Skip to content

Data Processing Agreement

Last Updated: August 28, 2026

1. Introduction and Purpose

This Data Processing Agreement ("DPA") is entered into by and between Etched, Inc., a Delaware corporation located at 3155 Olsen Drive, Suite 200, San Jose, CA 95117 ("Company," "Controller," or "Business"), and the vendor, supplier, contractor, consultant, or service provider that has entered into, accepted, or performs under an agreement with Company that references or incorporates this DPA ("Vendor," "Processor," or "Service Provider"). References to "Company" include Etched, Inc. and each of its Affiliates that receives the Services or on whose behalf Personal Data is Processed, each of which may enforce this DPA directly against Vendor.

This DPA sets forth the parties' obligations with respect to the processing of Personal Data by Vendor on behalf of Company in connection with the goods and/or services provided under the parties’ Master Services Agreement (the "MSA"). This DPA is the document referenced in Section 10 of the MSA and is incorporated into the MSA by reference. Where no MSA exists between the parties, this DPA is incorporated into and forms part of each Order, Statement of Work, purchase order, or other written or electronic agreement under which Vendor Processes Personal Data on behalf of Company (each, together with the MSA, an "Agreement"), and references in this DPA to the MSA shall be read as references to the applicable Agreement.

Acceptance. Vendor is bound by this DPA as of the earliest of the date Vendor: (a) executes or electronically accepts an MSA, Order, or SOW that references or incorporates this DPA; (b) receives Personal Data from or on behalf of Company; or (c) commences or continues Processing of Personal Data on behalf of Company (the "Acceptance Date"). No signature by Vendor is required for this DPA to be binding on Vendor, provided that where a Restricted Transfer requires an executed transfer mechanism, Vendor shall execute the SCCs, the UK Addendum, and/or the Swiss Addendum on request in accordance with Section 10.2. Company will record the Acceptance Date applicable to each Vendor.

References to the MSA. Where the applicable Agreement is not Company's standard form Master Services Agreement, references in this DPA to numbered sections of the MSA shall be read as references to the corresponding provisions of the applicable Agreement addressing the same subject matter; and where the applicable Agreement contains no such provision, the fallback terms set out in this DPA apply.

No Vendor Terms; Rejection of Conflicting Terms. This DPA is the exclusive data protection agreement between the parties. Any data processing agreement, data protection addendum, privacy policy, information security policy or addendum, acceptable use policy, click-through, browse-wrap, online terms, terms of service, quotation, invoice, portal terms, or other standard terms proposed, presented, referenced, linked, or otherwise made available by Vendor are expressly rejected and have no force or effect with respect to the Processing of Personal Data, regardless of whether Company or any Company personnel clicks, signs, accesses, or otherwise appears to accept them. No such terms shall be deemed accepted absent a written amendment that expressly identifies this Section and is signed by an authorized officer of Company.

Order of Precedence. In the event of any conflict between the terms of this DPA and the MSA with respect to the processing of Personal Data, the terms of this DPA shall control to the extent of such conflict. This DPA supplements but does not replace any obligations imposed on Vendor under Applicable Data Protection Laws.

Company may update this DPA from time to time to reflect changes in Applicable Data Protection Laws or Company's data protection practices. Any such update will be made in accordance with, and subject to the notice and objection procedures set forth in, Section 13.3. Vendor's continued Processing of Personal Data after the effective date of an update constitutes acceptance of the updated terms.

2. Definitions

The following terms have the meanings set forth below. Capitalized terms not defined in this DPA have the meanings assigned to them in the MSA or in Applicable Data Protection Laws, as context requires. Where no MSA exists between the parties, capitalized terms used but not defined in this DPA (including "Services," "Products," "Order," "SOW," "Company Data," and "Confidential Information") have the meanings given in the applicable Agreement or, absent a definition there, the meanings ordinarily given to them in the context of the Services, construed so as to give effect to the protections in this DPA.

"Applicable Data Protection Laws" means all laws and regulations relating to data protection, privacy, and the processing of Personal Data that apply to a party's performance under the MSA, including without limitation: the EU General Data Protection Regulation 2016/679 ("GDPR"); the UK General Data Protection Regulation and the Data Protection Act 2018 ("UK GDPR"); the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"); the Virginia Consumer Data Protection Act ("VCDPA"); the Connecticut Data Privacy Act ("CTDPA"); the Colorado Privacy Act ("CPA"); Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA"); Brazil's Lei Geral de Protecao de Dados ("LGPD"); Thailand's Personal Data Protection Act ("PDPA"); India's Digital Personal Data Protection Act ("DPDP Act"); Switzerland's Federal Act on Data Protection ("Swiss FADP"); Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25 ("Law 25"); the comprehensive consumer privacy statutes of Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island, and any other U.S. state consumer privacy statute now or hereafter in effect; the Washington My Health My Data Act and the Nevada Consumer Health Data Privacy Law; the Illinois Biometric Information Privacy Act and any other U.S. state biometric or genetic privacy statute; Australia's Privacy Act 1988 (including the Australian Privacy Principles); Japan's Act on the Protection of Personal Information ("APPI"); South Korea's Personal Information Protection Act ("PIPA"); China's Personal Information Protection Law ("PIPL"); South Africa's Protection of Personal Information Act ("POPIA"); Nigeria's Data Protection Act; the Kingdom of Saudi Arabia's Personal Data Protection Law; UAE Federal Decree-Law No. 45 of 2021; and any other applicable data protection, privacy, data security, breach notification, or data localization law or regulation, in each case as amended, supplemented, superseded, or replaced from time to time, together with any binding guidance, codes of practice, or decisions issued by a Supervisory Authority thereunder.

"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where "control" means ownership of more than fifty percent (50%) of the voting interests or the power to direct the management of the entity.

"De-Identified Data" means data that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable natural person or household, and that meets the standard for de-identified, anonymized, or aggregate data under the Applicable Data Protection Laws.

"DPF" means the EU-U.S. Data Privacy Framework, the UK Extension thereto, and the Swiss-U.S. Data Privacy Framework, in each case as administered by the U.S. Department of Commerce.

"Restricted Transfer" means any transfer of Personal Data, including remote access to Personal Data, to a country, territory, or recipient for which Applicable Data Protection Laws require a specified transfer mechanism, derogation, or additional safeguard.

"Sensitive Personal Data" means (a) special categories of personal data under Article 9 of the GDPR or UK GDPR; (b) "sensitive personal information" under the CCPA/CPRA; (c) "sensitive data" under U.S. state consumer privacy laws; and (d) any equivalent category under other Applicable Data Protection Laws, in each case including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health or consumer health data, sex life or sexual orientation, precise geolocation, government-issued identifiers, financial account or payment card data, account credentials, immigration or citizenship status, criminal history, and Personal Data of a child under the age of eighteen (18).

"Supervisory Authority" means any data protection authority, privacy commissioner, attorney general, or other regulator with jurisdiction over the Processing of Personal Data under the Agreement.

"Swiss Addendum" means the adaptations to the SCCs recognized by the Swiss Federal Data Protection and Information Commissioner ("FDPIC") for transfers subject to the Swiss FADP, as set out in Section 10.4.

"Business" has the meaning given under the CCPA/CPRA and refers to Company in its capacity as the entity that determines the purposes and means of processing Personal Data of California consumers.

"Controller" means the natural or legal person that determines the purposes and means of the processing of Personal Data, as defined under GDPR, UK GDPR, and equivalent Applicable Data Protection Laws. For purposes of this DPA, Company is the Controller.

"Data Subject" means the identified or identifiable natural person to whom Personal Data relates. This includes "consumers" under CCPA/CPRA, VCDPA, CPA, and CTDPA; "data subjects" under GDPR, UK GDPR, and LGPD; and equivalent terms under other Applicable Data Protection Laws.

