Protection Laws”); and laws applicable in the United States such as the CCPA, Virginia Consumer Data Protection Act, Colorado Privacy Act, Utah Consumer Privacy Act, and Connecticut Data Privacy Act.
1.6 “EEA Data” means Personal Data collected from Data Subjects when they were located in the European Economic Area (“EEA”).
1.7 “Personal Data” means any information relating to an identified or identifiable natural person (“Data Subject”), directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
1.8 “Subprocessor” means any Processor engaged by Paradigm to Process Personal Data on behalf of Paradigm in order to provide the Services to the Customer.
1.9 “UK Data” means Personal Data collected from Data Subjects when they were located in the United Kingdom.
2. DETAILS OF PROCESSING ACTIVITIES
2.1 In addition to details set out in Schedule 1, the details of Processing are as follows:
a) Subject Matter. Paradigm’s provision of Services to the Customer.
b) Purpose. Paradigm will Process Customer Data for the purpose of providing certain consulting and/or online services as provided by the Agreement.
c) Duration. The Processing of Customer Data will continue for the duration of the Agreement.
d) Type of Customer Data. Depending on the specific Services as contemplated by the Agreement, Customer Data Processed by Paradigm may include, without limitation:
Account and User Information: names, business contact information (e.g., email address, job title, department, employer name), account credentials, user identifiers, and platform usage metadata.
Organizational and Workforce Information: employee or contractor demographic or workforce composition information provided by Customer, such as job level, function, tenure, department, location, reporting structure, or similar workforce analytics data.
Training and Program Participation Data: records related to participation in Paradigm courses, workshops, coaching sessions, microlearnings, or other learning or advisory programs, including attendance data, completion status, or assessment results.
Content Submitted by Users: queries, prompts, comments, documents, attachments, free-text responses, survey and feedback data, communications data, or other information submitted or communicated by Customer or its end users through the Platform or other Services, including Inputs provided to AI-enabled tools and related Outputs generated by such tools.
End User Employee Data: names, emails, gender, age, race, ethnicity, and/or other Personal Data that is requested by Customer for Paradigm to Process about its employees or other end users as part of the Services requested by Customer.
e) Categories of Data Subjects. The Data Subjects may include Customer’s employees, end users, contractors, or other authorized representatives through the Platform, Services, or other consulting engagements as provided under the Agreement.
2.2 Roles of the Parties. To the extent provided under applicable Data Protection Laws, Customer shall act as Controller and Paradigm as Processor (or words of similar meaning under applicable Data Protection Laws) with respect to the Processing of Customer Data. To the extent Customer is a Business under the CCPA, Paradigm will act as a “Service Provider” or “Contractor” in its performance of its obligations under the Agreement. Paradigm will not Sell or Share Customer Data to the extent prohibited by applicable Data Protection Laws.
2.3 Customer Instructions. The Parties agree this DPA and the Agreement constitute Customer’s documented instructions regarding Paradigm’s Processing of Customer Data. Paradigm will Process Customer Data only in accordance with these documented instructions and in accordance with applicable Data Protection Laws.
2.4 Compliance with Laws. Each Party agrees to comply with all applicable Data Protection Laws during the Processing of Personal Data in connection with the Services. Each Party agrees to notify the other Party in the event the reporting Party can no longer meet its obligations under applicable Data Protection Laws.
3. CUSTOMER’S OBLIGATIONS
3.1 Instructions. Customer warrants that (i) the instructions it provides to Paradigm pursuant to this DPA and the Agreement comply with the Data Protection Laws, and (ii) it has provided, and will continue to provide, all notices and has obtained, and will continue to obtain, all consents and rights necessary under Data Protection Laws for Paradigm to Process Customer Data for the purposes described in the Agreement. Customer shall have sole responsibility for the accuracy, quality, and legality of Customer Data and the means by which Customer acquired the Customer Data. Customer specifically acknowledges that its use of the Services will not violate the rights of any Data Subject that has opted-out from the Sale, Sharing, or other Processing of Personal Data, to the extent applicable under Data Protection Laws. The Customer acknowledges that part or all of the Services offered by Paradigm to Customer may constitute ‘profiling’ as that term is defined under Data Protection Laws. Customer agrees to comply with all requirements and obligations related to profiling in connection with the Services, to the extent applicable. Paradigm will provide reasonable assistance to Customer related to profiling compliance, to the extent required by Data Protection Laws.
