CloudRaker Data Processing Addendum
Version 2026.1 — effective 3 August 2026
This Data Processing Addendum (the “DPA”) forms part of the Contract Documents under the CloudRaker Terms of Service or other master agreement between CloudRaker Inc. (“CloudRaker”) and the entity identified as the customer (“Customer”) governing the Services (the “Agreement”). It applies to CloudRaker’s Processing of Personal Data on Customer’s behalf in the course of providing the Services. Capitalized terms not defined in this DPA have the meaning given in the Agreement.
This DPA is versioned and pinned to each Order as provided in Section 1.2 of the Agreement, and CloudRaker may publish revised versions as provided in Sections 1.2 and 1.3 of the Agreement. In the event of conflict, the order of precedence in Section 1.4 of the Agreement applies, under which this DPA prevails over the body of the Agreement solely as to the Processing of Personal Data. Nothing in this DPA varies Section 9 (Limitation of Liability) of the Agreement, and Section 17 of this DPA governs how the caps and exclusions in Section 9 apply to it.
1. Interpretation and Definitions
1.1. Capitalized terms not defined in this Section 1 or elsewhere in this DPA have the meaning given in the Agreement or the applicable Order. Where a term used in this DPA is defined in the applicable Data Protection Laws (including “Data Subject”, “Processing”, “profiling”, and “supervisory authority”), it has that meaning, and the terms “Controller” and “Processor” are construed accordingly. References to a statute or regulation include any binding subordinate instrument and any successor to, or replacement of, it, together with binding guidance and decisions of a competent authority interpreting it.
1.2. “CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations.
1.3. “Controller” means the entity that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data; it includes a “business” under the CCPA and a person carrying on an enterprise who collects Personal Data under the Québec Private Sector Act.
1.4. “Data Protection Laws” means all laws relating to the Processing, protection, or privacy of Personal Data applicable to a Party in its performance under the Agreement, including, as applicable: (a) in Canada, the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and the Québec Act respecting the protection of personal information in the private sector, CQLR c. P-39.1, as amended by An Act to modernize legislative provisions as regards the protection of personal information (“Law 25”, and that Act as amended, the “Québec Private Sector Act”); (b) in the European Economic Area (the “EEA”), Regulation (EU) 2016/679 (the “EU GDPR”) and the national laws implementing it; (c) in the United Kingdom, the EU GDPR as incorporated into UK law by the European Union (Withdrawal) Act 2018 (the “UK GDPR”) and the Data Protection Act 2018; (d) in Switzerland, the Federal Act on Data Protection (the “FADP”); and (e) in the United States, the CCPA and other applicable state privacy laws. “GDPR” means the EU GDPR and the UK GDPR, together and individually as the context requires.
1.5. “Data Subject Request” means a request from or on behalf of a Data Subject to exercise rights under Data Protection Laws in respect of that Data Subject’s Personal Data, including rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
1.6. “Personal Data” means Personal Data (as defined in the Agreement) within the Customer Content, Input Data, or Output Data that CloudRaker Processes on Customer’s behalf under the Agreement. Personal Data does not include Aggregated Data.
1.7. “Restricted Country” means a country or territory to which the transfer of Personal Data is restricted or conditioned under Data Protection Laws in the absence of an approved transfer mechanism, including any country outside the EEA, the UK, or Switzerland that is not the subject of an adequacy decision, and, for the purposes of the Québec Private Sector Act, any jurisdiction outside Québec.
1.8. “Restricted Transfer” means a transfer, or onward transfer, of Personal Data to a Restricted Country that is prohibited or restricted absent an approved transfer mechanism or a completed assessment under Data Protection Laws.
1.9. “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Personal Data in CloudRaker’s possession or control. A Security Incident is a “confidentiality incident” for the purposes of the Québec Private Sector Act and a “personal data breach” for the purposes of the GDPR. A Security Incident does not include an unsuccessful attempt or activity that does not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial-of-service attacks, and other network attacks on firewalls or networked systems.
1.10. “Security Program” means CloudRaker’s technical and organizational security measures as described at trust.cloudraker.com, as updated from time to time in accordance with Section 7.3.
1.11. “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time.
1.12. “Sub-processor” means any third party (including a CloudRaker Affiliate) engaged by CloudRaker to Process Personal Data on CloudRaker’s behalf in connection with the Services.
