Data Processing Agreement

This Data Processing Addendum (the “DPA”) forms part of the written services agreement, Order (as defined below) and any other relevant agreement between Trestle Solutions, Inc., a Delaware corporation (“Trestle”) and the customer named therein (“Customer”) (such agreement, the “Principal Agreement”) and governs the Processing of Personal Data of individuals subject to Privacy and Data Protection Law pursuant to the Principal Agreement. Trestle and Customer are hereinafter collectively referred to as the “Parties” or each individually as a “Party.”

  1. Definitions and interpretation. Capitalized terms not otherwise defined herein have the same meaning given to them in the Principal Agreement. Except as modified below, the terms of the Principal Agreement remain in full force and effect.

The following terms have the meanings set out below for this DPA:

1.1 “Affiliate” means, in relation to a Party, any other entity which directly or indirectly Controls, is Controlled by, or is under direct or indirect common Control with that Party from time to time. “Control”, for the purposes of this definition, means direct or indirect ownership or control of more than 50 percent of the voting interests of the subject entity.

1.2 “Business Purpose” (or “Purpose”) means the use of Personal Data for Trestle or Customer’s operational purposes, or other notified purposes, provided that the use of Personal Data is reasonably necessary and proportionate to achieve the operational purpose for which the Personal Data was collected or processed or for another operational purpose that is compatible with the context in which the Personal Data was collected.

1.3 “CCPA” means the California Consumer Privacy Act of 2018 (California Civil Code §§ 1798.100 to 1798.199), as amended by the California Privacy Rights Act, and its implementing regulations as amended or superseded from time to time.

1.4 “Customer Data” means all electronic data and information submitted by or for Customer to Trestle in connection with the Services. Customer Data does not include Trestle Data or Metadata.

1.5 “Customer Personal Information” means Personal Information subject to Privacy and Data Protection Law that Trestle Processes on behalf of Customer to provide the Services to Customer.

1.6 “Data Protection Rights” means all rights granted to individuals under Privacy and Data Protection Law.

1.7 “Data Subject” means an identified or identifiable natural person whose Personal Data is Processed in the context of the Principal Agreement.

1.8 “Deidentified Data” means data generated or derived from Customer Data or the Services that cannot reasonably identify, relate to, describe, be capable of being associated with, or be linked, directly or indirectly, to a particular individual.

1.9 “EU Data Protection Law” means all of the following, each as amended and replaced from time to time: the EU General Data Protection Regulation 2016/679 (“EU GDPR”) and the e-Privacy Directive 2002/58/EC (as amended by Directive 2009/136/EC) and their respective national implementing legislations; the Swiss Federal Data Protection Act; the Monaco Data Protection Act; the UK Data Protection Act 2018 and UK GDPR (together “UK Data Protection Law”); and the Data Protection Acts of the European Economic Area (“EEA”) countries; each as applicable.

1.10 “Metadata” means the data that Trestle generates from its analysis of the Customer Data and other customers’ data. Metadata is pseudonymized, aggregated, and de-identified wherein the data does not identify or enable identification of the Customer, the Authorized Users, or any natural person. Examples of Metadata include: the number of times a specific data element of Trestle Data has been Queried in a period of time (velocity) or the last time a data element has been seen (recency). Metadata is not Customer Data. “Order” means a document or online order entered into between Customer and Trestle, or any of their Affiliates, that specifies the Services to be provided by Trestle and that includes but is not limited to, the pricing schedule, scope of use, the fees, and the subscription term. By entering into an Order, an Affiliate of Customer agrees to be bound by the terms of this DPA as if it were an original party.

1.11 “Personal Data” / “Personal Information” means any information relating to an identified or identifiable individual, including but not limited to contact information, demographic information, passport number, Social Security number or other national identification number, bank account information, Primary Account Number and authentication information.

1.12 “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, access to, or other unauthorized Processing of Personal Data transmitted, stored or otherwise Processed.

