Data Processing Addendum

(GDPR / UK GDPR / Swiss FADP / U.S. State Privacy Law Addendum)

Effective: July 1, 2026

This Data Processing Addendum, including its exhibits and appendices (the “Addendum” or “DPA“), is entered into between OAD, LLC, operating as OAD (“OAD,” “we,” “us,” or “Processor“), with a registered address at N24 W30953 Fairway Court, Pewaukee, WI 53072, USA, and the entity or individual accepting OAD’s Platform Terms of Service (the “Client,” “you,” or “Controller“) (each a “Party” and together the “Parties“).

This Addendum is incorporated by reference into, and forms an integral part of, OAD’s Platform Terms of Service (the “Platform Terms“), which govern Client’s subscription to and use of the OAD behavioral assessment platform and related services (the “Platform“). This Addendum takes effect automatically upon Client’s acceptance of the Platform Terms, without further action by either Party, and continues for as long as OAD Processes Personal Data on Client’s behalf.

Where there is a conflict between this Addendum and the Platform Terms, this Addendum will prevail, except with respect to the Disclaimer and Limitation of Liability provisions of the Platform Terms, which will prevail. Where there is a conflict between this Addendum and the Standard Contractual Clauses (“SCCs“) incorporated in Exhibit B, the SCCs shall prevail. This Addendum is intended to operate consistently with, and should be read alongside, OAD’s Acceptable Use PolicyAnti-Spam Policy, and Cookie Notice (together with this Addendum and the Privacy Notice, the “Related Policies“), each of which is incorporated into the Platform Terms and cross-referenced where relevant below.

1. DEFINITIONS

For the purposes of interpreting this Addendum, the following terms (and their cognates) have the meanings set out below:

  • “Admin User” means an employee or independent contractor of Client who is permitted to access or use Client’s Account and/or the Platform on Client’s behalf and for Client’s benefit.
  • “Applicable Data Protection Laws” means all laws and regulations applicable to the Processing of Personal Data under this Addendum, including but not limited to those identified in Exhibit B.
  • “Contact” means any person Client may contact through the Platform, or about whom Client has provided information to OAD, including individuals on Client’s distribution lists.
  • “Data Exporter” and “Data Importer” have the meanings assigned in Part A of Exhibit A.
  • “GDPR” means the EU GDPR and the UK GDPR, as defined in Exhibit B, as applicable.
  • “Personal Data” means any information relating to an identified or identifiable natural person that OAD Processes on behalf of Client in connection with the Platform, including Personal Data of Client’s Admin Users, Survey Subjects, and Contacts. Personal Data does not include Client’s own Account registration and billing information, which OAD Processes as an independent Controller under the OAD Privacy Notice.
  • “Restricted Transfer” means a transfer of Personal Data protected by Applicable Data Protection Laws to a Third Country or an international organization in a Third Country (including storage on servers located abroad).
  • “SCCs” / “Standard Contractual Clauses” means the model clauses for Restricted Transfers adopted from time to time by the relevant authorities identified in Exhibit B, to the extent approved as an appropriate safeguard for Restricted Transfers.
  • “Sub-Processor” means a third party engaged by OAD to Process Personal Data in connection with the Platform, including hosting, infrastructure, and communications providers.
  • “Survey Subject” means an individual invited to complete a behavioral or personality assessment through the Platform at Client’s direction, and about whom OAD generates an assessment report on Client’s behalf.

The terms “Controller,” “Data Protection Assessment,” “Data Subject,” “Member State,” “Personal Data Breach,” “Processing,” “Processor,” “Rights of the Data Subject,” “Supervisory Authority,” and “Third Country” have the meanings given under Applicable Data Protection Laws, and cognate terms shall be construed accordingly. Capitalized terms not defined herein have the meaning given in the Platform Terms.

