Data Processing Addendum (DPA)

This Data Processing Addendum (“DPA”) forms part of, and is subject to, the Master Subscription Agreement available at https://www.thetestmart.com/master-subscription-agreement or such other written or electronic agreement between the parties that governs Customer’s access to and use of the Services, including the Horizon platform (the “Agreement”), entered into between TheTestMart, Inc. (“TTM,” “we” or “us”) and the customer identified in the Agreement or an applicable Order Form (“Customer” or “you”). TTM and Customer are each a “Party” and together the “Parties.”

This DPA applies to the extent TTM Processes Personal Data on Customer’s behalf in providing the Services and such Processing is subject to Data Protection Laws. It is incorporated into the Agreement by reference. Capitalized terms not defined here have the meanings given in the Agreement. In the event of a conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA controls; in the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses control.

This DPA is effective and binding on the Parties as of the effective date of the Agreement, and no separate signature is required.

1.  Definitions

1.1 “Data Protection Laws” means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including, as applicable: (a) the EU General Data Protection Regulation 2016/679 (“EU GDPR”); (b) the EU GDPR as incorporated into United Kingdom law by the Data Protection Act 2018 and the European Union (Withdrawal) Act 2018 (“UK GDPR”); (c) the Swiss Federal Act on Data Protection (“FADP”); and (d) U.S. State Privacy Laws (as defined in Schedule 3), in each case as amended or superseded.

1.2 “Customer Personal Data” means Personal Data contained within Customer Data that TTM Processes on Customer’s behalf in providing the Services.

1.3 “Personal Data,” “Processing,” “Controller,” “Processor,” “Data Subject” and “Personal Data Breach” have the meanings given in the EU GDPR, and their equivalents under other Data Protection Laws (for example, “business,” “service provider,” “consumer,” “sell” and “share” under U.S. State Privacy Laws) apply where those laws govern.

1.4 “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of Personal Data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced.

1.5 “Sub-processor” means any third party (including a TTM Affiliate) engaged by TTM to Process Customer Personal Data in providing the Services.

1.6 “Supervisory Authority” means a competent data protection authority or regulator with jurisdiction over a Party’s Processing of Customer Personal Data.

2.  Roles and Scope of Processing

2.1 Roles. As between the Parties and with respect to Customer Personal Data, Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and TTM is the Processor. Where Customer is itself a Processor, Customer warrants that it has the necessary authority and instructions from the relevant Controller to engage TTM on the terms of this DPA. TTM will Process Customer Personal Data as a Processor (and, under U.S. State Privacy Laws, as a service provider or processor).

2.2 Subject matter and details. The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are described in Schedule 1.

2.3 Customer instructions. TTM will Process Customer Personal Data only on Customer’s documented instructions, including as set out in this DPA, the Agreement, the applicable Order Form and the Documentation, and as necessary to provide and secure the Services or comply with applicable law. The Agreement (together with Customer’s configuration and use of the Services) constitutes Customer’s complete and final documented instructions. Additional instructions outside the scope of the Agreement require prior written agreement and may be subject to reasonable fees.

2.4 Lawfulness of instructions. Customer is responsible for the accuracy, quality and legality of Customer Personal Data and for the means by which it acquired that data, and warrants that it has a valid legal basis and all necessary notices, consents and authorizations to Process and provide the Customer Personal Data and to authorize TTM’s Processing under this DPA. TTM will inform Customer if, in its reasonable opinion, an instruction infringes Data Protection Laws (but TTM has no obligation to otherwise monitor Customer’s compliance).

2.5 Compliance with law. If applicable law requires TTM to Process Customer Personal Data other than on Customer’s instructions, TTM will inform Customer of that requirement before Processing unless the law prohibits such notice on important grounds of public interest.

3.  Confidentiality of Processing

3.1 TTM will treat Customer Personal Data as Customer’s Confidential Information under the Agreement, and will ensure that personnel authorized to Process Customer Personal Data (a) are subject to binding confidentiality obligations, (b) access Customer Personal Data only on a need-to-know basis to provide the Services, and (c) receive appropriate data protection and security training.

4.  Security

4.1 Security measures. Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing as well as the risk to Data Subjects, TTM will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against a Personal Data Breach, as described in Schedule 2 and the TTM Trust and Compliance documentation. TTM may update its measures from time to time provided the overall level of security is not materially reduced.

