Legal

Data Processing Agreement

Version: September 2026

This Data Processing Agreement (the “DPA”) forms part of any Order Form and the Master Service Agreement (collectively, the “Agreement”) between Swantide, Inc. (“Company”) and Customer (“Customer”).

This DPA is incorporated into the Agreement between Company and Customer and applies to Company’s Processing of Personal Data in connection with Company’s provision of Services (as defined in the Agreement) to Customer. In the event of any inconsistency between the DPA and the Agreement as to Company’s Processing of Personal Data, the DPA shall control.

For purposes of this DPA, the following terms and those defined within the body of this DPA apply.

1. DEFINITIONS

In this DPA, the terms “Personal Data”, “Controller”, “Processor”, “Data Subject”, “Process” and “Supervisory Authority” shall have the same meaning as set out in applicable Data Protection Laws with the same or equivalent terms, and the following words and expressions shall have the following meanings unless the context otherwise requires:

“Customer Personal Data” means the Personal Data described in Annex 1 of Schedule 1, and any other Personal Data that Company Processes on behalf of Customer in connection with Company’s provision of the Services.
“Data Protection Laws” means all applicable laws, rules and regulations relating to the Company’s Processing of Personal Data as amended, repealed, consolidated or replaced from time to time.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, any Customer Personal Data held or stored by Company.
“Services” shall have the meaning set forth in the Agreement.
“Standard Contractual Clauses” means the standard contractual clauses for the transfer of personal data annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
“Subprocessor” means any Processor engaged by Company to Process Customer Personal Data on Company’s behalf.
“Third Country” means any country outside of a country in which the Data Protection Laws restrict transfers of Personal Data to destinations outside of that country, except where the Data Protection Laws and applicable regulatory authorities of the originating country adopted an adequacy decision regarding the Data Protection Laws of the destination country such that transfers of Personal Data to that destination country are not restricted.
“UK Addendum” means United Kingdom (“UK”) Information Commissioner’s Office (“ICO”) International Data Transfer Addendum to the EU Commission Standard Contractual Clauses Version B1.0 in force 21 March 2022.

Capitalized terms used in this DPA and not defined above shall have the meaning set forth in the Agreement.

2. DATA PROCESSING

2.1

Company will only Process Customer Personal Data (i) on Customer’s behalf for the purpose of providing and supporting the Services (including to provide insights, reporting, and analytics); (ii) in compliance with the written instructions received from Customer; and (iii) in a manner that provides no less than the level of privacy protection required of it by applicable Data Protection Laws, unless Processing is required by applicable Data Protection Laws, in which case Company shall, to the extent permitted by applicable law, inform Customer of that legal requirement before so Processing that Customer Personal Data. Company shall not Process Customer Personal Data outside of the direct business relationship between Customer and Company. Company shall not ‘sell’ or ‘share’ (as such terms may be specifically defined in applicable Data Protection Laws) Customer Personal Data. To the extent required by applicable Data Protection Laws, Company certifies that it understands the foregoing restrictions and will comply with them. The Agreement and DPA (subject to any changes to the Services) shall be Customer’s complete and final instructions to Company in relation to the Processing of Customer Personal Data. Processing outside the scope of the foregoing will require prior written agreement between Customer and Company on additional instructions for Processing and may be subject to additional fees. As part of the Services, and in compliance with Data Protection Law, Company may Process certain Customer Personal Data to optimize and improve the Services.

2.2

Customer shall provide all applicable notices to Data Subjects required under applicable Data Protection Laws for the lawful Processing of Customer Personal Data by Company in accordance with the Agreement, including notices for capturing images of Data Subjects. Customer shall obtain and maintain throughout the term of the Agreement any required consents and/or authorizations related to its provision of, and Company’s processing of, Customer Personal Data as part of the Services, including for capturing images of Data Subjects. If Customer is not required by Data Protection Laws to obtain and maintain valid consent from Data Subjects, Customer will otherwise obtain and maintain a valid legal basis in accordance with Data Protection Laws to Process Customer Personal Data and for providing such data to Company for Processing under the Agreement.

2.3

For the avoidance of doubt, Customer’s instructions for the processing of Customer Personal Data shall comply with all Data Protection Laws. Customer acknowledges that Company is reliant on Customer for direction as to the extent to which Company is entitled to use and Process Customer Personal Data. Consequently, Company will not be liable for any claim brought against Customer by a Data Subject arising from any act or omission by Company to the extent that such act or omission resulted from Customer’s instructions or Customer’s use of the Services.

2.4

Unless explicitly set forth in the Agreement, Customer Data may not include any “sensitive,” “special categories of data” or any other similar term set forth in Data Protection Laws, including without limitation, any payment card information, social security numbers, identification numbers, or any information considered “personal information” under United States state data breach laws.

