This Data Processing Addendum (“DPA”) forms part of, and is subject to, the Master Subscription Agreement available at https://www.thetestmart.com/master-subscription-agreement or such other written or electronic agreement between the parties that governs Customer’s access to and use of the Services, including the Horizon platform (the “Agreement”), entered into between TheTestMart, Inc. (“TTM,” “we” or “us”) and the customer identified in the Agreement or an applicable Order Form (“Customer” or “you”). TTM and Customer are each a “Party” and together the “Parties.”
This DPA applies to the extent TTM Processes Personal Data on Customer’s behalf in providing the Services and such Processing is subject to Data Protection Laws. It is incorporated into the Agreement by reference. Capitalized terms not defined here have the meanings given in the Agreement. In the event of a conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA controls; in the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses control.
This DPA is effective and binding on the Parties as of the effective date of the Agreement, and no separate signature is required.
1.1 “Data Protection Laws” means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including, as applicable: (a) the EU General Data Protection Regulation 2016/679 (“EU GDPR”); (b) the EU GDPR as incorporated into United Kingdom law by the Data Protection Act 2018 and the European Union (Withdrawal) Act 2018 (“UK GDPR”); (c) the Swiss Federal Act on Data Protection (“FADP”); and (d) U.S. State Privacy Laws (as defined in Schedule 3), in each case as amended or superseded.
1.2 “Customer Personal Data” means Personal Data contained within Customer Data that TTM Processes on Customer’s behalf in providing the Services.
1.3 “Personal Data,” “Processing,” “Controller,” “Processor,” “Data Subject” and “Personal Data Breach” have the meanings given in the EU GDPR, and their equivalents under other Data Protection Laws (for example, “business,” “service provider,” “consumer,” “sell” and “share” under U.S. State Privacy Laws) apply where those laws govern.
1.4 “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of Personal Data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced.
1.5 “Sub-processor” means any third party (including a TTM Affiliate) engaged by TTM to Process Customer Personal Data in providing the Services.
1.6 “Supervisory Authority” means a competent data protection authority or regulator with jurisdiction over a Party’s Processing of Customer Personal Data.
2.1 Roles. As between the Parties and with respect to Customer Personal Data, Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and TTM is the Processor. Where Customer is itself a Processor, Customer warrants that it has the necessary authority and instructions from the relevant Controller to engage TTM on the terms of this DPA. TTM will Process Customer Personal Data as a Processor (and, under U.S. State Privacy Laws, as a service provider or processor).
2.2 Subject matter and details. The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are described in Schedule 1.
2.3 Customer instructions. TTM will Process Customer Personal Data only on Customer’s documented instructions, including as set out in this DPA, the Agreement, the applicable Order Form and the Documentation, and as necessary to provide and secure the Services or comply with applicable law. The Agreement (together with Customer’s configuration and use of the Services) constitutes Customer’s complete and final documented instructions. Additional instructions outside the scope of the Agreement require prior written agreement and may be subject to reasonable fees.
2.4 Lawfulness of instructions. Customer is responsible for the accuracy, quality and legality of Customer Personal Data and for the means by which it acquired that data, and warrants that it has a valid legal basis and all necessary notices, consents and authorizations to Process and provide the Customer Personal Data and to authorize TTM’s Processing under this DPA. TTM will inform Customer if, in its reasonable opinion, an instruction infringes Data Protection Laws (but TTM has no obligation to otherwise monitor Customer’s compliance).
2.5 Compliance with law. If applicable law requires TTM to Process Customer Personal Data other than on Customer’s instructions, TTM will inform Customer of that requirement before Processing unless the law prohibits such notice on important grounds of public interest.
3.1 TTM will treat Customer Personal Data as Customer’s Confidential Information under the Agreement, and will ensure that personnel authorized to Process Customer Personal Data (a) are subject to binding confidentiality obligations, (b) access Customer Personal Data only on a need-to-know basis to provide the Services, and (c) receive appropriate data protection and security training.
4.1 Security measures. Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing as well as the risk to Data Subjects, TTM will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against a Personal Data Breach, as described in Schedule 2 and the TTM Trust and Compliance documentation. TTM may update its measures from time to time provided the overall level of security is not materially reduced.
4.2 Customer responsibilities. Customer is responsible for its own secure use and configuration of the Services, including managing user access and credentials, applying available security features, and determining whether the Services are appropriate for the Customer Personal Data it chooses to Process. Customer will not upload to the Services any special categories of Personal Data or other high-risk data except where expressly agreed in an Order Form and supported by the applicable Service.