1.13. “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (template B.1.0, in force 21 March 2022), as amended or replaced from time to time.
2. Roles of the Parties
2.1. For Personal Data Processed under the Agreement, Customer is the Controller and CloudRaker is the Processor, except that: (a) where Customer is itself a Processor acting on behalf of a third-party Controller, Customer is a Processor and CloudRaker is a Sub-processor, and Customer’s instructions and authority under this DPA are given on behalf of, and with the authority of, that Controller; and (b) under the CCPA, Customer is the business and CloudRaker is a service provider, and under the Québec Private Sector Act, CloudRaker acts as a service provider to whom Customer entrusts Personal Data by mandate. This DPA constitutes the written contract or mandate required by Data Protection Laws, including Article 28 of the GDPR and section 18.3 of the Québec Private Sector Act.
2.2. CloudRaker does not sell or share Personal Data and does not Process, retain, use, or disclose Personal Data for any purpose other than the purposes set out in this DPA and the Agreement or as otherwise permitted by Data Protection Laws for a Processor or service provider. CloudRaker does not combine Personal Data with personal information it receives from, or on behalf of, any other person, or collects from its own interaction with a Data Subject, except as permitted for a service provider under the CCPA. CloudRaker certifies that it understands and will comply with the restrictions in this Section 2.2.
3. Details of Processing
3.1. The subject-matter, duration, nature, and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Attachment 1 (Details of Processing). Customer is responsible for ensuring Attachment 1, together with the Order and Customer’s configuration of the Platform, accurately reflects the Personal Data it makes available for Processing.
3.2. CloudRaker Processes Personal Data for the duration of the Agreement and for such additional period as this DPA or applicable law requires or permits, after which it handles the Personal Data in accordance with Section 14 (Deletion and Return).
4. CloudRaker’s Processing Instructions
4.1. CloudRaker Processes Personal Data only on Customer’s documented instructions, including with respect to Restricted Transfers, unless required to Process it by a law to which CloudRaker is subject. The Agreement (including the purposes described in Sections 4.2 and 4.4 of the Agreement), each Order, this DPA, Customer’s configuration and use of the Services, and any further written instruction Customer gives that the Parties agree to, together constitute Customer’s complete and documented instructions. Processing necessary to provide, operate, secure, support, and bill for the Services, to generate Aggregated Data, and to comply with applicable law is within the scope of Customer’s instructions.
4.2. Where a law to which CloudRaker is subject requires it to Process Personal Data otherwise than on Customer’s instructions, CloudRaker will inform Customer of that legal requirement before Processing, unless the law prohibits such information on important grounds of public interest.
4.3. CloudRaker will inform Customer if, in its opinion, an instruction infringes Data Protection Laws, provided that CloudRaker has no obligation to review the lawfulness of Customer’s instructions and its notice is not legal advice or an acknowledgement of fault.
5. Customer’s Obligations
5.1. Customer is the Controller of, and solely responsible for, the accuracy, quality, and legality of the Personal Data and the means by which it acquired it. Customer represents and warrants that it has, and will maintain throughout the Term, all rights, consents, authorizations, and lawful bases necessary to make the Personal Data available to CloudRaker and its Sub-processors for Processing as contemplated by the Agreement, including for any Restricted Transfer.
5.2. Customer’s instructions will comply with Data Protection Laws. Customer will not, by instruction or otherwise, require or cause CloudRaker or any Sub-processor to Process Personal Data in a manner that breaches Data Protection Laws, and will not make available to CloudRaker any Personal Data the Processing of which is not permitted by the Agreement, including Restricted Data except as expressly authorized in the Order.
5.3. Customer is responsible for providing all notices to, and obtaining and maintaining all consents and authorizations from, Data Subjects required in connection with the Processing, and for establishing a lawful basis for the Processing, including for the use of any Foundation Model made available or configured by Customer.
6. Confidentiality and Personnel
6.1. CloudRaker will ensure that persons authorized to Process Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, and are subject to appropriate access controls under the least-privilege principle.
6.2. CloudRaker will take reasonable steps to ensure the reliability of its Personnel who have access to Personal Data and that access is limited to those who need it to provide the Services.
7. Security Measures
7.1. CloudRaker will implement and maintain the appropriate technical and organizational measures set out in the Security Program to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of the Processing, and the risks to Data Subjects. The Security Program is incorporated into this DPA by reference and forms part of Customer’s instructions.
