Certivo Legal

SaaS Agreement and Data Processing Addendum

Version 3.0 Effective September 2, 2026 Applies to customers who sign a Service Order or Statement of Work that references this Agreement All legal documents Download PDF

How this Agreement applies. This SaaS Agreement, including Exhibit A (Service Level Addendum) and Exhibit B (Data Processing Addendum), is incorporated by reference into every Certivo Service Order and Statement of Work that cites this page. Signing that Service Order or Statement of Work constitutes acceptance of this Agreement. Where a signed Service Order or Statement of Work conflicts with this Agreement, the signed document controls for commercial terms, and Exhibit B controls for data protection matters.

Relationship to the website Terms of Service. Customers with a signed Service Order, Statement of Work, or SaaS Agreement are governed by this Agreement, not the click-through Terms of Service. The Terms of Service apply only to trial, self-serve, and unsigned use of Certivo.

Prior versions. Customers who signed an earlier version of this Agreement remain governed by that version until renewal, unless both parties agree otherwise in writing. Prior versions are available on request at legal@certivo.com.

SaaS Agreement

This SaaS Agreement (the “Agreement”) is between Certivo, Inc. (“Certivo”) and the customer identified on the Service Order or Statement of Work that references this Agreement (“Client” and together with Certivo, the “Parties”, and each a “Party”), dated and effective as of the Effective Date.

1. Definitions

The following capitalized terms used in this Agreement have the following meanings:

"Affiliate(s)" means those entities that are directly or indirectly controlled by, control, or are under common control with a Party. The term “control” (in this context) means the possession, directly or indirectly, of the power to direct or cause the direction of the management and operating policies of the entity in respect of which the determination is being made through the ownership of the majority of its voting or equity securities, contract, or otherwise.

"Agreement" means this SaaS Agreement between Certivo and Client, and (unless referenced as separate from the foregoing) all SOWs effected hereunder.

"AI Client Input" means information, data, materials, text, prompts, images, or other content that is (a) input, entered, posted, uploaded, submitted, transferred, transmitted, or otherwise provided or made available by or on behalf of Client for processing by or through the Services, or (b) collected, downloaded, or otherwise received by the Services for or on behalf of Client, including in the case of (a) and (b) for purposes of fine-tuning, grounding, or otherwise modifying, refining, adapting, or customizing the Services by, for, or on behalf of Client.

"AI Client Output" means information, data, materials, text, images, code, works, expressions, or other content generated or otherwise output from the Services in response to AI Client Input or from use of the Services by or on behalf of Client.

"Applicable Law(s)" means applicable provisions of all laws, codes, statutes, regulations, ordinances, administrative rules, rules of court, and court orders which govern a Party’s operations.

"Certivo Data" means all content, information, and data that Certivo provides or makes available to Client through the Services, excluding Client Data.

"Claim(s)" means any and all notices, charges, claims, proceedings, actions, causes of action and suits brought by a third party.

"Client Data" means all content, information, and data that Client provides or makes available to Certivo under this Agreement.

"Data Protection Laws" means any Applicable Laws relating to the processing or protection of Client Data that is Personal Data, including without limitation, the California Consumer Privacy Act of 2018 (California Civil Code Sec. 1798.100 et seq) (“CCPA”), as amended by the California Privacy Rights Act of 2020 (“CPRA”), any other U.S. federal and state laws in effect as of the Effective Date of this Agreement, and Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (“GDPR”), as amended.

"Documentation" means any guides, manuals, instructions, FAQs, or similar materials related to the use of the Services that Certivo provides to Client.

"Effective Date" means the earlier of (a) the effective date specified in a SOW that has been accepted by both Parties (whether by signature, written confirmation, or issuance of an invoice by Certivo following Client’s written acceptance), or (b) the date that the Agreement is fully executed by both Parties.

"Implementation Services" means implementation, data migration, configuration, and other set-up Services to enable Client to use the Certivo platform, as specified in a SOW.

"Intellectual Property Rights" means copyrights, patents, patent disclosures and inventions (whether patentable or not), trademarks, service marks, trade secrets, know-how, trade dress, trade names, logos, corporate names and domain names, together with all of the goodwill associated therewith.

"Initial Term" means the initial period during which Client uses the Services under this Agreement.

"Personal Data" means “personal data” as defined under the GDPR; “personal information” as defined under the CCPA; and as similar terms, such as “personally identifiable information,” are defined under other applicable Data Protection Laws.

"SOW" means the statement of work, order form, or similar commercial document agreed between Certivo and Client (or a Client Affiliate, as applicable) that describes, as applicable, the scope of the Services to be provided by Certivo under this Agreement, the fees and expenses payable, timelines, term, and any additional terms. A SOW becomes effective upon acceptance by both parties to such SOW, whether by signature, countersigned email, electronic acceptance, or Certivo’s issuance of an invoice following written acceptance.

"Services" means those services set forth in a SOW to be provided by Certivo to Client in the form of an AI-powered agent and hosted business management solution, which permit Client to submit tasks, prompts, or other inputs to generate responsive outputs using artificial intelligence and integrations with third-party applications. All references to “Services” shall be read to include Implementation Services.

"Term" means the period during which this Agreement is effective, which starts on the Effective Date and continues until the date on which the subscriptions under all SOWs have expired or been terminated. The Term includes, as applicable, the Trial Term, the Initial Term, and each successive renewal period (each, a “Renewal Term”).

"Trial Term" means the period designated in a SOW, if any, during which Client is permitted to use the Services on a trial basis.

2. Services; Party Obligations

2.1 SOWs. Certivo grants Client a limited, non-exclusive, non-transferable, non-sublicensable, fully paid-up right and license, during the Term, to access and use the Services (including, to the extent applicable, Documentation, and Certivo Data that Certivo may make available to Client in connection with provision of the Services) for Client’s internal business purposes in accordance with the terms and conditions of this Agreement and any SOWs effected hereunder. SOWs are signed by the Parties (or, in the case of Client Affiliates, by such Affiliate and Certivo) as separate documents that reference this Agreement. All rights in the Services, Documentation, and Certivo Data not specifically granted to Client are reserved by Certivo. Changes to the scope of the Services or the assumptions upon which a SOW is based may require changes in the fees, expenses, timelines, or other terms, and will require a written amendment to the applicable SOW (“Change Order”). A Change Order will become effective only upon acceptance by authorized representatives of both Parties.

2.2 Client Obligations.

2.2.1 Without limiting its obligations as otherwise set forth in this Agreement, Client is responsible for securing, paying for, and maintaining (i) connectivity to Services from Client’s location(s) via the internet, including all related hardware, software, third party services, and related equipment and components for such connectivity, and (ii) all rights, consents, licenses, and permissions in the Client Data required by law to authorize the access, use, distribution, and processing thereof as contemplated by this Agreement.

2.2.2 Unless expressly set forth in a SOW, Client may not, and may not cause or permit others to: (a) reverse engineer, disassemble, adapt, translate, or decompile the Services, or otherwise attempt to derive source code, trade secrets, or know-how from the Services; (b) license, sell, lease, transfer, assign, distribute, or outsource use of the Services, or provide service bureau, data processing, or time sharing access to the Services; (c) license, sell, lease, transfer, assign, or distribute Certivo Data to a third party; (d) access or use the Services to build or support, directly or indirectly, products or services competitive to Certivo; (e) interfere with or disrupt the integrity or performance of any Services or any data contained therein; (f) attempt to gain unauthorized access to the Services or its related data, systems, or networks; (g) use robots, spiders, or data mining or extraction tools or collect or process information from the Services or engage in any web scraping, screen scraping, or other similar practices to access the Services or any information or data accessible from or through the Services; or (h) remove or alter any proprietary notices or marks on the Services.

2.2.3 In order to access and use the Services, Client will need to register and create an account for the Certivo platform (“Account”). Certivo reserves the right to suspend or terminate Client’s Account if any information provided during the registration process or thereafter is or becomes inaccurate, false or misleading. Client is responsible for maintaining the confidentiality of Client’s Account, and for all activities that occur under Client’s Account, including those carried out by its authorized users. Client agrees to notify Certivo if any passwords are lost, stolen, or disclosed to an unauthorized third party, and of any unauthorized use of or access to the Services.

2.3 Service Levels. During the Term, Certivo shall make the Services available in accordance with the service levels set out in Exhibit A.

2.4 Insurance. Certivo will obtain and maintain commercial general liability insurance, on an occurrence basis, covering all operations by or on behalf of Certivo against bodily injury (including death) and property damage (including loss of use), including premises/operations, personal and advertising injury, products/completed operations, and contractual liability. This commercial general liability insurance will be in limits of liability of not less than $1,000,000 per occurrence, combined single limit for bodily injury and property damage, with a $1,000,000 general aggregate. Certivo will obtain and maintain a cybersecurity liability insurance policy with minimum limits of $1,000,000 per claim and $1,000,000 in aggregate. All policies required pursuant to this Agreement will be written by insurance companies licensed to issue policies in the state(s) where Services are being performed and that have an A.M. Best rating of no less than “A-”.