2.5

If applicable Data Protection Laws recognize the roles of Controller and Processor as applied to Customer Personal Data then, as between Customer and Company, Customer acts as Controller and Company acts as a Processor (or subprocessor, as the case may be) of Customer Personal Data.

2.6

As required by applicable Data Protection Laws, if Company believes any Customer instructions to Process Customer Personal Data will violate applicable Data Protection Laws, or if applicable Data Protection Laws require Company to process Customer Personal Data relating to data subjects in a way that does not comply with Customer’s documented instructions, Company shall notify Customer in writing, unless applicable Data Protection Laws prohibit such notification, provided Company is not responsible for performing legal research or providing legal advice to Customer.

2.7

Company shall Process Customer Personal Data for the duration of the provision of Services in accordance with the Agreement and thereafter only as set forth in the Agreement and this DPA.

2.8

Each Party will comply with Data Protection Laws applicable to such Party in connection with the Agreement and this DPA.

3. SUBPROCESSORS

3.1

Consent to Subprocessor Engagement. Customer generally authorizes the engagement of third parties as Subprocessors, as required for Company’s business. For the avoidance of doubt, this authorization constitutes Customer’s prior written consent to the subprocessing of Customer Personal Data for purposes of Clause 9, Option 2 of the Standard Contractual Clauses and any similar requirements of other data transfer mechanisms.

3.2

Information about Subprocessors. Company is currently using the following Subprocessors found at http://www.swantide.com/subprocessors (“Subprocessor List”). Customer may sign up to receive notices of additions to the Subprocessor List by emailing privacy@swantide.com and asking to be notified of updates.

3.3

Requirements for Subprocessor Engagement. When engaging any new Subprocessor, Company will execute with Subprocessors a written agreement providing:

  • the Subprocessor only Processes Customer Personal Data to the extent required to perform the obligations subcontracted to it and does so in accordance with the Agreement and this DPA;
  • the Subprocessor utilize the same level of data protection and security with regard to its Processing of Customer Personal Data as are described in this DPA; and
  • be responsible for the Subprocessor’s violations of this DPA or Data Protection Laws in relation to the services such Subprocessor provides to Company to the extent Company would be liable for the same violations under the terms of the Agreement.
3.4

Opportunity to Object to Subprocessor Changes. Customer may, on reasonable and objective grounds, object to Company’s use of a new Subprocessor by providing Company with written notice within fifteen (15) days after Company has provided notice to Customer as described herein with documentary evidence that reasonably shows that the Subprocessor does not or cannot comply with the requirements in this DPA or Data Protection Laws (“Objection”). In the event of an Objection, Customer and Company will work together in good faith to find a mutually acceptable resolution to address such Objection, including but not limited to reviewing additional documentation supporting the Subprocessor’s compliance with the DPA or Data Protection Laws. To the extent Customer and Company do not reach a mutually acceptable resolution within a reasonable timeframe, Company will use reasonable endeavors to make available to Customer a change in the Services or will recommend a commercially reasonable change to the Services to prevent the applicable Subprocessor from Processing Customer Personal Data. If Company is unable to make available such a change within a reasonable period of time, which shall not exceed thirty (30) days, Company and Customer shall escalate to their applicable executive or senior leadership to discuss the matter in good faith and determine an appropriate resolution and next steps.

4. INTERNATIONAL TRANSFERS

4.1

In accordance with Customer’s instructions under Section 2, Company may Process Customer Personal Data on a global basis as necessary to provide the Services, including but not limited to, for IT security purposes, maintenance and provision of the Services and related infrastructure, technical support, and change management.

4.2

To the extent that the Processing of Customer Personal Data by Company involves the transfer of such Customer Personal Data from a country whose Data Protection Laws restrict the transfer of Personal Data to Third Countries, then such transfers shall be subject to the protections and provisions of the Standard Contractual Clauses (for which the SCC Appendix is attached to this DPA in Schedule 1), the UK Addendum for transfers from the UK to Third Countries, or other binding and appropriate transfer mechanisms that provide an adequate level of protection in compliance with Data Protection Laws.

4.3

Customer shall be deemed to have signed the SCC in Schedule 1, Annex I in its capacity of “data exporter” and Company in its capacity as “data importer.” Module Two of the SCC shall apply to the transfer. For purposes of Clauses 17 and 18 of the SCCs, the Parties select the country in which the data exporter is established. To the extent such a transfer includes Personal Data subject to Data Protection Laws of Switzerland, the Standard Contractual Clauses shall be adapted to use for Switzerland (where the Swiss Federal Act on Data Protection shall apply as the applicable Data Protection Law, Clauses 17 and 18 of the SCCs shall refer to Switzerland, and Data Subjects in Switzerland shall be able to avail themselves of any rights conferred by the Standard Contractual Clauses).

