Data Processing Agreement
This Data Processing Agreement (“DPA”) forms an integral part of, and is made subject to, the Intezer Master Subscription Terms and Conditions or other agreement signed between the Parties (as applicable the “Agreement”) entered into by and between the customer signed on the Agreement or corresponding Order Form (hereinafter referred to as “Customer” or “Controller”) and Intezer Labs Ltd., and/or its Affiliates (hereinafter collectively referred to as “Intezer” or “Processor”). Controller and Processor are hereinafter jointly referred to as the “Parties” and individually as the “Party.”
WHEREAS, Processor shall provide the services set forth in the Agreement (collectively, the “Services”) to Controller, as described in the Agreement; and
WHEREAS, the Parties wish to set forth the arrangements concerning the Processing of Personal Data within the context of the Services and agree to comply with the following provisions with respect to any Personal Data, each acting reasonably and in good faith.
NOW THEREFORE, in consideration of the mutual promises set forth herein and other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged by the Parties, the Parties, intending to be legally bound, agree as follows:
1. INTERPRETATION AND DEFINITIONS
1.1 The headings contained in this DPA are for convenience only and shall not be interpreted to limit or otherwise affect the provisions of this DPA. References to clauses or sections are references to the clauses or sections of this DPA unless otherwise stated. Words used in the singular include the plural and vice versa, as the context may require. Capitalized terms not defined herein shall have the meanings assigned to such terms in the Agreement.
1.2 Definitions:
- “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. “Control” for purposes of this definition means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
- “Controller” or “Business” as relevant under applicable Data Protection Laws, means the entity which determines the purposes and means of the Processing of Personal Data or such equivalent term under Data Protection Laws.
- “Customer Personal Data” means any Personal Data which is provided to and Processed by Intezer on behalf of Customer in order to provide the Services under the Agreement. Customer Personal Data does not include Personal Data that Intezer Processes as a Controller separately from its Processing obligations to Customer under the Agreement.
- “Data Protection Laws” means all laws and regulations of the European Union, the EEA and their Member States, Switzerland, the United Kingdom, and the United States, each to the extent applicable to the Processing of Customer Personal Data under the Agreement.
- “Data Subject” means the identified or identifiable person to whom the Customer Personal Data relates.
- “EEA” means the European Economic Area.
- “EU Data Protection Law” means the GDPR, and the UK GDPR.
- “Extended EEA Country” means a Member State of the EEA, Switzerland or the United Kingdom, and Extended EEA Countries means the foregoing countries collectively.
- “FADP” means the Swiss Federal Act on Data Protection dated 19 June, 1992 and any subsequent amendments, replacements, or supplements including any guidelines and clarifying materials published by the Swiss Federal Data Protection and Information Commissioner (FDPIC).
- “GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
- “Member State(s)” means a country that belongs to the European Union and/or the EEA.
- “Personal Data” means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier or such equivalent term under Data Protection Laws.
- “Process(ing)” means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- “Processor” or “Service Provider,” as relevant under applicable Data Protection Laws, means the entity which Processes Personal Data on behalf of the Controller or Business or such equivalent term under Data Protection Laws.
- “Relevant Amendments” means the amendments to the SCC, the UK Addendum, and the Swiss Addendum identified under Schedule 2 (Standard Contractual Clauses).
- “Standard Contractual Clauses” or “SCC” means the “standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council adopted by the European Commission decision of 4 June 2021” and published under document number C (2021) 3972 available at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0914&qid=1689513765256, in all cases incorporating the Relevant Amendments. Upon the effective date of adoption for any revised standard contractual clauses by the European Commission, all references in this DPA to the “SCCs” shall refer to that latest version and the parties shall cooperate to prepare such amendments to this DPA, including the Relevant Amendments, as may be required to take into account and give effect to the European Commission’s adoption of the revised standard contractual clauses. In the event of any conflict or inconsistency between the terms of this DPA and the provisions of the SCC (to the extent the latter has been entered into by the parties), the provisions of the SCC shall prevail.
- “Sub-Processor” means any Processor or Service Provider engaged by Intezer and/or Intezer Affiliate to Process Customer Personal Data.
- “Supervisory Authority” means the competent supervisory authority pursuant to the applicable Data Protection Laws.
- “Swiss Addendum” means the applicable standard data protection clauses issued, approved or recognized by the Swiss Federal Data Protection and Information Commissioner, specifically the FADP. Upon publication in the Federal Gazette and the entry into force of the revised FADP, this term will refer to the latter act (in force, August 27th, 2021).
- “Third Country” has the meaning given in Clause 8.2 below.