7.2. Customer is responsible for independently determining whether the Security Program meets Customer’s requirements and legal obligations, and for its own use and configuration of the Services, including the security of its Access Credentials, its networks and systems, and any Personal Data in transit to or from the Platform over systems not controlled by CloudRaker.
7.3. CloudRaker may update the Security Program from time to time as provided in Section 1.3 of the Agreement, provided that no update will materially reduce the overall security of the Services during a term.
8. Assistance and Cooperation
8.1. Taking into account the nature of the Processing and the information available to CloudRaker, CloudRaker will provide Customer with reasonable assistance, at Customer’s request and expense (subject to Section 16), with Customer’s obligations under Data Protection Laws in respect of the Personal Data Processed under the Agreement, including obligations relating to the security of Processing, notification of Security Incidents to supervisory authorities and Data Subjects, data protection impact assessments (and, under the Québec Private Sector Act, privacy impact assessments), and prior consultation with supervisory authorities.
8.2. CloudRaker’s assistance under this Section 8 is limited to assistance that is reasonable in scope, that relates to Personal Data Processed by CloudRaker as Processor, and that Customer cannot reasonably accomplish through the self-service functionality, documentation, audit reports, or other information CloudRaker makes generally available.
9. Data Subject Requests
9.1. Taking into account the nature of the Processing, CloudRaker will provide Customer with the assistance reasonably necessary and technically possible, through appropriate technical and organizational measures and the self-service functionality of the Platform, to enable Customer to respond to Data Subject Requests.
9.2. If CloudRaker receives a Data Subject Request directly, it will, to the extent legally permitted, promptly notify Customer and will not respond to the request other than to direct the Data Subject to Customer, except on Customer’s documented instruction or as required by law. Customer is solely responsible for responding to Data Subject Requests.
9.3. CloudRaker’s notification of, or response to, a Data Subject Request is not an acknowledgement or admission of any fault or liability.
10. Security Incidents
10.1. CloudRaker will notify Customer without undue delay after becoming aware of a Security Incident affecting Personal Data. Where CloudRaker acts as a Sub-processor, that notice is given to Customer for onward provision to the relevant Controller.
10.2. CloudRaker’s notification will describe, to the extent then known and as it becomes available, the nature of the Security Incident, including where possible the categories and approximate number of Data Subjects and records concerned, its likely consequences, the measures taken or proposed to address it and to mitigate its adverse effects, and a contact point from whom further information may be obtained. CloudRaker will take reasonable steps to mitigate the effects of, and to minimize any damage resulting from, the Security Incident.
10.3. CloudRaker will maintain a register of confidentiality incidents as required by the Québec Private Sector Act and records of Security Incidents as required by Data Protection Laws, and will make relevant extracts available to Customer on reasonable request to the extent they relate to Customer’s Personal Data.
10.4. Customer is solely responsible for assessing whether a Security Incident is notifiable and for complying with any obligation to notify supervisory authorities (including the Commission d’accès à l’information du Québec and the Office of the Privacy Commissioner of Canada) and Data Subjects. CloudRaker’s notification of a Security Incident is not an acknowledgement or admission of any fault or liability.
11. Sub-processors
11.1. Customer provides general written authorization for CloudRaker to engage Sub-processors to Process Personal Data. CloudRaker maintains a current list of Sub-processors, with a mechanism to subscribe to notice of changes, at trust.cloudraker.com/en/subprocessors. CloudRaker will impose on each Sub-processor, by a written contract, data protection obligations that provide at least the same level of protection for Personal Data as this DPA requires, and CloudRaker remains responsible to Customer for the acts and omissions of its Sub-processors as if they were its own.
11.2. CloudRaker will give Customer notice of the addition or replacement of a Sub-processor, by posting to the location in Section 11.1 or by notice to subscribers, at least fifteen (15) days before that Sub-processor begins Processing Personal Data. Customer may object to the change on reasonable data-protection grounds by written notice given within that period, detailing its concerns. If Customer does not object within that period, the change is deemed approved and CloudRaker may proceed.
11.3. If Customer objects within the period in Section 11.2, the Parties will discuss the objection in good faith and CloudRaker will consider Customer’s concerns and inform Customer of any reasonable steps or alternatives available. If the Parties do not reach a resolution and CloudRaker, acting reasonably, is unable to accommodate the objection without material cost or operational impact, CloudRaker may, as Customer’s sole and exclusive remedy, either (a) not appoint the Sub-processor for Customer, where technically feasible, with any resulting change in the Services or Fees to be agreed; or (b) on notice, adjust the Fees or terminate the affected Order, in which case CloudRaker will refund prepaid, unused Fees for the terminated portion of the then-current term.
