OBSIDIAN SECURITY, INC.
This Data Processing Addendum, including its Annexes and the Standard Contractual Clauses (the "DPA"), is incorporated by reference into each agreement between Obsidian Security, Inc. or its Affiliate ("Obsidian") and the entity that has entered into such agreement as a service provider, vendor, or contractor ("Vendor") (each such agreement, the "Agreement") and applies solely to the extent that Vendor processes any Obsidian Personal Data (defined below) in connection with the Services. By entering into an Agreement that references this DPA, Vendor agrees to be bound by the terms herein. Obsidian enters into this DPA on behalf of itself and, if applicable and to the extent required under Applicable Data Protection Laws, in the name and on behalf of its Affiliates. All capitalized terms not defined herein shall have the meaning set forth in the Agreement.
This DPA is effective as of the effective date of the applicable Agreement and does not require a separate signature.
ANNEX 1(A): LIST OF PARTIES
Data exporter
Name of the data exporter: Obsidian Security, Inc. or the Obsidian Affiliate identified in the applicable Agreement or Statement of Work.
Contact person’s name, position, and contact details: As specified in the Agreement or as otherwise provided to Vendor.
Activities relevant to the data transferred: The activities specified in Annex 1(B) below.
Signature and date: By entering into an Agreement that references this DPA.
Role (Controller/Processor): Controller (for Module 2) or Processor (for Module 3).
Data importer
Name of the data importer: The entity identified as "Vendor" in the Agreement and this DPA.
Contact person’s name, position, and contact details: As specified in the Agreement or as otherwise provided to Obsidian.
Activities relevant to the data transferred: The activities specified in Annex 1(B) below.
Signature and date: By entering into an Agreement that references this DPA.
Role (Controller/Processor): Processor or Subprocessor
ANNEX 1(B): DESCRIPTION OF THE PROCESSING / TRANSFER
Categories of data subjects whose personal data is transferred:
Individual employee and contractor users of Obsidian’s Services and the associated information gathered by the SaaS applications that Obsidian’s customers have authorized Obsidian’s technology to connect to and individuals whose data are found in the monitored data drawn from Obsidian’s customer’s monitored SaaS applications
Categories of personal data transferred:
Sensitive data transferred (if appropriate)
N/A
Frequency of the Transfer
Continuous
Nature, subject matter, and duration of the processing:
For the provision of the Services and support under the Agreement
Purpose(s) of the data transfer and further processing:
Providing the Services and support set out in the Agreement.
Period for which the personal data will be retained:
For the duration of the Agreement, unless otherwise specified in the Agreement or required by applicable law.
For transfers to(sub-)processors, also specify subject matter, nature, and duration of the processing:
As specified by Vendor in the Subprocessor List.
ANNEX 1(C): COMPETENT SUPERVISORY AUTHORITY
Competent supervisory authority
The data exporter's competent supervisory authority will be determined in accordance with the EU GDPR.