- “UK Addendum” means the International Data Transfer Addendum to the EU Commission standard contractual clauses issued by the UK Information Commissioner’s Office (version, B1.0, in force March 21st, 2022).
- “UK GDPR” means the GDPR as incorporated into United Kingdom domestic law pursuant to Section 3 of the European Union (Withdrawal) Act 2018.
- “US Privacy Laws” means the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended by the California Privacy Rights Act of 2020 along with any associated regulations (“CCPA”); the Virginia Consumer Data Protection Act (“VCDPA”); the Colorado Privacy Act; and any similar U.S. laws governing data privacy and security once effective.
2. CUSTOMER’S PROCESSING OF PERSONAL DATA
Customer shall, in its use of the Services, Process Customer Personal Data in accordance with the requirements of Data Protection Laws. For the avoidance of doubt, Customer’s instructions for the Processing of Customer Personal Data shall comply with Data Protection Laws. As between the Parties, Customer shall have sole responsibility for the means by which Customer acquired Customer Personal Data. Without limitation, to the extent applicable, Customer shall comply with any and all transparency-related obligations (including, without limitation, displaying any and all relevant and required privacy notices or policies) and shall have any and all required legal basis in order to collect, Process, and transfer to Intezer the Customer Personal Data and to authorize the Processing by Intezer of the Customer Personal Data which is authorized in this DPA.
3. INTEZER’S PROCESSING OF PERSONAL DATA
3.1 Application. As used in Clauses 3 – 9 herein, Customer Personal Data refers to Customer Personal Data that is subject to Data Protection Laws.
3.2 Roles of the Parties. The Parties acknowledge and agree that with regard to the Processing of Customer Personal Data: (a) Customer is the Controller or Business or, where Customer is acting behalf of its own customers, a Processor; (b) Intezer is the Processor or Service Provider; and (c) Intezer or its Affiliates may engage Sub-Processors pursuant to the requirements set forth in Clause 6 below.
3.3 Intezer and its Affiliates (as applicable) shall Process Customer Personal Data only in accordance with Customer’s documented instructions, which are set out in the Agreement, as necessary for the performance of the Services and for the performance of the Agreement and this DPA, unless required to otherwise by any applicable law, court of competent jurisdiction, or other Supervisory Authority to which Intezer and its Affiliates are subject, in which case, Intezer shall inform Customer of the legal requirement before Processing, unless that law prohibits such information. Customer agrees that the Agreement is Customer’s complete and final instruction to Intezer in relation to the Processing of Personal Data. Processing any Personal Data outside the scope of the Agreement will require prior written agreement between Intezer and Customer by way of an amendment to the Agreement and may include any additional fees that may be payable by Customer to Intezer for carrying out such instructions. The duration of the Processing, the nature and purposes of the Processing, as well as the types of Customer Personal Data Processed and categories of Data Subjects under this DPA are further specified in Schedule 1 to this DPA.
3.4 To the extent that Intezer or its Affiliates cannot comply with an instruction from Customer and/or its Authorized Users relating to Processing of Customer Personal Data or where Intezer considers such instruction to be unlawful, Intezer (a) shall inform Customer, providing relevant details of the problem; (b) may, without any kind of liability towards Customer, temporarily cease all Processing of the affected Customer Personal Data (other than securely storing those data); and (c) if the Parties do not agree on a resolution to the issue in question and the costs thereof, each Party may, as its sole remedy, terminate the Agreement and this DPA with respect to the affected Processing, and Customer shall pay to Intezer all the amounts owed to Intezer or due before the date of termination.
3.5 Without derogating from any other provision of the Agreement, and in the event that the Customer Personal Data includes, any Personal Data which is not expressly identified under Schedule 1 (collectively, “Excess Personal Data”), Customer and not Intezer, shall be fully responsible for any use, processing, editing, hosting, transferring, storing, reproducing, modifying of such Excess Personal Data, and Customer hereby represents that Customer has provided sufficient notices and obtained necessary or advisable consents required from any third-party and otherwise has the lawful basis upon which to share the Excess Personal Data, included therein with Intezer and its Affiliates, and to make any and all uses as otherwise contemplated under the Agreement.
4. RIGHTS OF DATA SUBJECTS
Customer shall be solely responsible for compliance with any statutory obligations concerning requests to exercise Data Subject rights under Data Protection Laws (e.g., for access, rectification, deletion of Customer Personal Data, etc.). If Intezer receives a request from a Data Subject to exercise its rights under Data Protection Laws (“Data Subject Request”), Intezer shall, to the extent legally permitted, promptly notify and forward such Data Subject Request to Customer. Taking into account the nature of the Processing, Intezer shall use commercially reasonable efforts to assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Customer’s obligation to respond to a Data Subject Request under Data Protection Laws.