2. SCOPE AND APPLICABILITY

  • Duration. This Addendum takes effect on the date Client accepts the Platform Terms and continues for as long as OAD Processes Personal Data under the Platform Terms.
  • Scope. This Addendum applies to all Processing of Personal Data of Client’s Admin Users, Survey Subjects, and Contacts, regardless of country of origin, place of Processing, or location of the Data Subjects. It does not apply to OAD’s processing of Client’s own Account and billing data, which is governed by the OAD Privacy Notice.
  • Exhibits. This Addendum includes: Exhibit A (Details of Processing); Appendix I to Exhibit A (Technical and Organizational Security Measures); Exhibit B (Jurisdiction Specific Terms); and Appendix I to Exhibit B (Supplemental Clauses to the SCCs).

3. PROCESSING OF PERSONAL DATA

AD will act as a Processor (or, where Client is itself a processor of the relevant Personal Data, as a Sub-Processor) of Personal Data Processed in connection with the Platform. Client will act as the Controller (or processor) of that Personal Data, including with respect to its Survey Subjects and Contacts.

OAD shall:

  1. Comply with all Applicable Data Protection Laws in its Processing of Personal Data;
  2. Not Process Personal Data other than on Client’s documented instructions — including to provide, secure, and improve the Platform (which instructions include authorization to generate assessment reports, and anonymize or aggregate Personal Data as described in Section 3B) — unless required to do otherwise by Applicable Data Protection Laws; and
  3. Promptly inform Client if, in OAD’s reasonable opinion, an instruction from Client infringes Applicable Data Protection Laws. OAD shall not be required to act on such instruction unless and until the matter has been resolved by agreement of the Parties.

Full details of the Processing are set out in Exhibit A. Client instructs OAD (and authorizes OAD to instruct each Sub-Processor) to Process, and where necessary transfer, Personal Data only as reasonably necessary to provide the Platform and consistent with the Platform Terms and this Addendum.

Compliance and Safety Review. Client’s instructions under this Section 3 include authorization for OAD to access, review, and, where necessary, remove or restrict Content (including Personal Data) to the extent reasonably necessary for OAD to enforce its Acceptable Use Policy and Anti-Spam Policy, investigate a reported violation, or otherwise comply with its legal obligations, consistent with Section “OAD’s Rights” of the Acceptable Use Policy. This authorization does not expand OAD’s role beyond that of a Processor and does not permit OAD to use Personal Data for any independent purpose of its own.

OAD does not knowingly collect or Process protected health information subject to HIPAA through the Platform. Client shall not submit any such information to the Platform, and OAD’s obligations under this Addendum do not extend to HIPAA-regulated data. Consistent with OAD’s Acceptable Use Policy, Client shall also not submit government identification numbers, payment card numbers, account passwords, or other sensitive identifiers as Content unless Client has obtained the consent required to do so and such data is reasonably necessary to provide the Platform.

Automated Decision-Making. The Platform generates behavioral and personality assessment outputs that Client may use as one input into its own decisions concerning Survey Subjects. OAD does not itself make, and the Platform is not designed to make, any decision producing legal or similarly significant effects concerning a Survey Subject, including any hiring, promotion, or other employment decision. As between the Parties, Client is solely responsible for: (i) determining whether and how to use assessment outputs in any decision concerning a Survey Subject; (ii) ensuring that no such decision is based solely on automated Processing where prohibited by Applicable Data Protection Laws; (iii) implementing any human review, meaningful oversight, or safeguards required under Applicable Data Protection Laws; and (iv) providing Survey Subjects with the information and rights required under Article 22 of the GDPR and equivalent provisions of Applicable Data Protection Laws, including the right to obtain human intervention, to express their point of view, and to contest a decision. Taking into account the nature of the Processing, OAD will provide Client with reasonably available information regarding the general logic of the assessment methodology to assist Client in meeting its transparency obligations, subject to OAD’s trade secrets and intellectual property rights.

Service Improvement and Model Development.

(a) OAD may use data derived from the Processing to develop, train, test, evaluate, and improve OAD’s assessment methodologies, models, algorithms, and the Platform, provided that such use is limited to Anonymized Data and/or Aggregated Data.

