Data Processing Agreement V8.0

 

This Data Processing Agreement (“DPA”) forms an integral part of, and is hereby incorporated into, the Agreement between Lead Forensics (herein “Lead Forensics” or the “Data Processor”) and Customer (herein the “Customer” or “Data Controller”) for the purchase of services from Lead Forensics pursuant to the “Agreement”. Hereinafter jointly referred to as the “Parties”.

 

1. General Terms

1.1 Under the main Agreement between the Parties, “Lead Forensics” may refer to either Lead Forensics Limited or Lead Forensics, Inc.
1.2 This DPA applies to the Services purchased under the Agreement and any additional Services subsequently purchased by the Customer, in each case to the extent the relevant processing is described in the applicable Order Form or Appendix A, B or C.
1.3 This DPA shall supersede and prevail over any prior, concurrent, or related agreements between the Parties concerning the Processing of Personal Data, in the event of any conflict or inconsistency.
1.4 The Parties acknowledge and agree that this DPA constitutes an Embedded Term of the Agreement.
1.5 By signing the Agreement, the Customer accepts this DPA solely on its own behalf. Affiliates, subsidiaries, or any third party authorised by the Customer may access or use the Services, but no such authorisation shall be deemed to bind Lead Forensics to any affiliate, subsidiary, or third party or extend this DPA to any affiliate, subsidiary or third party unless expressly agreed.
1.6 Lead Forensics may generate and use statistics, analytics, benchmarks and other insights derived from the provision of the Services, provided that such information is aggregated and/or de-identified so that it does not identify, and cannot reasonably be used to identify, the Customer, any Data Subject, or any household or device, and provided that such use is permitted by applicable Data Protection Laws.

Definitions

The terms in this DPA shall have the following meanings:
(a) “Agreement” means the Order Form, these Terms, and any documents expressly incorporated by reference into either of them.
(b) “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party, for the purposes of this Agreement.
(c) “Data Controller”, “Data Processor”, “Data Subject”, “Personal Data Breach”, “Personal Data”, and “Processing” shall each have the meanings ascribed to them under the DP Laws.
(d) “Customer Personal Data” shall mean the applicable personal data processed as part of the Services set out in Appendix A, B, C (as applicable).
(e) “DP Laws” means, to the extent applicable to the activities or obligations of the parties relevant to this DPA, all data protection and privacy laws, including: the EU GDPR, UK GDPR, the Data Protection Act 2018, the CCPA/CPRA and other U.S. state privacy laws, PIPEDA, and any related regulations or amendments.
(f) “Lead Forensics Proprietary Data” means all data, information, and materials owned, licensed, sourced, collected, or developed by Lead Forensics independently of the Customer and not provided by or on behalf of the Customer, including, without limitation, business firmographic data, algorithms, templates, software code, and any other proprietary datasets or materials of Lead Forensics. To the extent that IP addresses are used by Lead Forensics solely in a business-to-business context to identify a business or business location as part of Lead Forensics’ proprietary datasets, such data shall form part of Lead Forensics Proprietary Data. For the avoidance of doubt, Lead Forensics Proprietary Data does not constitute Customer Personal Data and is excluded from the scope of this DPA, except to the extent required by applicable Data Protection Laws.
(g) “Services” applies to all products, solutions, platforms, and deliverables provided by Lead Forensics, including any of its parent companies, subsidiaries, affiliates, and any other entities under common ownership or control, regardless of how such Services are branded, delivered, or contracted.
(h) “Sub-Processors” means any third-party processors appointed or engaged by Lead Forensics to process Customer Personal Data in connection with the services.

2. Commencement

2.1 This DPA shall commence on the date on which the Parties executed the Agreement.
2.2 If a subsequent DPA supersedes this version, the original Agreement’s effective date shall remain unchanged, except in the event of termination of the Agreement.

3. Customer Personal Data

3.1 The processing particulars are set out in Appendix A, B, or C (as applicable) of this DPA.
3.2 The duration of the Customer Personal Data processing is continuous and shall continue for the duration of the Services and thereafter as set out in clause 10 and Appendix A, B, or C (as applicable).