5. INTEZER PERSONNEL
5.1 Intezer shall take reasonable steps to ensure that access to the Customer Personal Data is limited to persons under its authority (including, without limitation, its personnel) only on a need-to-know basis and ensure that such persons engaged in the Processing of Customer Personal Data have committed themselves to confidentiality.
6. AUTHORIZATION REGARDING SUB-PROCESSORS
6.1 Customer hereby grants general written authorization to Intezer to appoint Sub-Processors to perform specific Processing activities on Customer Personal Data on its behalf. Intezer’s current list of Sub-Processors is included in Schedule 3 to this DPA (“Sub-Processor List”) and is hereby approved by Customer.
6.2 Objection Right for Sub-Processors. Intezer may appoint new Sub-Processors and shall give notice (for instance by e-mail or prominent service notice) of the appointment of any new Sub-Processor expected to have access to and a material impact on the Processing of Customer Personal Data, whether by general or specific reference to such Sub-Processor (e.g., by name or type of service), including relevant details of the Processing to be undertaken by the new Sub-Processor. In the event Customer reasonably objects to a Sub-Processor by notifying Intezer in writing within seven (7) days after receipt of Intezer’s notice including the reasons for objecting to Intezer’s use of such Sub-Processor, Intezer will use commercially reasonable efforts to make available to Customer a change in the Services to avoid Processing of Customer Personal Data by the objected-to Sub-Processor without unreasonably burdening Customer. Where such steps are not sufficient to relieve Customer’s reasonable objections then Customer or Intezer may, by written notice to the other Party, with immediate effect, terminate the Agreement to the extent that it relates to the Services which require the use of the proposed Sub-Processor without bearing liability for such termination. Otherwise, Customer shall be deemed to have accepted such appointment. Until a decision is made regarding the Sub-Processor, Intezer may temporarily suspend the Processing of the affected Customer Personal Data.
6.3 With respect to each new Sub-Processor, Intezer shall: (i) take reasonable steps before the Sub-Processor first Processes Customer Personal Data, to ensure that the Sub-Processor is committed to provide the level of protection for Customer Personal Data required by the Agreement; (ii) ensure that the arrangement between Intezer and the Sub-Processor is governed by a written contract, including terms which offer a materially similar level of protection for Customer Personal Data as those set out in this DPA and meet the requirements of Data Protection Laws; and (iii) remain fully liable to Customer for the performance of any and all Processing of Customer Personal Data performed by Sub-Processor in connection with the specific Processing activities performed by Sub-Processor on behalf of Customer.
7. SECURITY
7.1 Controls for the Protection of Customer Personal Data. Taking into account the state of the art, Intezer shall maintain industry-standard technical and organizational measures, including as required pursuant to Article 32 of the GDPR and other applicable Data Protection Laws, for protection of the security (including protection against unauthorized or unlawful Processing and against accidental or unlawful destruction, loss or alteration or damage, unauthorized disclosure of, or access to, Customer Personal Data), confidentiality and integrity of Customer Personal Data, as set forth in the Agreement and as identified under Schedule 4 to this DPA (Technical and Organizational Measures). Upon Customer’s request, Intezer will use commercially reasonable efforts to assist Customer in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR and other applicable Data Protection Laws, taking into account the nature of the processing, the state of the art, the costs of implementation, the scope, the context, the purposes of the Processing, and the information available to Intezer.
7.2 Third-Party Certifications and Audits. Upon Customer’s written request at reasonable intervals, and subject to the confidentiality obligations set forth in the Agreement, Intezer shall make available to Customer (or Customer’s independent, third-party auditor that is not reasonably objected to by Intezer and bound by confidentiality obligations) a copy of Intezer’s then most recent third-party audits or certifications, as applicable (provided, however, that any such documentation shall be Intezer’s Confidential Information and shall only be used by Customer to assess compliance with this DPA, and shall not be used for any other purpose or disclosed to any third party without Intezer’s prior written approval and, upon Intezer’s request, Customer shall return all such documentation in Customer’s possession or control). Only as required by applicable Data Protection Laws and at Customer’s cost and expense, not more than once per year, Intezer shall allow for and contribute to audits, including remote inspections, conducted by Customer (or Customer’s independent, third-party auditor that is not reasonably objected to by Intezer and that is bound by confidentiality obligations) provided that the Parties shall agree on the scope, methodology, timing, and conditions of such audits and inspections in advance. Notwithstanding anything to the contrary, such audits and/or inspections shall not contain any information, including without limitation, Personal Data that belongs to Intezer’s other customers.