11.4. Where Customer makes available, enables, or configures a Foundation Model within the Platform, or otherwise instructs CloudRaker to integrate a third-party service, the provider of that Foundation Model or service is deemed a Sub-processor authorized by Customer, and the objection right in Sections 11.2 and 11.3 does not apply to it.
11.5. Customer authorizes CloudRaker to enter into the Standard Contractual Clauses (and, where applicable, the UK Addendum) with a Sub-processor on Customer’s behalf, as Customer’s agent, where required to legitimize an onward Restricted Transfer.
12. International and Cross-Border Transfers
12.1. Customer acknowledges and instructs that CloudRaker and its Sub-processors may store and Process Personal Data outside Québec and outside the jurisdiction in which Customer or the relevant Data Subjects are located, including in Canada, the United States, and other jurisdictions in which CloudRaker or its Sub-processors operate. CloudRaker will ensure that any Restricted Transfer is subject to an appropriate transfer mechanism or safeguard required by Data Protection Laws.
12.2. EEA transfers. To the extent the Processing involves a Restricted Transfer of Personal Data protected by the EU GDPR from Customer (as data exporter) to CloudRaker (as data importer), the SCCs are incorporated into and form part of this DPA and are deemed executed by the Parties, completed and populated as set out in Part 1 of Attachment 2.
12.3. UK transfers. To the extent the Processing involves a Restricted Transfer of Personal Data protected by the UK GDPR, the SCCs as varied and supplemented by the UK Addendum are incorporated into and form part of this DPA and are deemed executed by the Parties, completed and populated as set out in Part 2 of Attachment 2.
12.4. Swiss transfers. To the extent the Processing involves a Restricted Transfer of Personal Data protected by the FADP, the SCCs apply as populated in Part 1 of Attachment 2, subject to the adaptations in Part 3 of Attachment 2 (including that references to the GDPR are to the FADP, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner, and, during any transition period, the SCCs also protect the data of legal entities and data relating to deceased persons).
12.5. Québec transfers. In respect of the communication of Personal Data outside Québec, the Parties acknowledge that they have assessed, taking into account the sensitivity of the Personal Data, the purposes for which it is used, the protection measures (including the contractual measures in this DPA and the measures in the Security Program) that would apply to it, and the legal framework applicable in the jurisdictions in which it would be Processed, that the Personal Data would benefit from protection adequate under the Québec Private Sector Act. This DPA constitutes the written agreement required by that Act in respect of such communication. Customer, as the person carrying on the enterprise, remains responsible for conducting and documenting its own privacy impact assessment where required.
12.6. Conflict; execution. If there is any conflict between this DPA and the SCCs (as varied by the UK Addendum, where applicable), the SCCs prevail. At either Party’s request, the Parties will execute the SCCs or the UK Addendum as separate standalone documents, and will take such further steps as a supervisory authority or Data Protection Laws require to give effect to a Restricted Transfer.
13. Demonstration of Compliance; Audits
13.1. CloudRaker will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and the obligations of a Processor under Data Protection Laws. The Parties intend that this obligation is satisfied, so far as possible, by CloudRaker making available its then-current third-party audit reports, certifications, and security documentation (such as a SOC 2 Type II report or equivalent) under the confidentiality provisions of the Agreement, and the Parties will use these to minimize the burden and frequency of audits.
13.2. Where the information made available under Section 13.1 is not sufficient to demonstrate compliance, or where a supervisory authority requires it, Customer (or a qualified, independent third-party auditor Customer appoints that is not a CloudRaker competitor and is bound by confidentiality obligations at least as protective as the Agreement) may conduct an audit of CloudRaker’s compliance with this DPA, subject to the following: (a) no more than once in any twelve (12) month period, except where a supervisory authority expressly requires more frequent audits; (b) on at least sixty (60) days’ prior written notice, except where a shorter period is required by a supervisory authority or by a Security Incident; (c) during CloudRaker’s normal business hours, for no more than two (2) Business Days, and conducted so as to minimize disruption and to avoid or mitigate risk to CloudRaker’s other customers and to the confidentiality of their data; (d) accompanied by CloudRaker Personnel; and (e) limited in scope to information and systems relevant to Customer’s Personal Data.