4.2 Customer responsibilities. Customer is responsible for its own secure use and configuration of the Services, including managing user access and credentials, applying available security features, and determining whether the Services are appropriate for the Customer Personal Data it chooses to Process. Customer will not upload to the Services any special categories of Personal Data or other high-risk data except where expressly agreed in an Order Form and supported by the applicable Service.

5.  Sub-processors

5.1 General authorization. Customer provides TTM with a general authorization to engage Sub-processors (including TTM Affiliates and cloud infrastructure providers such as Microsoft Azure) to Process Customer Personal Data in providing the Services. A current list of Sub-processors is set out in Schedule 3 and/or made available to Customer on request.

5.2 Flow-down and liability. TTM will impose on each Sub-processor data protection obligations that are substantially the same as, and no less protective than, those in this DPA, and will remain responsible to Customer for each Sub-processor’s performance of its data protection obligations.

5.3 Notice and objection. TTM will give Customer notice (by updating the Sub-processor list, email, or in-product notice) before authorizing a new Sub-processor to Process Customer Personal Data. Customer may object on reasonable, documented data-protection grounds within fourteen (14) days of the notice. The Parties will work in good faith to resolve the objection. If they cannot, Customer’s sole and exclusive remedy is to terminate the affected Service by written notice and receive a pro-rata refund of any prepaid fees for the terminated portion of the then-current subscription term.

6.  Data Subject Requests

6.1 The Services provide Customer with controls to access, correct, delete, restrict, export and otherwise manage Customer Personal Data so that Customer can respond to requests from Data Subjects to exercise their rights under Data Protection Laws (“Data Subject Requests”). Taking into account the nature of the Processing, TTM will provide reasonable assistance to enable Customer to respond to Data Subject Requests to the extent Customer cannot do so through the Services. If TTM receives a Data Subject Request directly, it will not respond (except to confirm the request relates to Customer or to direct the Data Subject to Customer) and, where legally permitted, will promptly forward the request to Customer.

7.  Assistance, DPIAs and Consultations

7.1 Taking into account the nature of the Processing and the information available to TTM, TTM will provide reasonable assistance to Customer with its obligations under Data Protection Laws in relation to security of Processing, data protection impact assessments, prior consultations with Supervisory Authorities, and Personal Data Breach notifications. Assistance that exceeds the functionality of the Services or TTM’s standard documentation may be subject to reasonable fees, notified in advance.

8.  Personal Data Breach Notification

8.1 Notice. TTM will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe, to the extent known and as information becomes available, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it.

8.2 No admission; cooperation. TTM’s notification of or response to a Personal Data Breach is not an acknowledgement of fault or liability. TTM will take reasonable steps to mitigate the effects of the breach and will reasonably cooperate with Customer so that Customer can meet its own notification obligations. Notices will be delivered to the administrative or security contact designated by Customer in the Services or an Order Form.

9.  International Data Transfers

9.1 General. Customer authorizes TTM and its Sub-processors to transfer and Process Customer Personal Data in the United States and other countries in which TTM or its Sub-processors operate, subject to this Section 9. Where TTM Processes Personal Data protected by the EU GDPR, UK GDPR or FADP and transfers it to a country that has not received an adequacy decision, the transfer mechanisms in this Section 9 apply.

9.2 EU Standard Contractual Clauses. The SCCs are incorporated into this DPA by reference and apply to transfers of Personal Data protected by the EU GDPR to countries not deemed adequate, completed as follows: (a) Module Two (Controller to Processor) applies where Customer is a Controller, and Module Three (Processor to Processor) applies where Customer is a Processor; (b) in Clause 7, the optional docking clause applies; (c) in Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 5.3 of this DPA; (d) in Clause 11, the optional independent dispute-resolution language does not apply; (e) in Clause 17, the SCCs are governed by the law of Ireland; (f) in Clause 18(b), disputes will be resolved before the courts of Ireland; and (g) Annexes I, II and III of the SCCs are populated by Schedules 1, 2 and 3 of this DPA.

9.3 UK transfers. For transfers of Personal Data protected by the UK GDPR, the SCCs apply as modified by the UK International Data Transfer Addendum issued by the Information Commissioner (“UK Addendum”), which is incorporated by reference. Tables 1 to 3 of the UK Addendum are completed with the information in Schedules 1-3 of this DPA; in Table 4, the Importer may end the UK Addendum as permitted by its terms.