(b) “Anonymized Data” means data that has been irreversibly altered such that no natural person is identifiable, directly or indirectly, by any party using means reasonably likely to be used, and that therefore does not constitute Personal Data. “Aggregated Data” means data combined across multiple Survey Subjects and/or Clients such that it does not identify, and cannot reasonably be used to identify, any individual, Client, or Survey Subject.

(c) OAD’s creation of Anonymized Data and Aggregated Data from Personal Data is a Processing activity carried out on Client’s documented instructions under Section 3. Once data has been Anonymized in accordance with paragraph (b), it falls outside the scope of Applicable Data Protection Laws and this Addendum, and OAD may retain and use it without limitation for the purposes in paragraph (a).

(d) OAD shall not use Personal Data that has not been Anonymized to develop or train models except where OAD has established a valid legal basis to do so as an independent Controller and the information required under Applicable Data Protection Laws has been provided to the relevant Survey Subjects. Where OAD acts as an independent Controller under this paragraph, it does so under the OAD Privacy Notice and not under this Addendum.

(e) Client may opt out of the use of Aggregated Data derived from its Personal Data for the purposes in paragraph by written notice to privacy@oad.ai. OAD will give effect to such opt-out on a going-forward basis within a reasonable period.

4. PERSONNEL

OAD shall take reasonable steps to ensure:

  • the reliability of any employee, contractor, or agent (each, a member of OAD’s “Team”) who may access Personal Data;
  • that access to Personal Data is limited to Team members who need such access to perform Client’s documented instructions or to comply with Applicable Data Protection Laws; and
  • that all such individuals are bound by written confidentiality obligations.

6. SUB-PROCESSORS

  • Authorization for Existing Sub-Processors. Client authorizes OAD’s continued use of the Sub-Processors engaged as of the Effective Date, including: (i) cloud hosting and infrastructure providers; (ii) email and messaging delivery providers used to send assessment invitations, consistent with the Anti-Spam Policy; (iii) payment processors, including Stripe and PayPal, as referenced in the Acceptable Use Policy, which Process billing and payment-related Personal Data subject to their own applicable terms; and (iv) analytics and advertising-technology partners that place performance and targeting cookies as described in the Cookie Notice, to the extent such partners receive Personal Data of Platform visitors — each as listed at https://oad.ai/sub-processors/ (the “Sub-Processor List”). Client further authorizes OAD to appoint additional Sub-Processors, provided the obligations of this Section 6 are met.
  • Notice of New Sub-Processors. OAD will provide Client with prior written notice (which may take the form of an update to the Sub-Processor List, together with an email or in-app notice) before appointing an additional Sub-Processor, describing the Processing to be undertaken.
  • Objection. Client will be deemed to have consented to a new Sub-Processor if no objection is received within thirty (30) days of notice. Client may object in writing, stating the name of the Sub-Processor and a reasonable basis for objection. If the Parties cannot reach a mutually agreeable resolution, Client may terminate the Platform Terms upon written notice, with no further Fees due other than those already accrued, and OAD shall cease Processing the affected Personal Data.
  • Flow-Down Obligations. With respect to each Sub-Processor, OAD shall (i) restrict the Sub-Processor’s access to Personal Data to what is necessary to provide the relevant part of the Platform, and (ii) impose data protection terms on the Sub-Processor that offer materially the same level of protection as this Addendum. Where a Sub-Processor is a payment processor such as Stripe or PayPal, Client’s and Survey Subjects’ use of that processor’s services is additionally subject to that processor’s own acceptable use and privacy terms, as flagged in the Acceptable Use Policy.
  • Liability for Sub-Processors. Where a Sub-Processor fails to fulfil its data protection obligations, OAD remains fully liable to Client for the performance of that Sub-Processor’s obligations, subject to the limitations of liability in the Platform Terms.

7. RIGHTS OF THE DATA SUBJECTS

Taking into account the nature of the Processing, OAD shall assist Client, through appropriate technical and organizational measures insofar as reasonably possible, to respond to valid requests to exercise the Rights of Data Subjects under Applicable Data Protection Laws.