8. TRANSFERS OF DATA
8.1 Transfers to countries that offer adequate level of data protection. Personal Data may be transferred from the Extended EEA Countries to countries or frameworks that offer adequate level of data protection (e.g Canada, Israel, Switzerland) under or pursuant to the adequacy decisions published by the relevant data protection authorities of the Extended EEA Countries (“Adequacy Decisions”), without any further safeguard being necessary.
8.2 Transfers to other countries. If, and to the extent, the Processing of Customer Personal Data which is subject to Data Protection Laws of the Extended EEA Countries includes transfers by Customer from the Extended EEA Countries to Intezer in countries outside the Extended EEA Countries which have not been subject to an Adequacy Decision (“Third Countries”), the Parties agree that such transfers shall be undertaken on the basis of the Standard Contractual Clauses, which will be deemed to have been signed by each Party on the Effective Date of this Agreement, are incorporated herein by reference and construed in accordance with Schedule 2 below, unless another mechanism provided for in the Data Protection Laws of the applicable Extended EEA Country applies.
8.3 In the event Customer enables third party services through integrations available on the Services which involve transfers of Customer Personal Data between Intezer and the third party services provider, Customer acknowledges and agrees that (a) such third party providers are not Sub-Processors of Intezer; (b) such transfers are conducted at Customer’s instruction in accordance with an agreement between the Customer and such third party provider (which Intezer is not a party to); and (c) Customer shall be solely responsible for such transfers and their compliance with Data Protection Laws, including without limitation, executing Standard Contractual Clauses with such third party providers as required.
9. US PRIVACY LAWS
9.1 In performing its obligations under the Agreement and this DPA, Intezer shall comply with its applicable obligations under US Privacy Laws, including by providing the level of privacy protection as is required by applicable US Privacy Laws to Customer Personal Data subject to the US Privacy Laws. Intezer will not: (a) “sell” or “share” for purposes of “cross-context behavioral advertising” or “targeted advertising” (as defined by applicable US Privacy Laws) any Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the contractual business purpose set forth herein and in the Agreement or as otherwise permitted under US Privacy Laws or outside of the direct business relationship between Intezer and Customer; or (c) attempt to re-identify any pseudonymized, anonymized, aggregate, or de-identified Customer Personal Data.
9.2 Intezer will (a) comply with any applicable restrictions under applicable US Privacy Laws on combining Customer Personal Data with Personal Data that Intezer receives from, or on behalf of, another person or persons; and (b) promptly notify Customer if Intezer determines that it (i) can no longer meet its obligations under this DPA or applicable US Privacy Laws; or (ii) in Intezer’s opinion, an instruction from Customer infringes applicable US Privacy Laws.
9.3 To the extent required under US Privacy Laws, Customer may take reasonable and appropriate steps to help to ensure that Intezer uses Customer Personal Data in a manner consistent with Customer’s obligations under US Privacy Laws and to stop and remediate unauthorized use of the Customer Personal Data.
9.4 Intezer certifies that it understands its obligations in this Clause 9. The Parties agree that Schedule 1 hereto shall satisfy any requirement under applicable U.S. Privacy Law to provide details regarding the nature of the Processing activities related to Customer Personal Data.
10. PERSONAL DATA INCIDENT MANAGEMENT AND NOTIFICATION
To the extent required under applicable Data Protection Laws, Intezer shall notify Customer without undue delay after having actual knowledge of the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data (a “Personal Data Incident”). Intezer shall make reasonable efforts to identify the cause of such Personal Data Incident and take those steps as Intezer deems necessary, possible, and reasonable under the circumstances in order to remediate the cause of such a Personal Data Incident. Customer (or its customers), as the Controller or Business, will be the party responsible for notifying Supervisory Authorities and/or concerned Data Subjects (where required by Data Protection Laws).
11. RETURN AND DELETION OF PERSONAL DATA
Subject to the Agreement, upon termination or expiry of the Services, Intezer shall, make available for return the Customer Personal Data via the Services and delete such Customer Personal Data in accordance with Intezer’s customer data retention & deletion policy unless applicable law requires storage of the Customer Personal Data. In any event, Customer agrees that Intezer may retain Customer Personal Data in accordance with its standard backup policy, for evidence purposes and/or for the establishment, exercise or defense of legal claims and/or to comply with applicable laws and regulations. Notwithstanding anything to the contrary, Customer hereby agrees and understands that, to the extent Intezer performs cloud scanning on behalf of Customer, if and when Customer wants to delete specific Customer Personal Data, Customer may delete such Customer Personal Data from its own databases, and it will automatically be erased from Intezer’s databases within a reasonable market standard timeframe. If Customer requests return of the Customer Personal Data, it shall be returned in an industry standard format generally available for Intezer’s customers.
