Data Processing Addendum: Ledgy's Commitment to Security

Data Processing Addendum

Date updated: August 2022
Version number: 2.0

Ledgy AG, a company incorporated under the laws of Switzerland, having its registered office and principal place of business at Förrlibuckstrasse 190, 8005 Zürich, Switzerland, as registered with the Commercial Register of the Canton of Zurich under number CHE-261.454.963 (“Ledgy”, the “Data Processor” or the “Processor”), and the customer (the “Customer”, the “Data Controller” or the “Controller”), hereby agree as follows:

1. Scope

This data processing addendum (the “Data Processing Addendum” or “Addendum”) applies exclusively to the processing of personal data (the “Customer Personal Data” or “Personal Data”) that is subject to European Union (EU), United Kingdom (UK), and Swiss data privacy law, in the scope of the services (the “Services Agreement”) between the Data Controller and the Processor (each a “Party” and together the “Parties”) for the provision of services (the “Services”).

1.1

The term EU data privacy law (“EU Data Privacy Law”) means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation or GDPR). The term UK data privacy law (“UK Data Privacy Law”) means all laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the UK GDPR and the Data Protection Act 2018. The term Swiss data privacy law means the Federal Act of 19 June 1992 on Data Protection, including any future revision thereof (“Swiss Data Privacy Law”). EU Data Privacy Law, UK Data Privacy Law and Swiss Data Privacy Law are collectively referred to as “Data Privacy Law”.

1.2

Terms such as “Processing”, “Personal Data”, “Data Controller” and “Processor” shall have the meaning ascribed to them in EU Data Privacy Law, UK Data Privacy Law and Swiss Data Privacy Law, as applicable.

1.3

In so far as the Data Processor will be processing Personal Data of the Data Controller subject to the EU Data Privacy Law, UK Data Privacy Law, and Swiss Data Privacy Law in the course of the performance of the Services Agreement with the Data Controller, the terms of this Data Processing Addendum shall apply. An overview of the categories of Personal Data, the types of data subjects (the “Data Subjects”), and purposes (the “Purposes”) for which the Personal Data are being processed is provided below.

2. Binding character of this Addendum

The Parties hereby agree to be bound by the provisions and obligations set forth in this Addendum in respect of all their data protection obligations and data processing relationships and agree that any data protection and data processing obligations as agreed to previously amongst the Parties shall be deleted and repealed in its entirety and be replaced with this Addendum.

3. Information required by Data Privacy Law

The Parties agree to the following information, as required by the EU, UK and Swiss Data Privacy Law:

4. Ledgy as Processor

The Customer and Ledgy hereby agree that for the purposes of this Addendum, Ledgy (and each permitted subcontractor) shall be the Data Processor.

5. Ledgy’s obligations

Ledgy, acting as Data Processor, shall:

5.1 only process the Customer Personal Data as necessary to perform its obligations under this Services Agreement, as required by laws applicable to it (provided that Ledgy first informs the Customer of that legal requirement before processing, unless that law prohibits this on important grounds of public interest);

5.2 ensure that all staff who have access to Customer Personal Data have committed themselves to appropriate obligations of confidentiality;

5.3 maintain all appropriate technical and organizational measures to ensure the security of the Customer Personal Data. The Parties acknowledge that security requirements are constantly changing and that effective security requires frequent evaluation and regular improvements of outdated security measures.

5.4 assist, to the extent possible, the Customer to fulfill its obligations in responding to requests for exercising of Data Subject rights set out in the applicable Data Privacy Law;

5.5 not engage any other processor in relation to the Services except in accordance with Customer’s general authorization. See Annex 1 for the list of current sub-processors used by Ledgy.

5.6 subcontracting relationships within the meaning of this Clause 5 shall not include services which Ledgy makes use of with third parties as an ancillary service to support the execution of the order.

5.7 permit Customer or a third-party auditor acting under the Customer’s direction to conduct data protection audits, assessments and inspections concerning Ledgy’s data protection procedures.

5.8 notify the Customer as soon as reasonably practicable in writing if it becomes aware of a reportable breach.

5.9 assist the Customer in complying with Article 35 (Data protection impact assessment) and Article 36 (Prior consultation) of the GDPR.

5.10 on termination or expiry of this Addendum however made and for any reason, destroy all Customer Personal Data or transfer it to the Customer or a nominated third party.

5.11 Ledgy’s aggregate liability to the Customer hereunder shall be limited to and shall not exceed 100% of the fees paid by the Customer in a Contract Year under the Services Agreement.

5.12 for cross border transfers to countries that do not provide an adequate data protection level, Ledgy will implement adequate security measures including the Standard Contractual Clauses (SCCs).

6. The Customer’s obligations

The Customer, acting as the Controller, hereby warrants and represents:

6.1 that all processing of Customer Personal Data will be in compliance with all Data Privacy Law.

6.2 that Customer Personal Data provided to Ledgy are accurate and will be updated to ensure continued accuracy as required;

6.3 that it has notified Data Subjects of any applicable period for which Customer Personal Data will be stored by Ledgy;

6.4 that the Customer has the right to provide Customer Personal Data to Ledgy and has provided Data Subjects with all necessary information and data protection notices.

6.5 Customer warrants that the Customer will not provide Ledgy with High-Risk Personal Data.

6.6 that the Customer shall keep the login credentials used to access the Services secure.

7. Liability

The Customer acknowledges that Ledgy is reliant on the Customer for instructions and shall indemnify Ledgy against all costs, claims, demands, expenses, losses, actions, proceedings and liabilities incurred by Ledgy.

8. Indemnification

The Customer shall indemnify Ledgy against all costs, claims, demands, expenses, losses, actions, proceedings and liabilities arising from any failure of the Customer or any third party appointed by the Customer to comply with any of the provisions of Clause 6.

9. Prevalence of this Addendum

This Addendum shall prevail in the event of any conflict between this Addendum and any parts of the Services Agreement.

10. Compensation

To the extent that either Party has an entitlement under Data Privacy Law to claim from the other Party compensation paid by the Claiming Party to a data subject as a result of a breach of Data Privacy Law.

11. Competent Court

Any disputes arising from or in connection with this Data Processing Addendum shall be brought exclusively before the competent courts of the Canton of Zurich, Switzerland.

Name of sub-processors