OBSIDIAN SECURITY, INC.
ANNEX 1(A): LIST OF PARTIES
Data exporter
Name of the data exporter: The entity identified as the “Subscriber” in the Agreement and this DPA.
Contact person’s name, position, and contact details: The address and contact details associated with Subscriber's Obsidian account, or as otherwise specified in this DPA or the Agreement.
Activities relevant to the data transferred: The activities specified in Annex 1(B)below.
Signature and date: By acceptance of the Agreement and its effective date
Role (Controller/Processor): Controller (for Module 2) or Processor (for Module 3).
Data importer
Name of the data importer: Obsidian Security, Inc. or the Obsidian Affiliate named on the applicable Order Form
Contact person’s name, position, and contact details: The person identified in the Documentation for a specific Service
Activities relevant to the data transferred: The activities specified in Annex 1.B below.
Signature and date: By acceptance of the Agreement and its effective date
Role (Controller/Processor): Processor or Subprocessor
ANNEX 1(B): DESCRIPTION OF THE PROCESSING / TRANSFER
Categories of data subjects whose personal data is transferred:
Individual employee and contractor users of the Third-Party Applications that Subscriber has authorized Obsidian’s services to connect to and individuals whose data are found in the monitored data drawn from Subscriber’s Third-Party Applications.
Categories of personal data transferred:
Sensitive data transferred (if appropriate)
N/A
Frequency of the Transfer
Continuous
Nature, subject matter, and duration of the processing:
Purpose(s) of the data transfer and further processing:
Providing the Services set out in the Agreement and any applicable Order Form or statement of work.
Period for which the personal data will be retained:
Obsidian will retain Subscriber Personal Data for the term of the Agreement and any period after the termination of expiry of the Agreement during which Obsidian processes Subscriber Personal Data in accordance with the Agreement.
ANNEX 1(C): COMPETENT SUPERVISORY AUTHORITY
Competent supervisory authority
The data exporter's competent supervisory authority will be determined in accordance with the EU GDPR.
Subprocessors
Subprocessor List
Obsidian’s list of subprocessors is available at trust.obsidiansecurity.com