"Personal Data" means any information relating to an identified or identifiable natural person that is processed by Vendor on behalf of Company under the MSA. This includes "personal information" as defined under CCPA/CPRA, "personal data" as defined under GDPR, UK GDPR, LGPD, PDPA, and DPDP Act, and equivalent terms under other Applicable Data Protection Laws.

"Processing" (and "Process") means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.

"Processor" means the natural or legal person that processes Personal Data on behalf of the Controller, as defined under GDPR, UK GDPR, and equivalent Applicable Data Protection Laws. For purposes of this DPA, Vendor is the Processor.

"Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed by Vendor or its Sub-processors on behalf of Company, and any reasonably suspected occurrence of any of the foregoing. A Security Incident also includes any ransomware, extortion, or denial-of-service event affecting systems or environments in which Personal Data is stored or Processed; any unauthorized access to Vendor credentials, keys, or systems that could permit access to Personal Data; and any accidental or unlawful loss of availability of Personal Data. A Security Incident does not require confirmation that Personal Data has in fact been accessed, exfiltrated, or misused. This includes a "personal data breach" under GDPR/UK GDPR, a "breach of the security of the system" under CCPA/CPRA, and equivalent events under other Applicable Data Protection Laws.

"Service Provider" has the meaning given under the CCPA/CPRA and refers to Vendor in its capacity as the entity that processes Personal Data on behalf of Company pursuant to a written contract.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to processors established in third countries, as adopted by the European Commission (currently Commission Implementing Decision (EU) 2021/914), as may be amended, superseded, or replaced. If the SCCs are annulled, invalidated, or replaced, the successor clauses or other lawful transfer mechanism approved by the European Commission shall apply automatically to transfers under this DPA as of the date the successor mechanism takes effect, and Vendor shall promptly execute any documents Company reasonably requires to give effect to the same.

"Sub-processor" means any third party engaged by Vendor (or by another Sub-processor of Vendor) to process Personal Data on behalf of Company in connection with the Services under the MSA.

"UK International Data Transfer Addendum" or "UK IDTA" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under Section 119A of the Data Protection Act 2018 (also referred to in this DPA as the "UK Addendum"). For clarity, this DPA relies on the Addendum to the EU Commission SCCs and not on the Information Commissioner's standalone International Data Transfer Agreement.

3. Scope and Purpose of Processing

3.1 Purpose

Vendor shall process Personal Data solely for the purpose of providing the Services to Company as described in the MSA and the applicable Order(s)/SOW(s), and in accordance with Company's documented instructions. Vendor shall not process Personal Data for any other purpose, including for Vendor's own commercial purposes, unless expressly authorized in advance and in writing by an authorized officer of Company or required by Applicable Data Protection Laws (in which case Vendor shall inform Company of such legal requirement before processing, unless prohibited by law). Without limiting the foregoing, Vendor shall not Process Personal Data for Vendor's own product development, research, analytics, benchmarking, quality assurance, marketing, advertising, model training, or any other internal purpose, and shall not derive value from Personal Data other than the fees payable under the Agreement.

3.2 CCPA/CPRA-Specific Restrictions

To the extent the CCPA/CPRA applies, Vendor, as a Service Provider, shall not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than performing the Services specified in the MSA, including for a commercial purpose other than providing the Services; (c) retain, use, or disclose Personal Data outside of the direct business relationship between Vendor and Company; (d) combine Personal Data received from Company with personal information received from other sources or collected from Vendor's own interactions with Data Subjects, except as expressly permitted by the CCPA/CPRA; or (e) use Personal Data for cross-context behavioral advertising, whether or not for monetary or other valuable consideration.

Vendor further agrees that it shall: (i) comply with all obligations applicable to a Service Provider or Contractor under the CCPA/CPRA and provide the same level of privacy protection as is required of Company as a Business; (ii) notify Company promptly, and in no event later than three (3) business days, if Vendor determines that it can no longer meet its obligations under the CCPA/CPRA; (iii) grant Company the right, upon notice, to take reasonable and appropriate steps to ensure that Vendor uses Personal Data in a manner consistent with Company's obligations under the CCPA/CPRA, and to stop and remediate any unauthorized use of Personal Data; (iv) engage subcontractors only pursuant to a written contract that imposes the same restrictions applicable to Vendor under this Section and the CCPA/CPRA, and notify Company of any such engagement in accordance with Section 6; and (v) cooperate with Company in honoring opt-out preference signals and any Company-directed limitation on the use or disclosure of Sensitive Personal Data.

The business purposes for which Vendor is permitted to Process Personal Data are limited to those necessary to provide the Services described in the applicable Order/SOW, together with the following purposes to the extent necessary and proportionate: maintaining the security and integrity of Vendor's systems; debugging and error correction; and compliance with law. Vendor shall not retain, use, or disclose Personal Data for any other business or commercial purpose.

3.3 Details of Processing

The following describes the general nature of the Processing carried out under this DPA. Additional or more specific details regarding the Processing performed for a particular engagement are set forth in the applicable Order/SOW, which supplements but does not limit the description below:

Subject Matter of Processing: The provision of the Products and/or Services described in the MSA and the applicable Order/SOW, which may involve the Processing of Personal Data submitted by or on behalf of Company.

Duration of Processing: Coterminous with the term of the MSA and each applicable Order/SOW, as further described in Section 13.1 of this DPA.

Nature and Purpose of Processing: Processing as necessary to provide the Products and Services described in the MSA and the applicable Order/SOW, which may include the collection, storage, use, transmission, and deletion of Personal Data in connection with service delivery, support, and related administrative functions.

Categories of Personal Data: Determined by Company based on the nature of the Services and may include, without limitation, business contact information, employment-related information, and other Personal Data submitted by or on behalf of Company in connection with the Services, as further described in the applicable Order/SOW.

Categories of Data Subjects: Determined by Company based on the nature of the Services and may include, without limitation, Company’s employees, contractors, customers, and other individuals whose Personal Data is submitted in connection with the Services.

Special Categories of Data: Vendor shall not Process Sensitive Personal Data unless expressly identified and instructed by Company in the applicable Order/SOW, and then only subject to the additional safeguards specified therein. Vendor shall not solicit, collect, or request Sensitive Personal Data from Company or from any Data Subject.

Frequency of Transfer: Continuous for the duration of the applicable Order/SOW, or on such other basis as described in the applicable Order/SOW.

Retention Period: Personal Data shall be retained only for the duration of the applicable Order/SOW and shall be returned or deleted in accordance with Section 9, and in no event retained more than thirty (30) days following termination or expiration, subject to the backup expiration and legal-retention provisions of Sections 9.2 and 9.3.

Transfers to Sub-processors: The subject matter, nature, and duration of Processing by each Sub-processor shall be as described in the list maintained under Section 14, and in each case shall be limited to what is necessary to perform the Services.

Competent Supervisory Authority: For transfers subject to the GDPR: (i) where Company has appointed a representative under Article 27 of the GDPR, the supervisory authority of the EU Member State in which that representative is established; or (ii) where Company has not appointed such a representative, the supervisory authority of the EU Member State in which the Data Subjects whose Personal Data is transferred are located, as identified in the applicable Order/SOW. For transfers subject to the UK GDPR, the UK Information Commissioner's Office. For transfers subject to the Swiss FADP, the FDPIC.