12. TERMINATION
This DPA shall automatically terminate upon the termination or expiration of the Agreement under which the Services are provided, provided that, to the extent Intezer retains any Customer Personal Data following termination or expiration of the Agreement, this DPA shall survive for such period that Intezer retains Customer Personal Data. All clauses that by their nature are intended to survive termination or expiration shall survive the termination or expiration of this DPA for any reason. This DPA cannot, in principle, be terminated separately to the Agreement, except where the Processing ends before the termination of the Agreement, in which case, this DPA shall automatically terminate.
13. RELATIONSHIP WITH AGREEMENT
Subject to any provisions in Schedule 2 regarding governing law and choice of forum of the Standard Contractual Clauses, the governing law and choice of forum provision in the Agreement shall apply to this DPA. In the event of any conflict between the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA shall prevail over the conflicting provisions of the Agreement.
14. AFFILIATES
Any Intezer obligation hereunder may be performed (in whole or in part), and any Intezer right (including invoice and payment rights) or remedy may be exercised (in whole or in part), by an Affiliate of Intezer. To the extent that any of Customer’s Affiliate(s): (a) is subject to the Data Protection Laws; (b) provides Customer Personal Data to Intezer in the context of the Services; and (c) is permitted to use the Services pursuant to the Agreement but has not signed its own agreement with Intezer and is not a “Customer” as defined under the Agreement, the Parties acknowledge and agree that, by executing the Agreement, Customer enters into this DPA on behalf of itself and, in the name and on behalf of such Affiliates, subject to the following: (i) each Affiliate agrees to be bound by the obligations under this DPA and any violation of this DPA by an Affiliate shall be deemed a violation by Customer; (ii) Customer shall remain exclusively responsible for coordinating all communication with Intezer under the Agreement and shall be entitled to make and receive any communication in relation to this DPA on behalf of its Affiliates; and (iii) Affiliates shall not be entitled to bring a claim directly against Intezer. If an Affiliate seeks to assert a legal demand, action, suit, claim, proceeding or other forms of complaints or proceedings against Intezer (“Affiliate Claim”): (1) Customer must bring such Affiliate Claim directly against Intezer on behalf of such Affiliate, unless Data Protection Laws require the Affiliate be a party to such claim; and (2) all Affiliate Claims shall be considered claims made by Customer and shall be subject to the limitation of liability set forth in the Agreement.
15. CHANGES IN LAWS
Customer may by at least forty-five (45) calendar days’ prior written notice to Intezer, request in writing any variations to this DPA if they are required, as a result of any change in, or decision of a competent authority under any applicable Data Protection Law, to allow Processing of those Customer Personal Data to be made (or continue to be made) without breach of that Data Protection Law. If Customer gives notice with respect to its request to modify this DPA under this Section, Intezer shall make commercially reasonable efforts to accommodate such modification request; and Customer shall not unreasonably withhold or delay agreement to any consequential variations to this DPA proposed by Intezer to protect the Intezer against additional risks, or to indemnify and compensate Intezer for any further steps and costs associated with the variations made herein. If Customer gives notice under this Section 15 the Parties shall promptly discuss the proposed variations and negotiate in good faith with a view to agreeing and implementing those or alternative variations designed to address the requirements identified in Customer’s notice as soon as is reasonably practicable. In the event that the Parties are unable to reach such an agreement within thirty (30) days, then Customer or Intezer may, by written notice to the other Party, with immediate effect, terminate the Agreement to the extent that it relates to the Services which are affected by the proposed variations (or lack thereof).
List of Schedules
- SCHEDULE 1 – DETAILS OF THE PROCESSING
- SCHEDULE 2 – STANDARD CONTRACTUAL CLAUSES
- SCHEDULE 3 – LIST OF AUTHORIZED SUB-PROCESSORS
- SCHEDULE 4 - TECHNICAL AND ORGANIZATIONAL MEASURES
Schedule 1 – DETAILS OF THE PROCESSING
Details of Processing of Customer Personal Data
| Data Exporter | Data Importer |
| Name: The Customer identified in the Agreement | Name: Intezer Labs Ltd. |
| Role: Processor and/or Controller | Role: Processor |
1. Subject Matter and Duration of the Processing of Customer Personal Data. The subject matter and duration of the Processing of the Customer Personal Data are set out in the Agreement.
2. The nature and purpose of the Processing of Customer Personal Data: Performing the Agreement, this DPA and/or other contracts executed by the Parties, including, providing the Service(s) and support and technical maintenance to Customer and complying with documented reasonable instructions provided by Customer where such instructions are consistent with the terms of the Agreement. The nature of the Processing includes the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, or restricting, erasing or destroying data (whether or not by automated means).