4. PARADIGM’S OBLIGATIONS
4.1 Scope of Processing. Paradigm will Process the Customer Data on documented instructions from Customer in such manner as is necessary for the provision of Services under the Agreement, except as may be required to comply with any legal obligation to which Paradigm is subject or as allowed under Data Protection Laws. Customer may take reasonable and appropriate steps (i) to ensure Paradigm uses the Customer Data in a manner consistent with Paradigm’s obligations under this DPA; and (ii) to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Data.
4.2 Restrictions on Retention, Use, or Disclosure of Customer Data. Paradigm agrees that it will not use, retain, disclose, or otherwise Process Customer Data outside of the direct business relationship between Paradigm and Customer or for any commercial purpose or other purpose other than providing the Services to Customer as specified in the Agreement or as allowed under applicable Data Protection Laws. Paradigm agrees not to combine, update, or otherwise merge Customer Data with other Personal Data in violation of applicable Data Protection Laws. Notwithstanding any other provision in this DPA, Paradigm may internally use Customer Data to build or improve the quality of the Services it provides to Customer.
4.3 Deletion or Return of Customer Data. Upon expiration or termination of the Agreement, Paradigm shall return or destroy all Customer Data in its possession which is no longer needed to provide the Services, unless Paradigm is prohibited from doing so under applicable law. The confidentiality protections in this DPA shall apply to any Customer Data in Paradigm’s possession or control until such Customer Data is deleted or returned to Customer.
4.4 Deidentified Information. Notwithstanding the foregoing, unless prohibited by applicable Data Protection Law, the Parties agree that Paradigm may convert Customer Data into Deidentified Information (as defined under applicable Data Protection Laws), which it may use for any lawful purpose. Paradigm agrees that, to the extent it converts Customer Data into Deidentified Information, Paradigm will (i) take reasonable measures to ensure the Deidentified Information cannot be associated with a Data Subject or household; (ii) publicly commit to maintain and use the Deidentified Information in deidentified form; and (iii) not attempt to reidentify the Deidentified Information except for the sole purpose of determining whether Paradigm’s deidentification processes satisfy the requirements of Data Protection Laws.
4.5 Data Breach. Paradigm shall, to the extent permitted by applicable Data Protection Laws, notify Customer of any Data Breach involving Customer Data in accordance with applicable Data Protection Laws, and specifically for EEA Data and UK Data, without undue delay, and no more than seventy-two (72) hours after confirming a Data Breach has occurred. Paradigm will use reasonable efforts to investigate the Data Breach and take any actions that are reasonably necessary to mitigate damage, as required by applicable Data Protection Laws and as appropriate under the circumstances, and Paradigm will provide Customer with information necessary to fulfill its notification obligations under Data Protection Laws. Paradigm will reasonably assist Customer in fulfilling its obligations to notify Data Subjects and the relevant authorities in relation to a Data Breach as required by Data Protection Laws, provided that nothing in this section shall prevent either Party from complying with its obligations under Data Protection Laws. The Parties agree to coordinate in good faith on developing the content of any related public statements.
4.6 Notice of Complaints and Data Subject Requests. Paradigm shall, to the extent legally permitted, promptly notify Customer in writing of any complaints, questions or requests received from Data Subjects or regulators regarding the Personal Data. Customer shall be responsible for communications and leading any efforts to comply with all requests made by Data Subjects and all communications from regulators that relate to the Personal Data. In addition, Paradigm shall inform Customer if it receives a request from a Data Subject to exercise their rights under Data Protection Laws. Paradigm shall provide such reasonable assistance pursuant to its obligations under Data Protection Laws as Customer requests to help Customer fulfill its obligations under Data Protection Laws to respond to Data Subject requests. Notwithstanding its obligations under this Section, Paradigm is not obligated to respond to a Data Subject request directly from a Data Subject and does not otherwise assume any liability or responsibility for responding to Data Subject requests.
4.7 Assistance. Taking into account the nature of Processing and the information available to Paradigm, Paradigm will provide all reasonable assistance and cooperation to Customer in respect of its relevant obligations under applicable Data Protection Laws, including, without limitation, with respect to conducting privacy and data protection impact assessments.