With respect to such requests, OAD shall:

  1. promptly notify Client if it, or any of its Sub-Processors, receives a request directly from a Survey Subject or Contact relating to their Personal Data;
  2. not respond to that request itself, except on Client’s documented instructions or as required by Applicable Data Protection Laws (in which case OAD will inform Client of that legal requirement before responding, to the extent legally permitted); and
  3. promptly comply with Client’s documented instructions regarding a response to such a request.

Notwithstanding the foregoing, if Client is subject to EU Data Protection Law (as defined in Exhibit B), Client acknowledges and agrees that it has given OAD prior written authorization to respond, at OAD’s discretion, directly to any data subject access request OAD receives from a Survey Subject or Contact under EU Data Protection Law, or, alternatively, OAD may direct such individual to Client so that Client can respond to the request.

Objections via unsubscribe. Where a Contact exercises a right to object to processing by unsubscribing from an assessment invitation or other communication, Client remains responsible, consistent with the Anti-Spam Policy, for actively managing and processing that unsubscribe request within ten (10) days of submission (or such shorter period as Applicable Data Protection Laws require) and for updating its own lists accordingly. OAD’s role is limited to providing the unsubscribe mechanism and honoring Client’s resulting instructions within the Platform.

8. PERSONAL DATA BREACHES

  • Breach Response. If OAD discovers, is notified of, or has reason to suspect a Personal Data Breach affecting Personal Data under its or a Sub-Processor’s control, OAD will (i) take prompt measures to contain and stop the unauthorized access, (ii) secure the Personal Data, and (iii) notify Client without undue delay and, in any event, within 72 hours of becoming aware of the suspected Personal Data Breach.
  • Breach Obligations. OAD’s notification shall, to the extent reasonably available, describe: (i) the nature of the Personal Data Breach; (ii) the categories and approximate number of affected Data Subjects and Personal Data records; (iii) the likely consequences of the Personal Data Breach; and (iv) the measures taken or proposed to address it. OAD will supplement the notification as further information becomes available and will reasonably assist Client in meeting its own notification obligations to Supervisory Authorities or Data Subjects.
  • No Admission. A notification or response under this Section is not an acknowledgment of fault or liability by OAD. This Section does not apply to unsuccessful access attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial-of-service attacks, or similar network events.

9. DATA PROTECTION IMPACT ASSESSMENTS

OAD shall provide Client with reasonably available information and assistance to help Client comply with its own obligations to carry out data protection impact assessments and, where required, prior consultations with Supervisory Authorities — limited to Personal Data Processed by OAD and its Sub-Processors, and taking into account the nature of the Processing and information reasonably available to OAD. OAD may charge Client a reasonable fee for such assistance where it is not commercially reasonable to provide it without charge, and will provide an estimate of any applicable fees in advance.

10. DELETION OR RETURN OF PERSONAL DATA

  • OAD shall provide Client with technical means, consistent with how the Platform is provided, to delete Personal Data, subject to any retention required by applicable law.
  • Upon Client’s request following termination of the Platform Terms, OAD shall promptly delete or return all Personal Data (including copies), subject to legally required retention.
  • Default post-termination deletion of Survey Subject Data. Absent an earlier request from Client, and consistent with the Acceptable Use Policy, OAD will delete Survey Subject Personal Data no later than ninety (90) days after termination of Client’s Account. This 90-day period applies specifically to Personal Data of Survey Subjects; other, non-personal Account Content may be retained by OAD for up to twelve (12) months following termination, as described in the Platform Terms, before permanent deletion. Client should export or request any Personal Data it wishes to retain before the applicable deletion period elapses.
  • OAD shall cause its Sub-Processors that received Personal Data to likewise delete or return it, subject to legally required retention.
  • This Section does not apply to Personal Data archived on back-up systems, which will be securely isolated and protected from further Processing except as required by law.