9.4 Swiss transfers. For transfers of Personal Data protected by the FADP, the SCCs apply with the following modifications: references to the GDPR are read as references to the FADP; the competent authority is the Swiss Federal Data Protection and Information Commissioner; and the term “member state” does not prevent Data Subjects in Switzerland from exercising rights in their place of habitual residence.

9.5 Alternative mechanisms. TTM may adopt an alternative lawful transfer mechanism (such as an adequacy decision or a certification under an approved data transfer framework, including the EU-U.S. Data Privacy Framework and its UK and Swiss extensions if and when TTM is certified) for some or all transfers, in which case that mechanism applies instead of the SCCs to the transfers it covers.

10.  Records and Audit

10.1 Compliance information. TTM will maintain records of its Processing and will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR, primarily through TTM’s then-current third-party audit reports and certifications (for example, SOC 2 and ISO 27001, where available) and responses to reasonable security questionnaires.

10.2 Audits. Where the compliance information in Section 10.1 is not sufficient to demonstrate compliance, or where required by a Supervisory Authority or Data Protection Laws, TTM will allow and contribute to an audit conducted by Customer or a qualified independent auditor mandated by Customer and bound by confidentiality. Such audits will be conducted on at least thirty (30) days’ prior written notice, during business hours, no more than once in any twelve (12) month period (except where a Supervisory Authority or applicable law requires otherwise, or following a Personal Data Breach affecting Customer Personal Data), in a manner that does not disrupt TTM’s operations or compromise the security or confidentiality of other customers’ data, and at Customer’s expense. This Section satisfies the audit and inspection requirements of the SCCs.

11.  Return and Deletion of Customer Personal Data

11.1 During the subscription term, Customer may access and export Customer Personal Data through the Services. Following expiration or termination of the Agreement, TTM will make Customer Personal Data available for export for the period stated in the Agreement (and, absent a different period, for thirty (30) days), after which TTM will delete or render inaccessible the Customer Personal Data in its possession or control, and instruct its Sub-processors to do the same, except to the extent retention is required by applicable law or for routine backup, in which case the data will remain subject to the protections of this DPA until deleted. TTM will, on request, confirm deletion in writing.

12.  U.S. State Privacy Laws

12.1 This Section applies to Customer Personal Data protected by U.S. State Privacy Laws (as defined in Schedule 3). The Parties acknowledge that TTM is a “service provider” or “processor” and Customer is a “business,” “controller” or third-party “processor,” as those terms are used in those laws, and that Customer discloses Customer Personal Data to TTM solely for the limited and specified business purpose of providing the Services under the Agreement.

12.2 Restrictions. TTM will not: (a) sell or share Customer Personal Data; (b) retain, use or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement, including outside the direct business relationship with Customer, except as permitted by U.S. State Privacy Laws; (c) combine Customer Personal Data with Personal Data obtained from other sources, except as permitted by U.S. State Privacy Laws to perform a business purpose; or (d) Process Customer Personal Data outside the scope of the Agreement. TTM certifies that it understands and will comply with these restrictions.

12.3 Assistance. TTM will provide reasonable assistance to enable Customer to comply with consumer-rights requests under U.S. State Privacy Laws and will notify Customer without undue delay if TTM determines it can no longer meet its obligations under those laws. Customer may take reasonable and appropriate steps under U.S. State Privacy Laws to remediate unauthorized Processing.

13.  Liability, Term and General

13.1 Liability. Each Party’s and its Affiliates’ total liability arising out of or related to this DPA and the SCCs, whether in contract, tort or under any other theory, is subject to the exclusions and limitations of liability set out in the Agreement, and any reference to the liability of a Party in this DPA or the SCCs means the aggregate liability of that Party and its Affiliates under the Agreement and all DPAs together.

13.2 Term. This DPA takes effect on the effective date of the Agreement and remains in force until TTM has ceased all Processing of Customer Personal Data. Provisions that by their nature should survive termination will survive.

13.3 Affiliates. Customer enters into this DPA on behalf of itself and, to the extent required under Data Protection Laws, in the name and on behalf of its Affiliates that are permitted to use the Services under the Agreement.

13.4 Changes. TTM may update this DPA from time to time to reflect changes in Data Protection Laws, transfer mechanisms, Sub-processors or the Services, provided that no update will materially reduce the protections for Customer Personal Data. The current version applies to Processing under the then-current Agreement.

13.5 Governing law; precedence. Except where Data Protection Laws or the SCCs require otherwise, this DPA is governed by the law and subject to the venue stated in the Agreement. Except as expressly amended by this DPA, the Agreement remains in full force and effect.