3. Fees and Expenses

3.1 Fees. As consideration for the provision of the Services, Client will pay the fees set out in each SOW on the timelines set forth therein. Except as expressly provided in this Agreement, payment obligations are non-cancellable and fees paid are non-refundable. Client may withhold from payment any and all payments of fees that Client disputes in good faith, pending resolution of such dispute, provided that Client: (a) timely renders all payments and amounts that are not in dispute; (b) notifies Certivo of the dispute prior to the due date for payment, specifying in such notice the amount in dispute and the reason for the dispute; (c) works with Certivo in good faith to promptly resolve the dispute; and (d) promptly pays any amount determined to be payable by resolution of the dispute.

3.2 Taxes. Client will be responsible for all taxes, duties and charges imposed by any federal, state or local governmental entity on any amounts payable by Client hereunder. To the extent Certivo is required to pay any such taxes, duties or charges in the course of providing the Services to Client, Client will reimburse Certivo for such payment. Notwithstanding the previous sentence, in no event will Client pay or be responsible for any taxes imposed on, or regarding, Certivo’s income, revenues, gross receipts, personnel, or real or personal property or other assets.

3.3 Late Payment. All payable amounts which are not timely paid hereunder will bear interest at the lesser of (a) the rate of 1.5% per month, and (b) the highest rate permissible under Applicable Laws, calculated daily and compounded monthly. Client will reimburse Certivo for all reasonable costs incurred in collecting any late payments, including, without limitation, reasonable attorneys’ fees. In addition to all other remedies available under this Agreement or at law (which Certivo does not waive by the exercise of any rights hereunder), if Client fails to pay any undisputed amounts when due hereunder and such failure continues for 5 days following written notice thereof, Certivo may suspend the provision of Services until such amounts are paid in full.

4. Ownership and Intellectual Property

4.1 Client Data. As between Client and Certivo, Client owns and will retain ownership of the entire right, title, and interest in and to Client Data, including all Intellectual Property Rights therein. Client grants to Certivo a limited, non-exclusive, non-transferable, non-sublicensable, fully paid-up right and license, during the term of the applicable SOW, to access, display, process, and use the Client Data for the purposes of providing the Services to Client and maintaining and improving the Services. All rights in the Client Data not specifically granted to Certivo are reserved by Client.

4.2 Certivo Materials. As between Certivo and Client, Certivo owns and will retain ownership of the entire right, title, and interest in and to the Documentation, Certivo Data, Services, and including all Intellectual Property Rights therein.

4.3 Feedback. Client has no obligation to provide any suggestion, enhancement request, recommendation, correction, or other feedback about the Services (“Feedback”). If Client elects to provide Feedback, Client grants to Certivo a worldwide, perpetual, irrevocable, royalty-free license to use, distribute, disclose, and make and incorporate into its products and services any such Feedback.

5. Data Security

5.1 Security. Certivo shall use commercially reasonable efforts to ensure that no computer viruses, malware or similar items are introduced into Client’s computing and network environment by the Services. Where the transfer of Personal Data from Client to Certivo becomes necessary for the performance of the services contemplated by this Agreement, the Parties agree to be bound by the Data Processing Addendum set forth in Exhibit B, which is incorporated by reference into this Agreement. Execution of this Agreement constitutes execution of the Data Processing Addendum.

5.2 License to Client Data. Subject to the terms and conditions of this Agreement, Client hereby grants Certivo a limited, royalty-free, fully paid-up, non-exclusive, non-sublicensable license to Process the Client Data to provide the Services as provided in this Agreement for so long as Client uploads or stores such Client Data for processing by the Services. For the avoidance of doubt, except as set forth in Section 5.3 of this Agreement, Certivo shall not use Client Data or any other Confidential Information of Client to train, retrain, tune, validate, modify, update, or otherwise improve the Services, or any other product or service.

5.3 Anonymization Exceptions. Notwithstanding anything to the contrary in this Agreement, Certivo may monitor Client’s use of the Services and collect and use usage data in an aggregate and anonymized manner to compile statistical and performance information related to the provision and operation of the Services, and may aggregate and anonymize AI Client Input and AI Client Output to train, retrain, tune, validate, modify, update, or otherwise improve the Services (collectively, “Aggregated Service Data”). For the avoidance of doubt, Aggregated Service Data shall not constitute Client Data or Client’s Confidential Information, provided that all such data is de-identified and aggregated in accordance with industry standards, does not contain any personal data subject to data privacy laws, and cannot reasonably be used to identify Client or its Confidential Information.

6. Confidentiality

6.1 Definition. Confidential Information is any non-public information relating to a Party that is disclosed pursuant to this Agreement, and which reasonably should be understood by the recipient of such information to be confidential because of (a) legends or other markings; (b) the circumstances of the disclosure; or (c) the nature of the information itself. Without limiting the foregoing, Client Data shall constitute the Confidential Information of Client and Certivo Data shall constitute Certivo’s Confidential Information.

6.2 Exceptions. Information will not be considered Confidential Information if the information was: (a) in the public domain without any breach of this Agreement; (b) disclosed to the receiving Party on a non-confidential basis from a source lawfully in possession of such Confidential Information and, to the knowledge of the receiving Party, is not prohibited from disclosing such Confidential Information to receiving Party; (c) released in writing from confidential treatment by disclosing Party; or (d) independently developed by the receiving Party without use of or reference to the Confidential Information of the Disclosing Party.

6.3 Nondisclosure, Protection, and Use. Except as expressly permitted in this section, neither Party will disclose the other Party’s Confidential Information to any third party. Each Party will secure and protect the Confidential Information of the other Party with a reasonable standard of care using precautions that are at least as stringent as it takes to protect its own Confidential Information of like nature, but no less than reasonable precautions. Each Party will only use the Confidential Information of the other Party as expressly permitted by or as required to exercise their rights, duties, and obligations under this Agreement. Each Party retains all ownership rights in and to its Confidential Information.

6.4 Disclosure Exceptions. Confidential Information may be shared with and disclosed to (a) any Affiliate, subcontractor, or other third party who has a need to know to enable the receiving Party to exercise its rights or perform its obligations in connection with this Agreement and have non-disclosure obligations at least as stringent as the confidentiality provisions of this Agreement that apply to the Confidential Information; or (b) any court or governmental agency of competent jurisdiction, pursuant to a subpoena, order, civil investigative demand or similar process with which the receiving Party is legally obligated to comply, and of which the receiving Party notifies disclosing Party as required by a legal process, including in connection with any proceeding to establish a Party’s rights or obligations under this Agreement (provided however that, when permitted by Applicable Law, a Party will give the other reasonable prior written notice so that the disclosing Party has an opportunity to contest any disclosure required by a legal process).

7. Representations and Warranties

7.1 Mutual. Each Party represents and warrants that: (a) it has the full right and authority to enter into this Agreement; and (b) the performance of its obligations under this Agreement shall not conflict with or result in a breach of any other agreement of such Party or any judgment, order, or decree by which such Party is bound.

7.2 Client’s Representations and Warranties. Client represents and warrants to Certivo that (i) the collection, use, and processing of the Client Data in accordance with this Agreement will not violate any law or rights of others; and (ii) Client will not, or allow a third party to, either (a) take any action, or (b) upload, download, post, submit or otherwise distribute or facilitate distribution of any content on or through the Services that contains any viruses, worms, time bombs, Trojan horses, malware, spyware, and other malicious code, files, scripts, agents or programs designed to damage, destroy, or alter any software, hardware or data stored therein or breach the security thereof.

7.3 Certivo’s Representations and Warranties. Certivo warrants that any Services provided hereunder will substantially conform with the applicable SOW and Documentation and that the functionality of the Services will not be materially diminished during the Term. If Certivo breaches the warranty described in this paragraph, as Client’s exclusive remedy and Certivo’s sole obligation, Certivo will, without additional cost to Client, make commercially reasonable efforts to remedy such breach. If Certivo cannot remedy the breach, then Client may terminate the affected Services in accordance with the Agreement. Client must report any non-conformance of the Services within thirty (30) days of its discovery and provide Certivo with reasonable information and assistance to enable Certivo to reproduce or verify the non-conforming aspect of the Services.