1.13 “Privacy and Data Protection Law” means any law, statute, declaration, decree, legislation, enactment, order, ordinance, regulation or rule (as amended and replaced from time to time) which relates to the protection of individuals with regards to the Processing of Personal Data to which the Parties are subject, including without limitation State Comprehensive Privacy Law and the EU Data Protection Law.

1.14 “Processing of Personal Data” (or “Processing/Process”) means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, including any operation defined as “Processing” under applicable Privacy and Data Protection Law.

1.15 “Sensitive Data” means any Personal Data considered to be sensitive according to applicable Privacy and Data Protection Law.

1.16 “Services” are Trestle’s suite of products and services as further defined in the Principal Agreement. For clarity, Services exclude Trestle Data.

1.17 “State Comprehensive Privacy Law” means CCPA, Colorado Privacy Act, Connecticut Data Privacy Act, Delaware Personal Data Privacy Act, Indiana Consumer Data Protection Act, Iowa Consumer Data Protection Act, Kentucky Consumer Data Protection Act, Maryland Online Data Privacy Act, Minnesota Consumer Data Privacy Act, Montana Consumer Data Protection Act, Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Protection Act, Oregon Consumer Privacy Act, Rhode Island Data Transparency and Privacy Protection Act, Tennessee Information Protection Act, Texas Data Privacy and Security Act, Utah Consumer Privacy Act, Virginia Consumer Data Protection Act, and other similar United States state comprehensive privacy law.

1.18 “Trestle Data” means information that Trestle provides or otherwise makes available to Customer through the Services or pursuant to an Order. Trestle Data includes, but is not limited to, information from publicly available sources and third-party data providers.

1.19 “User” means an individual who is authorized by Customer to access or use the Services, and who has been provided a user id and password, or other account credential.

2. Scope and Applicability. 

2.1 This DPA regulates the Processing of Personal Data subject to Privacy and Data Protection Law for the Services provided in the Principal Agreement.

2.2 In addition, though Trestle does not intend to Process Personal Data of individuals outside the country of origin, to the extent the Principal Agreement involves the Processing of Personal Data of individuals subject to EU Data Protection Law, the Parties have agreed to the terms set forth in Annex 2 of this DPA for the purpose of complying with EU Data Protection Law (the “EU Addendum”). To the extent Trestle Processes Customer Personal Information to provide the Services to Customer, Trestle and Customer will comply with their respective obligations pursuant to the terms set forth in Annex 3 of this DPA (the “United States Addendum”).

2.3 In the event of a conflict between the terms of the Principal Agreement and this DPA, the terms of this DPA will control to the extent of such conflict.

3. Compliance with Privacy and Data Protection Law. Both Parties represent and warrant that they will comply with Privacy and Data Protection Law when Processing Personal Data in the context of the Services, and that they will perform their obligations under this DPA in compliance with Privacy and Data Protection Law.

4. Roles of the Parties. The Parties acknowledge and confirm that each Party is responsible for the Processing of Personal Data for its own Business Purposes in the context of the Services specified in the Principal Agreement (each the “Trestle Purposes” and the “Customer Purposes”).

5. Obligations of the Parties. Unless otherwise governed by Section 6 of this DPA, each Party represents and warrants that, in relation to the Processing of Personal Data for its own Business Purposes through the Services, it will:

5.1 provide appropriate notice to, or seek consent from, individuals as required under Privacy and Data Protection Law (Notice and Consent);

5.2 ensure that, for any transfers of Personal Data through the Services, the recipient of Personal Data will protect the Personal Data with the same level of protection and through such means as provided by this DPA and as required under applicable Privacy and Data Protection Law (Transfers);

5.3 cooperate with the other Party in good faith to fulfil their respective data protection compliance obligations under Privacy and Data Protection Law (Cooperation and Assistance);

5.4 be responsible for compliance with this DPA and for the compliance of their respective Affiliates and Users;

5.5 conduct and review any relevant assessments as may be required by applicable Privacy and Data Protection Law with respect to the Services and any cross-border transfers of Personal Data.

