Veza DPA (EEA) – 260204

DATA PROCESSING AGREEMENT

This Data Processing Agreement (“DPA”) is effective as of the date of the later signature below and is between Veza Technologies, Inc. (“Processor”), and the entity identified on the signature page hereto as “Controller” (“Controller”). Intending to be legally bound hereby, Processor and Controller agree as follows:

1. DEFINITIONS. In this DPA:

2. PROCESSING OF PERSONAL DATA

3. SUB-PROCESSING OF PERSONAL DATA

    4. DATA SUBJECT RIGHTS. 

      5. SECURITY; SECURITY BREACHES

        6. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION. 

          7. DELETION OR RETURN OF PERSONAL DATA

            8. INFORMATION; AUDITS

              9. GENERAL TERMS

                  SECURITY EXHIBIT
                  (and Appendix 2 to the Standard Contractual Clauses)

                  STANDARD CONTRACTUAL CLAUSES EXHIBIT

                  SECTION 1

                  Clause 1 – Purpose and scope

                  Clause 2 – Effect and invariability of the Clauses

                  Clause 3 – Third-party beneficiaries

                  Clause 4 – Interpretation

                  Clause 5 – Hierarchy

                  Clause 6 – Description of the transfer(s)

                  Clause 7 – Docking clause

                  SECTION II – OBLIGATIONS OF THE PARTIES

                  Clause 8 – Data protection safeguards

                  8.1 Instructions

                  8.2 Purpose limitation

                  8.3 Transparency

                  8.4 Accuracy

                  8.5 Duration of processing and erasure or return of data

                  8.6 Security of processing

                  8.7 Sensitive data

                  8.8 Onward transfers

                  8.9 Documentation and compliance

                  Clause 9 – Use of sub-processors

                  Clause 10 – Data subject rights

                  Clause 11 – Redress

                  Clause 12 – Liability

                  Clause 13 – Supervision

                  SECTION III – LOCAL LAWS AND OBLIGATIONS IN CASE OF ACCESS BY PUBLIC AUTHORITIES

                  Clause 14 – Local laws and practices affecting compliance with the Clauses

                  Clause 15 – Obligations of the data importer in case of access by public authorities

                  15.1 Notification

                  15.2 Review of legality and data minimisation

                  SECTION IV – FINAL PROVISIONS

                  Clause 16 – Non-compliance with the Clauses and termination

                  Clause 17 – Governing law

                  Clause 18 – Choice of forum and jurisdiction