7.4 Disclaimer. TO THE EXTENT PERMITTED UNDER APPLICABLE LAWS, EACH PARTY DISCLAIMS ALL WARRANTIES NOT SET FORTH IN THIS AGREEMENT, EITHER EXPRESS OR IMPLIED, INCLUDING ALL WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING, USAGE, OR TRADE PRACTICE, IN CONNECTION WITH THIS AGREEMENT AND THE SERVICES. CERTIVO DOES NOT REPRESENT, WARRANT, OR COVENANT THAT THE SERVICES OR ANY OTHER PRODUCT OR SERVICE PROVIDED HEREUNDER WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE. THIS DISCLAIMER OF WARRANTY MAY NOT BE VALID IN SOME JURISDICTIONS AND CLIENT MAY HAVE WARRANTY RIGHTS UNDER LAW WHICH MAY NOT BE WAIVED OR DISCLAIMED. CERTAIN FEATURES OF THE SERVICES LEVERAGE STATE-OF-THE-ART LARGE LANGUAGE MODELS (LLMS) PROVIDED BY THIRD-PARTY SERVICE PROVIDERS. CERTIVO DOES NOT SCREEN, FILTER, OR OTHERWISE REVIEW INFORMATION, SERVICES, RESOURCES, CONTENT, OR OTHER DATA OR MATERIALS PROVIDED THROUGH THOSE LLMS. ANY RELIANCE ON THE SERVICES OR THE LLMS IS AT CLIENT’S OWN RISK. CLIENT ACKNOWLEDGES THAT, DUE TO THE NATURE OF THE SERVICES AND ARTIFICIAL INTELLIGENCE PLATFORMS GENERALLY, ANY OUTPUT GENERATED THROUGH CLIENT’S USE OF THE SERVICES’ AI FUNCTIONALITIES MAY NOT BE ORIGINAL OR UNIQUE, AND CLIENT IS SOLELY RESPONSIBLE FOR DETERMINING WHETHER ITS USE OF THE SERVICES AND CORRESPONDING OUTPUT IS APPROPRIATE FOR ITS PURPOSES.

8. Indemnification

8.1 By Certivo. Certivo will defend Client, its Affiliates, and their respective officers, directors, employees, agents and assigns (“Client Indemnitees”) against any Claim made or brought against any Client Indemnitee based upon or alleging that: (a) the Services or the Certivo Data infringes or misappropriates the Intellectual Property Rights of a third party; or (b) the Services or the Certivo Data violate Applicable Laws, including without limitation Data Protection Laws (“Claim against Client Indemnitees”). Certivo will indemnify Client Indemnitees for any damages, attorney fees, and costs finally awarded against Client Indemnitees as a result of, or for any amounts paid by Client Indemnitees under a court-approved settlement of a Claim against Client Indemnitees. Notwithstanding the foregoing, Certivo will have no liability or obligation to defend or indemnify Client to the extent the Claim Against Client Indemnitees is based on (i) use of the Services or Certivo Data in breach of this Agreement; or (ii) use, operation, or combination of the applicable Services or Certivo Data with programs, data, or materials not provided by Certivo if such infringement would have been avoided but for such use, operation or combination. If the use of the Services is, or Certivo believes is likely to be, alleged or held to infringe any third-party Intellectual Property Right, Certivo may, at its sole option and expense, (a) procure for Client the right to continue using the affected Services, (b) replace or modify the affected Services with functionally equivalent services so that they do not infringe, or, if either (a) or (b) is not commercially feasible, (c) terminate the Services and refund a pro-rata amount of the fees paid by Client for the affected Services for the remainder of the then-current term of the applicable SOW. The foregoing constitutes Certivo’s entire liability, and Client’s sole and exclusive remedy with respect to any Claims against Client Indemnitees.

8.2 By Client. Client will defend Certivo, its Affiliates, and their respective officers, directors, employees, agents and assigns (“Certivo Indemnitees”) against any Claim made or brought against any Certivo Indemnitee based upon or alleging that: (a) the Client Data infringes or misappropriates the Intellectual Property Rights of a third party; or (b) the Client Data violates Applicable Laws, including without limitation Data Protection Laws (“Claim against Certivo Indemnitees”). Client will indemnify Certivo Indemnitees for any damages, attorney fees, and costs finally awarded against Certivo Indemnitees as a result of, or for any amounts paid by Certivo Indemnitees under a court-approved settlement of a Claim against Certivo Indemnitees. Notwithstanding the foregoing, Client will have no liability or obligation to defend or indemnify Certivo to the extent the Claim Against Certivo Indemnitees is based on (i) use of the Client Data in breach of this Agreement; or (ii) use, operation, or combination of the Client Data with programs, data, or materials not provided by Client if such infringement would have been avoided but for such use, operation or combination. The foregoing constitutes Client’s entire liability, and Certivo’s sole and exclusive remedy with respect to any Claims against Certivo Indemnitees.

8.3 Indemnification Procedures. Any person or entity entitled to indemnification under this Section 8 will (a) give prompt written notice to the indemnifying Party of any Claim with respect to which it seeks indemnification (provided that any delay or failure to so notify the indemnifying Party will relieve the indemnifying Party of its obligations hereunder only to the extent that the indemnifying Party is materially prejudiced by reason of such delay or failure), (b) permit the indemnifying Party to assume control of the defense and settlement of the Claim (provided that the indemnifying Party may not settle any Claim unless the settlement unconditionally releases the indemnified Party of all liability), and (c) provide to the indemnifying Party all reasonable assistance, at the indemnifying Party’s expense. Any person or entity entitled to indemnification under this Section 8 will have the right to select and employ, at its expense, separate counsel of its choosing and to participate in (but not control) the defense of a Claim.

9. Limitations of Liability

9.1 Exclusion of Damages. IN NO EVENT WILL EITHER PARTY OR ITS AFFILIATES HAVE ANY LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT FOR ANY LOST PROFITS, REVENUES, GOODWILL, OR INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL, COVER, BUSINESS INTERRUPTION OR PUNITIVE DAMAGES, WHETHER AN ACTION IS IN CONTRACT OR TORT AND REGARDLESS OF THE THEORY OF LIABILITY, EVEN IF A PARTY OR ITS AFFILIATES HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

9.2 Monetary Cap. IN NO EVENT WILL THE AGGREGATE LIABILITY OF EACH PARTY TOGETHER WITH ALL OF ITS AFFILIATES ARISING OUT OF OR RELATED TO THIS AGREEMENT OR THE SERVICES EXCEED THE TOTAL AMOUNT PAID OR PAYABLE BY CLIENT HEREUNDER FOR THE SERVICES GIVING RISE TO THE LIABILITY IN THE TWELVE MONTHS PRECEDING THE FIRST INCIDENT OUT OF WHICH THE LIABILITY AROSE. THE FOREGOING LIMITATION WILL APPLY WHETHER AN ACTION IS IN CONTRACT OR TORT AND REGARDLESS OF THE THEORY OF LIABILITY BUT WILL NOT LIMIT CLIENT’S PAYMENT OBLIGATIONS UNDER THE “FEES AND EXPENSES” SECTION ABOVE.

9.3 Applicability of Limitations. NOTWITHSTANDING ANYTHING TO THE CONTRARY IN THIS AGREEMENT, NOTHING IN THIS SECTION 9 OR ELSEWHERE IN THIS AGREEMENT WILL OPERATE TO EXCLUDE OR LIMIT THE LIABILITY OF A PARTY TO THE EXTENT SUCH LIABILITY CANNOT LAWFULLY BE SO LIMITED OR EXCLUDED UNDER APPLICABLE LAWS. INSOFAR AS APPLICABLE LAWS PROHIBIT ANY LIMITATION ON LIABILITY CONTAINED IN THIS AGREEMENT, THE PARTIES AGREE THAT SUCH LIMITATION WILL BE AUTOMATICALLY MODIFIED, BUT ONLY TO THE EXTENT SO AS TO MAKE THE LIMITATION COMPLIANT WITH APPLICABLE LAWS. THE PARTIES AGREE THAT THE LIMITATIONS ON LIABILITIES SET FORTH IN THIS SECTION 9 ARE AGREED ALLOCATIONS OF RISK AND SUCH LIMITATIONS WILL APPLY NOTWITHSTANDING THE FAILURE OF ESSENTIAL PURPOSE OF ANY LIMITED REMEDY.

10. Term; Termination; Survival

10.1 Term of the Agreement. The Term of this Agreement commences on the Effective Date and continues until the stated term in each applicable SOW has expired or has otherwise been terminated as provided in this Agreement or in the SOW. Unless earlier terminated in accordance with this Agreement: (a) upon expiration of a Trial Term, this Agreement will automatically renew for the Initial Term indicated on the applicable SOW; and (b) upon expiration of the Initial Term, this Agreement will automatically renew for successive periods equal in duration to the Initial Term.

10.2 Termination For Cause. Either Party may terminate this Agreement or any SOW effected hereunder upon written notice to the other Party if the other Party breaches any material obligation under this Agreement and the breaching Party does not cure the breach within 30 days of its receipt of written notice of breach. Either Party may immediately terminate this Agreement and all SOWs under this Agreement if the other Party has a receiver or similar party appointed for its property, becomes insolvent, acknowledges its insolvency in any manner, ceases to do business, makes an assignment for the benefit of its creditors, or files a petition in bankruptcy.