6. Customer’s Obligations. 

6.1 Generally. Customer will use best efforts to prevent unauthorized access to, or Processing of, Trestle Data and will notify Trestle without undue delay of any such unauthorized access or Processing. Customer will use the Services and Trestle Data only to the extent permitted by the Principal Agreement. Customer is solely responsible for ensuring that its use of the Services and Trestle Data, including Customer’s provision of Customer Data to Trestle, does not violate any applicable Privacy and Data Protection Law or laws generally. Any use of the Services in breach of this DPA by Customer, its Affiliates, or any Users, may result in Trestle’s immediate suspension of the Services.

6.2 Customer’s Privacy Notice. Notwithstanding Section 5 of this DPA, Customer will not collect, provide, or make available to Trestle any Customer Data that is not collected or stored in accordance with applicable law and Customer’s privacy notice (or the privacy notice of Customer’s customers, if applicable). Customer represents and warrants that Customer will provide Data Subjects with all notices and obtain from them all rights and consents necessary for the provision and transfer of such data to Trestle, the Processing of such data by or on behalf of Trestle, and Customer’s use of Trestle Data pursuant to this DPA. As between Customer and Trestle, Customer is solely responsible for providing such notice and obtaining such consent. Customer confirms and warrants that it will inform Data Subjects, as applicable, of the transfer and storage by Trestle of their Personal Data outside the country in which it was collected (though Trestle does not customarily collect, transfer, or store Personal Data outside its country of origin), the ways in which their Personal Data will be Processed by Customer and Trestle, and any other information required by applicable Privacy and Data Protection Law. Customer will ensure that Customer’s privacy notice is readily accessible and, if required by applicable law, Customer will provide those Data Subjects with the ability to exercise any rights under applicable Privacy and Data Protection Law.

6.3 Data Integrity. Customer is exclusively responsible for the accuracy, completeness, relevance, and integrity of all Personal Data provided to Trestle.

6.4 No Automated Decision-Making. Customer hereby represents and warrants that it will not use the Services to make any automated decisions that produce legal effects concerning Data Subjects or similarly significantly affect Data Subjects.

7. Trestle’s Obligations. To the extent that Trestle uses any subprocessor to Process Personal Data (Subprocessor), Trestle will enter into a written agreement with such Subprocessor which imposes the same obligations on the Subprocessor as this DPA imposes on Trestle. Trestle will be liable for any breach of this DPA that is caused by an act, error or omission of its Subprocessors.

8. Transfers. Customer acknowledges and agrees that Trestle does not customarily transfer or store any data, including Personal Data Processed in connection with this DPA, outside the country in which such Personal Data was collected, but to the extent Trestle ever does transfer or store any Personal Data outside the country in which it was collected, then Customer represents and warrants that it has all necessary consents, authorizations, permissions and approvals if applicable and in accordance with applicable Privacy and Data Protection Law.

9. Security of the Processing, Confidentiality, and Personal Data Breach Notification. Each Party agrees and warrants that:

9.1 it has implemented and maintains a comprehensive written information security program that complies with Privacy and Data Protection Law and Annex 1 of this DPA (Information Security Program); and

9.2 it has taken steps to ensure that any person or entity acting under its authority, who Processes or in any way has access to Personal Data (including any entity engaged by a Party or any Subprocessor) is only granted access if necessary and is subject to a contractual or statutory confidentiality obligation (Confidentiality).

10. Notification Obligations. 

10.1 Trestle agrees and warrants that it will:

(a) immediately inform Customer, in writing, of any request, question, objection, complaint, investigation or any other inquiry, received from any individual, regulator or public authority of whatever jurisdiction, that relates to Customer Personal Information Processed through Services, unless otherwise restricted by applicable law. Trestle will provide Customer with a copy of any such requests within 48 (forty-eight) hours of receipt  by email to the contact address provided in the Principal Agreement, and will respond to such requests only in accordance with Customer’s prior written authorization, unless otherwise prohibited by applicable law (Notification Obligations); and

(b) implement appropriate administrative, technical, operational and organizational measures to ensure that the Processing of Personal Data is performed in accordance with this DPA and applicable Privacy and Data Protection Law (Accountability). 