3.4 Prohibition on Artificial Intelligence and Machine Learning Uses

Vendor shall not, and shall not permit any Sub-processor, Affiliate, or other third party to, use, input, submit, or otherwise make available Personal Data to train, retrain, fine-tune, calibrate, validate, benchmark, evaluate, test, ground, or otherwise develop or improve any machine learning model, foundation model, large language model, algorithm, or artificial intelligence system, whether Vendor's own or a third party's, and whether or not the Personal Data is de-identified, pseudonymized, or aggregated for that purpose. Vendor shall not input Personal Data into any third-party artificial intelligence, generative AI, or machine learning service unless (a) Company has authorized that service in advance and in writing, and (b) the provider is engaged as a Sub-processor under Section 6 and is contractually prohibited from retaining or using Personal Data for its own purposes, including model training or model improvement. Vendor shall not use Personal Data to make or support any automated decision or profiling that produces legal effects concerning, or otherwise significantly affects, a Data Subject, except on Company's documented instructions. This Section does not prohibit Vendor from operating machine learning or artificial intelligence functionality that is itself the Service that Company has purchased, provided that such Processing is performed solely for Company's benefit, no Personal Data is used to train, tune, or improve any model that is available to or used for any other customer or for Vendor's own purposes, and Personal Data is not retained beyond the period necessary to deliver the output to Company.

3.5 De-Identified, Anonymized, and Aggregated Data

Vendor shall not create De-Identified Data, anonymized data, aggregated data, statistics, insights, or other derived data from Personal Data except as necessary to perform the Services and on Company's documented instructions. Where Vendor is expressly authorized to do so, Vendor shall: (a) take reasonable measures to ensure the data cannot be associated with any Data Subject or household; (b) publicly commit to maintain and use the data only in de-identified form and not to attempt to re-identify it, except as permitted by Applicable Data Protection Laws solely to test the effectiveness of de-identification; (c) contractually prohibit any recipient from re-identifying the data; and (d) not disclose or use such data in any manner that identifies Company as the source without Company's prior written consent. All such data, and all reports, insights, benchmarks, and derived works based on Personal Data, are Company Data and the exclusive property of Company.

3.6 Data Minimization

Vendor shall Process the minimum Personal Data necessary to perform the Services and shall not request, collect, or retain Personal Data beyond that minimum. If Vendor receives Personal Data outside the scope of the applicable Order/SOW, or receives Sensitive Personal Data that Company has not instructed Vendor to Process, Vendor shall promptly notify Company, shall not Process such data other than to secure and delete it, and shall securely delete it upon Company's instruction.

4. Roles and Responsibilities

4.1 General Allocation of Roles

For purposes of this DPA: (a) Company is the Controller (GDPR/UK GDPR), Business (CCPA/CPRA), or equivalent data-determining entity under other Applicable Data Protection Laws; and (b) Vendor is the Processor (GDPR/UK GDPR), Service Provider (CCPA/CPRA), or equivalent data-processing entity under other Applicable Data Protection Laws. Where Company Processes Personal Data as a processor or service provider on behalf of its own customers and Vendor Processes such Personal Data in connection with the Services, Vendor acts as a Sub-processor, this DPA applies to that Processing as if references to Company as Controller were references to Company acting on the documented instructions of its customer, and Module Three of the SCCs applies in accordance with Section 10.2. Vendor shall not act as, or hold itself out as, a controller, business, or independent third party with respect to Personal Data Processed on behalf of Company; this restriction does not prevent Vendor from acting as a controller in respect of its own business records, such as its billing records, its own personnel records, and records it is required by law to retain, provided those records are not used to circumvent this DPA. Any determination by Vendor of the purposes or means of Processing Personal Data other than on Company's documented instructions is a material breach of this DPA and of the Agreement.

4.2 Company Obligations

Company shall: (a) ensure it has a lawful basis for the processing of Personal Data and for instructing Vendor to process such data; (b) provide documented instructions to Vendor regarding the processing of Personal Data; (c) comply with its obligations as Controller/Business under Applicable Data Protection Laws; and (d) notify Vendor of any restrictions or special requirements regarding the processing of Personal Data that are not already set forth in this DPA or the MSA. Company's obligations under this Section 4.2 run solely to Vendor, and (except as expressly provided in the SCCs or the UK Addendum) create no rights in any third party, and shall not be construed to (a) impose on Company any obligation of a processor or service provider, (b) relieve Vendor of any obligation under this DPA or Applicable Data Protection Laws, or (c) constitute a condition precedent to Vendor's performance. Vendor shall not assert Company's alleged non-performance of this Section as a defense to Vendor's own non-compliance.

4.3 Vendor Obligations by Regime

In addition to its general obligations under this DPA, Vendor shall comply with the following regime-specific requirements to the extent applicable:

(a) GDPR and UK GDPR: Vendor shall process Personal Data only on documented instructions from Company (Article 28(3)(a)), including with regard to transfers of Personal Data to a third country. Vendor shall assist Company in ensuring compliance with Articles 32-36 (security, DPIAs, and prior consultation). Vendor shall make available to Company all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits and inspections.

(b) CCPA/CPRA: Vendor certifies that it understands and will comply with the restrictions and obligations applicable to a Service Provider under the CCPA/CPRA, including the prohibition on selling, sharing, or using Personal Data except as necessary to perform the Services. Vendor shall notify Company if it determines that it can no longer meet its obligations under the CCPA/CPRA.

(c) VCDPA, CTDPA, and CPA: Vendor shall process Personal Data in accordance with Company's instructions and shall assist Company in meeting its obligations under these state privacy laws, including responding to consumer rights requests, conducting data protection assessments, and ensuring appropriate security measures.

(d) PIPEDA: Vendor shall implement safeguards comparable to those required of Company under PIPEDA and shall process Personal Data only for the purposes identified by Company. Vendor shall support Company in responding to access and correction requests from Data Subjects.

(e) LGPD (Brazil): Vendor shall process Personal Data in compliance with the LGPD, adopt security measures adequate to protect Personal Data, and assist Company in fulfilling its obligations to the ANPD and to Data Subjects, including in responding to requests for the exercise of rights.

(f) PDPA (Thailand): Vendor shall implement appropriate security measures and shall process Personal Data only as instructed by Company. Vendor shall assist Company in complying with data subject rights under the PDPA and shall notify Company of any Security Incident in accordance with this DPA.

(g) DPDP Act (India): Vendor, as a Data Processor, shall process Personal Data only in accordance with the terms of a valid contract with Company and as instructed by Company. Vendor shall implement reasonable security safeguards and shall assist Company in responding to Data Principal rights requests.

(h) Swiss FADP: Vendor shall Process Personal Data in accordance with the Swiss FADP and shall cooperate with Company in any dealings with the FDPIC.

(i) Canada (PIPEDA and Quebec Law 25): Vendor shall implement safeguards comparable to those required of Company, shall notify Company before any transfer of Personal Data outside Canada or outside the Province of Quebec, and shall provide the information Company requires to conduct a privacy impact assessment under Law 25.

(j) Australia, Japan, and South Korea: Vendor shall Process Personal Data consistently with the Australian Privacy Principles, the APPI, and PIPA as applicable, including the restrictions each imposes on cross-border disclosure and on the use of personal information beyond the notified purpose, and shall provide the information Company requires to satisfy its notice and consent obligations under those laws.

(k) China (PIPL): Vendor shall not transfer Personal Data out of, or Process Personal Data outside of, the People's Republic of China except in compliance with the PIPL cross-border transfer requirements, and shall cooperate with Company in completing any required standard contract filing, security assessment, or certification.

(l) Other Applicable Data Protection Laws: To the extent any other data protection law applies to Vendor's processing of Personal Data on behalf of Company, Vendor shall comply with its obligations under such law and shall assist Company in meeting Company's obligations as a controller, business, or equivalent role.