5.1 General authorization. Customer provides TTM with a general authorization to engage Sub-processors (including TTM Affiliates and cloud infrastructure providers such as Microsoft Azure) to Process Customer Personal Data in providing the Services. A current list of Sub-processors is set out in Schedule 3 and/or made available to Customer on request.
5.2 Flow-down and liability. TTM will impose on each Sub-processor data protection obligations that are substantially the same as, and no less protective than, those in this DPA, and will remain responsible to Customer for each Sub-processor’s performance of its data protection obligations.
5.3 Notice and objection. TTM will give Customer notice (by updating the Sub-processor list, email, or in-product notice) before authorizing a new Sub-processor to Process Customer Personal Data. Customer may object on reasonable, documented data-protection grounds within fourteen (14) days of the notice. The Parties will work in good faith to resolve the objection. If they cannot, Customer’s sole and exclusive remedy is to terminate the affected Service by written notice and receive a pro-rata refund of any prepaid fees for the terminated portion of the then-current subscription term.
6.1 The Services provide Customer with controls to access, correct, delete, restrict, export and otherwise manage Customer Personal Data so that Customer can respond to requests from Data Subjects to exercise their rights under Data Protection Laws (“Data Subject Requests”). Taking into account the nature of the Processing, TTM will provide reasonable assistance to enable Customer to respond to Data Subject Requests to the extent Customer cannot do so through the Services. If TTM receives a Data Subject Request directly, it will not respond (except to confirm the request relates to Customer or to direct the Data Subject to Customer) and, where legally permitted, will promptly forward the request to Customer.
7.1 Taking into account the nature of the Processing and the information available to TTM, TTM will provide reasonable assistance to Customer with its obligations under Data Protection Laws in relation to security of Processing, data protection impact assessments, prior consultations with Supervisory Authorities, and Personal Data Breach notifications. Assistance that exceeds the functionality of the Services or TTM’s standard documentation may be subject to reasonable fees, notified in advance.
8.1 Notice. TTM will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe, to the extent known and as information becomes available, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it.
8.2 No admission; cooperation. TTM’s notification of or response to a Personal Data Breach is not an acknowledgement of fault or liability. TTM will take reasonable steps to mitigate the effects of the breach and will reasonably cooperate with Customer so that Customer can meet its own notification obligations. Notices will be delivered to the administrative or security contact designated by Customer in the Services or an Order Form.
9.1 General. Customer authorizes TTM and its Sub-processors to transfer and Process Customer Personal Data in the United States and other countries in which TTM or its Sub-processors operate, subject to this Section 9. Where TTM Processes Personal Data protected by the EU GDPR, UK GDPR or FADP and transfers it to a country that has not received an adequacy decision, the transfer mechanisms in this Section 9 apply.
9.2 EU Standard Contractual Clauses. The SCCs are incorporated into this DPA by reference and apply to transfers of Personal Data protected by the EU GDPR to countries not deemed adequate, completed as follows: (a) Module Two (Controller to Processor) applies where Customer is a Controller, and Module Three (Processor to Processor) applies where Customer is a Processor; (b) in Clause 7, the optional docking clause applies; (c) in Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 5.3 of this DPA; (d) in Clause 11, the optional independent dispute-resolution language does not apply; (e) in Clause 17, the SCCs are governed by the law of Ireland; (f) in Clause 18(b), disputes will be resolved before the courts of Ireland; and (g) Annexes I, II and III of the SCCs are populated by Schedules 1, 2 and 3 of this DPA.
9.3 UK transfers. For transfers of Personal Data protected by the UK GDPR, the SCCs apply as modified by the UK International Data Transfer Addendum issued by the Information Commissioner (“UK Addendum”), which is incorporated by reference. Tables 1 to 3 of the UK Addendum are completed with the information in Schedules 1-3 of this DPA; in Table 4, the Importer may end the UK Addendum as permitted by its terms.
9.4 Swiss transfers. For transfers of Personal Data protected by the FADP, the SCCs apply with the following modifications: references to the GDPR are read as references to the FADP; the competent authority is the Swiss Federal Data Protection and Information Commissioner; and the term “member state” does not prevent Data Subjects in Switzerland from exercising rights in their place of habitual residence.
9.5 Alternative mechanisms. TTM may adopt an alternative lawful transfer mechanism (such as an adequacy decision or a certification under an approved data transfer framework, including the EU-U.S. Data Privacy Framework and its UK and Swiss extensions if and when TTM is certified) for some or all transfers, in which case that mechanism applies instead of the SCCs to the transfers it covers.
10.1 Compliance information. TTM will maintain records of its Processing and will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR, primarily through TTM’s then-current third-party audit reports and certifications (for example, SOC 2 and ISO 27001, where available) and responses to reasonable security questionnaires.