10.3 Effect of Termination. Following termination of this Agreement:

  • All fees will be paid by Client for amounts owed through the effective date of termination, and, if the Agreement is terminated by Client pursuant to Section 10.2, any fees prepaid by Client for Services not rendered prior to the effective date of termination will be refunded to Client within thirty (30) days following the effective date of termination.

  • Certivo will cease to provide the Services to Client and Client’s right to use and access the Services, if applicable, will end as of the effective date of termination.

  • Upon Client’s written request at any time, subject to any contrary obligations under Applicable Laws, Certivo shall at Client’s direction return or destroy and erase all Client Data from all Certivo systems.

  • Unless otherwise set forth in the applicable SOW, all licenses granted by a Party to the other Party under this Agreement shall cease.

10.4 Survival. The rights and obligations of the Parties set forth in Section 10.3 and any right or obligation of the Parties in this Agreement which, by its nature, should survive termination or expiration of this Agreement, will survive any such termination or expiration of this Agreement.

11. Notices

11.1 All notices, requests, consents, claims, demands, waivers, and other communications under this Agreement (each, a “Notice”) must be in writing and addressed to the other Party at its address set forth in the applicable Service Order or SOW (or to such other address that the receiving Party may designate by notice from time to time in accordance with this section).

11.2 Unless otherwise agreed herein, all Notices must be delivered by personal delivery, nationally recognized overnight courier or certified or registered mail (in each case, return receipt requested, postage prepaid). A Notice is effective only (a) on receipt by the receiving Party; and (b) if the Party giving the Notice has complied with the requirements of this section.

12. General

12.1 Relationship of the Parties. The relationship between the Parties is that of independent contractors. Nothing contained in this Agreement will be construed as creating any agency, partnership, joint venture, or other form of joint enterprise, employment, or fiduciary relationship between the Parties, and neither Party will have authority to contract for or bind the other Party in any manner whatsoever.

12.2 No Third-Party Beneficiaries. This Agreement benefits solely the Parties to this Agreement and their respective permitted successors and assigns and nothing in this Agreement, express or implied, confers on any other person or entity any legal or equitable right, benefit, or remedy of any nature whatsoever under or by reason of this Agreement.

12.3 Amendments. No amendment to or modification of this Agreement is effective unless it is in writing, identified as an amendment to this Agreement and signed by an authorized representative of each Party.

12.4 Severability and Waiver. The invalidity or illegality of any provision in this Agreement will not affect the validity of any other provision. All unaffected provisions remain in full force and effect. The waiver of any breach of this Agreement will not constitute a waiver of any subsequent breach or default and will not negate the rights of the waiving Party.

12.5 Assignment. Neither Party will assign this Agreement, or its rights and obligations herein, without obtaining the prior written consent of the other Party, which shall not be unreasonably withheld. Any attempted assignment in violation of the foregoing will be null and void; provided, however, that either Party may assign this Agreement to an Affiliate, or to a third party in connection with a merger, acquisition, reorganization or sale of all or substantially all of its assets, or other operation of law, without any consent of the other Party. The terms of this Agreement will be binding upon the Parties and their respective successors and permitted assigns.

12.6 Successors and Assigns. This Agreement is binding on and inures to the benefit of the Parties to this Agreement and their respective successors and permitted assigns.

12.7 Force Majeure. A Party will not be liable to the other Party, or be deemed to have defaulted under or breached this Agreement, for any failure or delay in fulfilling or performing any obligation of this Agreement (except for any obligations of the Client to make payments to Certivo hereunder), when and to the extent such failure or delay is caused by or results from acts or circumstances beyond the impacted Party’s (“Impacted Party”) reasonable control (each, a “Force Majeure Event”). The Impacted Party will notify the other Party within 2 business days of the Force Majeure Event, stating the period of time the occurrence is expected to continue, if known. The Impacted Party will use diligent efforts to end the failure or delay and ensure the effects of such Force Majeure Event are minimized. The Impacted Party will resume the performance of its obligations as soon as reasonably practicable after the removal of the cause. If the Impacted Party’s failure or delay continues for a period of 15 days or more following written notice given by it under this Section 12.7, the other Party may terminate this Agreement upon 5 days’ prior written notice.

12.8 Choice of Law; Forum. This Agreement and all matters arising out of or relating to this Agreement, shall be governed by, and construed in accordance with, the laws of the State of Washington, without giving effect to the conflict of laws provisions thereof to the extent such principles or rules would require or permit the application of the laws of any jurisdiction other than those of the State of Washington. Each Party irrevocably and unconditionally agrees that it will not commence any action, litigation, or proceeding of any kind whatsoever against the other Party in any way arising from or relating to this Agreement, in any forum other than the United States District Court for the Western District of Washington or, if such court does not have subject matter jurisdiction, the courts of the State of Washington sitting in King County, Washington, and any appellate court from any thereof. Each Party irrevocably and unconditionally submits to the exclusive jurisdiction of such courts.

12.9 Entire Agreement. This Agreement, including any attached exhibits, schedules, attachments, and appendices (including the Data Processing Addendum at Exhibit B), together with any SOWs executed by the Parties (or by Client Affiliates pursuant to Section 12.11) that reference this Agreement, constitutes the sole and entire agreement of the Parties with respect to the subject matter contained herein, and supersedes all prior and contemporaneous understandings, agreements, representations, and warranties, both written and oral, regarding such subject matter. If there is any conflict between the terms and conditions of this Agreement and the terms and conditions of any SOW, the terms of the SOW shall supersede and control, except that, in the event of a conflict between the Data Processing Addendum and a SOW or the body of this Agreement, the Data Processing Addendum shall control to the extent necessary to comply with Data Protection Laws.

12.10 Counterparts. This Agreement may be executed in counterparts, each of which is deemed an original, but all of which together are deemed to be one and the same agreement. A signed copy of this Agreement delivered by facsimile, email, or other means of electronic transmission is deemed to have the same legal effect as delivery of an original signed copy of this Agreement.

12.11 Affiliate Deployments. This Agreement may be extended to one or more of Client’s Affiliates through the execution of a SOW by such Affiliate and Certivo. Each such SOW, once executed, shall be governed by the terms of this Agreement as if such Affiliate were the Client thereunder, provided that (a) each Affiliate shall be responsible solely for its own obligations under its respective SOW and shall not be responsible for the obligations of Client or any other Affiliate, (b) Client shall remain responsible for compliance with this Agreement by any Affiliate that has executed a SOW hereunder, and (c) any notice, consent, or election under this Agreement may be given by Client on behalf of any such Affiliate, unless the affected Affiliate has expressly notified Certivo in writing that it will exercise such rights directly.

Exhibit A: Service Level Addendum

1. Service Level. Subject to the terms herein, during the Term, Certivo agrees that the online components of the Services will be operational and available to Client at least 99.5% of the time, except for: (i) Scheduled Downtime, or (ii) unavailability of the Services due to the exclusions described below (“Availability Commitment”). If Certivo does not meet the Availability Commitment, Client will receive the Service Credit described below. This Service Level Addendum states Client’s sole and exclusive remedy for any failure by Certivo to provide the Services in accordance with the Availability Commitment.

2. Definitions. The following definitions shall apply to the Certivo Availability Commitment.

  • Downtime means, for a Client, that the Services are not accessible to or functional for the Client. The measurement of Downtime is based on server-side error rate.

  • Monthly Uptime Percentage means total number of minutes in a calendar month minus the number of minutes of Downtime suffered in a calendar month, divided by the total number of minutes in a calendar month. If Client’s contract for the Services is for a partial month, then the numerator and denominator of the Monthly Uptime Percentage shall only include those days during which Client received the Services.

  • Scheduled Downtime means those times where Certivo publishes or notifies Clients of periods of Downtime with at least seven (7) business days’ advance written notice. Scheduled Downtime must be scheduled on weekdays between 9 pm and 12 am Pacific time or on weekends. When it occurs in accordance with this section, such Scheduled Downtime is not considered Downtime for purposes of the Availability Commitment.

  • Service Credit means the following:

Monthly Uptime Percentage Percentage of Monthly Fee Refundable to Client
99.5% or higher None
98.0% to 99.49% 10%
95.0% to 97.99% 25%
Under 95.0% 50%

3. Remedies. Client shall notify Certivo of any failures to meet the Availability Commitment within thirty (30) days following the end of each calendar month in which such failure allegedly occurred. Certivo shall calculate the applicable Service Credit and include an invoice for the Service Credit where applicable. Except as set forth herein, Service Credits may not be exchanged for, or converted to, monetary amounts.

4. Availability Commitment Exclusions. The Availability Commitment does not apply (a) to mere performance issues; or (b) to unavailability of the Services caused by factors outside of Certivo’s reasonable control, including without limitation, acts of God, acts of government, flood, fire, earthquakes, civil unrest, acts of terror, strikes or other labor problems (other than those involving Certivo employees); or (c) to unavailability of the Services that result from equipment and/or Services of third parties where such equipment and/or Services is not within the reasonable control of Certivo; or (d) to unavailability of the Services caused by abuse or misuse of the Services (or any component thereof) by Client; or (e) to unavailability of the Services caused by use or maintenance of the Services (or any component thereof) by Client in a manner not materially conforming to the requirements described in the Documentation or in the Agreement.