4. Obligations of the Parties

4.1 Lead Forensics

4.1.1 Instruction to Process: Lead Forensics shall process Customer Personal Data in accordance with the Customer’s documented instructions, whether specific or general, for the purpose of providing the Services under the Agreement, except to the extent that Lead Forensics is required to process or disclose such Customer Personal Data under applicable DP Laws. In such circumstances, Lead Forensics shall, where legally permissible, promptly notify the Customer of the requirement prior to such processing or disclosure.
4.1.2 Opinion of Non-Compliance: Lead Forensics shall notify the Customer if, in Lead Forensics’ reasonable opinion, an instruction issued by the Customer constitutes or may constitute non-compliance with applicable DP Laws.
4.1.3 Records of Processing Activities: In accordance with DP Laws, Lead Forensics shall maintain records of the processing activities undertaken on behalf of the Customer, including the name and contact details of each Sub-Processor, the categories of Customer Personal Data processed, and details of any transfers of such data outside the UK/EEA along with the applicable safeguards.
4.1.4 Data Subject Access Requests: Lead Forensics will promptly notify the Customer upon becoming aware of any Data Subject request, will not respond without the Customer’s authorisation, and will, considering the nature of the processing, assist the Customer in fulfilling its obligations to address such requests.
4.1.5 Data Protection Impact Assessment (DPIA): Lead Forensics will provide reasonable assistance to the Customer with any Data Protection Impact Assessments required under Articles 35 or 36 of the EU/UK GDPR or equivalent DP Laws, taking into account the nature of the processing.
4.1.6 Demonstrate Compliance: Lead Forensics shall make available to the Customer all information necessary to demonstrate its compliance with this DPA and applicable DP Laws.
4.1.7 Audit rights: Lead Forensics shall make available current third-party audit reports and certifications. On-site audits may be conducted no more than once annually, or more frequently only following a Security Incident or regulator request, on reasonable notice and subject to confidentiality and non-disruption requirements. Any audit shall be limited to the Customer’s Personal Data described in Appendix A, B, or C (as applicable) and restricted to the processing activities under this DPA.

4.2 Customer

4.2.1 The Customer is responsible for ensuring that its use of the Services complies with applicable Data Protection Laws. This includes, where required, providing appropriate privacy notices, identifying and relying on a valid lawful basis, obtaining any necessary consents, and taking any other steps required to enable Lead Forensics to process Personal Data in accordance with this DPA, the Agreement, and the Customer’s documented instructions. The Customer confirms that it has all necessary rights and authority to provide Personal Data to Lead Forensics and that its instructions will not cause Lead Forensics to breach any applicable law or infringe any third-party rights. The Customer is also responsible for determining whether any cookies, identifiers, or similar technologies used through the Services require consent or other user choices under applicable Data Protection Laws, and for implementing any required consent mechanism, notices, or settings before such technologies are deployed.
4.2.2 Where the Customer instructs Lead Forensics to provide the Services in respect of any URL, domain, website or other digital property that the Customer manages or operates on behalf of a third party, the Customer warrants that it is authorised to do so and is solely responsible for ensuring that any processing of Personal Data in connection with that third-party, including its collection, disclosure and transfer to Lead Forensics, complies with Applicable Data Protection Law. The Customer shall ensure that all required privacy notices, transparency information, authorisations, consents, permissions and authorisations are in place, and that its instructions to Lead Forensics are lawful. Lead Forensics may rely on the Customer’s instructions and shall have no obligation to verify the Customer’s authority, or the compliance of the Customer or any third party with Applicable Data Protection Law, except to the extent required in respect of Lead Forensics’ direct obligations as a processor under Applicable Data Protection Law. The Customer shall indemnify and hold harmless Lead Forensics against any losses, liabilities, claims, fines, penalties, costs and expenses arising from a breach of this clause, except to the extent caused by Lead Forensics’ own breach of this DPA or Applicable Data Protection Law.
4.2.3 The Customer remains responsible for assessing how applicable Data Protection Laws apply to its own processing activities and for complying with its obligations under those laws. Lead Forensics is not responsible for any failure by the Customer to comply with applicable Data Protection Laws or this DPA.
4.2.4 The Customer will not knowingly provide Lead Forensics with any special category or otherwise sensitive Personal Data, including health-related data, unless expressly agreed in writing in advance and permitted under applicable Data Protection Laws.