4.4

The SCC, or UK Addendum, as applicable, will cease to apply if Company has implemented an alternative recognized compliance mechanism for the lawful transfer of personal data in accordance with applicable Data Protection Laws.

4.5

In the event of any conflict between any terms in the SCC or UK Addendum, as applicable, and the DPA, the SCC or UK Addendum, as applicable, shall prevail to the extent of the conflict.

5. DATA SECURITY AND SECURITY NOTIFICATIONS

5.1

Company Security Obligations. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Company shall implement appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk of the Processing, including the measures set out in Schedule 1. Company may update its security practices from time to time but will not materially decrease the overall security of the Services during the term of the Agreement. Such measures shall include process for regularly testing, assessing, and evaluating the effectiveness of the measures.

5.2

Upon Customer’s written request, Company shall make available all information reasonably necessary to demonstrate compliance with this DPA as required by Data Protection Laws.

5.3

Personal Data Breach Notification. If Company becomes aware of and determines a Personal Data Breach has occurred, Company will:

  • notify Customer of the Personal Data Breach without undue delay and, in any case, as soon as practicable after such determination, at the contact information on file, where such notification shall describe, to the extent reasonably known to Company: (1) the nature of the Personal Data Breach including where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned; (2) the reasonably anticipated consequence of the Personal Data Breach; (3) measures taken to mitigate any possible adverse effects; and (4) other information concerning the Personal Data Breach reasonably known or available to Company that Customer is required to disclose to a Supervisory Authority or Data Subjects under Data Protection Laws; and
  • investigate the Personal Data Breach and provide such reasonable assistance to Customer (and any law enforcement or regulatory official) as required to investigate the Personal Data Breach.
5.4

Except as required by applicable Data Protection Laws, the obligations set out in Section 5.3 shall not apply to Personal Data Breaches caused by Customer.

5.5

Company’s provision of any notification of a Personal Data Breach shall not constitute an admission of fault.

5.6

Customer is solely responsible for fulfilling any Personal Data Breach notification obligations applicable to Customer. Customer and Company shall work together in good faith within the timeframes for Customer to provide Personal Data Breach notifications in accordance with Data Protection Laws to finalize the content of any notifications to Data Subjects or Supervisory Authorities, as required by Data Protection Laws. Company’s prior written approval shall be required for any statements regarding, or references to, Company made by Customer in any such notifications.

5.7

Company Employees and Personnel. Company shall treat Customer Personal Data as the Confidential Information of Customer, and shall put procedures in place to ensure that:

  • access to Customer Personal Data is limited to those employees or other personnel who have a business need to have access to such Customer Personal Data; and
  • any employees or other personnel with access to Customer Personal Data have committed themselves to confidentiality of Customer Personal Data or are under an appropriate statutory obligation of confidentiality and do not Process such Customer Personal Data other than in accordance with this DPA.

6. ACCESS REQUESTS AND DATA SUBJECT RIGHTS

6.1

Except if prohibited under applicable law, Company shall promptly notify Customer of any request received by Company or any Subprocessor from a Data Subject in respect of their Personal Data included in Customer Personal Data (“Data Subject Request”) and shall not respond to the Data Subject Request where the Data Subject identifies Customer as its Controller. If a Data Subject does not identify a Controller, Company will instruct the Data Subject to identify and contact the relevant Controller.

6.2

Where applicable, and taking into account the nature of the Processing, Company shall use reasonable endeavors to assist Customer by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Customer’s obligation to respond to Data Subject Requests as required by Data Protection Laws. In order to receive such assistance, and to the extent that Customer cannot fulfill such request through functionality in the Services, Customer shall submit a support request to correct, delete, block, access or copy the Personal Data of a Data Subject.

7. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION

7.1

To the extent required under applicable Data Protection Laws, Company shall provide reasonable assistance to Customer with any data protection impact assessments and with any prior consultations to any Supervisory Authority of Customer, in each case solely in relation to Processing of Customer Personal Data and taking into account the nature of the Processing and information available to Company.

7.2

Such cooperation and assistance are provided to the extent Customer does not otherwise have access to the relevant information, and to the extent such information is available to Company. Company may fulfil its above obligations by providing Customer with documentation regarding its Processing operations.

8. RETENTION AND DELETION OF PERSONAL DATA

8.1

During the Term, the Services retain Personal Data for a period of time based on Customer’s configuration of the Services. Within a reasonable period of time following termination or expiration of the Agreement, or deactivation of the Services, Company shall delete Personal Data.