10.2 Customer agrees and warrants that it will:

(a) Immediately inform Trestle, in writing, of any request, question, objection, complaint, investigation or any other inquiry, received from any individual, regulator or public authority of whatever jurisdiction, that relates to Trestle Data received by Customer, unless otherwise restricted by applicable law. Customer will provide Trestle with a copy of any such requests within 48 (forty-eight) hours of receipt by email to legal@trestleiq.com and will respond to such requests only in accordance with Trestle’s prior written authorization, unless otherwise prohibited by applicable law (Notification Obligations); and

(b) Implement appropriate administrative, technical, operational and organizational measures to ensure that use, storage, and access to Trestle Data is performed in accordance with this DPA and applicable Privacy and Data Protection Law (Accountability).

11. Data Disclosures. The Parties represent and warrant that they will only disclose Personal Data to a third party in accordance with applicable Privacy and Data Protection Law, this DPA, and the Principal Agreement, and will require such third party in writing to comply with the same as appropriate and relevant, unless it is otherwise not possible to do so.

12. Personal Data Breach Notification. Trestle will promptly notify Customer of a Personal Data Breach that relates to Customer Personal Information, but in no event later than twenty (20) days after having become aware of a Personal Data Breach. Customer must promptly notify Trestle of a Personal Data Breach that relates to Trestle Data in its possession or control, but in no event later than twenty (20) days after having become aware of a Personal Data Breach. The Parties will assist each other in complying with their obligations to notify of a Personal Data Breach, including by informing the other Party of the nature of the Personal Data Breach, the categories and number of individuals, the categories and amount of Personal Data, the likely consequences of the Personal Data Breach, and the measures taken or proposed to be taken to address the Personal Data Breach and mitigate possible adverse effects.

13. Liability. The Parties agree that if Trestle has paid compensation, damages or fines, Trestle is entitled to claim back from Customer that part of the compensation, damages or fines, corresponding to Customer’s culpability for the same.

14. Applicable Law and Jurisdiction. The Processing of Personal Data under this DPA is governed by the law applicable to the Principal Agreement. Any disputes between the Parties relating to the Processing of Personal Data under this DPA will be subject to the exclusive jurisdiction of the courts in the Principal Agreement.

15. Modification of this Agreement. This DPA may only be modified by a written amendment signed by each of the Parties.

16. Termination. The Parties agree that this DPA is terminated upon the termination of the Principal Agreement, unless otherwise extended by applicable Privacy and Data Protection Law.

17. Severability. If any provision of this DPA is found by any court or administrative body of a competent jurisdiction to be invalid or unenforceable, the invalidity or unenforceability of such provision will not affect any other provision of this DPA, and all provisions not affected by such invalidity or unenforceability will remain in full force and effect.

 

ANNEX 1
TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

Trestle has implemented the security standards outlined below, which may be updated or modified from time to time, provided such updates and modifications will not result in a degradation of the overall security of the processing services it is providing the Customer:

  • Implementation of and compliance with a written information security program consistent with established industry standards and including administrative, technical, and physical safeguards appropriate to the nature of the Customer’s data and designed to protect such information from: unauthorized access, destruction, use, modification, or disclosure; unauthorized access to or use that could result in substantial harm or inconvenience to the Customer, its customers, or its employees; and any anticipated threats or hazards to the security or integrity of such information.
  • Adopting and implementing reasonable policies and standards related to security.
  • Assigning responsibility for information security and privacy management.
  • Devoting adequate personnel resources to information security.
  • Carrying out verification checks on permanent staff who will have access to the Customer’s data.
  • Conducting appropriate background checks and requiring employees, vendors, and others with access to the Customer’s data to enter into written confidentiality agreements.
  • Conducting training to make employees and others with access to the Customer’s data aware of information security risks and to enhance compliance with Trestle’s policies and standards related to data protection.
  • Preventing unauthorized access to the Customer’s data through the use, as appropriate, of physical and logical (passwords) entry controls, secure areas for data processing, procedures for monitoring the use of data processing facilities, built-in system audit trails, use of secure passwords, network intrusion detection technology, encryption and authentication technology, secure log-on procedures, and virus protection, monitoring compliance with Trestle’s policies and standards related to data protection on an ongoing basis.