Exhibit B: Data Processing Addendum

This Data Processing Addendum (“DPA”) supplements the SaaS Agreement (the “Agreement”) to which it is attached as Exhibit B, entered into by and between the party identified as the Client in the applicable Service Order or SOW (“Client”) and Certivo, Inc. (“Certivo”), and is effective as of the Effective Date of the Agreement. The Parties’ execution of the Agreement constitutes execution of this DPA, and no separate signature is required. Any terms not defined in this DPA shall have the meanings set forth in the Agreement. In the event of a conflict between the terms and conditions of this DPA and the Agreement, the terms and conditions of this DPA shall control to the extent necessary to comply with Data Protection Laws (as defined below).

1. Definitions

"CCPA" means the California Consumer Privacy Act of 2018, as codified at California Civil Code Sections 1798.100 through 1798.199.100, and its associated regulations, and as amended by the California Privacy Rights Act of 2020, and as subsequently further amended from time to time.

"Data Controller" means the entity which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. With respect to Personal Data subject to the CCPA, the term Data Controller shall be read to mean entities that would qualify as a “business” subject to the CCPA.

"Data Processor" means the entity which Processes Personal Data on behalf of the Data Controller. With respect to Personal Data subject to the CCPA, the term Data Processor shall be read to mean entities that would qualify as a “service provider” subject to the CCPA.

"Data Protection Law(s)" means all local, state, national and/or foreign data protection and privacy laws, treaties and/or regulations applicable to the collection, use, transfer, storage, correction, disclosure, deletion, and other Processing of Personal Data under this DPA, including, where applicable, U.S. Data Protection Law(s) and European Data Protection Law(s).

"Data Subject" means a natural person who has been or is identified or identifiable, directly or indirectly, by reference to (i) one or more identifiers such as a name, an identification number, location data, an online identifier and/or (ii) one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. With respect to Personal Data subject to the CCPA, the term Data Subject shall be read to mean persons who would qualify as a “consumer” entitled to exercise certain rights related to his or her Personal Data under the CCPA.

"European Data Protection Law(s)" means all EU and U.K. laws, rules, regulations or other legislation applicable (in whole or in part) to the Processing of Personal Data under the Agreement (such as Regulation (EU) 2016/679 (the “GDPR”), the U.K. GDPR (defined below), and the Swiss Federal Data Protection Act on 19 June 1992 and its Ordinance (“Swiss DPA”); the national laws of each EEA member state and the U.K. implementing any EU directive applicable (in whole or in part) to the Processing of Personal Data (such as Directive 2002/58/EC); and any other national laws of each EEA member state and the U.K. applicable (in whole or in part) to the Processing of Personal Data; in each case as amended or superseded from time to time.

"Instruction(s)" means a direction made in writing, either in textual form (e.g. by e-mail) or by using a software or online tool by or on behalf of Client to Certivo with respect to the Processing of Personal Data.

"Personal Data" means any information that (i) is provided by or on behalf of Client to Certivo (directly or indirectly) for Processing under the Agreement, (ii) relates to a Data Subject, and (iii) is governed by Data Protection Laws. Where the CCPA applies, ‘personal data’ includes “personal information” as defined by the CCPA.

"Process or Processing" means any operation or set of operations which is performed upon the Personal Data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure, or destruction.

"Security Incident" means a breach and/or a suspected breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed by Certivo.

"Services" means, collectively, those products and/or services to be provided by Certivo to Client pursuant to the Agreement.

"Sub-Processor" means a third party engaged by or on behalf of a Data Processor to Process Personal Data on behalf of and under the instructions of the Data Controller.

"Standard Contractual Clauses" means those terms set forth in the European Commission’s Implementing Decision of 4.6.2021 on standard contractual clauses, selecting Module Two between controllers and processors in any case where Certivo is a Data Controller, and Module Three between processors in any case where Certivo is a Data Processor, under Article 28(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council and Article 29(7) of Regulation (EU) 2018/1725 of the European Parliament and of the Council dated June 4, 2021, and any replacement, amendment or restatement of the foregoing issued by the European Commission on or after the effective date of this DPA.

"U.K. GDPR" means the GDPR, as it forms part of the domestic law of the United Kingdom by virtue of Section 3 of the European Union (Withdrawal) Act 2018.

"U.S. Data Protection Law(s)" means all U.S. state and federal laws, rules, and regulations applicable to the Processing of Personal Data hereunder, which may include (without limitation) the CCPA, the Colorado Privacy Act, the Connecticut Personal Data Privacy and Online Monitoring Act, the Montana Consumer Data Privacy Act, the Oregon Consumer Data Privacy Act, the Tennessee Information Protection Act, the Texas Data Privacy and Security Act, the Utah Consumer Privacy Act, and the Virginia Consumer Data Protection Act, in each case as amended or superseded from time to time.

2. Scope of DPA; Processing of Data

2.1 Scope of DPA. This DPA applies to the Processing of Personal Data by Certivo in providing the Services to Client. The subject matter, nature, purpose, and duration of this Processing, as well as the types of Personal Data and categories of Data Subjects, are described in Appendix I to this DPA. As between the Parties, Client is the Data Controller and Certivo is the Data Processor of Personal Data. To the extent that any Personal Data provided by Client is subject to European Data Protection Laws, such Personal Data shall be Processed in accordance with Section 6 of this DPA. To the extent that any Personal Data provided by Client is subject to the CCPA, such Personal Data shall be Processed in accordance with Section 10 of this DPA. To the extent that any Personal Data provided by Client is subject to U.S. Data Protection Laws other than the CCPA, such Personal Data shall be Processed in accordance with Section 11 of this DPA.

2.2 Instructions for Processing. Certivo shall Process the Personal Data strictly in accordance with Client’s documented Instructions. Client hereby instructs Certivo to Process Personal Data only as necessary to provide the Services in accordance with the Agreement (including this DPA). Client may provide additional Instructions to Certivo to Process Personal Data from time to time at Client’s discretion. In no event shall Certivo Process Personal Data for its own purposes or those of any third party, including for the purposes of training its Services. Notwithstanding the foregoing, Certivo may from time to time Process Personal Data to generate anonymized, aggregated, and de-identified data sets in connection with its performance of the Services under the Agreement, such that the data in such data sets no longer qualify as “Personal Data”.

3. Client Obligations

While this DPA is in effect, Client shall at all times be responsible for:

  • Complying with applicable Data Protection Law, including but not limited to providing notice to Data Subjects and obtaining the consent of Data Subjects where required for purposes of Client’s own Processing of Personal Data, in Client’s use of Certivo’s Services, and in enabling Certivo to perform the Services pursuant to the terms of the Agreement;

  • Processing Personal Data, and providing instructions to Certivo for the Processing of Personal Data, in compliance with any and all applicable Data Protection Laws; and

  • Verifying the accuracy, quality, and legality of the Personal Data and the means by which Client acquired such Personal Data.

Client shall not provide to Certivo any Personal Data in violation of the Agreement or otherwise inappropriate for the nature of the Services, and shall indemnify Certivo from claims and losses in connection therewith. Client represents and warrants to Certivo that Client has obtained the Personal Data in accordance with applicable Data Protection Laws, and that Client is and will at all times during the term of the Agreement and this DPA remain duly and effectively authorized to have the right to transfer Personal Data to Certivo for Processing in accordance with the Agreement and this DPA.

4. Certivo’s Obligations

While this DPA is in effect, Certivo shall be responsible for:

  • Processing Personal Data in a manner consistent with the terms and conditions set forth in this DPA, the Agreement, and/or any other lawful and documented instructions provided by Client;

  • Complying with all Data Protection Laws applicable in its role as a Data Processor;

  • Ensuring that any person authorized by Certivo to Process Personal Data (including Certivo’s employees, agents and subcontractors) shall be subject to a strict duty of confidentiality (whether a contractual duty or a statutory duty) and shall not permit any person to Process such Personal Data who is not under such a duty of confidentiality;

  • Promptly notifying Client if an instruction, in Certivo’s opinion, infringes applicable Data Protection Laws or the guidance, instructions, or orders provided by an applicable Authority; and

  • Otherwise assisting Client in meeting its obligation to ensure security of Processing the Personal Data to the extent required by applicable Data Protection Laws.

To the extent Client requires Certivo’s assistance to meet its obligations under Article 35 and 36 of the GDPR to carry out a data protection impact assessment and prior consultation with the competent supervisory authority (as defined in Appendix III) related to Client’s use of the Services, and taking into account the nature of the Processing and the information available to Certivo, Certivo shall provide Client with reasonable and timely assistance with any data protection impact assessments as required by applicable Data Protection Law and, where necessary, consultations with data protection authorities.