The types of Customer Personal Data to be Processed are as follows:
1. Customer business contact information / employee contact information of Customer’s personnel necessary for the management of the business relationship;
2. Personal Data as may be transmitted in logs;
3. If Customer uses Intezer for scanning documents or other materials, Personal Data might be temporarily processed by Intezer during such scanning. The types of Personal Data depend on the Customer environment and which sources Customer connects to the Services.
4. Intezer may process metadata such as CVEs, misconfigurations, list of installed packages, cloud events, local cloud user accounts, cloud object identifiers and (depending on the features used by Customer) logs and file paths. Depending on the Customer’s environment and naming conventions and features used by Customer, some limited Personal Data may be included in the metadata findings. For example, cloud user account names, logs and artifacts could include an individual’s name, associated email address, professional phone number, or IP address as well as information about device and operating system and (if specific Intezer features are enabled) pseudonymized samples of findings to enable Customer to locate, verify, and remediate the finding(s).
Special Categories of Personal Data are as follows: Not Applicable / Not required.
The categories of Data Subjects to whom the Customer Personal Data relates to are as follows: Personnel on behalf of a Customer who uses the Services. As part of providing the Services, Intezer may process Personal Data related to Customer’s customers or users, leads, employees, and service providers, the extent of which is solely determined by Customer through the use of the Services.
The obligations and rights of Customer are as follows: The obligations and rights of Customer and Customer Affiliates are set out in the Principal Agreement and this DPA.
| Data Exporter: | Customer. |
| Data Importer: | Intezer Labs: Asher-Tsvi Schwed legal@Intezer.com |
| Categories of data subjects whose personal data is transferred: | See Schedule 1 |
| Categories of personal data transferred: | See Schedule 1 |
| Special categories of personal data (if applicable): | See Schedule 1 |
| The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis): | The Processing is continuous for the duration of the Principal Agreement. |
| Nature of the Processing: | The nature and purpose of Processing of Personal Data for the Controller are defined in the Principal Agreement. |
| Purpose(s) of the data transfer and further processing: | The nature and purpose of Processing of Personal Data for the Controller are defined in the Principal Agreement. |
| The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: | The personal data will be Processed in accordance with this DPA. |
| Competent supervisory authority: | Irish Data Protection Commission |
| Technical and organizational measures (only for MODULE TWO and MODULE THREE): | See Schedule 4 for technical and organizational measures implemented by the data importer. |
| List of sub-processors (only for MODULE TWO and MODULE THREE): | See Schedule 3 below. |
Schedule 2 – STANDARD CONTRACTUAL CLAUSES
1. Incorporation and interpretation of the Standard Contractual Clauses
1.1 In relation to transfers by Customer of Customer Personal Data which are subject to Data Protection Laws of the Extended EEA Countries to Intezer in Third Countries, the Parties agree that Module Two (Transfer controller to processor) or Module 3 (Transfer processor to processor) of the Standard Contractual Clauses shall apply, as applicable.
1.2 The Parties acknowledge that the information required to be provided in the Standard Contractual Clauses, including the appendices, is set out in Appendix 1 below.
1.3 If there is a conflict between the provisions of this Agreement and the Standard Contractual Clauses, the Standard Contractual Clauses will prevail, provided that, except to the extent prohibited by applicable law, the Standard Contractual Clauses shall be interpreted in accordance with and subject to this DPA and the Agreement, including without limitation, the provisions on limitation of liability, instructions, storage, erasure and return of Personal Data, audits and engagement of Sub-Processors.
1.4 If any provision or part-provision of this DPA or the Agreement causes the Standard Contractual Clauses to become an invalid export mechanism in the relevant Extended EEA Country, it shall be deemed deleted but that shall not affect the validity and enforceability of the rest of this Agreement and the parties shall negotiate in good faith to agree a replacement provision that, to the greatest extent possible, achieves the intended commercial result of the original provision.
1.5 Where requested by Intezer, Customer shall provide reasonable assistance to Intezer and be responsible for issuing such communications to Data Subjects and/or the Controller (to the extent Module Three applies) as are required in order for Intezer to comply with its obligations under the Standard Contractual Clauses.
1.6 For the purpose of Section III, Clause 14 of the Standard Contractual Clauses, the Parties acknowledge and agree that, as between the Parties, the Customer (acting as data exporter) is responsible for: (a) assessing the laws of the country to which it transfers Personal Data; and (b) determining whether or not the transfer meets the requirements of Section III, Clause 14(a) of the Standard Contractual Clauses. Where Intezer (as data importer) provides information to the Customer (acting as data exporter) for assisting the Customer in its assessment, such information is provided on an “as is” basis for informational purposes only. Without prejudice to Section III, Clause 14(c) of the Standard Contractual Clauses, Intezer (as data importer) shall not be liable for any losses suffered by the Customer in connection with its assessment.