4.4 Sector-Specific Regimes

Where Vendor Processes Personal Data that is subject to a sector-specific law, the following apply in addition to this DPA: (a) if Vendor creates, receives, maintains, or transmits protected health information on behalf of Company or of a Company-sponsored health plan, Vendor shall execute a business associate agreement under HIPAA before receiving such data, and that agreement controls to the extent of any conflict with this DPA; (b) if Vendor acts as a consumer reporting agency or furnishes consumer reports to Company, the Fair Credit Reporting Act and applicable state analogues govern that activity, and this DPA applies only to the extent not inconsistent with them; and (c) if Vendor Processes nonpublic personal information subject to the Gramm-Leach-Bliley Act, or cardholder data subject to the PCI DSS, Vendor shall comply with the applicable safeguards and standards and provide evidence of compliance upon request.

5. Vendor Processing Obligations

5.1 Documented Instructions

Vendor shall process Personal Data only on and in accordance with Company's documented instructions, unless required to process by Applicable Data Protection Laws. The MSA, this DPA, and any applicable Orders/SOWs constitute Company's initial documented instructions. Instructions may be given by Company in the Agreement, in an Order/SOW, through Company's documented policies or product configuration settings, or by written notice (including email) from Company's legal or security function. If Vendor believes an instruction from Company infringes Applicable Data Protection Laws, Vendor shall promptly notify Company and may suspend performance of that specific instruction, but shall not suspend any other performance. Vendor shall comply with Company's instructions at no additional charge.

5.2 Confidentiality of Personnel

Vendor shall ensure that all persons authorized to process Personal Data have committed themselves to confidentiality obligations (whether contractual or statutory) and have received appropriate training on data protection requirements. Access to Personal Data shall be limited to personnel who require such access to perform the Services.

5.3 General Compliance

Vendor shall: (a) maintain a written record of processing activities carried out on behalf of Company, as required under Applicable Data Protection Laws; (b) cooperate with supervisory authorities and regulators upon reasonable request; (c) designate a data protection officer or equivalent contact where required by law; and (d) not process Personal Data in a manner that would cause Company to violate Applicable Data Protection Laws.

5.4 Consistency with MSA Confidentiality Obligations

Vendor's obligations regarding the security and confidentiality of Personal Data under this DPA supplement and are in addition to Vendor's obligations regarding Confidential Information and Company Data under Section 9 of the MSA. In the event of a conflict between this DPA and the MSA regarding the protection of Personal Data, this DPA controls.

5.5 Processing Locations and Remote Access

Vendor shall Process Personal Data only in the countries and facilities disclosed to Company in writing, and shall notify Company at least thirty (30) days before Processing, storing, or accessing Personal Data in or from any additional country. Vendor shall not permit personnel, contractors, or Sub-processors to access Personal Data remotely from any country not so disclosed. Vendor shall not Process Personal Data in, or permit access from, any jurisdiction that is the subject of comprehensive economic sanctions administered by the U.S. Office of Foreign Assets Control or where such Processing or access would cause Company to violate applicable export control or sanctions laws. Vendor shall not permit access to Personal Data or to Company technical data by any individual where such access would constitute a deemed export requiring authorization under the U.S. Export Administration Regulations or the International Traffic in Arms Regulations.

5.6 Government, Law Enforcement, and Third-Party Requests

If Vendor or any Sub-processor receives a legally binding request, subpoena, warrant, national security demand, court order, or other request from a public authority or third party for disclosure of or access to Personal Data, Vendor shall: (a) notify Company promptly and, where lawful, before disclosure, and in any event within twenty-four (24) hours of receipt, except where notification is prohibited by law (in which case subsection (f) applies); (b) inform the requesting authority that Vendor is a processor acting on Company's behalf and direct the request to Company; (c) use all lawful and reasonable means to challenge, narrow, resist, or seek interim relief against the request, including seeking a protective order and pursuing available appeals where there is a reasonable prospect of success, consistent with Clause 15.2 of the SCCs; (d) disclose only the minimum Personal Data legally required, based on a reasonable interpretation of the request; (e) document its legal assessment and the disclosure made, and provide that documentation to Company; and (f) if prohibited from notifying Company, use best efforts to obtain a waiver of that prohibition and provide Company, on request, with aggregate statistics regarding the number and type of requests received. Vendor shall not provide any public authority with direct, blanket, or back-door access to Personal Data or to systems containing Personal Data, and shall not create or maintain any capability for such access. Vendor represents that, as of the Acceptance Date, it has no reason to believe that any law applicable to it or to its Sub-processors prevents it from fulfilling its obligations under this DPA, and shall notify Company promptly if that ceases to be the case.

5.7 Cooperation at No Additional Charge

Vendor shall perform all of its obligations under this DPA, including assistance with Data Subject Requests, Security Incident response, audits, transfer impact assessments, data protection impact assessments, regulatory inquiries, and the return or deletion of Personal Data, at no additional charge to Company, and shall not condition performance on payment of any amount, resolution of any dispute, or execution of any additional agreement.

5.8 Annual Certification and Regulatory Notifications

Upon Company's written request (no more than once per twelve (12) month period, or at any time following a Security Incident), Vendor shall provide a written certification signed by an officer of Vendor confirming its compliance with this DPA. Vendor shall notify Company within three (3) business days of becoming aware of (a) any inquiry, investigation, audit, complaint, or enforcement action by a Supervisory Authority relating to Personal Data Processed under the Agreement or to Vendor's data protection or security practices generally, and (b) any material adverse change in Vendor's security posture, certifications, or ability to comply with this DPA. Vendor shall not identify Company in any response to a Supervisory Authority without Company's prior written consent unless legally required to do so.

6. Sub-processors

6.1 General Authorization

Company provides Vendor with general written authorization to engage Sub-processors to process Personal Data on behalf of Company, subject to the requirements of this Section 6. Vendor shall maintain and make available to Company its current list of authorized Sub-processors in accordance with Section 14. Vendor's engagement of a Sub-processor does not relieve Vendor of any obligation under this DPA.

6.2 Notice of Changes

Vendor shall notify Company in writing at least thirty (30) days before engaging any new Sub-processor or replacing an existing Sub-processor ("Sub-processor Change Notice"). Such notice shall identify the Sub-processor, its location, and the processing activities to be performed.

6.3 Right to Object

Company may object to a proposed Sub-processor on reasonable grounds relating to data protection by notifying Vendor in writing within fifteen (15) days of receiving the Sub-processor Change Notice. If Company objects, Vendor shall either: (a) not engage the objected-to Sub-processor for processing Company's Personal Data and, where possible, provide the Services without such Sub-processor; or (b) take corrective steps reasonably requested by Company to address Company's objection. Pending resolution of an objection, Vendor shall not disclose or make Personal Data available to the objected-to Sub-processor. If Vendor cannot accommodate Company's objection within thirty (30) days, Company may, without penalty or liability, suspend the affected Processing and/or terminate the affected Order/SOW or the MSA in whole or in part upon written notice, and Vendor shall refund on a pro-rata basis all fees prepaid for periods after the effective date of termination.

6.4 Flow-Down Obligations

Vendor shall impose on each Sub-processor, by way of a written contract, data protection obligations no less protective than those set out in this DPA. Such contract shall include the transfer mechanism required under Section 10 and audit, security, and deletion obligations sufficient to allow Vendor to satisfy Sections 8, 9, and 11. Upon request, Vendor shall provide Company with a copy of the data protection terms of any Sub-processor agreement, which may be redacted as to commercial terms. Vendor shall remain fully and primarily liable to Company for the acts and omissions of its Sub-processors as if they were Vendor's own acts and omissions, and no limitation or exclusion of Vendor's liability shall apply to the acts or omissions of its Sub-processors.

6.5 Due Diligence

Vendor shall conduct appropriate due diligence on each Sub-processor before engagement, evaluating the Sub-processor's ability to meet the data protection obligations required under this DPA and Applicable Data Protection Laws.