4.1 Deletion or Return of Personal Data. Client shall notify Certivo of its election to have Personal Data returned or deleted within thirty (30) days of termination or expiry of the Agreement (or such other period as may be specified therein). If Client makes a timely election, Certivo shall return or delete Personal Data pursuant to the election. Certivo may delete all Personal Data after the thirty (30) day period. This requirement shall not apply to the extent that Certivo is required by applicable laws to retain some or all of the Personal Data, in which event Certivo shall isolate and protect the Personal Data from any further Processing except to the extent required by such law, shall only retain such Data for as long as it is required under applicable laws, and shall continue to ensure compliance with all applicable Data Protection Laws during such retention.

4.2 Law Enforcement Requests. If Certivo receives notice from any law enforcement, regulatory, judicial or governmental authority (each an “Authority”) that such Authority wishes to obtain access to the Personal Data, whether on a voluntary or a mandatory basis, then Certivo shall (unless legally prohibited): (a) promptly notify Client of such Authority’s request; (b) inform the Authority that any and all requests or demands for access to Personal Data should be notified to or served upon Client in writing; and (c) not provide the Authority with access to the Personal Data unless authorized by Client.

5. Authorized Sub-Processors

5.1 List. A list of Certivo’s current Sub-Processors is available at https://app.vanta.com/certivo.com/trust/5p49ctv4za4cwjuvdms2zl/subprocessors (the “List”). As of the date of this DPA, and continuing throughout the term of the Agreement, the List sets forth the up-to-date details of the Processing activity/ies that each such Sub-Processor performs or will perform for Certivo in the performance of the Services, and the location of Processing for each Sub-Processor.

5.2 Client’s General Authorization. By executing the Agreement (which incorporates this DPA), Client hereby:

  • Acknowledges and agrees that (i) the Sub-Processors set forth in the List are authorized to access and to Process Client’s Personal Data in connection with the Services and (ii) from time to time, Certivo may engage additional third parties as Sub-Processors for the purpose of providing the Services, including without limitation the Processing of Personal Data;

  • Consents to the transfer by Certivo of Client’s Personal Data to each of the Sub-Processors identified on the List, as updated from time to time in accordance with Section 5.3 of this DPA, as necessary to provide Client with Services pursuant to the Agreement; and

  • Provides general written authorization to Certivo to engage additional third parties as Sub-Processors as necessary to perform the Services, subject to the terms set forth in Section 5.3 below.

5.3 Engaging Additional Sub-Processors. If Certivo engages, or wishes to engage, or removes or wishes to remove, any Sub-Processors from the List following the date of the Agreement, such engagement shall be subject to the terms set forth below:

  • At least ten (10) days before enabling any third party other than currently authorized Sub-Processors to access or participate in the Processing of Personal Data, Certivo will: (i) add the proposed Sub-Processor to the List; (ii) ensure the entry of each proposed Sub-Processor includes (a) the entity name of such Sub-Processor, (b) the Processing activities for which the Sub-Processor was engaged, (c) the location of such Sub-Processor’s Processing activities, and (d) the date on which the proposed Sub-Processor was added to the List, highlighted or otherwise visually marked within the List as a new entry; and (iii) notify Client in accordance with Certivo’s notice obligations under the Agreement that the List has been updated.

  • If Client objects to Certivo’s appointment of a Sub-Processor on reasonable grounds relating to the protection of the Personal Data, Client may reasonably object to such an engagement on legitimate grounds by informing Certivo in writing within ten (10) days of receipt of the aforementioned notice by Certivo. Client’s objection shall be sent to and explain the reasonable grounds for Client’s objection. If Client does not object to the engagement of a third party in accordance with this Section 5.3 within ten (10) days of notice by Certivo, Certivo will deem Client to have authorized the new Sub-Processor and that third party will be deemed an authorized Sub-Processor for the purposes of this DPA.

  • If Client timely objects to the engagement of a third party in accordance with Section 5.3, the Parties will discuss Client’s concerns in good faith and use commercially reasonable efforts to achieve a resolution. Should no resolution be reached, either Certivo will not appoint the Sub-Processor, or (should Certivo choose to retain the objected-to Sub-Processor) Client may elect to suspend or discontinue the affected Services by providing written notice to Certivo. Termination shall not relieve Client of any fees owed to Certivo under the Agreement, nor any other obligations of Client which are intended to survive the Agreement.

5.4 Obligations of Sub-Processors. Certivo will enter into a written agreement with each Sub-Processor, imposing on the Sub-Processor data protection obligations that are substantially the same as those imposed on Certivo under this DPA with respect to the protection of Personal Data. Certivo will remain fully liable to Client for any breach of this DPA that is caused by an act, error or omission of any Sub-Processor’s obligations under such agreement.

5.5 Disclosure of Sub-Processor Agreements. For purposes of clause 9(c) of the Standard Contractual Clauses, Client acknowledges that Certivo may be restricted from disclosing Sub-Processor agreements to Client, but Certivo agrees to use reasonable efforts to request any Sub-Processor to disclose the Sub-Processor agreement to Client and will provide (on a confidential basis) all Sub-Processor information reasonably possible without breaching any obligations of confidentiality Certivo may have to the Sub-Processor.

6. International Transfers of Personal Data

6.1 Location of Processing. Certivo is located in the United States and Processes Personal Data in the United States. The Parties acknowledge and agree that, for Certivo to perform Services for Client pursuant to the Agreement, Client shall transfer (directly or indirectly) Personal Data to Certivo in the United States.

6.2 Terms Applicable to Processing of EU/U.K./Swiss Personal Data. With respect to Personal Data provided by Client that is subject to European Data Protection Law, the Parties agree to abide by and Process the Personal Data pursuant to the terms set forth hereunder:

  • The relevant provisions contained in the Standard Contractual Clauses are incorporated by reference and are an integral part of this DPA, subject to further specification below. For purposes of the descriptions in the Standard Contractual Clauses: (i) Certivo agrees that it is the “data importer” and Client is the “data exporter”; (ii) the Agreement, together with this DPA, represents Client’s complete and final documented Instructions as of the Effective Date for the Processing of Personal Data; (iii) Appendix I (Processing Particulars) and Appendix II (Specific Security Measures) of this DPA shall form Annex I and Annex II of the Standard Contractual Clauses, respectively; and (iv) Option 2 under clause 9 of the Standard Contractual Clauses will apply with respect to any Sub-Processor engaged by Certivo under this DPA. For purposes of clause 9(a) of the Standard Contractual Clauses, Certivo has Client’s general authorization for the engagement of Sub-Processor(s) from the List (as defined in Section 5.1 and updated from time to time in accordance with Section 5.3), which shall be amended from time to time in accordance with the terms of the Agreement, this DPA, and all applicable Data Protection Laws.

  • To the extent that the Standard Contractual Clauses permit the selection of modules and clauses, the Parties agree to the following: (i) the Docking option under clause 7 of the Standard Contractual Clauses shall apply; (ii) the audits described in clause 8.9 of the Standard Contractual Clauses shall be carried out in accordance with the audit provisions detailed in Section 8 of this DPA; and (iii) the option under clause 11 (Redress) of the Standard Contractual Clauses shall not apply.

  • It is not the intention of either Party, nor the effect of this DPA, to contradict or restrict any of the provisions set forth in the Standard Contractual Clauses. Accordingly, if and to the extent the Standard Contractual Clauses conflict with any provision of this DPA, the Standard Contractual Clauses shall prevail to the extent of such conflict with respect to Personal Data Processed pursuant to the Standard Contractual Clauses. In no event does this DPA restrict or limit the rights of any Data Subject or of any competent supervisory authority (as defined in Appendix III).

7. Data Subjects

Client is responsible for responding to requests from Data Subjects to exercise the Data Subject’s right of: access, rectification, erasure, data portability, restriction or cessation of Processing, withdrawal of consent to Processing, and/or objection to being subject to Processing that constitutes automated decision-making with respect to Personal Data (such requests individually and collectively “Data Subject Request(s)”). If Certivo receives a Data Subject Request in relation to Client’s Personal Data, Certivo will promptly inform Client of the same. Client is solely responsible for ensuring that Data Subject Requests for erasure, restriction or cessation of Processing, or withdrawal of consent to Processing of any Personal Data are communicated to Certivo; provided that Certivo shall provide all reasonable and timely assistance to enable Client to respond to: (i) any request from a Data Subject to exercise any of its rights under applicable Data Protection Law; and (ii) any other correspondence received from a regulator or public authority in connection with the Processing of the Personal Data.

8. Audit

8.1 Client’s Right to Review. Upon written request, Certivo shall make available for Client’s review copies of certifications or reports demonstrating Certivo’s compliance with prevailing data security standards applicable to the Processing of Personal Data.