1.7 Notwithstanding anything to the contrary, where the applicable Extended EEA Country where the data exporter is established or from where the transferred personal data originated is the UK, template Addendum B.1.0 issued by the UK ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses, (the “UK Approved Addendum”) shall amend the Standard Contractual Clauses in respect of such transfers and Part 1 of the UK Approved Addendum shall be populated as set out below:
Table 1. The “start date” will be the date this DPA enters into force. The “Parties” are Customer as exporter Intezer as importer.
Table 2. The “Addendum EU SCCs” are the modules and clauses of the Standard Contractual Clauses selected in relation to a particular transfer in accordance with paragraphs 1.1 and 1.2 of this Schedule.
Table 3. The “Appendix Information” is as set out in Appendix 1 to this Schedule.
Table 4. Neither party may end the UK Approved Addendum in accordance with its Section 19.
1.8 Except where paragraph 1.7 above applies, but notwithstanding anything else to the contrary, where the applicable Extended EEA Country where the data exporter is established or from where the transferred personal data originated is not a Member State of the European Union, references in the Standard Contractual Clauses to:
(a) “Member States of the European Union” shall refer to the applicable Extended EEA Country in which the data exporter is established or from where the transferred Personal Data originated (as applicable);
(b) “the GDPR” shall refer to the Data Protection Laws of the Extended EEA Country in which the data exporter is established or from where the Personal Data originated; and
(c) “supervisory authority” shall refer to the data protection authority in the Extended EEA Country as determined in Annex I(C) below.
Appendix 1 – Completion of the Standard Contractual Clauses
| A. LIST OF THE PARTIES | |
| Data Exporter: | Name and address: Customer, as set out in the Agreement / Order Contact details: As set out in the Agreement / Order Activities relevant to the data transferred under these Clauses: Receipt of Intezer Services, as set out in the Agreement and this DPA |
| Data Importer: | Name and address: Intezer, as set out in the Agreement / Order Contact details: Privacy Officer, Asher-Tsvi Schwed ats@Intezer.com Activities relevant to the data transferred under these Clauses: Provision of Intezer Services, as set out in the Agreement and this DPA |
| B. DETAILS OF PROCESSING/TRANSFER | |
| CATEGORIES OF DATA SUBJECTS | As described in Schedule 1 |
| CATEGORIES OF PERSONAL DATA | As described in Schedule 1 |
| SPECIAL CATEGORIES OF DATA (IF APPLICABLE) | Not applicable. Intezer does not control which Personal Data Customer shares with it in the context of the Services. Special Category data are not required for use of the Services. If Customer uses Intezer’s features specifically designed to scan data stores via a SaaS deployment, Intezer will temporarily Process any Special Category data included within the data source(s) that Customer connects for scanning. |
| FREQUENCY OF THE TRANSFER | As regular as is required to provide the Services |
| NATURE AND PURPOSE OF THE PROCESSING | As described in Schedule 1 |
| RETENTION | As described in Schedule 1 |
| TRANSFER TO (SUB)PROCESSORS | As set out in Intezer’s Sub-Processor List |
| C. COMPETENT SUPERVISORY AUTHORITY | |
| The competent supervisory authority shall be determined in accordance with Clause 13 of the Standard Contractual Clauses. Where an EU Representative has not been appointed by data exporter, the competent supervisory authority shall be the supervisory authority of Ireland. | |
| D. GOVERNING LAW AND CHOICE OF FORUM | |
| GOVERNING LAW | For the purposes of Clause 17 of the Standard Contractual Clauses the Parties select OPTION 1: the law of Ireland. |
| CHOICE OF FORUM | For the purposes of Clause 18 of the SCCs: the Parties select the courts of Ireland. |
| E. OTHER | |
Where the Standard Contractual Clauses identify optional provisions (or provisions with multiple options) the following will apply:
☒ MODULE TWO: Transfer controller to processor ☒ MODULE THREE: Transfer processor to processor | |
UK Addendum
| Start date | The execution date of the DPA |
| Addendum EU SCCs | The UK Addendum is appended to the Standard Contractual Clauses incorporated by the DPA, as modified. |
| List of Parties | Data Exporter: See Appendix 1 Data Importer: See Appendix 1 |
| Description of Transfer | See Appendix 1 |
| Technical and Organizational Measures | See Schedule 4 below |
| List of Sub processors | See Schedule 3 below |
| Ending the UK Addendum when the Approved UK Addendum changes | Neither of the Parties may end the UK Addendum. |
The Parties agree that the UK Addendum is appended to the Standard Contractual Clauses as modified (including the selection of modules and disapplication of optional clauses) by Appendix 1.