5. International Transfers

5.1 Lead Forensics shall not transfer Customer Personal Data to a country outside the UK or the European Economic Area (EEA) unless it has ensured that such transfer is carried out in compliance with applicable Data Protection Laws. Where Customer Personal Data processed under this DPA is transferred to a Sub-Processor or other recipient outside the UK or EEA, Lead Forensics shall ensure that appropriate safeguards are in place to protect the Customer Personal Data, including, where applicable, the European Commission’s Standard Contractual Clauses, the UK Addendum, or any equivalent transfer mechanism recognised under applicable Data Protection Laws.
5.2 Where the Customer is established in the UK or EEA and contracts with Lead Forensics, Inc., Appendix F shall apply.
5.3 Where Lead Forensics transfers Customer Personal Data to the Customer or its authorised recipient, the parties acknowledge that such transfer shall be assessed in accordance with applicable Data Protection Laws and, where that transfer is not regarded as a restricted transfer, no additional transfer mechanism shall be required.

6. Security of Processing

6.1 Technical and Organisational Measures are defined in Appendix D.
6.2 ISO 27001 Certification and ISMS

6.2.1 Lead Forensics maintains ISO 27001 certification.
6.2.2 Lead Forensics maintains an Information Security Management System (ISMS) designed to protect the confidentiality, integrity, and availability of Customer Personal Data and other sensitive information.

6.3 Access and Confidentiality

6.3.1 Lead Forensics shall ensure that all employees and other persons acting under its authority who have access to, or otherwise process, Personal Data on behalf of the Customer: (a) are granted access to such Personal Data on a need-to-know basis and only to the extent necessary for the performance of their duties; (b) are bound by appropriate contractual or statutory obligations of confidentiality with respect to such Personal Data; (c) receive appropriate and up-to-date training and awareness; and (d) Statutory background checks will be conducted for all prospective employees. Enhanced screening is carried out if appropriate to the role.

6.4 Personal Data Breach

6.4.1 Lead Forensics shall maintain and operate an incident management process in accordance with its Information Security Management System (ISMS). This process shall enable the timely identification, reporting, assessment, escalation, containment, and resolution of any Personal Data Breach affecting Customer Personal Data.
6.4.2 Lead Forensics shall notify using the email address of the Authorised Individual specified in the Agreement, or any updated contact details that the Customer has provided via https://www.leadforensics.com/dpa-update-notification/.
6.4.3 Lead Forensics shall notify the Customer without undue delay and, where feasible, within 48 hours of becoming aware. The notification shall include all relevant information available at the time, including (a) a description of the nature of the breach; (b) the categories and approximate number of Data Subjects and records affected, if known; (c) the likely consequences; and (d) the measures taken or proposed to address and mitigate the breach.
6.4.4 In accordance with its ISMS, Lead Forensics shall take prompt action to contain and remediate the breach, undertake root cause analysis, implement corrective actions, and prevent recurrence. Lead Forensics shall maintain incident records and provide the Customer with updates as additional information becomes available.
6.4.5 Lead Forensics shall not notify any Supervisory Authority, regulator, or third party of a Personal Data Breach except where required to do so by applicable law. It shall not make any such notification without first informing the Customer, unless prohibited by law.
6.4.6 Lead Forensics shall cooperate fully with the Customer in meeting the Customer’s obligations under applicable DP Laws, including risk assessments and notifications to Supervisory Authorities or affected Data Subjects.