8.2 Client’s Right to Audit. Certivo uses an external auditor to verify the adequacy of its security measures and controls for its Services. Upon written request, Certivo shall provide to Client a copy of Certivo’s most recent report from such audit (“Audit Report”), along with such other information as Client shall reasonably request from Certivo for purposes of verifying Certivo’s compliance with applicable Data Protection Laws; provided that the Parties acknowledge and agree that the Audit Report constitutes Certivo’s confidential information, and that Client’s receipt, review, and retention of the Audit Report shall be subject to confidentiality obligations of the Agreement and/or such other non-disclosure agreement as the Parties may execute to cover the Audit Report. If the Audit Report and other information that Certivo provides to Client is insufficient to fulfill Certivo’s obligations under applicable Data Protection Law (such as, without limitation, Article 28(3)(h) of the GDPR in cases where Personal Data provided by Client pursuant to this DPA includes Personal Data subject to the GDPR), then Certivo shall permit Client to audit Certivo’s compliance with this DPA, subject to Section 8.3 of this DPA.

8.3 Audit Conditions. Client shall be entitled to request an audit by an independent third party for purposes of reviewing Certivo’s compliance with this DPA. Client shall not be entitled to more than one audit of Certivo per calendar year, except (i) following the occurrence of a Security Incident, or (ii) following an instruction by a regulator or public authority, where Client shall be entitled to arrange one (1) additional audit for that calendar year. The scope of Client’s audit shall be limited to such documents, materials, information, systems, and/or Certivo staff as shall be reasonably required to assess Certivo’s compliance with this DPA. Certivo and Client shall mutually agree in advance on the date, scope, duration, and security and confidentiality controls applicable to the audit; provided that the audit shall begin on a date that is no less than thirty (30) days following Certivo’s receipt of Client’s written notice of request to audit, unless such requirement is expressly waived by Certivo in writing. To the extent that such procedures are necessary to assess Certivo’s compliance with this DPA, Client’s audit may include (by way of example): a site visit (during normal office hours and with reasonable prior notice), review of Certivo’s policies and procedures as reasonably related to the Personal Data, inspection of Certivo’s data security infrastructure and procedures, and/or provision of such other documentary evidence as Client shall reasonably request for purposes of verifying Certivo’s compliance with its obligations under this DPA. During the audit, Client, and any third parties assisting Client in the audit, shall strictly abide by Certivo’s rules and requirements regarding security and confidentiality with respect to Certivo’s property and/or any disclosures made by or on behalf of Certivo in the course of the audit. Client shall be responsible for the costs of any such audits, including without limitation a reimbursement to Certivo for any time expended for on-site audits.

9. Security of Personal Data; Security Incidents

9.1 Certivo’s Security Measures. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Certivo shall maintain appropriate technical and organizational measures to protect the Personal Data from (i) accidental or unlawful destruction, and (ii) loss, alteration, unauthorized disclosure of, or access to, the Personal Data. At a minimum, such measures shall include the security measures identified in Appendix II. Certivo may review and update its security measures from time to time, provided that any such updates are consistent with this DPA and do not diminish the security of Certivo’s Processing with respect to the Personal Data.

9.2 Certivo’s Obligations in the Event of a Security Incident. Upon becoming aware of a Security Incident, Certivo shall:

  • Without undue delay, inform Client of the Security Incident;

  • Provide all such timely information and cooperation reasonably within Certivo’s abilities to enable Client to fulfill its data breach reporting obligations under (and in accordance with the timescales required by) applicable Data Protection Law; and

  • Not notify any third parties of Personal Data being affected by a Security Incident unless and to the extent that: (a) Client has agreed to such notification, and/or (b) notification is required to be made by Certivo under applicable Data Protection Law.

10. Additional Terms for CCPA Data

The provisions of this Section 10 will apply only with respect to Personal Data that is subject to the CCPA (“CCPA Data”).

10.1 Defined Terms of the CCPA. The terms “service provider,” “share,” and “sell”, as used in this Section 10, are as defined in Section 1798.140 of the CCPA.

10.2 Obligations Regarding CCPA Data. Certivo acknowledges and agrees that all CCPA Data is disclosed by Client hereunder only for those limited and specified purposes set forth in the Agreement. Certivo shall comply with all obligations of the CCPA applicable to service providers, and except and unless expressly permitted by law, shall:

  • Not sell or share any CCPA Data;

  • Not retain, use or disclose any such CCPA Data for a commercial purpose other than performing the Services as set forth in the Agreement with Client, or as otherwise expressly permitted under this DPA, the Agreement, and the CCPA;

  • Not retain, use or disclose CCPA Data to any party outside of the direct business relationship between Certivo and Client;

  • Promptly notify Client if it determines at any time that it can no longer meet its obligations under applicable Data Protection Laws;

  • Cooperate with and otherwise assist Client’s reasonable and appropriate efforts to ensure that Certivo Processes the CCPA Data transferred in a manner consistent with each Party’s obligations under the CCPA;

  • Not combine the CCPA Data relating to a specific consumer with any other data about the same consumer in Certivo’s possession and/or control, whether received from or on behalf of another person or persons or collected by Certivo from its own interaction(s) with the consumer;

  • Ensure that persons authorized by Certivo to access the CCPA Data comply with all of the foregoing obligations; and

  • To the extent required by applicable Data Protection Laws, post and/or otherwise make available a legally adequate privacy notice describing its practices with respect to Personal Data.

11. Data Processing Obligations (U.S. Data Protection Laws)

With respect to Personal Data that is subject to U.S. Data Protection Laws, Certivo agrees that it shall adhere to Client’s instructions in the Processing of such Personal Data, and shall assist Client in meeting its obligations under applicable U.S. Data Protection Laws on the terms described in this DPA.

12. Miscellaneous

12.1 Termination. The term of this DPA will terminate automatically without requiring any further action by either Party upon the later of (i) the termination of the Agreement, or (ii) when all Personal Data is removed from Certivo’s systems and records.

12.2 Survival. Notwithstanding Section 12.1, Certivo’s obligations under this DPA shall survive so long as Certivo and/or its Sub-Processors Process Personal Data provided by Client.

12.3 Conflict; Invalidation. This DPA is subject to the terms of the Agreement; provided that, in the event of inconsistencies between the provisions of this DPA and the Agreement, this DPA shall prevail with regard to the Parties’ data protection obligations. If any provision of this DPA is deemed invalid or unenforceable, the invalid or unenforceable provision shall be either (i) amended to ensure its validity and enforceability while preserving the Parties’ intentions as closely as possible; or (ii) if that is not possible, then construed in a manner as if the invalid or unenforceable part had never been included herein.

12.4 Change of Law. If there is a change in law requiring a change to this DPA in order for each Party to comply with its obligations under applicable Data Protection Laws, the Parties will in good faith (i) negotiate an amendment to this DPA implementing that change, and (ii) take such additional actions, including (without limitation) execution and delivery of additional documents to effectuate the purposes of the amendment, as shall be reasonably necessary to comply with applicable Data Protection Laws.

Appendix I: Details of Processing

List of Parties

Data Exporter:

Name: Client

Address: As set forth in the Agreement, or else as provided below.

E-mail: As set forth in the Agreement, or else as provided below.

Role: Data Controller (or Data Processor, as applicable)

Data Importer:

Name: Certivo, Inc.

Address: 400 University St, 4th Floor, Seattle, WA 98101

E-mail: As set forth in the Agreement, or else as provided below.

Role: Data Processor (or Sub-Processor, as applicable)

Nature and Purpose of Processing:

Personal Data shall be Processed solely in connection with and for the purpose of providing the Services to Client, as set forth in the Agreement.

Duration of Processing:

Personal Data shall be Processed during the term of the Agreement, and may be Processed following termination only as permitted by applicable laws, rules, and regulations.

Categories of Data Subjects:

Client may submit Personal Data, the extent of which is determined and controlled by Client in its sole discretion, including (without limitation) Personal Data relating to the following categories of Data Subjects: Client’s personnel or Client’s end users (to the extent that the foregoing are natural persons).

Types of Personal Data Transferred:

Client may submit the following categories of Personal Data, the extent of which is determined and controlled by Client in its sole discretion:

Category Examples
Identifiers Name (First and Last); Email Address; Telephone Number; Physical Address (e.g., street, city, postal code); Date of Birth; Username
Customer Records Information Job Title; Company/Organization Name; Department/Business Unit; Business Contact Details (Work Email, Work Phone Number); Employment History; Professional Qualifications
Commercial Information Transaction History; Billing Information (e.g., invoice address, tax information, payment card or bank information)
Internet or Other Electronic Network Activity Information IT information (e.g., computer ID, user ID and password, log files, software and hardware inventory); IT-related data (e.g., IP addresses, online navigation data, browser type, language preferences, pixel data, cookies data, web beacon data); Browsing history, search history, user settings, and information regarding user interaction with the Services
Professional/Employment Information Résumés or CVs; Educational Background; References (names and contact details); Recruitment Assessments/Notes; Background Check Information

Frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis):

Data is transferred on a continuous basis during the term of the Agreement and this DPA.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period:

Personal Data shall be retained by Certivo for no longer than necessary to effect the services set out in the Agreement, subject to exemptions as set forth in the DPA.