ANNEX 2
EUROPEAN DATA PROCESSING ADDENDUM

Customer and Trestle agree that the terms and conditions set out below are added as the European Data Processing Addendum (“EU Addendum”) to, and forms an integral part of, the DPA to which it is attached. This EU Addendum regulates the Processing of Personal Data of Data Subjects subject to EU Data Protection Law.

In the event of a conflict between the terms of this EU Addendum and the DPA with respect to the subject matter of this EU Addendum, the terms of this EU Addendum will control to the extent of such conflict.

  1. Definitions. Capitalized terms not otherwise defined herein have the meaning given to them in the DPA. Except as modified below, the terms of the DPA remain in full force and effect.

The following terms have the meanings set out below for this EU Addendum:

1.1 The terms “Binding Corporate Rules”, “Controller,” “Data Subject,” “Personal Data”, “Personal Data Breach”, “Processing/Process of Personal Data,” “Processor”, and “Supervisory Authority” shall have the meanings given to them under EU Data Protection Law.

1.2 “Europe” means the European Economic Area, Switzerland, Monaco and the United Kingdom.

1.3 “EEA Standard Contractual Clauses” or “SCCs” means the clauses annexed to the EU Commission Decision 2021/914 of June 4, 2021, on standard contra ctual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended from time to time.

1.4 “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses.

2. Roles of the Parties. With respect to the Principal Agreement and the DPA, the Parties acknowledge and confirm that Customer appoints Trestle to Process Personal Data. Notwithstanding this Controller-Processor relationship, each Party remains a Controller for the Processing of certain Personal Data for its own Business Purposes in the context of the Services (as specified in Section 4 of the Principal Agreement). The Parties further confirm that the DPA does not create a joint-Controllership relationship as between the Parties.

3. Obligations of the Parties. 

3.1 When Trestle acts as a Processor for Customer Personal Information, it will not Process Personal Data other than on and according to Customer’s documented instructions, as set out in the Principal Agreement, unless required by applicable Privacy and Data Protection Law, in which case Trestle will, to the extent permitted by law, inform Customer of such legal requirement before the relevant Processing.

3.2 Subject to Section 6 of the DPA, each Party represents and warrants that, in relation to the Processing of Personal Data, when a Customer acts as a Controller for any Customer Data or Trestle acts as a Controller for any Trestle Data and the respective data is accessed by or shared with the other Party:

(a) the Receiving Party complies with EU Data Protection Law in respect of Processing of Personal Data;

(b) the Disclosing Party provides appropriate and timely notice to the Data Subjects regarding the Processing of Personal Data with the elements required under EU Data Protection Law (Notice);

(c) each Party takes reasonable steps to ensure that Personal Data is accurate, complete, current, relevant, and limited to what is necessary, and kept in a form which permits identification of Data Subjects for no longer than is necessary unless a longer retention is required or allowed under applicable law;

(d) the Receiving Party implements appropriate technical and organizational measures to ensure that the Processing of Personal Data is performed in accordance with EU Data Protection Law;

(e) the Disclosing Party responds to Data Subject requests to exercise any rights granted under EU Data Protection Law; and

(f) each Party cooperates with the other Party to fulfill their respective data protection compliance obligations under EU Data Protection Law.

4. International Data Transfers.

4.1 Though outside customary practice, the Parties may transfer the Personal Data Processed in connection with the Services outside of Europe in accordance with EU Data Protection Law, provided that the Personal Data is transferred to a country which provides an adequate level of protection under EU Data Protection Law or to a recipient which has implemented adequate safeguards under EU Data Protection Law.

4.2 In the unlikely event Trestle or the Customer transfers Personal Data subject to the EU GDPR or Swiss Data Protection Act to the other Party in a country that is not part of the EEA or subject to a European Commission adequacy decision, the Parties agree that the transfer shall be governed by the EEA Standard Contractual Clauses, which are hereby incorporated into this EU Addendum by reference.