6.6 Restricted Sub-processors

Vendor shall not engage any Sub-processor that: (a) is identified on the U.S. Department of the Treasury Specially Designated Nationals and Blocked Persons List, the U.S. Department of Commerce Entity List or Unverified List, or any equivalent restricted-party list; (b) is organized under the laws of, or Processes Personal Data in, a jurisdiction subject to comprehensive U.S. sanctions or to export controls applicable to Company's business; (c) is a direct competitor of Company that Company has identified to Vendor in writing and that would have access to Personal Data, other than a general-purpose cloud infrastructure, network, or productivity provider engaged on its standard terms; or (d) is unable to comply with the obligations flowed down under Section 6.4. Vendor shall promptly cease using, and shall securely delete or cause the deletion of Personal Data held by, any Sub-processor that becomes subject to this Section.

7. Data Subject Rights

7.1 Assistance with Requests

Vendor shall promptly assist Company in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws, including rights of access, rectification, erasure (right to be forgotten), restriction of processing, data portability, objection to processing, and the right to opt out of the sale or sharing of Personal Data (collectively, "Data Subject Requests").

7.2 Notification of Requests

If Vendor receives a Data Subject Request directly, Vendor shall promptly (and in any event within two (2) business days) notify Company and shall not respond to the request directly unless authorized by Company or required by Applicable Data Protection Laws. Vendor shall provide Company with all cooperation and assistance reasonably necessary in relation to the handling of such requests, within the timeframes Company specifies in order to meet its statutory deadlines, and at no additional charge.

7.3 Technical Capabilities

Vendor shall maintain technical and organizational measures to enable it to assist Company in responding to Data Subject Requests, including the ability to search, retrieve, correct, delete, restrict, and export Personal Data in a structured, commonly used, and machine-readable format, as applicable.

7.4 Regime-Specific Rights

Without limiting the generality of the foregoing, Vendor shall assist Company in responding to the following regime-specific rights upon Company's request:

(a) GDPR/UK GDPR: Access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making (Articles 15-22).

(b) CCPA/CPRA: Right to know/access, right to delete, right to correct, right to opt out of sale/sharing, and right to limit use of sensitive personal information.

(c) VCDPA/CTDPA/CPA: Access, correction, deletion, portability, and opt-out of targeted advertising, sale of personal data, and profiling.

(d) LGPD: Confirmation of processing, access, correction, anonymization/blocking/deletion, portability, information about sharing, and revocation of consent.

(e) PDPA (Thailand): Access, correction, deletion, restriction, portability, objection, and withdrawal of consent.

(f) DPDP Act (India): Access, correction, erasure, and nomination rights of Data Principals.

(g) Other regimes: Equivalent rights under other Applicable Data Protection Laws.

8. Security Measures and Incident Response

8.1 Technical and Organizational Measures

Vendor shall implement and maintain appropriate technical and organizational security measures to protect Personal Data against Security Incidents, taking into account the state of the art, costs of implementation, the nature, scope, context, and purposes of processing, and the risks to Data Subjects.

Such measures shall include, at a minimum:

(a) Encryption of Personal Data in transit and at rest using industry-standard encryption protocols;

(b) Measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services;

(c) Access controls, including role-based access, multi-factor authentication, and least-privilege principles;

(d) Regular testing, assessment, and evaluation of the effectiveness of security measures;

(e) Personnel security measures, including background checks, training, and confidentiality obligations;

(f) Physical security of facilities where Personal Data is processed or stored;

(g) Network security measures, including firewalls, intrusion detection/prevention, and monitoring;

(h) Vulnerability management and patching programs;

(i) Business continuity and disaster recovery capabilities;

(j) Secure disposal and deletion of Personal Data when no longer required;

(k) Where the Processing involves Sensitive Personal Data, Personal Data relating to more than five thousand (5,000) Data Subjects, or Vendor hosting of Personal Data in systems under Vendor's control, maintenance of a SOC 2 Type II attestation, ISO/IEC 27001 certification, or equivalent independent third-party assessment, renewed at least annually, with copies of reports, bridge letters, and remediation plans provided to Company upon request; and in all other cases, a documented information security program reviewed at least annually;

(l) Logging and monitoring of access to and Processing of Personal Data, with tamper-resistant audit logs retained for not less than twelve (12) months and made available to Company in the event of a Security Incident;

(m) Secure software development practices, including code review, dependency and supply-chain security, and segregation of production from development and test environments, together with a prohibition on the use of Personal Data in non-production environments;

(n) Encryption key management, including key rotation and restriction of key access to authorized personnel, with keys stored separately from the data they protect;

(o) Endpoint protection, mobile device management, and hardening standards for all systems used to access Personal Data;

(p) At least annual penetration testing by a qualified independent third party, with summary results provided to Company upon request and remediation of critical and high findings within thirty (30) days;

(q) Remediation or documented mitigation of critical vulnerabilities within seven (7) days and of high vulnerabilities within thirty (30) days of identification; and

(r) Logical segregation ensuring Personal Data is separated from the data of Vendor's other customers and from Vendor's own data.

These measures supplement and are consistent with the administrative, technical, and physical safeguards required under Section 9 of the MSA regarding Confidential Information and Company Data. Vendor shall not materially decrease the overall protection afforded to Personal Data during the term of the Agreement. Where Vendor has represented specific security measures to Company, including in any security questionnaire, due diligence response, or security exhibit, those measures form part of Vendor's obligations under this Section 8.1.

8.2 Incident Notification

Upon becoming aware of a Security Incident, Vendor shall:

(a) GDPR/UK GDPR incidents: Notify Company without undue delay, and in any event within twenty-four (24) hours of becoming aware of the Security Incident, to enable Company to comply with its own notification obligations under Articles 33 and 34 of the GDPR/UK GDPR (which run from Company's awareness and cannot be met if Vendor consumes the full statutory period).

(b) All other incidents: Notify Company without undue delay, and in any event no later than twenty-four (24) hours after becoming aware of the Security Incident (or such shorter period as required by Applicable Data Protection Laws).

(c) Method and content of notice: Notice shall be given by email to legal@etched.com and security@etched.com and followed by telephonic confirmation to Company's designated contact. Vendor shall not delay notification in order to complete its investigation, determine root cause, quantify impact, or obtain legal review, and shall not condition notification on Company's execution of any agreement. For purposes of this Section 8.2, Vendor is "aware" of a Security Incident when any of Vendor's personnel, contractors, or Sub-processors knows or reasonably suspects that a Security Incident has occurred.

For clarity, these notification timelines are independent of and without prejudice to the three (3) business day notification requirement under Section 9 of the MSA for unauthorized access, use, or disclosure of Confidential Information. In all cases, the shorter of the applicable timelines controls. Vendor's obligations under this Section 8.2 apply to Security Incidents affecting any Sub-processor, and Vendor shall procure from each Sub-processor notification rights sufficient to meet these timelines.

8.3 Content of Breach Notification

Vendor's Security Incident notification shall include, to the extent reasonably available:

(a) A description of the nature of the Security Incident, including the categories and approximate number of Data Subjects and Personal Data records affected;

(b) The name and contact details of Vendor's data protection officer or other contact from whom more information can be obtained;

(c) A description of the likely consequences of the Security Incident;

(d) A description of the measures taken or proposed to address the Security Incident, including measures to mitigate its possible adverse effects; and

(e) Any other information required by Applicable Data Protection Laws.

If Vendor cannot provide all required information simultaneously, it shall provide initial notification with available information and supplement as additional details become known.

8.4 Cooperation and Remediation

Vendor shall: (a) take immediate steps to contain and remediate the Security Incident and minimize harm to Data Subjects; (b) cooperate with Company in investigating and remediating the Security Incident; (c) preserve evidence related to the Security Incident; (d) assist Company with any notifications to supervisory authorities, regulators, or Data Subjects as required by Applicable Data Protection Laws; and (e) not make any public statements or notifications regarding the Security Incident without Company's prior written consent, unless required by law.