11. AUDIT RIGHTS

OAD shall make available to Client information reasonably necessary to demonstrate compliance with this Addendum and shall allow for and contribute to audits, including remote inspections, conducted by Client or an auditor mandated by Client, of OAD’s Processing of Personal Data. OAD may require reasonable advance notice, may limit the frequency of on-site audits to once per twelve-month period (absent a Personal Data Breach or regulatory requirement), and may charge Client for time expended on any audit at OAD’s then-current professional services rates. Where OAD makes available a current third-party audit report or certification evidencing the implementation and effectiveness of its technical and organizational measures, OAD may satisfy an audit request by providing such report or certification in lieu of an on-site audit, save where an on-site audit is required following a Personal Data Breach or by a Supervisory Authority. OAD may require any auditor mandated by Client to enter into an appropriate confidentiality undertaking before the audit, and may object to an auditor that is a competitor of OAD or is otherwise not suitably independent, in which case Client shall appoint an alternative auditor.

12. JURISDICTION SPECIFIC TERMS

To the extent OAD Processes Personal Data originating from or protected by the Applicable Data Protection Laws of a jurisdiction listed in Exhibit B, the corresponding Jurisdiction Specific Terms apply in addition to this Addendum.

13. RESTRICTED TRANSFERS

  • Restricted Transfers within the scope of this Addendum shall be conducted in accordance with Exhibit B and Applicable Data Protection Laws.
  • If a relevant authority adopts a new version of the SCCs, the Parties are deemed to have agreed to execute that new version, and OAD may update Exhibit A and Exhibit B accordingly.
  • If OAD adopts an alternative lawful transfer mechanism (such as Binding Corporate Rules or a valid adequacy decision) during the term of the Platform Terms, the Parties will rely on that mechanism instead, to the extent it applies.

14. NO SELLING OF PERSONAL DATA

OAD confirms that it does not receive Personal Data as consideration for any part of the Platform. As between Client and OAD, Client retains all rights and interests in Personal Data relating to its Survey Subjects and Contacts as against OAD’s role as Processor. OAD shall not “sell” or “share” such Personal Data as those terms are defined under Applicable Data Protection Laws.

15. AMENDMENT AND ONLINE HOSTING

OAD may host the Sub-Processor List and the content of the exhibits and appendices to this Addendum online in OAD’s Legal and Policy Center and may update them from time to time, provided that prior notice is given to Client. If no objection is received within fourteen (14) days of such notice, Client is deemed to have consented. If Client objects and the Parties cannot reach a mutually agreeable resolution, Client may terminate the Platform Terms upon written notice, with no further Fees due other than those already accrued. Where hosted online, the latest published version of an exhibit or appendix takes precedence over the version reproduced in this Addendum.

16. LIABILITY

Subject to Applicable Data Protection Laws, each Party’s liability under this Addendum is subject to the exclusions and limitations of liability set out in the Platform Terms.

17. GENERAL TERMS

  • Notice. The Parties shall use the Data Protection Contact set out in Part A of Exhibit A for all notices under this Addendum, including notice of a Personal Data Breach and Data Subject rights inquiries.
  • Entire Agreement on Subject Matter. This Addendum supersedes any prior data processing terms between the Parties relating to the subject matter herein.
  • Annual Review. Each Party shall review this Addendum (including Exhibit A) at reasonable intervals, and whenever there is a material change to the Personal Data, purposes of Processing, or risk profile of the Processing.
  • Conflicts. In the event of a conflict between the Platform Terms and this Addendum, this Addendum prevails except as stated in the preamble. In the event of a conflict between the Jurisdiction Specific Terms and any other terms of this Addendum, the Jurisdiction Specific Terms prevail.
  • Severability. If any provision is held invalid or unenforceable, it will be replaced with a valid, enforceable provision that most closely reflects the Parties’ original intent, and the remainder of the Addendum continues in effect.
  • Non-Compliance. If OAD determines it can no longer meet its obligations under this Addendum, Applicable Data Protection Laws, or the SCCs, it shall (i) promptly notify Client and (ii) cease the relevant Processing if requested by Client, or take other reasonable steps to remediate the non-compliance.
  • Disclosure to Supervisory Authorities. Either Party may disclose this Addendum and relevant privacy provisions of the Platform Terms to a Supervisory Authority or other competent regulator upon request.
  • Authority to Sign. A person accepting this Addendum on behalf of a Party represents that they have authority to bind that Party.
  • Related Policies. This Addendum should be read together with OAD’s Acceptable Use Policy, Anti-Spam Policy, and Cookie Notice, each available in OAD’s Legal and Policy Center and incorporated into the Platform Terms. To the extent any of those policies impose a data-handling obligation on OAD or Client that is more specific than a corresponding general provision of this Addendum (for example, the Acceptable Use Policy’s 90-day post-termination deletion commitment referenced in Section 10), the more specific provision controls with respect to that subject matter.