4.3 The Parties agree that the UK Addendum for transfers of Personal Data subject to UK Data Protection Law to a country that is not subject to a UK adequacy decision shall control and which is hereby incorporated into this EU Addendum by reference.

4.4 If either Party’s compliance with EU Data Protection Law applicable to transfers of Personal Data is affected by circumstances outside of either Party’s control, then the Parties will work together in good faith to reasonably resolve such non-compliance.

4.5 Notwithstanding anything to the contrary in the DPA, Customer shall promptly and no later than 48 hours from becoming aware inform Trestle in writing to legal@trestleiq.com, with the subject line “Data Processing Agreement Notification”, if it has reason to believe that it is or has become subject to laws or practices that prevent the Customer or Trestle from fulfilling its obligations under this EU Addendum. Customer shall provide the description of the non-compliance and the reasons for the non-compliance, and its impact or likely impact on Trestle or Trestle’s customers.

5. Data Disclosures. Trestle represents and warrants that it will only disclose Customer Personal Information Processed to a third party in accordance with EU Data Protection Law and will require such third party to comply, in writing, with EU Data Protection Law, as well as the obligations imposed by this EU Addendum, as appropriate and relevant. Customer will not disclose any Trestle Data to third parties.

6. Security of the Processing, Confidentiality, and Personal Data Breach Notification.

6.1 The Parties must implement and maintain a comprehensive written information security program with appropriate technical and organizational measures to ensure a level of security appropriate to the risk, and as appropriate: (a) the pseudonymization and encryption of Personal Data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.

6.2 The Parties shall take steps to ensure that any person acting under their authority who has access to Personal Data is subject to a contractual or statutory confidentiality obligation, and, if applicable, Process Personal Data in accordance with the Controller’s instructions.

6.3 Trestle must promptly notify Customer of a Personal Data Breach that relates to Customer Personal Information, but in no event later than forty-eight (48) hours after having become aware of a Personal Data Breach. Customer must promptly notify Trestle of a Personal Data Breach that relates to Trestle Data in its possession or control, but in no event later than forty-eight (48) hours after having become aware of a Personal Data Breach. The Parties will assist each other in complying with their obligations to notify of a Personal Data Breach. The Party which becomes aware of a Personal Data Breach will promptly notify any applicable competent Supervisory Authority required by EU Data Protection Law. When the Personal Data Breach is likely to result in a high risk to the rights and freedoms of Data Subjects, or upon the competent Supervisory Authority’s request to do so, such Party must promptly communicate the Personal Data Breach to the Data Subject as required by EU Data Protection Law.

6.4 The Parties will use their best efforts to reach an agreement on how to notify persons or entities of a Personal Data Breach, and must document all facts, effects, and remedial actions taken with respect to such Personal Data Breaches.

7. Liability Towards Data Subject. Subject to the limitation of liability clauses in the Principal Agreement, where the Parties are involved in the same Processing and where they are responsible for any damage caused by the Processing of Personal Data, both Customer and Trestle may be held jointly and severally liable in order to ensure effective compensation of the Data Subject. If Trestle pays full compensation for the damage suffered, it is entitled to claim back from Customer that part of the compensation corresponding to Customer’s culpability.

8. Applicable Law and Jurisdiction. The Parties agree that this EU Addendum and the Processing of Personal Data will be governed by the law of the Principal Agreement, and that any dispute will be submitted to the state and federal courts having jurisdiction over the Principal Agreement.

The Parties are signing this EU Addendum on the Effective Date as defined in the Principal Agreement.