8.5 Security Incident Costs

Vendor shall bear all reasonable costs and expenses arising from a Security Incident caused by, or occurring within the systems or personnel of, Vendor or its Sub-processors, including: (a) forensic investigation and root-cause analysis by a firm reasonably acceptable to Company; (b) legal and regulatory response, including responses to Supervisory Authorities; (c) preparation and delivery of notifications to Data Subjects, Supervisory Authorities, media, and other parties; (d) call center and inquiry-handling services; (e) credit monitoring, identity theft protection, and identity restoration services for affected Data Subjects for not less than twenty-four (24) months, or such longer period as required by law; (f) crisis communications and public relations support; (g) remediation of the vulnerability or deficiency that gave rise to the Security Incident; and (h) Company's reasonable internal costs, including personnel time, incurred in responding to the Security Incident. These obligations are in addition to, and not in lieu of, Vendor's indemnification obligations under Section 12.

8.6 Cyber Liability Insurance

Vendor shall maintain, at its own expense and throughout the term of the Agreement and for two (2) years thereafter, cyber liability and technology errors and omissions insurance with limits of not less than five million U.S. dollars (US$5,000,000) per claim and in the aggregate, covering data breach response costs, privacy regulatory defense and fines where insurable, network security liability, and unauthorized disclosure of Personal Data. Coverage shall be written by an insurer rated A- or better by A.M. Best. Vendor shall name Company as an additional insured to the extent permitted by the policy, provide certificates of insurance upon request, and give Company at least thirty (30) days' notice of cancellation, non-renewal, or material reduction in coverage. Vendor's insurance shall not limit Vendor's liability under this DPA or the Agreement.

8.7 Extortion and Ransomware

Vendor shall notify Company before responding to, negotiating with, or making any payment in response to any ransomware or extortion demand affecting Personal Data; shall not represent or purport to act on behalf of Company in any such communication; and shall not make any payment that would cause Company to violate applicable sanctions or anti-money laundering laws. Vendor shall not delete, encrypt, withhold, or render inaccessible any Personal Data as a means of enforcing a payment dispute or other claim against Company.

9. Data Retention, Deletion, and Return

9.1 Retention Limitation

Vendor shall not retain Personal Data for longer than necessary to perform the Services under the MSA and applicable Orders/SOWs, unless a longer retention period is required or permitted by Applicable Data Protection Laws. Vendor shall implement appropriate data retention and deletion policies and procedures.

9.2 Deletion or Return Upon Termination

Upon termination or expiration of the MSA, any applicable Order/SOW, or upon Company's written request at any time, Vendor shall, at Company's election: (a) return all Personal Data to Company in a structured, commonly used, and machine-readable format; or (b) securely delete or destroy all Personal Data in Vendor's possession or control (including all copies, backups, and archives), and certify such deletion or destruction in writing, signed by an officer of Vendor, within thirty (30) days. Deletion shall be performed in accordance with NIST Special Publication 800-88 or an equivalent recognized standard, including cryptographic erasure where media cannot be sanitized. Where Personal Data resides in backups or archives that cannot immediately be deleted, Vendor shall isolate and protect that data, cease all other Processing of it, and delete it in accordance with Vendor's documented backup expiration schedule, which shall not exceed ninety (90) days, and shall provide a supplemental certification upon deletion of those isolated copies. Vendor shall not condition the return or deletion of Personal Data on payment of any amount, resolution of any dispute, or execution of any additional agreement, and shall return Personal Data in a format and by a method that permits Company to migrate to an alternative provider. Vendor shall instruct its Sub-processors to do the same.

9.3 Exceptions

Vendor may retain Personal Data to the extent required by Applicable Data Protection Laws, provided that Vendor: (a) limits such retention to the minimum required by law; (b) continues to protect such data in accordance with this DPA; (c) processes such data only for the purpose required by law; and (d) promptly informs Company in writing of the specific legal basis, categories of data, and duration of such retention (to the extent permitted by law); and (e) deletes such data promptly upon expiry of the legal requirement and certifies that deletion to Company. Vendor may not rely on this Section to retain Personal Data for its own business, analytics, product improvement, or model development purposes.

10. International Data Transfers

10.1 General Restriction

Vendor shall not transfer Personal Data to a country or territory outside the jurisdiction in which it was collected unless such transfer is made in compliance with Applicable Data Protection Laws and subject to appropriate safeguards as described in this Section 10. Each transfer described in this Section 10.1, including any remote access to Personal Data from outside that jurisdiction, is a Restricted Transfer.

10.2 EU/EEA Transfers

For transfers of Personal Data from the EU/EEA to countries not subject to an adequacy decision by the European Commission, the parties agree that the Standard Contractual Clauses (SCCs) adopted by Commission Implementing Decision (EU) 2021/914 are hereby incorporated by reference. The parties agree to Module Two (Controller to Processor) of the SCCs, with Company as the data exporter and Vendor as the data importer. Where Company Processes Personal Data as a processor on behalf of its own customers, Module Three (Processor to Processor) of the SCCs applies to that Processing, with Company as data exporter and Vendor as data importer. The following elections apply to the SCCs: (a) Clause 7 (docking clause) applies; (b) the option elected in Clause 9(a) is Option 2 (general written authorization), with the notice period for Sub-processor changes being thirty (30) days as set forth in Section 6.2; (c) the optional language in Clause 11(a) regarding an independent dispute resolution body does not apply; (d) for Clause 13 and Annex I.C, the competent supervisory authority is as identified in Section 3.3; (e) for Clause 17, the SCCs are governed by the law of Ireland; (f) for Clause 18(b), disputes shall be resolved before the courts of Ireland; (g) Annex I.A (List of Parties) is completed by the parties identified in Section 1, the Company contacts identified in Section 13.7, and the entity details and data protection contact that Vendor is required to provide under Section 13.7, which Vendor shall supply within ten (10) business days of request; (h) Annex I.B (Description of Transfer) is completed by Section 3.3; (i) Annex II (Technical and Organisational Measures) is completed by Sections 8.1 and 5.5, as supplemented by any measures specified in the applicable Order/SOW; and (j) the list of Sub-processors maintained under Section 14 constitutes the agreed record of Sub-processors for purposes of Clause 9 and, where Option 1 of Clause 9(a) applies, Annex III. Vendor shall complete, execute, and return any documentation Company reasonably requests to evidence the SCCs, including a signed copy of the SCCs and their Annexes, within ten (10) business days of request; failure to do so is a material breach, and Company may suspend the affected transfers and terminate the affected Order/SOW without penalty or liability. Where Vendor is not itself subject to the GDPR, the SCCs are the sole transfer mechanism unless Vendor validly relies on an adequacy decision or the DPF in accordance with Section 10.5, or Company agrees otherwise in writing.

10.3 UK Transfers

For transfers of Personal Data from the United Kingdom, the UK International Data Transfer Addendum (UK IDTA) issued by the UK Information Commissioner is hereby incorporated by reference and shall apply in addition to, or in lieu of, the SCCs as required by UK data protection law. The details of the UK IDTA are completed as follows: Table 1 (Parties) by Section 1 and Section 13.7; Table 2 (Selected SCCs, Modules and Selected Clauses) by the Module Two and, where applicable, Module Three SCCs as elected in Section 10.2; Table 3 (Appendix Information) by Sections 1, 3.3, 8.1, 13.7 and 14; and for Table 4, only the Exporter (Company) may end the UK IDTA when the Approved Addendum changes, as provided in Section 19 of the UK IDTA. The start date of the UK IDTA is the Acceptance Date.