EXHIBIT A — DETAILS OF PROCESSING

A. List of Parties

Details

OAD (Data Importer / Processor)

OAD, LLC, N24 W30953 Fairway Court, Pewaukee, WI 53072, USA

Data Protection Contact — OAD

Privacy Team, privacy@oad.ai

EU Representative

European Data Protection Office (EDPO), Avenue Huart Hamoir 71, 1030 Brussels, Belgium — https://edpo.com/gdpr-data-request/

UK Representative

EDPO UK Ltd, 8 Northumberland Avenue, London WC2N 5BY, United Kingdom — https://edpo.com/uk-gdpr-data-request/

Client (Data Exporter / Controller)

Client’s legal entity name as provided on its OAD Account

Data Protection Contact — Client

The contact details provided by Client in its OAD Account

B. Details of Processing

Details

Subject Matter

Provision of the OAD behavioral assessment Platform under the Platform Terms.

Nature and Purpose

Processing of Personal Data as necessary to administer behavioral and personality assessments, generate assessment reports, manage Client accounts and Admin Users, and provide related coaching, reporting, and support features, in accordance with Client’s instructions.

Duration

For as long as Client maintains an active Account and uses the Platform, plus any post-termination retention period described in Section 10 and the OAD Privacy Notice.

Categories of Data Subjects

Client’s Admin Users and authorized personnel (who must be at least 18 years old under the Platform Terms); Client’s Survey Subjects (e.g., job candidates, employees, or other individuals invited to complete an assessment, who under the Acceptable Use Policy must not be given access to the Platform if under 16 years of age, or any higher minimum age applicable in their jurisdiction); and Client’s Contacts.

Categories of Personal Data

Identifiers such as name, email address, phone number, and job title; employment and professional background information; assessment questionnaire responses and derived behavioral trait scores; assessment reports; and account/usage data. Consistent with the Acceptable Use Policy, Client shall not submit government identification numbers, payment card numbers, account passwords, or similarly sensitive identifiers as Personal Data unless it has obtained the necessary consent and such data is reasonably necessary to provide the Platform.

Special Categories of Personal Data

OAD’s assessments are designed to measure workplace behavioral traits and are not intended to elicit health, medical, or psychotherapeutic information. The Parties do not anticipate the Processing of special category data. Client shall not submit special category data (e.g., health, biometric, or genetic data, or data revealing racial/ethnic origin, religious belief, sexual orientation, or trade union membership) into the Platform unless it has first notified OAD in writing and the Parties have agreed on appropriate additional safeguards. OAD is not a clinical, medical, or psychotherapy service provider. Where a Survey Subject is under 18, Client is responsible for ensuring any additional protections required for minors’ data under Applicable Data Protection Laws (for example, parental or guardian consent where required) have been obtained before submitting that Survey Subject’s Personal Data to the Platform.

Frequency of Transfer

Continuous, for as long as Client uses the Platform.

Sub-Processors

As set out in Section 6 and the Sub-Processor List.

APPENDIX I TO EXHIBIT A — TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

Throughout the term of the Platform Terms, OAD shall implement and maintain at least the following (or superior) technical and organizational measures (“TOMs”) to safeguard Personal Data.

Catgegory

Measures

Encryption

Personal Data is encrypted in transit and at rest using industry-standard encryption protocols.

Access Control

Role-based access controls (RBAC) restricting Personal Data access to Team members who need it to perform their job function; support for multi-factor authentication (MFA) on Client Accounts, which OAD recommends and may require for certain features.

Authentication

For as long as Client maintains an active Account and uses the Platform, plus any post-termination retention period described in Section 10 and the OAD Privacy Notice.