4.8 Security. Paradigm will take commercially reasonable steps to keep Customer Data confidential and, taking into account the context of the Processing, implement and maintain administrative, physical, technical and organizational safeguards designed to provide for the security (including protection against accidental or unlawful loss, destruction, alteration, damage, unauthorized disclosure of, or access to, Customer Data transmitted, stored or otherwise Processed), confidentiality and integrity of Customer Data including, by implementing the following:
a) Access Control of Processing Areas. Internal processes to prevent unauthorized persons from gaining access to the Paradigm data processing equipment (namely telephones, database and application servers and related hardware) where the Customer Data are Processed or used, to include: establishing security areas and clear protocols; protection and restriction of access paths; securing the data processing equipment and personal computers; establishing access authorization for employees and third parties, including respective authorization; all access to the data centers where Customer Data are hosted is logged, monitored, and tracked; and the data centers where Customer Data are hosted is secured by a security alarm system, and other appropriate security measures.
b) Access Control to Data Processing Systems. Processes to prevent Paradigm data processing systems from being used by unauthorized persons, to include: identification of the terminal and/or the terminal user to the data processor systems; two-step authentication & SSO for secure access to data processor systems; automatic time-out of user terminal if left idle, identification and password required to reopen; regular examination of security risks by internal personnel and qualified third-parties; issuing and safeguarding of identification codes; password complexity requirements (minimum length, expiry of passwords, etc.); protection against external access by means of firewall and network access controls; and ensure that key personnel engaged in the Processing of Customer Data are subject to binding confidentiality obligations.
c) Access Control to Use Specific Areas of Data Processing Systems. Measures to ensure that persons entitled to use Paradigm data processing systems are only able to access the data within the scope and to the extent covered by their respective access permission (authorization) and that Customer Data cannot be read, copied or modified or removed without authorization, to include by: implementing binding employee policies and providing training in respect of each employee’s access rights to the Customer Data; assignment of unique user identifiers with permissions appropriate to the role; effective and measured disciplinary action against individuals who access Personal Data without authorization; release of data to only authorized persons; and policies controlling the retention of backup copies.
d) Transmission Control. Procedures to prevent Customer Data from being read, copied, altered or deleted by unauthorized parties during the transmission thereof or during the transport of the data media and to ensure that it is possible to check and establish to which bodies the transfer of Customer Data by means of data transmission facilities is envisaged, to include: use of firewall and encryption technologies to protect the gateways and pipelines through which the data travels; implementation of encrypted connections to safeguard the connection to Paradigm systems; constant monitoring of infrastructure (e.g. ICMP-Ping at network level, disk space examination at system level, successful delivery of specified test pages at application level); and monitoring of the completeness and correctness of the transfer of data.
e) Input Control. Measures to ensure that it is possible to check and establish whether and by whom Customer Data has been input into data processing systems or removed; protective measures for the data input into memory, as well as for the reading, alteration and deletion of stored data; segregation and protection of stored data via database schemas and logical access controls; utilization of user codes (passwords); proof established within data importer’s organization of the input authorization; and providing that entries to data processing facilities (the rooms housing the computer hardware and related equipment) are capable of being locked.
f) Availability Control. Measures to ensure that Customer Data are protected from accidental destruction or loss, to include: automatic failover between sites; infrastructure redundancy; and regular backups performed on database servers.
5. CONTRACTING WITH SUBPROCESSORS
5.1 Authorized Subprocessors. Customer acknowledges and expressly agrees Paradigm may engage existing Subprocessors as outlined here: https://trust.paradigmiq.com/subprocessors. Paradigm may engage new Subprocessors as described in Section 5.2.
5.2 New Subprocessors. Before Paradigm engages any new Subprocessor to carry out Processing activities on Customer Data on behalf of Customer, Paradigm will update the list of authorized Subprocessors available in Section 5.1 of this DPA. Paradigm will notify Customer of any changes to the Subprocessor List via blog post, notification within the Services or other reasonable means, or via email if Customer subscribes to email notifications on the Sub-Processor List site: https://info.paradigmiq.com/subscribe-to-new-sub-processors. If the Customer has a reasonable objection to any new or replacement Subprocessor related to the privacy or security of the Customer Data, it shall notify Paradigm of such objections in writing within thirty (30) days of the notification and the Parties will seek to resolve the matter in good faith. Paradigm will use reasonable efforts to make a change in the Service or recommend a commercially reasonable change to avoid Processing by such Subprocessor. If, after good faith discussions, the Parties are unable to agree on a resolution regarding the engagement of a new Subprocessor, Paradigm may terminate the Agreement upon written notice to Customer, without penalty, liability, or obligation to pay any termination fees.