13.3. An audit does not include, and Customer will not perform or attempt, any penetration test, vulnerability scan, code inspection, or other active security testing of, or access to, the Platform or CloudRaker’s systems, except with CloudRaker’s prior written consent (which, if given, will be on terms agreed with CloudRaker’s Chief Information Security Officer). CloudRaker may require an audit to be conducted remotely where reasonably necessary for health, safety, security, or the protection of other customers. Customer will provide CloudRaker with any audit report before disclosing it to any third party, and audit reports are the Confidential Information of CloudRaker.
14. Deletion and Return
14.1. On expiry or termination of the Agreement, or on Customer’s earlier written instruction, CloudRaker will cease Processing Personal Data except as necessary to perform this Section 14 or as required by applicable law.
14.2. CloudRaker will delete Personal Data in accordance with Section 6.5 of the Agreement and this Section 14. Customer may export its Customer Content and Output Data using the Platform’s standard export functionality during the Term and for thirty (30) days afterwards, and CloudRaker will not delete Personal Data before the end of that period. Following a deletion request or the expiry of that period, CloudRaker will delete the Personal Data within thirty (30) days, except for copies retained on back-up media in the ordinary course and deleted at regular intervals, and except to the extent, and for so long as, applicable law requires CloudRaker to retain it, in which case CloudRaker will protect it in accordance with this DPA and Process it only as necessary for the purpose of that retention.
14.3. On Customer’s written request, CloudRaker will certify in writing that it has complied with this Section 14.
15. Region-Specific Terms
15.1. Canada (PIPEDA and the Québec Private Sector Act). CloudRaker will Process Personal Data only for the purposes for which Customer entrusted it, will not keep it after the completion of its mandate except as permitted under Section 14, and will notify Customer of any Security Incident as provided in Section 10 so that Customer may discharge its obligations, including any obligation to notify the Commission d’accès à l’information du Québec, the Office of the Privacy Commissioner of Canada, and affected individuals where there is a risk of serious injury or a real risk of significant harm. Each Party has designated a person responsible for the protection of personal information; CloudRaker’s privacy officer may be contacted at privacy@cloudraker.com.
15.2. California (CCPA). The Parties acknowledge that CloudRaker is a service provider that Processes Personal Data on Customer’s behalf for the business purposes set out in the Agreement and this DPA. CloudRaker will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, including retaining, using, or disclosing it for a commercial purpose other than providing the Services, or outside the direct business relationship between the Parties, except as permitted by the CCPA; or (c) combine Personal Data with personal information it receives from or on behalf of another person, or collects from its own interaction with the consumer, except as the CCPA permits a service provider to do. CloudRaker will comply with the applicable obligations of a service provider under the CCPA and provide the same level of privacy protection as the CCPA requires. Customer may take reasonable and appropriate steps to help ensure CloudRaker uses Personal Data consistently with Customer’s obligations under the CCPA and, on notice, to stop and remediate any unauthorized use. CloudRaker will notify Customer if it determines it can no longer meet its obligations under the CCPA.
15.3. EEA, UK, and Switzerland (GDPR and FADP). The transfer mechanisms in Section 12 and Attachment 2 apply. Where CloudRaker acts as a Sub-processor for Customer as Processor, the Module Three (Processor-to-Processor) provisions of the SCCs apply as indicated in Attachment 2, and CloudRaker’s obligations run for the benefit of the relevant Controller as provided in the SCCs.
16. Reimbursement
Except to the extent an obligation arises from CloudRaker’s breach of this DPA, Customer will reimburse CloudRaker for its reasonable costs incurred in providing the assistance and cooperation requested under Sections 8 (Assistance and Cooperation), 9 (Data Subject Requests), and 13 (Demonstration of Compliance; Audits), at CloudRaker’s then-current professional services rates.
17. Liability
17.1. Each Party’s liability arising out of or relating to this DPA, whether in contract, extra-contractual liability, tort, or otherwise, is subject to, and counts toward, the exclusions and limitations of liability in Section 9 of the Agreement. Without limiting Section 9, the Parties acknowledge that a breach of this DPA and a Security Incident are subject to the super-cap in Section 9.3 of the Agreement.