7. Sub-Processors

7.1 The Customer hereby provides general written authorisation for Lead Forensics to engage Sub-Processors listed in Appendix E and to appoint replacement or additional Sub-Processors in accordance with this Clause 7.
7.1.1 Lead Forensics shall provide prior notice of any new or replacement Sub-Processor by updating the Sub-Processor list at https://www.leadforensics.com/sub-processors/ and, where the Customer has provided a designated notification email address, by sending notice to that address. The Customer may object on reasonable data protection grounds within fourteen (14) business days of such notice.
7.1.2 The parties shall work in good faith to resolve any such objection. If the Customer does not object within the fourteen (14) business-day period, the Customer shall be deemed to have approved the relevant new or replacement Sub-Processor.
7.2 If, within a reasonable cure period of no more than thirty (30) days, Lead Forensics is unable either to revert to the original Sub-Processors or to cure the material processing issue, Customer may, upon written notice and without penalty, terminate the affected Services or this DPA to the extent affected, unless the replacement Sub-Processor does not materially adversely impact the Services provided to Customer.
7.3 When Lead Forensics engages a Sub-Processor to process Personal Data, Lead Forensics will:
7.3.1 remain liable to the Customer for the performance of the Sub-Processor in accordance with this DPA.
7.3.2 have a contract with the Sub-Processor that imposes data protection obligations on the Sub-Processor that are no less protective than those set out in this DPA, to the extent applicable to the services performed by that Sub-Processor.

8. Notification

8.1 The Customer is responsible for ensuring the correct contact for DPA notifications is provided by updating this link https://www.leadforensics.com/dpa-update-notification/.
8.2 Lead Forensics may amend this DPA from time to time only where reasonably necessary to reflect changes in applicable law, regulatory guidance, security practices, or the Services, provided that such amendment does not materially reduce the protection afforded to Customer Personal Data. Lead Forensics shall provide prior written notice of any material amendment, and where Customer reasonably objects on data protection grounds, the parties shall work in good faith to resolve the objection.

9. Termination

9.1 The Customer is responsible for removing the Lead Forensics code from its website.
9.2 To the extent the Customer has procured or obtained contact data through or in connection with the Services and has not contacted the relevant data subjects using that contact data before termination or expiry of the Agreement, the Customer shall, on termination or expiry of the Agreement, promptly and securely delete or irreversibly anonymise such contact data, save to the extent its retention is required by Applicable Data Protection Law. The Customer shall be solely responsible for ensuring compliance with this clause and all Applicable Data Protection Laws in relation to such contact data.
9.3 This DPA shall remain in effect until the earlier of: (a) the deletion or return of Customer Personal Data in accordance with clause 10; or (b) termination of all Processing activities subject to this DPA, except for any provisions that expressly or by implication survive termination.

10. Retention, Return and Deletion of Customer Personal Data

10.1 Upon termination or expiry of the Agreement, Lead Forensics may retain Customer Personal Data for up to thirty (30) days to enable Customer to retrieve such data and elect in writing whether it should be returned or deleted. During this period, Lead Forensics shall continue to protect Customer Personal Data in accordance with this DPA and shall not Process it except as necessary for post-termination access, security, system integrity, or compliance with applicable law.
10.2 If the Customer elects return within that thirty (30) day period, Lead Forensics shall make Customer Personal Data available through the available self-serve options or another reasonable method agreed by the parties. If the Customer elects deletion, or does not make an election within that period, Lead Forensics shall delete Customer Personal Data without undue delay thereafter.
10.3 Archived backup copies of Customer Personal Data may be retained for up to two (2) years following termination, provided that such copies remain subject to strict access controls, appropriate technical and organisational measures, and no active Processing other than storage, disaster recovery, restoration testing, or as required by applicable law.
10.4 Where Lead Forensics is required by applicable law to retain Customer Personal Data, it may retain such data only to the extent and for the period required by law and shall continue to protect it in accordance with this DPA.