10.4 Swiss Transfers

For transfers of Personal Data subject to the Swiss FADP, the SCCs apply with the following adaptations (the "Swiss Addendum"): (a) references to the GDPR are to be understood as references to the Swiss FADP; (b) references to "Member State" and "EU Member State" shall not be interpreted so as to exclude Data Subjects in Switzerland from the possibility of enforcing their rights in their place of habitual residence; (c) the competent supervisory authority is the FDPIC; (d) the Swiss FADP as revised with effect from 1 September 2023 protects the Personal Data of natural persons, and no extension to data relating to legal entities is required; and (e) for transfers governed exclusively by the Swiss FADP, references to the law of Ireland in Clause 17 shall be read as references to the law of Switzerland.

10.5 Adequacy Decisions and Other Mechanisms

Where a transfer of Personal Data is made to a country or territory that is subject to an adequacy decision by the European Commission (for GDPR transfers), a UK adequacy regulation (for UK GDPR transfers), or an equivalent recognition under other Applicable Data Protection Laws, such adequacy decision or recognition shall serve as the lawful transfer mechanism. The parties may also rely on other transfer mechanisms permitted under Applicable Data Protection Laws (e.g., binding corporate rules, certifications, or approved codes of conduct), provided that such mechanisms are documented in writing and approved by Company in advance in writing. If Vendor relies on certification under the DPF, Vendor shall: (a) maintain an active certification covering the categories of Personal Data Processed and the relevant frameworks (EU-U.S., UK Extension, and Swiss-U.S.); (b) comply with the DPF Principles, including the Accountability for Onward Transfer Principle; (c) notify Company within five (5) business days if its certification lapses, is withdrawn, is not renewed, or becomes subject to enforcement; and (d) acknowledge that if the DPF is annulled, suspended, invalidated, or otherwise ceases to provide a lawful transfer mechanism, or if Vendor's certification lapses, the SCCs as elected in Section 10.2 (together with the UK IDTA and the Swiss Addendum, as applicable) apply automatically and without further action as of that date. Vendor shall not rely on a derogation under Article 49 of the GDPR, on consent, or on contractual necessity as a transfer mechanism without Company's prior written approval.

10.6 Transfer Impact Assessments

Vendor shall cooperate with Company in conducting transfer impact assessments where required by Applicable Data Protection Laws or supervisory authority guidance, and shall implement supplementary measures as necessary to ensure an essentially equivalent level of protection for transferred Personal Data. Vendor shall provide, at no charge and within fifteen (15) business days of request, the information Company reasonably requires in order to conduct such assessments, including: the identity and location of all entities with access to Personal Data; a description of the local laws permitting public authority access to Personal Data; the volume, nature, and sensitivity of the data transferred; the technical and organizational supplementary measures in place, including encryption and key custody arrangements; and a summary of any government access requests received under Section 5.6.

10.7 Onward Transfers

Vendor shall not make onward transfers of Personal Data to Sub-processors in third countries unless (a) the Sub-processor engagement is authorized under Section 6, and (b) an appropriate transfer mechanism under this Section 10 is in place for the onward transfer. Each onward transfer shall be governed by the same or an equivalent transfer mechanism, and Vendor shall provide evidence of that mechanism upon request.

10.8 Data Localization

Vendor shall comply with all data localization, in-country storage, and cross-border transfer restrictions imposed by Applicable Data Protection Laws or by Company's written instructions, including any requirement that Personal Data remain within a specified country or region. Vendor shall not relocate, replicate, mirror, cache, or route Personal Data, including for backup, disaster recovery, support, or content delivery purposes, outside an approved region without Company's prior written consent, except for transient routing in encrypted form where Vendor retains sole custody of the decryption keys within an approved region.

10.9 Suspension and Termination on Transfer Invalidity

If any transfer mechanism relied upon under this Section 10 is invalidated or suspended, or is determined by a Supervisory Authority, by a court, or by Company's reasonable assessment to be insufficient to ensure an adequate level of protection, Vendor shall promptly, and in any event within thirty (30) days, implement an alternative lawful mechanism or additional safeguards acceptable to Company. Pending implementation, Company may instruct Vendor to suspend the affected transfers and Vendor shall comply. If Vendor cannot implement an acceptable alternative, Company may terminate the affected Order/SOW or the MSA in whole or in part without penalty or liability, Vendor shall refund all fees prepaid for periods after termination, and Vendor shall return or delete Personal Data in accordance with Section 9.

11. Audit Rights

11.1 Right to Audit

Company (or its authorized third-party auditor, subject to confidentiality obligations) shall have the right to audit, inspect, and verify Vendor's compliance with this DPA and Applicable Data Protection Laws. Vendor shall make available all information reasonably necessary to demonstrate compliance and shall cooperate with such audits at no charge. Vendor shall procure and maintain equivalent audit rights in respect of each Sub-processor and shall, at Company's request, exercise those rights on Company's behalf or facilitate Company's direct exercise of them.

11.2 Methods of Audit

Company may exercise its audit rights through any of the following methods:

(a) Written questionnaires and information requests regarding Vendor's data processing practices and security measures;

(b) Review of third-party certifications, audit reports, and compliance documentation (e.g., SOC 2 Type II reports, ISO 27001 certificates, penetration test results);

(c) Remote or on-site inspections of Vendor's facilities and systems where Personal Data is processed, conducted with reasonable advance notice (at least fifteen (15) days except in the case of a Security Incident or reasonable suspicion of non-compliance); and

(d) Review of Vendor's data protection impact assessments, records of processing activities, and policies and procedures.

11.3 Frequency and Scope

Company may conduct on-site or remote system inspections under Section 11.2(c) no more than once per twelve (12) month period during the term of the MSA (requests under Sections 11.2(a), (b), and (d) are not subject to this limit), unless: (a) a Security Incident has occurred; (b) Company has reasonable grounds to believe Vendor is not in compliance with this DPA; or (c) an audit is required by a supervisory authority or regulator. Vendor shall respond to written audit questionnaires within fifteen (15) business days, and within five (5) business days where the request follows a Security Incident. Audits shall be conducted during normal business hours and in a manner designed to minimize disruption to Vendor's operations.

11.4 Costs

Vendor shall bear its own costs of cooperating with audits. If an audit reveals material non-compliance with this DPA, Vendor shall promptly remediate such non-compliance at its own expense and shall reimburse Company for reasonable audit costs incurred.

12. Liability and Indemnification

12.1 Cross-Reference to MSA

The parties' respective liability and indemnification obligations with respect to Security Incidents, data breaches, unauthorized access, use, or disclosure of Personal Data, and violations of Applicable Data Protection Laws are governed by Sections 12 (Limitation of Liability) and 13 (Indemnification) of the MSA. Where the MSA so provides, data breaches are carved out from the aggregate liability cap; and the allocation set out in Section 12.2 controls to the extent of any inconsistency with the MSA. If the applicable Agreement does not contain limitation of liability or indemnification provisions addressing the matters described in this Section 12, then: (a) Vendor shall defend, indemnify, and hold harmless Company and its Affiliates, and their respective officers, directors, employees, and agents, from and against all claims, losses, damages, liabilities, fines, penalties, assessments, costs, and expenses (including reasonable attorneys' fees and the costs described in Section 8.5) arising out of the matters described in Section 12.2; and (b) Vendor's liability under this DPA shall not be subject to any cap, and no exclusion of indirect, incidental, consequential, special, punitive, or exemplary damages, or of lost profits or lost data, shall apply to Vendor's breach of this DPA or to any Security Incident; and (c) Company's aggregate liability arising out of this DPA shall not exceed the fees paid by Company under the applicable Order/SOW in the twelve (12) months preceding the claim, and Company shall not be liable for indirect, incidental, consequential, special, punitive, or exemplary damages or for lost profits.