For transfers to (sub-)processors, also specify subject matter, nature and duration of the Processing:

Certivo transfers the Personal Data listed above to certain Sub-Processors (as described in the DPA) for the sole purpose of facilitating Certivo’s provision of Services under the Agreement. Sub-Processors have been instructed to retain any Personal Data Processed by Certivo for no longer than necessary to render sub-processing services for Certivo.

Appendix II: Technical and Organizational Measures

Throughout the term of the DPA, Certivo will implement and maintain administrative, physical, and technical safeguards for the protection of the security, confidentiality, and integrity of Personal Data uploaded to the Services, including, at a minimum, technical and organizational measures that are reasonably calculated to achieve the following (in each case to the extent appropriate and applicable, and taking into account the nature, scope, context, and purposes of the data importer’s Processing of Personal Data):

  • Prevent unauthorized persons from gaining access to its systems for Processing Personal Data.

  • Prevent Certivo’s systems that Process Personal Data from being used without authorization.

  • Ensure that persons authorized to access Processing Personal Data gain access only to such Personal Data in accordance with their access rights, and that, in the course of Processing, Personal Data cannot be read, copied, modified, or deleted beyond the scope of the granted access rights without authorization.

  • Establish an audit trail to document whether and by whom Personal Data have been entered into, modified in, or removed from Processing systems.

  • Protect Personal Data against unauthorized access or disclosure, as well as unauthorized, unlawful, or accidental loss, destruction, acquisition, or damage.

Certivo’s administrative, physical, and technical safeguards will include the following:

  • Encryption of Personal Data: Implementing robust encryption protocols (e.g., AES-256) to protect Personal Data during transmission and storage, ensuring data confidentiality and integrity.

  • User Identification and Authorization: Requiring unique usernames and strong passwords for system access; enabling multi-factor authentication (MFA) for additional security.

  • Confidentiality, Integrity, and Resilience: Conducting regular security assessments, vulnerability scans, and penetration testing to maintain the ongoing confidentiality, integrity, availability, and resilience of Certivo’s processing systems and services.

  • Data Transmission Protection: Employing secure protocols such as HTTPS and TLS to safeguard data during transmission over public and private networks.

  • Data Storage Protection: Ensuring Personal Data is stored in encrypted and access-controlled environments, with regular monitoring for unauthorized access attempts.

  • Disaster Recovery and Business Continuity: Maintaining the ability to restore the availability and access to Personal Data in a timely manner in the event of a Security Incident, including a disaster recovery plan.

  • Testing and Evaluation: Regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures to ensure the security of Personal Data processing.

  • Physical Security: Securing all physical locations where Personal Data is processed through controlled access, video surveillance, and environmental monitoring systems.

  • Certification and Assurance: Pursuing relevant security certifications (e.g., ISO 27001, SOC 2) to demonstrate commitment to rigorous security practices.

  • Logical Separation: Ensuring that Personal Data is logically separated from any other data or information collected by Certivo for different purposes.

Certivo may update or modify the foregoing security measures from time to time upon written notice to Client, provided that such updates and modifications do not result in the degradation of the overall security of the Services.

Appendix III: Competent Supervisory Authority

For the purposes of any personal data subject to the GDPR or the GDPR as implemented in the domestic law of the United Kingdom by virtue of Section 3 of the European Union (Withdrawal) Act 2018, where such Personal Data is Processed in accordance with the Standard Contractual Clauses, the competent supervisory authority shall be as follows:

(i) where Client is established in an EU member state, the supervisory authority with responsibility for ensuring Client’s compliance with the GDPR shall act as competent supervisory authority;

(ii) where Client is not established in an EU member state, but falls within the extra-territorial scope of the GDPR and has appointed a representative, the supervisory authority of the EU member state in which Client’s representative is established shall act as competent supervisory authority; or

(iii) where Client is not established in an EU member state but falls within the extra-territorial scope of the GDPR without however having to appoint a representative, the supervisory authority of the EU member state in which the Data Subjects are predominantly located shall act as competent supervisory authority.

In relation to Personal Data that is subject to the U.K. GDPR, the competent supervisory authority is the United Kingdom Information Commissioner’s Office, subject to the additional terms set forth in the International Data Transfer Addendum to the EU Standard Contractual Clauses attached hereto as Appendix V.

In relation to Personal Data that is subject to the Swiss DPA, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.

Appendix IV: Swiss Addendum to the Standard Contractual Clauses

This Appendix IV amends the Standard Contractual Clauses with respect to transfers of Personal Data from Switzerland, to the extent that the Swiss DPA (as may be amended, superseded or replaced) apply to the Processing undertaken under the DPA.

The Standard Contractual Clauses shall be amended with the following modifications, in each case as applicable:

(i) references to “Regulation (EU) 2016/679” shall be interpreted as references to the Swiss DPA;

(ii) references to specific Articles of “Regulation (EU) 2016/679” shall be replaced with the equivalent article or section of the Swiss DPA;

(iii) references to Regulation (EU) 2018/1725 shall be removed;

(iv) references to “EU”, “Union” and “Member State” shall be replaced with references to “Switzerland”;

(v) Clause 13(a) is not used and the “competent supervisory authority” shall be the Swiss Federal Data Protection Information Commissioner;

(vi) references to the “competent supervisory authority” and “competent courts” shall be replaced with references to the “Swiss Federal Data Protection Information Commissioner” and “courts of Switzerland”;

(vii) in Clause 17, the Standard Contractual Clauses shall be governed by the laws of Switzerland; and

(viii) to the extent the Swiss DPA applies to the Processing, Clause 18 shall be replaced to state: “Any dispute arising from these Clauses shall be resolved by the competent courts of Switzerland. The Parties agree to submit themselves to the jurisdiction of such courts.”

Appendix V: U.K. International Data Transfer Addendum

This U.K. International Data Transfer Addendum (“IDTA”) forms a part of the Data Processing Addendum (“DPA”) entered into by and between Certivo and Client, as attached hereto. Unless otherwise specified, all capitalized terms used in this IDTA have the meanings provided in the DPA.

1. Scope of IDTA. The obligations set forth in this IDTA apply solely to Personal Data subject to the U.K. GDPR that is Processed under the DPA (“U.K. Personal Data”).

2. Incorporation of the U.K. DPA. The Parties agree that the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, as issued by the U.K. Information Commissioner’s Office under s.119A (1) of the U.K. Data Protection Act 2018 (“U.K. DPA”) is incorporated by reference into and forms a part of this IDTA as if fully set forth herein. Each Party agrees that execution of the DPA (to which this IDTA is attached as an appendix and incorporated by reference) shall have the same effect as if the Parties had simultaneously executed a copy of the U.K. DPA.

3. Interpretation of the Standard Contractual Clauses. For purposes of Processing U.K. Personal Data, any references in the DPA to the Standard Contractual Clauses shall be read to incorporate the mandatory amendments to the Standard Contractual Clauses set forth in the U.K. DPA.

4. DPA Terms. Tables 1 through 4 of the U.K. DPA shall be completed as follows:

  • In Table 1 of the U.K. DPA, the “Start Date” shall be the effective date of the DPA, and the details and contact information for the “data exporter” and the “data importer” shall be as specified in Appendix I of the DPA.

  • In Table 2 of the U.K. DPA: (i) the version of the Standard Contractual Clauses incorporated by reference into the DPA shall be the version applicable to this IDTA; (ii) those provisions of the Standard Contractual Clauses applicable under Module Two (or, where Client is a Data Processor, Module Three) shall apply to this IDTA; and (iii) the optional clauses and provisions of the Standard Contractual Clauses applicable to this IDTA shall be those clauses and provisions specified in the DPA.

  • In Table 3 of the U.K. DPA, the information required in Annexes I (both 1A and 1B), II, and III shall be as provided in Appendices I, II, and III of the DPA, respectively.

  • In Table 4 of the U.K. DPA, if the ICO issues any revisions to the U.K. DPA after the effective date of the DPA (“ICO Revision”), Client and Certivo shall each have the right to terminate this IDTA in accordance with the U.K. DPA, the DPA, and the Agreement. Upon such termination of this IDTA: (i) Certivo shall cease its Processing of the U.K. Personal Data; and (ii) each Party shall follow the processes described of the DPA with respect to the Processing of U.K. Personal Data following termination.

Notwithstanding the foregoing, termination of this IDTA in the event of an ICO Revision shall not terminate the DPA, the Agreement, and/or the obligations of either Party arising thereunder with respect to Personal Data other than U.K. Personal Data, except and unless expressly agreed by and between the Parties.

Page 1 of 2