8.2

Subject to Section 8.3 below, where deletion of Personal Data is not possible, Company will sufficiently de-identify Customer Personal Data that is reasonably capable of deidentification such that it is no longer Personal Data, except for compliance, audit, security, or Service optimization purposes.

8.3

Company and its Subprocessors may retain Customer Personal Data to the extent required by applicable laws.

9. GENERAL

9.1

With regard to the subject matter of this DPA, in the event of inconsistencies between the provisions of this DPA and any other agreements between the parties, including but not limited to the Agreement, the provisions of this DPA shall prevail with regard to the parties’ data protection obligations for Customer Personal Data of a Data Subject.

9.2

Company may share and disclose Customer Personal Data and other data of Customer in connection with, or during the negotiation of, any merger, sale of company assets, consolidation or restructuring, financing, or acquisition of all or a portion of Company’s business by or to another company, including the transfer of contact information and data of customers, partners and end users.

9.3

Should any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability, while preserving the parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.

Schedule 1

APPENDIX TO THE STANDARD CONTRACTUAL CLAUSES

ANNEX I

A. LIST OF PARTIES

Data exporter

Name:

The data exporter is the entity identified as “Customer” in the DPA

Address:

As set forth in the Agreement

Contact person:

As set forth in the Notices provision in the Agreement or Order Form

Activities relevant to the data transferred under these Clauses:

As set forth in the Agreement

Signature and date:

Refer to DPA or Agreement, as applicable

Role:

Controller, except when processing data on behalf of another entity

Data importer

Name:

The data importer is the entity identified as “Company” in the DPA

Address:

As set forth in the Agreement

Contact person:

Taylor Lint, taylor@swantide.com

Activities relevant to the data transferred under these Clauses:

As set forth in the Agreement

Signature and date:

Refer to DPA or Agreement, as applicable

Role:

Processor, or Subprocessor if data exporter is a Processor

B. DESCRIPTION OF TRANSFER

Categories of data subjects whose personal data is transferred:

Data exporter’s contacts including its employees, contractors, suppliers and subcontractors and other personnel, its customers and prospective customers, and other individuals identified in data exporter’s ticketing system (including ticket requesters and other individuals referenced in ticket content, comments, or attachments).

Categories of personal data transferred:

Depending on data exporter’s configuration of the data importer’s Services categories of personal data may include contact information including name, email address, phone number, and other contact details, application/website usage information, ticket content, ticket comments, user information (name, email) in the ticketing system, and document attachments.

Sensitive categories of data (if appropriate):

N/A

The frequency of the transfer:

As set forth in the Agreement

Nature of the processing:

The subject-matter and nature of the processing of data exporter Personal Data by data importer is for the provision of the Services to the data exporter under the Agreement

Purposes of the data transfer and further processing:

Refer to DPA.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period:

Personal Data will be processed for the duration of the Agreement

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing:

Refer to DPA and the Agreement

C. COMPETENT SUPERVISORY AUTHORITY

The competent Supervisory Authority shall be the country in which the data exporter is established, or the UK ICO for matters related to data subjects in the UK.

ANNEX II

Company agrees to implement appropriate technical and organizational measures designed to protect Customer Personal Data as required by applicable Data Protection Law(s). Such measures will include:

1.

Establish and maintain an information security program designed to (i) protect the security and confidentiality of data exporter’s Personal Data; (ii) protect against any anticipated threats or hazards to the security or integrity of data exporter’s Personal Data; (iii) protect against unauthorized access to or use of data exporter’s Personal Data; and (iv) ensure the proper disposal of data exporter’s Personal Data.

2.

Provide security awareness and training programs delivered not less than annually, for all Company personnel who access data exporter’s Personal Data.

3.

Maintain controls that provide reasonable assurance that access to data importer’s cloud servers (“Systems”) is limited to properly authorized individuals.

4.

Maintain policies and procedures designed to protect the confidentiality, integrity, and availability of Personal Data and protect it from unauthorized disclosure, alteration, or destruction.

5.

Maintain a security incident response plan that includes procedures to be followed in the event of any incident that results in a Personal Data Breach. The procedures include:

  • Roles and responsibilities: formation of an internal incident response team with a response leader.
  • Investigation: assessing the risk the Personal Data Breach poses and determining which customers may be affected.
  • Communication: internal reporting as well as a notification process to data importer customers and other applicable third parties.
6.

Implement storage and transmission security measures designed to guard against unauthorized access to Personal Data that is being transmitted over an electronic communications network. Such measures include requiring NIST-acceptable encryption of any Personal Data stored on desktops, laptops or other mobile computer devices. Data importer will encrypt sensitive data when stored.

ANNEX III

The data exporter has authorized the use of the following subprocessors: http://www.swantide.com/subprocessors