5.3 Subprocessor Obligations. Paradigm will enter into a written agreement with each Subprocessor and, to the extent that the Subprocessor is performing or assisting with Processing services as outlined in the Agreement, Paradigm will impose on the Subprocessor contractual obligations materially similar to those in this DPA with respect to the protection of Customer Data to the extent applicable to the nature of the Services provided by such Subprocessor and required by applicable Data Protection Laws.
5.4 Responsibility. Paradigm will remain liable for any acts and omissions of its Subprocessors that cause Paradigm to breach any of Paradigm’s obligations under this DPA.
6. INTERNATIONAL TRANSFERS
6.1 General Transfer Acknowledgement. Customer acknowledges that Paradigm may, without Customer’s prior written consent, transfer the Customer Data to a foreign jurisdiction as necessary to provide the Services as set forth in the Agreement provided such transfer is either (i) to a country or territory which has been formally recognized as affording the Customer Data an adequate level of protection or (ii) the transfer is otherwise safeguarded by mechanisms, making it a legal transfer.
6.2 Transfers of EEA Data. The Parties agree that the information contained in the EU Standard Contractual Clauses (“EU SCCs”) (attached as Schedule 2) will apply to EEA Data that is transferred outside the EEA, either directly or via onward transfer, to any country not recognized by the European Commission as providing an adequate level of protection for Personal Data (as described by the EU Data Protection Laws). In the event of any conflict between this DPA and the EU SCCs as set out in Schedule 2, the EU SCCs shall prevail.
6.3 UK Transfers. In case of any transfers of UK Data under this DPA that require the execution of the UK Standard Contractual Clauses (“UK SCCs”), the Parties agree that the information contained in the UK SCCs, attached to this DPA as Schedule 3, will apply to UK Data transferred to Paradigm, either directly from the United Kingdom or via onward transfer. In the event of any conflict or inconsistency between the provisions of this DPA and the UK SCCs as set out in Schedule 3, the provisions of the UK SCCs shall prevail.
6.4 Swiss Transfers. In case of any transfers of Customer Data under this DPA from Switzerland to a jurisdiction that require such transfer mechanism, the Parties agree that the EU SCC attached at Schedule 2 will apply to such Customer Data transferred to Paradigm, either directly from Switzerland or via onward transfer. The Parties agree that the following additional clarifications apply to Schedule 2 as to the Processing of such Customer Data: (i) for purposes of Annex I.C under EU SCC Clause 13, insofar as the data transfer is governed by the Switzerland Federal Act on Data Protection of 19 June 1992 (SR 235.1; FADP) or the FADP’s revised 25 September 2020 version, the Supervisory Authority shall be Switzerland’s Federal Data Protection and Information Commissioner (FDPIC); (ii) for transfers of Swiss Personal Data the applicable law for contractual claims pursuant to EU SCC Clause 17 and the applicable place of jurisdiction pursuant to EU SCC Clause 18(b) shall be Ireland; and (iii) the term “member state” must not be interpreted in such a way as to exclude Data Subjects in Switzerland from the possibility of suing for their rights in Switzerland in accordance with EU SCC Clause 18(c). The EU SCCs as outlined in Section 6.2 shall also protect the data of Switzerland legal entities until the entry into force of the 25 September 2020 revised version of the Federal Act on Data Protection (revised FADP).
7. AUDITS. Upon request from Customer, Paradigm shall make available to Customer information reasonably necessary to demonstrate compliance with the obligations set forth in this DPA and Data Protection Laws. In instances where the provided documentation is not reasonably sufficient to demonstrate Paradigm’s compliance with this DPA, Paradigm will allow, upon reasonable notice, for inspections to be conducted by the Customer to assess compliance with the DPA. Audits and inspections shall be conducted only during Paradigm’s normal business hours and not more than once every 12 months and shall take place in a manner that minimizes burdens on Paradigm’s business. If an audit finds material non-compliance under this DPA, Paradigm shall take all reasonable steps to promptly remedy any breach or provide a detailed report as to why such breach cannot be remedied. All information provided during such review will be deemed Paradigm’s Confidential Information and shall be protected by the auditor in accordance with the confidentiality provisions as outlined in the Agreement.