11. Lawful Jurisdiction

11.1 The lawful jurisdiction specified in the Agreement shall govern this DPA.

 

APPENDIX A

Customer Personal Data (Lead Forensics)

The following categories of Customer Personal Data are necessary to be processed as part of the service:

 

Description Nature of the Processing Purpose Data Subjects Retention
IP Address, to the extent that it is considered personal data. Collection, recording, storage, hosting, access, use, analysis, consultation, transmission, support. To identify a business in our proprietary database and present this in the Customer portal/reporting. Website visitors. Subject to Termination and Retention and Deletion Policy in the DPA.
Contact Data, including name, email. Collection, recording, storage, hosting, access, use, analysis, transmission, support, deletion or return. Login credentials, Single Sign-on. Customer employee. Subject to Termination and Retention and Deletion Policy in the DPA.
Search Terms. Collection, recording, storage, hosting, access, use, analysis, transmission, support. Freestyle text input by the website visitor to the extent that it may be considered personal data. Website visitors. Subject to Termination and Retention and Deletion Policy in the DPA.

The names of the code and identifiers in the JavaScript we provide may vary from Customer to Customer for security and compliance reasons.

 

Customer Personal Data Continued (Lead Forensics)

The following data is provided and processed as standard. Processor shall process such data only to provide the Services. The code may process identifiers, webpage endpoints, cookie or mobile identifier presence, and hashed email values to improve matching capabilities, in each case subject to the Customer’s compliance obligations under applicable Data Protection Laws. The Customer may request removal at any time; such requests must be received and confirmed in writing by emailing [email protected].

Description Nature of the Processing Purpose Data Subjects Retention
Contact Data. For example, first name, surname, job title, LinkedIn URL (as provided by Customer) Collection, recording, storage, hosting, access, use, analysis, transmission, support, deletion. Applies if data is uploaded or PURLs used (purpose defined by the Customer).

As defined by the Customer.

It may also apply to an integration.

Subject to Termination and Retention and Deletion Policy in the DPA.
B2B Contact Data. First name, surname, job title, LinkedIn URL. Collection, recording, storage, hosting, access, use, analysis, transmission, support, deletion or return. To provide contact data upon request. Employees of a matched business or a business of interest. For example, prospects, customers, and leads (as defined by Customer). Subject to Termination and Retention and Deletion Policy in the DPA.
Lead Forensics Advanced Cookie (lfuuid). Collection, recording, storage, access, use, analysis, transmission, support.

This is not standard for all customers in the UK/EU/ROW, but it is standard in the US.

May increase matching capabilities.

Website visitors. First-party cookie expires after 1 year.
Our standard code may process identifiers, webpage endpoints, cookie/mobile ID presence, and hashed email (HEM). Collection, recording, storage, access, use, analysis, transmission. May increase matching capabilities for US website visitors. US website visitors only. 14 days.

No special categories of data or health information are intended to be transferred under this DPA.

 

APPENDIX B

Customer Personal Data (Lead Forensics + Chat)

In addition to the processing covered in Appendix A, Lead Forensics Chat processes the following:

Description Nature of the Processing Purpose Data Subjects Retention
GUUID (First-Party Cookie). Collection, recording, storage, hosting, access, use, analysis, transmission, support.

Dropped only when the user engages.

Strictly necessary to uphold user requests and interactions.

Website visitors. Expires 48 hours after engagement, save that each further active engagement refreshes the expiry period for an additional 48 hours.
Contact Data, Freestyle text. Collection, recording, storage, hosting, access, use, analysis, transmission, support, deletion or return. Form-fill, engagement with Chat. Required to provide the service. Website visitors. Subject to Termination and Retention and Deletion Policy in the DPA.

No special categories of data or health information are intended to be transferred under this DPA.