10.2 Audits. Where the compliance information in Section 10.1 is not sufficient to demonstrate compliance, or where required by a Supervisory Authority or Data Protection Laws, TTM will allow and contribute to an audit conducted by Customer or a qualified independent auditor mandated by Customer and bound by confidentiality. Such audits will be conducted on at least thirty (30) days’ prior written notice, during business hours, no more than once in any twelve (12) month period (except where a Supervisory Authority or applicable law requires otherwise, or following a Personal Data Breach affecting Customer Personal Data), in a manner that does not disrupt TTM’s operations or compromise the security or confidentiality of other customers’ data, and at Customer’s expense. This Section satisfies the audit and inspection requirements of the SCCs.
11.1 During the subscription term, Customer may access and export Customer Personal Data through the Services. Following expiration or termination of the Agreement, TTM will make Customer Personal Data available for export for the period stated in the Agreement (and, absent a different period, for thirty (30) days), after which TTM will delete or render inaccessible the Customer Personal Data in its possession or control, and instruct its Sub-processors to do the same, except to the extent retention is required by applicable law or for routine backup, in which case the data will remain subject to the protections of this DPA until deleted. TTM will, on request, confirm deletion in writing.
12.1 This Section applies to Customer Personal Data protected by U.S. State Privacy Laws (as defined in Schedule 3). The Parties acknowledge that TTM is a “service provider” or “processor” and Customer is a “business,” “controller” or third-party “processor,” as those terms are used in those laws, and that Customer discloses Customer Personal Data to TTM solely for the limited and specified business purpose of providing the Services under the Agreement.
12.2 Restrictions. TTM will not: (a) sell or share Customer Personal Data; (b) retain, use or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement, including outside the direct business relationship with Customer, except as permitted by U.S. State Privacy Laws; (c) combine Customer Personal Data with Personal Data obtained from other sources, except as permitted by U.S. State Privacy Laws to perform a business purpose; or (d) Process Customer Personal Data outside the scope of the Agreement. TTM certifies that it understands and will comply with these restrictions.
12.3 Assistance. TTM will provide reasonable assistance to enable Customer to comply with consumer-rights requests under U.S. State Privacy Laws and will notify Customer without undue delay if TTM determines it can no longer meet its obligations under those laws. Customer may take reasonable and appropriate steps under U.S. State Privacy Laws to remediate unauthorized Processing.
13.1 Liability. Each Party’s and its Affiliates’ total liability arising out of or related to this DPA and the SCCs, whether in contract, tort or under any other theory, is subject to the exclusions and limitations of liability set out in the Agreement, and any reference to the liability of a Party in this DPA or the SCCs means the aggregate liability of that Party and its Affiliates under the Agreement and all DPAs together.
13.2 Term. This DPA takes effect on the effective date of the Agreement and remains in force until TTM has ceased all Processing of Customer Personal Data. Provisions that by their nature should survive termination will survive.
13.3 Affiliates. Customer enters into this DPA on behalf of itself and, to the extent required under Data Protection Laws, in the name and on behalf of its Affiliates that are permitted to use the Services under the Agreement.
13.4 Changes. TTM may update this DPA from time to time to reflect changes in Data Protection Laws, transfer mechanisms, Sub-processors or the Services, provided that no update will materially reduce the protections for Customer Personal Data. The current version applies to Processing under the then-current Agreement.
13.5 Governing law; precedence. Except where Data Protection Laws or the SCCs require otherwise, this DPA is governed by the law and subject to the venue stated in the Agreement. Except as expressly amended by this DPA, the Agreement remains in full force and effect.
This Schedule completes Annex I of the SCCs and Article 28(3) GDPR.
For EU GDPR transfers, the supervisory authority of Ireland (Data Protection Commission) acts as competent supervisory authority, without prejudice to the identification of a different lead authority under Article 56 GDPR. For UK transfers, the UK Information Commissioner. For Swiss transfers, the Federal Data Protection and Information Commissioner.
TTM maintains the following categories of technical and organizational measures, appropriate to the risk, to protect Customer Personal Data. Current details and certifications are available at https://thetestmart.trustshare.com/home. These measures apply to TTM and, as relevant, to its Sub-processors, including the security controls of the underlying cloud infrastructure (Microsoft Azure).
The current Sub-processor list is maintained by TTM and available to Customer on request or via TTM’s trust site. TTM will update this list when adding or replacing Sub-processors, subject to Section 5.
“U.S. State Privacy Laws” means U.S. state laws relating to the privacy or protection of Personal Data that are applicable to the Processing under the Agreement, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and its regulations, and the comprehensive privacy laws of states including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states, in each case as amended or superseded and once in effect.