17.2. Any liability arising under the SCCs, including as between a data exporter and data importer, counts toward and is subject to the limitations in Section 9 of the Agreement, except to the extent Data Protection Laws do not permit those limitations to apply to a Data Subject’s rights under the SCCs.
17.3. As between the Parties, each Party is responsible for the administrative fines, penalties, and Data-Subject claims imposed on or made against it to the extent they arise from that Party’s own breach of Data Protection Laws or of this DPA.
18. General
18.1. Term. This DPA takes effect on the effective date of the Agreement (or, if later, the first date on which CloudRaker Processes Personal Data on Customer’s behalf) and continues until CloudRaker has ceased all Processing of Personal Data and complied with Section 14.
18.2. Governing law; language. This DPA is governed by, and the venue and dispute-resolution provisions are those of, Section 11.8 of the Agreement, except that the SCCs are governed by the law, and subject to the forum, stated in Attachment 2, and except as Data Protection Laws otherwise require. The Parties have expressly required that this DPA be drafted in English. / Les Parties ont expressément exigé que le présent addenda soit rédigé en langue anglaise.
18.3. Changes. CloudRaker may publish revised versions of this DPA as provided in Sections 1.2 and 1.3 of the Agreement, including to reflect changes in Data Protection Laws or in the approved form of the SCCs or the UK Addendum. Where a change in law renders a transfer mechanism in Section 12 invalid, the Parties will work in good faith to implement an alternative mechanism, and Section 12 is deemed amended to incorporate it.
18.4. Precedence within this DPA. In the event of conflict, the following order of precedence applies within this DPA: (a) the SCCs (as varied by the UK Addendum, where applicable); (b) the body of this DPA; and (c) the Attachments, except that Attachment 1 prevails over the body of this DPA as to the description of the Processing.
18.5. Notices. Notices under this DPA are given as provided in Section 11.6 of the Agreement, except that operational notices contemplated by this DPA (including Sub-processor change notices under Section 11) may be given through the Platform or the applicable published location.
Attachment 1 — Details of Processing
A. Parties. The data exporter is Customer, whose details are set out in the Order. The data importer is CloudRaker Inc., 1300 Sherbrooke St. W, 6th Floor, Montréal, Québec, H3G 1H9, Canada; contact: privacy@cloudraker.com.
B. Subject-matter and duration of the Processing. The provision of the Services as described in the Agreement and the applicable Order, for the duration of the Agreement and any period permitted under Section 14 of this DPA.
C. Nature and purpose of the Processing. Hosting, storage, execution, transmission, display, analysis, and other Processing of Personal Data as necessary to provide, operate, maintain, secure, support, and bill for the CloudRaker software-as-a-service platform and the Professional Services, including the execution of Customer-defined Playbooks and agents, the generation of Output Data through the integration layer, and the diagnosis and prevention of technical and security issues.
D. Types of Personal Data. The types of Personal Data contained in the Customer Content, Input Data, and Output Data that Customer, its Authorized Users, and its Customer End Users choose to make available to the Platform, which Customer determines and controls. These may include identification and contact data (such as name, email address, telephone number, and business address), account and Authorized-User credentials and identifiers, and any other Personal Data contained in the documents, media, records, and messages Customer processes through the Platform. Customer will not make available, and the Platform is not intended to Process, Restricted Data (including special categories of Personal Data, health information, biometric identifiers, and the personal information of children) except as expressly authorized in the Order.
E. Categories of Data Subjects. The categories of Data Subjects that Customer determines, which may include Customer’s Authorized Users, Personnel, customers, prospective customers, Customer End Users, suppliers, and other individuals whose Personal Data is contained in the Customer Content or Input Data.
F. Sensitivity and constraints. Given the potential for the Processing of sensitive Personal Data where Customer chooses to make it available, the applicable constraints are the measures in the Security Program and the Restrictions in the Agreement.
G. Frequency of the transfer. Continuous, for the duration of the Agreement.
H. Sub-processors. As listed at trust.cloudraker.com/en/subprocessors, subject to Section 11 of this DPA.
I. Retention. Personal Data is retained and deleted in accordance with Section 14 of this DPA and Section 6.5 of the Agreement.
Attachment 2 — Standard Contractual Clauses: Population and Transfer Mechanisms
Part 1 — EU Standard Contractual Clauses
Where the SCCs apply under Section 12.2, they are completed as follows:
- Modules. Module Two (Controller-to-Processor) applies where Customer is a Controller. Module Three (Processor-to-Processor) applies where Customer is a Processor acting on behalf of a third-party Controller.