8. OBLIGATIONS POST-TERMINATION. Termination or expiration of this DPA shall not discharge the Parties from their obligations that by their nature may reasonably be deemed to survive the termination or expiration of this DPA.
9. LIMITATION OF LIABILITY. Each Party’s liability in the aggregate arising out of or related to this DPA (including the SCCs) shall be subject to the limitations of liability set forth in the Agreement.
10. SEVERABILITY. Any provision of this DPA that is prohibited or unenforceable in any jurisdiction shall, as to such jurisdiction, be ineffective to the extent of such prohibition or unenforceability without invalidating the remaining provisions hereof, and any such prohibition or unenforceability in any jurisdiction shall not invalidate or render unenforceable such provision in any other jurisdiction. The Parties will attempt in good faith to agree upon a valid and enforceable provision that is a reasonable substitute and shall incorporate such substitute provision into this DPA and Agreement.
List of Schedules:
Schedule 1: Details of Processing
Schedule 2: EU Standard Contractual Clauses – Module Two Controller to Processor
Schedule 3: UK Standard Contractual Clauses – UK Addendum to the EU Standard Contractual Clauses
SCHEDULE 1 DETAILS OF PROCESSING
The details of the processing as contemplated by the Agreement and the DPA are as follows:
Categories of data subjects whose personal data is transferred: Paradigm will only Process the Personal Data that is strictly necessary for it to provide its Services in accordance with the Agreement. All categories of Data Subjects whose Personal Data is Processed by Paradigm in providing the Services under the Agreement may include: customer’s employees.
Categories of personal data transferred: Customer will only transfer categories of Personal Data to Paradigm which are strictly necessary for Paradigm to provide its Services in accordance with the Agreement. This may entail Processing one or more of the following categories of categories of Personal Data: Personal details, which may include information that identifies the data subject and their personal characteristics, including: name, address, gender, education, employment information, demographic information, contact details such as email address, and company name.
Sensitive data transferred (if applicable): Customer Data may also include special categories of data such as information revealing racial or ethnic origins, political opinions, religious or philosophical beliefs, trade-union membership, sexual orientation or sex life, and health data.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis): Continuous basis for the Agreement.
Nature of the processing: The Personal Data transferred will be subject to the following basic processing activities (please specify): receiving data, including collection, accessing, retrieval, recording, and data entry; and using data, including analysing for purposes of providing the Services.
Purpose(s) of the data transfer and further processing: Paradigm will Process the Personal Data on Customer’s instructions, for the purposes of providing the Service that are described in the Agreement.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: The Personal Data will be retained for the period required under the Service Agreement, and as required under the applicable law.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: See Subprocessors list in Section 5.1 of the DPA.
Safeguards for Sensitive Personal Data:
For special categories of personal data processed by Paradigm (as described in Article 9 GDPR and similar regulations; see above), Paradigm will implement in addition to the general measures outlined in Section 4.8 of the DPA and Annex II of the SCCs, the following specific safeguards:
All sensitive data will be encrypted at rest and in transit using industry standard protocols (AES-256/GCM, TLS 1.3+).
Access to sensitive data is strictly limited to employees with a documented business need, subject to approval and audit, and access rights are reviewed at minimum quarterly.
Pseudonymization/anonymization will be applied where technically feasible; in particular, survey data and analytics fields will be anonymized before processing or stored in a manner which prevents attribution to an identifiable individual outside administrative access.
All access to sensitive data will be logged and subject to audit.
Sensitive fields will be subject to a data minimization principle: only such data strictly necessary for the provision of the Services will be processed.
Security awareness and privacy training includes emphasis on handling of sensitive categories of data.
SCHEDULE 2
STANDARD CONTRACTUAL CLAUSES: CONTROLLER TO PROCESSOR
The Parties hereby agree that they will comply with the EU Standard Contractual Clauses: Module 2, which are incorporated herein by reference, a copy of which can be found at https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc/standard-contractual-clauses-international-transfers_en. The Parties agree that the following terms apply:
Clause 7: The Parties have chosen to include Clause 7.