 

APPENDIX C

Customer Personal Data (Lead Forensics + Webeo)

The following categories of Customer Personal Data are necessary to be processed as part of the service:

Description Nature of the Processing Purpose Data Subjects Retention
IP Address, to the extent that it is considered personal data. Collection, recording, storage, hosting, access, use, analysis, transmission, support. To identify a business in our proprietary database and present this in the Customer portal. Website visitors. Subject to Termination and Retention and Deletion Policy in the DPA.
Contact Data, including name, email. Collection, recording, storage, hosting, access, use, analysis, transmission, support, deletion or return. Login credentials, Single Sign-on. Customer employee. Subject to Termination and Retention and Deletion Policy in the DPA.
Search Terms. Collection, recording, storage, hosting, access, use, analysis, transmission, support. Freestyle text input by the website visitor to the extent that it may be considered personal data. Website visitors. Subject to Termination and Retention and Deletion Policy in the DPA.

No special categories of data or health information are intended to be transferred under this DPA.

 

The following personal data are optional features.

Description Nature of the Processing Purpose Data Subjects Retention

Webeo Cookie (personalisation enablement).

A first-party cookie.

Collection, recording, storage, hosting, access, use, analysis, transmission, support, deletion. Tracks visitor behaviour anonymously until the user identifies themselves via a form. Website visitors. Expires after 1 year.

 

APPENDIX D

Technical and Organisational Measures

Click this link to access the Technical and Organisational Measures:

https://www.leadforensics.com/toms/

 

APPENDIX E

Sub-Processors

https://www.leadforensics.com/sub-processors/

 

APPENDIX F

1. Standard Contractual Clauses (SCCs)

1.1 To the extent that Lead Forensics Processes Customer Personal Data in connection with a Restricted Transfer from the EEA, and Customer acts as controller and Lead Forensics acts as processor in respect of such transfer, the parties agree that Module Two (Controller to Processor) of the standard contractual clauses adopted by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914 (the “EU SCCs”) is incorporated by reference into, and forms part of, this DPA.
1.2 For the purposes of Section 1.1 and the EU SCCs, the Customer shall be the data exporter, and Lead Forensics shall be the data importer.
1.3 In relation to each Restricted Transfer described in Section 1.1, the EU SCCs shall apply as follows:
1.3.1 Clause 7 (Docking Clause) shall apply;
1.3.2 Clause 9, Option 2 shall apply, and the period for prior notice of any new Sub-Processor or replacement Sub-Processor shall be ten (10) business days;
1.3.3 Clause 11, the optional language shall not apply;
1.3.4 Clause 17, Option 1 shall apply, and the EU SCCs shall be governed by the laws of the Republic of Ireland; and
1.3.5 Pursuant to Clause 18(b), disputes arising from the EU SCCs shall be resolved by the courts of the Republic of Ireland.
1.4 The EU SCCs shall be deemed completed as follows:
1.4.1 Annex I.A shall be deemed completed with the parties’ details set out in the Order Form and this DPA;
1.4.2 Annex I.B shall be deemed completed with the description of the transfer set out in Appendix A, B, or C (as applicable under the DPA), including the categories of data subjects, categories of personal data, purpose of the processing, and processing duration.
Special categories of personal data: None are intended to be transferred under this DPA unless expressly agreed in writing in the applicable Order Form or Appendix A, B, or C (as applicable under the DPA).
The transfer is continuous.
1.4.3 Annex II shall be deemed completed with the technical and organisational measures set out in Appendix D in the DPA; and
1.4.4 Annex III shall be deemed completed with the list of Sub-Processors set out in Appendix E in the DPA, where applicable.

 

Annex I.A Parties Order Form
Annex I.B Description of transfer Appendix A, B, or C (as applicable)
Annex II TOMs Appendix D
Annex III Sub-Processors Appendix E

 