APPENDIX 1
PROCESSING OF PERSONAL DATA

A. List of Parties.

  1. Data exporter (for transfer from Trestle to Customer) and data importer (for transfer from Customer to Trestle):

Name: Trestle Solutions, Inc.
Address: 12819 SE 38th St # 263, Bellevue, WA, 98006-1326, United States
Contact Information: Jordan Reynolds,  legal@trestleiq.com
Activities relevant to the data transferred: Providing the Services as described in the Principal Agreement and the DPA.
Signature and Date: Please refer to the signature page to the DPA.
Role: Controller for the purposes listed in Section 3 of the Principal Agreement

2. Data importer (for transfers from Trestle to Customer) and data exporter (for transfers from Customer to Trestle):

Name: Customer
Address: The Customer’s address specified in the Order
Contact: The contact party and email address specified in the Orde
Activities relevant to the data transferred: Receiving the Services as described in the Principal Agreement and the DPA.
Signature and date: please refer to the signature page of the Order or Principal Agreement, as applicable.
Role: Controller for the purposes listed in Section 4.1 of the Principal Agreement.

B. Description of the Transfer.

Data Subjects: Users of Customer’s Products and Services.
Categories of Data: First and last name, physical address, email address, IP address, and phone number.
Sensitive Data Transferred: The Parties do not process any sensitive data.
Frequency of the Transfer: Trestle’s customary practice is not to transfer data outside the country of origin, but in such event, upon Customer’s request on a per query basis via batch file transfer.
Nature of Processing: Collection, storage, analysis, combining with other sources, disclosure by transfer/making available.
Purposes of the Transfer(s): To the extent a transfer is requested by Customer, the transfer is made for the following purpose(s): to provide/receive identity verification, fraud detection, and fraud prevention solutions. 
Period for Which Personal Data is Retained: Persona Data will be retained for as long as permitted under the Principal Agreement or the DPA.

 

ANNEX 3
UNITED STATES ADDENDUM

This UNITED STATES Addendum (“US Addendum”) forms part of the DPA and sets forth the additional terms in respect of the Parties’ compliance with State Comprehensive Privacy Law. In the event of a conflict between the terms of this US Addendum and the DPA with respect to the subject matter of this US Addendum, the terms of this US Addendum will control to the extent of such conflict.

In this US Addendum, the capitalized terms (i) “Aggregate Consumer Information,” “Business,” “Business Purpose,” “Commercial Purpose,” “Deidentified,” “Personal Information,” “Processing,” “Sell,” and “Service Provider” and similar terms are defined as set forth in the applicable State Comprehensive Privacy Law and (ii) “Metadata” and “Services” are defined as set forth in the DPA.

WHEREAS, pursuant to the DPA, Trestle provides to Customer certain Services in support of one or more Business Purposes.

WHEREAS, the Parties intend for the terms of this US Addendum to apply to the extent Trestle collects, receives, or otherwise, Processes Personal Information on Customer’s behalf to provide the Services to Customer.

NOW THEREFORE, for good and other valuable consideration, the Parties hereby agree as follows:

  1. Roles of the Parties. The Parties agree that Customer is the Controller or Business and Trestle is the Processor or Service Provider with respect to any Customer Personal Information. Each Party will comply with its respective obligations under State Comprehensive Privacy Law. For the avoidance of doubt, Trestle’s collection, retention, use, disclosure, sale, or other Processing of Personal Information for its own purposes independent of Customer’s use of the Services as specified in the DPA are outside the scope of this US Addendum.

    2. Processing of Customer Personal Information.

2.1 Trestle will not Process Customer Personal Information other than on and according to Customer’s documented instructions, as set out in the Principal Agreement, unless required by applicable State Comprehensive Privacy Law, in which case Trestle will, to the extent permitted by law, inform Customer of such legal requirement before the relevant Processing.

2.2 Trestle will collect, use, retain, disclose, and otherwise Process Customer Personal Information (i) to perform the Services, including in support of its internal operations and to identify and protect against fraudulent or illegal activity; (ii) as set forth in the DPA and this US Addendum; (iii) to comply with legal or contractual obligations; and (iv) as otherwise permitted by State Comprehensive Privacy Law.