Clause 9(a): The data importer has the data exporter’s general authorisation for the engagement of sub-processor(s) from an agreed list. The data importer shall specifically inform the data exporter in writing of any intended changes to that list through the addition or replacement of sub- processors at least sixty (60) days in advance, thereby giving the data exporter sufficient time to be able to object to such changes prior to the engagement of the sub-processor(s). The data importer shall provide the data exporter with the information necessary to enable the data exporter to exercise its right to object.
Clause 11(a): The Parties do not incorporate the optional language allowing a data subject to lodge a complaint with an independent dispute resolution body at no cost to the data subject.
Clause 13(a): The supervisory authority of one of the Member States in which the data subjects whose personal data is transferred under these Clauses in relation to the offering of goods or services to them, or whose behaviour is monitored, are located, as indicated in Annex I.C, shall act as competent supervisory authority.
Clause 17: These Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third-party beneficiary rights. The Parties agree that this shall be the law of (Ireland).
Clause 18(b): The Parties agree that those shall be the courts of Ireland.
ANNEX I to EU Standard Contractual Clauses – Module Two Controller to Processor
LIST OF PARTIES:
Data exporter(s):
Name: Company that has signed up and agreed to receive the Services.
Address: See applicable Agreement.
Contact person’s name, position and contact details: See applicable Agreement.
Role (controller/processor): CONTROLLER
Activities relevant to the data transferred under these Clauses: Controller will transfer the personal data for Processor to provide the Services.
Data importer(s):
Name: Paradigm Strategy Inc.
Address: 3000 El Camino Real, STE 4-200, Palo Alto, CA 94306, US
Contact person’s name, position and contact details: Aimy Ngo, Chief Operating Officer, privacy@paradigmiq.com.
Role (controller/processor): PROCESSOR
Activities relevant to the data transferred under these Clauses: Paradigm will process the personal data to provide the Services.
DESCRIPTION OF TRANSFER: Refer to Section 2 of the DPA and Schedule 1 of this DPA.
COMPETENT SUPERVISORY AUTHORITY: Irish Data Protection Authority
ANNEX II to EU Standard Contractual Clauses – Module Two Controller to Processor
Technical and Organisational Measures: A description of the technical and organisational measures implemented by the data importer(s) is set forth in Section 4.8 of the DPA.
SCHEDULE 3
UK STANDARD CONTRACTUAL CLAUSES – UK ADDENDUM TO THE EU STANDARD CONTRACTUAL CLAUSES
This Addendum has been issued by the Information Commissioner (“ICO”) for Parties making Restricted Transfers. The ICO considers that it provides Appropriate Safeguards for Restricted Transfers when it is entered into as a legally binding contract.
PART 1: TABLES
Table 1: Parties
Start date: The date of the Agreement to which this Addendum is attached (“DPA”)
The Parties: Exporter (who sends the Restricted Transfer) Importer (who receives the Restricted Transfer)
Parties’ details: As set out in Annex I.A to EU Standard Contractual Clauses As set out in Annex I.A to EU Standard Contractual Clauses
Table 2: Selected SCCs, Modules and Selected Clauses
☐ The version of the Approved EU SCCs which this Addendum is appended to, detailed below, including the Appendix Information.
Addendum EU SCCs: ☒ The Standard Contractual Clauses as defined in the DPA.
Table 3: Appendix Information
“Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in:
Annex 1A:: List of Parties: As set out in the DPA
Annex 1B:: Description of Transfer: As set out in Annex 1B of the Addendum EU SCCs
Annex II:: Technical and organisational measures including technical and organisational measures to ensure the security of the data: As set out in Annex II of the Addendum EU SCCs
Annex III:: List of Subprocessors (Modules 2 and 3 only): As set out in Section 5.1 of the DPA
Table 4: Ending this Addendum when the Approved Addendum Changes
Which Parties may end this Addendum as set out in Section 19:
☒ Importer
☒ Exporter
Ending this Addendum when the Approved Addendum changes: ☐ neither Party
PART 2: MANDATORY CLAUSES
Mandatory Clauses: The Parties agree to incorporate and adhere to the Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022.