2. UK Transfers

2.1 To the extent that Lead Forensics Processes Customer Personal Data in connection with a Restricted Transfer from the United Kingdom, and Customer acts as controller and Lead Forensics acts as processor in respect of such transfer, the parties agree that the EU SCCs referred to in Sections 1.1 to 1.4, as amended by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office (the “UK Addendum”), are incorporated by reference into, and form part of, this DPA.
2.2 For the purposes of the UK Addendum:
2.2.1 Table 1 shall be deemed completed with the parties’ details set out in the applicable Order Form and this DPA, with Customer as Exporter and Lead Forensics as Importer;
2.2.2 Table 2 shall be deemed completed by selecting the same Approved EU SCCs, module and optional clauses as are set out in Sections 1.1 to 1.4 of this Appendix F;
2.2.3 Table 3 shall be deemed completed with the information referred to in Section 1.4 of this Appendix F;
2.2.4 In Table 4, both the Importer and the Exporter may end the UK Addendum as set out in Section 19 of the UK Addendum.
2.3 The Mandatory Clauses of the UK Addendum are incorporated by reference into, and form part of, this DPA and shall apply to each Restricted Transfer described in Section 2.1.
2.4 If and to the extent there is any conflict between this Section 2 and the EU SCCs and/or the UK Addendum, the EU SCCs or the UK Addendum (as applicable) shall prevail in respect of the relevant Restricted Transfer.
2.5 For the avoidance of doubt, in accordance with Section 12(c) of the UK Addendum, the UK Addendum (including the Addendum EU SCCs incorporated into it) is governed by the laws of England and Wales, and any dispute arising from it shall be resolved by the courts of England and Wales.

3. Swiss Transfers

3.1 To the extent that Lead Forensics Processes Customer Personal Data in connection with a Restricted Transfer from Switzerland, and Customer acts as controller and Lead Forensics acts as processor in respect of such transfer, the parties agree that the EU SCCs referred to in Sections 1.1 to 1.4 of this Appendix F shall apply to such transfer, subject to the amendments set out in this Section 3.
3.2 For the purposes of Section 3.1 and the EU SCCs:
3.2.1 References to “Regulation (EU) 2016/679” or “GDPR” shall be interpreted as references to the Swiss Federal Act on Data Protection (“FADP”), to the extent required for the relevant Restricted Transfer from Switzerland;
3.2.2 References to “Member State” shall be interpreted to include Switzerland, where required, and shall not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of exercising or enforcing their rights under the EU SCCs.
3.2.3 References to the “competent supervisory authority” shall be interpreted as references to the Swiss Federal Data Protection and Information Commissioner (“FDPIC”), where and to the extent required by the FADP;
3.2.4 Clause 13 and Annex I.C of the EU SCCs shall be interpreted accordingly to refer to the FDPIC, where and to the extent required by the FADP;
3.2.5 References to the “competent courts” shall be interpreted as references to the competent courts of Switzerland, where and to the extent required by the FADP; and
3.2.6 Customer shall be the data exporter and Lead Forensics shall be the data importer.
3.3 In relation to each Restricted Transfer described in Section 3.1, the EU SCCs shall apply as follows:
3.3.1 Clause 7 (Docking Clause) shall apply;
3.3.2 Clause 9, Option 2 shall apply, and the period for prior notice of any new Sub-Processor or replacement Sub-Processor shall be ten (10) business days;
3.3.3 Clause 11, the optional language shall not apply;
3.3.4 Clause 17, Option 1 shall apply, and the EU SCCs shall be governed by the laws of Switzerland; and
3.3.5 Pursuant to Clause 18(b), disputes arising from the EU SCCs shall be resolved by the competent courts of Switzerland.
3.4 In relation to each Restricted Transfer described in Section 3.1, the EU SCCs shall be deemed completed as follows:
3.4.1 Annex I.A shall be deemed completed with the parties’ details set out in the Order Form and this DPA;
3.4.2 Annex I.B shall be deemed completed with the description of the transfer set out in Appendix A, B, or C (as applicable under the DPA), including the categories of data subjects, categories of personal data, purpose of the processing, and processing duration.
3.4.3 Special categories of personal data: None are intended to be transferred under this DPA unless expressly agreed in writing in the applicable Order Form or Appendix A, B, or C (as applicable under the DPA).
3.4.4 The transfer is continuous.
3.4.5 Annex II shall be deemed completed with the technical and organisational measures set out in Appendix D in the DPA; and
3.4.6 Annex III shall be deemed completed with the list of Sub-Processors set out in Appendix E in the DPA, where applicable.
3.5 If and to the extent there is any conflict between this Section 3 and the EU SCCs, the EU SCCs as amended by this Section 3 shall prevail in respect of the relevant Restricted Transfer from Switzerland.