Categories of Data Subjects

Password-protected accounts; MFA available and, where required by OAD, enforced for Account or feature access.

Monitoring

Active monitoring of information systems and shared information to detect and respond to anomalous or unauthorized activity.

Transmission Security

HTTPS/TLS encryption for data transmitted to and from the Platform.

Storage Security

Encryption at rest for stored Personal Data on OAD’s hosting infrastructure.

Confidentiality

Written confidentiality obligations for all Team members and contractors with access to Personal Data.

Data Minimization

Collection limited to fields necessary to administer assessments and operate the Platform.

Backup & Resilience

Regular backups of Platform data to support recovery in the event of a technical incident, consistent with Client’s own obligation to maintain independent backups of its Content.

Incident Response

Documented internal process for identifying, containing, and notifying Client of a Personal Data Breach within the timeframe specified in Section 8.

Governance

Internal accountability for data protection and security compliance, including periodic review of this Addendum and its appendices.

Sub-Processor Oversight

Contractual flow-down of equivalent security obligations to Sub-Processors, as described in Section 6.

EXHIBIT B — JURISDICTION SPECIFIC TERMS

1. European Economic Area

  • “EEA” means the European Economic Area, consisting of the EU Member States, Iceland, Liechtenstein, and Norway.
  • “EEA Data Protection Laws” means the EU GDPR and all applicable EU/EEA laws and regulations governing the Processing of Personal Data.
  • “EU GDPR” means Regulation (EU) 2016/679, as amended from time to time.

Restricted Transfers
With regard to any Restricted Transfer subject to EEA Data Protection Laws, the following mechanisms apply in order of precedence: (i) a valid adequacy decision under Article 45 GDPR; (ii) the appropriate Standard Contractual Clauses adopted by the European Commission from time to time; or (iii) any other lawful transfer mechanism recognized under EEA Data Protection Laws.

Standard Contractual Clauses
This Addendum incorporates by reference the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (“EU 2021 SCCs”). The Parties are deemed to have executed the EU 2021 SCCs in their entirety, including the annexures, with the following selections:

  • Module: Module Two (Controller-to-Processor) applies where Client is the Controller; Module Three (Processor-to-Sub-Processor) applies where Client is itself a processor.
  • Clause 7 (Docking Clause): Included.
  • Clause 9 (Sub-Processors): Option 2, General Written Authorization, with the 30-day objection period set out in Section 6 of this Addendum.
  • Clause 11: The optional independent dispute resolution body language is not included.
  • Clause 13 / Annex I.C: The competent Supervisory Authority is determined in accordance with GDPR Article 51 based on Client’s establishment or main place of business in the EEA.
  • Clause 17: Governed by the laws of Ireland.
  • Clause 18: Disputes resolved by the courts of Ireland.
  • Annex I(A) and (B): As set out in Exhibit A.
  • Annex II: As set out in Appendix I to Exhibit A.

The terms in Appendix I to Exhibit B supplement the SCCs. Where the SCCs conflict with this Addendum, the SCCs prevail as to the Restricted Transfer in question.

EU Representative
OAD has appointed the European Data Protection Office (EDPO) as its representative in the EEA pursuant to Article 27 of the GDPR. EDPO may be contacted regarding GDPR matters via the online request form at https://edpo.com/gdpr-data-request/, or by writing to EDPO at Avenue Huart Hamoir 71, 1030 Brussels, Belgium.

2. United Kingdom
“UK Data Protection Laws” means the UK Data Protection Act 2018 and the UK GDPR. With regard to any Restricted Transfer subject to UK Data Protection Laws, the following mechanisms apply in order of precedence: (i) a valid adequacy decision under Article 45 of the UK GDPR; (ii) the UK International Data Transfer Addendum to the EU 2021 SCCs, as issued under Section 119A of the Data Protection Act 2018; or (iii) any other lawful transfer mechanism under UK Data Protection Laws.

This Addendum incorporates by reference the EU 2021 SCCs together with the UK Transfer Addendum, populated using Exhibit A and Appendix I to Exhibit A, with the UK Information Commissioner’s Office as the competent authority, and governed by the laws of England and Wales.