- Clause 7 (Docking clause). The optional docking clause applies.
- Clause 9 (Use of sub-processors). Option 2 (general written authorization) applies. The minimum notice period for changes to the list of Sub-processors is the period stated in Section 11.2 of this DPA.
- Clause 11 (Redress). The optional language allowing Data Subjects to lodge complaints with an independent dispute-resolution body is not used.
- Clause 17 (Governing law). Option 1 applies; the SCCs are governed by the law of Ireland.
- Clause 18 (Choice of forum and jurisdiction). Disputes are resolved before the courts of Ireland.
- Annex I.A (List of Parties). The data exporter and data importer, and their roles, are as set out in Attachment 1, Section A. Customer is the data exporter; CloudRaker is the data importer.
- Annex I.B (Description of transfer). As set out in Attachment 1, Sections B–G and I.
- Annex I.C (Competent supervisory authority). The competent supervisory authority is determined in accordance with the SCCs and is: (i) where Customer is established in an EEA Member State, the supervisory authority of that Member State; (ii) where Customer is not established in the EEA but has appointed a representative under Article 27 of the EU GDPR, the supervisory authority of the Member State in which the representative is established; and (iii) otherwise, the supervisory authority of the Member State in which the Data Subjects whose Personal Data is transferred are located.
- Annex II (Technical and organizational measures). As set out in Attachment 3 and the Security Program.
- Annex III (List of sub-processors). As set out at trust.cloudraker.com/en/subprocessors.
The Parties are deemed to have signed the SCCs at the signature blocks in Annex I on the effective date of the applicable Order.
Part 2 — UK Transfers (UK Addendum)
Where the UK Addendum applies under Section 12.3, the SCCs as populated in Part 1 are varied and supplemented by the UK Addendum as follows:
- Table 1 (Parties). As set out in Attachment 1, Section A.
- Table 2 (Selected SCCs, modules, and clauses). The SCCs as populated in Part 1, including the module(s) applicable to the transfer.
- Table 3 (Appendix information). Annexes I, II, and III are as set out in Part 1 and Attachment 3.
- Table 4 (Ending the Addendum). Neither Party may end the UK Addendum as set out in Section 19 of its Mandatory Clauses, except that the “Importer” may do so where required.
- The Parties are bound by the Mandatory Clauses of the UK Addendum. Any reference in this DPA to the SCCs in the context of a UK transfer is a reference to the SCCs as varied by the UK Addendum.
Part 3 — Swiss Transfers (FADP adaptations)
Where the FADP applies under Section 12.4, the SCCs as populated in Part 1 apply subject to the following adaptations: (a) references to the GDPR are to the FADP insofar as the transfer is governed by it; (b) the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner in respect of transfers governed by the FADP; (c) the term “Member State” is not interpreted to exclude Data Subjects in Switzerland from exercising their rights in their place of habitual residence; and (d) until the entry into force of the revised FADP is fully reflected, the SCCs also protect the Personal Data of legal entities and data relating to deceased persons.
Attachment 3 — Technical and Organizational Measures
The technical and organizational measures CloudRaker implements and maintains are set out in the Security Program at trust.cloudraker.com, which is incorporated by reference and, for the purposes of the SCCs, constitutes Annex II. Those measures address, at a minimum and as appropriate to the risk: (a) pseudonymization and encryption of Personal Data in transit and at rest; (b) measures to ensure the ongoing confidentiality, integrity, availability, and resilience of Processing systems and services; (c) measures to restore the availability of and access to Personal Data in a timely manner following a physical or technical incident; (d) a process for regularly testing, assessing, and evaluating the effectiveness of the measures; (e) access controls under the least-privilege principle, including authentication, authorization, and logging; (f) network, application, and infrastructure security, including vulnerability management and secure software development practices; (g) personnel security, including confidentiality obligations and training; (h) physical security of facilities and hosting environments; and (i) governance of Sub-processors. Where CloudRaker acts as data importer under the SCCs, it will grant access to Personal Data only to the extent strictly necessary for the provision of the Services.
This document is a template prepared for CloudRaker's internal use and should be reviewed by qualified legal counsel, and confirmed against CloudRaker's actual data-processing practices, Security Program, and Sub-processor list, before it is published or relied upon. It does not constitute legal advice.