Schedule 1 - Details of Processing

This Schedule completes Annex I of the SCCs and Article 28(3) GDPR.

A. List of Parties

List of Parties
Data Exporter Customer, as identified in the Agreement or Order Form. Role: Controller (or Processor on behalf of a third-party Controller). Contact: the administrative/privacy contact designated by Customer in the Services or Order Form.
Data Importer TheTestMart, Inc., 2121 Ponce de Leon Blvd., Suite 840, Coral Gables, FL 33134, USA. Role: Processor. Contact: legal@thetestmart.com. Activities: provision of the Horizon automation testing, validation and related SaaS Services.

B. Description of Transfer / Processing

Description of Transfer and Processing
Categories of Data Subjects Customer's employees, contractors, users and administrators; Customer's customers, suppliers and end users; and any other individuals whose Personal Data is contained in Customer Data submitted to the Services (for example, within ERP/Dynamics 365 test datasets).
Categories of Personal Data Identification and contact data (e.g., name, business email, phone, user ID); employment or role data; account and usage data; and any other Personal Data Customer chooses to include in Customer Data. Customer controls the data it submits.
Special categories of data Not required or requested by the Services. Customer should not submit special categories of Personal Data unless expressly agreed in an Order Form; if submitted, additional safeguards apply as described in Schedule 2.
Nature and purpose Hosting, storage and Processing of Customer Data to provide automated software testing, validation, configuration, support and related Services for Customer's ERP and business applications, as described in the Agreement and Documentation.
Frequency of transfer Continuous, for the duration of the subscription term.
Duration / retention For the term of the Agreement plus the post-termination export and deletion periods described in Section 11, subject to legal retention requirements.
Sub-processor transfers As set out in Schedule 3; subject matter, nature and duration as described above.

C. Competent Supervisory Authority

For EU GDPR transfers, the supervisory authority of Ireland (Data Protection Commission) acts as competent supervisory authority, without prejudice to the identification of a different lead authority under Article 56 GDPR. For UK transfers, the UK Information Commissioner. For Swiss transfers, the Federal Data Protection and Information Commissioner.

Schedule 2 - Technical and Organizational Measures

TTM maintains the following categories of technical and organizational measures, appropriate to the risk, to protect Customer Personal Data. Current details and certifications are available at https://thetestmart.trustshare.com/home. These measures apply to TTM and, as relevant, to its Sub-processors, including the security controls of the underlying cloud infrastructure (Microsoft Azure).

Technical and Organizational Measures
Measure Description
Access control Role-based access on least-privilege and need-to-know principles; unique IDs; multi-factor authentication for administrative access; periodic access recertification and prompt revocation on role change or departure.
Encryption Encryption of Customer Personal Data in transit (TLS) and at rest using industry-standard algorithms; managed key management.
Network & infrastructure security Segmented networks, firewalls, and hardened configurations within Microsoft Azure data centers; intrusion detection/prevention and continuous monitoring.
Physical security Customer Personal Data hosted in Microsoft Azure facilities with 24/7 physical access controls, monitoring and environmental safeguards.
Secure development Documented software development lifecycle, change management, code review and vulnerability management, including periodic testing.
Logging & monitoring Audit logging of key events; production monitoring and alerting; incident detection and response procedures.
Resilience Backup, redundancy and disaster-recovery procedures designed to restore availability and access to Customer Personal Data in a timely manner after an incident.
Personnel Confidentiality obligations, background screening where permitted, and regular security and privacy training.
Vendor management Security assessment and contractual data-protection obligations for Sub-processors.
Incident response Documented Personal Data Breach identification, escalation, mitigation and notification procedures.

Schedule 3 - Sub-processors and U.S. State Privacy Laws

A. Approved Sub-processors

Approved Sub-processors
Sub-processor Service Location
Microsoft Corporation (Microsoft Azure) Cloud hosting and infrastructure for the Horizon platform United States / region(s) specified in the Order Form or Documentation
TheTestMart Affiliates Support, engineering and service delivery United States

The current Sub-processor list is maintained by TTM and available to Customer on request or via TTM’s trust site. TTM will update this list when adding or replacing Sub-processors, subject to Section 5.

B. Definition of U.S. State Privacy Laws

“U.S. State Privacy Laws” means U.S. state laws relating to the privacy or protection of Personal Data that are applicable to the Processing under the Agreement, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and its regulations, and the comprehensive privacy laws of states including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states, in each case as amended or superseded and once in effect.