UK Representative
OAD has appointed EDPO UK Ltd as its representative in the United Kingdom pursuant to the Data Protection Act 2018. EDPO UK may be contacted via the online request form at https://edpo.com/uk-gdpr-data-request/, or by writing to EDPO UK at 8 Northumberland Avenue, London WC2N 5BY, United Kingdom.

3. Switzerland
“Swiss Data Protection Laws” means the Federal Act on Data Protection (FADP) and its implementing ordinance. With regard to any Restricted Transfer subject to Swiss Data Protection Laws, the following mechanisms apply in order of precedence: (i) a valid adequacy decision of the Swiss Federal Data Protection and Information Commissioner (“FDPIC”); (ii) the EU 2021 SCCs as adapted for Switzerland by the FDPIC; or (iii) any other lawful transfer mechanism. Where the EU 2021 SCCs apply, the FDPIC is the competent authority, and the SCCs are governed by the laws of Switzerland, subject to the FDPIC’s required modifications.

4. United States
“United States Data Protection Laws” means applicable U.S. state privacy laws, including but not limited to the California Consumer Privacy Act (as amended by the CPRA), and comparable laws of other states as enacted or amended from time to time.

  • Client discloses Personal Data to OAD solely for valid business purposes and to enable OAD to perform the Platform.
  • OAD does not sell Personal Data. To the extent United States Data Protection Laws define “sale” or “share” broadly (for example, in connection with online analytics or advertising technologies), OAD’s practices are described in the OAD Privacy Notice, together with instructions for opting out.
  • OAD shall not retain, use, or disclose Personal Data except to provide the Platform or as otherwise permitted by United States Data Protection Laws, and shall not combine Personal Data with data OAD processes on behalf of other Clients, except as permitted by law.
  • Upon termination of the Platform Terms, OAD shall, as soon as reasonably practicable, delete or return all Personal Data it Processed on Client’s behalf, unless applicable law requires or permits continued storage, consistent with Section 10.

APPENDIX I TO EXHIBIT B — SUPPLEMENTAL CLAUSES TO THE STANDARD CONTRACTUAL CLAUSES

This Appendix provides additional safeguards and redress mechanisms for Data Subjects whose Personal Data is transferred under the SCCs. It supplements, and does not modify, the SCCs applicable to a given Restricted Transfer.

1. Applicability of Surveillance Laws

  • OAD represents that, as of the Effective Date, it has not received any national security order of the type described in the Schrems II judgment (Case C-311/18).
  • OAD will notify Client if it becomes subject to a legally binding request from a public authority for disclosure of Personal Data, unless prohibited by law from doing so, and will challenge such requests where it has reasonable grounds to consider them unlawful.

2. No Backdoors
OAD certifies that it has not purposefully created backdoors or similar mechanisms that would allow governmental agencies to access Personal Data or its systems, and that it is not required by applicable law or government policy to create or maintain such mechanisms. If this changes, OAD will notify Client, who may terminate the Platform Terms on short notice.

3. Government Access Requests
Where legally required to disclose Personal Data to a public authority, OAD will (i) require an official, signed legal document before considering any request; (ii) scrutinize the request for validity and challenge or narrow overbroad requests; (iii) respond as narrowly as possible; and (iv) notify Client of the request, unless prohibited by law.

4. Termination
This Appendix automatically terminates with respect to a given Restricted Transfer if a competent Supervisory Authority approves an alternative transfer mechanism that does not require these additional safeguards.

SIGNATURE / ACCEPTANCE

This Addendum is accepted electronically by Client upon acceptance of OAD’s Platform Terms of Service (including by clicking “I Agree,” checking an acceptance box, or continuing to use the Platform after notice), and no further signature is required for it to take effect. Clients requiring a manually countersigned copy for internal compliance purposes may request one at support@oad.ai.

OAD

Client

Name

[Authorized Signatory Name]

[Client Authorized Signatory Name]

Title

[Title]

[Title]

Date

Signature