Swiss Addendum
Insofar as the data transfer under the DPA is governed by the FADP, provided that none of these amendments will have the effect or be construed to amend the Standard Contractual Clauses in relation to the processing of Personal Data under the GDPR, the following shall apply:
1. the Swiss Federal Data Protection and Information Commissioner (the “FDPIC”) will be the competent supervisory authority, in Annex I.C under Clause 13 of the Swiss Addendum;
2. the applicable law for contractual claims and place of jurisdiction for actions between the parties under Clauses 17 and 18 of the Standard Contractual Clauses shall be as set forth in the Standard Contractual Clauses, provided that the term “member state” must not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18c;
3. references to the “GDPR” should be understood as references to the “FADP;” and
4. where the FADP protects legal entities as data subjects, the Swiss Addendum will apply to data relating to identified or identifiable legal entities.
| Start date | The execution date of the DPA |
| Addendum EU SCCs | The Swiss Addendum is appended to the EU Standard Contractual Clauses incorporated by Section 13.4 of the DPA as modified by Section A of Exhibit 3. |
| List of Parties | Data Exporter: See Appendix 1 Data Importer: See Appendix 1 |
| Description of Transfer | See Appendix 1 |
| Technical and Organizational Measures | See Schedule 4 below |
| List of Sub Processors | See Schedule 3 below |
The Parties agree that the Swiss Addendum is appended to the EU Standard Contractual Clauses as modified by Appendix 1.
Schedule 3 – List of Authorized Sub Processors
Can be found at https://trust.intezer.com
Schedule 4 – Technical and Organizational Measures
Intezer’s technical and organizational measures (TOMs) provided below apply to all standard service offerings provided by Intezer to Customer intended to ensure the confidentiality, integrity and availability of Personal Data, and protect against any reasonably anticipated threats or hazards to the confidentiality, integrity and availability of Personal Data. Intezer's Information Security Program shall include, but not be limited to, the following safeguards where appropriate or necessary to ensure the protection of Personal Data:
(i) Access Controls – policies, procedures and physical and technical controls: (i) to ensure that all members of its workforce who require access to Personal Data have appropriately controlled access, and to prevent those workforce members and others who should not have access from obtaining access; (ii) to authenticate and permit access only to authorized individuals and to prevent members of its workforce from providing Personal Data or information relating thereto to unauthorized individuals; and (iii) to encrypt and decrypt Personal Data where appropriate.
(ii) Security Awareness and Training – a security awareness and training program for all members of Intezer's workforce (including management and contractors), which includes training on how to implement and comply with its Information Security Program.
(iii) Security Incident Procedures – policies and procedures to detect, respond to and otherwise address security incidents, including procedures to monitor systems and to detect actual and attempted attacks on or intrusions into Personal Data or information systems relating thereto, and procedures to identify and respond to suspected or known security incidents, mitigate harmful effects of security incidents, and document security incidents and their outcomes.
(iv) Contingency Planning – policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system failure and natural disaster) that damages Personal Data or systems that contain Personal Data, including a data backup plan and a disaster recovery plan.
(vi) Audit Controls – hardware, software and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic information, including appropriate logs and reports concerning these security requirements and compliance therewith.
(vii) Data Integrity – policies and procedures to ensure the confidentiality, integrity and availability of Personal Data and protect it from disclosure, improper alteration or destruction.
(viii) Storage and Transmission Security – technical security measures to guard against unauthorized access to Personal Data that is being transmitted over an electronic communications network, including a mechanism to encrypt electronic information whenever appropriate, such as while in transit or in storage on networks or systems to which unauthorized individuals may have access.
(ix) Secure Disposal – policies and procedures regarding the disposal of Personal Data, and tangible property containing Personal Data, taking into account available technology so that Personal Data cannot be practicably read or reconstructed.
(x) Assigned Security Responsibility – Intezer shall designate a security official responsible for the development, implementation and maintenance of its Information Security Program. Intezer shall inform Data Controller as to the person responsible for security.
(xi) Adjust the Program – Intezer shall monitor, evaluate and adjust, as appropriate, the Information Security Program in light of any relevant changes in technology or industry security standards, the sensitivity of Personal Data, internal or external threats to Intezer or Personal Data, requirements of applicable work orders, and Intezer's own changing business arrangements, such as mergers and acquisitions, alliances and joint ventures, outsourcing arrangements and changes to information systems.
See a live demo
Ready to dive deeper into Intezer’s extensive capabilities? Reach out to us to book a live demo and consultation to understand how Intezer could support your team.