2.3 Trestle may disclose Customer Personal Information to, and permit the Processing of Customer Personal Information by, its sub-contractors (Service Providers or Subprocessors) who perform services on behalf of Trestle. Trestle may retain, use, or disclose Customer Personal Information to detect data security incidents or protect against fraudulent or illegal activity. Further, Trestle may retain and use Customer Personal Information (and combine it with Personal Data from other customers) to build or improve the quality of its fraud detection and identity verification services, provided Trestle does not: (i) build or modify profiles to use in providing services to another business; or (ii) correct or augment data acquired from another source.

2.4 With respect to Customer Personal Information, the Parties acknowledge and agree that:

(a) Trestle does not receive Customer Personal Information as consideration for any of the Services;

(b) Trestle will not Sell Customer Personal Information provided by Customer for the provision of the Services to Customer;

(c) except as otherwise permitted by State Comprehensive Privacy Law, Trestle will not use, retain, or disclose Customer Personal Information except as necessary to perform the Services and as set forth herein, and not for any Commercial Purpose; and

(d) as further set out in Sections 3 and 4 below, any Customer Personal Information that has been pseudonymized, aggregated, and de-identified is no longer considered to be Personal Data under State Comprehensive Privacy Law and can be retained, used, or disclosed by Trestle for the provision of services or for a commercial purpose, and can be combined with data acquired from another source.

2.5 Customer acknowledges and agrees that it is responsible for compliance with all requirements under State Comprehensive Privacy Law (including but not limited to requests to know, requests to delete, and requests to opt out), and as may be required by other applicable law (“Consumer Requests”).

2.6 Upon reasonable request, Trestle will provide assistance to permit Customer to respond to Consumer Requests to the extent required by State Comprehensive Privacy Law. Upon direction by Customer, and in any event no later than thirty (30) days after receipt of a written request from Customer, Trestle shall promptly delete the Customer Personal Information as directed by Customer.

2.7 Upon reasonable request, Trestle will provide Customer with information reasonably necessary for Customer to conduct and document data protection assessments and with information reasonably necessary for Customer to verify Trestle’s compliance with its obligations under the DPA. Trestle will notify Customer if it makes a determination that it can no longer meet its obligations under this DPA. If Trestle so notifies Customer or if Customer has a reasonable belief that that Trestle can no longer meet its obligations under this DPA based upon other information, Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Information.

2.8 Notwithstanding any provision to the contrary of the DPA or this Addendum, the terms of this Addendum shall not apply to Trestle’s Processing of Customer Personal Information that is exempt from State Comprehensive Privacy Law.

3. Processing of Metadata. Customer acknowledges and agrees that Trestle may Process Metadata derived or generated from Customer Personal Information for its Business Purposes. For the avoidance of doubt, Metadata does not include identifiers that indicate Customer as the source of Metadata. As between Trestle and Customer, Trestle exclusively owns rights, title, and interest in and to Metadata.

4. Deidentified Data and Aggregated Data.

4.1 Customer acknowledges and agrees that Trestle may Process Aggregate Consumer Information and De-identified data (together, “Deidentified Data”) relating to, derived, or generated from Customer Personal Information or the Services for any lawful purpose. As between Trestle and Customer, Trestle exclusively owns rights, title, and interest in and to Deidentified Data. Customer further acknowledges and agrees that Deidentified Data does not constitute Customer Personal Information pursuant to the DPA and this US Addendum, and Trestle may use, maintain, disclose, and otherwise Process such Deidentified Data for any lawful purpose.

4.2 In the event that either Party shares Deidentified Data with the other Party, the receiving Party warrants that it: (i) has implemented technical safeguards designed to prohibit reidentification of the Consumer to whom the Deidentified Data may pertain; (ii) has implemented business processes designed to specifically prohibit reidentification of the Deidentified Data; (iii) has implemented business processes designed to prevent inadvertent release of the Deidentified Data; and (iv) will make no attempt to reidentify Deidentified Data.

5. Changes in Data Protection Laws. If any modification to this US Addendum is required as a result of a change in data protection laws or regulations, then either Party may provide written notice to the other Party of that change in law. The Parties will negotiate in good faith any necessary amendments to this US Addendum to address such change. If Customer gives notice under this Section 5, the Parties shall, as soon as reasonably practice, negotiate and implement any variations in good faith.