 

APPENDIX G – US State Privacy Addendum

1. Supplementary Terms for US State Privacy Laws

1.1 To the extent Lead Forensics Processes Personal Information subject to applicable US state privacy laws, including the CCPA/CPRA, Lead Forensics shall Process such Personal Information only on Controller’s documented instructions, for the limited and specified purposes set out in the Agreement and this DPA, and only as permitted by applicable law.
1.2 Lead Forensics shall not: (a) sell or share such Personal Information; (b) retain, use, or disclose such Personal Information for any purpose other than the specific purposes set out in the Agreement and this DPA, unless permitted under this DPA or applicable US state privacy laws; or (c) combine such Personal Information with personal information received from, or on behalf of, another person or collected from Lead Forensics’ own interaction with any consumer, unless permitted under this DPA or applicable US state privacy laws.
1.3 Lead Forensics shall comply with the obligations applicable to it under applicable US state privacy laws in its capacity as a service provider, contractor, processor, or similar role, as applicable, including by:
1.3.1 providing the same level of privacy protection required by applicable law;
1.3.2 ensuring that persons authorised to Process such Personal Information are subject to an appropriate duty of confidentiality;
1.3.3 notifying Controller without undue delay if Lead Forensics determines that it can no longer meet its obligations under applicable US state privacy laws or this DPA in relation to such Personal Information;
1.3.4 assisting Controller, taking into account the nature of the Processing and the information available to Lead Forensics, with responding to consumer rights requests and meeting Controller’s obligations under applicable US state privacy laws;
1.3.5 deleting or returning such Personal Information at the end of the provision of the Services in accordance with Clause 10 of this DPA, unless retention is required by applicable law;
1.3.6 upon Controller’s reasonable request, making available information necessary to demonstrate Lead Forensics’ compliance with this Appendix G, to the extent required by applicable US state privacy laws.
1.4 Where Lead Forensics engages any subcontractor to Process Personal Information subject to applicable US state privacy laws, Lead Forensics shall enter into a written agreement with such subcontractor that imposes privacy obligations no less protective than those set out in this Appendix G, to the extent required by applicable law.
1.5 Unless this DPA expressly states otherwise, Lead Forensics’ obligations for Personal Information subject to applicable US state privacy laws are limited to those required by applicable US state privacy laws and the terms expressly set out in this DPA.
1.6 Lead Forensics grants the Customer the right, upon notice, to take reasonable and appropriate steps to stop and remediate Lead Forensics’ unauthorised use of such Personal Information, to the extent required by applicable US state privacy laws.
1.7 Lead Forensics shall, to the extent legally permitted, promptly notify Customer in writing of any request, subpoena, judicial or administrative order, regulatory request, governmental request or other legal process that Lead Forensics receives seeking access to or disclosure of Customer Personal Data. Lead Forensics shall reasonably cooperate with Customer, at Customer’s cost, in connection with any lawful efforts by Customer to oppose, limit or intervene in respect of such request or process. Nothing in this clause shall require Lead Forensics to act in breach of applicable law, any binding order or requirement of a court, supervisory authority, regulator or governmental authority, or to waive or prejudice any legal privilege, confidentiality obligation, defence, right or remedy available to Lead Forensics.
1.8 In the event of any conflict between this Appendix G and any other provision of this DPA, the terms of this DPA shall prevail, except to the extent this Appendix G is required to supplement the DPA in order to satisfy applicable US state privacy laws, in which case this Appendix G shall prevail solely to the extent of that conflict.

 

Jump to:

Award-winning software

Summer 2025 Grid Leader award by G2
Summer 2025 regional Leader mid-market award by G2
Summer 2025 regional Leader small business award by G2
Summer 2025 regional Leader small business award by G2
Summer 2025 regional Leader small business award by G2
Summer 2025 regional Leader small business award by G2