12.2 Vendor Indemnification

Without limiting or duplicating the MSA's indemnification provisions, Vendor acknowledges that its indemnification obligations under Section 13 of the MSA extend to all claims (including class actions and representative actions), losses, damages, liabilities, costs, and expenses (including reasonable attorneys' fees and regulatory fines to the extent permitted by law) arising from or related to: (a) Vendor's breach of this DPA; (b) any Security Incident caused by Vendor or its Sub-processors; (c) Vendor's violation of Applicable Data Protection Laws; or (d) Vendor's unauthorized Processing of Personal Data; (e) Vendor's failure to comply with Sections 3.4, 3.5, 5.5, 5.6, 6, or 10; or (f) any claim by a Data Subject, Supervisory Authority, or Company customer arising from Vendor's Processing. Vendor's obligations under this Section are not subject to, and shall not be counted against, any limitation of liability, cap, or damages exclusion in the Agreement, and expressly include statutory damages and civil penalties (including under the CCPA/CPRA and the Illinois Biometric Information Privacy Act) and administrative fines imposed on Company to the extent attributable to Vendor's acts or omissions and to the extent such indemnification is permitted by applicable law.

12.3 Allocation of Responsibility

Vendor shall be liable for damages caused by Processing that violates this DPA or Applicable Data Protection Laws, or where Vendor has acted outside of or contrary to Company's lawful instructions, and for the acts and omissions of its Sub-processors and personnel. Where Company and Vendor are found jointly liable to a Data Subject or a Supervisory Authority, Vendor shall reimburse Company for any amount Company pays in excess of the portion of responsibility attributable to Company. Nothing in this DPA limits any right or remedy available to Company under Applicable Data Protection Laws, under the Agreement, or at law or in equity.

12.4 Equitable Relief

Vendor acknowledges that a breach or threatened breach of Sections 3, 5, 6, 8, 9, or 10 of this DPA would cause Company irreparable harm for which monetary damages would be an inadequate remedy, and that Company is entitled to seek specific performance, injunctive relief, and other equitable remedies without the necessity of posting a bond or proving actual damages, in addition to all other remedies available to it.

13. General Terms

13.1 Term

This DPA shall remain in effect for as long as Vendor processes Personal Data on behalf of Company under the MSA or any Order/SOW. Upon termination of the MSA, the provisions of this DPA that by their nature should survive (including Sections 3.4, 3.5, 5.6, 5.7, 8, 9, 10, 11, 12, 13.4, and 13.8) shall continue to apply until Vendor ceases all processing of Personal Data on behalf of Company.

13.2 Order of Precedence

In the event of a conflict between the terms of this DPA and the MSA with respect to the processing of Personal Data, this DPA shall prevail. In the event of a conflict between this DPA and the Standard Contractual Clauses (where applicable), the Standard Contractual Clauses shall prevail with respect to transfers subject to GDPR. In all other cases, this DPA controls.

13.3 Amendments

Company may update this DPA from time to time by posting a revised version at https://www.etched.com/legal/dpa and providing Vendor with at least thirty (30) days' written notice of material changes. Except for updates required to comply with changes in Applicable Data Protection Laws (which may be effective upon posting), material amendments shall take effect thirty (30) days after notice unless Vendor provides written objection within that period. If Vendor objects and the parties cannot resolve the objection within thirty (30) days, either party may terminate the affected Order/SOW upon written notice, and Vendor shall continue to comply with the version of this DPA in effect immediately before the update until Processing ceases. Vendor's continued Processing of Personal Data after the effective date of an update, absent a written objection delivered within the notice period, constitutes acceptance of the updated DPA. Company shall retain prior versions of this DPA, or a record of changes made, and make them available upon request.

13.4 Governing Law

This DPA shall be governed by and construed in accordance with the laws of the State of California, consistent with Section 16.g of the MSA, without regard to conflict of laws principles. However, the SCCs are governed by the law of Ireland as elected in Section 10.2(e), the UK IDTA is governed by the laws of England and Wales, and the Swiss Addendum is governed by Swiss law, in each case only with respect to the transfers to which they apply; and to the extent Applicable Data Protection Laws mandate the application of other law to specific provisions, that law shall govern only those provisions. Nothing in this Section limits Company's right to seek injunctive relief in any jurisdiction.

13.5 Severability

If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect. The invalid or unenforceable provision shall be reformed to the minimum extent necessary to make it valid and enforceable while preserving its original intent.

13.6 Entire Agreement

This DPA, together with the MSA and any applicable Orders/SOWs, constitutes the entire agreement between the parties with respect to the processing of Personal Data by Vendor on behalf of Company. This DPA supersedes any prior data processing agreements between the parties to the extent they relate to the same subject matter; provided that a data processing agreement or data protection addendum that has been negotiated and executed by both parties continues to apply, and controls, to the extent it affords Company greater protection than this DPA.

13.7 Contact Information

Company Contact for Data Protection Matters:

Etched, Inc.

Attn: Legal

3155 Olsen Drive, Suite 200, San Jose, CA 95117

Email: legal@etched.com

Vendor Contact for Data Protection Matters:

Vendor’s data protection contact, as identified in the applicable MSA, Order, or SOW, or as otherwise designated by Vendor in writing to Company from time to time. Vendor shall designate a named individual responsible for data protection matters and provide that individual's name, title, email address, and telephone number to Company; shall maintain a monitored 24x7 contact method for Security Incident notifications; and shall notify Company within five (5) business days of any change. Vendor shall also provide, on request, the full legal name, entity type, and registered address of each Vendor entity that Processes Personal Data, for the purpose of completing Annex I.A of the SCCs and Table 1 of the UK Addendum. Notices from Vendor under this DPA shall be sent to the Company addresses above and are effective upon receipt. Notices from Company to Vendor under this DPA may be given to the Vendor contact identified in the applicable Agreement, to Vendor's designated data protection or Security Incident contact, or to the last email address Vendor provided to Company, and are effective upon transmission.

13.8 No Third-Party Beneficiaries

Except for (a) Company's Affiliates, which are intended beneficiaries of this DPA and may enforce it directly against Vendor, and (b) Data Subjects, to the extent expressly provided in the SCCs or the UK IDTA, this DPA creates no rights in any third party.

13.9 Assignment and Change of Control

Vendor may not assign or transfer this DPA, or delegate any of its obligations under it, without Company's prior written consent. Vendor shall notify Company at least thirty (30) days before any change of control, merger, acquisition, or sale of substantially all assets affecting the entity that Processes Personal Data. If the acquiring or surviving entity is a competitor of Company, is subject to a restricted-party list or sanctions regime described in Section 6.6, or in Company's reasonable assessment presents a materially increased data protection or security risk, Company may terminate the affected Order/SOW or the MSA without penalty and require the return or deletion of Personal Data under Section 9.

13.10 Vendor Responsibility for Its Own Compliance

Nothing in this DPA obligates Vendor to Process Personal Data in a manner that violates Applicable Data Protection Laws. Vendor is solely responsible for determining whether it can comply with this DPA and with Applicable Data Protection Laws before accepting Personal Data, and Vendor's acceptance of Personal Data constitutes its representation that it can do so.

14. Sub-processor List and Records of Processing

Vendor shall maintain a current, accurate, and complete list of all Sub-processors authorized under Section 6 of this DPA, including each Sub-processor’s name, location, and the nature of the processing activity performed. Vendor shall make this list available to Company upon written request and shall provide advance notice of changes to the list in accordance with Section 6.2 of this DPA. Vendor shall also maintain, and make available to Company upon request, records of Processing sufficient to satisfy Article 30(2) of the GDPR and UK GDPR and the equivalent requirements of other Applicable Data Protection Laws, including the categories of Processing carried out, the countries in which Personal Data is Processed, and the transfer mechanisms relied upon. This list constitutes Annex III to the SCCs where applicable.